EDBT 2026 Demo / reviewers in the wild / expert
Felipe Huici
dblp:80/5046
· DBLP profile ↗
29ranked-venue papers
2as first author
7since 2021 · last 2026
0009-0008-9094-3585ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 2 first-authorSystems, architecture and hardware · 10 · 5 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Wayfinder: Automated Operating System SpecializationabstractOperating system specialization is a well-known approach to optimize a specific application's performance, memory usage, security, or other important metrics. Specializing an OS for an application is typically a manual process that requires great expertise. Specialization through configuration lends itself well to automation; however, it is challenging due to the sheer size of the configuration space of modern OSes, the difficulty to quantify that space, the long time it takes to evaluate a configuration, and the large number of invalid configurations. Hence, existing attempts at specializing OSes automatically are limited to switching features on and off to minimize memory consumption or attack surface, and cannot target metrics such as performance. Alexander Jung 0002, Cezar Craciunoiu, Nikolaos Karaolidis, Hugo Lefeuvre, Daniel Oñoro-Rubio, Felipe Huici, Charalampos Rotsos, Pierre Olivier |
EuroSys | 6 |
| 2024 | Loupe: Driving the Development of OS Compatibility LayersabstractSupporting mainstream applications is fundamental for a new OS to have impact. It is generally achieved by developing a layer of compatibility allowing applications developed for a mainstream OS like Linux to run unmodified on the new OS. Building such a layer, as we show, results in large engineering inefficiencies due to the lack of efficient methods to precisely measure the OS features required by a set of applications. Hugo Lefeuvre, Gaulthier Gain, Vlad-Andrei Badoiu, Daniel Dinca, Vlad-Radu Schiller, Costin Raiciu, Felipe Huici, Pierre Olivier |
ASPLOS (1) | 7 |
| 2023 | Assessing the Impact of Interface Vulnerabilities in Compartmentalized Software
Hugo Lefeuvre, Vlad-Andrei Badoiu, Felipe Huici, Nathan Dautenhahn, Pierre Olivier |
NDSS | 4 |
| 2022 | FlexOS: towards flexible OS isolationabstractAt design time, modern operating systems are locked in a specific safety and isolation strategy that mixes one or more hardware/software protection mechanisms (e.g. user/kernel separation); revisiting these choices after deployment requires a major refactoring effort. This rigid approach shows its limits given the wide variety of modern applications' safety/performance requirements, when new hardware isolation mechanisms are rolled out, or when existing ones break. Hugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung 0002, Stefan Teodorescu, Sebastian Rauch, Felipe Huici, Costin Raiciu, Pierre Olivier |
ASPLOS | 6 |
| 2022 | Want more unikernels?: inflate them!abstractUnikernels are on the rise in the cloud. These lightweight virtual machines (VMs) specialized to a single application offer the same level of isolation as full-blown VMs, while providing performance superior to standard Linux-based VMs or even to containers. However, their inherent specialization renders memory deduplication ineffective, causing unikernels, in practice, to consume more memory than their small memory footprint would suggest. This makes them less advantageous when thousands of SaaS and/or FaaS unikernels instances have to run on the same server. Gaulthier Gain, Cyril Soldani, Felipe Huici, Laurent Mathy |
SoCC | 3 |
| 2021 | Unikraft: fast, specialized unikernels the easy wayabstractUnikernels are famous for providing excellent performance in terms of boot times, throughput and memory consumption, to name a few metrics. However, they are infamous for making it hard and extremely time consuming to extract such performance, and for needing significant engineering effort in order to port applications to them. We introduce Unikraft, a novel micro-library OS that (1) fully modularizes OS primitives so that it is easy to customize the unikernel and include only relevant components and (2) exposes a set of composable, performance-oriented APIs in order to make it easy for developers to obtain high performance. Simon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam, Alexander Jung 0002, Gaulthier Gain, Cyril Soldani, Costin Lupu, Stefan Teodorescu, Costi Raducanu, Cristian Banu, Laurent Mathy, Razvan Deaconescu, Costin Raiciu, Felipe Huici |
EuroSys | 15 |
| 2021 | FlexOS: making OS isolation flexibleabstractOS design is traditionally heavily intertwined with protection mechanisms. OSes statically commit to one or a combination of (1) hardware isolation, (2) runtime checking, and (3) software verification early at design time. Changes after deployment require major refactoring; as such, they are rare and costly. In this paper, we argue that this strategy is at odds with recent hardware and software trends: protections break (Meltdown), hardware becomes heterogeneous (Memory Protection Keys, CHERI), and multiple mechanisms can now be used for the same task (software hardening, verification, HW isolation, etc). In short, the choice of isolation strategy and primitives should be postponed to deployment time. Hugo Lefeuvre, Vlad-Andrei Badoiu, Stefan Teodorescu, Pierre Olivier, Tiberiu Mosnoi, Razvan Deaconescu, Felipe Huici, Costin Raiciu |
HotOS | 7 |
| 2020 | SOL: Effortless Device Support for AI Frameworks without Source Code ChangesabstractModern high performance computing clusters heavily rely on accelerators to overcome the limited compute power of CPUs. These supercomputers run various applications from different domains such as simulations, numerical applications or artificial intelligence (AI). As a result, vendors need to be able to efficiently run a wide variety of workloads on their hardware.In the AI domain this is in particular exacerbated by the existance of a number of popular frameworks (e.g, PyTorch, TensorFlow, etc.) that have no common code base, and can vary in functionality. The code of these frameworks evolves quickly, making it expensive to keep up with all changes and potentially forcing developers to go through constant rounds of upstreaming.In this paper we explore how to provide hardware support in AI frameworks without changing the framework's source code in order to minimize maintenance overhead. We introduce SOL, an AI acceleration middleware that provides a hardware abstraction layer that allows us to transparently support heterogenous hardware. As a proof of concept, we implemented SOL for PyTorch with three backends: CPUs, GPUs and vector processors. Nicolas Weber, Felipe Huici |
CCGRID | 2 |
| 2020 | Towards Highly Specialized, POSIX -compliant Software Stacks with Unikraft: Work-in-ProgressabstractIncreasingly, embedded devices are being equipped with ARM processors. Because of ease-of-use and widespread support for drivers and applications, Linux is often used as the OS of choice, even though it consumes a significant amount of the device's limited resources and its large attack surface presents opportunities for exploits. In this paper we propose Unikraft, a fully librarized operating system and build tool which allows for generating specialized OSes and software stacks targeting specific applications, while removing unneeded functionality. As a proof of concept, we port Unikraft to the Raspberry Pi 3 B+ and to a Xilinx Ultra96-V2. On these boards, Unikraft is able to boot in 88-158 milliseconds, consume only hundreds of KBs of memory when running real-world application such as NGINX, all the while providing visible reductions in power consumption compared to Linux distributions. Unikraft is an open source project and can be found at unikraft.org. Sharan Santhanam, Simon Kuenzer, Hugo Lefeuvre, Felipe Huici, Alexander Jung 0002, Santiago Pagani, George-Cristian Muraru, Stefano Stabellini, Justin He, Jonathan Beri |
EMSOFT | 4 |
| 2019 | FlowBlaze: Stateful Packet Processing in Hardware
Salvatore Pontarelli, Roberto Bifulco, Marco Bonola, Carmelo Cascone, M. Spaziani Brunella, Valerio Bruschi, Davide Sanvito, Giuseppe Siracusano, Antonio Capone, Michio Honda, Felipe Huici |
NSDI | 11 |
| 2019 | Unleashing the power of unikernels with unikraftabstractRecent research has shown that unikernels, lightweight virtual machines tailored to specific applications, have great potential in terms of performance, tiny boot times, small memory consumption, and a reduced trusted compute base. Creating and optimizing them, however, is currently a painful, time-consuming process that often needs redoing for every application. With Unikraft, we introduce a system for automatically building unikernels that drastically reduces this time without negatively impacting performance. Simon Kuenzer, Sharan Santhanam, Yuri Volchkov, Felipe Huici, Joel Nider, Mike Rapoport, Costin Lupu |
SYSTOR | 5 |
| 2019 | Cellular access multi-tenancy through small-cell virtualization and common RF front-end sharingabstractMobile traffic demand is expected to grow as much as eight-fold in the coming next five years, putting strain in current wireless infrastructures . Meanwhile the diversity of traffic and standards may explode as well. One of the most common means for matching these mounting requirements is through network densification , essentially increasing the density of deployment of operators’ base stations in many small cells and handling timing critical traffic at the edge. In this paper we take a step in that direction by implementing a virtualized small cell base station consisting of multiple, isolated LTE PHY stacks running concurrently on top of a hypervisor deployed on a cheap, off-the-shelf x86 server and a shared radio head. In particular, we show that it is possible to run multiple virtualized base stations while achieving throughput equal or close to the theoretical maximum. In contrast to C-RAN (Cloud/Centralized Radio Access Network), our virtualized small cell base station has full stack at the edge so that a low latency high throughput front-haul, which is necessary in C-RAN architecture, is not needed. This approach brings all the flexibility and configurability (from network management point of view) that a software based implementation provides while the transparent architecture enables the possibility of multiple standards sharing the same radio infrastructure. Jose Mendes, Xianjun Jiao, Andres Garcia-Saavedra, Felipe Huici, Ingrid Moerman |
Comput. Commun. | 4 |
| 2017 | HyperNF: building a high performance, high utilization and fair NFV platformabstractNetwork Function Virtualization has been touted as the silver bullet for tackling a number of operator problems, including vendor lock-in, fast deployment of new functionality, converged management, and lower expenditure since packet processing runs on inexpensive commodity servers. The reality, however, is that, in practice, it has proved hard to achieve the stable, predictable performance provided by hardware middleboxes, and so operators have essentially resorted to throwing money at the problem, deploying highly underutilized servers (e.g., one NF per CPU core) in order to guarantee high performance during peak periods and meet SLAs. Kenichi Yasukata, Felipe Huici, Vincenzo Maffione, Giuseppe Lettieri, Michio Honda |
SoCC | 2 |
| 2017 | My VM is Lighter (and Safer) than your ContainerabstractContainers are in great demand because they are lightweight when compared to virtual machines. On the downside, containers offer weaker isolation than VMs, to the point where people run containers in virtual machines to achieve proper isolation. In this paper, we examine whether there is indeed a strict tradeoff between isolation (VMs) and efficiency (containers). We find that VMs can be as nimble as containers, as long as they are small and the toolstack is fast enough. Filipe Manco, Costin Lupu, Florian Schmidt 0002, Jose Mendes, Simon Kuenzer, Sumit Sati, Kenichi Yasukata, Costin Raiciu, Felipe Huici |
SOSP | 9 |
| 2017 | Unikernels Everywhere: The Case for Elastic CDNsabstractVideo streaming dominates the Internet's overall traffic mix, with reports stating that it will constitute 90% of all consumer traffic by 2019. Most of this video is delivered by Content Delivery Networks (CDNs), and, while they optimize QoE metrics such as buffering ratio and start-up time, no single CDN provides optimal performance. In this paper we make the case for elastic CDNs, the ability to build virtual CDNs on-the-fly on top of shared, third-party infrastructure at a scale. To bring this idea closer to reality we begin by large-scale simulations to quantify the effects that elastic CDNs would have if deployed, and build and evaluate MiniCache, a specialized, minimalistic virtualized content cache that runs on the Xen hypervisor. MiniCache is able to serve content at rates of up to 32 Gb/s and handle up to 600K reqs/sec on a single CPU core, as well as boot in about 90 milliseconds on x86 and around 370 milliseconds on ARM32. Simon Kuenzer, Anton Ivanov, Filipe Manco, Jose Mendes, Yuri Volchkov, Florian Schmidt 0002, Kenichi Yasukata, Michio Honda, Felipe Huici |
VEE | 9 |
| 2017 | Re-Designing Dynamic Content Delivery in the Light of a Virtualized InfrastructureabstractWe explore the opportunities and design options enabled by novel SDN and NFV technologies, by re-designing a dynamic content delivery network (CDN) service. Our system, named MOSTO, provides performance levels comparable to that of a regular CDN, but does not require the deployment of a large distributed infrastructure. In the process of designing the system, we identify relevant functions that could be integrated in the future Internet infrastructure. Such functions greatly simplify the design and effectiveness of services, such as MOSTO. We demonstrate our system using a mixture of simulation, emulation, testbed experiments, and by realizing a proof-of-concept deployment in a planet-wide commercial cloud system. Giuseppe Siracusano, Roberto Bifulco, Martino Trevisan, Tobias Jacobs, Simon Kuenzer, Stefano Salsano, Nicola Blefari-Melazzi, Felipe Huici |
IEEE J. Sel. Areas Commun. | 8 |
| 2015 | In-Net: in-network processing for the massesabstractNetwork Function Virtualization is pushing network operators to deploy commodity hardware that will be used to run middlebox functionality and processing on behalf of third parties: in effect, network operators are slowly but surely becoming in-network cloud providers. The market for innetwork clouds is large, ranging from content providers, mobile applications and even end-users. Radu Stoenescu, Vladimir Andrei Olteanu, Matei Popovici, Mohamed Ahmed 0001, Roberto Bifulco, Filipe Manco, Felipe Huici, Georgios Smaragdakis, Mark Handley, Costin Raiciu |
EuroSys | 8 |
| 2015 | Enhancing the BRAS through virtualizationabstractBroadband Remote Access Servers (BRASes) are crucial middleboxes in DSL access networks, providing the first IP point in the network for subscribers and enforcing operator policies. The number of functions provided by BRASes, combined with the key role they play in the network, means that these devices are expensive, difficult to change, and constitute a single point of failure. In order to overcome these limitations, we propose to virtualize the BRAS and to enhance it with a control interface that can be exploited by management systems in order to introduce live session migration and higher reliability. Our proof-of-concept implementation shows that our virtual software BRAS is able to handle thousands of sessions while forwarding and shaping traffic at rates of millions of packets per second on commodity hardware, and that the live session migration feature enables the implementation of high-reliability scenarios. Thomas Dietz, Roberto Bifulco, Filipe Manco, Hans-Jörg Kolbe, Felipe Huici |
NetSoft | 6 |
| 2014 | ClickOS and the Art of Network Function Virtualization
Mohamed Ahmed 0001, Costin Raiciu, Vladimir Andrei Olteanu, Michio Honda, Roberto Bifulco, Felipe Huici |
NSDI | 7 |
| 2014 | Towards the super fluid cloudabstractTraditionally, the number of VMs running on a server and how quickly these can be migrated has been less than optimal mostly because of the memory and CPU requirements imposed on the system by the full-fledged OSes that the VMs run. More recently, work towards VMs based on minimalistic or specialized OSes has started pushing the envelope of how reactive or fluid the cloud can be. In this demo we will demonstrate how to concurrently execute thousands of Xen-based VMs on a single inexpensive server. We will also show instantiation and migraion of such VMs in tens of milliseconds, and transparent, wide area migration of virtualized middleboxes by combining such VMs with the multi-path TCP (MPTCP) protocol. Filipe Manco, Felipe Huici |
SIGCOMM | 3 |
| 2013 | Toward composable network traffic measurementabstractAs the growth of Internet traffic volume and diversity continues, passive monitoring and data analysis, crucial to the correct operation of networks and the systems that rely on them, has become an increasingly difficult task. We present the design and implementation of Blockmon, a flexible, high performance system for network monitoring and analysis. We present experimental results demonstrating Blockmon's performance, running simple analyses at 10Gb/s line rate on commodity hardware; and compare its performance with that of existing programmable measurement systems, showing significant improvement (as much as twice as fast) especially for small packet sizes. We further demonstrate Blockmon's applicability to measurement and data analysis by implementing and evaluating three sample applications: a flow meter, a TCP SYN flood detector, and a VoIP anomaly-detection system. Andrea Di Pietro, Felipe Huici, Nicola Bonelli, Brian Trammell, Petr Kastovsky, Tristan Groleat, Sandrine Vaton, Maurizio Dusi |
INFOCOM | 2 |
| 2013 | A peek into the future: predicting the evolution of popularity in user generated contentabstractContent popularity prediction finds application in many areas, including media advertising, content caching, movie revenue estimation, traffic management and macro-economic trends forecasting, to name a few. However, predicting this popularity is difficult due to, among others, the effects of external phenomena, the influence of context such as locality and relevance to users,and the difficulty of forecasting information cascades. Mohamed Ahmed 0001, Stella Spagna, Felipe Huici, Saverio Niccolini |
WSDM | 3 |
| 2012 | Enabling dynamic network processing with clickOSabstractNo abstract available. Mohamed Ahmed 0001, Felipe Huici, Armin Jahanpanah |
SIGCOMM | 2 |
| 2012 | Blockmon: a high-performance composable network traffic measurement systemabstractPassive network monitoring and data analysis, crucial to the correct operation of networks and the systems that rely on them, has become an increasingly difficult task given continued growth and diversification of the Internet. In this demo we present Blockmon, a novel composable measurement system with the flexibility to allow for a wide range of traffic monitoring and data analysis, as well as the necessary mechanisms to yield high performance on today's modern multi-core hardware. In this demo we use Blockmon's GUI to show how to easily create Blockmon applications and display data exported by them. We present a simple flow meter application and a more involved VoIP nomaly detection one. Felipe Huici, Andrea Di Pietro, Brian Trammell, José María Gómez Hidalgo, Daniel Martinez Ruiz, Nico d'Heureuse |
SIGCOMM | 1 |
| 2010 | Crosstalk: A Scalable Cross-Protocol Monitoring System for Anomaly DetectionabstractMonitoring is crucial both to the correct operation of a network and to the services that run on it. Operators perform monitoring for various purposes, including traffic engineering, quality of service, security and detection of faults and mis-configurations. However, the relentless growth of IP traffic volume renders real-time monitoring and analysis of data a very challenging problem. In this paper we introduce Crosstalk, a scalable and efficient distributed monitoring architecture that uses cross-protocol correlation to detect network anomalies. While applicable to a wide range of applications such as botnet detection, spam mitigation and mis-configurations, we pick a point in this application space, concentrating on VoIP attacks. We present extensive simulation results based both on generated calls and on millions of Call Data Records (CDRs) from a large VoIP operator to show our approach's performance and effectiveness. Andrea Di Pietro, Felipe Huici, Diego Costantini, Takahide Sugita, Saverio Niccolini |
ICC | 2 |
| 2009 | Protecting SIP against Very Large Flooding DoS AttacksabstractThe use of the Internet for VoIP communications has seen an important increase over the last few years, with the Session Initiation Protocol (SIP) as the most popular protocol used for signaling. Unfortunately, SIP devices are quite vulnerable to Denial-of-Service (DoS) attacks, many of them becoming unresponsive and even resetting with floods of only hundreds of packets per second. In this paper we introduce SIP Defender, a new distributed filtering architecture designed to protect SIP devices against large, flooding DoS attacks. In addition, we describe the implementation of the architecture's SIP Controllers, the network devices in charge of performing the actual filtering. We further present testbed performance figures for these, showing that a controller built on commodity hardware can forward an impressive 2.5 million packets per second for small SIP packets while applying one million filters as well as anti-spoofing mechanisms. Felipe Huici, Saverio Niccolini, Nico d'Heureuse |
GLOBECOM | 1 |
| 2009 | Enabling high-speed and extensible real-time communications monitoringabstractThe use of the Internet as a medium for real-time communications has grown significantly over the past few years. However, the best-effort model of this network is not particularly well-suited to the demands of users who are familiar with the reliability, quality and security of the public switched telephone network. If the growth is to continue, monitoring and real time analysis of communication data will be needed in order to ensure good call quality, and should degradation occur, to take corrective action. Writing this type of monitoring application is difficult and time consuming: VoIP traffic not only tends to use dynamic ports, but its real-time nature, along with the fact that its packets tend to be small, impose non-trivial performance requirements. In this paper we present RTC-Mon, the real-time communications monitoring framework, which provides an extensible platform for the quick development of high-speed, real-time monitoring applications. While the focus is on VoIP traffic, the framework is general and is capable of monitoring any type of real-time communications traffic. We present testbed performance results for the various components of RTC-Mon, showing that it can monitor a large number of concurrent flows without losing packets. In addition, we implemented a proof-of-concept application that can not only track statistics about a large number of calls and their users, but that consists of only 800 lines of code, showing that the framework is efficient and that it also significantly reduces development time. Francesco Fusco, Felipe Huici, Luca Deri, Saverio Niccolini, Thilo Ewald |
Integrated Network Management | 2 |
| 2009 | ROAR: increasing the flexibility and performance of distributed searchabstractTo search the web quickly, search engines partition the web index over many machines, and consult every partition when answering a query. To increase throughput, replicas are added for each of these machines. The key parameter of these algorithms is the trade-off between replication and partitioning: increasing the partitioning level improves query completion time since more servers handle the query, but may incur non-negligible startup costs for each sub-query. Finding the right operating point and adapting to it can significantly improve performance and reduce costs. Costin Raiciu, Felipe Huici, Mark Handley, David S. Rosenblum |
SIGCOMM | 2 |
| 2008 | Towards high performance virtual routers on commodity hardwareabstractModern commodity hardware architectures, with their multiple multi-core CPUs and high-speed system interconnects, exhibit tremendous power. In this paper, we study performance limitations when building both software routers and software virtual routers on such systems. We show that the fundamental performance bottleneck is currently the memory system, and that through careful mapping of tasks to CPU cores, we can achieve forwarding rates of 7 million minimum-sized packets per second on mid-range server-class systems, thus demonstrating the viability of software routers. We also find that current virtualisation systems, when used to provide forwarding engine virtualisation, yield aggregate performance equivalent to that of a single software router, a tenfold improvement on current virtual router platform performance. Finally, we identify principles for the construction of high-performance software router systems on commodity hardware, including full router virtualisation support. Norbert Egi, Adam Greenhalgh, Mark Handley, Mickaël Hoerdt, Felipe Huici, Laurent Mathy |
CoNEXT | 5 |