VLDB 2026 Research / reviewers in the wild / expert
Davide Maiorca
dblp:116/5225
· DBLP profile ↗
24ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0003-2640-4663ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 4 first-author · 11 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Analysis of Modern Web Security Vulnerabilities Inside WebAssembly Applications
Lorenzo Corrias, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ICISSP (1) | 3 |
| 2026 | Race against time: investigating the factors that influence web race condition exploitsabstractRace conditions (RC) pose a critical security threat to web applications by exploiting the non-deterministic behavior of multithreaded request handling. This can lead to unpredictable outcomes such as data corruption, Time of Check to Time of Use (TOCTOU) vulnerabilities, and deadlocks. While previous research has identified poor design practices that contribute to RC vulnerabilities, no existing studies have explored the factors that influence the severity or impact of race conditions. This paper introduces a comprehensive methodology for testing and quantifying how different variables affect the exploitability of race conditions in vulnerable web servers, providing a framework for future research to investigate this issue more thoroughly. In addition, we present an experimental evaluation of our methodology under various conditions. Specifically, we examine six RC exploitation tools using four different attack techniques across both HTTP/1.1 and HTTP/2 protocols. To provide a complete overview of race conditions across all HTTP versions, we also introduce the first race condition attack tool for HTTP/3, named QUICker. Furthermore, we assess how the choice of database management systems and programming languages used in web application deployment can affect susceptibility to race condition attacks. This study offers key insights into how these factors influence the exploitability of RC vulnerabilities. Federico Loi, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Giorgio Giacinto |
Comput. Secur. | 4 |
| 2026 | Statistical effort modelling of game resource localisation attacksabstractEvidence on the effectiveness of ManMachine-At-The-End (MATE) software protections, such as code obfuscation, has mainly come from limited empirical research. Recently, however, a meta-model and an automatable method waswere proposed to obtain statistical models of the required effort to attack (protected) software. The proposed method was sketched for a number of attack strategies but not instantiated, evaluated, or validated for those that require human interaction with the attacked software. In this paper, we present an fullend-to-end instantiation, formalisation, implementation, and validation of thethat existing meta-model and method to obtain statistical effort models for game resource localisation attacks, which represent a major step towards creating game cheats, a prime example of MATE attacks. We discuss in detail all relevant aspects of our instantiation and the results obtained for two game use cases. Our results confirm the feasibility of the proposedexisting meta-model and method, and itstheir utility for decision support for users of software protection tools. These results open up a new avenue for obtaining models of the impact of software protections on reverse engineering attacks, which will scale much better than empirical research involving human participants. Alessandro Sanna, Waldo Verstraete, Leonardo Regano, Davide Maiorca, Bjorn De Sutter |
Comput. Secur. | 4 |
| 2026 | An Assessment of the Overlooked Dangers of Template EnginesabstractTemplate engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development. Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ACM Trans. Web | 2 |
| 2025 | Evaluation of Resource-Aware HTTP/3 Proxies for Smuggling Resilience in IoT EnvironmentsabstractThe growing integration of IoT devices into Edge and Fog infrastructures, alongside the increasing adoption of low-latency QUIC-based protocols like HTTP/3, has intensified the need for lightweight, resource-efficient security mechanisms to counter emerging threats such as request smuggling. Within this context, proxy-based architectures offer an optimal trade-off to strengthen network security while accommodating the limited computational capacity of IoT devices. In this direction, this paper presents a comprehensive experimental evaluation of the impact of different proxies for HTTP/3 services on resource usage when deployed on platforms such as the Raspberry Pi (RPi), considering diverse traffic patterns, operational conditions, and device configurations. The results highlight that proxies can achieve a promising balance between security and resource overhead, confirming their viability for integration into distributed IoT-based Edge and Fog networks. Lorenzo Pisu, Giovanni Pettorru, Leonardo Regano, Davide Maiorca, Giorgio Giacinto, Marco Martalò |
GLOBECOM | 4 |
| 2025 | {{alert('CSTI')}}: Large-Scale Detection of Client-Side Template InjectionabstractTemplate engines are software components that enable the creation of reusable HTML elements containing special keywords that can dynamically alter the page’s rendering based on the presented data. This technology is widely used in server-side applications and frameworks, and in recent years, it has also gained adoption on the client side through JavaScript frameworks and libraries. Client-Side Template Injection (CSTI) is a vulnerability that occurs when user input is reflected inside a template and rendered as part of it, allowing attackers to inject malicious instructions. This can trick the template engine into executing arbitrary JavaScript code, potentially leading to Cross-Site Scripting (XSS). Despite the widespread adoption of template engines in production websites, a comprehensive study of their characteristics remains absent. In our study, we begin by providing an overview of the main features of template engines, highlighting attributes that play a crucial role in escalating CSTI to XSS. We then use these extracted characteristics to develop a systematic methodology for detecting CSTI vulnerabilities. Based on this methodology, we create an automatic CSTI detection tool, CSTI-Alert. By running CSTI-Alert on the Tranco top 1 million domains, we identify 532 CSTI-vulnerable domains, with 72% directly leading to XSS through GET parameters or CSRF. Finally, we discuss potential approaches to defend against CSTI based on the result of semi-automatic exploitability analysis. Lorenzo Pisu, Davide Balzarotti, Davide Maiorca, Giorgio Giacinto |
RAID | 3 |
| 2025 | DroidReach++: Exploring the reachability of native code in android applications
Luca Borzacchiello, Matteo Cornacchia, Davide Maiorca, Giorgio Giacinto, Emilio Coppa |
Comput. Secur. | 3 |
| 2024 | HTTP/3 will not Save you from Request Smuggling: A Methodology to Detect HTTP/3 Header (mis)ValidationsabstractHTTP/3 will be the new de-facto standard for communication in web applications. Despite its increasing integration into modern browsers, its security properties have not yet been fully investigated. A significant problem is represented by request smuggling attacks, which may constitute a critical issue concerning web applications’ security and privacy, leading to critical consequences such as cache poisoning, session hijacking, and Denial Of Service (DOS). This category of attacks is particularly interesting as it involves abusing the characteristics of the HTTP protocol to manipulate and craft malicious requests that the server will misinterpret, creating desynchronizations between the frontend and the backend. In this paper, we present the first taxonomy of request smuggling attacks in HTTP/3. Specifically, we focus on conversion and validation issues observed in HTTP/2 that can persist in HTTP/3 environments. Since these attacks depend on how proxies parse incoming requests, we also present a methodology to discover possible header validation issues that can cause request smuggling in proxies and frameworks. Finally, we apply this methodology to four proxies and a Python framework, finding various incoherences in their ways to parse malformed requests. Our work aims to underscore the importance of vigilance in current and future applications utilizing HTTP/3 protocols to mitigate potential security risks. Despite the limited availability of libraries and frameworks supporting HTTP/3 at the present moment, its rapid adoption calls for consideration and analysis of its security. Lorenzo Pisu, Federico Loi, Davide Maiorca, Giorgio Giacinto |
NCA | 3 |
| 2024 | Do You Trust Your Device? Open Challenges in IoT Security AnalysisabstractSeveral critical contexts, such as healthcare, smart cities, drones, transportation, and agriculture, nowadays rely on IoT, or more in general embedded, devices that require comprehensive security analysis to ensure their integrity before deployment. Security concerns are often related to vulnerabilities that result from inadequate coding or undocumented features that may create significant privacy issues for users and companies. Current analysis methods, albeit dependent on complex tools, may lead to superficial assessments due to compatibility issues, while authoritative entities struggle with specifying feasible firmware analysis requests for manufacturers within operational contexts. This paper urges the scientific community to collaborate with stakeholders—manufacturers, vendors, security analysts, and experts—to forge a cooperative model that clarifies manufacturer contributions and aligns analysis demands with operational constraints. Aiming at a modular approach, this paper highlights the crucial need to refine security analysis, ensuring more precise requirements, balanced expectations, and stronger partnerships between vendors and analysts. To achieve this, we propose a threat model based on the feasible interactions of actors involved in the security evaluation of a device, with a particular emphasis on the responsibilities and necessities of all entities involved. Lorenzo Binosi, Pietro Mazzini, Alessandro Sanna, Michele Carminati, Giorgio Giacinto, Riccardo Lazzeretti, Stefano Zanero, Mario Polino, Emilio Coppa, Davide Maiorca |
SECRYPT | 10 |
| 2024 | Bringing Binary Exploitation at Port 80: Understanding C Vulnerabilities in WebAssemblyabstractWebAssembly (Wasm) has emerged as a novel approach for integrating binaries into web applications starting from various programming languages such as C, Rust and Python. Despite the numerous claims about its memory safety, issues such as buffer overflow, format strings, use after free, and integer overflow have resurfaced within Wasm. These vulnerabilities can be used to impact web application security, potentially leading to critical issues like Cross-Site Scripting (XSS) and Remote Code Execution (RCE). Our work aims to demonstrate how memory-related vulnerabilities in C codes, when compiled into Wasm, can be exploited for XSS and RCE. Our methodology proposes proof of concepts related to exploiting important stack- and heap-based vulnerabilities. In particular, we demonstrate for the first time that specific vulnerabilities (such as format string) can be effectively employed to achieve arbitrary read and write in Wasm contexts. Our results pose serious concerns about the reliability of Wasm in terms of memory safety, which we believe should be addressed in the next releases. Emmanuele Massidda, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
SECRYPT | 3 |
| 2024 | Enhancing android malware detection explainability through function call graph APIsabstractNowadays, mobile devices are massively used in everyday activities. Thus, they contain sensitive data targeted by threat actors like bank accounts and personal information. Through the years, Machine Learning approaches have been proposed to identify malicious Android applications, but recent research highlights the need for better explanations for model decisions, as existing ones may not be related to the app’s malicious functionalities. This paper proposes an explainable approach based on static analysis to detect Android malware. The novelty lies in the specific analysis conducted to select and extract the features (i.e., APIs taken from the DEX Call Graph) that immediately provide meaningful explanations of the model functionality, thus allowing a significant correlation of the malware behavior with its family. Moreover, since we contain the number and type of features, the distinct impacts of each one appear more evident. The attained results show that it is possible to reach comparable results (in terms of accuracy) to existing state-of-the-art models while providing easy-to-understand explanations, which may yield significant insights into the malicious functionalities of the samples. Diego Soi, Alessandro Sanna, Davide Maiorca, Giorgio Giacinto |
J. Inf. Secur. Appl. | 3 |
| 2022 | Extended Abstract: Effective Call Graph Fingerprinting for the Analysis and Classification of Windows Malware
Francesco Meloni, Alessandro Sanna, Davide Maiorca, Giorgio Giacinto |
DIMVA | 3 |
| 2022 | Reach Me if You Can: On Native Vulnerability Reachability in Android Apps
Luca Borzacchiello, Emilio Coppa, Davide Maiorca, Andrea Columbu, Camil Demetrescu, Giorgio Giacinto |
ESORICS (3) | 3 |
| 2022 | A Longitudinal Study of Cryptographic API: A Decade of Android MalwareabstractCryptography has been extensively used in Android applications to guarantee secure communications, conceal critical data from reverse engineering, or ensure mobile users' privacy. Various system-based and third-party libraries for Android provide cryptographic functionalities, and previous works mainly explored the misuse of cryptographic API in benign applications. However, the role of cryptographic API has not yet been explored in Android malware. This paper performs a comprehensive, longitudinal analysis of cryptographic API in Android malware. In particular, we analyzed 603 937 Android applications (half of them malicious, half benign) released between 2012 and 2020, gathering more than 1 million cryptographic API expressions. Our results reveal intriguing trends and insights on how and why cryptography is employed in Android malware. For instance, we point out the widespread use of weak hash functions and the late transition from insecure DES to AES. Additionally, we show that cryptography-related characteristics can help to improve the performance of learning-based systems in detecting malicious applications. Adam Janovsky, Davide Maiorca, Dominik Macko, Vashek Matyas, Giorgio Giacinto |
SECRYPT | 2 |
| 2020 | Adversarial Detection of Flash Malware: Limitations and Open Issues
Davide Maiorca, Ambra Demontis, Battista Biggio, Fabio Roli, Giorgio Giacinto |
Comput. Secur. | 1 |
| 2019 | PowerDrive: Accurate De-obfuscation and Analysis of PowerShell Malware
Denis Ugarte, Davide Maiorca, Fabrizio Cara, Giorgio Giacinto |
DIMVA | 2 |
| 2019 | On the effectiveness of system API-related information for Android ransomware detection
Michele Scalas, Davide Maiorca, Francesco Mercaldo, Corrado Aaron Visaggio, Fabio Martinelli, Giorgio Giacinto |
Comput. Secur. | 2 |
| 2019 | Yes, Machine Learning Can Be More Secure! A Case Study on Android Malware DetectionabstractTo cope with the increasing variability and sophistication of modern attacks, machine learning has been widely adopted as a statistically-sound tool for malware detection. However, its security against well-crafted attacks has not only been recently questioned, but it has been shown that machine learning exhibits inherent vulnerabilities that can be exploited to evade detection at test time. In other words, machine learning itself can be the weakest link in a security system. In this paper, we rely upon a previously-proposed attack framework to categorize potential attack scenarios against learning-based malware detection tools, by modeling attackers with different skills and capabilities. We then define and implement a set of corresponding evasion attacks to thoroughly assess the security of Drebin, an Android malware detector. The main contribution of this work is the proposal of a simple and scalable secure-learning paradigm that mitigates the impact of evasion attacks, while only slightly worsening the detection rate in the absence of attack. We finally argue that our secure-learning approach can also be readily applied to other malware detection tasks. Ambra Demontis, Marco Melis, Battista Biggio, Davide Maiorca, Daniel Arp, Konrad Rieck, Igino Corona, Giorgio Giacinto, Fabio Roli |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2016 | Evaluating Analysis Tools for Android Apps: Status Quo and Robustness Against ObfuscationabstractThe recent past has shown that Android smartphones became the most popular target for malware authors. Malware families offer a variety of features that allow, among the others, to steal arbitrary data and to cause significant monetary losses. This circumstances led to the development of many different analysis methods that are aimed to assess the absence of potential harm or malicious behavior in mobile apps. In return, malware authors devised more sophisticated methods to write mobile malware that attempt to thwart such analyses. In this work, we briefly describe assumptions analysis tools rely on to detect malicious content and behavior. We then present results of a new obfuscation framework that aims to break such assumptions, thus modifying Android apps to avoid them being analyzed by the targeted systems. We use our framework to evaluate the robustness of static and dynamic analysis systems for Android apps against such transformations. Teemu Rytilahti, Davide Maiorca, Marcel Winandy, Giorgio Giacinto, Thorsten Holz |
CODASPY | 3 |
| 2015 | On the Robustness of Mobile Device Fingerprinting: Can Mobile Users Escape Modern Web-Tracking Mechanisms?abstractClient fingerprinting techniques enhance classical cookie-based user tracking to increase the robustness of tracking techniques. A unique identifier is created based on characteristic attributes of the client device, and then used for deployment of personalized advertisements or similar use cases. Whereas fingerprinting performs well for highly customized devices (especially desktop computers), these methods often lack in precision for highly standardized devices like mobile phones. Thomas Hupperich, Davide Maiorca, Marc Kührer, Thorsten Holz, Giorgio Giacinto |
ACSAC | 2 |
| 2015 | A Structural and Content-based Approach for a Precise and Robust Detection of Malicious PDF FilesabstractDuring the past years, malicious PDF files have become a serious threat for the security of modern computer systems. They are characterized by a complex structure and their variety is considerably high. Several solutions have been academically developed to mitigate such attacks. However, they leveraged on information that were extracted from either only the structure or the content of the PDF file. This creates problems when trying to detect non-Javascript or targeted attacks. In this paper, we present a novel machine learning system for the automatic detection of malicious PDF documents. It extracts information from both the structure and the content of the PDF file, and it features an advanced parsing mechanism. In this way, it is possible to detect a wide variety of attacks, including non-Javascript and parsing-based ones. Moreover, with a careful choice of the learning algorithm, our approach provides a significantly higher accuracy compared to other static analysis techniques, especially in the presence of adversarial malware manipulation. Davide Maiorca, Davide Ariu, Igino Corona, Giorgio Giacinto |
ICISSP | 1 |
| 2015 | Stealth attacks: An extended insight into the obfuscation effects on Android malware
Davide Maiorca, Davide Ariu, Igino Corona, Marco Aresu, Giorgio Giacinto |
Comput. Secur. | 1 |
| 2013 | Looking at the bag is not enough to find the bomb: an evasion of structural methods for malicious PDF files detectionabstractPDF files have proved to be excellent malicious-code bearing vectors. Thanks to their flexible logical structure, an attack can be hidden in several ways, and easily deceive protection mechanisms based on file-type filtering. Recent work showed that malicious PDF files can be accurately detected by analyzing their logical structure, with excellent results. In this paper, we present and practically demonstrate a novel evasion technique, called reverse mimicry, that can easily defeat such kind of analysis. We implement it using real samples and validate our approach by testing it against various PDF malware detectors proposed so far. Finally, we highlight the importance of developing systems robust to adversarial attacks and propose a framework to strengthen PDF malware detection against evasion. Davide Maiorca, Igino Corona, Giorgio Giacinto |
AsiaCCS | 1 |
| 2013 | Evasion Attacks against Machine Learning at Test Time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, Fabio Roli |
ECML/PKDD (3) | 3 |