EDBT 2026 Demo / reviewers in the wild / expert
David Dantas
dblp:397/6959
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2026
0009-0003-9933-1810ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 30% Blockchain and cryptocurrency security · 23% Privacy and data protection · 23% |
Topics — the 4 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic primitives and cryptanalysis › searchable encryption
searchable symmetric encryption |
1.0 | 1 | 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code Privacy · IEEE Trans. Dependable Secur. Comput. 2026 |
Systems and software security › vulnerability discovery
static analysis |
1.0 | 1 | 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code Privacy · IEEE Trans. Dependable Secur. Comput. 2026 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
1.0 | 1 | 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code Privacy · IEEE Trans. Dependable Secur. Comput. 2026 |
Systems and software security › program analysis
data flow analysis |
0.3 | 1 | 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code Privacy · IEEE Trans. Dependable Secur. Comput. 2026 |
Methods — techniques the papers use, named apart from their topics
static analysis · 1.0searchable symmetric encryption · 1.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code PrivacyabstractSoftware vulnerabilities continue to be the primary cause of cyberattacks. It is crucial to identify vulnerabilities in applications' source code before attackers gain access to them and exploit any vulnerability they may contain. Developers have used static analysis tools (SATs) to find vulnerabilities in unprotected application code, and software testing companies have started offering software code analysis as a service to assist developers in these findings. Such services require access to unprotected code, which raises concerns about its privacy and intellectual property theft. Attackers can also perform this analysis using similar tools, if they gain access to the code. It is, therefore, beneficial to have a system that can maintain code privacy by protecting it with cryptographic techniques, while still allowing authorised people to detect vulnerabilities in the encrypted code. This paper presents such a solution, a novel approach to Software Quality and Privacy that allows source code to be analysed in a protected manner, preserving its privacy. The proposed solution combines Static Analysis with Searchable Symmetric Encryption (SSE) for confidential vulnerability detection, enabling data and dependency tracking for data flow analysis over encrypted source code. The solution represents the code's data and control flows as an Encrypted Inverted Index, in a connected way that enables SSE's queries for vulnerability discovery. The solution was implemented as the CoCoA tool and evaluated with synthetic and real PHP web applications. Results show that CoCoA has similar precision as (non-confidential) SATs - 93% - with real applications, requiring only 209 ms to process 4k LoC - a modest overhead of 42.7% compared to a non-confidential baseline. This paper also defines a new research field - Confidential Code Analysis -, from which other types of code analysis tasks can be derived. David Dantas, Rafael Ramires, Bernardo Ferreira, Iberia Medeiros |
IEEE Trans. Dependable Secur. Comput. | 2 |