VLDB 2026 Research / reviewers in the wild / expert
Maria Apostolaki
dblp:180/5502
· DBLP profile ↗
23ranked-venue papers
2as first author
18since 2021 · last 2026
0000-0003-0342-2631ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 14 since 2021Security and privacy · 6 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Confucius: Adapting Home Routers to Congestion Control's Reactions for Consistent Low LatencyabstractEmerging high-quality real-time applications require consistently low latency, which is often disrupted by latency spikes. We identify the reason as the mismatch between the abrupt bandwidth reallocation on routers and gradual sending rate reaction of congestion control. For example, when a burst of new flows arrives, queue schedulers such as fair queueing immediately reallocate the bandwidth for existing and new flows. However, the flow's sending rate, determined by the congestion control algorithm (CCA), needs several RTTs to converge to the new available bandwidth, during which severe stalls occur. This has been increasingly critical with the demand on consistent low latency. In this paper, we present Confucius, a practical queue management scheme that reallocate the bandwidth for flows following CCA's reaction. Confucius slows down bandwidth adjustment to match the reaction of congestion control, so that the end host can reduce the sending rate without overshooting the network. Confucius is designed for offering real-time flows with consistently low latency regardless of uncertain competition. Experiments show that Confucius reduces the stall duration by more than 50% against existing practical schemes, while competing flows also fairly enjoy on-par performance.Available at: https://github.com/hkust-spark/confucius-qdisc Zili Meng, Nirav Atre, Bochun Zhang, Mingwei Xu 0001, Justine Sherry, Maria Apostolaki |
INFOCOM | 6 |
| 2026 | Making Logic a First-Class Citizen in Generative ML for Networking
Hongyu Hè, Minhao Jin, Maria Apostolaki |
NSDI | 3 |
| 2026 | Starfish: A Topology-Routing Co-Design for Small-Scale Data Centers
Anchengcheng Zhou, Vipul Harsh, Sangeetha Abdu Jyothi, Maria Apostolaki |
NSDI | 4 |
| 2026 | Controlling Arbitrary Internet Queues with Titrate
Anchengcheng Zhou, Joshua Lau, Brighten Godfrey, Maria Apostolaki |
NSDI | 4 |
| 2025 | Just-in-Time Logic Enforcement: A new paradigm of combining statistical and symbolic reasoning for network managementabstractWhile ML can greatly aid network management, it often makes glaring mistakes that contradict common sense or domain-specific constraints, undermining its trustworthiness and hindering adoption. To address this mismatch, this paper advocates for enforcing logic during ML inference (or Just-In-Time), rather than during training or post-inference in prior work. We find that this approach offers correctness guarantees without sacrificing statistical fidelity, thereby maximizing the benefits of both ML and formal reasoning. Hongyu Hè, Maria Apostolaki |
HotNets | 2 |
| 2025 | Mitigating Inter-datacenter Incast with a Proxy: The shortest path is not necessarily the fastestabstractMany-to-one communication (i.e., incast) is a long-standing challenge in networking with a wide range of proposed solutions. However, as incast-inducing applications today (e.g., storage, ML training) scale beyond a single datacenter, they introduce new challenges that current solutions do not handle. In particular, inter-datacenter links have orders of magnitude higher latency than intra-datacenter paths, lengthening the feedback loop that senders rely on to adjust their sending rates and drastically increasing incast completion times. Anchengcheng Zhou, Carter Costic, Hongyu Hè, Ahmad Ghalayini, Abdul Kabbani, Maria Apostolaki |
HotNets | 6 |
| 2025 | A Layered Formal Methods Approach to Answering Queue-related Queries
Divya Raghunathan, Maria Apostolaki, Aarti Gupta |
NSDI | 2 |
| 2025 | Global BGP Attacks that Evade Route Monitoring
Henry Birge-Lee, Maria Apostolaki, Jennifer Rexford |
PAM | 2 |
| 2025 | Robustifying ML-powered Network Classifiers with PANTS
Minhao Jin, Maria Apostolaki |
USENIX Security Symposium | 2 |
| 2024 | TrustSketch: Trustworthy Sketch-based Telemetry on Cloud Hosts
Maria Apostolaki, Zaoxing Liu, Vyas Sekar |
NDSS | 2 |
| 2024 | Reverie: Low Pass Filter-Based Switch Buffer Sharing for Datacenters with RDMA and TCP Traffic
Vamsi Addanki, Wei Bai 0001, Stefan Schmid 0001, Maria Apostolaki |
NSDI | 4 |
| 2024 | TANGO: Secure Collaborative Route Control across the Public Internet
Henry Birge-Lee, Sophia Yoo, Benjamin Herber, Jennifer Rexford, Maria Apostolaki |
NSDI | 5 |
| 2024 | Zoom2Net: Constrained Network Telemetry ImputationabstractFine-grained monitoring is crucial for multiple data-driven tasks such as debugging, provisioning, and securing networks. Yet, practical constraints in collecting, extracting, and storing data often force operators to use coarse-grained sampled monitoring, degrading the performance of the various tasks. In this work, we explore the feasibility of leveraging the correlations among coarse-grained time series to impute their fine-grained counterparts in software. We present Zoom2Net, a transformer-based model for network imputation that incorporates domain knowledge through operational and measurement constraints, ensuring that the imputed network telemetry time series are not only realistic but align with existing measurements. This approach enhances the capabilities of current monitoring infrastructures, allowing operators to gain more insights into system behaviors without the need for hardware upgrades. We evaluate Zoom2Net on four diverse datasets (e.g., cloud telemetry and Internet data transfer) and use cases (e.g., bursts analysis and traffic classification). We demonstrate that Zoom2Net consistently achieves high imputation accuracy with a zoom-in factor of up to 100 and performs better on downstream tasks compared to baselines by an average of 38%. Fengchen Gong, Divya Raghunathan, Aarti Gupta, Maria Apostolaki |
SIGCOMM | 4 |
| 2023 | Towards Integrating Formal Methods into ML-Based Systems for NetworkingabstractOwing to its adaptability and scalability, Machine Learning (ML) has gained significant momentum in the networking community. Yet, ML models can still produce outputs that contradict knowledge, i.e., established networking rules and principles. On the other hand, Formal Methods (FM) use rigorous mathematical reasoning based on knowledge, but suffer from the lack of scalability. To capitalize on the complementary strengths of both approaches, we advocate for the integration of knowledge-based FM into ML-based systems for networking problems. Through a case study, we demonstrate the benefits and limitations of using ML models or FM alone. We find that incorporating FM in the training and inference of an ML model yields not only more reliable results but also better performance in various downstream tasks. We hope that our paper inspires a tighter integration of FM-based and ML-based approaches in networking, facilitating the development of more robust and dependable systems. Fengchen Gong, Divya Raghunathan, Aarti Gupta, Maria Apostolaki |
HotNets | 4 |
| 2023 | A First Look at Third-Party Service Dependencies of Web Services in Africa
Aqsa Kashaf, Jiachen Dou, Margarita Belova, Maria Apostolaki, Yuvraj Agarwal, Vyas Sekar |
PAM | 4 |
| 2022 | Lumen: a framework for developing and evaluating ML-based IoT network anomaly detectionabstractThe rise of IoT devices brings a lot of security risks. To mitigate them, researchers have introduced various promising network-based anomaly detection algorithms, which oftentimes leverage machine learning. Unfortunately, though, their deployment and further improvement by network operators and the research community are hampered. We believe this is due to three key reasons. First, known ML-based anomaly detection algorithms are evaluated -in the best case- on a couple of publicly available datasets, making it hard to compare across algorithms. Second, each ML-based IoT anomaly-detection algorithm makes assumptions about attacker practices/classification granularity, which reduce their applicability. Finally, the implementation of those algorithms is often monolithic, prohibiting code reuse. To ease deployment and promote research in this area, we present Lumen. Lumen is a modular framework paired with a benchmarking suite that allows users to efficiently develop, evaluate, and compare IoT ML-based anomaly detection algorithms. We demonstrate the utility of Lumen by implementing state-of-the-art anomaly detection algorithms and faithfully evaluating them on various datasets. Among other interesting insights that could inform real-world deployments and future research, using Lumen, we were able to identify what algorithms are most suitable to detect particular types of attacks. Lumen can also be used to construct new algorithms with better performance by combining the building blocks of competing efforts and improving the training setup. Rahul Anand Sharma, Ishan Sabane, Maria Apostolaki, Anthony Rowe 0001, Vyas Sekar |
CoNEXT | 3 |
| 2022 | It takes two to tango: cooperative edge-to-edge routingabstractIn their unrelenting quest for lower latency, cloud providers are deploying servers closer to their customers and enterprises are adopting paid Network-as-a-Service (NaaS) offerings with performance guarantees. Unfortunately, these trends contribute to greater industry consolidation, benefiting larger companies and well-served regions while leaving little room for smaller cloud providers and enterprises to flourish. Instead, we argue that the public Internet could offer good enough performance, if only edge networks could work together to achieve better visibility and control over wide-area routing. We present Tango, a cooperative architecture where pairs of edge networks (e.g., access, enterprise, and data-center networks) collaborate to expose more wide-area paths, collect more accurate measurements, and split traffic more intelligently over the paths. Tango leverages programmable switches at the borders of the edge networks, coupled with techniques to coax BGP into exposing more paths, without requiring support from end hosts or intermediate ASes. Experiments with our preliminary Tango deployment (using IPv6 addresses and the Vultr cloud provider) show that Tango could offer much greater visibility and control over wide-area routing, allowing the public Internet to meet the needs of many modern networked applications. Henry Birge-Lee, Maria Apostolaki, Jennifer Rexford |
HotNets | 2 |
| 2022 | ABM: active buffer management in datacentersabstractToday's network devices share buffer across queues to avoid drops during transient congestion and absorb bursts. As the buffer-per-bandwidth-unit in datacenter decreases, the need for optimal buffer utilization becomes more pressing. Typical devices use a hierarchical packet admission control scheme: First, a Buffer Management (BM) scheme decides the maximum length per queue at the device level and then an Active Queue Management (AQM) scheme decides which packets will be admitted at the queue level. Unfortunately, the lack of cooperation between the two control schemes leads to (i) harmful interference across queues, due to the lack of isolation; (ii) increased queueing delay, due to the obliviousness to the per-queue drain time; and (iii) thus unpredictable burst tolerance. To overcome these limitations, we propose ABM, Active Buffer Management which incorporates insights from both BM and AQM. Concretely, ABM accounts for both total buffer occupancy (typically used by BM) and queue drain time (typically used by AQM). We analytically prove that ABM provides isolation, bounded buffer drain time and achieves predictable burst tolerance without sacrificing throughput. We empirically find that ABM improves the 99th percentile FCT for short flows by up to 94% compared to the state-of-the-art buffer management. We further show that ABM improves the performance of advanced datacenter transport protocols in terms of FCT by up to 76% compared to DCTCP, TIMELY and PowerTCP under bursty workloads even at moderate load conditions. Vamsi Addanki, Maria Apostolaki, Manya Ghobadi, Stefan Schmid 0001, Laurent Vanbever |
SIGCOMM | 2 |
| 2020 | P2GO: P4 Profile-Guided OptimizationsabstractProgrammable devices allow the operator to specify the data-plane behavior of a network device in a high-level language such as P4. The compiler then maps the P4 program to the hardware after applying a set of optimizations to minimize resource utilization. Yet, the lack of context restricts the compiler to conservatively account for all possible inputs -- including unrealistic or infrequent ones -- leading to sub-optimal use of the resources or even compilation failures. To address this inefficiency, we propose that the compiler leverages insights from actual traffic traces, effectively unlocking a broader spectrum of possible optimizations. We present a system working alongside the compiler that uses traffic-awareness to reduce the allocated resources of a P4 program by: (i) removing dependencies that do not manifest; (ii) adjusting table and register sizes to reduce the pipeline length; and (iii) offloading parts of the program that are rarely used to the controller. Our prototype implementation on the Tofino switch automatically profiles the P4 program, detects opportunities and performs optimizations to improve the pipeline efficiency. Our work showcases the potential benefit of applying profiling techniques used to compile general-purpose languages to compiling P4 programs. Patrick Wintermeyer, Maria Apostolaki, Alexander Dietmüller, Laurent Vanbever |
HotNets | 2 |
| 2019 | SABRE: Protecting Bitcoin against Routing Attacks
Maria Apostolaki, Gian Marti, Laurent Vanbever |
NDSS | 1 |
| 2019 | Blink: Fast Connectivity Recovery Entirely in the Data Plane
Thomas Holterbach, Edgar Costa Molero, Maria Apostolaki, Alberto Dainotti, Stefano Vissicchio, Laurent Vanbever |
NSDI | 3 |
| 2017 | Hijacking Bitcoin: Routing Attacks on CryptocurrenciesabstractAs the most successful cryptocurrency to date, Bitcoin constitutes a target of choice for attackers. While many attack vectors have already been uncovered, one important vector has been left out though: attacking the currency via the Internet routing infrastructure itself. Indeed, by manipulating routing advertisements (BGP hijacks) or by naturally intercepting traffic, Autonomous Systems (ASes) can intercept and manipulate a large fraction of Bitcoin traffic. This paper presents the first taxonomy of routing attacks and their impact on Bitcoin, considering both small-scale attacks, targeting individual nodes, and large-scale attacks, targeting the network as a whole. While challenging, we show that two key properties make routing attacks practical: (i) the efficiency of routing manipulation; and (ii) the significant centralization of Bitcoin in terms of mining and routing. Specifically, we find that any network attacker can hijack few (<;100) BGP prefixes to isolate ~50% of the mining power-even when considering that mining pools are heavily multi-homed. We also show that on-path network attackers can considerably slow down block propagation by interfering with few key Bitcoin messages. We demonstrate the feasibility of each attack against the deployed Bitcoin software. We also quantify their effectiveness on the current Bitcoin topology using data collected from a Bitcoin supernode combined with BGP routing data. The potential damage to Bitcoin is worrying. By isolating parts of the network or delaying block propagation, attackers can cause a significant amount of mining power to be wasted, leading to revenue losses and enabling a wide range of exploits such as double spending. To prevent such effects in practice, we provide both short and long-term countermeasures, some of which can be deployed immediately. Maria Apostolaki, Aviv Zohar, Laurent Vanbever |
IEEE Symposium on Security and Privacy | 1 |
| 2016 | A reputation-based collaborative schema for the mitigation of distributed attacks in SDN domainsabstractIn this paper, we investigate collaborative schemes to mitigate Distributed Denial of Service attacks in multi-domain Software Defined Networks (SDNs). The mitigation process itself is distributed, initiated by the domain of the victim, and involving all domains in the path of an attack (transit domains). We emphasize on filtering malicious flows as close to the attack sources as possible. We propose a modular and scalable approach that leverages on the SDNi (SDN interface) protocol, as the enabler for information exchange between adjacent SDN domains. We extend this protocol by publishing and exchanging pointers to incident reports, formatted according to the IETF IODEF standards and exposed through domain SDN Controllers. Thus, an SDN domain hosting the victim of the attack is able to notify the recipients about the malicious flows that they forward, requesting their filtering until the attack ceases. In order to motivate close cooperation of SDN domains governed by diverse authorities, we implemented and evaluated a reputation mechanism, whereby domains historically assess the behavior of their neighbors, discouraging assistance in case the domain of the victim has a poor cooperation track record. Kostas Giotis, Maria Apostolaki, Vasilis S. Maglaris |
NOMS | 2 |