Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code
Summary: Membrane splits Spark’s driver to rewrite plans with security boundaries, protecting fine-grained row/column policies from imperative UDFs and side channels. Supports secure SQL and MapReduce jobs with negligible performance and cost overhead. (summarized by gpt-5.6-luna on Jul 24 2026)
Incoming Non-self Citations Over Time
Authors
- 1. Andrei Paduroiu (Amazon)
- 2. Sungheun Wi (Amazon)
- 3. Yan Yan (Amazon)
- 4. Roni Burd (Amazon)
- 5. Ruhollah Farchtchi (Amazon)
- 6. Giovanni Matteo Fumarola (Amazon)
BibTeX Citation
@article{paduroiu_vldb24,
title = {{Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code}},
author = {Paduroiu, Andrei and Wi, Sungheun and Yan, Yan and Burd, Roni and Farchtchi, Ruhollah and Fumarola, Giovanni Matteo},
journal = {PVLDB},
series = {{VLDB} '24},
volume = {17},
number = {12},
pages = {3813--3826},
doi = {10.14778/3685800.3685808},
url = {https://doi.org/10.14778/3685800.3685808},
year = {2024}
}
Incoming Citations (Sorted by Pagerank)
Showing 1 of 1 citing papers.
| Rank | Citing Paper | Year | Venue | Pagerank |
|---|---|---|---|---|
| 8,001 | Databricks Lakeguard: Supporting Fine-grained Access Control and Multi-user Capabilities for Apache Spark Workloads | 2025 | SIGMOD | 5.4082868e-05 |
Previous
Page 1 / 1
Next
Outgoing Citations (Sorted by Pagerank)
Showing 9 of 9 cited papers.
Citations counted here include only citations to other VLDB/SIGMOD/CIDR/PODS papers in this database.
| Rank | Cited Paper | Year | Venue | Pagerank |
|---|---|---|---|---|
| 23 | Spark SQL: Relational Data Processing in Spark | 2015 | SIGMOD | 0.00055384955 |
| 272 | An Overview of Query Optimization in Relational Systems | 1998 | PODS | 0.0002251422 |
| 480 | The Making of TPC-DS | 2006 | VLDB | 0.00017615432 |
| 568 | Extending Query Rewriting Techniques for Fine-Grained Access Control | 2004 | SIGMOD | 0.00016254878 |
| 1,961 | Limiting Disclosure in Hippocratic Databases | 2004 | VLDB | 9.3082602e-05 |
| 5,460 | Evolution of a Compiling Query Engine | 2021 | VLDB | 6.1210985e-05 |
| 7,202 | Optimizing Queries over Partitioned Tables in MPP Systems | 2014 | SIGMOD | 5.584637e-05 |
| 9,062 | RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution Time | 2023 | SIGMOD | 5.2278013e-05 |
| 9,063 | Redundancy and Information Leakage in Fine-Grained Access Control | 2006 | SIGMOD | 5.2278013e-05 |
Previous
Page 1 / 1
Next
Semantically Similar Papers
| # | Overall Rank | Paper | Year | Venue |
|---|---|---|---|---|
| 1 | 416 | SystemML: Declarative Machine Learning on Spark | 2016 | VLDB |
| 2 | 3,804 | Evolving Databases for New-Gen Big Data Applications | 2017 | CIDR |
| 3 | 10,129 | End-to-End Declarative Data Analytics: Co-designing Engines, Interfaces, and Cloud Infrastructure | 2026 | CIDR |
| 4 | 6,922 | Petabyte-Scale Row-Level Operations in Data Lakehouses | 2024 | VLDB |
| 5 | 9,330 | Dynamic Speculative Optimizations for SQL Compilation in Apache Spark | 2020 | VLDB |
| 6 | 11,466 | Off-the-shelf Data Analytics on Serverless | 2024 | CIDR |
| 7 | 1,123 | Structured Streaming: A Declarative API for Real-Time Applications in Apache Spark | 2018 | SIGMOD |
| 8 | 10,936 | A Decade of Apache Spark Structured Streaming: How We Evolved The Architecture To Meet Real-World Needs | 2026 | VLDB |
| 9 | 7,221 | Flare: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework | 2023 | VLDB |
| 10 | 8,001 | Databricks Lakeguard: Supporting Fine-grained Access Control and Multi-user Capabilities for Apache Spark Workloads | 2025 | SIGMOD |