Jacopo Cortellazzi

dblp:184/5990 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0003-1421-2058ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Intriguing Properties of Adversarial ML Attacks in the Problem Space [Extended Version]
abstract
Recent research efforts on adversarial machine learning (ML) have investigated problem-space attacks, focusing on the generation of real evasive objects in domains where, unlike images, there is no clear inverse mapping to the feature space (e.g., software). However, the design, comparison, and real-world implications of problem-space attacks remain underexplored. This article makes three major contributions. Firstly, we propose a general formalization for adversarial ML evasion attacks in the problem-space, which includes the definition of a comprehensive set of constraints on available transformations, preserved semantics, absent artifacts, and plausibility. We shed light on the relationship between feature space and problem space, and we introduce the concept of side-effect features as the by-product of the inverse feature-mapping problem. This enables us to define and prove necessary and sufficient conditions for the existence of problem-space attacks. Secondly, building on our general formalization, we propose a novel problem-space attack on Android malware that overcomes past limitations in terms of semantics and artifacts. We have tested our approach on a dataset with 150K Android apps from 2016 and 2018 which show the practical feasibility of evading a state-of-the-art malware classifier along with its hardened version. Thirdly, we explore the effectiveness of adversarial training as a possible approach to enforce robustness against adversarial samples, evaluating its effectiveness on the considered machine learning models under different scenarios. Our results demonstrate that “adversarial-malware as a service” is a realistic threat, as we automatically generate thousands of realistic and inconspicuous adversarial applications at scale, where on average it takes only a few minutes to generate an adversarial instance.
Jacopo Cortellazzi, Erwin Quiring, Daniel Arp, Feargus Pendlebury, Fabio Pierazzi, Lorenzo Cavallaro
ACM Trans. Priv. Secur.1
2024 How to Train your Antivirus: RL-based Hardening through the Problem Space
abstract
ML-based malware detection on dynamic analysis reports is vulnerable to both evasion and spurious correlations. In this work, we investigate a specific ML architecture employed in the pipeline of a widely-known commercial antivirus, with the goal to harden it against adversarial malware. Adversarial training, the most reliable defensive technique that can confer empirical robustness, is not applicable out of the box in this domain, for the principal reason that gradient-based perturbations rarely map back to feasible problem-space programs. We introduce a novel Reinforcement Learning approach for constructing adversarial examples, a constituent part of adversarially training a model against evasion. Our approach comes with multiple advantages. It performs modifications that are feasible in the problem-space, and only those; thus it circumvents the inverse mapping problem. It also makes it possible to provide theoretical guarantees on the robustness of the model against a well-defined set of adversarial capabilities. Our empirical exploration validates our theoretical insights, where we can consistently reach 0% Attack Success Rate after a few adversarial retraining iterations.
Ilias Tsingenopoulos, Jacopo Cortellazzi, Branislav Bosanský, Simone Aonzo, Davy Preuveneers, Wouter Joosen, Fabio Pierazzi, Lorenzo Cavallaro
RAID2
2023 Inclusive Group Work Assessment for Cybersecurity
abstract
This poster presents an ongoing study that takes a diverse and inclusive approach to designing a practical group work assessment for an undergraduate cybersecurity course delivered to third year university cohorts. Students were given the choice to either work individually or as part of a group to complete the assignment in virtual laboratories. The study evaluates how student grouping preferences change when the teaching structure adapts in response to the the Covid-19 pandemic and how grouping preference impacts upon academic performance. Students reflected positively on the assignment and demonstrated a preference for treating group information as private. No disputes regarding group marks or contributions from different group members arose despite the number of groups involved. Students have taken responsibility for their choices and have accepted the outcomes of their teamwork.
Hannan Xiao, Joseph Spring, Ievgeniia Kuzminykh, Jacopo Cortellazzi
ITiCSE (2)4
2023 Jigsaw Puzzle: Selective Backdoor Attack to Subvert Malware Classifiers
abstract
Malware classifiers are subject to training-time exploitation due to the need to regularly retrain using samples collected from the wild. Recent work has demonstrated the feasibility of backdoor attacks against malware classifiers, and yet the stealthiness of such attacks is not well understood. In this paper, we focus on Android malware classifiers and investigate backdoor attacks under the clean-label setting (i.e., attackers do not have complete control over the training process or the labeling of poisoned data). Empirically, we show that existing backdoor attacks against malware classifiers are still detectable by recent defenses such as MNTD. To improve stealthiness, we propose a new attack, Jigsaw Puzzle (JP), based on the key observation that malware authors have little to no incentive to protect any other authors’ malware but their own. As such, Jigsaw Puzzle learns a trigger to complement the latent patterns of the malware author’s samples, and activates the backdoor only when the trigger and the latent pattern are pieced together in a sample. We further focus on realizable triggers in the problem space (e.g., software code) using bytecode gadgets broadly harvested from benign software. Our evaluation confirms that Jigsaw Puzzle is effective as a backdoor, remains stealthy against state-of-the-art defenses, and is a threat in realistic settings that depart from reasoning about feature-space-only attacks. We conclude by exploring promising approaches to improve backdoor defenses.
Zhi Chen 0028, Jacopo Cortellazzi, Feargus Pendlebury, Kevin Tu, Fabio Pierazzi, Lorenzo Cavallaro, Gang Wang 0011
SP3
2020 Intriguing Properties of Adversarial ML Attacks in the Problem Space
abstract
Recent research efforts on adversarial ML have investigated problem-space attacks, focusing on the generation of real evasive objects in domains where, unlike images, there is no clear inverse mapping to the feature space (e.g., software). However, the design, comparison, and real-world implications of problem-space attacks remain underexplored.This paper makes two major contributions. First, we propose a novel formalization for adversarial ML evasion attacks in the problem-space, which includes the definition of a comprehensive set of constraints on available transformations, preserved semantics, robustness to preprocessing, and plausibility. We shed light on the relationship between feature space and problem space, and we introduce the concept of side-effect features as the byproduct of the inverse feature-mapping problem. This enables us to define and prove necessary and sufficient conditions for the existence of problem-space attacks. We further demonstrate the expressive power of our formalization by using it to describe several attacks from related literature across different domains.Second, building on our formalization, we propose a novel problem-space attack on Android malware that overcomes past limitations. Experiments on a dataset with 170K Android apps from 2017 and 2018 show the practical feasibility of evading a state-of-the-art malware classifier along with its hardened version. Our results demonstrate that "adversarial-malware as a service" is a realistic threat, as we automatically generate thousands of realistic and inconspicuous adversarial applications at scale, where on average it takes only a few minutes to generate an adversarial app. Yet, out of the 1600+ papers on adversarial ML published in the past six years, roughly 40 focus on malware [15]-and many remain only in the feature space.Our formalization of problem-space attacks paves the way to more principled research in this domain. We responsibly release the code and dataset of our novel attack to other researchers, to encourage future work on defenses in the problem space.
Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, Lorenzo Cavallaro
SP3
2016 Crowdsensing and proximity services for impaired mobility
abstract
New sensors embedded into modern smartphones has led into a new data collection prospective in which people directly collect all the sensitive data. This feature has found different applications, in particular in the Smart Cities area, in order to establish dynamic communications between the citizens and the city government. This category of application is nestled into the Mobile Crowd Sensing (MCS) application group, due to their final purpose of sharing sensing data to an open platform that includes a huge number of people. This paper presents an extension of the general-purpose ParticipAct platform, a MCS application developed by the University of Bologna, focused on the needs of people with impaired mobility. The goal is specializing ParticipAct to enable a crowdsourcing platform that guarantees a solid support for their lifetime allowing reviewing and sharing opinions regarding public and private places and architectonic barriers of a city area. Showed results confirm the effectiveness of the developed application in terms of both its viability via integration with existing and widely diffused Geographical Information Systems (GIS), and its feasibility in terms of system and user-perceived performances.
Jacopo Cortellazzi, Luca Foschini 0001, Carlos Roberto De Rolt, Antonio Corradi, Carlos Augusto Alperstedt Neto, Graziela Dias Alperstedt
ISCC1