VLDB 2026 Research / reviewers in the wild / expert
Bert Lagaisse
dblp:49/6710
· DBLP profile ↗
22ranked-venue papers
1as first author
10since 2021 · last 2025
0000-0002-2543-6658ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 1 first-author · 4 since 2021Systems, architecture and hardware · 5 · 3 since 2021Security and privacy · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ICVul: A Well-labeled C/C++ Vulnerability Dataset with Comprehensive Metadata and VCCsabstractMachine learning-based software vulnerability detection requires high-quality datasets, which is essential for training effective models. To address challenges related to data label quality, diversity, and comprehensiveness, we constructed ICVul, a dataset emphasizing data quality and enriched with comprehensive metadata, including Vulnerability-Contributing Commits (VCCs). We began by filtering Common Vulnerabilities and Exposures from the NVD, retaining only those linked to GitHub fix commits. Then we extracted functions and files along with relevant metadata from these commits and used the SZZ algorithm to trace VCCs. To further enhance label reliability, we developed the ESC (Eliminate Suspicious Commit) technique, ensuring credible data labels. The dataset is stored in a relationallike database for improved usability and data integrity. Both ICVul and its construction framework are publicly accessible on GitHub, supporting research in related field. Chaomeng Lu, Toon Dehaene, Bert Lagaisse |
MSR | 4 |
| 2024 | Enhancing Effective Bidirectional Isolation for Function Fusion in Serverless ArchitecturesabstractServerless computing has emerged as a popular paradigm in modern cloud environments, offering flexibility and scalability to tenants. A serverless function might handle sensitive tenant data. Employing Trusted Execution Environment (TEE) techniques to protect such a function from untrusted cloud service providers is attractive for tenant privacy. However, this introduces response latency, thereby impacting the performance of function execution. This paper introduces Fundue, a serverless architecture with bidirectional isolation between tenant and cloud provider that achieves light-weight isolation of functions and reduces cold start latency by fusing functions. Fundue enables multiple functions uploaded by the same tenant to share a single execution environment embedded into the enclave. Fundue allocates separate memory for each serverless function within the execution environment and establishes robust isolation between functions through bounds checking mechanisms. We extensively evaluate Fundue with diverse workloads and representative serverless functions. Our results demonstrate a significant reduction in response latency of serverless function execution, ranging from 17.8% to 88.7% compared to AccTEE, an open-source two-way sandbox serverless framework. Additionally, Fundue mitigates vulnerabilities in existing execution environments, such as stack-based buffer overflows. Yingpeng Chen, Donghui Yu, Yuanyuan Zhang 0002, Bert Lagaisse |
Middleware | 5 |
| 2024 | A Self-Sovereign Identity Approach to Decentralized Access Control with Transitive DelegationsabstractIn this paper, we introduce a new decentralized access control framework with transitive delegation capabilities that tackles the performance and scalability limitations of the existing state-of-the-art solutions. In order to accomplish this, the proposed solution is anchored in the self-sovereign identity (SSI) paradigm, which embodies a distributed identity management system. By adopting this paradigm, we obviate slow cryptographic premises such as identity-based encryption (IBE) that were used in prior work. Furthermore, we enhance the existing verifiable credentials (VCs) from this paradigm by introducing our own decentralized permission objects to support the concept of transitive delegations. This concept allows delegates to further delegate their access to resources with the same or fewer privileges to other entities within the framework. This renders our solution suitable for diverse scenarios, including applications in decentralized building access management. To the best of our knowledge, we are the first to introduce the concept of transitive delegations in this paradigm. Finally, our performance experiments show a performance enhancement of three orders of magnitude compared to the prevailing state-of-the-art solutions. Pieter-Jan Vrielynck, Tim Van hamme, Rawad Ghostin, Bert Lagaisse, Davy Preuveneers, Wouter Joosen |
SACMAT | 4 |
| 2023 | BeauForT: Robust Byzantine Fault Tolerance for Client-Centric Mobile Web ApplicationsabstractIn recent years, part of the web is shifting to a client-centric, decentralized model where web clients become the leading execution environment for application logic and data storage. However, current solutions to build decentralized web applications with multiple distrusting parties often involve a decentralized backend of servers running a BFT protocol between them. Existing consensus protocols using either all-to-all communication, or leader-based gossip suffer from performance degradation in unstable network conditions. In this paper, we present BeauForT, a purely browser-based platform for decentralized BFT consensus in client-centric, community-driven applications. We propose a novel, optimistic, leaderless, gossip-based consensus protocol, tolerating Byzantine replicas, combined with a robust and efficient state-based synchronization protocol. This protocol makes BeauForT well suited for the decentralized client-centric web and its dynamic nature with many network disruptions or node failures. Kristof Jannes, Emad Heydari Beni, Bert Lagaisse, Wouter Joosen |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2021 | ThunQ: A Distributed and Deep Authorization Middleware for Early and Lazy Policy Enforcement in Microservice Applications
Martijn Sauwens, Emad Heydari Beni, Kristof Jannes, Bert Lagaisse, Wouter Joosen |
ICSOC | 4 |
| 2021 | Shared memory protection in a multi-tenant JVMabstractMulti-tenant Software-as-a-Service (SaaS) providers allow tenants to customize the application at different levels. When the customization involves tenant custom code and a single application instance is shared among multiple tenants, the issue of tenant isolation becomes critical. In common practice, tenant isolation, which amounts to protection of tenants against any interference and disturbance from each other, is performed by isolating tenant custom code in either a dedicated Virtual Machine (VM) or a dedicated container. Majid Makki, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
MPLR | 3 |
| 2021 | Thread-level resource consumption control of tenant custom code in a shared JVM for multi-tenant SaaS
Majid Makki, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
Future Gener. Comput. Syst. | 3 |
| 2021 | CryptDICE: Distributed data protection system for secure cloud data storage and computation
Ansar Rafique, Dimitri Van Landuyt, Emad Heydari Beni, Bert Lagaisse, Wouter Joosen |
Inf. Syst. | 4 |
| 2021 | SEQUOIA: A Middleware Supporting Policy-Based Access Control for Search and Aggregation in Data-Driven ApplicationsabstractApplication-level access control is a top priority when hardening software applications. In particular, run-time customization of access control policies and separation for concerns are becoming increasingly important. While these requirements are generally well-supported for request-response applications, there is a lack of support for data-focused operations, such as search or data aggregation, in a multi-tier architecture. Moreover, an ability to specify fine-grained access control policies is generally lacking for such applications. This puts at risk the security of organizations that employ existing and emerging database technologies and requires solutions that alleviate this issue. This paper approaches this issue through query rewriting. We present Sequoia, a data access middleware that enables attribute-based, application-level access control in data-driven applications. The middleware enforces external access control policies on data-focused operations such as search and aggregation queries by means of query rewriting based on dynamic run-time conditions. Sequoia provides run-time enforcement of policies that is scalable with regard to the database size. This paper presents an extensible architecture for both relational databases and document stores. It discusses the rewriting approach, and provides a formal verification of equivalencyand an extensive evaluation that shows that this approach scales better than the current state of practice and is an important track for future research. Jasper Bogaerts, Bert Lagaisse, Wouter Joosen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | OWebSync: Seamless Synchronization of Distributed Web ClientsabstractMany enterprise software services are adopting a fully web-based architecture for both internal line-of-business applications and for online customer-facing applications. Although wireless connections are becoming more ubiquitous and faster, mobile employees and customers are often offline due to expected or unexpected network disruptions. Nevertheless, continuous operation of the software is expected. This article presents OWebSync: a web-based middleware for data synchronization in interactive groupware with fast resynchronization of offline clients and continuous, interactive synchronization of online clients. To automatically resolve conflicts, OWebSync implements a fine-grained data synchronization model and leverages state-based Conflict-free Replicated Data Types. This middleware uses Merkle-trees embedded in the tree-structured data and virtual Merkle-tree levels to achieve the required interactive performance. Our comparative evaluation with available operation-based and delta-state-based middleware solutions shows that OWebSync is especially better in operating in and recovering from offline settings and network disruptions. In addition, OWebSync scales more efficiently over time, as it does not store version vectors or other meta-data for all past clients. Kristof Jannes, Bert Lagaisse, Wouter Joosen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2019 | Thread-Level CPU and Memory Usage Control of Custom Code in Multi-tenant SaaS
Majid Makki, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
ICSOC | 3 |
| 2019 | Infracomposer: Policy-driven adaptive and reflective middleware for the cloudification of simulation & optimization workflows
Emad Heydari Beni, Bert Lagaisse, Wouter Joosen |
J. Syst. Archit. | 2 |
| 2018 | Evaluation of Container Orchestration Systems for Deploying and Managing NoSQL Database ClustersabstractContainer orchestration systems, such as Docker Swarm, Kubernetes and Mesos, provide automated support for deployment and management of distributed applications as sets of containers. While these systems were initially designed for running load-balanced stateless services, they have also been used for running database clusters because of improved resilience attributes such as fast auto-recovery of failed database nodes, and location transparency at the level of TCP/IP connections between database instances. In this paper we evaluate the performance overhead of Docker Swarm and Kubernetes for deploying and managing NoSQL database clusters, with MongoDB as database case study. As the baseline for comparison, we use an OpenStack IaaS cloud that also allows attaining these improved resilience attributes although in a less automated manner. Eddy Truyen, Matt Bruzek, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
IEEE CLOUD | 4 |
| 2018 | A comparative study of workflow customization strategies: Quality implications for multi-tenant SaaS
Majid Makki, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
J. Syst. Softw. | 3 |
| 2018 | On the Performance Impact of Data Access Middleware for NoSQL Data Stores A Study of the Trade-Off between Performance and Migration CostabstractThe last few years have seen a drastic increase in the amount and the heterogeneity of NoSQL data stores. Consequently, exploration and comparison of these data stores have become difficult. Once chosen, it is hard to migrate to different data stores. Recently, a number of data access middleware platforms for NoSQL have emerged that provide access to different NoSQL data stores\nfrom standardized APIs. \n\nHowever, there are two key concerns related to: (i) the performance overhead introduced by these platforms,\nand (ii) the effort required to migrate between different data stores. \n\nIn this paper, we present two complementary studies that provide answers to the above mentioned concerns for three of the most mature data access middleware platforms: Impetus Kundera, Playorm, and Spring Data. First, we evaluate the performance overhead introduced by these platforms for the CRUD operations. Second, we compare the cost of migration with and without these platforms. \n\nOur study shows that, despite their similarity in design, these platforms are still substantially different performance-wise. Both studies are complementary as they show the trade-off inherent in adopting a data access middleware platform for NoSQL: by allowing some performance overhead, the developer gain benefits in terms of portability and easy migration across heterogeneous data stores. Ansar Rafique, Dimitri Van Landuyt, Bert Lagaisse, Wouter Joosen |
IEEE Trans. Cloud Comput. | 3 |
| 2015 | Entity-Based Access Control: supporting more expressive access control policiesabstractAccess control is an important part of security that restricts the actions that users can perform on resources. Policy models specify how these restrictions are formulated in policies. Over the last decades, we have seen several such models, including role-based access control and more recently, attribute-based access control. However, these models do not take into account the relationships between users, resources and entities and their corresponding properties. This limits the expressiveness of these models. In this work, we present Entity-Based Access Control (EBAC). EBAC introduces entities as a primary concept and takes into account both attributes and relationships to evaluate policies. In addition, we present Auctoritas. Auctoritas is a authorization system that provides a practical policy language and evaluation engine for EBAC. We find that EBAC increases the expressiveness of policies and fits the application domain well. Moreover, our evaluation shows that entity-based policies described in Auctoritas can be enforced with a low policy evaluation latency. Jasper Bogaerts, Maarten Decat, Bert Lagaisse, Wouter Joosen |
ACSAC | 3 |
| 2015 | Scalable and Secure Concurrent Evaluation of History-based Access Control PoliciesabstractMany of today's applications are deployed on large-scale distributed infrastructures to handle large amounts of users concurrently. When applying access control to such applications, the access control policies must be evaluated concurrently as well. However, for certain classes of policies such as history-based policies one access decision depends on the previous ones. As a result, concurrency can be exploited to achieve incorrect access decisions and privilege escalation. Moreover, general techniques for concurrency control are not able to scale to the size of current applications and at the same time provide the full consistency required for security. Therefore, we present an efficient concurrency control scheme specifically for access control. By leveraging the specific structure of a policy evaluation, this scheme is able to prevent incorrect decisions due to concurrency and at the same time scale to a large number of machines while incurring only a limited and bounded latency overhead. As such, this work facilitates the adoption of policy-based access control in realistic and large-scale applications. Maarten Decat, Bert Lagaisse, Wouter Joosen |
ACSAC | 2 |
| 2014 | Characterizing the performance of tenant data management in multi-tenant cloud authorization systemsabstractMulti-tenancy leads to improved efficiency, improved scalability, and lower costs. With the recent evolution of Cloud Computing and Software-as-a-Service (SaaS) in particular, a flexible and scalable multi-tenant architecture is becoming highly important. In multi-tenant applications, each tenant has its own users and administrators and tenants even tend to be divided into multiple subtenants. As the number of tenants grows, the number of users and amount of data grows, thus a scalable architecture for the access control system is needed. The question arises how to distribute the users and data over multiple database instances. In this paper we present a hierarchical data management approach, taking performance metrics into account, for structuring the storage of tenant data in large multi-tenant environments. We introduce a logical representation of the tenants, the tenant tree, and make a mapping to the physical storage by introducing three models for load-balancing. Next, we focus on how to efficiently locate the required data and introduce multiple search approaches. We characterize the impact on the performance both theoretically and experimentally. Experiments confirm that the theoretical analysis is in line with the experimental results. When the amount of data increases significantly, dividing the data over multiple datastores in an efficient way will eliminate the overhead and lead to a performance gain, especially if most of the data is located at the leaf nodes of the tenant tree. Pieter-Jan Maenhaut, Hendrik Moens, Maarten Decat, Jasper Bogaerts, Bert Lagaisse, Wouter Joosen, Veerle Ongenae, Filip De Turck |
NOMS | 5 |
| 2013 | Policy-driven customization of cross-organizational features in distributed service systemsabstractSUMMARY In a cross‐organizational context, software services are provided and consumed by different organizations. Ensuring that the non‐functional requirements of all the involved organizations are satisfied is hard to achieve in such a distributed and heterogeneous environment: the implementation of features, for example, security, is scattered across the services of multiple organizations. In this paper, we present a coordination architecture for flexible and policy‐driven composition of cross‐organizational features in distributed service systems. The underlying approach of this architecture is to specify the features and their composition at a higher level that abstracts the internal implementation mechanisms of the organizations involved. By means of feature composition policies, the organizations specify at a fine‐grained level which features are required and when they have to apply. Driven by these policies, our coordination middleware dynamically integrates the appropriate features throughout the cross‐organizational service composition in a consistent and efficient way. We have validated our architecture in a proof of concept showing limited performance overhead. Copyright © 2011 John Wiley & Sons, Ltd. Stefan Walraven, Bert Lagaisse, Eddy Truyen, Wouter Joosen |
Softw. Pract. Exp. | 2 |
| 2011 | A Generic Solution for Agile Run-Time Inspection Middleware
Wouter De Borger, Bert Lagaisse, Wouter Joosen |
Middleware | 2 |
| 2010 | Dynamic Composition of Cross-Organizational Features in Distributed Software Systems
Stefan Walraven, Bert Lagaisse, Eddy Truyen, Wouter Joosen |
DAIS | 2 |
| 2006 | True and Transparent Distributed Composition of Aspect-Components
Bert Lagaisse, Wouter Joosen |
Middleware | 1 |