VLDB 2026 Research / reviewers in the wild / expert
Gianluca Lax
dblp:21/350
· DBLP profile ↗
45ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0002-5226-0870ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 20 · 2 first-author · 2 since 2021Security and privacy · 15 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 11 · 1 first-authorSoftware engineering, systems software and programming languages · 4Human-computer interaction and ubiquitous computing · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A cost-effective solution leveraging public blockchain for massively sharing malware signaturesabstractIn recent years, the proliferation of malware has reached unprecedented levels, leading to escalating cybercrime costs. Signatures extracted by static analysis of files have been widely adopted for malware detection: vendors maintain databases of known malware signatures that are shared with registered users. The recent literature has proposed the use of private and consortium (thus, permissioned) blockchains for spreading signatures among blockchain users. These approaches require controlled access to enhance trust and accountability but restrict the widespread sharing of up-to-date signatures because users must be registered. In this paper, we present a novel technique that leverages a public blockchain to enable the massive dissemination of malware signatures among any users since a public blockchain is permissionless. On the other hand, the use of a public blockchain introduces new challenges related to security and data privacy, which our solution solves. The main benefit and outcome of our solution is that any users can securely access and verify malware signatures facilitating real-time detection of malicious files. We implemented our solution in Ethereum and exploited a smart contract written in Solidity to demonstrate that our approach is highly cost-effective. Aurelio Loris Canino, Gianluca Lax |
J. Inf. Secur. Appl. | 2 |
| 2024 | Corrigendum to "Disarming visualization-based approaches in malware detection systems" [Computers & Security Volume 126, March 2023, 103062]
Lara Saidia Fascì, Marco Fisichella, Gianluca Lax, Chenyin Qian |
Comput. Secur. | 3 |
| 2024 | Enabling secure health information sharing among healthcare organizations by public blockchainabstractAbstract The facilitation of sharing and exchanging patients’ health records is a paramount opportunity in e-health, enabling healthcare providers to garner a comprehensive and clear perspective of patients’ medical histories without necessitating direct inquiries. Besides this great advantage, it introduces substantial issues on security and privacy, mainly related to unauthorized access to e-health records when different healthcare service providers maintain records. In this paper, we deal with this problem and propose using the blockchain technology (1) to obfuscate the linkage between patients’ identities and their e-health records and (2) to grant access to e-health records exclusively to entities authorized by patients themselves. Key outcomes include using a digital identity based on the Electronic Identification, Authentication, and Trust Services Regulation (eIDAS) to control access to these records, and a concrete implementation by adopting the Ethereum blockchain. Our solution relies on using a public blockchain, which is an improvement for the state of the art, in which only private or consortium blockchains have been proposed. The resulting solution has been analyzed, and the effectiveness and affordability of the proposal have been shown. Gianluca Lax, Roberto Nardone, Antonia Russo |
Multim. Tools Appl. | 1 |
| 2023 | Disarming visualization-based approaches in malware detection systemsabstractVisualization-based approaches have recently been used in conjunction with signature-based techniques to detect variants of malware files. Indeed, it is sufficient to modify some byte of executable files to modify the signature and, thus, to elude a signature-based detector. In this paper, we design a GAN-based architecture that allows an attacker to generate variants of a malware in which the malware patterns found by visualization-based approaches are hidden, thus producing a new version of the malware that is not detected by both signature-based and visualization-based techniques. The experiments carried out on a well-known malware dataset show a success rate of 100% in generating new variants of malware files that are not detected from the state-of-the-art visualization-based technique. Lara Saidia Fascì, Marco Fisichella, Gianluca Lax, Chenyin Qian |
Comput. Secur. | 3 |
| 2022 | An integrity-preserving technique for range queries over data streams in two-tier sensor networks
Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax |
Comput. Networks | 3 |
| 2022 | Partially-federated learning: A new approach to achieving privacy and effectiveness
Marco Fisichella, Gianluca Lax, Antonia Russo |
Inf. Sci. | 2 |
| 2021 | A Blockchain-based approach for matching desired and real privacy settings of social network users
Gianluca Lax, Antonia Russo, Lara Saidia Fascì |
Inf. Sci. | 1 |
| 2021 | A Lightweight Scheme Exploiting Social Networks for Data Minimization According to the GDPRabstractIn many application domains, there is a need to ensure that users satisfy some requirements to use a service: for example, there is a minimum age to buy alcoholic beverages or to watch some videos on YouTube. In these situations, organizations typically collect more personal information than necessary to provide a better service. The consequence is a personal data leakage that violates the data minimization principle stated by the General Data Protection Regulation 2016/679. This article proposes a new approach for allowing individuals to maintain control over the disclosure of their data, deciding which information to disclose and for how long. Our approach is based on the use of social networks, and implementation on Facebook is presented to show that the proposed solution is effective, cheap, friendly, and simple to adopt. Gianluca Lax, Antonia Russo |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2020 | A Privacy-Preserving Localization Service for Assisted Living FacilitiesabstractIn this paper, we propose a novel localization service to monitor the position of residents in assisted living facilities. The service supports a configurable balancing between precision and privacy, in such a way that the right of the residents to move freely in the environment in which they live without being tracked is preserved. However, in case of need, they can always be quickly localized. To do this, we implement, on top of an RFID-based architecture, a probabilistic model guaranteeing that the probability of identifying a person in a given (sensitive) place is at most k-1, where k represents the required privacy level. This is obtained by ensuring that the EPC sent by RFID tags is not an identifier, but is equal to that of at least other k - 1 people, each afferent to a different reader. We show that our method reaches the goal, resisting also attacks aimed at breaking privacy on the basis of humans' movement models. Importantly, privacy is guaranteed against both misuse of the administrator and client-side eavesdropping attacks. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
IEEE Trans. Serv. Comput. | 2 |
| 2019 | An Attribute-Based Privacy-Preserving Ethereum Solution for Service Delivery with Accountability RequirementsabstractThe main benefit of smart contracts over Ethereum is that different parties with conflicting interests can exchange value without trusting each other. As a matter of fact, solutions in which service delivery is regulated by smart contracts are proliferating. Sometimes, services can be negotiated and delivered only on the basis of some attributes, without disclosing the identity of the customer to the service supplier. However, accountability is still required, so that, in case of need, the identity of the customer should be linked to the service delivered and communicated to the appropriate parties. In this paper, we propose a practical solution to the above problem that integrates the features of Ethereum with a (Ciphertext-Policy) Attribute-Based Encryption scheme. To show the effectiveness of our proposal, we instantiate the general model to a significant use case. Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax, Lorenzo Musarella, Antonia Russo |
ARES | 3 |
| 2019 | A system to enforce user's preference in OSN advertisingabstractSocial network advertising is currently one of the most effective advertising types available to promote a product or a brand. The problem discussed in this paper concerns the possibility to ensure that advertising reaches really interested users, and also to prove this. At this aim, we propose the use of Blockchain to store users' interest and to obtain an assertion that a user is interested in a product before the advertising is shown. The proposal has been implemented by a Solidity smart contract in Ethereum and has been shown to be effective and cheap. Gianluca Lax, Antonia Russo |
ASONAM | 1 |
| 2019 | A Novel Query Language for Data Extraction from Social NetworksabstractOnline Social Networks (OSNs) represent an important source of information since they manage a huge amount of data that can be used in many different contexts. Moreover, many people create and manage more than one social profile in the different available OSNs. The combination and the extraction of the set of data from contained in OSNs can produce a huge amount of additional information regarding both a single person and the overall society. Consequently, the data extraction from multiple social networks is a topic of growing interest. There are many techniques and technologies for data extraction from a single OSN, but there is a lack of simple query languages which can be used by programmers to retrieve data, correlate resources and integrate results from multiple OSNs. This work describes a novel query language for data extraction from multiple OSNs and the related supporting tool to edit and validate queries. With respect to existing languages, the designed language is general enough to include the variety of resources managed by the different OSNs. Moreover, thanks to the support of the editing environment, the language syntax can be customised by programmers to express searching criteria that are specific for a social network. Francesco Buccafurri, Gianluca Lax, Lorenzo Musarella, Roberto Nardone |
WEBIST | 2 |
| 2017 | Overcoming Limits of Blockchain for IoT ApplicationsabstractBlockchain technology allows the implementation of a public ledger securely recording transactions among peers without the need of trusted third parties. For both researchers and industry IoT appears a domain in which there would be extraordinary benefits if the features of Blockchain can be exploited. Indeed, the possibility that IoT devices participate in public shared transactions enables a lot of challenging applications. However, there are some aspects that may limit the use of Blockchain in IoT. These are mainly related to the low computational power and storage capabilities of IoT devices. In this paper, we propose an alternative way to implement a public ledger overcoming the above drawbacks, thus appearing more suitable to IoT applications. The proposed protocol leverages the popular social network Twitter and works by building a meshed chain of tweets to ensure transaction security. Importantly, Twitter does not play neither the role of trusted third party nor the role of ledger provider. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 2 |
| 2017 | Contrasting False Identities in Social Networks by Trust Chains and Biometric ReinforcementabstractFake identities and identity theft are issues whose relevance is increasing in the social network domain. This paper deals with this problem by proposing an innovative approach which combines a collaborative mechanism implementing a trust graph with keystroke-dynamic-recognition techniques to trust identities. The trust of each node is computed on the basis of neighborhood recognition and behavioral biometric support. The model leverages the word of mouth propagation and a settable degree of redundancy to obtain robustness. Experimental results show the benefit of the proposed solution even if attack nodes are present in the social network. Francesco Buccafurri, Gianluca Lax, Denis Migdal, Serena Nicolazzo, Antonino Nocera, Christophe Rosenberger |
CW | 2 |
| 2017 | Tweetchain: An Alternative to Blockchain for Crowd-Based Applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ICWE | 2 |
| 2016 | Range Query Integrity in Cloud Data Streams with Efficient Insertion
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
CANS | 2 |
| 2016 | A New Approach for Electronic SignatureabstractThere are many application contexts in which guaranteeing authenticity and integrity of documents is essential.In these cases, the typical solution relies on digital signature, which is based on the use of a PKI infrastructure and suitable devices (smart card or token USB).For several reasons, including certificate and device cost, many countries, such as the United States, the European Union, India, Brazil and Australia, have introduced the possibility to use simple generic electronic signature, which is less secure but reduces the drawbacks of digital signature.In this paper, we propose a new type of electronic signature that is based on the use of social networks.We formalize the proposal in a generic scenario and then, show a possible implementation on Twitter.Our proposal is proved to be secure, cheap and simple to adopt. Gianluca Lax, Francesco Buccafurri, Serena Nicolazzo, Antonino Nocera, Lidia Fotia |
ICISSP | 1 |
| 2016 | Interest Assortativity in TwitterabstractAssortativity is the preference for a person to relate to others who are someway similar.This property has been widely studied in real-life social networks in the past and, more recently, great attention is devoted to study various forms of assortativity also in online social networks, being aware that it does not suffice to apply past scientific results obtained in the domain of real-life social networks.One of the aspects not yet analyzed in online social networks is interest assortativity, that is the preference for people to share the same interest (e.g., sport, music) with their friends.In this paper, we study this form of assortativity on Twitter, one of the most popular online social networks.After the introduction of the background theoretical model, we analyze Twitter, discovering that users clearly show interest assortativity.Beside the theoretical assessment, our result leads to identify a number of interesting possible applications. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
WEBIST (1) | 2 |
| 2016 | Analysis-preserving protection of user privacy against information leakage of social-network Likes
Francesco Buccafurri, Lidia Fotia, Gianluca Lax, Vishal Saraswat |
Inf. Sci. | 3 |
| 2016 | A model to support design and development of multiple-social-network applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
Inf. Sci. | 2 |
| 2015 | A Model Implementing Certified Reputation and Its Application to TripAdvisorabstractMany real-life reputation models suffer from classical drawbacks making the systems where they are used vulnerable to users' misbehavior. TripAdvisor is a good example of this problem. Indeed, despite its popularity, the weakness of its reputation model is resulting in loss of credibility and growth of legal disputes. In this paper, we propose a reputation model abstractly considering service providers, users and feedbacks, and implementing the theoretical notion of certified reputation to concretely define a strategy to normalize feedback scores towards reliable values. We apply the model to the case of TripAdvisor, by proposing a solution to improve its dependability not increasing invasiveness nor reducing usability of the system. Moreover, it fully guarantees backward compatibility. In the context of project activities, we are in progress to fully implement the system and validate it on real-life data. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 2 |
| 2015 | Practical and Secure Integrated PKE+PEKS with Keyword PrivacyabstractPublic-key encryption with keyword search (PEKS) schemes are useful to delegate searching capabilities on encrypted data to a third party, who does not hold the entire secret key, but only an appropriate token which allows searching operations but preserves data privacy. We propose an efficient and practical integrated public-key encryption (PKE) and public-key encryption with keyword search (PEKS) scheme (PKE+PEKS) which we prove to be secure in the strongest security notion for PKE+PEKS schemes. In particular, we provide a unified security proof of its joint CCA-security in standard model. The security of our scheme relies on Symmetric eXternal Diffie-Hellman (SXDH) assumption which is a much simpler and more standard hardness assumption than the ones used in most of the comparable schemes. Ours is the first construction to use asymmetric pairings which enable an extremely fast implementation useful for practical applications. Finally we compare our scheme with other proposed integrated PKE+PEKS schemes and provide a relative analysis of its efficiency. Francesco Buccafurri, Gianluca Lax, Rajeev Anand Sahu, Vishal Saraswat |
SECRYPT | 2 |
| 2015 | Accountability-Preserving Anonymous Delivery of Cloud Services
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
TrustBus | 2 |
| 2015 | A new form of assortativity in online social networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera |
Int. J. Hum. Comput. Stud. | 2 |
| 2015 | Discovering missing me edges across social networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 2 |
| 2015 | A system for extracting structural information from Social Network accountsabstractThe social network phenomenon involves hundreds of millions of people every day. This enormous volume of activity results in a huge source of information that can be valuable in many fields, for both research and application purposes. The relevance of this information strongly depends on the evolution occurring in the social Web, in which interaction among different social networks and their cross-relationships are becoming progressively more important. This, in fact, represents the basis of an emergent scenario called Social Internetworking Scenario. However, efficiently accessing and fruitfully querying this huge information source is not easy, because no tool to support applications needing a massive utilization of cross-social-network data exists. In this paper, we fill this gap by proposing Social Network Account Knowledge Extractor (SNAKE), a system supporting the extraction of structural data from a social network account. SNAKE is implemented in such a way as to be easily integrated in any social-network-based application. To show the practical relevance of our proposal, we present our experience gained in three possible real-life applications strongly relying on information provided by SNAKE. Copyright © 2014 John Wiley & Sons, Ltd. Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Softw. Pract. Exp. | 2 |
| 2014 | Driving Global Team Formation in Social Networks to Obtain Diversity
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera, Domenico Ursino |
ICWE | 2 |
| 2014 | A Trust-Based Approach to Clustering Agents on the Basis of Their Expertise
Francesco Buccafurri, Antonello Comi, Gianluca Lax, Domenico Rosaci |
KES-AMSTA | 3 |
| 2014 | Trust-Based Intrusion Tolerant Routing in Wireless Sensor Networks
Francesco Buccafurri, Luigi Coppolino, Salvatore D'Antonio, Alessia Garofalo, Gianluca Lax, Antonino Nocera, Luigi Romano |
SAFECOMP | 5 |
| 2014 | A Novel Pseudo Random Number Generator Based on L'Ecuyer's SchemeabstractIn this paper, we propose a new lightweight L'Ecuyer-based pseudo random number generator (PRNG). We show that our scheme, despite the very simple functions on which it relies on, is strongly secure in the sense that our number sequences pass the state-of-the-art randomness tests and, importantly, an accurate and deep security analysis shows that it is resistant to a number of attacks. Francesco Buccafurri, Gianluca Lax |
SECRYPT | 2 |
| 2014 | Moving from social networks to social internetworking scenarios: The crawling perspective
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 2 |
| 2013 | Allowing privacy-preserving analysis of social network likesabstractSocial network Likes, as the “Like Button” records of Facebook, can be used to automatically and accurately predict highly sensitive personal attributes. Even though this could be done for non malicious reasons, for example to improve products, services, and targeting, it represents a dangerous invasion of privacy with sometimes intolerable consequences. Anyway, completely defusing the information power of Likes appears improper. In this paper, we propose a mechanism able to keep Likes unlinkable to the identity of their authors, but to allow the user to choose every time she expresses a Like, those non-identifying (even sensitive) attributes she wants to reveal. This way, anonymous analysis relating Likes to various characteristics of the population is preserved, with no risk for users' privacy. The protocol is shown to be secure and also ready to the possible future evolution of social networks towards P2P fully distributed models. Francesco Buccafurri, Lidia Fotia, Gianluca Lax |
PST | 3 |
| 2013 | Bridge analysis in a Social Internetworking Scenario
Francesco Buccafurri, Vincenzo Daniele Foti, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 3 |
| 2012 | Crawling Social Internetworking SystemsabstractIn new generation social networks, we expect that the paradigm of Social Internetworking Systems (SISs, for short) will be more and more important. In this new scenario, the role of Social Network Analysis is of course still crucial but the preliminary step to do is designing a good way to crawl the underlying graph. While this aspect has been deeply investigated in the field of social networks, it is an open issue when moving towards SISs. Indeed, we cannot expect that a crawling strategy which is good for social networks, is still valid in a Social Internetworking Scenario, due to its specific topological features. In this paper, we first confirm the above claim and, then, define a new crawling strategy specifically conceived for SISs. Finally, we show that it fully overcomes the drawbacks of the state-of-the-art crawling strategies. Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
ASONAM | 2 |
| 2012 | Discovering Links among Social Networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
ECML/PKDD (2) | 2 |
| 2012 | Privacy-preserving resource evaluation in social networksabstractIn new generation social networks, we expect that the demand of tools allowing the user to effectively control privacy, without relying on the provider trustworthiness, will be more and more increasing. A lot of precious information is currently released by users with no privacy control whenever they evaluate resources, which, for example, is done in Facebook through the “Like Button”. A mechanism allowing the user to express her preferences fully preserving her privacy is thus desired, especially if it is able to protect user privacy also in case of untrustworthy social network provider. In this paper, we propose a solution to this problem, based on a DHT-based P2P social network and on a cryptographic protocol relying on partially blind digital signatures. The protocol is shown to be a solution to the trade-off between feasibility and security, since it guarantees the needed security requirements without including the complex features of existing e-voting systems. Francesco Buccafurri, Lidia Fotia, Gianluca Lax |
PST | 3 |
| 2010 | Approximating sliding windows by cyclic tree-like histograms for efficient range queries
Francesco Buccafurri, Gianluca Lax |
Data Knowl. Eng. | 2 |
| 2009 | Fortifying the dalì attack on digital signatureabstractIn the recent literature a new vulnerability of digital signature has been addressed, based on a novel mechanism (denoted Dalì attack) allowing ambiguous presentation of electronic documents. This mechanism operates by a non-trivial inclusion into a single polymorphic file of a pair of different contents, encoded through two different format types. In this paper we overcome the main limitation of the above attack, consisting in the necessity of having html among the two involved formats. Here, exploiting an unusual feature of the pdf standard, we are able to enhance the attack in such a way that the two filetypes, namely pdf and tiff, embedded into the polymorphic file are both extremely safe, allowing the attacker to produce a fake document that appears in a format widely accepted in the context of e-government activities both whenever it is signed and whenever it is fraudulently exploited. This significantly increases both the danger and the plausibility of the Dalì attack. Francesco Buccafurri, Gianluca Caminiti, Gianluca Lax |
SIN | 3 |
| 2008 | Analysis of QoS in cooperative services for real time applications
Francesco Buccafurri, Pasquale De Meo, Maria Grazia Fugini, Roberto Furnari, Anna Goy, Gianluca Lax, Pasquale Lops, Stefano Modafferi, Barbara Pernici, Domenico Redavid, Giovanni Semeraro, Domenico Ursino |
Data Knowl. Eng. | 6 |
| 2008 | Enhancing histograms by tree-like bucket indices
Francesco Buccafurri, Gianluca Lax, Domenico Saccà, Luigi Pontieri, Domenico Rosaci |
VLDB J. | 2 |
| 2006 | Dealing with semantic heterogeneity for improving Web usage
Francesco Buccafurri, Gianluca Lax, Domenico Rosaci, Domenico Ursino |
Data Knowl. Eng. | 2 |
| 2004 | Reducing Data Stream Sliding Windows by Cyclic Tree-Like Histograms
Francesco Buccafurri, Gianluca Lax |
PKDD | 2 |
| 2004 | Fast range query estimation by N-level tree histograms
Francesco Buccafurri, Gianluca Lax |
Data Knowl. Eng. | 2 |
| 2003 | Pre-computing Approximate Hierarchical Range Queries in a Tree-Like Histogram
Francesco Buccafurri, Gianluca Lax |
DaWaK | 2 |
| 2002 | Binary-Tree Histograms with Tree Indices
Francesco Buccafurri, Filippo Furfaro, Gianluca Lax, Domenico Saccà |
DEXA | 3 |