VLDB 2026 Research / reviewers in the wild / expert
Lorenzo De Carli
dblp:23/7380
· DBLP profile ↗
39ranked-venue papers
3as first author
19since 2021 · last 2026
0000-0003-0432-3686ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 1 first-author · 12 since 2021Computer networks · 9 · 2 first-authorSoftware engineering, systems software and programming languages · 8 · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Local Privacy Laws in a Globalized WorldabstractPersonal data has emerged as a highly valuable yet sensitive asset that drives business decisions, enables targeted advertising, and generates substantial revenue for companies, while simultaneously facilitating invasive monitoring of users. In recent years, research on digital privacy violations, including undue access, collection, and sharing of user data, has grown significantly. Much of this research adopts the European General Data Protection Regulation (GDPR) as the primary reference framework. This is reasonable, as GDPR was a pioneering legislation, and many of its stipulations are clear and unambiguous. However, we argue that focusing solely on GDPR (and a small set of other Western regulatory frameworks) ignores privacy-related concerns, attitudes, and problems faced by users from other locales, creating a significant research blind spot. Shantanu Sharma 0001, Ethan Myers, Lorenzo De Carli, Ritwik Banerjee, Indrakshi Ray |
CODASPY | 3 |
| 2026 | Behavioral Analysis of AI Code Generation Agents: Edit, Rewrite, and RepetitionabstractArtificial intelligence code generation agents have become transformative tools in modern software development, yet their behavioral patterns remain poorly understood. This paper presents a study analyzing pull request patches from the AIDev dataset to characterize the behavioral signatures of five code generation agents (Claude Code, Copilot, Cursor, Devin, and OpenAI Codex) across the top five programming languages (TypeScript, Python, Go, Java, and C#) in the dataset. We investigate two key research questions: “Do agents edit or rewrite existing code?”, and “How repetitive is each agent’s generated code?” Using token-level similarity metrics (Jaccard, TF-IDF, and fuzzy matching) and repetition analysis (n-gram distributions and Shannon entropy), we characterize edit-rewrite behavior by whether new code closely resembles or substantially differs from existing code. Our results show that Claude Code tends toward lower-similarity changes and higher token diversity, Devin tends toward higher-similarity changes indicative of more incremental modification, and OpenAI Codex exhibits mixed patterns across similarity measures. These behavioral patterns provide insights into how different AI agents approach code generation tasks. Mahdieh Abazar, Reyhaneh Farahmand, Gouri Ginde, Benjamin Tan 0001, Lorenzo De Carli |
MSR | 5 |
| 2025 | Minerva: A File-Based Ransomware DetectorabstractRansomware attacks have caused billions of dollars in damages in recent years, and are expected to cause billions more in the future. Consequently, significant effort has been devoted to ransomware detection and mitigation. Behavioral-based ransomware detection approaches have garnered considerable attention recently. These behavioral detectors typically rely on process-based behavioral profiles to identify malicious behaviors. However, with an increasing body of literature highlighting the vulnerability of such approaches to evasion attacks, a comprehensive solution to the ransomware problem remains elusive. This paper presents Minerva, a novel robust approach to ransomware detection. Minerva is engineered to be robust by design against evasion attacks, with architectural and feature selection choices informed by their resilience to adversarial manipulation. We conduct a comprehensive analysis of Minerva across a diverse spectrum of ransomware types, encompassing unseen ransomware as well as variants designed specifically to evade Minerva. Our evaluation showcases the ability of Minerva to accurately identify ransomware, generalize to unseen threats, and withstand evasion attacks. Furthermore, over of detected ransomware are identified within 0.52sec of activity, enabling the adoption of data loss prevention techniques with near-zero overhead. Dorjan Hitaj, Giulio Pagnotta, Fabio De Gaspari, Lorenzo De Carli, Luigi V. Mancini |
AsiaCCS | 4 |
| 2025 | SCORED '25: Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractAttacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software (including AI applications) requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is the leading venue for academics, industry practitioners, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, deployment experiences, adoption requirements and best practices in the software supply chain. The complete SCORED '25 workshop proceedings are available at: https://doi.org/10.1145/3733827 Aditya Sirish A Yelgundhalli, Behnaz Hassanshahi, Dennis Roellke, Drew Davidson, Kathleen Moriarty, Lorenzo De Carli, Marcela S. Melara, Santiago Torres-Arias, Sarah Evans, Yuchen Zhang 0006 |
CCS | 6 |
| 2025 | Hiding in Plain Sight: On the Robustness of AI-Generated Code Detection
Saman Pordanesh, Sufiyan Bukhari, Benjamin Tan 0001, Lorenzo De Carli |
DIMVA (2) | 4 |
| 2025 | Characterizing Packages for Vulnerability PredictionabstractModern software development relies heavily on the use of external libraries and packages as software reuse provides benefits, such as reduced time to market and lower development cost. However, these libraries often come with their own set of direct and indirect dependencies which could introduce vulnerabilities, compromising the security of end users. Prior work shows that developers may remain unaware of these vulnerabilities until a security incident that exploits them occurs, leading to potential consequences for data privacy. Therefore, it is essential for developers to have the ability, before committing time to a project, to understand whether the external libraries and packages they intend to use may induce vulnerabilities, and how that might happen. In our work, we use the dataset made available by the Goblin framework to identify and evaluate salient features for predicting the vulnerability profile of software packages. We use these features to build classifiers for predicting whether or not a dependency-related vulnerability will occur within 3, 6, or 12 months. Our approach proves to be effective, achieving F1-scores of 0.74, 0.79 and 0.86 in the 3, 6, and 12 month contexts respectively. Providing timely vulnerability information could help developers identify potential security weaknesses before deploying a package to production, thereby minimizing the risk of security incidents. Saviour Owolabi, Francesco Rosati, Ahmad Abdellatif, Lorenzo De Carli |
MSR | 4 |
| 2025 | Harnessing Language Models to Analyze Android App Permission FidelityabstractAndroid’s vast app ecosystem (over 2 million apps) poses significant privacy risks, as current methods for inferring permissions from descriptions - keyword matching, traditional natural language processing (NLP), and recurrent neural networks (RNNs) - struggle with accurate inference due to imprecise, ambiguous, or incomplete natural language descriptions. This gap undermines regulatory transparency and user trust, necessitating tools that reconcile stated functionality with actual data practices. We demonstrate that large language models like GPT-4o, applied in a zero-shot inference setting, leverage contextual reasoning to infer permissions competitively, while fine-tuned encoders (BERT, BART) surpass state-of-the-art performance when trained on minimally annotated datasets augmented with paraphrases, achieving $50-70 \%$ gains in weighted and macro $F_{1}$ scores. By enabling precise permission auditing with reduced annotation costs, our work advances scalable, adaptable solutions for privacy compliance across resource-constrained and highstakes environments. Yunik Tamrakar, Ritwik Banerjee, Ethan Myers, Lorenzo De Carli, Indrakshi Ray |
PST | 4 |
| 2025 | Evaluating LLM-Based Detection of Malicious Package Updates in npmabstractThe npm software package ecosystem is a notable target for adversarial actors, who seek to compromise software dependencies to exploit software developers and the end-users of their software. One especially dangerous form of attack involves the compromise of a package update. By sneaking malicious code into a package update, adversaries can trick package users into unknowingly installing malware. Detecting malicious package updates is an active research problem, as prospective solutions need to keep pace with the near-constant stream of new package updates, while also maintaining high detection accuracy. In this context, one potentially interesting and emergent approach involves utilizing large language models (LLMs) to identify malicious behaviors from the text of package code. However, practical use of LLMs also poses unique first-order challenges, as models are expensive to run and are known to struggle with task performance as input size increases. This work provides a critical exploration into the practicality and effectiveness of LLMs for detecting malicious package updates. We overcome the immediate challenges for LLM-based applications by preprocessing inputs for analysis and post-processing outputs for malware classification. We find this approach to be practical at repository scale and effective at detecting historical malware incidents, with our best-performing model correctly flagging 209 out of 209 malicious samples across a collection of historical attacks, while only flagging 8 out of 2,000 benign samples across a dataset of typical package updates. With first-order obstacles overcome, we then conduct a deeper investigation into the reasoning capabilities of LLMs–demonstrating specific mild code obfuscations that uniquely challenge tested LLMs and enable adaptive adversaries to subvert detection. Ultimately, our findings demonstrate nuanced potential for employing LLMs as a part of a larger security tool-belt for detecting package malware. Elizabeth Wyss, Dominic Tassio, Lorenzo De Carli, Drew Davidson |
RAID | 3 |
| 2025 | REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance Decoding
Tongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli, Robert J. Walls |
USENIX Security Symposium | 4 |
| 2025 | A Multi-Dimensional Analysis of IoT Companion Apps: A Look at Privacy, Security and AccessibilityabstractInternet of Things (IoT) devices provide convenience to users by simplifying household tasks. Most IoTs can be remotely controlled via mobile companion apps, which constitute the main interface between devices themselves and their users. Such apps are used to configure, update, and control the device(s) and thus constitute a critical component in the IoT ecosystem. However, they have historically been understudied which prompts us to look into them. In this paper, we report on a study where we evaluated a sample of 455 IoT companion apps and analyze their privacy, security, and accessibility aspects. Our research aim is to understand these metrics, gauge their state and evaluate whether there is a correlation between them. Our primary findings from the analysis are: (i) most apps have reasonable security and accessibility posture, but in several dimensions there exists a long tail of apps with significant problems and (ii) apps tend to over-request permissions which are not related to their main goal. Moreover, the quality of an app along one aspect is uncorrelated to the same along other aspects. We conclude with actionable recommendations for companion app developers. Faiza Tazi, Suleiman Saka, Shradha Neupane, Ethan Myers, Sanchari Das 0001, Lorenzo De Carli, Indrakshi Ray |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Beyond Typosquatting: An In-depth Look at Package Confusion
Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, Lorenzo De Carli |
USENIX Security Symposium | 5 |
| 2022 | Wolf at the Door: Preventing Install-Time Attacks in npm with LatchabstractThe npm software ecosystem allows developers to easily import code written by others. However, manual vetting of every individual installed component is made difficult in many cases by the number of transitive dependencies brought in by installing popular packages. This has enabled attackers to propagate malicious code by hiding it deep into the dependency chains of popular packages. A particularly dangerous form of attack comes from malicious code embedded into package install scripts. Elizabeth Wyss, Alexander Wittman, Drew Davidson, Lorenzo De Carli |
AsiaCCS | 4 |
| 2022 | On the Data Privacy, Security, and Risk Postures of IoT Mobile Companion Apps
Shradha Neupane, Faiza Tazi, Upakar Paudel, Freddy Veloz Baez, Merzia Adamjee, Lorenzo De Carli, Sanchari Das 0001, Indrakshi Ray |
DBSec | 6 |
| 2022 | What the Fork? Finding Hidden Code Clones in npmabstractThis work presents findings and mitigations on an understudied issue, which we term shrinkwrapped clones, that is endemic to the npm software package ecosystem. A shrink-wrapped clone is a package which duplicates, or near-duplicates, the code of another package without any indication or reference to the original package. This phenomenon represents a challenge to the hygiene of package ecosystems, as a clone package may siphon interest from the package being cloned, or create hidden duplicates of vulnerable, insecure code which can fly under the radar of audit processes. Elizabeth Wyss, Lorenzo De Carli, Drew Davidson |
ICSE | 2 |
| 2022 | Breaking Embedded Software Homogeneity with Protocol Mutations
Tongwei Ren, Sirshendu Ganguly, Lorenzo De Carli, Long Lu |
SecureComm | 4 |
| 2022 | Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniquesabstractAbstract Recent progress in machine learning has led to promising results in behavioral malware detection. Behavioral modeling identifies malicious processes via features derived by their runtime behavior. Behavioral features hold great promise as they are intrinsically related to the functioning of each malware, and are therefore considered difficult to evade. Indeed, while a significant amount of results exists on evasion of static malware features, evasion of dynamic features has seen limited work. This paper examines the robustness of behavioral ransomware detectors to evasion and proposes multiple novel techniques to evade them. Ransomware behavior differs significantly from that of benign processes, making it an ideal best case for behavioral detectors, and a difficult candidate for evasion. We identify and propose a set of novel attacks that distribute the overall malware workload across a small set of independent, cooperating processes in order to avoid the generation of significant behavioral features. Our most effective attack decreases the accuracy of a state-of-the-art classifier from 98.6 to 0% using only 18 cooperating processes. Furthermore, we show our attacks to be effective against commercial ransomware detectors in a black-box setting. Finally, we evaluate a detector designed to identify our most effective attack, as well as discuss potential directions to mitigate our most advanced attack. Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
Neural Comput. Appl. | 4 |
| 2022 | Reliable detection of compressed and encrypted dataabstractAbstract Several cybersecurity domains, such as ransomware detection, forensics and data analysis, require methods to reliably identify encrypted data fragments. Typically, current approaches employ statistics derived from byte-level distribution, such as entropy estimation, to identify encrypted fragments. However, modern content types use compression techniques which alter data distribution pushing it closer to the uniform distribution. The result is that current approaches exhibit unreliable encryption detection performance when compressed data appear in the dataset. Furthermore, proposed approaches are typically evaluated over few data types and fragment sizes, making it hard to assess their practical applicability. This paper compares existing statistical tests on a large, standardized dataset and shows that current approaches consistently fail to distinguish encrypted and compressed data on both small and large fragment sizes. We address these shortcomings and design EnCoD, a learning-based classifier which can reliably distinguish compressed and encrypted data. We evaluate EnCoD on a dataset of 16 different file types and fragment sizes ranging from 512B to 8KB. Our results highlight that EnCoD outperforms current approaches by a wide margin, with accuracy ranging from $$\sim 82\%$$ ∼ 82 % for 512B fragments up to $$\sim 92\%$$ ∼ 92 % for 8KB data fragments. Moreover, EnCoD can pinpoint the exact format of a given data fragment, rather than performing only binary classification like previous approaches. Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
Neural Comput. Appl. | 4 |
| 2022 | Guided Feature Identification and Removal for Resource-constrained FirmwareabstractIoT firmware oftentimes incorporates third-party components, such as network-oriented middleware and media encoders/decoders. These components consist of large and mature codebases, shipping with a variety of non-critical features. Feature bloat increases code size, complicates auditing/debugging, and reduces stability. This is problematic for IoT devices, which are severely resource-constrained and must remain operational in the field for years. Unfortunately, identification and complete removal of code related to unwanted features requires familiarity with codebases of interest, cumbersome manual effort, and may introduce bugs. We address these difficulties by introducing PRAT, a system that takes as input the codebase of software of interest, identifies and maps features to code, presents this information to a human analyst, and removes all code belonging to unwanted features. PRAT solves the challenge of identifying feature-related code through a novel form of differential dynamic analysis and visualizes results as user-friendly feature graphs . Evaluation on diverse codebases shows superior code removal compared to both manual feature deactivation and state-of-art debloating tools, and generality across programming languages. Furthermore, a user study comparing PRAT to manual code analysis shows that it can significantly simplify the feature identification workflow. Tongwei Ren, Lorenzo De Carli, Long Lu, Gillian Smith 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2021 | Detection of Anomalous User Activity for Home IoT DevicesabstractDataset of IoT network traces labeled with user activity Vishwajeet Bhosale, Lorenzo De Carli, Indrakshi Ray |
IoTBDS | 2 |
| 2020 | The Naked Sun: Malicious Cooperation Between Benign-Looking Processes
Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
ACNS (2) | 4 |
| 2020 | EnCoD: Distinguishing Compressed and Encrypted File Fragments
Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
NSS | 4 |
| 2020 | Defending Against Package Typosquatting
Ruturaj K. Vaidya, Drew Davidson, Lorenzo De Carli, Vaibhav Rastogi |
NSS | 4 |
| 2020 | Assessing Adaptive Attacks Against Trained JavaScript Classifiers
Niels Hansen, Lorenzo De Carli, Drew Davidson |
SecureComm (1) | 2 |
| 2020 | Enabling Security Analysis of IoT Device-to-Cloud TrafficabstractEnd-to-end encryption is now ubiquitous on the internet. By securing network communications with TLS, parties can insure that in-transit data remains inaccessible to collection and analysis. In the IoT domain however, end-to-end encryption can paradoxically decrease user privacy, as many IoT devices establish encrypted communications with the manufacturer's cloud backend. The content of these communications remains opaque to the user and in several occasions IoT devices have been discovered to exfiltrate private information (e.g., voice recordings) without user authorization. In this paper, we propose Inspection-Friendly TLS (IF-TLS), an IoT-oriented, TLS-based middleware protocol that preserves the encryption offered by TLS while allowing traffic analysis by middleboxes under the user's control. Differently from related efforts, IF-TLS is designed from the ground up for the IoT world, adding limited complexity on top of TLS and being fully controllable by the residential gateway. At the same time it provides flexibility, enabling the user to offload traffic analysis to either the gateway itself, or cloud-based middleboxes. We implemented a stable, Python-based prototype IF-TLS library; preliminary results show that performance overhead is limited and unlikely to affect quality-of-experience. Eda Zhou, Joseph Turcotte, Lorenzo De Carli |
TrustCom | 3 |
| 2017 | Botnet protocol inference in the presence of encrypted trafficabstractNetwork protocol reverse engineering of botnet command and control (C&C) is a challenging task, which requires various manual steps and a significant amount of domain knowledge. Furthermore, most of today's C&C protocols are encrypted, which prevents any analysis on the traffic without first discovering the encryption algorithm and key. To address these challenges, we present an end-to-end system for automatically discovering the encryption algorithm and keys, generating a protocol specification for the C&C traffic, and crafting effective network signatures. In order to infer the encryption algorithm and key, we enhance state-of-the-art techniques to extract this information using lightweight binary analysis. In order to generate protocol specifications we infer field types purely by analyzing network traffic. We evaluate our approach on three prominent malware families: Sality, ZeroAccess and Ramnit. Our results are encouraging: the approach decrypts all three protocols, detects 97% of fields whose semantics are supported, and infers specifications that correctly align with real protocol specifications. Lorenzo De Carli, Ruben Torres, Gaspar Modelo-Howard, Alok Tongaonkar, Somesh Jha |
INFOCOM | 1 |
| 2017 | Cimplifier: automatically debloating containersabstractApplication containers, such as those provided by Docker, have recently gained popularity as a solution for agile and seamless software deployment. These light-weight virtualization environments run applications that are packed together with their resources and configuration information, and thus can be deployed across various software platforms. Unfortunately, the ease with which containers can be created is oftentimes a double-edged sword, encouraging the packaging of logically distinct applications, and the inclusion of significant amount of unnecessary components, within a single container. These practices needlessly increase the container size-sometimes by orders of magnitude. They also decrease the overall security, as each included component-necessary or not-may bring in security issues of its own, and there is no isolation between multiple applications packaged within the same container image. We propose algorithms and a tool called Cimplifier, which address these concerns: given a container and simple user-defined constraints, our tool partitions it into simpler containers, which (i) are isolated from each other, only communicating as necessary, and (ii) only include enough resources to perform their functionality. Our evaluation on real-world containers demonstrates that Cimplifier preserves the original functionality, leads to reduction in image size of up to 95%, and processes even large containers in under thirty seconds. Vaibhav Rastogi, Drew Davidson, Lorenzo De Carli, Somesh Jha, Patrick D. McDaniel |
ESEC/SIGSOFT FSE | 3 |
| 2014 | Beyond Pattern Matching: A Concurrency Model for Stateful Deep Packet InspectionabstractThe ever-increasing sophistication in network attacks, combined with larger and larger volumes of traffic, presents a dual challenge to network intrusion detection systems (IDSs). On one hand, to take advantage of modern multi-core processing platforms IDSs need to support scalability, by distributing traffic analysis across a large number of processing units. On the other hand, such scalability must not come at the cost of decreased effectiveness in attack detection. In this paper, we present a novel domain-specific concurrency model that addresses this challenge by introducing the notion of detection scope: a unit for partitioning network traffic such that the traffic contained in each resulting "slice" is independent for detection purposes. The notion of scope enables IDSs to automatically distribute traffic processing, while ensuring that information necessary to detect intrusions remains available to detector instances. We show that for a large class of detection algorithms, scope can be automatically inferred via program analysis; and we present scheduling algorithms that ensure safe, scope-aware processing of network events. We evaluate our technique on a set of IDS analyses, showing that our approach can indeed exploit the concurrency inherent in network traffic to provide significant throughput improvements. Lorenzo De Carli, Robin Sommer, Somesh Jha |
CCS | 1 |
| 2014 | Memory processing unitsabstractPresents a conference poster that addresses the technology of memory processing units. Some of the following topics are examined: current processing capabilities; MPU hardware; performance and energy output; and new trends in the industry. Jai Menon 0003, Lorenzo De Carli, Vijayraghavan Thiruvengadam, Karthikeyan Sankaralingam, Cristian Estan |
Hot Chips Symposium | 2 |
| 2014 | HILTI: an Abstract Execution Environment for Deep, Stateful Network Traffic AnalysisabstractWhen developing networking systems such as firewalls, routers, and intrusion detection systems, one faces a striking gap between the ease with which one can often describe a desired analysis in high-level terms, and the tremendous amount of low-level implementation details that one must still grapple with to come to a robust solution. We present HILTI, a platform that bridges this divide by providing to application developers much of the low-level functionality, without tying it to a specific analysis structure. HILTI consists of two parts: (1) an abstract machine model that we tailor specifically to the networking domain, directly supporting the field's common abstractions and idioms in its instruction set; and (2) a compilation strategy for turning programs written for the abstract machine into optimized, natively executable code. We have developed a prototype of the HILTI compiler toolchain that fully implements the design's functionality, and ported exemplars of networking applications to the HILTI model to demonstrate the aptness of its abstractions. Our evaluation of HILTI's functionality and performance confirms its potential to become a powerful platform for future application development. Robin Sommer, Matthias Vallentin, Lorenzo De Carli, Vern Paxson |
Internet Measurement Conference | 3 |
| 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximationabstractIPSs determine whether incoming traffic matches a database of vulnerability signatures defined as regular expressions. DFA representations are popular, but suffer from the state-explosion problem. We introduce a new matching structure: a tree of DFAs where the DFA associated with a node over-approximates those at its children, and the DFAs at the leaves represent the signature set. Matching works top-down, starting at the root of the tree and stopping at the first node whose DFA does not match. In the common case (benign traffic) matching does not reach the leaves. DFA-trees are built using Compact Overapproximate DFAs (CODFAs). A CODFA D' for D over-approximates the language accepted by D, has a smaller number of states than D, and has a low false-match rate. Although built from approximate DFAs, DFA-trees perform exact matching faster than a commonly used method, have a low memory overhead and a guaranteed good worst case performance. Daniel Luchaup, Lorenzo De Carli, Somesh Jha, Eric Bach 0001 |
INFOCOM | 2 |
| 2014 | A Scheduling Framework for Spatial Architectures Across Multiple Constraint-Solving TheoriesabstractSpatial architectures provide energy-efficient computation but require effective scheduling algorithms. Existing heuristic-based approaches offer low compiler/architect productivity, little optimality insight, and low architectural portability. We seek to develop a spatial-scheduling framework by utilizing constraint-solving theories and find that architecture primitives and scheduler responsibilities can be related through five abstractions: computation placement, data routing, event timing, resource utilization, and the optimization objective. We encode these responsibilities as 20 mathematical constraints, using SMT and ILP, and create schedulers for the TRIPS, DySER, and PLUG architectures. Our results show that a general declarative approach using constraint solving is implementable, is practical, and can outperform specialized schedulers. Tony Nowatzki, Michael Sartin-Tarm, Lorenzo De Carli, Karthikeyan Sankaralingam, Cristian Estan, Behnam Robatmili |
ACM Trans. Program. Lang. Syst. | 3 |
| 2013 | SWSL: SoftWare Synthesis for network LookupabstractData structure lookups are among the most expensive operations on routers' critical path in terms of latency and power. Therefore, efficient lookup engines are crucial. Several approaches have been proposed, based on either custom ASICs, general-purpose processors, or specialized engines. ASICs enable high performance but have long design cycle and scarce flexibility, while general-purpose processors present the opposite trade-off. Specialized programmable engines achieve some of the benefits of both approaches, but are still hard to program and limited either in terms of flexibility or performance. In this paper we investigate a different design point. Our solution, SWSL (SoftWare Synthesis for network Lookup) generates hardware logic directly from lookup applications written in C++. Therefore, it retains a simple programming model yet leads to significant performance and power gains. Moreover, compiled application can be deployed on either FPGA or ASIC, enabling a further trade-off between flexibility and performance. While most high-level synthesis compilers focus on loop acceleration, SWSL generates entire lookup chains performing aggressive pipelining to achieve high throughput. Initial results are promising: compared with a previously proposed solution, SWSL gives 2-4 × lower latency and 3-4× reduced chip area with reasonable power consumption. Lorenzo De Carli, Karthikeyan Sankaralingam, Cristian Estan |
ANCS | 2 |
| 2013 | A general constraint-centric scheduling framework for spatial architecturesabstractSpecialized execution using spatial architectures provides energy efficient computation, but requires effective algorithms for spatially scheduling the computation. Generally, this has been solved with architecture-specific heuristics, an approach which suffers from poor compiler/architect productivity, lack of insight on optimality, and inhibits migration of techniques between architectures. Tony Nowatzki, Michael Sartin-Tarm, Lorenzo De Carli, Karthikeyan Sankaralingam, Cristian Estan, Behnam Robatmili |
PLDI | 3 |
| 2012 | LEAP: latency- energy- and area-optimized lookup pipelineabstractTable lookups and other types of packet processing require so much memory bandwidth that the networking industry has long been a major consumer of specialized memories like TCAMs. Extensive research in algorithms for longest prefix matching and packet classification has laid the foundation for lookup engines relying on area- and power-efficient random access memories. Motivated by costs and semiconductor technology trends, designs from industry and academia implement multi-algorithm lookup pipelines by synthesizing multiple functions into hardware, or by adding programmability. In existing proposals, programmability comes with significant overhead. We build on recent innovations in computer architecture that demonstrate the efficiency and flexibility of dynamically synthesized accelerators. In this paper we propose LEAP, a latency- energy- and area- optimized lookup pipeline based on an analysis of various lookup algorithms. We compare to PLUG, which relies on von-Neumann-style programmable processing. We show that LEAP has equivalent flexibility by porting all lookup algorithms previously shown to work with PLUG. At the same time, LEAP reduces chip area by 1.5X, power consumption by 1.3X, and latency typically by 5X. Furthermore, programming LEAP is straight-forward; we demonstrate an intuitive Python-based API. Eric N. Harris, Samuel L. Wasmundt, Lorenzo De Carli, Karthikeyan Sankaralingam, Cristian Estan |
ANCS | 3 |
| 2011 | Experiences in Co-designing a Packet Classification Algorithm and a Flexible Hardware PlatformabstractAlgorithmic solutions to the packet classification problem in network equipment have long been a subject of study in academia and industry and with increases in network speeds they are becoming even more important. Since general purpose processors cannot meet performance and cost requirements, researchers have been assuming that ASICs or FPGAs are necessary for hardware implementation. Industry and academia have been working on SRAM-based platforms specialized for tables used in network equipment, but existing publications only describe the mapping of simpler exact match or prefix match lookups to such platforms. In this paper we adopt a software-hardware co-design approach mapping the EffiCuts algorithm to the PLUG platform. Our work confirms that this solution achieves high throughput (142 million packets per second) and low power (3.1 Watts). It identifies and evaluates changes to the original algorithm and to the platform that can improve throughput and memory utilization. Nilay Vaish, Thawan Kooburat, Lorenzo De Carli, Karthikeyan Sankaralingam, Cristian Estan |
ANCS | 3 |
| 2011 | Deja vu: fingerprinting network problemsabstractWe ask the question: can network problems experienced by applications be identified based on symptoms contained in a network packet trace? An answer in the affirmative would open the doors to many opportunities, including non-intrusive monitoring of such problems on the network and matching a problem with past instances of the same problem. Bhavish Agarwal, Ranjita Bhagwan, Lorenzo De Carli, Venkat N. Padmanabhan, Krishna P. N. Puttaswamy |
CoNEXT | 3 |
| 2010 | Design and implementation of the PLUG architecture for programmable and efficient network lookupsabstractThis paper proposes a new architecture called Pipelined LookUp Grid (PLUG) that can perform data structure lookups in network processing. PLUGs are programmable and through simplicity achieve power efficiency. We draw upon one key insights: data structure lookups have natural structure that can be statically determined and exploited. The PLUG execution model transforms data-structure lookups into pipelined stages of computation and associates small code-blocks with data. The PLUG architecture is a tiled architecture with each tile consisting predominantly of SRAMs, a lightweight no-buffering router, and an array of lightweight computation cores. Using a principle of fixed delays in the execution model, the architecture is contention-free and completely statically scheduled thus achieving high energy efficiency. The architecture enables rapid deployment of new network protocols and generalizes as a data-structure accelerator. Amit Kumar 0007, Lorenzo De Carli, Marc de Kruijf, Karthikeyan Sankaralingam, Cristian Estan, Somesh Jha |
PACT | 2 |
| 2009 | Increasing performances of TCP data transfers through multiple parallel connectionsabstractAlthough Transmission Control Protocol (TCP) is a widely deployed and successful protocol, it shows some limitations in present-day environments. In particular, it is unable to exploit multiple (physical or logical) paths between two hosts. This paper presents PATTHEL, a session-layer solution designed for parallelizing stream data transfers. Parallelization is achieved by striping the data flow among multiple TCP channels. This solution does not require invasive changes to the networking stack and can be implemented entirely in user space. Moreover, it is flexible enough to suit several scenarios - e.g. it can be used to split a data transfer among multiple relays within a peer-to-peer overlay network. Andrea Baldini, Lorenzo De Carli, Fulvio Risso |
ISCC | 2 |
| 2009 | PLUG: flexible lookup modules for rapid deployment of new protocols in high-speed routersabstractNew protocols for the data link and network layer are being proposed to address limitations of current protocols in terms of scalability, security, and manageability. High-speed routers and switches that implement these protocols traditionally perform packet processing using ASICs which offer high speed, low chip area, and low power. But with inflexible custom hardware, the deployment of new protocols could happen only through equipment upgrades. While newer routers use more flexible network processors for data plane processing, due to power and area constraints lookups in forwarding tables are done with custom lookup modules. Thus most of the proposed protocols can only be deployed with equipment upgrades. To speed up the deployment of new protocols, we propose a flexible lookup module, PLUG (Pipelined Lookup Grid). We can achieve generality without loosing efficiency because various custom lookup modules have the same fundamental features we retain: area dominated by memories, simple processing, and strict access patterns defined by the data structure. We implemented IPv4, Ethernet, Ethane, and SEATTLE in our dataflow-based programming model for the PLUG and mapped them to the PLUG hardware which consists of a grid of tiles. Throughput, area, power, and latency of PLUGs are close to those of specialized lookup modules. Lorenzo De Carli, Amit Kumar 0007, Cristian Estan, Karthikeyan Sankaralingam |
SIGCOMM | 1 |