VLDB 2026 Research / reviewers in the wild / expert
Riccardo Spolaor
dblp:149/2739
· DBLP profile ↗
36ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0002-3878-7940ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 4 first-author · 9 since 2021Computer networks · 13 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VeinPhantom: Electromagnetic Side-channel Eavesdropping on Palm Vein Information
Zhenwei Lu, Yetong Cao, Riccardo Spolaor, Yanni Yang 0003, Pengfei Hu 0001 |
INFOCOM | 5 |
| 2026 | PowerEar: An Audio Eavesdropping Attack on Mobile Devices Through USB Power Side ChannelabstractWith the increasing popularity of voice-centric applications, acoustic eavesdropping attacks pose a significant threat to user privacy. Although smartphones require explicit user permission to access the microphone, such attacks can bypass this restriction by exploiting power consumption data through compromised power supplies, such as USB adapters, public charging stations, and power banks. However, previous attempts can only recognize a limited set of hotwords or digits. To address this limitation, we introduce PowerEar, an acoustic eavesdropping attack that leverages the power side channel to reconstruct any audio reproduced by the built-in loudspeaker of a mobile device with an unconstrained vocabulary. Our approach relies on a combination of signal processing and generative techniques to learn the mapping between power consumption and audio playback, enabling the reconstruction of such audio through spectrogram enhancement. To validate the effectiveness of PowerEar attack, we carry out a comprehensive set of experiments using audio samples from various public personalities. Our results obtained through objective and subjective evaluations clearly demonstrate that PowerEar can successfully recover user speeches from power consumption data in comprehensive realistic settings, including speech utterances of individuals and different devices, mobile operating systems, activities, charging technology, battery and volume levels. Riccardo Spolaor, Heyuan Shi, Zekun Miao, Yanni Yang 0003, Xiuzhen Cheng, Pengfei Hu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Vehisper: Eavesdropping on In-Vehicle Audio via Secondary Magnetic LeakageabstractModern vehicles are widely equipped with in-vehicle audio systems, and drivers routinely play music, podcasts, navigation prompts, phone calls, and various voice services during daily commutes. Due to the enclosed nature of the vehicle cabin and the presence of substantial ambient noise, in-vehicle content is commonly assumed to be inherently private and imperceptible from outside the vehicle. In this work, we show that this assumption does not always hold and reveal a previously unexplored leakage channel for in-vehicle audio. We propose Vehisper, the first systematic study investigating the feasibility of passively eavesdropping on in-vehicle audio from outside a moving vehicle. We discover that, during operation, in-vehicle loudspeakers excite the vehicle's metallic structure, giving rise to observable low-frequency magnetic leakage outside the vehicle, which forms a stealthy side channel that has not been explored in prior work. Building on this insight, we design a compact external sensing device and develop a multi-stage signal processing pipeline to systematically cope with the strong and complex magnetic interference introduced by vehicle motion, as well as spectral distortion and perceptual degradation induced by the leakage channel. We conduct a comprehensive evaluation of Vehisper on 20 commercial vehicles from 10 major manufacturers. Experimental results demonstrate that, under real driving conditions, Vehisper can reliably recover in-vehicle audio, achieving an average word error rate of 7.85%. Heqiang Fu, Yanni Yang 0003, Riccardo Spolaor, Xiuzhen Cheng, Pengfei Hu 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | Palm Vein Reconstruction From Electromagnetic Side-Channel EmissionsabstractPalm vein recognition has gained traction in secure authentication due to its unique, stable, and inherently concealed biometric characteristics. However, the electromagnetic (EM) emissions from subcutaneous vein imaging sensors (SVIS) may unintentionally leak sensitive biometric information, fundamentally challenging the assumed security guarantees. In this paper, we propose VeinPhantom, a novel side-channel attack that reconstructs palm vein patterns from unintended EM emissions of SVIS, ultimately enabling spoofing attacks against biometric authentication systems. To overcome the challenge of low information entropy caused by weak EM signals and complex environmental interference, VeinPhantom first analyzes palm vein information from EM signals, then employs a cascaded enhancement strategy and incorporates a Dynamic Guidance Diffusion framework to progressively reconstruct high-fidelity palm vein patterns. Extensive experiments demonstrate that VeinPhantom achieves an average structure similarity index measure (SSIM) of 0.56 on commercial devices, along with a 56.96% spoofing success rate against state-of-the-art authentication systems. We further discuss potential mitigation strategies to defend against the attack. Zhenwei Lu, Ning Gao 0001, Yetong Cao, Riccardo Spolaor, Yanni Yang 0003, Xiuzhen Cheng, Pengfei Hu 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | PowerApp: Mobile Apps and User Actions Identification via USB Power Channel AnalysisabstractWith the advancement of technology, the functionality of mobile applications has become increasingly powerful, and users are heavily relying on these apps for various entertainment and business activities. However, the frequent use of these applications accelerates smartphone battery consumption, which can require multiple charging sessions per day. As a result, USB charging facilities and shared mobile power banks have become more widespread. Although their popularity indeed provides convenience to users, it also introduces security risks, such as information theft through USB data transfer. In this paper, we propose PowerApp, a novel framework that identifies mobile applications running and ongoing user actions by analyzing their energy consumption of a USB-connected mobile device. In particular, we passively measure the current withdrawal by the charging mobile device from the power source. We demonstrate the effectiveness and practicality of PowerApp through extensive experiments involving 190 popular mobile apps. Our experimental results show that PowerApp can successfully identify these apps with around 95% accuracy on average. Riccardo Spolaor, Ning Feng, Xiuzhen Cheng, Pengfei Hu 0001 |
ICC | 1 |
| 2025 | Collaborative Countermeasure Against Network Traffic Analyses Based on Packet AggregationabstractNetwork traffic analysis attacks represent a significant threat to information security and user privacy. Leveraging machine learning, these attacks can infer sensitive information even when encryption and anonymization techniques are in place. This paper proposes TravelingTogether, a novel framework that leverages packet aggregation from multiple source hosts to defend users against network traffic analysis. TravelingTogether works at the network level, providing transparent and seamless protection to any hosts connected to the network. We evaluate our defense across different scenarios through a comprehensive set of experiments, demonstrating its effectiveness in thwarting website fingerprinting attacks as a representative use case, and its efficiency in terms of low time and bandwidth overhead. Riccardo Spolaor, Heyuan Shi, Fabio De Gaspari, Luigi V. Mancini, Dongxiao Yu, Xiuzhen Cheng |
ICC | 1 |
| 2025 | EMIRIS: Eavesdropping on Iris Information via Electromagnetic Side Channel
Wenhao Li 0008, Yanni Yang 0003, Riccardo Spolaor, Xiuzhen Cheng, Pengfei Hu 0001 |
NDSS | 5 |
| 2025 | CovertPower: A Covert Channel on Android Devices Through USB Power LineabstractAndroid operating system restricts access to data by enabling data control flow and permission systems to reduce the risk of information theft. Therefore, attackers are constantly looking for alternative and stealthy approaches to exfiltrate private data from a targeted device. This paper presents CovertPower, a covert channel attack that exfiltrates user data by actively inducing power consumption on Android devices. At the transmitting end, our CovertPower app modulates binary data into a timed resource workload (e.g., processor, write-on-memory), producing power consumption bursts. On the receiving end, we acquire power consumption traces via a low-cost hardware tool that can be easily concealed in USB wall-socket adapters or powerbanks. Therefore, a signal processing-based decoder analyzes such traces and retrieves the exfiltrated information. We demonstrate the feasibility of our attack with a thorough experimental evaluation on 14 mobile devices and various real-world settings such as display state, ongoing activities, and charging technologies. Our attack achieves a transfer speed of up to 10 bps with a high bit sequence similarity on most devices and settings considered. Riccardo Spolaor, Veelasha Moonsamy, Mauro Conti, Xiuzhen Cheng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Acoustic Eavesdropping From Sound-Induced Vibrations With Multi-Antenna mmWave RadarabstractAcoustic eavesdropping against private or confidential spaces is a significant threat in the realm of privacy protection. While the presence of soundproof material would weaken such an attack, current eavesdropping technology may be able to bypass these protections. Fortunately, existing studies either inadequately cover the full spectrum of human speech due to low-frequency responses or rely heavily on the prior knowledge used to train a model. To address these challenges, this paper introduces mmEcho, a new acoustic eavesdropping method that utilizes millimeter-wave signals to sense vibration induced by sound precisely. Through signal processing techniques such as the intra-chirp scheme and phase calibration algorithm, mmEcho achieves micrometer-level vibration extraction without requiring target-related data. To improve the range of eavesdropping attacks while reducing noise, we optimize radar signals by leveraging the widespread availability of multiple antennas on commercial off-the-shelf radars. We comprehensively evaluate the performance of mmEcho in different real-world settings. Experimental results demonstrate that, with the aid of multi-antenna technology, mmEcho can more effectively reconstruct the audio from the target at various distances, directions, sound insulators, reverberating objects, sound levels, and languages. Compared to existing methods, our approach provides better effectiveness without prior knowledge, such as the speech data from the target. Wenhao Li 0008, Riccardo Spolaor, Chuanwen Luo, Yuchao Sun, Huashan Chen, Yanni Yang 0003, Xiuzhen Cheng, Pengfei Hu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | UltraAdv: An Ultrasonic Adversarial Attack on Closed-Box Speech Recognition SystemsabstractAttacks on speech recognition systems often use adversarial or inaudible commands. However, a challenge is that adversarial perturbations typically fall within the audible frequency range, making it difficult to achieve inaudibility. Additionally, the non-linear effects of loudspeakers often cause inaudible commands to become audible at higher power levels. Therefore, minimizing the power requirements of the attack is essential to maintain inaudibility. Another significant obstacle is the conversion of variable-length commands, especially longer ones, into shorter target commands. In this paper, we present UltraAdv, a method for generating long-range adversarial perturbations capable of compromising commands of arbitrary length in closed-box setting. By combining the ultrasonic signal with the normal one, rather than negating it as in DolphinAttack, we significantly improve the energy efficiency, thus enhancing its attack distance. We also propose a dynamically adjustable suppression-interference method based on automatic gain control to address the challenge of mismatched durations between long commands and target commands (length-independent). Experiments demonstrate that using a single perturbation, we achieve impressive success rates of 98.84% and 96.62% and 98.32% across a diverse set of 12,260 speeches on DeepSpeech, iFlytek, and Whisper. The attack range reaches up to 15 m, surpassing DolphinAttack's 5 m range at equivalent power. Riccardo Spolaor, Yanni Yang 0003, Xiaoyu Ji 0001, Xiuzhen Cheng, Pengfei Hu 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | AccEmo: Accelerometer Based Human Emotion Recognition for Eyewear DevicesabstractWith the increasing popularity of virtual reality applications, there is an increasing demand for more interactive entertainment, learning, social interactions, and other activities on eyewear devices. Recognizing users’ emotion and providing reliable feedback can significantly improve the immersive experience for users. However, previous works in emotion recognition required modifications to existing eyewear devices and the integration of additional sensors, or relied on specialized sensors in expensive commercial-grade eyewear devices, making direct deployment on existing consumer-grade eyewear devices challenging. In this paper, we proposeAccEmo, the first system that analyzes the data from the built-in accelerometer sensor on eyewear devices to accurately recognize human emotion.AccEmofirst employs signal processing technologies to process raw accelerometer data, and then uses a binary classification network to determine whether the accelerometer data is influenced by emotional changes. Subsequently,AccEmoproposes a network architecture based on residual neural network and channel-wise attention mechanism as a universal feature extractor to extract complex features related to human emotions from the accelerometer data. Finally,AccEmouses personalized classifiers to achieve emotion recognition for different users. Extensive performance evaluation ofAccEmoacross diverse users demonstrates an exceptional average accuracy of 94.3%. Additionally, the robustness ofAccEmois validated through evaluations in various scenarios, yielding promising results. Hui Zhuang, Yanni Yang 0003, Zhe Chen 0015, Riccardo Spolaor, Xiuzhen Cheng, Prasant Mohapatra, Pengfei Hu 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Robust Network Intrusion Detection via Semi-supervised Deep Reinforcement Learning
Riccardo Spolaor, Tianhao Chen, Pengfei Hu 0001, Xiuzhen Cheng |
SecureComm (3) | 1 |
| 2023 | HiPo: Detecting Fake News via Historical and Multi-Modal Analyses of Social Media PostsabstractIn recent years, fake news has been a primary concern as it plays a significant role in influencing the political, economic, and social spheres. The scientific community has proposed several solutions to detect such fraudulent information. However, such solutions are unsuitable for social media posts since they cannot extract sufficient information from one-line textual and graphical content or are highly dependent on prior knowledge, which may be unavailable in the case of unprecedented events (e.g., breaking news). Tianshu Xiao, Sichang Guo, Jingcheng Huang, Riccardo Spolaor, Xiuzhen Cheng |
CIKM | 4 |
| 2023 | Plug and Power: Fingerprinting USB Powered Peripherals via Power Side-channelabstractThe literature and the news regularly report cases of exploiting Universal Serial Bus (USB) devices as attack tools for malware injections and private data exfiltration. To protect against such attacks, security researchers proposed different solutions to verify the identity of a USB device via side-channel information (e.g., timing or electromagnetic emission). However, such solutions often make strong assumptions on the measurement (e.g., electromagnetic interference-free area around the device), on a device’s state (e.g., only at the boot or during specific actions), or are limited to one particular type of USB device (e.g., flash drive or input devices).In this paper, we present PowerID, a novel method to fingerprint USB peripherals based on their power consumption. PowerID analyzes the power traces from a peripheral to infer its identity and properties. We evaluate the effectiveness of our method on an extensive power trace dataset collected from 82 USB peripherals, including 35 models and 8 types. Our experimental results show that PowerID accurately recognizes a peripheral type, model, activity, and identity. Riccardo Spolaor, Federico Turrin, Mauro Conti, Xiuzhen Cheng |
INFOCOM | 1 |
| 2023 | mmEcho: A mmWave-based Acoustic Eavesdropping MethodabstractAcoustic eavesdropping targeting private or confidential spaces is one of the most severe privacy threats. Soundproof rooms may reduce such risks, but they cannot prevent sophisticated eavesdropping, which has been an emerging research trend in recent years. Researchers have investigated such acoustic eavesdropping attacks via sensor-enabled side-channels. However, such attacks either make unrealistic assumptions or have considerable constraints. This paper introduces mmEcho, an acoustic eavesdropping system that uses a millimeter-wave radio signal to accurately measure the micrometer-level vibration of an object induced by sound waves. Compared with previous works, our eavesdropping method is highly accurate and requires no prior knowledge about the victim. We evaluate the performance of mmEcho under extensive real-world settings and scenarios. Our results show that mmEcho can accurately reconstruct audio from moving sources at various distances, orientations, reverberating objects, sound insulators, spoken languages, and sound levels. Pengfei Hu 0001, Wenhao Li 0008, Riccardo Spolaor, Xiuzhen Cheng |
SP | 3 |
| 2022 | BLEWhisperer: Exploiting BLE Advertisements for Data Exfiltration
Ankit Gangwal, Riccardo Spolaor, Abhijeet Srivastava |
ESORICS (1) | 3 |
| 2022 | AccEar: Accelerometer Acoustic Eavesdropping with Unconstrained VocabularyabstractWith the increasing popularity of voice-based applications, acoustic eavesdropping has become a serious threat to users’ privacy. While on smartphones the access to microphones needs an explicit user permission, acoustic eavesdropping attacks can rely on motion sensors (such as accelerometer and gyroscope), which access is unrestricted. However, previous instances of such attacks can only recognize a limited set of pre-trained words or phrases. In this paper, we present AccEar, an accelerometer-based acoustic eavesdropping attack that can reconstruct any audio played on the smartphone’s loudspeaker with unconstrained vocabulary. We show that an attacker can employ a conditional Generative Adversarial Network (cGAN) to reconstruct high-fidelity audio from low-frequency accelerometer signals. The presented cGAN model learns to recreate high-frequency components of the user’s voice from low-frequency accelerometer signals through spectrogram enhancement. We assess the feasibility and effectiveness of AccEar attack in a thorough set of experiments using audio from 16 public personalities. As shown by the results in both objective and subjective evaluations, AccEar successfully reconstructs user speeches from accelerometer signals in different scenarios including varying sampling rate, audio volume, device model, etc. Pengfei Hu 0001, Hui Zhuang, Panneer Selvam Santhalingam, Riccardo Spolaor, Parth H. Pathak, Xiuzhen Cheng |
SP | 4 |
| 2022 | Side-channel attacks on mobile and IoT devices for Cyber-Physical systems
Mauro Conti, Eleonora Losiouk, Radha Poovendran, Riccardo Spolaor |
Comput. Networks | 4 |
| 2021 | Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandabstractAs malware detection algorithms and methods become more sophisticated, malware authors adopt equally sophisticated evasion mechanisms to defeat them. Anecdotal evidence claims Living-Off-The-Land (LotL) techniques are one of the major evasion techniques used in many malware attacks. These techniques leverage binaries already present in the system to conduct malicious actions. We present the first large-scale systematic investigation of the use of these techniques by malware on Windows systems.In this paper, we analyse how common the use of these native system binaries is across several malware datasets, containing a total of 31,805,549 samples. We identify an average 9.41% prevalence. Our results show that the use of LotL techniques is prolific, particularly in Advanced Persistent Threat (APT) malware samples where the prevalence is 26.26%, over twice that of commodity malware.To illustrate the evasive potential of LotL techniques, we test the usage of LotL techniques against several fully patched Windows systems in a local sandboxed environment and show that there is a generalised detection gap in 10 of the most popular anti-virus products. Frederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor, Ivan Martinovic |
SP | 4 |
| 2021 | USB powered devices: A survey of side-channel threats and countermeasuresabstractRecent technological innovations lead to the rise of a plethora of portable electronic devices such as smartphones, small household appliances, and other IoT devices. To power or recharge the battery of such devices, manufacturers identified in the ubiquitous Universal Serial Bus (USB) standard a convenient solution, as it enables both communication and energy supply. Unfortunately, the default trust on USB ports has been exploited by hackers to extract highly sensitive user data on such devices. Despite the efforts by security experts and manufacturers to detect and block this threat, an even more stealthy approach to undermine users privacy relies on side-channel attacks on the USB interface, such as electromagnetic emissions and power consumption. In this paper, we present a comprehensive survey of the state-of-the-art of side-channel analysis on the security of USB-powered devices. Differently from other surveys on USB-based attacks via the communication interface only, this survey considers research works that aim to infer or extract private information from the energy supply, the device itself, or unintentionally available functionalities. In particular, we consider this emergent trend of security work that was not previously considered in other surveys, such as the energy consumption and electromagnetic emission analyses, as well as Juice Filming Charging (JFC) attacks. We first analyze the physical properties of the side-channels and technical characteristics of such research work, we then summarize the countermeasures proposed in the state-of-the-art. Finally, we also identify some possible future directions to foster further research in this field. Riccardo Spolaor, Federico Turrin, Riccardo Bonafede, Mauro Conti |
High Confid. Comput. | 2 |
| 2020 | BOTection: Bot Detection by Building Markov Chain Models of Bots Network BehaviorabstractBotnets continue to be a threat to organizations, thus various machine learning-based botnet detectors have been proposed. However, the capability of such systems in detecting new or unseen botnets is crucial to ensure its robustness against the rapid evolution of botnets. Moreover, it prolongs the effectiveness of the system in detecting bots, avoiding frequent and time-consuming classifier re-training. We present BOTection, a privacy-preserving bot detection system that models the bot network flow behavior as a Markov Chain. The Markov Chain state transitions capture the bots' network behavior using high-level flow features as states, producing content-agnostic and encryption resilient behavioral features. These features are used to train a classifier to first detect flows produced by bots, and then identify their bot families. We evaluate our system on a dataset of over 7M malicious flows from 12 botnet families, showing its capability of detecting bots' network traffic with 99.78% F-measure and classifying it to a malware family with a 99.09% F-measure. Notably, due to the modeling of general bot network behavior by the Markov Chains, BOTection can detect traffic belonging to unseen bot families with an F-measure of 93.03% making it robust against malware evolution. Bushra A. AlAhmadi, Enrico Mariconti, Riccardo Spolaor, Gianluca Stringhini, Ivan Martinovic |
AsiaCCS | 3 |
| 2020 | Network-based Malware Detection with a Two-tier Architecture for Online Incremental UpdateabstractAs smartphones carry more and more private information, it has become the main target of malware attacks. Threats on mobile devices have become increasingly sophisticated, making it imperative to develop effective tools that are able to detect and counter such threats. Unfortunately, existing malware detection tools based on machine learning techniques struggle to keep up due to the difficulty in performing online incremental update on the detection models. In this paper, a Two-tier Architecture Malware Detection (TAMD) method is proposed, which can learn from the statistical features of network traffic to detect malware. The first layer of TAMD identifies uncertain samples in the training set through a preliminary classification, whereas the second layer builds an improved classifier by filtering out such samples. We enhance TAMD with an incremental leaning based technique (TAMD-IL), which allows to incrementally update the detection models without retraining it from scratch by removing and adding sub-models in TAMD. We experimentally demonstrate that TAMD outperforms the existing methods with up to 98.72% on precision and 96.57% on recall. We also evaluate TAMD-IL on four concept drift datasets and compare it with classical machine learning algorithms, two state-of-the-art malware detection technologies, and three incremental learning technologies. Experimental results show that TAMD-IL is efficient in terms of both update time and memory usage. Anli Yan, Riccardo Spolaor, Shuaishuai Tan, Lizhi Peng, Bo Yang 0001 |
IWQoS | 3 |
| 2019 | DART: Detecting Unseen Malware Variants using Adaptation Regularization Transfer LearningabstractNetwork traffic analysis has been widely used for detecting malware at a large-scale network. Nevertheless, the emerging malware variants and zero-day exploits keep posing significant challenges to malware detection systems. In this paper, we propose DART, a framework for detecting malicious network traffic based on Adaptation Regularization Transfer Learning (ARTL), which effectively copes with the unseen malware variants problem. Specifically, DART trains the adaptive classifier by simultaneously optimizing three factors: (i) the structural risk functions; (ii) the joint distribution between the known malware and unseen malware variants domains; and (iii) the manifold consistency underlying marginal distribution. In addition, DART also works with encrypted network traffic since it does not leverage information related to the packet content. We assess the effectiveness and efficiency of our proposal with a thorough set of experiments. DART achieves over 90% F-measure and 91% recall, outperforming conventional traffic classification methods and other state-of-the-art intrusion detection systems. Riccardo Spolaor, Qiben Yan 0001, Bo Yang 0001 |
ICC | 3 |
| 2019 | CompactFlow: A Hybrid Binary Format for Network Flow Data
Michal Piskozub, Riccardo Spolaor, Ivan Martinovic |
WISTP | 2 |
| 2018 | Lexical Mining of Malicious URLs for Classifying Android Malware
Shanshan Wang 0003, Qiben Yan 0001, Lin Wang 0004, Riccardo Spolaor, Bo Yang 0001, Mauro Conti |
SecureComm (1) | 5 |
| 2018 | Robust Smartphone App Identification via Encrypted Network Traffic AnalysisabstractThe apps installed on a smartphone can reveal much information about a user, such as their medical conditions, sexual orientation, or religious beliefs. In addition, the presence or absence of particular apps on a smartphone can inform an adversary, who is intent on attacking the device. In this paper, we show that a passive eavesdropper can feasibly identify smartphone apps by fingerprinting the network traffic that they send. Although SSL/TLS hides the payload of packets, side-channel data, such as packet size and direction is still leaked from encrypted connections. We use machine learning techniques to identify smartphone apps from this side-channel data. In addition to merely fingerprinting and identifying smartphone apps, we investigate how app fingerprints change over time, across devices, and across different versions of apps. In addition, we introduce strategies that enable our app classification system to identify and mitigate the effect of ambiguous traffic, i.e., traffic in common among apps, such as advertisement traffic. We fully implemented a framework to fingerprint apps and ran a thorough set of experiments to assess its performance. We fingerprinted 110 of the most popular apps in the Google Play Store and were able to identify them six months later with up to 96% accuracy. Additionally, we show that app fingerprints persist to varying extents across devices and app versions. Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | DELTA: Data Extraction and Logging Tool for AndroidabstractIn recent years, the use of smartphones has increased exponentially, and so have their capabilities. Together with an increase in processing power, smartphones are now equipped with a variety of sensors and provide an extensive set of API. These capabilities allow us to extract data related to environment, user habits, and operating system itself. This data is extremely valuable in many research fields such as user authentication, intrusion, and information leaks detection. For these reasons, researchers need a solid and reliable logging tool to collect data from mobile devices. In this paper, we first survey the existing logging tools available on the Android platform, comparing their features and their impact on the system. Then, we present DELTA - Data Extraction and Logging Tool for Android, which improves the existing Android logging solutions in terms of flexibility, fine-grained tuning capabilities, extensibility, and available set of logging features. We fully implement DELTA and we run a thorough performance evaluation. The results show that our tool has a low impact on the performance of the system, on battery consumption, and on user experience. Finally, we make the DELTA source code available to the research community. Riccardo Spolaor, Elia Dal Santo, Mauro Conti |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | Type Me the Truth!: Detecting Deceitful Users via Keystroke DynamicsabstractIn this paper, we propose a novel method, based on keystroke dynamics, to distinguish between fake and truthful personal information written via a computer keyboard. Our method does not need any prior knowledge about the user who is providing data. To our knowledge, this is the first work that associates the typing human behavior with the production of lies regarding personal information. Via experimental analysis involving 190 subjects, we assess that this method is able to distinguish between truth and lies on specific types of autobiographical information, with an accuracy higher than 75%. Specifically, for information usually required in online registration forms (e.g., name, surname and email), the typing behavior diverged significantly between truthful or untruthful answers. According to our results, keystroke analysis could have a great potential in detecting the veracity of self-declared information, and it could be applied to a large number of practical scenarios requiring users to input personal data remotely via keyboard. Merylin Monaro, Riccardo Spolaor, Mauro Conti, Luciano Gamberini, Giuseppe Sartori |
ARES | 2 |
| 2017 | No Free Charge Theorem: A Covert Channel via USB Charging Cable on Mobile Devices
Riccardo Spolaor, Laila Abudahi, Veelasha Moonsamy, Mauro Conti, Radha Poovendran |
ACNS | 1 |
| 2017 | Mirage: Toward a Stealthier and Modular Malware Analysis Sandbox for Android
Lorenzo Bordoni, Mauro Conti, Riccardo Spolaor |
ESORICS (1) | 3 |
| 2017 | You Surf so Strange Today: Anomaly Detection in Web Services via HMM and CTMC
Maddalena Favaretto, Riccardo Spolaor, Mauro Conti, Marco Ferrante |
GPC | 2 |
| 2016 | CAPTCHaStar! A Novel CAPTCHA Based on Interactive Shape Discovery
Mauro Conti, Claudio Guarisco, Riccardo Spolaor |
ACNS | 3 |
| 2016 | On the Effectiveness of Sensor-enhanced Keystroke Dynamics Against Statistical AttacksabstractIn recent years, simple password-based authentication systems have increasingly proven ineffective for many classes of real-world devices. As a result, many researchers have concentrated their efforts on the design of new biometric authentication systems. This trend has been further accelerated by the advent of mobile devices, which offer numerous sensors and capabilities to implement a variety of mobile biometric authentication systems. Along with the advances in biometric authentication, however, attacks have also become much more sophisticated and many biometric techniques have ultimately proven inadequate in face of advanced attackers in practice. Valeriu-Daniel Stanciu, Riccardo Spolaor, Mauro Conti, Cristiano Giuffrida |
CODASPY | 2 |
| 2016 | AppScanner: Automatic Fingerprinting of Smartphone Apps from Encrypted Network TrafficabstractAutomatic fingerprinting and identification of smartphone apps is becoming a very attractive data gathering technique for adversaries, network administrators, investigators and marketing agencies. In fact, the list of apps installed on a device can be used to identify vulnerable apps for an attacker to exploit, uncover a victim's use of sensitive apps, assist network planning, and aid marketing. However, app fingerprinting is complicated by the vast number of apps available for download, the wide range of devices they may be installed on, and the use of payload encryption protocols such as HTTPS/TLS. In this paper, we present a novel methodology and a framework implementing it, called AppScanner, for the automatic fingerprinting and real-time identification of Android apps from their encrypted network traffic. To build app fingerprints, we run apps automatically on a physical device to collect their network traces. We apply various processing strategies to these network traces before extracting the features that are used to train our supervised learning algorithms. Our fingerprint generation methodology is highly scalable and does not rely on inspecting packet payloads, thus our framework works even when HTTPS/TLS is employed. We built and deployed this lightweight framework and ran a thorough set of experiments to assess its performance. We automatically profiled 110 of the most popular apps in the Google Play Store and were later able to re-identify them with more than 99% accuracy. Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic |
EuroS&P | 2 |
| 2016 | Analyzing Android Encrypted Network Traffic to Identify User ActionsabstractMobile devices can be maliciously exploited to violate the privacy of people. In most attack scenarios, the adversary takes the local or remote control of the mobile device, by leveraging a vulnerability of the system, hence sending back the collected information to some remote web service. In this paper, we consider a different adversary, who does not interact actively with the mobile device, but he is able to eavesdrop the network traffic of the device from the network side (e.g., controlling a Wi-Fi access point). The fact that the network traffic is often encrypted makes the attack even more challenging. In this paper, we investigate to what extent such an external attacker can identify the specific actions that a user is performing on her mobile apps. We design a system that achieves this goal using advanced machine learning techniques. We built a complete implementation of this system, and we also run a thorough set of experiments, which show that our attack can achieve accuracy and precision higher than 95%, for most of the considered actions. We compared our solution with the three state-of-the-art algorithms, and confirming that our system outperforms all these direct competitors. Mauro Conti, Luigi V. Mancini, Riccardo Spolaor, Nino Vincenzo Verde |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Can't You Hear Me Knocking: Identification of User Actions on Android Apps via Traffic AnalysisabstractWhile smartphone usage become more and more pervasive, people start also asking to which extent such devices can be maliciously exploited as "tracking devices". The concern is not only related to an adversary taking physical or remote control of the device, but also to what a passive adversary without the above capabilities can observe from the device communications. Work in this latter direction aimed, for example, at inferring the apps a user has installed on his device, or identifying the presence of a specific user within a network. Mauro Conti, Luigi V. Mancini, Riccardo Spolaor, Nino Vincenzo Verde |
CODASPY | 3 |