Double Acceptance at ESORICS'26 Workshops
17 August 2026, by Mathias Fischer

Photo: https://sites.google.com/di.uniroma1.it/esorics2026/
We are excited to announce that two papers have been accepted for the ESORICS'26 workshops, HotDiSec and MIST.
We congratulate the authors on their achievements and look forward to presenting our work and exchanging ideas with researchers at the workshops.
The accepted papers are:
“Federated Learning based Multivariate Time-series Intelligence for Generalized C2 Beaconing Detection”— accepted at HotDiSec
“FIIPS@Home+: Towards a Decentralized, Privacy-Preserving and Explainable Edge Security Architecture for Smart Homes and SMEs” — accepted at MIST
Abstract – Federated Learning based Multivariate Time-series Intelligence for Generalized C2 Beaconing Detection
Command-and-control (C2) malware often evades detection through sophisticated beaconing, creating a significant generalization gap for anomaly-based models deployed across diverse network environments. We introduce a federated learning framework based on the Multivariate Time Series (MVTS) Transformer that enables robust, cross-organizational threat detection without compromising data privacy.
The framework employs a sliding-window pipeline with log-transformed inter-arrival time features to construct multivariate representations suitable for the transformer architecture. Validated on the IoT-23 and CIC-IoT-DIAD-2024datasets, the federated model demonstrates strong robustness by generalizing effectively to completely unseen traffic patterns. It achieves F1-scores of 98% for benign and 97% for malicious traffic at the window level, and 99% for benign and 91% for malicious traffic at the conversation level.
We further examine the challenges of federating across highly heterogeneous datasets and highlight the influence of temporal granularity on model stability. Our findings confirm that federated learning can produce a robust detector capable of overcoming the generalization limitations of local models by leveraging shared intelligence across distributed infrastructures.
Abstract – FIIPS@Home+: Towards a Decentralized, Privacy-Preserving and Explainable Edge Security Architecture for Smart Homes and SMEs
The increasing number of connected devices in smart homes and small to medium-sized enterprises (SMEs) has significantly expanded the attack surface for malicious actors. Existing security solutions are often too resource-intensive, technically complex for lay users, or pose severe privacy risks by relying on centralized cloud processing.
To address these challenges, we present FIIPS@Home+, a modular, decentralized, and privacy-friendly cybersecurity system. Building upon an edge architecture, our system integrates an automated Security Operations Center (SOC) driven by specialized AI agents to detect and mitigate threats locally.
To assist non-expert users, FIIPS@Home+ employs a Large Language Model (LLM) interface that translates complex security telemetry into actionable, natural-language explanations based on Explainable AI (XAI) principles. A multi-stage anonymization mask protects sensitive user data before it interacts with the LLM. Furthermore, the platform enables the privacy-preserving exchange of Cyber Threat Intelligence (CTI) across communities using a federated reputation system.

