Blog

Graph-Based Representation of Infrastructure-as-Code: Enabling Semantic Reasoning for Containerized Systems

The work by researchers Guilherme M. Soares, Lucas S. Vrielink, Juliano A. Wickboldt, Jéferson C. Nobre, and Lisandro Z. Granville, from the Institute of Informatics at the Federal University of Rio Grande do Sul (UFRGS), proposes a way to transform computer configuration files (such as Docker Compose) into a “smart map” that Artificial Intelligence (AI) can understand, allowing users to get answers to questions about their infrastructure simply by conversing.

The paper, presented at SBRC 2026, addresses a context in which containers (small, isolated systems for running websites and apps) are widely used by approximately 90% of companies (Nutanix 2025), and microservices architectures are becoming increasingly complex.

Orchestration tools such as Kubernetes are increasingly being used to manage this expansion and rising complexity, leading to the Infrastructure as Code (IAC) paradigm. However, tools commonly used for automation (linters, CLIs) focus solely on the containers currently running and the syntax of definition files.

As a result, there is a lack of a unified view of the infrastructure that provides an understanding of how components interact, and existing solutions do not offer facilitating mechanisms such as natural language queries to audit transitive dependencies or security risks in complex architectures.

This means that, currently, companies use hundreds of containers (small, isolated systems), and the instructions for these systems are stored in text files known as Docker Compose files. However, traditional tools only check whether the text is written correctly (i.e., syntax). They cannot “see” the big picture—for example: “If this database fails, which other 10 services will go down?”

The system proposed by the researchers transforms cold, technical files into active knowledge that AI uses to help system administrators avoid serious errors and security attacks much more quickly and easily. The proposed framework creates an intelligent map—or a knowledge graph—based on these files. It’s like a mind map where each service, network, or volume is a node connected to another. This map is organized by an ontology—that is, a set of rules defining how each component can connect to others (for example: a service uses an image; a service connects to a network).

Innovation: Using the Model Context Protocol (MCP) to connect this map to AI (such as ChatGPT or Claude)

The project’s major innovation is using the Model Context Protocol (MCP) to connect this graph to generative AI (such as ChatGPT or Claude). Normally, AI makes up answers if it doesn’t know something. With this system, the AI is required to consult the “smart map” before responding.

Thanks to the use of natural language, you don’t need to be an expert in coding. You can ask, “Are there any security risks on my network?” and the system analyzes all connections to provide the answer.

The researchers tested the system in real-world scenarios, and it uncovered issues that common tools overlook, such as the Domino Effect: it was found that a database failure would bring down a service that wasn’t even directly connected to it, but that depended on other services in between.

Another problem detected was a network intrusion via a “hidden path” that a hacker could use to jump from a public network to a secure private network (lateral movement).

In addition, “port” conflicts were identified, which occur when two services attempt to use the same computer “port” at the same time, causing an error during execution.

The researchers’ full article is available at this link

Graph-Based Representation of Infrastructure-as-Code: Enabling Semantic Reasoning for Containerized Systems

The work by researchers Guilherme M. Soares, Lucas S. Vrielink, Juliano A. Wickboldt, Jéferson C. Nobre, and Lisandro Z. Granville, from the Institute of Informatics at the Federal University of Rio Grande do Sul (UFRGS), proposes a way to transform computer configuration files (such as Docker Compose) into a “smart map” that Artificial Intelligence (AI) can understand, allowing users to get answers to questions about their infrastructure simply by conversing.

The paper, presented at SBRC 2026, addresses a context in which containers (small, isolated systems for running websites and apps) are widely used by approximately 90% of companies (Nutanix 2025), and microservices architectures are becoming increasingly complex.

Orchestration tools such as Kubernetes are increasingly being used to manage this expansion and rising complexity, leading to the Infrastructure as Code (IAC) paradigm. However, tools commonly used for automation (linters, CLIs) focus solely on the containers currently running and the syntax of definition files.

As a result, there is a lack of a unified view of the infrastructure that provides an understanding of how components interact, and existing solutions do not offer facilitating mechanisms such as natural language queries to audit transitive dependencies or security risks in complex architectures.

This means that, currently, companies use hundreds of containers (small, isolated systems), and the instructions for these systems are stored in text files known as Docker Compose files. However, traditional tools only check whether the text is written correctly (i.e., syntax). They cannot “see” the big picture—for example: “If this database fails, which other 10 services will go down?”

The system proposed by the researchers transforms cold, technical files into active knowledge that AI uses to help system administrators avoid serious errors and security attacks much more quickly and easily. The proposed framework creates an intelligent map—or a knowledge graph—based on these files. It’s like a mind map where each service, network, or volume is a node connected to another. This map is organized by an ontology—that is, a set of rules defining how each component can connect to others (for example: a service uses an image; a service connects to a network).

Innovation: Using the Model Context Protocol (MCP) to connect this map to AI (such as ChatGPT or Claude)

The project’s major innovation is using the Model Context Protocol (MCP) to connect this graph to generative AI (such as ChatGPT or Claude). Normally, AI makes up answers if it doesn’t know something. With this system, the AI is required to consult the “smart map” before responding.

Thanks to the use of natural language, you don’t need to be an expert in coding. You can ask, “Are there any security risks on my network?” and the system analyzes all connections to provide the answer.

The researchers tested the system in real-world scenarios, and it uncovered issues that common tools overlook, such as the Domino Effect: it was found that a database failure would bring down a service that wasn’t even directly connected to it, but that depended on other services in between.

Another problem detected was a network intrusion via a “hidden path” that a hacker could use to jump from a public network to a secure private network (lateral movement).

In addition, “port” conflicts were identified, which occur when two services attempt to use the same computer “port” at the same time, causing an error during execution.

The researchers’ full article is available at this link

1st Brazilian Symposium on Quantum Computing and Communication (SBCCQ 2026) will take place on July 23 at CSBC

The 1st Brazilian Symposium on Quantum Computing and Communication is part of the CBSC program. It is coordinated by ICoNIoT researchers Antônio Jorge Abelém (UFPA) and Jeferson Nobre (UFRGS), alongside researcher Adenilton Silva (UFPE). The event will take place in the Hortênsia Esquerda Room starting at 8 a.m. The program includes the lecture “Synthesis of Quantum Circuits,” paper and poster presentations, the SECOMU base event, and four Technical Sessions:

TS 1 – Quantum Algorithms, Compilation, and Programming – Chair: Antônio Abelém;
TS 2 – Variational Algorithms and Quantum Optimization – Chair: Diego Abreu;
TS 3 – Quantum Artificial Intelligence and Applications – Chair: Adenilton José da Silva;
TS 4 – Quantum Networks, Security, and Ecosystem – Chair: Jéferson Nobre

All information is available at the symposium website

Bike SP Project is in its second pilot phase and is accepting applications until August 24

The Bike SP Project, co-coordinated by researcher Fabio Kon (IME-USP and ICoNIoT), will launch its second pilot program in September/October 2026. The project offers credits on the Bilhete Único transit card to citizens who use bicycles for their daily commutes.

The Bike SP Project, co-coordinated by researcher Fabio Kon (IME-USP and ICoNIoT), will launch its second pilot program in September/October 2026. The project offers credits on the Bilhete Único transit card to citizens who use bicycles for their daily commutes.
Researchers from IME-USP and FGV Cidades are leading an initiative to assess the impact of the Bike SP program on urban mobility behavior. The study, supported by FAPESP, CNPq, and Tembici, aims to inform evidence-based public policies at a time when the city government is considering regulations for the program.

Up to August 24, any adult resident of the city of São Paulo who owns an Android phone, has an active Bilhete Único, and is able to ride a bike can sign up for the pilot program. Registration is done via the link ime.usp.br/bikesp, after completing a free, mandatory mini-course on traffic safety.

Those selected to participate in the pilot program will be notified by email. Currently, the project is particularly interested in attracting people who do not use bicycles for their daily commutes. Residents of the East, South, and North Zones are also given priority.

Starting in July, selected participants should download the Bike SP app (available only for Android phones) and register the addresses they most frequently use as the starting point or destination of their trips. In September, the pilot program will officially begin: up to two bike trips per day will earn credits on the Bilhete Único, which will be added directly to your card and can be validated at the physical recharge machines already available at public transportation terminals and stations.

“The Municipal Department of Transportation approached us to provide a scientific basis for the Bike SP regulations. Our intention in turning it into a pilot project on the streets was to use the scientific method to understand how the program and its associated software would function in a real-world environment. We will derive the necessary insights by analyzing cyclists’ behavior,” explains Fabio Kon. He is coordinating the research alongside Ciro Biderman, director and researcher at FGV Cidades.

Innovation

The Bike SP program was created by Municipal Law 16.547/2016, which established the possibility of compensating cyclists as a way to encourage active mobility and reduce the use of motorized transportation. The policy, however, was never regulated or actually implemented, and until now, it had not been tested on a large scale.

The city of São Paulo has been expanding its network of bike lanes and already boasts the largest network dedicated to cyclists in Brazil, spanning more than 770 km. The city’s goal is to increase the number of cyclists on the streets fivefold by 2030, as outlined in the São Paulo Municipal Climate Action Plan 2020–2050. The pilot project aims to help the city achieve this goal. The research is funded by FAPESP, CNPq, and Tembici, and is affiliated with EcoSustain, INCT ICoNIoT, and FGV Cidades, the Center for Innovation in Urban Public Policy.

The project’s website provides additional information; visit it and share it.

A Decentralized Architecture for Blockchain-Based Federated Learning: A Case Study on Consensus Mechanisms

Federated Learning is already a well-established technology widely used by companies such as Google, which employs this approach in training carried out directly on users’ devices. However, in this study, researchers Francinaldo Barbosa (UFPI), Luis Guilherme Silva (UFPI), Iure Fé (UFPI), Israel Cardoso (UFPI), Alex Vieira (UFJF), Geraldo P. Rocha Filho (UESB), and Francisco Airton Silva (UFPI) focused on expanding this architecture by integrating Federated Learning with blockchain, aiming to enhance the security and reliability of the distributed training process.

This paper addresses distributed machine learning, which differs from the traditional machine learning model in that, in the latter, client data is sent to a central server, which has greater computational capacity to process it and train the model. However, this process requires large volumes of data to be transmitted over the network, which can lead to issues related to privacy, security, and the risk of malicious attacks. Federated Learning was developed precisely to minimize these problems. Instead of sending user data to the server, each client trains the model locally using its own data. After this step, only the updated model parameters or weights are sent to the central server, while the data remains stored on the client’s device. This reduces the circulation of sensitive information and preserves user privacy.

To achieve their goal, the authors used FLEX, a framework designed for federated learning simulations. This framework includes various libraries, among them FlexBlock, which is responsible for integrating federated learning with blockchain. This integration allows model updates to be recorded and validated in a decentralized manner, increasing the security of the process and making malicious manipulation more difficult.

The proposed architecture combines two communication models:

Client-server, used during training performed by clients and when sending model updates; Peer-to-peer (P2P), used for communication between the different nodes (servers) in the blockchain network.

In the blockchain architecture, servers participate in a consensus process to decide which update will be incorporated into the next block in the chain. The article compares two consensus mechanisms.

The first mechanism is based on logic similar to Proof of Work (PoW), in which the server that performs the most computational work to validate the block wins.

The second mechanism takes into account the performance achieved during training, prioritizing the server that produced the best results (for example, higher accuracy) when updating the model.

The objective of the study was to compare these mechanisms to identify which one offers better performance and greater potential for application in real-world scenarios of Federated Learning with Blockchain.

Training occurs through successive rounds, a characteristic typical of Federated Learning. In each round, clients train the model locally, send their updated parameters to the server, and a new global model is generated. This process is repeated for a predefined number of rounds.

One of the key metrics analyzed was accuracy, which indicates how much the model improves its performance over the course of training rounds—that is, it measures how much the model has “learned.”

The authors observed that the Proof-of-Work-based mechanism exhibits more pronounced fluctuations in accuracy over time. This occurs because the consensus favors the server that expended the greatest computational effort, and not necessarily the one that produced the best trained model. Thus, it is possible for a server to win the consensus even without having the best training results.

Ideally, the evolution of accuracy is expected to show gradual and stable growth until it reaches a point of stabilization, indicating model convergence.

Another result analyzed is shown in Figure 2 on page 11 (the article is published here), which presents the model’s loss over the rounds. This metric indicates the model’s error during training and allows us to assess its ability to converge: the lower the loss, the better the model’s performance tends to be.

Identified Challenges

The authors highlight some limitations of the study.

The main limitation is that the FLEX framework is still quite new, with little documentation and few published works on its specific libraries, especially FlexBlock. This limitation makes comparisons with other studies difficult and limits the tool’s maturity.

Another point noted is that, although the library provides three consensus mechanisms, only two were used in the research. A third mechanism was not included because it appeared to be outdated or not yet fully functional.

Furthermore, the study could have been enriched by comparing a larger number of consensus mechanisms used in blockchain, thereby broadening the analysis of performance, security, and efficiency.

Future Work

As a continuation of this research, the authors suggest the following steps: evaluate a larger number of performance metrics; compare other consensus mechanisms for blockchain; investigate the computational and energy costs of each mechanism throughout the training rounds; and expand the experiments to scenarios more closely resembling real-world applications of Federated Learning.

Read the full article in the SBRC 2026 proceedings

Dynamic Link Aggregation and Traffic Redistribution in Hybrid SDN Networks

Authored by researchers William L. Reiznautt and Nelson Fonseca of the Institute of Computing at the State University of Campinas (UNICAMP), this research paper presents H-DLAFR, a technological solution designed to manage dynamic link aggregation and traffic redistribution in networks that combine modern SDN (Software-Defined Networking) equipment with traditional switches.

SDN networks use an architecture that separates the control plane from the data plane, allowing forwarding policies to be programmed and managed centrally.

As a result, large networks—such as those of companies with geographically distributed branches—can simplify management, reduce operating costs, and facilitate the automation of changes and policies for data flow distribution.

Despite its advances, the full adoption of SDN still faces challenges in corporate and academic environments, especially due to the presence of traditional or legacy equipment that does not support SDN programmability or cannot be updated to incorporate this functionality. It is in this context that hybrid SDN networks have emerged, combining the programmability of SDN with the stability of traditional networks. In these networks, SDN equipment is deployed at strategic points, allowing for indirect control of legacy devices and the collection of metrics on the network’s overall behavior.

The gap that motivated this work was the lack of a solution that combines the programmability of SDN with the compatibility of traditional switches to enable dynamic aggregation and adaptive flow redistribution in hybrid networks. The model proposed in this article, called H-DLAFR (Hybrid Dynamic Link Aggregation and Flow Redistribution), was developed precisely to address this gap, offering a compatible, automated, and resilient approach to link aggregation in hybrid SDN networks.

Innovation

The project’s key innovation consists of using RARP frames to indirectly update the MAC address forwarding table—known as the FDB—in traditional switches.

In addition, the H-LARP policy periodically monitors link utilization and redistributes data flows based on observed conditions, reducing overloads and overcoming the limitations of the static load balancing used by LACP. Experimental tests confirm that this approach significantly increases aggregate throughput and infrastructure resilience, ensuring an efficient transition to programmable networks. Thus, the model offers automation and adaptive load balancing in heterogeneous network environments. In addition to the experimentally demonstrated gains in throughput and link utilization, the architecture incorporates fault detection and self-healing mechanisms.

The experiments were conducted in a combination of a virtualized environment and actual physical equipment.

The research, presented at SBRC 2026, is published at https://sol.sbc.org.br/index.php/sbrc/article/view/42278/42045

Virtualization in Industry: From Fixed Hardware to Edge Applications

Sharing the application at the edge can cause latency issues. However, research by Professor Marcelo Fernandes of INCT ICoNIoT has shown that, depending on the control system, sharing is feasible

Historically, control systems in industrial plants (such as tanks in the chemical processing industry, industrial motors, production lines, and others) involved fixed, dedicated control equipment located near the plant. However, the vast majority of this equipment is undergoing a process of virtualization, becoming software. In modern edge computing architecture, this control equipment can be transformed into microservices in the form of applications running on edge servers. This transition offers a crucial advantage: the ability to share resources. Whereas physical equipment was previously required for each element of the plant (for example, one piece of equipment for each tank), the edge application can now be shared across multiple tanks. This leads to significant cost and energy savings.

However, the shift to shared microservices presents a new challenge: latency. Previously, the proximity of control equipment and industrial IoT devices ensured low latency. Sharing the application at the edge can introduce latency issues. However, research by Professor Marcelo Fernandes of INCT ICoNIoT has shown that, depending on the control system, sharing is feasible. For example, inherently slow systems, such as temperature or level control, tolerate latency and can be shared without issues. Marcelo Fernandes’s line of research, focused on edge computing and industrial IoT, aims precisely to use AI techniques for horizontal scaling. Horizontal scaling refers to the use of AI to automatically increase or decrease the number of these control applications, ensuring that the system continues to function properly.

Hypothesis Confirmed and Next Steps

Articles based on Dr. Fernandes’s research confirm the hypothesis that there are situations in which it is possible to share these control systems (emulating industrial plants) while ensuring they continue to function properly. The next step is crucial: using machine learning to perform horizontal scaling specifically in the context of industrial IoT plants. This is necessary because the parameters analyzed for horizontal scaling differ in each specific situation.

——————————————————————————–

Professor Marcelo Fernandes’ work also includes collaboration with Professor Debora Saade (UFF) in the field of Health, demonstrating the potential for exchange and interdisciplinary collaboration fostered by INCT ICoNIoT.

CSBC begins on July 19 in Gramado

CSBC—the Brazilian Computer Society Conference—begins on the 19th and runs through July 23, and the full program is now available on the website.

This year, the conference features 10 main events and 17 satellite events. Organized by the Brazilian Computer Society (SBC), the leading scientific organization in this field in Brazil, this year’s conference is being organized by researchers Weverton Cordeiro and Alberto Egon Schaeffer Filho (UFRGS)—both affiliated with INCT ICoNIoT—who look forward to welcoming everyone in Gramado.

Social Role

Beyond being a scientific conference, CSBC fulfills a vital social role by bringing our community together to present results and strengthen relationships that drive innovation.

The conference helps professors, students, and professionals from across the country finally reconnect and collaborate. Each year, the conference sets a new challenge. For the 46th edition in 2026, the central theme chosen is: “Digital Transformation for a World in the Face of Climate Emergency.”

Learn more

Weverton Cordeiro and Alberto Egon Schaeffer Filho explain that this choice was motivated by recent climate events, such as the floods in Rio Grande do Sul and the heavy rains with severe impacts that recently occurred in Juiz de Fora, MG. In light of these scenarios, the field of computing proves to be an indispensable ally in the search for solutions, which include monitoring systems and high-precision sensors

 

Researcher Dr. Luiz Bittencourt will present a webinar on July 2

The presentation will be titled ‘The Computing Continuum: Beyond Cloud and Edge Intelligence’

With the combination of Internet of things, edge, and cloud computing, computing services can be scattered over a set of computing resources that encompass everything between users’ devices and, including intermediate computing infrastructure deployed in between. The evolving networking technologies promote enhanced bandwidth and data transmission capacity with lower delays, which enables distributed computing resources to be faced as an entangled, distributed heterogeneous platform. This continuum of computing capacity can be used to process large amounts of data with reduced response times. However, creating a seamless distributed computing infrastructure and managing its resources to optimize applications with widely heterogeneous requirements is still a challenge, even after decades of research. The rise of distributed machine learning techniques adds more complexity but also brings additional mechanisms to address this problem. In this talk, I will present an overview of the resource allocation problem, focusing on aspects that can help build an Intelligent Computing Continuum.

The speaker

Luiz Bittencourt is an Associate Professor at Universidade Estadual de Campinas (UNICAMP), Brazil. Luiz was awarded with the IEEE ComSoc Latin America Young Professional Award in 2013. He acts on the organization of several conferences in the cloud and edge computing topics, and in several technical program committees. He served as associate editor for the IEEE Cloud Computing Magazine, and currently serves as AE for the Computers and Electrical Engineering and the Internet of Things journals, for the Journal of Network and Systems Management, and for IEEE Networking Letters. His main interests are in resource management and scheduling in cloud, edge, and fog computing, and their synergy towards an intelligent computing continuum through distributed machine learning techniques.

webinar with dr luiz bittencourt on july 2 2026

CSBC 2026 will feature a diverse program

The 2026 edition of CSBC will feature 10 main events and 16 satellite events, covering different fields and levels of education.

Highlights include the Computer Science Update Conference (JAI), Women in Information Technology (WIT), the Thesis and Dissertation Competition (CTD), the National Computing Conference of Federal Institutes (ENCompIF), and COMPUTEC.

This diversity allows for the participation of a wide range of audiences, from students in their early stages of education to researchers and professionals engaged in advanced discussions on technology, the market, and management.

CSBC 2026 will be held July 19–23 in Gramado. Learn more