EDBT 2026 Demo / reviewers in the wild / expert
Mario Südholt
dblp:s/MarioSudholt
· DBLP profile ↗
28ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0002-1855-1519ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 1 first-authorSystems, architecture and hardware · 6 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 61% Performance modeling and evaluation · 30% Energy-efficient computing · 9% | |
| Software engineering, system software, and programming languages
2 papers |
Programming languages and type systems · 92% Software maintenance and evolution · 8% |
Topics — the 9 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cloud and datacenter computing
cluster resource management and scheduling |
0.4 | 1 | 2019 | Putting the Next 500 VM Placement Algorithms to the Acid Test: The Infrastructure Provider Viewpoint · IEEE Trans. Parallel Distributed Syst. 2019 |
Performance modeling and evaluation › simulation › simulation software
simulation framework |
0.4 | 1 | 2019 | Putting the Next 500 VM Placement Algorithms to the Acid Test: The Infrastructure Provider Viewpoint · IEEE Trans. Parallel Distributed Syst. 2019 |
Cloud and datacenter computing › virtualization › virtual machine management
virtual machine placement |
0.4 | 1 | 2019 | Putting the Next 500 VM Placement Algorithms to the Acid Test: The Infrastructure Provider Viewpoint · IEEE Trans. Parallel Distributed Syst. 2019 |
Programming languages and type systems
aspect-oriented programming |
0.2 | 2 | 2012 | Essential AOP: The a calculus · ACM Trans. Program. Lang. Syst. 2012 On the automatic evolution of an OS kernel using temporal logic and AOP · ASE 2003 |
Programming languages and type systems › type systems
type soundness |
0.1 | 1 | 2012 | Essential AOP: The a calculus · ACM Trans. Program. Lang. Syst. 2012 |
Programming languages and type systems
type systems |
0.1 | 1 | 2012 | Essential AOP: The a calculus · ACM Trans. Program. Lang. Syst. 2012 |
Energy-efficient computing › energy-aware resource management
energy-aware resource allocation |
0.1 | 1 | 2019 | Putting the Next 500 VM Placement Algorithms to the Acid Test: The Infrastructure Provider Viewpoint · IEEE Trans. Parallel Distributed Syst. 2019 |
Programming languages and type systems
object-oriented programming |
0.0 | 1 | 2012 | Essential AOP: The a calculus · ACM Trans. Program. Lang. Syst. 2012 |
Software maintenance and evolution › software evolution
automated software evolution |
0.0 | 1 | 2003 | On the automatic evolution of an OS kernel using temporal logic and AOP · ASE 2003 |
Methods — techniques the papers use, named apart from their topics
simulation · 0.4load balancing · 0.4consolidation · 0.4type soundness proof · 0.1first-class closures · 0.1coq · 0.1temporal logic · 0.0aspect-oriented programming · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A New vTPM Architecture with Strong Isolation for the Cloud
Samia Boutalbi, Remous-Aris Koutsiamanis, Maissa Dammak, Mario Südholt |
ICA3PP (7) | 4 |
| 2024 | Ti-skol: A Modular Federated Learning Framework Supporting Security Countermeasure CompositionabstractFederated Learning (FL) is a growing technology that enables training of Deep Learning models on private data. Many FL enhancements have been proposed, notably for better security and privacy. Current architectures and frameworks focus on specific sets of enhancements with little extensibility and do not support composition of enhancements. In this paper, we introduce Ti-skol, an architecture and framework that supports composition of security and privacy countermeasures, including countermeasure incompatibilities. Ti-skol also enables modular management of FL enhancements beyond security, being compatible with most enhancements. Ti-skol is promising to assess the cost of countermeasures, individually or in combination. We evaluate our framework on a use-case of Volunteer Deep Learning – applying Volunteer Computing to reduce the cost of large model training by harnessing idle resources of single machines into the required massive distributed computing power. Experimental results show that Ti-skol is scalable as the network size increases. While adding security countermeasures such as Byzantine protections or secure aggregation substantially increase computing overheads, they do not change their order of magnitude, individually or in combination. This tends to show the practicality of the Ti-skol framework for on-demand FL security. Divi De Lacour, Marc Lacoste, Mario Südholt, Jacques Traoré |
IEEE Big Data | 3 |
| 2023 | Mobile Edge Slice Broker: Mobile Edge Slices Deployment in Multi-Cloud EnvironmentsabstractHarnessing the network slicing feature of the 5G architecture and the mobile cloud computing capabilities offered by Mobile Edge Computing (MEC), mobile edge communication systems are emerging that contribute to the convergence of telecom and cloud services. In this scenario, mobile edge slices can be created and deployed by leveraging multi-cloud infrastructure. However, it becomes difficult for potential users, such as mobile edge slice tenants, to evaluate and select the Cloud Infrastructure Provider (CIP) which best meets their heterogeneous require-ments. Therefore, mobile edge systems require slice brokering to mediate with resource and infrastructure providers, so that mobile edge slice tenants can specify a single set of network and cloud service Key Performance Indicator (KPI) requirements. In this paper we present a new type of broker, the Mobile Edge Slice Broker, that allows designing, provisioning, and orchestrating the deployment and operation of end-to-end mobile edge slices over edge and multi-cloud environments, while maintaining dynamic monitoring, reconfiguration and optimization capabilities. Samia Boutalbi, Nizar Kheir, Remous-Aris Koutsiamanis, Mario Südholt, Yann Dan Moussa |
ICFEC | 4 |
| 2021 | Secure Distribution of Factor Analysis of Mixed Data (FAMD) and Its Application to Personalized Medicine of Transplanted Patients
Sirine Sayadi, Estelle Geffard, Mario Südholt, Nicolas Vince, Pierre-Antoine Gourraud |
AINA (1) | 3 |
| 2021 | A Hybrid Cloud Deployment Architecture for Privacy-Preserving Collaborative Genome-Wide Association Studies
Fatima-Zahra Boujdad, David Niyitegeka, Reda Bellafqira, Gouenou Coatrieux, Emmanuelle Génin, Mario Südholt |
ICDF2C | 6 |
| 2020 | Distributed Contextualization of Biomedical Data: A Case Study in Precision MedicineabstractAn important aspect of precision medicine consists in patient-centered contextualization analyses that are used as part of biomedical interactive tools. Such analyses often harness data of large populations of patients from different research centers and can often benefit from a distributed implementation. However, performance and the security and privacy concerns of sharing sensitive biomedical data can become a major issue. We have investigated these issues in the context of a kidney transplanted patient contextualization project: the Kidney Transplantation Application (KITAPP). In this paper, we present a motivation for distributed implementations in this context, notably for computing percentiles for contextualization. We present a corresponding system architecture, motivate privacy and performance issues, and present a novel distributed implementation that is evaluated in a realistic multi-site setting. Sirine Sayadi, Estelle Geffard, Mario Südholt, Nicolas Vince, Pierre-Antoine Gourraud |
AICCSA | 3 |
| 2019 | On Distributed Collaboration for Biomedical AnalysesabstractCooperation of research groups is nowadays common for the development and execution of biomedical analyses. Multiple partners contribute data in this context, data that is often centralized for processing at some cluster-based or supercomputer-based infrastructure. In contrast, real distributed collaboration that involves processing of data from several partners at different sites is rare. However, such distributed analyses are often very interesting, in particular, for scalability, security and privacy reasons. In this article, we motivate the need for real distributed biomedical analyses in the context of several ongoing projects, including the ICAN project that involves 34 French hospitals and affiliated research groups. We present a set of distributed architectures for such analyses that we have derived from discussions with different medical research groups and a study of related work. These architectures allow for scalability, security/privacy and reproducibility issues to be taken into account. Finally, we illustrate that these architectures can serve as the basis of a development method for biomedical distributed analyses. Fatima-Zahra Boujdad, Alban Gaignard, Mario Südholt, Wilmer Garzón Alfonso, Luis Daniel Benavides Navarro, Richard Redon |
CCGRID | 3 |
| 2019 | Putting the Next 500 VM Placement Algorithms to the Acid Test: The Infrastructure Provider ViewpointabstractMost current infrastructures for cloud computing leverage static and greedy policies for the placement of virtual machines. Such policies impede the optimal allocation of resources from the infrastructure provider viewpoint. Over the last decade, more dynamic and often more efficient policies based, e.g., on consolidation and load balancing techniques, have been developed. Due to the underlying complexity of cloud infrastructures, these policies are evaluated either using limited scale testbeds/in-vivo experiments or ad-hoc simulators. These validation methodologies are unsatisfactory for two important reasons: they (i) do not model precisely enough real production platforms (size, workload variations, failure, etc.) and (ii) do not enable the fair comparison of different approaches. More generally, new placement algorithms are thus continuously being proposed without actually identifying their benefits with respect to the state of the art. In this article, we show how VMPlaceS, a dedicated simulation framework enables researchers (i) to study and compare VM placement algorithms from the infrastructure perspective, (ii) to detect possible limitations at large scale and (iii) to easily investigate different design choices. Built on top of the SimGrid simulation platform, VMPlaceS provides programming support to ease the implementation of placement algorithms and runtime support dedicated to load injection and execution trace analysis. To illustrate the relevance of VMPlaceS, we first discuss a few experiments that enabled us to study in details three well known VM placement strategies. Diving into details, we also identify several modifications that can significantly increase their performance in terms of reactivity. Second, we complete this overall presentation of VMPlaceS by focusing on the energy efficiency of the well-know FFD strategy. We believe that VMPlaceS will allow researchers to validate the benefits of new placement algorithms, thus accelerating placement research and favouring the transfer of results to IaaS production platforms. Adrien Lèbre, Jonathan Pastor, Anthony Simonet, Mario Südholt |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2018 | Constructive Privacy for Shared Genetic DataabstractInternational audience Fatima-Zahra Boujdad, Mario Südholt |
CLOSER | 2 |
| 2018 | Secure Distributed Computing on Untrusted Fog Infrastructures Using Trusted Linux ContainersabstractFog and Edge computing provide a large pool of resources at the edge of the network that may be used for distributed computing. Fog infrastructure heterogeneity also results in complex configuration of distributed applications on computing nodes. Linux containers are a mainstream technique allowing to run packaged applications and micro services. However, running applications on remote hosts owned by third parties is challenging because of untrusted operating systems and hardware maintained by third parties. To meet such challenges, we may leverage trusted execution mechanisms. In this work, we propose a model for distributed computing on Fog infrastructures using Linux containers secured by Intel's Software Guard Extensions (SGX) technology. We implement our model on a Docker and OpenSGX platform. The result is a secure and flexible approach for distributed computing on Fog infrastructures. Mohammad-Mahdi Bazm, Marc Lacoste, Mario Südholt, Jean-Marc Menaud |
CloudCom | 3 |
| 2015 | VMPlaceS: A Generic Tool to Investigate and Compare VM Placement Algorithms
Adrien Lèbre, Jonathan Pastor, Mario Südholt |
Euro-Par | 3 |
| 2014 | Enforcing Expressive Accountability PoliciesabstractAccountability policies for the enforcement of the responsible stewardship of personal data have to support the gathering of information at all levels of the service stack and across different policy domains, for instance, for the retrospective enforcement of transparency and remediation properties. Existing approaches to accountability, however, often do not meet these requirements and corresponding implementation support is lacking. In this paper we show how expressive accountability policies can be defined in terms of policy domains, accessible data at all levels of the service stack, and preventive and retrospective mechanisms. Additionally, we present a notion of accountability schemes that support the constructive implementation of our accountability policies. Finally, we motivate and apply our approach in the context of real-world attacks to OAuth-based authorization and authentication protocols. Ronan-Alexandre Cherrueau, Mario Südholt |
WETICE | 2 |
| 2013 | Adapting Workflows Using Generic Schemas: Application to the Security of Business ProcessesabstractExisting approaches to the adaptation of workflows over Web services fall short in two respects. First, they only provide, if ever, limited means for taking into account the execution history of a workflow. Second, they do not support adaptations that require modifications not only at the service composition level but also at the levels of interceptors and service implementations. This is particular problematic for the enforcement of security properties over workflows: enforcing authorization properties, for instance, frequently requires execution contexts to be defined and modifications to be applied at all these abstraction levels of Web services. We present two main contributions in this context. First, we introduce workflow adaptation schemas (WAS), a new notion of generic protocol-based workflow adapters. WAS enable the declarative definition of adaptations involving complex service compositions and implementations. Second, we present two real-world security issues related to the use of OAuth 2.0, a recent and widely used framework for the authorization of resource accesses. As we motivate, these security issues require history-based adaptations over different abstraction levels of services. We then show how to resolve these issues using WAS. Ronan-Alexandre Cherrueau, Mario Südholt, Omar Chebaro |
CloudCom (1) | 2 |
| 2013 | Cooperative and reactive scheduling in large-scale virtualized platforms with DVMSabstractSUMMARY One of the principal goals of cloud computing is the outsourcing of the hosting of data and applications, thus enabling a per‐usage model of computation. Data and applications may be packaged in virtual machines (VM), which are themselves hosted by nodes, that is, physical machines. Several frameworks have been designed to manage VMs on pools of physical machines; most of them, however, do not efficiently address a major objective of cloud providers: maximizing system utilization while ensuring the QoS. Several approaches promote virtualization capabilities to improve this trade‐off. However, the dynamic scheduling of a large number of VMs as part of a large distributed infrastructure is subject to important and hard scalability problems that become even worse when VM image transfers have to be managed. Consequently, most current frameworks schedule VMs statically using a centralized control strategy. In this article, we present distributed VM scheduler, a framework that enables VMs to be scheduled cooperatively and dynamically in large‐scale distributed systems. We describe, in particular, how several VM reconfigurations can be dynamically calculated in parallel and applied simultaneously. Reconfigurations are enabled by partitioning the system (i.e., nodes and VMs) on the fly. Partitions are created with a minimum of resources necessary to find a solution to the reconfiguration problem. Moreover, we propose an algorithm to handle deadlocks that may appear because of the partitioning policy. We have evaluated our prototype through simulations and compared our approach with a centralized one. The results show that our scheduler permits VMs to be reconfigured more efficiently: the time needed to manage thousands of VMs on hundreds of machines is typically reduced to a tenth or less. Copyright © 2012 John Wiley & Sons, Ltd. Flavien Quesnel, Adrien Lèbre, Mario Südholt |
Concurr. Comput. Pract. Exp. | 3 |
| 2012 | Accountability for cloud and other future Internet servicesabstractCloud and IT service providers should act as responsible stewards for the data of their customers and users. However, the current absence of accountability frameworks for distributed IT services makes it difficult for users to understand, influence and determine how their service providers honour their obligations. The A4Cloud project will create solutions to support users in deciding and tracking how their data is used by cloud service providers. By combining methods of risk analysis, policy enforcement, monitoring and compliance auditing with tailored IT mechanisms for security, assurance and redress, A4Cloud aims to extend accountability across entire cloud service value chains, covering personal and business sensitive information in the cloud. Siani Pearson, Vasilios Tountopoulos, Daniele Catteddu, Mario Südholt, Refik Molva, Christoph Reich, Simone Fischer-Hübner, Christopher Millard, Volkmar Lotz, Martin Gilje Jaatun, Ronald E. Leenes, Chunming Rong, Javier López 0001 |
CloudCom | 4 |
| 2012 | A Message-passing Model for Service Oriented Computing
Diana Allam, Rémi Douence, Hervé Grall, Jean-Claude Royer, Mario Südholt |
WEBIST | 5 |
| 2012 | Essential AOP: The a calculusabstractAspect-oriented programming (AOP) has produced interesting language designs, but also ad hoc semantics that needs clarification. We contribute to this clarification with a calculus that models essential AOP, both simpler and more general than existing formalizations. In AOP, advice may intercept method invocations, and proceed executes the suspended call. Proceed is an ad hoc mechanism, only usable inside advice bodies. Many pointcut mechanisms, for example, wildcards, also lack regularity. We model proceed using first-class closures, and shift complexity from pointcuts to ordinary object-oriented code. Two well-known pointcut categories, call and execution , are commonly considered similar. We formally expose their differences, and resolve the associated soundness problem. Our calculus includes type ranges , an intuitive and concise alternative to explicit type variables that allows advice to be polymorphic over intercepted methods. We use calculus parameters to cover type safety for a wide design space of other features. Type soundness is verified in Coq. Bruno De Fraine, Erik Ernst, Mario Südholt |
ACM Trans. Program. Lang. Syst. | 3 |
| 2010 | Essential AOP: The A Calculus
Bruno De Fraine, Erik Ernst, Mario Südholt |
ECOOP | 3 |
| 2010 | Scoping strategies for distributed aspects
Éric Tanter, Johan Fabry, Rémi Douence, Jacques Noyé, Mario Südholt |
Sci. Comput. Program. | 5 |
| 2008 | Debugging and Testing Middleware with Aspect-Based Control-Flow and Causal Patterns
Luis Daniel Benavides Navarro, Rémi Douence, Mario Südholt |
Middleware | 3 |
| 2008 | Aspect-Based Patterns for Grid ProgrammingabstractThe development of grid algorithms is frequently hampered by limited means to describe topologies and lack of support for the invasive composition of legacy components in order to pass data between them. In this paper we present a solution to overcome these limitations using the notion of invasive patterns for the construction of distributed algorithms, a recent extension of well-known computation and communication patterns. Concretely, we present two contributions. First, based on a study of how patterns are instantiated in NAS Grid, a well-known benchmark used for evaluating performance of computational grids, we show how invasive patterns can be used for the declarative definition of large-scale grid topologies and checkpointing algorithms. Second, we qualitatively and quantitatively evaluate how our approach can be used to implement the checkpointing on top of grid applications. Luis Daniel Benavides Navarro, Rémi Douence, Fabien Hermenier, Jean-Marc Menaud, Mario Südholt |
SBAC-PAD | 5 |
| 2006 | Concurrent aspectsabstractAspect-Oriented Programming (AOP) promises the modularization of so-called crosscutting functionalities in large applications. Currently, almost all approaches to AOP provide means for the description of sequential aspects that are to be applied to a sequential base program. In particular, there is no formally-defined concurrent approach to AOP, with the result that coordination issues between aspects and base programs as well as between aspects cannot precisely be investigated.This paper presents Concurrent Event-based AOP (CEAOP), which addresses this issue. Our contribution can be detailed as follows. First, we formally define a model for concurrent aspects which extends the sequential Event-based AOP approach. The definition is given as a translation into concurrent specifications using Finite Sequential Processes (FSP), thus enabling use of the Labelled Transition System Analyzer (LTSA) for formal property verification. Further, we show how to compose concurrent aspects using a set of general composition operators. Finally, we sketch a Java prototype implementation for concurrent aspects, which generates coordination specific code from the FSP model defining the concurrent AO application. Rémi Douence, Didier Le Botlan, Jacques Noyé, Mario Südholt |
GPCE | 4 |
| 2006 | VPA-Based Aspects: Better Support for AOP over ProtocolsabstractAspect-Oriented Programming is a promising approach to the construction of large-scale software systems. The declarativeness of aspect definitions and support for verification of AO programs crucially depends on the expressiveness of the aspect languages used. Currently, a large spectrum of pointcut languages, i.e., the languages that define where aspects may apply modifications to an application, have been proposed. Their expressiveness ranges from regular expression languages, which, e.g., provide support for static interaction analysis, to context-free or turing complete languages, the latter almost without any support for analysis or verification. In this paper we investigate the use of Visibly Pushdown Automata (VPA) [4] as a basis for an aspect language in order to enable more declarative aspect definitions (compared to regular approaches) for protocollike relationships and static verification of properties, in particular analysis of interactions among aspects. Concretely, we present four contributions: (i) we provide a set of examples motivating the use of VPA-based aspect definitions in the context of P2P systems, (ii) formally define a core aspect language for protocols with a VPA-based pointcut language, (iii) show that this language supports the analysis of interaction properties among aspects, and (iv) briefly present a freely available library implementing basic VPA operations, which we have used to analyze some interaction examples. Dong Ha Nguyen, Mario Südholt |
SEFM | 2 |
| 2005 | Automating adaptive image generation for medical devices using aspect-oriented programmingabstractImage generation, e.g., in computer tomographs, requires the use of sophisticated algorithms which are characterized (i) by a large variability to enable generation of different types of images and (ii) a strong need for dynamic reconfiguration to adapt image generation, e.g., to individual patients. On the application level, such characteristics are frequently scattered all over the code of the application. This suggests the use of aspect-oriented programming (AOP) techniques to modularize such crosscutting functionality. In this paper we present an approach to automate image generation tasks using AOP and their application in the context of medical devices from Siemens AG, Germany. Concretely, we present three results: (i) a motivation why imaging software can benefit from dynamic AOP, (ii) a case study of how image generation, in particular for medical devices, can be adapted using the Arachne system for dynamic AOP in C, and (iii) a suitable aspect language and its realization within Arachne. Thomas Fritz 0001, Marc Ségura, Mario Südholt, Egon Wuchner, Jean-Marc Menaud |
ETFA | 3 |
| 2003 | On the automatic evolution of an OS kernel using temporal logic and AOPabstractAutomating software evolution requires both identifying precisely the affected program points and selecting the appropriate modification at each point. This task is particularly complicated when considering a large program, even when the modifications appear to be systematic. We illustrate this situation in the context of evolving the Linux kernel to support Bossa, an event-based framework for process-scheduler development. To support Bossa, events must be added at points scattered throughout the kernel. In each case, the choice of event depends on properties of one or a sequence of instructions. To describe precisely the choice of event, we propose to guide the event insertion by using a set of rules, amounting to an aspect that describes the control-flow contexts in which each event should be generated. In this paper, we present our approach and describe the set of rules that allows proper event insertion. These rules use temporal logic to describe sequences of instructions that require events to be inserted. We also give an overview of an implementation that we have developed to automatically perform this evolution. Rickard A. Åberg, Julia Lawall, Mario Südholt, Gilles Muller, Anne-Françoise Le Meur |
ASE | 3 |
| 2002 | A Framework for the Detection and Resolution of Aspect Interactions
Rémi Douence, Pascal Fradet, Mario Südholt |
GPCE | 3 |
| 1997 | Modeling Railway Control Systems Using Graph Grammars: A Case Study
A. A. Holzbacher, Michaël Périn, Mario Südholt |
COORDINATION | 3 |
| 1992 | On Interprocedural Data Flow Analysis for Object Oriented Languages
Mario Südholt, Christoph Steigner |
CC | 1 |