VLDB 2026 Research / reviewers in the wild / expert
Agathe Blaise
dblp:226/7147
· DBLP profile ↗
10ranked-venue papers
6as first author
6since 2021 · last 2026
0000-0002-9598-8482ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 first-author · 1 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automated Analysis of Security Policy Violations in Helm ChartsabstractThe advent of Infrastructure-as-Code (IaC) and cloud platforms has transformed applications into ephemeral deployments of configuration files, where containers live for only a few minutes. Several industry-level static analyzers are available to check security misconfigurations before deployment, but the experimental evidence that we report in this paper is that they provide different and possibly inconsistent results. We developed an automated pipeline to evaluate and compare static analyzers for Helm charts, a popular package manager to deploy Kubernetes (K8s) applications, in finding a functional configuration adhering to the principle of least privilege. We evaluated seven open-source chart analyzer tools on the 60 most common Artifact Hub Helm charts (returned by the Application Programming Interface — API upon first invocation) and found that overly permissive ClusterRoles are the most common misconfiguration, and using a high user ID is the most commonly needed permission. During the evaluation, we also found several bugs, both false positives and negatives, that we reported to the tool developers. Securing cloud configurations still requires significant manual intervention, and more effort should be spent on standardizing the analysis of misconfiguration. Francesco Minna, Agathe Blaise, Katja Tuma, Fabio Massacci |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | An AI Security Testbed for the 5G CoreabstractThe 5G core network is the backbone of modern mobile communication, providing high-speed, low-latency, and diverse services for users and industries. Artificial Intelligence (AI) plays an important role in this network by optimizing per-formance, supporting dynamic resource scaling, and improving security through anomaly detection and threat mitigation. Testing AI in 5G environments is difficult because of the complexity of the network and the many possible attack vectors. In this paper, we present a modular and reproducible testbed for evaluating AI-based security mechanisms in the 5G core. The testbed emulates key 5G components and traffic patterns, enabling systematic experiments under realistic conditions. It also provides reliable measurements of Key Performance Indicators (KPIs) to evaluate the effectiveness, robustness, and operational impact of AI solutions, including their ability to detect and mitigate threats. Our work provides a structured framework for testing AI solutions and supports the development of secure, resilient, and AI -enhanced 5G networks. Clément Legrand-Duchesne, Johannes Härtel, Fabio Massacci, Mengyuan Zhang 0001, Agathe Blaise |
CloudCom | 5 |
| 2022 | Learning State Machines to Monitor and Detect Anomalies on a Kubernetes ClusterabstractThese days more companies are shifting towards using cloud environments to provide their services to their client. While it is easy to set up a cloud environment, it is equally important to monitor the system’s runtime behaviour and identify anomalous behaviours that occur during its operation. In recent years, the utilisation of Recurrent Neural Networks (RNNs) and Deep Neural Networks (DNNs) to detect anomalies that might occur during runtime has been a trending approach. However, it is unclear how to explain the decisions made by these networks and how these networks should be interpreted to understand the runtime behaviour that they model. On the contrary, state machine models provide an easier manner to interpret and understand the behaviour that they model. In this work, we propose an approach that learns state machine models to model the runtime behaviour of a cloud environment that runs multiple microservice applications. To the best of our knowledge, this is the first work that tries to apply state machine models to microservice architectures. The state machine model is used to detect the different types of attacks that we launch on the cloud environment. From our experiment results, our approach can detect the attacks very well, achieving a balanced accuracy of 99.2% and a F1 score of 0.982. Clinton Cao, Agathe Blaise, Sicco Verwer, Filippo Rebecchi |
ARES | 2 |
| 2022 | Stay at the Helm: secure Kubernetes deployments via graph generation and attack reconstructionabstractIn recent years, there has been an explosion of attacks directed at microservice-based platforms – a trend that follows closely the massive shift of the digital industries towards these environments. Management and operation of container-based microservices is automation-heavy, leveraging on container orchestration engines such as Kubernetes (K8s). Helm is the package manager of choice for K8s and provides Charts, i.e., configuration files that define a programmatic model for application deployments. In this paper, we propose a novel methodology for extracting and evaluating the security model of Helm Charts. Our proposal extracts a topological graph of the Chart, whose nodes and edges are then characterised by security features. We carry out risk assessments that refer to the attack tactics of the MITRE ATT&CK framework. Furthermore, starting from these scores, we extract the riskiest attack paths. We adopt an experimental validation approach by analysing a dataset created from multiple publicly accessible Helm Chart repositories. Our methodology reveals that, in most cases, they have vulnerabilities that can be exploited through complex attack paths. Agathe Blaise, Filippo Rebecchi |
CLOUD | 1 |
| 2022 | Group anomaly detection in mobile app usages: A spatiotemporal convex hull methodology
Agathe Blaise, Mathieu Bouet, Vania Conan, Stefano Secci |
Comput. Networks | 1 |
| 2021 | An Upcycling Tokenization Method for Credit Card NumbersabstractInternet users are increasingly concerned about their privacy and are looking for ways to protect their data. Additionally, they may rightly fear that companies extract information about them from their online behavior. The so-called tokenization process allows for the use of trusted third-party managed temporary identities, from which no personal data about the user can be inferred. We consider in this paper tokenization systems allowing a customer to hide their credit card number from a webshop. We present here a method for managing tokens in RAM using a table. We refer to our approach as upcycling as it allows for regenerating used tokens by maintaining a table of currently valid tokens. We compare our approach to existing ones and analyze its security. Contrary to the main existing system (Voltage), our table does not increase in size nor slow down over time. The approach we propose satisfies the common specifications of the domain. It is validated by measurements from an implementation. By reaching 70 thousand tries per timeframe, we almost exhaust the possibilities of the 8-digit model for properly dimensioned systems. Cyrius Nugier, Diane Leblanc-Albarel, Agathe Blaise, Simon Masson, Paul Huynh, Yris Brice Wandji Piugie |
SECRYPT | 3 |
| 2020 | BotFP: FingerPrints Clustering for Bot DetectionabstractEfficient bot detection is a crucial security matter and has been widely explored in the past years. Recent approaches supplant flow-based detection techniques and exploit graph-based features, incurring however in scalability issues in terms of time and space complexity. Bots exhibit specific communication patterns: they use particular protocols, contact specific domains, hence can be identified by analyzing their communication with the outside. To simplify the communication graph, we look at frequency distributions of protocol attributes capturing the specificity of botnets behaviour. In this paper, we propose a bot detection technique named BotFP, for BotFinger-Printing, which acts by (i) characterizing hosts behaviour with at-tribute frequency distribution signatures, (ii) learning behaviour of benign hosts and bots through a clustering technique, and (iii) classifying new hosts based on distances to labelled clusters. We validate our solution on the CTU-13 dataset, which contains 13 scenarios of bot infections, connecting to a Command-and-Control (C&C) channel and launching malicious actions such as port scanning or Denial-of-Service (DDoS) attacks. Our approach applies to various bot activities and network topologies. The approach is lightweight, can handle large amounts of data, and shows better accuracy than state-of-the-art techniques. Agathe Blaise, Mathieu Bouet, Vania Conan, Stefano Secci |
NOMS | 1 |
| 2020 | Detection of zero-day attacks: An unsupervised port-based approach
Agathe Blaise, Mathieu Bouet, Vania Conan, Stefano Secci |
Comput. Networks | 1 |
| 2020 | Botnet Fingerprinting: A Frequency Distributions Scheme for Lightweight Bot DetectionabstractEfficient bot detection is a crucial security matter and widely explored in the past years. Recent approaches supplant flow-based detection techniques and exploit graph-based features, incurring however in scalability issues, with high time and space complexity. Bots exhibit specific communication patterns: they use particular protocols, contact specific domains, hence can be identified by analyzing their communication with the outside. A way we follow to simplify the communication graph and avoid scalability issues is looking at frequency distributions of protocol attributes capturing the specificity of botnets behaviour. We propose a bot detection technique named BotFP, for BotFingerPrinting, which acts by (i) characterizing hosts behaviour with attribute frequency distribution signatures, (ii) learning benign hosts and bots behaviours through either clustering or supervised Machine Learning (ML), and (iii) classifying new hosts either as bots or benign ones, using distances to labelled clusters or relying on a ML algorithm. We validate BotFP on the CTU-13 dataset, which contains 13 scenarios of bot infections, connecting to a Command-and-Control (C&C) channel and launching malicious actions such as port scanning or Denial-of-Service (DDoS) attacks. Compared to state-of-the-art techniques, we show that BotFP is more lightweight, can handle large amounts of data, and shows better accuracy. Agathe Blaise, Mathieu Bouet, Vania Conan, Stefano Secci |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Split and Merge: Detecting Unknown Botnets
Agathe Blaise, Mathieu Bouet, Stefano Secci, Vania Conan |
IM | 1 |