VLDB 2026 Research / reviewers in the wild / expert
Vita Santa Barletta
dblp:235/1547
· DBLP profile ↗
16ranked-venue papers
9as first author
14since 2021 · last 2025
0000-0002-0163-6786ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 4 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 6 · 3 first-author · 5 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Preface for "Quantum Programming for Software Engineering (QP4SE)"
Fabiano Pecorelli, Vita Santa Barletta, Manuel A. Serrano |
Sci. Comput. Program. | 2 |
| 2024 | Supporting Therapies for Eating Disorders: a Case StudyabstractEating disorders are disturbances in people’s eating behaviours that can influence their social and private lives, with consequences related to mental and physical health. Therefore, they must be timely and appropriately treated by professionals and, in this context, the employment of technology can improve the efficiency of treatments allowing remote assistance, continuous monitor, and less stress than the traditional medical approach. Vita Santa Barletta, Miriana Calvano, Antonio Curci, Rosa Lanzilotti, Antonio Piccinno |
AVI | 1 |
| 2024 | CyberSecurity Education for Industry and Academia (CSE4IA 2024)abstractThe cybersecurity domain faces a critical disparity between the escalating demand for skilled professionals and the limited talent pool. This gap is primarily driven by the surge in cyberattacks perpetrated by malicious actors seeking financial gain or disruption. These attacks, encompassing tactics like Distributed Denial-of-Service (DDoS) and ransomware, pose significant threats to data security and public safety. To bridge this gap, several challenges must be addressed. We need to prioritize initiatives that enhance people’s awareness and education in cybersecurity. Additionally, exploring innovative training methods and leveraging technology to equip cybersecurity professionals with the necessary skillsets is crucial. Vita Santa Barletta, Federica Caruso, Tania Di Mascio, Francesco Greco, Tasmina Islam, Veronica Rossano, Hannan Xiao |
AVI | 1 |
| 2024 | Quantum-based Automotive Threat Intelligence and CountermeasuresabstractDue to the increasing amount of software and hardware in connected and autonomous cars, the attack surface is growing, which increases the risk of security attacks. Researchers proposed machine learning or deep learning techniques to identify threats in in-vehicle networks. However, using these techniques is not enough to support the automotive industry since new processes or techniques must be conceptualized to make automotive systems more secure. Therefore, this research work presents a methodology, Quantum-based Automotive Threat Intelligence and Countermeasures (QUANTICAR), that integrates quantum optimization for CAN bus Intrusion Detection and the National Vulnerability Database (NVD) to understand the automotive attacks. In the first phase, QUANTICAR identifies the different types of attacks and then, based on the specific attack class, extracts new knowledge using the NVD. This contributes not only to improving attack detection but also to developing an Automotive Knowledge Base that can support developers and security experts in the secure development of automotive components in compliance with ISO/SAE 21434. Vita Santa Barletta, Danilo Caivano, Christian Catalano, Mirko De Vincentiis |
EASE | 1 |
| 2024 | Integrating Security and Privacy in Quantum Software EngineeringabstractIn the dynamic landscape of Quantum Software Engineering (QSE), ensuring the integrity of sensitive data is critical, which stipulates integrating security and privacy measures during the Quantum Software Development Life Cycle (QDLC) rather than providing cost-inefficient post-production software fixes. This paper proposes a Quantum Privacy Knowledge Base (QPKB) and Quantum Privacy-Oriented Software Development (QPOSD) approach that integrates privacy and security protocols into quantum hybrid software development, complementing existing software development processes. QPKB is formalized as the interrelationship between five key elements: Quantum Privacy by Design principles, Quantum Privacy Design Strategies, Quantum Privacy Patterns, Quantum Bugs and Vulnerabilities, and Quantum Hybrid Context. The step-by-step methodology for QPOSD spans analysis, design, coding, verification and validation, and deployment phases. With the help of a scenario, we demonstrate how QPOSD can effectively integrate security and privacy imperatives in QDLC. This study acts as a starting point for serving operational guidelines for quantum development teams, providing strategies for integrating privacy and security measures into QSE practices. Vita Santa Barletta, Danilo Caivano, Anibrata Pal |
EASE | 1 |
| 2024 | Translating Privacy Design Principles Into Human-Centered Software Lifecycle: A Literature ReviewabstractCompanies and organizations involved in software development are stimulated and often obliged to consider procedures and technical solutions to guarantee data privacy and protection from the early phases of the software lifecycle. In addition, by default, personal data might be processed with the highest privacy protection level. These two requirements are Privacy by Design and Privacy by Default principles. Their importance has grown quickly in the last few years, as demonstrated by data protection regulations, like GDPR and PIPEDA, which include them as an important part of some of their articles. However, such regulations do not provide any practical or concrete indications of software requirements, and developers often lack adequate knowledge to understand the privacy prescriptions expressed in legal language. This study addresses these limitations by presenting a systematic and rigorous literature review that aims to answer the following research questions: (RQ1) How do Privacy-By-Design and Privacy-By-Default principles translate into software requirements? and (RQ2) How Privacy-By-Design and Privacy-By-Default principles integrate into a Human-Centred Design process? For RQ1, the analysis of the resulting publications led to identifying several software requirements and business processes organized along 8 data-oriented and process-oriented privacy design strategies. For RQ2, the analysis of the retrieved publications provided a comprehensive view of the HCI methodologies adopted to comply with privacy requirements identified current shortcomings, and proposed future research directions. The results have been distilled into an initial framework that may aid the development of software that must comply with such principles and aims to integrate them into an HCD process. Marco Saltarella, Giuseppe Desolda, Rosa Lanzilotti, Vita Santa Barletta |
Int. J. Hum. Comput. Interact. | 4 |
| 2024 | Hybrid quantum architecture for smart city securityabstractCurrently and in the near future, Smart Cities are vital to enhance urban living, address resource challenges, optimize infrastructure, and harness technology for sustainability, efficiency, and improved quality of life in rapidly urbanizing environments. Owing to the high usage of networks, sensors, and connected devices, Smart Cities generate a massive amount of data. Therefore, Smart City security concerns encompass data privacy, Internet-of-Things (IoT) vulnerabilities, cyber threats, and urban infrastructure risks, requiring robust solutions to safeguard digital assets, citizens, and critical services. Some solutions include robust cybersecurity measures, data encryption, Artificial Intelligence (AI)-driven threat detection, public–private partnerships, standardized security protocols, and community engagement to foster a resilient and secure smart city ecosystem. For example, Security Information and Event Management (SIEM) helps in real-time monitoring, threat detection, and incident response by aggregating and analyzing security data. To this end, no integrated systems are operating in this context. In this paper, we propose a Hybrid Quantum-Classical Architecture for bolstering Smart City security that exploits Quantum Machine Learning (QML) and SIEM to provide security based on Quantum Artificial Intelligence and patterns/rules. The validity of the hybrid quantum-classical architecture was proven by conducting experiments and a comparison of the QML algorithms with state-of-the-art AI algorithms. We also provide a proof of concept dashboard for the proposed architecture. Vita Santa Barletta, Danilo Caivano, Mirko De Vincentiis, Anibrata Pal, Michele Scalera |
J. Syst. Softw. | 1 |
| 2024 | Minimizing incident response time in real-world scenarios using quantum computingabstractAbstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA). Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina |
Softw. Qual. J. | 6 |
| 2023 | A Rapid Review of Responsible AI frameworks: How to guide the development of ethical AIabstractIn the last years, the raise of Artificial Intelligence (AI), and its pervasiveness in our lives, has sparked a flourishing debate about the ethical principles that should lead its implementation and use in society. Driven by these concerns, we conduct a rapid review of several frameworks providing principles, guidelines, and/or tools to help practitioners in the development and deployment of Responsible AI (RAI) applications. We map each framework w.r.t. the different Software Development Life Cycle (SDLC) phases discovering that most of these frameworks fall just in the Requirements Elicitation phase, leaving the other phases uncovered. Very few of these frameworks offer supporting tools for practitioners, and they are mainly provided by private companies. Our results reveal that there is not a "catching-all" framework supporting both technical and non-technical stakeholders in the implementation of real-world projects. Our findings highlight the lack of a comprehensive framework encompassing all RAI principles and all (SDLC) phases that could be navigated by users with different skill sets and with different goals. Vita Santa Barletta, Danilo Caivano, Domenico Gigante, Azzurra Ragone |
EASE | 1 |
| 2023 | A New Interactive Paradigm for Speech Therapy
Vita Santa Barletta, Miriana Calvano, Antonio Curci, Antonio Piccinno |
INTERACT (4) | 1 |
| 2023 | Resolving Security Issues via Quality-Oriented Refactoring: A User StudyabstractSoftware quality is crucial in software development: if not addressed in early phases of the software development life cycle, it may even lead to technical bankruptcy, i.e., a situation in which modifications cost more than redeveloping the application from scratch. In addition, code security must also be addressed to reduce software vulnerabilities and to comply with legal requirements. In this work, we aim to investigate the relationship between refactoring code quality and software security, with the purpose of understanding whether and to what extent improving software quality could have a positive impact on software security as well. Specifically, we investigate to what extent rule violations of a software quality tool such as SonarQube overlap with rule violations of a software vulnerability tool like Fortify Static Code Analyzer. We first compared the rules encoded in the quality models of both tools, to discover possible overlapping cases. Later, we compared the issues raised by both tools on a set of open source Java projects; we also investigated the cases in which a quality refactoring process impacts over software security (thus removing one or more vulnerabilities). We furthermore validated our results statistically. Our results show that resolving software quality issues might also resolve security issues but only in part: many security issues still persist in the source code; also, some quality aspects are more likely to be improved in respect to others. In addition, this empirical study uncovers rule co-occurrences between the two tools. This study confirms the need for using a security-oriented static analysis tool to enforce software security instead of relying only on a quality-oriented one. Results have highlighted important insights for practitioners. Domenico Gigante, Fabiano Pecorelli, Vita Santa Barletta, Andrea Janes, Valentina Lenarduzzi, Davide Taibi 0001, Maria Teresa Baldassarre |
TechDebt@ICSE | 3 |
| 2023 | Machine Learning for Automotive Security in Technology Transfer
Vita Santa Barletta, Danilo Caivano, Christian Catalano, Mirko De Vincentiis, Anibrata Pal |
WorldCIST (4) | 1 |
| 2022 | Supporting Secure Agile Development: the VIS-PRISE ToolabstractPrivacy by Design and Security by Design are two fundamental aspects in the current technological and regulatory context. Therefore, software development must integrate these aspects and consider software security on one hand, and user-centricity from the design phase on the other. It is necessary to support the team in all stages of the software lifecycle in integrating privacy and security requirements. Taking these aspects into account, the paper presents VIS-PRISE prototype, a visual tool for supporting the design team in the secure agile development. Maria Teresa Baldassarre, Vita Santa Barletta, Giovanni Dimauro, Domenico Gigante, Alessandro Pagano, Antonio Piccinno |
AVI | 2 |
| 2022 | From GDPR to Privacy Design Patterns: The MATERIALIST FrameworkabstractPrivacy is becoming an increasingly important factor in software production. Indeed, besides increasing software quality, privacy is a mandatory aspect of national and supranational regulations like GDPR. However, several aspects like lack of knowledge on privacy and data protection regulations ambiguities limit the adoption of proper privacy implementation mechanisms during the software lifecycle. To fill this gap, this paper presents a framework, MATERIALIST, which aims to guide developers in choosing privacy design patterns to be used during software development. In particular, this paper focuses on the selection of privacy design patterns starting from the GDPR requirements. In this way, what is currently prescribed by GDPR in a non-technical way becomes a practical solution that software developers can adopt during their work. Vita Santa Barletta, Giuseppe Desolda, Domenico Gigante, Rosa Lanzilotti, Marco Saltarella |
SECRYPT | 1 |
| 2020 | A Visual Tool for Supporting Decision-Making in Privacy Oriented Software DevelopmentabstractNowadays, the dimension and complexity of software development projects increase the possibility of cyber-attacks, information exfiltration and data breaches. In this context, developers play a primary role in addressing privacy requirements and, consequently security, in software applications. Currently, only general guidelines exist that are difficult to put in operation due to the lack of the required security skills and knowledge, and to the use of legacy software development processes that do not deal with privacy and security aspects. This paper presents a knowledge base, the Privacy Knowledge Base (PKB), and the VIS-PRISE prototype (Visually Inspection to Support Privacy and Security) a visual tool that support developers' decisions to integrate privacy and security requirements in all software development phases. An initial experimental study with junior developers is also presented. Maria Teresa Baldassarre, Vita Santa Barletta, Danilo Caivano, Antonio Piccinno |
AVI | 2 |
| 2020 | Integrating security and privacy in software development
Maria Teresa Baldassarre, Vita Santa Barletta, Danilo Caivano, Michele Scalera |
Softw. Qual. J. | 2 |