Skip to content
Enrique Tomás Martínez Beltrán
HomeResearchPublicationsTopicsTeachingBlog
Contact
EN/ES
HomeResearchPublicationsTopicsTeachingBlogContact
EN/ES

Enrique Tomás Martínez Beltrán

Postdoctoral research in AI, cybersecurity and federated learning, spanning threat analysis, closed-loop cyberdefense and trustworthy decentralized learning.

  • Privacy Policy
  • Terms of Service
  • Accessibility Statement
  • Google Scholaropens in a new tab
  • ORCIDopens in a new tab
  • LinkedInopens in a new tab
  • GitHubopens in a new tab
All profiles
  • ResearchGateopens in a new tab
  • Scopusopens in a new tab
  • DBLPopens in a new tab
  • Web of Scienceopens in a new tab

Enrique Tomás Martínez Beltrán. All rights reserved.

Back to top

This site loads optional analytics from Google and external analytics providers only if you accept. You can decline and continue using the site normally.

  1. Home
  2. AI and Machine Learning for Cyberdefense
Research topic

AI and Machine Learning for Cyberdefense

AI and machine learning methods for threat detection, incident management, situational awareness and attack mitigation.

CyberdefenseCybersecurityMachine Learning for Security

From detection to operational decisions

AI for cyberdefense is valuable when it helps analysts detect, interpret and respond to hostile activity. The technical challenge is not only predictive accuracy, but also reliability under noisy telemetry, adversarial pressure and incomplete context.

  • Threat detection across network, IoT, industrial and mission-oriented environments.
  • Situational awareness for understanding what is happening and why it matters.
  • Mitigation support that keeps human operators in control of critical decisions.

Why distributed AI matters

Cyberdefense data is rarely centralized in a clean, complete and shareable dataset. Distributed learning, federated approaches and privacy-aware collaboration make it possible to learn from multiple environments without exposing all raw traces to one party.

Research angles represented here

The portfolio connects cyberdefense AI with decentralized federated learning, attack explanation, mitigation recommendation, robust aggregation and applied systems such as aerial reconnaissance, energy anomaly detection and IoT security.

On this page

From detection to operational decisionsWhy distributed AI mattersResearch angles represented hereFrequently asked questions

Frequently asked questions

What is AI for cyberdefense?

It is the use of machine learning and AI methods to detect threats, prioritize incidents, explain attacker behavior and support mitigation in security operations.

Why is explainability important in cyberdefense AI?

Security teams need to understand why a model raised an alert before they trust it in high-impact response workflows.

Can cyberdefense AI work without centralizing data?

Yes, federated and decentralized learning can train or adapt models across different environments while keeping raw telemetry local.

Related projects

DEFENDIS: Decentralized Federated Learning for IoT Device Identification and Security

DEFENDIS develops a framework for uniquely identifying IoT devices in a distributed manner while solving security threats through decentralized federated learning.

View Project

EU-GUARDIAN: European Framework and Proofs-of-concept for the Intelligent Automation of Cyber Defence Incident Management

A European research project on methods and proofs of concept for supporting cyber defence incident management.

View Project

ROBUST-6G: Smart, Automated and Reliable Security Service Platform for 6G

ROBUST-6G studies security mechanisms for 6G systems, including monitoring, secure data management, trustworthy AI services, federated learning, and threat response.

View Project

CyberBrain: Cybersecurity in BCI for Advanced Driver Assistance

A cybersecurity framework for Brain-Computer Interface systems in advanced driver assistance scenarios, focused on detecting and preventing attacks across the BCI lifecycle.

View Project

Related notes

Large Language Models for Cybersecurity: A Careful Starting Point

A practical map of LLM roles in cyberdefense, from threat-intelligence support to alert triage and explanation, with explicit limits and controls.

Large Language ModelsLLMsCybersecurity
Read More

Autonomous Cyberdefense Needs More Than an LLM

How to frame autonomous cyberdefense as a bounded control loop with evidence, policies, recovery paths and accountable human intervention.

Autonomous CyberdefenseLLMsCybersecurity
Read More

LLM-Supported Attack Mitigation Without Unsafe Autopilot

A design pattern for using language models to explain incidents and compare mitigation options while approved policies retain control of execution.

Attack MitigationLLMsAutonomous Cyberdefense
Read More

Retrieval-Augmented Generation for Cybersecurity Workflows

A grounded introduction to RAG for threat intelligence, incident analysis and cyberdefense, including retrieval quality, provenance and failure modes.

RAGRetrieval-Augmented GenerationLLMs
Read More

GraphRAG for Cyber Threat Intelligence

How graph-based retrieval can connect actors, techniques, assets and incidents while preserving a traceable path to source evidence.

GraphRAGRAGThreat Intelligence
Read More