Gregorio Martínez Pérez

dblp:p/GregorioMartinezPerez · DBLP profile ↗
← Back
101ranked-venue papers
4as first author
46since 2021 · last 2026
0000-0001-5532-6604ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 12 since 2021Computer networks · 22 · 1 first-author · 9 since 2021Artificial intelligence and machine learning · 16 · 11 since 2021Systems, architecture and hardware · 15 · 6 since 2021Software engineering, systems software and programming languages · 6 · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 FedEnD: Communication-efficient Federated Learning for non-IID data via decentralized ensemble distillation
abstract
Federated Learning (FL) offers a paradigm for collaborative AI that mitigates raw data exposure, yet the statistical heterogeneity of client data severely constrains its practical application. This non-independent and identically distributed (non-IID) setting induces client drift, leading to unstable optimization and degraded generalization, particularly for under-represented classes. Existing solutions present a difficult trade-off: iterative, regularization-based methods suffer from high communication overhead and a centralized bottleneck, while knowledge-distillation-based approaches rely on impractical artifacts, such as shared public datasets. This work introduces FedEnD , a novel framework that addresses the previous challenge through an efficient, fully decentralized architecture. FedEnD employs a two-stage protocol that decouples local specialist training from a collaborative fusion stage. Following a communication-free training phase, clients perform a one-shot peer-to-peer broadcast that shares (optionally privatized) specialist parameters and lightweight class-count statistics. Each client then uses these statistics to construct a class-distribution-weighted teacher ensemble from the received specialists. Crucially, this ensemble’s knowledge is distilled into a robust global model on each client, using only their local data as unlabeled inputs, obviating the need for a central server or auxiliary data. Extensive experiments on MNIST, FashionMNIST, SVHN, and CIFAR-10 demonstrate that FedEnD outperforms baselines, surpassing robust methods such as SCAFFOLD by +5.7% on complex datasets in pathologically skewed settings. This superior accuracy is achieved while reducing communication bandwidth by 68.6% compared to standard iterative averaging, and by up to 84% compared to gradient-correction methods like SCAFFOLD, highlighting a favorable trade-off between accuracy and communication bandwidth in decentralized learning under severe non-IID partitions.
Enrique Tomás Martínez Beltrán, Philip Giryes, Gérôme Bovet, Burkhard Stiller, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Future Gener. Comput. Syst.5
2025 ProFe: Communication-Efficient Decentralized Federated Learning via Distillation and Prototypes
abstract
Decentralized Federated Learning (DFL) trains models in a collaborative and privacy-preserving manner while removing model centralization risks and improving communication bottlenecks. However, DFL faces challenges in efficient communication management and model aggregation within decentralized environments, especially with heterogeneous data distributions. Thus, this paper introduces ProFe, a novel communication optimization algorithm for DFL that combines knowledge distillation, prototype learning, and quantization techniques. ProFe utilizes knowledge from large local models to train smaller ones for aggregation, incorporates prototypes to better learn unseen classes, and applies quantization to reduce data transmitted during communication rounds. The performance of ProFe has been validated and compared to the literature by using benchmark datasets like MNIST, CIFAR10, and CIFAR100. Results showed that the proposed algorithm reduces communication costs by up to$\approx 40-50 \%$while maintaining or improving model performance. In addition, it adds$\approx 20 \%$training time due to increased complexity, generating a trade-off.
Pedro Miguel Sánchez Sánchez, Enrique Tomás Martínez Beltrán, Miguel Fernández Llamas, Gérôme Bovet, Gregorio Martínez Pérez, Alberto Huertas Celdrán
ICC5
2025 S-VOTE: Similarity-based Voting for Client Selection in Decentralized Federated Learning
abstract
Decentralized Federated Learning (DFL) enables collaborative, privacy-preserving model training without relying on a central server. This decentralized approach reduces bottlenecks and eliminates single points of failure, enhancing scalability and resilience. However, DFL also introduces challenges, such as suboptimal models with non-IID data distributions, increased communication overhead, and resource usage. Thus, this work proposes S-VOTE, a voting-based client selection mechanism that optimizes resource usage and enhances model performance in federations with non-IID data conditions. S-VOTE considers an adaptive strategy for spontaneous local training that addresses participation imbalance, allowing underutilized clients to contribute without significantly increasing resource costs. Extensive experiments on benchmark datasets demonstrate the S-VOTE effectiveness. More in detail, it achieves lower communication costs by up to 21%, 4-6% faster convergence, and improves local performance by 9-17% compared to baseline methods in some configurations, all while achieving a 14-24% energy consumption reduction. These results highlight the potential of S-VOTE to address DFL challenges in heterogeneous environments.
Pedro Miguel Sánchez Sánchez, Enrique Tomás Martínez Beltrán, Chao Feng 0001, Gérôme Bovet, Gregorio Martínez Pérez, Alberto Huertas Celdrán
IJCNN5
2025 De-VertiFL: A Solution for Decentralized Vertical Federated Learning
abstract
Federated Learning (FL), introduced in 2016, was designed to enhance data privacy in collaborative model training environments. Among the FL paradigm, horizontal FL, where clients share the same set of features but different data samples, has been extensively studied in both centralized and decentralized settings. In contrast, Vertical Federated Learning (VFL), which is crucial in real-world decentralized scenarios where clients possess different, yet sensitive, data about the same entity, remains underexplored. Thus, this work introduces De-VertiFL, a novel solution for training models in a decentralized VFL setting. De-VertiFL contributes by introducing a new network architecture distribution, an innovative knowledge exchange scheme, and a distributed federated training process. Specifically, De-VertiFL enables the sharing of hidden layer outputs among federation clients, allowing participants to benefit from intermediate computations, thereby improving learning efficiency. De-VertiFL has been evaluated using a variety of well-known datasets, including both image and tabular data, across binary and multiclass classification tasks. The results demonstrate that De-VertiFL generally surpasses state-of-the-art methods in F1-score performance, while maintaining a decentralized and privacy-preserving framework.
Alberto Huertas Celdrán, Chao Feng 0001, Sabyasachi Banik, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
NOMS5
2025 When Brain-Computer Interfaces meet the metaverse: Landscape, demonstrator, trends, challenges, and concerns
abstract
The metaverse has gained tremendous popularity in recent years, allowing the interconnection of users worldwide. However, current systems in metaverse scenarios, such as virtual reality glasses, offer a partial immersive experience. In this context, Brain–Computer Interfaces (BCIs) can introduce a revolution in the metaverse, although a study of the applicability and implications of BCIs in these virtual scenarios is required. Based on a limited number of publications, this work reviews the applicability of BCIs in the metaverse, analyzing the current status of this integration based on different categories related to virtual worlds and the evolution of BCIs in these scenarios in the medium and long term. This work also proposes the design and implementation of a general framework that integrates BCIs with different data sources from sensors and actuators (e.g., VR glasses) based on a modular design to be easily extended. This manuscript also validates the framework in a demonstrator consisting of driving a car within a metaverse, using a BCI for neural data acquisition, a VR headset to provide realism, and a steering wheel and pedals. Four use cases (UCs) are selected, focusing on cognitive and emotional assessment of the driver, detection of drowsiness, and driver authentication while using the vehicle. The results demonstrate the applicability of BCIs to metaverse scenarios using the proposed framework, achieving over 80% F1-score for all UCs, with performance close to 100% for detecting emotions and authenticating users. Moreover, this manuscript offers an analysis of BCI trends in the metaverse, also identifying future challenges that the intersection of these technologies will face. Finally, it reviews the concerns that using BCIs in virtual world applications could generate according to different categories: accessibility, user inclusion, privacy, cybersecurity, physical safety, and ethics.
Sergio López Bernal, Mario Quiles Pérez, Enrique Tomás Martínez Beltrán, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Neurocomputing4
2025 Neural cyberattacks applied to the vision under realistic visual stimuli
abstract
Brain-Computer Interfaces (BCIs) are systems traditionally used in medicine and designed to interact with the brain to record or stimulate neurons. Despite their benefits, the literature has demonstrated that invasive BCIs focused on neurostimulation present vulnerabilities allowing attackers to gain control. In this context, neural cyberattacks emerged as threats able to disrupt spontaneous neural activity by performing neural overstimulation or inhibition. Previous work validated these attacks in small-scale simulations with a reduced number of neurons, lacking real-world complexity. Thus, this work tackles this limitation by analyzing the impact of two existing neural attacks, Neuronal Flooding (FLO) and Neuronal Jamming (JAM), on a complex neuronal topology of the primary visual cortex of mice consisting of approximately 230,000 neurons, tested on three realistic visual stimuli: flash effect, movie, and drifting gratings. Each attack was evaluated over three relevant events per stimulus, also testing the impact of attacking 25 % and 50 % of the neurons. The results, based on the number of spikes and shift percentage metrics, showed that the attacks caused the greatest impact on the movie, while dark and static events exhibited highest resilience. Although both attacks can significantly affect neural activity, JAM was generally more damaging, producing longer temporal delays, and had a larger prevalence. Finally, JAM did not require altering many neurons to significantly affect neural activity, while the impact of FLO increased with the number of neurons attacked. • Evaluation of two neural cyberattacks on a realistic simulation of the visual cortex. • Use of a rich topology with 230,000 neurons from six cortical layers. • Attacks tested on different events within three visual stimuli used as visual input. • Evaluation of both threats using two metrics: number of spikes and shift percentage. • Both attacks can disrupt neural activity, having effects lasting for hundreds of milliseconds.
Victoria Magdalena López Madejska, Sergio López Bernal, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Neurocomputing3
2025 CyberForce: A Federated Reinforcement Learning Framework for Malware Mitigation
abstract
Recent research has shown that the integration of Reinforcement Learning (RL) with Moving Target Defense (MTD) can enhance cybersecurity in Internet-of-Things (IoT) devices. Nevertheless, the practicality of existing work is hindered by data privacy concerns associated with centralized data processing in RL, and the unsatisfactory time needed to learn right MTD techniques that are effective against a rising number of heterogeneous zero-day attacks. Thus, this work presents CyberForce, a framework that combines Federated and Reinforcement Learning (FRL) to collaboratively and privately learn suitable MTD techniques for mitigating zero-day attacks. CyberForce integrates device fingerprinting and anomaly detection to reward or penalize MTD mechanisms chosen by an FRL-based agent. The framework has been deployed and evaluated in a scenario consisting of ten physical devices of a real IoT platform affected by heterogeneous malware samples. A pool of experiments has demonstrated that CyberForce learns the MTD technique mitigating each attack faster than existing RL-based centralized approaches. In addition, when various devices are exposed to different attacks, CyberForce benefits from knowledge transfer, leading to enhanced performance and reduced learning time in comparison to recent works. Finally, different aggregation algorithms used during the agent learning process provide CyberForce with notable robustness to malicious attacks.
Chao Feng 0001, Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Jan Kreischer, Jan von der Assen, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
IEEE Trans. Dependable Secur. Comput.7
2024 Evaluating the impact of contextual information on the performance of intelligent continuous authentication systems
abstract
Nowadays, the usage of computers ranges from activities that do not consider sensitive data, such as playing video games, to others managing confidential information, like military operations. Additionally, regardless of the actions performed by subjects, most computers store different pieces of sensitive data, making the implementation of robust security mechanisms a critical and mandatory task. In this context, continuous authentication has been proposed as a complementary mechanism to improve the limitations of conventional authentication methods. However, mainly driven by the evolution of Machine Learning (ML), a series of challenges related to authentication performance and, therefore, the feasibility of existing systems are still open. This work proposes the usage of contextual information related to the applications executed in the computers to create ML models able to authenticate subjects continuously. To evaluate the suitability of the proposed context-aware ML models, a continuous authentication framework for computers has been designed and implemented. Then, a set of experiments with a public dataset with 12 subjects demonstrated the improvement of the proposed approach compared to the existing ones. Precision, recall, and F1-Score metrics are raised from an average of 0.96 (provided by general ML models proposed in the literature) to 0.99-1.
Pedro Miguel Sánchez Sánchez, Adrián Abenza Cano, Alberto Huertas Celdrán, Gregorio Martínez Pérez
ARES4
2024 Unlocking the Potential of Knowledge Graphs: A Cyber Defense Ontology for a Knowledge Representation and Reasoning System
abstract
In today’s dynamic and complex warfare landscape, characterized by the convergence of traditional and emerging threats, the significance of cybersecurity in shaping modern conflicts cannot be overstated. Such trend presents a challenging paradigm shift in how military organizations approach mosaic warfare in the digital age since new attack vectors and targets appear in their landscapes. In this vein, it is pivotal for military teams to have a clear and concise roadmap for cybersecurity incidents linked to potential mosaic warfare. This manuscript introduces a novel approach to bolstering mosaic warfare strategies by integrating an advanced Knowledge Representation and Reasoning system and a tailored ontology. Motivated by the critical role of cybersecurity in contemporary warfare, the proposed system aims to enhance situational awareness, decision-making capabilities, and operational effectiveness in the face of evolving cyber threats. In this sense, this manuscript entails a new ontology that not only covers the cybersecurity realm but also introduces key concepts related to strategic and operational military levels at the same time. The ad-hoc ontology is also compared against other well-known ones, such as MITRE, NATO, or UCO approaches and manifests a significant performance by employing standardized quality metrics for ontologies. Lastly, a realistic mosaic warfare scenario is contextualized to demonstrate the deployment of the proposed system and how it can properly represent all information gathered from heterogeneous data sources.
José María Jorquera Valero, Antonio López Martínez, Pedro Miguel Sánchez Sánchez, Daniel Navarro-Martínez, Rodrigo Varas López, Javier Ignacio Rojo Lacal, Antonio Lopez Vivar, Marco Antonio Sotelo Monge, Manuel Gil Pérez, Gregorio Martínez Pérez
ARES10
2024 Bridging the Gap: Cyber Defence Skills for the Future
abstract
As cyber threats continue to evolve, the need for highly skilled cyber defence operators becomes increasingly critical. In this work, we aim to provide a multidisciplinary exploration into the current educational landscape, focusing on the following pivotal areas: cyber defence educational initiatives, digital skills, technological enablers, and ethical considerations. First, we present the current landscape of cyber defence educational initiatives. Then, we examine the required digital skills, virtual reality and augmented reality initiatives for immersive learning experiences and delve into the advantages of game-based learning for skill acquisition in order to finally provide a holistic evaluation of the complexities involved in cyber defence training. We underscore the importance of standardising training modules tailored to diverse roles within cyber defence. The discussion emphasises the need for ethical and legal guidelines, especially concerning privacy and bias in AI-driven educational tools. Finally, we highlight the importance of dynamic curricula that include technical, legal, and soft skills, along with hands-on training through simulations to prepare operators for real-world cyber threats. This work will serve as a foundation for academics, industry professionals, and policy-makers interested in elevating the standards and effectiveness of cyber defence training suggesting ideas for more specialised, adaptable, and ethically responsible programs.
Sofia Strukova, Mariano Albaladejo-González, Maya Bozhilova, Alejandro Campos Fuentes, Simone Lenti, Gregorio Martínez Pérez, Daniel Navarro-Martínez, Pantaleone Nespoli, Giuseppe Santucci, Marco Antonio Sotelo Monge, Nikolai Stoianov, Eugenio Viesca Revuelta, José A. Ruipérez-Valiente
EDUCON6
2024 Analyzing the robustness of decentralized horizontal and vertical federated learning architectures in a non-IID scenario
abstract
Abstract Federated learning (FL) enables participants to collaboratively train machine and deep learning models while safeguarding data privacy. However, the FL paradigm still has drawbacks that affect its trustworthiness, as malicious participants could launch adversarial attacks against the training process. Previous research has examined the robustness of horizontal FL scenarios under various attacks. However, there is a lack of research evaluating the robustness of decentralized vertical FL and comparing it with horizontal FL architectures affected by adversarial attacks. Therefore, this study proposes three decentralized FL architectures: HoriChain, VertiChain, and VertiComb. These architectures feature different neural networks and training protocols suitable for horizontal and vertical scenarios. Subsequently, a decentralized, privacy-preserving, and federated use case with non-IID data to classify handwritten digits is deployed to assess the performance of the three architectures. Finally, a series of experiments computes and compares the robustness of the proposed architectures when they are affected by different data poisoning methods, including image watermarks and gradient poisoning adversarial attacks. The experiments demonstrate that while specific configurations of both attacks can undermine the classification performance of the architectures, HoriChain is the most robust one.
Pedro Miguel Sánchez Sánchez, Alberto Huertas Celdrán, Enrique Tomás Martínez Pérez, Daniel Demeter, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
Appl. Intell.6
2024 Single-board device individual authentication based on hardware performance and autoencoder transformer models
abstract
The proliferation of the Internet of Things (IoT) has led to the emergence of crowdsensing applications, where a multitude of interconnected devices collaboratively collect and analyze data. Ensuring the authenticity and integrity of the data collected by these devices is crucial for reliable decision-making and maintaining trust in the system. Traditional authentication methods are often vulnerable to attacks or can be easily duplicated, posing challenges to securing crowdsensing applications. Besides, current solutions leveraging device behavior are mostly focused on device identification, which is a simpler task than authentication. To address these issues, an individual IoT device authentication framework based on hardware behavior fingerprinting and Transformer autoencoders is proposed in this work. To support the design, a threat model details the security problems faced when performing hardware-based authentication in IoT. This solution leverages the inherent imperfections and variations in IoT device hardware to differentiate between devices with identical specifications. By monitoring and analyzing the behavior of key hardware components, such as the CPU, GPU, RAM, and Storage on devices, unique fingerprints for each device are created. The performance samples are considered as time series data and used to train outlier detection transformer models, one per device and aiming to model its normal data distribution. Then, the framework is validated within a spectrum crowdsensing system leveraging Raspberry Pi devices. After a pool of experiments, the model from each device is able to individually authenticate it between the 45 devices employed for validation. An average True Positive Rate (TPR) of 0.74±0.13 and an average maximum False Positive Rate (FPR) of 0.06±0.09 demonstrate the effectiveness of this approach in enhancing authentication, security, and trust in crowdsensing applications.
Pedro Miguel Sánchez Sánchez, Alberto Huertas Celdrán, Gérôme Bovet, Gregorio Martínez Pérez
Comput. Secur.4
2024 Corrigendum to "Fedstellar: A platform for decentralized federated learning" [Expert Syst. Appl. 242 (2024) 122861]
Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Pedro Guijas Bravo, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Expert Syst. Appl.9
2024 Fedstellar: A Platform for Decentralized Federated Learning
abstract
In 2016, Google proposed Federated Learning (FL) as a novel paradigm to train Machine Learning (ML) models across the participants of a federation while preserving data privacy. Since its birth, Centralized FL (CFL) has been the most used approach, where a central entity aggregates participants’ models to create a global one. However, CFL presents limitations such as communication bottlenecks, single point of failure, and reliance on a central server. Decentralized Federated Learning (DFL) addresses these issues by enabling decentralized model aggregation and minimizing dependency on a central entity. Despite these advances, current platforms training DFL models struggle with key issues such as managing heterogeneous federation network topologies, adapting the FL process to virtualized or physical deployments, and using a limited number of metrics to evaluate different federation scenarios for efficient implementation. To overcome these challenges, this paper presents Fedstellar, a novel platform designed to train FL models in a decentralized, semi-decentralized, and centralized fashion across diverse federations of physical or virtualized devices. Fedstellar allows users to create federations by customizing parameters like the number and type of devices training FL models, the network topology connecting them, the machine and deep learning algorithms, or the datasets of each participant, among others. Additionally, it offers real-time monitoring of model and network performance. The Fedstellar implementation encompasses a web application with an interactive graphical interface, a controller for deploying federations of nodes using physical or virtual devices, and a core deployed on each device, which provides the logic needed to train, aggregate, and communicate in the network. The effectiveness of the platform has been demonstrated in two scenarios: a physical deployment involving single-board devices such as Raspberry Pis for detecting cyberattacks and a virtualized deployment comparing various FL approaches in a controlled environment using MNIST and CIFAR-10 datasets. In both scenarios, Fedstellar demonstrated consistent performance and adaptability, achieving F1scores of 91%, 98%, and 91.2% using DFL for detecting cyberattacks and classifying MNIST and CIFAR-10, respectively, reducing training time by 32% compared to centralized approaches.
Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Expert Syst. Appl.8
2024 A Big Data architecture for early identification and categorization of dark web sites
abstract
The dark web has become notorious for its association with illicit activities and there is a growing need for systems to automate the monitoring of this space. This paper proposes an end-to-end scalable architecture for the early identification of new Tor sites and the daily analysis of their content. The solution is built using an Open Source Big Data stack for data serving with Kubernetes, Kafka, Kubeflow, and MinIO, continuously discovering onion addresses in different sources (threat intelligence, code repositories, web-Tor gateways, and Tor repositories), downloading the HTML from Tor and deduplicating the content using MinHash LSH, and categorizing with the BERTopic modeling (SBERT embedding, UMAP dimensionality reduction, HDBSCAN document clustering and c-TF-IDF topic keywords). In 93 days, the system identified 80,049 onion services and characterized 90% of them, addressing the challenge of Tor volatility. A disproportionate amount of repeated content is found, with only 6.1% unique sites. From the HTML files of the dark sites, 31 different low-topics are extracted, manually labeled, and grouped into 11 high-level topics. The five most popular included sexual and violent content, repositories, search engines, carding, cryptocurrencies, and marketplaces. During the experiments, we identified 14 sites with 13,946 clones that shared a suspiciously similar mirroring rate per day, suggesting an extensive common phishing network. Among the related works, this study is the most representative characterization of onion services based on topics to date.
Javier Pastor-Galindo, Hông-Ân Sandlin, Félix Gómez Mármol, Gérôme Bovet, Gregorio Martínez Pérez
Future Gener. Comput. Syst.5
2024 Adversarial attacks and defenses on ML- and hardware-based IoT device fingerprinting and identification
abstract
In the last years, the number of IoT devices deployed has suffered an undoubted explosion, reaching the scale of billions. However, some new cybersecurity issues have appeared together with this development. Some of these issues are the deployment of unauthorized devices, malicious code modification, malware deployment, or vulnerability exploitation. This fact has motivated the requirement for new device identification mechanisms based on behavior monitoring. Besides, these solutions have recently leveraged Machine and Deep Learning (ML/DL) techniques due to the advances in this field and the increase in processing capabilities. In contrast, attackers do not stay stalled and have developed adversarial attacks focused on context modification and ML/DL evaluation evasion applied to IoT device identification solutions. However, literature has not yet analyzed in detail the impact of these attacks on individual identification solutions and their countermeasures. This work explores the performance of hardware behavior-based individual device identification, how it is affected by possible context- and ML/DL-focused attacks, and how its resilience can be improved using defense techniques. In this sense, it proposes an LSTM-CNN architecture based on hardware performance behavior for individual device identification. Then, the most usual ML/DL classification techniques have been compared with the proposed architecture using a hardware performance dataset collected from 45 Raspberry Pi devices running identical software. The LSTM-CNN improves previous solutions achieving a +0.96 average F1-Score and 0.8 minimum TPR for all devices. Afterward, context- and ML/DL-focused adversarial attacks were applied against the previous model to test its robustness. A temperature-based context attack was not able to disrupt the identification, but some ML/DL state-of-the-art evasion attacks were successful. Finally, adversarial training and model distillation defense techniques are selected to improve the model resilience to evasion attacks, improving its robustness from up to 0.88 attack success ratio to 0.17 in the worst attack case, without degrading its performance in an impactful manner.
Pedro Miguel Sánchez Sánchez, Alberto Huertas Celdrán, Gérôme Bovet, Gregorio Martínez Pérez
Future Gener. Comput. Syst.4
2024 FederatedTrust: A solution for trustworthy federated learning
abstract
The rapid expansion of the Internet of Things (IoT) and Edge Computing has presented challenges for centralized Machine and Deep Learning (ML/DL) methods due to the presence of distributed data silos that hold sensitive information. To address concerns regarding data privacy, collaborative and privacy-preserving ML/DL techniques like Federated Learning (FL) have emerged. FL ensures data privacy by design, as the local data of participants remains undisclosed during the creation of a global and collaborative model. However, data privacy and performance are insufficient since a growing need demands trust in model predictions. Existing literature has proposed various approaches dealing with trustworthy ML/DL (excluding data privacy), identifying robustness, fairness, explainability, and accountability as important pillars. Nevertheless, further research is required to identify trustworthiness pillars and evaluation metrics specifically relevant to FL models, as well as to develop solutions that can compute the trustworthiness level of FL models. This work examines the existing requirements for evaluating trustworthiness in FL and introduces a comprehensive taxonomy consisting of six pillars (privacy, robustness, fairness, explainability, accountability, and federation), along with over 30 metrics for computing the trustworthiness of FL models. Subsequently, an algorithm named FederatedTrust is designed based on the pillars and metrics identified in the taxonomy to compute the trustworthiness score of FL models. A prototype of FederatedTrust is implemented and integrated into the learning process of FederatedScope, a well-established FL framework. Finally, five experiments are conducted using different configurations of FederatedScope (with different participants, selection rates, training rounds, and differential privacy) to demonstrate the utility of FederatedTrust in computing the trustworthiness of FL models. Three experiments employ the FEMNIST dataset, and two utilize the N-BaIoT dataset, considering a real-world IoT security use case.
Pedro Miguel Sánchez Sánchez, Alberto Huertas Celdrán, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
Future Gener. Comput. Syst.5
2024 NeuronLab: BCI framework for the study of biosignals
abstract
Brain–Computer Interfaces (BCIs) allow the acquisition of brain activity using non-invasive techniques such as Electroencephalography (EEG). Since BCI devices do not commonly interpret the acquired EEG signals, external software applications play a critical role in the BCI lifecycle. Despite the literature offering a great variety of platforms and frameworks, they present several limitations, such as implementing old software architectures or needing more functionality to cover all phases of the BCI lifecycle. Based on these limitations, this work proposes the design and implementation of NeuronLab, a secure, multi-platform, standalone, multi-paradigm, and web-based framework that defines all BCI lifecycle phases and provides novel functionality compared to current open-source BCI software, such as sharing experiments between researchers and storing data on the cloud. This framework has been validated in two experiments common in BCI literature: P300 identification and limb movements detection. This verification has been performed based on performance metrics, such as CPU and RAM consumption, highlighting that NeuronLab is a promising solution for BCI scenarios requiring a distributed and collaborative platform for researchers and practitioners.
Sergio López Bernal, Juan Antonio Martínez López, Enrique Tomás Martínez Beltrán, Mario Quiles Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Neurocomputing5
2024 Privacy-preserving hierarchical federated learning with biosignals to detect drowsiness while driving
abstract
Abstract In response to the global safety concern of drowsiness during driving, the European Union enforces that new vehicles must integrate detection systems compliant with the general data protection regulation. To identify drowsiness patterns while preserving drivers’ data privacy, recent literature has combined Federated Learning (FL) with different biosignals, such as facial expressions, heart rate, electroencephalography (EEG), or electrooculography (EOG). However, existing solutions are unsuitable for drowsiness detection where heterogeneous stakeholders want to collaborate at different levels while guaranteeing data privacy. There is a lack of works evaluating the benefits of using Hierarchical FL (HFL) with EEG and EOG biosignals, and comparing HFL over traditional FL and Machine Learning (ML) approaches to detect drowsiness at the wheel while ensuring data confidentiality. Thus, this work proposes a flexible framework for drowsiness identification by using HFL, FL, and ML over EEG and EOG data. To validate the framework, this work defines a scenario of three transportation companies aiming to share data from their drivers without compromising their confidentiality, defining a two-level hierarchical structure. This study presents three incremental Use Cases (UCs) to assess detection performance: UC1) intra-company FL, yielding a 77.3% accuracy while ensuring the privacy of individual drivers’ data; UC2) inter-company FL, achieving 71.7% accuracy for known drivers and 67.1% for new subjects, ensuring data confidentiality between companies but not intra-organization; and UC3) HFL inter-company, which ensured comprehensive data privacy both within and between companies, with an accuracy of 71.9% for training subjects and 65.5% for new subjects.
Sergio López Bernal, José Manuel Hidalgo Rogel, Enrique Tomás Martínez Beltrán, Mario Quiles Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Neural Comput. Appl.5
2024 CyberSpec: Behavioral Fingerprinting for Intelligent Attacks Detection on Crowdsensing Spectrum Sensors
abstract
Integrated sensing and communication is a novel paradigm using crowdsensing spectrum sensors to help with the management of spectrum scarcity. However, well-known vulnerabilities of resource-constrained spectrum sensors and the possibility of being manipulated by users with physical access complicate their protection against spectrum sensing data falsification (SSDF) attacks. Most recent literature suggests using behavioral fingerprinting and Machine/Deep Learning (ML/DL) for improving similar cybersecurity issues. Nevertheless, the applicability of these techniques in resource-constrained devices, the impact of attacks affecting spectrum data integrity, and the performance and scalability of models suitable for heterogeneous sensors types are still open challenges. To improve limitations, this work presents seven SSDF attacks affecting spectrum sensors and introduces CyberSpec, an ML/DL-oriented framework using device behavioral fingerprinting to detect anomalies produced by SSDF attacks. CyberSpec has been implemented and validated in ElectroSense, a real crowdsensing RF monitoring platform where several configurations of the proposed SSDF attacks have been executed in different sensors. A pool of experiments with different unsupervised ML/DL-based models has demonstrated the suitability of CyberSpec detecting the previous attacks within an acceptable timeframe.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
IEEE Trans. Dependable Secur. Comput.4
2024 Studying the Robustness of Anti-Adversarial Federated Learning Models Detecting Cyberattacks in IoT Spectrum Sensors
abstract
Device fingerprinting combined with Machine and Deep Learning (ML/DL) report promising performance when detecting spectrum sensing data falsification (SSDF) attacks. However, the amount of data needed to train models and the scenario privacy concerns limit the applicability of centralized ML/DL. Federated learning (FL) addresses these drawbacks but is vulnerable to adversarial participants and attacks. The literature has proposed countermeasures, but more effort is required to evaluate the performance of FL detecting SSDF attacks and their robustness against adversaries. Thus, the first contribution of this work is to create an FL-oriented dataset modeling the behavior of resource-constrained spectrum sensors affected by SSDF attacks. The second contribution is a pool of experiments analyzing the robustness of FL models according to i) three families of sensors, ii) eight SSDF attacks, iii) four FL scenarios dealing with anomaly detection and binary classification, iv) up to 33% of participants implementing data and model poisoning attacks, and v) four aggregation functions acting as anti-adversarial mechanisms. In conclusion, FL achieves promising performance when detecting SSDF attacks. Without anti-adversarial mechanisms, FL models are particularly vulnerable with$>$16% of adversaries. Coordinate-wise-median is the best mitigation for anomaly detection, but binary classifiers are still affected with$>$33% of adversaries.
Pedro Miguel Sánchez Sánchez, Alberto Huertas Celdrán, Timo Schenk, Adrian Lars Benjamin Iten, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
IEEE Trans. Dependable Secur. Comput.6
2024 SLA-Driven Trust and Reputation Management Framework for 5G Distributed Service Marketplaces
abstract
The fifth generation (5G) of mobile telecommunications is characterized by massive growth in the number of stakeholders, interconnected devices, and available services distributed under different administrative domains. Distributed marketplaces aim at facilitating stakeholders in the quest and hiring of third party resources and services. Establishing trustworthiness in such an open ecosystem is a cornerstone for the final deployment of these marketplaces in 5G networks and beyond. Hence, building trust management systems that ensure the selection of reliable parties or assets in 5G distributed marketplaces is essential. Thus, a reputation-based trust management framework is proposed to analyze stakeholder behavior patterns and predict trust scores to establish trustworthy relationships across domains. Furthermore, an Service Level Agreement (SLA)-driven reward and punishment mechanism is designed and developed on top of the reputation-based trust framework. Such a mechanism enables continuously adapting trust scores by gathering breach predictions, breach detections, and SLA violations in real time. Furthermore, an edge-based use case is presented to contextualize our reputation-based framework in a tangible enforcement scenario. In conclusion, three experiments were conducted on real-life testbeds demonstrating that our framework fairly distinguishes bad-mouthing attacks with 67% accuracy, when 50% recommenders are corrupted, and is resilient to continuous misbehavior bursts.
José María Jorquera Valero, Vasileios Theodorou, Manuel Gil Pérez, Gregorio Martínez Pérez
IEEE Trans. Dependable Secur. Comput.4
2024 RL and Fingerprinting to Select Moving Target Defense Mechanisms for Zero-Day Attacks in IoT
abstract
Moving Target Defense (MTD) is a promising approach to mitigate attacks by dynamically altering target attack surfaces. Still, selecting suitable MTD techniques for zero-day attacks is an open challenge. Reinforcement Learning (RL) could be an effective approach to optimize the MTD selection through trial and error, but the literature fails when i) evaluating the performance of RL and MTD solutions in real-world scenarios, ii) studying whether behavioral fingerprinting is suitable for RL, and iii) calculating the consumption of resources in single-board computers (SBC). Thus, the work at hand proposes an online RL-based framework that learns correct MTD mechanisms mitigating heterogeneous zero-day attacks in SBC. The framework considers behavioral fingerprinting to represent SBCs’ states and RL to learn MTD techniques that mitigate each malicious state. It has been deployed on a real IoT crowdsensing scenario with a Raspberry Pi acting as a spectrum sensor. The Raspberry Pi has been infected with different samples of command and control malware, rootkits, and ransomware to later select between four existing MTD techniques. A set of experiments demonstrated the suitability of the framework to learn proper MTD techniques mitigating all attacks (except a harmfulness rootkit) while consuming$\approx 10$% of RAM, and negligible CPU.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Jan von der Assen, Timo Schenk, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
IEEE Trans. Inf. Forensics Secur.6
2024 Mitigating communications threats in decentralized federated learning through moving target defense
abstract
Abstract The rise of Decentralized Federated Learning (DFL) has enabled the training of machine learning models across federated participants, fostering decentralized model aggregation and reducing dependence on a server. However, this approach introduces unique communication security challenges that have yet to be thoroughly addressed in the literature. These challenges primarily originate from the decentralized nature of the aggregation process, the varied roles and responsibilities of the participants, and the absence of a central authority to oversee and mitigate threats. Addressing these challenges, this paper first delineates a comprehensive threat model focused on DFL communications. In response to these identified risks, this work introduces a security module to counter communication-based attacks for DFL platforms. The module combines security techniques such as symmetric and asymmetric encryption with Moving Target Defense (MTD) techniques, including random neighbor selection and IP/port switching. The security module is implemented in a DFL platform, Fedstellar, allowing the deployment and monitoring of the federation. A DFL scenario with physical and virtual deployments have been executed, encompassing three security configurations: (i) a baseline without security, (ii) an encrypted configuration, and (iii) a configuration integrating both encryption and MTD techniques. The effectiveness of the security module is validated through experiments with the MNIST dataset and eclipse attacks.The results showed an average F1 score of 95%, with the most secure configuration resulting in CPU usage peaking at 68% (± 9%) in virtual deployments and network traffic reaching 480.8 MB (± 18 MB), effectively mitigating risks associated with eavesdropping or eclipse attacks.
Enrique Tomás Martínez Beltrán, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Wirel. Networks6
2024 Impact of neural cyberattacks on a realistic neuronal topology from the primary visual cortex of mice
abstract
Abstract Brain-computer interfaces (BCIs) are widely used in medical scenarios to treat neurological conditions, such as Parkinson’s disease or epilepsy, when a pharmacological approach is ineffective. Despite their advantages, these BCIs target relatively large areas of the brain, causing side effects. In this context, projects such as Neuralink aim to stimulate and inhibit neural activity with single-neuron resolution, expand their usage to other sectors, and thus democratize access to neurotechnology. However, these initiatives present vulnerabilities in their designs that cyberattackers can exploit to cause brain damage. Specifically, the literature has documented the applicability of neural cyberattacks, threats capable of stimulating or inhibiting individual neurons to alter spontaneous neural activity. However, these works were limited by a lack of realistic neuronal topologies to test the cyberattacks. Surpassed this limitation, this work considers a realistic neuronal representation of the primary visual cortex of mice to evaluate the impact of neural cyberattacks more realistically. For that, this publication evaluates two existing cyberattacks, Neuronal Flooding and Neuronal Jamming, assessing the impact that different voltages on a particular set of neurons and the number of neurons simultaneously under attack have on the amount of neural activity produced. As a result, both cyberattacks increased the number of neural activations, propagating their impact for approximately 600 ms, where the activity converged into spontaneous behavior. These results align with current evidence about the brain, highlighting that neurons will tend to their baseline behavior after the attack.
Victoria Magdalena López Madejska, Sergio López Bernal, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Wirel. Networks3
2023 RansomAI: AI-Powered Ransomware for Stealthy Encryption
abstract
Cybersecurity solutions have shown promising performance when detecting ransomware samples that use fixed algorithms and encryption rates. However, due to the current explosion of Artificial Intelligence (AI), sooner than later, ransomware, and malware in general, will incorporate AI techniques to intelligently and dynamically adapt its behavior to be undetected. It might result in ineffective and obsolete cybersecurity solutions, but the literature lacks AI-powered ransomware samples to verify it. Thus, this work proposes RansomAI, a Reinforcement Learning-based framework that can be integrated into existing ransomware samples to adapt their encryption behavior and stay stealthy while encrypting files. RansomAI presents an agent that learns the best encryption algorithm, rate, and duration that minimizes its detection (using a reward mechanism and a fingerprinting intelligent detection system) while maximizing its damage. The proposed framework was validated with Ransomware-PoC, a ransomware that infected a Raspberry Pi 4 acting as a crowdsensor. A pool of experiments with Deep Q-Learning and Isolation Forest (deployed on the agent and detection system, respectively) has demonstrated that RansomAI evades the detection of Ransomware-PoC affecting the Raspberry Pi 4 in a few minutes with >90% accuracy.
Jan von der Assen, Alberto Huertas Celdrán, Janik Luechinger, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
GLOBECOM6
2023 A Lightweight Moving Target Defense Framework for Multi-purpose Malware Affecting IoT Devices
abstract
Malware affecting Internet of Things (IoT) devices is rapidly growing due to the relevance of this paradigm in real-world scenarios. Specialized literature has also detected a trend towards multi-purpose malware able to execute different malicious actions such as remote control, data leakage, encryption, or code hiding, among others. Protecting IoT devices against this kind of malware is challenging due to their well-known vulnerabilities and limitation in terms of CPU, memory, and storage. To improve it, the moving target defense (MTD) paradigm was proposed a decade ago and has shown promising results, but there is a lack of IoT MTD solutions dealing with multi-purpose malware. Thus, this work proposes four MTD mechanisms changing IoT devices' network, data, and runtime environment to mitigate multi-purpose malware. Furthermore, it presents a lightweight and IoT-oriented MTD framework to decide what, when, and how the MTD mechanisms are deployed. Finally, the efficiency and effectiveness of the framework and MTD mechanisms are evaluated in a real-world scenario with one IoT spectrum sensor affected by multi-purpose malware.
Jan von der Assen, Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Jordan Cedeño, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
ICC6
2023 Fedstellar: A Platform for Training Models in a Privacy-preserving and Decentralized Fashion
abstract
This paper presents Fedstellar, a platform for training decentralized Federated Learning (FL) models in heterogeneous topologies in terms of the number of federation participants and their connections. Fedstellar allows users to build custom topologies, enabling them to control the aggregation of model parameters in a decentralized manner. The platform offers a Web application for creating, managing, and connecting nodes to ensure data privacy and provides tools to measure, monitor, and analyze the performance of the nodes. The paper describes the functionalities of Fedstellar and its potential applications. To demonstrate the applicability of the platform, different use cases are presented in which decentralized, semi-decentralized, and centralized architectures are compared in terms of model performance, convergence time, and network overhead when collaboratively classifying hand-written digits using the MNIST dataset.
Enrique Tomás Martínez Beltrán, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán
IJCAI6
2023 Early Detection of Cryptojacker Malicious Behaviors on IoT Crowdsensing Devices
abstract
Traditionally, IoT crowdsensing devices have been outside the cryptomining domain due to their limitations in terms of computational power. In 2014, Monero (XNR) changed this situation forever. Monero is an open-source digital payment token that can be mined in resource-constrained devices like IoT and single-board computers. Despite the Monero advantages, it opened the door for cryptojackers illicitly mining cryptocurrencies by exploiting well-known vulnerabilities of IoT devices. Existing detection solutions provide good performance while detecting the mining phase of cryptojackers, but early detection is desired to avoid malware spreading and resource misuse. Thus, this work proposes a framework that combines device behavioral fingerprinting and machine learning to detect and classify preparatory phases of cryptojackers. The framework has been deployed in a crowdsensing IoT spectrum sensor, Raspberry Pi, infected by a recent cryptojacker called Linux.MulDrop.14. Promising detection results demonstrate the framework’s suitability while detecting early phases of cryptojackers.
Alberto Huertas Celdrán, Jan von der Assen, Konstantin Moser, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
NOMS6
2023 Trust-as-a-Service: A reputation-enabled trust framework for 5G network resource provisioning
abstract
Trust, security, and privacy are three of the major pillars to assemble the fifth-generation network and beyond. Despite such pillars are principally interconnected, a multitude of challenges arise that need to be addressed separately. 5G networks ought to offer flexible and pervasive computing capabilities across multiple domains according to user demands and assure trustworthy network providers. To this end, distributed marketplaces expect to boost the trading of heterogeneous resources so as to enable the establishment of pervasive service chains between cross-domains. Yet, the need for selecting reliable parties as “marketplace operators” plays a pivotal role in achieving a trustworthy ecosystem. Two of the principal blockages in managing foreseeable networks are the need to consider trust as a property in the resource provisioning process and adapt previous trust models to accomplish the new network and business requirements. In this regard, this article is centered on the trust management of 5G multi-party network resource provisioning. As a result, a reputation-based trust framework is proposed as a Trust-as-a-Service (TaaS) solution for a distributed multi-stakeholder environment where requirements such as zero trust and zero-touch principles should be met. Besides, a literature review is also conducted to recognize the network and business requirements currently envisaged. Finally, the validation of the proposed trust framework was performed in a real research environment, the 5GBarcelona testbed, leveraging 12% of a 2.1 GHz CPU with 20 cores and 2% of the 30 GiB memory. These outcomes reveal the TaaS solution’s feasibility and conservative approach in the context of determining reliable network operators.
José María Jorquera Valero, Pedro Miguel Sánchez Sánchez, Manuel Gil Pérez, Alberto Huertas Celdrán, Gregorio Martínez Pérez
Comput. Commun.5
2023 Behavioral fingerprinting to detect ransomware in resource-constrained devices
abstract
The Internet of Things (IoT), a network of interconnected devices, has grown and gained traction over the last few years. This paradigm can impact our lives while also providing significant economic benefits. However, although resource-constrained IoT devices offer numerous advantages, they are also vulnerable to cyberattacks. As a result, ransomware severely threatens IoT devices managing sensitive and relevant information. Solutions based on Machine and Deep Learning (ML/DL) that consider behavioral data have been identified as promising. However, most detection solutions have been developed for Windows-based systems, which generally have more resources than IoT devices. As a result, these solutions are not suitable for resource-constrained components. In addition, no solution compares the pros and cons of different behavioral dimensions of resource-constrained devices. Thus, this work presents a framework that combines three different behavioral sources with supervised and unsupervised ML/DL algorithms to detect and classify heterogeneous ransomware impacting resource-constrained spectrum sensors. A pool of experiments has demonstrated the suitability of the proposed solution and compared its performance with a rule-based system. In conclusion, the usage of resources combined with local outlier factor and decision tree are the most promising combinations to detect anomalies and classify ransomware while consuming CPU, RAM, and time of devices in a reduced manner.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Jan von der Assen, Dennis Shushack, Ángel Luis Perales Gómez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
Comput. Secur.7
2023 On the gathering of Tor onion addresses
abstract
Exploring the Tor network requires acquiring onion addresses, which are crucial for accessing anonymous websites. However, the Tor protocol presents a challenge, as it lacks a standard method for finding these complex links composed of either 16 or 56 base32-coded characters and featuring the unique “.onion” top-level domain. This study delves into the existing literature analyzing onion services and categorizes the various strategies employed to gather their addresses. The success of each approach is measured by the number of addresses obtained, while the relevancy of the work is evaluated by comparing the number of services uncovered to Tor’s official count. The results indicate that the most used techniques are Tor crawling and repositories, whereas the most effective methods are relay injection, repositories, and Tor crawling. This paper also estimates the representativeness of literature collections, revealing that most past works explored a small portion of the Tor network. The study also uncovers the limitations of onion gathering and sheds light on the challenges for future research to provide more representative datasets for dark web exploration.
Javier Pastor-Galindo, Félix Gómez Mármol, Gregorio Martínez Pérez
Future Gener. Comput. Syst.3
2023 Privacy-Preserving and Syscall-Based Intrusion Detection System for IoT Spectrum Sensors Affected by Data Falsification Attacks
abstract
Crowdsensing platforms collect, process, transmit, and analyze spectrum data worldwide to optimize radio frequency spectrum usage. However, Internet of Things (IoT) spectrum sensors, performing some of the previous tasks, are exposed to software manipulation aiming to execute spectrum sensing data falsification (SSDF) attacks to compromise data integrity and spectrum optimization. Novel intrusion detection systems (IDSs) combining device fingerprinting with machine and deep learning (ML/DL) improve the limitation of traditional solutions and remove the necessity of redundant sensors and reputation mechanisms. However, they fail when detecting SSDF attacks accurately while protecting sensors privacy. This work proposes a novel host-based and federated learning-oriented IDS for IoT spectrum sensors that consider unsupervised ML/DL and fingerprints based on system calls. The framework detection performance and consumption of resources are analyzed in local and federated scenarios with six spectrum sensors deployed on Raspberry Pis. The obtained results significantly improve related work when detecting SSDF attacks while protecting sensors privacy, and consuming CPU, memory, and storage of sensors in a reduced manner.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Chao Feng 0001, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
IEEE Internet Things J.5
2023 CGAPP: A continuous group authentication privacy-preserving platform for industrial scene
abstract
In Industry 4.0, security begins with the workers’ authentication, which can be done individually or in groups. Recently, group authentication is gaining momentum, allowing users to authenticate as group members without the need to specify the particular individual. Continuous authentication and federated learning are promising techniques that might help group authentication by providing privacy, by its own design, and extra security compared to traditional methods based on passwords, tokens, or biometrics. However, these techniques have not previously been combined or evaluated for authenticating workers in Industry 4.0. Thus, this paper proposes a novel continuous group authentication privacy-preserving (CGAPP)platform that is suitable for the industry. The CGAPP platform incorporates statistical data from workers’ smartphones and employs federated learning-based outlier detection for group worker authentication while ensuring the privacy of personal data vectors. A series of experiments were performed to measure the framework’s suitability and address the following research questions: (i) What is the cost of using FL compared to full data access in industrial scenarios? (ii) How robust is federated learning against adversarial attacks, specifically, how much malicious data is required to deceive the model? and (iii) How much noise is required to disrupt the authentication system? The results demonstrate the effectiveness of the CGAPP platform in the industry since it provides factory safety while preserving privacy. This platform achieves an accuracy of 92%, comparable to the 96% obtained by traditional approaches in the literature that do not address privacy concerns. The platform’s robustness is tested against attacks in the second and third experiments, and various countermeasures are evaluated. While the CGAPP platform exhibits certain vulnerabilities to data injection attacks, straightforward countermeasures can alleviate them. Nevertheless, the system’s performance experiences a notable impact in the event of a data perturbation attack, and the countermeasures investigated are ineffective in addressing this issue.
Juan M. Espín, Alberto Huertas Celdrán, Francisco Esquembre, Gregorio Martínez Pérez, Javier G. Marín-Blázquez
J. Inf. Secur. Appl.4
2023 A methodology to identify identical single-board computers based on hardware behavior fingerprinting
abstract
The connectivity and resource-constrained nature of single-board devices open the door to cybersecurity concerns affecting Internet of Things (IoT) scenarios. One of the most important issues is the presence of unauthorized IoT devices that want to impersonate legitimate ones by using identical hardware and software specifications. This situation can provoke sensitive information leakages, data poisoning, or privilege escalation in IoT scenarios. Combining behavioral fingerprinting and Machine/Deep Learning (ML/DL) techniques is a promising approach to identify these malicious spoofing devices by detecting minor performance differences generated by imperfections in manufacturing. However, existing solutions are not suitable for single-board devices since they do not consider their hardware and software limitations, underestimate critical aspects such as fingerprint stability or context changes, and do not explore the potential of ML/DL techniques. To improve it, this work first identifies the essential properties for single-board device identification: uniqueness, stability, diversity, scalability, efficiency, robustness, and security. Then, a novel methodology relies on behavioral fingerprinting to identify identical single-board devices and meet the previous properties. The methodology leverages the different built-in components of the system and ML/DL techniques, comparing the device internal behavior with each other to detect variations that occurred in manufacturing processes. The methodology validation has been performed in a real environment composed of 15 identical Raspberry Pi 4 Model B and 10 Raspberry Pi 3 Model B+ devices, obtaining a 91.9% average TPR with an XGBoost model and achieving the identification for all devices by setting a 50% threshold in the evaluation process. Finally, a discussion compares the proposed solution with related work, highlighting the fingerprint properties not met, and provides important lessons learned and limitations.
Pedro Miguel Sánchez Sánchez, José María Jorquera Valero, Alberto Huertas Celdrán, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez
J. Netw. Comput. Appl.6
2023 Analyzing the impact of Driving tasks when detecting emotions through brain-computer interfaces
abstract
Abstract Traffic accidents are the leading cause of death among young people, a problem that today costs an enormous number of victims. Several technologies have been proposed to prevent accidents, being brain–computer interfaces (BCIs) one of the most promising. In this context, BCIs have been used to detect emotional states, concentration issues, or stressful situations, which could play a fundamental role in the road since they are directly related to the drivers’ decisions. However, there is no extensive literature applying BCIs to detect subjects’ emotions in driving scenarios. In such a context, there are some challenges to be solved, such as (i) the impact of performing a driving task on the emotion detection and (ii) which emotions are more detectable in driving scenarios. To improve these challenges, this work proposes a framework focused on detecting emotions using electroencephalography with machine learning and deep learning algorithms. In addition, a use case has been designed where two scenarios are presented. The first scenario consists in listening to sounds as the primary task to perform, while in the second scenario listening to sound becomes a secondary task, being the primary task using a driving simulator. In this way, it is intended to demonstrate whether BCIs are useful in this driving scenario. The results improve those existing in the literature, achieving 99% accuracy for the detection of two emotions (non-stimuli and angry), 93% for three emotions (non-stimuli, angry and neutral) and 75% for four emotions (non-stimuli, angry, neutral and joy).
Mario Quiles Pérez, Enrique Tomás Martínez Beltrán, Sergio López Bernal, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Neural Comput. Appl.4
2022 RITUAL: a Platform Quantifying the Trustworthiness of Supervised Machine Learning
abstract
This demo presents RITUAL, a platform composed of a novel algorithm and a Web application quantifying the trustworthiness level of supervised Machine and Deep Learning (ML/DL) models according to their fairness, explainability, robustness, and accountability. The algorithm is deployed on a Web application to allow users to quantify and compare the trustworthiness of their ML/DL models. Finally, a scenario with ML/DL models classifying network cyberattacks demonstrates the platform applicability.
Alberto Huertas Celdrán, Melike Demirci, Joel Leupp, Muriel Figueredo Franco, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
CNSM8
2022 Intelligent Fingerprinting to Detect Data Leakage Attacks on Spectrum Sensors
abstract
Data confidentiality protection is a must for IoT and crowdsensing platforms, and a challenge due to the constrained nature of their sensors. Currently, the combination of device fingerprinting and anomaly detection systems based on Machine and Deep Learning (ML/DL) techniques is one of the most promising approaches to detect zero-day cyberattacks. However, most of existing work is not suitable for resource-constrained devices or does not deal with cyberattacks affecting data confidentiality of spectrum sensors. Thus, this paper proposes a framework that monitors network interface events of sensors, uses unsupervised learning to create fingerprints, and detects anomalies produced by such cyberattacks. The framework validation has been performed in the crowdsensing platform ElectroSense, where a sensor has been infected by a backdoor leaking different sensitive data during an experiment. A set of unsupervised learning algorithms has been evaluated, being Autoencoder the one showing the best balance when detecting normal behavior and data leakages of different sizes and at frequencies, while providing a reduced detection time and sensor resources consumption.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
ICC4
2022 Policy-based and Behavioral Framework to Detect Ransomware Affecting Resource-constrained Sensors
abstract
Traditionally, data centers have been the preferred target for ransomware attacks. However, the increasing number of IoT (Internet-of-Things) devices managing valuable data is attracting the attention of cybercriminals and ransomware towards resource-constrained devices. So far, literature has demonstrated the suitability of monitoring the behavior of devices to detect some malware infections. However, most of these existing solutions have been designed and validated in Windows-based systems without computational restrictions.Thus, this work presents a lightweight policy-based framework that uses behavioral fingerprinting to detect anomalies and classify ransomware affecting resource-constrained and Linux-based sensors. The framework detection capabilities have been validated in a resource-constrained spectrum sensor belonging to ElectroSense, a real crowdsensing platform. In particular, three policies, created as a proof-of-concept, resulted in promising findings in terms of detection performance and time, when identifying anomalies by classifying two recent ransomware samples affecting a Raspberry Pi acting as sensor.
Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Eder J. Scheid, Timucin Besken, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller
NOMS6
2022 Neuronal Jamming cyberattack over invasive BCIs affecting the resolution of tasks requiring visual capabilities
abstract
Invasive Brain-Computer Interfaces (BCIs) are extensively used in medical application scenarios to record, stimulate, or inhibit neural activity with different purposes. An example is the stimulation of some brain areas to reduce the effects generated by Parkinson’s disease. Despite the advances in recent years, cybersecurity on BCIs is an open challenge since attackers can exploit the vulnerabilities of invasive BCIs to induce malicious stimulation or treatment disruption, affecting neuronal activity. In this work, we design and implement a novel neuronal cyberattack called Neuronal Jamming (JAM), which prevents neurons from producing spikes. To implement and measure the JAM impact, and due to the lack of realistic neuronal topologies in mammalians, we have defined a use case using a Convolutional Neural Network (CNN) trained to allow a simulated mouse to exit a particular maze. The resulting model has been translated to a biological neural topology, simulating a portion of a mouse’s visual cortex. The impact of JAM on both biological and artificial networks is measured, analyzing how the attacks can both disrupt the spontaneous neural signaling and the mouse’s capacity to exit the maze. Besides, another contribution of the work focuses on comparing the impacts of both JAM and FLO (an existing neural cyberattack), demonstrating that JAM generates a higher impact in terms of neuronal spike rate. As a final contribution, we discuss whether and how JAM and FLO attacks could induce the effects of neurodegenerative diseases if the implanted BCI had a comprehensive electrode coverage of the targeted brain regions.
Sergio López Bernal, Alberto Huertas Celdrán, Gregorio Martínez Pérez
Comput. Secur.3
2022 SAFECAR: A Brain-Computer Interface and intelligent framework to detect drivers' distractions
abstract
As recently reported by the World Health Organization (WHO), the high use of intelligent devices such as smartphones, multimedia systems, or billboards causes an increase in distraction and, consequently, fatal accidents while driving. The use of EEG-based Brain–Computer Interfaces (BCIs) has been proposed as a promising way to detect distractions. However, existing solutions are not well suited for driving scenarios. They do not consider complementary data sources, such as contextual data, nor guarantee realistic scenarios with real-time communications between components. This work proposes an automatic framework for detecting distractions using BCIs and a realistic driving simulator. The framework employs different supervised Machine Learning (ML)-based models on classifying the different types of distractions using Electroencephalography (EEG) and contextual driving data collected by car sensors, such as line crossings or objects detection. This framework has been evaluated using a driving scenario without distractions and a similar one where visual and cognitive distractions are generated for ten subjects. The proposed framework achieved 83.9% F1-score with a binary model and 73% with a multiclass model using EEG, improving 7% in binary classification and 8% in multi-class classification by incorporating contextual driving into the training dataset. Finally, the results were confirmed by a neurophysiological study, which revealed significantly higher voltage in selective attention and multitasking.
Enrique Tomás Martínez Beltrán, Mario Quiles Pérez, Sergio López Bernal, Gregorio Martínez Pérez, Alberto Huertas Celdrán
Expert Syst. Appl.4
2022 Profiling users and bots in Twitter through social media analysis
abstract
Social networks were designed to connect people online but have also been exploited to launch influence operations for manipulating society. The deployment of social bots has proven to be one of the most effective enablers to polarize and destabilize platforms. While automatic tools have been developed for their detection, the way to characterize these accounts and measure their impact is heterogeneous in the literature. In this work, we select metrics and algorithms from existing efforts to ensemble a data-driven methodology to profile groups of users and bots of Twitter from seven perspectives. We apply the framework to a dataset of Twitter retweets before the 10 November 2019 Spanish elections to characterize potential interferences. In this case study, Likely Bots (fully automated accounts) and Likely Semi-Bots (partially automated accounts) interacted with the same tendencies as Likely Humans (non-automated users), generating similar virality (information cascades) over time and without compromising the network connectivity. However, Likely Bots particularly stood out as close, visible, and reachable to other users. Likely Semi-Bots attracted particular attention, created proportionally more retweets, and were placed in strategically key positions in the core of the network. Results suggest that semi-automated accounts would be more threatening than fully automated ones.
Javier Pastor-Galindo, Félix Gómez Mármol, Gregorio Martínez Pérez
Inf. Sci.3
2022 A Supervised ML Biometric Continuous Authentication System for Industry 4.0
abstract
Continuous authentication (CA) is a promising approach to authenticate workers and avoid security breaches in the industry, especially in Industry 4.0, where most interaction between workers and devices takes place. However, introducing CA in industries raises the following unsolved questions regarding machine learning (ML) models: its precision and performance; its robustness; and the issue about if or when to retrain the models. To answer these questions, this article explores these issues with a proposed supervised versus nonsupervised ML-based CA system that uses sensors, applications statistics, or speaker data collected by the operator’s devices. Experiments show supervised models with equal error rates of 7.28% using sensors data, 9.29% with statistics, and 0.31% with voice, a significant improvement of 71.97, 62.14, and 97.08%, respectively, over unsupervised models. Voice is the most robust dimension when adding new workers, with less than 2% of false acceptance rate even if workforce size is doubled.
Juan M. Espín, Alberto Huertas Celdrán, Francisco Esquembre, Gregorio Martínez Pérez, Javier G. Marín-Blázquez
IEEE Trans. Ind. Informatics4
2021 AuthCODE: A privacy-preserving and multi-device continuous authentication architecture based on machine and deep learning
Pedro Miguel Sánchez Sánchez, Lorenzo Fernández Maimó, Alberto Huertas Celdrán, Gregorio Martínez Pérez
Comput. Secur.4
2021 Mitigation of cyber threats: Protection mechanisms in federated SDN/NFV infrastructures for 5G within FIRE+
abstract
Summary Cyber attacks are becoming a very common trend in existing networks, expecting to be even more acute in future 5G networks due to greater number of connected devices, higher mobile data volume, low latency, etc. Security mechanisms to tackle cyber threats should be updated when users, possibly carrying devices with some kind of malware, move in highly dynamic mobile networks in order to continue providing the same detection and mitigation capabilities along user's path. This paper presents BotsOnFIRE, an experiment of the EU H2020 SoftFIRE project for the detection and mitigation of botnets in the SoftFIRE federated testbed for 5G within FIRE+, by combining Software‐Defined Networking (SDN) and Network Functions Virtualization (NFV) technologies. Bots' mobility is considered to trigger reconfiguration of security‐related SDN/NFV applications, when needed, so as to update security capabilities of the SoftFIRE infrastructure. The BotsOnFIRE experiment contributes to the wider 5G objective of more secure and resilient networks and services, where botnets are actually one of the most powerful cyber threats capable of orchestrating the remote execution of cyber‐attacks. Experiments confirm that BotsOnFIRE is feasible to conduct the expected detection and mitigation procedures in the SoftFIRE federated environment, being evaluated through some Key Performance Indicators.
Manuel Gil Pérez, Alberto Huertas Celdrán, Pietro G. Giardina, Giacomo Bernini, Simone Pizzimenti, Félix J. García Clemente, Gregorio Martínez Pérez, Giovanni Festa, Fabio Paglianti
Concurr. Comput. Pract. Exp.7
2021 SafeMan: A unified framework to manage cybersecurity and safety in manufacturing industry
abstract
Summary Industrial control systems (ICS) are considered cyber‐physical systems that join both cyber and physical worlds. Due to their tight interaction, where humans and robots co‐work and co‐inhabit in the same workspaces and production lines, cyber‐attacks targeting ICS can alter production processes and even bypass safety procedures. As an example, these cyber‐attacks could interrupt physical industrial processes and cause potential injuries to workers. In this article, we present SafeMan, a unified management framework based on the Edge Computing paradigm that provides high‐performance applications for the detection and mitigation of both cyber‐attacks and safety threats in industrial scenarios. Three use cases show specific threats in manufacturing as well as the SafeMan actions carried out to detect and mitigate them. In order to validate our proposal, a pool of experiments was performed with Electra, an industrial dataset with normal network traffic and different cyber‐attacks by using a given number of Modbus TCP and S7Comm devices. The experiments measured the runtime performance of anomaly detection techniques based on machine learning and deep learning to detect cyber‐attacks in control networks. The experimental results show that Neural Networks report the best performance, being able to examine 217 feature vectors per second over Electra, and therefore demonstrating that it can be used as detection model for SafeMan in real scenarios.
Ángel Luis Perales Gómez, Lorenzo Fernández Maimó, Alberto Huertas Celdrán, Félix J. García Clemente, Manuel Gil Pérez, Gregorio Martínez Pérez
Softw. Pract. Exp.6
2020 Welcome Messages from IEEE EUC 2020 Program Chairs
abstract
On behalf of the Program Committee of the 18th IEEE International Conference on Embedded and Ubiquitous Computing (IEEE EUC 2020), we would like to welcome you to join the conference in Guangzhou, China, December 29, 2020 - January 1, 2021.
Gregorio Martínez Pérez, Scott Fowler, Kuanching Li
EUC1
2020 PROTECTOR: Towards the protection of sensitive data in Europe and the US
Alberto Huertas Celdrán, Manuel Gil Pérez, Izidor Mlakar, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Md. Zakirul Alam Bhuiyan
Comput. Networks6
2020 UMUDGA: A dataset for profiling DGA-based botnet
Mattia Zago, Manuel Gil Pérez, Gregorio Martínez Pérez
Comput. Secur.3
2020 Scalable detection of botnets based on DGA: Efficient feature discovery process in machine learning techniques
Mattia Zago, Manuel Gil Pérez, Gregorio Martínez Pérez
Soft Comput.3
2020 SELFNET 5G mobile edge computing infrastructure: Design and prototyping
abstract
Summary This paper presents the design and prototype implementation of the SELFNET fifth‐generation (5G) mobile edge infrastructure. In line with the current and emerging 5G architectural principles, visions, and standards, the proposed infrastructure is established primarily based on a mobile edge computing paradigm. It leverages cloud computing, software‐defined networking, and network function virtualization as core enabling technologies. Several technical solutions and options have been analyzed. As a result, a novel portable 5G infrastructure testbed has been prototyped to enable the preliminary testing of the integrated key technologies and to provide a realistic execution platform for further investigating and evaluating software‐defined networking– and network function virtualization–based application scenarios in 5G networks.
Enrique Chirivella-Perez, Ricardo Marco Alaez, Alba Hita, Ana Serrano Mamolar, José M. Alcaraz Calero, Qi Wang 0001, Pedro Neves 0001, Giacomo Bernini, Konstantinos Koutsopoulos, Manuel Gil Pérez, Gregorio Martínez Pérez, Maria João Barros, Anastasius Gavras
Softw. Pract. Exp.11
2020 Spotting Political Social Bots in Twitter: A Use Case of the 2019 Spanish General Election
Javier Pastor-Galindo, Mattia Zago, Pantaleone Nespoli, Sergio López Bernal, Alberto Huertas Celdrán, Manuel Gil Pérez, José A. Ruipérez-Valiente, Gregorio Martínez Pérez, Félix Gómez Mármol
IEEE Trans. Netw. Serv. Manag.8
2019 Detection of economic denial of sustainability (EDoS) threats in self-organizing networks
Marco Antonio Sotelo Monge, Jorge Maestre Vidal, Gregorio Martínez Pérez
Comput. Commun.3
2019 Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Gregorio Martínez Pérez
Mob. Networks Appl.4
2019 Dynamic network slicing management of multimedia scenarios for future remote healthcare
Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Fabrizio Ippoliti, Gregorio Martínez Pérez
Multim. Tools Appl.5
2019 Security, Privacy, and Trust for Cyberphysical-Social Systems
Laurence T. Yang, Wei Wang 0088, Gregorio Martínez Pérez, Willy Susilo
Secur. Commun. Networks3
2018 Catalog-Driven Services in a 5G SDN/NFV Self-Managed Environment
abstract
With the Fifth-Generation (5G) mobile networks set to arrive within the next years, this new generation will transform the industry with a profound impact on its customers as well as on the existing technologies and network architectures. Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) will play key roles for the network operators as they prepare the migration to 5G, allowing them to quickly scale their networks. This paper presents a research work undertaken on this new paradigm of virtualized and programmable networks, aiming to address Self-Organizing Networks (SON) scenarios in a NFV/SDN context, focusing on detection and prediction of potential network and service anomalies. Towards this end, the performance management system performs aggregation, correlation and analysis of data gathered from the virtualized and programmable network elements. In particular, customized catalog-driven tools are developed, and the results show that they are able to successfully address these requirements. Current performance management platforms in production are designed for non-virtualized (non-NFV) and non-programmable (non-SDN) networks, and the knowledge gathered from this research brings some new understanding on how management platforms must evolve in order to be prepared for the upcoming next-generation mobile networks.
Nuno Henriques, Susana Sargento, Pedro Neves 0001, Manuel Gil Pérez, Gregorio Martínez Pérez, Giacomo Bernini, Qi Wang 0001, José M. Alcaraz Calero, Konstantinos Koutsopoulos
ISCC5
2018 Real-time aggregation framework in a 5G SDN self-management environment
abstract
The next-generation 5G mobile networks are expected to bring a major shift on the management paradigm based on Network Function Virtualization (NFV) and Software-Defined Networking (SDN) compared with its precursor, 4G. Consequently, operators need to significantly change their network architectures, management mechanisms and business models to accommodate and address the 5G challenges. This paper contributes to advancing the operators' management capabilities in the monitoring and analytic domains, looking at the evolution of the existing performance management platform from a leading operator to a new SDN/NFV-enabled platform, in the context of the EU 5G project SELFNET. This work focuses on designing and prototyping the essential functionalities to perform real-time processing over network infrastructure data. This work devises a new Complex Event Processing (CEP) framework, a realtime framework for processing and aggregating big data using a dynamic rule-based approach. This CEP framework has been successfully implemented and deployed, with aggregation rules applied to a Self-Protection use case, which is able to provide in real-time information about detected botnets in the network. From a high-level perspective, this work brings some new understanding about the role of SDN/NFV network management tools for 5G network operators.
Rui Pedro, Susana Sargento, Pedro Neves 0001, Manuel Gil Pérez, Gregorio Martínez Pérez, Giacomo Bernini, Qi Wang 0001, José M. Alcaraz Calero
WCNC5
2018 Guest Editorial Deep Learning Models for Industry Informatics
abstract
The papers in this special issue mainly focus on deep learning models for industry informatics, addressing both original algorithmic development and new applications of deep learning.
Dharma P. Agrawal, Brij B. Gupta, Haoxiang Wang 0001, Xiaojun Chang, Shingo Yamaguchi 0001, Gregorio Martínez Pérez
IEEE Trans. Ind. Informatics6
2017 SecRBAC: Secure data in the Clouds
abstract
Most current security solutions are based on perimeter security. However, Cloud computing breaks the organization perimeters. When data resides in the Cloud, they reside outside the organizational bounds. This leads users to a loos of control over their data and raises reasonable security concerns that slow down the adoption of Cloud computing. Is the Cloud service provider accessing the data? Is it legitimately applying the access control policy defined by the user? This paper presents a data-centric access control solution with enriched role-based expressiveness in which security is focused on protecting user data regardless the Cloud service provider that holds it. Novel identity-based and proxy re-encryption techniques are used to protect the authorization model. Data is encrypted and authorization rules are cryptographically protected to preserve user data against the service provider access or misbehavior. The authorization model provides high expressiveness with role hierarchy and resource hierarchy support. The solution takes advantage of the logic formalism provided by Semantic Web technologies, which enables advanced rule management like semantic conflict detection. A proof of concept implementation has been developed and a working prototypical deployment of the proposal has been integrated within Google services.
Juan Manuel Marín Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta
IEEE Trans. Serv. Comput.2
2016 MASTERY: A multicontext-aware system that preserves the users' privacy
abstract
Users' privacy is a critical challenge for any information management system. The proliferation of mobile devices has promoted the use of context-aware solutions, making the protection of the users' information an even greater challenge. Addressing this requires a given mechanism that allows users to manage and control their personal information. In this sense, this paper proposes a privacy-preserving and context-aware system named MASTERY (Multicontext-Aware System That prEserves the useRs' privacY) that manages the privacy of the users' information in intra- and inter-context scenarios. MASTERY is a trusted third party that suggests to users a pool of privacy policies (profiles) aware to the context in which they are located, who can modify them according to their interests. These policies protect the privacy of the users' information being accessed from others without their consent. The information about users and contexts is managed by using semantic web techniques. This provides a common infrastructure that makes possible to represent, process, and share information between independent systems easily.
Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Gregorio Martínez Pérez
NOMS4
2016 Dynamic counter-measures for risk-based access control systems: An evolutive approach
Daniel Díaz López, Ginés Dólera Tormo, Félix Gómez Mármol, Gregorio Martínez Pérez
Future Gener. Comput. Syst.4
2016 A Script-Based Prototyping Framework to Boost Agile-UX Developments
Pedro Luis Mateo Navarro, Gregorio Martínez Pérez, Diego Sevilla Ruiz
J. Comput. Sci. Technol.2
2016 A lightweight framework for dynamic GUI data verification based on scripts
abstract
Runtime verification (RV) provides essential mechanisms to enhance software robustness and prevent malfunction. However, RV often entails complex and formal processes that could be avoided in scenarios in which only invariants or simple safety properties are verified, for example, when verifying input data in Graphical User Interfaces (GUIs). This paper describes S-DAVER, a lightweight framework aimed at supporting separate data verification in GUIs. All the verification processes are encapsulated in an independent layer and then transparently integrated into an application. The verification rules are specified in separate files and written in interpreted languages to be changed/reloaded at runtime without recompilation. Superimposed visual feedback is used to assist developers during the testing stage and to improve the experience of users during execution. S-DAVER provides a lightweight, easy-to-integrate and dynamic verification framework for GUI data. It is an integral part of the development, testing and execution stages. An implementation of S-DAVER was successfully integrated into existing open-source applications, with promising results. Copyright © 2015 John Wiley & Sons, Ltd.
Pedro Luis Mateo Navarro, Diego Sevilla Ruiz, Gregorio Martínez Pérez
Softw. Test. Verification Reliab.3
2015 Managing XACML systems in distributed environments through Meta-Policies
Daniel Díaz López, Ginés Dólera Tormo, Félix Gómez Mármol, Gregorio Martínez Pérez
Comput. Secur.4
2015 Towards privacy-preserving reputation management for hybrid broadcast broadband applications
Ginés Dólera Tormo, Félix Gómez Mármol, Gregorio Martínez Pérez
Comput. Secur.3
2015 Dynamic and flexible selection of a reputation mechanism for heterogeneous environments
Ginés Dólera Tormo, Félix Gómez Mármol, Gregorio Martínez Pérez
Future Gener. Comput. Syst.3
2015 Intercloud Trust and Security Decision Support System: an Ontology-based Approach
Jorge Bernal Bernabé, Gregorio Martínez Pérez, Antonio F. Skarmeta
J. Grid Comput.2
2015 Chasing Offensive Conduct in Social Networks: A Reputation-Based Practical Approach for Frisber
abstract
Social network users take advantage of anonymity to share rumors or gossip about others, making it important to provide means to report offensive conduct. This article presents a proposal to automatically manage these reports. We consider not only the users’ public behavior, but also private messages between users. The automatic approach is based, in both cases, on the reporters’ reputation along with other metrics intrinsic to social networks. Promising results from adopting the proposed reporting methods on Frisber, a geolocalized social network in production, are presented as well as some experiments based on real data extracted from Frisber.
Santiago Pina Ros, Ángel Pina Canelles, Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez
ACM Trans. Internet Techn.5
2014 Trustworthy placements: Improving quality and resilience in collaborative attack detection
Manuel Gil Pérez, Juan Tapiador, John A. Clark, Gregorio Martínez Pérez, Antonio F. Skarmeta
Comput. Networks4
2014 Semantic-aware multi-tenancy authorization system for cloud architectures
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta
Future Gener. Comput. Syst.5
2014 A Context-Aware Interaction Model for the Analysis of Users' QoE in Mobile Environments
abstract
This article describes a novel approach to model the quality of experience (QoE) of users in mobile environments. The context-aware and ratings interaction model (CARIM) addresses the open questions of how to quantify user experiences from the analysis of interaction in mobile scenarios, and how to compare different QoE records to each other. A set of parameters are used to dynamically describe the interaction between the user and the system, the context in which it is performed and the perceived quality of users. CARIM structures these parameters into a uniform representation, supporting the dynamic analysis of interaction to determine QoE of users and enabling the comparison between different interaction records. Its run-time nature allows applications to make context- and QoE-based decisions in real time to adapt themselves, and thus provide a better experience to users. As a result, CARIM provides unified criteria for the inference and analysis of QoE in mobile scenarios. Its design and implementation can be integrated (and easily extended if needed) into many different development environments. An experiment with real users comparing two different interaction designs and validating user behavior hypotheses proved the effectiveness of applying CARIM for the assessment of QoE in mobile applications.
Pedro Luis Mateo Navarro, Gregorio Martínez Pérez, Diego Sevilla Ruiz
Int. J. Hum. Comput. Interact.2
2014 Editorial: Cloud computing service and architecture models
Gregorio Martínez Pérez, Sherali Zeadally, Han-Chieh Chao
Inf. Sci.1
2014 Editorial: Special issue on Identity Protection and Management
Adrian Waller, Gregorio Martínez Pérez, Félix Gómez Mármol
J. Inf. Secur. Appl.2
2014 Building a reputation-based bootstrapping mechanism for newcomers in collaborative alert systems
Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez, Antonio F. Skarmeta
J. Comput. Syst. Sci.3
2014 Editorial: Developments in Security and Privacy-Preserving Mechanisms for Future Mobile Communication Networks
Georgios Kambourakis, Gregorio Martínez Pérez, Félix Gómez Mármol
Mob. Networks Appl.2
2014 Taxonomy of trust relationships in authorization domains for cloud computing
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta
J. Supercomput.5
2013 RECLAMO: Virtual and Collaborative Honeynets Based on Trust Management and Autonomous Systems Applied to Intrusion Management
abstract
Security intrusions in large systems is a problem due to its lack of scalability with the current IDS-based approaches. This paper describes the RECLAMO project, where an architecture for an Automated Intrusion Response System (AIRS) is being proposed. This system will infer the most appropriate response for a given attack, taking into account the attack type, context information, and the trust and reputation of the reporting IDSs. RECLAMO is proposing a novel approach: diverting the attack to a specific honey net that has been dynamically built based on the attack information. Among all components forming the RECLAMO's architecture, this paper is mainly focused on defining a trust and reputation management model, essential to recognize if IDSs are exposing an honest behavior in order to accept their alerts as true. Experimental results confirm that our model helps to encourage or discourage the launch of the automatic reaction process.
Manuel Gil Pérez, Verónica Mateos Lanchas, David Fernández 0002, Gregorio Martínez Pérez, Víctor A. Villagrá
CISIS4
2012 LFTM, linguistic fuzzy trust mechanism for distributed networks
abstract
SUMMARY Trust is, in some cases, being considered as a requirement in highly distributed communication scenarios. Before accessing a particular service, a trust model is then being used in these scenarios to determine if the service provider can be trusted or not. It is done usually on behalf of the final user or service customer, and with a little intervention of him or her. This is usually happening with the main aim of automatizing the process and because trust models are normally making use of reasoning mechanisms and models difficult to understand by humans. In this paper, we propose the adaptation of a bio‐inspired trust model to deal with linguistic fuzzy labels, which are closer to the human way of thinking. This Linguistic Fuzzy Trust Model also uses fuzzy reasoning. Results show that the new model keeps the accuracy of the underlying bio‐inspired trust model and the level of client satisfaction, while enhancing the interpretability of the model and thus making it closer to the final user. Copyright © 2011 John Wiley & Sons, Ltd.
Félix Gómez Mármol, Javier G. Marín-Blázquez, Gregorio Martínez Pérez
Concurr. Comput. Pract. Exp.3
2012 TRIP, a trust and reputation infrastructure-based proposal for vehicular ad hoc networks
Félix Gómez Mármol, Gregorio Martínez Pérez
J. Netw. Comput. Appl.2
2012 A Non-monotonic Expressiveness Extension on the Semantic Web Rule Language
José M. Alcaraz Calero, Andrés Muñoz 0001, Gregorio Martínez Pérez, Juan A. Botía Blaya, Antonio F. Skarmeta
J. Web Eng.3
2011 Enhancing OpenID through a Reputation Framework
Félix Gómez Mármol, Marcus Q. Kuhnen, Gregorio Martínez Pérez
ATC3
2011 Towards Software Quality and User Satisfaction through User Interfaces
abstract
With this work we expect to provide the community and the industry with a solid basis for the development, integration, and deployment of software testing tools. As a solid basis we mean, on one hand, a set of guidelines, recommendations, and clues to better comprehend, analyze, and perform software testing processes, and on the other hand, a set of robust software frameworks that serve as a starting point for the development of future testing tools.
Pedro Luis Mateo Navarro, Gregorio Martínez Pérez, Diego Sevilla Ruiz
ICST2
2011 Towards an Authorization System for Cloud Infrastructure Providers
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta
SECRYPT5
2011 Semantic-based authorization architecture for Grid
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta
Future Gener. Comput. Syst.5
2010 The SignSpeak Project - Bridging the Gap Between Signers and Speakers
Philippe Dreuw, Hermann Ney, Gregorio Martínez Pérez, Onno Crasborn, Justus H. Piater, Jose Miguel Moya, Mark Wheatley
LREC3
2010 TRIMS, a privacy-aware trust and reputation model for identity management systems
Félix Gómez Mármol, Joao Girão, Gregorio Martínez Pérez
Comput. Networks3
2010 PKI-based trust management in inter-domain scenarios
Gabriel López Millán, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta
Comput. Secur.3
2010 Detection of semantic conflicts in ontology and rule-based information systems
José M. Alcaraz Calero, Juan Manuel Marín Pérez, Jorge Bernal Bernabé, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta
Data Knowl. Eng.5
2010 Towards an authorisation model for distributed systems based on the Semantic Web
abstract
Authorisation is a crucial process in current information systems. Nowadays, many of the current authorisation systems do not provide methods to describe the semantics of the underlying information model which they are protecting. This fact can lead to mismatch problems between the semantics of the authorisation model and the semantics of the underlying data and resources being protected. In order to solve this problem, this paper describes an authorisation model based on Semantic Web technologies. This authorisation model uses the common information model (CIM) to represent the underlying information model. For this reason, a new conversion process of CIM into the Semantic Web languages has been proposed converting properly the semantics available in the CIM model. This representation provides a suitable information model based on a well-known logic formalism for implementing the authorisation model and a formal language for describing concisely the semantic of the information models being protected. The formal authorisation model supports role-based access control (RBAC), hierarchical RBAC, conditional RBAC and object hierarchies, among other features. Moreover, this paper describes an authorisation architecture for distributed systems taking into account aspects such as privacy among parties and trust management. Finally, some implementation aspects of this system have also been described.
José M. Alcaraz Calero, Gregorio Martínez Pérez, Antonio F. Skarmeta
IET Inf. Secur.2
2009 TRMSim-WSN, Trust and Reputation Models Simulator for Wireless Sensor Networks
abstract
Trust and reputation models research and development for distributed systems such as P2P networks, wireless sensor networks (WSNs) or multi-agent systems has arisen and taken importance in the last recent years among the international research community. However it is not always easy to check the correctness and accuracy of a model and even more, to compare it against other trust and reputation models. This paper presents TRMSim-WSN, a Java-based trust and reputation models simulator aimed to provide an easy way to test a trust and/or reputation model over WSNs and to compare it against other models. It allows the user to adjust several parameters such as the percentage of malicious nodes or the possibility of forming a collusion, among many others.
Félix Gómez Mármol, Gregorio Martínez Pérez
ICC2
2009 Security threats scenarios in trust and reputation models for distributed systems
Félix Gómez Mármol, Gregorio Martínez Pérez
Comput. Secur.2
2009 Towards the homogeneous access and use of PKI solutions: Design and implementation of a WS-XKMS server
José M. Alcaraz Calero, Gabriel López Millán, Gregorio Martínez Pérez, Antonio F. Skarmeta
J. Syst. Archit.3
2009 Intrusion detection using a linguistic hedged fuzzy-XCS classifier system
Javier G. Marín-Blázquez, Gregorio Martínez Pérez
Soft Comput.2
2008 Building and Managing Policy-Based Secure Overlay Networks
abstract
Overlay networks represent a flexible approach for distributed services deployed across different administrative domains to group according to a given criteria without modification of the underlying network. Two key features for such overlays to be effective and useful are security and dynamicity. This paper introduces a proposal for the elements (i.e., architecture, protocols, and formal information models) needed to dynamically deploy secure overlay networks in certain multi-domain scenarios.
Gregorio Martínez Pérez, Félix J. García Clemente, Antonio F. Skarmeta
PDP1
2007 A Linguistic Fuzzy-XCS Classifier System
abstract
Data-driven construction of fuzzy systems has followed two different approaches. One approach is termed precise (or approximative) fuzzy modelling, that aims at numerical approximation of functions by rules, but that pays little attention to the interpretability of the resulting rule base. On the other side is linguistic (or descriptive) fuzzy modelling, that aims at automatic rule extraction but that uses fixed human provided and linguistically labelled fuzzy sets. This work follows the linguistic fuzzy modelling approach. It uses an extended Classifier System (XCS) as mechanism to extract linguistic fuzzy rules. XCS is one of the most successful accuracy-based learning classifier systems. It provides several mechanisms for rule generalization and also allows for online training if necessary. It can be used in sequential and non-sequential tasks. Although originally applied in discrete domains it has been extended to continuous and fuzzy environments. The proposed Linguistic Fuzzy XCS has been applied to several well-known classification problems and the results compared with both, precise and linguistic fuzzy models.
Javier G. Marín-Blázquez, Gregorio Martínez Pérez, Manuel Gil Pérez
FUZZ-IEEE2
2006 Dynamic and secure management of VPNs in IPv6 multi-domain scenarios
Gregorio Martínez Pérez, Gabriel López Millán, Félix J. García Clemente, Antonio F. Skarmeta
Comput. Commun.1
2005 Implementing RADIUS and Diameter AAA Systems in IPv6-Based Scenarios
abstract
AAA (authentication, authorization and accounting) frameworks are defined as a set of models, infrastructures and protocols needed to interconnect AAA entities. They have been mainly deployed so far using the RADIUS protocol in IPv4 networks. However, when taking such AAA systems to IPv6 networks some interesting issues appear that need to be addressed. This is the main focus of this paper where both RADIUS and diameter protocols are deployed in different IPv6-related scenarios.
Rafael Marín López, Gregorio Martínez Pérez, Antonio F. Skarmeta
AINA2
2005 Deploying Secure Cryptographic Services in Multi-Domain IPv6 Networks
abstract
There are several reasons to offer PKI (public key infrastructure) services in IPv6 multidomain scenarios. The first reason is to provide IPv6-only or dual-stack connectivity to those Internet users and entities who want to use certification services, but there are other important motivations. If we want to enable and promote security services in IPv6 networks, like end-to-end security, AAA (authentication, authorization and accounting) services, HTTP or DNSsec services, or VPN networks, it is needed to offer the public key services required by the involved protocols. Other relevant reason is to allow services or devices to use X.509 public key certificates containing IPv6 information, such as IPv6 addresses used, for example, by any IPsec-based VPN end point. This is the main motivation of the research work presented in this paper where the most relevant design and implementation issues related with the deployment of PKI services in a multidomain IPv6 network are presented.
Gabriel López Millán, Félix J. García Clemente, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta
AINA4
2003 New security services based on PKI
Antonio F. Skarmeta, Gregorio Martínez Pérez, Óscar Cánovas Reverte
Future Gener. Comput. Syst.2
2001 SPEED Protocol: Smartcard-Based Payment with Encrypted Electronic Delivery
Antonio Ruiz-Martínez, Gregorio Martínez Pérez, Óscar Cánovas Reverte, Antonio F. Skarmeta
ISC2