VLDB 2026 Research / reviewers in the wild / expert
Etienne Borde
dblp:36/7358
· DBLP profile ↗
22ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-1418-8193ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 3 first-author · 2 since 2021Systems, architecture and hardware · 6 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Multi-agent Simulation and Reinforcement Learning to Optimize Moving Target Defense
William Valentine, Etienne Borde, Mengmeng Ge 0001 |
ARES (2) | 2 |
| 2025 | Exploring the Efficacy of Multi-Agent Reinforcement Learning for Autonomous Cyber Defence: A CAGE Challenge 4 PerspectiveabstractAs cyber threats become increasingly automated and sophisticated, novel solutions must be introduced to improve defence of enterprise networks. Deep Reinforcement Learning (DRL) has demonstrated potential in mitigating these advanced threats. Single DRL Agents have proven utility toward execution of autonomous cyber defence. Despite the success of employing single DRL Agents, this approach presents significant limitations, especially regarding scalability within large enterprise networks. An attractive alternative to the single agent approach is the use of Multi-Agent Reinforcement Learning (MARL). However, developing MARL agents is costly with few options for examining MARL cyber defence techniques against adversarial agents. This paper presents a MARL network security environment, the fourth iteration of the Cyber Autonomy Gym for Experimentation (CAGE) challenges. This challenge was specifically designed to test the efficacy of MARL algorithms in an enterprise network. Our work aims to evaluate the potential of MARL as a robust and scalable solution for autonomous network defence. Mitchell Kiely, Metin Ahiskali, Etienne Borde, Benjamin Bowman, David Bowman, Dirk Van Bruggen, KC Cowan, Prithviraj Dasgupta, Erich Devendorf, Ben Edwards, Alex Fitts, Sunny Fugate, Ryan Gabrys, Wayne Gould, H. Howie Huang, Jules Jacobs, Ryan Kerr, Isaiah J. King, Li Li 0009, Luis Martinez, Christopher Moir, Craig Murphy, Olivia Naish, Claire Owens, Miranda Purchase, Ahmad Ridley, Adrian Taylor, Sara Farmer, William John Valentine, Yiyi Zhang 0002 |
AAAI | 3 |
| 2024 | Multi-Criteria Optimization of Distributed Real-Time Network TopologiesabstractCommunication needs in avionics and transportation have radically changed over the recent years. Traditionally, the underlying hard real-time networks were designed in a centralized way, focusing on redundancy and isolation. Today, real-time communication is ubiquitous, from large airplanes to small vehicles. The associated networks must support a wide range of applications, and large amounts of data. Centralized approaches from the avionics domain, e.g., AFDX, are too costly, too heavyweight, and not flexible enough for these applications.In this paper we explore a new distributed network architecture designed to support jumbo airliners, but also small aircraft and drones. Communication redundancy is achieved using redundant paths, which have to be adapted and optimized to the application. The main challenge then is to build an optimized network configuration ensuring safety, fault tolerance, timing, and performance of both critical, and non-critical communication. Minimizing volume and weight of the equipment is also mandatory. Since the solution space is too large to be explored in reasonable time, we propose a genetic algorithm. Our experiments show that our algorithm converges quickly and offers solutions of excellent quality. The computed solutions are in the top 2% among the best solutions obtained using an exhaustive exploration. Our approach thus enables system engineers to quickly explore and choose very good solution for their systems. Florient Champenois, Florian Brandner, Thierry Grandpierre, Etienne Borde, Abraham Suissa, Laurent Georges |
ISORC | 4 |
| 2023 | The Last-Level-Cache Interference in Guest Performance: a Case-Study with Zephyr OSabstractEmbedded systems are increasingly relying on virtual machines (VMs) to ensure portability and composability of services. To achieve high-performance and resources' isolation, the VM can be mapped to a dedicated core. In shared-memory multi/many cores architectures, the last level cache (LLC) is shared among cores. The state-of-the-art shows that interference on LLC can be a bottleneck for VM's performance. Such interference can depend on several factors, including the design of the applications, guest and host OSes, the hypervisor, and the architecture. Therefore, it is expected that studies analyze in-depth each of these factors. The goal of this work is focusing on the interference that cannot be mitigated by cache isolation techniques supported by the hypervisor, for instance, those caused by host OS applications. Such interference is unpredictable and can jeopardize the performance of the guest. The contribution is a new perspective about how cache interference affects the latency of the guest application and guest OS, crossing different performance metrics in comprehensive plots. We run our experiments on Arm Cortex-A53 processor, and, as guest OS, we employ the state-of-the-art Zephyr OS. Thus, a side contribution is to show Zephyr performance facing cache interference. Our results show that interference on LLC can affect in up to +8 × to slow down the guest application and up to +2.8 ×the subset of kernel functions which are involved for the application execution. Results also show that the guest is mostly affected when its data can fit on the LLC: after this point, the LLC saturation occurs and the host interference becomes insignificant from a guest perspective. Marcelo Ruaro, Hadrien Barral, Matteo Bertolino, Rodrigo Cataldo, Roberto Medina 0001, Mohamed Karaoui, Etienne Borde |
DSD | 7 |
| 2023 | A benchmark of incremental model transformation tools based on an industrial case study with AADL
Hana Mkaouar, Dominique Blouin, Etienne Borde |
Softw. Syst. Model. | 3 |
| 2021 | Moving Target Defense Strategy in Critical Embedded Systems: A Game-theoretic ApproachabstractMoving Target Defense (MTD) is a promising de-fense technique that aims to break the asymmetry between attacker and defender by reconfiguring a system's assets. When used in a critical embedded system, non-functional constraints limit the set of usable MTD techniques, therefore limiting the entropy of reconfigurations. It is therefore necessary to compute an optimal moving target strategy in order to reduce the time between reconfigurations, while managing their impact on the quality of service provided to users. In this paper, we propose a game-theoretic approach to define an optimal moving target defense strategy. Our approach translates risk analysis parame-ters into a Bayesian Stackelberg game, which we translate to a mixed integer linear program. We validate our approach on an industrial case study from the automotive domain, showing the practical usability of our approach. In further experiments, we assess the scalability of our method, as well as the solution's stability in case new vulnerabilities are discovered after the deployment of the system. Maxime Ayrault, Etienne Borde, Ulrich Kühne, Jean Leneutre |
PRDC | 2 |
| 2021 | Online cycle detection for models with mode-dependent input and output dependencies
HeeJong Park 0001, Arvind Easwaran, Etienne Borde |
J. Syst. Archit. | 3 |
| 2021 | Generalized Mixed-Criticality Static Scheduling for Periodic Directed Acyclic Graphs on Multi-Core ProcessorsabstractIn safety-critical systems many software components of different criticalities or assurance levels need to interact in a timely manner to keep the system and environment safe. Nowadays, these systems are challenged by technological progress resulting in rapid increases in both software complexity and processing demands. Efficiently designing safety-critical systems subject to stringent timing requirements is therefore a challenge and a necessity. In this article, we consider the mixed-criticality execution model and homogeneous multi-core processors. We begin by defining a task model incorporating mixed-criticality, real-time and precedence constraints in the form of directed acyclic graphs. A meta-heuristic to solve the scheduling problem of this task model is then defined and proved to respect deadlines, even when the system needs to give more processing power to the most critical tasks. The state-of-the-art techniques capable of scheduling a similar task model have only been developed for dual-criticality systems. Conversely, the meta-heuristic we propose has been generalized to support an arbitrary number of criticality levels. We instantiated our meta-heuristic adopting scheduling algorithms such as G-EDF, G-LLF, or G-EDZL for each level of criticality. The experiments show excellent results in terms of acceptance ratio and number of preemptions. Roberto Medina 0001, Etienne Borde, Laurent Pautet |
IEEE Trans. Computers | 2 |
| 2019 | Fast and robust modelling using a direct translation from a robotic application to its abstracted behaviourabstractIn traditional model-based engineering (MBE), explicit behavioural models are defined with modelling or domain-specific languages like UML or AADL. These models then refer to corresponding parts of the source code. We propose an alternative scheme, where the application's abstracting code is both the behavioural model and an integral part of the implementation. Together with a special library of explicit objects, like a periodic thread, a running application is able to export its abstracted model. That model can then be refined with our translator from application sources to state machines. As we model cyberphysical systems, the models in question can be probabilistic, non-deterministic and temporal. Artur Rataj, Etienne Borde |
RSP | 2 |
| 2019 | Multi-objective exploration of architectural designs by composition of model transformations
Smail Rahmoun, Asma Mehiaoui-Hamitou, Etienne Borde, Laurent Pautet, Elie Soubiran |
Softw. Syst. Model. | 3 |
| 2019 | Translation of ATL to AGT and application to a code generator for Simulink
Elie Richa, Etienne Borde, Laurent Pautet |
Softw. Syst. Model. | 2 |
| 2018 | Availability enhancement and analysis for mixed-criticality systems on multi-coreabstractIn the critical systems domain, Mixed Criticality Systems (MCS) improve considerably the usage of computation resources by running tasks with different levels of criticality on multi-core processors. To ensure the safety of MCS, services provided by low criticality tasks are degraded or stopped whenever high criticality tasks need more computation time than initially credited. The evaluation of this degradation is hardly considered in the literature although low criticality services are of prime importance for the quality of service (QoS) of critical systems. In this paper, we propose a method to evaluate the availability of low criticality services, i.e. how often these services are delivered in MCS. We also propose a task model that improves this availability, demonstrated thanks to our evaluation method on an illustrative example of MCS. Roberto Medina 0001, Etienne Borde, Laurent Pautet |
DATE | 2 |
| 2018 | Scheduling Multi-periodic Mixed-Criticality DAGs on Multi-core ArchitecturesabstractThanks to Mixed-Criticality (MC) scheduling, high and low-criticality tasks can share the same execution platform, improving considerably the usage of computation resources. Even if the execution platform is shared with low-criticality tasks, deadlines of high-criticality tasks must be respected. This is usually enforced thanks to operational modes of the system: if necessary, a high-criticality execution mode allocates more time to high-criticality tasks at the expense of low-criticality tasks' execution. Nonetheless, most MC scheduling policies in the literature have only considered independent task sets. For safety-critical real-time systems, this is a strong limitation: models used to describe reactive safety-critical software often consider dependencies among tasks or jobs. In this paper, we define a meta-heuristic to schedule multiprocessor systems composed of multi-periodic Directed Acyclic Graphs of MC tasks. This meta-heuristic computes the scheduling of the system in the high-criticality mode first. The computation of the low-criticality scheduling respects a condition on high-criticality tasks' jobs, ensuring that high-criticality tasks never miss their deadlines. An efficient implementation of this meta-heuristic is presented. In high-criticality mode, high-criticality tasks are scheduled as late as possible. Then two global scheduling tables are produced, one per criticality mode. Experimental results demonstrate our method outperforms approaches of the literature in terms of acceptance rate for randomly generated systems. Roberto Medina 0001, Etienne Borde, Laurent Pautet |
RTSS | 2 |
| 2015 | Multi-objectives Refinement of AADL Models for the Synthesis Embedded Systems (mu-RAMSES)abstractModel transformation has become now well established as an approach to control and automate the production of the software targeted at large or embedded systems. However, this approach still lacks the ability to be fully automated and to take into account the possibly very large number of Non Functional properties (NFPs) required by the system. Starting from a design written in an architecture description language (AADL), a large number of valid transformations are candidates to be applied, with the aim to refine this design, in a step wise manner, towards its implementation. These transformations may be interdependent, and their selection should take the complex dependency relation into account. The selection should also take into account the impact on NFPs, especially knowing that NFPs may very often be in conflict. In this paper, we propose an approach that automates (i) the identification of model transformation alternatives (MTAs) taking into account their dependencies, and (ii) the selection of MTAs, based on evolutionary algorithms (EAs), that produce the best output models with respect to NFPs. Experiments on a case study provide evidence that the approach can be successfully applied for code generation of real time embedded applications. Smail Rahmoun, Etienne Borde, Laurent Pautet |
ICECCS | 2 |
| 2014 | Architecture models refinement for fine grain timing analysis of embedded systemsabstractAs real-time systems have become more and more complex, architects rely on abstract models of computation in order to design and analyse these systems. In order to ease the production of source code that respects such models of computation, developper can take advantage of code generators and/or middleware. However, when analyzing an abstract model of computation, timing overheads due to generated code or middleware components are not taken into account. Answering this issue is even more problematic in the domain of embedded systems because of the variability of execution platforms. To tackle this problem, we present in this paper a model refinement and timing analysis framework: abstract models of computation are first transformed in more precise models, which include the timing characteristics of the execution platform. These refined models are then used for a more precise timing analysis. The experiment results we present in this paper show that our method can deal with realistic software architecture of real-time systems. Etienne Borde, Smail Rahmoun, Fabien Cadoret, Laurent Pautet, Frank Singhoff, Pierre Dissaux |
RSP | 1 |
| 2013 | Deterministic implementation of periodic-delayed communications and experimentation in AADLabstractThe design of hard real-time embedded systems has to comply with strong requirements with respect to time determinism and resource consumption. However, interacting tasks may induce pessimism in schedulability analysis or introduce significant overheads in memory usage. In this paper, we restrict the execution and communication models to enforce an efficient and predictable implementation. To ensure determinism, a message sent by an emitting task is delivered at its deadline. We take advantage of a wait-free specialized message queues to provide predictable and efficient implementation. The integration of such mechanisms is assisted by a model driven engineering framework1. Fabien Cadoret, Thomas Robert 0003, Etienne Borde, Laurent Pautet, Frank Singhoff |
ISORC | 3 |
| 2012 | Model driven resource usage simulation for critical embedded systemsabstractFacing a growing complexity, embedded systems design relies on model-based approaches to ease the exploration of a design space. A key aspect of such exploration is performance evaluation, mainly depending on usage of the hardware resources. In model-driven engineering, hardware resources usage is often approximated by static properties. In this paper, we propose an extensible modeling framework, to describe with different levels of detail the hardware resource usage. Our method relies on the AADL to describe the whole system, and SystemC to refine the execution platform description. In this paper we expose how we generate and compose SystemC models from the execution platform model described in AADL. We also present promising experimental results obtained on an avionics use-case. Michaël Lafaye, Laurent Pautet, Etienne Borde, Marc Gatti, David Faura |
DATE | 3 |
| 2012 | Design Patterns for Rule-Based Refinement of Safety Critical Embedded Systems Models
Fabien Cadoret, Etienne Borde, Sébastien Gardoll, Laurent Pautet |
ICECCS | 2 |
| 2011 | Hierarchical Composition of Parametric WCET in a Component Based ApproachabstractWorst Case Execution Time (WCET) computation is crucial to the overall timing analysis of real-time embedded systems. Facing the ever increasing complexity of such systems, techniques dedicated to WCET analysis can take advantage of Component Based Software Engineering (CBSE) by decomposing a difficult problem into smaller pieces, easier to analyse. To achieve this objective, the corresponding analysis results have to be composed to provide timing guarantees on the whole system. In this paper, we express the WCET of a component as a formula, allowing to represent its different computational modes. We then propose a Model Driven Engineering (MDE) approach that derives parametric WCET for composite components from parametric WCET of their subcomponents. This approach gives more accurate WCET estimates than naaive additive compositional analysis by taking into account usage context of components. However, analysis scalability concerns lead us to consider a trade-off between precision and scalability. This trade-off can be specified in the model. The composition of WCET estimations is automated and produces the parametric WCET expression of the composite component under analysis. This approach has been integrated in PRIDE. Thomas Leveque, Etienne Borde, Amine Marref, Jan Carlson |
ISORC | 2 |
| 2011 | PRIDE - An Environment for Component-Based Development of Distributed Real-Time Embedded SystemsabstractSettling down the software architecture for embedded system is a complex and time consuming task. Specific concerns that are generally issued from implementation details must be captured in the software architecture and assessed to ensure system correctness. The matter is further complicated by the inherent complexity and heterogeneity of the targeted systems, platforms and concerns. In addition, tools capable of conjointly catering for the complete design-verification deployment cycle, extra-functional properties and reuse are currently lacking. To address this, we have developed Pride, an integrated development environment for component-based development of embedded systems. Pride is based on an architecture relying on components with well-defined semantics that serve as the central development entity, and as means to support and aggregate various analysis and verification techniques throughout the development -- from early specification to synthesis and deployment. Pride also provides generic support for integrating extra-functional properties into architectural definitions. Etienne Borde, Jan Carlson, Juraj Feljan, Luka Lednicki, Thomas Leveque, Josip Maras, Ana Petricic, Séverine Sentilles |
WICSA | 1 |
| 2009 | Mode-based reconfiguration of critical software component architecturesabstractDesigning reconfigurable yet critical embedded and complex systems (i.e. systems composed of different subsystems) requires making these systems adaptable while guaranteeing that they operate with respect to predefined safety properties. When it comes to complex systems, component-based software engineering methods provide solutions to master this complexity (ldquodivide to conquerrdquo). In addition, architecture description languages provide solutions to design and analyze critical and reconfigurable embedded systems. In this paper we propose a methodology that combines the benefits of these two approaches by leaning on both AADL and Lightweigth CCM standards. This methodology is materialized through a complete design process and an associated framework, MyCCM-HI, dedicated to designing reconfigurable, critical, and complex embedded systems. Etienne Borde, Grégory Haïk, Laurent Pautet |
DATE | 1 |
| 2008 | Automatic Composition of AADL Models for the Verification of Critical Component-Based Embedded SystemsabstractEarly analysis and verification of a critical embedded system requires a precise platform specific model (PSM) of the whole system. On the other hand, to master the complexity of large complex critical distributed real-time and embedded systems (DRES), a component-oriented approach is adopted, which entails a higher-level of structural modeling. This contribution presents some AADL usage guidelines for component based systems, and details model transformation rules to obtain PSM also in AADL. The approach is based on automatic model composition from component-based architecture diagrams, and allows to take into account separation of concerns in the platform-level system design. Hugues Balp, Etienne Borde, Grégory Haïk, Jean-François Tilman |
ICECCS | 2 |