VLDB 2026 Research / reviewers in the wild / expert
Djob Mvondo
dblp:237/7624
· DBLP profile ↗
17ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0002-2622-7970ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 5 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DroidHunter: A Robust Vision-Based Detection Against Hidden Android MalwareabstractDue to their large popularity, Android smartphones are often targeted by malware attacks. Several strategies exist to detect malware code. However, we show that they are insufficient when dealing with obfuscation techniques. DroidHunter is our novel method for detecting Android malwares. DroidHunter leverages opcodes and their parameters, transforming those into RGB images and specific encoding techniques. The generated images are then used to train two different classification models based on support vector machines, convolutional neural networks, and a vision-based transformer. We evaluate DroidHunter on several datasets with up to 476,937 APKs from multiple sources. With detection rates from 98.65% to 99.94%, DroidHunter overcomes nine state-of-the-art malware detection techniques, including Drebin, MaMadroid, DexRay. Moreover, DroidHunter demonstrates strong resilience against hidden malware with detection rates up to 98.98%, and shows robustness on newly emerging threats, achieving an AUT of 0.89 on recent malware samples. We release our code to the research community, with instructions to reproduce our evaluation available at: https://zenodo.org/doi/10.5281/zenodo.10977166. Victoire Nganfang, Simon Queyrut, Yérom-David Bromberg, Valerio Schiavoni, Djob Mvondo, Kengne Tchendji Vianney |
AsiaCCS | 5 |
| 2026 | Efficient Memory Usage For Edge FaaS Platforms
Djob Mvondo, Boris Teabe, Nikos Parlavantzas |
PerCom | 1 |
| 2025 | Secure access to network data for mobile network traffic analysis applicationsabstractMainstream mobile operating systems (mOSes), such as Android or IOS, do not allow applications to perform network traffic analysis (NTA) by design for security reasons. Indeed, users’ network traffic data contain sensitive information, such as browsing history, that can be maliciously exploited, e.g., sold to entities or for blackmailing.In this paper, we explore the problem of providing a secure and efficient way to grant full network data access to a mobile application willing to perform NTA while preventing misuse of the latter data. We consider the network data to be misused if the latter is sent or leaked out of control of the mobile device, e.g., to an external server. To this aim, we design SANeM, an on-device kernel-level solution. It takes the form of permission that provides a means for an application to perform NTA without being able to misuse the user’s network data.We implement a corresponding prototype atop Android 14. Our evaluation on a rooted Samsung S20 shows that SANeM incurs a small overhead on NTA applications that load it and the overall system resources. Furthermore, compared to other workaround mechanisms, such as on-device local/fake VPNs, the overhead with SANeM is considerably lower. Djob Mvondo, Yérom-David Bromberg |
DSN | 1 |
| 2025 | DISC: Backpressure Mitigation In Multi-tier Applications With Distributed Shared Connection
Brice Ekane, Djob Mvondo, Renaud Lachaize, Yérom-David Bromberg, Alain Tchana, Daniel Hagimont |
NSDI | 2 |
| 2025 | The Impact of Kernel Asynchronous APIs on the Performance of a Kernel VPNabstractLinux kernel VPNs suffer from severe performance degradation under high load due to execution order inversion (EoI), a phenomenon where packet recombination functions preempt earlier pipeline stages. This leads to severe latency spikes and throughput reductions. We investigate kernel threads and workqueues as alternative kernel asynchronous APIs to address these limitations, achieving up to a 4.7× increase in throughput while reducing tail latency by 65%. These results demonstrate the importance of selecting appropriate kernel asynchronous APIs for kernel-level network applications. Honore Cesaire Mounah, Djob Mvondo, Julia Lawall, Yérom-David Bromberg |
SYSTOR | 2 |
| 2024 | On the Cost of Model-Serving Frameworks: An Experimental EvaluationabstractIn machine learning (ML), the inference phase is the process of applying pre-trained models to new, unseen data with the objective of making predictions. During the inference phase, end-users interact with ML services to gain insights, recommendations, or actions based on the input data. For this reason, serving strategies are nowadays crucial for deploying and managing models in production environments effectively. These strategies ensure that models are available, scalable, reliable, and performant for real-world applications, such as time series forecasting, image classification, natural language processing, and so on. In this paper, we evaluate the performances of five widely-used model serving frameworks (TensorFlow Serving, TorchServe, MLServer, MLflow, and BentoML) under four different scenarios (malware detection, cryptocoin prices forecasting, image classification, and sentiment analysis). We demonstrate that TensorFlow Serving is able to outperform all the other frameworks in serving deep learning (DL) models. Moreover, we show that DL-specific frameworks (TensorFlow Serving and TorchServe) display significantly lower latencies than the three general-purpose ML frameworks (BentoML, MLFlow, and MLServer). Pasquale De Rosa, Yérom-David Bromberg, Pascal Felber, Djob Mvondo, Valerio Schiavoni |
IC2E | 4 |
| 2024 | HORSE: Ultra-low latency workloads on FaaS platformsabstractWe investigate if FaaS platforms can handle ultra-low latency workloads that run as low as less than 1μs and show that even for a warm start, the initialization time takes up to 99, 99% of the total execution time. This is due to the resume process of warm sandboxes that takes more time as the number of the sandbox's allocated virtual CPUs (vCPUs) increases. We uncover that two operations use up to 93, 1% of the resume time. The first is the insertion of the paused sandbox's vCPUs to a CPU-sorted run queue. The second is the update of a lock-protected variable, which represents the vCPUs' load on each CPU. This variable is used for frequency scaling. Djob Mvondo, François Taïani, Yérom-David Bromberg |
Middleware | 1 |
| 2024 | UTwinVM: Reliable hints on the effects of hypervisor updates on VMs in the CloudabstractWe investigate the problem of getting hints on the effects of virtualization system (aka hypervisor) updates impact on virtual machines (VMs). System administrators can be reluctant to apply updates due to vague hints regarding the updates' impact on running applications. The problem is challenging since VMs are black boxes by design, reducing the scope of the data that can be retrieved and analyzed. Additionally, cloning VMs is only sometimes possible for obvious legal and privacy concerns. Djob Mvondo, Tong Xing 0002, Antonio Barbalace |
Middleware | 1 |
| 2023 | Basalt: A Rock-Solid Byzantine-Tolerant Peer Sampling for Very Large Decentralized NetworksabstractRecent large-scale Byzantine-Fault-Tolerant (BFT) algorithms provide scalability at a low cost by exploiting a secure Random Peer Sampling (RPS) service: a service that provides a stream of random network nodes where no attacking entity can become over-represented. Unfortunately, producing good peer samples untainted by Byzantine behavior in a large-scale network is particularly difficult, with existing solutions unable to withstand aggressive attacks. In this paper, we propose a novel RPS algorithm, BASALT, that implements what we have termed a stubborn chaotic search over node IDs to counter attackers' attempts at becoming over-represented. Our evaluation based on a theoretical analysis, Monte Carlo simulations, and experiments on a live cryptocurrency network shows that BASALT delivers close-to-optimal protection against malicious behaviors and outperforms state-of-the-art solutions by a wide margin. Alex Auvolat, Yérom-David Bromberg, Davide Frey, Djob Mvondo, François Taïani |
Middleware | 4 |
| 2023 | Takeaways of Implementing a Native Rust UDP Tunneling Network Driver in the Linux KernelabstractC is the primary programming language used in the Linux kernel. Recently, the Linux developer community oversaw the experimental addition of Rust into the kernel's build system. Networking is one of the areas often mentioned when discussing the adoption of Rust. In networking, both perfect memory management and performance are critical. Amélie Gonzalez, Djob Mvondo, Yérom-David Bromberg |
PLOS@SOSP | 2 |
| 2021 | Tell me when you are sleepy and what may wake you up!abstractNowadays, there is a shift in the deployment model of Cloud and Edge applications. Applications are now deployed as a set of several small units communicating with each other - the microservice model. Moreover, each unit - a microservice, may be implemented as a virtual machine, container, function, etc., spanning the different Cloud and Edge service models including IaaS, PaaS, FaaS. A microservice is instantiated upon the reception of a request (e.g., an http packet or a trigger), and a rack-level or data-center-level scheduler decides the placement for such unit of execution considering for example data locality and load balancing. With such a configuration, it is common to encounter scenarios where different units, as well as multiple instances of the same unit, may be running on a single server at the same time. Djob Mvondo, Antonio Barbalace, Alain Tchana, Gilles Muller |
SoCC | 1 |
| 2021 | OFC: an opportunistic caching system for FaaS platformsabstractCloud applications based on the "Functions as a Service" (FaaS) paradigm have become very popular. Yet, due to their stateless nature, they must frequently interact with an external data store, which limits their performance. To mitigate this issue, we introduce OFC, a transparent, vertically and horizontally elastic in-memory caching system for FaaS platforms, distributed over the worker nodes. OFC provides these benefits cost-effectively by exploiting two common sources of resource waste: (i) most cloud tenants overprovision the memory resources reserved for their functions because their footprint is non-trivially input-dependent and (ii) FaaS providers keep function sandboxes alive for several minutes to avoid cold starts. Using machine learning models adjusted for typical function input data categories (e.g., multimedia formats), OFC estimates the actual memory resources required by each function invocation and hoards the remaining capacity to feed the cache. We build our OFC prototype based on enhancements to the OpenWhisk FaaS platform, the Swift persistent object store, and the RAM-Cloud in-memory store. Using a diverse set of workloads, we show that OFC improves by up to 82 % and 60 % respectively the execution time of single-stage and pipelined functions. Djob Mvondo, Mathieu Bacou, Kevin Nguetchouang, Lucien Ngale, Stéphane Pouget, Josiane Kouam, Renaud Lachaize, Jinho Hwang, Timothy Wood 0001, Daniel Hagimont, Noel De Palma, Bernabe Batchakui, Alain Tchana |
EuroSys | 1 |
| 2021 | Extending Intel PML for hardware-assisted working set size estimation of VMsabstractIntel page modification logging (PML) is a hardware feature introduced in 2015 for tracking modified memory pages of virtual machines (VMs). Although initially designed to improve VMs checkpointing and live migration, we present in this paper how we can take advantage of this virtualization technology to efficiently estimate the working set size (WSS) of a VM. To this end, we first conduct a study of PML with the Xen hypervisor to investigate its performance impact on VMs and the accuracy of a WSS estimation system that relies on the current version of PML. Our three main findings are as follows. (1) PML reduces by up to 10.18% the time of both VM live migration and checkpointing. (2) PML slightly reduces the negative impact of live migration on application performance by up to 0.95%. (3) A WSS estimation system based on the current version of PML provides inaccurate results. Moreover, our experiments show that write-intensive applications are negatively impacted, with up to 34.9% of performance degradation, when using PML to estimate the WSS of a VM that runs these applications. Based on the aforementioned findings, we introduce page reference logging (PRL), an extended version of PML that allows both read and write memory accesses to be tracked without impacting user VMs, thus more suitable for WSS estimation. We propose a WSS estimation system that leverages PRL and show how it can be used in a data center exploiting memory overcommitment. We implement PRL and the underlying WSS estimation system under Gem5, a popular open-source computer architecture simulator. Evaluation results validate the accuracy of the WSS estimation system and show that PRL does not incur more performance degradation on user’s VMs. Stella Bitchebe, Djob Mvondo, Laurent Réveillère, Noel De Palma, Alain Tchana |
VEE | 2 |
| 2020 | Fine-Grained Fault Tolerance for Resilient pVM-Based Virtual Machine MonitorsabstractVirtual machine monitors (VMMs) play a crucial role in the software stack of cloud computing platforms: their design and implementation have a major impact on performance, security and fault tolerance. In this paper, we focus on the latter aspect (fault tolerance), which has received less attention, although it is now a significant concern. Our work aims at improving the resilience of the "pVM-based" VMMs, a popular design pattern for virtualization platforms. In such a design, the VMM is split into two main components: a bare-metal hypervisor and a privileged guest virtual machine (pVM). We highlight that the pVM is the least robust component and that the existing fault-tolerance approaches provide limited resilience guarantees or prohibitive overheads. We present three design principles (disaggregation, specialization, and pro-activity), as well as optimized implementation techniques for building a resilient pVM without sacrificing end-user application performance. We validate our contribution on the mainstream Xen platform. Djob Mvondo, Alain Tchana, Renaud Lachaize, Daniel Hagimont, Noel De Palma |
DSN | 1 |
| 2019 | When eXtended Para - Virtualization (XPV) Meets NUMAabstractThis paper addresses the problem of efficiently virtualizing NUMA architectures. The major challenge comes from the fact that the hypervisor regularly reconfigures the placement of a virtual machine (VM) over the NUMA topology. However, neither guest operating systems (OSes) nor system runtime libraries (e.g., Hotspot) are designed to consider NUMA topology changes at runtime, leading end user applications to unpredictable performance. This paper presents eXtended Para-Virtualization (XPV), a new principle to efficiently virtualize a NUMA architecture. XPV consists in revisiting the interface between the hypervisor and the guest OS, and between the guest OS and system runtime libraries (SRL) so that they can dynamically take into account NUMA topology changes. The paper presents a methodology for systematically adapting legacy hypervisors, OSes, and SRLs. We have applied our approach with less than 2k line of codes in two legacy hypervisors (Xen and KVM), two legacy guest OSes (Linux and FreeBSD), and three legacy SRLs (Hotspot, TCMalloc, and jemalloc). The evaluation results showed that XPV outperforms all existing solutions by up to 304%. Vo Quoc Bao Bui, Djob Mvondo, Boris Teabe, Kevin Jiokeng, Patrick Lavoisier Wapet, Alain Tchana, Gaël Thomas 0001, Daniel Hagimont, Gilles Muller, Noel De Palma |
EuroSys | 2 |
| 2019 | Memory flipping: a threat to NUMA virtual machines in the CloudabstractvNUMA is the most recent technology used by hypervisors to deal with Non Uniform Memory Access (NUMA) machines, which currently composed most datacenters. vNUMA consists in presenting to the virtual machine (VM) the initial mapping (at boot time) of its virtual resources to physical resources. By this way, all NUMA optimizations implemented by almost all VM’s OS (e.g. Linux) can become effective. However, in order to be effective itself, vNUMA imposes that the initial resource mapping of the VM should remain unchanged during the VM lifetime. Current hypervisors enforce this requirement by avoiding virtual resource migration (between different NUMA nodes, in the same machine), VM migration (between different machines), and memory ballooning.However, we found that memory flipping the most efficient network virtualization approach violates the above requirement. In other words, a VM which performs network operations leads the hypervisor implicitly performs memory page migrations. In this paper, we show that violating this requirement can degrade performance by up to 18%. We present two solutions which mitigate the issue. We prototype these solutions in Xen hypervisor, a popular open source hypervisor, which is widely used by Amazon Web Services. The evaluation results, performed with well known benchmarks, show that our two solutions are able to almost cancel the issue, while keeping memory flipping effective. Djob Mvondo, Boris Teabe, Alain Tchana, Daniel Hagimont, Noel De Palma |
INFOCOM | 1 |
| 2019 | Closer: A New Design Principle for the Privileged Virtual Machine OSabstractIn most of today's virtualized systems (e.g., Xen), the hypervisor relies on a privileged virtual machine (pVM). The pVM accomplishes work both for the hypervisor (e.g., VM life cycle management) and for client VMs (I/O management). Usually, the pVM is based on a standard OS (Linux). This is source of performance unpredictability, low performance, resource waste, and vulnerabilities. This paper presents Closer, a principle for designing a suitable OS for the pVM. Closer consists in respectively scheduling and allocating pVM's tasks and memory as close to the involved client VM as possible. By revisiting Linux and Xen hypervisor, we present a functioning implementation of Closer. The evaluation results of our implementation show that Closer outperforms standard implementations. Djob Mvondo, Boris Teabe, Alain Tchana, Daniel Hagimont, Noel De Palma |
MASCOTS | 1 |