VLDB 2026 Research / reviewers in the wild / expert
Stefano Braghin
dblp:07/4982
· DBLP profile ↗
23ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0001-5519-1674ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 6 · 2 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Security and privacy · 4 · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BRAT: An Intent-to-Kubernetes Translation via LLM Fine-Tuning
Antonino Angi, Liubov Nedoshivina, Alessio Sacco, Stefano Braghin, Mark Purcell |
HPSR | 4 |
| 2026 | INTELLECT: From federated training to resource-aware cyber threat detection
Simone Magnani, Liubov Nedoshivina, Roberto Doriguzzi Corin, Stefano Braghin, Domenico Siracusa |
Comput. Networks | 4 |
| 2025 | Verifiability and Privacy in Federated Learning through Context-Hiding Multi-Key Homomorphic AuthenticatorsabstractFederated Learning has rapidly expanded from its original inception to now have a large body of research, several frameworks, and sold in a variety of commercial offerings. Thus, its security and robustness is of significant importance. There are many algorithms that provide robustness in the case of malicious clients. However, the aggregator itself may behave maliciously, for example, by biasing the model or tampering with the weights to weaken the model’s privacy. In this work, we introduce a verifiable federated learning protocol that enables clients to verify the correctness of the aggregator’s computation without compromising the confidentiality of their updates. Our protocol uses a standard secure aggregation technique to protect individual model updates with a linearly homomorphic authenticator scheme that enables efficient, privacy-preserving verification of the aggregated result. Our construction ensures that clients can detect manipulation by the aggregator while maintaining low computational overhead. We demonstrate that our approach scales to large models, enabling verification over large neural networks with millions of parameters. Simone Bottoni, Giulio Zizzo, Stefano Braghin, Alberto Trombetta |
BDCAT | 3 |
| 2024 | Securing Floating-Point Arithmetic for Noise AdditionabstractFloating-point arithmetic is ubiquitous across computing, with its wide range of values, large and small, making it the preferred tool for storing, analysing, and manipulating numerical data. Its flexibility comes at the cost of additional risks in some security/privacy-aware settings. In this paper, we discuss the threat of information leakage caused by floating-point arithmetic when adding noise to sensitive values, which can allow the sensitive information to be recovered (e.g., in differential privacy). We present a solution, Mantissa Bit Manipulation (MBM), that is orders of magnitude faster than the current state-of-the-art, applicable to most continuous probability distributions and to all floating-point number formats. Naoise Holohan, Stefano Braghin, Mohamed Suliman 0002 |
CCS | 2 |
| 2024 | Building the Cloud Continuum with REARabstractThe computing continuum combines computational resources and services from edge to cloud, promising enhanced efficiency and resilience with respect to the traditional siloed-based approach. This study presents the REAR (Resource Advertisement and Reservation) protocol, which tackles the complexities of managing resources within this continuum. REAR establishes standardized interfaces to enable interoperability, enhances resource allocation efficiency, and maintains security measures for workload execution. The paper details the protocol’s design, key components, operational workflows, and potential uses, contributing to the optimization of resource use across the computing continuum. Stefano Galantino, Elisa Albanese, Nasir Asadov, Stefano Braghin, Francesco Cappa, Andrea Colli-Vignarelli, Amjad Yousef Majid, Eduard Marin, Jacopo Marino, Lorenzo Moro, Liubov Nedoshivina, Fulvio Risso, Domenico Siracusa, Antonio F. Skarmeta, Luca Zuanazzi |
NetSoft | 4 |
| 2024 | Online Learning and Model Pruning Against Concept Drifts in Edge DevicesabstractThe proliferation of Internet of Things sensors has driven the adoption of the edge computing paradigm, which prioritizes processing the data close to the source to minimize data transfer to cloud servers, reduce latency, and enhance privacy and robustness. However, edge computing environments present limited computational power, storage capacity, and a non-negligible risk of cyber-attacks.This paper tackles the challenges of deploying Intrusion and/or Anomaly Detection Systems (I/ADSs) at the network’s edge, particularly for environments with evolving network attack patterns (concept drift). To this aim, we propose a methodology that leverages both Neural Network (NN) pruning and online learning. We empirically evaluate the proposed methodology under attack scenarios with concept drift in network traffic, where adaptation to new data trends is crucial. We also demonstrate that NN pruning leads to more energy-efficient and lightweight I/ADSs, which can be adopted also in devices with strict resource requirements. Simone Magnani, Seshu Tirupathi, Roberto Doriguzzi Corin, Liubov Nedoshivina, Stefano Braghin, Domenico Siracusa |
NetSoft | 5 |
| 2023 | Pruning Federated Learning Models for Anomaly Detection in Resource-Constrained EnvironmentsabstractThe evolving complexity of modern IT infrastructures has paved the way for malicious actors to exploit a wide array of vulnerabilities that can compromise the integrity of these systems. Monitoring complex IT systems is expensive and often requires dedicated infrastructure for deploying Intrusion and/or Anomaly Detection Systems. Moreover, ML-based solutions need large training sets, which add to the overall cost. To tackle these challenges we present INTELLECT, a novel approach to Intrusion and/or Anomaly Detection System, which leverages Federated Learning and model pruning techniques to cooperatively train high-accuracy models using distributed datasets and derive a fleet of lightweight models, which can be deployed without incurring additional costs for dedicated infrastructure. INTELLECT expands on the state-of-the-art techniques for feature selection, model pruning, and model distillation to create an interconnected pipeline. We empirically demonstrate the effectiveness of the methodology on benchmark datasets, and we present guidelines for the deployment in production systems. Simone Magnani, Stefano Braghin, Ambrish Rawat, Roberto Doriguzzi Corin, Mark Purcell, Domenico Siracusa |
IEEE Big Data | 2 |
| 2022 | Adaptive Replication Strategy in Highly Distributed Data Management SystemsabstractThe performance of the execution of an analytical workload critically impacts the speed at which companies are able to react to market changes. In the era of Big Data, it is imperative that large, complex analytics are executed in a timely manner. In this paper, we propose a method to analyze the data access pattern of analytical workloads on large datasets to identify optimal data partitioning and replication strategies. This, in turn, helps the already existing query optimization components of modern data management systems. Simone Bottoni, Stefano Braghin, Alberto Trombetta, Srikumar Venugopal |
IC2E | 2 |
| 2021 | Secure k-Anonymization over Encrypted DatabasesabstractData protection algorithms are becoming increasingly important to support modern business needs for facilitating data sharing and data monetization. Anonymization is an important step before data sharing. Several organizations leverage on third parties for storing and managing data. However, third parties are often not trusted to store plaintext personal and sensitive data; data encryption is widely adopted to protect against intentional and unintentional attempts to read personal/sensitive data. Traditional encryption schemes do not support operations over the ciphertexts and thus anonymizing encrypted datasets is not feasible with current approaches. This paper explores the feasibility and depth of implementing a privacy-preserving data publishing workflow over encrypted datasets leveraging on homomorphic encryption. We demonstrate how we can achieve uniqueness discovery, data masking, differential privacy and k-anonymity over encrypted data requiring zero knowledge about the original values. We prove that the security protocols followed by our approach provide strong guarantees against inference attacks. Finally, we experimentally demonstrate the performance of our data publishing workflow components. Manish Kesarwani, Akshar Kaul, Stefano Braghin, Naoise Holohan, Spiros Antonatos |
CLOUD | 3 |
| 2021 | Secure Random Sampling in Differential Privacy
Naoise Holohan, Stefano Braghin |
ESORICS (2) | 2 |
| 2019 | Computing Multi-Modal Journey Plans under UncertaintyabstractMulti-modal journey planning, which allows multiple types of transport within a single trip, is becoming increasingly popular, due to a strong practical interest and an increasing availability of data. In real life, transport networks feature uncertainty. Yet, most approaches assume a deterministic environment, making plans more prone to failures such as missed connections and major delays in the arrival. This paper presents an approach to computing optimal contingent plans in multi-modal journey planning. The problem is modeled as a search in an and/or state space. We describe search enhancements used on top of the AO* algorithm. Enhancements include admissible heuristics, multiple types of pruning that preserve the completeness and the optimality, and a hybrid search approach with a deterministic and a nondeterministic search. We demonstrate an NP-hardness result, with the hardness stemming from the dynamically changing distributions of the travel time random variables. We perform a detailed empirical analysis on realistic transport networks from cities such as Montpellier, Rome and Dublin. The results demonstrate the effectiveness of our algorithmic contributions, and the benefits of contingent plans as compared to standard sequential plans, when the arrival and departure times of buses are characterized by uncertainty. Adi Botea, Akihiro Kishimoto, Evdokia Nikolova, Stefano Braghin, Michele Berlingerio, Elizabeth Daly |
J. Artif. Intell. Res. | 4 |
| 2018 | PRIMA: An End-to-End Framework for Privacy at ScaleabstractPerson-specific data offer enormous opportunities for deriving insights that can radically improve different facets of our everyday lives, ranging from the provisioning of personalized medicine and healthcare, to the offering of smart transportation and smart energy. At the same time, the use of person-specific data to support these applications can come at a high cost to individuals' privacy, unless proper de-identification technology is in place to provide rigorous privacy guarantees. In this paper we introduce PRIMA, an end-to-end solution allowing decision makers to map out and execute their data privacy strategy through a comprehensive workflow. Our toolkit offers an intuitive risk-utility exploration framework for end users to navigate through the enormous number of possible combinations of anonymization settings and provide meaningful reports that help them understand the impact of each strategy in terms of utility and risk. Unlike traditional approaches, that rely on limited scale tools and manual analyses, our toolkit is the first scalable, production-grade system that can execute all of its components (such as vulnerability analysis, anonymization, risk and information loss measurements) on arbitrarily large datasets. Furthermore, it offers a flexible library for developers to integrate and extend its functionality to embed de-identification components into their applications. Spiros Antonatos, Stefano Braghin, Naoise Holohan, Yiannis Gkoufas, Pol Mac Aonghusa |
ICDE | 2 |
| 2015 | Mobility Mining for Journey Planning in Rome
Michele Berlingerio, Veli Bicer, Adi Botea, Stefano Braghin, Nuno Lopes 0002, Riccardo Guidotti, Francesca Pratesi |
ECML/PKDD (3) | 4 |
| 2015 | S&P360: Multidimensional Perspective on Companies from Online Data Sources
Michele Berlingerio, Stefano Braghin, Francesco Calabrese, Cody Dunne, Yiannis Gkoufas, Mauro Martino, Jamie C. Rasmussen, Steven I. Ross |
ECML/PKDD (3) | 2 |
| 2014 | The zen of multidisciplinary team recommendationabstractIt is often necessary to compose a team consisting of experts with diverse competencies to accomplish complex tasks. However, for its proper functioning, it is also preferable that a team be socially cohesive. A team recommendation system, which facilitates the search for potential team members, can be of great help both for (a) individuals who need to seek out collaborators and for (b) managers who need to build a team for some specific tasks. Such a decision support system that readily helps summarize multiple metrics indicating a team (and its members) quality, and possibly rank the teams in a personalized manner according to the end users' preferences, thus serves as a tool to cope with what would otherwise be an information avalanche. In this work, we present Social Web Application for Team Recommendation, a general‐purpose framework to compose various information retrieval and social graph mining and visualization subsystems together to build a composite team recommendation system, and instantiate it for a case study of academic teams. Anwitaman Datta, Jackson Tan Teck Yong, Stefano Braghin |
J. Assoc. Inf. Sci. Technol. | 3 |
| 2014 | Mosco: a privacy-aware middleware for mobile social computing
Tien Tuan Anh Dinh, Milind Ganjoo, Stefano Braghin, Anwitaman Datta |
J. Syst. Softw. | 3 |
| 2013 | A Framework for Trust-Based Multidisciplinary Team Recommendation
Lorenzo Bossi, Stefano Braghin, Anwitaman Datta, Alberto Trombetta |
UMAP | 2 |
| 2013 | Distributed access control policies for spectrum sharingabstractABSTRACT Cognitive radio is a novel wireless communication technology that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. Cognitive radio technology can be used in innovative spectrum management approaches such as spectrum sharing, where radio frequency spectral bands can be shared among various users through a dynamic exclusive‐use spectrum access model. Spectrum sharing can be applied to various scenarios in the commercial, public safety and military domain. In some scenarios, spectrum sharing demands a mechanism for expressing and enforcing access control policies for the allocation of resources including spectral bands. The access control polices should state what are the available resources (e.g., transmission/reception bandwidths), what are the users that are allowed to access them and under what conditions. However, because of the intrinsically highly dynamic nature of specific scenarios (e.g., public safety, military), where parties with various levels of authority may suddenly appear, it may be difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well‐known approach for expressing and enforcing distributed access control policies that depend on two or more parties. In this work, we present a trust negotiation‐based framework that allows for the definition of highly expressive and flexible distributed access control policies for the allocation of spectrum resources. Copyright © 2012 John Wiley & Sons, Ltd. Gianmarco Baldini, Igor Nai Fovino, Stefano Braghin, Alberto Trombetta |
Secur. Commun. Networks | 3 |
| 2012 | SWAT: Social Web Application for Team RecommendationabstractTeam recommendation aids decision support, by not only identifying individuals who are experts for various aspects of a complex task, but also determining various properties of the team as a group. Several aspects such as cohesion and repetition of teams have been identified as important indicators, besides individuals' expertise, in determining how well a team performs. While such information often do not exist explicitly, digital footprint of users' activities can be harnessed to retrieve the same from diverse sources. In this work, we lay out a proof-of-concept on how to do so in the case of scientific knowledge workers, as well as demonstrate some necessary visualization, manipulation and communication tools to determine and manage multi-disciplinary teams. While the focus of our presentation is the specific application 'SWAT' for team recommendation, it also serves as a vehicle demonstrating how, in general, apparently disparate data sources can be harnessed to provide decision support guided by suitable analytics. Stefano Braghin, Jackson Tan Teck Yong, Anthony Ventresque, Anwitaman Datta |
ICPADS | 1 |
| 2012 | A Flexible Approach to Multisession Trust NegotiationsabstractTrust Negotiation has shown to be a successful, policy-driven approach for automated trust establishment, through the release of digital credentials. Current real applications require new flexible approaches to trust negotiations, especially in light of the widespread use of mobile devices. In this paper, we present a multisession dependable approach to trust negotiations. The proposed framework supports voluntary and unpredicted interruptions, enabling the negotiating parties to complete the negotiation despite temporary unavailability of resources. Our protocols address issues related to validity, temporary loss of data, and extended unavailability of one of the two negotiators. A peer is able to suspend an ongoing negotiation and resume it with another (authenticated) peer. Negotiation portions and intermediate states can be safely and privately passed among peers, to guarantee the stability needed to continue suspended negotiations. We present a detailed analysis showing that our protocols have several key properties, including validity, correctness, and minimality. Also, we show how our negotiation protocol can withstand the most significant attacks. As by our complexity analysis, the introduction of the suspension and recovery procedures, and mobile negotiations does not significantly increase the complexity of ordinary negotiations. Our protocols require a constant number of messages whose size linearly depend on the portion of trust negotiation that has been carried before the suspensions. Anna Cinzia Squicciarini, Elisa Bertino, Alberto Trombetta, Stefano Braghin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2010 | Adaptive and Distributed Access Control in Cognitive Radio NetworksabstractCognitive Radio (CR) is a novel wireless technology communication that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. CR techniques may be applied to the resolution of emergency crisis to improve the spectrum utilization and the resilience of the wireless networks used by public safety organizations. Typically, such scenarios demand a mechanism for expressing and enforcing access control policies: that is, for stating what are the available resources (e.g. transmission/reception bandwidths), what are the parties that are allowed to access them and under what conditions. However, due to the intrinsically highly dynamic nature of such settings - in which unknown parties may suddenly appear and force a change in the configuration of other parties - it is extremely difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well-known approach for expressing and enforcing distributed access control policies which depend on two or more (initially mutually untrusting) parties. Such policies are determined on the fly by all the involved parties and do not require a centralized authority. In this work we present a trust negotiation-based framework which allows for the definition of highly expressive and flexible distributed access control policies and their efficient enforcement in cognitive radio networks. Gianmarco Baldini, Stefano Braghin, Igor Nai Fovino, Alberto Trombetta |
AINA | 2 |
| 2010 | Combining access control and trust negotiations in an On-line Social NetworkabstractProtection of On-line Social Networks (OSNs) resources has become a primary need since today OSNs are the hugest repository of personal information on the Web. This has resulted in the definition of some access control models tailored to the protection of OSN resources. One of the key parameter on w Stefano Braghin, Elena Ferrari 0001, Alberto Trombetta |
CollaborateCom | 1 |
| 2010 | Group-Based Negotiations in P2P SystemsabstractIn P2P systems, groups are typically formed to share resources and/or to carry on joint tasks. In distributed environments formed by a large number of peers conventional authentication techniques are inadequate for the group joining process, and more advanced ones are needed. Complex transactions among peers may require more elaborate interactions based on what peers can do or possess instead of peers' identity. In this work, we propose a novel peer group joining protocol. We introduce a highly expressive resource negotiation language, able to support the specification of a large variety of conditions applying to single peers or groups of peers. Moreover, we define protocols to test such resource availability customized to the level of assurance required by the peers. Our approach has been tested and evaluated on an extension of the JXTA P2P platform. Our results show the robustness of our approach in detecting malicious peers, detected both during the negotiation and during the peer group lifetime. Regardless of the peer group cardinality and interaction frequency, the peers always detect possible free riders within a small time frame. Anna Cinzia Squicciarini, Federica Paci, Elisa Bertino, Alberto Trombetta, Stefano Braghin |
IEEE Trans. Parallel Distributed Syst. | 5 |