EDBT 2026 Demo / reviewers in the wild / expert
Samuel Mergendahl
dblp:208/1995
· DBLP profile ↗
11ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0000-8333-4484ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Constellation Parameters for Minimizing Propagation Delay Over LEO Inter-Satellite Links
Robert Esswein, Quincy Bayer, Samuel Mergendahl, Jon Ruffley, Mai Abdelhakim, Robert K. Cunningham |
IEEE Trans. Netw. | 3 |
| 2025 | TAU: Trust via Asynchronous Updates for Satellite Network Resiliency
Quincy Bayer, Robert Esswein, Samuel Mergendahl, Jonathan Ruffley, Mai Abdelhakim, Robert K. Cunningham |
ACNS (1) | 3 |
| 2025 | LAMP: Low-Latency Dynamic Topology for LEO Satellite ConstellationsabstractIn recent years, LEO satellite constellations have been used to solve many problems in communication, navigation, and observation, thanks to the low cost of launching satellites into LEO orbit and the low communication latency compared with GEO orbit. In order for LEO constellations to provide global coverage, the satellites must be able to communicate with each other, typically with a grid-like topology. In this work, we show that a static grid-like topology results in high communication latency. We propose the LEO Approximate Minimum Propagation delay (LAMP) topology, an alternative topology design method using dynamic links. The LAMP topology starts with a backbone network of persistent inter-satellite links to ensure connectivity in the constellation. Then, with the unused laser transceivers, temporary links are added such that the mean communication latency across the constellation is reduced. We show that with the LAMP topology, the average latency can be reduced by 18.5% compared to the static grid topology, and 5.61% compared to the existing Dynamic Topology of Satellites. Additionally, the LAMP topology has lower variability on mean propagation delay as the constellation parameters change compared to the static grid topology; regardless of constellation configuration, the mean propagation delay remains low. Robert Esswein, Quincy Bayer, Samuel Mergendahl, Jonathan Ruffley, Mai Abdelhakim, Robert K. Cunningham |
ICC | 3 |
| 2024 | Manipulative Interference AttacksabstractA μ-kernel is an operating system (OS) paradigm that facilitates a strong cybersecurity posture for embedded systems. Unlike a monolithic OS such as Linux, a μ-kernel reduces overall system privilege by deploying most OS functionality within isolated, userspace protection domains. Moreover, a μ-kernel ensures confidentiality and integrity between protection domains (i.e., spatial isolation), and offers timing predictability for real-time tasks in mixed-criticality systems (i.e., temporal isolation). One popular μ-kernel is seL4 which offers extensive formal guarantees of implementation correctness and flexible temporal budgeting mechanisms. Samuel Mergendahl, Stephen Fickas, Boyana Norris, Richard Skowyra |
CCS | 1 |
| 2024 | A Two-Mode, Adaptive Security Framework for Smart Home Security ApplicationsabstractWith the growth of the Internet of Things (IoT), the number of cyber attacks on the Internet is on the rise. However, the resource-constrained nature of IoT devices and their networks makes many classical security systems ineffective or inapplicable. We introduce TWINKLE, a two-mode, adaptive security framework that allows an IoT network to be in regular mode for most of the time, which incurs a low resource consumption rate, and to switch to vigilant mode only when suspicious behavior is detected, which potentially incurs a higher overhead. Compared to the early version of this work, this article presents a more comprehensive design and architecture of TWINKLE, describes challenges and details in implementing TWINKLE, and reports evaluations of TWINKLE based on real-world IoT testbeds with more metrics. We show the efficacy of TWINKLE in two case studies where we examine two existing intrusion detection and prevention systems and transform both into new, improved systems using TWINKLE. Our evaluations show that TWINKLE is not only effective at securing resource-constrained IoT networks, but can also successfully detect and prevent attacks with a significantly lower overhead and detection latency than existing solutions. Devkishen Sisodia, Jun Li 0001, Samuel Mergendahl, Hasan Çam |
ACM Trans. Internet Things | 3 |
| 2022 | Toward a Resilient Key Exchange Protocol for IoTabstractIn order for resource-constrained Internet of Things (IoT) devices to set up secure communication channels to exchange confidential messages, Symmetric Key Cryptography (SKC) is usually preferred to resource-intensive Public Key Cryptography (PKC). At the core of setting up a secure channel is secure key exchange, the process of two IoT devices securely agreeing on a common session key before they communicate. While compared to using PKC, key exchange using SKC is more resource-aware for IoT environments, it requires either a pre-shared secret or trusted intermediaries between the two devices; neither assumption is realistic in IoT. In this paper, we relax the above assumptions and introduce a new intermediary-based secure key exchange protocol for IoT devices that do not support PKC. With a design that is lightweight and deployable in IoT, our protocol fundamentally departs from existing intermediary-based solutions in that (1) it leverages intermediary parties that can be malicious and (2) it can detect malicious intermediary parties. We provide a formal proof that our protocol is secure and conduct a theoretical analysis to show the failure probability of our protocol is easily negligible with a reasonable setup and its malicious helper detection probability can be 1.0 even when a malicious helper only tampers a small number of messages. We implemented our protocol and our experimental results show that our protocol significantly improves the computation time and energy cost. Dependent on the IoT device type (Raspberry Pi, Arduino Due, or Sam D21) and the PKC algorithms to compare against (ECDH, DH, or RSA), our protocol is 2.3 to 1591 times faster on one of the two devices and 0.7 to 4.67 times faster on the other. Zhangxiang Hu, Jun Li 0001, Samuel Mergendahl |
CODASPY | 3 |
| 2022 | Cross-Language Attacks
Samuel Mergendahl, Nathan Burow, Hamed Okhravi |
NDSS | 1 |
| 2022 | The Thundering Herd: Amplifying Kernel Interference to Attack Response TimesabstractEmbedded and real-time systems are increasingly attached to networks. This enables broader coordination beyond the physical system, but also opens the system to attacks. The increasingly complex workloads of these systems include software of varying assurance levels, including that which might be susceptible to compromise by remote attackers. To limit the impact of compromise, μ-kernels focus on maintaining strong memory protection domains between different bodies of software, including system services. They enable limited coordination between processes through Inter-Process Communication (IPC). Real-time systems also require strong temporal guarantees for tasks, and thus need temporal isolation to limit the impact of malicious software. This is challenging as multiple client threads that use IPC to request service from a shared server will impact each other’s response times.To constrain the temporal interference between threads, modern μ-kernels often build priority and budget awareness into the system. Unfortunately, this paper demonstrates that this is more challenging than previously thought. Adding priority awareness to IPC processing can lead to significant interference due to the kernel’s prioritization logic. Adding budget awareness similarly creates opportunities for interference due to the budget tracking and management operations. In both situations, a Thundering Herd of malicious threads can significantly delay the activation of mission-critical tasks. The Thundering Herd effects are evaluated on seL4 and results demonstrate that high-priority threads can be delayed by over 100,000 cycles per malicious thread. This paper reveals a challenging dilemma: the temporal protections μ-kernels add can, themselves, provide means of threatening temporal isolation. Finally, to defend the system, we identify and empirically evaluate possible mitigations, and propose an admission-control test based upon an interference-aware analysis. Samuel Mergendahl, Samuel Jero, Bryan C. Ward, Juliana Furgala, Gabriel Parmer, Richard Skowyra |
RTAS | 1 |
| 2021 | Keeping Safe Rust Safe with GaleedabstractRust is a programming language that simultaneously offers high performance and strong security guarantees. Safe Rust (i.e., Rust code that does not use the unsafe keyword) is memory and type safe. However, these guarantees are violated when safe Rust interacts with unsafe code, most notably code written in other programming languages, including in legacy C/C++ applications that are incrementally deploying Rust. This is a significant problem as major applications such as Firefox, Chrome, AWS, Windows, and Linux have either deployed Rust or are exploring doing so. It is important to emphasize that unsafe code is not only unsafe itself, but also it breaks the safety guarantees of ‘safe’ Rust; e.g., a dangling pointer in a linked C/C++ library can access and overwrite memory allocated to Rust even when the Rust code is fully safe. Elijah Rivera, Samuel Mergendahl, Howard E. Shrobe, Hamed Okhravi, Nathan Burow |
ACSAC | 2 |
| 2018 | FR-WARD: Fast Retransmit as a Wary but Ample Response to Distributed Denial-of-Service Attacks from the Internet of ThingsabstractWhile the Internet of Things (IoT) becomes increasingly popular and ubiquitous, IoT devices often remain unprotected and can be exploited to launch large-scale distributed denial-of-service (DDoS) attacks. One could attempt to employ traditional DDoS defense solutions, but these solutions are hardly suitable in IoT environments since they seldom consider the resource constraints of IoT devices. We present FR-WARD, a system that defends against DDoS attacks launched from an IoT network. FR-WARD operates close to potential attack sources at the gateway of an IoT network and drops packets to throttle any DDoS traffic that attempts to leave the IoT network. However, in order to properly react to traffic too difficult to categorically label as good or bad, FR-WARD employs a novel response based on the fast retransmit and flow control mechanisms of the Transmission Control Protocol (TCP) which minimizes the energy consumption and network latency of benign IoT devices within the policed network. Based on our mathematical analysis, simulation, and experimental evaluation, FR-WARD not only effectively mitigates DDoS traffic, but also minimizes the number of retransmitted packets and the connection durations of benign IoT devices. In fact, FR-WARD can successfully mitigate both naive flood attacks and smarter DDoS attacks that follow TCP congestion control but still reduce overhead caused by retransmitted packets for benign IoT devices by a up to a factor of 150. Samuel Mergendahl, Devkishen Sisodia, Jun Li 0001, Hasan Çam |
ICCCN | 1 |
| 2018 | Securing the Smart Home via a Two-Mode Security Framework
Devkishen Sisodia, Samuel Mergendahl, Jun Li 0001, Hasan Çam |
SecureComm (1) | 2 |