VLDB 2026 Research / reviewers in the wild / expert
Carlos Joseph Mera-Gómez
dblp:160/2198
· DBLP profile ↗
10ranked-venue papers
1as first author
8since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 1 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security Architectural Approaches and Risk Assessment Methods for Blockchain Systems: A Review and Future DirectionsabstractAmid the widespread use of blockchain technology, the escalating frequency of cyberattacks exploiting its inherent security challenges underscores the critical necessity for a robust and adaptable security risk assessment approach. The distinctive attributes and intricate internal structure of blockchain not only attract malicious actors but also elevate the risk of ill-informed architectural design decisions, potentially introducing security vulnerabilities. This study addresses this imperative by conducting a systematic literature review, classifying publications that elucidate secure architectural design approaches and categorising those that delineate methods for assessing security risks associated with blockchain and smart contracts. The findings reveal four prevalent approaches supporting secure architectural design—decision models, taxonomies, design patterns and guidelines—alongside contributions in blockchain risk assessment encompassing risk identification, analysis and evaluation methods. Furthermore, the study identifies unresolved architectural design challenges and proposes future research directions in this evolving landscape. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon, Rajkumar Buyya |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2025 | Decision Support Model for Selecting the Optimal Blockchain Oracle Platform: An Evaluation of Key FactorsabstractSmart contract-based applications are executed in a blockchain environment, and they cannot directly access data from external systems, which is required for the service provision of these applications. Instead, smart contracts use agents known as blockchain oracles to collect and provide data feeds to the contracts. The functionality and compatibility with smart contract applications need to be considered when selecting the best-fit oracle platform. As the number of oracle alternatives and their features increases, the decision-making process becomes increasingly complex. Selecting the wrong or sub-optimal oracle is costly and may lead to severe security risks. This article provides a decision support model for the oracle selection problem. The model supports smart contract decision-makers in selecting a secure, cost-effective, and feasible oracle platform for their applications. We interviewed oracle co-founders and smart contracts experts to refine and validate the decision model. Two real-world smart contract application case studies were used to evaluate the model. Our model prioritises and suggests more than one possible oracle platform based on the developer’s required criteria, security assessment and cost analysis. Moreover, this guided decision model serves to reveal issues that may go unnoticed if done haphazardly, reduce decision-making efforts and provide a cost-effective solution. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Siamak Farshidi, Rami Bahsoon, Rick Kazman |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2022 | Mining the Limits of Granularity for Microservice Annotations
Francisco Ramírez, Carlos Joseph Mera-Gómez, Rami Bahsoon, Yuqun Zhang |
ICSOC | 2 |
| 2022 | Semantics-Driven Learning for Microservice Annotations
Francisco Ramírez, Carlos Joseph Mera-Gómez, Shengsen Chen, Rami Bahsoon, Yuqun Zhang |
ICSOC | 2 |
| 2022 | Market-inspired framework for securing assets in cloud computing environmentsabstractAbstract Self‐adaptive security methods have been extensively leveraged for securing software systems and users from runtime threats in online and elastic environments, such as the cloud. The existing solutions treat security as an aggregated quality by enforcing “one service for all” without considering the explicit security requirements of each asset or the costs associated with security. Dealing with the security of assets in ultra‐large environments calls for rethinking the way we select and compose services—considering not only the services but the underlying supporting computational resources in the process. We motivate the need for an asset‐centric, self‐adaptive security framework that selects and allocates services and underlying resources in the cloud. The solution leverages learning algorithms and market‐inspired approaches to dynamically manage changes in the runtime security goals/requirements of assets with the provision of suitable services and resources, while catering for monetary and computational constraints. The proposed framework aims to inform the self‐adaptive security efforts of security researchers and practitioners operating in dynamic large‐scale environments, such as the Cloud. To illustrate the utility of the proposed framework it is evaluated using simulation on an application based scenario, involving cloud‐based storage and security services. Giannis Tziakouris, Carlos Joseph Mera-Gómez, Francisco Ramírez, Rami Bahsoon, Rajkumar Buyya |
Softw. Pract. Exp. | 2 |
| 2022 | A Study on Blockchain Architecture Design Decisions and Their Security Attacks and ThreatsabstractBlockchain is a disruptive technology intended to implement secure decentralised distributed systems, in which transactional data can be shared, stored, and verified by participants of the system without needing a central authentication/verification authority. Blockchain-based systems have several architectural components and variants, which architects can leverage to build secure software systems. However, there is a lack of studies to assist architects in making architecture design and configuration decisions for blockchain-based systems. This knowledge gap may increase the chance of making unsuitable design decisions and producing configurations prone to potential security risks. To address this limitation, we report our comprehensive systematic literature review to derive a taxonomy of commonly used architecture design decisions in blockchain-based systems. We map each of these decisions to potential security attacks and their posed threats. MITRE’s attack tactic categories and Microsoft STRIDE threat modeling are used to systematically classify threats and their associated attacks to identify potential attacks and threats in blockchain-based systems. Our mapping approach aims to guide architects to make justifiable design decisions that will result in more secure implementations. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon, Rick Kazman |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2021 | Assessing Smart Contracts Security Technical DebtsabstractSmart contracts are self-enforcing agreements that are employed to exchange assets without the approval of trusted third parties. This feature has encouraged various sectors to make use of smart contracts when transacting. Experience shows that many deployed contracts are vulnerable to exploitation due to their poor design, which allows attackers to steal valuable assets from the involved parties. Therefore, an assessment approach that allows developers to recognise the consequences of deploying vulnerable contracts is needed. In this paper, we propose a debt-aware approach for assessing security design vulnerabilities in smart contracts. Our assessment approach involves two main steps: (i) identification of design vulnerabilities using security analysis techniques and (ii) an estimation of the ramifications of the identified vulnerabilities leveraging the technical debt metaphor, its principal and interest. We use examples of vulnerable contracts to demonstrate the applicability of our approach. The results show that our assessment approach increases the visibility of security design issues. It also allows developers to concentrate on resolving smart contract vulnerabilities through technical debt impact analysis and prioritisation. Developers can use our approach to inform the design of more secure contracts and for reducing unintentional debts caused by a lack of awareness of security issues. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon |
TechDebt@ICSE | 2 |
| 2021 | Systematic Scalability Modeling of QoS-aware Dynamic Service CompositionabstractIn Dynamic Service Composition (DSC), an application can be dynamically composed using web services to achieve its functional and Quality of Services (QoS) goals. DSC is a relatively mature area of research that crosscuts autonomous and services computing. Complex autonomous and self-adaptive computing paradigms (e.g., multi-tenant cloud services, mobile/smart services, services discovery and composition in intelligent environments such as smart cities) have been leveraging DSC to dynamically and adaptively maintain the desired QoS, cost and to stabilize long-lived software systems. While DSC is fundamentally known to be an NP-hard problem, systematic attempts to analyze its scalability have been limited, if not absent, though such analysis is of a paramount importance for their effective, efficient, and stable operations. This article reports on a new application of goal-modeling, providing a systematic technique that can support DSC designers and architects in identifying DSC-relevant characteristics and metrics that can potentially affect the scalability goals of a system. The article then applies the technique to two different approaches for QoS-aware dynamic services composition, where the article describes two detailed exemplars that exemplify its application. The exemplars hope to provide researchers and practitioners with guidance and transferable knowledge in situations where the scalability analysis may not be straightforward. The contributions provide architects and designers for QoS-aware dynamic service composition with the fundamentals for assessing the scalability of their own solutions, along with goal models and a list of application domain characteristics and metrics that might be relevant to other solutions. Our experience has shown that the technique was able to identify in both exemplars application domain characteristics and metrics that had been overlooked in previous scalability analyses of these DSC, some of which indeed limited their scalability. It has also shown that the experiences and knowledge can be transferable: The first exemplar was used as an example to inform and ease the work of applying the technique in the second one, reducing the time to create the model, even for a non-expert. Leticia Duboc, Rami Bahsoon, Faisal Alrebeish, Carlos Joseph Mera-Gómez, Vivek Nallur, Rick Kazman, Philip Bianco, Muhammad Ali Babar 0001, Rajkumar Buyya |
ACM Trans. Auton. Adapt. Syst. | 4 |
| 2017 | A Market-Based Approach for Detecting Malware in the Cloud via Introspection
Nada Alruhaily, Carlos Joseph Mera-Gómez, Tom Chothia, Rami Bahsoon |
ICSOC | 2 |
| 2017 | A Debt-Aware Learning Approach for Resource Adaptations in Cloud Elasticity Management
Carlos Joseph Mera-Gómez, Francisco Ramírez, Rami Bahsoon, Rajkumar Buyya |
ICSOC | 1 |