VLDB 2026 Research / reviewers in the wild / expert
Danilo Giordano
dblp:160/8766
· DBLP profile ↗
27ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0002-6987-2064ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 5 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 7 since 2021Databases, data management, data science and information retrieval · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Internet usage and performance in GEO satellite networks: A large-scale study across Europe and AfricaabstractSatellite Communication (SatCom) offers internet connectivity where traditional infrastructures are too expensive to deploy. When using satellites in a geostationary orbit, the distance from Earth forces a round-trip time of at least 550 ms. Coupled with the constrained capacity of the physical link, this challenges the traditional internet access quality we are used to. In this paper, we present a complete passive characterization of the traffic carried by an operational SatCom provider. With this unique vantage point, we observe the performance of the SatCom technology, as well as the usage habits of subscribers in different countries in Europe and Africa. We highlight the implications of such technology on Internet usage and functioning, and we pinpoint technical challenges due to the CDN and DNS resolution issues, while discussing possible optimizations that the ISP could implement to improve the service offered to SatCom subscribers. We complete the characterization of the adoption and performance of newer protocols with a focus on IPv6 and QUIC. Gabriele Merlach, Daniel Perdices, Gianluca Perna, Martino Trevisan, Danilo Giordano, Marco Mellia |
Comput. Networks | 5 |
| 2026 | GLEm-Net: Unified framework for data reduction with categorical and numerical featuresabstract• Neural Network feature selection methodology for both numerical and categorical data. • Embedded feature selection provides model and feature subset in a single training. • Novel feature embedding for dealing with high-cardinality categorical features. • Validation of the methodology on several open and real industry dataset. • Comparison with several state-of-the-art feature selection methodologie. In an era of effortless data collection, the impact of machine learning — especially neural networks (NNs) — is undeniable. As datasets grow in size and complexity, efficiently handling mixed data types, including categorical and numerical features, becomes critical. Feature encoding and selection play a key role in improving NN performance, efficiency, interpretability, and generalisation. This paper presents GLEm-Net (Grouped Lasso with Embeddings Network), a novel NN-based approach that seamlessly integrates feature encoding and selection directly into the training process. GLEm-Net uses embedding layers to process categorical features with high cardinality, simplifying the model and improving generalisation. By extending the grouped Lasso regularisation to explicitly consider categorical features, GLEm-Net automatically identifies the most relevant features during training and returns them to the analyst. We evaluate GLEm-Net on open and proprietary industry datasets and compare it to state-of-the-art feature selection methodologies. Results show that GLEm-Net adapts to each dataset by allowing the NN to directly select subsets of most important features, offering on par performance with the best state-of-the-art feature selection methods, while eliminating the need for the external feature encoding and selection steps that are now incorporated in the NN training stage. Francesco De Santis, Danilo Giordano, Marco Mellia |
Knowl. Based Syst. | 2 |
| 2025 | MAD: Multicriteria Anomaly Detection of Suspicious Financial Accounts from Billions of Cash TransactionsabstractThis paper presents a real-world deployment case study on using unsupervised anomaly detection for Anti-Money Laundering (AML).Using more than 2 billion anonymized bank transactions that Intesa Sanpaolo, a primary Italian financial institution, registered over 8 months, we developed, tuned and deployed a machine learning pipeline in production.Experts from Intesa Sanpaolo validated the performance of our approach against the institution's traditional rule-based system and checked new real-world cases the system allowed them to identify.Besides increasing both precision and recall by a factor of 6 in the detection of high-risk cases, our pipeline raises 200+ additional alerts during the 8-month period, manually identified by branch managers, but missed by the rulebased system.More importantly, a manual inspection of 100 new unseen cases revealed 28 significant previously unreported cases.The pipeline, now fully deployed in Intesa Sanpaolo's Transaction Monitoring system, highlights the advantages of machine learning over traditional approaches typically adopted in this traditionally very conservative sector. Giordano Paoletti, Flavio Giobergia, Danilo Giordano, Luca Cagliero, Silvia Ronchiadin, Dario Moncalvo, Marco Mellia, Elena Baralis |
KDD (2) | 3 |
| 2025 | Towards Better Generalization and Interpretability in Unsupervised Concept-Based Models
Francesco De Santis, Philippe Bich, Gabriele Ciravegna, Pietro Barbiero, Tania Cerquitelli, Danilo Giordano |
ECML/PKDD (3) | 6 |
| 2025 | Linearly-interpretable concept embedding models for text analysisabstractAbstract Despite their success, Large-Language Models (LLMs) still face criticism due to their lack of interpretability. Traditional post-hoc interpretation methods, based on attention and gradient-based analysis, offer limited insights as they only approximate the model’s decision-making processes and have been proved to be unreliable. For this reason, Concept-Bottleneck Models (CBMs) have been lately proposed in the textual field to provide interpretable predictions based on human-understandable concepts. However, CBMs still exhibit several limitations due to their architectural constraints limiting their expressivity, to the absence of task-interpretability when employing non-linear task predictors and for requiring extensive annotations that are impractical for real-world text data. In this paper, we address these challenges by proposing a novel Linearly Interpretable Concept Embedding Model (LICEM) going beyond the current accuracy-interpretability trade-off. LICEMs classification accuracy is better than existing interpretable models and matches black-box ones. We show that the explanations provided by our models are more intervenable and causally consistent with respect to existing solutions. Finally, we show that LICEMs can be trained without requiring any concept supervision, as concepts can be automatically predicted when using an LLM backbone. Graphical abstract Francesco De Santis, Philippe Bich, Gabriele Ciravegna, Pietro Barbiero, Danilo Giordano, Tania Cerquitelli |
Mach. Learn. | 5 |
| 2024 | Monitoring Web QoE in Satellite Networks from Passive MeasurementsabstractSatellite Communication (SatCom) is the only choice to access the Internet in remote regions and is characterized by extreme latency and constrained capacity. For SatCom operators, it is thus fundamental to monitor the Quality of Experience (QoE) of subscribers, to measure their satisfaction, spot anomalies and optimize the peculiar network setup. The Web has become the primary source of Internet content, and Web browsing is the main activity of internauts. This paper addresses the challenge of monitoring Web QoE in SatCom environments, proposing a tailored system that employs a supervised approach to predict Web QoE using passive measurements. The system collects training data through Test Agents that mimic real subscribers' traffic patterns and uses them to build Machine Learning (ML) models that predict performance metrics. The findings demonstrate the feasibility of monitoring Web QoE in SatCom environments, with limitations on website applicability and temporal stability. The need for periodic data generation and the development of a general machine learning model for unseen websites remain open challenges. This research contributes to enhancing web browsing experiences in SatCom and expanding understanding of Web QoE monitoring in diverse network settings. Gianluca Perna, Martino Trevisan, Danilo Giordano, Daniel Perdices, Marco Mellia |
CCNC | 3 |
| 2024 | LogPrécis: Unleashing language models for automated malicious log analysisabstractSecurity logs are the key to understanding attacks and diagnosing vulnerabilities. Often coming in the form of text logs, their analysis remains a daunting challenge. Language Models (LMs) have demonstrated unmatched potential in understanding natural and programming languages. The question arises as to whether and how LMs could be also used to automatise the analysis of security logs. We here systematically study how to benefit from the state-of-the-art LM to support the analysis of text-like Unix shell attack logs automatically. For this, we thoroughly designed LogPrécis. LogPrécis receives as input malicious shell sessions. It then automatically identifies and assigns the attacker tactic to each portion of the session, i.e., unveiling the sequence of the attacker's goals. This creates a unique attack fingerprint. We demonstrate LogPrécis capability to support the analysis of two large datasets containing about 400,000 unique Unix shell attacks recorded in a 2-year-long honeypot deployment. LogPrécis reduces the analysis to about 3,000 unique fingerprints. Such abstraction lets us better understand attacks, extract attack prototypes, detect novelties, and track families and mutations. Overall, LogPrécis, released as open source, demonstrates the potential of adopting LMs for security analysis and paves the way for better and more responsive defence against cyberattacks. Matteo Boffa, Idilio Drago, Marco Mellia, Luca Vassio, Danilo Giordano, Rodolfo V. Valentim, Zied Ben-Houidi |
Comput. Secur. | 5 |
| 2023 | GLEm-Net: Unified Framework for Data Reduction with Categorical and Numerical FeaturesabstractIn the era of Big Data, effective data reduction through feature selection is of paramount importance for machine learning. This paper presents GLEm-Net (Grouped Lasso with Embeddings Network), a novel neural framework that seamlessly processes both categorical and numerical features to reduce the dimensionality of data while retaining as much information as possible. By integrating embedding layers, GLEm-Net effectively manages categorical features with high cardinality and compresses their information in a less dimensional space. By using a grouped Lasso penalty function in its architecture, GLEm-Net simultaneously processes categorical and numerical data, efficiently reducing high-dimensional data while preserving the essential information. We test GLEm-Net with a real-world application in an industrial environment where 6 million records exist and each is described by a mixture of 19 numerical and 7 categorical features with a strong class imbalance. A comparative analysis using state-of-the-art methods shows that despite the difficulty of building a high-performance model, GLEm-Net outperforms the other methods in both feature selection and classification, with a better balance in the selection of both numerical and categorical features. Francesco De Santis, Danilo Giordano, Marco Mellia, Alessia Damilano |
IEEE Big Data | 2 |
| 2023 | Data driven scalability and profitability analysis in free floating electric car sharing systems
Alessandro Ciociola, Danilo Giordano, Luca Vassio, Marco Mellia |
Inf. Sci. | 2 |
| 2023 | Enlightening the Darknets: Augmenting Darknet Visibility With Active ProbesabstractDarknets collect unsolicited traffic reaching unused address spaces. They provide insights into malicious activities, such as the rise of botnets and DDoS attacks. However, darknets provide a shallow view, as traffic is never responded. Here we quantify how their visibility increases by responding to traffic with interactive responders with increasing levels of interaction. We consider four deployments: Darknets, simple, vertical bound to specific ports, and, a honeypot that responds to all protocols on any port. We contrast these alternatives by analyzing the traffic attracted by each deployment and characterizing how traffic changes throughout the responder lifecycle on the darknet. We show that the deployment of responders increases the value of darknet data by revealing patterns that would otherwise be unobservable. We measure Side-Scan phenomena where once a host starts responding, it attracts traffic to other ports and neighboring addresses. uncovers attacks that darknets and would not observe, e.g. large-scale activity on non-standard ports. And we observe how quickly senders can identify and attack new responders. The “enlightened” part of a darknet brings several benefits and offers opportunities to increase the visibility of sender patterns. This information gain is worth taking advantage of, and we, therefore, recommend that organizations consider this option. Francesca Soro, Thomas Favale, Danilo Giordano, Idilio Drago, Tommaso Rescio, Marco Mellia, Zied Ben-Houidi, Dario Rossi 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Legal Entity Disambiguation for Financial Crime DetectionabstractTransaction Monitoring is one of the main labor-intensive tasks of anti-financial crime and it requires to scrutinise billions of transactions per month against possible crimes. The first step in the process is the correct identification of the involved parties. This foundational step defines the focal entities on which transaction monitoring algorithms rely to spot suspicious events. Unfortunately, the loose syntax of protocols and the free text fields of inter-banking communications make party disambiguation particularly challenging. The first step of a fully automated data-driven strategy is thus the detection of the actual entity owning or using a given account.In this paper, we leverage data-driven techniques to identify and disambiguate the owners of accounts involved in cross-border international transactions when a Financial Institution only knows a minority fraction of such parties as its own customers. For this, we propose a data science pipeline relying on hierarchical clustering to capture similarities among names of parties involved in actual transactions. We test and tune the proposed approach using a large, real-world, multi-language, proprietary dataset of actual international transactions. Our highly parallel implementation completes the identification of parties that share an account and identifies all accounts owned by a party with f-score higher than 0.8. Jacopo Fior, Thomas Favale, Luca Cagliero, Danilo Giordano, Marco Mellia, Elena Baralis, Silvia Ronchiadin, Paolo Baracco, Dario Moncalvo |
IEEE Big Data | 4 |
| 2022 | A first look at starlink performanceabstractWith new Low Earth Orbit satellite constellations such as Starlink, satellite-based Internet access is becoming an alternative to traditional fixed and wireless technologies with comparable throughputs and latencies. In this paper, we investigate the user-perceived performance of Starlink. Our measurements show that latency remains low and does not vary significantly under idle or lightly loaded links. Compared to another commercial Internet access using a geostationary satellite, Starlink achieves higher TCP throughput and provides faster web browsing. To avoid interference from performance enhancing proxies commonly used in satellite networks, we also use QUIC to assess performance under load and packet loss. Our results indicate that delay and packet loss increase slightly under load for both upload and download. François Michel, Martino Trevisan, Danilo Giordano, Olivier Bonaventure |
IMC | 3 |
| 2022 | When satellite is all you have: watching the internet from 550 msabstractSatellite Communication (SatCom) offers internet connectivity where traditional infrastructures are too expensive to deploy. When using satellites in a geostationary orbit, the distance from Earth forces a round trip time higher than 550 ms. Coupled with the limited and shared capacity of the physical link, this poses a challenge to the traditional internet access quality we are used to. Daniel Perdices, Gianluca Perna, Martino Trevisan, Danilo Giordano, Marco Mellia |
IMC | 4 |
| 2022 | A first look at HTTP/3 adoption and performance
Gianluca Perna, Martino Trevisan, Danilo Giordano, Idilio Drago |
Comput. Commun. | 3 |
| 2021 | Dissecting a data-driven prognostic pipeline: A powertrain use case
Danilo Giordano, Eliana Pastor, Flavio Giobergia, Tania Cerquitelli, Elena Baralis, Marco Mellia, Alessandra Neri, Davide Tricarico |
Expert Syst. Appl. | 1 |
| 2020 | Realistic testing of RTC applications under mobile networksabstractThe increasing usage of Real-Time Communication (RTC) applications for leisure and remote working calls for realistic and reproducible techniques to test them. They are used under very different network conditions: from high-speed broadband networks, to noisy wireless links. As such, it is of paramount importance to assess the impact of the network on users' Quality of Experience (QoE), especially when it comes to the application's mechanisms such as video quality adjustment or transmission of redundant data. In this work, we pose the basis for a system in which a target RTC application is tested in an emulated mobile environment. To this end, we leverage ERRANT, a data-driven emulator which includes 32 distinct profiles modeling mobile network performance in different conditions. As a use case, we opt for Cisco Webex, a popular RTC application. We show how variable network conditions impact the packet loss, and, in turn, trigger video quality adjustments, impairing the users' QoE. Gianluca Perna, Martino Trevisan, Danilo Giordano |
CoNEXT | 3 |
| 2020 | E-Scooter Sharing: Leveraging Open Data for System DesignabstractWith the shift toward a Mobility-as-a-Service paradigm, electric scooter sharing systems are becoming a popular transportation mean in cities. Given their novelty, we lack of consolidated approaches to study and compare different system design options. In this work, we propose a simulation approach that leverages open data to create a demand model that captures and generalises the usage of this transportation mean in a city. This calls for ingenuity to deal with coarse open data granularity. In particular, we create a flexible, data-driven demand model by using modulated Poisson processes for temporal estimation, and Kernel Density Estimation (KDE) for spatial estimation. We next use this demand model alongside a configurable e-scooter sharing simulator to compare performance of different electric scooter sharing design options, such as the impact of the number of scooters and the cost of managing their charging. We focus on the municipalities of Minneapolis and Louisville which provide large scale open data about e-scooter sharing rides. Our approach let researchers, municipalities and scooter sharing providers to follow a data driven approach to compare and improve the design of e-scooter sharing system in smart cities. Alessandro Ciociola, Michele Cocca, Danilo Giordano, Luca Vassio, Marco Mellia |
DS-RT | 3 |
| 2020 | ERRANT: Realistic emulation of radio access networks
Martino Trevisan, Ali Safari Khatouni, Danilo Giordano |
Comput. Networks | 3 |
| 2020 | Five Years at the Edge: Watching Internet From the ISP NetworkabstractThe Internet and the way people use it are constantly changing. Knowing traffic is crucial for operating the network, understanding users' needs, and ultimately improving applications. Here, we provide an in-depth longitudinal view of Internet traffic during 5 years (from 2013 to 2017). We take the point of the view of a national-wide ISP and analyze rich flow-level measurements to pinpoint and quantify changes. We observe the traffic, both from a point of view of users and services. We show that an ordinary broadband subscriber downloaded in 2017 more than twice as much as they used to do 5 years before. Bandwidth hungry video services drove this change at the beginning, while recently social messaging applications contribute to increase of data consumption. We study how protocols and service infrastructures evolve over time, highlighting events that may challenge traffic management policies. In the rush to bring servers closer and closer to users, we witness the birth of the sub-millisecond Internet, with caches located directly at ISP edges. The picture we take shows a lively Internet that always evolves and suddenly changes. To support new analyses, we make anonymized data available at https://smartdata.polito.it/five-years-at-the-edge/. Martino Trevisan, Danilo Giordano, Idilio Drago, Maurizio M. Munafò, Marco Mellia |
IEEE/ACM Trans. Netw. | 2 |
| 2019 | Data-Driven Emulation of Mobile Access NetworksabstractNetwork monitoring is fundamental to understand network evolution and behavior. However, monitoring studies have the main limitation of running new experiments when the phenomenon under analysis is over e.g., congestion. To overcome this limitation, network emulation is of vital importance for network testing and research experiments either in wired and mobile networks. When it comes to mobile networks, the variety of technical characteristics, coupled with the opaque network configurations, make realistic network emulation a challenging task. In this paper, we address this issue leveraging a large scale dataset composed of 500M network latency measurements in Mobile BroadBand networks. By using this dataset, we create 51 different network latency profiles based on the Mobile BroadBand operator, the radio access technology and signal strength. These profiles are then processed to make them compatible with the tc-netem emulation tool. Finally, we show that, despite the limitation of current tc-netem emulation tool, Generative Adversarial Networks are a promising solution used to create realistic temporal emulation. We believe that this work could be the first step toward a comprehensive data-driven network emulation. For this, we make our profiles and codes available to foster further studies in these directions. Ali Safari Khatouni, Martino Trevisan, Danilo Giordano |
CNSM | 3 |
| 2019 | A Machine Learning Application for Latency Prediction in Operational 4G Networks
Ali Safari Khatouni, Francesca Soro, Danilo Giordano |
IM | 3 |
| 2019 | Free floating electric car sharing design: Data driven optimisation
Michele Cocca, Danilo Giordano, Marco Mellia, Luca Vassio |
Pervasive Mob. Comput. | 2 |
| 2019 | Free Floating Electric Car Sharing: A Data Driven Approach for System DesignabstractIn this paper, we study the design of a free floating car sharing system based on electric vehicles. We rely on data about millions of rentals of a free floating car sharing operator based on internal combustion engine cars that we recorded in four cities. We characterize the nature of rentals, highlighting the non-stationary, and highly dynamic nature of usage patterns. Building on this data, we develop a discrete-event trace-driven simulator to study the usage of a hypothetical electric car sharing system. We use it to study the charging station placement problem, modeling different return policies, car battery charge and discharge due to trips, and the stochastic behavior of customers for plugging a car to a pole. Our data-driven approach helps car sharing providers to gauge the impact of different design solutions. Our simulations show that it is preferred to place charging stations within popular parking areas where cars are parked for short time (e.g., downtown). By smartly placing charging stations in just 8% of city zones, no trip ends with a discharged battery, i.e., all trips are feasible. Customers shall collaborate by bringing the car to a charging station when the battery level goes below a minimum threshold. This may reroute the customer to a different destination zone than the desired one; however, this happens in less than 10% of all trips. Michele Cocca, Danilo Giordano, Marco Mellia, Luca Vassio |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2018 | Five years at the edge: watching internet from the ISP networkabstractThe Internet and the way people use it are constantly changing. Knowing traffic is crucial for operating the network, understanding users' need, and ultimately improving applications. Here, we provide an in-depth longitudinal view of Internet traffic in the last 5 years (from 2013 to 2017). We take the point of the view of a national-wide ISP and analyze flow-level rich measurements to pinpoint and quantify trends. We evaluate the providers' costs in terms of traffic consumption by users and services. We show that an ordinary broadband subscriber nowadays downloads more than twice as much as they used to do 5 years ago. Bandwidth hungry video services drive this change, while social messaging applications boom (and vanish) at incredible pace. We study how protocols and service infrastructures evolve over time, highlighting unpredictable events that may hamper traffic management policies. In the rush to bring servers closer and closer to users, we witness the birth of the sub-millisecond Internet, with caches located directly at ISP edges. The picture we take shows a lively Internet that always evolves and suddenly changes. Martino Trevisan, Danilo Giordano, Idilio Drago, Marco Mellia, Maurizio M. Munafò |
CoNEXT | 2 |
| 2018 | Free Floating Electric Car Sharing in Smart Cities: Data Driven System DimensioningabstractCar sharing is a popular means of transport in smart cities. The free floating paradigm lets the customers autonomously pick and drop available cars freely, within city limits. In this work we study the different policies when designing an electric Free Floating Car Sharing (FFCS) system. This system has the need to guarantee battery charge, a time-consuming operation, for which charging stations availability becomes a key factor for the sustainability of the whole system. We harvest the data of an already operative FFCS provider, and extract information about actual users' driving patterns. We implement a trace driven simulator to replay collected users' trips and simulate car batteries consumption for different design parameters. In this work, we limit the study to a single city, Turin (Italy), where we leverage actual trips registered over 2 months. We analyse and discuss several system design alternatives: the number of charging stations, their placement, and when to force users to return cars for charge. We identify regimes where cars never discharge and users can freely drop cars anywhere, albeit they are rarely rerouted to a charging station, possibly located in a nearby area to their original destination. Surprisingly, our data shows that even few charging stations (15 or more, i.e., 6% of city areas) guarantees the system to work almost autonomously, making thus possible free floating car sharing a feasible solution with electric cars. Michele Cocca, Danilo Giordano, Marco Mellia, Luca Vassio |
SMARTCOMP | 2 |
| 2016 | BGPStream: A Software Framework for Live and Historical BGP Data Analysis
Chiara Orsini 0001, Alistair King, Danilo Giordano, Vasileios Giotsas, Alberto Dainotti |
Internet Measurement Conference | 3 |
| 2016 | SeLINA: A Self-Learning Insightful Network AnalyzerabstractUnderstanding the behavior of a network from a large scale traffic dataset is a challenging problem. Big data frameworks offer scalable algorithms to extract information from raw data, but often require a sophisticated fine-tuning and a detailed knowledge of machine learning algorithms. To streamline this process, we propose self-learning insightful network analyzer (SeLINA), a generic, self-tuning, simple tool to extract knowledge from network traffic measurements. SeLINA includes different data analytics techniques providing self-learning capabilities to state-of-the-art scalable approaches, jointly with parameter auto-selection to off-load the network expert from parameter tuning. We combine both unsupervised and supervised approaches to mine data with a scalable approach. SeLINA embeds mechanisms to check if the new data fits the model, to detect possible changes in the traffic, and to, possibly automatically, trigger model rebuilding. The result is a system that offers human-readable models of the data with minimal user intervention, supporting domain experts in extracting actionable knowledge and highlighting possibly meaningful interpretations. SeLINA's current implementation runs on Apache Spark. We tested it on large collections of real-world passive network measurements from a nationwide ISP, investigating YouTube, and P2P traffic. The experimental results confirmed the ability of SeLINA to provide insights and detect changes in the data that suggest further analyses. Daniele Apiletti, Elena Baralis, Tania Cerquitelli, Paolo Garza, Danilo Giordano, Marco Mellia, Luca Venturini |
IEEE Trans. Netw. Serv. Manag. | 5 |