VLDB 2026 Research / reviewers in the wild / expert
Giuseppe Garofalo
dblp:201/0393
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2024
0000-0003-2542-1680ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Novel Evaluation Framework for Biometric Security: Assessing Guessing Difficulty as a MetricabstractBiometric authentication systems have traditionally relied on the False Match Rate (FMR) to evaluate security against impersonation threats. However, this metric alone is insufficient for assessing vulnerabilities to statistical attacks because it cannot account for the non-uniformity of mismatches and atypical inputs that adversaries may manipulate. To address this issue, we propose a new evaluation framework that overcomes these limitations. The framework includes an estimate of the effective key space of biometrics and metrics that consider non-uniformity in the biometric embedding space. Our findings demonstrate that our framework provides a nuanced understanding of biometric security. Moreover, optimizing for the proposed metric leads to better security against statistical attacks than optimizing the FMR. Furthermore, the framework provides a comparative security analysis with traditional methods like passwords and PIN codes. It also quantifies the impact on security when adversaries partially know their victims, e.g., demographics. Tim Van hamme, Giuseppe Garofalo, Enrique Argones-Rúa, Davy Preuveneers, Wouter Joosen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Masterkey attacks against free-text keystroke dynamics and security implications of demographic factorsabstractThis paper presents and systematically evaluates the first masterkey attack against free-text keystroke dynamics. A masterkey is a typing sequence that matches, hence successfully impersonates, a large part of the population. Therefore, masterkeys are effective tools for an adversary who aims to impersonate someone without knowledge of their typing behavior. On top of the attack itself, we present a new unifying evaluation framework for masterkey attacks that allow for the comparison with knowledge-based authentication factors. In other words, we unify the evaluation of password security with that of masterkey attacks and demonstrate that typing biometrics is approximately 20 times less secure than passwords and approximately two times less secure than a 4-digit pin. Lastly, we study the effect of demographics on typing biometrics, which, among others, provides novel insights into the effect of being a well-versed typist on security. Tim Van hamme, Giuseppe Garofalo, Davy Preuveneers, Wouter Joosen |
EuroS&P | 2 |
| 2022 | PIVOT: Private and Effective Contact TracingabstractWe propose, design, and evaluate PIVOT, a privacy-enhancing and effective contact tracing solution that aims to strike a balance between utility and privacy: one that does not collect sensitive information yet allowing effective tracing and notifying the close contacts of diagnosed users. PIVOT requires a considerably low degree of trust in the entities involved compared to centralized alternatives while retaining the necessary utility. To protect users’ privacy, it uses local proximity tracing based on broadcasting and recording constantly changing anonymous public keys via short-range communication. These public keys are used to establish a shared secret key between two people in close contact. The three keys (i.e., the two public keys and the established shared key) are then used to generate two unique per-user-per-contact hashes: one for infection registration and one for exposure score query. These hashes are never revealed to the public. To improve utility, user exposure score computation is performed centrally, which provides health authorities with minimal, yet insightful and actionable data. Data minimization is achieved by the use of per-user-per-contact hashes and by enforcing role separation: the health authority act as a mixing node, while the matching between reported and queried hashes is outsourced to a third entity, an independent matching service (MS). This separation ensures that out-of-scope information, such as users’ social interactions, is hidden from the health authorities, whereas the MS does not learn users’ sensitive information. To sustain our claims, we conduct a practical evaluation that encompasses anonymity guarantees and energy requirements. Giuseppe Garofalo, Tim Van hamme, Davy Preuveneers, Wouter Joosen, Aysajan Abidin, Mustafa A. Mustafa |
IEEE Internet Things J. | 1 |