VLDB 2026 Research / reviewers in the wild / expert
Antonio Nappa
dblp:20/8280
· DBLP profile ↗
19ranked-venue papers
8as first author
9since 2021 · last 2026
0000-0002-2692-7336ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 7 first-author · 3 since 2021Computer networks · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Robust concept drift handling in dynamic industrial systems: A multi-objective optimization approachabstractMachine learning (ML) systems are increasingly integral to modern industrial environments, yet their performance is susceptible to “concept drift”—changes in data distribution or relationships over time—which can degrade predictive accuracy and operational efficiency. Conventional approaches often rely on periodic model retraining or drift detectors with fixed parameters, which can lead to suboptimal adaptation, frequent false alarms, or missed drifts. Moreover, the interplay between concept drift detection and retraining strategies is often overlooked in the current literature. Through a comprehensive multi-objective optimization analysis of drift detector parameters and retraining strategies, this work quantifies critical trade-offs and parameter importance across diverse drift types (abrupt, gradual, recurring, local, global) for classification and regression tasks. The analysis is grounded in both synthetic benchmark datasets and a real-world industrial case study from automotive component manufacturing. Our findings reveal that abrupt drifts demand distinct sensitivity parameters (e.g., low delta, lambda) and immediate retraining, while gradual drifts prioritize adaptation timing (e.g., high retraining lag) and larger data windows. Localized drifts further necessitate extended contextual windows. Results demonstrate that configurations optimized via our analysis significantly outperform defaults, improving detection timeliness and adaptation effectiveness in synthetic benchmarks as well as the industrial use case. The study provides practitioners with actionable, evidence-based and comprehensive guidelines for tailoring drift-handling mechanisms to specific operational constraints and drift characteristics, ultimately enhancing the robustness of industrial ML systems. Asier Diaz-Iglesias, Antonio Nappa, Carmine Delle Femine, Piero Rivera, Jorge Poyatos, Guillermo Gomez, Efrén Honrubia, Jan L. Bruse |
Knowl. Based Syst. | 2 |
| 2025 | Privacy-Preserving Clusterized Federated Learning Framework for Energy ForecastingabstractFederated Learning enables collaborative model training across distributed clients without exposing raw data, offering clear advantages for privacy and scalability. However existing approaches often fail to provide comprehensive protection across the entire lifecycle and struggle with client heterogeneity. This paper introduces a multi-stage privacy-preserving Federated Learning framework for short-term forecasting. On the privacy side, it integrates a threshold-based secret sharing protocol with mix-net–inspired anonymization. On the aggregation side, a lightweight clustering strategy that groups clients with similar consumption patterns is proposed, improving accuracy while preserving privacy. Real industrial and residential datasets have been used for validation purpose. Amaia Gil-Lerchundi, Lucía Muñoz-Solanas, Antonio Nappa, Izar Azpiroz |
NCA | 3 |
| 2024 | An Autoencoder-Based Approach for Anomaly Detection of Machining Processes Using Acoustic Emission Signals
Antonio Nappa, Juan Luis Ferrando Chacón, Izar Azpiroz, Pedro José Arrazola |
EANN | 1 |
| 2024 | Adaptation of Diffusion Models for Remote Sensing ImageryabstractThe present contribution focuses on applying Denoising Diffusion Probabilistic Models to Remote Sensing image classification, generation and super-resolution. Diffusion models are enhanced, including an attention block embedded in a UNet architecture is used to generate images to complement the EuroSAT data set. Furthermore, models with the same architecture super-resolve sentinel-2 optical images. The results indicate that diffusion models with attention can provide a promising methodological path for applications such as estimating the NDVI images most probably associated with given electro-optical and SAR acquisitions thereby overcoming limitations in observability due to cloud cover or solar illumination. Adriano Ettari, Antonio Nappa, Marco Quartulli, Izar Azpiroz, Giuseppe Longo |
IGARSS | 2 |
| 2022 | Scramblesuit: An effective timing side-channels framework for malware sandbox evasionabstractOnline malware scanners are one of the best weapons in the arsenal of cybersecurity companies and researchers. A fundamental part of such systems is the sandbox that provides an instrumented and isolated environment (virtualized or emulated) for any user to upload and run unknown artifacts and identify potentially malicious behaviors. The provided API and the wealth of information in the reports produced by these services have also helped attackers test the efficacy of numerous techniques to make malware hard to detect. The most common technique used by malware for evading the analysis system is to monitor the execution environment, detect the presence of any debugging artifacts, and hide its malicious behavior if needed. This is usually achieved by looking for signals suggesting that the execution environment does not belong to a native machine, such as specific memory patterns or behavioral traits of certain CPU instructions. In this paper, we show how an attacker can evade detection on such analysis services by incorporating a Proof-of-Work (PoW) algorithm into a malware sample. Specifically, we leverage the asymptotic behavior of the computational cost of PoW algorithms when they run on some classes of hardware platforms to effectively detect a non bare-metal environment of the malware sandbox analyzer. To prove the validity of this intuition, we design and implement Scramblesuit, a framework to automatically (i) implement sandbox detection strategies, and (ii) embed a test evasion program into an arbitrary malware sample. We perform a comprehensive evaluation of Scramblesuit across a wide range of: 1) COTS architectures (ARM, Apple M1, i9, i7 and Xeon), 2) malware families, and 3) online sandboxes (JoeSandbox, Sysinternals, C2AE, Zenbox, Dr.Web VX Cube, Tencent HABO, YOMI Hunter). Our empirical evaluation shows that a PoW-based evasion technique is hard to fingerprint, and reduces existing malware detection rate by a factor of 10. The only plausible counter-measure to Scramblesuit is to rely on bare-metal online malware scanners, which is unrealistic given they currently handle millions of daily submissions. Antonio Nappa, Aaron Úbeda-Portugués, Panagiotis Papadopoulos, Matteo Varvello, Juan Tapiador, Andrea Lanzi |
J. Comput. Secur. | 1 |
| 2021 | PoW-How: An Enduring Timing Side-Channel to Evade Online Malware Sandboxes
Antonio Nappa, Panagiotis Papadopoulos, Matteo Varvello, Daniel Aceituno Gomez, Juan Tapiador, Andrea Lanzi |
ESORICS (1) | 1 |
| 2021 | VPN-Zero: A Privacy-Preserving Decentralized Virtual Private NetworkabstractDistributed Virtual Private Networks (dVPNs) are new solutions aiming to solve the trust-privacy concern of a VPN's central authority by leveraging a distributed architecture. In this paper, we discuss the requirements of a successful dVPN system and we present VPN-Zero: a dVPN system with strong privacy guarantees that provides traffic accounting and has minimal performance impact on its users. VPN-Zero guarantees that a dVPN node only carries traffic it has “allowlisted”, without revealing its allowlist or knowing the traffic it tunnels. This is achieved via three main innovations: (a) an attestation mechanism which leverages TLS to certify a user visit to a specific domain, (b) a zero-knowledge proof to certify that some incoming traffic is authorized (e.g., falls in a node's allowlist, without disclosing the target domain), and (c) a dynamic chain of VPN tunnels to both increase privacy and guarantee service continuation while traffic certification is in place. The paper demonstrates VPN-Zero functioning when integrated with two production systems: BitTorrent's Distributed Hash Table and ProtonVPN. Early evaluation results show that the median setup time of VPN-Zero is about 10 seconds. Matteo Varvello, Iñigo Querejeta-Azurmendi, Antonio Nappa, Panagiotis Papadopoulos, Gonçalo Pestana, Benjamin Livshits |
Networking | 3 |
| 2021 | ZKSENSE: A Friction-less Privacy-Preserving Human Attestation Mechanism for Mobile Devices
Iñigo Querejeta-Azurmendi, Panagiotis Papadopoulos, Matteo Varvello, Antonio Nappa, Jiexin Zhang 0001, Benjamin Livshits |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | Blocklist Babel: On the Transparency and Dynamics of Open Source BlocklistingabstractBlocklists constitute a widely-used Internet security mechanism to filter undesired network traffic based on IP/domain reputation and behavior. Many blocklists are distributed in open source form by threat intelligence providers who aggregate and process input from their own sensors, but also from third-party feeds or providers. Despite their wide adoption, many open-source blocklist providers lack clear documentation about their structure, curation process, contents, dynamics, and inter-relationships with other providers. In this paper, we perform a transparency and content analysis of 2,093 free and open source blocklists with the aim of exploring those questions. To that end, we perform a longitudinal 6-month crawling campaign yielding more than 13.5M unique records. This allows us to shed light on their nature, dynamics, inter-provider relationships, and transparency. Specifically, we discuss how the lack of consensus on distribution formats, blocklist labeling taxonomy, content focus, and temporal dynamics creates a complex ecosystem that complicates their combined crawling, aggregation and use. We also provide observations regarding their generally low overlap as well as acute differences in terms of liveness (i.e., how frequently records get indexed and removed from the list) and the lack of documentation about their data collection processes, nature and intended purpose. We conclude the paper with recommendations in terms of transparency, accountability, and standardization. Álvaro Feal, Pelayo Vallina, Julien Gamba, Sergio Pastrana, Antonio Nappa, Oliver Hohlfeld, Narseo Vallina-Rodriguez, Juan Tapiador |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2016 | RevProbe: detecting silent reverse proxies in malicious server infrastructures
Antonio Nappa, Rana Faisal Munir, Irfan Khan Tanoli, Christian Kreibich, Juan Caballero |
ACSAC | 1 |
| 2015 | The Attack of the Clones: A Study of the Impact of Shared Code on Vulnerability PatchingabstractVulnerability exploits remain an important mechanism for malware delivery, despite efforts to speed up the creation of patches and improvements in software updating mechanisms. Vulnerabilities in client applications (e.g., Browsers, multimedia players, document readers and editors) are often exploited in spear phishing attacks and are difficult to characterize using network vulnerability scanners. Analyzing their lifecycle requires observing the deployment of patches on hosts around the world. Using data collected over 5 years on 8.4 million hosts, available through Symantec's WINE platform, we present the first systematic study of patch deployment in client-side vulnerabilities. We analyze the patch deployment process of 1,593 vulnerabilities from 10 popular client applications, and we identify several new threats presented by multiple installations of the same program and by shared libraries distributed with several applications. For the 80 vulnerabilities in our dataset that affect code shared by two applications, the time between patch releases in the different applications is up to 118 days (with a median of 11 days). Furthermore, as the patching rates differ considerably among applications, many hosts patch the vulnerability in one application but not in the other one. We demonstrate two novel attacks that enable exploitation by invoking old versions of applications that are used infrequently, but remain installed. We also find that the median fraction of vulnerable hosts patched when exploits are released is at most 14%. Finally, we show that the patching rate is affected by user-specific and application-specific factors, for example, hosts belonging to security analysts and applications with an automated updating mechanism have significantly lower median times to patch. Antonio Nappa, Leyla Bilge, Juan Caballero, Tudor Dumitras |
IEEE Symposium on Security and Privacy | 1 |
| 2015 | Ad Injection at Scale: Assessing Deceptive Advertisement ModificationsabstractToday, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Google -- tens of millions of users around the globe. Injected ads arrive on a client's machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved. Kurt Thomas, Elie Bursztein, Chris Grier, Grant Ho, Nav Jagpal, Alexandros Kapravelos, Damon McCoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab |
IEEE Symposium on Security and Privacy | 8 |
| 2014 | AUTOPROBE: Towards Automatic Active Malicious Server Probing Using Dynamic Binary AnalysisabstractMalware continues to be one of the major threats to Internet security. In the battle against cybercriminals, accurately identifying the underlying malicious server infrastructure (e.g., C&C servers for botnet command and control) is of vital importance. Most existing passive monitoring approaches cannot keep up with the highly dynamic, ever-evolving malware server infrastructure. As an effective complementary technique, active probing has recently attracted attention due to its high accuracy, efficiency, and scalability (even to the Internet level). In this paper, we propose Autoprobe, a novel system to automatically generate effective and efficient fingerprints of remote malicious servers. Autoprobe addresses two fundamental limitations of existing active probing approaches: it supports pull-based C&C protocols, used by the majority of malware, and it generates fingerprints even in the common case when C&C servers are not alive during fingerprint generation. Using real-world malware samples we show that Autoprobe can successfully generate accurate C&C server fingerprints through novel applications of dynamic binary analysis techniques. By conducting Internet-scale active probing, we show that Autoprobe can successfully uncover hundreds of malicious servers on the Internet, many of them unknown to existing blacklists. We believe Autoprobe is a great complement to existing defenses, and can play a unique role in the battle against cybercriminals. Zhaoyan Xu, Antonio Nappa, Robert Baykov, Guangliang Yang 0001, Juan Caballero, Guofei Gu |
CCS | 2 |
| 2014 | WhoWas: A Platform for Measuring Web Deployments on IaaS CloudsabstractPublic infrastructure-as-a-service (IaaS) clouds such as Amazon EC2 and Microsoft Azure host an increasing number of web services. The dynamic, pay-as-you-go nature of modern IaaS systems enable web services to scale up or down with demand, and only pay for the resources they need. We are unaware, however, of any studies reporting on measurements of the patterns of usage over time in IaaS clouds as seen in practice. We fill this gap, offering a measurement platform that we call WhoWas. Using active, but lightweight, probing, it enables associating web content to public IP addresses on a day-by-day basis. We exercise WhoWas to provide the first measurement study of churn rates in EC2 and Azure, the efficacy of IP blacklists for malicious activity in clouds, the rate of adoption of new web software by public cloud customers, and more. Liang Wang 0023, Antonio Nappa, Juan Caballero, Thomas Ristenpart, Aditya Akella |
Internet Measurement Conference | 2 |
| 2014 | CyberProbe: Towards Internet-Scale Active Detection of Malicious Servers
Antonio Nappa, Zhaoyan Xu, M. Zubair Rafique, Juan Caballero, Guofei Gu |
NDSS | 1 |
| 2013 | Driving in the Cloud: An Analysis of Drive-by Download Operations and Abuse Reporting
Antonio Nappa, M. Zubair Rafique, Juan Caballero |
DIMVA | 1 |
| 2012 | Manufacturing compromise: the emergence of exploit-as-a-serviceabstractWe investigate the emergence of the exploit-as-a-service model for driveby browser compromise. In this regime, attackers pay for an exploit kit or service to do the "dirty work" of exploiting a victim's browser, decoupling the complexities of browser and plugin vulnerabilities from the challenges of generating traffic to a website under the attacker's control. Upon a successful exploit, these kits load and execute a binary provided by the attacker, effectively transferring control of a victim's machine to the attacker. Chris Grier, Lucas Ballard, Juan Caballero, Neha Chachra, Christian Dietrich 0005, Kirill Levchenko, Panayiotis Mavrommatis, Damon McCoy, Antonio Nappa, Andreas Pitsillidis, Niels Provos, M. Zubair Rafique, Moheeb Abu Rajab, Christian Rossow, Kurt Thomas, Vern Paxson, Stefan Savage, Geoffrey M. Voelker |
CCS | 9 |
| 2012 | Undangle: early detection of dangling pointers in use-after-free and double-free vulnerabilitiesabstractUse-after-free vulnerabilities are rapidly growing in popularity, especially for exploiting web browsers. Use-after-free (and double-free) vulnerabilities are caused by a program operating on a dangling pointer. In this work we propose early detection, a novel runtime approach for finding and diagnosing use-after-free and double-free vulnerabilities. While previous work focuses on the creation of the vulnerability (i.e., the use of a dangling pointer), early detection shifts the focus to the creation of the dangling pointer(s) at the root of the vulnerability. Early detection increases the effectiveness of testing by identifying unsafe dangling pointers in executions where they are created but not used. It also accelerates vulnerability analysis and minimizes the risk of incomplete fixes, by automatically collecting information about all dangling pointers involved in the vulnerability. We implement our early detection technique in a tool called Undangle. We evaluate Undangle for vulnerability analysis on 8 real-world vulnerabilities. The analysis uncovers that two separate vulnerabilities in Firefox had a common root cause and that their patches did not completely fix the underlying bug. We also evaluate Undangle for testing on the Firefox web browser identifying a potential vulnerability. Juan Caballero, Gustavo Grieco, Mark Marron, Antonio Nappa |
ISSTA | 4 |
| 2010 | Take a Deep Breath: A Stealthy, Resilient and Cost-Effective Botnet Using Skype
Antonio Nappa, Aristide Fattori, Marco Balduzzi, Matteo Dell'Amico, Lorenzo Cavallaro |
DIMVA | 1 |