VLDB 2026 Research / reviewers in the wild / expert
Sevval Simsek
dblp:283/7990
· DBLP profile ↗
4ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0002-4909-4197ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Fixing Invalid CVE-CWE Mappings in Threat DatabasesabstractAccurate root cause analysis plays a key role for developing mitigation strategies and understanding attack paths. Many security analysis tools rely on threat databases to accurately report information related to vulnerabilities, such as root cause weaknesses or affected platforms. However, these databases are not entirely correct, with many instances of missing or erroneous information linked to vulnerabilities. This paper presents a method for automated correction of invalid Common Weakness Enumeration (CWE) mappings of Common Vulnerability and Exposure (CVE) entries in the National Vulnerability Database (NVD), which can also be applied to other threat databases. We systematically investigate the prevalence of incorrect or missing root-cause mappings, revealing that more than half of CVEs are linked to invalid or insufficiently detailed CWEs, particularly those categorized as Prohibited or Discouraged. Through a longitudinal analysis of the NVD, we detect trends in manual updates to CVE-CWE mappings and show how these can inform predictions for future corrections. We develop and present FixV2W, an automated correction method that uses a Knowledge Graph embedding model to predict and rank best-fitting CWE matches for correcting previously invalid CVE-CWE mappings. We evaluate FixV2w using invalid mappings that were subsequently corrected by the NVD. Notably, focusing on the top-10 ranked answers for correcting prohibited mappings, we show that FixV2W finds the correct CWE in 65% of the cases, and a candidate within the same branch as the correct CWE in 93% of the cases. Moreover, most of the correct mappings appear at the first or second ranks. Sevval Simsek, Howell Xia, Jonah Gluck, David Sastre Medina, David Starobinski |
COMPSAC | 1 |
| 2024 | Poster: Analyzing and Correcting Inaccurate CVE-CWE Mappings in the National Vulnerability DatabaseabstractWe conduct a longitudinal study of the National Vulnerability Database (NVD), focusing on the mappings between vulnerabilities (CVEs) and weaknesses (CWEs).Surprisingly, the study reveals that a significant portion of CVEs, fluctuating between 15% and 30% over the years, lack proper CWE mapping, and that almost 40% of the updates are non-informative.We introduce a methodology, based on knowledge graphs, for automating root cause weakness mapping for CVEs and for fixing existing inaccurate mappings.We showcase promising preliminary results toward this end. Sevval Simsek, Zhenpeng Shi, Howell Xia, David Sastre Medina, David Starobinski |
CCS | 1 |
| 2023 | SREP: Out-Of-Band Sync of Transaction Pools for Large-Scale BlockchainsabstractSynchronization of transaction pools (mempools) has shown potential for improving the performance and block propagation delay of state-of-the-art blockchains. Indeed, various heuristics have been proposed in the literature to this end, all of which incorporate exchanges of unconfirmed transactions into their block propagation protocol. In this work, we take a different approach, maintaining transaction synchronization outside (and independently) of the block propagation channel. In the process, we formalize the synchronization problem within a graph theoretic framework and introduce a novel algorithm (SREP - Set Reconciliation-Enhanced Propagation) with quantifiable guarantees. We analyze the algorithm's performance for various realistic network topologies, and show that it converges on any connected graph in a number of steps that is bounded by the diameter of the graph. We confirm our analytical findings through extensive simulations that include comparison with MempoolSync, a recent approach from the literature. Our simulations show that SREP incurs reasonable overall bandwidth overhead and, unlike MempoolSync, scales gracefully with the size of the network. Novak Boskov, Sevval Simsek, Ari Trachtenberg, David Starobinski |
ICBC | 2 |
| 2020 | Secure and Privacy-Aware Gateway for Home Automation SystemsabstractIn recent years, the Internet of Things has been widely used for academic and industrial purposes. One of the applications in the field of IoT is Home Automation Systems (HAS). Home automation systems are devices that allow homeowners to monitor and control their home from remote locations. However, smart home systems raise security and privacy concerns. In this paper, we propose a privacy-aware secure identification and authentication model. In our scheme, a middleware-layer design is adapted to build a secure and efficient intercommunication platform and provide a high protection for the users. In order to provide mutual authentication, we proposed a double verification protocol. Meanwhile, for privacy reasons, we introduce a communication model by generating fake proofs in order to hide the identity of the IoT devices. The experiments are conducted for different communication scenarios. The outcomes of experiments are promising that the proposed model can readily be implemented for home automation systems. Sinem Gur, Simge Demir, Sevval Simsek, Albert Levi |
SIN | 3 |