VLDB 2026 Research / reviewers in the wild / expert
Stephanos Matsumoto
dblp:153/5802
· DBLP profile ↗
15ranked-venue papers
6as first author
9since 2021 · last 2026
0000-0002-4659-054XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 9 · 2 first-author · 9 since 2021Security and privacy · 5 · 4 first-authorSystems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards a Shared Framework for Selection, Design, and Evaluation of Mastery Learning Models in Computing Education
Claudia Szabo, Miranda C. Parker, Judithe Sheard, Giulia Alberini, Andrew Luxton-Reilly, Stephanos Matsumoto, Fiona McNeill, Charlotte Pierce, Naaz Sibia, Jan Vahrenhold, Craig B. Zilles |
ITiCSE (2) | 6 |
| 2026 | An Experience Report: What Students Say Could be Done to Promote DispositionsabstractProfessional dispositions are important in numerous fields, including computing. However, strategies to promote dispositions are not yet well understood. In this experience report, we share what students suggest to promote five dispositions: being collaborative, meticulous, persistent, responsive, and self-directed. To get a broad perspective of students' voices, we gathered feedback over two terms in four courses at three institutions. Tammy VanDeGrift, Mihaela Sabin, Amruth N. Kumar, Bonnie K. MacKellar, Renée A. McCauley, Stephanos Matsumoto |
ITiCSE (1) | 6 |
| 2026 | Understanding Software Engineering Practices and Tools in Undergraduate Mechanical Engineering StudentsabstractThough software development has increasingly become a part of modern engineering practice, even outside of computing, we lack a sufficiently deep understanding of how engineers in many disciplines learn and use software engineering practices and tools (SEPTs). SEPTs include, but extend beyond, programming itself, consisting of practices (e.g., unit testing) and tools (e.g., version control software) that support the design, implementation, or maintenance of software. While many disciplines outside of computing teach programming in their undergraduate curricula, little is known about how these disciplines use, teach, or adopt SEPTs. We thus conducted an exploratory qualitative study on SEPTs among undergraduate students in mechanical engineering (ME), one of the largest engineering disciplines in the US. Specifically, we explored two research questions: (1) What SEPTs do undergraduate ME students use in their work? (2) What factors influence undergraduate ME students' adoption of these SEPTs? We conducted and analyzed three unstructured interviews with ME students at different institutions, using the Guide to the Software Engineering Body of Knowledge (SWEBOK) and the Unified Theory of Acceptance and Use of Technology (UTAUT) as theoretical frameworks. Our results show that ME students' SEPTs span relatively few SWEBOK areas, and are strongly influenced by course design, disciplinary context, and expected time/effort. These results suggest that with continued work in this area, we can likely gain and apply evidence-based insights to improve the teaching of SEPTs within ME in a way that is authentic to its disciplinary context. Prisha Bhatia, Ramzey Burdette, Titilayo Oshinowo, Michelle Jarvie-Eggart, Stephanos Matsumoto |
SIGCSE (1) | 5 |
| 2026 | Primarily Undergraduate Institution Faculty (2 & 4 year institutions)abstractIn this session, we aim to foster a community among computer science faculty across 2-year and 4-year primarily undergraduate institutions (PUIs). We will foster an inclusive environment through activities that allow for multiple forms of engagement (e.g. shows of hands, small group introductions, and full group discussion). We will facilitate discussions about ways computer science is changing at PUIs, differences seen across institutions, and ways that our community can be sustained outside of the SIGCSE TS. In prior years, discussions have focused on topics such as availability of course staff and tutors, availability of conference funding, organizational infrastructure such as sponsored program offices, and requirements for promotion. Sophia Krause-Levy, Cynthia Bagier Taylor, Stephanos Matsumoto, Jean Salac |
SIGCSE (2) | 3 |
| 2025 | The Self-Directed Disposition: What Computing Students SayabstractLifelong learning is essential in computing, given the dynamic nature of the field. Employers and curricular reviewers recognize the value of being self-directed in support of becoming a lifelong learner. The ACM/IEEE-CS Computing Curricula 2020 report identifies self-directed as having elements of self-motivation, determination, and independence. Little is known, however, about how to cultivate this disposition in computing courses. The motivation of this study is to better understand what behaviors computing students believe are self-directed. This study's research questions are: 1) What do students describe as their self-directed practices in computing? and 2) What do students report are factors that prevent them from being self-directed? Assignments in five undergraduate computing courses from four institutions included prompts to elicit student's reflections on how they were self-directed (or not). Thematic content analysis using the constant comparative method produced eight categories of self-directed behaviors (utilizing external resources, learning necessary material, working independently, assessing oneself, planning ahead, applying useful techniques, completing the assigned work, and reviewing against expectations). Thematic analysis also resulted in five categories of factors that impeded the self-directed behavior (assignment structure, unsuccessful effort, self-sufficiency, insufficient motivation, and insufficient time). Understanding how students describe self-directedness can help educators design pedagogical and assessment approaches that facilitate self-directed student behaviors in the classroom. Mihaela Sabin, Amruth N. Kumar, Bonnie K. MacKellar, Renée A. McCauley, Tammy VanDeGrift, Stephanos Matsumoto |
ITiCSE (1) | 6 |
| 2025 | Fostering an Entrepreneurial Mindset in CS EducationabstractThis tutorial will introduce the Entrepreneurial Mindset (EM), an approach from engineering education that aims to foster students' motivation and ability to identify innovative opportunities, address complex, societal problems, and create value in diverse ways. EM specifically centers around the ''3Cs'': Curiosity, Connections, and Creating Value, which are concepts that can benefit students not only in entrepreneurship, but also in their CS work generally. In the tutorial, we will define and operationalize each of these concepts, and facilitate discussions on how participants likely already cover some of these concepts in their courses. We will also discuss facets of CS that especially benefit from EM, as well as how the dispositions, competencies, and behaviors that comprise EM serve as helpful complements to the knowledge, skills, and dispositions described in the CS2023 guidelines. These activities will help participants build a basic understanding of EM-related concepts and its connections to CS. We will then ask participants to design an intervention to foster EM in one of their existing courses, including an activity and an assessment plan, and present this draft to others in the workshop for peer feedback. This activity will help participants apply their understanding to their own teaching, and create a potential plan for integrating EM into their classroom. The tutorial will also introduce the Kern Entrepreneurial Engineering Network (KEEN), which developed EM, and describe further resources to learn about and engage with KEEN. Stephanos Matsumoto, Julia Williams |
SIGCSE (2) | 1 |
| 2024 | WIP: Better Understanding Software Engineering Practices and Tools in Engineering EducationabstractIn this work-in-progress research paper, we present the design and preliminary results of an ongoing thematic analysis of software engineering practices and tools (SEPTs), using Bloom's cognitive taxonomy to analyze the content of the Software Engineering Body of Knowledge (SWEBOK) Guide. Our work is motivated by the fact that while the software development process is becoming increasingly important in engineering, software engineering skills are hardly taught in most undergraduate engineering curricula, and existing descriptions of these skills are not easily accessible to educators in many engineering disciplines. We present results from the analysis of the Software Requirements knowledge area, which those outside of computing have characterized as especially important but not well understood. We identified 92 practices and tools in the knowledge area, and found some promise in our approach: our results help highlight key topics within the knowledge area where SEPTs can be especially helpful, such as requirements elicitation, analysis, and change process management, and provide further clarity on SEPTs from prior work that may be helpful to engineering educators. Though our current findings do not cover the extent to which our identified SEPTs are accessible to those outside of engineering, we are optimistic that our work helps a broader range of engineering educators identify SEPTs that might be underutilized in their engineering practice, and the depth to which they might teach these SEPTs in their curricula. Our work is thus an important first step in addressing the gap between how we teach students to develop software in undergraduate engineering programs and how practitioners in the field develop software. Stephanos Matsumoto, Michelle Jarvie-Eggart |
FIE | 1 |
| 2024 | Introducing Code Quality in the CS1 ClassroomabstractCharacterising code quality is a challenge that was addressed by Börstler et al. 's working group in 2017. As emerged from their study, educators, developers and students have different perceptions of the manifold aspects involved, and a major conclusion of that WG was that "code quality should be discussed more thoroughly in educational programs" [2, p. 70]. However, the lack of materials and the time constraints have slowed down progress in that regard. Cruz Izu, Claudio Mirolo, Jürgen Börstler, Harold S. Connamacher, Ryan Crosby, Richard Glassey, Georgiana Haldeman, Olli Kiljunen, Amruth N. Kumar, David Liu 0002, Andrew Luxton-Reilly, Stephanos Matsumoto, Eduardo Carneiro de Oliveira, Seán Russell 0001, Anshul Shah 0002 |
ITiCSE (2) | 12 |
| 2024 | Computing as a University Graduation RequirementabstractComputing is everywhere, and it's here to stay. Computing is crucial in many disciplines and influences every discipline. It's unlikely we'll willingly return to a society unmediated by computing. How do our institutions proceed? Zachary Dodds, Yuan Garcia, Vidushi Ojha, Mark Guzdial, Tamara Nelson-Fromm, Valerie Barr, Stephanos Matsumoto |
SIGCSE (2) | 7 |
| 2020 | CAPS: Smoothly Transitioning to a More Resilient Web PKIabstractMany recent proposals to increase the resilience of the Web PKI against misbehaving CAs face significant obstacles to deployment. These hurdles include (1) the requirement of drastic changes to the existing PKI players and their interactions, (2) the lack of signaling mechanisms to protect against downgrade attacks, (3) the lack of an incremental deployment strategy, and (4) the use of inflexible mechanisms that hinder recovery from misconfiguration or from the loss or compromise of private keys. As a result, few of these proposals have seen widespread deployment, despite their promise of a more secure Web PKI. To address these roadblocks, we propose Certificates with Automated Policies and Signaling (CAPS), a system that leverages the infrastructure of the existing Web PKI to overcome the aforementioned hurdles. CAPS offers a seamless and secure transition away from today’s insecure Web PKI and towards present and future proposals to improve the Web PKI. Crucially, with CAPS, domains can take simple steps to protect themselves from MITM attacks in the presence of one or more misbehaving CAs, and yet the interaction between domains and CAs remains fundamentally the same. We implement CAPS and show that it adds at most 5% to connection establishment latency. Stephanos Matsumoto, Jay Bosamiya, Yucheng Dai, Paul C. van Oorschot, Bryan Parno |
ACSAC | 1 |
| 2017 | IKP: Turning a PKI Around with Decentralized Automated IncentivesabstractDespite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable. Stephanos Matsumoto, Raphael M. Reischuk |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | Authentication Challenges in a Global EnvironmentabstractIn this article, we address the problem of scaling authentication for naming, routing, and end-entity (EE) certification to a global environment in which authentication policies and users’ sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and EE certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose the Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities’ authentication information globally discoverable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures. Stephanos Matsumoto, Raphael M. Reischuk, Pawel Szalachowski, Tiffany Hyun-Jin Kim, Adrian Perrig |
ACM Trans. Priv. Secur. | 1 |
| 2016 | CASTLE: CA signing in a touch-less environment
Stephanos Matsumoto, Samuel Steffen, Adrian Perrig |
ACSAC | 1 |
| 2015 | ECO-DNS: Expected Consistency Optimization for DNSabstractThe flexibility of the current Domain Name System (DNS) has been stretched to its limits to accommodate new applications such as content delivery networks and dynamic DNS. In particular, maintaining cache consistency has become a much larger problem, as emerging technologies require increasingly-frequent updates to DNS records. Though Time-To-Live (TTL) is the most widely used method of controlling cache consistency, it does not offer the fine-grained control necessary for handling these frequent changes. In addition, TTLs are too static to handle sudden changes in traffic caused by Internet failures or social media trends, demonstrating their inflexibility in the face of unforeseen events. To address these problems, we first propose a metric called Expected Aggregate Inconsistency (EAI), which allows us to consider important factors such as a record's update frequency and popularity when quantitatively measuring inconsistency. We then design ECO-DNS, a lightweight system that leverages the information provided by EAI to optimize a record's TTL. This value can be tuned to individual cache servers' preferences between better consistency and bandwidth overhead. Further-more, our optimization model's flexibility allows us to easily adapt ECO-DNS to handle various caching hierarchies such as multi-level caching while considering the trade off among consistency, overhead, latency, and server load. Chen Chen 0013, Stephanos Matsumoto, Adrian Perrig |
ICDCS | 2 |
| 2014 | PoliCert: Secure and Flexible TLS Certificate ManagementabstractThe recently proposed concept of publicly verifiable logs is a promising approach for mitigating security issues and threats of the current Public-Key Infrastructure (PKI). Although much progress has been made towards a more secure infrastructure, the currently proposed approaches still suffer from security vulnerabilities, inefficiency, or incremental deployment challenges. Pawel Szalachowski, Stephanos Matsumoto, Adrian Perrig |
CCS | 2 |