EDBT 2026 Demo / reviewers in the wild / expert
Luis Ibañez-Lissen
dblp:381/5993
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0001-8659-1275ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LUMIA: Linear Probing for Unimodal and MultiModal Membership Inference Attacks Leveraging Internal LLM States
Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Nicolas Anciaux, Joaquín García 0001 |
ESORICS (1) | 1 |
| 2025 | Large language models can learn and generalize steganographic chain-of-thought under process supervisionabstractChain-of-thought (CoT) reasoning not only enhances large language model performance but also provides critical insights into decision-making processes, marking it as a useful tool for monitoring model intent and planning. By proactively preventing models from acting on CoT indicating misaligned or harmful intent, CoT monitoring can be used to reduce risks associated with deploying models. However, developers may be incentivized to train away the appearance of harmful intent from CoT traces, by either customer preferences or regulatory requirements. However, recent works have shown that banning the mention of a specific example of reward hacking causes obfuscation of the undesired reasoning traces but the persistence of the undesired behavior, threatening the reliability of CoT monitoring. However, obfuscation of reasoning can be due to its internalization to latent space computation, or its encoding within the CoT. We provide an extension to these results with regard to the ability of models to learn a specific type of obfuscated reasoning: steganography. First, we show that penalizing the use of specific strings within load-bearing reasoning traces causes models to substitute alternative strings. Crucially, this does not alter the underlying method by which the model performs the task, demonstrating that the model can learn to steganographically encode its reasoning. This is an example of models learning to encode their reasoning. We further demonstrate that models can generalize an encoding scheme. When the penalized strings belong to an overarching class, the model learns not only to substitute strings seen in training, but also develops a general encoding scheme for all members of the class which it can apply to held-out testing strings. Robert MC Carthy, Joey Skaf, Luis Ibañez-Lissen, Vasil Georgiev, Connor Watts, Hannes Whittingham, Lorena González-Manzano, Cameron Tice, Edward James Young, Puria Radmard, David Lindner |
NeurIPS | 3 |
| 2025 | Detecting Multi-Turn Jailbreak Attacks in Large Language Models via Linear ProbesabstractMulti-turn jailbreak attacks are a prominent threat for Large Language Models (LLMs). While internal LLM data has been used for single-turn jailbreaks, its suitability for multi-turn ones remains unexplored. This paper proposes a mechanism leveraging linear probes on layer activations. Interestingly, it enables characterizing the anticipation (or Early Warning, EW) in the detection, which has never been measured. To support the assessment, a novel dataset with +10k harmful and harmless conversations is produced. Experiments on Llama, Qwen and Mistral models show that the approach is specially effective in Llama – for 5-turn attacks, max F1=0.7 and average EW =2.64). Moreover, our results suggest that the effectiveness decreases with bigger model sizes. Jorge Marina-Metola, José María de Fuentes, Lorena González-Manzano, Luis Ibañez-Lissen |
TrustCom | 4 |
| 2025 | LPASS: Linear Probes as Stepping Stones for vulnerability detection using compressed LLMsabstractLarge Language Models (LLMs) are being extensively used for cybersecurity purposes. One of them is the detection of vulnerable codes. For the sake of efficiency and effectiveness, compression and fine-tuning techniques are being developed, respectively. However, they involve spending substantial computational efforts. In this vein, we analyze how Linear Probes (LPs) can be used to provide an estimation on the performance of a compressed LLM at an early phase — before fine-tuning. We also show their suitability to set the cut-off point when applying layer pruning compression. Our approach, dubbed L P A S S , is applied in BERT and Gemma for the detection of 12 of MITRE’s Top 25 most dangerous vulnerabilities on 480k C/C++ samples. LPs can be computed in 142.97 s. and provide key findings: (1) 33.3 % and 72.2% of layers can be removed, respectively, with no precision loss; (2) they provide an early estimate of the post-fine-tuning and post-compression model effectiveness, with 3% and 8.68% as the lowest and average precision errors, respectively. L P A S S -based LLMs outperform the state of the art, reaching 86.9% of accuracy in multi-class vulnerability detection. Interestingly, L P A S S -based compressed versions of Gemma outperform the original ones by 1.6% of F1-score at a maximum while saving 29.4 % and 23.8% of training and inference time and 42.98% of model size. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Nicolas Anciaux |
J. Inf. Secur. Appl. | 1 |
| 2025 | Use of Transfer Learning for Affordable In-Context Fake Review GenerationabstractFake content is a noteworthy threat which is managed by assorted means. This is a serious problem for online shopping platforms whose products can be affected by negative or positive reviews. Artificial intelligence is commonly applied for fake review generation, being transfer learning a promising approach to reduce training requirements. However, the feasibility of generating in-context fake reviews using transfer learning has not been explored yet. This paper analyses the suitability of a couple of transformers (T5 and BART) to generate realistic in-context fake reviews. Results show that 1) the diversity of generated reviews is comparable to existing works; 2) human-based detection is close to random; 3) just reviews generated with one of the used transformers can be detected with 38% precision; and 1 h of training and 8 k real reviews are needed to produce realistic fake reviews. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Manuel Goyanes |
IEEE Trans. Big Data | 1 |
| 2024 | Continuous Authentication Leveraging Matrix ProfileabstractContinuous Authentication (CA) mechanisms involve managing sensitive data from users which may change over time. Both requirements (privacy and adapting to new users) lead to a tension in the amount and granularity of the data at stake. However, no previous work has addressed them together. This paper proposes a CA approach that leverages incremental Matrix Profile (MP) and Deep Learning using accelerometer data. Results show that MP is effective for CA purposes, leading to 99% of accuracy when a single user is authorized. Besides, the model can on-the-fly increase the set of authorized users up to 10 while offering similar accuracy rates. The amount of input data is also characterized – the last 15 s. of data in the user device require 0.4 MB of storage and lead to a CA accuracy of 97% even with 10 authorized users. Luis Ibañez-Lissen, José María de Fuentes, Lorena González-Manzano, Nicolas Anciaux |
ARES | 1 |
| 2024 | On the Feasibility of Predicting Volumes of Fake News - The Spanish CaseabstractThe growing amount of news shared on the Internet makes it hard to verify them in real-time. Malicious actors take advantage of this situation by spreading fake news to impact society through misinformation. An estimation of future fake news would help to focus the detection and verification efforts. Unfortunately, no previous work has addressed this issue yet. Therefore, this work measures the feasibility of predicting the volume of future fake news in a particular context—Spanish contents related to Spain. The approach involves different artificial intelligence (AI) mechanisms on a dataset of 298k real news and 8.9k fake news in the period 2019–2022. Results show that very accurate predictions can be reached. In general words, the use of long short-term memory (LSTM) with attention mechanisms offers the best performance, being headlines useful when a small amount of days is taken as input. In the best cases, when predictions are made for periods, an error of 10.3% is made considering the mean of fake news. This error raises to 28.7% when predicting a single day in the future. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Manuel Goyanes |
IEEE Trans. Comput. Soc. Syst. | 1 |