VLDB 2026 Research / reviewers in the wild / expert
Stefano Iannucci
dblp:16/8326
· DBLP profile ↗
18ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0001-7485-9772ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 2 first-author · 4 since 2021Systems, architecture and hardware · 7 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-authorSecurity and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PANACEA: A Model-Based Framework for Self-Protecting Systems
Stefano Iannucci, Emiliano Casalicchio, Francesco Guerra 0001, Sara Pederzoli, Matteo Paganelli, Tommaso Caiazzi, Simone Albero |
COMPSAC | 1 |
| 2026 | From attack trees to timed stochastic games: A novel intrusion response approachabstractMost dynamic Intrusion Response Systems (IRSs) use models to characterize the attack patterns and the dynamics of the protected system. They are typically based on some mathematical framework and require a low-level modeling activity that is often difficult and error-prone, even for the experienced end-user. Furthermore, most of the model-based approaches proposed so far do not structurally include the notion of time, which is necessary to model non-instantaneous defense and attack actions. In this paper, we introduce a novel methodology for the automatic generation of IRSs based on Timed Competitive Stochastic Games from augmented Attack-Defense Trees (ADT), a formalism that is commonly used to represent attack patterns and to build IRSs based on a static mapping between attack and response. We formally and empirically prove that: (i) using a static mapping between attack and response or selecting the action with the immediate minimum cost to counter the attack without long-term planning leads to an underestimation of the defense cost; (ii) the total defense cost of a defense policy obtained with an IRS based on the proposed methodology is lower than or equal to the defense cost that can be obtained with an IRS based on static mapping; (iii) not considering time leads to an underestimation of the defense cost. We then perform experiments showing the scalability of the proposed approach in terms of planning time and memory usage. Tommaso Caiazzi, Stefano Iannucci, Valerio Marini, Matteo Foschi, Riccardo Torlone |
Comput. Secur. | 2 |
| 2026 | Introduction to the Special Issue on Artificial Intelligence for Adaptive and Autonomous Cloud/Edge Computing Systems
Gabriele Russo Russo, Valeria Cardellini, Ivana Dusparic, Stefano Iannucci |
ACM Trans. Auton. Adapt. Syst. | 4 |
| 2025 | Leveraging Semi-Supervised Learning to Reduce Labeled Data Requirements in Intrusion DetectionabstractDeep learning-based intrusion detection systems often depend on large labeled datasets and generating such data is both costly and sometimes impractical. To overcome this limitation, we propose a hybrid learning approach built on a transformer architecture. Our method integrates a self-supervised pretraining phase, where the model is trained to reconstruct noised segments of input traffic data from unlabeled sequences, with a supervised fine-tuning stage that requires only a fraction of labeled data. Our experiments demonstrate the effectiveness of this hybrid approach, achieving up to 98.8% of the performance of the supervised models using 50% of the labeled data. Index Terms—Intrusion Detection, Hybrid Learning Simone Albero, Tommaso Caiazzi, Stefano Iannucci, Paolo Merialdo, Riccardo Torlone |
COMPSAC | 3 |
| 2025 | A Novel Architecture for Cyber-Resilient Self-Protecting Systems Based on BlockchainabstractSelf-Protecting Systems (SPS) rely on an autonomic manager to detect and mitigate cyber threats. However, a major challenge in SPS design is ensuring the security of the autonomic manager itself, as its compromise could lead to complete control of the system by an attacker. In this work, we propose a cyber-resilient SPS architecture that leverages permissioned blockchain technology to enhance the trustworthiness of both Intrusion Detection (ID) and Intrusion Response (IR). The proposed architecture is technology-agnostic and adaptable to various ID and IR techniques. We implement a prototype using Quorum and a smart contract and evaluate its performance in terms of overhead and scalability. Experimental results show that the proposed architecture is technically feasible and that it introduces a minimal overhead with respect to non-smart contract-based transactions, and that it can be used on production systems with high event rates despite the inherent scalability issues deriving from the usage of the chosen blockchain technology. Tommaso Caiazzi, Stefano Iannucci, Valerio Marini, Diego Pennino, Maurizio Pizzonia, Riccardo Torlone |
COMPSAC | 2 |
| 2023 | Generating Host-Based Data from Network Traces for Intrusion DetectionabstractNetwork intrusion detection has been an active research area for the last 20 years. However, there is a limited amount of publicly available datasets, and, most importantly, most of them are either related to network traces or host-based metrics. For this reason, in this paper, a method for the generation of a hybrid dataset encompassing both network data and host-based data is proposed. We specifically focus on a case study based on the File Transfer Protocol (FTP), a well-known protocol already used with several existing datasets. The proposed methodology consists of two phases, namely: (i) the creation of a seed dataset with correlated network and host-based data and (ii) the creation of a model thereof based on a multi-layer perceptron with discretization for the prediction of host-based data given a network trace. The experimental results indicate that the accuracy of the generation is up to 98% and depends on the number of bins used to encode data and the network size. We also investigate the effects of scaling the network size and show that increasing the bin size is necessary to achieve similar results. To the best of our knowledge, this paper is the first to correlate network-based and host-based traffic. The developed source code was published with an open-source license as an additional contribution. Patrick Day, Stefano Iannucci, Ioana Banicescu |
COMPSAC | 2 |
| 2021 | Editorial for FGCS special issue: Advances in self-protecting systems
Stefano Iannucci, Emiliano Casalicchio, Byron Williams |
Future Gener. Comput. Syst. | 1 |
| 2020 | The state-of-the-art in container technologies: Application, orchestration and securityabstractSummary Containerization is a lightweight virtualization technology enabling the deployment and execution of distributed applications on cloud, edge/fog, and Internet‐of‐Things platforms. Container technologies are evolving at the speed of light, and there are many open research challenges. In this paper, an extensive literature review is presented that identifies the challenges related to the adoption of container technologies in High Performance Computing, Big Data analytics, and geo‐distributed (Edge, Fog, Internet‐of‐Things) applications. From our study, it emerges that performance, orchestration, and cyber‐security are the main issues. For each challenge, the state‐of‐the‐art solutions are then analyzed. Performance is related to the assessment of the performance footprint of containers and comparison with the footprint of virtual machines and bare metal deployments, the monitoring, the performance prediction, the I/O throughput improvement. Orchestration is related to the selection, the deployment, and the dynamic control of the configuration of multi‐container packaged applications on distributed platforms. The focus of this work is on run‐time adaptation. Cyber‐security is about container isolation, confidentiality of containerized data, and network security. From the analysis of 97 papers, it came out that the state‐of‐the‐art is more mature in the area of performance evaluation and run‐time adaptation rather than in security solutions. However, the main unsolved challenges are I/O throughput optimization, performance prediction, multilayer monitoring, isolation, and data confidentiality (at rest and in transit). Emiliano Casalicchio, Stefano Iannucci |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | Autonomic Feature Selection using Computational Intelligence
Patrick Day, Stefano Iannucci, Ioana Banicescu |
Future Gener. Comput. Syst. | 2 |
| 2020 | A hybrid model-free approach for the near-optimal intrusion response control of non-stationary systems
Stefano Iannucci, Valeria Cardellini, Ovidiu Daniel Barba, Ioana Banicescu |
Future Gener. Comput. Syst. | 1 |
| 2020 | A Model-Integrated Approach to Designing Self-Protecting SystemsabstractOne of the major trends in research on Self-Protecting Systems is to use a model of the system to be protected to predict its evolution. However, very often, devising the model requires special knowledge of mathematical frameworks, that prevents the adoption of this technique outside of the academic environment. Furthermore, some of the proposed approaches suffer from the curse of dimensionality, as their complexity is exponential in the size of the protected system. In this paper, we introduce a model-integrated approach for the design of Self-Protecting Systems, which automatically generates and solves Markov Decision Processes (MDPs) to obtain optimal defense strategies for systems under attack. MDPs are created in such a way that the size of the state space does not depend on the size of the system, but on the scope of the attack, which allows us to apply it to systems of arbitrary size. Stefano Iannucci, Sherif Abdelwahed, Andrea Montemaggio, Melissa Hannis, Leslie Leonard, Jason S. King, John Hamilton |
IEEE Trans. Software Eng. | 1 |
| 2018 | Model-Based Response Planning Strategies for Autonomic Intrusion ProtectionabstractThe continuous increase in the quantity and sophistication of cyberattacks is making it more difficult and error prone for system administrators to handle the alerts generated by intrusion detection systems (IDSs). To deal with this problem, several intrusion response systems (IRSs) have been proposed lately. IRSs extend the IDSs by providing an automatic response to the detected attack. Such a response is usually selected either with a static attack-response mapping or by quantitatively evaluating all available responses, given a set of predefined criteria. In this article, we introduce a probabilistic model-based IRS built on the Markov decision process (MDP) framework. In contrast to most existing approaches to intrusion response, the proposed IRS effectively captures the dynamics of both the defended system and the attacker and is able to compose atomic response actions to plan optimal multiobjective long-term response policies to protect the system. We evaluate the effectiveness of the proposed IRS by showing that long-term response planning always outperforms short-term planning, and we conduct a thorough performance assessment to show that the proposed IRS can be adopted to protect large distributed systems at runtime. Stefano Iannucci, Sherif Abdelwahed |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2017 | A Comparison of Graph-Based Synthetic Data Generators for Benchmarking Next-Generation Intrusion Detection SystemsabstractProperty-graphs are becoming popular for Intrusion Detection Systems (IDSs) because they allow to leverage distributed graph processing platforms in order to identify malicious network traffic patterns. However, a benchmark for studying their performance when operating on big data has not yet been reported. In general, benchmarking a system involves the execution of workloads on datasets, where both of them must be representative of the application of interest. However, few datasets containing real network traffic are openly available due to privacy concerns, which in turn could limit the scope and results of the benchmark. In this work, we build two synthetic data generators for benchmarking next generation IDSs by introducing the support for property-graphs in two well-known graph generation algorithms: Barabási-Albert and Kronecker. We run an extensive experimental evaluation using a publicly available dataset as seed for the data generation, and we show that the proposed approach is able to generate synthetic datasets with high veracity, while also exhibiting linear performance scalability. Stefano Iannucci, Hisham A. Kholidy, Amrita Dhakal Ghimire, Rui Jia, Sherif Abdelwahed, Ioana Banicescu |
CLUSTER | 1 |
| 2016 | High-Performance Intrusion Response Planning on Many-Core ArchitecturesabstractThe quantity and sophistication of cyber attacks have increased year by year, thus it is infeasible to manually process Intrusion Detection Systems (IDSs) alerts. Intrusion Response Systems (IRSs) extend IDSs by providing automatic protection mechanisms. The core of an IRS is its planning algorithm, in charge of selecting the best response action to counter the detected attacks. However, the planning algorithm has to be carefully designed and implemented in order to exhibit a low overhead and not to compromise the scalability of the protected system. In this paper we present the performance evaluation of an IRS based on Markov Decision Process (MDP), which leverages many-core co-processors. Such an IRS produces optimal long-term response policies evaluated according to a multi-criteria objective function. We show that, despite the complexity of the MDP modeling, the proposed IRS is able to protect large systems while introducing little to no overhead on the protected hosts. Stefano Iannucci, Qian Chen 0019, Sherif Abdelwahed |
ICCCN | 1 |
| 2015 | Cloud Desktop Workload: A Characterization StudyabstractToday the cloud-desktop service, or Desktop-as-a-Service (DaaS), is massively replacing Virtual Desktop Infrastructures (VDI), as confirmed by the importance of players entering the DaaS market. In this paper we study the workload of a DaaS provider, analyzing three months of real traffic and resource usage. What emerges from the study, the first on the subject at the best of our knowledge, is that the workload on CPU and disk usage are long-tail distributed (lognormal, weibull and pare to) and that the length of working sessions is exponentially distributed. These results are extremely important for: the selection of the appropriate performance model to be used in capacity planning or run-time resource provisioning, the setup of workload generators, and the definition of heuristic policies for resource provisioning. The paper provides an accurate distribution fitting for all the workload features considered and discusses the implications of results on performance analysis. Emiliano Casalicchio, Stefano Iannucci, Luca Silvestri |
IC2E | 2 |
| 2012 | MOSES: A Framework for QoS Driven Runtime Adaptation of Service-Oriented SystemsabstractArchitecting software systems according to the service-oriented paradigm and designing runtime self-adaptable systems are two relevant research areas in today's software engineering. In this paper, we address issues that lie at the intersection of these two important fields. First, we present a characterization of the problem space of self-adaptation for service-oriented systems, thus providing a frame of reference where our and other approaches can be classified. Then, we present MOSES, a methodology and a software tool implementing it to support QoS-driven adaptation of a service-oriented system. It works in a specific region of the identified problem space, corresponding to the scenario where a service-oriented system architected as a composite service needs to sustain a traffic of requests generated by several users. MOSES integrates within a unified framework different adaptation mechanisms. In this way it achieves greater flexibility in facing various operating environments and the possibly conflicting QoS requirements of several concurrent users. Experimental results obtained with a prototype implementation of MOSES show the effectiveness of the proposed approach. Valeria Cardellini, Emiliano Casalicchio, Vincenzo Grassi, Stefano Iannucci, Francesco Lo Presti, Raffaela Mirandola |
IEEE Trans. Software Eng. | 4 |
| 2010 | A Scalable and Highly Available Brokering Service for SLA-Based Composite Services
Alessandro Bellucci, Valeria Cardellini, Valerio Di Valerio, Stefano Iannucci |
ICSOC | 4 |
| 2010 | Designing a Broker for QoS-driven Runtime Adaptation of SOA ApplicationsabstractOne of the major current trends in service-oriented systems is the emphasis given to the need of introducing runtime adaptation features, so that the system can meet its QoS requirements in a volatile operating environment. In this paper we present the design and implementation of a service broker that supports the QoS-driven runtime adaptation of SOA applications offered as composite services to users. We describe the functionalities provided by the broker components and present their design and implementation according to two different versions we have developed and that are both based on open source products. The components of the first version have been developed in Java as Web services, while the second version takes advantage of OpenESB. Since the broker needs to sustain a traffic of requests generated by several concurrent users, we also present the replicated architectures of the two broker versions. We discuss the design tradeoffs and the lesson we have learned in developing the broker. Valeria Cardellini, Stefano Iannucci |
ICWS | 2 |