Iulian Sandu Popa

dblp:73/6460 · DBLP profile ↗
← Back
25ranked-venue papers in the field
4as first author
9since 2021 · last 2026
0000-0002-9937-4242ORCID · corroborated

Domains — venue-derived; a paper can count in several

Database Systems & Data Management · 23 (2 first)Other / Interdisciplinary · 2 (2 first)
YearPublicationVenuePosition
2026 Finding the Sweet Spot: Query Cost and Load Distribution for Spatio-Temporal Queries in Peer-to-Peer Systems
Zhan Ye, Laurent Yeh, Iulian Sandu Popa
DATA (1)3
2025 Enabling secure data-driven applications: an approach to personal data management using trusted execution environments
Robin Carpentier, Iulian Sandu Popa, Nicolas Anciaux
Distributed Parallel Databases2
2023 Federated Learning on Personal Data Management Systems: Decentralized and Reliable Secure Aggregation Protocols
abstract
The development and adoption of personal data management systems (PDMS) has been fueled by legal and technical means such as smart disclosure, data portability and data altruism. By using a PDMS, individuals can effortlessly gather and share data, generated directly by their devices or as a result of their interactions with companies or institutions. In this context, federated learning appears to be a very promising technology, but it requires secure, reliable, and scalable aggregation protocols to preserve user privacy and account for potential PDMS dropouts. Despite recent significant progress in secure aggregation for federated learning, we still lack a solution suitable for the fully decentralized PDMS context. This paper proposes a family of fully decentralized protocols that are scalable and reliable with respect to dropouts. We focus in particular on the reliability property which is key in a peer-to-peer system wherein aggregators are system nodes and are subject to dropouts in the same way as contributor nodes. We show that in a decentralized setting, reliability raises a tension between the potential completeness of the result and the aggregation cost. We then propose a set of strategies that deal with dropouts and offer different trade-offs between completeness and cost. We extensively evaluate the proposed protocols and show that they cover the design space allowing to favor completeness or cost in all settings.
Julien Mirval, Luc Bouganim, Iulian Sandu Popa
SSDBM3
2023 Highly distributed and privacy-preserving queries on personal data management systems
Luc Bouganim, Julien Loudet, Iulian Sandu Popa
VLDB J.3
2022 Local Personal Data Processing with Third Party Code and Bounded Leakage
Robin Carpentier, Iulian Sandu Popa, Nicolas Anciaux
DATA2
2022 An Extensive and Secure Personal Data Management System Using SGX
abstract
International audience
Robin Carpentier, Floris Thiant, Iulian Sandu Popa, Nicolas Anciaux, Luc Bouganim
EDBT3
2022 Data Leakage Mitigation of User-Defined Functions on Secure Personal Data Management Systems
abstract
Personal Data Management Systems (PDMSs) arrive at a rapid pace providing individuals with appropriate tools to collect, manage and share their personal data. At the same time, the emergence of Trusted Execution Environments (TEEs) opens new perspectives in solving the critical and conflicting challenge of securing users’ data while enabling a rich ecosystem of data-driven applications. In this paper, we propose a PDMS architecture leveraging TEEs as a basis for security. Unlike existing solutions, our architecture allows for data processing extensiveness through the integration of any user-defined functions, albeit untrusted by the data owner. In this context, we focus on aggregate computations of large sets of database objects and provide a first study to mitigate the very large potential data leakage. We introduce the necessary security building blocks and show that an upper bound on data leakage can be guaranteed to the PDMS user. We then propose practical evaluation strategies ensuring that the potential data leakage remains minimal with a reasonable performance overhead. Finally, we validate our proposal with an Intel SGX-based PDMS implementation on real data sets.
Robin Carpentier, Iulian Sandu Popa, Nicolas Anciaux
SSDBM2
2021 Practical Fully-Decentralized Secure Aggregation for Personal Data Management Systems
abstract
Personal Data Management Systems (PDMS) are flourishing, boosted by legal and technical means like smart disclosure, data portability and data altruism. A PDMS allows its owner to easily collect, store and manage data, directly generated by her devices, or resulting from her interactions with companies or administrations. PDMSs unlock innovative usages by crossing multiple data sources from one or many users, thus requiring aggregation primitives. Indeed, aggregation primitives are essential to compute statistics on user data, but are also a fundamental building block for machine learning algorithms. This paper proposes a protocol allowing for secure aggregation in a massively distributed PDMS environment, which adapts to selective participation and PDMSs characteristics, and is reliable with respect to failures, with no compromise on accuracy. Preliminary experiments show the effectiveness of our protocol which can adapt to several contexts with varying PDMSs characteristics in terms of communication speed or CPU resources and can adjust the aggregation strategy to the estimated selective participation.
Julien Mirval, Luc Bouganim, Iulian Sandu Popa
SSDBM3
2021 Mobile participatory sensing with strong privacy guarantees using secure probes
Iulian Sandu Popa, Dai Hai Ton That, Karine Zeitouni, Cristian Borcea
GeoInformatica1
2019 SEP2P: Secure and Efficient P2P Personal Data Processing
abstract
International audience
Julien Loudet, Iulian Sandu Popa, Luc Bouganim
EDBT2
2019 Personal Data Management Systems: The security and functionality standpoint
Nicolas Anciaux, Philippe Bonnet, Luc Bouganim, Benjamin Nguyen, Philippe Pucheral, Iulian Sandu Popa, Guillaume Scerri
Inf. Syst.6
2019 Personal Database Security and Trusted Execution Environments: A Tutorial at the Crossroads
abstract
Smart disclosure initiatives and new regulations such as GDPR in the EU increase the interest for Personal Data Management Systems (PDMS) being provided to individuals to preserve their entire digital life. Consequently, the thorny issue of data security becomes more and more prominent, but highly differs from traditional privacy issues in outsourced corporate databases. Concurrently, the emergence of Trusted Execution Environments (TEE) changes the game in privacy-preserving data management with novel security models. This tutorial offers a global perspective of the current state of work at the confluence of these two rapidly growing areas. The goal is threefold: (1) review and categorize PDMS solutions and identify existing privacy threats and countermeasures; (2) review new security models capitalizing on TEEs and related privacy-preserving data management solutions relevant to the personal context; (3) discuss new challenges at the intersection of PDMS security and TEE-based data management.
Nicolas Anciaux, Luc Bouganim, Philippe Pucheral, Iulian Sandu Popa, Guillaume Scerri
Proc. VLDB Endow.4
2019 DISPERS: Securing Highly Distributed Queries on Personal Data Management Systems
abstract
International audience
Julien Loudet, Iulian Sandu Popa, Luc Bouganim
Proc. VLDB Endow.2
2017 Supporting secure keyword search in the personal cloud
Saliha Lallali, Nicolas Anciaux, Iulian Sandu Popa, Philippe Pucheral
Inf. Syst.3
2016 Distributed Secure Search in the Personal Cloud
abstract
International audience
Thu Le, Nicolas Anciaux, Sébastien Guilloton, Saliha Lallali, Philippe Pucheral, Iulian Sandu Popa
EDBT6
2016 PAMPAS: Privacy-Aware Mobile Participatory Sensing Using Secure Probes
abstract
Mobile participatory sensing could be used in many applications such as vehicular traffic monitoring, pollution tracking, or even health surveying. However, its success depends on finding a solution for querying large numbers of users which protects user location privacy and works in real-time. This paper presents PAMPAS, a privacy-aware mobile distributed system for efficient data aggregation in mobile participatory sensing. In PAMPAS, mobile devices enhanced with secure hardware, called secure probes (SPs), perform distributed query processing, while preventing users from accessing other users' data. A supporting server infrastructure (SSI) coordinates the inter-SP communication and the computation tasks executed on SPs. PAMPAS ensures that SSI cannot link the location reported by SPs to the user identities even if SSI has additional background information. In addition to its novel system architecture, PAMPAS also proposes two new protocols for privacy-aware location-based aggregation and adaptive spatial partitioning of SPs that work efficiently on resource-constrained SPs. Our experimental results and security analysis demonstrate that these protocols are able to collect the data, aggregate them, and share statistics or derived models in real-time, without any location privacy leakage.
Dai Hai Ton That, Iulian Sandu Popa, Karine Zeitouni, Cristian Borcea
SSDBM2
2015 PPTM: Privacy-Aware Participatory Traffic Monitoring Using Mobile Secure Probes
abstract
Privacy became one of the main concerns in location-based services in general and in community-based traffic monitoring in particular. This demonstration presents a new approach for privacy preserving online traffic monitoring using mobile probes. It combines hardware and software solutions, and a secure protocol to collect, aggregate and share the traffic information.
Dai Hai Ton That, Iulian Sandu Popa, Karine Zeitouni
MDM (1)2
2015 A Secure Search Engine for the Personal Cloud
abstract
The emerging Personal Could paradigm holds the promise of a Privacy-by-Design storage and computing platform where personal data remain under the individual's control while being shared by valuable applications. However, leaving the data management control to user's hands pushes the security issues to the user's platform. This demonstration presents a Secure Personal Cloud Platform relying on a query and access control engine embedded in a tamper resistant hardware device connected to the user's platform. The main difficulty lies in the design of an inverted document index and its related search and update algorithms capable of tackling the strong hardware constraints of these devices. We have implemented our engine on a real tamper resistant hardware device and present its capacity to regulate the access to a personal dataspace. The objective of this demonstration is to show (1) that secure hardware is a key enabler of the Personal Cloud paradigm and (2) that new embedded indexing and querying techniques can tackle the hardware constraints of tamper-resistant devices and provide scalable solutions for the Personal Cloud.
Saliha Lallali, Nicolas Anciaux, Iulian Sandu Popa, Philippe Pucheral
SIGMOD Conference3
2015 Spatio-temporal compression of trajectories in road networks
Iulian Sandu Popa, Karine Zeitouni, Vincent Oria, Ahmed Kharrat
GeoInformatica1
2015 A Scalable Search Engine for Mass Storage Smart Objects
abstract
This paper presents a new embedded search engine designed for smart objects. Such devices are generally equipped with extremely low RAM and large Flash storage capacity. To tackle these conflicting hardware constraints, conventional search engines privilege either insertion or query scalability but cannot meet both requirements at the same time. Moreover, very few solutions support document deletions and updates in this context. In this paper, we introduce three design principles, namely Write-Once Partitioning, Linear Pipelining and Background Linear Merging, and show how they can be combined to produce an embedded search engine reconciling high insert/delete/update rate and query scalability. We have implemented our search engine on a development board having a hardware configuration representative for smart objects and have conducted extensive experiments using two representative datasets. The experimental results demonstrate the scalability of the approach and its superiority compared to state of the art methods.
Nicolas Anciaux, Saliha Lallali, Iulian Sandu Popa, Philippe Pucheral
Proc. VLDB Endow.3
2014 Tutorial: Managing Personal Data with Strong Privacy Guarantees
abstract
International audience
Nicolas Anciaux, Benjamin Nguyen, Iulian Sandu Popa
EDBT3
2013 Trusted Cells: A Sea Change for Personal Data Services
Nicolas Anciaux, Philippe Bonnet, Luc Bouganim, Benjamin Nguyen, Iulian Sandu Popa, Philippe Pucheral
CIDR5
2013 Personal Data Management with Secure Hardware: How to Keep Your Data at Hand
abstract
We review existing solutions for personal data management, present a functional architecture for such decentralized alternatives, expose recent techniques dealing with embedded data management and global query processing in this architecture, and conclude by presenting existing and future implementations.
Nicolas Anciaux, Benjamin Nguyen, Iulian Sandu Popa
MDM (2)3
2011 Indexing in-network trajectory flows
Iulian Sandu Popa, Karine Zeitouni, Vincent Oria, Dominique Barth, Sandrine Vial
VLDB J.1
2010 PARINET: A tunable access method for in-network trajectories
abstract
In this paper we propose PARINET, a new access method to efficiently retrieve the trajectories of objects moving in networks. The structure of PARINET is based on a combination of graph partitioning and a set of composite B+-tree local indexes. PARINET is designed for historical data and relies on the distribution of the data over the network as for historical data, the data distribution is known in advance. Because the network can be modeled using graphs, the partitioning of the trajectory data is based on graph partitioning theory and can be tuned for a given query load. The data in each partition is indexed on the time component using B+-trees. We study different types of queries, and provide an optimal configuration for several scenarios. PARINET can easily be integrated into any RDBMS, which is an essential asset particularly for industrial or commercial applications. The experimental evaluation under an off-the-shelf DBMS shows that PARINET is robust. It also significantly outperforms both MON-tree and another R-tree based access method which are the reference indexing techniques for in-network trajectory databases.
Iulian Sandu Popa, Karine Zeitouni, Vincent Oria, Dominique Barth, Sandrine Vial
ICDE1