VLDB 2026 Research / reviewers in the wild / expert
Christopher Gerking
dblp:145/4092
· DBLP profile ↗
10ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-5531-9607ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 2 first-author · 5 since 2021Computer networks · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enabling a model-driven workflow for ongoing interdisciplinary collaboration in legal threat modelingabstractContext: Software systems often provide critical functionality or process personal data, requiring compliance with applicable legal regulations. Ensuring legal conformity demands close collaboration between legal and technical experts, but differences in terminology and methodology make this challenging. Objective: In this article, we aim to address the challenges in legal interdisciplinary collaboration by proposing a model-based workflow for ongoing and collaborative legal assessments within the context of threat modeling. Method: The central aspects of the workflow are based on model-driven engineering techniques and were developed through active collaboration between researchers in software engineering and legal informatics/data protection at the KASTEL Security Research Labs. The goal of the collaboration was to integrate the methodologies of both domains into the workflow equally. Result: The proposed workflow centers on maintaining consistency between a legal viewpoint and data flow diagrams, addressing legal subsumption, allowing each discipline to work from its own perspective while providing automated support in threat identification through an extended existing data flow analysis framework that considers legal interpretation. We evaluate the workflow and its modeling artifacts by applying it in the domain of the GDPR, discussing feasibility and applicability, and measuring the accuracy and scalability of the extended data flow analysis. Conclusion: By combining discipline-specific viewpoints with automated consistency and threat identification, the workflow supports collaboration and enables iterative assessments. Our findings suggest that the presented workflow is suitable and operationalizable, but identify potential challenges in practical application or transfer to other legal domains. Nicolas Boltz, Leonie Sterz, Oliver Raabe, Christopher Gerking |
Inf. Softw. Technol. | 4 |
| 2025 | Towards Legal Knowledge Transfer Based on Software Architecture
Nicolas Boltz, Janne Wagner, Leonie Sterz, Oliver Raabe, Christopher Gerking |
ECSA | 5 |
| 2025 | Scaling Information Flow Control By-Construction to Component-Based Software Architectures
Rasmus C. Rønneberg, Tabea Bordis, Christopher Gerking, Asmae Heydari Tabar, Ina Schaefer |
FORTE | 3 |
| 2024 | Modeling and Analyzing Zero Trust Architectures Regarding Performance and Security
Nicolas Boltz, Larissa Schmid, Bahareh Taghavi, Christopher Gerking, Robert Heinrich |
ECSA | 4 |
| 2024 | A data-driven active learning approach to reusing ML solutions in scientific applicationsabstractArtificial intelligence can revolutionize scientific projects, but scientists face challenges in reusing, integrating, and deploying cost-effective and high-quality machine learning solutions. Determining suitable algorithms and parameters is difficult, especially for non-programmer scientists. Some algorithms, like deep learning-based methods, offer flexibility but require extensive training on annotated data. This poses a hurdle in labor-intensive tasks like biological image segmentation that relies on expert annotations. In this paper, we present a data-driven framework designed to assist scientists in selecting, reusing, and training machine learning solutions for microscopy image segmentation. The framework is based on establishing a mapping between object morphology features and the optimal segmentation algorithms and settings for individual objects. This mapping is iteratively refined through a combination of unsupervised learning and active learning iterations. To expedite convergence, objects are initially clustered based on their morphology. In each active learning iteration, the most informative and uncertain samples are selected and queried within a specific cluster. Through a biological case study, we demonstrate that our method enables the selection and training of segmentation algorithms specific to object types. Additionally, the selective requests for user input significantly reduce the number of user interactions required for this task. Hamideh Hajiabadi 0001, Christopher Gerking, Lennart Hilbert, Anne Koziolek |
J. Syst. Softw. | 2 |
| 2019 | Component-Based Refinement and Verification of Information-Flow Security Policies for Cyber-Physical Microservice ArchitecturesabstractSince cyber-physical systems are inherently vulnerable to information leaks, software architects need to reason about security policies to define desired and undesired information flow through a system. The microservice architectural style requires the architects to refine a macro-level security policy into micro-level policies for individual microservices. However, when policies are refined in an ill-formed way, information leaks can emerge on composition of microservices. Related approaches to prevent such leaks do not take into account characteristics of cyber-physical systems like real-time behavior or message passing communication. In this paper, we enable the refinement and verification of information-flow security policies for cyber-physical microservice architectures. We provide architects with a set of well-formedness rules for refining a macro-level policy in a way that enforces its security restrictions. Based on the resulting micro-level policies, we present a verification technique to check if the real-time message passing of microservices is secure. In combination, our contributions prevent information leaks from emerging on composition. We evaluate the accuracy of our approach using an extension of the CoCoME case study. Christopher Gerking, David Schubert |
ICSA | 1 |
| 2018 | Towards Preserving Information Flow Security on Architectural Composition of Cyber-Physical Systems
Christopher Gerking, David Schubert |
ECSA | 1 |
| 2018 | Towards ensuring security by design in cyber-physical systems engineering processesabstractEngineering cyber-physical systems secure by design requires engineers to consider security from the ground up. However, current systems engineering processes are not tailored to cyber-physical systems, or lack an integration with security engineering. In this paper, we integrate secure software engineering practices into an engineering process for cyber-physical systems. Thereby, we enable engineers to specify security requirements at the level of systems engineering, and to take effective countermeasures during both platform-independent and platform-specific software engineering. Our key contribution is the integration of threat models for tracing security requirements to countermeasures. We illustrate our approach by an autonomous car with high security requirements. Johannes Geismann, Christopher Gerking, Eric Bodden |
ICSSP | 2 |
| 2017 | How to Efficiently Build a Front-End Tool for UPPAAL: A Model-Driven Approach
Stefano Schivo, Bugra M. Yildiz, Enno Ruijters, Christopher Gerking, Rajesh Kumar 0012, Stefan Dziwok, Arend Rensink, Mariëlle Stoelinga |
SETTA | 4 |
| 2014 | A tool suite for the model-driven software engineering of cyber-physical systemsabstractCyber-physical systems, e.g., autonomous cars or trains, interact with their physical environment. As a consequence, they commonly have to coordinate with other systems via complex message communication while realizing safety-critical and real-time tasks. As a result, those systems should be correct by construction. Software architects can achieve this by using the MechatronicUML process and language. This paper presents the MechatronicUML Tool Suite that offers unique features to support the MechatronicUML modeling and analyses tasks. Stefan Dziwok, Christopher Gerking, Steffen Becker 0001, Sebastian Thiele 0002, Christian Heinzemann, Uwe Pohlmann |
SIGSOFT FSE | 2 |