VLDB 2026 Research / reviewers in the wild / expert
Dragoslav Stojadinovic
dblp:157/8347
· DBLP profile ↗
13ranked-venue papers
0as first author
11since 2021 · last 2026
0000-0003-4435-1104ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 9 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SlicePilot: Demystifying Network Slice Placement in Heterogeneous Cloud Infrastructures
Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas |
INFOCOM | 3 |
| 2026 | 5GC-Bench: A Framework for Stress-Testing and Benchmarking 5G Core VNFsabstractThe disaggregated, cloud-native design of the 5G Core (5GC) enables flexibility and scalability but introduces significant challenges. Control-plane procedures involve complex interactions across multiple Virtual Network Functions (VNFs), while the user plane must sustain diverse and resource-intensive traffic. Existing tools often benchmark these dimensions in isolation, rely on synthetic workloads, or lack visibility into fine-grained resource usage. This paper presents 5GC-Bench, a modular framework for stress-testing the 5GC under realistic workloads. 5GC-Bench jointly emulates signaling and service traffic, supporting both VNF profiling and end-to-end service-chain analysis. By characterizing bottlenecks and resource demands, it provides actionable insights for capacity planning and performance optimization. We integrated 5GC-Bench with the OpenAirInterface (OAI) 5GC and deployed it on a real 5G testbed, demonstrating its ability to uncover resource constraints and expose cross-VNF dependencies under scenarios that mirror operational 5G deployments. To foster reproducibility and further research, we release publicly all the artifacts. Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas |
WCNC | 3 |
| 2025 | 5G-STREAM: Service Mesh Tailored for Reliable, Efficient and Authorized Microservices in the CloudabstractExisting registration, discovery, and authorization mechanisms in the 5G core control plane present scalability and efficiency challenges. As cellular deployments scale to accommodate diverse user demands, the 5G core control plane suffers from increased inter-Virtual Network Function (VNF) communication latency, thus deteriorating the reliability of critical procedures. To address this problem, we propose 5G-STREAM (Service mesh Tailored for Reliable, Efficient, and Authorized Microservices) to optimize control plane traffic in distributed cloud environments by establishing a topology awareness of service chains across cloud hierarchies. Leveraging this awareness, 5G-STREAM dynamically configures communication pathways to reduce discovery and authorization signaling overhead, thus increasing the reliability of inter-VNF communication. We develop a prototype of 5G-STREAM and evaluate its performance. Our evaluation results show that 5G-STREAM significantly reduces the process completion time in core service chains by up to 2× inter VNF-Network Repository Function (NRF) latency per transaction, with more pronounced benefits in larger service chains. Furthermore, we show that the cost required to deploy 5G-STREAM is an additional 0.1 USD/hr on AWS for a VNF handling a sustained rate of 50,000 requests/minute. Tolga O. Atalay, Alireza Famili, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
DSN | 4 |
| 2025 | 5G-MAP: Demystifying the Performance Implications of Cloud-Based 5G Core DeploymentsabstractThe Fifth Generation (5G) core network is designed as a set of Virtual Network Functions (VNFs) hosted on Commercial-Off-the-Shelf (COTS) hardware. This creates a growing demand for general-purpose computing resources. Given their elastic infrastructure, cloud services like Amazon Web Services (AWS) are attractive platforms to address this need. Therefore, it is crucial to understand the Quality of Service (QoS) requirements associated with deploying the 5G core in the cloud. We developed the 5G-MAP (5G Measurement and Assessment Platform) to understand the trade-offs between different deployment strategies. Our framework facilitates detailed control and user plane performance assessments in varied deployment scenarios. We integrated 5G-MAP with the OpenAirInterface (OAI) 5G core and utilized it in a series of deployments across seven countries, leveraging eight AWS regions and eighteen edge zones. Our evaluations cover from HTTP transactions to user plane throughput and packet loss. We identify topologies that can considerably lower the 5G core service chain latencies due to a significant reduction in the number of inter-site hops. Such actionable performance improvements illustrate how operators can leverage 5G-MAP to optimize their cloud-based 5G deployments. Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001 |
MobiCom | 2 |
| 2025 | An OpenRAN Security Framework for Scalable Authentication, Authorization, and Discovery of xApps With Isolated Critical ServicesabstractThe OpenRAN initiative promotes an open Radio Access Network (RAN) and offers operators fine-grained control over the radio stack. To that end, O-RAN introduces new components to the 5G ecosystem, such as the near real-time RAN Intelligent Controller (near-RT RIC) and the accompanying extensible Applications (xApps). The introduction of these entities expands the 5G threat surface. Furthermore, with the movement from proprietary hardware to virtual environments enabled by Network Functions Virtualization (NFV), attack vectors that exploit the existing NFV attack surface pose additional threats. To deal with these threats, we propose the xApp repository function (XRF) framework for scalable authentication, authorization, and discovery of xApps. To harden the XRF microservices, we isolate them using Intel Software Guard Extensions (SGX). We benchmark the XRF modules individually and compare how different microservices behave in terms of computational overhead when deployed in virtual and hardware-based isolation sandboxes. Our evaluation shows that the XRF framework scales efficiently in a multi-threaded Kubernetes environment. The isolation of the XRF microservices introduces different amounts of processing overhead depending on the sandboxing strategy. Finally, a security analysis is conducted to show how the XRF framework addresses chosen key issues from the O-RAN and 5G standardization efforts. Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | 5G-WAVE: A Core Network Framework with Decentralized Authorization for Network Slicesabstract5G mobile networks leverage Network Function Virtualization (NFV) to offer services in the form of network slices. Each network slice is a logically isolated fragment constructed by service chaining a set of Virtual Network Functions (VNFs). The Network Repository Function (NRF) acts as a central OpenAuthorization (OAuth) 2.0 server to secure inter-VNF communications resulting in a single point of failure. Thus, we propose 5G-WAVE, a decentralized authorization framework for the 5G core by leveraging the WAVE framework and integrating it into the OpenAirInterface (OAI) 5G core. Our design relies on Side-Car Proxies (SCPs) deployed alongside individual VNFs, allowing point-to-point authorization. Each SCP acts as a WAVE engine to create entities and attestations and verify incoming service requests. We measure the authorization latency overhead for VNF registration, 5G Authentication and Key Agreement (AKA), and data session setup and observe that WAVE verification introduces 155ms overhead to HTTP transactions for decentralizing authorization. Additionally, we evaluate the scalability of 5G-WAVE by instantiating more network slices to observe 1.4x increase in latency with 10x growth in network size. We also discuss how 5G-WAVE can significantly reduce the 5G attack surface without using OAuth 2.0 while addressing several key issues of 5G standardization. Tolga O. Atalay, Hans-Andrew Gibbs, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
INFOCOM | 4 |
| 2023 | Demystifying 5G Traffic Patterns with an Indoor RAN Measurement CampaignabstractThe deployment of commercial 5G network is gaining momentum while research is already moving towards more advanced features. Currently, the lack of an easy-to-construct, open-source testbed that can support commercial off-the-shelf (COTS) devices has hindered academic research. In this paper, we build an open-source over-the-air testbed leveraging advanced features of 5G radio access and core networks developed by the OpenAirInterface (OAI) project. We evaluate the quality of service (QoS) achievable using this testbed and provide visibility into the compute consumption of individual components. Additionally, we present a method to utilize WiFi devices for experimenting with 5G QoS. We collect resource consumption analytics from the 5G user plane in correlation to raw traffic patterns. Our results show that the OAI testbed sustains sub-20ms latency with up to 80Mbps throughput over a 25m range using COTS devices. Device connection remains stable while supporting different use cases such as AR/VR, online gaming, video streaming and voice over IP (VoIP). Finally, we illustrate how these popular use cases affect the CPU utilization in the user plane. This provides insight into the capabilities of existing 5G solutions by demystifying the resource needs of specific use cases. All our results can be recreated using COTS equipment. Tolga O. Atalay, Alireza Famili, Dragoslav Stojadinovic, Angelos Stavrou |
GLOBECOM | 3 |
| 2023 | Securing 5G OpenRAN with a Scalable Authorization Framework for xAppsabstractThe ongoing transformation of mobile networks from proprietary physical network boxes to virtualized functions and deployment models has led to more scalable and flexible network architectures capable of adapting to specific use cases. As an enabler of this movement, the OpenRAN initiative promotes standardization allowing for a vendor-neutral radio access network with open APIs. Moreover, the O-RAN Alliance has begun specification efforts conforming to OpenRAN’s definitions. This includes the near-real-time RAN Intelligent Controller (RIC) overseeing a group of extensible applications (xApps). The use of these potentially untrusted third-party applications introduces a new attack surface to the mobile network plane with fundamental security and system design requirements that are yet to be addressed. To secure the 5G O-RAN xApp model, we introduce the xApp Repository Function (XRF) framework, which implements scalable authentication, authorization, and discovery for xApps. We first present the framework’s system design and implementation details, followed by operational benchmarks in a production-grade containerized environment. The evaluation results, centered on active processing and operation times, show that our proposed framework can scale efficiently in a multi-threaded Kubernetes microservice environment and support a large number of clients with minimal overhead. Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
INFOCOM | 3 |
| 2023 | Large-Scale Dynamic Spectrum Access with IEEE 1900.5.2 Spectrum Consumption ModelsabstractNext generation wireless services and applications, including Augmented Reality, Internet-of-Things, and Smart-Cities, will increasingly rely on Dynamic Spectrum Access (DSA) methods that can manage spectrum resources rapidly and efficiently. Advances in regulatory policies, standardization, networking, and wireless technology are enabling DSA methods on a more granular basis in terms of time, frequency, and geographical location which are key for the operation of 5G and beyond-5G networks. In this context, this paper proposes a novel DSA algorithm that leverages IEEE 1900.5.2 Spectrum Consumption Models (SCMs) which offer a mechanism for RF devices to: (i) "announce" or "declare" their intention to use the spectrum and their needs in terms of interference protection; and (ii) determine compatibility (i.e., non-interference) with existing devices. In this paper, we develop an SCM-based DSA algorithm for spectrum deconfliction in large-scale wireless network environments and evaluate this algorithm in terms of computation time, efficiency of spectrum allocation, and number of device reconfigurations due to interference using a custom simulation platform. The results demonstrate the benefits of using SCMs and their capabilities to perform fine grained spectrum assignments in dynamic and dense communication environments. Prasad Netalkar, Azhaan Zahabee, Carlos E. Caicedo Bastidas, Igor Kadota, Dragoslav Stojadinovic, Gil Zussman, Ivan Seskar, Dipankar Raychaudhuri |
WCNC | 5 |
| 2022 | Network-Slice-as-a-Service Deployment Cost Assessment in an End-to-End 5G TestbedabstractThe next generation of mobile networks will support a wide range of service requirements over a shared virtual infrastructure. Network functions virtualization (NFV) enables the deployment of Radio Access Network (RAN) and core network functions as virtual network functions (VNFs) on commodity hardware instead of proprietary servers. The deployment of the 5G core will be orchestrated between mobile virtual network operators (MVNOs) and cloud infrastructure providers by middle-men Network-slice-as-a-service (NSaaS) providers that will consume Infrastructure-as-a-service (IaaS) from the latter and offer network slices to the former. In this paper, we seek to leverage an end-to-end emulated 5G deployment to offer insight into the cost implications surrounding large-scale core network deployments. Our deployment features real-life traffic patterns corresponding to practical use cases which are fitted with network slicing models. These models are implemented in a 5G testbed to gather compute resource consumption. This data is used to formulate infrastructure procurement costs for popular cloud providers. Our results show steady patterns in compute consumption across all use cases, which we use to make high scale cost projections. In the end, we are able to observe the trade-off between cost and throughput achieved by decentralizing the network slices and offloading the user plane. Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001 |
GLOBECOM | 2 |
| 2022 | Scaling Network Slices with a 5G Testbed: A Resource Consumption StudyabstractThe next generation of networks will be utilized by multiple industry verticals with different service requirements on top of a common infrastructure. Through network function virtualization (NFV), the 5G core and Radio Access Network (RAN) functions are now implemented as virtual network functions (VNFs) on commercial off-the-shelf (COTS) hardware. The use of virtualized micro-services to implement these 5G VNFs enables end-to-end logically isolated network slices on a large scale. In this paper, we seek to measure, analyze, and understand the limits of 5G micro-service virtualization when using lightweight containers to realize different network slicing models with different service guarantees. Our deployment consists of the OpenAirInterface (OAI) core and a simulated RAN in a containerized setting to create a universally deployable testbed. We perform stress tests on individual VNFs and create network slicing models applicable to real-life scenarios. Our analysis captures the increase in compute resource consumption of individual 5G VNFs during various core network procedures. Furthermore, using different network slicing models, we are able to see the progressive increase in resource consumption as the service guarantees of the slices become more demanding. The framework created using this testbed is the first to provide such analytics on lightweight virtualized 5G core VNFs with large scale end-to-end connections. Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
WCNC | 2 |
| 2016 | Exploiting network awareness to enhance DASH over wirelessabstractThe introduction of Dynamic Adaptive Streaming over HTTP (DASH) helped reduce the consumption of resources in video delivery, but its client-based rate adaptation is unable to optimally use the available end-to-end network bandwidth. We consider the problem of optimizing the delivery of video content to mobile clients while meeting the constraints imposed by the available network resources. Observing the bandwidth available in the network's two main components, core network, transferring the video from the servers to edge nodes close to the client, and the edge network, which is in charge of transferring the content to the user via wireless links, we aim to find an optimal solution by exploiting the predictability of future user requests of sequential video segments, as well as the knowledge of available infrastructural resources at the core and edge wireless networks in a given future time window. Instead of regarding the bottleneck of the end-to-end connection as our throughput, we distribute the traffic load over time and use intermediate nodes between the server and the client for buffering video content to achieve higher throughput, and ultimately significantly improve the Quality of Experience for the end user in comparison with current solutions. Francesco Bronzino, Dragoslav Stojadinovic, Cédric Westphal, Dipankar Raychaudhuri |
CCNC | 2 |
| 2015 | Spectrum scanning when the intruder might have knowledge about the scanner's capabilitiesabstractDetecting malicious users in dynamic spectrum access scenarios is a crucial problem that requires an intrusion detection system (IDS) that scans spectrum for malicious activities. In this paper we design a spectrum scanning protocol that incorporates knowledge about the scanning effectiveness across different bands, which can increase scanning efficiency. The adversary, however, can also exploit such knowledge to its advantage. To understand the interplay underlying this problem, we formulate a Bayesian model, where the IDS faces a scanning allocation dilemma: if the intruder has no knowledge, then all the bands are under equal threat, while if the intruder has complete knowledge, then less-protected bands are more likely to be threatened. We solve this dilemma and show the optimal IDS strategy switches between the optimal response to these threats. Finally, we show that the strategy might be sensitive to prior knowledge, which can be corrected by adapted learning. Andrey Garnaev, Wade Trappe, Dragoslav Stojadinovic, Ivan Seskar |
ICASSP | 3 |