<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<title>IMDEA Networks</title>
<link>https://hdl.handle.net/20.500.12761/1</link>
<description/>
<pubDate>Sun, 20 Sep 2026 13:44:02 GMT</pubDate>
<dc:date>2026-09-20T13:44:02Z</dc:date>
<item>
<title>The Agent in the Middle: A Security and Privacy Analysis of Android AppFunctions</title>
<link>https://hdl.handle.net/20.500.12761/2072</link>
<description>The Agent in the Middle: A Security and Privacy Analysis of Android AppFunctions
Jackevicius, Tautvydas; Girish, Aniketh; Bandara, Vinuri; Suarez-Tangil, Guillermo; Tapiador, Juan; Vallina-Rodriguez, Narseo
Operating systems are beginning to integrate LLMs as agents capable of autonomously orchestrating actions across applications (apps) and services. Android AppFunctions represents one of the first major implementations of this paradigm, enabling privileged AI assistants to discover and invoke functionality exposed by third-party apps on behalf of users. While this architecture promises more capable and seamless user experiences, it also introduces a new security primitive: a privileged, non-deterministic orchestration layer operating across traditional process and permission boundaries. In this paper, we present the first systematic security and privacy analysis of Android AppFunctions. We develop a comprehensive threat model that characterizes the trust relationships between users, AI executors, the operating system, and AppFunction providers. We identify three fundamental classes of risks: (i) privacy violations, (ii) breaches of OS-enforced access control and process isolation mechanisms, and (iii) LLM-integrity attacks. We experimentally validate seven representative attacks, including three reproduced against commercial deployments on Samsung Galaxy S26 and Google Pixel 10 Pro devices. Our evaluation demonstrates that AI-mediated orchestration can enable permission-transitive information flows, provider-controlled side effects, and promptinjection attacks. We further conduct the first study of AppFunctions deployments in the wild and find that many security-critical decisions are delegated to individual providers, resulting in inconsistent protections and limited platform-level enforcement. Our findings show that AppFunctions challenges current Android security principles, assumptions, and privacy protections. By introducing AI assistants as privileged decision-making entities that can orchestrate actions across otherwise isolated apps, AppFunctions reshape Android’s long-standing trust boundaries. These results highlight the need for new approaches to permission mediation, access control, platform policies, app vetting mechanisms, and AI-agent governance.
</description>
<pubDate>Mon, 19 Jul 2027 00:00:00 GMT</pubDate>
<guid isPermaLink="false">https://hdl.handle.net/20.500.12761/2072</guid>
<dc:date>2027-07-19T00:00:00Z</dc:date>
</item>
<item>
<title>Scalable and Explainable Deep Neural Network Frameworks for Mobile Traffic Forecasting</title>
<link>https://hdl.handle.net/20.500.12761/2071</link>
<description>Scalable and Explainable Deep Neural Network Frameworks for Mobile Traffic Forecasting
Moghadas Gholian, Serly
This thesis investigates how deep neural networks can support reliable mobile traffic forecasting for 5G and future mobile networks. Accurate forecasts allow network operators to anticipate demand, allocate radio and computing resources efficiently, improve service quality, and reduce unnecessary energy consumption. However, despite their predictive power, deep learning models are often difficult to interpret and costly to operate at city scale, where traffic patterns vary across hundreds or thousands of base stations. The proposed methods are evaluated using two real-world mobile traffic datasets: the Telecom Italia Milan dataset and measurements from a production LTE network serving a major European metropolitan area.&#13;
&#13;
To address these challenges, the thesis develops an integrated framework centered on explainability, robustness, and scalability. It introduces DeExp, an explainable AI framework that adapts methods such as Layer-wise Relevance Propagation, Grad-CAM, SHAP, and LIME to spatio-temporal traffic forecasting. DeExp converts high-dimensional attribution scores into compact relevance maps, showing which base stations most influence each prediction. These insights are used to analyze model reliability under traffic perturbations, considering prediction error, overprovisioning costs, and service-level agreement violations. Targeted perturbations at influential base stations can increase prediction error by up to 250% in some scenarios.&#13;
&#13;
The thesis further studies realistic mobility-constrained adversaries that can only move locally across neighboring base stations under a limited movement budget. It proposes and evaluates two strategies: a Greedy Mobility-Constrained Attacker and a Smart Explainability-guided Attacker, which combines DeExp relevance scores with look-ahead decision-making. Finally, the thesis proposes a scalable clustering-based training framework that groups base stations with similar temporal behavior using K-means clustering with Dynamic Time Warping and selects the most informative inputs through explainability-guided relevance scores. This reduces telemetry, input-probe, and computational requirements by up to approximately 81% while maintaining competitive, localized forecasting accuracy.
</description>
<pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
<guid isPermaLink="false">https://hdl.handle.net/20.500.12761/2071</guid>
<dc:date>2026-07-23T00:00:00Z</dc:date>
</item>
<item>
<title>Digital Consumption and Political Alignment: Evidence from Mobile Data Across Two European Elections in France</title>
<link>https://hdl.handle.net/20.500.12761/2070</link>
<description>Digital Consumption and Political Alignment: Evidence from Mobile Data Across Two European Elections in France
Martínez-Durive, Orlando E.; Ucar, Iñaki; Smoreda, Zbigniew; Moro, Esteban; Fiore, Marco
Understanding how digital platform consumption relates to political alignment is paramount in contemporary democracies, yet large-scale observational evidence spanning multiple platforms and elections remains scarce. We analyze passive mobile network metadata from a major French mobile network operator (MNO) covering approximately 31% of the mobile market across urban and suburban areas of metropolitan France during the 2019 and 2024 European Parliament elections. Integrating demands for tens of mobile services, including social media, news, messaging, and streaming, with socioeconomic indicators, we model vote shares via Dirichlet regression. We find that digital consumption provides independent and complementary signals of political alignment that, for several parties, match or exceed the predictive power of traditional socioeconomic indicators; combining both increases explanatory ability by up to 28.23%. For instance, right-wing support is associated with higher consumption of Facebook and TikTok, whereas engagement with online news outlets, Twitter, and Instagram correlates with centrist and progressive vote. These associations are consistent across 2019 and 2024, providing a population-scale view of the relationship between mobile platform use and political alignment.
</description>
<pubDate>Mon, 12 Oct 2026 00:00:00 GMT</pubDate>
<guid isPermaLink="false">https://hdl.handle.net/20.500.12761/2070</guid>
<dc:date>2026-10-12T00:00:00Z</dc:date>
</item>
<item>
<title>The Circuit Breaker That Cried Wolf: Measuring BGP Maximum-Prefix Exceedance and Connectivity Impact</title>
<link>https://hdl.handle.net/20.500.12761/2069</link>
<description>The Circuit Breaker That Cried Wolf: Measuring BGP Maximum-Prefix Exceedance and Connectivity Impact
Martínez-Durive, Orlando E.; Chariton, Antonis; Fiore, Marco
The BGP maximum-prefix limit serves as a network circuit breaker, tearing down sessions when announcements exceed a configured threshold.&#13;
Despite its operational significance, little is known empirically about how accurately these limits reflect reality, how often they are exceeded, or what connectivity impact results from their exceedance. We present a first large-scale measurement study of BGP maximum-prefix limits in the wild, combining 12 months of RIPE RIS snapshots with PeeringDB metadata and CAIDA AS Rank data. Only 32.49% of RIS-visible ASes appear in PeeringDB, and 21--27% of recent limit fields carry a value of zero, indicating no declared limit; after filtering for recency and non-zero limits, 14,973 ASes form our analytical dataset.&#13;
Among these, 14.55% (IPv4) and 11.24% (IPv6) exceed their declared limit intermittently, and 2.15% and 2.32% do so in every observed snapshot.&#13;
These exceedances are driven by organic growth, such as new space acquisition or deaggregation, yet the mechanism responds identically to a route leak: Tier-1 and Major peers account for 18.4% of IPv4 lost sessions despite representing roughly 0.1% of all ASes.&#13;
Based on our findings, we offer recommendations for operators and IXPs and call for renewed IETF standardization of dynamic limit negotiation.
</description>
<pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate>
<guid isPermaLink="false">https://hdl.handle.net/20.500.12761/2069</guid>
<dc:date>2026-10-01T00:00:00Z</dc:date>
</item>
</channel>
</rss>
