EDBT 2026 Demo / reviewers in the wild / expert
James W. Mickens
dblp:90/1843 · also James Mickens
· DBLP profile ↗
38ranked-venue papers
12as first author
10since 2021 · last 2026
0009-0007-7296-5185ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 4 first-author · 1 since 2021Security and privacy · 11 · 2 first-author · 6 since 2021Systems, architecture and hardware · 10 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 5 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mirage: Private, Mobility-based Routing for Censorship Evasion
Zachary Ratliff, RuoxingYang, Avery Bai, Harel Berger, Micah Sherr, James W. Mickens |
NDSS | 6 |
| 2025 | Amigo: Secure Group Mesh Messaging in Realistic Protest SettingsabstractDuring large-scale protests, a repressive government will often disable the Internet to thwart communication between protesters. Smartphone mesh networks, which route messages over short-range, possibly ephemeral, radio connections between nearby phones, allow protesters to communicate without relying on centralized Internet infrastructure. Unfortunately, prior work on providing secure communication in Internet shutdown settings fails to adequately consider protester needs. Previous attempts fail to support efficient private group communication (a crucial requirement for protests), and evaluate their solutions in network environments which fail to accurately capture link churn, physical spectrum contention, and the mobility models found in realistic protest settings. In this paper, we introduce Amigo, a novel mesh messaging system which supports group communication through a decentralized approach to continuous key agreement, and forwards messages using a novel routing protocol. Amigo is uniquely designed to handle the challenges of ad-hoc routing scenarios, where dynamic network topologies and node mobility make achieving key agreement nontrivial. Our extensive simulations reveal the poor scalability of prior approaches, the benefits of Amigo's protest-specific optimizations, and the challenges that still must be solved to scale secure mesh networks to protests with thousands of participants. David Inyangson, Sarah Radway, Tushar M. Jois, Nelly Fazio, James W. Mickens |
CCS | 5 |
| 2025 | Timing Attacks on Differential Privacy are PracticalabstractDifferential privacy (DP) has become a standard approach for computing privacy-preserving statistics. However, in interactive settings, the observable runtime of DP queries can inadvertently leak sensitive information, violating privacy guarantees. Prior work has shown that timing side channels can undermine DP in specific settings. In this work, we show that popular libraries for implementing differential privacy, including diffprivlib, OpenDP, and PyDP, frequently introduce such timing side channels, leading to measurable privacy degradation. Our analysis reveals timing vulnerabilities not only within commonly used DP mechanisms (e.g., private sums, counts, means, and selection) but also in commonly used pre-processing steps such as filtering and sorting. We show that these seemingly innocuous operations frequently exhibit runtimes that are sensitive not only to the presence of an individual's data in the input but also to the ordering of the input data. Zachary Ratliff, Nicolás Berrios, James W. Mickens |
CCS | 3 |
| 2025 | Guillotine: Hypervisors for Isolating Malicious AIsabstractAs AI models become more embedded in critical sectors like finance, healthcare, and the military, their inscrutable behavior poses ever-greater risks to society. To mitigate this risk, we propose Guillotine, a hypervisor architecture for sandboxing powerful AI models---models that, by accident or malice, can generate existential threats to humanity. Although Guillotine borrows some well-known virtualization techniques, Guillotine must also introduce fundamentally new isolation mechanisms to handle the unique threat model posed by existential-risk AIs. For example, a rogue AI may try to introspect upon hypervisor software or the underlying hardware substrate to enable later subversion of that control plane; thus, a Guillotine hypervisor requires careful co-design of the hypervisor software and the CPUs, RAM, NIC, and storage devices that support the hypervisor software, to thwart side channel leakage and more generally eliminate mechanisms for AI to exploit reflection-based vulnerabilities. Beyond such isolation at the software, network, and microarchitectural layers, a Guillotine hypervisor must also provide physical fail-safes more commonly associated with nuclear power plants, avionic platforms, and other types of mission-critical systems. Physical fail-safes, e.g., involving electromechanical disconnection of network cables, or the flooding of a datacenter which holds a rogue AI, provide defense in depth if software, network, and microarchitectural isolation is compromised and a rogue AI must be temporarily shut down or permanently destroyed. James W. Mickens, Sarah Radway, Ravi Netravali |
HotOS | 1 |
| 2024 | SmartNIC Security Isolation in the Cloud with S-NICabstractModern smart NICs provide little isolation between the network functions belonging to different tenants. These NICs also do not protect network functions from the datacenter-provided management OS which runs on the smart NIC. We describe concrete attacks which allow a network function's state to leak to (or be modified by) another network function or the management OS. We then introduce S-NIC, a new hardware design for smart NICs that provides strong isolation guarantees. S-NIC pervasively virtualizes hardware accelerators, enforces single-owner semantics for each line in on-NIC cache and RAM, and provides dedicated bus bandwidth for each network function. Using this design, we eliminate side channels involving shared hardware state, and give each network function the illusion of having a private smart NIC. We show how these virtual NICs can be integrated with preexisting datacenter technologies for virtual LANs and trusted host-level computations like SGX enclaves. The overall result is that S-NIC enables strongly-isolated, NIC-accelerated datacenter applications; in these applications, network functions and host-level code receive hardware-guaranteed isolation from other applications and the datacenter provider. Yang Zhou 0008, Mark Wilkening, James W. Mickens, Minlan Yu |
EuroSys | 3 |
| 2024 | Holepunch: Fast, Secure File Deletion with Crash ConsistencyabstractA file system provides secure deletion if, after a file is deleted, an attacker with physical possession of the storage device cannot recover any data from the deleted file. Unfortunately, secure deletion is not provided by commodity file systems. Even file systems which explicitly desire to provide secure deletion are challenged by the subtleties of hardware controllers on modern storage devices; those controllers obscure the mappings between logical blocks and physical blocks, silently duplicate physical blocks, and generally make it hard for host-level software to make reliable assumptions about how file data is kept on the device. State-of-the-art frameworks for secure deletion also have no crash consistency, meaning that an ill-timed power outage or software fault will desynchronize keys and the associated encrypted file data, corrupting the file system.In this paper, we present Holepunch, a new software-level approach for implementing secure deletion. Holepunch treats the storage device as a black box, providing secure deletion via cryptographic erasure. Holepunch uses per-file keys to transparently encrypt outgoing file writes and decrypt incoming file reads, ensuring that all physical data in the storage device is always encrypted. Holepunch uses puncturable pseudorandom functions (PPRFs) to quickly access file keys; upon the deletion of file f, Holepunch updates the PPRF so that, even if the PPRF is recovered, the PPRF cannot be used to generate f’s key. By using PPRFs instead of the key trees leveraged by prior work, Holepunch reduces both the memory pressure caused by key management and the number of disk IOs needed to access files. Holepunch stores its master key in secure TPM storage, and uses a novel journaling scheme to provide crash consistency between TPM state and on-disk state. Zachary Ratliff, Wittmann Goh, Abe Wieland, James W. Mickens |
SP | 4 |
| 2023 | Splice: Efficiently Removing a User's Data from In-memory Application StateabstractSplice is a new programming framework that allows security-conscious applications to efficiently locate and delete a user's in-memory state. The core technical challenge is determining how to delete a user's memory values without breaking application-specific semantic invariants involving the memory state of remaining users. Splice solves this problem using three techniques: taint tracking (which traces how a user's data flows through memory), deletion by synthesis (which overwrites each user-owned memory value in place, replacing it with a value that preserves the symbolic constraints of enclosing data structures), and a novel type system (which forces applications to employ defensive programming to avoid computing over synthesize-deleted values in unsafe ways). Using four realistic applications that we ported to Splice, we show that Splice's type system and defensive programming requirements are not onerous for developers. We also demonstrate that Splice's run-time overheads are similar to those of prior taint tracking systems, while enabling strong deletion semantics. Xueyuan Han, James W. Mickens, Siddhartha Sen 0001 |
CCS | 2 |
| 2022 | Carbink: Fault-Tolerant Far Memory
Yang Zhou 0008, Hassan M. G. Wassel, Sihang Liu 0001, James W. Mickens, Minlan Yu, Chris Kennelly, David E. Culler, Henry M. Levy, Amin Vahdat |
OSDI | 5 |
| 2021 | Oblique: Accelerating Page Loads Using Symbolic Execution
Ronny Ko, James W. Mickens, Blake Loring, Ravi Netravali |
NSDI | 2 |
| 2021 | SIGL: Securing Software Installations Through Deep Graph Learning
Xueyuan Han, Xiao Yu 0007, Thomas Pasquier, Ding Li 0001, Junghwan Rhee, James W. Mickens, Margo I. Seltzer |
USENIX Security Symposium | 6 |
| 2020 | Unicorn: Runtime Provenance-Based Detector for Advanced Persistent Threats
Xueyuan Han, Thomas Pasquier, Adam Bates 0001, James W. Mickens, Margo I. Seltzer |
NDSS | 4 |
| 2019 | Reverb: Speculative Debugging for Web ApplicationsabstractBugs are common in web pages. Unfortunately, traditional debugging primitives like breakpoints are crude tools for understanding the asynchronous, wide-area data flows that bind client-side JavaScript code and server-side application logic. In this paper, we describe Reverb, a powerful new debugger that makes data flows explicit and queryable. Reverb provides three novel features. First, Reverb tracks precise value provenance, allowing a developer to quickly identify the reads and writes to JavaScript state that affected a particular variable's value. Second, Reverb enables speculative bug fix analysis. A developer can replay a program to a certain point, change code or data in the program, and then resume the replay; Reverb uses the remaining log of nondeterministic events to influence the post-edit replay, allowing the developer to investigate whether the hypothesized bug fix would have helped the original execution run. Third, Reverb supports wide-area debugging for applications whose server-side components use event-driven architectures. By tracking the data flows between clients and servers, Reverb enables speculative replaying of the distributed application. Ravi Netravali, James W. Mickens |
SoCC | 2 |
| 2019 | WatchTower: Fast, Secure Mobile Page Loads Using Remote Dependency ResolutionabstractRemote dependency resolution (RDR) is a proxy-driven scheme for reducing mobile page load times; a proxy loads a requested page using a local browser, fetching the page's resources over fast proxy-origin links instead of a client's slow last-mile links. In this paper, we describe two fundamental challenges to efficient RDR proxying: the increasing popularity of encrypted HTTPS content, and the fact that, due to time-dependent network conditions and page properties, RDR proxying can actually increase load times. We solve these problems by introducing a new, secure proxying scheme for HTTPS traffic, and by implementing WatchTower, a selective proxying system that uses dynamic models of network conditions and page structures to only enable RDR when it is predicted to help. WatchTower loads pages 21.2%-41.3% faster than state-of-the-art proxies and server push systems, while preserving end-to-end HTTPS security. Ravi Netravali, Anirudh Sivaraman, James W. Mickens, Hari Balakrishnan |
MobiSys | 3 |
| 2019 | Riverbed: Enforcing User-defined Privacy Constraints in Distributed Web Services
Frank Wang, Ronny Ko, James W. Mickens |
NSDI | 3 |
| 2018 | Veil: Private Browsing Semantics Without Browser-side Assistance
Frank Wang, James W. Mickens, Nickolai Zeldovich |
NDSS | 2 |
| 2018 | Prophecy: Accelerating Mobile Page Loads Using Final-state Write Logs
Ravi Netravali, James W. Mickens |
NSDI | 2 |
| 2018 | Vesper: Measuring Time-to-Interactivity for Web Pages
Ravi Netravali, Vikram Nathan, James W. Mickens, Hari Balakrishnan |
NSDI | 3 |
| 2016 | Polaris: Faster Page Loads Using Fine-grained Dependency Tracking
Ravi Netravali, Ameesh Goyal, James W. Mickens, Hari Balakrishnan |
NSDI | 3 |
| 2016 | Sieve: Cryptographically Enforced Access Control for User Data in Untrusted Clouds
Frank Wang, James W. Mickens, Nickolai Zeldovich, Vinod Vaikuntanathan |
NSDI | 2 |
| 2015 | Domino: understanding wide-area, asynchronous event causality in web applicationsabstractIn a modern web application, a single high-level action like a mouse click triggers a flurry of asynchronous events on the client browser and remote web servers. We introduce Domino, a new tool which automatically captures and analyzes end-to-end, asynchronous causal relationship of events that span clients and servers. Using Domino, we found uncharacteristically long event chains in Bing Maps, discovered data races in the WinJS implementation of promises, and developed a new server-side scheduling algorithm for reducing the tail latency of server responses. Ding Li 0001, James W. Mickens, Suman Nath, Lenin Ravindranath |
SoCC | 2 |
| 2015 | Amber: Decoupling User Data from Web Applications
Tej Chajed, Jon Gjengset, Jelle van den Hooff, M. Frans Kaashoek, James W. Mickens, Robert Morris 0005, Nickolai Zeldovich |
HotOS | 5 |
| 2015 | Mahimahi: Accurate Record-and-Replay for HTTP
Ravi Netravali, Anirudh Sivaraman, Somak Das, Ameesh Goyal, Keith Winstein, James W. Mickens, Hari Balakrishnan |
USENIX ATC | 6 |
| 2014 | Blizzard: Fast, Cloud-scale Block Storage for Cloud-oblivious Applications
James W. Mickens, Ed Nightingale, Jeremy Elson, Darren Gehring, Asim Kadav, Vijay Chidambaram, Krishna Nareddy |
NSDI | 1 |
| 2014 | Pivot: Fast, Synchronous Mashup Isolation Using Generator ChainsabstractPivot is a new JavaScript isolation framework for web applications. Pivot uses iframes as its low-level isolation containers, but it uses code rewriting to implement synchronous cross-domain interfaces atop the asynchronous cross-frame postMessage( ) primitive. Pivot layers a distributed scheduling abstraction across the frames, essentially treating each frame as a thread which can invoke RPCs that are serviced by external threads. By rewriting JavaScript call sites, Pivot can detect RPC invocations, Pivot exchanges RPC requests and responses via postMessage( ), and it pauses and restarts frames using a novel rewriting technique that translates each frame's JavaScript code into a restart able generator function. By leveraging both iframes and rewriting, Pivot does not need to rewrite all code, providing an order-of-magnitude performance improvement over rewriting-only solutions. Compared to iframe-only approaches, Pivot provides synchronous RPC semantics, which developers typically prefer over asynchronous RPCs. Pivot also allows developers to use the full, unrestricted JavaScript language, including powerful statements like eval( ). James W. Mickens |
IEEE Symposium on Security and Privacy | 1 |
| 2013 | Shroud: ensuring private access to large-scale data in the data center
Jacob R. Lorch, Bryan Parno, James W. Mickens, Mariana Raykova 0001, Joshua Schiffman |
FAST | 3 |
| 2012 | Rivet: Browser-agnostic Remote Debugging for Web Applications
James W. Mickens |
USENIX ATC | 1 |
| 2011 | Atlantis: robust, extensible execution environments for web applicationsabstractToday's web applications run inside a complex browser environment that is buggy, ill-specified, and implemented in different ways by different browsers. Thus, web applications that desire robustness must use a variety of conditional code paths and ugly hacks to deal with the vagaries of their runtime. Our new exokernel browser, called Atlantis, solves this problem by providing pages with an extensible execution environment. Atlantis defines a narrow API for basic services like collecting user input, exchanging network data, and rendering images. By composing these primitives, web pages can define custom, high-level execution environments. Thus, an application which does not want a dependence on Atlantis'predefined web stack can selectively redefine components of that stack, or define markup formats and scripting languages that look nothing like the current browser runtime. Unlike prior microkernel browsers like OP, and unlike compile-to-JavaScript frameworks like GWT, Atlantis is the first browsing system to truly minimize a web page's dependence on black box browser code. This makes it much easier to develop robust, secure web applications. James W. Mickens, Mohan Dhawan |
SOSP | 1 |
| 2011 | Memoir: Practical State Continuity for Protected ModulesabstractTo protect computation, a security architecture must safeguard not only the software that performs it but also the state on which the software operates. This requires more than just preserving state confidentiality and integrity, since, e.g., software may err if its state is rolled back to a correct but stale version. For this reason, we present Memoir, the first system that fully ensures the continuity of a protected software module's state. In other words, it ensures that a module's state remains persistently and completely inviolate. A key contribution of Memoir is a technique to ensure rollback resistance without making the system vulnerable to system crashes. It does this by using a deterministic module, storing a concise summary of the module's request history in protected NVRAM, and allowing only safe request replays after crashes. Since frequent NVRAM writes are impractical on modern hardware, we present a novel way to leverage limited trusted hardware to minimize such writes. To ensure the correctness of our design, we develop formal, machine-verified proofs of safety. To demonstrate Memoir's practicality, we have built it and conducted evaluations demonstrating that it achieves reasonable performance on real hardware. Furthermore, by building three useful Memoir-protected modules that rely critically on state continuity, we demonstrate Memoir's versatility. Bryan Parno, Jacob R. Lorch, John R. Douceur, James W. Mickens, Jonathan M. McCune |
IEEE Symposium on Security and Privacy | 4 |
| 2010 | Collaborative Measurements of Upload Speeds in P2P SystemsabstractIn this paper, we study the theory of collaborative upload bandwidth measurement in peer-to-peer environments. A host can use a bandwidth estimation probe to determine the bandwidth between itself and any other host in the system. The problem is that the result of such a measurement may not necessarily be the sender's upload bandwidth, since the most bandwidth restricted link on the path could also be the receiver's download bandwidth. In this paper, we formally define the bandwidth determination problem and devise efficient distributed algorithms. We consider two models, the free-departure and no-departure model, depending on whether hosts keep participating in the algorithm even after their bandwidth has been determined. We present lower bounds on the time-complexity of any collaborative bandwidth measurement algorithm in both models. We then show how, for realistic bandwidth distributions, the lower bounds can be overcome. Specifically, we present O(1) and O(log log n)-time algorithms for the two models. We corroborate these theoretical findings with practical measurements on a implementation on PlanetLab. John R. Douceur, James W. Mickens, Thomas Moscibroda, Debmalya Panigrahi |
INFOCOM | 2 |
| 2010 | Mugshot: Deterministic Capture and Replay for JavaScript Applications
James W. Mickens, Jeremy Elson, Jon Howell |
NSDI | 1 |
| 2010 | Crom: Faster Web Browsing Using Speculative Execution
James W. Mickens, Jeremy Elson, Jon Howell, Jacob R. Lorch |
NSDI | 1 |
| 2009 | ThunderDome: discovering upload constraints using decentralized bandwidth tournamentsabstractThunderDome is a system for collaboratively measuring upload bandwidths in ad-hoc peer-to-peer systems. It works by scheduling bandwidth probes between pairs of hosts, wherein each pairwise exchange reveals the upload constraint of one participant. Using the abstraction of bandwidth tournaments, unresolved hosts are successively paired with each other until every peer knows its upload bandwidth. To recover from measurement errors that corrupt its tournament schedule, ThunderDome aggregates multiple probe results for each host, avoiding pathological bandwidth estimations that would otherwise occur in systems with heterogeneous bandwidth distributions. For scalability, the coordination of probes is distributed across the hosts. Simulations on empirical and analytic bandwidth distributions--validated with wide-area PlanetLab experiments--show that ThunderDome efficiently yields upload bandwidth estimates that are robust to measurement error. John R. Douceur, James W. Mickens, Thomas Moscibroda, Debmalya Panigrahi |
CoNEXT | 2 |
| 2009 | Brief announcement: collaborative measurement of upload speeds in P2P systemsabstractWe define and study the bandwidth determination problem in ad-hoc P2P environments. Using point-to-point bandwidth probes, the goal is to quickly determine each host's upload and download bandwidth. We present matching upper and lower bounds on the number of probing rounds required by any algorithm. We also devise algorithms which, for realistic bandwidth distributions, beat the lower bounds. John R. Douceur, James W. Mickens, Thomas Moscibroda, Debmalya Panigrahi |
PODC | 2 |
| 2009 | StrobeLight: Lightweight Availability Mapping and Anomaly Detection
James W. Mickens, John R. Douceur, William J. Bolosky, Brian D. Noble |
USENIX ATC | 1 |
| 2007 | Concilium: Collaborative Diagnosis of Broken Overlay RoutesabstractIn a peer-to-peer overlay network, hosts cooperate to forward messages. When a message does not reach its final destination, there are two possible explanations. An intermediate overlay host may have dropped the message due to misconfiguration or malice. Alternatively, a bad link in the underlying IP network may have prevented an earnest, properly configured host from forwarding the data. In this paper, we describe how overlay peers can distinguish between the two situations and ascribe blame appropriately. We generate probabilistic notions of blame using distributed network tomography, fuzzy logic, and secure routing primitives. By comparing application-level drop rates with network characteristics inferred from tomography, we can estimate the likelihood that message loss is due to a misbehaving overlay host or a poor link in the underlying IP network. Since faulty nodes can submit inaccurate tomographic data to the collective, we also discuss mechanisms for detecting such misbehavior. James W. Mickens, Brian D. Noble |
DSN | 1 |
| 2007 | Analytical Models for Epidemics in Mobile Networks
James W. Mickens, Brian D. Noble |
WiMob | 1 |
| 2006 | Exploiting Availability Prediction in Distributed Systems
James W. Mickens, Brian D. Noble |
NSDI | 1 |
| 2005 | Predicting node availability in peer-to-peer networksabstractUnlike the well-administered servers in traditional distributed systems, machines in peer-to-peer networks have widely varying levels of availability. Accurate modeling of node uptime is crucial for predicting per-machine resource burdens and selecting appropriate data replication strategies. In this research project, we improve upon the accuracy of previous peer-to-peer availability models, which are often too conservative to dynamically predict system availability at a fine-grained level. We test our predictors on availability traces from the PlanetLab distributed test bed and the Microsoft corporate network. Each trace has a distinct predictability profile, and we explain these differences by examining the fundamental uptime classes contained in each trace. We also show how availability-guided replica placement reduces the amount of object copying in a distributed data store. James W. Mickens, Brian D. Noble |
SIGMETRICS | 1 |