<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2017">
  <identification id="comete" isproject="true">
    <shortname>COMETE</shortname>
    <projectName>Concurrency, Mobility and Transactions</projectName>
    <theme-de-recherche>Security and Confidentiality</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>http://www.lix.polytechnique.fr/comete/</urlTeam>
    <structure_exterieure type="Labs">
      <libelle>Laboratoire d'informatique de l'école polytechnique (LIX)</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>CNRS</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Ecole Polytechnique</libelle>
    </structure_exterieure>
    <header_dates_team>Creation of the Project-Team: 2008 January 01</header_dates_team>
    <LeTypeProjet>Project-Team</LeTypeProjet>
    <keywordsSdN>
      <term>A2.1.1. - Semantics of programming languages</term>
      <term>A2.1.5. - Constraint programming</term>
      <term>A2.1.6. - Concurrent programming</term>
      <term>A2.1.8. - Synchronous languages</term>
      <term>A2.4.1. - Analysis</term>
      <term>A2.4.2. - Model-checking</term>
      <term>A3.4. - Machine learning and statistics</term>
      <term>A4.1. - Threat analysis</term>
      <term>A4.5. - Formal methods for security</term>
      <term>A4.8. - Privacy-enhancing technologies</term>
    </keywordsSdN>
    <keywordsSecteurs>
      <term>B6.1. - Software industry</term>
      <term>B6.6. - Embedded systems</term>
      <term>B9.4.1. - Computer science</term>
      <term>B9.8. - Privacy</term>
    </keywordsSecteurs>
    <UR name="Saclay"/>
  </identification>
  <team id="uid1">
    <person key="comete-2014-idp100432">
      <firstname>Catuscia</firstname>
      <lastname>Palamidessi</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Team leader, Inria, Senior Researcher</moreinfo>
    </person>
    <person key="comete-2014-idp101696">
      <firstname>Konstantinos</firstname>
      <lastname>Chatzikokolakis</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>CNRS, Researcher</moreinfo>
    </person>
    <person key="comete-2014-idp102952">
      <firstname>Frank</firstname>
      <lastname>Valencia</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>CNRS, Researcher</moreinfo>
    </person>
    <person key="ascola-2015-idp118568">
      <firstname>Ali</firstname>
      <lastname>Kassem</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, from Jun 2017</moreinfo>
    </person>
    <person key="comete-2014-idp105440">
      <firstname>Michell</firstname>
      <lastname>Guzman</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="comete-2016-idp161312">
      <firstname>Anna</firstname>
      <lastname>Pazii</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Ecole polytechnique, from Oct 2017</moreinfo>
    </person>
    <person key="comete-2016-idp121664">
      <firstname>Tymofii</firstname>
      <lastname>Prokopenko</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="comete-2017-idp161328">
      <firstname>Marco</firstname>
      <lastname>Romanelli</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, from Oct 2017</moreinfo>
    </person>
    <person key="comete-2017-idp163760">
      <firstname>Hector</firstname>
      <lastname>Delgado Rios</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Ecole polytechnique, from May 2017 until Jul 2017</moreinfo>
    </person>
    <person key="comete-2017-idp166256">
      <firstname>Georgi</firstname>
      <lastname>Dikov</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Ecole polytechnique, from Aug 2017 until Nov 2017</moreinfo>
    </person>
    <person key="comete-2016-idp161312">
      <firstname>Anna</firstname>
      <lastname>Pazii</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, Jan 2017</moreinfo>
    </person>
    <person key="comete-2017-idp171216">
      <firstname>Joaquin</firstname>
      <lastname>Rodriguez Felici</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, from Sep 2017</moreinfo>
    </person>
    <person key="comete-2017-idp161328">
      <firstname>Marco</firstname>
      <lastname>Romanelli</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, from Jun 2017 until Sep 2017</moreinfo>
    </person>
    <person key="commands-2014-idp73120">
      <firstname>Jessica</firstname>
      <lastname>Gameiro</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="grace-2014-idp78336">
      <firstname>Hélèna</firstname>
      <lastname>Kutniak</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="comete-2017-idp181088">
      <firstname>Giovanni</firstname>
      <lastname>Cherubin</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Royal Holloway University of London, UK, Nov 2017</moreinfo>
    </person>
    <person key="comete-2015-idp110600">
      <firstname>Mario</firstname>
      <lastname>Ferreira Alvim Junior</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Federal University of Minas Gerais, Brazil, Dec 2017</moreinfo>
    </person>
    <person key="comete-2017-idp186080">
      <firstname>David</firstname>
      <lastname>Frutos Escrig</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Universidad Complutense Madrid, Spain, until Feb 2017</moreinfo>
    </person>
    <person key="comete-2014-idp112992">
      <firstname>Yusuke</firstname>
      <lastname>Kawamoto</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>AIST, Japan, Nov 2017</moreinfo>
    </person>
    <person key="comete-2017-idp191040">
      <firstname>Santiago</firstname>
      <lastname>Quintero</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Universidad Javeriana de Cali, Colombia, from Nov to Dec 2017</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>Our times are characterized by the massive presence of highly
<i>distributed systems</i> consisting of diverse and specialized devices,
forming heterogeneous networks, and providing different services and
applications. Revolutionary phenomena such as <i>social networks</i> and
<i>cloud computing</i> are examples of such systems.</p>
      <p>In Comète we study emerging concepts of this new era of computing.
<i>Security</i> and <i>privacy</i> are some of the fundamental concerns that
arise in this setting. In particular, in the modern digital world the problem of
keeping information secret or confidential is exacerbated by orders of
magnitude: the frequent interaction between users and electronic devices, and
the continuous connection between these devices and the internet, offer
malicious agents the opportunity to gather and store huge amount of information,
often without the individual even being aware of it. Mobility is an additional
source of vulnerability, since tracing may reveal significant information. To
avoid these kinds of hazards, <i>security protocols</i> and various techniques
for privacy protection have been designed. However, the properties that they
are supposed to ensure are rather subtle, and, furthermore, it is difficult to
foresee all possible expedients that a potential attacker may use. As a
consequence, even protocols that seem at first “obviously correct” are later
(often years later) found to be prone to attacks.</p>
      <p>In addition to the security problems, the problems of correctness, robustness
and reliability are made more challenging by the complexity of these systems,
since they are highly concurrent and distributed. Despite being based on
impressive engineering technologies, they are still prone to faulty behavior due
to errors in the software design.</p>
      <p>To overcome these drawbacks, we need to develop formalisms, reasoning
techniques, and verification methods, to specify systems and protocols, their
intended properties, and to guarantee that these intended properties of
correctness and security are indeed satisfied.</p>
      <p>In Comète we study formal computational frameworks for specifying these
systems, theories for defining the desired properties of correctness and
security and for reasoning about them, and methods and techniques for proving
that a given system satisfies the intended properties.</p>
    </subsection>
  </presentation>
  <fondements id="uid4">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid5" level="1">
      <bodyTitle>Probability and information theory</bodyTitle>
      <participants>
        <person key="comete-2014-idp101696">
          <firstname>Konstantinos</firstname>
          <lastname>Chatzikokolakis</lastname>
        </person>
        <person key="comete-2014-idp100432">
          <firstname>Catuscia</firstname>
          <lastname>Palamidessi</lastname>
        </person>
        <person key="comete-2017-idp161328">
          <firstname>Marco</firstname>
          <lastname>Romanelli</lastname>
        </person>
        <person key="comete-2016-idp161312">
          <firstname>Anna</firstname>
          <lastname>Pazii</lastname>
        </person>
      </participants>
      <p>Much of the research of Comète focuses on security and privacy. In
particular, we are interested in the problem of the leakage of secret
information through public observables.</p>
      <p>Ideally we would like systems to be completely secure, but in practice this goal
is often impossible to achieve. Therefore, we need to reason about the amount of
information leaked, and the utility that it can have for the adversary, i.e.
the probability that the adversary is able to exploit such information.</p>
      <p>The recent tendency is to use an information theoretic approach to model the
problem and define the leakage in a quantitative way. The idea is to consider
the system as an information-theoretic <i>channel</i>. The input represents the
secret, the output represents the observable, and the correlation between the
input and output (<i>mutual information</i>) represents the information leakage.</p>
      <p>Information theory depends on the notion of entropy as a measure of uncertainty.
From the security point of view, this measure corresponds to a particular model
of attack and a particular way of estimating the security threat (vulnerability
of the secret). Most of the proposals in the literature use Shannon entropy,
which is the most established notion of entropy in information theory. We,
however, consider also other notions, in particular Rényi min-entropy, which
seems to be more appropriate for security in common scenarios like one-try
attacks.</p>
    </subsection>
    <subsection id="uid6" level="1">
      <bodyTitle>Expressiveness of Concurrent Formalisms</bodyTitle>
      <participants>
        <person key="comete-2014-idp100432">
          <firstname>Catuscia</firstname>
          <lastname>Palamidessi</lastname>
        </person>
        <person key="comete-2014-idp102952">
          <firstname>Frank</firstname>
          <lastname>Valencia</lastname>
        </person>
      </participants>
      <p>We study computational models and languages for distributed, probabilistic and mobile systems,
with a particular attention to expressiveness issues. We aim at developing criteria to
assess the expressive power of a model or formalism in a distributed
setting, to compare existing models and formalisms, and to define new
ones according to an intended level of expressiveness, also taking
into account the issue of (efficient) implementability.</p>
    </subsection>
    <subsection id="uid7" level="1">
      <bodyTitle>Concurrent constraint programming</bodyTitle>
      <participants>
        <person key="comete-2014-idp105440">
          <firstname>Michell</firstname>
          <lastname>Guzman</lastname>
        </person>
        <person key="comete-2014-idp102952">
          <firstname>Frank</firstname>
          <lastname>Valencia</lastname>
        </person>
      </participants>
      <p>Concurrent constraint programming (ccp) is a well established process calculus for modeling systems where agents interact by posting and asking information in a store, much like in users interact in <i>social networks</i>.
This information is represented as first-order logic formulae, called constraints, on the shared variables of the system (e.g., <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>X</mi><mo>&gt;</mo><mn>42</mn></mrow></math></formula>). The most distinctive and appealing feature of ccp is perhaps that it unifies in a single formalism the operational view of processes based upon process calculi with a declarative one based upon first-order logic. It also has an elegant denotational semantics that interprets processes as closure operators (over the set of constraints ordered by entailment). In other words, any ccp process can be seen as an idempotent, increasing, and monotonic function from stores to stores. Consequently, ccp processes can be viewed
as: computing agents, formulae in the underlying logic, and closure operators. This allows ccp to benefit from the large body of techniques of process calculi, logic and domain theory.</p>
      <p>Our research in ccp develops along the following two lines:</p>
      <orderedlist>
        <li id="uid8">
          <p noindent="true"><b>(a)</b>
The study of a bisimulation semantics for ccp.
The advantage of bisimulation, over other kinds of semantics, is that it can be efficiently verified.</p>
        </li>
        <li id="uid9">
          <p noindent="true"><b>(b)</b>
The extension of ccp with constructs to capture emergent systems such as those in social networks and cloud computing.</p>
        </li>
      </orderedlist>
    </subsection>
    <subsection id="uid10" level="1">
      <bodyTitle>Model checking</bodyTitle>
      <participants>
        <person key="comete-2014-idp101696">
          <firstname>Konstantinos</firstname>
          <lastname>Chatzikokolakis</lastname>
        </person>
        <person key="comete-2014-idp100432">
          <firstname>Catuscia</firstname>
          <lastname>Palamidessi</lastname>
        </person>
      </participants>
      <p>Model checking addresses the problem of establishing whether a given specification satisfies a certain property.
We are interested in developing model-checking techniques for verifying concurrent systems of the kind explained above.
In particular, we focus on security and privacy, i.e., on the problem of proving that a given system satisfies the intended security or privacy properties.
Since the properties we are interested in have a probabilistic nature, we use probabilistic automata to model the protocols.
A challenging problem is represented by the fact that the interplay between nondeterminism and probability, which in security presents subtleties
that cannot be handled with the traditional notion of a scheduler,</p>
    </subsection>
  </fondements>
  <domaine id="uid11">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid12" level="1">
      <bodyTitle>Security and privacy</bodyTitle>
      <participants>
        <person key="comete-2014-idp101696">
          <firstname>Konstantinos</firstname>
          <lastname>Chatzikokolakis</lastname>
        </person>
        <person key="comete-2014-idp100432">
          <firstname>Catuscia</firstname>
          <lastname>Palamidessi</lastname>
        </person>
        <person key="ascola-2015-idp118568">
          <firstname>Ali</firstname>
          <lastname>Kassem</lastname>
        </person>
        <person key="comete-2016-idp161312">
          <firstname>Anna</firstname>
          <lastname>Pazii</lastname>
        </person>
        <person key="comete-2016-idp121664">
          <firstname>Tymofii</firstname>
          <lastname>Prokopenko</lastname>
        </person>
      </participants>
      <p>The aim of our research is the specification and verification
of protocols used in mobile distributed systems,
in particular security protocols. We are especially interested in
protocols for <i>information hiding</i>.</p>
      <p>Information hiding is a generic term which we use here to refer to
the problem of preventing the disclosure of information which is supposed to be secret or confidential.
The most prominent research areas which are concerned with this problem are those of
<i>secure information flow</i> and of <i>privacy</i>.</p>
      <p>Secure information flow refers to the problem of avoiding the so-called <i>propagation</i> of secret
data due to their processing. It was initially considered as related to software, and the research focussed on
type systems and other kind of static analysis to prevent dangerous operations,
Nowadays the setting is more general, and a large part of the research effort is directed
towards the investigation of probabilistic scenarios and treaths.</p>
      <p>Privacy denotes the issue
of preventing certain information to become publicly known. It may refer to the protection of <i>private data</i>
(credit card number, personal info etc.), of the
agent's identity (<i>anonymity</i>), of the link between information and user
(<i>unlinkability</i>), of its activities (<i>unobservability</i>),
and of its <i>mobility</i> (<i>untraceability)</i>.</p>
      <p>The common denominator of this class of problems is that an adversary
can try to infer the private information (<i>secrets</i>) from the
information that he can access (<i>observables</i>).
The solution is then to obfuscate the link between
secrets and observables as much as possible,
and often the use randomization, i.e. the introduction of <i>noise</i>,
can help to achieve this purpose. The system can then
be seen as a <i>noisy channel</i>, in the information-theoretic sense,
between the secrets and the observables.</p>
      <p>We intend to explore the rich set of concepts and techniques in the fields of
information theory and hypothesis testing
to establish the foundations of quantitive information flow and of privacy, and to develop heuristics and methods
to improve mechanisms for the protection of secret information. Our approach will be based on the specification of protocols
in the probabilistic asynchronous <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>π</mi></math></formula>-calculus, and the application of model-checking
to compute the matrices associated to
the corresponding channels.</p>
    </subsection>
  </domaine>
  <logiciels id="uid13">
    <bodyTitle>New Software and Platforms</bodyTitle>
    <subsection id="uid14" level="1">
      <bodyTitle>Location Guard</bodyTitle>
      <p><span class="smallcap" align="left">Keywords:</span> Privacy - Geolocation - Browser Extensions</p>
      <p noindent="true"><span class="smallcap" align="left">Scientific Description:</span> The purpose of Location Guard is to implement obfuscation techniques for achieving location privacy, in a an easy and intuitive way that makes them available to the general public. Various modern applications, running either on smartphones or on the web, allow third parties to obtain the user's location. A smartphone application can obtain this information from the operating system using a system call, while web application obtain it from the browser using a JavaScript call.</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> Websites can ask the browser for your location (via JavaScript). When they do so, the browser first asks your permission, and if you accept, it detects your location (typically by transmitting a list of available wifi access points to a geolocation provider such as Google Location Services, or via GPS if available) and gives it to the website.</p>
      <p>Location Guard is a browser extension that intercepts this procedure. The permission dialog appears as usual, and you can still choose to deny. If you give permission, then Location Guard obtains your location and adds "random noise" to it, creating a fake location. Only the fake location is then given to the website.</p>
      <p>In 2017 there was a major update to the Firefox version of Location Guard, to make it compatible with the Firefox Quantum. This latest Firefox version discontinued support for the legacy addon API, so Location Guard had to be adapted to the new WebExtensions API.</p>
      <p>Moreover, the latest version implements new features requested by users, such as the ability to search for a fixed location, as well as bugfixes.</p>
      <simplelist>
        <li id="uid15">
          <p noindent="true">Participants: Catuscia Palamidessi, Konstantinos Chatzikokolakis, Marco Stronati, Miguel Andrés and Nicolas Bordenabe</p>
        </li>
        <li id="uid16">
          <p noindent="true">Contact: Konstantinos Chatzikokolakis</p>
        </li>
        <li id="uid17">
          <p noindent="true">URL: <ref xlink:href="https://github.com/chatziko/location-guard" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>github.<allowbreak/>com/<allowbreak/>chatziko/<allowbreak/>location-guard</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid18" level="1">
      <bodyTitle>libqif - A Quantitative Information Flow C++ Toolkit Library</bodyTitle>
      <p><span class="smallcap" align="left">Keywords:</span> Information leakage - Privacy - C++ - Linear optimization</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> The goal of libqif is to provide an efficient C++ toolkit implementing a variety of techniques and algorithms from the area of quantitative information flow and differential privacy. We plan to implement all techniques produced by Comète in recent years, as well as several ones produced outside the group, giving the ability to privacy researchers to reproduce our results and compare different techniques in a uniform and efficient framework.</p>
      <p>Some of these techniques were previously implemented in an ad-hoc fashion, in small, incompatible with each-other, non-maintained and usually inefficient tools, used only for the purposes of a single paper and then abandoned. We aim at reimplementing those – as well as adding several new ones not previously implemented – in a structured, efficient and maintainable manner, providing a tool of great value for future research. Of particular interest is the ability to easily re-run evaluations, experiments and case-studies from all our papers, which will be of great value for comparing new research results in the future.</p>
      <p>The library's development continued in 2017 with several new added features. The project's git repository shows for this year 33 commits by 2 contributors. The new functionality was directly applied to the exeperimental results of several publications of the team (PETS'17, GameSec'17, VALUETOOLS'17).</p>
      <simplelist>
        <li id="uid19">
          <p noindent="true">Contact: Konstantinos Chatzikokolakis</p>
        </li>
        <li id="uid20">
          <p noindent="true">URL: <ref xlink:href="https://github.com/chatziko/libqif" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>github.<allowbreak/>com/<allowbreak/>chatziko/<allowbreak/>libqif</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid21" level="1">
      <bodyTitle>dspacenet</bodyTitle>
      <p>
        <i>Distributed-Spaces Network.</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Social networks - Distributed programming</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> DSpaceNet is a tool for social networking based on multi-agent spatial and timed concurrent constraint language.</p>
      <p>I - The fundamental structure of DSPaceNet is that of *space*: A space may contain</p>
      <p>(1) spatial-mobile-reactive tcc programs, and
(2) other spaces.</p>
      <p>Furthermore, (3) each space belongs to a given agent. Thus, a space of an agent j within the space of agent i means that agent i allows agent j to
use a computation sub-space within its space.</p>
      <p>II - The fundamental operation of DSPaceNet is that of *program posting*: In each time unit, agents can post spatial-mobile-reactive tcc programs
in the spaces they are allowed to do so (ordinary message posting corresponds to the posting of tell processes). Thus, an agent can for example
post a watchdog tcc process to react to messages in their space, e.g. whenever (*happy b*frank*) do tell("thank you!"). More complex mobile programs are also allowed (see below).</p>
      <p>The language of programs is a spatial mobile extension of tcc programs:</p>
      <p>
        <formula type="inline">
          <math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll">
            <mrow>
              <mi>P</mi>
              <mo>,</mo>
              <mi>Q</mi>
              <mo>.</mo>
              <mo>.</mo>
              <mo>.</mo>
              <mo>:</mo>
              <mo>=</mo>
              <mi>t</mi>
              <mi>e</mi>
              <mi>l</mi>
              <mi>l</mi>
              <mo>(</mo>
              <mi>c</mi>
              <mo>)</mo>
              <mo>|</mo>
              <mi>w</mi>
              <mi>h</mi>
              <mi>e</mi>
              <mi>n</mi>
              <mi>c</mi>
              <mi>d</mi>
              <mi>o</mi>
              <mi>P</mi>
              <mo>|</mo>
              <mo>|</mo>
              <mi>n</mi>
              <mi>e</mi>
              <mi>x</mi>
              <mi>t</mi>
              <mi>P</mi>
              <mo>|</mo>
              <mi>P</mi>
              <mo>|</mo>
              <mo>|</mo>
              <mi>Q</mi>
              <mo>|</mo>
              <mi>u</mi>
              <mi>n</mi>
              <mi>l</mi>
              <mi>e</mi>
              <mi>s</mi>
              <mi>s</mi>
              <mi>c</mi>
              <mi>n</mi>
              <mi>e</mi>
              <mi>x</mi>
              <mi>t</mi>
              <mi>P</mi>
              <mo>|</mo>
              <mo>[</mo>
              <mi>P</mi>
              <mo>]</mo>
              <mo>_</mo>
              <mi>i</mi>
              <mo>|</mo>
              <mo>↑</mo>
              <mo>_</mo>
              <mi>i</mi>
              <mi>P</mi>
              <mo>|</mo>
              <mi>r</mi>
              <mi>e</mi>
              <mi>c</mi>
              <mi>X</mi>
              <mo>.</mo>
              <mi>P</mi>
            </mrow>
          </math>
        </formula>
      </p>
      <p>computation of timed processes proceeds as in tcc. The spatial construct [ P ]_i runs P in the space of agent i and the mobile process
uparrow_i P, extrudes P from the space of i. By combining space and mobility, arbitrary processes can be moved from one a space into another. For example, one could send a trojan watchdog to another space for spying for a given message and report back to one's space.</p>
      <p>III- Constraint systems can be used to specify advance text message deduction, arithmetic deductions, scheduling, etc.</p>
      <p>IV - Epistemic Interpretation of spaces can be used to derive whether they are users with conflicting/inconsistent information, or whether a group
of agents may be able to deduce certain message.</p>
      <p>V - The scheduling of agent requests for program posts, privacy settings, friendship lists are handled by an external interface. For example, one could use type systems to check whether a program complies with privacy settings (for example checking that the a program does not move other program into a space it is not allowed into).</p>
      <simplelist>
        <li id="uid22">
          <p noindent="true">Partner: Pontificia Universidad Javeriana Cali</p>
        </li>
        <li id="uid23">
          <p noindent="true">Contact: Frank Valencia</p>
        </li>
        <li id="uid24">
          <p noindent="true">URL: <ref xlink:href="http://www.dspacenet.com" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>dspacenet.<allowbreak/>com</ref></p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid25">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid26" level="1">
      <bodyTitle>Foundations of information hiding </bodyTitle>
      <p>Information hiding refers to the problem of protecting private information
while performing certain tasks or interactions, and trying to avoid that an
adversary can infer such information. This is one of the main areas of
research in Comète; we are exploring several topics, described below.</p>
      <subsection id="uid27" level="2">
        <bodyTitle>Information Leakage Games</bodyTitle>
        <p>In <ref xlink:href="#comete-2017-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we studied a game-theoretic setting to model the interplay between attacker
and defender in the context of information flow, and to reason about their
optimal strategies. In contrast with standard game theory, in our games the
utility of a mixed strategy is a convex function of the distribution on the
defender's pure actions, rather than the expected value of their utilities.
Nevertheless, the important properties of game theory, notably the existence
of a Nash equilibrium, still hold for our (zero-sum) leakage games, and we
provided algorithms to compute the corresponding optimal strategies. As
typical in (simultaneous) game theory, the optimal strategy is usually mixed,
i.e., probabilistic, for both the attacker and the defender. From the point
of view of information flow, this was to be expected in the case of the
defender, since it is well known that randomization at the level of the
system design may help to reduce information leaks. Regarding the attacker,
however, this seems the first work (w.r.t. the literature in information
flow) proving formally that in certain cases the optimal attack strategy is
necessarily probabilistic.</p>
      </subsection>
      <subsection id="uid28" level="2">
        <bodyTitle>Efficient Utility Improvement for Location Privacy</bodyTitle>
        <p>The continuously increasing use of location-based services poses an important
threat to the privacy of users. A natural defense is to employ an obfuscation
mechanism, such as those providing geo-indistinguishability
<ref xlink:href="#comete-2017-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a framework for obtaining formal privacy
guarantees that has become popular in recent years. Ideally, one would like
to employ an optimal obfuscation mechanism, providing the best utility among
those satisfying the required privacy level. In theory optimal mechanisms can
be constructed via linear programming. In practice, however, this is only
feasible for a radically small number of locations. As a consequence, all
known applications of geo-indistinguishability simply use noise drawn from a
planar Laplace distribution.</p>
        <p>In <ref xlink:href="#comete-2017-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we studied
methods for substantially improving the utility of location obfuscation,
while maintaining practical applicability as a main goal. We provided such
solutions for both infinite (continuous or discrete) as well as large but
finite domains of locations, using a Bayesian remapping procedure as a key
ingredient. We evaluated our techniques in two real world complete datasets,
without any restriction on the evaluation area, and showed important utility
improvements with respect to the standard planar Laplace approach.</p>
      </subsection>
      <subsection id="uid29" level="2">
        <bodyTitle>Trading Optimality for Performance in Location Privacy</bodyTitle>
        <p>Location-Based Services (LBSs) provide invaluable aid in the everyday
activities of many individuals, however they also pose serious threats to the
user' privacy. There is, therefore, a growing interest in the development of
mechanisms to protect location privacy during the use of LBSs. Nowadays, the
most popular methods are probabilistic, and the so-called optimal method
achieves an optimal trade-off between privacy and utility by using linear
optimization techniques.</p>
        <p>Unfortunately, due to the complexity of linear programming, the method is
unfeasible for a large number <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>N</mi></math></formula> of locations, because the constraints are
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>O</mi><mo>(</mo><msup><mi>N</mi><mn>3</mn></msup><mo>)</mo></mrow></math></formula>. In <ref xlink:href="#comete-2017-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have proposed a technique to reduce the
number of constraints to <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>O</mi><mo>(</mo><msup><mi>N</mi><mn>2</mn></msup><mo>)</mo></mrow></math></formula>, at the price of renouncing to perfect
optimality. We have showed however that on practical situations the utility
loss is quite acceptable, while the gain in performance is significant.</p>
      </subsection>
      <subsection id="uid30" level="2">
        <bodyTitle>Methods for Location Privacy: A comparative overview</bodyTitle>
        <p>The growing popularity of location-based services, allowing to collect huge
amounts of information regarding users' location, has started raising serious
privacy concerns. In <ref xlink:href="#comete-2017-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we analyzed the
various kinds of privacy breaches that may arise in connection with the use
of location-based services, and we surveyd and compared the metrics and the
mechanisms that have been proposed in the literature.</p>
      </subsection>
      <subsection id="uid31" level="2">
        <bodyTitle>Quantifying Leakage in the Presence of Unreliable Sources of Information</bodyTitle>
        <p>Belief and min-entropy leakage are two well-known approaches to quantify
information flow in security systems. Both concepts stand as alternatives to
the traditional approaches founded on Shannon entropy and mutual information,
which were shown to provide inadequate security guarantees. In <ref xlink:href="#comete-2017-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we
unified the two concepts in one model so as to cope with the frequent
(potentially inaccurate, misleading or outdated) attackers' side information
about individuals on social networks, online forums, blogs and other forms of
online communication and information sharing. To this end we proposed a new
metric based on min-entropy that takes into account the adversary's beliefs.</p>
      </subsection>
      <subsection id="uid32" level="2">
        <bodyTitle>Differential Inference Testing: A Practical Approach to Evaluate Anonymized Data</bodyTitle>
        <p>In order to protect individuals' privacy, governments and institutions impose
some obligations on data sharing and publishing. Mainly, they require the
data to be “anonymized”. In this paper, we have shortly discussed the
criteria introduced by European General Data Protection Regulation to assess
anonymized data. We have argued that the evaluation of anonymized data should
be based on whether the data allows individual based inferences, instead of
being centered around the concept of re-identification as the regulation has
proposed.</p>
        <p>Then, we have proposed an inference-based framework that can be used to
evaluate the robustness of a given anonymized dataset against a specific
inference model, e.g. a machine learning model.</p>
        <p>Our approach evaluates the anonymized data itself, and deals with the related
anonymization technique as a black-box. Thus, it can be used to assess
datasets that are anonymized by organizations which may prefer not to provide
access to their techniques. Finally, we have used our framework to evaluate
two datasets after being anonymized using <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>k</mi></math></formula>-anonymity and <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>l</mi></math></formula>-diversity.</p>
      </subsection>
      <subsection id="uid33" level="2">
        <bodyTitle>Formal Analysis and Offline Monitoring of Electronic Exams</bodyTitle>
        <p>More and more universities are moving toward electronic exams (in short
e-exams). This migration exposes exams to additional threats, which may come
from the use of the information and communication technology. In
<ref xlink:href="#comete-2017-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have identified and defined several security
properties for e-exam systems. Then, we have showed how to use these
properties in two complementary approaches: model-checking and monitoring.</p>
        <p>We have illustrated the validity of our definitions by analyzing a real
e-exam used at the pharmacy faculty of University Grenoble Alpes (UGA) to
assess students. On the one hand, we have instantiated our properties as
queries for ProVerif, a process calculus based automatic verifier for
cryptographic protocols,</p>
        <p>and we have used it to check our modeling of UGA exam specifications.
ProVerif found some attacks. On the other hand, we have expressed our
properties as Quantified Event Automata (QEAs), and we have synthesized them
into monitors using MarQ, a Java tool designed to implement QEAs. Then, we
have used these monitors to verify real exam executions conducted by UGA. Our
monitors found fraudulent students and discrepancies between the
specifications of UGA exam and its implementation.</p>
      </subsection>
      <subsection id="uid34" level="2">
        <bodyTitle>On the Compositionality of Quantitative Information Flow</bodyTitle>
        <p>In the min-entropy approach to quantitative information flow, the leakage is
defined in terms of a minimization problem, which, in the case of large systems,
can be computationally rather heavy. The same happens for the recently proposed
generalization called <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>g</mi></math></formula>-vulnerability. In <ref xlink:href="#comete-2017-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we
studied the case in which the channel associated to the system can be decomposed
into simpler channels, which typically happens when the observables consist of
several components. Our main contribution is the derivation of bounds on the
<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>g</mi></math></formula>-leakage of the whole system in terms of the <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>g</mi></math></formula>-leakages of its components.
We also considered the particular cases of min-entropy leakage and of parallel
channels, generalizing and systematizing results from the literature. We
demonstrated the effectiveness of our method and evaluate the precision of our
bounds using examples.</p>
      </subsection>
    </subsection>
    <subsection id="uid35" level="1">
      <bodyTitle>Foundations of Concurrency</bodyTitle>
      <p>Distributed systems have changed substantially in the recent past with the
advent of phenomena like social networks and cloud computing. In the previous
incarnation of distributed computing the emphasis was on consistency, fault
tolerance, resource management and related topics; these were all characterized
by <i>interaction between processes</i>. Research proceeded along two lines: the
algorithmic side which dominated the Principles Of Distributed Computing
conferences and the more process algebraic approach epitomized by CONCUR where
the emphasis was on developing compositional reasoning principles. What marks
the new era of distributed systems is an emphasis on managing access to
information to a much greater degree than before.</p>
      <subsection id="uid36" level="2">
        <bodyTitle>Declarative Framework for Semantical Interpretations of Structured
Information — An Applicative Approach.</bodyTitle>
        <p>Spatial constraint systems are algebraic structures from concurrent
constraint programming to specify spatial and epistemic behavior in
multi-agent system. In <ref xlink:href="#comete-2017-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#comete-2017-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we studied
the applicability of declarative models to encode and describe structured
information by means of semantics. Specifically, we introduced D-SPACES, an
implementation of constraint systems with space and extrusion operators.
D-SPACES provides property-checking methods as well as an implementation of a
specific type of constraint systems (a spatial boolean algebra). We showed
the applicability of this framework with two examples; a scenario in the form
of a social network where users post their beliefs and utter their opinions,
and a semantical interpretation of a logical language to express time
behaviors and properties.</p>
      </subsection>
      <subsection id="uid37" level="2">
        <bodyTitle>Characterizing Right Inverses for Spatial Constraint Systems with
Applications to Modal Logic</bodyTitle>
        <p>In <ref xlink:href="#comete-2017-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> spatial constraint systems were used to give an
abstract characterization of the notion of normality in modal logic and to
derive right inverse/reverse operators for modal languages. In particular, a
necessary and sufficient condition for the existence of right inverses was
identified and the abstract notion of normality is shown to correspond to the
preservation of finite suprema. Furthermore, a taxonomy of normal right
inverses was provided, identifying the greatest normal right inverse as well
as the complete family of minimal right inverses. These results were applied
to existing modal languages such as the weakest normal modal logic,
Hennessy-Milner logic, and linear-time temporal logic. Some implications of
these results were also discussed in the context of modal concepts such as
bisimilarity and inconsistency invariance.</p>
      </subsection>
      <subsection id="uid38" level="2">
        <bodyTitle>Observational and Behavioural Equivalences for Soft Concurrent Constraint
Programming</bodyTitle>
        <p>In citegadducci:hal-01675060 we presented a labelled semantics for Soft
Concurrent Constraint Programming (SCCP), a meta-language where concurrent
agents may synchronise on a shared store by either posting or checking the
satisfaction of (soft) constraints. SCCP generalises the classical formalism
by parametrising the constraint system over an order-enriched monoid, thus
abstractly representing the store with an element of the monoid, and the
standard unlabelled semantics just observes store updates. The novel
operational rules were shown to offer a sound and complete co-inductive
technique to prove the original equivalence over the unlabelled semantics.
Based on this characterisation, we provided an axiomatisation for finite
agents.</p>
      </subsection>
      <subsection id="uid39" level="2">
        <bodyTitle>On the Expressiveness of Spatial Constraint Systems</bodyTitle>
        <p>The dissertation <ref xlink:href="#comete-2017-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> focused on the expressiveness of
spatial constraint systems in the broader perspective of modal and epistemic
behaviour. It was shown that that spatial constraint systems are sufficiently
robust to capture inverse modalities and to derive new results for modal
logics. It was shown that one can use scs’s to express a fundamental
epistemic behaviour such as knowledge. The dissertation also provided an
algebraic characterization of the notion of distributed information by means
of constructors over scs’s.</p>
      </subsection>
    </subsection>
  </resultats>
  <partenariat id="uid40">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid41" level="1">
      <bodyTitle>Regional Initiatives</bodyTitle>
      <subsection id="cid1" level="2">
        <bodyTitle>OPTIMEC</bodyTitle>
        <sanspuceslist>
          <li id="uid42">
            <p noindent="true">Project title: Optimal Mechanisms for Privacy Protection</p>
          </li>
          <li id="uid43">
            <p noindent="true">Funded by: DigiCosme</p>
          </li>
          <li id="uid44">
            <p noindent="true">Duration: September 2016 - August 2019</p>
          </li>
          <li id="uid45">
            <p noindent="true">Coordinator: Catuscia Palamidessi, Inria Saclay, EPI Comète</p>
          </li>
          <li id="uid46">
            <p noindent="true">Other PI's: Serge Haddadm ENS Cachan.</p>
          </li>
          <li id="uid47">
            <p noindent="true">Abstract: In this project we plan to investigate classes of utility and privacy measures, and to devise methods to obtain optimal mechanisms with respect to the trade-off between utility and privacy. In order to represent the probabilistic knowledge of the adversary and of the user, and the fact that mechanisms themselves can be randomized, we will consider a probabilistic setting. We will focus, in particular, on measures that are expressible as linear functions of the probabilities.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid48" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="cid2" level="2">
        <bodyTitle>REPAS</bodyTitle>
        <sanspuceslist>
          <li id="uid49">
            <p noindent="true">Program: ANR Blanc</p>
          </li>
          <li id="uid50">
            <p noindent="true">Project title: Reliable and Privacy-Aware Software Systems via Bisimulation Metrics</p>
          </li>
          <li id="uid51">
            <p noindent="true">Duration: October 2016 - September 2021</p>
          </li>
          <li id="uid52">
            <p noindent="true">Coordinator: Catuscia Palamidessi, Inria Saclay, EPI Comète</p>
          </li>
          <li id="uid53">
            <p noindent="true">Other PI's and partner institutions: Ugo del Lago, Inria Sophia Antipolis (EPI Focus) and University of Bologna (Italy).
Vincent Danos, ENS Paris. Filippo Bonchi, ENS Lyon.</p>
          </li>
          <li id="uid54">
            <p noindent="true">Abstract: In this project, we aim at investigating quantitative notions and tools for proving program correctness and protecting privacy. In particular, we will focus on bisimulation metrics, which are the natural extension of bisimulation on quantitative systems. As a key application, we will develop a mechanism to protect the privacy of users when their location traces are collected.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid55" level="1">
      <bodyTitle>International Initiatives</bodyTitle>
      <subsection id="uid56" level="2">
        <bodyTitle>Inria Associate Teams</bodyTitle>
        <subsection id="uid57" level="3">
          <bodyTitle>
            <ref xlink:href="http://www.lix.polytechnique.fr/~kostas/projects/logis/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">LOGIS </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid58">
              <p noindent="true">Title: Logical and Formal Methods for Information Security</p>
            </li>
            <li id="uid59">
              <p noindent="true">Inria principal investigator: Konstantinos Chatzikokolakis</p>
            </li>
            <li id="uid60">
              <p noindent="true">International Partners:</p>
              <sanspuceslist>
                <li id="uid61">
                  <p noindent="true">Mitsuhiro Okada, Keio University (Japan)</p>
                </li>
                <li id="uid62">
                  <p noindent="true">Yusuke Kawamoto, AIST (Japan)</p>
                </li>
                <li id="uid63">
                  <p noindent="true">Tachio Terauchi, JAIST (Japan)</p>
                </li>
                <li id="uid64">
                  <p noindent="true">Masami Hagiya, University of Tokyo (Japan)</p>
                </li>
              </sanspuceslist>
            </li>
            <li id="uid65">
              <p noindent="true">Start year: 2016</p>
            </li>
            <li id="uid66">
              <p noindent="true">URL: <ref xlink:href="http://www.lix.polytechnique.fr/~kostas/projects/logis/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lix.<allowbreak/>polytechnique.<allowbreak/>fr/<allowbreak/>~kostas/<allowbreak/>projects/<allowbreak/>logis/</ref></p>
            </li>
            <li id="uid67">
              <p noindent="true">Abstract: The project aims at integrating the logical / formal approaches to verify security protocols with (A) complexity theory and (B) information theory. The first direction aims at establishing the foundations of logical verification for security in the computational sense, with the ultimate goal of automatically finding attacks that probabilistic polynomial-time adversaries can carry out on protocols. The second direction aims at developing frameworks and techniques for evaluating and reducing information leakage caused by adaptive attackers.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid68" level="2">
        <bodyTitle>Inria International Partners</bodyTitle>
        <subsection id="uid69" level="3">
          <bodyTitle>Informal International Partners</bodyTitle>
          <sanspuceslist>
            <li id="uid70">
              <p noindent="true">Giovanni Cherubin, Royal Holloway, University of London, UK</p>
            </li>
            <li id="uid71">
              <p noindent="true">Geoffrey Smith, Florida International University, USA</p>
            </li>
            <li id="uid72">
              <p noindent="true">Carroll Morgan, NICTA , Australia</p>
            </li>
            <li id="uid73">
              <p noindent="true">Annabelle McIver, Maquarie University, Australia</p>
            </li>
            <li id="uid74">
              <p noindent="true">Moreno Falaschi, Professor, University of Siena, Italy</p>
            </li>
            <li id="uid75">
              <p noindent="true">Mario Ferreira Alvim Junior, Assistant Professor, Federal University of Minas Gerais, Brazil</p>
            </li>
            <li id="uid76">
              <p noindent="true">Camilo Rueda, Professor, Universidad Javeriana de Cali, Colombia</p>
            </li>
            <li id="uid77">
              <p noindent="true">Carlos Olarte, Universidade Federal do Rio Grande do Norte, Brazil</p>
            </li>
            <li id="uid78">
              <p noindent="true">Camilo Rocha, Associate Professor, Universidad Javeriana de Cali, Colombia</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid79" level="2">
        <bodyTitle>Participation in Other International Programs</bodyTitle>
        <subsection id="uid80" level="3">
          <bodyTitle>CLASSIC</bodyTitle>
          <sanspuceslist>
            <li id="uid81">
              <p noindent="true">Program: Colciencias - Conv. 712.</p>
            </li>
            <li id="uid82">
              <p noindent="true">Project acronym: CLASSIC.</p>
            </li>
            <li id="uid83">
              <p noindent="true">Project title: Concurrency, Logic and Algebra for Social and Spatial Interactive Computation.</p>
            </li>
            <li id="uid84">
              <p noindent="true">Duration: Oct 2016 - Oct 2019.</p>
            </li>
            <li id="uid85">
              <p noindent="true">URL: <ref xlink:href="http://goo.gl/Gv6Lij" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>goo.<allowbreak/>gl/<allowbreak/>Gv6Lij</ref></p>
            </li>
            <li id="uid86">
              <p noindent="true">Coordinator: Camilo Rueda, Universidad Javeriana de Cali, Colombia.</p>
            </li>
            <li id="uid87">
              <p noindent="true">Other PI's and partner institutions: Carlos Olarte, Universidade Federal do Rio Grande do Norte, Brazil. Frank Valencia, CNRS-LIX and Inria Saclay.</p>
            </li>
            <li id="uid88">
              <p noindent="true">Abstract: This project will advance the state of the art of domains such as mathematical logic, order theory and concurrency for reasoning about spatial and epistemic behaviour in multi-agent systems..</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid89" level="3">
          <bodyTitle>EPIC</bodyTitle>
          <sanspuceslist>
            <li id="uid90">
              <p noindent="true">Program: STIC-Amsud.</p>
            </li>
            <li id="uid91">
              <p noindent="true">Project acronym: EPIC.</p>
            </li>
            <li id="uid92">
              <p noindent="true">Project title: EPistemic Interactive Concurrency/</p>
            </li>
            <li id="uid93">
              <p noindent="true">Duration: Oct 2016 - Oct 2019.</p>
            </li>
            <li id="uid94">
              <p noindent="true">URL: <ref xlink:href="https://sites.google.com/site/sticamsudepic/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>sites.<allowbreak/>google.<allowbreak/>com/<allowbreak/>site/<allowbreak/>sticamsudepic/</ref></p>
            </li>
            <li id="uid95">
              <p noindent="true">Coordinator: Frank Valencia, CNRS-LIX and Inria Saclay.</p>
            </li>
            <li id="uid96">
              <p noindent="true">Other PI's and partner institutions: Carlos Olarte, Universidade Federal do Rio Grande do Norte, Brazil. Camilo Rueda, Universidad Javeriana de Cali, Colombia.</p>
            </li>
            <li id="uid97">
              <p noindent="true">Abstract: The aim of the project is to coherently combine and advance the state of the art of domains such as concurrency theory, information theory and rewriting systems for reasoning about social networks.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid98" level="1">
      <bodyTitle>International Research Visitors</bodyTitle>
      <subsection id="uid99" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <sanspuceslist>
          <li id="uid100">
            <p noindent="true">David de Frutos Escrig. Professor, Universidad Complutense Madrid, Spain. Jan-Feb 2017</p>
          </li>
          <li id="uid101">
            <p noindent="true">Giovanni Cherubin, PhD student, Royal Holloway, University of London, UK. May 2017 and Oct 2017</p>
          </li>
          <li id="uid102">
            <p noindent="true">Yusuke Kawamoto, Assistant Professor, National Institute of Advanced Industrial Science and Technology (AIST), Japan. July 2017 and Nov 2017</p>
          </li>
          <li id="uid103">
            <p noindent="true">Carlos Olarte, Assistant Professor, Universidade Federal do Rio Grande do Norte, Brazil. July 2017</p>
          </li>
          <li id="uid104">
            <p noindent="true">Camilo Rocha, Associate Professor, Universidad Javeriana de Cali, Colombia. Oct 2017</p>
          </li>
          <li id="uid105">
            <p noindent="true">Camilo Rueda, Professor, Universidad Javeriana de Cali, Colombia. Nov 2017</p>
          </li>
          <li id="uid106">
            <p noindent="true">Mario Ferreira Alvim Junior, Assistant Professor, Federal University of Minas Gerais, Brazil. Dec 2017</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid107" level="2">
        <bodyTitle>Internships</bodyTitle>
        <sanspuceslist>
          <li id="uid108">
            <p noindent="true">Anna Pazii. Univ. of Kiev, Ukraine. From July 2016 until Jan 2017.</p>
          </li>
          <li id="uid109">
            <p noindent="true">Hector Delgado, Universidad Javeriana de Cali, Colombia. From May 2017 until July 2017.</p>
          </li>
          <li id="uid110">
            <p noindent="true">Marco Romanelli. Univ. of Siena, Italy. From June 2017 until Sept 2017.</p>
          </li>
          <li id="uid111">
            <p noindent="true">Georgi Dikov. Tech. Univ. of Munich, Germany. From Sept 2017 until Nov 2017.</p>
          </li>
          <li id="uid112">
            <p noindent="true">Joaquin Felici. Univ. of Cordoba, Argentina. From Sept 2017 until Jan 2018.</p>
          </li>
          <li id="uid113">
            <p noindent="true">Santiago Quintero, Universidad Javeriana de Cali, Colombia. From Nov until Dec 2017.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid114">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid115" level="1">
      <bodyTitle>Promoting Scientific Activities</bodyTitle>
      <subsection id="uid116" level="2">
        <bodyTitle>Scientific events organisation</bodyTitle>
        <subsection id="uid117" level="3">
          <bodyTitle>Member of the organizing committee</bodyTitle>
          <p>Catuscia Palamidessi is member of:</p>
          <sanspuceslist>
            <li id="uid118">
              <p noindent="true">The Executive Committee of <ref xlink:href="http://siglog.hosting.acm.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">SIGLOG</ref>, the ACM Special Interest Group on Logic and Computation. Since 2014.</p>
            </li>
            <li id="uid119">
              <p noindent="true">The Organizing Committee of <ref xlink:href="http://lics.rwth-aachen.de/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">LICS</ref>, the ACM/IEEE Symposium on Logic in Computer Science. Since 2010.</p>
            </li>
            <li id="uid120">
              <p noindent="true">The Steering Committee of <ref xlink:href="http://www.etaps.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ETAPS</ref>, the European Joint Conferences on Theory and Practice of Software. Since 2006.</p>
            </li>
            <li id="uid121">
              <p noindent="true">The Steering Committee of <ref xlink:href="http://www.eacsl.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">EACSL</ref>, the European Association for Computer Science Logics. Since 2015.</p>
            </li>
            <li id="uid122">
              <p noindent="true">The Steering Committee of CONCUR, the International Conference in Concurrency Theory. Since 2016.</p>
            </li>
            <li id="uid123">
              <p noindent="true">The Steering Committee of FORTE, the International Conference on Formal Techniques for Distributed Objects, Components, and Systems. Since 2014.</p>
            </li>
            <li id="uid124">
              <p noindent="true"><ref xlink:href="http://www.kb.ecei.tohoku.ac.jp/IFIP-TC1/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">The IFIP Technical Committee 1</ref> – Foundations of Computer Science. Since 2007.</p>
            </li>
            <li id="uid125">
              <p noindent="true"><ref xlink:href="http://www.dsi.unive.it/IFIPWG1_7/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">The IFIP Working Group 1.7</ref> – Theoretical Foundations of Security Analysis and Design. Since 2010.</p>
            </li>
            <li id="uid126">
              <p noindent="true"><ref xlink:href="https://concurrency-theory.org/organizations/ifip" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">The IFIP Working Group 1.8</ref> – Concurrency Theory.</p>
            </li>
          </sanspuceslist>
          <p>Frank D. Valencia is member of:</p>
          <sanspuceslist>
            <li id="uid127">
              <p noindent="true">The steering committee of the International Workshop in Concurrency EXPRESS. Since 2010.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid128" level="2">
        <bodyTitle>Scientific events selection</bodyTitle>
        <subsection id="uid129" level="3">
          <bodyTitle>Member of conference program committees</bodyTitle>
          <p>Catuscia Palamidessi is/has been a member of the program committees
of the following conferences and workshops:</p>
          <sanspuceslist>
            <li id="uid130">
              <p noindent="true">PETS 2019. The 19th Privacy Enhancing Technologies Symposium. July 2019.</p>
            </li>
            <li id="uid131">
              <p noindent="true"><ref xlink:href="http://tase2018.jnu.edu.cn" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">TASE 2018</ref>. The 12th International Symposium on Theoretical Aspects of Software Engineering Guangzhou, China, 29-31 August 2018.</p>
            </li>
            <li id="uid132">
              <p noindent="true"><ref xlink:href="https://petsymposium.org/cfp18.php" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">PETS 2018</ref>. The 18th Privacy Enhancing Technologies Symposium. Barcelona, Spain, 24-27 July 2018.</p>
            </li>
            <li id="uid133">
              <p noindent="true"><ref xlink:href="https://www.etaps.org/2018/fossacs" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">FOSSACS 2018</ref>. The 21st International Conference on Foundations of Software Science and Computation Structures. (Part of <ref xlink:href="https://www.etaps.org/2018" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ETAPS 2018</ref>.) Thessaloniki, Greece, 14-21 April 2018.</p>
            </li>
            <li id="uid134">
              <p noindent="true"><ref xlink:href="http://www.sofsem.cz/sofsem18/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">SOFSEM 2018</ref>. The 44th Annual Int'l Conference on Current Trends in Theory and Practice of Computer Science (track on Foundations of Computer Science). Krems an der Donau, Austria, 29 January- 2 February, 2018.</p>
            </li>
            <li id="uid135">
              <p noindent="true"><ref xlink:href="http://fit.uet.vnu.edu.vn/ictac2017/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ICTAC 2017</ref>. The 14th International Colloquium on Theoretical Aspects of Computing.
Hanoi, Vietnam, 23-27 October 2017.</p>
            </li>
            <li id="uid136">
              <p noindent="true"><ref xlink:href="http://tase2017.unice.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">TASE 2017</ref>. The 11th International Symposium on Theoretical Aspects of Software Engineering.
Nice, France, 13-15 September 2017.</p>
            </li>
            <li id="uid137">
              <p noindent="true"><ref xlink:href="https://www.concur2017.tu-berlin.de/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CONCUR 2017</ref>. The 28th International Conference on Concurrency Theory. Berlin, Germany, 5-8 September 2017.</p>
            </li>
            <li id="uid138">
              <p noindent="true"><ref xlink:href="http://www.icsoft-pt.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CSL 2017</ref>. The 26th EACSL Annual Conference on Computer Science Logic. Stockholm, Sweden, 20-25 August 2017.</p>
            </li>
            <li id="uid139">
              <p noindent="true"><ref xlink:href="http://www.icsoft-pt.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ICSOFT-PT 2017</ref>. The 12th International Conference on Software Paradigm Trends. Lisbon, Portugal, 24-26 July 2017.</p>
            </li>
            <li id="uid140">
              <p noindent="true"><ref xlink:href="http://icalp17.mimuw.edu.pl/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ICALP 2017</ref> (Track B). The 44th International Colloquium on Automata, Languages, and Programming. Warsaw, Poland, 10–14 July 2017.</p>
            </li>
            <li id="uid141">
              <p noindent="true"><ref xlink:href="http://2017.discotec.org/calls/forte-2017" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">FORTE 2017</ref>. The 37th IFIP International Conference on Formal Techniques for Distributed Objects, Components, and Systems. Neuchâtel, Switzerland, 19-22 June 2017.</p>
            </li>
            <li id="uid142">
              <p noindent="true"><ref xlink:href="http://logic.pdmi.ras.ru/csr2017/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CSR 2017</ref>. The 12th International Computer Science Symposium in Russia. Kazan, Russia, 8–12 June 2017.</p>
            </li>
          </sanspuceslist>
          <p>Konstantinos Chatzikokolakis is/has been a member of the program committees
of the following conferences and workshops:</p>
          <sanspuceslist>
            <li id="uid143">
              <p noindent="true"><ref xlink:href="http://www.datastories.org/bmda18/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">BMDA 2018</ref>: Workshop on Big Mobility Data Analytics</p>
            </li>
            <li id="uid144">
              <p noindent="true"><ref xlink:href="http://www1.isti.cnr.it/~Massink/EVENTS/QAPL2018/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">QAPL 2018</ref>: International Workshop on Quantitative Aspects of Programming Languages and Systems</p>
            </li>
            <li id="uid145">
              <p noindent="true"><ref xlink:href="https://www.cs.ox.ac.uk/conferences/hotspot2018/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">HotSpot 2018</ref>: 6th Workshop on Hot Issues in Security Principles and Trust</p>
            </li>
            <li id="uid146">
              <p noindent="true"><ref xlink:href="http://icde2017.sdsc.edu/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">ICDE 2017</ref>: IEEE International Conference on Data Engineering</p>
            </li>
            <li id="uid147">
              <p noindent="true"><ref xlink:href="http://csf2017.tecnico.ulisboa.pt/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CSF 2017</ref>: 30th IEEE Computer Security Foundations Symposium</p>
            </li>
            <li id="uid148">
              <p noindent="true"><ref xlink:href="http://www.etaps.org/index.php/2017/post" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">POST 2017</ref>: 6th International Conference on Principles of Security and Trust</p>
            </li>
            <li id="uid149">
              <p noindent="true"><ref xlink:href="http://www-etis.ensea.fr/BigGeoQ-UP/bigqp2017/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">BIGQP 2017</ref>: International Workshop on Big Geo Data Quality and Privacy</p>
            </li>
          </sanspuceslist>
          <p>Frank D. Valencia is/has been a member of the program committees of the following conferences and workshops:</p>
          <sanspuceslist>
            <li id="uid150">
              <p noindent="true"><ref xlink:href="https://sites.google.com/site/radicalconcur/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">RADICAL-2017</ref>. International Workshop Recent Advances in Concurrency and Logic - RADICAL</p>
            </li>
            <li id="uid151">
              <p noindent="true"><ref xlink:href="http://cp2017.a4cp.org/doctoral_program/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CP-ICLP-SAT-DP-17</ref>. Doctoral Program of the 23rd International Conference on Principles and Practice of Constraint Programming</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid152" level="3">
          <bodyTitle>Reviewing</bodyTitle>
          <p>The members of the team reviewed several papers for international conferences and workshops.</p>
        </subsection>
      </subsection>
      <subsection id="uid153" level="2">
        <bodyTitle>Journals</bodyTitle>
        <subsection id="uid154" level="3">
          <bodyTitle>Member of the editorial board</bodyTitle>
          <p>Catuscia Palamidessi is:</p>
          <sanspuceslist>
            <li id="uid155">
              <p noindent="true">Member of the Editorial Board of
<ref xlink:href="https://www.degruyter.com/view/j/popets" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Proceedings on Privacy Enhancing Technologies</ref> (PoPETs), published by De Gruyter.</p>
            </li>
            <li id="uid156">
              <p noindent="true">Member of the Editorial Board of
<ref xlink:href="http://journals.cambridge.org/action/displayJournal?jid=MSC" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Mathematical Structures in Computer Science</ref>, published by the Cambridge University Press.</p>
            </li>
            <li id="uid157">
              <p noindent="true">Member of the Editorial Board of
<ref xlink:href="http://link.springer.com/journal/236" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Acta Informatica</ref>, published by Springer.</p>
            </li>
            <li id="uid158">
              <p noindent="true">Member of the Editorial Board of the
<ref xlink:href="http://www.elsevier.com/journals/electronic-notes-in-theoretical-computer-science/1571-0661" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Electronic Notes of Theoretical Computer Science</ref>,
published by Elsevier Science.</p>
            </li>
            <li id="uid159">
              <p noindent="true">Member of the Editorial Board of <ref xlink:href="http://www.dagstuhl.de/en/publications/lipics" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">LIPIcs: Leibniz International Proceedings in Informatics</ref>, Schloss Dagstuhl–Leibniz Center for Informatics.</p>
            </li>
          </sanspuceslist>
          <p>Konstantinos Chatzikokolakis is:</p>
          <sanspuceslist>
            <li id="uid160">
              <p noindent="true">Editorial board member of the newly established
<ref xlink:href="https://www.degruyter.com/view/j/popets" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Proceedings on Privacy Enhancing Technologies</ref> (PoPETs),
a scholarly journal for timely research papers on privacy.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid161" level="3">
          <bodyTitle>Reviewing</bodyTitle>
          <p>The members of the team regularly review papers for international journals and conferences.</p>
        </subsection>
      </subsection>
      <subsection id="uid162" level="2">
        <bodyTitle>Other Editorial Activities</bodyTitle>
        <p>Frank D. Valencia has been:</p>
        <sanspuceslist>
          <li id="uid163">
            <p noindent="true">Co-editor of the special issue on <ref xlink:href="http://journals.cambridge.org/action/displayJournal?jid=MSC" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Mathematical Structures in Computer Science</ref> dedicated to the best papers from the 12th International Colloquium on Theoretical Aspects of Computing.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid164" level="2">
        <bodyTitle>Participation in other committees</bodyTitle>
        <p>Catuscia Palamidessi has been serving in the following committees:</p>
        <sanspuceslist>
          <li id="uid165">
            <p noindent="true">Member of the committee for the assignment of the Inria International Chairs.</p>
          </li>
          <li id="uid166">
            <p noindent="true">Member of the committee for the <ref xlink:href="http://siglog.hosting.acm.org/awards/alonzo-church-award/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Alonzo Church Award</ref> for Outstanding Contributions to Logic and Computation. Since 2015. In 2018 Palamidessi is the president of this committee.</p>
          </li>
          <li id="uid167">
            <p noindent="true">President of the selection committee for the <ref xlink:href="http://www.eatcs.org/index.php/best-etaps-paper" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">EATCS Best Paper Award</ref> at the ETAPS conferences. Since 2006.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid168" level="2">
        <bodyTitle>Invited talks</bodyTitle>
        <p>Catuscia Palamidessi has given invited talks at the following conferences and workshops:</p>
        <sanspuceslist>
          <li id="uid169">
            <p noindent="true"><ref xlink:href="http://facs2017.di.uminho.pt/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">FACS 2017</ref>. The 14th International Conference on Formal Aspects of Component Software. Barga, Portugal. 10-13 Oct, 2017.</p>
          </li>
          <li id="uid170">
            <p noindent="true"><ref xlink:href="https://www.b2match.eu/ecw2017" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Cybersecurity 2017</ref>. Focus Day on Cyber Security and Helthcare. In the context of the European Cyber Week. Rennes, France, 30 November 2017.</p>
          </li>
          <li id="uid171">
            <p noindent="true"><ref xlink:href="http://disat.uninsubria.it/~simone.tini/workshop.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">QuaSy 2017</ref>. Quantitative Systems: Theory and Applications. Como, Italy, 16-17 October 2017.</p>
          </li>
          <li id="uid172">
            <p noindent="true"><ref xlink:href="https://sites.google.com/site/firstwomeninlogicworkshop/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Women in Logic 2017</ref>, Reykjavik, Island, June 2017.</p>
          </li>
          <li id="uid173">
            <p noindent="true"><ref xlink:href="http://crossfyre17.gforge.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CrossFyre 2017</ref> Workshop on Cryptography, Robustness, and Provably Secure Schemes. Paris. April 2017.</p>
          </li>
          <li id="uid174">
            <p noindent="true"><ref xlink:href="http://www.icissp.org/ForSE.aspx?y=2017" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">FORSE 2017</ref> (Keynote speaker). 1st International Workshop on FORmal methods for Security Engineering. Porto, Portugal. 19–21 February, 2017.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid175" level="2">
        <bodyTitle>Service</bodyTitle>
        <p>Catuscia Palamidessi has served as:</p>
        <sanspuceslist>
          <li id="uid176">
            <p noindent="true">Reviewer for the projects proposal for the program PRIN, sponsored by the Italian MIUR (“Ministero dell'Istruzione, dell'Università e della Ricerca”). Since 2004.</p>
          </li>
        </sanspuceslist>
        <p>Frank Valencia has served as:</p>
        <sanspuceslist>
          <li id="uid177">
            <p noindent="true">Directeur adjoint de l'UMR 7161, le Laboratoire d'Informatique de l'Ecole Polytechnique (LIX). May 2016 - .</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid178" level="1">
      <bodyTitle>Teaching - Supervision - Juries</bodyTitle>
      <subsection id="uid179" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <sanspuceslist>
          <li id="uid180">
            <p noindent="true">Master : Frank D. Valencia has been teaching the undergraduate course "Computability", 45 hours, at the Pontificia Universidad Javeriana de Cali, Colombia. July 27 - Nov 1, 2017.</p>
          </li>
          <li id="uid181">
            <p noindent="true">Master : Frank D. Valencia has been teaching the masters course "Foundations of Computer Science", 45 hours, at the Pontificia Universidad Javeriana de Cali, Colombia. Jan 27 - Jun 1, 2017.</p>
          </li>
          <li id="uid182">
            <p noindent="true">Master: Konstantinos Chatzikokolakis and Catuscia Palamidessi have been teaching a course on the Foundations of Privacy at the
<ref xlink:href="https://wikimpri.dptinfo.ens-cachan.fr/doku.php" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">MPRI</ref>, the Master Parisien pour la Recherche en Informatique. University of Paris VII. A.Y. 2016-17 and 2017-18. Total for each semester: 24 hours plus 6 hours for the exam and the exercise session is preparation to the exam.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid183" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <sanspuceslist>
          <li id="uid184">
            <p noindent="true">PhD in progress (2017-) Marco Romanelli. Co-supervised by Konstantinos Chatzikokolakis, Catuscia Palamidessi, and Moreno Falaschi (University of Siena, Italy). Thesis subject: Application of Information Flow to feature selection in machine learning.</p>
          </li>
          <li id="uid185">
            <p noindent="true">PhD in progress (2017-) Anna Pazii. Co-supervised by Konstantinos Chatzikokolakis and Catuscia Palamidessi. Thesis subject: Local Differential Privacy.</p>
          </li>
          <li id="uid186">
            <p noindent="true">PhD in progress (2016-) <ref xlink:href="http://www.lix.polytechnique.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Tymofii Prokopenko</ref>. Ecole Polytechnique and ENS Cachan. Grant Digiteo-Digicosme. Co-supervised by Konstantinos Chatzikokolakis, Catuscia Palamidessi, and Serge Haddad (ENS Cachan).</p>
          </li>
          <li id="uid187">
            <p noindent="true">PhD in progress (2017-) <ref xlink:href="https://sites.google.com/site/sergiosramirezrico/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Sergio Ramirez</ref>. Co-supervised by Frank Valencia and Camilo Rueda, Universidad Javeriana Cali. Thesis subject: Quantitive Spatial Constraint Systems.</p>
          </li>
          <li id="uid188">
            <p noindent="true">PhD terminated (2015-17) <ref xlink:href="http://www.lix.polytechnique.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Joris Lamare</ref>. Ecole Polytechnique. Grant MSR Center. Co-supervised by Catuscia Palamidessi and Konstantinos Chatzikokolakis. Joris has stopped his PhD due to personal reasons.</p>
          </li>
          <li id="uid189">
            <p noindent="true">PhD completed (2014-17) <ref xlink:href="http://www.lix.polytechnique.fr/~guzman/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Michel Guzman</ref>. Titile: On the Expressiveness of Spatial Constraint Systems <ref xlink:href="#comete-2017-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Ecole Polytechnique. Grant Inria CORDI-S. Co-supervised by Catuscia Palamidessi and Frank D. Valencia.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid190" level="2">
        <bodyTitle>Juries</bodyTitle>
        <p>Catuscia Palamidessi has been reviewer and member of the board at the PhD defense for the thesis of the following PhD student:</p>
        <sanspuceslist>
          <li id="uid191">
            <p noindent="true">Nicolas Bonifas (Ecole Polytechnique, France). Member of the committee board at the PhD defense. Title of the thesis: <i>Geometric and Dual Approaches to Cumulative Scheduling</i>. Supervised by Philippe Baptiste. Defended in December 2017.</p>
          </li>
          <li id="uid192">
            <p noindent="true">Maggie Mhanna (CentraleSupelec, France). Member of the committee board at the PhD defense. Supervised by Pablo Piantanida. Defended in January 2017.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid193" level="2">
        <bodyTitle>Other didactical duties</bodyTitle>
        <p>Catuscia Palamidessi is:</p>
        <sanspuceslist>
          <li id="uid194">
            <p noindent="true">Member of the advising committee for Hamid Ebadi, PhD student supervised by David Sands, Chalmers University, Sweden, since 2014. Also reviewer and member of the committee for the half-way thesis defense (Licentiate) that took place in June 2015.</p>
          </li>
          <li id="uid195">
            <p noindent="true">External member of the scientific council for the PhD in Computer Science at the University of Pisa, Italy. Since 2012.</p>
          </li>
          <li id="uid196">
            <p noindent="true">Member of the advising committee for the PhD of Jun Wang (PhD student supervised by Qiang Tang and Peter Ryan), University of Luxembourg. Since December 2014.</p>
          </li>
          <li id="uid197">
            <p noindent="true">Member of the advising committee for the PhD of Andrea Margheri (PhD student supervised by Rosario Pugliese), University of Florence, Italy. 2014-16.</p>
          </li>
        </sanspuceslist>
        <p>Konstantinos Chatzikokolakis and Catuscia Palamidessi have designed, and coordinate, a course on the Foundations of Privacy at the
<ref xlink:href="https://wikimpri.dptinfo.ens-cachan.fr/doku.php" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">MPRI</ref>, the Master Parisien pour la Recherche en Informatique. University of Paris VII. A.Y. Since 2015.</p>
      </subsection>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="comete-2017-bid20" type="article" rend="refer" n="refercite:alvim:hal-00940425">
      <identifiant type="doi" value="10.3233/JCS-150528"/>
      <identifiant type="hal" value="hal-00940425"/>
      <analytic>
        <title level="a">On the information leakage of differentially-private mechanisms</title>
        <author>
          <persName>
            <foreName>Mário Sérgio</foreName>
            <surname>Alvim</surname>
            <initial>M. S.</initial>
          </persName>
          <persName>
            <foreName>Miguel E.</foreName>
            <surname>Andrés</surname>
            <initial>M. E.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName>
            <foreName>Pierpaolo</foreName>
            <surname>Degano</surname>
            <initial>P.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Computer Security</title>
        <imprint>
          <biblScope type="volume">23</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2015</year>
          </dateStruct>
          <biblScope type="pages">427-469</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00940425" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00940425</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid15" type="inproceedings" rend="refer" n="refercite:alvim:hal-00989462">
      <identifiant type="doi" value="10.1109/CSF.2014.29"/>
      <identifiant type="hal" value="hal-00989462"/>
      <analytic>
        <title level="a">Additive and multiplicative notions of leakage, and their capacities</title>
        <author>
          <persName>
            <foreName>Mário S.</foreName>
            <surname>Alvim</surname>
            <initial>M. S.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName>
            <foreName>Annabelle</foreName>
            <surname>McIver</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Carroll</foreName>
            <surname>Morgan</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2015-idp114456">
            <foreName>Geoffrey</foreName>
            <surname>Smith</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">27th Computer Security Foundations Symposium (CSF 2014)</title>
        <loc>Vienna, Austria</loc>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2014</year>
          </dateStruct>
          <biblScope type="pages">308–322</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00989462" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00989462</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid19" type="inproceedings" rend="refer" n="refercite:alvim:hal-01330414">
      <identifiant type="hal" value="hal-01330414"/>
      <analytic>
        <title level="a">Axioms for Information Leakage</title>
        <author>
          <persName>
            <foreName>Mário S.</foreName>
            <surname>Alvim</surname>
            <initial>M. S.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName>
            <foreName>Annabelle</foreName>
            <surname>McIver</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Carroll</foreName>
            <surname>Morgan</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2015-idp114456">
            <foreName>Geoffrey</foreName>
            <surname>Smith</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">29th Computer Security Foundations Symposium (CSF 2016)</title>
        <loc>Lisbon, Portugal</loc>
        <imprint>
          <publisher>
            <orgName type="organisation">IEEE</orgName>
          </publisher>
          <dateStruct>
            <month>June</month>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">16</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01330414" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01330414</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid17" type="inproceedings" rend="refer" n="refercite:alvim:hal-00734044">
      <identifiant type="doi" value="10.1109/CSF.2012.26"/>
      <identifiant type="hal" value="hal-00734044"/>
      <analytic>
        <title level="a">Measuring Information Leakage using Generalized Gain Functions</title>
        <author>
          <persName>
            <foreName>Mário</foreName>
            <surname>Alvim</surname>
            <initial>M.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2015-idp114456">
            <foreName>Geoffrey</foreName>
            <surname>Smith</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Computer Security Foundations</title>
        <loc>Cambridge MA, United States</loc>
        <imprint>
          <publisher>
            <orgName>IEEE</orgName>
          </publisher>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <biblScope type="pages">265-279</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00734044" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00734044</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid18" type="inproceedings" rend="refer" n="refercite:andres:hal-00766821">
      <identifiant type="doi" value="10.1145/2508859.2516735"/>
      <identifiant type="hal" value="hal-00766821"/>
      <analytic>
        <title level="a">Geo-Indistinguishability: Differential Privacy for Location-Based Systems</title>
        <author>
          <persName>
            <foreName>Miguel</foreName>
            <surname>Andrés</surname>
            <initial>M.</initial>
          </persName>
          <persName key="comete-2014-idp104192">
            <foreName>Nicolás</foreName>
            <surname>Bordenabe</surname>
            <initial>N.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">20th ACM Conference on Computer and Communications Security</title>
        <loc>Berlin, Allemagne</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <publisher>
            <orgName type="organisation">ACM</orgName>
          </publisher>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">901-914</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00766821" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00766821</ref>
        </imprint>
      </monogr>
      <note type="bnote">DGA, Inria large scale initiative CAPPRIS</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid22" type="inproceedings" rend="refer" n="refercite:aristizabal:hal-00546722">
      <identifiant type="doi" value="10.1007/ISBN 978-3-642-19804-5"/>
      <identifiant type="hal" value="hal-00546722"/>
      <analytic>
        <title level="a">Deriving Labels and Bisimilarity for Concurrent Constraint Programming</title>
        <author>
          <persName>
            <foreName>Andrés</foreName>
            <surname>Aristizábal</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Filippo</foreName>
            <surname>Bonchi</surname>
            <initial>F.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp106688">
            <foreName>Luis</foreName>
            <surname>Pino</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>D.</foreName>
            <surname>Valencia</surname>
            <initial>D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Martin</foreName>
            <surname>Hofmann</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">FOSSACS 2011 : 14th International Conference on Foundations of Software Science and Computational Structures</title>
        <loc>Saarbrücken, Germany</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6604</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>March</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">138-152</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-00546722" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-00546722</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid16" type="inproceedings" rend="refer" n="refercite:Bordenabe:14:CCS">
      <identifiant type="doi" value="10.1145/2660267.2660345"/>
      <identifiant type="hal" value="hal-00950479"/>
      <analytic>
        <title level="a">Optimal Geo-Indistinguishable Mechanisms for Location Privacy</title>
        <author>
          <persName key="comete-2014-idp104192">
            <foreName>Nicolás E.</foreName>
            <surname>Bordenabe</surname>
            <initial>N. E.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Gail-Joon</foreName>
            <surname>Ahn</surname>
            <initial>G.-J.</initial>
          </persName>
          <persName>
            <foreName>Moti</foreName>
            <surname>Yung</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Ninghui</foreName>
            <surname>Li</surname>
            <initial>N.</initial>
          </persName>
        </editor>
        <title level="m">CCS - 21st ACM Conference on Computer and Communications Security</title>
        <loc>Scottsdale, Arizona, United States</loc>
        <title level="s">Proceedings of the 21st ACM Conference on Computer and Communications Security</title>
        <imprint>
          <publisher>
            <orgName>ACM</orgName>
          </publisher>
          <publisher>
            <orgName type="organisation">Gail-Joon Ahn</orgName>
          </publisher>
          <dateStruct>
            <month>November</month>
            <year>2014</year>
          </dateStruct>
          <biblScope type="pages">251-262</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00950479" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00950479</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid14" type="article" rend="refer" n="refercite:chatzikokolakis:hal-01270197">
      <identifiant type="doi" value="10.1515/popets-2015-0023"/>
      <identifiant type="hal" value="hal-01270197"/>
      <analytic>
        <title level="a">Constructing elastic distinguishability metrics for location privacy</title>
        <author>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp109176">
            <foreName>Marco</foreName>
            <surname>Stronati</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Proceedings on Privacy Enhancing Technologies</title>
        <imprint>
          <biblScope type="volume">2015</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <month>June</month>
            <year>2015</year>
          </dateStruct>
          <biblScope type="pages">156-170</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01270197" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01270197</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid23" type="article" rend="refer" n="refercite:guzman:hal-01257113">
      <identifiant type="doi" value="10.1016/j.jlamp.2016.09.001"/>
      <identifiant type="hal" value="hal-01257113"/>
      <analytic>
        <title level="a">Belief, Knowledge, Lies and Other Utterances in an Algebra for Space and Extrusion</title>
        <author>
          <persName key="comete-2014-idp105440">
            <foreName>Michell</foreName>
            <surname>Guzmán</surname>
            <initial>M.</initial>
          </persName>
          <persName key="mexico-2014-idm27712">
            <foreName>Stefan</foreName>
            <surname>Haar</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Salim</foreName>
            <surname>Perchy</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Camilo</foreName>
            <surname>Rueda</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank</foreName>
            <surname>Valencia</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Logical and Algebraic Methods in Programming</title>
        <imprint>
          <dateStruct>
            <month>September</month>
            <year>2016</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01257113" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01257113</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid21" type="inproceedings" rend="refer" n="refercite:knight:hal-00761116">
      <identifiant type="doi" value="10.1007/978-3-642-32940-1"/>
      <identifiant type="hal" value="hal-00761116"/>
      <analytic>
        <title level="a">Spatial and Epistemic Modalities in Constraint-Based Process Calculi</title>
        <author>
          <persName>
            <foreName>Sophia</foreName>
            <surname>Knight</surname>
            <initial>S.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Prakash</foreName>
            <surname>Panangaden</surname>
            <initial>P.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank D.</foreName>
            <surname>Valencia</surname>
            <initial>F. D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">CONCUR 2012 - Concurrency Theory - 23rd International Conference, CONCUR 2012</title>
        <loc>Newcastle upon Tyne, United Kingdom</loc>
        <imprint>
          <biblScope type="volume">7454</biblScope>
          <dateStruct>
            <month>September</month>
            <year>2012</year>
          </dateStruct>
          <biblScope type="pages">317-332</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00761116" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00761116</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid11" type="phdthesis" rend="year" n="cite:guzman:tel-01674956">
      <identifiant type="hal" value="tel-01674956"/>
      <monogr>
        <title level="m">On the Expressiveness of Spatial Constraint Systems</title>
        <author>
          <persName key="comete-2014-idp105440">
            <foreName>Michell</foreName>
            <surname>Guzmán</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">École Polytechnique X</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/tel-01674956" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>tel-01674956</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Theses</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid2" type="article" rend="year" n="cite:chatzikokolakis:hal-01422842">
      <identifiant type="doi" value="10.1515/popets-2017-0051"/>
      <identifiant type="hal" value="hal-01422842"/>
      <analytic>
        <title level="a">Efficient Utility Improvement for Location Privacy</title>
        <author>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2015-idp104296">
            <foreName>Ehab</foreName>
            <surname>Elsalamouny</surname>
            <initial>E.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02829">
        <idno type="issn">2299-0984</idno>
        <title level="j">Proceedings on Privacy Enhancing Technologies</title>
        <imprint>
          <biblScope type="volume">2017</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">308-328</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01422842" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01422842</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid4" subtype="nonparu-n" type="article" rend="year" n="cite:chatzikokolakis:hal-01421457">
      <identifiant type="hal" value="hal-01421457"/>
      <analytic>
        <title level="a">Methods for Location Privacy: A comparative overview</title>
        <author>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2015-idp104296">
            <foreName>Ehab</foreName>
            <surname>Elsalamouny</surname>
            <initial>E.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2016-idp161312">
            <foreName>Anna</foreName>
            <surname>Pazii</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03106">
        <idno type="issn">2474-1558</idno>
        <title level="j">Foundations and Trends® in Privacy and Security </title>
        <imprint>
          <biblScope type="volume">1</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">199-257</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01421457" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01421457</ref>
        </imprint>
      </monogr>
      <note type="bnote">Submitted for publication</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid12" type="article" rend="year" n="cite:gadducci:hal-01675060">
      <identifiant type="doi" value="10.1016/j.jlamp.2017.06.001"/>
      <identifiant type="hal" value="hal-01675060"/>
      <analytic>
        <title level="a">Observational and Behavioural Equivalences for Soft Concurrent Constraint Programming</title>
        <author>
          <persName>
            <foreName>Fabio</foreName>
            <surname>Gadducci</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Francesco</foreName>
            <surname>Santini</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Luis Fernando</foreName>
            <surname>Pino Duque</surname>
            <initial>L. F.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank</foreName>
            <surname>Valencia</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02911">
        <idno type="issn">2352-2208</idno>
        <title level="j">Journal of Logical and Algebraic Methods in Programming</title>
        <imprint>
          <biblScope type="volume">92</biblScope>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">45-63</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01675060" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01675060</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid9" type="article" rend="year" n="cite:haar:hal-01673529">
      <identifiant type="doi" value="10.1142/S1793351X17400189"/>
      <identifiant type="hal" value="hal-01673529"/>
      <analytic>
        <title level="a">Declarative Framework for Semantical Interpretations of Structured Information — An Applicative Approach</title>
        <author>
          <persName key="mexico-2014-idm27712">
            <foreName>Stefan</foreName>
            <surname>Haar</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Salim</foreName>
            <surname>Perchy</surname>
            <initial>S.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank</foreName>
            <surname>Valencia</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02199">
        <idno type="issn">1793-351X</idno>
        <title level="j">International Journal of Semantic Computing</title>
        <imprint>
          <biblScope type="volume">11</biblScope>
          <biblScope type="number">04</biblScope>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">451 - 472</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01673529" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01673529</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct subtype="nonparu-n" id="comete-2017-bid5" type="article" rend="year" n="cite:hamadou:hal-01421417">
      <identifiant type="hal" value="hal-01421417"/>
      <analytic>
        <title level="a">Quantifying Leakage in the Presence of Unreliable Sources of Information</title>
        <author>
          <persName>
            <foreName>Sardaouna</foreName>
            <surname>Hamadou</surname>
            <initial>S.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Vladimiro</foreName>
            <surname>Sassone</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01107">
        <idno type="issn">0022-0000</idno>
        <title level="j">Journal of Computer and System Sciences</title>
        <imprint>
          <biblScope type="volume">88</biblScope>
          <dateStruct>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">27-52</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01421417" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01421417</ref>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid6" type="article" rend="year" n="cite:kassem:hal-01653884">
      <identifiant type="doi" value="10.1007/s10703-017-0280-0"/>
      <identifiant type="hal" value="hal-01653884"/>
      <analytic>
        <title level="a">Formal analysis and offline monitoring of electronic exams</title>
        <author>
          <persName key="ascola-2015-idp118568">
            <foreName>Ali</foreName>
            <surname>Kassem</surname>
            <initial>A.</initial>
          </persName>
          <persName key="corse-2015-idp86000">
            <foreName>Yliès</foreName>
            <surname>Falcone</surname>
            <initial>Y.</initial>
          </persName>
          <persName>
            <foreName>Pascal</foreName>
            <surname>Lafourcade</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00603">
        <idno type="issn">0925-9856</idno>
        <title level="j">Formal Methods in System Design</title>
        <imprint>
          <biblScope type="volume">51</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>August</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">117 - 153</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01653884" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01653884</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid7" type="article" rend="year" n="cite:kawamoto:hal-01421424">
      <identifiant type="hal" value="hal-01421424"/>
      <analytic>
        <title level="a">On the Compositionality of Quantitative Information Flow</title>
        <author>
          <persName key="comete-2014-idp112992">
            <foreName>Yusuke</foreName>
            <surname>Kawamoto</surname>
            <initial>Y.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01362">
        <idno type="issn">1860-5974</idno>
        <title level="j">Logical Methods in Computer Science</title>
        <imprint>
          <biblScope type="volume">13</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>August</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">1-31</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01421424" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01421424</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1611.00455" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1611.<allowbreak/>00455</ref> - Submitted for publication to Logical Methods in Computer Science</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid0" type="inproceedings" rend="year" n="cite:alvim:hal-01678950">
      <identifiant type="doi" value="10.1007/978-3-319-68711-7_23"/>
      <identifiant type="hal" value="hal-01678950"/>
      <analytic>
        <title level="a"> Information Leakage Games</title>
        <author>
          <persName>
            <foreName>Mário S.</foreName>
            <surname>Alvim</surname>
            <initial>M. S.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp112992">
            <foreName>Yusuke</foreName>
            <surname>Kawamoto</surname>
            <initial>Y.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Stefan</foreName>
            <surname>Rass</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Bo</foreName>
            <surname>An</surname>
            <initial>B.</initial>
          </persName>
          <persName>
            <foreName>Christopher</foreName>
            <surname>Kiekintveld</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Fei</foreName>
            <surname>Fang</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Stefan</foreName>
            <surname>Schauer</surname>
            <initial>S.</initial>
          </persName>
        </editor>
        <title level="m">Decision and Game Theory for Security - 8th International Conference</title>
        <loc>Vienna, Austria</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10575</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">437-457</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01678950" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01678950</ref>
        </imprint>
        <meeting id="cid401151">
          <title>Conference on Decision and Game Theory for Security</title>
          <num>8</num>
          <abbr type="sigle">GAMESEC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid3" subtype="nonparu-p" type="inproceedings" rend="year" n="cite:chatzikokolakis:hal-01678256">
      <identifiant type="hal" value="hal-01678256"/>
      <analytic>
        <title level="a"> Trading Optimality for Performance in Location Privacy</title>
        <author>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="mexico-2014-idp66944">
            <foreName>Serge</foreName>
            <surname>Haddad</surname>
            <initial>S.</initial>
          </persName>
          <persName key="ascola-2015-idp118568">
            <foreName>Ali</foreName>
            <surname>Kassem</surname>
            <initial>A.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">11th EAI International Conference on Performance Evaluation Methodologies and Tools</title>
        <loc>Venice, Italy</loc>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01678256" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01678256</ref>
        </imprint>
        <meeting id="cid296546">
          <title>International Conference on Performance Evaluation Methodologies and Tools</title>
          <num>11</num>
          <abbr type="sigle">VALUETOOLS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid8" type="inproceedings" rend="year" n="cite:haar:hal-01328189">
      <identifiant type="hal" value="hal-01328189"/>
      <analytic>
        <title level="a">D-SPACES: Implementing Declarative Semantics for Spatially Structured Information</title>
        <author>
          <persName key="mexico-2014-idm27712">
            <foreName>Stefan</foreName>
            <surname>Haar</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Salim</foreName>
            <surname>Perchy</surname>
            <initial>S.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank</foreName>
            <surname>Valencia</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">11th International Conference on Semantic Computing</title>
        <loc>San Diego, California, United States</loc>
        <title level="s">IEEE ICSC 2017</title>
        <imprint>
          <biblScope type="volume">11</biblScope>
          <publisher>
            <orgName type="organisation">IEEE</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01328189" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01328189</ref>
        </imprint>
        <meeting id="cid498482">
          <title>IEEE International Conference on Semantic Computing</title>
          <num>11</num>
          <abbr type="sigle">ICSC</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid13" type="techreport" rend="year" n="cite:kassem:hal-01681014">
      <identifiant type="hal" value="hal-01681014"/>
      <monogr>
        <title level="m">Differential Inference Testing A Practical Approach to Evaluate Anonymized Data</title>
        <author>
          <persName key="ascola-2015-idp118568">
            <foreName>Ali</foreName>
            <surname>Kassem</surname>
            <initial>A.</initial>
          </persName>
          <persName key="privatics-2014-idp71632">
            <foreName>Gergely</foreName>
            <surname>Acs</surname>
            <initial>G.</initial>
          </persName>
          <persName key="privatics-2014-idm28616">
            <foreName>Claude</foreName>
            <surname>Castelluccia</surname>
            <initial>C.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="institution">Inria</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01681014" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01681014</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid10" subtype="nonparu-n" type="unpublished" rend="year" n="cite:guzman:hal-01675010">
      <identifiant type="hal" value="hal-01675010"/>
      <monogr>
        <title level="m">Characterizing Right Inverses for Spatial Constraint Systems with Applications to Modal Logic </title>
        <author>
          <persName key="comete-2014-idp105440">
            <foreName>Michell</foreName>
            <surname>Guzmán</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Salim</foreName>
            <surname>Perchy</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Camilo</foreName>
            <surname>Rueda</surname>
            <initial>C.</initial>
          </persName>
          <persName key="comete-2014-idp102952">
            <foreName>Frank</foreName>
            <surname>Valencia</surname>
            <initial>F.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01675010" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01675010</ref>
        </imprint>
      </monogr>
      <note type="bnote">Submitted to Theoretical Computer Science (TCS)</note>
    </biblStruct>
    
    <biblStruct id="comete-2017-bid1" type="inproceedings" rend="foot" n="footcite:andres:hal-00766821">
      <identifiant type="doi" value="10.1145/2508859.2516735"/>
      <identifiant type="hal" value="hal-00766821"/>
      <analytic>
        <title level="a">Geo-Indistinguishability: Differential Privacy for Location-Based Systems</title>
        <author>
          <persName>
            <foreName>Miguel</foreName>
            <surname>Andrés</surname>
            <initial>M.</initial>
          </persName>
          <persName key="comete-2014-idp104192">
            <foreName>Nicolás</foreName>
            <surname>Bordenabe</surname>
            <initial>N.</initial>
          </persName>
          <persName key="comete-2014-idp101696">
            <foreName>Konstantinos</foreName>
            <surname>Chatzikokolakis</surname>
            <initial>K.</initial>
          </persName>
          <persName key="comete-2014-idp100432">
            <foreName>Catuscia</foreName>
            <surname>Palamidessi</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">20th ACM Conference on Computer and Communications Security</title>
        <loc>Berlin, Allemagne</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <publisher>
            <orgName type="organisation">ACM</orgName>
          </publisher>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">901-914</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00766821" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00766821</ref>
        </imprint>
      </monogr>
      <note type="bnote">DGA, Inria large scale initiative CAPPRIS</note>
    </biblStruct>
  </biblio>
</raweb>
