scieee AI-readable full text Open interactive document viewer

[ECSS 2025] Presentations of the Early Career Researchers Workshop (27 October 2025)

Informatics Europe

Abstract

The 2025 edition of the Professional Development Workshop for Early Career Researchers held on 27 October at ECSS, focused on supporting the professional growth of early-career researchers while strengthening their engagement with senior colleagues in the Informatics community. Chaired by Dimka Karastoyanova (University of Groningen), Elisabetta Di Nitto (Politecnico di Milano) and Gregor Engels (University of Paderborn, Germany), the workshop is part of Informatics Europe's commitment to developing a diverse new generation of research leaders.

Full text

European Informatics Leaders Summit ECSS 2025 The European Voice of Informatics Research and Education Professional Development Workshop for Early Career Researchers Rennes, 27 October, 2025 Lessons learned from my doctoral studies or How I learned to (not) stop worrying Andrea Cini October 27, 2025 1IDSIA USI-SUPSI, Università della Svizzera italiana Who am I? PhD graduate from Università della Svizzera italiana (USI) in Lugano ( ). |Currently at University of Oxford ( ). CWorking on machine learning for time series and graph processing with applications to cyber-physical systems. 1 Today’s talk I will talk about my experience as a PhD student and what helped me during my studies. •Disclaimer: no two experiences are the same. •Your experience might be different from mine. •I hope hearing what worked for me might help you find what works for you. Photo taken on my first day in Lugano. 2 What was my thesis about? I worked on graph deep learning (GDL) methods for time series forecasting. •Graphs can represent relationships among time series. •Allow to introduce specialized neural networks that are effective and data efficient. GNN GNN GNN GNN GNN time History Predictions My thesis focused on understanding these models and making them practically viable. [1] Cini et al., “Graph Deep Learning for Time Series Forecasting”, ACM CSUR 2025. 3 A smooth journey? Ch. 2 Goal GNN GNN GNN GNN GNN GNN ? ? History Predictions Missing data Ch. 1 Local dynamics Ch. 3 Graph learning Ch. 4 Scalability Graph deep learning for time series forecasting Ch. 3 Ch. 4 Ch. 2 Ch. 1 time space Challenges This might look like a structured path... ... but the reality is very different.4 My experience in shaping my project •It took me a while to realize exactly the direction I wanted to follow. •Many things I worked on early on haven’t even ended up being included in my thesis. •My advisor gave me a lot of freedom and good advice →This really helped me develop my own approach to research. 5 Finding your path The first question we all try to answer is: what should I work on? •Work on something that feels relevant and fun for you. •Usually, your advisor helps define the high-level topic you work on. •Ideally, it is something that fits well with the research group. •But ... •... realize you are an active part of the process, it is your PhD. →Learning how to do independent research is the main objective of a PhD. →Ask your advisor for advice on how to do research, more than on what to work on. •Be open to detours and change of plans! But ... 6 Balance exploration and exploitation •At some point commit to a project, even if you feel uncertain. •You will learn a lot and most likely stumble upon something we don’t quite understand yet. •Start from the practical problem and ... •... translate it into a methodological/theoretical research question. →This problem-driven approach can work very well. Ch. 2 ? ? Missing data Ch. 1 Local dynamics Ch. 3 Graph learning Ch. 4 Scalability Ch. 3 Ch. 4 Ch. 2 Ch. 1 time space Challenges 7 Background BAC issues are the most common on the web (OWASP A01, 2021) Component-based JS frameworks generate obfuscated and minified production code Hypothesis: devs may considered safe to disclose sensitive data to the front-end (ID, token) or let it directly enforce RBAC/ABAC policies Framework internal APIs are often exposed in prod, allowing an attacker to tamper with the component tree, extracting sensitive data and bypass weak server-side checks Vulnerability condition Overpowered front-end (OP). At least 1 feature or resource already available to the front-end for which the front-end applies all access control policies Exposed resources (ER). At least 1 network request directed to a protected resource or feature that is directly accepted by the web server (IDOR, BOLA, MFLAC) Overtrusted front-end (OT). At least 1 network request that is accepted exclusively on the user permission declared by the front-end (HTTP parameter tampering) RQ1 JS frameworks comparative analysis RQ2 Prevalence and impact RQ3 Countermeasures and best practices Performing server-side checks on redirects, implementing incremental authorization techniques rather, keeping permission values under back-end control, securing at least critical functionality if major refactoring is not possible Contributions 3 formal conditions for web GEM vulnerability 20 vulnerabilities on 49 entries, 3 official ack, React, Vue, Ember found vulnerable to JCH with no effective mitigation 3 case studies State-of-art web scanners (Burp, OWASP ZAP) not being capable of detecting web GEMbased IDOR Provided mitigation and best practices derived from non vulnerable apps Fig 1: Distribution of vulnerable applications per category Fig.2 Distribution of vulnerability cases Web GEMs: Broken Access Control Vulnerabilities (BAC) in Large Web Front-Ends. An Empirical Study Nicolò CAVALLI, Arnaud BLOUIN, Djamel KHELLADI, Olivier BARAIS Future work Large scale analysis on Tranco’s top 100k LLM/ML based detection of sensitive HTTP bodies Log analysis Systematic Literature Review (SLR) - Quality Assurance in Infrastructure as Code: Issues, Approaches, and Open Challenges Provisioning (e.g. Terraform) Configuration management (e.g. Ansible) Orchestration (e.g. Kubernetes) Image building (e.g. Docker) Performance optimization Configuration consistency Context Challenges DevOps engineer RQ1. What quality issues have been investigated in IaC research, and what are their characteristics? RQ2. What support approaches have been proposed in the literature, and what are their properties? Extending Infrastructure as Code (IaC) languages by leveraging operational data to provide advanced DevOps support for infrastructure code development We want to investigate: Leveraging runtime metrics to optimize resource allocation and performance. Integrating log analysis into developer tools to enhance IaC quality during development. Haitam El Hayani, Jolan Philippe, Stéphanie Challita, Olivier Barais, Benoit Combemale Distribution of IaC technologies Technology dependency of quality issues Distribution of studied IaC layers Distribution of lifecycle of support approaches Distribution of quality issues Distribution of support techniques Develop IaC Deploy Infrastructure Infrastructure refers to the software, platform, or hardware that delivers or deploys applications to production Infrastructure as Code (IaC) is the approach for automating infrastructure management through machine-readable source code Performance of deployed applications: Under/Over-provisioning of infrastructure resources Inconsistent configurations over infrastructure resources Inconsistent configurations across infrastructure layers: Misalignment of configuration values over Application Application Runtime Platforms Infrastructure Platform IaC quality assurance: Limited evaluation and understanding of IaC quality issues Distribution of development phases Feedback ?