K. R. Jayaram

dblp:21/2983 · DBLP profile ↗
← Back
28ranked-venue papers
15as first author
6since 2021 · last 2025
0000-0001-5382-276XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 15 · 7 first-author · 3 since 2021Systems, architecture and hardware · 7 · 5 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 On Automating Security Policies with Contemporary LLMs (Short Paper)
abstract
The complexity of modern computing environments and the growing sophistication of cyber threats necessitate a more robust, adaptive, and automated approach to security enforcement. In this paper, we present a framework leveraging large language models (LLMs) for automating attack mitigation policy compliance through an innovative combination of in-context learning and retrieval-augmented generation (RAG). We begin by describing how our system collects and manages both tool and API specifications, storing them in a vector database to enable efficient retrieval of relevant information. We then detail the architectural pipeline that first decomposes high-level mitigation policies into discrete tasks and subsequently translates each task into a set of actionable API calls. Our empirical evaluation, conducted using publicly available CTI policies in STIXv2 format and Windows API documen-tation, demonstrates significant improvements in precision, recall, and Fl-score when employing RAG compared to a non-RAG baseline.
Pablo Fernández Saura, K. R. Jayaram, Vatche Isahagian, Jorge Bernal Bernabé, Antonio F. Skarmeta
SSE2
2025 Shift Happens: Mixture of Experts based Continual Adaptation in Federated Learning
abstract
Federated Learning (FL) enables collaborative model training across decentralized clients without sharing raw data, yet faces significant challenges in real-world settings where client data distributions evolve dynamically over time. This paper tackles the critical problem of covariate and label shifts in streaming FL environments, where non-stationary data distributions degrade model performance and necessitate a middleware layer that adapts FL to distributional shifts. We introduce ShiftEx a shift-aware mixture of experts framework that dynamically creates and trains specialized global models in response to detected distribution shifts using Maximum Mean Discrepancy for covariate shifts. The framework employs a latent memory mechanism for expert reuse and implements facility location-based optimization to jointly minimize covariate mismatch, expert creation costs, and label imbalance. Through theoretical analysis and comprehensive experiments on five datasets, we demonstrate 5.5–12.9 percentage point accuracy improvements and 22–95% faster adaptation compared to state-of-the-art FL baselines across diverse shift scenarios. The proposed approach offers a scalable, privacy-preserving middleware solution for FL systems operating in non-stationary, real-world conditions while minimizing communication and computational overhead.
Rahul Atul Bhope, K. R. Jayaram, Praveen Venkateswaran, Nalini Venkatasubramanian
Middleware2
2024 DeTA: Minimizing Data Leaks in Federated Learning via Decentralized and Trustworthy Aggregation
abstract
Federated learning (FL) relies on a central authority to oversee and aggregate model updates contributed by multiple participating parties in the training process. This centralization of sensitive model updates naturally raises concerns about the trustworthiness of the central aggregation server, as well as the potential risks associated with server failures or breaches, which could result in loss and leaks of model updates. Moreover, recent attacks have demonstrated that, by obtaining the leaked model updates, malicious actors can even reconstruct substantial amounts of private data belonging to training participants. This underscores the critical necessity to rethink the existing FL system architecture to mitigate emerging attacks in the evolving threat landscape. One straightforward approach is to fortify the central aggregator with confidential computing (CC), which offers hardware-assisted protection for runtime computation and can be remotely verified for execution integrity. However, a growing number of security vulnerabilities have surfaced in tandem with the adoption of CC, indicating that depending solely on this singular defense may not provide the requisite resilience to thwart data leaks.
Pau-Chen Cheng, Kevin Eykholt, Zhongshu Gu, Hani Jamjoom, K. R. Jayaram, Enriquillo Valdez, Ashish Verma 0001
EuroSys5
2023 FLIPS: Federated Learning using Intelligent Participant Selection
abstract
This paper presents the design and implementation of FLIPS, a middleware system to manage data and participant heterogeneity in federated learning (FL) training workloads. In particular, we examine the benefits of label distribution clustering on participant selection in federated learning. FLIPS clusters parties involved in an FL training job based on the label distribution of their data apriori, and during FL training, ensures that each cluster is equitably represented in the participants selected. FLIPS can support the most common FL algorithms, including FedAvg, FedProx, FedDyn, FedOpt and FedYogi. To manage platform heterogeneity and dynamic resource availability, FLIPS incorporates a straggler management mechanism to handle changing capacities in distributed, smart community applications. Privacy of label distributions, clustering and participant selection is ensured through a trusted execution environment (TEE). Our comprehensive empirical evaluation compares FLIPS with random participant selection, as well as three other "smart" selection mechanisms -- Oort [51], TiFL [15] and gradient clustering [27] using four real-world datasets, two different non-IID distributions and three common FL algorithms (FedYogi, FedProx and FedAvg). We demonstrate that FLIPS significantly improves convergence, achieving higher accuracy by 17-20 percentage points with 20-60% lower communication costs, and these benefits endure in the presence of straggler participants.
Rahul Atul Bhope, K. R. Jayaram, Nalini Venkatasubramanian, Ashish Verma 0001, Gegi Thomas
Middleware2
2022 Adaptive Aggregation For Federated Learning
abstract
In this paper, we present a new scalable and adaptive architecture for FL aggregation. First, we demonstrate how traditional tree overlay based aggregation techniques (from P2P, publish-subscribe and stream processing research) can help FL aggregation scale, but are ineffective from a resource utilization and cost standpoint. Next, we present the design and implementation of AdaFed, which uses serverless/cloud functions to adaptively scale aggregation in a resource efficient and fault tolerant manner. We describe how AdaFed enables FL aggregation to be dynamically deployed only when necessary, elastically scaled to handle participant joins/leaves and is fault tolerant with minimal effort required on the (aggregation) programmer side. We also demonstrate that our prototype based on Ray [1] scales to thousands of participants, and is able to achieve a > 90% reduction in resource requirements and cost, with minimal impact on aggregation latency.
K. R. Jayaram, Vinod Muthusamy, Gegi Thomas, Ashish Verma 0001, Mark Purcell
IEEE Big Data1
2022 Just-in-Time Aggregation for Federated Learning
abstract
The increasing number and scale of federated learning (FL) jobs necessitates resource efficient scheduling and management of aggregation to make the economics of cloud-hosted aggregation work. Existing FL research has focused on the design of FL algorithms and optimization, and less on aggregation efficacy. In this paper, we propose a new FL aggregation paradigm - “just-in-time” (JIT) aggregation that leverages unique properties of FL jobs, especially the periodicity of model updates, to defer aggregation as much as possible and free compute resources for other FL jobs or other datacenter workloads. We describe a novel way to prioritize FL jobs for aggregation, and demonstrate using multiple datasets, models and FL aggregation algorithms that our techniques can reduce resource usage by 60+% when compared to eager aggregation used in existing FL platforms. We demonstrate that using JIT aggregation has negligible overhead and impact on the latency of the FL job.
K. R. Jayaram, Ashish Verma 0001, Gegi Thomas, Vinod Muthusamy
MASCOTS1
2020 MYSTIKO: Cloud-Mediated, Private, Federated Gradient Descent
abstract
Federated learning enables multiple, distributed participants (potentially on different clouds) to collaborate and train machine/deep learning models by sharing parameters/gradients. However, sharing gradients, instead of centralizing data, may not be as private as one would expect. Reverse engineering attacks [1], [2] on plaintext gradients have been demonstrated to be practically feasible. Existing solutions for differentially private federated learning, while promising, lead to less accurate models and require nontrivial hyperparameter tuning. In this paper, we examine the use of additive homomorphic encryption (specifically the Paillier cipher) to design secure federated gradient descent techniques that (i) do not require addition of statistical noise or hyperparameter tuning, (ii) does not alter the accuracy or utility of the final model, (iii) ensure that the plaintext model parameters/gradients of a participant are never revealed to any other participant or third party coordinator involved in the federated learning job, (iv) minimize the trust placed in any third party coordinator and (v) are efficient, with minimal overhead, and cost effective.
K. R. Jayaram, Archit Verma, Ashish Verma 0001, Gegi Thomas, Colin Sutcher-Shepard
CLOUD1
2020 Effective Elastic Scaling of Deep Learning Workloads
abstract
We examine the elastic scaling of Deep Learning (DL) jobs and propose a novel resource allocation strategy for DL training jobs, resulting in improved job run time performance as well as increased cluster utilization. We begin by analyzing DL workloads and exploit the fact that DL jobs can be run with a range of batch sizes without affecting their final accuracy. We formulate an optimization problem that explores a dynamic batch size allocation to individual DL jobs based on their scaling efficiency, when running on multiple nodes. We design a fast dynamic programming based optimizer to solve this problem in real-time to determine jobs that can be scaled up/down, and use this optimizer in an autoscaler to dynamically change the allocated resources and batch sizes of individual DL jobs. We demonstrate empirically that our elastic scaling algorithm can complete up to as many jobs as compared to a strong baseline algorithm that also scales the number of GPUs but does not change the batch size, with average completion times up to faster.
Vaibhav Saxena, K. R. Jayaram, Saurav Basu, Yogish Sabharwal, Ashish Verma 0001
MASCOTS2
2019 FfDL: A Flexible Multi-tenant Deep Learning Platform
abstract
Deep learning (DL) is becoming increasingly popular in several application domains and has made several new application features involving computer vision, speech recognition and synthesis, self-driving automobiles, drug design, etc. feasible and accurate. As a result, large scale "on-premise" and "cloud-hosted" deep learning platforms have become essential infrastructure in many organizations. These systems accept, schedule, manage and execute DL training jobs at scale.
K. R. Jayaram, Vinod Muthusamy, Parijat Dube, Vatche Isahagian, Chen Wang 0039, Benjamin Herta, Scott Boag, Diana Arroyo, Asser N. Tantawi, Archit Verma, Falk Pollok, Rania Khalaf
Middleware1
2017 Agile Composition of Compliant Data Analytics Platforms
abstract
Sensitive data such as health records and financial transactions are increasingly being stored and processed in the cloud. Correspondingly, laws and regulations have been established to protect such data. For a cloud-based analytics service provider, it is of paramount importance to protect the sensitive information contained in customer data, while running analytics on it. While there exist a plethora of technologies to safeguard data, regulatory rules are not always defined in clear technical terms, and different regulations may impose different (or sometimes conflicting) rules on the analytics platform. Therefore, it remains a challenge in developing a platform that can support various security and compliance-enabling mechanisms, in a agile fashion, to reduce maintenance effort as well as improving scalability and performance. To address this challenge, we introduce the design and implementation of a cloud-based middleware platform that supports on-demand composition and configuration of security mechanisms to ease regulatory compliance enablement. We discuss at length our experiences and lessons learned from using our platform to deploy secure analytics systems at IBM and highlight the benefits of our approach by discussing the performance impact and trade-offs of different security mechanisms with respect to regulatory compliance.
Michael Le, K. R. Jayaram, Yaron Weinsberg, Daniel J. Dean, Shu Tao
IC2E2
2016 Exploiting Causality to Engineer Elastic Distributed Software
abstract
This goal of this paper is to anchor elasticity in terms of causality in distributed applications. Assuming a large-scale distributed application architected as a set of interacting components, we motivate the need for (1) analyzing causality between interactions, and (2) estimating casual probability that an increase in the frequency of interaction i1can increase the frequency of interaction i2caused by i1. We present algorithms to estimate causality and causal probability by combining well known sampling, program analysis, path profiling and dynamic slicing algorithms. We apply our algorithms for causal probability to three large-scale distributed applications, to evaluate (a) their effectiveness in the timely provisioning and de-provisioning of compute resources and (b) whether causality and causal probability present a fundamental and widely-applicable way of engineering auto-elasticity.
K. R. Jayaram
ICDCS1
2016 Quantifying the Attack Detection Accuracy of Intrusion Detection Systems in Virtualized Environments
abstract
With the widespread adoption of virtualization, intrusion detection systems (IDSes) are increasingly being deployed in virtualized environments. When securing an environment, IT security officers are often faced with the question of how accurate deployed IDSes are at detecting attacks. To this end, metrics for assessing the attack detection accuracy of IDSes have been developed. However, these metrics are defined with respect to a fixed set of hardware resources available to the tested IDS. Therefore, IDSes deployed in virtualized environments featuring elasticity (i.e., on-demand allocation or deallocation of virtualized hardware resources during system operation) cannot be evaluated in an accurate manner using existing metrics. In this paper, we demonstrate the impact of elasticity on IDS attack detection accuracy. In addition, we propose a novel metric and measurement methodology for accurately quantifying the accuracy of IDSes deployed in virtualized environments featuring elasticity. We demonstrate their practical use through case studies involving commonly used IDSes.
Aleksandar Milenkoski, K. R. Jayaram, Nuno Antunes, Marco Vieira, Samuel Kounev
ISSRE2
2015 Towards Explicitly Elastic Programming Frameworks
abstract
It is a widely held view that software engineers should not be "burdened" with the responsibility of making their application components elastic, and that elasticity should be either be implicit and automatic in the programming framework; or that it is the responsibility of the cloud provider's operational staff (DevOps) to make distributed applications written for dedicated clusters elastic and execute them on cloud environments. In this paper, we argue the opposite - we present a case for explicit elasticity, where software engineers are given the flexibility to explicitly engineer elasticity into their distributed applications. We present several scenarios where elasticity retrofitted to applications by DevOps is ineffective, present preliminary empirical evidence that explicit elasticity improves efficiency, and argue for elastic programming languages and frameworks to reduce programmer effort in engineering elastic distributed applications. We also present a bird's eye view of ongoing work on two explicitly elastic programming frameworks - Elastic Thrift (based on Apache Thrift) and Elastic Java, an extension of Java with support for explicit elasticity.
K. R. Jayaram
ICSE (2)1
2015 Subscription Normalization for Effective Content-Based Messaging
abstract
Efficient subscription summarization and event matching is key to the scalability of content-based publish/subscribe networks (CPSNs). Current summarization and event matching mechanisms based onsubscription subsumptioninduce heavy event processing load on brokers degrading the performance of CPSNs especially under high rates of churn, i.e., addition, deletion, or modification of subscriptions. Yet, many modern CPS applications such as location-based services or algorithmic trading inherently rely on high frequency subscription changes. This paper describes Beretta, a dynamic CPSN which sustains high throughput and low event-propagation latencies even under a high frequency of subscription changes. Beretta leveragesstrong event typingand represents all subscriptions in anormalized formas combinations ofvalue intervalsandset inclusionswithout compromising on expressiveness. Beretta’s “split and subsume” broker algorithm reduces the complexity of matching an event from$O(K\,N)$to$O(K\,\log \,N + |result|)$, with$N$being the number of subscriptions for the event type and$K$the number of its attributes. Event types and normalization are exploited tosplitsubscriptions into predicates onindividual event types and attributesand to efficiently regroup these insegment treesandhash mapswhich yield excellent subsumption properties and support attribute-wise split filtering during event matching. Normalization enables thesystematicintroduction of parameters into subscriptions to support both parametric and structural updates. This paper also empirically demonstrates the performance improvements due to our techniques through realistic algorithmic trading and highway traffic monitoring benchmarks.
K. R. Jayaram, Weihang Wang 0001, Patrick Eugster
IEEE Trans. Parallel Distributed Syst.1
2014 Fast, expressive top-k matching
abstract
Top-k matching is a fundamental problem underlying on-line advertising platforms, mobile social networks, etc. Distributed processes (e.g., advertisers) specify predicates, which we call subscriptions, for events (e.g., user actions) they wish to react to. Subscriptions define weights for elementary constraints on individual event attributes and do not require that events match all constraints. An event is multicast only to the processes with the k highest match scores for that event -- this score is the aggregation of the weights of all constraints in a subscription matching the event.
William Culhane, K. R. Jayaram, Patrick Eugster
Middleware2
2014 Trustworthy geographically fenced hybrid clouds
abstract
Adoption of hybrid clouds by enterprises has been hampered by the inability of current hybrid cloud infrastructures to provide scalable and efficient mechanisms (1) to ensure the trustworthiness and integrity of the software stack executing a hybrid application workload, or (2) to enforce governmental privacy, data jurisdiction and audit regulations by ensuring that remote data and computation do not cross specified geographic boundaries.
K. R. Jayaram, David Safford, Upendra Sharma, Vijay K. Naik, Dimitrios E. Pendarakis, Shu Tao
Middleware1
2014 Decentralized Fault-Tolerant Event Correlation
abstract
Despite the prognosed use of event correlation techniques for monitoring critical complex infrastructures or dealing with disasters in the physical world, little work exists on making event correlation systems themselves tolerant to failure. Existing systems either provide no guarantees on event deliveries, do not support multicast and thus provide no guarantees across individual processes, or then rely on centralized components or strong assumptions on the infrastructure. The FAIDECS system attempts to reconcile strong guarantees with practical performance in the presence of process crash failures. To that end, the FAIDECS system uses an overlay network with specific guarantees aligned with its proposed correlation language and guarantees. However, the language proposed lacks expressivity, and the system itself supports only very specific rigid semantics, incapable of supporting even fundamental features like sliding windows. After providing a comprehensive overview of the FAIDECS model and system, this article bridges the gap between strong guarantees and more established correlation languages and systems in several steps. First, we propose alternative semantics for several modules of the FAIDECS matching engine and revisit guarantees. Second, we pinpoint which guarantees are contradicted by which combinations of semantic options. Third, we investigate four correlation languages—StreamSQL, EQL, CEL, and TESLA—showing which semantic options their respective features correspond to in our model, and thus, ultimately, which guarantees of FAIDECS are maintained by which language features.
Gregory Aaron Wilkin, Patrick Eugster, K. R. Jayaram
ACM Trans. Internet Techn.3
2013 Elastic Remote Methods
K. R. Jayaram
Middleware1
2013 Views and Transactional Storage for Large Graphs
Michael Mihn-Jong Lee, Indrajit Roy 0001, Alvin AuYoung, Vanish Talwar, K. R. Jayaram, Yuanyuan Zhou 0001
Middleware5
2013 Parametric Content-Based Publish/Subscribe
abstract
Content-based publish/subscribe (CPS) is an appealing abstraction for building scalable distributed systems, e.g., message boards, intrusion detectors, or algorithmic stock trading platforms. Recently, CPS extensions have been proposed for location-based services like vehicular networks, mobile social networking, and so on. Although current CPS middleware systems are dynamic in the way they support the joining and leaving of publishers and subscribers, they fall short in supporting subscription adaptations. These are becoming increasingly important across many CPS applications. In algorithmic high frequency trading, for instance, stock price thresholds that are of interest to a trader change rapidly, and gains directly hinge on the reaction time to relevant fluctuations rather than fixed values. In location-aware applications, a subscription is a function of the subscriber location (e.g. GPS coordinates), which inherently changes during motion. The common solution for adapting a subscription consists of a resubscription, where a new subscription is issued and the superseded one canceled. This incurs substantial overhead in CPS middleware systems, and leads to missed or duplicated events during the transition. In this article, we explore the concept of parametric subscriptions for capturing subscription adaptations. We discuss desirable and feasible guarantees for corresponding support, and propose novel algorithms for updating routing mechanisms effectively and efficiently in classic decentralized CPS broker overlay networks. Compared to resubscriptions, our algorithms significantly improve the reaction time to subscription updates without hampering throughput or latency under high update rates. We also propose and evaluate approximation techniques to detect and mitigate pathological cases of high frequency subscription oscillations, which could significantly decrease the throughput of CPS systems thereby affecting other subscribers. We analyze the benefits of our support through implementations of our algorithms in two CPS systems, and by evaluating our algorithms on two different application scenarios.
K. R. Jayaram, Patrick Eugster, Chamikara Jayalath
ACM Trans. Comput. Syst.1
2012 Brief Announcement: Weighted Partial Message Matching for Implicit Multicast Systems
William Culhane, K. R. Jayaram, Patrick Eugster
DISC2
2011 Split and Subsume: Subscription Normalization for Effective Content-Based Messaging
abstract
Content-based publish/subscribe networks (CPSNs) scale to large numbers of publishers and subscribers by having brokers summarize subscriptions from subscribers and down-stream brokers based on coverage relationships ("subsumption") between subscriptions. A broker forwards the summary to brokers which are upstream on the routes to the publishers. Current summarization and event processing mechanisms induce heavy event processing load on brokers, leading to low event throughput and high latency and further sharp performance degradation under high rates of churn, i.e., addition, deletion, or modification of subscriptions. This paper describes Beretta, a novel CPSN that leverages a simple model of typed events, enabling a succinct and uniform normalized representation of subscriptions. This in turn supports highly effective subsumption and attribute-wise split filtering with matching complexity logarithmic in the number of subscriptions, and enables the systematic introduction of parameters into subscriptions to support both parametric and structural updates. We empirically demonstrate that our techniques significantly improve throughput and latency of event propagation and reduce response times to subscription updates.
K. R. Jayaram, Patrick Eugster
ICDCS1
2011 FAIDECS: Fair Decentralized Event Correlation
Gregory Aaron Wilkin, K. R. Jayaram, Patrick Eugster, Ankur Khetrapal
Middleware2
2010 Scalable Efficient Composite Event Detection
K. R. Jayaram, Patrick Eugster
COORDINATION1
2010 Parametric Subscriptions for Content-Based Publish/Subscribe Networks
K. R. Jayaram, Chamikara Jayalath, Patrick Eugster
Middleware1
2009 EventJava: An Extension of Java for Event Correlation
Patrick Eugster, K. R. Jayaram
ECOOP2
2008 On the Adequacy of Statecharts as a Source of Tests for Cryptographic Protocols
abstract
The effectiveness of statecharts as a tool to express the desired behavior of security protocols and a source of tests for their implementations was investigated. Specifically, TLS protocol was modeled as a statechart and tests generated from its flattened version. The GnuTLS implementation of the protocol was then tested against the generated tests. The MC/DC coverage of different components of the implementation varied from 51% to 81%. A "what if" analysis revealed that while some defects in the uncovered code will not lead to any security vulnerability due to in-built fault tolerance, others might lead to improper authentication, integrity failure, session hijacking, denial of service, and loss of confidentiality. The analysis suggests that statecharts alone might not be an adequate tool as a source of tests for implementations of security protocols and that tests so generated must be augmented through other formal means such as random testing, stress testing, and code coverage analysis.
K. R. Jayaram, Aditya P. Mathur
COMPSAC1
2006 Identifying andTesting for Insecure Paths in Cryptographic Protocol Implementations
abstract
Cryptographic protocols, which are also referred to as security protocols are used to process, store and transfer increasing volumes of information on our financial networks, health networks, and even our library systems, not to mention our conventional communication systems and our networked systems of personal and corporate computers. Users should be able to justifiably rely on their implementations to process, store, and communicate sensitive information securely. Testing is indispensable even when a security protocol is formally verified because most formal verification techniques only guarantee the correctness of the design, under certain assumptions. More importantly, no guarantees about the implementation are provided. A mathematical proof that an implementation of a security protocol conforms to its specifications is usually not feasible because it would require complicated formal semantics of the language in which it is written and the environment in which the protocol runs (the operating system and hardware)
K. R. Jayaram
COMPSAC (2)1