VLDB 2026 Research / reviewers in the wild / expert
Fran Casino
dblp:139/4352 · also Francisco Jose Casino Cembellin
· DBLP profile ↗
16ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0003-4296-2876ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The ECEAAS Project: Supporting Healthy, Autonomous and Active Ageing through Cognitive Environments
Edgar Batista 0001, Fran Casino, Agusti Solanas, Antoni Martínez-Ballesté |
COMPSAC | 2 |
| 2026 | Analysing Multidisciplinary Approaches to Fight Large-Scale Digital Influence Operations
David Arroyo, Rafael Mata Milla, Marc Almeida Ros, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Fran Casino |
ICISSP (1) | 7 |
| 2025 | Beyond the sandbox: Leveraging symbolic execution for evasive malware classificationabstractThreat actors continuously update their code to incorporate counter-analysis techniques designed to evade detection and hinder the blocking of their malware. The first line of defence for malware authors is often to bypass static analysis, a relatively straightforward task using readily available tools such as packers and cryptors. To address this shortcoming, defenders send potential malware samples for execution in a sandbox environment. While sandboxing can provide valuable insights into the behaviour of software on an information system, advanced techniques like anti-virtualisation and hooking evasion allow malware to escape detection. The primary objective of this work is to complement sandbox execution with symbolic execution frameworks to detect new malware strains efficiently. Symbolic execution offers a distinct advantage over sandboxing by achieving greater coverage of all possible execution traces, as it can explore every potential execution path, regardless of the evasion methods employed by the malware authors. By carefully selecting the samples to be analysed, we can significantly reduce the workload while extracting essential dynamic features in a fraction of the time and with far fewer computational resources compared to sandboxing. To this end, we leverage machine learning in an automated pipeline, enabling the accurate detection of sophisticated malware using a real-world dataset. Our approach yields average F1 scores of 0.93 for the benign class and 0.99 for the malware class in a binary classification setup, surpassing the detection rates reported in the literature. Additionally, our method outperforms a commercial malware sandbox when applied to the same dataset, further highlighting the efficacy of the proposed method. Vasilis Vouvoutsis, Fran Casino, Constantinos Patsakis |
Comput. Secur. | 2 |
| 2024 | Outside the Comfort Zone: Analysing LLM Capabilities in Software Vulnerability Detection
Yuejun Guo 0001, Constantinos Patsakis, Qiang Tang 0001, Fran Casino |
ESORICS (1) | 5 |
| 2024 | Assessing LLMs in malicious code deobfuscation of real-world malware campaignsabstractThe integration of large language models (LLMs) into various cybersecurity pipelines has become increasingly prevalent, enabling the automation of numerous manual tasks and often surpassing human performance. Recognising this potential, cybersecurity researchers and practitioners are actively investigating the application of LLMs to process vast volumes of heterogeneous data for anomaly detection, potential bypass identification, attack mitigation, and fraud prevention. Moreover, LLMs’ advanced capabilities in generating functional code, interpreting code context, and code summarisation present significant opportunities for reverse engineering and malware deobfuscation. In this work, we comprehensively examine the deobfuscation capabilities of state-of-the-art LLMs. Specifically, we conducted a detailed evaluation of four prominent LLMs using real-world malicious scripts from the notorious Emotet malware campaign. Our findings reveal that while current LLMs are not yet perfectly accurate, they demonstrate substantial potential in efficiently deobfuscating payloads. This study highlights the importance of fine-tuning LLMs for specialised tasks, suggesting that such optimisation could pave the way for future AI-powered threat intelligence pipelines to combat obfuscated malware. Our contributions include a thorough analysis of LLM performance in malware deobfuscation, identifying strengths and limitations, and discussing the potential for integrating LLMs into cybersecurity frameworks for enhanced threat detection and mitigation. Our experiments illustrate that LLMs can automatically and accurately extract the necessary indicators of compromise from a real-world campaign with an accuracy of 69.56% and 88.78% for the URLs and the corresponding domains of the droppers, respectively. Constantinos Patsakis, Fran Casino, Nikolaos Lykousas |
Expert Syst. Appl. | 2 |
| 2023 | A compression strategy for an efficient TSP-based microaggregationabstractThe advent of decentralised systems and the continuous collection of personal data managed by public and private entities require the application of measures to guarantee the privacy of individuals. Due to the necessity to preserve both the privacy and the utility of such data, different techniques have been proposed in the literature. Microaggregation, a family of data perturbation methods, relies on the principle of k-anonymity to aggregate personal data records. While several microaggregation heuristics exist, those based on the Travelling Salesman Problem (TSP) have been shown to outperform the state of the art when considering the trade-off between privacy protection and data utility. However, TSP-based heuristics suffer from scalability issues. Intuitively, methods that may reduce the computational time of TSP-based heuristics may incur a higher information loss. Nevertheless, in this article, we propose a method that improves the performance of TSP-based heuristics and can be used in both small and large datasets effectively. Moreover, instead of focusing only on the computational time perspective, our method can preserve and sometimes reduce the information loss resulting from the microaggregation. Extensive experiments with different benchmarks show how our method is able to outperform the current state of the art, considering the trade-off between information loss and computational time. Armando Maya López, Antoni Martínez-Ballesté, Fran Casino |
Expert Syst. Appl. | 3 |
| 2022 | Invoice #31415 attached: Automated analysis of malicious Microsoft Office documentsabstractMicrosoft Office may be by far the most widely used suite for processing documents, spreadsheets, and presentations. Due to its popularity, it is continuously utilised to carry out malicious campaigns. Threat actors, exploiting the platform’s dynamic features, use it to launch their attacks and penetrate millions of hosts in their campaigns. This work explores the modern landscape of malicious Microsoft Office documents, exposing the means that malware authors use. We leverage a taxonomy of the tools used to weaponise Microsoft Office documents and explore the modus operandi of malicious actors. Moreover, we generated and publicly shared a specially crafted dataset, which relies on incorporating benign and malicious documents containing many dynamic features such as VBA macros and DDE. The latter is crucial for a fair and realistic analysis, an open issue in the current state of the art. This allows us to draw safe conclusions on the malicious features and behaviour. More precisely, we extract the necessary features with an automated analysis pipeline to efficiently and accurately classify a document as benign or malicious using machine learning with an F1 score above 0.98, outperforming the current state of the art detection algorithms. Vasilios Koutsokostas, Nikolaos Lykousas, Theodoros Apostolopoulos, Gabriele Orazi, Amrita Ghosal, Fran Casino, Mauro Conti, Constantinos Patsakis |
Comput. Secur. | 6 |
| 2022 | On the effectiveness of binary emulation in malware classification
Vasilis Vouvoutsis, Fran Casino, Constantinos Patsakis |
J. Inf. Secur. Appl. | 2 |
| 2021 | EtherClue: Digital investigation of attacks on Ethereum smart contractsabstractProgramming errors in Ethereum smart contracts can result in catastrophic financial losses from stolen cryptocurrency. While vulnerability detectors can prevent vulnerable contracts from being deployed, this does not mean that such contracts will not be deployed. Once a vulnerable contract is instantiated on the blockchain and becomes the target of attacks, the identification of exploit transactions becomes indispensable in assessing whether it has been actually exploited and identifying which malicious or subverted accounts were involved. In this work, we study the problem of post-factum investigation of Ethereum attacks using Indicators of Compromise (IoC) specially crafted for use in the blockchain. IoC definitions need to capture the side-effects of successful exploitation in the context of the Ethereum blockchain. Therefore, we define a model for smart contract execution, comprising multiple abstraction levels that mirror the multiple views of code execution on a blockchain. Subsequently, we compare IoCs defined across the different levels in terms of their effectiveness and practicality through EtherClue, a prototype tool for investigating Ethereum security incidents. Our results illustrate that coarse-grained IoCs defined over blocks of transactions can detect exploit transactions with less computation. However, they are contract-specific and suffer from false negatives. On the other hand, fine-grained IoCs defined over virtual machine instructions can avoid these pitfalls at the expense of increased computation, which is nevertheless applicable for practical use. Simon Joseph Aquilina, Fran Casino, Mark Vella, Joshua Ellul, Constantinos Patsakis |
Blockchain Res. Appl. | 2 |
| 2021 | Unearthing malicious campaigns and actors from the blockchain DNS ecosystem
Fran Casino, Nikolaos Lykousas, Vasilios Katos, Constantinos Patsakis |
Comput. Commun. | 1 |
| 2021 | Exploiting statistical and structural features for the detection of Domain Generation Algorithms
Constantinos Patsakis, Fran Casino |
J. Inf. Secur. Appl. | 2 |
| 2021 | Intercepting Hail Hydra: Real-time detection of Algorithmically Generated Domains
Fran Casino, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Julio César Hernández Castro |
J. Netw. Comput. Appl. | 1 |
| 2020 | Encrypted and covert DNS queries for botnets: Challenges and countermeasures
Constantinos Patsakis, Fran Casino, Vasilios Katos |
Comput. Secur. | 2 |
| 2020 | Delegated content erasure in IPFS
Eugenia A. Politou, Efthymios Alepis, Constantinos Patsakis, Fran Casino, Mamoun Alazab |
Future Gener. Comput. Syst. | 4 |
| 2019 | HEDGE: Efficient Traffic Classification of Encrypted and Compressed PacketsabstractAs the size and source of network traffic increase, so does the challenge of monitoring and analyzing network traffic. Therefore, sampling algorithms are often used to alleviate these scalability issues. However, the use of high entropy data streams, through the use of either encryption or compression, further compounds the challenge as current state-of-the-art algorithms cannot accurately and efficiently differentiate between encrypted and compressed packets. In this paper, we propose a novel traffic classification method named High Entropy DistinGuishEr (HEDGE) to distinguish between compressed and encrypted traffic. HEDGE is based on the evaluation of the randomness of the data streams and can be applied to individual packets without the need to have access to the entire stream. The findings from the evaluation show that our approach outperforms current state of the art. We also make available our statistically sound dataset, based on known benchmarks, to the wider research community. Fran Casino, Kim-Kwang Raymond Choo, Constantinos Patsakis |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | A k-anonymous approach to privacy preserving collaborative filtering
Fran Casino, Josep Domingo-Ferrer, Constantinos Patsakis, Domenec Puig, Agusti Solanas |
J. Comput. Syst. Sci. | 1 |