Marc Lacoste

dblp:67/2171 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0001-8699-236XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Where Should Federated Learning Run? Design Rules for CCAM Cooperative Perception
Mohamed Coulibaly, Léo Mendiboure, Hasnaâ Aniss, Marc Lacoste, Sylvain Allio, Hugues Oudeville, Fabien Battello
WoWMoM4
2024 Ti-skol: A Modular Federated Learning Framework Supporting Security Countermeasure Composition
abstract
Federated Learning (FL) is a growing technology that enables training of Deep Learning models on private data. Many FL enhancements have been proposed, notably for better security and privacy. Current architectures and frameworks focus on specific sets of enhancements with little extensibility and do not support composition of enhancements. In this paper, we introduce Ti-skol, an architecture and framework that supports composition of security and privacy countermeasures, including countermeasure incompatibilities. Ti-skol also enables modular management of FL enhancements beyond security, being compatible with most enhancements. Ti-skol is promising to assess the cost of countermeasures, individually or in combination. We evaluate our framework on a use-case of Volunteer Deep Learning – applying Volunteer Computing to reduce the cost of large model training by harnessing idle resources of single machines into the required massive distributed computing power. Experimental results show that Ti-skol is scalable as the network size increases. While adding security countermeasures such as Byzantine protections or secure aggregation substantially increase computing overheads, they do not change their order of magnitude, individually or in combination. This tends to show the practicality of the Ti-skol framework for on-demand FL security.
Divi De Lacour, Marc Lacoste, Mario Südholt, Jacques Traoré
IEEE Big Data2
2023 Towards a Privacy-Preserving Attestation for Virtualized Networks
Ghada Arfaoui, Thibaut Jacques, Marc Lacoste, Cristina Onete, Léo Robert
ESORICS (4)3
2022 The Owner, the Provider and the Subcontractors: How to Handle Accountability and Liability Management for 5G End to End Service
abstract
The adoption of 5G services depends on the capacity to provide high-value services. In addition to enhanced performance, the capacity to deliver Security Service Level Agreements (SSLAs) and demonstrate their fulfillment would be a great incentive for the adoption of 5G services for critical 5G Verticals (e.g., service suppliers like Energy or Intelligent Transportation Systems) subject to specific industrial safety, security or service level rules and regulations (e.g., NIS or SEVESO Directives). Yet, responsibilities may be difficult to track and demonstrate because 5G infrastructures are interconnected and complex, which is a challenge anticipated to be exacerbated in future 6G networks. This paper describes a demonstrator and a use case that shows how 5G Service Providers can deliver SSLAs to their customers (Service Owners) by leveraging a set of network enablers developed in the INSPIRE-5Gplus project to manage their accountability, liability and trust placed in subcomponents of a service (subcontractors). The elaborated enablers are in particular a novel sTakeholder Responsibility, AccountabIity and Liability deScriptor (TRAILS), a Liability-Aware Service Management Referencing Service (LASM-RS), an anomaly detection tool (IoT-MMT), a Root Cause Analysis tool (IoT-RCA), two Remote Attestation mechanisms (Systemic and Deep Attestation), and two Security-by-Orchestration enablers (one for the 5G Core and one for the MEC).
Chrystel Gaber, Ghada Arfaoui, Yannick Carlinet, Nancy Perrot, Laurent Valeyre, Marc Lacoste, Jean-Philippe Wary, Yacine Anser, Rafal Artych, Aleksandra Podlasek, Edgardo Montes de Oca, Vinh Hoa La, Vincent Lefebvre, Gürkan Gür
ARES6
2021 Towards a Modular Attestation Framework for Flexible Data Protection for Drone Systems
abstract
Data protection is a rising concern for systems of drones to guarantee data integrity and privacy through the detection of drone violations in no-fly zones (NFZ). Despite their security guarantees, existing attestation frameworks present limited extensibility. This paper presents a modular attestation framework for drone systems overcoming such a barrier. The framework provides a high degree of flexibility to guarantee both data integrity within and across drones. We also propose a dedicated token-based attestation protocol to support NFZ violation detection. We implemented a proof-of-concept prototype using the OP-TEE and PX4 open environments for trusted execution and drone simulation. Evaluations show the framework guarantees strong data protection with a high level of flexibility while preserving performance and scalability.
Zineeddine Ould Imam, Marc Lacoste, Ghada Arfaoui
WiMob2
2018 Secure Distributed Computing on Untrusted Fog Infrastructures Using Trusted Linux Containers
abstract
Fog and Edge computing provide a large pool of resources at the edge of the network that may be used for distributed computing. Fog infrastructure heterogeneity also results in complex configuration of distributed applications on computing nodes. Linux containers are a mainstream technique allowing to run packaged applications and micro services. However, running applications on remote hosts owned by third parties is challenging because of untrusted operating systems and hardware maintained by third parties. To meet such challenges, we may leverage trusted execution mechanisms. In this work, we propose a model for distributed computing on Fog infrastructures using Linux containers secured by Intel's Software Guard Extensions (SGX) technology. We implement our model on a Docker and OpenSGX platform. The result is a secure and flexible approach for distributed computing on Fog infrastructures.
Mohammad-Mahdi Bazm, Marc Lacoste, Mario Südholt, Jean-Marc Menaud
CloudCom2
2017 Mantus: Putting Aspects to Work for Flexible Multi-Cloud Deployment
abstract
Cloud provider barriers still stand. After a decade of cloud computing, customers struggle to overcome the challenge of crossing multi-provider clouds to benefit from fine-grained resource distribution, business independence from CSPs and cost savings. Although increasingly popular, most adopted IaaS intercloud solutions are generally limited to specific public cloud providers or present maintainability issues. Remaining hurdles include complexity of management and operations of such infrastructures, in presence of per-customer customizations and provider configurations. The Infrastructure as Code (IaC) paradigm is emerging as key enabler for IaaS multi-clouds, to develop and manage infrastructure configurations. However, due to complexity of the infrastructure life-cycle, to heterogeneity of composing resources and to user-customizations, this approach is far from being viable. In this paper, we explore an aspect-oriented approach to IaC deployment and management. We propose Mantus, a IaC-based multi-cloud builder composed of an aspect-oriented Domain-Specific Language called TML, or TOSCA Manipulation Language, and a corresponding aspect weaver to inject flexibly non-functional services in TOSCA infrastructure templates. We show the practical feasibility of our approach, with also good results in terms of performance and scalability.
Alex Palesandro, Marc Lacoste, Nadia Bennani, Chirine Ghedira, Denis Bourge
CLOUD2
2016 Self-stabilizing Byzantine-Tolerant Distributed Replicated State Machine
Alexander Binun, Thierry Coupaye, Shlomi Dolev, Mohamed Kassi-Lahlou, Marc Lacoste, Alex Palesandro, Reuven Yagel, Leonid Yankulin
SSS5
2014 Self-Stabilizing Virtual Machine Hypervisor Architecture for Resilient Cloud
abstract
This paper presents the architecture for a self-stabilizing hypervisor able to recover itself in the presence of Byzantine faults regardless of the state it is currently in. Our architecture is applicable to wide variety of underlying hardware and software and does not require augmenting computers with special hardware. The actions representing defense and recovery strategies can be specified by a user. We describe our architecture in OS-independent terms, thus making it applicable to various virtualization infrastructures. We also provide a prototype extending the Linux-based hypervisor KVM with the self-stabilizing functionality. These features allow augmenting KVM with robustness functionality in the coming stages and moving to cloud management system architectures such as OpenStack to support more industrial scenarios.
Alexander Binun, Mark Bloch, Shlomi Dolev, Ramzi Martin Kahil, Boaz Menuhin, Reuven Yagel, Thierry Coupaye, Marc Lacoste, Aurélien Wailly
SERVICES8
2010 Pervasive authentication and authorization infrastructures for mobile users
Jordi Forné, M. Francisca Hinarejos, Andrés Marín López, Florina Almenárez, Javier López 0001, José A. Montenegro, Marc Lacoste, Daniel Díaz Sánchez
Comput. Secur.7
2009 Brief Announcement: An OS Architecture for Device Self-protection
Ruan He, Marc Lacoste, Jean Leneutre
SSS2
2008 A QoS and Security Adaptation Model for Autonomic Pervasive Systems
abstract
The unpredictable fluctuations in computing resources, contexts, and user preferences that characterize pervasive environments have stressed the need for context-aware self-adaptive systems. So far, this research area mostly dealt exclusively with concerns related either to standard QoS or to security. Taking into account trade-offs between these two conflicting concerns is a key issue, since they both compete for the same resources. This paper presents a general adaptivity model that reconciles these two concerns. This model is formalized as a component composition selection process, where the best composition is found by reasoning on security and non-security properties of the system. Utility functions are used to quantify how a component composition alternative is appropriate in a given context, with respect to the user preferences.
Mourad Alia, Marc Lacoste
COMPSAC2
2005 A Flexible and Modular Framework for Implementing Infrastructures for Global Computing
Lorenzo Bettini, Rocco De Nicola, Daniele Falassi, Marc Lacoste, Michele Loreti
DAIS4