EDBT 2026 Demo / reviewers in the wild / expert
Anderson Santana de Oliveira
dblp:s/AndersonSantana · also Anderson Santana
· DBLP profile ↗
19ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0003-0364-6328ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 since 2021Human-computer interaction and ubiquitous computing · 4Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Impact of Generalization Techniques on the Interplay Among Privacy, Utility, and FairnessabstractThis study investigates the trade-offs between fairness, privacy, and utility in image classification using machine learning (ML). Recent research suggests that generalization techniques can improve the balance between privacy and utility. One focus of this work is sharpness-aware training (SAT) and its integration with differential privacy (DP-SAT) to further improve this balance. Additionally, we examine fairness in both private and non-private learning models trained on datasets with synthetic and real-world biases. We also measure the privacy risks involved in these scenarios by performing membership inference attacks (MIAs) and explore the consequences of eliminating high-privacy risk samples, termed outliers. Moreover, we introduce a new metric, named harmonic score, which combines accuracy, privacy, and fairness into a single measure. Through empirical analysis using generalization techniques, we achieve an accuracy of 81.11% under (8, 10^-5)-DP on CIFAR-10, surpassing the 79.5% reported by De et al. (2022). Moreover, our experiments show that memorization of training samples can begin before the overfitting point, and generalization techniques do not guarantee the prevention of this memorization. Our analysis of synthetic biases shows that generalization techniques can amplify model bias in both private and non-private models. Additionally, our results indicate that increased bias in training data leads to reduced accuracy, greater vulnerability to privacy attacks, and higher model bias. We validate these findings with the CelebA dataset, demonstrating that similar trends persist with real-world attribute imbalances. Finally, our experiments show that removing outlier data decreases accuracy and further amplifies model bias. Ahmad Hassanpour, Amir Zarei, Khawla Mallat, Anderson Santana de Oliveira, Bian Yang |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | A Cautionary Tale: On the Role of Reference Data in Empirical Privacy DefensesabstractWithin the realm of privacy-preserving machine learning, empirical privacy defenses have been proposed as a solution to achieve satisfactory levels of training data privacy without a significant drop in model utility. Most existing defenses against membership inference attacks assume access to reference data, defined as an additional dataset coming from the same (or a similar) underlying distribution as training data. Despite the common use of reference data, previous works are notably reticent about defining and evaluating reference data privacy. As gains in model utility and/or training data privacy may come at the expense of reference data privacy, it is essential that all three aspects are duly considered. In this paper, we conduct the first comprehensive analysis of empirical privacy defenses. First, we examine the availability of reference data and its privacy treatment in previous works and demonstrate its necessity for fairly comparing defenses. Second, we propose a baseline defense that enables the utility-privacy tradeoff with respect to both training and reference data to be easily understood. Our method is formulated as an empirical risk minimization with a constraint on the generalization error, which, in practice, can be evaluated as a weighted empirical risk minimization (WERM) over the training and reference datasets. Although we conceived of WERM as a simple baseline, our experiments show that, surprisingly, it outperforms the most well-studied and current state-of-the-art empirical privacy defenses using reference data for nearly all relative privacy levels of reference and training data. Our investigation also reveals that these existing methods are unable to trade off reference data privacy for model utility and/or training data privacy, and thus fail to operate outside of the high reference data privacy case. Overall, our work highlights the need for a proper evaluation of the triad model utility / training data privacy / reference data privacy when comparing privacy defenses. Caelin Kaplan, Chuan Xu 0002, Othmane Marfoq, Giovanni Neglia, Anderson Santana de Oliveira |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Can Data Subject Perception of Privacy Risks Be Useful in a Data Protection Impact Assessment?abstractThe General Data Protection Regulation requires, where possible, to seek data subjects perception. Studies showed that people do not have a correct privacy risk perception. In this paper, we study how lay people perceive privacy risks once they are made aware and if experts can differentiate between security and privacy risks. Salimeh Dashti, Anderson Santana de Oliveira, Caelin Kaplan, Manuel Dalcastagné, Silvio Ranise |
SECRYPT | 2 |
| 2019 | Differentially Private Generative Adversarial Networks for Time Series, Continuous, and Discrete Open Data
Lorenzo Frigerio, Anderson Santana de Oliveira, Laurent Gomez, Patrick Duverger |
SEC | 2 |
| 2019 | Track Report of Future Internet Services and Applications (FISA'2019)abstractThe "Future Internet Services and Applications" (FISA) track focuses on three complementary aspects that have to be considered while setting up future Internet services: (i) their modeling, provisioning and management, (ii) data protection, and (iii) data collection, storage and analysis. FISA is in its fifth edition and aims at offering to academic and industrial researchers as well as practitioners a platform for discussions related to the aforementioned aspects of future Internet services and applications. This report briefly presents the main topics of FISA and lists the accepted papers. Mohamed Sellami, Hatem Hadj Kacem, Anderson Santana de Oliveira |
WETICE | 3 |
| 2017 | Analyzing Remote Server Locations for Personal Data Transfers in Mobile AppsabstractAbstract The prevalence of mobile devices and their capability to access high speed internet has transformed them into a portable pocket cloud interface. Being home to a wide range of users’ personal data, mobile devices often use cloud servers for storage and processing. The sensitivity of a user’s personal data demands adequate level of protection at the back-end servers. In this regard, the European Union Data Protection regulations (e.g., article 25.1) impose restriction on the locations of European users’ personal data transfer. The matter of concern, however, is the enforcement of such regulations. The first step in this regard is to analyze mobile apps and identify the location of servers to which personal data is transferred. To this end, we design and implement an app analysis tool, PDTLoc (Personal Data Transfer Location Analyzer), to detect violation of the mentioned regulations. We analyze 1, 498 most popular apps in the EEA using PDTLoc to investigate the data recipient server locations. We found that 16.5% (242) of these apps transfer users’ personal data to servers located at places outside Europe without being under the control of a data protection framework. Moreover, we inspect the privacy policies of the apps revealing that 51% of these apps do not provide any privacy policy while almost all of them contact the servers hosted outside Europe. Mojtaba Eskandari, Bruno Kessler, Maqsood Ahmad 0001, Anderson Santana de Oliveira, Bruno Crispo |
Proc. Priv. Enhancing Technol. | 4 |
| 2016 | AAL and Static Conflict Detection in Policy
Jean-Claude Royer, Anderson Santana de Oliveira |
CANS | 2 |
| 2016 | Track Report of Future Internet Services and Applications (FISA'2016)abstractThe "Future Internet Services and Applications" (FISA) track focuses on three complementary aspects that have to be considered while setting up future Internet services: (i) their modeling, provisioning and management, (ii) data protection, and (iii) data collection, storage and analysis. FISA is in its second edition and results from the fusion of the PASCS (Privacy and Accountability for Software and Cloud Services) and PROMASC (Provisioning and Management of Service Oriented Architecture and Cloud Computing) tracks from previous WETICE editions. This report briefly presents the main topics of FISA and presents the accepted papers. Riadh Ben Halima, Anderson Santana de Oliveira, Mohamed Sellami |
WETICE | 2 |
| 2015 | FISA 2015 Track Report: Future Internet Services and ApplicationsabstractThe "Future Internet Services and Applications" (FISA) track focuses on three complementary aspects that have to be considered while setting up future Internet services: (i) their modelling, provisioning and management, (ii) data protection, and (iii) data collection, storage and analysis. FISA is in its first edition and results from the fusion of the PASCS (Privacy and Accountability for Software and Cloud Services) and PROMASC (Provisioning and Management of Service Oriented Architecture and Cloud Computing) tracks from the previous WETICE editions. This report briefly presents the main topics of FISA and presents the accepted papers. Hatem Hadj Kacem, Anderson Santana de Oliveira, Mohamed Sellami, Sylvain Lefebvre 0002 |
WETICE | 2 |
| 2014 | A Cloud Accountability Policy Representation FrameworkabstractNowadays we are witnessing the democratization of cloud services. As a result, more and more end-users (individuals and businesses) are using these services for achieving their electronic transactions (shopping, administrative procedures, B2B transactions, etc.). In such scenarios, personal data is generally flowed between several entities and end-users need (i) to be aware of the management, processing, storage and retention of personal data, and (ii) to have necessary means to hold service providers accountable for the usage of their data. In fact, dealing with personal data raises several privacy and accountability issues that must be considered before to promote the use of cloud services. In this paper, we propose a framework for the representation of cloud accountability policies. Such policies offer to end-users a clear view of the privacy and accountability obligations asserted by the entities they interact with, as well as means to represent their preferences. This framework comes with two novel accountability policy languages. An abstract one devoted for the representation of preferences/obligations in an human readable fashion. And a concrete one for the mapping to concrete enforceable policies. We motivate our solution with concrete use case scenarios. Walid Benghabrit, Hervé Grall, Jean-Claude Royer, Mohamed Sellami, Monir Azraoui, Kaoutar Elkhiyaoui, Melek Önen, Anderson Santana de Oliveira, Karin Bernsmed |
CLOSER | 8 |
| 2014 | VLOC: An Approach to Verify the Physical Location of a Virtual Machine In CloudabstractThe geolocation of data stored and being processed in cloud is an important issue for many organisations due to obligations that require sensitive data to reside or be processed in particular countries. In this paper we introduce an approach, named VLOC, to verify the physical location of a virtual machine on which the customer applications and data are stored. VLOC is implemented as a software which is able to estimate the geolocation of itself and notify the corresponding user if the location is unauthorised. VLOC uses a number of arbitrary web-servers as external landmarks for localisation and employs network latency measurement for distance estimation. Due to the fluctuation in the network latency, VLOC employs a machine learning technique in order to adapt itself to various network latency tolerance. Different from most of geolocation estimation approaches, VLOC is installed inside the target host (inside the cloud). VLOC does not require special hardware nor a network of trusted landmarks. The experimental results shows the accuracy of VLOC is higher than other existing approaches. Mojtaba Eskandari, Anderson Santana de Oliveira, Bruno Crispo |
CloudCom | 2 |
| 2014 | Platform-level Support for Authorization in Cloud Services with OAuth 2abstractThe OAuth 2 web authorization framework allows services to act on behalf of users when interacting with other services. It avoids sharing username and passwords across services, thus, in principle protecting users from several threats. However, it is known that the implementation of this kind of authorization protocol is tricky, and potentially leads to vulnerable web services. In this paper we present a toolkit for Java-based Cloud platforms which facilitates the deployment of the OAuth 2 authorization framework into existing web services. We developed a set of interceptors, using aspect-oriented programming techniques for SOA, to handle the main OAuth flow. Secondly, we created an Eclipse plug-in to integrate OAuth into cloud services with minimum effort. Jakub Sendor, Yann Lehmann, Gabriel Serme, Anderson Santana de Oliveira |
IC2E | 4 |
| 2014 | Track Report of Privacy and Accountability for Software and Cloud Services (PASCS 2014)abstractThe goal of the PASCS track is to offer academic and industrial researchers and practitioners a platform for discussions related to privacy and accountability issues in software components and cloud services. For this first edition of PASCS we received 8 submissions. The program committe selected 3 long papers for presentation and publication in the WETICE proceedings on the basis of the originality, quality, and relevance to the topics of the track. Each submission received is reviewed at least by three reviewers. Mohamed Sellami, Jean-Claude Royer, Anderson Santana de Oliveira |
WETICE | 3 |
| 2013 | Monitoring Personal Data Transfers in the CloudabstractCloud computing brings a number of compliance risks to organisations because physical perimeters are not clearly delimited. Many regulations relate to the location of the data processing (and storage), including the EU Data protection directive. A major problem for cloud service consumers, acting as data controllers, is how to demonstrate compliance to data transfer constraints. We address the lack of tools to support accountable data localization and transfer across cloud software, platform and infrastructure services, usually run by data processors. In this paper we design a framework for automating the collection of evidence that obligations with respect to personal data handling are being carried out in what concerns personal data transfers. We experiment our approach in the Open Stack open source IaaS implementation, showing how auditors can verify whether data transfers were compliant. Anderson Santana de Oliveira, Jakub Sendor, Alexandr Garaga, Kateline Jenatton |
CloudCom (1) | 1 |
| 2013 | HiPoLDS: A Hierarchical Security Policy Language for Distributed Systems
Matteo Dell'Amico, Gabriel Serme, Muhammad Sabir Idrees, Anderson Santana de Oliveira, Yves Roudier |
Inf. Secur. Tech. Rep. | 4 |
| 2012 | Comparative Analysis of Clustering Algorithms Applied to the Classification of Bugs
Anderson Santana de Oliveira, Jackson Silva, Patrícia Muniz, Fabricio Araújo, Renata M. C. R. de Souza |
ICONIP (5) | 1 |
| 2012 | Enabling Message Security for RESTful ServicesabstractThe security and dependability of cloud applications require strong confidence in the communication protocol used to access web resources. The mainstream service providers nowadays are shifting to REST-based services in the detriment of SOAP-based ones. REST proposes a lightweight approach to consume resources with no specific encapsulation, thus lacking of meta-data descriptions for security requirements. Currently, the security of RESTful services relies on ad-hoc security mechanisms (whose implementation is error-prone) or on the transport layer security (offering poor flexibility). We introduce the REST security protocol to provide secure service communication, together with its performance analysis when compared to equivalent WS-Security configuration. Gabriel Serme, Anderson Santana de Oliveira, Julien Massiera, Yves Roudier |
ICWS | 2 |
| 2012 | HiPoLDS: A Security Policy Language for Distributed Systems
Matteo Dell'Amico, Gabriel Serme, Muhammad Sabir Idrees, Anderson Santana de Oliveira, Yves Roudier |
WISTP | 4 |
| 2007 | Modular Access Control Via Strategic Rewriting
Daniel J. Dougherty, Claude Kirchner, Hélène Kirchner, Anderson Santana de Oliveira |
ESORICS | 4 |