VLDB 2026 Research / reviewers in the wild / expert
Angel Luis Scull Pupo
dblp:225/6371
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-2083-1285ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DWasm: Portable Debugging for the WebabstractWebAssembly has established itself as a portable compilation target across a wide variety of environments, from browsers and cloud platforms to hardware-constrained devices such as microcontrollers.Its formal specification enables developers to reliably target a broad range of runtimes while compiler toolchains and runtime developers rely on the same formal model.Yet debugging support for WebAssembly remains at an early stage.Source maps often lack sufficient context for debugging, whereas DWARF offers rich type, scope, and location data that developers need for effective debugging.However, adding DWARF support requires non-trivial, timeconsuming runtime-specific efforts that must be repeated independently for each runtime.As a result, the set of debugging features available across runtimes is highly fragmented, while bugs that manifest exclusively in environments without debugging support cannot be analyzed at all.In this paper, we present DWasm, a runtime-independent debugger for WebAssembly.DWasm is realized as a binary transformation pass that instruments the target application with debugging support, without being implemented as part of a concrete runtime engine.By decoupling the debugger from the runtime, DWasm brings portable, DWARFbased debugging across WebAssembly environments.This approach further reduces tool development costs and enables debugging features to be customized for the applicationruntime combination at hand.For our benchmark programs, DWasm exhibits 2x memory overhead, which is low when compared with state-of-the-art debuggers for WebAssembly.In contrast, we observe a performance overhead consistently over 300x, where the shadow-execution instrumentation dominates the added overhead. Aäron Munsters, Nikita Servais, Carlos Rojas Castillo, Angel Luis Scull Pupo, Elisa Gonzalez Boix |
MPLR | 4 |
| 2025 | Wastrumentation: Portable WebAssembly Dynamic Analysis with Support for IntercessionabstractDynamic program analyses help in understanding a program’s runtime behavior and detect issues related to security, program comprehension, or profiling. Instrumentation platforms aid analysis developers by offering a high-level API to write the analysis, and inserting the analysis into the target program. However, current instrumentation platforms for WebAssembly (Wasm) restrict analysis portability because they require concrete runtime environments. Moreover, their analysis API only allows the development of analyses that observe the target program but cannot modify it. As a result, many popular dynamic analyses present for other languages, such as runtime hardening, virtual patching or runtime optimization, cannot currently be implemented for Wasm atop a dynamic analysis platform. Instead, they need to be built manually, which requires knowledge of low-level details of the Wasm’s semantics and instruction set, and how to safely manipulate it. This paper introduces Wastrumentation, the first dynamic analysis platform for WebAssembly that supports intercession. Our solution, based on source code instrumentation, weaves the analysis code directly into the target program code. Inlining the analysis into the target’s source code avoids dependencies on the runtime environment, making analyses portable across Wasm VMs. Moreover, it enables the implementation of analyses in any Wasm-compatible language. We evaluate our solution in two ways. First, we compare it against a state-of-the-art source code instrumentation platform using the WasmR3 benchmarks. The results show improved memory consumption and competitive performance overhead. Second, we develop an extensive portfolio of dynamic analyses, including novel analyses previously unattainable with source code instrumentation platforms, such as memoization, safe heap access, and the removal of NaN non-determinism. Aäron Munsters, Angel Luis Scull Pupo, Elisa Gonzalez Boix |
ECOOP | 2 |
| 2023 | Brigadier: A Datalog-based IAST framework for Node.js ApplicationsabstractThe NODE.JS runtime, in combination with Node Package Manager (NPM), is a popular ecosystem for building server-side web applications. Both JavaScript’s flexible and dynamic character and the vast amount of NPM libraries available can speed up the development of web applications. However, JavaScript and NODE.JS lack security mechanisms and abstractions. Despite the numerous language-based approaches proposed to protect JavaScript applications, no work supports application-level and business-level security properties. This means that in order to achieve both application-level and business-level security, developers are forced to rely on multiple different, unintegrated and incompatible tools and mechanisms.In this paper, we present BRIGADIER1, an interactive security testing framework for NODE.JS applications that enables the specification of both application-level and business-level security policies. Brigadier provides developers with a Datalog-based policy specification language that features close interoperability with running JavaScript programs under test. Input JavaScript programs are instrumented to emit relevant application events sent to a Datalog engine resulting from the compilation of the policies. We exhibit Brigadier’s expressiveness by implementing three case studies from the literature. We also assess Brigadier’s performance overhead on server-side applications. In our benchmarks, we observed a slowdown factor ranging from∼1.2x to ∼3x, which is acceptable for a testing scenario. Angel Luis Scull Pupo, Jens Nicolay, Elisa Gonzalez Boix |
SANER | 1 |
| 2022 | COAST: A Conflict-free Replicated Abstract Syntax Tree
Aäron Munsters, Angel Luis Scull Pupo, Jens Nicolay |
ICSOFT | 2 |
| 2022 | Easing Construction of Smart Agriculture Applications Using Low Code Development Tools
Isaac Nyabisa Oteyo, Angel Luis Scull Pupo, Jesse Zaman, Stephen Kimani, Wolfgang De Meuter, Elisa Gonzalez Boix |
MobiQuitous | 2 |
| 2019 | GUARDIAML: Machine Learning-Assisted Dynamic Information Flow ControlabstractDeveloping JavaScript and web applications with confidentiality and integrity guarantees is challenging. Information flow control enables the enforcement of such guarantees. However, the integration of this technique into software tools used by developers in their workflow is missing. In this paper we present GUARDIAML, a machine learning-assisted dynamic information flow control tool for JavaScript web applications. GUARDIAML enables developers to detect unwanted information flow from sensitive sources to public sinks. It can handle the DOM and interaction with internal and external libraries and services. Because the specification of sources and sinks can be tedious, GUARDIAML assists in this process by suggesting the tagging of sources and sinks via a machine learning component. Angel Luis Scull Pupo, Jens Nicolay, Kyriakos Efthymiadis, Ann Nowé, Coen De Roover, Elisa Gonzalez Boix |
SANER | 1 |
| 2018 | Practical Information Flow Control for Web Applications
Angel Luis Scull Pupo, Laurent Christophe, Jens Nicolay, Coen De Roover, Elisa Gonzalez Boix |
RV | 1 |