VLDB 2026 Research / reviewers in the wild / expert
Andrea Sabbioni
dblp:207/0334
· DBLP profile ↗
16ranked-venue papers
8as first author
15since 2021 · last 2026
0000-0001-9817-1702ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 8 first-author · 14 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forging Industry 5.0 DevOps: Towards Secure and Scalable OT Orchestration Powered by KubernetesabstractThe ongoing digitization of Operational Technology (OT) and the integration of Industrial Internet of Things (IIoT) devices are fundamentally transforming modern industrial systems. However, the heterogeneity of hardware and software ecosystems amplifies the complexity of this transformation, making orchestration and lifecycle management especially challenging. To address these challenges, modern DevOps practices—such as Continuous Integration and Continuous Deployment (CI/CD), runtime observability, and fine-grained access control—are essential. These practices help accelerate time-to-market, maintain service quality, manage operational complexity, and uphold security standards. Advancing toward seamless integration of OT within cloud-native environments, we introduce a prototype Orchestrator based on the Kubernetes plarform, aimed at providing a comprehensive lifecycle management for OT devices in industrial contexts. Our proposal bridges the traditional divide between IT and OT by seamlessly integrating with existing CI/CD pipelines and implementing Role-Based Access Control (RBAC) tailored to device-level permissions. Through a unified abstraction layer, it simplifies the management of heterogeneous, multi-vendor hardware, enabling scalable, secure, and efficient operations across diverse industrial deployments. Nicole Giulianelli, Andrea Sabbioni, Sofia Montebugnoli, Armir Bujari, Antonio Corradi |
CCNC | 2 |
| 2026 | Bridging Cloud and Edge for Digital Twins: A Qualitative and Quantitative Study of WASM, Unikernels, and Containers
Sofia Montebugnoli, Alessio Benenati, Andrea Sabbioni, Luca Foschini 0001 |
ICC | 3 |
| 2025 | CLO5ER: a Composable Lightweight Observability for 5g RAN Environment Inside Near RT RICabstractThe Open RAN specification introduces the Near Real-Time RAN Intelligent Controller (Near-RT RIC) as a closer point of orchestration, providing real-time analysis and control of gNBs through Operator-defined Near-Real Time Applications (xApps). The continuous gathering, storing, and processing of metrics and logs from various hardware and software components of the network is a complex task. In the cloud community, this complexity has been addressed through approaches and tools under the umbrella of observability. An observation framework applied to O-RAN can assure a holistic view of the infrastructure and services running on it, helping optimize performance, ensure interoperability among multi-vendor systems, enhance scalability, bolster security, and reduce operational costs by providing realtime insights. However, existing observability frameworks poorly fit O-RAN use cases due to their service-oriented architecture, which impacts performance and scalability. To fill this gap, we propose CLO5ER, a framework that facilitates the creation of observability workflows through the composition of O-xApp. Our solution integrates seamlessly with existing observability frameworks, providing an accelerated alternative path for processing signals from gNBs. Additionally, we introduce a novel xApp controller that optimizes O-xApp placement and instrumentation. Furthermore, our solution features a hierarchical message-oriented middleware that enhances xApp composability and data exchange. Sofia Montebugnoli, Andrea Sabbioni, Franco Callegati, Luca Foschini 0001, Paolo Bellavista |
ICC | 2 |
| 2025 | SFIOC: a Platform to Support Service Dependency Injection in Serverless FunctionsabstractFunction as a Service (FaaS) is a serverless cloud computing model that enables customers to encapsulate their business logic in functions. The platform automatically executes these functions each time a specified event occurs and are terminated once the triggering event is processed. Function as a Service (FaaS) workflows are often supported by ready-to-use and fully managed services hosted by cloud providers belonging to the so-called Backend as a Service (BaaS). The integration of these two serverless models offers comprehensive support to developers, enabling them to focus on business logic development while benefiting from a fully managed and automated infrastructure. However, state-of-the-art FaaS platforms currently lack direct support for integrating Backend as a Service (BaaS) services in FaaS functions, often resulting in service calls being hard-coded within function code. This approach reduces the modularity of functions, enforces vendor lock-in, and negatively impacts the performance of FaaS workloads.In this work, we propose SFIOC, an architecture that facilitates the integration of BaaS services into FaaS functions through Dependency Injection. SFIOC enhances existing FaaS solutions by enabling dynamic and at-runtime resolution of function service dependencies. SFIOC automates dependency management, thereby improving the maintainability and modularity of serverless functions while preserving workflow performance.The capabilities of our solution are demonstrated through an extensive testbed that encompasses the enhancement with SFIOC of a public cloud provider and an open-source-based private edge environment. Andrea Sabbioni, Luca Foschini 0001 |
ICCCN | 1 |
| 2025 | TORNADO: TOSCA-enabled Orchestration for RAN Network functions Automating DevOps in O-CloudabstractOpen Cloud (O-Cloud) is the Open Radio Access Network (O-RAN) computing infrastructure spanning edge to cloud sites defined by the O-RAN Alliance to support and coordinate RAN infrastructure management shared among multiple Mobile Network Operators (MNO). In the standard definition, O-Cloud ensures reliable connectivity, active coordination, and efficient distribution of the Radio Access Network (RAN) deployments. Thanks to these properties, O-Cloud can support Mobile Network and Infrastructure operators to achieve fully automated infrastructure management, self-service MNO portals, enhanced security measures, and O-Cloud infrastructure-agnostic management. In this paper, we present TORNADO: TOSCA-enabled Orchestration for RAN in Next-Generation Networks Automating DevOps in O-Cloud, an O-Cloud automation infrastructure designed to ease DevOps deployment and operation phases of RAN network functions for multiple MNOs. Our solution introduces infrastructure-agnostic automation for multi-site, multi-MNO RAN components, offering high-level, secure self-service MNO portals for defining RAN deployments. Performance evaluation of our solution for various RAN network functions demonstrated the capability of TORNADO to automate the deployment in a multi-site, multi-MNO heterogeneous infrastructure. Sofia Montebugnoli, Elisa Drudi, Andrea Sabbioni, Giuseppe Di Modica, Luca Foschini 0001 |
ISCC | 3 |
| 2025 | MLCOps: a Platform to Support Cloud Continuum Machine Learning OperationsabstractThe increasing reliance on Machine Learning (ML) to extract insights and value from data is driving researchers and businesses to seamlessly integrate it throughout the entire Cloud Continuum (CC), spanning from large-scale cloud infrastructures to edge computing and end devices. However, traditional service orchestration frameworks are fine-tuned to manage single-site general-purpose applications, struggling with the complexity of CC ML deployments, which seek customized strategies for enhanced performance and resiliency. To this end, we propose Machine Learning cloud Continuum Operations (MLCOps), an overlay solution that supports ML applications in CC deployments. MLCOps implements an innovative multisite orchestration layer and provides a new service runtime support, allowing one to react quickly to changing conditions. MLCOps advocates a layered approach to carry out specialized strategies, implementing global and local actions on infrastructure and environment to ensure the performance and availability of the deployed ML services. Without loss of generality, we show how the framework could be instantiated to support an anomaly detection task. In this context, we assess various (re)configuration strategies that can take place in actual deployments, assessing the ability of MLCOps to preserve the reliability of CC ML application deployments under dynamic workload conditions. Andrea Sabbioni, Luca Serfilippi, Sofia Montebugnoli, Armir Bujari, Antonio Corradi |
ISCC | 1 |
| 2025 | The Slices Cloud Continuum Blueprint: a Resilient Infrastructure to Support Large-scale Cloud Continuum Experiments
Andrea Sabbioni, Armir Bujari, Paolo Bellavista |
Networking | 1 |
| 2024 | Evaluating Mesh Communications in Disaggregated Near-RT RIC for 5G Open RAN: a Functional and Performance AnalysisabstractThe paradigm shift towards the fifth generation of mobile networks (5G) has entailed a transition from a monolithic architecture to a completely disaggregated microservice-based architecture of network functions. This architectural renovation decouples and distributes Containerized Network Functions (CNF), tailored to address the specialized requirements of the Open Radio Access Network (Open RAN) deployment. Specifically, Kubernetes has emerged as a pivotal orchestrator for CNF within the context of disaggregated Open RAN. In particular, the deployment of Operator-defined Applications (xApps) for Near Real-Time RAN Intelligent Controller (Near-RT RIC) scenarios calls for communication substrates to facilitate the communication and coordination with other RAN components, and consequently, to dial with increased dynamicity and flexibility of 5G deployments. To face these issues, we propose service mesh as a cloud-native technology extending the Kubernetes communication infrastructure. Service mesh fulfills diverse requisites of xApps running in the RAN Intelligent Controller for traffic management, instrumentation, security, and observability, inherently facilitating a zero-trust architecture through the incorporation of sidecar proxies co-located with microservices. Moreover, we evaluate the performances of another emerging paradigm, raising as a lightweight solution that allows a more incremental adoption compared to service mesh, represented by ambient mesh. This paper analyses service and ambient mesh for deploying xApps in a state-of-the-art Near-RT RIC, i.e., the O-RAN SC implementation, evaluating both qualitative and quantitative attributes. Sofia Montebugnoli, Andrea Sabbioni, Luca Foschini 0001 |
GLOBECOM | 2 |
| 2024 | A MECApp-aware Lifecycle Management Approach in 5G Edge-Cloud DeploymentsabstractThe recent trend pushing towards reliance on edge computing, virtualization and programmatic 5G network control has sparked the development of a myriad of open-source resource management and orchestration projects for improved control and added flexibility, making up for a rich and complex ecosystem of frameworks and tools with varying degree of support for standardized features. In this technological panorama, the ETSI Multi-Access Edge Computing (MEC) standard proposes a conceptual reference architecture, standardizing edge integration, interoperability and application management in an extended 5G edge-core architecture. In this context, we propose an application-aware orchestration solution for 5G edge-core distributed deployments, currently lacking support in state-of-the-art frameworks and tools. The proposal is built on an experimental and distributed deployment of the OpenAirInterface minimal MEC platform implementation and relies on the Kubernetes Operator pattern for the automatic MECApp lifecycle management. To validate our approach, we conduct a series of experiments, reporting key metrics of interest. Paolo Bellavista, Armir Bujari, Luca Foschini 0001, Andrea Sabbioni, Riccardo Venanzi |
ICCCN | 4 |
| 2024 | Function profiling to support smart Serverless service deployment in the Cloud continuumabstractThe adoption of the Cloud Continuum pattern, leveraging computational resources from both Cloud and Edge infrastructures provided by various vendors, is exacerbating the challenge of managing infrastructure and services. To forefront this complexity, Cloud providers and customers are evolving their usual approach to service development and deployment, seeking faster and easier paths that can sustain time-to-market business needs. Many Cloud providers are shaping their offerings to incorporate an ever-increasing number of Serverless Computing services, wherein they handle every aspect of customer service and infrastructure management. In this work, we aim to extend the principles of Serverless computing service development to Cloud continuum environments and put forth a proposal for enforcing smart deployment of Serverless applications over heterogeneous computing environments. Functional to this goal is the heuristic component, a founding element of our architectural proposal that is capable of building applications "footprint" in different execution environments offered by the provider infrastructure. In this preliminary work, we discuss the results obtained from testing the above-mentioned component on a sample set of functions. Mohammad Imran Ali, Giuseppe Di Modica, Giorgia Rondinini, Andrea Sabbioni, Antonio Corradi |
ISCC | 4 |
| 2022 | An Architectural Approach for Heterogeneous Data Access in Serverless PlatformsabstractThe continuous digitalization and application of modern ICT technologies in the Smart City and Tourism domains are paving the way to new, integrated and connected experiences with strong economic and social impact. However, the integration of services and data coming from different providers is hindered by a rapidly evolving ecosystem of tools and techniques, introducing substantial delays and costs in solution design, deployment, testing, and refinement. Serverless computing is a novel cloud computing model where the customers' business logic, structured as lightweight functions, is automatically put into execution in response to an incoming event. This emergent paradigm promises to be an appealing solution, lowering the development and management barrier for the adaptation, integration, and roll-out of services. However, the ephemeral nature of serverless functions clashes with the necessity of creating and maintaining persistent connections to the various data providers. In this work, we present the Serverless Persistence Support (SPS) service, a novel, distributed, and scalable service implementing an adaptation layer able to improve data access performance from serverless functions. To validate our proposal, we conduct a thorough analysis on a realistic testbed, contrasting various data layer supports and assessing SPS performance when compared to the classic approach where connections and operations are executed inside the business logic. The experimental analysis shows that our solution exhibits better performance both in terms of latency and throughput, while also improving resource utilization. Andrea Sabbioni, Armir Bujari, Stefano Romeo, Luca Foschini 0001, Antonio Corradi |
GLOBECOM | 1 |
| 2022 | A Fully Decentralized Architecture for Access Control Verification in Serverless EnvironmentsabstractServerless computing is a novel paradigm that has been widely adopted, in recent years, across many sectors due to its fine-grained scalability and fast time-to-market. This paradigm aims at offloading users from heavy burden tasks including those related to authentication and authorization. However, existing security mechanisms provided by cloud providers do not seem to be adequate to completely secure serverless platforms. In particular, typical access control solutions rely either on centralized authorization services or implement access control verification within the business logic. These approaches respectively degrade system performance and lead to security issues derived from the tight coupling among code and authorization verification. In this paper, we present a solution to address these problems with a fully decentralized architecture integrating access control verification in serverless environments. We implemented a prototype of the proposed architecture and evaluated its performance under different load conditions. Experiments show that our proposal outperforms other approaches. Andrea Sabbioni, Carlo Mazzocca, Michele Colajanni, Rebecca Montanari, Antonio Corradi |
ISCC | 1 |
| 2022 | DIFFUSE: A DIstributed and decentralized platForm enabling Function composition in Serverless Environments
Andrea Sabbioni, Lorenzo Rosa, Armir Bujari, Luca Foschini 0001, Antonio Corradi |
Comput. Networks | 1 |
| 2021 | Enhancing the Performance of Industry 4.0 Scenarios via Serverless Processing at the EdgeabstractIndustry 4.0 aims to revolutionize and digitize the manufacturing sector by enabling and facilitating interoperability, solution agility, flexible (re)configuration of production chain(s) while, at the same time, reducing costs by exploiting real time data. These capabilities require to link the plant floor with data flows from/to the enterprise borders and include as core enabling technologies the Internet of Things (IoT), cloud, and edge computing key to move and execute parts of the business logic. The new capabilities might be leveraged in an innovative way, especially in the plant floor to dynamically change the monitoring/control logic of the smart machinery. In our reference scenario, the data flows originating from the plant floor can be processed and filtered locally, creating the basis for a selective Quality of Service (QoS) mechanism allowing for the implementation of reactive services, such as predictive maintenance. To that end, we propose an innovative serverless edge processing solution used for monitoring geo-distributed industrial plants. The proposal is validated in realistic settings, under different operational regimes, exhibiting acceptable performance trends under realistic periodic and variable traffic scenarios. Armir Bujari, Antonio Corradi, Luca Foschini 0001, Lorenzo Patera, Andrea Sabbioni |
ICC | 5 |
| 2021 | A Shared Memory Approach for Function Chaining in Serverless PlatformsabstractServerless platforms are increasingly gaining importance in the cloud computing landscape due to their benefit of shortening the time to market of solutions and capability of automatic, fast, fine-grained scaling of resources. In this context, function chaining represents an appealing feature, allowing the composition of two or more functions to create a complex computation from simpler units while incentivizing modularity and reusability of functions. In this paper, we propose a portable and transparent, container-based serverless architecture that introduces an innovative infrastructural support, enabling an efficient composition of functions co-located on the same host. The proposal relies on a shared-memory approach and a message-oriented middleware serving as a communication medium among components. The experimental assessment shows the approach comes with the benefit of optimized resource usage and performance benefits measured in terms of request completion rate and a decrease in response latency. Andrea Sabbioni, Lorenzo Rosa, Armir Bujari, Luca Foschini 0001, Antonio Corradi |
ISCC | 1 |
| 2020 | An Efficient and Reliable Multi-Cloud Provider Monitoring SolutionabstractCloud computing has transformed the way IT services are provisioned and consumed, shifting the burden of configuration and management to the cloud provider. A lot of research has been conducted in the field aimed at optimizing and/or devise new in-cloud service delivery models. Yet, service outages are a norm rather than an exception. A natural evolution for application developers, especially for those applications that must meet high availability requirements, is to rely on resources and services provisioned by multiple cloud simultaneously. The so-called multi-cloud, distributed deployment model coupled with a monitoring solution spanning multiple domains could help in a timely identification and isolation of faulty components, alleviating service impairment issues. To this end, we propose an extension to NoMISHAP, a Platform as a Service (PaaS) multicloud middleware, introducing a cross layer monitoring solution for use in distributed cloud environments. Experimental results show the effectiveness of our approach and its ease of adoption for management tasks. Andrea Sabbioni, Armir Bujari, Luca Foschini 0001, Antonio Corradi |
GLOBECOM | 1 |