Searcharxiv⌕ Search

arXiv subjects

André Martin

Publications and source records attributed to André Martin.

At least 19 recordsLinked to original sources

A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software

Open-source libraries are widely used by software developers to speed up the development of products, however, they can introduce security vulnerabilities, leading to incidents like Log4Shell. With the expanding usage of open-source libraries, it becomes even more imperative to comprehend and address these dependency vulnerabilities. The use of Software Composition Analysis (SCA) tools does greatly help here as they provide a deep insight on what dependencies are used in a project, enhancing the security and integrity in the software supply chain. In order to learn how wide spread vulnerabilities are and how quickly they are being fixed, we conducted a study on over 1k open-source software projects with about 50k releases comprising several languages such as Java, Python, Rust, Go, Ruby, PHP, and JavaScript. Our objective is to investigate the severity, persistence, and distribution of these vulnerabilities, as well as their correlation with project metrics such as team and contributors size, activity and release cycles. In order to perform such analysis, we crawled over 1k projects from github including their version history ranging from 2013 to 2023 using VODA, our SCA tool. Using our approach, we can provide information such as library versions, dependency depth, and known vulnerabilities, and how they evolved over the software development cycle. Being larger and more diverse than datasets used in earlier works and studies, ours provides better insights and generalizability of the gained results. The data collected answers several research questions about the dependency depth and the average time a vulnerability persists. Among other findings, we observed that for most programming languages, vulnerable dependencies are transitive, and a critical vulnerability persists in average for over a year before being fixed.

cs.SE↗

TICAL: Trusted and Integrity-protected Compilation of AppLications

During the past few years, we have witnessed various efforts to provide confidentiality and integrity for applications running in untrusted environments such as public clouds. In most of these approaches, hardware extensions such as Intel SGX, TDX, AMD SEV, etc., are leveraged to provide encryption and integrity protection on process or VM level. Although all of these approaches increase the trust in the application at runtime, an often overlooked aspect is the integrity and confidentiality protection at build time, which is equally important as maliciously injected code during compilation can compromise the entire application and system. In this paper, we present Tical, a practical framework for trusted compilation that provides integrity protection and confidentiality in build pipelines from source code to the final executable. Our approach harnesses TEEs as runtime protection but enriches TEEs with file system shielding and an immutable audit log with version history to provide accountability. This way, we can ensure that the compiler chain can only access trusted files and intermediate output, such as object files produced by trusted processes. Our evaluation using micro- and macro-benchmarks shows that Tical can protect the confidentiality and integrity of whole CI/CD pipelines with an acceptable performance overhead.

cs.CR↗

Heterogeneous Datasets for Federated Survival Analysis Simulation

Survival analysis studies time-modeling techniques for an event of interest occurring for a population. Survival analysis found widespread applications in healthcare, engineering, and social sciences. However, the data needed to train survival models are often distributed, incomplete, censored, and confidential. In this context, federated learning can be exploited to tremendously improve the quality of the models trained on distributed data while preserving user privacy. However, federated survival analysis is still in its early development, and there is no common benchmarking dataset to test federated survival models. This work provides a novel technique for constructing realistic heterogeneous datasets by starting from existing non-federated datasets in a reproducible way. Specifically, we propose two dataset-splitting algorithms based on the Dirichlet distribution to assign each data sample to a carefully chosen client: quantity-skewed splitting and label-skewed splitting. Furthermore, these algorithms allow for obtaining different levels of heterogeneity by changing a single hyperparameter. Finally, numerical experiments provide a quantitative evaluation of the heterogeneity level using log-rank tests and a qualitative analysis of the generated splits. The implementation of the proposed methods is publicly available in favor of reproducibility and to encourage common practices to simulate federated environments for survival analysis.

cs.LG↗

New result on phase shift analysis

Assuming a certain continuity property, we prove, using the old results of Itzykson and Martin, that, except for an obvious ambiguity, there are only at most two amplitudes reproducing an elastic differential cross section at a given energy.

math-ph↗

Trust Management as a Service: Enabling Trusted Execution in the Face of Byzantine Stakeholders

Trust is arguably the most important challenge for critical services both deployed as well as accessed remotely over the network. These systems are exposed to a wide diversity of threats, ranging from bugs to exploits, active attacks, rogue operators, or simply careless administrators. To protect such applications, one needs to guarantee that they are properly configured and securely provisioned with the "secrets" (e.g., encryption keys) necessary to preserve not only the confidentiality, integrity and freshness of their data but also their code. Furthermore, these secrets should not be kept under the control of a single stakeholder - which might be compromised and would represent a single point of failure - and they must be protected across software versions in the sense that attackers cannot get access to them via malicious updates. Traditional approaches for solving these challenges often use ad hoc techniques and ultimately rely on a hardware security module (HSM) as root of trust. We propose a more powerful and generic approach to trust management that instead relies on trusted execution environments (TEEs) and a set of stakeholders as root of trust. Our system, PALAEMON, can operate as a managed service deployed in an untrusted environment, i.e., one can delegate its operations to an untrusted cloud provider with the guarantee that data will remain confidential despite not trusting any individual human (even with root access) nor system software. PALAEMON addresses in a secure, efficient and cost-effective way five main challenges faced when developing trusted networked applications and services. Our evaluation on a range of benchmarks and real applications shows that PALAEMON performs efficiently and can protect secrets of services without any change to their source code.

cs.CR↗

A rigorous lower bound on the scattering amplitude at large angle

We prove a lower bound for the modulus of the amplitude for a two-body process at large scattering angle. This is based on the interplay of the analyticity of the amplitude and the positivity properties of its absorptive part. The assumptions are minimal, namely those of local quantum field theory (in the case when dispersion relations hold). In Appendix A, lower bounds for the forward particle-particle and particle-antiparticle amplitudes are obtained. This is of independent interest.

hep-th↗

PubSub-SGX: Exploiting Trusted Execution Environments for Privacy-Preserving Publish/Subscribe Systems

This paper presents PUBSUB-SGX, a content-based publish-subscribe system that exploits trusted execution environments (TEEs), such as Intel SGX, to guarantee confidentiality and integrity of data as well as anonymity and privacy of publishers and subscribers. We describe the technical details of our Python implementation, as well as the required system support introduced to deploy our system in a container-based runtime. Our evaluation results show that our approach is sound, while at the same time highlighting the performance and scalability trade-offs. In particular, by supporting just-in-time compilation inside of TEEs, Python programs inside of TEEs are in general faster than when executed natively using standard CPython.

cs.DC↗

Grand Challenge: Real-time Destination and ETA Prediction for Maritime Traffic

In this paper, we present our approach for solving the DEBS Grand Challenge 2018. The challenge asks to provide a prediction for (i) a destination and the (ii) arrival time of ships in a streaming-fashion using Geo-spatial data in the maritime context. Novel aspects of our approach include the use of ensemble learning based on Random Forest, Gradient Boosting Decision Trees (GBDT), XGBoost Trees and Extremely Randomized Trees (ERT) in order to provide a prediction for a destination while for the arrival time, we propose the use of Feed-forward Neural Networks. In our evaluation, we were able to achieve an accuracy of 97% for the port destination classification problem and 90% (in mins) for the ETA prediction.

cs.LG↗

A Lower Bound on Inelasticity in Pion-Pion Scattering

Assuming that the pion-pion scattering amplitude and its absorptive part are analytic inside an ellipse in $t$- plane with foci $t=0$, $u=0$ and right extremity $t=4 m_π^2 +ε$, ($ε> 0$), except for cuts prescribed by Mandelstam representation for $t\geq 4 m_π^2$, $u\geq 4 m_π^2$ , and bounded by $s^N$ on the boundary of this domain, we prove that for $s\rightarrow \infty$, σ_{inel} (s) > \frac{Const}{s^{5/2} }\exp {[-\frac{\sqrt{s}}{4} (N+5/2) \ln {s} ]}.

hep-ph↗

Elastic and Secure Energy Forecasting in Cloud Environments

Although cloud computing offers many advantages with regards to adaption of resources, we witness either a strong resistance or a very slow adoption to those new offerings. One reason for the resistance is that (i) many technologies such as stream processing systems still lack of appropriate mechanisms for elasticity in order to fully harness the power of the cloud, and (ii) do not provide mechanisms for secure processing of privacy sensitive data such as when analyzing energy consumption data provided through smart plugs in the context of smart grids. In this white paper, we present our vision and approach for elastic and secure processing of streaming data. Our approach is based on StreamMine3G, an elastic event stream processing system and Intel's SGX technology that provides secure processing using enclaves. We highlight the key aspects of our approach and research challenges when using Intel's SGX technology.

cs.DC↗

Froissart Bound on Inelastic Cross Section Without Unknown Constants

Assuming that axiomatic local field theory results hold for hadron scattering, André Martin and S. M. Roy recently obtained absolute bounds on the D-wave below threshold for pion-pion scattering and thereby determined the scale of the logarithm in the Froissart bound on total cross sections in terms of pion mass only. Previously, Martin proved a rigorous upper bound on the inelastic cross-section $σ_{inel}$ which is one-fourth of the corresponding upper bound on $σ_{tot}$, and Wu, Martin,Roy and Singh improved the bound by adding the constraint of a given $σ_{tot}$. Here we use unitarity and analyticity to determine, without any high energy approximation, upper bounds on energy averaged inelastic cross sections in terms of low energy data in the crossed channel. These are Froissart-type bounds without any unknown coefficient or unknown scale factors and can be tested experimentally. Alternatively, their asymptotic forms,together with the Martin-Roy absolute bounds on pion-pion D-waves below threshold, yield absolute bounds on energy-averaged inelastic cross sections. E.g. for $π^0 π^0$ scattering, defining $σ_{inel}=σ_{tot} -\big (σ^{π^0 π^0 \rightarrow π^0 π^0} + σ^{π^0 π^0 \rightarrow π^+ π^-} \big )$,we show that for c.m. energy $\sqrt{s}\rightarrow \infty $, $\barσ_{inel }(s,\infty)\equiv s\int_{s} ^{\infty } ds'σ_{inel }(s')/s'^2 \leq (π/4) (m_{π})^{-2} [\ln (s/s_1)+(1/2)\ln \ln (s/s_1) +1]^2$ where $1/s_1= 34π\sqrt{2π}\>m_{π}^{-2} $ . This bound is asymptotically one-fourth of the corresponding Martin-Roy bound on the total cross section, and the scale factor $s_1$ is one-fourth of the scale factor in the total cross section bound. The average over the interval (s,2s) of the inelastic $π^0 π^0 $cross section has a bound of the same form with $1/s_1$ replaced by $1/s_2=2/s_1 $.

hep-ph↗

Froissart Bound on Total Cross-section without Unknown Constants

We determine the scale of the logarithm in the Froissart bound on total cross-sections using absolute bounds on the D-wave below threshold for $ππ$ scattering. E.g. for $π^0 π^0$ scattering we show that for c.m. energy $\sqrt{s}\rightarrow \infty $, $\barσ_{tot}(s,\infty)\equiv s\int_{s} ^{\infty} ds'σ_{tot}(s')/s'^2 \leq π(m_π)^{-2} [\ln (s/s_0)+(1/2)\ln \ln (s/s_0) +1]^2$ where $m_π^2/s_0= 17π\sqrt{π/2} $ .

hep-ph↗

An upper bound on the total inelastic cross-section as a function of the total cross-section

Recently André Martin has proved a rigorous upper bound on the inelastic cross-section $σ_{inel}$ at high energy which is one-fourth of the known Froissart-Martin-Lukaszuk upper bound on $σ_{tot}$. Here we obtain an upper bound on $σ_{inel}$ in terms of $σ_{tot}$ and show that the Martin bound on $σ_{inel}$ is improved significantly with this added information.

hep-ph↗

The Froissart bound for inelastic cross-sections

We prove that while the total cross{}-section is bounded by $(π/m_π^2) \ln^2 s$, where $s$ is the square of the c.m. energy and $m_π$ the mass of the pion, the total inelastic cross{}-section is bounded by $(1/4)(π/m_π^2) \ln^2 s$, which is 4 times smaller. We discuss the implications of this result on the total cross{}-section itself.

hep-ph↗

The rigorous analyticity-unitarity program and its successes

We show how the combination of analyticity properties derived from local field theory and the unitarity condition (in particular positivity) leads to non-trivial physical results, including the proof of the "Froissart bound" from first principles and the existence of absolute bounds on the pion-pion scattering amplitude.

hep-ph↗