EDBT 2026 Demo / reviewers in the wild / expert
Yanis Sellami
dblp:222/6181
· DBLP profile ↗
1ranked-venue papers
1as first author
1since 2021 · last 2024
0009-0006-8833-3863ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program verification · 50% Program analysis · 50% | |
| Network and information security
1 paper |
Systems and software security · 100% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis › static analysis › constraint-based analysis
constraint inference |
0.8 | 1 | 2024 | Inference of Robust Reachability Constraints · Proc. ACM Program. Lang. 2024 |
Program verification › model checking › state space exploration
reachability analysis |
0.8 | 1 | 2024 | Inference of Robust Reachability Constraints · Proc. ACM Program. Lang. 2024 |
Systems and software security › vulnerability management
vulnerability characterization |
0.2 | 1 | 2024 | Inference of Robust Reachability Constraints · Proc. ACM Program. Lang. 2024 |
Methods — techniques the papers use, named apart from their topics
robust reachability oracle · 1.5abduction · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Inference of Robust Reachability ConstraintsabstractCharacterization of bugs and attack vectors is in many practical scenarios as important as their finding. Recently, Girol et al. have introduced the concept of robust reachability , which ensures a perfect reproducibility of the reported violations by distinguishing inputs that are under the control of the attacker ( controlled inputs ) from those that are not ( uncontrolled inputs ), and proposed first automated analysis for it. While it is a step toward distinguishing severe bugs from benign ones, it fails for example to describe violations that are mostly reproducible, i.e., when triggering conditions are likely to happen, meaning that they happen for all uncontrolled inputs but a few corner cases. To address this issue, we propose to leverage theory-agnostic abduction techniques to generate constraints on the uncontrolled program inputs that ensure that a target property is robustly satisfied . Our proposal comes with an extension of robust reachability that is generic on the type of trace property and on the technology used to verify the properties. We show that our approach is complete w.r.t. its inference language , and we additionally discuss strategies for the efficient exploration of the inference space. We demonstrate the feasibility of the method and its practical ability to refine the notion of robust reachability with an implementation that uses robust reachability oracles to generate constraints on standard benchmarks from software verification and security analysis. We illustrate the use of our implementation to a vulnerability characterization problem in the context of fault injection attacks. Our method overcomes a major limitation of the initial proposal of robust reachability, without complicating its definition. From a practical view, this is a step toward new verification tools that are able to characterize program violations through high-level feedback. Yanis Sellami, Guillaume Girol, Frédéric Recoules, Damien Couroussé, Sébastien Bardin |
Proc. ACM Program. Lang. | 1 |