Torben Weis

dblp:39/6057 · DBLP profile ↗
← Back
35ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-6594-326XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 1 since 2021Security and privacy · 8 · 3 since 2021Human-computer interaction and ubiquitous computing · 7 · 1 first-author · 3 since 2021Computer networks · 4Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Size Does Matter: The Impact of Embedding Models and Sizes on Spam Email Classification
abstract
Spam and phishing emails remain a major cybersecurity challenge, even after decades of research into reliable detection methods. Modern ML-based spam filters typically rely on text embeddings to represent email content, yet the choice of embedding model and size is often treated as secondary. This work empirically compares a diverse set of sentence embedders to assess how model type and embedding dimensionality influence downstream email spam classification. Using both classical and ML-based classifiers, we evaluate performance across multiple embedding configurations. Our results show that embedder choice-especially embedding size-substantially affects classification performance and generalisation. We observe performance differences of up to 13% overall, alongside variations of 25% in misclassified spam and 10% in misclassified ham across embedders. These findings highlight that embedding models are not interchangeable; rather, their deliberate selection is just as critical as choosing the right classifier when designing AI-based spam detection pipelines.
Malte Josten, Gérald Kämmerer, Arne Kummerow, Torben Weis
SECRYPT (1)4
2025 Measuring the Power Consumption of Video Games
abstract
The optimization of video games towards energy efficiency on resource-limited devices like smartphones or handhelds is an ongoing challenge in research and industry. Platforms like PCs or consoles do not receive similar attention because such devices are more likely limited by the capabilities of hardware components than the amount of power available to them. Yet, there exists no dedicated method to measure the actual power consumption of video games, on which power optimizations could be based. In this paper, we propose a comprehensive method and provide a prototype implementation to measure the power consumption of video games. The method generates context-aware data usable by both developers and players while being independent of device type and concrete hardware configurations. This independence allows for power measurements on platforms reliant on energy efficiency, like smartphones, as well as underrepresented platforms like the PC. We extend the idea of a power model and use data from hardware sensors, operating system metrics, and video game profilers to calculate the power consumption of video games, their components, and individual functionalities. This method not only helps developers to achieve better energy efficiency in video games but also lays the foundation for future work towards green gaming that relies on the data generated by this method.
Julien Lukasewycz, Torben Weis
CoG2
2025 Navigating the Security Challenges of LLMs: Positioning Target-Side Defenses and Identifying Research Gaps
Malte Josten, Matthias Schaffeld, René Lehmann, Torben Weis
ICISSP (2)4
2024 Investigating the Effectiveness of Bayesian Spam Filters in Detecting LLM-Modified Spam Mails
Malte Josten, Torben Weis
ICDF2C (1)2
2023 Towards Distributed Control Under Deficient Communication with Multi-agent Reinforcement Learning
Arne Kummerow, Torben Weis
MobiQuitous (2)2
2023 Modeling Emergent Behaviour for Enhanced Autonomy in Cyber-Physical Systems
Matthias Schaffeld, Torben Weis
MobiQuitous (2)2
2022 A Digital-Twin Based Architecture for Software Longevity in Smart Homes
abstract
Smart homes usually consist of smart objects (SOs) with limited resources and capabilities, and therefore constrain the complexity of applications that can be performed on them. In particular, updating smart objects within a smart home is a challenging undertaking, as seemingly insignificant updates affect the longevity of the deployment if they cause previously established dependencies to break. In this paper, we propose an architecture that we call Longevity Digital Twins (LDTs) as a strategic counterpart of SOs, aimed at running at the edge, as local to the smart home as possible. With this architecture, the capabilities of a SO can be virtually enhanced to support the software update process in the smart home. In this context, foresighted software management requires both a local capability to describe involved functionalities together with awareness about existing dependencies in this distributed system. Using a simulated smart home environment, we first measure the impact of conventional update strategies and then present the noticeable improvement that LDTs offer to this problem. Going further, we present the analysis of a real-world use case that showcases the potential of LDTs on how it could not only prevent the installation of breaking updates but also extend a SOs capabilities and its overall longevity.
Peter Zdankin, Marco Picone 0001, Marco Mamei, Torben Weis
ICDCS4
2022 Lifecycle-Based View on Cyber-Physical System Models Using Extended Hidden Markov Models
abstract
Many components of Cyber-Physical Systems (CPS) are designed based on models that represent the assumed behavior of the CPS at the time of deployment. However, significant or continuous small changes in the CPS, as well as wear and tear reduce the effectiveness of the CPS and its model and may lead to a total failure of the overall system. In this paper, we propose a novel lifecycle-based view of CPS models. First, we define the model's lifespan as the period from the initial conception of the model until it is no longer fit to represent the system behavior. For better differentiation, a lifespan is divided into the initial, operation, and adaptation phases. In the initial phase, a known-good baseline performance metric is established for the model's suitability to reflect the system behavior. In the operation phase, the model is used for CPS analysis, data smoothing, and fault location while its suitability is monitored. The adaptation phase is intended for necessary adaptations to the model and to the CPS itself, which lead to new iterations. To implement these lifecycle augmentations of the CPS, we use formal modeling in the form of Hidden Markov Models extended by unobservable transitions (Є-HMMT) to represent the assumed system behavior and compare the data of the observed system behavior with this modeling. In addition, we are testing our proposed formalism by designing a CPS model based on smart home systems and running a simulation for validation. The simulation covers unforeseen system changes and corrupted data.
Matthias Schaffeld, Rebecca Bernemann, Torben Weis, Barbara König 0001, Viktor Matkovic
MEMOCODE3
2020 A Digital Forensic Approach for Optimizing the Investigation of Hit-and-Run Accidents
Marian Waltereit, Maximilian Uphoff, Peter Zdankin, Viktor Matkovic, Torben Weis
ICDF2C5
2020 Towards Bike Type and E-Scooter Classification With Smartphone Sensors
abstract
In this paper, we present a novel approach for identifying various bike types and e-scooters using sensor readings from the cyclist’s smartphone. Bike type identification is necessary to provide context-aware navigation services that consider e-scooter- and bike-specific road conditions in route planning and improve safety and comfort by suggesting roads suitable for the cyclist’s bike type. In addition, the idea of bike type identification is useful for advertising purposes or for improving VPA (Virtual Personal Assistants) capabilities with non-intrusive, bike or e-scooter specific suggestions. We employ a CNN (Convolutional Neural Network) deep learning approach to differentiate between various bike-types and e-scooters. The evaluation includes various roads, cyclists, bike types and smartphones. The results show that bike types are identified with average F1-scores, Accuracy and AUC of up to 0.92, 0.90 and 0.98 respectively.
Viktor Matkovic, Marian Waltereit, Peter Zdankin, Torben Weis
MobiQuitous4
2020 Online Driving Behavior Scoring using Wheel Speeds
Marian Waltereit, Peter Zdankin, Viktor Matkovic, Maximilian Uphoff, Torben Weis
VEHITS5
2019 Domain Impersonation is Feasible: A Study of CA Domain Validation Vulnerabilities
abstract
Web security relies on the assumption that certificate authorities (CAs) issue certificates to rightful domain owners only. However, we show that CAs expose vulnerabilities which allow an attacker to obtain certificates from major CAs for domains he does not own. We present a measurement method that allows us to check CAs for a list of technical weaknesses during their domain validation procedures. Our results show that all tested CAs are vulnerable in one or even multiple ways, because they rely on a combination of insecure protocols like DNS and HTTP and do not implement existing secure alternatives like DNSSEC and TLS. We have validated our methodology experimentally and disclosed these vulnerabilities to CAs. Based upon our findings we provide recommendations to domain owners and CAs to close this fundamental weakness in web security.
Lorenz Schwittmann, Matthäus Wander, Torben Weis
EuroS&P3
2019 Mobile Devices as Digital Sextants for Zero-Permission Geolocation
Lorenz Schwittmann, Matthäus Wander, Torben Weis
ICISSP3
2017 Domain Name System Without Root Servers
Matthäus Wander, Christopher Boelmann, Torben Weis
CRiSIS3
2017 Identifying TV Channels & On-Demand Videos using Ambient Light Sensors
Lorenz Schwittmann, Christopher Boelmann, Viktor Matkovic, Matthäus Wander, Torben Weis
Pervasive Mob. Comput.5
2016 Application-Level Determinism in Distributed Systems
abstract
Deterministic and reproducible program execution eases the development and debugging of distributed systems. However, deterministic execution comes at high performance costs and is hard to achieve, especially when running on different hardware. In this paper we introduce the concept of application-level determinism and describe how the parallel programming model Spawn & Merge can be used for scalable and deterministic distributed computation. Application-level deterministic applications yield reproducible deterministic results independent of the number of nodes participating in the computation, even though intermediate tasks may be executed in an unpredictable schedule. To achieve consistency independent of the order in which operations have been applied we present a new Operational Transformation algorithm, which mitigates the performance loss of introducing determinism with Spawn & Merge. We show that such deterministic processing can scale across a cluster of compute nodes and discuss for which kind of workload the programming model is feasible. Furthermore, for high and low workloads, we evaluate the cost of adding determinism to be 28% and 40% higher than perfect parallel computation.
Christopher Boelmann, Lorenz Schwittmann, Marian Waltereit, Matthäus Wander, Torben Weis
ICPADS5
2016 Video recognition using ambient light sensors
abstract
We present a method for recognizing a video that is playing on a TV screen by sampling the ambient light sensor of a user's smartphone. This improves situation awareness in pervasive systems because the phone can determine what the user is currently watching on TV. Our method works even if the phone has no direct line of sight to the TV screen, since ambient light reflected from walls is sufficient. Our evaluation shows that a 100% recognition ratio of the current TV channel is possible by sampling a sequence of 15 to 120 seconds length, depending on more or less favorable measuring conditions. In addition, we evaluated the recognition ratio when the user is watching video-on-demand, which exhibits a large set of possible videos. Recognizing professional YouTube videos resulted in a 92% recognition ratio; amateur videos were recognized correctly with 60% because these videos have fewer cuts. Our method focuses on detecting the time difference between video cuts because the light emitted by the screen changes instantly with most cuts and this is easily measurable with the ambient light sensor. Using the ambient light sensor instead of the camera greatly benefits energy consumption, bandwidth usage and raises less privacy concerns. Hence, it is feasible to run the measurement in the background for a longer time without draining the battery and without sending camera shots to a remote server for analysis.
Lorenz Schwittmann, Viktor Matkovic, Matthäus Wander, Torben Weis
PerCom4
2014 GPU-Based NSEC3 Hash Breaking
abstract
When a client queries for a non-existent name in the Domain Name System (DNS), the server responds with a negative answer. With the DNS Security Extensions (DNSSEC), the server can either use NSEC or NSEC3 for authenticated negative answers. NSEC3 claims to protect DNSSEC servers against domain enumeration, but incurs significant CPU and bandwidth overhead. Thus, DNSSEC server admins must choose between more efficiency (NSEC) or privacy (NSEC3). We present a GPU-based attack on NSEC3 that revealed 64% of all DNSSEC names in the com domain in 4.5 days. This attack shows that the NSEC3 privacy promises are weak and thus DNSSEC server admins must carefully decide whether the limited privacy is worth the overhead. Furthermore, we show that an increase of the cryptographic strength of NSEC3 puts attackers at an advantage, since the cost of an attack does not rise faster than the costs incurred on the DNSSEC server.
Matthäus Wander, Lorenz Schwittmann, Christopher Boelmann, Torben Weis
NCA4
2013 Development of Efficient Role-Based Sensor Network Applications with Excel Spreadsheets
abstract
Natural scientists use large scale sensor networks for gathering and analyzing environmental data. However, the implementation work requires expert programmers. The problem is complicated by limited battery lifetime, processing power and memory capacity of the nodes, because this requires a low-level programming language. Since scientists are used to analyzing data with spreadsheets, researchers have studied the possibility of applying spreadsheet-based programming to sensor networks. The approaches so far either require a central server to execute the spreadsheet, or they execute a spreadsheet run-time on each node. The first approach causes higher communication cost since all data has to be routed to the central server and the second one causes computational overhead, because evaluating a spreadsheet is slower than executing handcrafted NesC-code. Hence, we present a spreadsheet driven tool-chain that can create efficient NesC-code and allows for simulation in the spreadsheet itself. The nodes have to recompute the spreadsheet formulas upon new data. However, we can avoid a large fraction of this recomputation by applying several optimization strategies during code generation. In our example scenario, sensor nodes compute the variance across a series of sensor readings. We can show that the optimizations save 65% CPU cycles and the code size decreases by 12% when compared to non-optimized execution of the spreadsheet. Thus, our approach can deliver an easy way of developing sensor network programs while yielding very efficient code.
Christopher Boelmann, Torben Weis
ICPADS2
2013 Measuring Occurrence of DNSSEC Validation
Matthäus Wander, Torben Weis
PAM2
2012 An architecture for complex P2P systems
abstract
This article presents an architecture for research and development of peer-to-peer (P2P) systems. A complete P2P application has to cope with problems such as NAT-traversal, bootstrapping, connection management, routing, storage, and security. Therefore, our approach separates the system into layers and components. A developer can easily build a complete P2P stack by plugging layers and components together, which allows for easy code reuse and interchangeability. Furthermore, our architecture allows us to run a discrete event simulation by using a special programming model. This way we can use the same code base for productive applications as well as for measurements & tests on a compute cluster. Our evaluation shows that using our architecture has a negligible effect on performance and a very small memory footprint, which allows us to simulate thousands of peer instances running the real application code on a single machine.
Sebastian Holzapfel, Arno Wacker, Torben Weis, Matthäus Wander
CCNC3
2012 NTALG - TCP NAT traversal with application-level gateways
abstract
Consumer computers or home communication devices are usually connected to the Internet via a Network Address Translation (NAT) router. This imposes restrictions for networking applications that require inbound connections. Existing solutions for NAT traversal can remedy the restrictions, but still there is a fraction of home users which lack support of it, especially when it comes to TCP. We present a framework for traversing NAT routers by exploiting their built-in FTP and IRC application-level gateways (ALG) for arbitrary TCP-based applications. While this does not work in every scenario, it significantly improves the success chance without requiring any user interaction at all. To demonstrate the framework, we show a small test setup with laptop computers and home NAT routers.
Matthäus Wander, Sebastian Holzapfel, Arno Wacker, Torben Weis
CCNC4
2012 Self-Stabilizing Micro Controller for Large-Scale Sensor Networks in Spite of Program Counter Corruptions Due to Soft Errors
abstract
For large installations of networked embedded systems it is important that each entity is self-stabilizing, because usually there is nobody to restart nodes that have hung up. Self-stabilization means to recover from temporary failures (soft errors) and adapt to a change of network topology caused by permanent failures. On the software side self-stabilizing algorithms must assume that the hardware is executing the software correctly. In this paper we discuss cases in which soft errors invalidate this assumption, especially in cases where CPU registers or the watchdog timer are affected by the fault. Based on the observation that a guaranteed self-stabilization is only possible as long as the watchdog-timer is working properly after temporary failures, we propose and compare three different approaches that meet the requirements of sensor networks, to solve this problem with a combination of hardware- and software-modifications: 1) A run-time verification of every watchdog access 2) A completely hardware-based approach, without any software modifications 3) A2X byte code alignment, to realign a corrupted program counter Furthermore we determine the average code-size increase and evaluate necessary hardware-modifications that come along with each approach.
Christopher Boelmann, Torben Weis, Michael Engel, Arno Wacker
ICPADS2
2011 Introduction
Eric Fleury, Pedro José Marrón, Torben Weis
Euro-Par (2)4
2011 Detecting Opportunistic Cheaters in Volunteer Computing
abstract
For computationally expensive but parallelizable search problems distributed computing approaches based on volunteer computing can be used. Volunteering users spend their computation time to gain some sort of credit or for the sake of appearing in a ranking. Some of the users may try to gain reward without investing their computation time, i.e. they cheat. Hence, a cheat detection mechanism against such opportunistic cheaters is needed. The simplest approach is the recalculation of all results by multiple users followed by a voting. This simple approach is inefficient since it increases the computational complexity by the factor of the executed recalculations. In this paper we propose a new and efficient approach for cheat detection in search problems using a combination of sample testing and result aggregation. Our approach provides a high probability of detecting a cheating user while reducing the computational complexity using sample testing and the required bandwidth using result aggregation. In a limited range, one can compensate a small available bandwidth with more computations, thus providing a trade-off between bandwidth and computational complexity.
Matthäus Wander, Torben Weis, Arno Wacker
ICCCN2
2011 SYNI - TCP Hole Punching Based on SYN Injection
abstract
The shortage of IPv4 addresses and the very slow transition to IPv6 leads to pragmatic solutions in the Internet: today many hosts are still using IPv4 and are connected to the Internet over a Network Address Translation (NAT) router. However, there are many applications, which need inbound connections, like e.g. peer-to-peer-based systems or voice-over-IP. For such NATed hosts inbound connections usually pose a problem, since without additional measures the router filters the incoming connection attempts. These additional measures are usually referred to as NAT traversal mechanisms and hole punching is one of those techniques. In this paper we propose a new protocol for a TCP-based hole punching mechanism based on self-injecting SYN-packets in the local network stack.
Sebastian Holzapfel, Matthäus Wander, Arno Wacker, Torben Weis
NCA4
2010 Towards peer-to-peer-based cryptanalysis
abstract
Modern cryptanalytic algorithms require a large amount of computational power. An approach to cope with this requirement is to distribute these algorithms among many computers and to perform the computation massively parallel. However, existing approaches for distributing cryptanalytic algorithms are based on a client/server or a grid architecture. In this paper we propose the usage of peer-to-peer (P2P) technology for distributed cryptanalytic calculations. Our contribution in this paper is three-fold: We first identify the challenges resulting from this approach and provide a classification of algorithms suited for P2P-based computation. Secondly, we discuss and classify some specific cryptanalytic algorithms and their suitability for such an approach. Finally we provide a new, fully decentralized approach for distributing such computationally intensive jobs. Our design takes special care about scalability and the possible untrustworthy nature of the participating peers.
Matthäus Wander, Arno Wacker, Torben Weis
LCN3
2008 Bootstrapping in Peer-to-Peer Systems
abstract
Peer-to-Peer systems have become a substantial element in computer networking. Distributing the load and splitting complex tasks are only some reasons why many developers have come to adopt this technology. However, all of them face a severe problem at the very beginning: setting up an overlay network, such that other clients can easily join it. With an empty peer cache common bootstrapping methods require some manually triggered actions for discovering a peer on the overlay. We therefore introduce an approach for an automated bootstrapping based on DDNS. In this paper we give detailed information about our protocol and document its efficiency and scalability.
Mirko Knoll, Arno Wacker, Gregor Schiele, Torben Weis
ICPADS4
2008 A NAT Traversal Mechanism for Peer-To-Peer Networks
abstract
In this demo we present our approach for establishing a communication channel between hosts behind a NAT-based router. To do so, we developed a peer-to-peer based variant of the STUN protocol using so-called superpeers. Using this protocol we determine the used NAT types for the hosts and select a suitable NAT traversal technique dynamically.
Arno Wacker, Gregor Schiele, Sebastian Holzapfel, Torben Weis
Peer-to-Peer Computing4
2007 Requirements of Peer-to-Peer-based Massively Multiplayer Online Gaming
abstract
Massively multiplayer online games have become increasingly popular. However, their operation is costly, as game servers must be maintained. To reduce these costs, we aim at providing a communication engine to develop massively multiplayer online games based on a peer-to-peer system. In this paper we analyze the requirements of such a system and present an overview of our current work.
Gregor Schiele, Richard Süselbeck, Arno Wacker, Jörg Hähner, Christian Becker 0001, Torben Weis
CCGRID6
2006 Customizable Pervasive Applications
abstract
Human behavior and housing resist every standardization effort. Many aspects such as different technical equipment, furniture, and usage patterns make our surroundings as individual as ourselves. Thus, the personalization of pervasive applications is a fundamental requirement. To enable the development of custom pervasive applications, we propose a software development process. This process is based on the successful process for modern desktop applications. There, developers create extensible applications and components. Customizers use the resulting artifacts to develop custom applications. Finally, users configure applications to their individual needs by adjusting predefined settings. To adopt this process for pervasive computing, we present a component system for developers, a graphical toolkit for customizers, and self-configuration algorithms to ease the deployment
Torben Weis, Marcus Handte, Mirko Knoll, Christian Becker 0001
PerCom1
2005 Self-stabilizing Publish/Subscribe Systems: Algorithms and Evaluation
Gero Mühl, Michael A. Jaeger, Klaus Herrmann 0001, Torben Weis, Andreas Ulbrich, Ludger Fiege
Euro-Par4
2004 Quality of Service in Middleware and Applications: A Model-Driven Approach
Torben Weis, Andreas Ulbrich, Kurt Geihs, Christian Becker 0001
EDOC1
2003 Quality of Service Engineering with UML, .NET, and CORBA
abstract
The concern for non-functional properties of software components and distributed applications has increased significantly in recent years. Non-functional properties are often subsumed under the term Quality of Service (QoS). It refers to quality aspects of a software component or service such as real-time response guarantees, availability and fault-tolerance, the degree of data consistency, the precision of some computation, or the level of security. Consequently, the specification and implementation of QoS mechanisms has become an important concern in the engineering of distributed applications. In this tutorial the attendees will learn how non-functional requirements can be engineered in a systematic way into applications on top of distribution platforms such as CORBA and .NET The tutorial focuses on two major subjects areas: (1) Specification of QoS properties and (2) implementation of QoS mechanisms in middleware. We present a comprehensive, model-driven approach. It starts with a platform-independent model (PIM) in UML that captures the application QoS requirements. This model is mapped by a tool to a platform-specific model (PSM) tailored for a specific middleware, which is extended with the corresponding QoS mechanisms. Finally, the PSM is translated to code. Participants in this tutorial will get a thorough understanding of general QoS requirements, QoS modeling alternatives and QoS mechanism integration in respect to popular distributed object middleware. Furthermore, we will discuss the pros and cons of CORBA and .NET for QoS engineering. A tool will be demonstrated that eases substantially the modeling stages and the code generation.
Torben Weis, Andreas Ulbrich, Kurt Geihs
ICSE1
2003 DotQoS - A QoS Extension for .NET Remoting
Andreas Ulbrich, Torben Weis, Kurt Geihs, Christian Becker 0001
IWQoS2