EDBT 2026 Demo / reviewers in the wild / expert
Vladislav Dubrovenski
dblp:296/3382
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0008-9367-6398ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detecting Obligation Races in NGAC SystemsabstractIn NGAC (Next Generation Access Control) systems, an access event can trigger concurrent obligations that dynamically modify authorization policy elements and, consequently, user privileges. A race condition arises when the resulting privileges depend on the execution order of these obligations, potentially causing serious security issues such as privilege escalation or denial of service. Although race conditions have been extensively studied in other computing systems, they pose a novel challenge in access control because NGAC introduces concurrent, privilege-changing obligations. To address this challenge, this paper investigates the use of SMT (Satisfiability Modulo Theories) to detect their presence. The SMT encoding approach precisely captures the procedural semantics of obligations, allowing for a thorough analysis of interdependence within obligations and between concurrent obligations. We implemented this approach using the NGAC reference implementation and the CVC5 SMT solver, and applied it to real-world systems. The results demonstrate that our approach can effectively identify obligation races. Vladislav Dubrovenski, Dianxiang Xu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Security of LLM Agents: A Case Study ApproachabstractAs large language models (LLMs) evolve into autonomous agents equipped with tools and communication capabilities, they are increasingly deployed in multi-agent systems (MASs) to perform complex tasks. While these systems offer new levels of functionality and efficiency, their security risks remain underexplored. In this paper, we present a focused security analysis of LLM agents by implementing six representative attacks on two real-world MASs. These attacks expose structural and behavioral vulnerabilities unique to agent-based systems. We also introduce and evaluate defensive mechanisms such as fine-tuned agent behaviors, access control via the NGAC (Next Generation Access Control) standard, and a novel "sanity checker" agent for validating agent outputs. Our findings highlight the urgent need for robust, standardized security frameworks for LLM-based MASs and suggest promising directions for future research in agent-level threat modeling and mitigation. Casey Fan, Diyana Tial, Vladislav Dubrovenski, Mengtao Zhang, Yugyung Lee, Dianxiang Xu |
TrustCom | 3 |
| 2025 | Detecting Errors in NGAC Policies via Fault-Based TestingabstractNext Generation Access Control (NGAC) is a standard for implementing dynamic attribute-based access control. It allows access events to trigger programmed administrative obligations and change access privileges during policy execution. However, complex obligations in an NGAC application have the potential of “grave harm to the authorization state through error or intent.” The existing work on NGAC policy testing and verification has limited effectiveness in detecting obligation errors. To address this limitation, we present a novel fault-based testing approach to determining the presence or absence of errors in NGAC policies. It hypothesizes potential errors (faults) in the given policy according to a comprehensive fault model, represents the corrected versions by policy mutants, and validates the hypotheses by generating and executing distinguishing tests. The distinguishing test of a mutant ensures that the mutant and the policy yield distinct execution results – the hypothetical error is present in the policy if the policy's execution result is wrong. We have implemented the approach based on the NGAC reference implementation and applied it to two case studies, including the first fully-fledged NGAC application with sophisticated obligations. The experiment results demonstrate that (a) the subject policies are absent from all hypothetical faults, and (b) all faulty policies represented by the mutants are revealed by fault-based tests. The results also show that the obligation tests targeting individual faults have effectively revealed multi-fault errors. Thus, the proposed approach can help detect potential errors in the development process of NGAC applications. Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | SMT-Based Verification of NGAC PoliciesabstractNext Generation Access Control (NGAC) is a standard for implementing attribute-based access control in computer software. It allows for run-time privilege changes through administrative obligations triggered by access events. However, incorrect privilege changes due to error or intent can cause grave harm to the authorization state. It is important to ensure that the run-time privilege changes meet the access control requirements. To address this issue, we present an efficient approach to verifying NGAC policies by leveraging SMT to deal with complex policy structures and semantics. We have implemented our approach based on the NGAC reference implementation and applied it to two case studies, including the first and only fully-fledged NGAC application. We have formalized 259 access control requirements and successfully verified them against the subject policies. To further evaluate the error detection capability of our approach, we have verified 205 policy versions with a single-seeded obligation error and 154 versions with multiple-seeded obligation errors. The verification results show that all faulty policies failed to satisfy the requirements, and thus the errors were revealed. Vladislav Dubrovenski, Erzhuo Chen, Dianxiang Xu |
COMPSAC | 1 |
| 2023 | Coverage-Based Testing of Obligations in NGAC SystemsabstractThe administrative obligation is a unique feature of Next Generation Access Control (NGAC), a standard for implementing fine-grained attribute-based access control. It provides a programming mechanism for run-time privilege changes by attaching administrative operations to authorized access events. However, dynamic privilege change raises a major concern because the application of NGAC has the potential of "grave harm to the authorization state through error or intent." It is important to reveal potential obligation errors that lead to incorrect privileges and privilege changes. To address this issue, this paper presents a family of coverage-based test generation methods for the obligations in NGAC applications. These methods can generate obligation tests to achieve the corresponding coverage criterion (obligation coverage, action coverage, decision coverage, or factor decision coverage). Each test consists of a sequence of obligation-triggering access events. We have applied the proposed methods to three NGAC applications. The experiment results demonstrate that they have different levels of fault-detection capability and cost-effectiveness. Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu |
SACMAT | 2 |
| 2021 | Mutation Analysis of NGAC PoliciesabstractThe NGAC (Next Generation Access Control) standard for attribute-based access control (ABAC) allows for run-time changes of the permission and prohibition configurations through administrative obligations triggered by access events. It makes access control more fine-grained and dynamic. However, it raises challenges for assuring the correctness of NGAC policies. As policy testing is an important technique for quality assurance, this paper presents an approach to mutation analysis of NGAC policies. It can evaluate the effectiveness of a testing method and reveal potential faults in an inadequately tested policy. The mutation analysis covers various types of potential faults in the assignments, associations, prohibitions, and obligations of NGAC policies. This paper also proposes an incremental testing approach that first validates the initial configuration of a policy and then the policy as a whole. It helps determine whether faults appear in the configuration or the obligations. To evaluate the work, we have developed four working policies and their test suites based on the current NGAC reference implementation. The empirical studies show that the mutation analysis can shed light on the strengths and weaknesses of the test suites. They also demonstrate the need for developing more cost-effective testing methods. Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu |
SACMAT | 2 |