VLDB 2026 Research / reviewers in the wild / expert
Giorgia Azzurra Marson
dblp:123/8740
· DBLP profile ↗
14ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0001-5264-7285ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Lightweight Secure Aggregation Protocol for Federated Learning ApplicationsabstractFederated learning (FL) enables a server and a set of users to jointly train a model without the need to disclose training data. To guarantee strong privacy for users, FL must be combined with a secure aggregation (SA) protocol ensuring that individual gradients remain confidential. Pioneering SA protocols for FL applications exhibit a per-user overhead that grows logarithmically with the number of users and require multiple rounds of communication.In this paper we present LISA, a lightweight SA protocol that leverages public randomness to reduce both per-user overhead and the number of rounds needed. LISA requires only two rounds of interaction for most users, offering a communication overhead asymptotically equivalent to that of a non-private protocol where the server obtains user inputs in the clear. More concretely, LISA uses public randomness to select a small committee of users tasked with aiding the server in the aggregation process. Users blind their individual inputs with random masks shared with each committee member, and after sending their blinded input to the server they can go offline. Committee members provide the server with an aggregation of the shared masks over all users, so that the server can remove all masks and obtain the aggregated input. Hence, as long as one committee member is honest, the server can only obtain the aggregation of threshold-many inputs without learning any individual input. We compare LISA with existing SA protocols through both theoretical analysis and simulations. We further integrate LISA in an FL pipeline and compare its accuracy and time to converge with those of a non-private FL application. Elina van Kempen, Giorgia Azzurra Marson, Claudio Soriente |
ICDCS | 3 |
| 2024 | Closing the Gap: Achieving Better Accuracy-Robustness Tradeoffs against Query-Based AttacksabstractAlthough promising, existing defenses against query-based attacks share a common limitation: they offer increased robustness against attacks at the price of a considerable accuracy drop on clean samples. In this work, we show how to efficiently establish, at test-time, a solid tradeoff between robustness and accuracy when mitigating query-based attacks. Given that these attacks necessarily explore low-confidence regions, our insight is that activating dedicated defenses, such as random noise defense and random image transformations, only for low-confidence inputs is sufficient to prevent them. Our approach is independent of training and supported by theory. We verify the effectiveness of our approach for various existing defenses by conducting extensive experiments on CIFAR-10, CIFAR-100, and ImageNet. Our results confirm that our proposal can indeed enhance these defenses by providing better tradeoffs between robustness and accuracy when compared to state-of-the-art approaches while being completely training-free. Pascal Zimmer, Sébastien Andreina, Giorgia Azzurra Marson, Ghassan Karame |
AAAI | 3 |
| 2024 | Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better SecurityabstractExtensive research on Nakamoto-style consensus protocols has shown that network delays degrade the security of these protocols. Established results indicate that, perhaps surprisingly, maximal security is achieved when the network is as small as two nodes due to increased delays in larger networks. This contradicts the very foundation of blockchains, namely that decentralization improves security.In this paper, we take a closer look at how the network scale affects security of Nakamoto-style blockchains. We argue that a crucial aspect has been neglected in existing security models: the larger the network, the harder it is for an attacker to control a significant amount of power. To this end, we introduce a probabilistic corruption model to express the increasing difficulty for an attacker to corrupt resources in larger networks. Based on our model, we analyze the impact of the number of nodes on the (maximum) network delay and the fraction of adversarial power. In particular, we show that (1) increasing the number of nodes eventually violates security, but (2) relying on a small number of nodes does not provide decent security provisions either. We then validate our analysis by means of an empirical evaluation emulating hundreds of thousands of nodes in deployments such as Bitcoin, Monero, Cardano, and Ethereum Classic. Based on our empirical analysis, we concretely analyze the impact of various real-world parameters and configurations on the consistency bounds in existing deployments and on the adversarial power that can be tolerated while providing security. As far as we are aware, this is the first work that analytically and empirically explores the real-world tradeoffs achieved by current popular Nakamoto-style deployments. Jannik Albrecht, Sébastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Azzurra Marson, Julian Willingmann |
SP | 5 |
| 2023 | Short Paper: Estimating Patch Propagation Times Across Blockchain Forks
Sébastien Andreina, Lorenzo Alluminio, Giorgia Azzurra Marson, Ghassan Karame |
FC | 3 |
| 2022 | PoTS: A Secure Proof of TEE-Stake for Permissionless BlockchainsabstractProof of Stake (PoS) blockchain protocols emerged as a promising alternative to the largely energy-wasteful proof of work mechanisms currently in place. In contrast to computing power, however, “stake” is a virtual resource that can be replicated or reused, opening the door to attack vectors that have no counterpart in a PoW setting, and are much harder to defeat. We present PoTS (Proof of TEE-Stake), a novel PoS protocol that leverages properties of trusted execution environments (TEEs) to limit the attack surface of malicious validators, and employs techniques such as forward security to guarantee protection against posterior-corruption attacks. We show that PoTS is secure against nothing at stake, grinding, and long range attacks down to realistic hardware assumptions on TEE and well-established cryptographic assumptions, and retains reasonable security even in face of compromised TEEs. We evaluate the performance of our proposal by means of implementation. Our evaluation results demonstrate that PoTS offers an excellent trade-off between security and performance. Sébastien Andreina, Jens-Matthias Bohli, Ghassan Karame, Wenting Li 0001, Giorgia Azzurra Marson |
IEEE Trans. Serv. Comput. | 5 |
| 2021 | Mitosis: Practically Scaling Permissioned BlockchainsabstractScalability remains one of the biggest challenges to the adoption of permissioned blockchain technologies for large-scale deployments. Namely, permissioned blockchains typically exhibit low latencies, compared to permissionless deployments—however at the cost of poor scalability. As a remedy, various solutions were proposed to capture “the best of both worlds”, targeting low latency and high scalability simultaneously. Among these, blockchain sharding emerges as the most prominent technique. Most existing sharding proposals exploit features of the permissionless model and are therefore restricted to cryptocurrency applications. A few permissioned sharding proposals exist, however, they either make strong trust assumptions on the number of faulty nodes or rely on trusted hardware or assume a static participation model where all nodes are expected to be available all the time. In practice, nodes may join and leave the system dynamically, which makes it challenging to establish how to shard and when. Giorgia Azzurra Marson, Sébastien Andreina, Lorenzo Alluminio, Konstantin Munichev, Ghassan Karame |
ACSAC | 1 |
| 2021 | On the Synchronization Power of Token Smart ContractsabstractModern blockchains support a variety of distributed applications beyond cryptocurrencies, including smart contracts, which let users execute arbitrary code in a distributed and decentralized fashion. Regardless of their intended application, blockchain platforms implicitly assume consensus for the correct execution of a smart contract, thus requiring that all transactions are totally ordered. It was only recently recognized that consensus is not necessary to prevent double-spending in a cryptocurrency, contrary to common belief. This result suggests that current implementations may be sacrificing efficiency and scalability because they synchronize transactions much more tightly than actually needed. In this work, we study the synchronization requirements of Ethereum's ERC20 token contract, one of the most widely adopted smart contacts. Namely, we model a smart-contract token as a concurrent object and analyze its consensus number as a measure of synchronization power. We show that the richer set of methods supported by ERC20 tokens, compared to standard cryptocurrencies, results in strictly stronger synchronization requirements. More surprisingly, the synchronization power of ERC20 tokens depends on the object's state and can thus be modified by method invocations. To prove this result, we develop a dedicated framework to express how the object's state affects the needed synchronization level. Our findings indicate that ERC20 tokens, as well as other token standards, are more powerful and versatile than plain cryptocurrencies, and are subject to dynamic requirements. Developing specific synchronization protocols that exploit these dynamic requirements will pave the way towards more robust and scalable blockchain platforms. Orestis Alpos, Christian Cachin, Giorgia Azzurra Marson, Luca Zanolini |
ICDCS | 3 |
| 2021 | BaFFLe: Backdoor Detection via Feedback-based Federated LearningabstractRecent studies have shown that federated learning (FL) is vulnerable to poisoning attacks that inject a backdoor into the global model. These attacks are effective even when performed by a single client, and undetectable by most existing defensive techniques. In this paper, we propose Backdoor detection via Feedback-based Federated Learning (BAFFLE), a novel defense to secure FL against backdoor attacks. The core idea behind BAFFLE is to leverage data of multiple clients not only for training but also for uncovering model poisoning. We exploit the availability of diverse datasets at the various clients by incorporating a feedback loop into the FL process, to integrate the views of those clients when deciding whether a given model update is genuine or not. We show that this powerful construct can achieve very high detection rates against state-of-the-art backdoor attacks, even when relying on straightforward methods to validate the model. Through empirical evaluation using the CIFAR-10 and FEMNIST datasets, we show that by combining the feedback loop with a method that suspects poisoning attempts by assessing the per-class classification performance of the updated model, BAFFLE reliably detects state-of-the-art backdoor attacks with a detection accuracy of 100% and a false-positive rate below 5%. Moreover, we show that our solution can detect adaptive attacks aimed at bypassing the defense. Sébastien Andreina, Giorgia Azzurra Marson, Helen Möllering, Ghassan Karame |
ICDCS | 2 |
| 2020 | On the Security of Randomized Defenses Against Adversarial SamplesabstractDeep Learning has been shown to be particularly vulnerable to adversarial samples. To combat adversarial strategies, numerous defensive techniques have been proposed. Among these, a promising approach is to use randomness in order to make the classification process unpredictable and presumably harder for the adversary to control. In this paper, we study the effectiveness of randomized defenses against adversarial samples. To this end, we categorize existing state-of-the-art adversarial strategies into three attacker models of increasing strength, namely blackbox, graybox, and whitebox (a.k.a. adaptive) attackers. We also devise a lightweight randomization strategy for image classification based on feature squeezing, that consists of pre-processing the classifier input by embedding randomness within each feature, before applying feature squeezing. We evaluate the proposed defense and compare it to other randomized techniques in the literature via thorough experiments. Our results indeed show that careful integration of randomness can be effective against both graybox and blackbox attacks without significantly degrading the accuracy of the underlying classifier. However, our experimental results offer strong evidence that in the present form such randomization techniques cannot deter a whitebox adversary that has access to all classifier parameters and has full knowledge of the defense. Our work thoroughly and empirically analyzes the impact of randomization techniques against all classes of adversarial strategies. Kumar Sharad, Giorgia Azzurra Marson, Hien Thi Thu Truong, Ghassan Karame |
AsiaCCS | 2 |
| 2018 | A Cryptographic Look at Multi-party ChannelsabstractCryptographic channels aim to enable authenticated and confidential communication over the Internet. The general understanding seems to be that providing security in the sense of authenticated encryption for every (unidirectional) point-to-point link suffices to achieve this goal. As recently shown (in FSE17/ToSC17), however, the security properties of the unidirectional links do not extend, in general, to the bidirectional channel as a whole. Intuitively, the reason for this is that the increased interaction in bidirectional communication can be exploited by an adversary. The same applies, a fortiori, in a multi-party setting where several users operate concurrently and the communication develops in more directions. In the cryptographic literature, however, the targeted goals for group communication in terms of channel security are still unexplored. Applying the methodology of provable security, we fill this gap by defining exact (game-based) authenticity and confidentiality goals for broadcast communication, and showing how to achieve them. Importantly, our security notions also account for the causal dependencies between exchanged messages, thus naturally extending the bidirectional case where causal relationships are automatically captured by preserving the sending order. On the constructive side we propose a modular and yet efficient protocol that, assuming only point-to-point links between users, leverages (non-cryptographic) broadcast and standard cryptographic primitives to a full-fledged broadcast channel that provably meets the security notions we put forth. Patrick Eugster, Giorgia Azzurra Marson, Bertram Poettering |
CSF | 2 |
| 2015 | Data Is a Stream: Security of Stream-Based Channels
Marc Fischlin, Felix Günther 0001, Giorgia Azzurra Marson, Kenneth G. Paterson |
CRYPTO (2) | 3 |
| 2014 | Even More Practical Secure Logging: Tree-Based Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering |
ESORICS (2) | 1 |
| 2013 | A Cryptographic Analysis of OPACITY - (Extended Abstract)
Özgür Dagdelen, Marc Fischlin, Tommaso Gagliardoni, Giorgia Azzurra Marson, Arno Mittelbach, Cristina Onete |
ESORICS | 4 |
| 2013 | Practical Secure Logging: Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering |
ESORICS | 1 |