Fabien Dagnat

dblp:60/6389 · DBLP profile ↗
← Back
15ranked-venue papers
0as first author
5since 2021 · last 2025
0000-0002-2419-7587ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 3 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Towards a Constraint-Driven Deployment Process for Cloud-Native Applications
abstract
Cloud-native deployments are typically ad-hoc and fragmented, leading to repeated misconfigurations and increased security risk. A challenge that arises often in modern deployment processes is the use of diverse heterogeneous technologies, such as Infrastructure-as-Code frameworks and cloud-specific tools. This causes a technological lock-in, making migration, adoption of alternative solutions, and supporting multi-cloud environments difficult. Another issue that further complicates current deployment processes is the collaboration of multiple actors during the process, such as developers, cloud architects, and business decision-makers whose roles are not well defined.To address these challenges, we advocate for a constraint-based approach of deployment. We emphasize security and compliance where constraints are declarative and treated as first-class inputs. This process would enable the specification of high-level constraints (e.g. security, cost, legal, etc.) and technical requirements in a unified and structured manner. This makes deployments portable across environments and cloud providers, auditable, and resilient to evolution. By introducing clear role separation and constraints validation, our approach promotes accountability while reducing the cognitive load on individual deployment actors.We propose a framework that enables actors involved in the deployment to specify constraints at various stages (architecture level, implementation level, etc.). These constraints are evaluated and verified by a constraint solver, and results into a set of feasible deployment options. Deployment scripts are generated from one of the feasible deployments in order to deploy the application. It is worth stressing that our intention is not to replace existing deployment workflows, but rather to provide a complementary approach.
Ouail Derghal, Jean-Christophe Bach, Fabien Dagnat
IC2E3
2024 Maintaining Security Consistency During System Development with Security-Oriented Model Federation
abstract
Multi-modeling is an approach within the MDE realm that promotes the development of complex systems by decomposing them in sets of heterogeneous models. These models are defined using different modeling languages and constructed using diverse tools. They represent different but often interdependent views. However, the models of a system are far from being static. They change to accommodate new requirements, functionality improvements, bug fixes, and other evolution events. These changes represent a challenge w.r.t. consistency. This is especially true in security-critical scenarios. Indeed, security information is often integrated within the systems models so that security requirements are met following what is called "security-by-design". In such scenarios, the security concern of the systems models must remain consistent across changes so that security properties continue to hold.
Chahrazed Boudjemila, Fabien Dagnat, Salvador Martínez Perez
ICSSP2
2024 10 years of Model Federation with Openflexo: Challenges and Lessons Learned
abstract
In the context of complex system development, heterogeneous modeling responds to the need to integrate several domains. This need requires the use of the most appropriate formalism and tooling for each domain to be efficient. Model federation promotes the semantic interoperability of heterogeneous models by providing the means to reify correspondences between different model elements, add custom behaviors and bridge the gap between technological spaces. As such, it can be used as an infrastructure to address many different system engineering problems. This is what we have been doing for over a decade, as part of a close collaboration between a small software engineering startup and academia. This paper reports on this experience.
Jean-Christophe Bach, Antoine Beugnard, Joël Champeau, Fabien Dagnat, Sylvain Guérin, Salvador Martínez Perez
MODELS4
2022 How IT Infrastructures Break: Better Modeling for Better Risk Management
Benjamin Somers, Fabien Dagnat, Jean-Christophe Bach
CRiSIS2
2021 PAMELA: An annotation-based Java modeling framework
Sylvain Guérin, Guillaume Polet, Caine Silva, Joël Champeau, Jean-Christophe Bach, Salvador Martínez Perez, Fabien Dagnat, Antoine Beugnard
Sci. Comput. Program.7
2018 [Research Paper] Combining Obfuscation and Optimizations in the Real World
abstract
Code obfuscation is the de facto standard to protect intellectual property when delivering code in an unmanaged environment. It relies on additive layers of code tangling techniques, white-box encryption calls and platform-specific or tool-specific countermeasures to make it harder for a reverse engineer to access critical pieces of data or to understand core algorithms. The literature provides plenty of different obfuscation techniques that can be used at compile time to transform data or control flow in order to provide some kind of protection against different reverse engineering scenarii. Scheduling code transformations to optimize a given metric is known as the pass scheduling problem, a problem known to be NP-hard, but solved in a practical way using hard-coded sequences that are generally satisfactory. Adding code obfuscation to the problem introduces two new dimensions. First, as a code obfuscator needs to find a balance between obfuscation and performance, pass scheduling becomes a multi-criteria optimization problem. Second, obfuscation passes transform their inputs in unconventional ways, which means some pass combinations may not be desirable or even valid. This paper highlights several issues met when blindly chaining different kind of obfuscation and optimization passes, emphasizing the need of a formal model to combine them. It proposes a non-intrusive formalism to leverage on sequential pass management techniques. The model is validated on real-world scenarii gathered during the development of an industrial-strength obfuscator on top of the LLVM compiler infrastructure.
Serge Guelton, Adrien Guinet, Pierrick Brunet, Juan Manuel Martinez Caamaño, Fabien Dagnat, Nicolas Szlifierski
SCAM5
2018 Bridging the Gap Between Informal Requirements and Formal Specifications Using Model Federation
Fahad Rafique Golra, Fabien Dagnat, Jeanine Souquières, Imen Sayar, Sylvain Guérin
SEFM2
2017 Continuous Process Compliance Using Model Driven Engineering
Fahad Rafique Golra, Fabien Dagnat, Reda Bendraou, Antoine Beugnard
MEDI2
2016 Using free modeling as an agile method for developing domain specific modeling languages
Fahad Rafique Golra, Antoine Beugnard, Fabien Dagnat, Sylvain Guérin, Christophe Guychard
MoDELS3
2016 Continuous Requirements Engineering Using Model Federation
abstract
Researchers in software engineering have been striving to produce new methods to improve the quality of development methodologies to consequently produce quality products. Proposition of iterative and evolutionary approaches was triggered by the realization that requirements engineering is not confined to the initial phases of software development only. With this shift of perspective, requirements engineering has become more or less a continuous process in software development lifecycles. We believe that existing requirements engineering approaches and associated tooling leave a room for improvement in putting 'continuity' into practice. A continuous requirements engineering methodology needs to take into account different concerns of all the stakeholders involved in the process. Approaches like KAOS bring the multi-view nature of requirements modeling in focus by using different views for goal, responsibility, object and operation modeling. We argue that a multi-view approach, maintaining a dynamic link between the requirement models and multiple sources of requirements, can offer a better support for continuous requirements engineering methodology. In this paper, we expand on this argument and present the early findings with the associated in progress tooling support.
Fahad Rafique Golra, Antoine Beugnard, Fabien Dagnat, Sylvain Guérin, Christophe Guychard
RE3
2016 Safe reconfiguration of Coqcots and Pycots components
Jérémy Buisson, Fabien Dagnat, Elena Leroux, Sebastien Martinez
J. Syst. Softw.2
2012 Generation of dynamic process models for multi-metamodel applications
abstract
Multi-metamodel application development processes have to deal with specific needs including flexible support for structured artifacts like models, multi-layered modeling support and dynamic process updates. In order to deal with the requirements of dynamic process updates and multi-layered modeling support, we propose to model the processes in multiple abstraction levels. The use of conditions on structured artifacts, considered as models, allows enhanced activity interactions, specifically for iterative interactions. This endeavor presented as CAMA Process Modeling Framework (CPMF) counts towards the greater goal of automation of software development processes in the future.
Fahad Rafique Golra, Fabien Dagnat
ICSSP2
2011 The lazy initialization multilayered modeling framework
abstract
Lazy Initialization Multilayer Modeling (LIMM) is an object oriented modeling language targeted to the declarative definition of Domain Specific Languages (DSLs) for Model Driven Engineering. It focuses on the precise definition of modeling frameworks spanning over multiple layers. In particular, it follows a two dimensional architecture instead of the linear architecture followed by many other modeling frameworks. The novelty of our approach is to use lazy initialization for the definition of mapping between different modeling abstractions, within and across multiple layers, hence providing the basis for exploiting the potential of metamodeling.
Fahad Rafique Golra, Fabien Dagnat
ICSE2
2010 ReCaml: execution state as the cornerstone of reconfigurations
abstract
To fix bugs or to enhance a software system without service disruption, one has to update it dynamically during execution. Most prior dynamic software updating techniques require that the code to be changed is not running at the time of the update. However, this restriction precludes any change to the outermost loops of servers, OS scheduling loops and recursive functions. Permitting a dynamic update to more generally manipulate the program's execution state, including the runtime stack, alleviates this restriction but increases the likelihood of type errors. In this paper we present ReCaml, a language for writing dynamic updates to running programs that views execution state as a delimited continuation. ReCaml includes a novel feature for introspecting continuations called match_cont which is sufficiently powerful to implement a variety of updating policies. We have formalized the core of ReCaml and proved it sound (using the Coq proof assistant), thus ensuring that state-manipulating updates preserve type-safe execution of the updated program. We have implemented ReCaml as an extension to the Caml bytecode interpreter and used it for several examples.
Jérémy Buisson, Fabien Dagnat
ICFP2
2008 Experiments with Fractal on Modular Reflection
abstract
In most reflective systems, the model of reflection objects often mirrors (a part of) the metamodel of the system. As a result, reflection is commonly tightly bound to the rest of the system. In this paper, we investigate the loosening of that coupling. With the rise of domain-specific modeling the need for separation of concerns and reuse when designing metamodels become critical. Therefore, we advocate the use of general design patterns abstracting the details of modeling languages when working on cross-cutting concerns (such as reflection) of a metamodel. Once the abstract patterns for reflection are built, they are mapped onto concrete modeling languages thanks to model engineering tools. In this paper, we apply this approach to the fractal component model. Following this process, reflection mechanisms built at the abstract level are straightforwardly reused and the resulting reflection system gains modularity.
Jérémy Buisson, Fabien Dagnat
SERA2