VLDB 2026 Research / reviewers in the wild / expert
Peter Vörös
dblp:132/6357 · also Péter Vörös
· DBLP profile ↗
13ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0001-7539-9878ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 6 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | In-Network Attack Detection Using Disaggregated Inference & Online LearningabstractThis paper presents a low-latency network attack detection model based on in-network inference. Rather than employing pre-trained models or resorting to manual management, the proposed model operates in a zero-touch manner, relying exclusively on online learning aided by an IDS deployed within the control plane. Flows are classified as-soon-as-possible, enabling the mitigation with minimal delay, typically requiring only a few packets from each flow to be processed. The attack detection system was implemented using the P4 data plane programming language and was evaluated using two different types of programmable switches: CPU-based eBPF switches and the Intel Tofino hardware switch. The evaluation results demonstrate that the proposed model can achieve highly accurate attack detection, with F1 scores reaching approximately 0.95. Gergely Sárközi, Peter Vörös |
GLOBECOM | 2 |
| 2024 | Extensible FRER Security Testbed in a BoxabstractTime-Sensitive Networking (TSN) is expected to provide reliable, low-latency communication for critical systems. Leveraging the Frame Replication and Elimination for Reliability (FRER) protocol, it protects against packet loss by replicating individual packets and delivering them on disjoint forwarding paths. FRER does not contain any in-built security solutions, and several FRER-related security vulnerabilities have recently been identified that could undermine TSN’s ultimate goal of providing extreme reliability. In this paper, we introduce a comprehensive security-focused testbed for analyzing FRER vulnerabilities. Our self-contained setup employs open and adaptable components, runnable on a single server, ensuring flexibility and accessibility. Leveraging eBPF/XDP, it efficiently implements FRER’s data plane functionalities, accommodating both fast-path and slow-path attacks. Parameters like delay, jitter, loss rate, and bandwidth are easily customizable. We validate the testbed’s effectiveness with various attack scenarios. Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Géza Szabó, Sándor Laki |
NetSoft | 3 |
| 2023 | Optimizing Asynchronous Extern Execution in Programmable Software Data PlanesabstractP4 has gained a significant attention as a programming language for describing target-independent packet processing. It supports a diverse hardware and software targets through various architecture models that declare external functions called externs representing target-specific functionalities. These externs may require specific or dedicated resources (e.g., cryptography co-processor, FPGA, etc.) for increased processing speed. In order to process tasks in bulk mode, packet processing may need to be temporarily suspended, while waiting for the function to return. Linear execution of the packet processing pipeline implemented by most P4 software targets cannot efficiently handle such situations. Asynchronous packet processing has been proposed to solve this issue by enabling to serve incoming packets while others are processed by an extern. In this paper, we explore existing approaches for extern execution in software data planes and propose a new lightweight asynchronous method for offloading extern execution to dedicated resources, such as cryptography coprocessors, which perform the extern computations. Our analysis show that the propose method can significantly improve the performance of extern execution in various use cases like IPsec, simple encryption and other small tasks and has negligible overhead compared to a prior solution. We also demonstrate that our method has clear benefits on constrained hardware (PcEngines APU single board computer) where the overhead of extern execution has bigger impact on the overall performance and prior approaches are not practical. Péter Hudoba, Róbert Kitlei, Sándor Laki, Peter Vörös |
GLOBECOM | 4 |
| 2023 | In-Network Quality Control of IP Camera StreamsabstractManufacturing processes are often monitored by IP cameras. The generated video streams can be transferred via a wireless link to be processed and used by remote industrial controllers that manage and configure the industrial task in real-time. However, the link has limited bandwidth and is not capable of transmitting the aggregated traffic of all the IP cameras. Moreover, the platform provider of the remote controller (e.g., cloud) might charge extra fees for high volumes of network traffic. To optimize the data transport, we propose an in-network video quality control method for IP camera streams that drops non-essential frames from temporally irrelevant IP camera streams even when bandwidth is available. Our solution introduces a high-level API through which the operator can define which camera streams are needed with high quality at which actuator positions/states of the industrial process. Our method assumes an aggregation point that monitors the actuators' states and reduces the quality of camera streams that are not important for the control process, selectively dropping a set of video frames. We have implemented a P4-based prototype of the aggregation point and show that the remote controller can be fed with high-quality video streams while meeting bandwidth limitations and potentially saving data transfer costs without modifying the end-points. Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Sándor Laki, Géza Szabó |
MobiHoc | 3 |
| 2023 | In-Network Security Applications with P4RROTabstractComputer networks have become a key infrastructure for many different business domains. Ensuring the security of such interoperable systems is essential in many areas. The emergence of in-network computing and data plane programmability has opened the door to novel security approaches. Although the logic behind most novel solutions is simple, their implementation in P4 is often complex for a non-domain expert or requires problem-specific languages and code generators. Existing in-network approaches only solve specific subproblems and are not general purpose. In this paper, we show how the open-source P4 code generator called P4RROT can simplify the implementation of various in-network security applications. To demonstrate its applicability, we reproduce three recent P4-based security methods. During the implementation, we extended P4RROT with new primitives needed for such applications and also added support for Intel Tofino ASICs. The complexity of the corresponding P4RROT codes is a magnitude lower than the investigated original P4 programs. Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Sándor Laki |
MobiHoc | 3 |
| 2023 | Hybrid P4 Programmable Pipelines for 5G gNodeB and User Plane FunctionsabstractThis paper focuses on hybrid pipeline designs for User Plane Function and next-generation NodeB leveraging target-specific features and an insightful discussion of P4 and target challenges and limitations. The entire or disaggregated UPF runs on P4 targets and allocates packet processing data paths in P4 hardware or DPDK/x86 software based on flow characteristics (e.g., heavy hitters) and QoS requirements (e.g., low-latency slices). For the hybrid gNodeB, most packet processing is executed in commodity Tofino hardware, while unsupported functions such as Automatic Repeat Request and cryptography are performed in DPDK/x86. We show that our hybrid UPF improves the scalability by 18× and reduces latency up to 50%. The results also suggest that careful traffic allocation to pipeline targets is required to optimize each target's strength and avoid processing delays. Finally, we demonstrate a QoS-oriented application of the hybrid UPF and present gNodeB buffer service benchmarks. Suneet Kumar Singh, Christian Esteve Rothenberg, Jonatan Langlet, Andreas Kassler, Peter Vörös, Sándor Laki, Gergely Pongrácz |
IEEE Trans. Mob. Comput. | 5 |
| 2022 | NETREACT: Distributed Event Detection in Sensor Data Streams with Disaggregated Packet Processing PipelinesabstractA new phenomenon called in-network computing has recently emerged with the aim of offloading calculations beyond the traditional task of packet forwarding to network switches. One of the most studied in-network computing applications is processing of sensor data streams. Existing works such as FastReact focus on solving this problem using flexible SmartNICs. In this paper, we propose NETREACT: an improved ASIC-oriented design for distributed event detection in sensor data streams to achieve a disaggregated processing pipeline. In contrast to existing approaches, NETREACT distributes the event detection task among a set of switches while leveraging the capabilities of the Intel Tofino platform in terms of boosting throughput and reducing latency. The proposed event-rule disaggregation method has the advantage of overcoming the hardware resource constraints and improving the overall network performance. Csaba Györgyi, Károly Kecskeméti, Hiba Mallouhi, Peter Vörös, Sándor Laki |
NetSoft | 4 |
| 2022 | In-Network Velocity Control of Industrial Robot Arms
Sándor Laki, Csaba Györgyi, József Peto, Peter Vörös, Géza Szabó |
NSDI | 4 |
| 2021 | In-network Solution for Network Traffic Reduction in Industrial Data CommunicationabstractIndustrial networks rely on standard real-time communication protocols like ProfiNet. These protocols are used for cyclic data exchange between IO devices and controllers. Since continuous monitoring of IO devices is important, a large number of data packets can be observed in such field networks between the IO devices and controllers. Each IO device cyclically reports its data or internal state to a controller at a predefined frequency. However, the reported data of most IO devices are not changing all the time, and thus the same bytes are transmitted multiple times. The majority of data packets is only used for checking the availability of such devices. In this paper, we consider an industrial environment where IO devices are located in an industrial site while controllers are running remotely (e.g., a software PLC in a private or edge cloud), and there is a radio link (e.g., 5G radio) between the two sides. We propose an in-network traffic reduction method that filters out the unnecessary data traffic at the two ends of the radio link, detects failure of devices and the radio link fast, and does not require any modification in the IO devices and controllers. Our solution is based on the cooperation of two P4-programmable networking elements deployed at the two sides of the radio link. Our preliminary measurements with P4-programmable hardware switches and emulated ProfiNet devices show that the method can significantly reduce the load on the radio link, while it could seamlessly be deployed in existing industrial environments. Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Géza Szabó, Sándor Laki |
NetSoft | 3 |
| 2019 | Asynchronous Extern Functions in Programmable Software Data PlanesabstractTarget-independent packet processing languages support diverse hardware and software targets by generalizing over the set of primitive operations (extern-functions)available on the target. In P4, the language specification does not specify whether the invocation of an extern function is synchronous or asynchronous - supposedly synchronous by default. However, in some use cases, it makes more sense to invoke such functions in an asynchronous way and let the thread keep processing packets while the extern operation is being performed by a dedicated resource or accelerator device. In this paper, we propose a method for transparent description and efficient implementation of asynchronous extern function calls in P4-programmable software data planes. Our DPDK - based early prototype relies on the concept of coroutines used for saving packet contexts and manual switching between them. The overhead of the proposed solution is analyzed with a packet encryption case study. Dániel Horpácsi, Sándor Laki, Peter Vörös, Máté Tejfel, Gergely Pongrácz, László Molnár |
ANCS | 3 |
| 2018 | T4P4S: A Target-independent Compiler for Protocol-independent Packet ProcessorsabstractAlthough the programmability of control planes has been thoroughly examined in the past years, only a limited number of studies go beyond the consideration that the data plane is only a collection of simple packet forwarding devices. Even OpenFlow, a popular, very expressive data plane programming language, is still restricted to supporting a subset of existing protocol headers. To overcome such limitations, new data plane programming models have recently emerged. One of the them is P4, a high-level language for programming packet processors that enables great flexibility in the description of packet structures and processing pipelines. In this paper, we propose T4P4S1, a multi-target compiler generating high performance switch programs from P4 descriptions. To support multiple targets, a networking hardware abstraction layer (NetHAL) is defined; the compiler generates a core switch code which is then linked with a target-specific NetHAL implementation. To avoid performance degradation, the boundaries of this separation should be chosen carefully, since the core program is only responsible for target-independent optimization, while the implementation of NetHAL should cover target-dependent enhancements. To analyze the performance, thorough measurements have been carried out, showing that the switch generated by T4P4S can easily scale beyond 100 Gbps. Peter Vörös, Dániel Horpácsi, Róbert Kitlei, Dániel Leskó, Máté Tejfel, Sándor Laki |
HPSR | 1 |
| 2018 | The Price for Programmability in the Software Data Plane: The Vendor PerspectiveabstractThe killer features of the next-generation 5G mobile standard, including mobile edge computing and network slicing, will be very difficult to support with traditional fixed-function network appliances. Rather, the 5G core will depend on programmable switches, which allow packet processing functionality to be reconfigured on the fly in order to deploy virtualized network functions and service chains instantaneously. With 5G on the close horizon, it has become crucial to identify the price for programmability in the software data plane, considering the expected complexity and scale of the next-generation mobile core. In this paper, we report on a multi-year data-plane scalability study we have conducted for a large mobile vendor. Our results paint a rather pessimistic picture on the current landscape of the programmable software data plane. We find that the prominent programmable switches either do not provide all the features necessary to implement 5G telco pipelines efficiently or struggle to meet the scale, and the performance operators have come to expect from conventional fixed-function appliances. The only exception, ESwitch, remains proprietary. We call for further work on data-plane scalability and sketch some directions for future research. Tamás Lévai, Gergely Pongrácz, Péter Megyesi, Peter Vörös, Sándor Laki, Felician Németh, Gábor Rétvári |
IEEE J. Sel. Areas Commun. | 4 |
| 2016 | High speed packet forwarding compiled from protocol independent data plane specificationsabstractP4 is a high level language for programming network switches that allows for great flexibility in the description of packet structure and processing, independent of the specifics of the underlying hardware. In this demo, we present our prototype P4 compiler in which the hardware independent and hardware specific functionalities are separated. We have identified the requisites of the latter, which form the interface of our target specific Hardware Abstraction Library (HAL); the compiler turns P4 code into a target independent core program that is linked to this library and invokes its operations. The two stage separation improves portability: to support a new architecture, only the hardware dependent library has to be implemented. In the demo, we demonstrate the flexibility of our compiler with a HAL for Intel DPDK, and show the packet processing and forwarding performance of compiled switches in different scenarios. Sándor Laki, Dániel Horpácsi, Peter Vörös, Róbert Kitlei, Dániel Leskó, Máté Tejfel |
SIGCOMM | 3 |