VLDB 2026 Research / reviewers in the wild / expert
Ioannis Papagiannis
dblp:45/4905
· DBLP profile ↗
8ranked-venue papers
1as first author
1since 2021 · last 2023
0009-0005-2304-3497ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Security and privacy · 2Systems, architecture and hardware · 1Computer networks · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Software maintenance and evolution · 56% Compilers and program optimization · 44% | |
| Network and information security
3 papers |
Privacy and data protection · 52% Authentication and access control · 34% Web and mobile security · 10% | |
| Databases, data mining, and information retrieval
2 papers |
Distributed and cloud data management · 55% Data stream processing · 46% |
Topics — the 6 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Compilers and program optimization
dead code elimination |
0.7 | 1 | 2023 | Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023 |
Software maintenance and evolution
software maintenance |
0.7 | 1 | 2023 | Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023 |
Privacy and data protection › privacy-enhancing technologies
data deletion |
0.4 | 1 | 2020 | DELF: Safeguarding deletion correctness in Online Social Networks · USENIX Security Symposium 2020 |
Authentication and access control
authorization |
0.3 | 1 | 2017 | IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks · IEEE Symposium on Security and Privacy 2017 |
Software maintenance and evolution
software ecosystems |
0.2 | 1 | 2023 | Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023 |
Web and mobile security
online social network security |
0.1 | 1 | 2017 | IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks · IEEE Symposium on Security and Privacy 2017 |
Methods — techniques the papers use, named apart from their topics
static analysis · 0.7automated code removal · 0.7invariant learning · 0.3dynamic enforcement · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated DataabstractSoftware constantly evolves in response to user needs: new features are built, deployed, mature and grow old, and eventually their usage drops enough to merit switching them off. In any large codebase, this feature lifecycle can naturally lead to retaining unnecessary code and data. Removing these respects users’ privacy expectations, as well as helping engineers to work efficiently. In prior software engineering research, we have found little evidence of code deprecation or dead-code removal at industrial scale. We describe Systematic Code and Asset Removal Framework (SCARF), a product deprecation system to assist engineers working in large codebases. SCARF identifies unused code and data assets and safely removes them. It operates fully automatically, including committing code and dropping database tables. It also gathers developer input where it cannot take automated actions, leading to further removals. Dead code removal increases the quality and consistency of large codebases, aids with knowledge management and improves reliability. SCARF has had an important impact at Meta. In the last year alone, it has removed petabytes of data across 12.8 million distinct assets, and deleted over 104 million lines of code. Will Shackleton, Katriel Cohn-Gordon, Peter C. Rigby, Rui Abreu 0001, James Gill, Nachiappan Nagappan, Karim Nakad, Ioannis Papagiannis, Luke Petre, Giorgi Megreli, Patrick Riggs, James Saindon |
ESEC/SIGSOFT FSE | 8 |
| 2020 | DELF: Safeguarding deletion correctness in Online Social Networks
Katriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova, Benoît Reitz, Benjamin Strahs, Daniel Obenshain, Paul Pearce, Ioannis Papagiannis, Available Media |
USENIX Security Symposium | 9 |
| 2017 | IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social NetworksabstractAuthorization bugs, when present in online social networks, are usually caused by missing or incorrect authorization checks and can allow attackers to bypass the online social network's protections. Unfortunately, there is no practical way to fully guarantee that an authorization bug will never be introduced-even with good engineering practices-as a web application and its data model become more complex. Unlike other web application vulnerabilities such as XSS and CSRF, there is no practical general solution to prevent missing or incorrect authorization checks. In this paper we propose Invariant Detector (IVD), a defense-in-depth system that automatically learns authorization rules from normal data manipulation patterns and distills them into likely invariants. These invariants, usually learned during the testing or pre-release stages of new features, are then used to block any requests that may attempt to exploit bugs in the social network's authorization logic. IVD acts as an additional layer of defense, working behind the scenes, complementary to privacy frameworks and testing. We have designed and implemented IVD to handle the unique challenges posed by modern online social networks. IVD is currently running at Facebook, where it infers and evaluates daily more than 200,000 invariants from a sample of roughly 500 million client requests, and checks the resulting invariants every second against millions of writes made to a graph database containing trillions of entities. Thus far IVD has detected several high impact authorization bugs and has successfully blocked attempts to exploit them before code fixes were deployed. Paul Marinescu, Chad Parry, Marjori Pomarole, Yuan Tian 0001, Patrick Tague, Ioannis Papagiannis |
IEEE Symposium on Security and Privacy | 6 |
| 2016 | BrowserFlow: Imprecise Data Flow Tracking to Prevent Accidental Data Disclosure
Ioannis Papagiannis, Pijika Watcharapichat, Divya Muthukumaran, Peter R. Pietzuch |
Middleware | 1 |
| 2014 | Information Flow Control for Secure Cloud ComputingabstractSecurity concerns are widely seen as an obstacle to the adoption of cloud computing solutions. Information Flow Control (IFC) is a well understood Mandatory Access Control methodology. The earliest IFC models targeted security in a centralised environment, but decentralised forms of IFC have been designed and implemented, often within academic research projects. As a result, there is potential for decentralised IFC to achieve better cloud security than is available today. In this paper we describe the properties of cloud computing-Platform-as-a-Service clouds in particular-and review a range of IFC models and implementations to identify opportunities for using IFC within a cloud computing context. Since IFC security is linked to the data that it protects, both tenants and providers of cloud services can agree on security policy, in a manner that does not require them to understand and rely on the particulars of the cloud software stack in order to effect enforcement. Jean Bacon, David M. Eyers, Thomas Pasquier, Jatinder Singh, Ioannis Papagiannis, Peter R. Pietzuch |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2011 | SafeWeb: A Middleware for Securing Ruby-Based Web Applications
Petr Hosek 0001, Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, David Evans 0002, Brian Shand, Jean Bacon, Peter R. Pietzuch |
Middleware | 3 |
| 2010 | Distributed Middleware Enforcement of Event Flow Security Policy
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch |
Middleware | 2 |
| 2010 | DEFCON: High-Performance Event Processing with Information Security
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch |
USENIX ATC | 2 |