VLDB 2026 Research / reviewers in the wild / expert
Chrystel Gaber
dblp:117/8249
· DBLP profile ↗
16ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0001-5768-7665ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 2 since 2021Computer networks · 5 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TinyContainer: Container Runtime Middleware Enabling Multi-tenant Microcontrollers with Built-in SecurityabstractSoftware containerization technologies for resource-limited devices enable multi-tenant microcontrollers, which allow running multiple applications with different permission levels. However, current solutions lack run time configuration over various settings on container scheduling and container permissions to host resources. This limits the applicability of constrained containerization in dynamic and heterogeneous environments. This paper introduces TinyContainer, a lightweight software container management middleware designed for multi-tenant microcontrollers. TinyContainer provides per-container configurable scheduling and fine-grained access control to host resources through a metadata-driven approach, supporting multiple runtimes via a runtime abstraction layer. We analyze the performance of TinyContainer with a small WebAssembly runtime, CS4WAMR, and RIOT OS, a common RTOS. We report on experiments using popular IoT boards based on various Cortex-M microcontrollers. We show the endpoint system brought by TinyContainer allowing to regulate access of containers to host resources and provide host services to containers with an overhead of up to 4 ms per call. In particular, we showcase a TinyML use case, whereby containers retain data and model weights, while model inference is delegated to native host RTOS services. Bastien Buil, Chrystel Gaber, Samuel Legouix, Emmanuel Baccelli, Samia Bouzefrane 0001 |
WISEC | 2 |
| 2025 | Shared Responsibility in Multi-Tenant MicrocontrollersabstractInternational audience Bastien Buil, Chrystel Gaber, Sylvain Plessis, Emmanuel Baccelli, Samia Bouzefrane 0001 |
CNSM | 2 |
| 2025 | TinyML as a Service on Multi-Tenant Microcontrollers
Bastien Buil, Emmanuel Baccelli, Chrystel Gaber, Samia Bouzefrane 0001 |
EWSN | 3 |
| 2025 | A Continuous Certification Readiness Framework for Cloudification of IT/OT Platforms (Vision Paper)abstractCloud-centric services are becoming the norm in modern IT and Operational Technology (OT) platforms, where cybersecurity risks are also on the rise. The evolving regulatory landscape within Europe, exemplified by the Network and Information Security 2 (NIS2) directive and the Cyber Resilience Act (CRA), further amplifies the necessity for rigorous compliance measures. The presumption of conformity for platforms certified under EU-recognized certification schemes, as outlined by the CRA, is anticipated to promote the certification of IT and OT platforms. Nevertheless, the certification process for these platforms is challenging due to the complexity of cloud architectures and the constantly evolving threats, which require continuous adaptation. Furthermore, both NIS2 and CRA introduce new mandates, including the obligation to manage risks, report incidents to relevant authorities, inform customers about vulnerabilities, and provide relevant mitigation strategies. Consequently, there exists an urgent demand for tools and frameworks that support sustained certification in the cloudification of IT/OT platforms. This paper introduces the Continuous Certification Readiness Framework (CCRF), which is engineered to automate tasks related to certification preparation and support ongoing compliance assessments, thereby enabling organizations to effectively manage risks and uphold a high level of assurance within their cloud environments. Chrystel Gaber, Nicolas Dejon, Ndeye Gagnessiry Ndiaye, Karl Waedt, Vincent Lefebvre, Gürkan Gür, Marc Rennhard, Achilleas Marinakis, Christos-Antonios Gizelis, Jean-Philippe Wary, Claire Loiseaux |
IC2E | 1 |
| 2025 | Liability and Trust Analysis Framework for Multi-Actor Dynamic MicroservicesabstractMicroservices architecture has become an increasingly common approach for building complex software systems. With the distributed nature of microservices, multiple actors can contribute to a service, hence affecting the dynamics of the environment and making the management of liabilities and trust more challenging. Service-Level Agreements (SLAs) are critical in that regard and any SLA violation or breach can result in significant financial damages. One major challenge is the lack of indicators to handle the liability and trust in such architectures. To address this issue, in this paper we propose a liability and trust analysis framework, namely the LASM Analysis Service (LAS), for multi-actor dynamic microservices that employs Machine Learning (ML) techniques. Yacine Anser, Chrystel Gaber, Jean-Philippe Wary, Samia Bouzefrane 0001, Méziane Yacoub, Onur Kalinagac, Gürkan Gür |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Code to Qed, the Project Manager's Guide to Proof EngineeringabstractDespite growing efforts and encouraging successes in recent decades, fully formally verified projects are still rare in the industrial landscape. The industry often lacks the tools and methodologies to efficiently scale the proof development process. In this work, we give a comprehensible overview of the proof development process for proof developers and project managers. The goal is to support proof developers by rationalizing the proof development process, which currently relies heavily on their intuition and expertise, and by facilitating communication with the management line. To this end, we concentrate on the aspect of proof manufacturing and highlight the most significant sources of proof effort. We propose means to mitigate the latter through proof practices (proof structuring, proof strategies, and proof planning), proof metrics, and tools. Our approach is project-agnostic, independent of specific proof expertise, and computed estimations do not assume prior similar developments. We evaluate our guidelines using a separation kernel undergoing formal verification, driving the proof process in an optimised way. Feedback from a project manager unfamiliar with proof development confirms the benefits of detailed planning of the proof development steps, clear progress communication to the hierarchy line, and alignment with established practices in the software industry. Nicolas Dejon, Chrystel Gaber, Gilles Grimaud, Narjes Jomaa |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2023 | Root Cause and Liability Analysis in the Microservices Architecture for Edge IoT ServicesabstractIn this work, we present a liability analysis frame-work for root cause analysis (RCA) in the microservices architecture with IoT-oriented containerized network services. We keep track of the performance metrics of microservices, such as service response time, memory usage and availability, to detect anomalies. By injecting faults in the services, we construct a Causal Bayesian Network (CBN) which represents the relation between service faults and metrics. Service Level Agreement (SLA) data obtained from a descriptor named TRAILS (sTakeholder Responsibility, AccountabIlity and Liability deScriptor) is also used to flag service providers which have failed their commitments. In the case of SLA violation, the constructed CBN is used to predict the fault probability of services under given metric readings and to identify the root cause. Onur Kalinagac, Wissem Soussi, Yacine Anser, Chrystel Gaber, Gürkan Gür |
ICC | 4 |
| 2023 | Demonstrating Liability and Trust Metrics for Multi-Actor, Dynamic Edge and Cloud MicroservicesabstractTransitioning edge and cloud computing in 5G networks towards service-based architecture increases their complexity as they become even more dynamic and intertwine more actors or delegation levels. In this paper, we demonstrate the Liability-aware security manager Analysis Service (LAS), a framework that uses machine learning techniques to compute liability and trust indicators for service-based architectures such as cloud microservices. Based on the commitments of Service Providers (SPs) and real-time observations collected by a Root Cause Analysis (RCA) tool GRALAF, the LAS computes three categories of liability and trust indicators, specifically, a Commitment Trust Score, Financial Exposure, and Commitment Trends. Yacine Anser, Chrystel Gaber, Romain Cajeat, Jean-Philippe Wary, Samia Bouzefrane 0001, Méziane Yacoub, Onur Kalinagac, Gürkan Gür |
MobiCom | 2 |
| 2022 | The Owner, the Provider and the Subcontractors: How to Handle Accountability and Liability Management for 5G End to End ServiceabstractThe adoption of 5G services depends on the capacity to provide high-value services. In addition to enhanced performance, the capacity to deliver Security Service Level Agreements (SSLAs) and demonstrate their fulfillment would be a great incentive for the adoption of 5G services for critical 5G Verticals (e.g., service suppliers like Energy or Intelligent Transportation Systems) subject to specific industrial safety, security or service level rules and regulations (e.g., NIS or SEVESO Directives). Yet, responsibilities may be difficult to track and demonstrate because 5G infrastructures are interconnected and complex, which is a challenge anticipated to be exacerbated in future 6G networks. This paper describes a demonstrator and a use case that shows how 5G Service Providers can deliver SSLAs to their customers (Service Owners) by leveraging a set of network enablers developed in the INSPIRE-5Gplus project to manage their accountability, liability and trust placed in subcomponents of a service (subcontractors). The elaborated enablers are in particular a novel sTakeholder Responsibility, AccountabIity and Liability deScriptor (TRAILS), a Liability-Aware Service Management Referencing Service (LASM-RS), an anomaly detection tool (IoT-MMT), a Root Cause Analysis tool (IoT-RCA), two Remote Attestation mechanisms (Systemic and Deep Attestation), and two Security-by-Orchestration enablers (one for the 5G Core and one for the MEC). Chrystel Gaber, Ghada Arfaoui, Yannick Carlinet, Nancy Perrot, Laurent Valeyre, Marc Lacoste, Jean-Philippe Wary, Yacine Anser, Rafal Artych, Aleksandra Podlasek, Edgardo Montes de Oca, Vinh Hoa La, Vincent Lefebvre, Gürkan Gür |
ARES | 1 |
| 2022 | TRAILS: Extending TOSCA NFV profiles for liability management in the Cloud-to-IoT continuumabstractTo address the growing amount of data generated by the Internet of Things (IoT), Network Functions Virtualization (NFV), 5G, Fog and Edge computing converge to form a Cloud-to-IoT continuum. This complex multi-layer architecture involves several actors among which responsibilities may be blurred. Existing profiles mostly describe deployment aspects and elude responsibility, accountability or liability characteristics. Moreover, the multiplicity of component profiles prevents uniform service management. This paper proposes TRAILS (sTakeholder Responsibility, AccountabIity and Liability deScriptor), an extension of the TOSCA NFV profile that merges the existing profiles and adds a description of the responsibilities and accountabilities of supply chain actors. This allows a uniform and liability-aware management of services involving IoT devices, fog, edge and cloud nodes. To show the usability of our model, we discuss the ecosystem around the generation of the proposed extension as well as its application in an ontology-based referencing module of a liability-aware service manager that we designed. Yacine Anser, Chrystel Gaber, Jean-Philippe Wary, Sara Nieves Matheu-García, Samia Bouzefrane 0001 |
NetSoft | 2 |
| 2021 | A semantic approach for comparing Fog Service Placement Problems
Tanguy Godquin, Morgan Barbier, Chrystel Gaber, Jean-Luc Grimault, Jean-Marie Le Bars |
IM | 3 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 10 |
| 2020 | Applied graph theory to security: A qualitative placement of security solutions within IoT networks
Tanguy Godquin, Morgan Barbier, Chrystel Gaber, Jean-Luc Grimault, Jean-Marie Le Bars |
J. Inf. Secur. Appl. | 3 |
| 2019 | Placement optimization of IoT security solutions for edge computing based on graph theoryabstractIn this paper, we propose a new method for optimizing the deployment of security solutions within an IoT network. Our approach uses dominating sets and centrality metrics to propose an IoT security framework where security functions are optimally deployed among devices. An example of such a solution is presented based on EndToEnd like encryption. The results reveal overall increased security within the network with minimal impact on the traffic. Tanguy Godquin, Morgan Barbier, Chrystel Gaber, Jean-Luc Grimault, Jean-Marie Le Bars |
IPCCC | 3 |
| 2014 | No Smurfs: Revealing Fraud Chains in Mobile Money TransfersabstractMobile Money Transfer (MMT) services provided by mobile network operators enable funds transfers made on mobile devices of end-users, using digital equivalent of cash (electronic money) without any bank accounts involved. MMT simplifies banking relationships and facilitates financial inclusion, and, therefore, is rapidly expanding all around the world, especially in developing countries. MMT systems are subject to the same controls as those required for financial institutions, including the detection of Money Laundering (ML) - a source of concern for MMT service providers. In this paper we focus on an often practiced ML technique known as micro-structuring of funds or smurfing and introduce a new method for detection of fraud chains in MMT systems. Whereas classical detection methods are based on machine learning and data mining, this work builds on Predictive Security Analysis at Runtime (PSA@R), a model-based approach for event-driven process analysis. We provide an extension to PSA@R which allows us to identify fraudsters in an MMT service monitoring network behavior of its end-users. We evaluate our method on simulated transaction logs, containing approximately 460,000 transactions for 10,000 end-users, and compare it with classical fraud detection approaches. With 99.81% precision and 90.18% recall, we achieve better recognition performance in comparison with the state of the art. Maria Zhdanova, Jürgen Repp, Roland Rieke, Chrystel Gaber, Baptiste Hemery |
ARES | 4 |
| 2013 | Fraud Detection in Mobile Payments Utilizing Process Behavior AnalysisabstractGenerally, fraud risk implies any intentional deception made for financial gain. In this paper, we consider this risk in the field of services which support transactions with electronic money. Specifically, we apply a tool for predictive security analysis at runtime which observes process behavior with respect to transactions within a money transfer service and tries to match it with expected behavior given by a process model. We analyze deviations from the given behavior specification for anomalies that indicate a possible misuse of the service related to money laundering activities. We evaluate the applicability of the proposed approach and provide measurements on computational and recognition performance of the tool - Predictive Security Analyser - produced using real operational and simulated logs. The goal of the experiments is to detect misuse patterns reflecting a given money laundering scheme in synthetic process behavior based on properties captured from real world transaction events. Roland Rieke, Maria Zhdanova, Jürgen Repp, Romain Giot, Chrystel Gaber |
ARES | 5 |