EDBT 2026 Demo / reviewers in the wild / expert
Eduardo Fernández-Medina
dblp:f/EduardoFernandezMedina
· DBLP profile ↗
10ranked-venue papers in the field
4as first author
3since 2021 · last 2025
0000-0003-2553-9320ORCID · verified
Domains — venue-derived; a paper can count in several
Database Systems & Data Management · 3 (2 first)Data Mining & Knowledge Discovery · 2Big Data, Cloud & Distributed Data Systems · 2Business Process & Enterprise Data · 2 (1 first)Knowledge Engineering, Semantic Web & Information Systems · 1 (1 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Early detection of backdoor attacks in federated learning via ecosystemic symmetry breakingabstractEvasive poisoning attacks such as semantic backdoors pose a growing threat to federated learning because they mimic benign client updates and evade detectors under secure aggregation. We introduce an unsupervised, per-client structural check that runs after each local round, before aggregation, requiring only compact statistical summaries derived from each client update after a geometric transformation that removes dependence on the global model. Client-update statistics are compared against a calibrated benign reference, and deviations are detected through statistical distances. Energy and Wasserstein-1 jointly define an operational pattern where threshold exceedances across projections reveal structural deviations even in apparently benign updates. Evaluated on canonical backdoor scenarios from Bagdasaryan et al., the method detects both strong and stealthy attacks in the first local round through consistent multi-projection threshold excesses, while benign updates show only isolated ones. The procedure is lightweight, unsupervised, compatible with secure aggregation, and does not require trigger datasets. By providing early per-client warnings before aggregation, it complements classical defenses such as norm clipping, differential privacy, and robust aggregation, enabling proactive mitigation of poisoning in federated learning. Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina |
BDCAT | 3 |
| 2025 | Towards a Framework for Personal and Domestic CybersecurityabstractThe expansion of the digital world increasingly surrounds us, making our lives easier and more connected. However, it also brings a range of risks and threats that we accept—sometimes consciously, sometimes unconsciously—for the sake of productivity or convenience. These cybersecurity risks affect almost every sector of society and have been mainly analyzed within government and corporate contexts. Despite this, comprehensive studies are still lacking for the personal and domestic sphere. In this domain, cybersecurity risks have a wide scope: they can affect the physical safety of individuals, lead to privacy breaches, or expose personal data for criminal use. Many other situations may also arise, severely impacting people in their everyday digital environment. This article analyzes previous work related to the lack of cybersecurity solutions for individuals in the personal domain. In addition, and given the absence of comprehensive approaches, it presents an initial version of a personal cybersecurity framework and a conceptual application model. Ángel Suarez-Bárcena, Antonio Santos-Olmo, Eduardo Fernández-Medina |
BDCAT | 3 |
| 2021 | Improving security in NoSQL document databases through model-driven modernizationabstractAbstract NoSQL technologies have become a common component in many information systems and software applications. These technologies are focused on performance, enabling scalable processing of large volumes of structured and unstructured data. Unfortunately, most developments over NoSQL technologies consider security as an afterthought, putting at risk personal data of individuals and potentially causing severe economic loses as well as reputation crisis. In order to avoid these situations, companies require an approach that introduces security mechanisms into their systems without scrapping already in-place solutions to restart all over again the design process. Therefore, in this paper we propose the first modernization approach for introducing security in NoSQL databases, focusing on access control and thereby improving the security of their associated information systems and applications. Our approach analyzes the existing NoSQL solution of the organization, using a domain ontology to detect sensitive information and creating a conceptual model of the database. Together with this model, a series of security issues related to access control are listed, allowing database designers to identify the security mechanisms that must be incorporated into their existing solution. For each security issue, our approach automatically generates a proposed solution, consisting of a combination of privilege modifications, new roles and views to improve access control. In order to test our approach, we apply our process to a medical database implemented using the popular document-oriented NoSQL database, MongoDB. The great advantages of our approach are that: (1) it takes into account the context of the system thanks to the introduction of domain ontologies, (2) it helps to avoid missing critical access control issues since the analysis is performed automatically, (3) it reduces the effort and costs of the modernization process thanks to the automated steps in the process, (4) it can be used with different NoSQL document-based technologies in a successful way by adjusting the metamodel, and (5) it is lined up with known standards, hence allowing the application of guidelines and best practices. Alejandro Maté, Jesús Peral Cortés, Juan Trujillo 0001, Carlos Blanco 0001, Diego García-Saiz, Eduardo Fernández-Medina |
Knowl. Inf. Syst. | 6 |
| 2018 | Towards a Security Reference Architecture for Big Data
Julio Moreno, Manuel A. Serrano, Eduardo Fernández-Medina, Eduardo B. Fernández |
DOLAP | 3 |
| 2018 | How the Conceptual Modelling Improves the Security on Document Databases
Carlos Blanco 0001, Diego García-Saiz, Jesús Peral Cortés, Alejandro Maté, Alejandro Oliver, Eduardo Fernández-Medina |
ER | 6 |
| 2009 | Towards a Modernization Process for Secure Data Warehouses
Carlos Blanco 0001, Ricardo Pérez-Castillo, Arnulfo Hernández, Eduardo Fernández-Medina, Juan Trujillo 0001 |
DaWaK | 4 |
| 2007 | Model-driven multidimensional modeling of secure data warehousesabstractData Warehouses (DW), Multidimensional (MD) databases, and On-Line Analytical Processing (OLAP) applications provide companies with many years of historical information for the decision-making process. Owing to the relevant information managed by these systems, they should provide strong security and confidentiality measures from the early stages of a DW project in the MD modeling and enforce them. In the last years, there have been some proposals to accomplish the MD modeling at the conceptual level. Nevertheless, none of them considers security measures as an important element in their models, and therefore, they do not allow us to specify confidentiality constraints to be enforced by the applications that will use these MD models. In this paper, we present an Access Control and Audit (ACA) model for the conceptual MD modeling. Then, we extend the Unified Modeling Language (UML) with this ACA model, representing the security information (gathered in the ACA model) in the conceptual MD modeling, thereby allowing us to obtain secure MD models. Moreover, we use the OSCL (Object Security Constraint Language) to specify our ACA model constraints, avoiding in this way an arbitrary use of them. Furthermore, we align our approach with the Model-Driven Architecture, the Model-Driven Security and the Model-Driven Data Warehouse, offering a proposal highly compatible with the more recent technologies. Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini |
Eur. J. Inf. Syst. | 1 |
| 2007 | Developing secure data warehouses with a UML extension
Eduardo Fernández-Medina, Juan Trujillo 0001, Rodolfo Villarroel, Mario Piattini |
Inf. Syst. | 1 |
| 2004 | Extending UML for Designing Secure Data Warehouses
Eduardo Fernández-Medina, Juan Trujillo 0001, Rodolfo Villarroel, Mario Piattini |
ER | 1 |
| 2003 | Designing Secure Databases for OLS
Eduardo Fernández-Medina, Mario Piattini |
DEXA | 1 |