EDBT 2026 Demo / reviewers in the wild / expert
Neelu S. Kalani
dblp:309/7800 · also Neelu Shivprakash Kalani
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0006-1507-5787ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 77% Embedded and real-time systems · 23% | |
| Network and information security
1 paper |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Operating systems · 100% |
Topics — the 3 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cloud and datacenter computing
virtualization |
0.9 | 1 | 2025 | The Design and Implementation of a Virtual Firmware Monitor · SOSP 2025 |
Operating systems › resource management › process management
context switching |
0.3 | 1 | 2025 | Save what must be saved: Secure context switching with Sailor · USENIX Security Symposium 2025 |
Embedded and real-time systems › embedded software
firmware |
0.3 | 1 | 2025 | The Design and Implementation of a Virtual Firmware Monitor · SOSP 2025 |
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tyche: Composable Isolation as a Foundation to Manage Trust in the CloudabstractCloud workloads combine software components from different parties to process sensitive data. Each component has its own trust model - it must protect its assets from the rest of the system, yet share sensitive data with components it cannot trust to keep confidential. This tension requires composing isolation boundaries for confidentiality and encapsulation. Unfortunately, the cloud offers no direct way to compose such boundaries, forcing tenants to assemble, deploy, and maintain their own solutions. This paper shifts that burden back to the infrastructure by making composable, attestable isolation a first-class systems abstraction. We present Tyche, a security monitor that centers isolation around a unified composable abstraction: security domains (SDs). An SD is an execution environment whose access to machine resources - memory, cores, devices - is controlled through explicit capabilities. A small set of capability operations enables SDs to partition, share, and reclaim resources; by nesting recursively, SDs compose attestable trust boundaries for confidentiality and encapsulation. Tyche attests these compositions, providing end-to-end security guarantees for workloads made of mutually distrustful components. As a first-class cloud primitive, this single abstraction subsumes enclaves, sandboxes, CVMs, and their compositions. Tyche provides composable isolation without sacrificing compatibility with existing hardware and software stacks. It runs on commodity x86 64 hardware without security extensions, and a RISC-V prototype demonstrates portability across platforms. Our SDK composes isolation for unmodified workloads within SDs with minimal overhead. In a confidential LLM inference scenario with mutually distrustful users, model owners, and cloud providers, the slowdown is just 2% compared to bare-metal Linux. Adrien Ghosn, Charly Castes, Neelu S. Kalani, Yuchen Qian, Marios Kogias, Edouard Bugnion |
EuroS&P | 3 |
| 2025 | The Design and Implementation of a Virtual Firmware Monitor
Charly Castes, François Costa, Neelu S. Kalani, Timothy Roscoe, Nate Foster, Thomas Bourgeat, Edouard Bugnion |
SOSP | 3 |
| 2025 | Save what must be saved: Secure context switching with Sailor
Neelu S. Kalani, Thomas Bourgeat, Guerney D. H. Hunt, Wojciech Ozga |
USENIX Security Symposium | 1 |
| 2023 | Creating Trust by Abolishing HierarchiesabstractSoftware is going through a trust crisis. Privileged code is no longer trusted and processes insufficiently protect user code from unverified libraries. While usually treated separately, confidential computing and program compartmentalization are both symptoms of the same problem, deeply rooted in hierarchical commodity systems: privileged software's monopoly over isolation. Charly Castes, Adrien Ghosn, Neelu S. Kalani, Yuchen Qian, Marios Kogias, Mathias Payer, Edouard Bugnion |
HotOS | 3 |