IEEE CCGrid 2026
PoliFlow
Inferring Control-Flow Policies
from Serverless Workflows
Pedro Escaleira
escaleira@ua.pt
Vitor A. Cunha
vitorcunha@ua.pt
João P. Barraca
jpbarraca@ua.pt
Diogo Gomes
dgomes@ua.pt
Rui L. Aguiar
ruilaa@ua.pt
IEEE CCGrid 2026
Inferring Control-Flow Policies
from Serverless Workflows
Pedro Escaleira
escaleira@ua.pt
Vitor A. Cunha
vitorcunha@ua.pt
João P. Barraca
jpbarraca@ua.pt
Diogo Gomes
dgomes@ua.pt
Rui L. Aguiar
ruilaa@ua.pt
Core issue
Motivating example
Intended flow
Attack path — bypasses f1 and f2
Related work
| System | Approach | Order-aware? | No profiling? |
|---|---|---|---|
| Valve1 | Network-layer profiling | ✗ | ✗ |
| Kalium2 | Learned path models | ✓ | ✗ |
| PoliFlow | Specification-derived | ✓ | ✓ |
1 P. Datta et al., “Valve: Securing Function Workflows on Serverless Computing Platforms,” The Web Conference 2020 – Proceedings of the World Wide Web Conference, WWW 2020, pp. 939–950, 2020. DOI: 10.1145/3366423.3380173.
2 D. S. Jegan et al., “Guarding Serverless Applications with Kalium,” 32nd USENIX Security Symposium, USENIX Security 2023, vol. 6, pp. 4087–4104, 2023. [Online]. Available: https://www.usenix.org/conference/usenixsecurity23/presentation/jegan.
Key idea
Architecture
Instantiation
Extractor
Extractor
One path per branch
Parallel structure preserved
Parallel marked loop=true
Enforcer
Enforcement — execution examples
Evaluation
Results — overhead
Sidecar image size
Deployment time
Refund workflow (5 functions in sequence)
Refund workflow (5 functions in sequence)
Valve real-estate (12 functions in sequence)
Results — scalability
Sequence of 70 functions — latency overhead per function
70 parallel states (140 functions) — latency overhead per function
PoliFlow turns that intent into enforceable control-flow policies, with no profiling.
Each function validates only its own relevant prefixes. No central coordinator, no SPOF.
Milliseconds per function impact
Looking ahead
Extend PoliFlow to cover serverless functions invoked via direct HTTP calls, beyond orchestrated workflows, enabling full enforcement without an explicit workflow definition
Support for workflow languages beyond SonataFlow / CNCF Serverless Workflow — including AWS Step Functions, Azure Durable Functions, and Argo Workflows
Integration with complementary serverless security mechanisms such as IAM policy generation, anomaly detection, and runtime introspection to form a layered defence
Harden the PoliFlow Enforcer against compromised functions that may attempt to alter or bypass its behaviour at runtime
Thank you
github.com/ATNoG/poliflow