EDBT 2026 Demo / reviewers in the wild / expert
Miguel L. Pardal
dblp:77/8922
· DBLP profile ↗
27ranked-venue papers
1as first author
15since 2021 · last 2025
0000-0003-2872-7300ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Road Sight Unit: Edge Image Processing for Vehicle Trajectory and Collision PredictionabstractRoad accidents remain a leading cause of harm despite advances in vehicle safety systems. Onboard sensors improve awareness but are limited by field of view and positioning. Effective collision warnings require timely and contextualized information for accurate trajectory prediction. This paper proposes the use of edge computing devices equipped with cameras to detect and track vehicles. It introduces a similarity-based trajectory predictor that combines vehicle movement history with road information, including lane structure, curvature, and likely paths. This approach achieved an average positional error of $50 \mathrm{~cm}(19.69 \mathrm{in})$ and improves the accuracy of collision prediction, achieving $83 \%$ compared to $50 \%$ with the baseline Extended Kalman Filter, while requiring less data than machine learning methods. It reduces false positives and enhances confidence in predicted trajectories, enabling earlier and more reliable collision detection. José Cutileiro, Pedro Rosa, Orlando Remédios, Miguel L. Pardal |
NCA | 4 |
| 2025 | EvoChain: A Recovery Approach for Permissioned Blockchain ApplicationsabstractBlockchain technology provides decentralized data storage and processing. It can ensure data integrity and auditability. Many applications now adopt it in scenarios with multiple stakeholders and shared ownership, such as supply chain management. However, strict immutability makes it difficult to correct mistakes or intrusions in real-world deployments.This paper presents EvoChain, a chaincode extension for Hyperledger Fabric, a permissioned blockchain platform. EvoChain adds controlled mutability, allowing data to be corrected or recovered under time-limited or specific conditions. Changes can be made during a grace period, after which immutability is enforced again.We evaluated our approach with WineTracker, a supply chain application. It was modified to allow some users to cancel unwanted operations while preserving the security and consistency of data in the blockchain. Performance results show minimal overhead with functional benefits. Francisco Faria, Samih Eisa, David R. Matos, Miguel L. Pardal |
NCA | 4 |
| 2025 | Bonsai: A Recovery Approach for Ethereum ERC-20 TransactionsabstractBlockchain technology offers a mechanism for storing data with cryptographic links between blocks, creating a tamper-resistant ledger. Although this immutability ensures data integrity, it complicates recovery in cases of errors or intrusions. This work proposes Bonsai, an error and intrusion recovery system designed for token exchanges on Ethereum based applications. The system includes a custom ERC-20 token (BON) that maintains a one to one peg with ETH tokens while enabling transaction reversals through arbitration trials and an insurance mechanism to protect users against losses. Our experimental evaluation on Ethereum Sepolia and ZKsync Sepolia demonstrates that Bonsai can successfully trace and reverse token flows through up to five wallets in under 20 seconds, at an average cost of approximately ${\$}$0.30 on ZKsync. Existing blockchain recovery approaches are slow and costly, with reversal operations taking up to 126 seconds, and some may not be able to complete the reversal. The system provides a practical solution for blockchain applications requiring error and intrusion correction capabilities while preserving the authentication, integrity, immutability, and non-repudiation properties of Blockchain. Diogo Melita, David R. Matos, Miguel L. Pardal |
NCA | 3 |
| 2025 | CC2C: Confidential Channel-to-Channel Data Exchange in a Permissioned BlockchainabstractBlockchain technology is increasingly studied as a means to replace trusted intermediaries in consortium settings. While permissioned blockchains offer better control and security, they face the challenge of balancing decentralization with local governance. Each organization must define and enforce its own access rules, which complicates collaboration. In particular, ensuring data confidentiality is challenging, as data owners are often very strict about what to share and with whom.This paper presents the design of mechanism for secure and confidential data sharing between separate blockchain organization groups. It leverages channels in Hyperledger Fabric to achieve data isolation but also includes the ability to filter and transform the data to be shared. A case study in fruit traceability demonstrates how the proposal meets important requirements of real-world supply chains. Emanuel Nunes, Samih Eisa, Miguel L. Pardal, Mário Calha |
NCA | 3 |
| 2025 | SafeBike: improving collision warnings using wayward path predictionabstractEuropean cities face rising safety concerns with the growing use of bicycles and e-scooters, which now account for approximately 10% of EU road fatalities. A major challenge in protecting these vulnerable road users stems from their unpredictable and variable movement patterns, often referred to as "wayward paths", where they frequently shift between bike lanes, roadways, and sidewalks depending on what feels safe or convenient at the moment. To address this, we extend an existing smartphone-based early warning system to integrate short-term trajectory prediction and road geometry to enhance collision avoidance and enable timely alerts. The system was evaluated with simulations and field experiments. The results show a significant improvement in short-term trajectory prediction accuracy, reducing the mean spatial error by up to 40% compared to baseline methods, making it a reliable positioning system for complex urban roads. Simão Gato, Pedro Rosa, Orlando Remédios, Miguel L. Pardal |
VTC2025-Fall | 4 |
| 2024 | SafeWalk: Early Warning System for PedestriansabstractPedestrians on streets are exposed to dangerous situations, particularly when large vehicles cross urban areas and visibility is limited. However, there is a potential way to mitigate these dangers, as sensor technologies are increasingly ubiquitous in vehicles and nearly everyone carries a smartphone.This paper presents a safety application for pedestrians that uses Bluetooth Low Energy (BLE) in smartphones to broadcast Personal Safety Messages (PSMs) with the position, speed and heading of walkers. We started by evaluating the performance of BLE in some smartphone models and obtained very promising results. This technology can provide information even without a direct line of sight between the driver and the pedestrian. Then we developed an Android application with an algorithm for managing the data exchanged between the two parties. The PSMs received by the vehicles are compared with their current location to determine whether a collision will occur, and the driver is warned accordingly. We evaluated in different scenarios, two of which are also used in Euro NCAP tests since 2020. The results are very encouraging because detections were achieved in a timely manner, resulting in a practical early warning system. Diogo Dias, Pedro M. Rosa, Miguel L. Pardal |
VTC Fall | 3 |
| 2023 | Decentralized position detection for moving vehiclesabstractModern cars are equipped with sensors that can detect other moving vehicles and obstacles on the road. However, their range is usually limited to line-of-sight and their accuracy is also limited. To provide information beyond the sensor range, each vehicle broadcasts Basic Safety Messages (BSMs) with its position and speed. For road awareness, it would be best if multiple vehicles could confirm the position (redundancy), using their on-board sensors for verification (diversity), and excluding position and speed errors (plausibility). This paper presents a decentralized solution that uses multiple vantage points to provide more trust in moving vehicle position data. It extends broadcast messages with sensor verification and plausibility filtering. It processes a stream of data from nearby vehicles and for short time periods, to achieve the safety benefits without the privacy risks of long-term data retention. The proposal was evaluated with detailed simulations with different levels of traffic and misbehavior. It provides good detection results with only a limited increase in network and computing resources. Francesco Pollicino, Samih Eisa, Pedro M. Rosa, Miguel L. Pardal, Mirco Marchetti |
VTC2023-Spring | 4 |
| 2023 | MultiTLS: using multiple and diverse ciphers for stronger secure channels
Ricardo Moura, Ricardo Lopes, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Comput. Secur. | 4 |
| 2023 | MIRES: Intrusion Recovery for Applications Based on Backend-As-a-ServiceabstractThe Backend-as-a-Service (BaaS) cloud computing model supports many modern popular mobile applications because it simplifies the development and management of services such as data storage, user authentication, and notifications. However, vulnerabilities and other issues may allow malicious actions on the client side to have impact on the backend, i.e., to corrupt the state of the application in the cloud. To deal with these attacks – after they occur and are successful – it is necessary to remove the direct effects of malicious requests and the effects derived from later operations on corrupted data. We introduce MIRES, the first intrusion recovery service for mobile applications based on the BaaS model. MIRES uses a two-stage recovery process that restores the integrity of the mobile application and minimizes its unavailability. MIRES provides multi-service recovery for applications that use more than one data store. We implemented MIRES for Android and for the Firebase cloud-based BaaS platform. We did experiments on 4 mobile applications which showed that MIRES can revert hundreds to thousands of operations in seconds, with an associated unavailability of the application also in the range of seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | Sanare: Pluggable Intrusion Recovery for Web ApplicationsabstractWeb applications are exposed to many threats and, despite the best defensive efforts, are often successfully attacked. Reverting the effects of an attack on the state of such an application requires a profound knowledge about the application, to understand what data did the attack corrupt. Furthermore, it requires knowing what steps are needed to revert the effects without modifying legitimate data created by legitimate users. Existing intrusion recovery systems are capable of reverting the effects of the attack but they require modifications to the source code of the application, which may be unpractical. We presentSanare, a pluggable intrusion recovery system designed for web applications that use different data storage systems to keep their state. Sanare does not require any modification to the source code of the application or the web server. Instead, it uses a new deep learning scheme that we also introduce in the article,Matchare, that learns the matches between the HTTP requests and the database statements, file system operations, and web service requests that the HTTP requests caused. We evaluated Sanare with three open source web applications: WordPress, GitLab and ownCloud. In our experiments, Matchare achieved precision and recall higher than 97.5% with a performance overhead of less than 18% to the application. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | A Study on the Best Way to Compress Natural Language Processing ModelsabstractCurrent research in Natural Language Processing shows a growing number of models extensively trained with large computational budgets. However, these models present computationally demanding requirements, preventing them from being deployed in devices with strict resource and response latency limitations. In this paper, we apply state-of-the-art model compression techniques to create compact versions of several of these models. In order to evaluate whether the trade-off between model performance and budget is worthwhile, we evaluate them in terms of efficiency, model simplicity and environmental foot-print. We also present a brief comparison between uncompressed and compressed models when running in low-end hardware. João Antunes, Miguel L. Pardal, Luísa Coheur |
FUZZ-IEEE | 2 |
| 2022 | SureRepute: Reputation System for Crowdsourced Location WitnessesabstractLocation is an important attribute for many mobile applications but it needs to be verified. For example, a user of a tourism application that gives out rewards can falsify his location to pretend that he has visited many attractions and thus receive benefits without deserving them. To counter these attacks, the system asks users to prove their location through witnesses, i.e., other devices that happen to be at the location at the same time and that can be partially trusted. However, for this approach to be effective, it is important to keep track of the witness behavior over time. Many crowdsourcing applications, like Waze, build up reputations for their users, and rely on user co-location and redundant inputs for data verification.In this work, we present SureRepute, a reputation system capable of withstanding reputation attacks while still maintaining user privacy. The results show that the system is able to protect itself and its configuration is flexible, allowing different trade-offs between security and usability, as required in real-world applications. The experiments show how the reputation system can be easily integrated into existing applications without producing a significant overhead in response times. Rafael Figueiredo, Samih Eisa, Miguel L. Pardal |
NCA | 3 |
| 2022 | Bluetooth Peer-to-Peer Location Certification with a Gamified Mobile ApplicationabstractNowadays, tourists turn to digital platforms to discover new places to explore. CROSS City is a smart tourism mobile application that enhances the user experience of tourists visiting points of interest in a route by rewarding them in the end, if they actually visited all locations. From a technical standpoint, the user location is certified resorting to strategies that take advantage of both the diversity of the existing Wi-Fi network infrastructure throughout the city, as well as the presence of other users at the same site using Bluetooth. This work developed a new, peer-to-peer location certification strategy and added gamification elements to encourage users to keep the wireless radios turned on and use the app more. This work was evaluated both in laboratory experiments and with users in a real-world scenario which demonstrated that the new Bluetooth peer-based strategy is both feasible and resistant to collusion attacks. Ricardo Grade, Samih Eisa, Miguel L. Pardal |
NCA | 3 |
| 2022 | LoCaaS: Location-Certification-as-a-ServiceabstractMillions of tourists each year use smartphone applications to discover points of interest. Despite relying heavily on location sensing, most of them are susceptible to location spoofing, but not all. CROSS City is a smart tourism application that rewards users for completing tourist itineraries and uses location certificates to prevent attacks. In this case, the location verification relies on the periodic collection of public Wi-Fi network observations by multiple users to make sure the travelers actually went to the points of interest.In this paper, we introduce the Location-Certification-as-a-Service (LoCaaS) approach, supported by a cloud-native and improved location certification system, capable of producing and validating time-bound location proofs using network data collected by tourists’ mobile devices. We show that the system can efficiently compute the stable and transient networks for a given location that are used, respectively, to validate the location of a tourist and to prove the time-of-visit. The system was deployed to the Google Cloud Platform and was validated with performance experiments and a real-world deployment. Lucas H. Vicente, Samih Eisa, Miguel L. Pardal |
NCA | 3 |
| 2021 | Secure protocol buffers for Bluetooth Low-Energy communication with wearable devicesabstractWearable devices are further connecting people to the world, extending the reach of smartphones and the Internet. New applications are possible such as activity and location tracking that allows health monitoring and increased access to health services. Bluetooth Low-Energy (BLE) is a pivotal technology for this vision, as it allows power-efficient network connections to smartphones and to service infrastructure. However, there are design flaws and implementation vulnerabilities in BLE that affect the most widely used chipsets and operating systems. In this paper, we present POSE, an end-to-end security layer, that can mitigate attacks on BLE pairing and link-layer communications. POSE uses protocol buffers for efficient message data serialization/deserialization and, on top of them, provides message confidentiality and authenticity, including message freshness. POSE was implemented and its processing time, packet overhead, and CPU usage were evaluated. The results show that POSE is an efficient solution for secure communication with wearables and other constrained devices, especially when they already use protocol buffers. Miguel C. Francisco, Samih Eisa, Miguel L. Pardal |
NCA | 3 |
| 2020 | MIRES: Recovering Mobile Applications based on Backend-as-a-Service from Cyber AttacksabstractMany popular mobile applications rely on the Backend-as-a-Service (BaaS) cloud computing model to simplify the development and management of services like data storage, user authentication and notifications. However, vulnerabilities and other issues may lead to malicious operations on the mobile application client-side and malicious requests being sent to the backend, corrupting the state of the application in the cloud. To deal with these attacks after they happen and are successful, it is necessary to remove the immediate effects created by the malicious requests and subsequent effects derived from later requests. In this paper, we present MIRES, an intrusion recovery service for mobile applications based on BaaS. MIRES uses a two-phase recovery process that restores the integrity of the mobile application and minimizes its unavailability. We implemented MIRES in Android and with the Firebase platform and made experiments with 3 mobile applications that showed results of 1000 operations reverted in less than 1 minute and with the mobile application inaccessible only for less than 15 seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
MobiQuitous | 3 |
| 2020 | Recoverable Token: Recovering from Intrusions against Digital Assets in EthereumabstractBlockchain systems allow storing digital assets in a tamper-proof, consensus-based, append-only ledger in a decentralized fashion, where no single party has full control. A blockchain is an immutable, append-only, log of transactions. Unfortunately, in some cases there is the need to undo transactions that result from intrusions, e.g., when the private keys of a wallet are stolen, when one of the transaction participants does not comply with what was agreed upon, or when smart contract vulnerabilities are exploited by attackers. There are also accidental scenarios, e.g., when private keys are lost leaving the associated digital assets inaccessible. Although there have been a few proposals which allow modifications to the blockchain, they break the basic guarantees they are supposed to provide. We propose an approach for wallet owners to recover from attacks against their digital assets and accidental loss, while still assuring fundamental properties of the blockchain technology. We implemented the mechanism for Ethereum / EVM. Filipe F. Martins, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 3 |
| 2020 | MultiTLS: Secure Communication Channels with Cipher Suite Diversity
Ricardo Moura, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
SEC | 3 |
| 2018 | RockFS: Cloud-backed File System Resilience to Client-Side AttacksabstractCloud-backed file systems provide on-demand, high-availability, scalable storage. Their security may be improved with techniques such as erasure codes and secret sharing to fragment files and encryption keys in several clouds. Attacking the server-side of such systems involves penetrating one or more clouds, which can be extremely difficult. David R. Matos, Miguel L. Pardal, Georg Carle, Miguel Correia 0001 |
Middleware | 2 |
| 2018 | Tamper-Proof Incentive Scheme for Mobile Crowdsensing SystemsabstractPeople are increasingly connected to the Internet through their smartphones and each of these mobile devices has a wide range of sensors. The users themselves can be asked short questions about what they see. This crowdsensing has the potential to improve our daily lives by providing actual data about the environment and the use of services. However, there are significant obstacles to user participation like resource consumption and privacy concerns. There is a need for incentives to motivate the users. In this paper, we propose a tamper-proof incentive scheme for a mobile crowdsensing system that supports open sensing, with both automated and manual participation. We implemented a prototype of the system with server components and a mobile application. The proposed incentive scheme implements a tit-for-tat approach: positive user participation is rewarded with points that are stored in a shared record. This incentive ledger uses a Blockchain so that it can be trusted by every participant. The evaluation results show that the proposed scheme is practical and can be used to motivate increased participation in crowdsensing. Diogo Calado, Miguel L. Pardal |
NCA | 2 |
| 2018 | Witness-Based Location Proofs for Mobile DevicesabstractLocation-aware mobile applications are gaining popularity. This growth has caused the emergence of services that are offered to the users only when they are at specific locations. To implement valuable services, like a product sale, it is necessary to verify the presence of the user's device in a way which can be reliably trusted by the providers. This paper presents a system to support the creation of proofs that the user's device is at a claimed location. The system relies on different techniques for location estimation and on witness devices to testify to the presence of the user's device. A prototype was implemented and evaluated in regard to response times, accuracy of location estimates, and feasibility of proof exchanges. The results show that the solution is both practical and useful. Miguel L. Pardal |
NCA | 2 |
| 2017 | Rectify: black-box intrusion recovery in PaaS cloudsabstractWeb applications hosted on the cloud are exposed to cyberattacks and can be compromised by HTTP requests that exploit vulnerabilities. Platform as a Service (PaaS) offerings often provide a backup service that allows restoring application state after a serious attack, but all valid state changes since the last backup are lost. We propose Rectify, a new approach to recover from intrusions on applications running in a PaaS. Rectify is a service designed to be deployed alongside the application in a PaaS container. It does not require modifications to the software and the recovery can be performed by a system administrator. Machine learning techniques are used to associate the requests received by the application to the statements issued to the database. Rectify was evaluated using three widely used web applications - Wordpress, LimeSurvey and MediaWiki - and the results show that the effects of malicious requests can be removed whilst preserving the valid application data. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Middleware | 2 |
| 2017 | Vulnerability-Tolerant Transport Layer SecurityabstractSSL/TLS communication channels play a very important role in Internet security, including cloud computing and server infrastructures. There are often concerns about the strength of the encryption mechanisms used in TLS channels. Vulnerabilities can lead to some of the cipher suites once thought to be secure to become insecure and no longer recommended for use or in urgent need of a software update. However, the deprecation/update process is very slow and weeks or months can go by before most web servers and clients are protected, and some servers and clients may never be updated. In the meantime, the communications are at risk of being intercepted and tampered by attackers. In this paper we propose an alternative to TLS to mitigate the problem of secure commu- nication channels being susceptible to attacks due to unexpected vulnerabilities in its mechan- isms. Our solution, called Vulnerability-Tolerant Transport Layer Security (vtTLS), is based on diversity and redundancy of cryptographic mechanisms and certificates to ensure a secure communication even when one or more mechanisms are vulnerable. Our solution relies on a combination of k cipher suites which ensure that even if k − 1 cipher suites are insecure or vul- nerable, the remaining cipher suite keeps the communication channel secure. The performance and cost of vtTLS were evaluated and compared with OpenSSL, one of the most widely used implementations of TLS. André Joaquim, Miguel L. Pardal, Miguel Correia 0001 |
OPODIS | 2 |
| 2016 | DARSHANA: Detecting route hijacking for communication confidentialityabstractThe Border Gateway Protocol (BGP) plays a critical role in the Internet providing connectivity to hosts across the world. Unfortunately, due to its limited security, attackers can hijack traffic by generating invalid routes. Some detection systems for route hijacking have been presented, but they require non-public information, high resources, or can easily be circumvented by attackers. We propose DARSHANA, a monitoring solution that detects route hijacking based solely on data-plane information, and has enough redundancy to prevent attacker countermeasures such as dropping of traceroute probes. DARSHANA uses active probing techniques that enable detection in near real-time. By using diverse methods, DARSHANA can still detect attacks even if the adversary manages to counter some techniques. We show that our solution allows effective detection of many hijacking attacks by emulating them using PlanetLab and Amazon AWS. Karan Balu, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 2 |
| 2016 | vtTLS: A vulnerability-tolerant communication protocolabstractWe present VTTLS, a vulnerability-tolerant communication protocol. There are often concerns about the strength of some of the encryption mechanisms used in SSL/TLS channels, with some regarded as insecure at some point in time. VTTLS is our solution to mitigate the problem of secure communication channels being vulnerable to attacks due to unexpected vulnerabilities in encryption mechanisms. It is based on diversity and redundancy of cryptographic mechanisms and certificates to provide a secure communication channel even when one or more mechanisms are vulnerable. VTTLS relies on a combination of k cipher suites. Even if k-1 cipher suites are insecure or vulnerable, VTTLS relies on the remaining cipher suites to maintain the channel secure. We evaluated the performance of VTTLS by comparing it to an OpenSSL channel. André Joaquim, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 2 |
| 2016 | MACHETE: Multi-path communication for securityabstractCommunication through the Internet raises privacy and confidentiality concerns. Protocols such as HTTPS may be used to protect the communication, but occasionally vulnerabilities that may allow snooping on packet content are discovered. To address this issue, we present MACHETE, an application-layer multi-path communication mechanism that provides additional confidentiality by splitting data streams in different physical paths. MACHETE has to handle two challenges: sending packets over different paths when Internet's routing imposes a single path between pairs of network interfaces; splitting streams of data sent over TCP connections. MACHETE is the first to exploit MultiPath TCP (MPTCP) for security purposes. It leverages overlay networks and multihoming to handle the first challenge and MPTCP to handle the second. MACHETE establishes an overlay network and scatters the data over the available paths, thus reducing the effectiveness of snooping attacks. Mechanisms are provided to select paths based on path diversity. Diogo Raposo, Miguel L. Pardal, Luís E. T. Rodrigues, Miguel Correia 0001 |
NCA | 2 |
| 2012 | Improving Web Services Performance, One Step at a Time
Miguel L. Pardal, Joana Paulo Pardal, José Alves Marques |
CLOSER | 1 |