VLDB 2026 Research / reviewers in the wild / expert
Sonia Ben Mokhtar
dblp:b/SoniaBenMokhtar
· DBLP profile ↗
57ranked-venue papers
11as first author
19since 2021 · last 2026
0000-0003-2821-7714ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 14 · 5 first-author · 4 since 2021Systems, architecture and hardware · 12 · 2 first-author · 3 since 2021Computer networks · 7 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TriHaRd: Higher Resilience for TEE Trusted TimeabstractAccurately measuring time passing is critical for many applications. However, in Trusted Execution Environments (TEEs) such as Intel SGX, the time source is outside the Trusted Computing Base: a malicious host can manipulate the TEE’s notion of time, jumping in time or affecting perceived time speed. Previous work (Triad) proposes protocols for TEEs to maintain a trustworthy time source by building a cluster of TEEs that collaborate with each other and with a remote Time Authority to maintain a continuous notion of passing time. However, such approaches still allow an attacker to control the operating system and arbitrarily manipulate their own TEE’s perceived clock speed. An attacker can even propagate faster passage of time to honest machines participating in Triad’s trusted time protocol, causing them to skip to timestamps arbitrarily far in the future. We propose TriHaRd, a TEE trusted time protocol achieving high resilience against clock speed and offset manipulations, notably through Byzantine-resilient clock updates and consistency checks. We empirically show that TriHaRd mitigates known attacks against Triad. This repository contains the source code, as well as deployment and analysis scripts, for the "TriHaRd: Higher Resilience for TEE Trusted Time" paper, accepted for publication at the INFOCOM'26 conference. Matthieu Bettinger, Sonia Ben Mokhtar, Pascal Felber, Etienne Rivière, Valerio Schiavoni, Anthony Simonet |
INFOCOM | 2 |
| 2026 | Dropout-Robust Mechanisms for Differentially Private and Fully Decentralized Mean EstimationabstractAchieving differentially private computations in decentralized settings poses significant challenges, particularly regarding accuracy, communication cost, and robustness against information leakage. While cryptographic solutions offer promise, they often suffer from high communication overhead or require centralization in the presence of network failures. Conversely, existing fully decentralized approaches typically rely on relaxed adversarial models or pairwise noise cancellation, the latter suffering from substantial accuracy degradation if parties unexpectedly disconnect. In this work, we propose IncA, a new protocol for fully decentralized mean estimation, a powerful primitive in data-intensive processing. Our protocol, which enforces differential privacy, requires no central orchestration and employs low-variance correlated noise, achieved by incrementally injecting sensitive information into the computation. First, we theoretically demonstrate that, when no parties permanently disconnect, our protocol achieves accuracy comparable to that of a centralized setting—already an improvement over most existing decentralized differentially private techniques. Second, we empirically show that our use of low-variance correlated noise significantly mitigates the accuracy loss experienced by existing techniques in the presence of dropouts. César Sabater, Sonia Ben Mokhtar, Jan Ramon |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Cool-Tee: Client-Tee Collaboration for Resilient Distributed SearchabstractCurrent marketplaces rely on search mechanisms with distributed systems but centralized governance, making them vulnerable to attacks, failures, censorship and biases. While search mechanisms with more decentralized governance (e.g., DeSearch) have been recently proposed, these are still exposed to information head-start attacks (IHS) despite the use of Trusted Execution Environments (TEEs). These attacks allow malicious users to gain a head-start over other users for the discovery of new assets in the market, which give them an unfair advantage in asset acquisition. We propose COoL-TEE, a TEE-based provider selection mechanism for distributed search, running in single-or multi-datacenter environments, that is resilient to information head-start attacks. COoL-TEE relies on a Client-TEE collaboration, which enables clients to distinguish between slow providers and malicious ones. Performance evaluations in single-and multidatacenter environments show that, using COoL-TEE, malicious users respectively gain only up to 2 % and 7 % of assets more than without IHS, while they can claim 20 % or more on top of their fair share in the same conditions with DeSearch. Matthieu Bettinger, Etienne Rivière, Sonia Ben Mokhtar, Anthony Simonet |
CCGrid | 3 |
| 2025 | PriviRec: Confidential and Decentralized Graph Filtering for Recommender SystemsabstractRecent advances in recommender systems have shown that relying on graph filters, such as the normalized item-item adjacency matrix and the ideal low-pass filter yields competitive performance and scales better than Graph Convolutional Networks-based solutions. However, these solutions require centralizing user data, which raises concerns over data privacy, security, and the monopolization of user data by a few actors. To address those concerns, we propose PriviRec and PriviRec-k, two complementary recommendation frameworks. In PriviRec, we show that it is possible to decompose widely used filters so that they can be computed in a distributed setting using Secure Aggregation and a distributed version of the Randomized Power Method, without revealing individual users contributions. PriviRec-k extends this approach by having users securely aggregate low-rank projections of their contributions, enabling a tunable balance between communication overhead and recommendation accuracy. We demonstrate theoretically as well as experimentally on Gowalla, Yelp2018, and Amazon-Book that our methods achieve performance comparable to centralized state-of-the-art recommender systems and superior to decentralized ones, while preserving confidentiality and low communication and computational overheads. Julien Nicolas, César Sabater, Mohamed Maouche, Mark Coates, Sonia Ben Mokhtar |
CIKM | 5 |
| 2025 | Decentralised Machine Learning As an Enabler of Decentralised Online Services
Sonia Ben Mokhtar |
CLOSER | 1 |
| 2025 | Inferring Communities of Interest in Collaborative Learning-based Recommender SystemsabstractCollaborative-learning-based recommender systems, such as those employing Federated Learning (FL) and Gossip Learning (GL), allow users to train models while keeping their history of liked items on their devices. While these methods were seen as promising for enhancing privacy, recent research has shown that collaborative learning can be vulnerable to various privacy attacks. In this paper, we propose a novel attack called Community Inference Attack (CIA), which enables an adversary to identify community members based on a set of target items. What sets CIA apart is its efficiency: it operates at low computational cost by eliminating the need for training surrogate models. Instead, it uses a comparison-based approach, inferring sensitive information by comparing users’ models rather than targeting any specific individual model. To evaluate the effectiveness of CIA, we conduct experiments on three real-world recommendation datasets using two recommendation models under both Federated and Gossip-like settings. The results demonstrate that CIA can be up to 10 times more accurate than random guessing. Additionally, we evaluate two mitigation strategies: Differentially Private Stochastic Gradient Descent (DP-SGD) and a Share less policy, which involves sharing fewer, less sensitive model parameters. Our findings suggest that the Share less strategy offers a better privacy-utility trade-off, especially in GL. Yacine Belal, Mohamed Maouche, Sonia Ben Mokhtar, Anthony Simonet |
ICDCS | 3 |
| 2025 | Exposing the Vulnerability of Decentralized Learning to Membership Inference Attacks Through the Lens of Graph MixingabstractThe primary promise of decentralized learning is to allow users to engage in the training of machine learning models in a collaborative manner while keeping their data on their premises and without relying on any central entity. However, this paradigm necessitates the exchange of model parameters or gradients between peers. Such exchanges can be exploited to infer sensitive information about training data, which is achieved through privacy attacks (e.g., Membership Inference Attacks - MIA). In order to devise effective defense mechanisms, it is important to understand the factors that increase/reduce the vulnerability of a given decentralized learning architecture to MIA. In this study, we extensively explore the vulnerability to MIA of various decentralized learning architectures by varying the graph structure (e.g., number of neighbors), the graph dynamics, and the aggregation strategy, across diverse datasets and data distributions. Our key finding, which to the best of our knowledge we are the first to report, is that the vulnerability to MIA is heavily correlated to (i) the local model mixing strategy performed by each node upon reception of models from neighboring nodes and (ii) the global mixing properties of the communication graph. We illustrate these results experimentally using four datasets and by theoretically analyzing the mixing properties of various decentralized architectures. We also empirically show that enhancing mixing properties is highly beneficial when combined with other privacy-preserving techniques such as Differential Privacy. Our paper draws a set of lessons learned for devising decentralized learning systems that reduce by design the vulnerability to MIA. Ousmane Touat, Jezekael Brunon, Yacine Belal, Julien Nicolas, César Sabater, Mohamed Maouche, Sonia Ben Mokhtar |
Middleware | 7 |
| 2025 | Keynote: On the Safety and Security of Decentralised Machine Learning
Sonia Ben Mokhtar |
SSS | 1 |
| 2025 | Tee-based key-value stores: a survey
Aghiles Ait Messaoud, Sonia Ben Mokhtar, Anthony Simonet |
VLDB J. | 2 |
| 2022 | SplitBFT: Improving Byzantine Fault Tolerance Safety Using Trusted CompartmentsabstractByzantine fault-tolerant agreement (BFT) in a partially synchronous system usually requires 3f + 1 nodes to tolerate f faulty replicas. Due to their high throughput and finality property, BFT algorithms build the core of recent permissioned blockchains. As a complex and resource-demanding infrastructure, multiple cloud providers have started offering Blockchain-as-a-Service. This eases the deployment of permissioned blockchains but places the cloud provider in a central controlling position, thereby questioning blockchains' fault tolerance and decentralization properties and their underlying BFT algorithm. This paper presents SplitBFT, a new way to utilize trusted execution technology (TEEs), such as Intel SGX, to harden the safety and confidentiality guarantees of BFT systems, thereby strengthening the trust in could-based deployments of permissioned blockchains. Deviating from standard assumptions, SplitBFT acknowledges that code protected by trusted execution may fail. We address this by splitting and isolating the core logic of BFT protocols into multiple compartments resulting in a more resilient architecture. We apply SplitBFT to the traditional practical byzantine fault tolerance algorithm (PBFT) and evaluate it using SGX. Our results show that SplitBFT adds only a reasonable overhead compared to the non-compartmentalized variant. Ines Messadi, Markus Horst Becker, Kai Bleeke, Leander Jehl, Sonia Ben Mokhtar, Rüdiger Kapitza |
Middleware | 5 |
| 2022 | Shielding federated learning systems against inference attacks with ARM TrustZoneabstractFederated Learning (FL) opens new perspectives for training machine learning models while keeping personal data on the users premises. Specifically, in FL, models are trained on the users' devices and only model updates (i.e., gradients) are sent to a central server for aggregation purposes. However, the long list of inference attacks that leak private data from gradients, published in the recent years, have emphasized the need of devising effective protection mechanisms to incentivize the adoption of FL at scale. While there exist solutions to mitigate these attacks on the server side, little has been done to protect users from attacks performed on the client side. In this context, the use of Trusted Execution Environments (TEEs) on the client side are among the most proposing solutions. However, existing frameworks (e.g., DarkneTZ) require statically putting a large portion of the machine learning model into the TEE to effectively protect against complex attacks or a combination of attacks. We present GradSec, a solution that allows protecting in a TEE only sensitive layers of a machine learning model, either statically or dynamically, hence reducing both the Trusted Computing Base (TCB) size and the overall training time by up to 30% and 56%, respectively compared to state-of-the-art competitors. Aghiles Ait Messaoud, Sonia Ben Mokhtar, Vlad Nitu, Valerio Schiavoni |
Middleware | 2 |
| 2022 | Quantifying fairness of federated learning LPPM modelsabstractDespite the great potential offered by Artificial Intelligence in the context of smart mobility, it comes with the greater challenge of preserving the privacy of users. Federated Learning (FL) has gained popularity as a privacy-friendly approach, however, an equally important aspect rarely addressed in the literature, is its fairness. In this work we audit a FL-based privacy-preserving model. We use Entropy to determine similarity within the system's input data and compare its value against that of the output to detect unfair treatment. Amina Ben Salem, Besma Khalfoun, Sonia Ben Mokhtar, Afra J. Mashhadi |
MobiSys | 3 |
| 2022 | In-depth analysis of the IDA-Gossip protocolabstractGossip-based dissemination protocols are important building blocks of large-scale distributed systems as they may impact both the systems’ efficiency and fault tolerance. There exist many flavors of gossip dissemination protocols. IDA-Gossip is one of the gossip dissemination protocols proposed in the context of blockchains to efficiently disseminate large messages. It relies on multi-chunk gossip dissemination, erasure coding, and Merkle hash trees. However, despite its claimed efficiency, there is no in-depth analysis of this protocol to understand its behavior under different conditions (e.g., with injected faults). In this work, we evaluate the behavior of IDA-Gossip by relying on extensive experiments and simulations. Specifically, we evaluate IDA-Gossip both in terms of performance and resilience to faults by varying its configuration parameters and the number of faulty nodes, respectively. This study results in several takeaways. First, IDA-Gossip provides excellent dissemination latency compared to classic gossip. Second, it provides excellent coverage even with 40 percent of faulty nodes in the system. Finally, the use of erasure coding provides an important advantage to IDA-Gossip compared to classic multi-chunk gossip dissemination protocols. Kadir Korkmaz 0001, Joachim Bruneau-Queyreix, Stéphane Delbruel, Sonia Ben Mokhtar, Laurent Réveillère |
NCA | 4 |
| 2022 | ALDER: Unlocking blockchain performance by multiplexing consensus protocolsabstractMost of today’s online services (e.g., social networks, search engines, marketplace places) are centralized, which most users recognize as unsatisfactory for various reasons (e.g., centralized governance, censorship, loss of control over personal data). Blockchain technologies promise a new Web revolution (Web 3.0) through the decentralization of online services. However, one of the fundamental limitations for this revolution to happen at a planetary scale is the poor performance of today’s permissionless blockchains. In this paper, we propose ALDER, a generic construction that multiplexes off-the-shelf permissionless blockchain protocols to address the performance bottleneck due to store-validate-forward block dissemination techniques in blockchain protocols. We apply ALDER to two representative blockchains, namely Algorand (Proof-of-Stake) and Bitcoin (Proof-of-Work), to illustrate the benefits it brings to blockchain performance. Our evaluations show that ALDER can drastically improve the throughput of blockchains when bottlenecks exist. Kadir Korkmaz 0001, Joachim Bruneau-Queyreix, Sonia Ben Mokhtar, Laurent Réveillère |
NCA | 3 |
| 2021 | Uniqueness Assessment of Human Mobility on Multi-Sensor DatasetsabstractThe widespread adoption of handheld devices (e.g., smartphones, tablets) makes mobility traces of users broadly available to third party services. These traces are collected by means of various sensors embedded in the users’ devices, including GPS, WiFi and GSM. We study in this paper the mobility of 300 users over a period up to 31 months from the perspective of the above three types of data and with a focus on two cities, i.e., Lausanne (Switzerland) and Lyon (France). We found that users’ mobility traces, no matter if they are collected using GPS, WiFi or GSM antennas, are highly unique. We show that on average only four spatio-temporal points from the WiFi, GSM and GPS traces are enough to uniquely identify 94% of the individuals, on both datasets. In addition, we show that using the temporal dimension (i.e., whether users move or are in a meaningful location such as their home or their working place) drastically improves the capacity to uniquely identify them compared to when only exploiting the spatial dimension (by 14% on average). In some cases, using the temporal dimension alone can represent a better mobility footprint than the spatial dimension to discriminate users. We further conduct a de-anonymisation attack to assess how mobility traces can be re-identified, and show that almost all users can be de-anonymised with a high success rate. Finally, we apply different Location Privacy Protection Mechanisms (LPPMs), including spatial filtering, temporal cloaking, adding spatial noise to mobility data, or using generalisation, and analyse the impact of these mechanisms on both the uniqueness of users’ mobility traces and the outcome of the de-anonymisation attack. We show that spatially obfuscating mobility data is not enough to protect users, and that classical LPPMs are not able to protect users against a de-anonymisation attack. We finally conclude this paper by drawing some insights towards future spatio-temporal LPPMs. Antoine Boutet, Sonia Ben Mokhtar |
ARES | 2 |
| 2021 | Taming Tail Latency in Key-Value Stores: A Scheduling Perspective
Sonia Ben Mokhtar, Louis-Claude Canon, Anthony Dugois, Loris Marchal, Etienne Rivière |
Euro-Par | 1 |
| 2021 | PProx: efficient privacy for recommendation-as-a-serviceabstractWe present PProx, a system preventing recommendation-as-a-service (RaaS) providers from accessing sensitive data about the users of applications leveraging their services. PProx does not impact recommendations accuracy, is compatible with arbitrary recommendation algorithms, and has minimal deployment requirements. Its design combines two proxying layers directly running inside SGX enclaves at the RaaS provider side. These layers transparently pseudonymize users and items and hide links between the two, and PProx privacy guarantees are robust even to the corruption of one of these enclaves. We integrated PProx with Harness's Universal Recommender and evaluated it on a 27-node cluster. Our results indicate its ability to withstand a high number of requests with low end-to-end latency, horizontally scaling up to match increasing workloads of recommendations. Guillaume Rosinosky, Simon Da Silva, Sonia Ben Mokhtar, Daniel Négru, Laurent Réveillère, Etienne Rivière |
Middleware | 3 |
| 2021 | Automatic Privacy and Utility Preservation for Mobility Data: A Nonlinear Model-Based ApproachabstractThe widespread use of mobile devices and location-based services has generated a large number of mobility databases. While processing these data is highly valuable, privacy issues can occur if personal information is revealed. The prior art has investigated ways to protect mobility data by providing a wide range of Location Privacy Protection Mechanisms (LPPMs). However, the privacy level of the protected data significantly varies depending on the protection mechanism used, its configuration and on the characteristics of the mobility data. Meanwhile, the protected data still needs to enable some useful processing. To tackle these issues, we present PULP, a framework that finds the suitable protection mechanism and automatically configures it for each user in order to achieve user-defined objectives in terms of both privacy and utility. PULP uses nonlinear models to capture the impact of each LPPM on data privacy and utility levels. Evaluation of our framework is carried out with two protection mechanisms from the literature and four real-world mobility datasets. Results show the efficiency of PULP, its robustness and adaptability. Comparisons between LPPMs' configurators and the state of the art further illustrate that PULP better realizes users' objectives, and its computation time is in orders of magnitude faster. Sophie Cerf, Sara Bouchenak, Bogdan Robu, Nicolas Marchand, Vincent Primault, Sonia Ben Mokhtar, Antoine Boutet, Lydia Y. Chen |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | Enhancing Robustness of On-Line Learning Models on Highly Noisy DataabstractClassification algorithms have been widely adopted to detect anomalies for various systems, e.g., IoT, cloud and face recognition, under the common assumption that the data source is clean, i.e., features and labels are correctly set. However, data collected from the wild can be unreliable due to careless annotations or malicious data transformation for incorrect anomaly detection. In this article, we extend a two-layer on-line data selection framework: Robust Anomaly Detector (RAD) with a newly designed ensemble prediction where both layers contribute to the final anomaly detection decision. To adapt to the on-line nature of anomaly detection, we consider additional features of conflicting opinions of classifiers, repetitive cleaning, and oracle knowledge. We on-line learn from incoming data streams and continuously cleanse the data, so as to adapt to the increasing learning capacity from the larger accumulated data set. Moreover, we explore the concept of oracle learning that provides additional information of true labels for difficult data points. We specifically focus on three use cases, (i) detecting 10 classes of IoT attacks, (ii) predicting 4 classes of task failures of big data jobs, and (iii) recognising 100 celebrities faces. Our evaluation results show that RAD can robustly improve the accuracy of anomaly detection, to reach up to 98.95 percent for IoT device attacks (i.e., +7%), up to 85.03 percent for cloud task failures (i.e., +14%) under 40 percent label noise, and for its extension, it can reach up to 77.51 percent for face recognition (i.e., +39%) under 30 percent label noise. The proposed RAD and its extensions are general and can be applied to different anomaly detection algorithms. Zilong Zhao 0001, Robert Birke, Rui Han 0001, Bogdan Robu, Sara Bouchenak, Sonia Ben Mokhtar, Lydia Y. Chen |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2020 | TailX: Scheduling Heterogeneous Multiget Queries to Improve Tail Latencies in Key-Value Stores
Vikas Jaiman, Sonia Ben Mokhtar, Etienne Rivière |
DAIS | 2 |
| 2019 | Robust Anomaly Detection on Unreliable DataabstractClassification algorithms have been widely adopted to detect anomalies for various systems, e.g., IoT and cloud, under the common assumption that the data source is clean, i.e., features and labels are correctly set. However, data collected from the field can be unreliable due to careless annotations or malicious data transformation for incorrect anomaly detection. In this paper, we present a two-layer learning framework for robust anomaly detection (RAD) in the presence of unreliable anomaly labels. The first layer of quality model filters the suspicious data, where the second layer of classification model detects the anomaly types. We specifically focus on two use cases, (i) detecting 10 classes of IoT attacks and (ii) predicting 4 classes of task failures of big data jobs. Our evaluation results show that RAD can robustly improve the accuracy of anomaly detection, to reach up to 98% for IoT device attacks (i.e., +11%) and up to 83% for cloud task failures (i.e., +20%), under a significant percentage of altered anomaly labels. Zilong Zhao 0001, Sophie Cerf, Robert Birke, Bogdan Robu, Sara Bouchenak, Sonia Ben Mokhtar, Lydia Y. Chen |
DSN | 6 |
| 2019 | MooD: MObility Data Privacy as Orphan Disease: Experimentation and Deployment PaperabstractWith the increasing development of handheld devices, Location Based Services (LBSs) became very popular in facilitating users' daily life with a broad range of applications (e.g. traffic monitoring, geo-located search, geo-gaming). However, several studies have shown that the collected mobility data may reveal sensitive information about end-users such as their home and workplaces, their gender, political, religious or sexual preferences. To overcome these threats, many Location Privacy Protection Mechanisms (LPPMs) were proposed in the literature. While the existing LPPMs try to protect most of the users in mobility datasets, there is usually a subset of users who are not protected by any of the existing LPPMs. By analogy to medical research, there are orphan diseases, for which the medical community is still looking for a remedy. In this paper, we present MooD, a fine-grained multi-LPPM user-centric solution whose main objective is to find a treatment to mobile users' orphan disease by protecting them from re-identification attacks. Our experiments are conducted on four real world datasets. The results show that MooD outperforms its competitors, and the amount of user mobility data it is able to protect is in the range between 97.5% to 100% on the various datasets. Besma Khalfoun, Mohamed Maouche, Sonia Ben Mokhtar, Sara Bouchenak |
Middleware | 3 |
| 2019 | PrivaTube: Privacy-Preserving Edge-Assisted Video StreamingabstractVideo on Demand (VoD) streaming is the largest source of Internet traffic. Efficient and scalable VoD requires Content Delivery Networks (CDNs) whose cost are prohibitive for many providers. An alternative is to cache and serve video content using end-users devices. Direct connections between these devices complement the resources of core VoD servers with an edge-assisted collaborative CDN. Simon Da Silva, Sonia Ben Mokhtar, Stefan Contiu, Daniel Négru, Laurent Réveillère, Etienne Rivière |
Middleware | 2 |
| 2019 | RACOON++: A Semi-Automatic Framework for the Selfishness-Aware Design of Cooperative SystemsabstractA challenge in designing cooperative distributed systems is to develop feasible and cost-effective mechanisms to foster cooperation among selfish nodes, i.e., nodes that strategically deviate from the intended specification to increase their individual utility. Finding a satisfactory solution to this challenge may be complicated by the intrinsic characteristics of each system, as well as by the particular objectives set by the system designer. Our previous work addressed this challenge by proposing RACOON, a general and semi-automatic framework for designing selfishness-resilient cooperative systems. RACOON relies on classical game theory and a custom built simulator to predict the impact of a fixed set of selfish behaviours on the designer's objectives. In this paper, we present RACOON++, which extends the previous framework with a declarative model for defining the utility function and the static behaviour of selfish nodes, along with a new model for reasoning on the dynamic interactions of nodes, based on evolutionary game theory. We illustrate the benefits of using RACOON++ by designing three cooperative systems: a peer-to-peer live streaming system, a load balancing protocol, and an anonymous communication system. Extensive experimental results using the state-of-the-art PeerSim simulator verify that the systems designed using RACOON++ achieve both selfishness-resilience and high performance. Guido Lena Cota, Sonia Ben Mokhtar, Gabriele Gianini, Ernesto Damiani, Julia Lawall, Gilles Muller, Lionel Brunie |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Dynamic Modeling of Location Privacy Protection Mechanisms
Sophie Cerf, Sonia Ben Mokhtar, Sara Bouchenak, Nicolas Marchand, Bogdan Robu |
DAIS | 2 |
| 2018 | CYCLOSA: Decentralizing Private Web Search through SGX-Based Browser ExtensionsabstractBy regularly querying Web search engines, users (unconsciously) disclose large amounts of their personal data as part of their search queries, among which some might reveal sensitive information (e.g. health issues, sexual, political or religious preferences). Several solutions exist to allow users querying search engines while improving privacy protection. However, these solutions suffer from a number of limitations: some are subject to user re-identification attacks, while others lack scalability or are unable to provide accurate results. This paper presents CYCLOSA, a secure, scalable and accurate private Web search solution. CYCLOSA improves security by relying on trusted execution environments (TEEs) as provided by Intel SGX. Further, CYCLOSA proposes a novel adaptive privacy protection solution that reduces the risk of user re-identification. CYCLOSA sends fake queries to the search engine and dynamically adapts their count according to the sensitivity of the user query. In addition, CYCLOSA meets scalability as it is fully decentralized, spreading the load for distributing fake queries among other nodes. Finally, CYCLOSA achieves accuracy of Web search as it handles the real query and the fake queries separately, in contrast to other existing solutions that mix fake and real query results. Rafael Pires 0001, David Goltzsche, Sonia Ben Mokhtar, Sara Bouchenak, Antoine Boutet, Pascal Felber, Rüdiger Kapitza, Marcelo Pasin, Valerio Schiavoni |
ICDCS | 3 |
| 2018 | ACCIO: How to Make Location Privacy Experimentation Open and EasyabstractThe advent of mobile applications collecting and exploiting the location of users opens a number of privacy threats. To mitigate these privacy issues, several protection mechanisms have been proposed this last decade to protect users' location privacy. However, these protection mechanisms are usually implemented and evaluated in monolithic way, with heterogeneous tools and languages. Moreover, they are evaluated using different methodologies, metrics and datasets. This lack of standard makes the task of evaluating and comparing protection mechanisms particularly hard. In this paper, we present ACCIO, a unified framework to ease the design and evaluation of protection mechanisms. Thanks to its Domain Specific Language, ACCIO allows researchers and practitioners to define and deploy experiments in an intuitive way, as well as to easily collect and analyse the results. ACCIO already comes with several state-of-the-art protection mechanisms and a toolbox to manipulate mobility data. Finally, ACCIO is open and easily extensible with new evaluation metrics and protection mechanisms. This openness, combined with a description of experiments through a user-friendly DSL, makes ACCIO an appealing tool to reproduce and disseminate research results easier. In this paper, we present ACCIO's motivation and architecture, and demonstrate its capabilities through several use cases involving multiples metrics, state-of-the-art protection mechanisms, and two real-life mobility datasets collected in Beijing and in the San Francisco area. Vincent Primault, Mohamed Maouche, Antoine Boutet, Sonia Ben Mokhtar, Sara Bouchenak, Lionel Brunie |
ICDCS | 4 |
| 2018 | EActors: Fast and flexible trusted computing using SGXabstractNovel trusted execution support, as offered by Intel's Software Guard eXtensions (SGX), embeds seamlessly into user space applications by establishing regions of encrypted memory, called enclaves. Enclaves comprise code and data that is executed under special protection of the CPU and can only be accessed via an enclave defined interface. To facilitate the usability of this new system abstraction, Intel offers a software development kit (SGX SDK). While the SDK eases the use of SGX, it misses appropriate programming support for inter-enclave interaction, and demands to hardcode the exact use of trusted execution into applications, which restricts flexibility. Vasily A. Sartakov, Stefan Brenner, Sonia Ben Mokhtar, Sara Bouchenak, Gaël Thomas 0001, Rüdiger Kapitza |
Middleware | 3 |
| 2018 | Héron: Taming Tail Latencies in Key-Value Stores Under Heterogeneous WorkloadsabstractAvoiding latency variability in distributed storage systems is challenging. Even in well-provisioned systems, factors such as the contention on shared resources or the unbalanced load between servers affect the latencies of requests and in particular the tail (95th and 99th percentile) of their distribution. One effective counter measure for reducing tail latency in key-value stores is to provide efficient replica selection algorithms. However, existing solutions are based on the assumption that all requests have almost the same execution time. This is not true for real workloads. This mismatch leads to increased latencies for requests with short execution time that get scheduled behind requests with large execution times. We propose Héron, a replica selection algorithm that supports workloads with heterogeneous request execution times. We evaluate Héron in a cluster of machines using a synthetic dataset inspired from the Facebook dataset as well as two real datasets from Flickr and WikiMedia. Our results show that Héron outperforms state-of-the-art algorithms by reducing both median and tail latency by up to 41%. Vikas Jaiman, Sonia Ben Mokhtar, Vivien Quéma, Lydia Y. Chen, Etienne Rivière |
SRDS | 2 |
| 2017 | A reputation system resilient against colluding and malicious adversaries in mobile participatory sensing applicationsabstractParticipatory sensing is an emerging paradigm in which citizens voluntarily use their mobile phones to capture and share sensed data from their surrounding environment in order to monitor and analyze some phenomena. Participating users can disrupt the system by contributing corrupted, fabricated, or erroneous data. Different reputation systems have been proposed to monitor participants' behavior and to estimate their honesty. There are some attacks that were not considered by the existing reputation systems in this context including corruption, collusion, and on-off attack. In this paper, we propose a more robust and efficient reputation system designed for these applications. Our reputation system incorporates a mechanism to defend against those attacks. Experimental results indicate that our system can tolerate up to 60% of colluding adversaries involved in the sensing campaign. This enables our system to aggregate the data more accurately compared with the state-of-the art. Moreover, the system can detect on-off attackers even if they strategically contribute some good data with high probability (e.g. 0.8). Hayam Mousa, Sonia Ben Mokhtar, Omar Hasan, Lionel Brunie, Osama S. Younes, Mohey M. Hadhoud |
CCNC | 2 |
| 2017 | Analysing Selfishness Flooding with SEINEabstractSelfishness is one of the key problems that confronts developers of cooperative distributed systems (e.g., file-sharing networks, voluntary computing). It has the potential to severely degrade system performance and to lead to instability and failures. Current techniques for understanding the impact of selfish behaviours and designing effective countermeasures remain manual and time-consuming, requiring multi-domain expertise. To overcome these difficulties, we propose SEINE, a simulation framework for rapid modelling and evaluation of selfish behaviours in a cooperative system. SEINE relies on a domain-specific language (SEINE-L) for specifying selfishness scenarios, and provides semi-automatic support for their implementation and study in a state-of-the-art simulator. We show in this paper that (1) SEINE-L is expressive enough to specify fifteen selfishness scenarios taken from the literature, (2) SEINE is accurate in predicting the impact of selfishness compared to real experiments, and (3) SEINE substantially reduces the development effort compared to traditional manual approaches. Guido Lena Cota, Sonia Ben Mokhtar, Gabriele Gianini, Ernesto Damiani, Julia Lawall, Gilles Muller, Lionel Brunie |
DSN | 2 |
| 2017 | X-search: revisiting private web search using intel SGXabstractThe exploitation of user search queries by search engines is at the heart of their economic model. As consequence, offering private Web search functionalities is essential to the users who care about their privacy. Nowadays, there exists no satisfactory approach to enable users to access search engines in a privacy-preserving way. Existing solutions are either too costly due to the heavy use of cryptographic mechanisms (e.g., private information retrieval protocols), subject to attacks (e.g., Tor, TrackMeNot, GooPIR) or rely on weak adversarial models (e.g., PEAS). This paper introduces X-Search, a novel private Web search mechanism building on the disruptive Software Guard Extensions (SGX) proposed by Intel. We compare X-Search to its closest competitors, Tor and PEAS, using a dataset of real web search queries. Our evaluation shows that: (1) X-Search offers stronger privacy guarantees than its competitors as it operates under a stronger adversarial model; (2) it better resists state-of-the-art re-identification attacks; and (3) from the performance perspective, X-Search outperforms its competitors both in terms of latency and throughput by orders of magnitude. Sonia Ben Mokhtar, Antoine Boutet, Pascal Felber, Marcelo Pasin, Rafael Pires 0001, Valerio Schiavoni |
Middleware | 1 |
| 2017 | AP-Attack: A Novel User Re-identification Attack On Mobility DatasetsabstractSince the advent of hand held devices (e.g., smartphones, tablets, smart watches) with Ubiquitous computing and the wide popularity of location-based mobile applications, the amount of captured user location data is dramatically increasing. However, the gathering and exploitation of this data by mobile application providers raises many privacy threats as sensitive information can be inferred from it (e.g., home and work locations, religious beliefs, sexual orientations and social relationships). To address this issue a number of data obfuscation techniques (also called Location Privacy Protection Mechanisms or LPPMs) have been proposed in the literature. One of the existing methods to assess the effectiveness of LPPMs is to test them against user re-identification attacks. The aim of these attacks is to break user anonymity by re-associating data obfuscated using a given LPPM with user profiles built from user past mobility. In this paper, we present AP-Attack a novel re-identification attack that relies on a heatmap representation of user mobility data. Our experiments run against three representative LPPMs of the literature using four real mobility datasets show that AP-Attack succeeds in re-identifying up to 79% users in non-obfuscated data, +27% more users than POI-Attack and PIT-Attack two well known state-of-the-art attacks. We also present a simple technique to improve user protection against our attack, which relies on a user-centric application of multiple-LPPMs. Mohamed Maouche, Sonia Ben Mokhtar, Sara Bouchenak |
MobiQuitous | 2 |
| 2017 | PrivaSense: Privacy-Preserving and Reputation-Aware Mobile Participatory SensingabstractThe integration of privacy into reputation systems is a crucial need for building secure and reliable participatory sensing applications. Participants are given the assurance that their privacy is preserved even if they contribute some personal sensitive data. In addition, reputation systems allow an application server to monitor participants' behaviors and evict those who provide the system with corrupted data. However, this integration requires achieving seemingly conflicting objectives. Reputation systems monitor participants behaviors along subsequent interactions. Whereas, one of the major objectives of privacy preserving systems is to unlink subsequent interactions. In this paper, we define a new attack (RR attack), which exploits this conflict in order to detect the succession of contributions provided by the same participant and to subsequently re-identify his original identity. We show that using this attack, more than 35% of contributions can be associated to their successive contributions in each campaign. We then propose PrivaSense as a new privacy preserving reputation system that integrates both reputation and privacy such that their objectives are simultaneously achieved. Experimental results are conducted using a real data-set. These results show that PrivaSense decreases by up to 80% the number of contributions linked to their original providers. Hayam Mousa, Sonia Ben Mokhtar, Omar Hasan, Lionel Brunie, Osama S. Younes, Mohey M. Hadhoud |
MobiQuitous | 2 |
| 2017 | PULP: Achieving Privacy and Utility Trade-Off in User Mobility DataabstractLeveraging location information in location-based services leads to improving service utility through geocontextualization. However, this raises privacy concerns as new knowledge can be inferred from location records, such as user's home and work places, or personal habits. Although Location Privacy Protection Mechanisms (LPPMs) provide a means to tackle this problem, they often require manual configuration posing significant challenges to service providers and users. Moreover, their impact on data privacy and utility is seldom assessed. In this paper, we present PULP, a model-driven system which automatically provides user-specific privacy protection and contributes to service utility via choosing adequate LPPM and configuring it. At the heart of PULP is nonlinear models that can capture the complex dependency of data privacy and utility for each individual user under given LPPM considered, i.e., Geo-Indistinguishability and Promesse. According to users' preferences on privacy and utility, PULP efficiently recommends suitable LPPM and corresponding configuration. We evaluate the accuracy of PULP's models and its effectiveness to achieve the privacy-utility trade-off per user, using four real-world mobility traces of 770 users in total. Our extensive experimentation shows that PULP ensures the contribution to location service while adhering to privacy constraints for a great percentage of users, and is orders of magnitude faster than non-model based alternatives. Sophie Cerf, Vincent Primault, Antoine Boutet, Sonia Ben Mokhtar, Robert Birke, Sara Bouchenak, Lydia Y. Chen, Nicolas Marchand, Bogdan Robu |
SRDS | 4 |
| 2017 | Adaptive and context-aware service composition for IoT-based smart cities
Aitor Urbieta, Alejandra N. González-Beltrán, Sonia Ben Mokhtar, M. Anwar Hossain 0001, Licia Capra |
Future Gener. Comput. Syst. | 3 |
| 2016 | PAG: Private and Accountable GossipabstractA large variety of content sharing applications rely, at least partially, on gossip-based dissemination protocols. However, these protocols are subject to various types of faults, among which selfish behaviours performed by nodes that benefit from the system without contributing their fair share to it. Accountability mechanisms (e.g., PeerReview, AVMs, FullReview), which require that nodes log their interactions with others and periodically inspect each others' logs are effective solutions to deter faults. However, these solutions require that nodes disclose the content of their logs, which may leak sensitive information about them. Building on a monitoring infrastructure and on homomorphic cryptographic procedures, we propose in this paper PAG, the first accountable and partially privacy-preserving gossip protocol. We assess PAG theoretically using the ProVerif cryptographic protocol verifier and evaluate it experimentally using both a real deployment on a cluster of 48 machines and simulations. The performance evaluation of PAG, performed using a video live streaming application, shows that it is compatible with the visualisation of live video content on commodity Internet connections. Furthermore, PAG's bandwidth consumption inherits the desirable scalability properties of gossip when the number of users in the system grows. Jeremie Decouchant, Sonia Ben Mokhtar, Albin Petit, Vivien Quéma |
ICDCS | 2 |
| 2016 | Adaptive Location Privacy with ALPabstractWith the increasing amount of mobility data being collected on a daily basis by location-based services (LBSs) comes a new range of threats for users, related to the over-sharing of their location information. To deal with this issue, several location privacy protection mechanisms (LPPMs) have been proposed in the past years. However, each of these mechanisms comes with different configuration parameters that have a direct impact both on the privacy guarantees offered to the users and on the resulting utility of the protected data. In this context, it can be difficult for non-expert system designers to choose the appropriate configuration to use. Moreover, these mechanisms are generally configured once for all, which results in the same configuration for every protected piece of information. However, not all users have the same behaviour, and even the behaviour of a single user is likely to change over time. To address this issue, we present in this paper ALP (which stands for Adaptive Location Privacy), a new framework enabling the dynamic configuration of LPPMs. ALP can be used in two scenarios: (1) offline, where ALP enables a system designer to choose and automatically tune the most appropriate LPPM for the protection of a given dataset, (2) online, where ALP enables the user of a crowd sensing application to protect consecutive batches of her geolocated data by automatically tuning a given LPPM to fulfil a set of privacy and utility objectives. We evaluate ALP on both scenarios with two real-life mobility datasets and two state-of-the-art LPPMs. Our experiments show that the adaptive LPPM configurations found by ALP outperform static configurations in terms of trade-off between privacy and utility. Vincent Primault, Antoine Boutet, Sonia Ben Mokhtar, Lionel Brunie |
SRDS | 3 |
| 2016 | 4PR: Privacy preserving routing in mobile delay tolerant networks
Jingwei Miao, Omar Hasan, Sonia Ben Mokhtar, Lionel Brunie, Ammar Hasan |
Comput. Networks | 3 |
| 2015 | Privacy-Preserving Publication of Mobility Data with High UtilityabstractAn increasing amount of mobility data is being collected every day by different means, e.g., By mobile phone operators. This data is sometimes published after the application of simple anonymization techniques, which might lead to severe privacy threats. We propose in this paper a new solution whose novelty is two-fold. Firstly, we introduce an algorithm designed to hide places where a user stops during her journey (namely points of interest), by enforcing a constant speed along her trajectory. Secondly, we leverage places where users meet to take a chance to swap their trajectories and therefore confuse an attacker. Vincent Primault, Sonia Ben Mokhtar, Lionel Brunie |
ICDCS | 2 |
| 2015 | A Framework for the Design Configuration of Accountable Selfish-Resilient Peer-to-Peer SystemsabstractA challenge in designing a peer-to-peer (P2P) system is to ensure that the system is able to tolerate selfish nodes that strategically deviate from their specification whenever doing so is convenient. In this paper, we propose RACOON, a framework for the design of P2P systems that are resilient to selfish behaviours. While most existing solutions target specific systems or types of selfishness, RACOON proposes a generic and semi-automatic approach that achieves robust and reusable results. Also, RACOON supports the system designer in the performance-oriented tuning of the system, by proposing a novel approach that combines Game Theory and simulations. We illustrate the benefits of using RACOON by designing two P2P systems: a live streaming and an anonymous communication system. In simulations and a real deployment of the two applications on a testbed comprising 100 nodes, the systems designed using RACOON achieve both resilience to selfish nodes and high performance. Guido Lena Cota, Sonia Ben Mokhtar, Julia Lawall, Gilles Muller, Gabriele Gianini, Ernesto Damiani, Lionel Brunie |
SRDS | 2 |
| 2015 | A delay and cost balancing protocol for message routing in mobile delay tolerant networks
Jingwei Miao, Omar Hasan, Sonia Ben Mokhtar, Lionel Brunie, Gabriele Gianini |
Ad Hoc Networks | 3 |
| 2015 | Trust management and reputation systems in mobile participatory sensing applications: A survey
Hayam Mousa, Sonia Ben Mokhtar, Omar Hasan, Osama S. Younes, Mohey M. Hadhoud, Lionel Brunie |
Comput. Networks | 2 |
| 2014 | FullReview: Practical Accountability in Presence of Selfish NodesabstractAccountability is becoming increasingly required in today's distributed systems. Indeed, accountability allows not only to detect faults but also to build provable evidence about the misbehaving participants of a distributed system. There exists a number of solutions to enforce accountability in distributed systems, among which PeerReview is the only solution that is not specific to a given application and that does not rely on any special hardware. However, this protocol is not resilient to selfish nodes, i.e., nodes that aim at maximising their benefit without contributing their fair share to the system. Our objective in this paper is to provide a software solution to enforce accountability on any underlying application in presence of selfish nodes. To tackle this problem, we propose the FullReview protocol. FullReview relies on game theory by embedding incentives that force nodes to stick to the protocol. We theoretically prove that our protocol is a Nash equilibrium, i.e., that nodes do not have any interest in deviating from it. Furthermore, we practically evaluate FullReview by deploying it for enforcing accountability in two applications: (1) SplitStream, an efficient multicast protocol, and (2) Onion routing, the most widely used anonymous communication protocol. Performance evaluation shows that FullReview effectively detects faults in presence of selfish nodes while incurring a small overhead compared to PeerReview and scaling as PeerReview. Amadou Diarra, Sonia Ben Mokhtar, Pierre-Louis Aublin, Vivien Quéma |
SRDS | 2 |
| 2014 | AcTinG: Accurate Freerider Tracking in GossipabstractGossip-based content dissemination protocols are a scalable and cheap alternative to centralized content sharing systems. However, it is well known that these protocols suffer from rational nodes, i.e., nodes that aim at downloading the content without contributing their fair share to the system. While the problem of rational nodes that act individually has been well addressed in the literature, colluding rational nodes is still an open issue. Indeed, LiFTinG, the only existing gossip protocol addressing this issue, yields a high ratio of false positive accusations of correct nodes. In this paper, we propose AcTinG, a protocol that prevents rational collusions in gossip-based content dissemination protocols, while guaranteeing zero false positive accusations. We assess the performance of AcTinG on a testbed comprising 400 nodes running on 100 physical machines, and compare its behaviour in the presence of colluders against two state-of-the-art protocols: BAR Gossip that is the most robust protocol handling non-colluding rational nodes, and LiFTinG, the only existing gossip protocol that handles colluding nodes. The performance evaluation shows that AcTinG is able to deliver all messages despite the presence of colluders, whereas LiFTinG and BAR Gossip, both suffer heavy message losses. Finally, using simulations involving up to a million nodes, we show that AcTinG exhibits similar scalability properties as standard gossip-based dissemination protocols. Sonia Ben Mokhtar, Jeremie Decouchant, Vivien Quéma |
SRDS | 1 |
| 2013 | A Privacy Preserving Prediction-based Routing Protocol for Mobile Delay Tolerant NetworksabstractA prediction-based routing protocol for mobile delay tolerant networks functions by forwarding a message from one intermediate node to another if the latter has higher probability of encountering the destination node. However, this process compromises the privacy of the nodes by revealing their mobility patterns. In this paper, we propose a privacy preserving prediction-based routing protocol that forwards messages by comparing information about communities of nodes instead of individual nodes. Specifically, it compares the maximum probability that a node in the community of a potential intermediate node will encounter the destination node. We present theoretical security analyses as well as practical performance evaluations. Our simulations on a well established community-based mobility model demonstrate that our protocol has comparable performance to existing prediction-based protocols. Yet our protocol is the only one that preserves the privacy of nodes. Omar Hasan, Jingwei Miao, Sonia Ben Mokhtar, Lionel Brunie |
AINA | 3 |
| 2013 | RBFT: Redundant Byzantine Fault ToleranceabstractByzantine Fault Tolerant state machine replication (BFT) protocols are replication protocols that tolerate arbitrary faults of a fraction of the replicas. Although significant efforts have been recently made, existing BFT protocols do not provide acceptable performance when faults occur. As we show in this paper, this comes from the fact that all existing BFT protocols targeting high throughput use a special replica, called the primary, which indicates to other replicas the order in which requests should be processed. This primary can be smartly malicious and degrade the performance of the system without being detected by correct replicas. In this paper, we propose a new approach, called RBFT for Redundant-BFT: we execute multiple instances of the same BFT protocol, each with a primary replica executing on a different machine. All the instances order the requests, but only the requests ordered by one of the instances, called the master instance, are actually executed. The performance of the different instances is closely monitored, in order to check that the master instance provides adequate performance. If that is not the case, the primary replica of the master instance is considered malicious and replaced. We implemented RBFT and compared its performance to that of other existing robust protocols. Our evaluation shows that RBFT achieves similar performance as the most robust protocols when there is no failure and that, under faults, its maximum performance degradation is about 3%, whereas it is at least equal to 78% for existing protocols. Pierre-Louis Aublin, Sonia Ben Mokhtar, Vivien Quéma |
ICDCS | 2 |
| 2013 | RAC: A Freerider-Resilient, Scalable, Anonymous Communication ProtocolabstractEnabling anonymous communication over the Internet is crucial. The first protocols that have been devised for anonymous communication are subject to freeriding. Recent protocols have thus been proposed to deal with this issue. However, these protocols do not scale to large systems, and some of them further assume the existence of trusted servers. In this paper, we present RAC, the first anonymous communication protocol that tolerates freeriders and that scales to large systems. Scalability comes from the fact that the complexity of RAC in terms of the number of message exchanges is independent from the number of nodes in the system. Another important aspect of RAC is that it does not rely on any trusted third party. We theoretically prove, using game theory, that our protocol is a Nash equilibrium, i.e, that freeriders have no interest in deviating from the protocol. Further, we experimentally evaluate RAC using simulations. Our evaluation shows that, whatever the size of the system (up to 100.000 nodes), the nodes participating in the system observe the same throughput. Sonia Ben Mokhtar, Gautier Berthou 0002, Amadou Diarra, Vivien Quéma, Ali Shoker |
ICDCS | 1 |
| 2012 | Fair content dissemination in participatory DTNs
Afra J. Mashhadi, Sonia Ben Mokhtar, Licia Capra |
Ad Hoc Networks | 2 |
| 2010 | FireSpam: Spam Resilient Gossiping in the BAR ModelabstractGossip protocols are an efficient and reliable way to disseminate information. These protocols have nevertheless a drawback: they are unable to limit the dissemination of spam messages. Indeed, messages are redundantly disseminated in the network and it is enough that a small subset of nodes forward spam messages to have them received by a majority of nodes. In this paper, we present FireSpam, a gossiping protocol that is able to limit spam dissemination. FireSpam organizes nodes in a ladder topology, where nodes highly capable of filtering spam are at the top of the ladder, whereas nodes with a low spam filtering capability are at the bottom of the ladder. Messages are disseminated from the bottom of the ladder to its top. The ladder does thus act as a progressive spam filter. In order to make it usable in practice, we designed FireSpam in the BAR model. This model takes into account selfish and malicious behaviors. We evaluate FireSpam using simulations. We show that it drastically limits the dissemination of spam messages, while still ensuring reliable dissemination of good messages. Sonia Ben Mokhtar, Alessio Pace, Vivien Quéma |
SRDS | 1 |
| 2009 | Habit: Leveraging human mobility and social network for efficient content dissemination in Delay Tolerant NetworksabstractThis paper proposes Habit, an efficient multi-layered approach to content dissemination in Delay Tolerant Networks (DTN) that leverages information about nodes' colocation (physical layer) and their social network (application layer). More precisely, the regularity of users' colocation is learned based on historical colocation observations; also, the users' social network (or `network of interest') is dynamically propagated during periods of colocation; finally, these distinct pieces of information are locally combined and used to compute the paths that content should follow, in a way that maximises both precision (i.e., nodes receive only content they are interested in) and recall (i.e., all relevant content is received by interested nodes). Afra J. Mashhadi, Sonia Ben Mokhtar, Licia Capra |
WOWMOM | 2 |
| 2008 | Distributed Behavioural Adaptation for the Automatic Composition of Semantic Services
Tarek Melliti, Pascal Poizat, Sonia Ben Mokhtar |
FASE | 3 |
| 2008 | EASY: Efficient semAntic Service discoverY in pervasive computing environments with QoS and context support
Sonia Ben Mokhtar, Davy Preuveneers, Nikolaos Georgantas, Valérie Issarny, Yolande Berbers |
J. Syst. Softw. | 1 |
| 2007 | COCOA: COnversation-based service COmposition in pervAsive computing environments with QoS support
Sonia Ben Mokhtar, Nikolaos Georgantas, Valérie Issarny |
J. Syst. Softw. | 1 |
| 2006 | Efficient Semantic Service Discovery in Pervasive Computing Environments
Sonia Ben Mokhtar, Anupam Kaul, Nikolaos Georgantas, Valérie Issarny |
Middleware | 1 |
| 2005 | QoS-aware dynamic service composition in ambient intelligence environmentsabstractDue to the large success of wireless networks and handheld devices, the ambient intelligence (AmI) paradigm is becoming a reality. One of the most challenging objectives to achieve in AmI environments is to enable a user to perform a task by composing on the fly networked services available at a specific time and place. Towards this goal, we propose a solution based on semantic Web services, and we show how service capabilities described as conversations can be integrated to perform a user task that is also described as a conversation, further meeting the QoS requirements of the user task. Experimental results show that the runtime overhead of our algorithm is reasonable, and further, that QoS-awareness improves its performance. Sonia Ben Mokhtar, Jinshan Liu, Nikolaos Georgantas, Valérie Issarny |
ASE | 1 |
| 2005 | The Amigo Service Architecture for the Open Networked Home EnvironmentabstractThe Amigo project aims to develop a networked home system enabling the ambient intelligence / pervasive computing vision by effectively integrating devices and their hosted services in today’s home. The Amigo system architecture poses limited technology-specific restrictions, supporting interoperability among heterogeneous services. Nikolaos Georgantas, Sonia Ben Mokhtar, Yérom-David Bromberg, Valérie Issarny, Jarmo Kalaoja, Julia Kantorovitch, Anne Gérodolle, Ron Mevissen |
WICSA | 2 |