VLDB 2026 Research / reviewers in the wild / expert
Charles Morisset
dblp:98/4006
· DBLP profile ↗
21ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0001-9559-3352ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LLMs as PDPs Within a Smart-Home Environment: Accuracy, Ambiguity, and Latency [Work in Progress Paper]
Zachary Edwards, Charles Morisset |
SACMAT | 2 |
| 2025 | Towards Explainable Access Control [BlueSky Paper]abstractAccess control (AC) systems play an important role in ensuring security by regulating how resources are accessed, protecting sensitive information, and maintaining system integrity. Their complexity arises not only from diverse policies and mechanisms but also from the involvement of multiple stakeholders, including resource owners, administrators, and end-users. Taking inspiration from explainable AI and explainable security, we define the first model of access control explainability, as a quality measure of the explanation graph constructed around the decisions made within the AC system. We then explore the literature to identify how existing work can be integrated as explanatory processes. Finally, we leverage our framework to articulate three open research challenges: the collection and interpretation of AC decisions, the effective construction of AC explanation graphs, and the definition of meaningful and computationally efficient explanation quality metrics. Gelareh Hasel Mehri, Charles Morisset, Nicola Zannone |
SACMAT | 2 |
| 2023 | Impact of Using a Privacy Model on Smart Buildings Data for CO2 Prediction
Marlon P. da Silva, Henry C. Nunes, Charles V. Neu, Luana T. Thomas, Avelino Francisco Zorzo, Charles Morisset |
DBSec | 6 |
| 2022 | Threat Modeling for Machine Learning-Based Network Intrusion Detection SystemsabstractNetwork Intrusion Detection Systems (NIDS) monitor networking environments for suspicious events that could compromise the availability, integrity, or confidentiality of the network’s resources. To ensure NIDSs play their vital roles, it is necessary to identify how they can be attacked by adopting a viewpoint similar to the adversary to identify vulnerabilities and defenses hiatus. Accordingly, effective countermeasures can be designed to thwart any potential attacks. Machine learning (ML) approaches have been adopted widely for network anomaly detection. However, it has been found that ML models are vulnerable to adversarial attacks. In such attacks, subtle perturbations are inserted to the original inputs at inference time in order to evade the classifier detection or at training time to degrade its performance. Yet, modeling adversarial attacks and the associated threats of employing the machine learning approaches for NIDSs was not addressed. One of the growing challenges is to avoid ML-based systems’ diversity and ensure their security and trust. In this paper, we conduct threat modeling for ML-based NIDS using STRIDE and Attack Tree approaches to identify the potential threats on different levels. We model the threats that can be potentially realized by exploiting vulnerabilities in ML algorithms through a simplified structural attack tree. To provide holistic threat modeling, we apply the STRIDE method to systems’ data flow to uncover further technical threats. Our models revealed a noticing of 46 possible threats to consider. These presented models can help to understand the different ways that a ML-based NIDS can be attacked; hence, hardening measures can be developed to prevent these potential attacks from achieving their goals. Huda Ali Alatwi, Charles Morisset |
IEEE Big Data | 2 |
| 2022 | Simple and Efficient Identification of Personally Identifiable Information on a Public WebsiteabstractPersonally Identifiable Information (PII) is a key concept in privacy regulation. This form of information can provide revealing information about individuals, which may be collected and used for malicious purposes, such as social engineering and identity theft [1]. Consequently, privacy preserving legislations, such as GDPR place the responsibility of appropriately handling PII onto organisations who may process large amounts of personal data as part of their day to day operations. Therefore, it is necessary to develop processes that can provide privacy assurances but also to do so with increased automation and reliability [2]. This work will focus on assessing the ability of the Natural Language Processing tool, sentiment analysis and text classification algorithms to detect PII automatically, reliably and without too much complexity. To achieve this a dataset containing web pages from Newcastle University’s website, with a focus on staff profiles was created and manually labelled to indicate which sentences contained PII. The dataset was then used to train three text classification algorithms: Multinominal Naïve Bayes, Random Forest Classifier and LSTM model in order to predict the labels of an unseen portion of the dataset. The algorithms all performed well at detecting PII, with Random Forest achieving the highest accuracy at 96% and 96% F1-Score. Nevertheless, the models all mislabelled more sentences containing PII as not containing PII, than those which did not contain PII but were labelled as doing so. Caitlin Brown, Charles Morisset |
IEEE Big Data | 2 |
| 2019 | A framework for the extended evaluation of ABAC policiesabstractA main challenge of attribute-based access control (ABAC) is the handling of missing information. Several studies have shown that the way standard ABAC mechanisms, e.g. based on XACML, handle missing information is flawed, making ABAC policies vulnerable to attribute-hiding attacks. Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation, where the evaluation of a query considers all queries that can be obtained by extending the initial query. This method counters attribute-hiding attacks, but a naïve implementation is intractable, as it requires an evaluation of the whole query space. In this paper, we present a framework for the extended evaluation of ABAC policies. The framework relies on Binary Decision Diagram (BDDs) data structures for the efficient computation of the extended evaluation of ABAC policies. We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation, respectively. We illustrate our framework using three real-world policies, which would be intractable with the original method but which are analyzed in seconds using our framework. Charles Morisset, Tim A. C. Willemse, Nicola Zannone |
Cybersecur. | 1 |
| 2018 | VisABAC: A Tool for Visualising ABAC Policies
Charles Morisset |
ICISSP | 1 |
| 2018 | Efficient Extended ABAC EvaluationabstractA main challenge of attribute-based access control (ABAC) is the handling of missing information. Several studies show that the way standard ABAC mechanisms (e.g., XACML) handle missing information is flawed, making ABAC policies vulnerable to attribute-hiding attacks. Recent work addressed the problem of missing information in ABAC by introducing the notion of extended evaluation, where the evaluation of a query considers all possible ways of extending that query. This method counters attribute-hiding attacks, but a naive implementation is intractable, as it requires an evaluation of the whole query space. In this paper, we present an efficient extended ABAC evaluation method that relies on the encoding of ABAC policies as multiple Binary Decision Diagrams (BDDs), and on the specification of query constraints to avoid including the evaluation of queries that do not represent a valid state of the system. We illustrate our approach on two real-world case studies, which would be intractable with the original method and are analyzed in seconds with our method. Charles Morisset, Tim A. C. Willemse, Nicola Zannone |
SACMAT | 1 |
| 2016 | Modeling and analysis of influence power for information security decisions
Iryna Yevseyeva, Charles Morisset, Aad P. A. van Moorsel |
Perform. Evaluation | 2 |
| 2015 | On Missing Attributes in Access Control: Non-deterministic and Probabilistic Attribute RetrievalabstractAttribute Based Access Control (ABAC) is becoming the reference model for the specification and evaluation of access control policies. In ABAC policies and access requests are defined in terms of pairs attribute names/values. The applicability of an ABAC policy to a request is determined by matching the attributes in the request with the attributes in the policy. Some languages supporting ABAC, such as PTaCL or XACML 3.0, take into account the possibility that some attributes values might not be correctly retrieved when the request is evaluated, and use complex decisions, usually describing all possible evaluation outcomes, to account for missing attributes. Jason Crampton, Charles Morisset, Nicola Zannone |
SACMAT | 2 |
| 2015 | Probabilistic cost enforcement of security policiesabstractThis paper presents a formal framework for run-time enforcement mechanisms, or monitors, based on probabilistic input/output automata [Task-structured probabilistic I/O automata, Technical Report MIT-CSAIL-TR-2006-060, 2006; Proceedings of the 8th International Workshop on Discrete Event Systems , 2006, pp. 207–214], which allows for the modeling of complex and interactive systems. We associate with each trace of a monitored system (i.e., a monitor interposed between a system and an environment) a probability and a real number that represents the cost that the actions appearing on the trace incur on the monitored system. This allows us to calculate the probabilistic (expected) cost of the monitor and the monitored system, which we use to classify monitors, not only in the typical sense, as sound and transparent [ ACM Transactions on Information and System Security 12 (3) (2009), 1–41], but also at a more fine-grained level, as cost-optimal or cost-efficient. We show how a cost-optimal monitor can be built using information about cost and the probabilistic future behavior of the system and the environment, showing how deeper knowledge of a system can lead to construction of more efficient security mechanisms. Yannis Mallios, Lujo Bauer, Dilsun Kirli Kaynar, Fabio Martinelli, Charles Morisset |
J. Comput. Secur. | 5 |
| 2014 | Quantitative Workflow Resiliency
John C. Mace, Charles Morisset, Aad P. A. van Moorsel |
ESORICS (1) | 2 |
| 2014 | Reduction of access control decisionsabstractAccess control has been proposed as "the" solution to prevent unauthorized accesses to sensitive system resources. Historically, access control models use a two-valued decision set to indicate whether an access should be granted or denied. Many access control models have extended the two-valued decision set to indicate, for instance, whether a policy is applicable to an access query or an error occurred during policy evaluation. Decision sets are often coupled with operators for combining decisions from multiple applicable policies. Although a larger decision set is more expressive, it may be necessary to reduce it to a smaller set in order to simplify the complexity of decision making or enable comparison between access control models. Moreover, some access control mechanisms like XACML~v3 uses more than one decision set. The projection from one decision set to the other may result in a loss of accuracy, which can affect the final access decision. In this paper, we present a formal framework for the analysis and comparison of decision sets centered on the notion of decision reduction. In particular, we introduce the notion of safe reduction, which ensures that a reduction can be performed at any level of policy composition without changing the final decision. We demonstrate the framework by analyzing XACML v3 against the notion of safe reduction. From this analysis, we draw guidelines for the selection of the minimal decision set with respect to a given set of combining operators. Charles Morisset, Nicola Zannone |
SACMAT | 1 |
| 2013 | Detection of attack strategiesabstractAn intrusion and attack detection system usually focuses on classifying a record as either normal or abnormal. In some cases such as insider attacks, attackers rely on feedback from the attacked system, which enables them to gradually manipulate their attempts in order to avoid detection. This paper proposes the notion of accumulative manipulation that can be observed through a number of attempts accomplished by the attacker, which forms the basis of the Attacker Learning Curve (ALC). Based on a controlled experiment, we first show that the ALC for three different attack strategies are consistent between two different groups of subjects. We then define a strategy detection mechanism, which is experimentally shown to be accurate more than 70% of the time. Suliman A. Alsuhibany, Charles Morisset, Aad P. A. van Moorsel |
CRiSIS | 2 |
| 2013 | Automated Certification of Authorisation Policy Resistance
Andreas Griesmayer, Charles Morisset |
ESORICS | 2 |
| 2012 | Quantitative access control with partially-observable Markov decision processesabstractThis paper presents a novel access control framework reducing the access control problem to a traditional decision problem, thus allowing a policy designer to reuse tools and techniques from the decision theory. We propose here to express, within a single framework, the notion of utility of an access, decisions beyond the traditional allowing/denying of an access, the uncertainty over the effect of executing a given decision, the uncertainty over the current state of the system, and to optimize this process for a (probabilistic) sequence of requests. We show that an access control mechanism including these different concepts can be specified as a (Partially Observable) Markov Decision Process, and we illustrate this framework with a running example, which includes notions of conflict, critical resource, mitigation and auditing decisions, and we show that for a given sequence of requests, it is possible to calculate an optimal policy different from the naive one. This optimization is still possible even for several probable sequences of requests. Fabio Martinelli, Charles Morisset |
CODASPY | 2 |
| 2012 | Risk-based security decisions under uncertaintyabstractThis paper addresses the making of security decisions, such as access-control decisions or spam filtering decisions, under uncertainty, when the benefit of doing so outweighs the need to absolutely guarantee these decisions are correct. For instance, when there are limited, costly, or failed communication channels to a policy-decision-point. Previously, local caching of decisions has been proposed, but when a correct decision is not available, either a policy-decision-point must be contacted, or a default decision used. We improve upon this model by using learned classifiers of access control decisions. These classifiers, trained on known decisions, infer decisions when an exact match has not been cached, and uses intuitive notions of utility, damage and uncertainty to determine when an inferred decision is preferred over contacting a remote PDP. Clearly there is uncertainty in the predicted decisions, introducing a degree of risk. Our solution proposes a mechanism to quantify the uncertainty of these decisions and allows administrators to bound the overall risk posture of the system. The learning component continuously refines its models based on inputs from a central policy server in cases where the risk is too high or there is too much uncertainty. We have validated our models by building a prototype system and evaluating it with requests from real access control policies. Our experiments show that over a range of system parameters, it is feasible to use machine learning methods to infer access control policies decisions. Thus our system yields several benefits, including reduced calls to the PDP, reducing latency and communication costs; increased net utility; and increased system survivability. Ian M. Molloy, Luke Dickens, Charles Morisset, Pau-Chen Cheng, Jorge Lobo 0001, Alessandra Russo |
CODASPY | 3 |
| 2012 | A Quantitative Approach for Inexact Enforcement of Security Policies
Peter Drábik, Fabio Martinelli, Charles Morisset |
ISC | 3 |
| 2010 | Robustness testing for software components
Xuandong Li, Zhiming Liu 0001, Charles Morisset, Volker Stolz |
Sci. Comput. Program. | 4 |
| 2008 | A Formal Comparison of the Bell & LaPadula and RBAC ModelsabstractIn this paper we address the problem of comparing access control models. Indeed, many access control models can be found in the literature and in order to choose one model for a particular context, some tools helping such a choice are needed. We develop here a complete example allowing to compare (in a formal way) the Bell and LaPadula (BLP) model and the Role-Based (RBAC) model. In order to achieve this goal, we first express these models in a uniform way, then we introduce concepts (mostly based on simulations) allowing to compare access control models. Lionel Habib, Mathieu Jaume, Charles Morisset |
IAS | 3 |
| 2008 | A Component-Based Access Control Monitor
Zhiming Liu 0001, Charles Morisset, Volker Stolz |
ISoLA | 2 |