Simone Lenti

dblp:207/1665 · DBLP profile ↗
← Back
17ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0001-8281-3723ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 11 · 4 since 2021Security and privacy · 8 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 VISPEK: a Visual Interactive System for Progressive Ensemble K-Means Clustering
abstract
K-means clustering is widely used, but its iterative and initialization-sensitive nature makes results hard to interpret, compare, and debug, especially when multiple runs are needed to obtain a reliable solution. This paper presents VISPEK, a visual interactive system for progressive ensemble k-means clustering that helps users understand how clustering results evolve and how agreement emerges across runs. By combining Progressive Visual Analytics with an ensemble-based strategy, VISPEK exposes intermediate results, stability and quality metrics, and similarities among runs, enabling users to inspect, explain, and steer the clustering process before convergence. In this way, VISPEK supports the interpretation of consensus formation, highlights uncertainty, and helps users identify promising results early. We validate the approach through two usage scenarios and an expert study with data science and machine learning experts, showing that VISPEK improves analysis transparency while reducing time and computational effort.
Marco Angelini, Graziano Blasilli, Giorgio Cazzetta, Simone Lenti, Alessia Palleschi, Giuseppe Santucci
AVI4
2026 Improving the understandability of declarative process discovery results using easyDeclare
abstract
Declarative process models allow us to capture the behavior of a business process through temporal constraints on the evolution of process activities. In process mining, declarative process discovery focuses on deriving these constraints from event logs. Although the semantic aspects of declarative processes have been extensively investigated, there has been less focus on designing declarative visual notations that enhance model understanding and support analysts in solving process mining tasks. To improve the human understandability of declarative process models, in this paper, we present easyDeclare , a novel visual notation to specify declarative process models using the Declare language. easyDeclare was developed with consideration of the well-established Moody’s design principles. We conducted extensive user experiments to demonstrate that easyDeclare , when compared with the original graphical representation of Declare , reduces the cognitive load required to interpret Declare models of increasing complexity, making it a promising alternative to enhancing overall comprehension of declarative process discovery tasks.
Graziano Blasilli, Lauren S. Ferro, Simone Lenti, Fabrizio Maria Maggi, Andrea Marrella, Tiziana Catarci
Inf. Syst.3
2024 SoK: A Unified Data Model for Smart Contract Vulnerability Taxonomies
abstract
Modern blockchains support the execution of application-level code in the form of smart contracts, allowing developers to devise complex Distributed Applications (DApps). Smart contracts are typically written in high-level languages, such as Solidity, and after deployment on the blockchain, their code is executed in a distributed way in response to transactions or calls from other smart contracts. As a common piece of software, smart contracts are susceptible to vulnerabilities, posing security threats to DApps and their users.
Claudia Ruggiero, Pietro Mazzini, Emilio Coppa, Simone Lenti, Silvia Bonomi
ARES4
2024 Improving Attack Graph-Based Self-protecting Systems: A Computational Pipeline for Accuracy-Scalability Trade-off
Silvia Bonomi, Marco Cuoci, Simone Lenti, Alessandro Palma
CRiSIS3
2024 Bridging the Gap: Cyber Defence Skills for the Future
abstract
As cyber threats continue to evolve, the need for highly skilled cyber defence operators becomes increasingly critical. In this work, we aim to provide a multidisciplinary exploration into the current educational landscape, focusing on the following pivotal areas: cyber defence educational initiatives, digital skills, technological enablers, and ethical considerations. First, we present the current landscape of cyber defence educational initiatives. Then, we examine the required digital skills, virtual reality and augmented reality initiatives for immersive learning experiences and delve into the advantages of game-based learning for skill acquisition in order to finally provide a holistic evaluation of the complexities involved in cyber defence training. We underscore the importance of standardising training modules tailored to diverse roles within cyber defence. The discussion emphasises the need for ethical and legal guidelines, especially concerning privacy and bias in AI-driven educational tools. Finally, we highlight the importance of dynamic curricula that include technical, legal, and soft skills, along with hands-on training through simulations to prepare operators for real-world cyber threats. This work will serve as a foundation for academics, industry professionals, and policy-makers interested in elevating the standards and effectiveness of cyber defence training suggesting ideas for more specialised, adaptable, and ethically responsible programs.
Sofia Strukova, Mariano Albaladejo-González, Maya Bozhilova, Alejandro Campos Fuentes, Simone Lenti, Gregorio Martínez Pérez, Daniel Navarro-Martínez, Pantaleone Nespoli, Giuseppe Santucci, Marco Antonio Sotelo Monge, Nikolai Stoianov, Eugenio Viesca Revuelta, José A. Ruipérez-Valiente
EDUCON5
2024 A Visual Analytics Conceptual Framework for Explorable and Steerable Partial Dependence Analysis
abstract
Machine learning techniques are a driving force for research in various fields, from credit card fraud detection to stock analysis. Recently, a growing interest in increasing human involvement has emerged, with the primary goal of improving the interpretability of machine learning models. Among different techniques, Partial Dependence Plots (PDP) represent one of the main model-agnostic approaches for interpreting how the features influence the prediction of a machine learning model. However, its limitations (i.e., visual interpretation, aggregation of heterogeneous effects, inaccuracy, and computability) could complicate or misdirect the analysis. Moreover, the resulting combinatorial space can be challenging to explore both computationally and cognitively when analyzing the effects of more features at the same time. This paper proposes a conceptual framework that enables effective analysis workflows, mitigating state-of-the-art limitations. The proposed framework allows for exploring and refining computed partial dependences, observing incrementally accurate results, and steering the computation of new partial dependences on user-selected subspaces of the combinatorial and intractable space. With this approach, the user can save both computational and cognitive costs, in contrast with the standard monolithic approach that computes all the possible combinations of features on all their domains in batch. The framework is the result of a careful design process involving experts' knowledge during its validation and informed the development of a prototype, W4SP (available athttps://aware-diag-sapienza.github.io/W4SP/), that demonstrates its applicability traversing its different paths. A case study shows the advantages of the proposed approach.
Marco Angelini, Graziano Blasilli, Simone Lenti, Giuseppe Santucci
IEEE Trans. Vis. Comput. Graph.3
2023 FuzzPlanner: Visually Assisting the Design of Firmware Fuzzing Campaigns
abstract
Embedded devices are pivotal in many aspects to our everyday life, acting as key elements within our critical infrastructures, e-health sector, and the IoT ecosystem. These devices ship with custom software, dubbed firmware, whose development may not have followed strict security-by-design guidelines and for which no detailed documentation may be available. Given their critical role, testing their software before deploying them is crucial. Software fuzzing is a popular software testing technique that has shown to be quite effective in the last decade. However, the firmware may contain thousands of subcomponents with unexpected interplays. Moreover, operators may have a tight time budget to perform a security evaluation, requiring focused fuzzing on the most critical subcomponents. Also, considering the lack of accurate documentation for a device, it is quite hard for a security operator to understand what to fuzz and how to fuzz a specific device firmware. In this paper, we present Fuzzplanner, a visual analytics solution that enables security operators during the design of a fuzzing campaign over a device firmware. Fuzzplanner helps the operator identify the best candidates for fuzzing using several innovative visual aids. Our contributions include introducing Fuzzplanner, exploring diverse analytical tools to pinpoint critical binaries, and showing its efficacy with two real-world firmware image scenarios.
Emilio Coppa, Alessio Izzillo, Riccardo Lazzeretti, Simone Lenti
VizSec4
2022 Effectiveness Error: Measuring and Improving RadViz Visual Effectiveness
abstract
RadViz contributes to multidimensional analysis by using 2D points for encoding data elements and interpreting them along the original data dimensions. For these characteristics it is used in different application domains, like clustering, anomaly detection, and software visualization. However, it is likely that using the dimension arrangement that comes with the data will produce a plot that leads users to make inaccurate conclusions about points values and data distribution. This article attacks this problem without altering the original RadViz design: It defines, for both a single point and a set of points, the metric of effectiveness error, and uses it to define the objective function of a dimension arrangement strategy, arguing that minimizing it increases the overall RadViz visual quality. This article investigated the intuition that reducing the effectiveness error is beneficial for other well-known RadViz problems, like points clumping toward the center, many-to-one plotting of non-proportional points, and cluster separation. It presents an algorithm that reduces to zero the effectiveness error for a single point and a heuristic that approximates the dimension arrangement minimizing the effectiveness error for an arbitrary set of points. A set of experiments based on 21 real datasets has been performed, with the goals of analyzing the advantages of reducing the effectiveness error, comparing the proposed dimension arrangement strategy with other related proposals, and investigating the heuristic accuracy. The Effectiveness Error metric, the algorithm, and the heuristic presented in this article have been made available in a d3.js plugin at https://aware-diag-sapienza.github.io/d3-radviz.
Marco Angelini, Graziano Blasilli, Simone Lenti, Alessia Palleschi, Giuseppe Santucci
IEEE Trans. Vis. Comput. Graph.3
2021 BUCEPHALUS: a BUsiness CEntric cybersecurity Platform for proActive anaLysis Using visual analyticS
abstract
Analyzing and mitigating the threats that cyber-attacks pose on the services of a critical infrastructure is not a trivial activity. Research solutions have been developed using data about the devices used for implementing the services, services dependencies, network topology, and the vulnerabilities that can be exploited to attack the network. However, most of the proposed solutions fail to consider these aspects in an integrated fashion, allowing the user to understand global dependencies and weaknesses. This paper contributes this issue with BUCEPHALUS, a Visual Analytics solution providing a) a visual overview of the existing relationships among business functions, devices, and vulnerabilities, and b) a what-if analysis scenario, in which the user is supported on making decisions on which vulnerabilities are more appropriate to fix. BUCEPHALUS has been developed and validated within a user-centered design process involving security professionals.
Marco Angelini, Graziano Blasilli, Silvia Bonomi, Simone Lenti, Alessia Palleschi, Giuseppe Santucci, Emiliano De Paoli
VizSec4
2020 CrossWidgets: Enhancing Complex Data Selections through Modular Multi Attribute Selectors
abstract
Filtering is one of the basic interaction techniques in Information Visualization, with the main objective of limiting the amount of displayed information using constraints on attribute values. Research focused on direct manipulation selection means or on simple interactors like sliders or check-boxes: while the interaction with a single attribute is, in principle, straightforward, getting an understanding of the relationship between multiple attribute constraints and the actual selection might be a complex task. To cope with this problem, usually referred as cross-filtering, the paper provides a general definition of the structure of a filter, based on domain values and data distribution, the identification of visual feedbacks on the relationship between filters status and the current selection, and guidance means to help in fulfilling the requested selection. Then, leveraging on the definition of these design elements, the paper proposes CrossWidgets, modular attribute selectors that provide the user with feedback and guidance during complex interaction with multiple attributes. An initial controlled experiment demonstrates the benefits that CrossWidgets provide to cross-filtering activities.
Marco Angelini, Graziano Blasilli, Simone Lenti, Alessia Palleschi, Giuseppe Santucci
AVI3
2019 SymNav: Visually Assisting Symbolic Execution
abstract
Modern software systems require the support of automatic program analyses to answer questions about their correctness, reliability, and safety. In recent years, symbolic execution techniques have played a pivotal role in this field, backing research in different domains such as software testing and software security. Like other powerful machine analyses, symbolic execution is often affected by efficiency and scalability issues that can be mitigated when a domain expert interacts with its working, steering the computation to achieve the desired goals faster. In this paper we explore how visual analytics techniques can help the user to grasp properties of the ongoing analysis and use such insights to refine the symbolic exploration process. To this end, we discuss two real-world usage scenarios from the malware analysis and the vulnerability detection domains, showing how our prototype system can help users make a wiser use of symbolic exploration techniques in the analysis of binary code.
Marco Angelini, Graziano Blasilli, Luca Borzacchiello, Emilio Coppa, Daniele Cono D'Elia, Camil Demetrescu, Simone Lenti, Simone Nicchi, Giuseppe Santucci
VizSEC7
2019 Vulnus: Visual Vulnerability Analysis for Network Security
abstract
Vulnerabilities represent one of the main weaknesses of IT systems and the availability of consolidated official data, like CVE (Common Vulnerabilities and Exposures), allows for using them to compute the paths an attacker is likely to follow. However, even if patches are available, business constraints or lack of resources create obstacles to their straightforward application. As a consequence, the security manager of a network needs to deal with a large number of vulnerabilities, making decisions on how to cope with them. This paper presents VULNUS (VULNerabilities visUal aSsessment), a visual analytics solution for dynamically inspecting the vulnerabilities spread on networks, allowing for a quick understanding of the network status and visually classifying nodes according to their vulnerabilities. Moreover, VULNUS computes the approximated optimal sequence of patches able to eliminate all the attack paths and allows for exploring sub-optimal patching strategies, simulating the effect of removing one or more vulnerabilities. VULNUS has been evaluated by domain experts using a lab-test experiment, investigating the effectiveness and efficiency of the proposed solution.
Marco Angelini, Graziano Blasilli, Tiziana Catarci, Simone Lenti, Giuseppe Santucci
IEEE Trans. Vis. Comput. Graph.4
2018 Visual exploration and analysis of the italian cybersecurity framework
abstract
In the last years, several standards and frameworks have been developed to help organizations to increase the security of their Information Technology (IT) systems. In order to deal with the continuous evolution of the cyber-attacks complexity, such solutions have to cope with an overwhelming set of concepts, and are perceived as complex and hard to implement. The exploration of the cyber-security state of an organization can be made more effective and proficient if supported by the right level of automation. This paper presents the implementation of a visual analytics solution, called CybeR secUrity fraMework BrowSer (CRUMBS) [2], targeted at dealing with the Italian Adaptation of the Cyber Security Framework (IACSF), derived by the National Institute of Standards and Technology (NIST) proposal [1], adaptation that, in its full complexity, presents the security managers with hundreds of scattered concepts, like functions, categories, subcategories, priorities, maturity levels, current and target profiles, and controls, making its adoption a complex activity. The prototype is available at: http://awareserver.dis.uniroma1.it:11768/crumbs/.
Marco Angelini, Graziano Blasilli, Simone Lenti, Giuseppe Santucci
AVI3
2018 Guess What I Want: I am in Hurry and I am Using my Phone while Driving
abstract
This paper presents a system that prioritizes user actions according to the domain context and user preferences, in order to provide the adaptation process with a partial order of functionalities, useful to optimize the user interface with the main goal of minimizing screen usage and user interaction. The solution is instantiated in a smart home environment in the form of a smart user interface exploiting visual means to convey information. An user evaluation based on this use case is provided, confirming the benefits of the solution in terms of utility and easiness of usage.
Marco Angelini, Graziano Blasilli, Simone Lenti, Giuseppe Santucci
IV3
2018 ROPMate: Visually Assisting the Creation of ROP-based Exploits
abstract
Exploits based on ROP (Return-Oriented Programming) are increasingly present in advanced attack scenarios. Testing systems for ROP-based attacks can be valuable for improving the security and reliability of software. In this paper, we propose ROPMATE, the first Visual Analytics system specifically designed to assist human red team ROP exploit builders. In contrast, previous ROP tools typically require users to inspect a puzzle of hundreds or thousands of lines of textual information, making it a daunting task. ROPMATE presents builders with a clear interface of well-defined and semantically meaningful gadgets, i.e., fragments of code already present in the binary application that can be chained to form fully-functional exploits. The system supports incrementally building exploits by suggesting gadget candidates filtered according to constraints on preserved registers and accessed memory. Several visual aids are offered to identify suitable gadgets and assemble them into semantically correct chains. We report on a preliminary user study that shows how ROPMATE can assist users in building ROP chains.
Marco Angelini, Graziano Blasilli, Pietro Borrello, Emilio Coppa, Daniele Cono D'Elia, Serena Ferracci, Simone Lenti, Giuseppe Santucci
VizSEC7
2017 The goods, the bads and the uglies: Supporting decisions in malware detection through visual analytics
abstract
Malware associated with Web downloads is responsible for many attacks trying to execute malicious code on a remote machine. Web browsers are protected by anti-malware utilities that try to distinguish between good downloads and bad downloads, blocking the bad ones and alerting the user. In order to cope with the uncertainty of such a process, very often the final decision is made using suitable thresholds, giving rise to a 3 categories classification: good downloads, bad downloads, and “in the middle” downloads (i.e., the uglies). In this situation, it is possible to involve the user (e.g., the security manager) in the decision loop, presenting him with the details of the decision process in a way he can either be more confident about the system decisions or he can refine what has been done automatically, e.g., promoting an ugly download to a good one. The paper addresses this problem presenting a visual analytics solution supporting the analysis of the classification system presented in AMICO [24], providing the user with a better understanding of the classification decisions and the possibility of changing the classification results. A prototype is available at: http://awareserver.dis.uniroma1.it:11768/malvis/.
Marco Angelini, Leonardo Aniello, Simone Lenti, Giuseppe Santucci, Daniele Ucci
VizSEC3
2017 CRUMBS: A cyber security framework browser
abstract
In the last years, several standards and frameworks have been developed to help organizations to increase the security of their Information Technology (IT) systems. In order to deal with the continuous evolution of the cyberattacks complexity, such solutions have to cope with an overwhelming set of concepts, and are perceived as complex and hard to implement. This paper presents a visual analytics solution targeted at dealing with the Italian Adaptation of the Cyber Security Framework (IACSF), derived by the National Institute of Standards and Technology (NIST) proposal, adaptation that, in its full complexity, presents the security managers with hundreds of scattered concepts, like functions, categories, subcategories, priorities, maturity levels, current and target profiles, and controls, making its adoption a complex activity. The system has been designed together with the security experts of one of the largest Italian public organization and has the goal of providing a continuous overview of the adoption process, providing a prioritizing view that helps in effectively planning the required activities. A prototype is available at: http://awareserver.dis.uniroma1.it:11768/crumbs/.
Marco Angelini, Simone Lenti, Giuseppe Santucci
VizSEC2