VLDB 2026 Research / reviewers in the wild / expert
Jorn Lapon
dblp:32/1665
· DBLP profile ↗
15ranked-venue papers
2as first author
7since 2021 · last 2024
0000-0002-1863-1172ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Compromising anonymity in identity-reserved k-anonymous datasets through aggregate knowledgeabstractData processors increasingly rely on external data sources to improve strategic or operational decision taking. Data owners can facilitate this by releasing datasets directly to data processors or doing so indirectly via data spaces. As data processors often have different needs and due to the sensitivity of the data, multiple anonymized versions of an original dataset are often released. However, doing so can introduce severe privacy risks. Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2024 | Demo: Backdoor Through the Front Door: Demonstrating Security Flaws in the Eufy EcosystemabstractAs Internet of Things (IoT) devices become increasingly integrated into modern homes, ensuring their security is critical to safeguarding personal privacy and home networks. This demonstration reveals significant security vulnerabilities within Eufy's smart home ecosystem, including weak key derivation mechanisms and inadequate network isolation. These weaknesses allow an attacker to compromise not only the Eufy devices but also the entire home network, posing a broader risk to connected systems and sensitive data. Our demo underscores the urgent need for stronger security measures in IoT ecosystems, illustrating how flaws in edge devices can jeopardize the safety of modern smart homes and their broader infrastructures. Victor Goeman, Tom Cordemans, Dairo de Ruck, Jorn Lapon, Vincent Naessens |
SEC | 4 |
| 2023 | IoT Security Seminar: Raising Awareness and Sharing Critical KnowledgeabstractThe security of the Internet of Things (IoT) devices has become a major concern as the number of connected devices continues to increase. Despite this concern, there is a lack of training opportunities to educate IoT developers on security measures. While there are ample ICT and Network Management courses for developers, there is a lack of security courses scoped for this audience. One of the reasons is that raising cybersecurity awareness and increasing the security expertise of developers presents a significant challenge due to the complexity of IoT security. Victor Goeman, Dairo de Ruck, Ilse Bohé, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2023 | Linux-based IoT Benchmark Generator For Firmware Security Analysis ToolsabstractThere is a growing interest of IoT manufacturers to incorporate firmware analysis tools in their development pipeline to evaluate the security of new embedded devices. This has the advantage of discovering security issues before the device is marketed. However, each device has its own design, including different architectures, services and communication protocols, programmed and configured in different programming languages. This diversity results in potentially complete categories of vulnerabilities discarded by the firmware security analysis tools. Hence, a positive outcome of such tools may result in incorrect conclusions. Dairo de Ruck, Victor Goeman, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2023 | A hybrid anonymization pipeline to improve the privacy-utility balance in sensitive datasets for ML purposesabstractThe modern world is data-driven. Businesses increasingly take strategic decisions based on customer data, and companies are founded with a sole focus of performing machine-learning driven data analytics for third parties. External data sources containing sensitive records are often required to build qualitative machine learning models and, hence, perform accurate and meaningful predictions. However, exchanging sensitive datasets is no sinecure. Personal data must be managed according to privacy regulation. Similarly, loss of strategic data can negatively impact the competitiveness of a company. In both cases, dataset anonymization can overcome the aforementioned obstacles. Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2022 | Reviewing review platforms: a privacy perspectiveabstractMany tourists heavily rely on online review platforms for decisions with respect to food, visits and hotel bookings today. Review communities rigorously log all experiences on popular online platforms such as Google Maps, Tripadvisor and Yelp. However, many contributors are unaware that, along with experiences, a lot of sensitive information is often indirectly exposed to platform visitors. Examples are reviewer’s locations in the privacy sphere, age, medical information and financial status. Malicious entities could potentially employ this information in various ways, for example during extortion or targeted phishing attempts. This work outlines the potential risks for contributors on review platforms. The Google Maps review platform is applied as a prototypical example, with a special focus on predicting the reviewer’s home location. The accuracy of our predictions is assessed by relying on ground truth datasets. This paper further presents and evaluates strategies to tackle common problems. Kevin De Boeck, Jenno Verdonck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2021 | A clustering approach to anonymize locations during dataset de-identificationabstractCompanies increasingly rely on massive amounts of data for strategic decision making purposes. In order to optimize business intelligence, companies often try to enrich their models with datasets acquired from third parties. Datasets containing sensitive attributes must be anonymized before release. For large datasets containing microdata, an often applied anonymization technique is data generalization with the goal of achieving privacy metrics such as k-anonymity. Location is an often recurring yet strategic attribute in many use cases. Multiple strategies can be employed to obfuscate precise coordinates. For example, the most significant digits can be dropped or their value can be replaced by a ZIP code. While these methods might be useful in some applications, these approaches often result in too much information loss, undermining strategic decision making. This paper proposes a novel approach to anonymize location by means of clustering. Its feasibility is evaluated and compared to traditional techniques. Jenno Verdonck, Kevin De Boeck, Michiel Willocx, Jorn Lapon, Vincent Naessens |
ARES | 4 |
| 2016 | Symmetric key infrastructure for authenticated key establishment between resource constrained nodes and powerful devicesabstractAbstract This paper presents a generic lightweight solution for authentication between powerful devices and resource constrained nodes. The approach is validated through the architectural design of multiple applications in different domains. The paper further discusses variants that might increase the usability of the approach in different settings. More precisely, the solution is tuned for open systems, closed systems and hierarchically structured systems. Further, two use cases are presented in which the open system and closed system approach is applied. Copyright © 2011 John Wiley & Sons, Ltd. Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
Secur. Commun. Networks | 2 |
| 2014 | Trusted Computing to Increase Security and Privacy in eID Authentication
Jan Vossaert, Jorn Lapon, Bart De Decker, Vincent Naessens |
SEC | 2 |
| 2011 | Structure Preserving CCA Secure Encryption and Applications
Jan Camenisch, Kristiyan Haralambiev, Markulf Kohlweiss, Jorn Lapon, Vincent Naessens |
ASIACRYPT | 4 |
| 2010 | PriMan : A Privacy-Preserving Identity Framework
Kristof Verslype, Pieter Verhaeghe, Jorn Lapon, Vincent Naessens, Bart De Decker |
DBSec | 3 |
| 2010 | Performance Analysis of Accumulator-Based Revocation Mechanisms
Jorn Lapon, Markulf Kohlweiss, Bart De Decker, Vincent Naessens |
SEC | 1 |
| 2010 | Building advanced applications with the Belgian eIDabstractAbstract The Belgian Electronic Identity Card (eID) was introduced in 2002. The card enables Belgian citizens to digitally prove their identity and to sign electronic documents. Today, only a limited number of citizens really use the card in electronic applications. An important reason is the lack of killer functionality and killer applications. This paper presents two reusable extensions to the Belgian eID technology that opens up new opportunities for application developers. First, a secure and ubiquitously accessible remote storage service is presented. Second, it is shown how the eID card can be used to issue new certificates. The feasibility and reusability of both extensions are validated through the development of several applications in different domains. Copyright © 2010 John Wiley & Sons, Ltd. Jorn Lapon, Vincent Naessens, Bram Verdegem, Pieter Verhaeghe, Bart De Decker |
Secur. Commun. Networks | 1 |
| 2009 | Security and Privacy Improvements for the Belgian eID Technology
Pieter Verhaeghe, Jorn Lapon, Bart De Decker, Vincent Naessens, Kristof Verslype |
SEC | 2 |
| 2008 | A Privacy-Preserving Ticketing System
Kristof Verslype, Bart De Decker, Vincent Naessens, Girma Nigusse, Jorn Lapon, Pieter Verhaeghe |
DBSec | 5 |