Keith Winstein

dblp:38/11404 · DBLP profile ↗
← Back
34ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0003-2305-8048ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 22 · 3 first-author · 5 since 2021Systems, architecture and hardware · 7 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Fix: externalizing network I/O in serverless computing
abstract
We describe a system for serverless computing where users, programs, and the underlying platform share a common representation of a computation: a deterministic procedure, run in an environment of well-specified data or the outputs of other computations. This representation externalizes I/O: data movement over the network is performed exclusively by the platform. Applications can describe the precise data needed at each stage, helping the provider schedule tasks and network transfers to reduce starvation. The design suggests an end-to-end argument for outsourced computing, shifting the service model from "pay-for-effort" to "pay-for-results."
Yuhan Deng, Akshay Srivatsan, Sebastian Ingino, Francis Chua, Yasmine Mitchell, Matthew Vilaysack, Keith Winstein
EuroSys7
2025 Internet Connection Splitting: What's Old is New Again
Gina Yuan, Thea Rossman, Keith Winstein
USENIX ATC3
2024 Sidekick: In-Network Assistance for Secure End-to-End Transport Protocols
Gina Yuan, Matthew Sotoudeh, David K. Zhang, Michael Welzl, David Mazières, Keith Winstein
NSDI6
2022 Computation-centric networking
abstract
We propose putting computation at the center of what networked computers and cloud services do for their users. We envision a shared representation of a computation: a deterministic procedure, run in an environment of well-specified dependencies. This suggests an end-to-end argument for serverless computing, shifting the service model from "renting CPUs by the second" to "providing the unambiguously correct result of a computation." Accountability to these higher-level abstractions could permit agility and innovation on other axes.
Yuhan Deng, Angela Montemayor, Amit Levy 0001, Keith Winstein
HotNets4
2022 Sidecar: in-network performance enhancements in the age of paranoid transport protocols
abstract
In response to ossification and privacy concerns, post-TCP transport protocols such as QUIC are designed to be "paranoid"---opaque to meddling middleboxes by encrypting and authenticating the header and payload---making it impossible for Performance-Enhancing Proxies (PEPs) to provide the same assistance as before. We propose a research agenda towards an alternate approach to PEPs, creating a sidecar protocol that is loosely-coupled to the unchanged and opaque, underlying transport protocol. The key technical challenge to sidecar protocols is how to usefully refer to the packets of the underlying connection without ossification. We have made progress on this problem by creating a tool we call a quACK (quick ACK), a concise representation of a multiset of numbers that can be used to efficiently decode the randomly-encrypted packet contents a sidecar has received. We implement the quACK and discuss how to achieve several applications with this approach: alternate congestion control, ACK reduction, and PEP-to-PEP retransmission across a lossy subpath.
Gina Yuan, David K. Zhang, Matthew Sotoudeh, Michael Welzl, Keith Winstein
HotNets5
2022 Side-Facing UHF-Band Radar System to Monitor Tree Water Status
abstract
Vegetation water stress is a key control on wildfire risk, tree mortality, and ecosystem water and carbon fluxes. Although active microwave remote sensing methods have been used to estimate vegetation water, they remain poorly validated because of the immense mismatch between the scale of radar pixel resolutions (100 m to 25 km) and field measurements (individual trees). In this study, we present a new plot-scale vegetation water measurement technique using a side-facing bistatic radar. Using field experiments and a matched filtering technique to isolate the radar signal from noise, we show that radar amplitude is sensitive to xylem water potential (a measure of tree water status). However, our results are affected by periodic noise (period of~12 hours), which may be due to radio frequency interference. We discuss potential pathways to isolate the signal and the implications of the new tree water status measurement system for global validation of microwave remote sensing.
Krishna Rao, Yesenia J. Ulloa, Nicole L. Bienert, Nona R. Chiariello, Natan Holtzman, Gregory R. Quetin, Sean T. Peters, Keith Winstein, Davide Castelletti, Dustin M. Schroeder, Alexandra Georges Konings
IGARSS8
2022 R2E2: low-latency path tracing of terabyte-scale scenes using thousands of cloud CPUs
abstract
In this paper we explore the viability of path tracing massive scenes using a "supercomputer" constructed on-the-fly from thousands of small, serverless cloud computing nodes. We present R2E2 (Really Elastic Ray Engine) a scene decomposition-based parallel renderer that rapidly acquires thousands of cloud CPU cores, loads scene geometry from a pre-built scene BVH into the aggregate memory of these nodes in parallel, and performs full path traced global illumination using an inter-node messaging service designed for communicating ray data. To balance ray tracing work across many nodes, R2E2 adopts a service-oriented design that statically replicates geometry and texture data from frequently traversed scene regions onto multiple nodes based on estimates of load, and dynamically assigns ray tracing work to lightly loaded nodes holding the required data. We port pbrt's ray-scene intersection components to the R2E2 architecture, and demonstrate that scenes with up to a terabyte of geometry and texture data (where as little as 1/250th of the scene can fit on any one node) can be path traced at 4K resolution, in tens of seconds using thousands of tiny serverless nodes on the AWS Lambda platform.
Sadjad Fouladi, Brennan Shacklett, Fait Poms, Arjun Arora, Alex Ozdemir, Deepti Raghavan, Pat Hanrahan, Kayvon Fatahalian, Keith Winstein
ACM Trans. Graph.9
2022 NetKernel: Making Network Stack Part of the Virtualized Infrastructure
abstract
This paper presents a system called NetKernel that decouples the network stack from the guest virtual machine and offers it as an independent module. NetKernel represents a new paradigm where network stack can be managed as part of the virtualized infrastructure. It provides important efficiency benefits: By gaining control and visibility of the network stack, operators can perform network management more directly and flexibly, such as multiplexing VMs running different applications to the same network stack module to save CPU cores, and enforcing fair bandwidth sharing. Users also benefit from the simplified stack deployment and better performance: For example mTCP can be deployed without API change to support nginx natively, and shared memory networking can be readily enabled to improve performance of colocated VMs. Testbed evaluation using 100G NICs shows that NetKernel preserves the performance and scalability of both kernel and userspace network stacks, and provides the same isolation as the current architecture.
Zhixiong Niu, Peng Cheng 0005, Yongqiang Xiong, Dongsu Han, Keith Winstein, Chun Jason Xue, Hong Xu 0001
IEEE/ACM Trans. Netw.6
2021 Revisiting Acknowledgment Mechanism for Transport Control: Modeling, Analysis, and Implementation
abstract
The shared nature of the wireless medium induces contention between data transport and backward signaling, such as acknowledgment. The current way of TCP acknowledgment induces control overhead which is counter-productive for TCP performance especially in wireless local area network (WLAN) scenarios. In this paper, we present a new acknowledgment called TACK (“Tame ACK”), as well as its TCP implementation TCP-TACK. TACK seeks to minimize ACK frequency, which is exactly what is required by transport. TCP-TACK works on top of commodity WLAN, delivering high wireless transport goodput with minimal control overhead in the form of ACKs, without any hardware modification. Evaluation results show that TCP-TACK achieves significant advantages over legacy TCP in WLAN scenarios due to less contention between data packets and ACKs. Specifically, TCP-TACK reduces over 90% of ACKs and also obtains an improvement of up to 28% on goodput. A TACK-based protocol is a good replacement of the legacy TCP to compensate for scenarios where the acknowledgment overhead is non-negligible.
Tong Li 0014, Kai Zheng 0003, Ke Xu 0002, Rahul Arvind Jadhav, Keith Winstein, Kun Tan 0002
IEEE/ACM Trans. Netw.6
2020 Time-of-Flight Soil Moisture Estimation Using RF Backscatter Tags
abstract
Agricultural soil moisture measurement is usually done with extensive in situ sensor deployments. These sensor networks are often difficult to install and maintain. Ground penetrating radars have also been used to do fine-grained moisture measurements in farm fields, but usually require the radar to be in or near contact with the soil. In this paper we propose a hybrid approach that combines an in situ backscatter reflector with an ultra-wideband radar that is small enough to be handheld or mounted to a drone. The underground backscatter reflector allows for accurate time-of-flight measurements. The time-of-flight is determined by the permittivity of the soil, which is influenced primarily by the soil water content for non-saline soils. We performed both laboratory and in situ measurements, achieving an average accuracy within 0.013 cm3/ cm3of the ground truth with a 90th percentile of 0.034 cm3/cm3. This demonstrates the feasibility of our approach.
Colleen Josephson, Bradley Barnhart, Keith Winstein, Sachin Katti, Ranveer Chandra
IGARSS3
2020 Demo Abstract: RF Soil Moisture Sensing via Radar Backscatter Tags
abstract
We present a sensing system that determines soil moisture via RF using backscatter tags paired with a commodity ultra-wideband RF transceiver. Despite decades of research confirming the benefits, soil moisture sensors are still not widely adopted on working farms for three key reasons: the high cost of sensors, the difficulty of deploying and maintaining these sensors, and the lack of reliable internet access in rural areas. We seek to address some of these obstacles by designing a low-cost soil moisture sensing system that uses a hybrid approach of pairing completely wireless backscatter tags with a mobile reader.(p)(/p)We designed and built a backscatter tag prototype and tested our system both in laboratory and in situ at an organic farm field. Our backscatter tag has a projected battery lifetime of up to 15 years on 4xAA batteries, and can operate at a depth of at least 30cm and up to 75cm. It achieves an average accuracy within 0.01-0.03cm3/cm3of the ground truth with a 90th percentile of 0.034cm3/cm3, which is comparable to state-of-the-art commercial soil sensors, at an order of magnitude lower cost.
Colleen Josephson, Bradley Barnhart, Sachin Katti, Keith Winstein, Ranveer Chandra
IPSN4
2020 Learning in situ: a randomized experiment in video streaming
Francis Y. Yan, Hudson Ayers, Chenzhi Zhu, Sadjad Fouladi, Keyi Zhang, Philip Alexander Levis, Keith Winstein
NSDI8
2020 TACK: Improving Wireless Transport Performance by Taming Acknowledgments
abstract
The shared nature of the wireless medium induces contention between data transport and backward signaling, such as acknowledgement. The current way of TCP acknowledgment induces control overhead which is counter-productive for TCP performance especially in wireless local area network (WLAN) scenarios.
Tong Li 0014, Kai Zheng 0003, Ke Xu 0002, Rahul Arvind Jadhav, Keith Winstein, Kun Tan 0002
SIGCOMM6
2020 NetKernel: Making Network Stack Part of the Virtualized Infrastructure
Zhixiong Niu, Hong Xu 0001, Peng Cheng 0005, Yongqiang Xiong, Tao Wang 0088, Dongsu Han, Keith Winstein
USENIX ATC8
2019 From Laptop to Lambda: Outsourcing Everyday Jobs to Thousands of Transient Functional Containers
Sadjad Fouladi, Francisco Romero, Dan Iter, Qian Li 0027, Shuvo Chatterjee, Christoforos E. Kozyrakis, Matei Zaharia, Keith Winstein
USENIX ATC8
2018 Salsify: Low-Latency Network Video through Tighter Integration between a Video Codec and a Transport Protocol
Sadjad Fouladi, John Emmons, Emre Orbay, Catherine Wu, Riad S. Wahby, Keith Winstein
NSDI6
2018 Pantheon: the training ground for Internet congestion-control research
Francis Y. Yan, Jestin Ma, Greg D. Hill, Deepti Raghavan, Riad S. Wahby, Philip Alexander Levis, Keith Winstein
USENIX ATC7
2018 Secure serverless computing using dynamic information flow control
abstract
The rise of serverless computing provides an opportunity to rethink cloud security. We present an approach for securing serverless systems using a novel form of dynamic information flow control (IFC). We show that in serverless applications, the termination channel found in most existing IFC systems can be arbitrarily amplified via multiple concurrent requests, necessitating a stronger termination-sensitive non-interference guarantee, which we achieve using a combination of static labeling of serverless processes and dynamic faceted labeling of persistent data. We describe our implementation of this approach on top of JavaScript for AWS Lambda and OpenWhisk serverless platforms, and present three realistic case studies showing that it can enforce important IFC security properties with modest overhead.
Kalev Alpernas, Cormac Flanagan, Sadjad Fouladi, Leonid Ryzhyk, Shmuel Sagiv, Thomas Schmitz 0001, Keith Winstein
Proc. ACM Program. Lang.7
2017 The Case For Secure Delegation
abstract
Today's secure stream protocols, SSH and TLS, were designed for end-to-end security and do not include a role for semi-trusted third parties. As a result, users who wish to delegate some of their authority to third parties (e.g., to run SSH clients in the cloud, or to host websites on CDNs) rely on insecure workarounds such as ssh-agent forwarding and Keyless TLS. We argue that protocol designers should consider the delegation use-case explicitly, and we propose a definition of "secure" delegation: Before a principal agrees to delegate its authority, a system should provide it with secure advance notice of who will do what to whom under that authority.
Dmitry Kogan, Henri Stern, Ashley Tolbert, David Mazières, Keith Winstein
HotNets5
2017 Network Stack as a Service in the Cloud
abstract
The tenant network stack is implemented inside the virtual machines in today's public cloud. This legacy architecture presents a barrier to protocol stack innovation due to the tight coupling between the network stack and the guest OS. In particular, it causes many deployment troubles to tenants and management and efficiency problems to the cloud provider. To address these issues, we articulate a vision of providing the network stack as a service. The central idea is to decouple the network stack from the guest OS, and offer it as an independent entity implemented by the cloud provider. This re-architecting allows tenants to readily deploy any stack independent of its kernel, and the provider to offer meaningful SLAs to tenants by gaining control over the network stack. We sketch an initial design called NetKernel to accomplish this vision. Our preliminary testbed evaluation with a prototype shows the feasibility and benefits of our idea.
Zhixiong Niu, Hong Xu 0001, Dongsu Han, Peng Cheng 0005, Yongqiang Xiong, Guo Chen 0001, Keith Winstein
HotNets7
2017 Congestion-Control Throwdown
abstract
Congestion control is a perennial topic of networking research. In making decisions about who sends data when, congestion-control schemes prevent collapses and ultimately determine the allocation of scarce communications resources among contending users and applications.
Michael Schapira, Keith Winstein
HotNets2
2017 Privacy Protection in Online Multimedia
abstract
Online multimedia has been growing rapidly due to ubiquitous mobile phones, widely deployed surveillance cameras, dashcams and mini-drones. When one takes photographs or videos at a public location, it is highly likely that some other people ("bystanders") also appear in the visual data. The data may be available online, such as shared by social media, and questions about privacy arise. This panel discusses the issues about privacy in online multimedia from legal, technological, and social aspects.
Yung-Hsiang Lu, Andrea Cavallaro, Catherine Crump, Gerald Friedland, Keith Winstein
ACM Multimedia5
2017 Trust but Verify: Auditing the Secure Internet of Things
abstract
Internet-of-Things devices often collect and transmit sensitive information like camera footage, health monitoring data, or whether someone is home. These devices protect data in transit with end-to-end encryption, typically using TLS connections between devices and associated cloud services. But these TLS connections also prevent device owners from observing what their own devices are saying about them. Unlike in traditional Internet applications, where the end user controls one end of a connection (e.g., their web browser) and can observe its communication, Internet-of-Things vendors typically control the software in both the device and the cloud. As a result, owners have no way to audit the behavior of their own devices, leaving them little choice but to hope that these devices are transmitting only what they should.
Judson Wilson, Riad S. Wahby, Henry Corrigan-Gibbs, Dan Boneh, Philip Alexander Levis, Keith Winstein
MobiSys6
2017 Encoding, Fast and Slow: Low-Latency Video Processing Using Thousands of Tiny Threads
Sadjad Fouladi, Riad S. Wahby, Brennan Shacklett, Karthikeyan Balasubramaniam, William Zeng, Rahul Bhalerao, Anirudh Sivaraman, George Porter, Keith Winstein
NSDI9
2017 The Design, Implementation, and Deployment of a System to Transparently Compress Hundreds of Petabytes of Image Files for a File-Storage Service
Daniel Reiter Horn, Ken Elkabany, Chris Lesniewski-Laas, Keith Winstein
NSDI4
2016 Beetle: Flexible Communication for Bluetooth Low Energy
abstract
The next generation of computing peripherals will be low-power ubiquitous computing devices such as door locks, smart watches, and heart rate monitors. Bluetooth Low Energy is a primary protocol for connecting such peripherals to mobile and gateway devices. Current operating system support for Bluetooth Low Energy forces peripherals into vertical application silos. As a result, simple, intuitive applications such as opening a door with a smart watch or simultaneously logging and viewing heart rate data are impossible. We present Beetle, a new hardware interface that virtualizes peripherals at the application layer, allowing safe access by multiple programs without requiring the operating system to understand hardware functionality, fine-grained access control to peripheral device resources, and transparent access to peripherals connected over the network. We describe a series of novel applications that are impossible with existing abstractions but simple to implement with Beetle.
Amit Levy 0001, Laurynas Riliskis, Philip Alexander Levis, Keith Winstein
MobiSys5
2015 Mahimahi: Accurate Record-and-Replay for HTTP
Ravi Netravali, Anirudh Sivaraman, Somak Das, Ameesh Goyal, Keith Winstein, James W. Mickens, Hari Balakrishnan
USENIX ATC5
2014 Mahimahi: a lightweight toolkit for reproducible web measurement
abstract
This demo presents a measurement toolkit, Mahimahi, that records websites and replays them under emulated network conditions. Mahimahi is structured as a set of arbitrarily composable UNIX shells. It includes two shells to record and replay Web pages, RecordShell and ReplayShell, as well as two shells for network emulation, DelayShell and LinkShell. In addition, Mahimahi includes a corpus of recorded websites along with benchmark results and link traces (https://github.com/ravinet/sites).
Ravi Netravali, Anirudh Sivaraman, Keith Winstein, Somak Das, Ameesh Goyal, Hari Balakrishnan
SIGCOMM3
2014 An experimental study of the learnability of congestion control
abstract
When designing a distributed network protocol, typically it is infeasible to fully define the target network where the protocol is intended to be used. It is therefore natural to ask: How faithfully do protocol designers really need to understand the networks they design for? What are the important signals that endpoints should listen to? How can researchers gain confidence that systems that work well on well-characterized test networks during development will also perform adequately on real networks that are inevitably more complex, or future networks yet to be developed? Is there a tradeoff between the performance of a protocol and the breadth of its intended operating range of networks? What is the cost of playing fairly with cross-traffic that is governed by another protocol?
Anirudh Sivaraman, Keith Winstein, Pratiksha Thaker, Hari Balakrishnan
SIGCOMM2
2013 No silver bullet: extending SDN to the data plane
abstract
The data plane is in a continuous state of flux. Every few months, researchers publish the design of a new high-performance queueing or scheduling scheme that runs inside the network fabric. Many such schemes have been queen for a day, only to be surpassed soon after as methods --- or evaluation metrics --- evolve.
Anirudh Sivaraman, Keith Winstein, Suvinay Subramanian, Hari Balakrishnan
HotNets2
2013 Stochastic Forecasts Achieve High Throughput and Low Delay over Cellular Networks
Keith Winstein, Anirudh Sivaraman, Hari Balakrishnan
NSDI1
2013 TCP ex machina: computer-generated congestion control
abstract
This paper describes a new approach to end-to-end congestion control on a multi-user network. Rather than manually formulate each endpoint's reaction to congestion signals, as in traditional protocols, we developed a program called Remy that generates congestion-control algorithms to run at the endpoints.
Keith Winstein, Hari Balakrishnan
SIGCOMM1
2012 Mosh: An Interactive Remote Shell for Mobile Clients
Keith Winstein, Hari Balakrishnan
USENIX ATC1
2011 End-to-end transmission control by modeling uncertainty about the network state
abstract
This paper argues that the bar for the incorporation of a new subnetwork or link technology in the current Internet is much more than the ability to send minimum-sized IP packets: success requires that TCP perform well over any subnetwork. This requirement imposes a number of additional constraints, some hard to meet because TCP's network model is limited and its overall objective challenging to specify precisely. As a result, network evolution has been hampered and the potential of new subnetwork technologies has not been realized in practice. The poor end-to-end performance of many important subnetworks, such as wide-area cellular networks that zealously hide non-congestive losses and introduce enormous delays as a result, or home broadband networks that suffer from the notorious "bufferbloat" problem, are symptoms of this more general issue.
Keith Winstein, Hari Balakrishnan
HotNets1