Matteo Cardaioli

dblp:205/3630 · DBLP profile ↗
← Back
12ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0002-1482-3513ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2025 Your PIN is Mine: Uncovering Users' PINs at Point of Sale Machines
abstract
Point of Sale (PoS) machines have become extremely popular recently. In many economies, most transactions occur using them. Although PoS technology is evolving, PINs are still heavily used. In this paper, we perform a large-scale study to understand how difficult it is to uncover user PINs at PoS, even when the users cover the pad with their hands. Our study involves 142 participants, two types of PoS, and around 13,800 PINs. We develop machine learning techniques to infer PoS PINs by using hidden cameras. Our results show that uncovering PINs in PoS is more complex than in other cases where a user PIN is used, e.g., ATMs, because of the small pad area of PoS. Nevertheless, we could achieve more than 50% Top-3 accuracy for 4-digit PINs and 45% Top-3 accuracy for 5-digit PINs, even when the PIN is covered by the user's hand. We comment on the impact of the camera's position and PoS on the successful inference of the user's PINs. We also comment on the hardness of inferring PINs depending on the physical distance of digits and recommend what are good practices to generate PINs and cover PoS to make PIN inference difficult.
Stefano Cecconello, Matteo Cardaioli, Luca Pasa, Stjepan Picek, Georgios Smaragdakis
IEEE Trans. Dependable Secur. Comput.2
2023 BLUFADER: Blurred face detection & recognition for privacy-friendly continuous authentication
abstract
Authentication and de-authentication phases should occur at the beginning and end of secure user sessions, respectively. A secure session requires the user to pass the former, but the latter is often underestimated or ignored. Unattended or dangling sessions expose users to well-known Lunchtime Attacks. To mitigate this threat, researchers focused on automated de-authentication systems, either as a stand-alone mechanism or as a result of continuous authentication failures. Unfortunately, no single approach offers security, privacy, and usability. Face-recognition methods, for example, may be suitable for security and usability, but they violate user privacy by continuously recording their actions and surroundings. In this work, we propose BLUFADER, a novel continuous authentication system that takes advantage of blurred face detection and recognition to fast, secure, and transparent de-authenticate users, preserving their privacy. We obfuscate a webcam with a physical blur layer and use deep learning algorithms to perform face detection and recognition continuously. To evaluate BLUFADER’s practicality, we collected two datasets formed by 30 recruited subjects (users) and thousands of physically blurred celebrity photos. The de-authentication system was trained and evaluated using the former, while the latter was used to appraise the privacy and increase variance at training time. To guarantee the privacy-preserving effectiveness of the selected physical blurring filter, we show that state-of-the-art deblurring models are not able to revert our physical blur. Further, we demonstrate that our approach outperforms state-of-the-art methods in detecting blurred faces, achieving up to 95% accuracy. Moreover, BLUFADER effectively de-authenticates users up to 100% accuracy in under 3 seconds, while satisfying security, privacy, and usability requirements. Last, our continuous authentication face recognition module based on Siamese Neural Network preventively protect users from adversarial attacks, enhancing the overall system security.
Matteo Cardaioli, Mauro Conti, Gabriele Orazi, Pier Paolo Tricomi, Gene Tsudik
Pervasive Mob. Comput.1
2022 We Can Hear Your PIN Drop: An Acoustic Side-Channel Attack on ATM PIN Pads
Kiran S. Balagani, Matteo Cardaioli, Stefano Cecconello, Mauro Conti, Gene Tsudik
ESORICS (1)2
2022 For Your Voice Only: Exploiting Side Channels in Voice Messaging for Environment Detection
Matteo Cardaioli, Mauro Conti, Arpita Ravindranath
ESORICS (3)1
2022 Face the Truth: Interpretable Emotion Genuineness Detection
abstract
The identification of emotions conveyed by faces as genuine or not is a topic under-explored. While some controversial insights are available for happiness (where genuine happiness is supposed to create crow's feet around the eyes), nothing is known regarding other emotions. This topic is important as human beings are known to perform around the chance level to identify genuine emotions. It is thus pivotal to identify the relevant features for the correct identification of a facial emotion as genuine. To this aim, we capitalized on explainable artificial intelligence (XAI), characterized by a superior ability to detect subtle patterns in the data. Two different XAI models were created and applied to a dataset including 50 participants displaying both genuine and not genuine emotions. Results revealed that ML models achieved high accuracies in genuineness discrimination (78 % of average) while being robust and interpretable. The robustness of the results, ensured by their stability across different models and experimental conditions, is critical to improving the generalizability of the results. Our XAI algorithms provided interpretable results as they correctly identified facial muscle movements that are critical for the classification of emotions as genuine or fake.
Matteo Cardaioli, Alessio Miolla, Mauro Conti, Giuseppe Sartori, Merylin Monaro, Cristina Scarpazza, Nicolò Navarin
IJCNN1
2022 Privacy-Friendly De-authentication with BLUFADE: Blurred Face Detection
abstract
Ideally, secure user sessions should start and end with authentication and de-authentication phases, respectively. While the user must pass the former to start a secure session, the latter’s importance is often ignored or underestimated. Dangling or unattended sessions expose users to well-known Lunchtime Attacks. To mitigate this threat, the research community focused on automated de-authentication systems. Unfortunately, no single approach offers security, privacy, and usability. For instance, although facial recognition-based methods might be a good fit for security and usability, they violate user privacy by constantly recording the user and the surrounding environment.In this work, we propose BLUFADE, a fast, secure, and transparent de-authentication system that takes advantage of blurred faces to preserve user privacy. We obfuscate a webcam with a physical blur layer and use deep learning algorithms to perform face detection continuously. To assess BLUFADE‘s practicality, we collected two datasets formed by 30 recruited subjects (users) and thousands of physically blurred celebrity photos. The former was used to train and evaluate the deauthentication system performances, the latter to assess the privacy and to increase variance in training data. We show that our approach outperforms state-of-the-art methods in detecting blurred faces, achieving up to 95% accuracy. Furthermore, we demonstrate that BLUFADE effectively de-authenticates users up to 100% accuracy in under 3 seconds, while satisfying security, privacy, and usability requirements.
Matteo Cardaioli, Mauro Conti, Pier Paolo Tricomi, Gene Tsudik
PerCom1
2022 Hand Me Your PIN! Inferring ATM PINs of Users Typing with a Covered Hand
Matteo Cardaioli, Stefano Cecconello, Mauro Conti, Simone Milani, Stjepan Picek, Eugen Saraci
USENIX Security Symposium1
2021 It's a Matter of Style: Detecting Social Bots through Writing Style Consistency
abstract
Social bots are computer algorithms able to produce content and interact with other users on social media autonomously, trying to emulate and possibly influence humans’ behavior. Indeed, bots are largely employed for malicious purposes, like spreading disinformation and conditioning electoral campaigns. Nowadays, bots’ capability of emulating human behaviors has become increasingly sophisticated, making their detection harder. In this paper, we aim at recognizing bot-driven accounts by evaluating the consistency of users’ writing style over time. In particular, we leverage the intuition that while bots compose posts according to fairly deterministic processes, humans are influenced by subjective factors (e.g., emotions) that can alter their writing style. To verify this assumption, by using stylistic consistency indicators, we characterize the writing style of more than 12,000 among bot-driven and human-operated Twitter accounts and find that statistically significant differences can be observed between the different types of users. Thus, we evaluate the effectiveness of different machine learning (ML) algorithms based on stylistic consistency features in discerning between human-operated and bot-driven Twitter accounts and show that the experimented ML algorithms can achieve high performance (i.e., F-measure values up to 98%) in social bot detection tasks.
Matteo Cardaioli, Mauro Conti, Andrea Di Sorbo, Enrico Fabrizio, Sonia Laudanna, Corrado Aaron Visaggio
ICCCN1
2021 Malingering Scraper: A Novel Framework to Reconstruct Honest Profiles from Malingerer Psychopathological Tests
Matteo Cardaioli, Stefano Cecconello, Merylin Monaro, Giuseppe Sartori, Mauro Conti, Graziella Orrù
ICONIP (6)1
2020 Predicting Twitter Users' Political Orientation: An Application to the Italian Political Scenario
abstract
Recently, the increasing spread of Online Social Networks (OSNs) provided an unprecedented opportunity of analysing online traces of human behaviour to get insight on individuals and society. Among the others, the possibility of predicting users' political orientation relying on data extracted from OSNs received growing attention. In this study, we introduce and make publicly available a dataset composed of 6.685 unique Twitter users and 9.593.055 Tweets. Differently from most of the dataset currently available in the literature, here, each user was manually labeled according to their political orientation by a pool of human judges, using strict inclusion criteria. Further, we address the feasibility of the automatic classification of Italian Twitter users' political orientation based on their Tweets content. Our analysis focuses first on implementing a series of classifiers with the aim of predicting users' political preference as right- or left-oriented. The built models were then evaluated for inferring the political orientation of those users supporting “Movimento 5 Stelle” (M5S), an Italian political party with a still unclear political leaning. Results show high performances on the left-right classification task, with accuracy rates up to 93%. Finally, classification performances obtained on M5S supporters and possible applications of our findings are discussed.
Matteo Cardaioli, Pallavi Kaliyar, Pasquale Capuozzo, Mauro Conti, Giuseppe Sartori, Merylin Monaro
ASONAM1
2020 Your PIN Sounds Good! Augmentation of PIN Guessing Strategies via Audio Leakage
Matteo Cardaioli, Mauro Conti, Kiran S. Balagani, Paolo Gasti
ESORICS (1)1
2019 PILOT: Password and PIN information leakage from obfuscated typing videos
abstract
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters (∗ or ∙) that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos ( PILOT ). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work (In European Symposium on Research in Computer Security ( 2018 ) 263–280 Springer). In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.
Kiran S. Balagani, Matteo Cardaioli, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
J. Comput. Secur.2