VLDB 2026 Research / reviewers in the wild / expert
Luca Verderame
dblp:14/11488
· DBLP profile ↗
24ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0001-7155-7429ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Empirical Study on Reproducible Packaging in Open-Source EcosystemsabstractThe integrity of software builds is fundamental to the security of the software supply chain. While Thompson first raised the potential for attacks on build infrastructure in 1984, limited attention has been given to build integrity in the past 40 years, enabling recent attacks on SolarWinds, event-stream, and xz. The best-known defense against build system attacks is creating reproducible builds; however, achieving them can be complex for both technical and social reasons and thus is often viewed as impractical to obtain. In this paper, we analyze reproducibility of builds in a novel context: reusable components distributed as packages in six popular software ecosystems (npm, Maven, PyPI, Go, RubyGems, and Cargo). Our quantitative study on a representative sample of 4000 packages in each ecosystem raises concerns: Rates of reproducible builds vary widely between ecosystems, with some ecosystems having all packages reproducible whereas others have reproducibility issues in nearly every package. However, upon deeper investigation, we identified that with relatively straightforward infrastructure configuration and patching of build tools, we can achieve very high rates of reproducible builds in all studied ecosystems. We conclude that if the ecosystems adopt our suggestions, the build process of published packages can be independently confirmed for nearly all packages without individual developer actions, and doing so will prevent significant future software supply chain attacks. Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, Luca Verderame |
ICSE | 9 |
| 2024 | Obfuscating Code Vulnerabilities Against Static Analysis in Android Apps
Francesco Pagano, Luca Verderame, Alessio Merlo |
SEC | 2 |
| 2023 | PARIOT: Anti-repackaging for IoT firmware integrityabstractIoT repackaging refers to an attack devoted to tampering with a legitimate firmware package by modifying its content (e.g., injecting some malicious code) and re-distributing it in the wild. In such a scenario, the firmware delivery and update processes are central to ensuring firmware integrity. Unfortunately, several existing solutions lack proper integrity verification, exposing firmware to repackaging attacks. If this is not the case, they still require an external trust anchor (e.g., signing keys or secure storage technologies), which could limit their adoption in resource-constrained environments. In addition, state-of-the-art frameworks do not cope with the entire firmware production and delivery process, thereby failing to protect the content generated by the firmware producers through the whole supply chain. To mitigate such a problem, in this paper, we introduce PARIOT, a novel self-protecting scheme for IoT that injects integrity checks, called anti-tampering (AT) controls, directly into the firmware. The AT controls enable the runtime detection of repackaging attempts without needing signing keys, internet connection, secure storage technologies, or external trusted parties. PARIOT can be adopted on top of existing state-of-the-art solutions ensuring the widest compatibility with current IoT ecosystems and update frameworks. Also, we have implemented this scheme into PARIOTIC, a prototype to protect C/C++ IoT firmware automatically. The evaluation phase of 50 real-world firmware samples demonstrated the proposed methodology’s feasibility and robustness against practical repackaging attacks without altering the firmware behavior or severe overheads. Luca Verderame, Antonio Ruggia, Alessio Merlo |
J. Netw. Comput. Appl. | 1 |
| 2023 | You Can't Always Get What You Want: Towards User-Controlled Privacy on AndroidabstractMobile applications (hereafter, apps) collect a plethora of information regarding the user behavior and his device through third-party analytics libraries. However, the collection and usage of such data raised several privacy concerns, mainly because the end-user - i.e., the actual owner of the data - is out of the loop in this collection process. Also, the existing privacy-enhanced solutions that emerged in the last years follow an ”all or nothing” approach, leaving the user the sole option to accept or completely deny access to privacy-related data. This work has the two-fold objective of assessing the privacy impact of mobile analytics libraries and proposing a data anonymization methodology that offers a trade-off between the utility and privacy of the collected data and enables complete control over the sharing process. To achieve that, we present an empirical privacy assessment on the analytics libraries used in the 4500 most-used Android apps of the Google Play Store in late 2020. Then, we propose an empowered anonymization methodology, based on MobHide (Caputoet al., 2020), that gives the end-user complete control over the collection and anonymization process. Finally, we empirically demonstrate the applicability and effectiveness of our solution thanks to HideDroid, a fully-fledged anonymization app for the Android ecosystem. Davide Caputo, Francesco Pagano, Giovanni Bottino, Luca Verderame, Alessio Merlo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Repack Me If You Can: An Anti-Repackaging Solution Based on Android VirtualizationabstractA growing trend in repackaging attacks exploits the Android virtualization technique, in which malicious code can run together with the victim app in a virtual container. In such a scenario, the attacker can directly build a malicious container capable of hosting the victim app instead of tampering with it, thus neglecting any anti-repackaging protection developed so far. Also, existing anti-virtualization techniques are ineffective since the malicious container can intercept - and tamper with - such controls at runtime. So far, only two solutions have been specifically designed to address virtualization-based repackaging attacks. However, their effectiveness is limited since they both rely on static taint analysis, thus not being able to evaluate code dynamically loaded at runtime. Antonio Ruggia, Eleonora Losiouk, Luca Verderame, Mauro Conti, Alessio Merlo |
ACSAC | 3 |
| 2021 | You Shall not Repackage! Demystifying Anti-Repackaging on Android
Alessio Merlo, Antonio Ruggia, Luigi Sciolla, Luca Verderame |
Comput. Secur. | 4 |
| 2021 | ARMAND: Anti-Repackaging through Multi-pattern Anti-tampering based on Native Detection
Alessio Merlo, Antonio Ruggia, Luigi Sciolla, Luca Verderame |
Pervasive Mob. Comput. | 4 |
| 2020 | On the (Un)Reliability of Privacy Policies in Android AppsabstractThe access to privacy-sensitive information on Android is a growing concern in the mobile community. Albeit Google Play recently introduced some privacy guidelines, it is still an open problem to soundly verify whether apps actually comply with such rules. To this aim, in this paper, we discuss a novel methodology based on a fruitful combination of static analysis, dynamic analysis, and machine learning techniques, which allows assessing such compliance. More in detail, our methodology checks whether each app i) contains a privacy policy that complies with the Google Play privacy guidelines, and ii) accesses privacy-sensitive information only upon the acceptance of the policy by the user. Furthermore, the methodology also allows checking the compliance of third-party libraries embedded in the apps w.r.t. the same privacy guidelines. We implemented our methodology in a tool, 3PDroid, and we carried out an assessment on a set of recent and most-downloaded Android apps in the Google Play Store. Experimental results suggest that more than 95% of apps access user's privacy-sensitive information, but just a negligible subset of them (≈ 1%) fully complies with the Google Play privacy guidelines. Luca Verderame, Davide Caputo, Andrea Romdhana, Alessio Merlo |
IJCNN | 1 |
| 2020 | Enabling Next-Generation Cyber Ranges with Mobile Security Components
Enrico Russo 0001, Luca Verderame, Alessio Merlo |
ICTSS | 2 |
| 2020 | APPregator: A Large-Scale Platform for Mobile Security Analysis
Luca Verderame, Davide Caputo, Andrea Romdhana, Alessio Merlo |
ICTSS | 1 |
| 2020 | Securing PIN-based authentication in smartwatches with just two gesturesabstractSummary Smartwatches are becoming increasingly ubiquitous as they offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers. The services provided include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. Indeed, PINs and Pattern Lock have been widely used in smartwatches for user authentication. However, such authentication methods are not robust against various forms of cybersecurity attacks, such as side channel, phishing, smudge, shoulder surfing, and video‐recording attacks. Moreover, the recent adoption of hardware‐based solutions, like the Trusted Execution Environment (TEE), can mitigate only partially such problems. Thus, the user's security and privacy are at risk without a strong authentication scheme in place. In this work, we propose 2GesturePIN, a new authentication framework that allows users to authenticate securely to their smartwatches and related sensitive services through solely two gestures. 2GesturePIN leverages the rotating bezel or crown, which are the most intuitive ways to interact with a smartwatch, as a dedicated hardware. 2GesturePIN improves the resilience of the regular PIN authentication method against state‐of‐the‐art cybersecurity attacks while maintaining a high level of usability. Meriem Guerar, Mauro Migliardi, Francesco Palmieri 0002, Luca Verderame, Alessio Merlo |
Concurr. Comput. Pract. Exp. | 4 |
| 2020 | A secure cloud-edges computing architecture for metagenomics analysis
Luca Verderame, Ivan Merelli, Lucia Morganti, Elena Corni, Daniele Cesini, Daniele D'Agostino, Alessio Merlo |
Future Gener. Comput. Syst. | 1 |
| 2020 | CirclePIN: A Novel Authentication Mechanism for Smartwatches to Prevent Unauthorized Access to IoT DevicesabstractIn the last months, the market for personal wearable devices has been booming significantly, and, in particular, smartwatches are starting to assume a fundamental role in the Bring Your Own Device (BYOD) arena as well as in the more general Internet of Things (IoT) ecosystem, by acting both as sensitive data sources and as user identity proxies. These new roles, complementing the more traditional personal assistance and telemetry/tracking ones, open new perspectives in their integration in complex IoT-based critical infrastructures such as e-payment, health care monitoring, and emergency systems, as well as in their usage as remote control facilities in smart services. Users can access their IoT devices at any time from any place through smartwatches. We argue that this new scenario calls for a strengthened and more resilient authentication of users on these devices, despite their limitations in terms of dimensions and hardware constraints that may considerably affect the usability of security mechanisms. In this article, we present an innovative authentication scheme targeted at smartwatches, namely CirclePIN, that provides both resilience to most common attacks and a high level of usability in tests with real users. Meriem Guerar, Luca Verderame, Alessio Merlo, Francesco Palmieri 0002, Mauro Migliardi, Luca Vallerini |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2019 | Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps
Davide Caputo, Luca Verderame, Simone Aonzo, Alessio Merlo |
DBSec | 2 |
| 2019 | Blockchain-based risk mitigation for invoice financingabstractThe market for invoice financing has been steadily growing in the last few years and has been the third financing market in size in 2016. Most solutions in this field are based on private platforms and even the new proposals based on blockchain are mostly adopting a private, permissioned blockchain. In this paper, we propose an idea based on a public blockchain that allows both fully open and group-restricted auctioning of invoices. Furthermore, our proposal introduces a reputation system that is based on the past behavior of entities, as it is photographed by the public blockchain, to allow insurance companies modulate the cost of the insurance contracts they offer. This combination guarantees the complete transparency and tamperproof-ness of a public blockchain, while it allows reducing insurance costs and fraud possibilities. Meriem Guerar, Luca Verderame, Alessio Merlo, Mauro Migliardi |
IDEAS | 2 |
| 2019 | 2GesturePIN: Securing PIN-Based Authentication on SmartwatchesabstractSmartwatches offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers and are becoming increasingly ubiquitous. The kind of services these devices are capable to provide include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. PINs and Pattern Lock have been widely used in smartwatches for user authentication, however, those types of passwords are not robust against various forms of attacks, such as side channel, phishing, smudge, shoulder surfing, and videorecording attacks. In this work, we propose 2GesturePIN, a new authentication method that allows users to authenticate securely to their smartwatches and sensitive services through solely two gestures. It leverages the rotating bezel or the crown which are the most intuitive channels to interact with a smartwatch. 2GesturePIN enhances the resilience of the regular PIN to common attacks while maintaining a high level of usability. Meriem Guerar, Luca Verderame, Mauro Migliardi, Alessio Merlo |
WETICE | 2 |
| 2019 | Towards Policy-Driven Monitoring of Fog ApplicationsabstractThis paper introduces a proposal aimed at defining a novel methodology for run-time monitoring of Fog applications which is both policy-driven and app-agnostic. The first feature grants the possibility to define security policies that are enforced at run-time on a single or a set of Fog applications. The latter allows to enforce the security policies independently from the execution environment of the Fog applications (e.g., Virtual Machine, Container, PaaS, ...). The paper also discusses a PoC implementation on Cisco IOx. Enrico Russo 0001, Luca Verderame, Alessio Merlo |
WETICE | 2 |
| 2019 | Automated Security Analysis of IoT Software Updates
Nicolas Dejon, Davide Caputo, Luca Verderame, Alessandro Armando, Alessio Merlo |
WISTP | 3 |
| 2018 | Automatic security verification of mobile app configurations
Gabriele Costa 0001, Alessio Merlo, Luca Verderame, Alessandro Armando |
Future Gener. Comput. Syst. | 3 |
| 2016 | Android vs. SEAndroid: An empirical assessment
Alessio Merlo, Gabriele Costa 0001, Luca Verderame, Alessandro Armando |
Pervasive Mob. Comput. | 3 |
| 2014 | Enabling BYOD through secure meta-marketabstractMobile security is a hot research topic. Yet most of available techniques focus on securing individual applications and therefore cannot possibly tackle security weaknesses stemming from the combined use of one or more applications (e.g. confused deputy attacks). Preventing these types of attacks is crucial in many important application scenarios. For instance, their prevention is a prerequisite for the widespread adoption of the BYOD paradigm in the corporate setting. Alessandro Armando, Gabriele Costa 0001, Alessio Merlo, Luca Verderame |
WISEC | 4 |
| 2013 | An Empirical Evaluation of the Android Security Framework
Alessandro Armando, Alessio Merlo, Luca Verderame |
SEC | 3 |
| 2013 | Breaking and fixing the Android Launching Flow
Alessandro Armando, Alessio Merlo, Mauro Migliardi, Luca Verderame |
Comput. Secur. | 4 |
| 2012 | Would You Mind Forking This Process? A Denial of Service Attack on Android (and Some Countermeasures)
Alessandro Armando, Alessio Merlo, Mauro Migliardi, Luca Verderame |
SEC | 4 |