VLDB 2026 Research / reviewers in the wild / expert
Frank Pallas
dblp:06/8643
· DBLP profile ↗
16ranked-venue papers
4as first author
11since 2021 · last 2025
0000-0002-5543-0265ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 5 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-authorSecurity and privacy · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Prink: ks-Anonymization for Streaming Data in Apache Flink
Philip Groneberg, Saskia Nuñez von Voigt, Thomas Janke, Louis Loechel, Karl Wolf, Elias Grünewald, Frank Pallas |
ARES (1) | 7 |
| 2025 | Energy-aware Prediction-based Scheduling of Dataflow Processing on the Cloud, Fog, and EdgeabstractGlobal climate change is a significant environmental concern, and reducing greenhouse gas emissions is crucial to mitigating this issue. Moreover, there is a need to exploit a prediction-based method to assess the future requirements of applications and (re-)schedule them with the aim of reducing completion time and energy consumption. Therefore, we consider the stochastic requirements of users and investigate an Energy-aware Prediction-based scheduling of dataflow processing on the cloud, fog, and edge method, named EPreMatch, for microservice scaling by applying a machine learning (ML) model based on gradient boosting regression (GBR) and scheduling due to ranking and matching game principles. Firstly, EPreMatch predicts the number of microservice replicas using GBR. Then, the ranking method orders the microservice replicas and devices based on completion times and energy consumption. Thereafter, the EPreMatch schedules microservice replicas requiring dataflow processing on computing devices. Experimental analysis reveals lower completion times, energy consumption, and CO2emission compared to a related prediction-based scheduling method. Narges Mehran, Zahra Najafabadi Samani, Samira Afzal, Frank Pallas |
IC2E | 4 |
| 2025 | Energy-aware Prediction-based Scheduling of Dataflow Processing on the Cloud, Fog, and EdgeabstractGlobal climate change is a significant environmental concern, and reducing greenhouse gas emissions is crucial to mitigating this issue. Moreover, there is a need to exploit a prediction-based method to assess the future requirements of applications and (re-)schedule them with the aim of reducing completion time and energy consumption. Therefore, we consider the stochastic requirements of users and investigate an Energy-aware Prediction-based scheduling of dataflow processing on the cloud, fog, and edge method, named EPreMatch, for microservice scaling by applying a machine learning (ML) model based on gradient boosting regression (GBR) and scheduling due to ranking and matching game principles. Firstly, EPreMatch predicts the number of microservice replicas using GBR. Then, the ranking method orders the microservice replicas and devices based on completion times and energy consumption. Thereafter, the EPreMatch schedules microservice replicas requiring dataflow processing on computing devices. Experimental analysis reveals lower completion times, energy consumption, and CO2emission compared to a related prediction-based scheduling method. Narges Mehran, Zahra Najafabadi Samani, Samira Afzal, Frank Pallas |
IC2E | 4 |
| 2025 | ADApt: Edge Device Anomaly Detection and Microservice Replica PredictionabstractThe increased usage of Internet of Things devices at the network edge and the proliferation of microservice-based applications create new orchestration challenges in Edge computing. These include detecting overutilized resources and scaling out overloaded microservices in response to surging requests. This work presents ADApt, an extension of the ADA-PIPE tool developed in the DataCloud project, using the monitoring data related to Edge devices, detecting the utilization-based anomalies of resources (e.g., processing or memory), investigating the scalability in microservices, and adapting the application executions. To reduce the overutilization bottleneck, we first explore monitored devices executing microservices over various time slots, detecting overutilization-based processing events, and scoring them. Thereafter, based on the memory requirements, ADApt predicts the processing requirements of the microservices and estimates the number of replicas running on the overutilized devices. The prediction results show that the gradient boosting regression-based replica prediction reduces the MAE, MAPE, and RMSE compared to other models. Moreover, ADApt can estimate the number of replicas for each microservice close to the actual data without any prediction and reduce the CPU utilization of the device by 14 % − 28 %. Narges Mehran, Nikolay Nikolov, Radu Prodar, Dumitru Romar, Dragi Kimovski, Frank Pallas, Peter Dorfinger |
ICFEC | 6 |
| 2024 | ALASCA: Function-Driven Advanced Access Control for Big Cold Data
Karl Wolf, Frank Pallas, Sebastian Werner 0001 |
CLOSER | 2 |
| 2024 | Hook-in Privacy Techniques for gRPC-Based Microservice Communication
Louis Loechel, Siar-Remzi Akbayin, Elias Grünewald, Jannis Kiesel, Inga Strelnikova, Thomas Janke, Frank Pallas |
ICWE | 7 |
| 2023 | Hawk: DevOps-driven Transparency and Accountability in Cloud Native SystemsabstractTransparency is one of the most important principles of modern privacy regulations, such as the GDPR or CCPA. To be compliant with such regulatory frameworks, data controllers must provide data subjects with precise information about the collection, processing, storage, and transfer of personal data. To do so, respective facts and details must be compiled and always kept up to date. In traditional, rather static system environments, this inventory (including details such as the purposes of processing or the storage duration for each system component) could be done manually. In current circumstances of agile, DevOps-driven, and cloud-native information systems engineering, however, such manual practices do not suit anymore, making it increasingly hard for data controllers to achieve regulatory compliance. To allow for proper collection and maintenance of always up-to-date transparency information smoothly integrating into DevOps practices, we herein propose a set of novel approaches explicitly tailored to specific phases of the DevOps lifecycle most relevant in matters of privacy-related transparency and accountability at runtime: Release, Operation, and Monitoring. For each of these phases, we examine the specific challenges arising in determining the details of personal data processing, develop a distinct approach and provide respective proof of concept implementations that can easily be applied in cloud native systems. We also demonstrate how these components can be integrated with each other to establish transparency information comprising design- and runtime-elements. Furthermore, our experimental evaluation indicates reasonable overheads. On this basis, data controllers can fulfill their regulatory transparency obligations in line with actual engineering practices. Elias Grünewald, Jannis Kiesel, Siar-Remzi Akbayin, Frank Pallas |
CLOUD | 4 |
| 2023 | Streamlining Personal Data Access Requests: From Obstructive Procedures to Automated Web Workflows
Nicola Leschke, Florian Kirsten, Frank Pallas, Elias Grünewald |
ICWE | 3 |
| 2022 | Non-disclosing Credential On-chaining for Blockchain-Based Decentralized Applications
Jonathan Heiss, Robert Muth, Frank Pallas, Stefan Tai |
ICSOC | 3 |
| 2022 | Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs
Frank Pallas, David Hartmann, Paul Heinrich, Josefine Kipke, Elias Grünewald |
ICWE | 1 |
| 2021 | Messaging with Purpose Limitation -Privacy-Compliant Publish-Subscribe SystemsabstractPurpose limitation is an important privacy principle to ensure that personal data may only be used for the declared purposes it was originally collected for. Ensuring compliance with respective privacy regulations like the GDPR, which codify purpose limitation as an obligation, consequently, is a major challenge in real-world enterprise systems. Technical solutions under the umbrella of purpose-based access control (PBAC), however, focus mostly on data being held at-rest in databases, while PBAC for communication and publish-subscribe messaging in particular has received only little attention. In this paper, we argue for PBAC to be also applied to data-in-transit and introduce and study a concrete proof-of-concept implementation, which extends a popular MQTT message broker with purpose limitation. On this basis, purpose limitation as a core privacy principle can be addressed in enterprise IoT and message-driven integration architectures that do not focus on databases but event-driven communication and integration instead. Karl Wolf, Frank Pallas, Stefan Tai |
EDOC | 2 |
| 2020 | Evaluating the Accuracy of Cloud NLP Services Using Ground-Truth ExperimentsabstractCloud services for natural language processing (NLP) increasingly establish as viable alternatives to self-maintained and self-trained NLP pipelines. In particular, they feature low access barriers and management overhead, a pay-as-you-go pricing model, and elastic scalability allowing to process large amounts of natural language data ad hoc. Any deliberation about employing cloud NLP services in practice does, however, face the challenge that so far, little is known about the accuracy provided by such services as well as about how to conduct respective quality assessments.In this paper, we therefore present a method for evaluating the accuracy provided by cloud NLP services and apply it to cloud services for three prominent NLP tasks offered by Amazon, Google, Microsoft, and IBM. Our results show significantly different accuracies as well as different dependencies on the specifics of input data among the covered providers. Our insights therefore allow for a more evidence-based quality-driven choice of the provider to be used for NLP in practice. Furthermore, the general approach employed may also serve as a blueprint for additional future evaluations of cloud NLP services for other tasks or offered by other providers. Frank Pallas, Dimitri Staufer, Jörn Kuhlenkamp |
IEEE BigData | 1 |
| 2018 | Three Tales of Disillusion: Benchmarking Property Preserving Encryption Schemes
Frank Pallas, Martin Grambow |
TrustBus | 1 |
| 2016 | Pick your choice in HBase: Security or performanceabstractWhen analyzing sensitive data in a cloud-deployed Hadoop stack, data-in-transit security needs to be enabled, especially in the underlying storage tier. This, however, will affect the performance of the system and may partially offset the cost benefits of the cloud. In this paper, we discuss two strategies for securing HBase deployments in the cloud. For both, we present benchmarking results which show performance impacts that significantly exceed the suggested 10% from the official documentation. These results demonstrate (i) that security configurations should follow a rational decision process based on benchmarking results and (ii) that the security architecture of HBase/HDFS should be redesigned with an emphasis on performance. Frank Pallas, Johannes Günther 0003, David Bermbach |
IEEE BigData | 1 |
| 2014 | Benchmarking the Performance Impact of Transport Layer Security in Cloud Database SystemsabstractCloud storage services and NoSQL systems are optimized for performance and availability. Hence, enterprise-grade features like security mechanisms are typically neglected even though there is a need for them with increased cloud adoption by enterprises. Only Transport Layer Security (TLS) is frequently supported. Furthermore, the standard Transport Layer Security (TLS) protocol offers many configuration options which are usually chosen purely based on chance. We argue that in cloud database systems, configuration options should be chosen based on the degree of vulnerability to attacks and security threats as well as on the performance overhead of the respective algorithms. Our contributions are a benchmarking approach for transparent analysis of the performance impact of various TLS configuration options and a custom TLS socket implementation which offers more fine-grained control over the configuration options chosen. We also use our benchmarking approach to study the performance impact of TLS in Amazon DynamoDB and Apache Cassandra. Steffen Müller 0002, David Bermbach, Stefan Tai, Frank Pallas |
IC2E | 4 |
| 2013 | An Architectural Model for Deploying Critical Infrastructure Services in the CloudabstractThe Cloud Computing operational model is a major recent trend in the IT industry, which has gained tremendous momentum. This trend will likely also reach the IT services that support Critical Infrastructures (CI), because of the potential cost savings and benefits of increased resilience due to elastic cloud behaviour. However, realizing CI services in the cloud introduces security and resilience requirements that existing offerings do not address well. For example, due to the opacity of cloud environments, the risks of deploying cloud-based CI services are difficult to assess, especially at the technical level, but also from legal or business perspectives. This paper discusses challenges and objectives related to bringing CI services into cloud environments, and presents an architectural model as a basis for the development of technical solutions with respect to those challenges. Marcus Schöller, Roland Bless, Frank Pallas, Jens Horneber, Paul Smith 0001 |
CloudCom (1) | 3 |