EDBT 2026 Demo / reviewers in the wild / expert
Martin Kayondo
dblp:353/7547
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0009-0003-7340-6968ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SECV: Securing Connected Vehicles with Hardware Trust Anchors
Martin Kayondo, Junseung You, Eunmin Kim, Yunheung Paek |
NDSS | 1 |
| 2025 | ROSec: Intra-Process Isolation for ROS Composition With Memory Protection KeysabstractRobot Operating System(ROS) is a software framework for robotic systems that includes various packages for developing robotic applications.Compositionis a package that combines multiple applications, namely,nodes, to be loaded and executed in a single process. However, permitting multiple nodes to share the address space could expand the attack surface such that vulnerabilities in a node are more likely to be exploited to subvert nodes running in the same space. We propose ROSec, an in-process isolation solution for ROS composition that utilizes Intel Memory Protection Keys. ROSecaims to enforce memory isolation between nodes within a process by preventing unauthorized access from one node to another. Unlike previous works that assume the number and sizes of nodes are statically defined and partitioned by developers, ROSecis designed to handle the dynamic nature of nodes that can be loaded and executed in a process at any time during execution. To achieve this, ROSecadopts a unique scheduling mechanism that utilizes theexecutor-centricexecution model of ROS to perform two main operations for MPK-based isolation:protection key assignmentandreassignment. Our evaluation shows that ROSeceffectively enforces in-process isolation while incurring a 6.4% performance overhead on a real-world application.Note to Practitioners—Cyber-Physical Systems are the core of modern applications, particularly robotics, as they integrate computing and physical processes. ROS necessitates real-time and security guarantees, which, unfortunately, trade-off with each other. While traditional ROS architecture relies on process isolation to separate various nodes, ROS2 introduces a feature called composition, which allows multiple nodes to run inside a single process, thus exposing various nodes to potential malicious compromises from others. This paper proposes a technique that utilizes Intel memory protection keys (MPK) to provide intraprocess isolation for ROS composition. Given that ROS nodes are dynamic, ROSEC provides key assignment and reassignment techniques to configure MPK dynamically. Martin Kayondo, Jeonghwan Kang, Kyeongryong Lee, Donghyun Kwon, Yunheung Paek |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2024 | MetaSafe: Compiling for Protecting Smart Pointer Metadata to Ensure Safe Rust Integrity
Martin Kayondo, Inyoung Bang, Yeongjun Kwak, Hyungon Moon, Yunheung Paek |
USENIX Security Symposium | 1 |
| 2023 | TRust: A Compilation Framework for In-process Isolation to Protect Safe Rust against Untrusted Code
Inyoung Bang, Martin Kayondo, Hyungon Moon, Yunheung Paek |
USENIX Security Symposium | 2 |