VLDB 2026 Research / reviewers in the wild / expert
Nicolas Boltz
dblp:276/7310
· DBLP profile ↗
6ranked-venue papers
5as first author
5since 2021 · last 2026
0009-0005-5613-2111ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 5 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enabling a model-driven workflow for ongoing interdisciplinary collaboration in legal threat modelingabstractContext: Software systems often provide critical functionality or process personal data, requiring compliance with applicable legal regulations. Ensuring legal conformity demands close collaboration between legal and technical experts, but differences in terminology and methodology make this challenging. Objective: In this article, we aim to address the challenges in legal interdisciplinary collaboration by proposing a model-based workflow for ongoing and collaborative legal assessments within the context of threat modeling. Method: The central aspects of the workflow are based on model-driven engineering techniques and were developed through active collaboration between researchers in software engineering and legal informatics/data protection at the KASTEL Security Research Labs. The goal of the collaboration was to integrate the methodologies of both domains into the workflow equally. Result: The proposed workflow centers on maintaining consistency between a legal viewpoint and data flow diagrams, addressing legal subsumption, allowing each discipline to work from its own perspective while providing automated support in threat identification through an extended existing data flow analysis framework that considers legal interpretation. We evaluate the workflow and its modeling artifacts by applying it in the domain of the GDPR, discussing feasibility and applicability, and measuring the accuracy and scalability of the extended data flow analysis. Conclusion: By combining discipline-specific viewpoints with automated consistency and threat identification, the workflow supports collaboration and enables iterative assessments. Our findings suggest that the presented workflow is suitable and operationalizable, but identify potential challenges in practical application or transfer to other legal domains. Nicolas Boltz, Leonie Sterz, Oliver Raabe, Christopher Gerking |
Inf. Softw. Technol. | 1 |
| 2025 | Towards Legal Knowledge Transfer Based on Software Architecture
Nicolas Boltz, Janne Wagner, Leonie Sterz, Oliver Raabe, Christopher Gerking |
ECSA | 1 |
| 2024 | Modeling and Analyzing Zero Trust Architectures Regarding Performance and Security
Nicolas Boltz, Larissa Schmid, Bahareh Taghavi, Christopher Gerking, Robert Heinrich |
ECSA | 1 |
| 2022 | Handling Environmental Uncertainty in Design Time Access Control AnalysisabstractThe high complexity, connectivity, and data exchange of modern software systems make it crucial to consider confidentiality early. An often used mechanism to ensure confidentiality is access control. When the system is modeled during design time, access control can already be analyzed. This enables early identification of confidentiality violations and the ability to analyze the impact of what-if scenarios. However, due to the abstract view of the design time model and the ambiguity in the early stages of development, uncertainties exist in the system environment. These uncertainties can have a direct effect on the validity of access control attributes in use, which might result in compromised confidentiality.To handle such known uncertainty, we present a notion of confidence in the context of design time access control. We define confidence as a composition of known uncertainties in the environment of the system, which influence the validity of access control attributes. We extend an existing modeling and analysis approach for design time access control with our notion of confidence. For evaluation, we apply the notion of confidence to multiple real-world case studies and discuss the resulting benefits for different stages of system development. We also analyze the expressiveness of the extended approach in defining confidentiality constraints and measure the accuracy in identifying confidentiality violations. Our results show that using the notion of confidence increases expressiveness while being able to accurately identify access control violations. Nicolas Boltz, Sebastian Hahner, Maximilian Walter, Stephan Seifermann, Robert Heinrich, Tomás Bures, Petr Hnetynka |
SEAA | 1 |
| 2022 | Evaluation Methods and Replicability of Software Architecture Research ObjectsabstractContext: Software architecture (SA) as research area experienced an increase in empirical research, as identified by Galster and Weyns in 2016 [1]. Empirical research builds a sound foundation for the validity and comparability of the research. A current overview on the evaluation and replicability of SA research objects could help to discuss our empirical standards as a community. However, no such current overview exists.Objective: We aim at assessing the current state of practice of evaluating SA research objects and replication artifact provision in full technical conference papers from 2017 to 2021.Method: We first create a categorization of papers regarding their evaluation and provision of replication artifacts. In a systematic literature review (SLR) with 153 papers we then investigate how SA research objects are evaluated and how artifacts are made available.Results: We found that technical experiments (28%) and case studies (29%) are the most frequently used evaluation methods over all research objects. Functional suitability (46% of evaluated properties) and performance (29%) are the most evaluated properties. 17 papers (11%) provide replication packages and 97 papers (63%) explicitly state threats to validity. 17% of papers reference guidelines for evaluations and 14% of papers reference guidelines for threats to validity.Conclusions: Our results indicate that the generalizability and repeatability of evaluations could be improved to enhance the maturity of the field; although, there are valid reasons for contributions to not publish their data. We derive from our findings a set of four proposals for improving the state of practice in evaluating software architecture research objects. Researchers can use our results to find recommendations on relevant properties to evaluate and evaluation methods to use and to identify reusable evaluation artifacts to compare their novel ideas with other research. Reviewers can use our results to compare the evaluation and replicability of submissions with the state of the practice. Marco Konersmann, Angelika Kaplan, Thomas Kühn 0001, Robert Heinrich, Anne Koziolek, Ralf Reussner, Jan Jürjens, Mahmood al-Doori, Nicolas Boltz, Marco Ehl, Dominik Fuchß, Katharina Großer, Sebastian Hahner, Jan Keim, Matthias Lohr, Timur Saglam, Sophie Corallo, Jan-Philipp Töberg |
ICSA | 9 |
| 2020 | Context-Based Confidentiality Analysis for Industrial IoTabstractIn this research paper, we present an approach for an analysis process, which can find confidentiality issues in data-exchange, on the architectural level of Industrial Internet of Things software systems. Existing approaches provide an insufficient definition of dataflow or lack support of finely granulated information for providing confidentiality. Based on an existing modeling and analysis process for Data-Driven Software Architecture, we extend the role-based approach for access control, with a model to model transformation utilizing a context-based approach. Using a case study based evaluation we show that our approach works accurately and scales in a way that is feasible for big organizations. Nicolas Boltz, Maximilian Walter, Robert Heinrich |
SEAA | 1 |