VLDB 2026 Research / reviewers in the wild / expert
Serena Nicolazzo
dblp:135/0904
· DBLP profile ↗
28ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0003-2719-9526ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | How secure is forgetting? Linking machine unlearning to machine learning attacksabstractAs Machine Learning (ML) continues to evolve, so does the sophistication of security threats targeting data privacy and model integrity. In response, Machine Unlearning (MU) has emerged as a promising paradigm that enables the selective removal of data influence from trained models. By supporting compliance with privacy regulations (such as the GDPR’s right to be forgotten) and facilitating model refinement, MU holds significant practical and legal value. Additionally, MU effective deployment introduces new security concerns. In real-world settings, malicious actors may exploit vulnerabilities in MU mechanisms, such as incomplete or inaccurate data removal, to infer deleted information, reintroduce adversarial behavior, or manipulate model updates. These risks highlight the urgency of understanding how classical ML threats relate to the design and operation of MU systems. However, despite its growing relevance, this intersection remains underexplored. In this article, we present a structured analysis of four major attack classes in ML (Backdoor Attacks, Membership Inference Attacks, Adversarial Attacks, and Inversion Attacks) and examine their implications for MU across multiple dimensions: (i) as direct threats targeting MU mechanisms, (ii) as challenges that MU can potentially mitigate, (iii) as evaluation metrics to measure the effectiveness and performance of MU techniques, and (iv) as verification factors to validate the success and completeness of the Unlearning process. We note that not all attacks exhibit all these perspectives simultaneously; their relevance varies depending on the attack characteristics and MU scenario. We also propose a novel classification that reflects how these attacks are typically employed in this context. Finally, we identify open challenges, including ethical considerations, and highlight promising directions for future research to advance secure and privacy-preserving Machine Unlearning. Muhammed Shafi K. P., Serena Nicolazzo, Antonino Nocera, P. Vinod 0001 |
Neurocomputing | 2 |
| 2025 | A Privacy-Preserving and Biometric-Aware Tasks Reallocation Strategy in Industry 5.0abstractIndustry 5.0 represents an emerging industrial paradigm that emphasizes seamless collaboration between human workers, collaborative robots (cobots), and smart objects. Its goal is to enable intelligent, adaptive manufacturing environments that not only boost operational efficiency and ensure regulatory compliance but also enhance workplace safety. In this context, we designed a complete framework based on a Reinforcement Learning (RL) strategy for intelligent and privacy-preserving task reallocation. Central to our vision is the prioritization of human well-being ensuring that both worker safety and privacy are protected, while the performance and reliability of machines and devices are optimized to support a truly human-centric manufacturing system. Our solution monitors workers’ physiological states and detects signs of fatigue, stress, or overload, ensuring that tasks can be dynamically reallocated to another worker or cobot to promote well-being without manual intervention. Moreover, by ensuring biometric data remains local to the worker’s device, the system respects data sovereignty and avoids unnecessary sharing of sensitive health information, guaranteeing compliance with regulations like GDPR. Our solution can adapt dynamically to the changing conditions and needs of human operators creating a privacy-preserving, safe, and efficient collaborative environment between people and machines. A comprehensive experimental analysis assesses the accuracy and performance of the proposed approach. Marco Arazzi, Mert Cihangiroglu, Serena Nicolazzo, Antonino Nocera |
ETFA | 3 |
| 2025 | Securing IoE Environments with Semantic Data Stream Analysis and Behavioral FingerprintingabstractIn the landscape of Industry 5.0, Internet of Everything (IoE) networks are emerging as crucial components for connecting diverse industrial sensors and devices, expanding beyond traditional IoT boundaries to integrate people, processes, and data. However, this increased connectivity raises significant security concerns, as the growing complexity of IoE environments introduces new attack vectors and privacy risks. Additionally, the integration of heterogeneous devices and data sources presents both technical and semantic interoperability challenges, requiring robust mechanisms for meaningful data interpretation and secure exchange. This paper, developed within the HOMEY project, presents an architecture for gathering and monitoring semantic data streams in IoE environments, addressing both interoperability and security challenges. Our approach leverages Knowledge Graphs to represent sensor metadata, locations, access rights, and operational contexts, enabling dynamic stream monitoring and data querying. An approach based on Federated Learning allows distributed behavioral fingerprinting of IoE devices, which is exploited on top of the platform to perform anomaly detection from real-time data streams. The approach enhances reliable, privacy-preserving anomaly detection, contributing to the security and resilience of next-generation industrial IoE ecosystems. Marco Arazzi, Monica Marconi Sciarroni, Serena Nicolazzo, Antonino Nocera, Emanuele Storti |
ETFA | 3 |
| 2025 | Augmented Knowledge Graph Querying leveraging LLMsabstractAdopting Knowledge Graphs (KGs) as a structured, semantic-oriented, data representation model has significantly improved data integration, reasoning, and querying capabilities across different domains. This is especially true in modern scenarios such as Industry 5.0, where the integration of data from humans, smart devices, and production processes is crucial, not only for industrial innovation, but also for supporting the digital transition of government administrations and organizations. However, the management, retrieval, and visualization of data from a KG using formal query languages can be difficult for non-expert users due to their technical complexity, thus limiting their usage inside industrial environments. For this reason, we introduce SparqLLM, a framework that utilizes a Retrieval-Augmented Generation (RAG) solution, to enhance the querying of Knowledge Graphs (KGs). SparqLLM executes the Extract, Transform, and Load (ETL) pipeline to construct KGs from raw data. It also features a natural language interface powered by Large Language Models (LLMs) to enable automatic SPARQL query generation. By integrating template-based methods as retrieved-context for the LLM, SparqLLM enhances query reliability and reduces semantic errors, ensuring more accurate and efficient KG interactions. Moreover, to improve usability, the system incorporates a dynamic visualization dashboard that adapts to the structure of the retrieved data, presenting the query results in an intuitive format. Rigorous experimental evaluations demonstrate that SparqLLM achieves high query accuracy, improved robustness, and user-friendly interaction with KGs, establishing it as a scalable solution to access semantic data. Marco Arazzi, Davide Ligari, Serena Nicolazzo, Antonino Nocera |
IJCNN | 3 |
| 2025 | Secure Federated Dataset DistillationabstractDataset Distillation (DD) is a powerful technique for reducing large datasets into compact, representative synthetic datasets, accelerating Machine Learning training. However, traditional DD methods operate in a centralized manner, which poses significant privacy threats and reduces its applicability. To mitigate these risks, we propose a Secure Federated Data Distillation (SFDD) framework to decentralize the distillation process while preserving privacy. Unlike existing Federated Distillation techniques that focus on training global models with distilled knowledge, our approach aims to produce a distilled dataset without exposing local contributions. We leverage the gradient-matching-based distillation method, adapting it for a distributed setting where clients contribute to the distillation process without sharing raw data. The central aggregator iteratively refines a synthetic dataset by integrating client-side updates while ensuring data confidentiality. To make our approach resilient to inference attacks perpetrated by the server that could exploit gradient updates to reconstruct private data, we create an optimized Local Differential Privacy approach, called LDPO-RLD (Label Differential Privacy Obfuscation via Randomized Linear Dispersion). Furthermore, we assess the framework’s resilience against malicious clients executing backdoor attacks (such as Doorping) and demonstrate robustness under the assumption of a sufficient number of participating clients. Our experimental results demonstrate the effectiveness of SFDD and that the proposed defense concretely mitigates the identified vulnerabilities, with minimal impact on the performance of the distilled dataset. By addressing the interplay between privacy and federation in dataset distillation, this work advances the field of privacy-preserving Machine Learning making our SFDD framework a viable solution for sensitive data-sharing applications. Marco Arazzi, Mert Cihangiroglu, Serena Nicolazzo, Antonino Nocera |
Eng. Appl. Artif. Intell. | 3 |
| 2025 | SeCTIS: A framework to Secure CTI SharingabstractThe rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof. Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, P. Vinod 0001 |
Future Gener. Comput. Syst. | 5 |
| 2025 | A defense mechanism against label inference attacks in Vertical Federated Learning
Marco Arazzi, Serena Nicolazzo, Antonino Nocera |
Neurocomputing | 2 |
| 2025 | DroidTTP: Mapping android applications with TTP for Cyber Threat IntelligenceabstractThe widespread use of Android devices for sensitive operations has made them prime targets for sophisticated cyber threats, including Advanced Persistent Threats (APT). Traditional malware detection methods focus primarily on malware classification, often failing to reveal the Tactics, Techniques, and Procedures (TTPs) used by attackers. To address this issue, we propose DroidTTP, a novel system for mapping Android malware to attack behaviors. We curated a dataset linking Android applications to Tactics and Techniques and developed an automated mapping approach using the Problem Transformation Approach and Large Language Models (LLMs). Our pipeline includes dataset construction, feature selection, data augmentation, model training, and explainability via SHAP. Furthermore, we explored the use of LLMs for TTP prediction using both Retrieval Augmented Generation and fine-tuning strategies. The Label Powerset XGBoost model achieved the best performance, with Jaccard Similarity scores of 0.9893 for Tactic classification and 0.9753 for Technique classification. The fine-tuned LLaMa model also performed competitively, achieving 0.9583 for Tactics and 0.9348 for Techniques. Although XGBoost slightly outperformed LLMs, the narrow performance gap highlights the potential of LLM-based approaches for Tactic and Technique prediction. Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Mauro Conti |
J. Inf. Secur. Appl. | 4 |
| 2024 | Relation Extraction Techniques in Cyber Threat Intelligence
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Mauro Conti |
NLDB (1) | 4 |
| 2024 | Privacy-preserving in Blockchain-based Federated Learning systems
K. M. Sameera, Serena Nicolazzo, Marco Arazzi, Antonino Nocera, Rafidha Rehiman K. A., P. Vinod 0001, Mauro Conti |
Comput. Commun. | 2 |
| 2024 | OSTIS: A novel Organization-Specific Threat Intelligence System
Dincy R. Arikkat, P. Vinod 0001, Rafidha Rehiman K. A., Serena Nicolazzo, Antonino Nocera, Georgiana Timpau, Mauro Conti |
Comput. Secur. | 4 |
| 2024 | A deep reinforcement learning approach for security-aware service acquisition in IoT
Marco Arazzi, Serena Nicolazzo, Antonino Nocera |
J. Inf. Secur. Appl. | 2 |
| 2024 | A novel IoT trust model leveraging fully distributed behavioral fingerprinting and secure delegationabstractThe pervasiveness and high number of Internet of Things (IoT) applications in people’s daily lives make this context a very critical attack surface for cyber threats. The high heterogeneity of involved entities, both in terms of hardware and software characteristics, does not allow the definition of uniform, global, and efficient security solutions. Therefore, researchers have started to investigate novel mechanisms, in which a super node (a gateway, a hub, or a router) analyzes the interactions of the target node with other peers in the network, to detect possible anomalies. The most recent of these strategies base such an analysis on the modeling of the fingerprint of a node behavior in an IoT; nevertheless, existing solutions do not cope with the fully distributed nature of the referring scenario. In this paper, we try to provide a contribution in this setting, by designing a novel and fully distributed trust model exploiting point-to-point devices’ behavioral fingerprints, a distributed consensus mechanism, and Blockchain technology. In our solution we tackle the non-trivial issue of equipping smart things with a secure mechanism to evaluate, also through their neighbors, the trustworthiness of an object in the network before interacting with it. Beyond the detailed description of our framework, we also illustrate the security model associated with it and the tests carried out to evaluate its correctness and performance. Marco Arazzi, Serena Nicolazzo, Antonino Nocera |
Pervasive Mob. Comput. | 2 |
| 2023 | The importance of the language for the evolution of online communities: An analysis based on Twitter and Reddit
Marco Arazzi, Serena Nicolazzo, Antonino Nocera, Manuel Zippo |
Expert Syst. Appl. | 2 |
| 2022 | A two-tier Blockchain framework to increase protection and autonomy of smart objects in the IoT
Enrico Corradini, Serena Nicolazzo, Antonino Nocera, Domenico Ursino, Luca Virgili |
Comput. Commun. | 2 |
| 2020 | A privacy-preserving approach to prevent feature disclosure in an IoT scenario
Serena Nicolazzo, Antonino Nocera, Domenico Ursino, Luca Virgili |
Future Gener. Comput. Syst. | 1 |
| 2020 | A Privacy-Preserving Localization Service for Assisted Living FacilitiesabstractIn this paper, we propose a novel localization service to monitor the position of residents in assisted living facilities. The service supports a configurable balancing between precision and privacy, in such a way that the right of the residents to move freely in the environment in which they live without being tracked is preserved. However, in case of need, they can always be quickly localized. To do this, we implement, on top of an RFID-based architecture, a probabilistic model guaranteeing that the probability of identifying a person in a given (sensitive) place is at most k-1, where k represents the required privacy level. This is obtained by ensuring that the EPC sent by RFID tags is not an identifier, but is equal to that of at least other k - 1 people, each afferent to a different reader. We show that our method reaches the goal, resisting also attacks aimed at breaking privacy on the basis of humans' movement models. Importantly, privacy is guaranteed against both misuse of the administrator and client-side eavesdropping attacks. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
IEEE Trans. Serv. Comput. | 3 |
| 2018 | Is the Sharing Economy About Sharing at All? A Linguistic Analysis of Airbnb Reviews
Giovanni Quattrone, Serena Nicolazzo, Antonino Nocera, Daniele Quercia, Licia Capra |
ICWSM | 2 |
| 2017 | Overcoming Limits of Blockchain for IoT ApplicationsabstractBlockchain technology allows the implementation of a public ledger securely recording transactions among peers without the need of trusted third parties. For both researchers and industry IoT appears a domain in which there would be extraordinary benefits if the features of Blockchain can be exploited. Indeed, the possibility that IoT devices participate in public shared transactions enables a lot of challenging applications. However, there are some aspects that may limit the use of Blockchain in IoT. These are mainly related to the low computational power and storage capabilities of IoT devices. In this paper, we propose an alternative way to implement a public ledger overcoming the above drawbacks, thus appearing more suitable to IoT applications. The proposed protocol leverages the popular social network Twitter and works by building a meshed chain of tweets to ensure transaction security. Importantly, Twitter does not play neither the role of trusted third party nor the role of ledger provider. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 3 |
| 2017 | Contrasting False Identities in Social Networks by Trust Chains and Biometric ReinforcementabstractFake identities and identity theft are issues whose relevance is increasing in the social network domain. This paper deals with this problem by proposing an innovative approach which combines a collaborative mechanism implementing a trust graph with keystroke-dynamic-recognition techniques to trust identities. The trust of each node is computed on the basis of neighborhood recognition and behavioral biometric support. The model leverages the word of mouth propagation and a settable degree of redundancy to obtain robustness. Experimental results show the benefit of the proposed solution even if attack nodes are present in the social network. Francesco Buccafurri, Gianluca Lax, Denis Migdal, Serena Nicolazzo, Antonino Nocera, Christophe Rosenberger |
CW | 4 |
| 2017 | Tweetchain: An Alternative to Blockchain for Crowd-Based Applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ICWE | 3 |
| 2016 | Range Query Integrity in Cloud Data Streams with Efficient Insertion
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
CANS | 3 |
| 2016 | A New Approach for Electronic SignatureabstractThere are many application contexts in which guaranteeing authenticity and integrity of documents is essential.In these cases, the typical solution relies on digital signature, which is based on the use of a PKI infrastructure and suitable devices (smart card or token USB).For several reasons, including certificate and device cost, many countries, such as the United States, the European Union, India, Brazil and Australia, have introduced the possibility to use simple generic electronic signature, which is less secure but reduces the drawbacks of digital signature.In this paper, we propose a new type of electronic signature that is based on the use of social networks.We formalize the proposal in a generic scenario and then, show a possible implementation on Twitter.Our proposal is proved to be secure, cheap and simple to adopt. Gianluca Lax, Francesco Buccafurri, Serena Nicolazzo, Antonino Nocera, Lidia Fotia |
ICISSP | 3 |
| 2016 | Interest Assortativity in TwitterabstractAssortativity is the preference for a person to relate to others who are someway similar.This property has been widely studied in real-life social networks in the past and, more recently, great attention is devoted to study various forms of assortativity also in online social networks, being aware that it does not suffice to apply past scientific results obtained in the domain of real-life social networks.One of the aspects not yet analyzed in online social networks is interest assortativity, that is the preference for people to share the same interest (e.g., sport, music) with their friends.In this paper, we study this form of assortativity on Twitter, one of the most popular online social networks.After the introduction of the background theoretical model, we analyze Twitter, discovering that users clearly show interest assortativity.Beside the theoretical assessment, our result leads to identify a number of interesting possible applications. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
WEBIST (1) | 3 |
| 2016 | A model to support design and development of multiple-social-network applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
Inf. Sci. | 3 |
| 2015 | A Model Implementing Certified Reputation and Its Application to TripAdvisorabstractMany real-life reputation models suffer from classical drawbacks making the systems where they are used vulnerable to users' misbehavior. TripAdvisor is a good example of this problem. Indeed, despite its popularity, the weakness of its reputation model is resulting in loss of credibility and growth of legal disputes. In this paper, we propose a reputation model abstractly considering service providers, users and feedbacks, and implementing the theoretical notion of certified reputation to concretely define a strategy to normalize feedback scores towards reliable values. We apply the model to the case of TripAdvisor, by proposing a solution to improve its dependability not increasing invasiveness nor reducing usability of the system. Moreover, it fully guarantees backward compatibility. In the context of project activities, we are in progress to fully implement the system and validate it on real-life data. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 3 |
| 2015 | Accountability-Preserving Anonymous Delivery of Cloud Services
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
TrustBus | 3 |
| 2014 | Driving Global Team Formation in Social Networks to Obtain Diversity
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera, Domenico Ursino |
ICWE | 3 |