PoliFlow
Infers control-flow policies from serverless workflows and enforces them transparently at runtime, protecting the intended execution structure without modifying function code.
Serverless security · Cloud-native systems
I design transparent runtime defences for serverless applications, from control-flow enforcement to system-call anomaly detection.

Research
My work explores how serverless applications can be protected transparently across workflows, functions, and orchestration layers—while leaving the tenant's application code unchanged.
Infers control-flow policies from serverless workflows and enforces them transparently at runtime, protecting the intended execution structure without modifying function code.
Uses moving target defence and n-version programming to improve the resilience of vulnerable serverless functions while preserving the availability expected from cloud-native applications.
Detects anomalous serverless function behaviour from eBPF system-call traces, extending protection from workflow structure into the function runtime.
Current focus
My PhD investigates adaptive, transparent mechanisms that can detect and mitigate threats at runtime while preserving cloud-native scalability and performance.
Background
I am a PhD student and researcher at the University of Aveiro and Instituto de Telecomunicações. My current work focuses on dynamic protection for serverless applications, building on a background in cybersecurity, 5G, NFV, and edge computing.
Before beginning my PhD, I worked on standards-aligned MEC architectures and moving-target defence. Since 2024, I have served on the Technical Steering Committee of ETSI Open Source MANO.
Contributing to the technical direction of a standards-aligned open-source network orchestration project.
Recognition from IEEE Portugal, AP2SI, and APDC for the Master's thesis on securing real-world 5G MEC deployments.
Critical vulnerability disclosed in ETSI OSM and later used as a practical security challenge at an OSM Hackfest.
Journal of Network and Systems Management, Vol. 34, No. 3
IEEE International Symposium on Cluster, Cloud and Internet Computing (IEEE CCGrid)
Cluster Computing, Vol. 28, No. 7, p. 465