VLDB 2026 Research / reviewers in the wild / expert
Antonio Ken Iannillo
dblp:156/2310
· DBLP profile ↗
13ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-9358-7100ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 1 first-authorSecurity and privacy · 4 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Integrated Hybrid Framework for Green Heterogeneous Vehicle Routing with Mixed Pickup and Deliveryabstractpeer reviewed Prateek Gupta, Devanand Padha, Jorge Augusto Meira, Antonio Ken Iannillo, Daniel Antunes Pedrozo, Danilo D'Aversa |
ICORES | 4 |
| 2025 | On-Chain Risk Signals: Predicting Security Threats in DeFi ProjectsabstractBlockchain has revolutionized finance through decentralization, eliminating the need for traditional intermediaries. However, security concerns remain a major barrier to adoption, as DeFi platforms increasingly face targeted attacks. In this paper, we present the first methodology for automatically assessing and quantifying the risk of fund loss in DeFi projects due to smart contract exploits. By analyzing on-chain behaviors that signal potential malicious interactions, our approach assigns a dynamic risk score to DeFi projects over time. Relying solely on on-chain data ensures resistance to data manipulation and enhances the integrity of the assessment.We evaluated 220 compromised and 200 unaffected DeFi projects on multiple EVM-compatible blockchains – including Ethereum, BSC, Polygon, Arbitrum, Optimism, and Fantom – and conducted a comparative risk assessment on these projects. Our findings reveal statistically significant differences in risk scores before attacks compared to a control group without attacks. We anticipated potential threats to 86% of the projects that were later attacked, one day before the incidents, with a precision of 78%. Bahareh Parhizkari, Antonio Ken Iannillo, Edward Zulkoski, Christof Ferreira Torres, Radu State |
TrustCom | 2 |
| 2024 | Beyond the Public Mempool: Catching DeFi Attacks Before They Happen with Real-Time Smart Contract Analysis
Bahareh Parhizkari, Antonio Ken Iannillo, Christof Ferreira Torres, Sebastian Banescu, Joseph Jiaqi Xu, Radu State |
SecureComm (3) | 2 |
| 2021 | ConFuzzius: A Data Dependency-Aware Hybrid Fuzzer for Smart ContractsabstractSmart contracts are Turing-complete programs that are executed across a blockchain. Unlike traditional programs, once deployed, they cannot be modified. As smart contracts carry more value, they become more of an exciting target for attackers. Over the last years, they suffered from exploits costing millions of dollars due to simple programming mistakes. As a result, a variety of tools for detecting bugs have been proposed. Most of these tools rely on symbolic execution, which may yield false positives due to over-approximation. Recently, many fuzzers have been proposed to detect bugs in smart contracts. However, these tend to be more effective in finding shallow bugs and less effective in finding bugs that lie deep in the execution, therefore achieving low code coverage and many false negatives. An alternative that has proven to achieve good results in traditional programs is hybrid fuzzing, a combination of symbolic execution and fuzzing. In this work, we study hybrid fuzzing on smart contracts and present ConFuzzius, the first hybrid fuzzer for smart contracts. ConFuzzius uses evolutionary fuzzing to exercise shallow parts of a smart contract and constraint solving to generate inputs that satisfy complex conditions that prevent evolutionary fuzzing from exploring deeper parts. Moreover, ConFuzzius leverages dynamic data dependency analysis to efficiently generate sequences of transactions that are more likely to result in contract states in which bugs may be hidden. We evaluate the effectiveness of ConFuzzius by comparing it with state-of-the-art symbolic execution tools and fuzzers for smart contracts. Our evaluation on a curated dataset of 128 contracts and a dataset of 21K real-world contracts shows that our hybrid approach detects more bugs than state-of-the-art tools (up to 23%) and that it outperforms existing tools in terms of code coverage (up to 69%). We also demonstrate that data dependency analysis can boost bug detection up to 18%. Christof Ferreira Torres, Antonio Ken Iannillo, Arthur Gervais, Radu State |
EuroS&P | 2 |
| 2021 | Dependability Assessment of the Android OS Through Fault InjectionabstractThe reliability of mobile devices is a challenge for vendors, since the mobile software stack has significantly grown in complexity. In this article, we study how to assess the impact of faults on the quality of user experience in the Android mobile OS through fault injection. We first address the problem of identifying a realistic fault model for the Android OS, by providing to developers a set of lightweight and systematic guidelines for fault modeling. Then, we present an extensible fault injection tool (AndroFIT) to apply such fault model on actual, commercial Android devices. Finally, we present a large fault injection experimentation on three Android products from major vendors, and point out several reliability issues and opportunities for improving the Android OS. Domenico Cotroneo, Antonio Ken Iannillo, Roberto Natella, Stefano Rosiello |
IEEE Trans. Reliab. | 2 |
| 2020 | Leveraging eBPF to preserve user privacy for DNS, DoT, and DoH queriesabstractThe Domain Name System (DNS), a fundamental protocol that controls how users interact with the Internet, inadequately provides protection for user privacy. Recently, there have been advancements in the field of DNS privacy and security in the form of the DNS over TLS (DoT) and DNS over HTTPS (DoH) protocols. The advent of these protocols and recent advancements in large-scale data processing have drastically altered the threat model for DNS privacy. Users can no longer rely on traditional methods, and must instead take active steps to ensure their privacy. In this paper, we demonstrate how the extended Berkeley Packet Filter (eBPF) can assist users in maintaining their privacy by leveraging eBPF to provide privacy across standard DNS, DoH, and DoT communications. Further, we develop a method that allows users to enforce application-specific DNS servers. Our method provides users with control over their DNS network traffic and privacy without requiring changes to their applications while adding low overhead. Sean Rivera, Vijay K. Gurbani, Sofiane Lagraa, Antonio Ken Iannillo, Radu State |
ARES | 4 |
| 2020 | ROS-FM: Fast Monitoring for the Robotic Operating System(ROS)abstractIn this paper, we leverage the newly integrated extended Berkely Packet Filters (eBPF) and eXpress Data Path (XDP) to build ROS-FM, a high-performance inline network-monitoring framework for ROS. We extend the framework with a security policy enforcement tool and distributed data visualization tool for ROS1 and ROS2 systems. We compare the overhead of this framework against the generic ROS monitoring tools, and we test the policy enforcement against existing ROS penetration testing tools to evaluate their effectiveness. We find that the network monitoring framework and the associated visualization tools outperform the existing ROS monitoring tools for all robots with more than 10 running processes and that the monitoring tool uses only 4% of the overhead of the generic tools for robots with 80 processes. We further demonstrate the effectiveness of the security tool against common attacks in both ROS1 and ROS2. Sean Rivera, Antonio Ken Iannillo, Sofiane Lagraa, Clément Joly, Radu State |
ICECCS | 2 |
| 2020 | A comprehensive study on software aging across android versions and vendors
Domenico Cotroneo, Antonio Ken Iannillo, Roberto Natella, Roberto Pietrantuono |
Empir. Softw. Eng. | 2 |
| 2019 | Analyzing the Context of Bug-Fixing Changes in the OpenStack Cloud Computing PlatformabstractMany research areas in software engineering, such as mutation testing, automatic repair, fault localization, and fault injection, rely on empirical knowledge about recurring bug-fixing code changes. Previous studies in this field focus on what has been changed due to bug-fixes, such as in terms of code edit actions. However, such studies did not consider where the bug-fix change was made (i.e., the context of the change), but knowing about the context can potentially narrow the search space for many software engineering techniques (e.g., by focusing mutation only on specific parts of the software). Furthermore, most previous work on bug-fixing changes focused on C and Java projects, but there is little empirical evidence about Python software. Therefore, in this paper we perform a thorough empirical analysis of bug-fixing changes in three OpenStack projects, focusing on both the what and the where of the changes. We observed that all the recurring change patterns are not oblivious with respect to the surrounding code, but tend to occur in specific code contexts. Domenico Cotroneo, Luigi De Simone, Antonio Ken Iannillo, Roberto Natella, Stefano Rosiello, Nematollah Bidokhti |
ISSRE | 3 |
| 2019 | Evolutionary Fuzzing of Android OS Vendor System Services
Domenico Cotroneo, Antonio Ken Iannillo, Roberto Natella |
Empir. Softw. Eng. | 2 |
| 2017 | Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service CustomizationsabstractAndroid has become the most popular mobile OS, as it enables device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers.This paper presents Chizpurfle, a novel "gray-box" fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a device emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services. Antonio Ken Iannillo, Roberto Natella, Domenico Cotroneo, Cristina Nita-Rotaru |
ISSRE | 1 |
| 2016 | Software Aging Analysis of the Android Mobile OSabstractMobile devices are significantly complex, feature-rich, and heavily customized, thus they are prone to software reliability and performance issues. This paper considers the problem of software aging in Android mobile OS, which causes the device to gradually degrade in responsiveness, and to eventually fail. We present a methodology to identify factors (such as workloads and device configurations) and resource utilization metrics that are correlated with software aging. Moreover, we performed an empirical analysis of recent Android devices, finding that software aging actually affects them. The analysis pointed out processes and components of the Android OS affected by software aging, and metrics useful as indicators of software aging to schedule software rejuvenation actions. Domenico Cotroneo, Francesco Fucci, Antonio Ken Iannillo, Roberto Natella, Roberto Pietrantuono |
ISSRE | 3 |
| 2015 | Dependability evaluation and benchmarking of Network Function Virtualization InfrastructuresabstractNetwork Function Virtualization (NFV) is an emerging solution that aims at improving the flexibility, the efficiency and the manageability of networks, by leveraging virtualization and cloud computing technologies to run network appliances in software. However, the “softwarization” of network functions raises reliability concerns, as they will be exposed to faults in commodity hardware and software components. In this paper, we propose a methodology for the dependability evaluation and benchmarking of NFV Infrastructures (NFVIs), based on fault injection. We discuss the application of the methodology in the context of a virtualized IP Multimedia Subsystem (IMS), and the pitfalls in the design of a reliable NFVI. Domenico Cotroneo, Luigi De Simone, Antonio Ken Iannillo, Anna Lanzaro, Roberto Natella |
NetSoft | 3 |