VLDB 2026 Research / reviewers in the wild / expert
Sebastian Gallenmüller
dblp:162/5308
· DBLP profile ↗
25ranked-venue papers
5as first author
15since 2021 · last 2025
0000-0002-7173-3573ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SLICES-RI Pre-Operation Methodology and ServicesabstractSLICES-RI is being developed as a scientific instrument, following established methodologies and best practices from the scientific community. This approach is increasingly essential to address the accelerating pace of data-driven research, which continuously generates a deluge of publications. The core mission of a scientific instrument is to provide a standardized and trusted reference, enabling direct performance comparisons of algorithms and ensuring reproducibility — thereby simplifying and strengthening the peer review process. To meet these goals, SLICES-RI adopts an intent-based design and generates tailored Blueprints for specific scientific questions. While it does not aim to be exhaustive, this approach significantly reduces the complexity involved in designing and executing experiments. In this presentation, we share the current deployment status of SLICES-RI as it entered its pre-operational phase. We illustrate its capabilities through the Post-5G and Federated Learning Blueprints. Additionally, we highlight MRS/DMI, a key feature of SLICES-RI, which offers an advanced data management framework aligned with the FAIR principles and fully integrated into the experimental workflow. Serge Fdida, Panayiotis Andreou, Nikos Makris, Damien Saucez, Sebastian Gallenmüller, Brecht Vermeulen |
ICCCN | 5 |
| 2025 | TEE Time at P4-Performance Analysis of Trusted Execution Environments for Packet ProcessingabstractModern computer networks, such as 5G/6G networks, require high-performance, low-latency, and secure packet processing while ensuring data confidentiality in cloud environments. Trusted Execution Environments (TEEs) address these security requirements and provide encrypted memory areas that protect sensitive data from untrusted cloud providers. This paper presents a performance analysis of TEE technologies, specifically Intel SGX and AMD SEV-SNP, in the context of software-based user-space packet processing with DPDK and the P4 language. We evaluate two architectural approaches: (1) integrating TEEs as external processing modules implemented with SGX and (2) executing the entire P4 pipeline inside a TEE using AMDSEV. Our analysis examines computational and I/O overhead across different CPU architectures. The results show the tradeoffs between TEE designs, implementations, and performance, demonstrating that AMD SEV-SNP offers better scalability with lower performance penalties compared to Intel SGX. Manuel Simon, Sebastian Warter, Sebastian Gallenmüller, Georg Carle |
NetSoft | 3 |
| 2025 | Forward Error Correction and Weighted Hierarchical Fair Multiplexing for HTTP/3 over QUIC
Kilian Holzinger, Daniel Petri, Stefan Lachnit, Marcel Kempf, Henning Stubbe, Sebastian Gallenmüller, Stephan M. Günther, Georg Carle |
Networking | 6 |
| 2025 | Reproducible Experimentation with Beyond-5G Blueprints in SLICES-RIabstractExperimental research in Post-5G involves complex interactions between software, hardware, and protocols. Therefore, it is crucial to develop solutions that allow researchers to conduct their experiments in a reproducible manner. To support this need, the EU SLICES Research Infrastructure (RI) provides a scientific instrument that encompasses all the needs for Post-5G experimental research. The facility is currently being built to enable experimentation with state-of-the-art resources in various fields. SLICES-RI is intent-driven and facilitates the entire lifecycle of thought experiments. This is achieved by enabling reproducible deployment of experiments over the infrastructure using blueprints and by systematically collecting and archiving all outputs through a clear and structured methodology for experimentation. For this demonstration, we focus on the Post-5G part of the facility and will showcase how the entire lifecycle of such an experiment is orchestrated using the tools and functionalities developed. We will showcase blueprints for deploying a cloud-native 5G core and a split 7.2 radio network using open-source software in a fully reproducible manner, with the results being automatically archived and published using the SLICES metadata model. The reproducibility, deployment options, experimenter control capabilities, and access to the collected results will be highlighted. Damien Saucez, Sebastian Gallenmüller, Nikos Makris, Raymond Knopp, Serge Fdida |
WCNC | 2 |
| 2025 | A methodology for reproducible and portable experiment workflows
Henning Stubbe, Sebastian Gallenmüller, Georg Carle |
Comput. Commun. | 2 |
| 2024 | On-the-fly Table Insertions on Programmable Software Data PlanesabstractNovel applications require a robust and reliable connection to provide the services for next-generation networks. The complex nature of these algorithms needs fast and efficient stateful processing. Using Software-defined Networking (SDN), new algorithms can be implemented into the network in a platform-independent way. The upcoming Portable NIC Architecture (PNA) for P4, a language to program data planes in SDN, allows inserting new table entries without controller interaction. Thus, it unleashes more performant and stateful applications without the overhead of the controller. We implement and evaluate these so-called ‘add-on-miss’ insertions introduced by the PNA for a P4 software target. In addition, we discuss the influence of latency and throughput optimizations on software packet processing systems. We determine the impact of these optimization strategies and which performance properties and costs can be measured with each. In our analysis, we model the costs of insertions based on an extensive baseline and compare them to table entry lookups and updates. We analyze the influence of the frequency of insertions and multi-core scenarios. Finally, we demonstrate that the approach scales for realistic scenarios. Manuel Simon, Sebastian Gallenmüller, Georg Carle |
CNSM | 2 |
| 2024 | Shells Bells: Cyber-Physical Anomaly Detection in Data CentersabstractMonitoring the side-channel sound can improve anomaly detection (AD) in data centers (DCs). However, a DC’s dense setup results in a composite soundscape which makes it difficult to attribute sounds to individual devices.We propose a novel cyber-physical AD approach that validates device activity in realistic composite audio signals. By leveraging information from management network traffic, we predict changes in the DC soundscape. We use a convolutional neural network to compare our predictions with real observations to validate correct device activity and identify anomalies. Our evaluation using data from a real DC environment identifies spoofed and masqueraded activity with an accuracy of 98.62 %. Lars Wüstrich, Sebastian Gallenmüller, Stephan M. Günther, Georg Carle, Marc-Oliver Pahl |
NOMS | 2 |
| 2024 | Exploring Data Plane Updates on P4 Switches with P4RuntimeabstractThe development and roll-out of new Ethernet standards increase the available bandwidths in computer networks. This growth presents significant advantages, enabling novel applications. At the same time, the increase introduces new challenges; higher data rates reduce the available time budget to process each packet. This development also impacts software-defined networks. Their data planes need to keep up with the increased traffic rates. Nevertheless, the control plane must not be ignored; fast reaction times are necessary to handle the increased rates handled by data planes efficiently. In our work, we analyze the interaction of a high-performance data plane and different implementations for the control plane. We selected a P4 switching ASIC as our data plane. For the control plane, we investigate vendor-specific implementations and a standardized implementation called P4Runtime. To determine the performance of the control plane, we introduce a novel measurement methodology. This methodology allows measuring the delay between the initiation of rule updates on the control plane and their application on the data plane. We investigate the behavior of the data plane, its performance and non-atomicity of updates. Based on our findings, we apply different optimization strategies to improve control plane performance. Our measurements show that neglecting the control plane performance may impact network behavior due to delayed updates, but we also show how to minimize this delay and, thereby, its impact. We have released the experiment artifacts of our study including experiment scripts and measurement data. Henning Stubbe, Sebastian Gallenmüller, Manuel Simon, Eric Hauser, Dominik Scholz, Georg Carle |
Comput. Commun. | 2 |
| 2022 | BFT-Blocks: The Case for Analyzing Networking in Byzantine Fault Tolerant ConsensusabstractByzantine fault tolerant (BFT) consensus allows the construction of robust, distributed systems via the state-machine replication (SMR) approach. Still, after more than 40 years of research, limitations on performance and scalability for practical systems remain. A large corpus of existing work improves on consensus complexity, performance and introduces a multitude of optimization techniques. The state-of-the-art is complex. On the other hand, many protocols designed for practical deployments are built on strong, common assumptions about underlying communication and authentication primitives. To fulfill these assumptions, often, commodity tools and libraries are employed without further analysis and caution for negative interplay.Instead of contributing to the existing complexity, we choose a different approach. In this paper, we outline the feasibility and potential impact of the optimization of common building blocks of BFT-SMR systems. We systemize existing work in terms of common model assumptions and identify optimization potential. Finally, we choose the building block of networking transport as a representative example and analyze its optimization space, both in context of general BFT-SMR systems and a case study of the HotStuff protocol. We describe behavior, challenges, and desired configuration of network transports for use in byzantine agreement, and identify lossy links as the main catalyst for significant performance differences between protocols and configurations. Richard von Seck, Filip Rezabek, Benedikt Jaeger, Sebastian Gallenmüller, Georg Carle |
NCA | 4 |
| 2022 | AC/DCIM: Acoustic Channels for Data Center Infrastructure MonitoringabstractData center infrastructure monitoring (DCIM) uses various features to track a data center’s state. In addition to collecting device-level information, the monitoring also includes physical features such as temperature or power intake to detect equipment failures and anomalies. Measuring physical features requires dedicated sensors at specific vantage points for efficient and reliable data collection. We propose a novel approach for DCIM using acoustic channels. Audio-based DCIM offers substantial benefits: sensors are affordable, data collection is non-intrusive, and audio processing is well-understood. Information extraction from acoustic channels can be challenging due to audio consisting of multiple devices’ mixed and often noisy signals. Our paper demonstrates the feasibility of single-node state detection over audio side-channels. Experiments in a real data center show that our sound-based approach can successfully detect errors. Lars Wüstrich, Sebastian Gallenmüller, Marc-Oliver Pahl, Georg Carle |
NOMS | 2 |
| 2021 | A Framework for Reproducible Data Plane Performance ModelingabstractLanguages for programming data planes like P4 sparked a plethora of new applications in the data plane. The dynamic, evolving environment makes it challenging to understand what performance can be expected when running a program in a specific data plane target. However, knowing this is crucial for network operators when upgrading their networks. Dominik Scholz, Hasanin Harkous, Sebastian Gallenmüller, Henning Stubbe, Max Helm, Benedikt Jaeger, Nemanja Deric, Endri Goshi, Zikai Zhou, Wolfgang Kellerer, Georg Carle |
ANCS | 3 |
| 2021 | High-Performance Match-Action Table Updates from within Programmable Software Data PlanesabstractFor long, P4's mantra was that table entries could only be updated by the control plane. With the ongoing Portable NIC Architecture (PNA) standardization efforts, this is changing. In fact, PNA presumably includes explicit methods for table updates from within the data planes. Now, it is onto manufacturers and developers to integrate and use this mechanism in future P4 data planes. This would enable novel and improved applications, e.g., requiring means for maintaining state. Manuel Simon, Henning Stubbe, Dominik Scholz, Sebastian Gallenmüller, Georg Carle |
ANCS | 4 |
| 2021 | Ducked Tails: Trimming the Tail Latency of(f) Packet Processing SystemsabstractLatency can be caused by delayed processing of packets on the nodes of a computer network. Latency figures tend to fluctuate, eventually creating substantial spikes leading to a long-tailed latency distribution. The absolute latency value and its distribution over time impact the service quality of computer networks-an essential requirement for novel services such as networked industrial control systems or remote medical procedures. In this work, we present our measurement methodology for packet processing systems to determine the latency reliably, and more importantly, its distribution, using highly accurate and precise hardware timestamping on off-the-shelf network interface cards (NICs). Further, we introduce an optimized software stack to run low-latency applications on regular Linux servers. Our investigation focuses on realtime features of the Linux kernel. The performance of our optimized software stack is demonstrated using a real-world application, the Snort intrusion prevention system (IPS). Across various scenarios, we achieve a maximum worst-case latency as low as 25 µs. This result is an almost 5-fold reduction of the measured tail latencies compared to a previous study. Sebastian Gallenmüller, Florian Wiedner, Johannes Naab, Georg Carle |
CNSM | 1 |
| 2021 | EnGINE: Developing a Flexible Research Infrastructure for Reliable and Scalable Intra-Vehicular TSN NetworksabstractDriver assistance, self-driving, and multimedia systems have two common implications: increasing demand on network bandwidth and the need for more powerful computation nodes. As a result, intra-vehicular networks (IVNs) change their layout. They are built around central nodes connected to the rest of the vehicle via Ethernet. The usage of Ethernet presents a challenge, as it lacks support for deterministic behavior by design. The solution is found within the IEEE Time-Sensitive Networking (TSN) standards, introducing real-time, low-latency, and deterministic communication into the Ethernet ecosystem. These new networked systems need to be thoroughly evaluated with IVN requirements in mind. To assess numerous configurations of IVN setups, in this work, we introduce a novel Environment for Generic In-vehicular Networking Experiments — EnGINE. It allows, among many others, repeatable, reproducible, and replicable TSN experiments with high precision and flexibility, which is not possible to run using proprietary solutions. EnGINE is based exclusively on commercial off-the-shelf components and is orchestrated by a flexible Ansible framework. This approach allows us to configure various topologies emulating realistic IVNs behavior, which is challenging using simulations. Based on available related work, we further address the challenges found in the IVNs. We derive additional requirements for experiments in the TSN domain and present our approach to fulfill them in an experimental setting. We believe that EnGINE provides the ideal environment for TSN network experiments. Filip Rezabek, Marcin Bosk, Thomas Paul, Kilian Holzinger, Sebastian Gallenmüller, Angela Gonzalez Mariño, Abdoul Kane, Francesc Fons, Haigang Zhang, Georg Carle, Jörg Ott |
CNSM | 5 |
| 2021 | The pos framework: a methodology and toolchain for reproducible network experimentsabstractIn scientific research, the independent reproduction of experimental results is the source of trust. The release of experimental artifacts enables the reproduction of results; however, additional efforts of researchers are required to prepare and document their experiments accordingly. To honor this increased effort, multiple initiatives were implemented to incentivize the creation and release of experimental artifacts, e.g., awards for papers that provide experimental artifacts. Sebastian Gallenmüller, Dominik Scholz, Henning Stubbe, Georg Carle |
CoNEXT | 1 |
| 2020 | NCSbench: Reproducible Benchmarking Platform for Networked Control SystemsabstractThe evolution of the Internet of Things accelerated the development of Cyber-Physical Systems. Among them, Networked Control Systems (NCS) gained notable attention thanks to their application to industrial operations. Experimental NCS require expertise from control, computation, and communication disciplines. This requirement, together with the fragmentation of implementation platforms and experimental investigations, represents a challenge for the reproducibility and comparison of research results. In this paper, we tackle this problem by proposing a novel NCS benchmarking methodology that aids the reproducibility of NCS experiments. Relying on a novel approach to model the architectural elements and the delays of NCS, the methodology defines the experiment parameters and the relevant Key Performance Indicators (KPIs) that need to be observed during its execution. Furthermore, we detail the implementation of the first reproducible benchmarking platform for NCS. The proposed platform is open-source and designed to be easily reproducible and extensible by anyone. Finally, we replicate and evaluate the platform following the proposed NCS benchmarking methodology. The experimental results evaluate and compare the KPIs during the execution of the platform in different benchmarking scenarios, proving the validity of the proposed benchmarking methodology. Samuele Zoppi, Onur Ayan, Fabio Molinari, Zenit Music, Sebastian Gallenmüller, Georg Carle, Wolfgang Kellerer |
CCNC | 5 |
| 2020 | NCSbench Demo: Reproducible Benchmarking Platform for Networked Control SystemsabstractCyber-Physical Systems (CPS) are widely spreading thanks to fast-paced technological breakthroughs of microcontrollers and communication networks. Among them, Networked Control Systems (NCS) gained notable attention thanks to their application in industrial operations. In NCS, the interconnection of a control logic with sensors and actuators used to steer a physical system occurs over a communication network. Despite large research interest on NCS, the reproducibility and comparison of experimental results are difficult to achieve. This is caused by the lack of well-established models and methodologies that combine the theoretical and practical aspects of NCS. We tackle this problem by proposing and demonstrating NCSbench: the first open-source reproducible benchmarking platform for NCS. NCSbench enables the benchmarking of research experiments using a networked two-wheeled inverted pendulum robot. For each benchmarking experiment, a set of values is measured and used to quantify the key performance indicators (KPIs) of the NCS. In our demonstration, we visualize in real-time the evolution of the benchmarking KPIs on a web-based Graphical User Interface. Samuele Zoppi, Onur Ayan, Fabio Molinari, Zenit Music, Sebastian Gallenmüller, Georg Carle, Wolfgang Kellerer |
CCNC | 5 |
| 2020 | Performance Analysis of VPN Gateways
Maximilian Pudelko, Paul Emmerich, Sebastian Gallenmüller, Georg Carle |
Networking | 3 |
| 2020 | 5G QoS: Impact of Security Functions on LatencyabstractNetwork slicing is considered a key enabler to 5th Generation (5G) communication networks. Mobile network operators may deploy network slices-complete logical networks customized for specific services expecting a certain Quality of Service (QoS). New business models like Network Slice-as-a-Service offerings to customers from vertical industries require negotiated Service Level Agreements (SLA), and network providers need automated enforcement mechanisms to assure QoS during instantiation and operation of slices. In this paper, we focus on ultra-reliable low-latency communication (URLLC). We propose a software architecture for security functions based on off-the-shelf hardware and open-source software and demonstrate, through a series of measurements, that the strict requirements of URLLC services can be achieved. As a real-world example, we perform our experiments using the intrusion prevention system (IPS) Snort to demonstrate the impact of security functions on latency. Our findings lead to the creation of a model predicting the system load that still meets the URLLC latency requirement. We fully disclose the artifacts presented in this paper including pcap traces, measurement tools, and plotting scripts at https://gallenmu.github.io/low-latency. Sebastian Gallenmüller, Johannes Naab, Iris Adam, Georg Carle |
NOMS | 1 |
| 2019 | Cryptographic Hashing in P4 Data PlanesabstractP4 introduces a standardized, universal way for data plane programming. Secure and resilient communication typically involves the processing of payload data and specialized cryptographic hash functions. We observe that current P4 targets lack the support for both. Therefore, applications and protocols, which require message authentication codes or hashing structures that are resilient against attacks such as denial-of-service, cannot be implemented. To enable authentication and resilience, we make the case for extending P4 targets with cryptographic hash functions. We propose an extension of the P4 Portable Switch Architecture for cryptographic hashes and discuss our prototype implementations for three different P4 target platforms: CPU, NPU, and FPGA. To assess the practical applicability, we conduct a performance evaluation and analyze the resource consumption. Our prototype implementations show that cryptographic hashing can be integrated efficiently. We cannot identify a single hash function delivering satisfying performance on all investigated platforms. Therefore, we recommend a set of hash functions to optimize target-specific performance. Dominik Scholz, Andreas Oeldemann, Fabien Geyer, Sebastian Gallenmüller, Henning Stubbe, Thomas Wild, Andreas Herkersdorf, Georg Carle |
ANCS | 4 |
| 2017 | Mind the Gap - A Comparison of Software Packet GeneratorsabstractNetwork research relies on packet generators to assess performance and correctness of new ideas. Software-based generators in particular are widely used by academic researchers because of their flexibility, affordability, and open-source nature. The rise of new frameworks for fast IO on commodity hardware is making them even more attractive. Longstanding performance differences of software generation versus hardware in terms of throughput are no longer as big of a concern as they used to be few years ago. This paper investigates the properties of several high-per-formance software packet generators and the implications on their precision when a given traffic pattern needs to be generated. We believe that the evaluation strategy presented in this paper helps understanding the actual limitations in high-performance software packet generation, thus helping the research community to build better tools. Paul Emmerich, Sebastian Gallenmüller, Gianni Antichi, Andrew W. Moore 0002, Georg Carle |
ANCS | 2 |
| 2017 | Building Fast but Flexible Software RoutersabstractCreating quick and dirty prototypes is a simple and effective way to demonstrate the feasibility of new ideas in network research. Though, small scale proof-of-concepts may lack the performance needed to apply them to real world test cases. Thanks to powerful packet processing frameworks such as netmap and DPDK, high-performance packet forwarding systems can be implemented in software today. We present MoonRoute, a framework dedicated to developing powerful software routers. It is built on top of DPDK and utilizes a highly parallelized architecture to achieve high performance (see Section 2).MoonRoute offers methods to reuse existing libraries and a scripting interface for easy extensibility (see Section 3). An example implementation based on the MoonRoute framework is carefully evaluated to demonstrate the performance and compare it to other relevant software routers (see Section 4). The entire MoonRoute framework including a reference implementation of a software router is available as free software under MIT license [2]. A technical report featuring details about our architecture and more profiling results is available [1]. Sebastian Gallenmüller, Paul Emmerich, Rainer Schonberger, Daniel Raumer, Georg Carle |
ANCS | 1 |
| 2015 | Comparison of Frameworks for High-Performance Packet IOabstractNetwork stacks currently implemented in operating systems can no longer cope with the packet rates offered by 10 Gbit Ethernet. Thus, frameworks were developed claiming to offer a faster alternative for this demand. These frameworks enable arbitrary packet processing systems to be built from commodity hardware handling a traffic rate of several 10 Gbit interfaces, entering a domain previously only available to custom-built hardware. In this paper, we survey various frameworks for high-performance packet IO. We analyze the performance of the most prominent frameworks based on representative measurements in packet forwarding scenarios. Therefore, we quantify the effects of caching and look at the tradeoff between throughput and latency. Moreover, we introduce a model to estimate and assess the performance of these packet processing frameworks. Sebastian Gallenmüller, Paul Emmerich, Florian Wohlfart, Daniel Raumer, Georg Carle |
ANCS | 1 |
| 2015 | Performance benchmarking of a software-based LTE SGWabstractNetwork Functions Virtualization (NFV) is a concept that aims at providing network operators with benefits in terms of cost, flexibility, and vendor independence by utilizing virtualization techniques to run network functions as software on commercial off-the-shelf (COTS) hardware. In contrast, prior solutions rely on specialized hardware for each function. Performance evaluation of such systems usually requires a dedicated testbed for each individual component. Rather than analyzing these proprietary black-box components, Virtualized Network Functions (VNFs) are pieces of software that run on COTS hardware and whose properties can be investigated in a generic testbed. However, depending on the underlying hardware, operating system, and implementation, VNFs might behave differently. Therefore, mechanisms for the performance evaluation of VNFs should be similar to benchmarking of software, where different implementations are compared by applying them to predefined test cases and scenarios. This work presents a first step towards a benchmarking framework for VNFs. Given two different implementations of a VNF that acts as LTE Serving Gateway (SGW), influence factors and key performance indicators are identified and a comparison between the two mechanisms is drawn. Stanislav Lange, Anh Nguyen-Ngoc, Steffen Gebert, Thomas Zinner, Michael Jarschel, Andreas Köpsel, Marc Suñé, Daniel Raumer, Sebastian Gallenmüller, Georg Carle, Phuoc Tran-Gia |
CNSM | 9 |
| 2015 | MoonGen: A Scriptable High-Speed Packet GeneratorabstractWe present MoonGen, a flexible high-speed packet generator. It can saturate 10 GbE links with minimum-sized packets while using only a single CPU core by running on top of the packet processing framework DPDK. Linear multi-core scaling allows for even higher rates: We have tested MoonGen with up to 178.5 Mpps at 120 Gbit/s. Moving the whole packet generation logic into user-controlled Lua scripts allows us to achieve the highest possible flexibility. In addition, we utilize hardware features of commodity NICs that have not been used for packet generators previously. A key feature is the measurement of latency with sub-microsecond precision and accuracy by using hardware timestamping capabilities of modern commodity NICs. We address timing issues with software-based packet generators and apply methods to mitigate them with both hardware support and with a novel method to control the inter-packet gap in software. Features that were previously only possible with hardware-based solutions are now provided by MoonGen on commodity hardware. MoonGen is available as free software under the MIT license in our git repository at https://github.com/emmericp/MoonGen Paul Emmerich, Sebastian Gallenmüller, Daniel Raumer, Florian Wohlfart, Georg Carle |
Internet Measurement Conference | 2 |