VLDB 2026 Research / reviewers in the wild / expert
Luca Piras 0003
dblp:00/7629-3
· DBLP profile ↗
20ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-7530-4119ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Novel Approach to SBOM Extraction from HTTP Messages in Identity Management Security Testing
Andrea Bisegna, Laura Cristiano, Pietro De Matteis, Eleonora Marchesini, Luca Piras 0003, Silvio Ranise |
DBSec | 5 |
| 2026 | Sentiment-Driven Stock Price Prediction: Analysing Green Finance News Using Large Language Models for Tesla
Amir Lorvand, Halil Yetgin, Serengul Smith, Duaa Alkubaisy, Luca Piras 0003 |
ICAART (3) | 5 |
| 2025 | A Risk Assessment of Information Security in a Diet Centre Business: A Case Study
Tasneem Annahdi, Duaa Alkubaisy, Luca Piras 0003 |
ENASE | 3 |
| 2025 | Enhancing Privacy, Censorship Resistance, and User Engagement in a Blockchain-Based Social Network
Myo Thiha, Halil Yetgin, Luca Piras 0003, Mohammed Al-Obeidallah |
ENASE | 3 |
| 2024 | Gamification of E-Learning Apps via Acceptance Requirements Analysis
Federico Calabrese, Luca Piras 0003, Mohammed Al-Obeidallah, Benedicta Oghenevoke Egbikuadje, Duaa Alkubaisy |
ENASE | 2 |
| 2024 | Model-Based Gamification Design with Web-Agon: An Automated Analysis Tool for GamificationabstractDesigning effective gamified solutions is a difficult and highly complex task. Supporting tools for requirements analyst are very rare, while most existing tools provide automation for reasoning over complex knowledge models. Drawing from our involvement in EU Projects and extensive analyst feedback, this paper presents crucial lessons learned on automating gamification analysis and design. We employed these lessons to guide the development of Web-Agon, a web-based solution that automates reasoning over models to support the analyst. Web-Agon, based on the Acceptance/Gamification Requirements Agon Framework, facilitates systematic gamification analysis of software systems. This approach, driven by acceptance (psychological, sociologi-cal, behavioral) requirements, has proven effective in designing systems that positively engage users. Based on models and gamification principles, Web-Agon contributes to building user-centered, engaging software systems. We have evaluated the effectiveness of our tool through a case study on Participatory Architectural Change Management in Air Traffic Management (ATM) systems with the use of Web-Agon for system gamification. We obtained positive results in terms of supporting analyst in a structured, systematic and automated way, reducing potential errors, thanks to automated functionalities, as well as speeding up the gamification process. Hein Khant Zaw, Luca Piras 0003, Federico Calabrese, Mohammed Al-Obeidallah |
SEAA | 2 |
| 2024 | Defendroid: Real-time Android code vulnerability detection via blockchain federated neural network with XAIabstractEnsuring strict adherence to security during the phases of Android app development is essential, primarily due to the prevalent issue of apps being released without adequate security measures in place. While a few automated tools are employed to reduce potential vulnerabilities during development, their effectiveness in detecting vulnerabilities may fall short. To address this, “Defendroid”, a blockchain-based federated neural network enhanced with Explainable Artificial Intelligence (XAI) is introduced in this work. Trained on the LVDAndro dataset, the vanilla neural network model achieves a 96% accuracy and 0.96 F1-Score in binary classification for vulnerability detection. Additionally, in multi-class classification, the model accurately identifies Common Weakness Enumeration (CWE) categories with a 93% accuracy and 0.91 F1-Score. In a move to foster collaboration and model improvement, the model has been deployed within a blockchain-based federated environment. This environment enables community-driven collaborative training and enhancements in partnership with other clients. The extended model demonstrates improved accuracy of 96% and F1-Score of 0.96 in both binary and multi-class classifications. The use of XAI plays a pivotal role in presenting vulnerability detection results to developers, offering prediction probabilities for each word within the code. This model has been integrated into an Application Programming Interface (API) as the backend and further incorporated into Android Studio as a plugin, facilitating real-time vulnerability detection. Notably, Defendroid exhibits high efficiency, delivering prediction probabilities for a single code line in an average processing time of a mere 300 ms. The weight-sharing transparency in the blockchain-driven federated model enhances trust and traceability, fostering community engagement while preserving source code privacy and contributing to accuracy improvement. Janaka Senanayake, Harsha K. Kalutarage, Andrei Petrovski 0001, Luca Piras 0003, M. Omar Al-Kadri |
J. Inf. Secur. Appl. | 4 |
| 2023 | Android Code Vulnerabilities Early Detection Using AI-Powered ACVED Plugin
Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Andrei Petrovski 0001, Luca Piras 0003 |
DBSec | 5 |
| 2023 | Goal-Modeling Privacy-by-Design Patterns for Supporting GDPR Compliance
Mohammed Al-Obeidallah, Luca Piras 0003, Onyinye Iloanugo, Haralambos Mouratidis, Duaa Alkubaisy, Daniele Dellagiacoma |
ICSOFT | 2 |
| 2023 | Labelled Vulnerability Dataset on Android Source Code (LVDAndro) to Develop AI-Based Code Vulnerability Detection ModelsabstractEnsuring the security of Android applications is a vital and intricate aspect requiring careful consideration during development. Unfortunately, many apps are published without sufficient security measures, possibly due to a lack of early vulnerability identification. One possible solution is to employ machine learning models trained on a labelled dataset, but currently, available datasets are suboptimal. This study creates a sequence of datasets of Android source code vulnerabilities, named LVDAndro, labelled based on Common Weakness Enumeration (CWE). Three datasets were generated through app scanning by altering the number of apps and their sources. The LVDAndro, includes over 2,000,000 unique code samples, obtained by scanning over 15,000 apps. The AutoML technique was then applied to each dataset, as a proof of concept to evaluate the applicability of LVDAndro, in detecting vulnerable source code using machine learning. The AutoML model, trained on the dataset, achieved accuracy of 94% and F1-Score of 0.94 in binary classification, and accuracy of 94% and F1-Score of 0.93 in CWE-based multi-class classification. The LVDAndro dataset is publicly available, and continues to expand as more apps are scanned and added to the dataset regularly. The LVDAndro GitHub Repository also includes the source code for dataset generation, and model training. Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Luca Piras 0003, Andrei Petrovski 0001 |
SECRYPT | 4 |
| 2022 | Developing Secured Android Applications by Mitigating Code Vulnerabilities with Machine LearningabstractMobile application developers sometimes might not be serious about source code security and publish apps to the marketplaces. Therefore, it is essential to have a fully automated security solutions generator to integrate security-by-design into the development practices, especially for the Android platform. This research proposes a Machine Learning (ML) based highly accurate method to detect Android source code vulnerabilities. A new labelled dataset containing Android source code vulnerability samples was generated initially. The dataset was used to train binary and multi-class classification based ML models, to identify code issues by following a static analysis approach. The proposed model can detect code vulnerabilities with a 0.90 F1-Score and vulnerability categories (CWE) with a 0.96 F1-Score. By integrating this with the Android development environment, app developers can analyse source code and identify security vulnerabilities in real-time. The proposed framework can be extended to suggest suitable patches to overcome the source code issues by providing real-time fixes in future. Janaka Senanayake, Harsha K. Kalutarage, M. Omar Al-Kadri, Andrei Petrovski 0001, Luca Piras 0003 |
AsiaCCS | 5 |
| 2021 | ConfIs: A Tool for Privacy and Security Analysis and Conflict Resolution for Supporting GDPR Compliance through Privacy-by-DesignabstractPrivacy and security requirements, and their potential conflicts, are increasingly having more and more importance. It is becoming a necessary part to be considered, starting from the very early stages of requirements engineering, and in the entire software engineering cycle, for the design of any software system. In the last few years, this has been even more emphasized and required by the law. A relevant example is the case of the General Data Protection Regulation (GDPR), which requires organizations, and their software engineers, to enforce and guarantee privacy-by-design to make their platforms compliant with the regulation. In this context, complex activities related to privacy and security requirements elicitation, analysis, mapping and identification of potential conflicts, and the individuation of their resolution, become crucial. In the literature, there is not available a comprehensive requirement engineering oriented tool for supporting the requirements analyst. In this paper, we propose ConfIs, a tool for supporting the analyst in performing a process covering these phases in a systematic and interactive way. We present ConfIs and its process with a realistic example from DEFeND, an EU project aiming at supporting organizations in achieving GDPR compliance. In this context, we evaluated ConfIs by involving privacy/security requirements experts, which recognized our tool and method as supportive, concerning these complex activities. Duaa Alkubaisy, Luca Piras 0003, Mohammed Al-Obeidallah, Karl Cox, Haralambos Mouratidis |
ENASE | 2 |
| 2020 | DEFeND DSM: A Data Scope Management Service for Model-Based Privacy by Design GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Michalis Pavlidis, Haralambos Mouratidis, Aggeliki Tsohou, Emmanouil Magkos, Andrea Praitano, Annarita Iodice, Beatriz Gallego-Nicasio |
TrustBus | 1 |
| 2020 | Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platformabstractPurpose General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings The findings provide the process for the DEFeND platform requirements’ elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value This is the first paper, according to the best of the authors’ knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives. Aggeliki Tsohou, Emmanouil Magkos, Haralambos Mouratidis, George Chrysoloras, Luca Piras 0003, Michalis Pavlidis, Julien Debussche, Marco Rotoloni, Beatriz Gallego-Nicasio |
Inf. Comput. Secur. | 5 |
| 2019 | Design Thinking and Acceptance Requirements for Designing Gamified SoftwareabstractGamification is increasingly applied to engage people in performing tool-supported collaborative tasks. From previous experiences we learned that available gamification guidelines are not sufficient, and more importantly that motivational and acceptance aspects need to be considered when designing gamified software applications. To understand them, stakeholders need to be involved in the design process. This paper aims to (i) identify key requirements for designing gamified solutions, and (ii) understand if existing methods (partially fitting those requirements) can be selected and combined to provide a comprehensive gamification design method. We discuss a set of key requirements for a suitable gamification design method. We illustrate how to select and combine existing methods to define a design approach that fits those requirements usingDesign Thinking and the Agon framework. Furthermore, we present a first empirical evaluation of the integrated design method, with participants including both requirements analysts and end-users of the gamified software. Our evaluation offers initial ideas towards a more general, systematic approach for gamification design. Luca Piras 0003, Daniele Dellagiacoma, Anna Perini, Angelo Susi, Paolo Giorgini, John Mylopoulos |
RCIS | 1 |
| 2019 | DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Andrea Praitano, Aggeliki Tsohou, Haralambos Mouratidis, Beatriz Gallego-Nicasio, Jean Baptiste Bernard, Marco Fiorani, Emmanouil Magkos, Andrès Castillo Sanz, Michalis Pavlidis, Roberto D'Addario, Giuseppe Giovanni Zorzino |
TrustBus | 1 |
| 2019 | Goal-oriented requirements engineering: an extended systematic mapping studyabstractOver the last two decades, much attention has been paid to the area of goal-oriented requirements engineering (GORE), where goals are used as a useful conceptualization to elicit, model, and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within requirements engineering (RE) and beyond, such as agent orientation, aspect orientation, business intelligence, model-driven development, and security. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. In this work, we present a systematic mapping study, covering the 246 top-cited GORE-related conference and journal papers, according to Scopus. Our literature map addresses several research questions: we classify the types of papers (e.g., proposals, formalizations, meta-studies), look at the presence of evaluation, the topics covered (e.g., security, agents, scenarios), frameworks used, venues, citations, author networks, and overall publication numbers. For most questions, we evaluate trends over time. Our findings show a proliferation of papers with new ideas and few citations, with a small number of authors and papers dominating citations; however, there is a slight rise in papers which build upon past work (implementations, integrations, and extensions). We see a rise in papers concerning adaptation/variability/evolution and a slight rise in case studies. Overall, interest in GORE has increased. We use our analysis results to make recommendations concerning future GORE research and make our data publicly available. Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, Luca Piras 0003, John Mylopoulos, Paolo Giorgini |
Requir. Eng. | 8 |
| 2017 | Goal Models for Acceptance Requirements Analysis and Gamification Design
Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos |
ER | 1 |
| 2017 | Gamification solutions for software acceptance: A comparative study of Requirements Engineering and Organizational Behavior techniquesabstractGamification is a powerful paradigm and a set of best practices used to motivate people carrying out a variety of ICT-mediated tasks. Designing gamification solutions and applying them to a given ICT system is a complex and expensive process (in time, competences and money) as software engineers have to cope with heterogeneous stakeholder requirements on one hand, and Acceptance Requirements on the other, that together ensure effective user participation and a high level of system utilization. As such, gamification solutions require significant analysis and design as well as suitable supporting tools and techniques. In this work, we compare concepts, tools and techniques for gamification design drawn from Software Engineering and Human and Organizational Behaviors. We conduct a comparison by applying both techniques to the specific Meeting Scheduling exemplar used extensively in the Requirements Engineering literature. Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos, Roberta Cuel, Diego Ponte |
RCIS | 1 |
| 2016 | Acceptance Requirements and Their Gamification SolutionsabstractWe live in the days of social software where social interactions, from simple notifications to complex business processes, are supported by software platforms such as Facebook and Twitter. But for any social software to be successful, it must be used by a sizeable portion of its intended user community. Usage requirements are usually referred to as Acceptance Requirements and they have been studied in the literature both for general technology as well as software. Operationalization techniques for such requirements often consist of making a game out of software usage where users are rewarded/penalized depending onthe degree of their participation. The game may be competitive or non-competitive, depending on the anticipated personality traits of intended users. Making a game out of usage is often referred to as Gamification, and gamification has attracted huge attention in the literature for the past few years because it offers a novelapproach to software technology usage. This paper proposes a generic framework for designing gamified solutions for acceptance requirements. The framework consists of a generic acceptance goal model that characterizes the problem space by capturing possible refinements for acceptance requirements, and a generic gamification model that capturespossible gamified operationalizations of acceptance requirements. These models have been extracted from the literature and they are highly dependent on context (cognitive and social) elements of the intended user community. The proposed framework isillustrated with the Meeting Scheduler exemplar. Luca Piras 0003, Paolo Giorgini, John Mylopoulos |
RE | 1 |