Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code
Summary: Membrane splits Spark’s driver to rewrite plans with security boundaries, protecting fine-grained row/column policies from imperative UDFs and side channels. Supports secure SQL and MapReduce jobs with negligible performance and cost overhead. (summarized by gpt-5.6-luna on Jul 24 2026)
Incoming Non-self Citations Over Time
Authors
- 1. Andrei Paduroiu (Amazon)
- 2. Sungheun Wi (Amazon)
- 3. Yan Yan (Amazon)
- 4. Roni Burd (Amazon)
- 5. Ruhollah Farchtchi (Amazon)
- 6. Giovanni Matteo Fumarola (Amazon)
BibTeX Citation
@article{paduroiu_vldb24,
title = {{Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code}},
author = {Paduroiu, Andrei and Wi, Sungheun and Yan, Yan and Burd, Roni and Farchtchi, Ruhollah and Fumarola, Giovanni Matteo},
journal = {PVLDB},
series = {{VLDB} '24},
volume = {17},
number = {12},
pages = {3813--3826},
doi = {10.14778/3685800.3685808},
url = {https://doi.org/10.14778/3685800.3685808},
year = {2024}
}
Incoming Citations (Sorted by Pagerank)
Showing 1 of 1 citing papers.
| Rank | Citing Paper | Year | Venue | Pagerank |
|---|---|---|---|---|
| 9,127 | Databricks Lakeguard: Supporting Fine-grained Access Control and Multi-user Capabilities for Apache Spark Workloads | 2025 | SIGMOD | 5.3189314e-05 |
Previous
Page 1 / 1
Next
Outgoing Citations (Sorted by Pagerank)
Showing 9 of 9 cited papers.
Citations counted here include only citations to other VLDB/SIGMOD/CIDR/PODS papers in this database.
| Rank | Cited Paper | Year | Venue | Pagerank |
|---|---|---|---|---|
| 24 | Spark SQL: Relational Data Processing in Spark | 2015 | SIGMOD | 0.00054865648 |
| 290 | An Overview of Query Optimization in Relational Systems | 1998 | PODS | 0.0002227038 |
| 476 | The Making of TPC-DS | 2006 | VLDB | 0.00017860667 |
| 552 | Extending Query Rewriting Techniques for Fine-Grained Access Control | 2004 | SIGMOD | 0.00016630306 |
| 1,896 | Limiting Disclosure in Hippocratic Databases | 2004 | VLDB | 9.5249347e-05 |
| 5,376 | Evolution of a Compiling Query Engine | 2021 | VLDB | 6.2415397e-05 |
| 7,090 | Optimizing Queries over Partitioned Tables in MPP Systems | 2014 | SIGMOD | 5.706401e-05 |
| 8,899 | RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution Time | 2023 | SIGMOD | 5.3493418e-05 |
| 8,900 | Redundancy and Information Leakage in Fine-Grained Access Control | 2006 | SIGMOD | 5.3493418e-05 |
Previous
Page 1 / 1
Next
Semantically Similar Papers
| # | Overall Rank | Paper | Year | Venue |
|---|---|---|---|---|
| 1 | 2,681 | Exploiting Matrix Dependency for Efficient Distributed Matrix Computation | 2015 | SIGMOD |
| 2 | 415 | SystemML: Declarative Machine Learning on Spark | 2016 | VLDB |
| 3 | 3,819 | Evolving Databases for New-Gen Big Data Applications | 2017 | CIDR |
| 4 | 10,121 | End-to-End Declarative Data Analytics: Co-designing Engines, Interfaces, and Cloud Infrastructure | 2026 | CIDR |
| 5 | 7,780 | Petabyte-Scale Row-Level Operations in Data Lakehouses | 2024 | VLDB |
| 6 | 11,112 | Off-the-shelf Data Analytics on Serverless | 2024 | CIDR |
| 7 | 9,167 | Dynamic Speculative Optimizations for SQL Compilation in Apache Spark | 2020 | VLDB |
| 8 | 1,190 | Structured Streaming: A Declarative API for Real-Time Applications in Apache Spark | 2018 | SIGMOD |
| 9 | 7,165 | Flare: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework | 2023 | VLDB |
| 10 | 9,127 | Databricks Lakeguard: Supporting Fine-grained Access Control and Multi-user Capabilities for Apache Spark Workloads | 2025 | SIGMOD |