VLDB 2026 Research / reviewers in the wild / expert
Tanmay Singla
dblp:354/7122
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2025
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 50% Authentication and access control · 33% Network security · 17% | |
| Software engineering, system software, and programming languages
2 papers |
Software maintenance and evolution · 67% Empirical software engineering · 33% |
Topics — the 7 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
software supply chain security |
1.7 | 2 | 2025 | An Industry Interview Study of Software Signing for Supply Chain Security · USENIX Security Symposium 2025 $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Authentication and access control
access control |
0.9 | 1 | 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Authentication and access control › access control
least privilege |
0.9 | 1 | 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Systems and software security › software supply chain security
software signing |
0.9 | 1 | 2025 | An Industry Interview Study of Software Signing for Supply Chain Security · USENIX Security Symposium 2025 |
Network security › network security architecture
zero trust architecture |
0.9 | 1 | 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Software maintenance and evolution › software ecosystems
dependency management |
0.3 | 1 | 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Software maintenance and evolution
software ecosystems |
0.3 | 1 | 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies · ICSE 2025 |
Methods — techniques the papers use, named apart from their topics
zero-trust architecture · 1.7runtime monitoring · 1.7interview study · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust DependenciesabstractThird-party libraries like Log4j accelerate software application development but introduce substantial risk. Vulnerabilities in these libraries have led to Software Supply Chain (SSC) attacks that compromised resources within the host system. These attacks benefit from current application permissions approaches: third-party libraries are implicitly trusted in the application runtime. An application runtime designed with ZeroTrust Architecture (ZTA) principles - secure access to resources, continuous monitoring, and least-privilege enforcement - could mitigate SSC attacks, as it would give zero implicit trust to these libraries. However, no individual security defense incorporates these principles at a low runtime cost. This paper proposes Zero-Trust Dependencies to mitigate SSC vulnerabilities: we apply the NIST ZTA to software applications. First, we assess the expected effectiveness and configuration cost of Zero-Trust Dependencies using a study of third-party software libraries and their vulnerabilities. Then, we present a system design,$\text{ZTD}_{\text{Sys}}$, that enables the application of Zero-Trust Dependencies to software applications and a prototype,$\text{ZTD}_{\text{JAVA}}$, for Java applications. Finally, with evaluations on recreated vulnerabilities and realistic applications, we show that$\text{ZTD}_{\text{JAVA}}$can defend against prevalent vulnerability classes, introduces negligible cost, and is easy to configure and use. Paschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng, Aravind Machiry, Santiago Torres-Arias, James C. Davis 0001 |
ICSE | 3 |
| 2025 | An Industry Interview Study of Software Signing for Supply Chain Security
Kelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias, James C. Davis 0001 |
USENIX Security Symposium | 2 |