EDBT 2026 Demo / reviewers in the wild / expert
Gaël Bernard
dblp:190/0994
· DBLP profile ↗
6ranked-venue papers in the field
5as first author
4since 2021 · last 2024
0000-0001-7299-1286ORCID · corroborated
Domains — venue-derived; a paper can count in several
Database Systems & Data Management · 2 (2 first)Information Retrieval & Web Search · 2 (1 first)Business Process & Enterprise Data · 2 (2 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Know their Customers: An Empirical Study of Online Account Enumeration AttacksabstractInternet users possess accounts on dozens of online services where they are often identified by one of their e-mail addresses. They often use the same address on multiple services and for communicating with their contacts. In this paper, we investigate attacks that enable an adversary (e.g., company, friend) to determine (stealthily or not) whether an individual, identified by their e-mail address, has an account on certain services (i.e., an account enumeration attack ). Such attacks on account privacy have serious implications as information about one’s accounts can be used to (1) profile them and (2) improve the effectiveness of phishing. We take a multifaceted approach and study these attacks through a combination of experiments (63 services), surveys (318 respondents), and focus groups (13 participants). We demonstrate the high vulnerability of popular services (93.7%) and the concerns of users about their account privacy, as well as their increased susceptibility to phishing e-mails that impersonate services on which they have an account. We also provide findings on the challenges in implementing countermeasures for service providers and on users’ ideas for enhancing their account privacy. Finally, our interaction with national data protection authorities led to the inclusion of recommendations in their developers’ guide. Maël Maceiras, Kavous Salehzadeh Niksirat, Gaël Bernard, Benoît Garbinato, Mauro Cherubini, Mathias Humbert, Kévin Huguenin |
ACM Trans. Web | 3 |
| 2023 | An Empirical Study of the Usage of Checksums for Web DownloadsabstractChecksums, typically provided on webpages and generated from cryptographic hash functions (e.g., MD5, SHA256) or signature schemes (e.g., PGP), are commonly used on websites to enable users to verify that the files they download have not been tampered with when stored on possibly untrusted servers. In this paper, we elucidate the current practices regarding the usage of checksums for web downloads (hash functions used, visibility and validity of checksums, type of websites and files, etc.), as this has been mostly overlooked so far. Using a snowball-sampling strategy for the 200000 most popular domains of the Web, we first crawled a dataset of 8.5M webpages, from which we built, through an active-learning approach, a unique dataset of 277 diverse webpages that contain checksums. Our analysis of these webpages reveals interesting findings about the usage of checksums. For instance, it shows that checksums are used mostly to verify program files, that weak hash functions are frequently used, and that a non-negligible proportion of the checksums provided on webpages do not match that of their associated files. Finally, we complement our analysis with a survey of the webmasters of the considered webpages (N = 26), thus shedding light on the reasons behind the checksum-related choices they make. Gaël Bernard, Rémi Coudert, Bertil Chapuis, Kévin Huguenin |
WWW | 1 |
| 2021 | Cut to the Trace! Process-Aware Partitioning of Long-Running Cases in Customer Journey Logs
Gaël Bernard, Arik Senderovich, Periklis Andritsos |
CAiSE | 1 |
| 2021 | Selecting Representative Sample Traces from Large Event LogsabstractWhen event logs are large, the time needed to analyze them using process mining techniques can become prohibitive. In this paper, using sampling, we aim to reduce the size of event logs to p-traces, while minimizing the Earth Movers’ Distance (EMD) from the unsampled original event log. We contribute by formalizing log sampling in a canonical form and show its link with the EMD, a metric increasingly used for process mining. Next, we propose three log-sampling algorithms that we evaluate using a collection of 18 event logs from industry. We show that our approach largely reduces the EMD compared to existing sampling strategies. Moreover, we highlight that sampled event logs with low EMDs tend to have better behavioural quality, highlighting the generality of our work. Gaël Bernard, Periklis Andritsos |
ICPM | 1 |
| 2019 | Accurate and Transparent Path Prediction Using Process Mining
Gaël Bernard, Periklis Andritsos |
ADBIS | 1 |
| 2019 | Contextual and Behavioral Customer Journey Discovery Using a Genetic Approach
Gaël Bernard, Periklis Andritsos |
ADBIS | 1 |