VLDB 2026 Research / reviewers in the wild / expert
Brent Lagesse
dblp:97/1335
· DBLP profile ↗
16ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-0996-408XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 8 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Security and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Emulated Autoencoder: A Defense against CNN Evasion Attacks for Resource Constrained Devices and High Throughput Applications
Dat Le, Brent Lagesse |
SmartComp | 2 |
| 2025 | Toward Easier Development of Privacy-Preserving Mobile Crowdsensing ApplicationsabstractFully Homomorphic Encryption (FHE) schemes allow computations over encrypted data without access to the decryption key. This technique can be a valuable tool for building privacy into crowdsensing systems; however, many existing FHE implementations, such as Microsoft's SEAL, are difficult to implement into mobile applications. This paper presents a natively compiled Dart plugin that abstracts the underlying C/C++ SEAL library. The FHE Library plugin enables developers to access SEAL's full functionality within other Dart plugins and Flutter applications and is extensible to other encryption libraries. To evaluate the versatility of the plugin, we develop a Dart plugin to calculate several distance measures between two sets of encrypted inputs and we develop a Flutter application called GhostPeerShare. The Distance Measure plugin implements Kullback-Leibler Divergence, Bhattacharyya Coefficient, and Cramer Distance. GhostPeerShare demonstrates the use of a plugin by re-implementing Proof of Presence Share (PopShare), a mobile application that privately identifies similar videos recorded by users, as a Flutter application. Through these applications, we demonstrate that performance is similar to native applications and that utilizing FHE is more accessible to researchers developing crowdsensing applications. Jeffrey Murray Jr, Brent Lagesse |
MDM | 2 |
| 2024 | Thimblerig: A Game-Theoretic, Adaptive, Risk-limiting Security System for Cloud SystemsabstractA significant portion of organizations and applications host client facing servers on cloud-based systems. As the first line of access into a system’s services, these clientfacing servers have a significant attack surface from network adversaries. Once compromised, these systems may be used to send spam, mine crypto, launch DDoS attacks, or used for other nefarious purposes. We propose an adaptive moving target defense that uses game theory to optimize the security and cost to the cloud system. This system leverages the fault-tolerant capabilities of cloud systems with large numbers of client facing servers and the virtualization of these client facing servers by strategically crashing random systems. As a result, an attacker who has compromised a system loses access to it and incurs the cost of having to re-compromise the system once they notice it has been lost. This approach drastically limits the amount of time that an attacker can utilize compromised systems and raises the overall investment required for that time. We have demonstrated via simulation a 90% reduction in the amount of time that an attacker has control over a compromised system for realistic scenarios based on previous data collection of live systems. This approach is agnostic to the method of compromise, so it is even effective against zero-day attacks. Brent Lagesse |
NOMS | 2 |
| 2024 | The Diversity-Hire Narrative in CS: Sources, Impacts, and ResponsesabstractBackground : Affirmative action programs (AAPs) aim to increase the representation of people from historically underrepresented groups (HUGs) in the workforce, but can unintentionally signal that a person from a HUG was selected for their identity rather than their merit. We call this signal the diversity-hire narrative. Prior work has found that women hear the diversity-hire narrative during their computer science (CS) internships, but women and non-binary students' experiences surrounding the narrative are important to understand and have not been thoroughly explored. Christopher Perdriau, Vidushi Ojha, Kaitlynn T. Gray, Brent Lagesse, Colleen M. Lewis |
SIGCSE (1) | 4 |
| 2023 | The Diversity-Hire Narrative in CS: Sources, Impacts, and Mitigation StrategiesabstractBackground: The goal of affirmative action programs (AAPs) is to address the underrepresentation of people from historically underrepresented groups (HUGs) in the workforce. People who identify as women, Black or African American, Hispanic or Latinx/a/o/*, Native American, Native Alaskan, Native Hawai’ian, and/or Pacific Islander are considered to be a part of HUGs in computing. AAPs can unintentionally signal that a person from a HUG was selected for a position based on their gender or race/ethnicity rather than their merit [2, 3, 5, 6]. We call this signal the diversity-hire narrative. In computing, prior work has found that women hear the diversity-hire narrative during their computer science (CS) internships [4], but women’s experiences surrounding the narrative have not been thoroughly explored. Christopher Perdriau, Vidushi Ojha, Kaitlynn T. Gray, Brent Lagesse, Colleen M. Lewis |
ICER (2) | 4 |
| 2023 | Keyword Extraction From Specification Documents for Planning Security MechanismsabstractSoftware development companies heavily invest both time and money to provide post-production support to fix security vulnerabilities in their products. Current techniques identify vulnerabilities from source code using static and dynamic analyses. However, this does not help integrate security mechanisms early in the architectural design phase. We develop VDocScan, a technique for predicting vulnerabilities based on specification documents, even before the development stage. We evaluate VDocScan using an extensive dataset of CVE vulnerability reports mapped to over 3600 product documentations. An evaluation of 8 CWE vulnerability pillars shows that even interpretable whitebox classifiers predict vulnerabilities with up to 61.1% precision and 78% recall. Further, using strategies to improve the relevance of extracted keywords, addressing class imbalance, segregating products into categories such as Operating Systems, Web applications, and Hardware, and using blackbox ensemble models such as the random forest classifier improves the performance to 96% precision and 91.1% recall. The high precision and recall shows that VDocScan can anticipate vulnerabilities detected in a product's lifetime ahead of time during the Design phase to incorporate necessary security mechanisms. The performance is consistently high for vulnerabilities with the mode of introduction: architecture and design. Jeffy Jahfar Poozhithara, Hazeline U. Asuncion, Brent Lagesse |
ICSE | 3 |
| 2023 | Computing Specializations: Perceptions of AI and Cybersecurity Among CS StudentsabstractArtificial intelligence (AI) and cybersecurity are in-demand skills, but little is known about what factors influence computer science (CS) undergraduate students' decisions on whether to specialize in AI or cybersecurity and how these factors may differ between populations. In this study, we interviewed undergraduate CS majors about their perceptions of AI and cybersecurity. Qualitative analyses of these interviews show that students have narrow beliefs about what kind of work AI and cybersecurity entail, the kinds of people who work in these fields, and the potential societal impact AI and cybersecurity may have. Specifically, students tended to believe that all work in AI requires math and training models, while cybersecurity consists of low-level programming; that innately smart people work in both fields; that working in AI comes with ethical concerns; and that cybersecurity skills are important in contemporary society. Some of these perceptions reinforce existing stereotypes about computing and may disproportionately affect the participation of students from groups historically underrepresented in computing. Our key contribution is identifying beliefs that students expressed about AI and cybersecurity that may affect their interest in pursuing the two fields and may, therefore, inform efforts to expand students' views of AI and cybersecurity. Expanding student perceptions of AI and cybersecurity may help correct misconceptions and challenge narrow definitions, which in turn can encourage participation in these fields from all students. Vidushi Ojha, Christopher Perdriau, Brent Lagesse, Colleen M. Lewis |
SIGCSE (1) | 3 |
| 2022 | Towards Lightweight Detection of Design Patterns in Source CodeabstractIdentifying which design patterns exist in source code helps maintenance engineers better understand source code and determine if new requirements can be satisfied.Automated techniques for finding design patterns generally require much time to label training datasets or to specify rules/queries for each pattern, and is difficult to extend support to secure design patterns (SDPs) and combination patterns.To address these challenges, we introduce PatternScout, a technique for automatic generation of SPARQL queries from UML Class diagrams and Sequence diagrams.These queries are used to detect patterns in the source code.Our results indicate that PatternScout can detect object-oriented design patterns (OODP) with accuracy that is comparable or better than existing techniques.It can also generate queries for SDPs that can be represented as UML Class diagrams. Jeffy Jahfar Poozhithara, Hazeline U. Asuncion, Brent Lagesse |
SEKE | 3 |
| 2020 | Detecting hidden webcams with delay-tolerant similarity of simultaneous observation
Kevin Wu, Brent Lagesse |
Pervasive Mob. Comput. | 2 |
| 2019 | Do You See What I See?Detecting Hidden Streaming Cameras Through Similarity of Simultaneous ObservationabstractSmall, low-cost, wireless cameras are becoming increasingly commonplace making surreptitious observation of people more difficult to detect. Previous work in detecting hidden cameras has only addressed limited environments in small spaces where the user has significant control of the environment. To address this problem in a less constrained scope of environments, we introduce the concept of similarity of simultaneous observation where the user utilizes a camera (Wi-Fi camera, camera on a mobile phone or laptop) to compare timing patterns of data transmitted by potentially hidden cameras and the timing patterns that are expected from the scene that the known camera is recording. To analyze the patterns, we applied several similarity measures and demonstrated an accuracy of over 87% and and F1 score of 0.88 using an efficient threshold-based classification. Furthermore, we used our data set to train a neural network and saw improved results with accuracy as high as 97% and an F1 score over 0.95 for both indoors and outdoors settings. From these results, we conclude that similarity of simultaneous observation is a feasible method for detecting hidden wireless cameras that are streaming video of a user. Our work removes significant limitations that have been put on previous detection methods. Kevin Wu, Brent Lagesse |
PerCom | 2 |
| 2017 | Limited Use Cryptographic Tokens in Securing Ephemeral Cloud Servers
Brent Lagesse |
ICISSP | 2 |
| 2016 | Special issue on "Internet of Things: Research challenges and Solutions"
Eleonora Borgia, Danielo Goncalves Gomes, Brent Lagesse, Rodger Lea, Daniele Puccinelli |
Comput. Commun. | 3 |
| 2009 | Trust and Security in Dynamic SystemsabstractAs pervasive systems become more prevalent, the need to protect these systems increases. In staying with the ideals of pervasive computing, we want to provide protection for these systems while remaining as unobtrusive to the user. It is seldom possible to guarantee the trustworthiness of users and resources. As a result, we devise systems designed to elicit the trustworthiness of users and resources and adapt access patterns based on this information. We present our mechanisms for determining trustworthiness and illustrates their suitability in pervasive systems through simulation results. Brent Lagesse |
PerCom | 1 |
| 2009 | DTT: A Distributed Trust Toolkit for Pervasive SystemsabstractEffective security mechanisms are essential to the widespread deployment of pervasive systems. Much of the research focus on security in pervasive computing has revolved around distributed trust management. While such mechanisms are effective in specific environments, there is no generic framework for deploying and extending these mechanisms over a variety of pervasive systems. We present the design and implementation of a novel framework called distributed trust toolkit (DTT), for implementing and evaluating trust mechanisms in pervasive systems. The DTT facilitates the extension and adaptation of trust mechanisms by abstracting trust mechanisms into interchangeable components. Furthermore, the DTT provides a set of tools and interfaces to ease implementation of trust mechanisms and facilitate their execution on a variety of platforms and networks. In addition to the adaptability and extensibility provided by this design, we demonstrate through simulation that use of DTT improves utilization of resources and enhances performance of existing trust mechanisms in pervasive systems. We are currently developing an implementation of the DTT that can be easily deployed in pervasive environments. Brent Lagesse, Mohan Kumar, Justin Mazzola Paluska, Matthew Wright 0001 |
PerCom | 1 |
| 2008 | AREX: An Adaptive System for Secure Resource Access in Mobile P2P SystemsabstractIn open environments, such as mobile peer-to-peer systems, participants may need to access resources from unknown users. A critical security concern in such systems is the access of faulty resources, thereby wasting the requester's time and energy and possibly causing damage to her system. A common approach to mitigating the problem involves reputation mechanisms; however, since reputation relies on cooperation, a reputation mechanism's effectiveness can be significantly diminished in hostile environments. Reputation systems also require substantial communication among peers leading to: i) vulnerability to errors caused by intermittent connectivity; ii) message delivery disruptions caused by malicious peers; and iii) energy sapping message overheads. In this paper, we present AREX, a low-cost, adaptive mechanism designed to provide security for peers in hostile and uncertain environments, which are common in mobile P2P systems. AREX features an adaptive exploration strategy that increases the system's utility for benign peers and decreases the systempsilas utility for malicious peers. AREX reduces vulnerabilities and energy costs by operating without communication between peers. Through simulation, we demonstrate AREX's ability to reduce energy costs, protect benign peers, and diminish malicious peers' motivation to attack in a variety of hostile environments. Brent Lagesse, Mohan Kumar, Matthew Wright 0001 |
Peer-to-Peer Computing | 1 |
| 2008 | A Novel Utility and Game-Theoretic Based Security Mechanism for Mobile P2P SystemsabstractResearch on security in peer-to-peer (P2P) systems is dominated by reputation-based solutions. These solutions propagate opinions about other peers in order to help identify the best set of peers to utilize. In this paper, we model peers with utility functions and use those functions to examine the case in which an individual peer participates in an unfamiliar and untrusted system, similar to one in which a mobile peer can enter when moving into a new location. We additionally introduce a novel security mechanism for P2P systems called resource exploration in order to mitigate the problems inherent in reputation-based systems and analyze its effect on a 2-player game (between an attacker and the benign peer). Brent Lagesse, Mohan Kumar |
PerCom | 1 |