VLDB 2026 Research / reviewers in the wild / expert
Nicola Mazzocca
dblp:24/2916
· DBLP profile ↗
96ranked-venue papers
2as first author
27since 2021 · last 2026
0000-0002-0401-9687ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 36 · 1 first-author · 8 since 2021Software engineering, systems software and programming languages · 18 · 1 first-author · 1 since 2021Security and privacy · 13Applied, interdisciplinary, general and emerging computing · 10 · 6 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Computer networks · 5 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Architecting software monitors for control-flow anomaly detection through large language models and conformance checking
Francesco Vitale, Francesco Flammini, Mauro Caporuscio, Nicola Mazzocca |
Inf. Softw. Technol. | 4 |
| 2026 | A material-aware, multi-modal synthetic dataset for smart city applications: Design and constructionabstractLarge-scale synthetic environments are essential for advancing smart cities research. However, existing urban benchmarks typically prioritize either visual photorealism or geometric fidelity, often neglecting the material-level semantics and physical attributes required for simulations. To address this gap, this paper introduces UR-MAT , a modular design framework and a multimodal synthetic dataset specifically built to bridge computer vision and physics-based modelling. We present a unified construction workflow that integrates georeferenced geometry, physically based rendering (PBR) materials, and domain-specific metadata (e.g., electromagnetic properties based on ITU-R standards) into a traceable data representation. The resulting dataset encompasses eight heterogeneous urban scenarios, providing spatially aligned RGB imagery, depth maps, semantic segmentation masks, and 3D point clouds. The utility of UR-MAT is validated through cross-domain experiments: (i) a quantitative baseline analysis on semantic material segmentation across fourteen material classes, where the best-performing model achieved 0.787 mIoU and 0.968 pixel accuracy, and (ii) electromagnetic ray-tracing simulations, which verify that the dataset’s material annotations yield physically consistent and deterministic radio propagation patterns. By enabling perception and simulation tasks within a single coherent framework, UR-MAT serves as a resource for developing perception-driven communication strategies and next-generation Digital Twins. Debora Russo, Domenico Amalfitano, Gerardo Di Martino, Nicola Mazzocca, Valeria Vittorini |
Inf. Sci. | 4 |
| 2026 | Distilling knowledge for low-energy AIoTabstractThe Artificial Intelligence of Things (AIoT) empowers IoT devices to leverage the advantages of AI near data-sources, reducing data movement, latency, and mitigating privacy issues. However, AI workloads are notoriously energy-intensive, posing significant challenges for energy-constrained IoT devices. Since such devices are often deployed in thousands of instances, even minor inefficiencies can significantly increase carbon emissions and energy consumptions. Model compression techniques have been employed to enable AI inference in resource-constrained environments. For example, Knowledge Distillation (KD) is an elaborate approach targeting low-footprint and high-accuracy models, although introducing further complexity during training due to inefficient grid searches of additional hyperparameters. The emerging wave of AIoT, however, calls for prioritizing energy-awareness both in inference and training. To address this shortcoming, this work proposes a three-stage design workflow for low-energy AIoT applications, driven primarily by an input energy budget characterizing the target IoT scenario. Given a specific CNN architecture and IoT platform, our workflow identifies the most effective student under the imposed energy constrained and derives an efficient configuration of the KD hyperparameters that maximizes student accuracy, while avoiding inefficient and expensive grid-search. Hence, this approach enable energy-efficient CNN inference while substantially reducing overall training costs. We validate our workflow with a systematic experimental campaign using ResNets and DenseNets on CIFAR-10, CIFAR-100,and Tiny Imagenet datasets, on an AMD Xilinx Zynq Ultrascale+ ZCU102 MPSoC. Our proposal maintains high accuracy while lowering energy consumption by up to 80%, highlighting the potential of our flow for real-world AIoT applications. Franca Rocco di Torrepadula, Vincenzo Maisto, Alessandro Cilardo, Nicola Mazzocca |
J. Syst. Archit. | 4 |
| 2025 | Bridging Efficient and Explainable Traffic Flow Prediction on the Edge
Mario Barbareschi, Antonio Emmanuele, Nicola Mazzocca, Franca Rocco di Torrepadula |
AINA (6) | 3 |
| 2025 | Designing Energy-Efficient Approximate Circuits for the FPGA TechnologyabstractA significant number of contributions focusing on approximation techniques for Application Specific Integrated Circuits (ASIC) has become part of the scientific literature. Conversely, Field Programmable Gate Arrays (FPGAs) are often overlooked, despite their increasing spread. ASIC-based techniques are, however, often unsuitable when it comes to FPGA, providing little or no advantages at all, due to the inherent differences in the two target technologies. Most of the FPGA-based approximation techniques being recently proposed either rely on manual approximation, or are too tightly coupled with a particular FPGA fabric, making them ineffective or even inapplicable to other devices. Furthermore, they rely on machine-learning based predictors to drive the Design Space Exploration (DSE), that, given the high fidelity required, are usually burdensome to achieve, or even unfeasible when little or no training data is available. In this paper, we discuss a fabricand workload-independent approach to design power-optimized approximate circuits for FPGA. We exploit the existing bond between Look-Up Table (LUT)-mapping in FPGA synthesis and cut-enumeration in And-Inverter graph representation of digital circuits, and we resort to an analytical model to estimate the power consumption during the DSE, avoiding costly synthesis as well as machine-learning based predictors for hardware resources during the DSE. Several benchmark circuits are considered for evaluation purposes, and the significant savings achieved allow us to claim our approach is suitable for addressing approximate circuit design while targeting the FPGA. Mario Barbareschi, Salvatore Barone, Nicola Mazzocca, Alberto Moriconi |
DSD | 3 |
| 2025 | Material-Aware Synthetic Data Generation for Smart City ApplicationsabstractThe development of smart city applications increasingly relies on datasets that capture not only urban geometry but also the material properties that influence real-world interactions. However, most existing datasets lack detailed semantic labels and physical attributes, limiting their applicability to tasks such as signal propagation modeling and material-aware analysis. In this paper, we propose a structured process and a tool pipeline for generating material-aware synthetic datasets from custom 3D urban scenes. Our approach integrates 3D modeling, physically-based rendering, and automated data capture to produce multimodal outputs, including RGB images, depth maps, segmentation masks, structured metadata, and annotated 3D meshes. We demonstrate the process and pipeline instantiation using the Louvre Museum district as a running scenario, capturing the site's complex architecture and material diversity. A preliminary ray-tracing simulation in MATLAB further demonstrates how the generated data can support material-aware applications. By bridging geometry, appearance, and physical information, the proposed solution can contribute to advancing simulation-ready datasets for smart city research. Debora Russo, Domenico Amalfitano, Gerardo Di Martino, Nicola Mazzocca, Valeria Vittorini |
HPCC | 4 |
| 2025 | UR-MAT: A Multimodal, Material-Aware Synthetic Dataset of Urban ScenariosabstractWe present UR-MAT, a multimodal, material-aware synthetic dataset for urban scene understanding and physics-based simulation. UR-MAT comprises seven diverse outdoor environments, ranging from historic districts to modern office areas, reconstructed from OpenStreetMap data and procedurally enhanced in Unreal Engine. Each scene includes semantically structured 3D meshes and physically based rendering (PBR) materials annotated with electromagnetic properties such as permittivity, reflectance, and attenuation. The dataset provides spatially aligned RGB images, material segmentation masks, depth maps, point clouds, camera poses, and 3D mesh files in .glb format. All data is generated through a deterministic, reproducible pipeline integrating OSM2World, Unreal Engine, and UnrealCV. UR-MAT supports a wide range of research tasks, from semantic segmentation and 3D reconstruction to material-aware electromagnetic simulation (e.g., mmWave propagation). We also release two utility scripts to extract mesh-material relationships and assign physical metadata, enabling dataset extension and reproducibility. By bridging computer vision and physical modeling, UR-MAT serves as a testbed for multimodal AI and signal-aware urban simulation. Debora Russo, Nicola Mazzocca, Valeria Vittorini |
ACM Multimedia | 2 |
| 2025 | Designing on-board explainable passenger flow predictionabstractNowadays, predicting public transport passenger flow (PF) is essential to optimize service planning and provide information to commuters. However, while current research focuses on enhancing accuracy using advanced models, like recurrent and graph neural networks, other key aspects, such as interpretability and computational efficiency, are often neglected. To fill this gap, we propose a framework to design on-board explainable PF prediction based on eXtreme Gradient Boosting (XGBoost). This framework enhances model interpretability and reduces computational costs, making the resulting PF predictive model suitable for inference on low-end devices. The proposed framework is validated on a real-world dataset from a major Italian city, involving 25 buses. Our results show that the framework achieves performance comparable to Convolutional Neural Networks (CNNs), with only a 0.2% percentage increase in Mean Absolute Percentage Error (MAPE). Additionally, it significantly reduces both inference time and energy consumption, with percentage decrease of 63%. Finally, we present examples to illustrate the interpretability of the predictions using the SHapley Additive exPlanation (SHAP) method. • Passenger flow (PF) prediction supports transport companies and passengers. • Currently, the main objective of research on PF is maximizing accuracy. • Our XGBoost-based framework provide accurate and explainable predictions. • The resulting model can be effectively executed on low end devices. Mario Barbareschi, Antonio Emmanuele, Nicola Mazzocca, Franca Rocco di Torrepadula |
Eng. Appl. Artif. Intell. | 3 |
| 2025 | Engineering SRAM-PUF on Arduino microcontrollerabstractThe emergence of the Internet of Things (IoT) enables both people and devices to access services, data, and actuator control from remote locations, even spanning thousands of miles. Ensuring authentication, communication integrity, and confidentiality for IoT devices is essential for systems security and still an open challenge too. In this context, Physical Unclonable Functions (PUFs) have gained significant attention due to their ability to generate stable, tamper-resistant, and random fingerprints that can be successfully exploited to provide cryptography keys or to implement authentication schemes. However, PUFs necessitate dedicated hardware, making them costly and available only in specific designs, thereby impeding their broader adoption. In this paper, we enable the usage of static random access memory (SRAM)-based PUF on Arduino UNO device, an open-source board implemented upon an ATMega328P, without requiring special hardware. We analyze SRAM PUF quality parameters and how to reconstruct a reliable cryptography key by engineering a fuzzy extractor. Additionally, we design a secure bootloader as root-of-trust and, as a case study, we detail how to authenticate Arduino Sketches and how to implement an authentication scheme. Mario Barbareschi, Franco Cirillo, Christian Esposito 0001, Nicola Mazzocca |
J. Syst. Archit. | 4 |
| 2025 | Control-flow anomaly detection by process mining-based feature extraction and dimensionality reductionabstractThe business processes of organizations may deviate from normal control flow due to disruptive anomalies, including unknown, skipped, and wrongly-ordered activities. To identify these control-flow anomalies, process mining can check control-flow correctness against a reference process model through conformance checking, an explainable set of algorithms that allows linking any deviations with model elements. However, the effectiveness of conformance checking-based techniques is negatively affected by noisy event data and low-quality process models. To address these shortcomings and support the development of competitive and explainable conformance checking-based techniques for control-flow anomaly detection , we propose a novel process mining-based feature extraction approach with alignment-based conformance checking. This variant aligns the deviating control flow with a reference process model; the resulting alignment can be inspected to extract additional statistics such as the number of times a given activity caused mismatches. We integrate this approach into a flexible and explainable framework for developing techniques for control-flow anomaly detection . The framework combines process mining-based feature extraction and dimensionality reduction to handle high-dimensional feature sets, achieve detection effectiveness, and support explainability. The results show that the framework techniques implementing our approach outperform the baseline conformance checking-based techniques while maintaining the explainable nature of conformance checking. We also provide an explanation of why existing conformance checking-based techniques may be ineffective. Finally, the results indicate that detection effectiveness is not solely dependent on the specific framework technique used, as no one-size-fits-all process mining-based feature extraction approach is suitable for all the synthetic and real-world datasets. Francesco Vitale, Marco Pegoraro 0001, Wil M. P. van der Aalst, Nicola Mazzocca |
Knowl. Based Syst. | 4 |
| 2025 | Fedflow: a personalized federated learning framework for passenger flow predictionabstractAbstract In the Intelligent Public Transportation Systems (IPTS) domain, predicting the number of commuters on-board, entering or leaving a metro train or a bus, i.e. the Passenger Flow (PF), is crucial for optimizing resource allocation and enhancing commuter satisfaction. In urban scenarios, the public transport system is often managed by distinct competing mobility providers. Traditional centralized machine learning models for PF prediction usually require data sharing among such competitors, leading to privacy and economic concerns. To overcome these issues, we propose exploiting Federated Learning (FL) in the PF predictions problem, as only model parameters must be shared among entities. Still, a straightforward application of FL can have some pitfalls. On one hand, it is widely recognized that FL can struggle with data heterogeneity, which is likely in the case of data acquired by distinct companies managing different public mobility services. Moreover, spatio-temporal features are not explicitly handled by classical FL. In this paper, we propose FedFlow: a personalized federated learning framework tailored for PF prediction. The proposed framework encompasses a personalized mechanism meant to refine local models based on client similarities, calculated by only leveraging publicly available domain-dependent information. The proposed framework has been experimentally validated on mobility data collected in a major Italian city, comparing FL predictions obtained by FedFlow against those obtained by LSTM models trained on local data, centralized data, FedAvg, and PerFedAvg. Results show that FedFlow outperforms all the considered adversary techniques. This work demonstrates that our proposal of personalized FL is effective in predicting PF while ensuring data privacy. Franca Rocco di Torrepadula, Marco Fisichella, Sergio Di Martino, Nicola Mazzocca |
Mach. Learn. | 4 |
| 2025 | Process Mining for Digital Twin Development of Industrial Cyber-Physical SystemsabstractDigital twin development of industrial cyber-physical systems requires modeling, simulation, and monitoring to provide accurate digital replicas mimicking system dynamics. To this aim, modern solutions employ data-driven approaches to capture normal system dynamics using historical data, and anomaly detection using run-time data. However, these approaches are typically process-agnostic and have limited explainability, which negatively impacts trustworthiness. Hence, we propose a novel framework for the digital twin development of industrial cyber-physical systems based on process mining, which connects data-driven and process-based analyses. The framework implements an offline phase that systematically identifies the most suitable process model to capture normal dynamics and simulates faulty dynamics for what-if analysis. The subsequent online phase involves run-time monitoring for anomaly detection. We develop a proof-of-concept application of the framework addressing a water distribution case study that allows physical fault injection. Results highlight the importance of adopting high-quality process models to significantly improve anomaly detection and time performance. Francesco Vitale, Simone Guarino, Francesco Flammini, Luca Faramondi, Nicola Mazzocca, Roberto Setola |
IEEE Trans. Ind. Informatics | 5 |
| 2024 | Exploiting Functional Approximation on Decision-Tree Based Multiple Classifier SystemsabstractMultiple Classifier Systems (MCSs) have been in-creasingly designed to take advantage of hardware features, such as high parallelism and computational power, to guarantee higher throughput and lower latency. Although the combination of multiple classifiers leads to high classification accuracy, the required area overhead makes the design of a hardware accelerator unfeasible, hindering the adoption of commercial configurable devices. For this reason, in this paper, we exploit the Approximate Computing (AxC) design paradigm to automatically generate approximated hardware implementations of MCSs by trading hardware area overhead off for classification accuracy. In particular, we propose an algorithm that identifies the resiliency source of the model and uses it to introduce approximation with minimum accuracy loss. Mario Barbareschi, Salvatore Barone, Antonio Emmanuele, Nicola Mazzocca |
VLSI-SoC | 4 |
| 2024 | Machine Learning for public transportation demand prediction: A Systematic Literature Review
Franca Rocco di Torrepadula, Enea Vincenzo Napolitano, Sergio Di Martino, Nicola Mazzocca |
Eng. Appl. Artif. Intell. | 4 |
| 2024 | A visual-based toolkit to support mobility data analyticsabstractThe Knowledge Discovery from Data (KDD) process is widely used across various domains to get valuable insights from data. Many platforms, like KNIME or RapidMiner, offer effective tools for KDD analysts, allowing them to perform data analytics tasks in a visual fashion, without writing code. In recent years, the increasing availability of mobility data has led to a surge in KDD-based initiatives from both industry and academia in the Intelligent Transportation Systems (ITS) domain. Still, KDD platforms lack comprehensive support for some typical mobility data manipulation tasks. As a result, mobility data analysis still requires a significant coding phase, with reduced productivity and hindered replicability of results. To address this gap, this paper presents a novel solution aimed at supporting ITS data analysts in defining KDD processes more efficiently. More in detail, we extended the KNIME platform by introducing a collection of new components explicitly tailored to facilitate some peculiar KDD tasks from mobility data. These components encompass critical functionalities such as map coverage analysis, trajectory partitioning and map-matching. To showcase the effectiveness of the proposed solution, we used it to replicate a study published in the ITS data analytics domain. Thanks to our proposal, such replication can be accomplished in a few minutes and with just a few clicks, without any manual coding, resulting in a pipeline that is easier to understand, distribute and re-execute, also for domain experts with no programming experience. Our solution is open-source and freely downloadable from the Knime Hub. In this way, we aim to foster data-driven research and practice in the ITS field, by providing researchers and practitioners with more effective analytics tools to handle mobility data. Sergio Di Martino, Enrico Landolfi, Nicola Mazzocca, Franca Rocco di Torrepadula, Luigi L. L. Starace |
Expert Syst. Appl. | 3 |
| 2024 | The convergence of Digital Twins and Distributed Ledger Technologies: A systematic literature review and an architectural proposalabstractIn recent years, the emerging Digital Twin (DT) technology is playing a key role in fostering the transition towards the Industry 4.0. DTs, representing virtual replicas of physical objects, products or processes established thanks to a bidirectional continuous flow of information between the physical and the virtual world, are currently adopted in multiple domains such as manufacturing, aerospace, automotive, energy, construction, smart cities and smart mobility, etc.. DTs live together with the physical system they replicate, receiving the same data and often triggering specific control actions that directly impact on the real system status. When dealing with DTs of complex Cyber-Physical Systems (CPSs), the data sources may be heterogeneous and untrustworthy, which requires the DT to be able to address security issues related to data in transit from/to the physical twin and data at rest. A possible way to address these data security issues consists in adopting Distributed Ledger Technologies (DLTs) which provide several security guarantees on data through cryptographic hashing techniques. In this work, we present a three-fold contribution: (i) we discuss the results of a Systematic Literature Review (SLR) on the state-of-the-art of the research related to the integration between DLT and Digital Twins, aimed at clarifying relevant aspects such as, among others, what is the favourite DLT choice in existing proposals or what is the type of DT-related information to store on-chain; (ii) leveraging the SLR results and other related research, we propose an architectural framework for the integration of DT and DLTs (more specifically, blockchains); (iii) we validate the proposed architecture by means of two proof-of-concept implementations leveraging different technological stacks and taking into account two different operational scenarios. Finally, we conduct a requirements coverage analysis and compare the PoCs through a coverage matrix. Alessandra Somma, Alessandra De Benedictis, Christian Esposito 0001, Nicola Mazzocca |
J. Netw. Comput. Appl. | 4 |
| 2024 | FPGA approximate logic synthesis through catalog-based AIG-rewriting techniqueabstractDue to their run-time reconfigurability, short time-to-market, and lower prototype costs, FPGAs have become increasingly popular since their introduction. They found use in a wide variety of applications, including high-performance computing. However, when compared to ASICs, FPGAs offer lower performance, and they are power-hungry devices with low energy-efficiency. The emergence of Approximate Computing (AxC) represents a significant advancement in terms of enabling technology when applied to FPGA-based computing platforms. It has been effectively exploited in several application fields, achieving significant savings in energy and latency through a selective degradation of the output quality. Nevertheless, a generalized and systematic methodology for FPGA-based circuit design is still lacking. Indeed, most of the methods target ASIC-based systems, and, consequently, they offer minimal advantages or even an increase in resources when synthesized for FPGAs due to the architectural differences between the technologies. In this paper, we attempt to address this shortcoming by introducing our method for designing combinational logic circuits. It is based on and-inverter graph rewriting and multi-objective optimization, aiming for optimal trade-offs between quality of results and hardware overhead. Extensive experimental campaigns empirically prove that both generic logic and arithmetic circuits benefit from this approach. Mario Barbareschi, Salvatore Barone, Nicola Mazzocca, Alberto Moriconi |
J. Syst. Archit. | 3 |
| 2024 | An Approach to the Systematic Characterization of Multitask Accelerated CNN Inference in Edge MPSoCsabstractDeep Learning is ubiquitous today and is increasingly moving from the cloud down to the edge of networked infrastructures, where it enables embedded applications to perform complex inference tasks close to the data sources, reducing long-distance data movement and alleviating the need for a powerful cloud infrastructure. Edge-class multi-processor system on chip (MPSoC) devices featuring an on-chip FPGA fabric offer key advantages for Deep Learning inference tasks, especially for complex applications where multiple models may be run concurrently in the same platform. In this work, we propose an approach and a practical framework for the systematic characterization of multithreaded Deep Learning inference on edge FPGA MPSoCs. We instantiate the framework into a real-world MPSoC platform, targeting Xilinx Vitis-AI as a representative example of a commercial Deep Learning acceleration toolkit for edge environments. We design a comprehensive experimental campaign and apply it to the platform for several convolutional neural networks, each trained on three different datasets. We show that our approach can be used for both hardware- and software-level analysis of a target system. Among other findings, the analysis revealed a suboptimal behavior of the underlying toolkit runtime, involving the utilization of the accelerator cores and the uneven software latency of the support library, influenced by the shapes of the input tensors. Alessandro Cilardo, Vincenzo Maisto, Nicola Mazzocca, Franca Rocco di Torrepadula |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2023 | Mobility Data Analytics with KNOT: The KNime mObility Toolkit
Sergio Di Martino, Nicola Mazzocca, Franca Rocco di Torrepadula, Luigi L. L. Starace |
W2GIS | 2 |
| 2023 | Evaluating virtualization for fog monitoring of real-time applications in mixed-criticality systemsabstractAbstract Technological advances in embedded systems and the advent of fog computing led to improved quality of service of applications of cyber-physical systems. In fact, the deployment of such applications on powerful and heterogeneous embedded systems, such as multiprocessors system-on-chips (MPSoCs), allows them to meet latency requirements and real-time operation. Highly relevant to the industry and our reference case-study, the challenging field of nuclear fusion deploys the aforementioned applications, involving high-frequency control with hard real-time and safety constraints. The use of fog computing and MPSoCs is promising to achieve safety, low latency, and timeliness of such control. Indeed, on one hand, applications designed according to fog computing distribute computation across hierarchically organized and geographically distributed edge devices, enabling timely anomaly detection during high-frequency sampling of time series, and, on the other hand, MPSoCs allow leveraging fog computing and integrating monitoring by deploying tasks on a flexible platform suited for mixed-criticality software, leading to so-called mixed criticality systems (MCSs). However, the integration of such software on the same MPSoC opens challenges related to predictability and reliability guarantees, as tasks interfering with each other when accessing the same shared MPSoC resources may introduce non-deterministic latency, possibly leading to failures on account of deadline overruns. Addressing the design, deployment, and evaluation of MCSs on MPSoCs, we propose a model-based system development process that facilitates the integration of real-time and monitoring software on the same platform by means of a formal notation for modeling the design and deployment of MPSoCs. The proposed notation allows developers to leverage embedded hypervisors for monitoring real-time applications and guaranteeing predictability by isolation of hardware resources. Providing evidence of the feasibility of our system development process and evaluating the industry-relevant class of nuclear fusion applications, we experiment with a safety-critical case-study in the context of the ITER nuclear fusion reactor. Our experimentation involves the design and evaluation of several prototypes deployed as MCSs on a virtualized MPSoC, showing that deployment choices linked to the monitor placement and virtualization configurations (e.g., resource allocation, partitioning, and scheduling policies) can significantly impact the predictability of MCSs in terms of Worst-Case Execution Times and other related metrics. Marcello Cinque, Luigi De Simone, Nicola Mazzocca, Daniele Ottaviano, Francesco Vitale |
Real Time Syst. | 3 |
| 2023 | Digital Twins for Anomaly Detection in the Industrial Internet of Things: Conceptual Architecture and Proof-of-ConceptabstractModern cyber-physical systems based on the Industrial Internet of Things (IIoT) can be highly distributed and heterogeneous, and that increases the risk of failures due to misbehavior of interconnected components, or other interaction anomalies. In this paper, we introduce a conceptual architecture for IIoT anomaly detection based on the paradigms of Digital Twins (DT) and Autonomic Computing (AC), and we test it through a proof-of-concept of industrial relevance. The architecture is derived from the current state-of-the-art in DT research and leverages on the MAPE-K feedback loop of AC in order to monitor, analyze, plan, and execute appropriate reconfiguration or mitigation strategies based on the detected deviation from prescriptive behavior stored as shared knowledge. We demonstrate the approach and discuss results by using a reference operational scenario of adequate complexity and criticality within the European Railway Traffic Management System. Alessandra De Benedictis, Francesco Flammini, Nicola Mazzocca, Alessandra Somma, Francesco Vitale |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Digital Twins in Healthcare: An Architectural Proposal and Its Application in a Social Distancing Case StudyabstractThe digital transformation process fostered by the development of Industry 4.0 technologies has largely affected the health sector, increasing diagnostic capabilities and improving drug effectiveness and treatment delivery. The Digital Twin (DT) technology, based on the virtualization of physical assets/processes and on a bidirectional communication between the digital and physical space for data exchange, is considered a game changer in modern health systems. Digital Twin applications in healthcare are various, ranging from virtualization of hospitals' physical spaces/organizational processes to individuals' physiological/genetic/lifestyle characteristics replication, and include the modeling of public health-related processes for monitoring, optimization and planning purposes. In this paper, motivated by the current COVID-19 pandemic, we focus on the application of the Digital Twin technology for virus containment on the workplace through social distancing. The contribution of this paper is three-fold: i) we review the existing literature on the adoption of the Digital Twin technology in the healthcare domain, and propose a classification of DT applications into four categories; ii) we propose a generalized Digital Twin architecture that can be used as reference to identify the main functional components of a Digital Twin system; iii) we present CanTwin, a real-life industrial case study developed by Hitachi and representing the Digital Twin of a canteen service serving 1100 workers, set up for social distancing monitoring, queue inspection, people counting and tracking, table occupancy supervision. Alessandra De Benedictis, Nicola Mazzocca, Alessandra Somma, Carmine Strigaro |
IEEE J. Biomed. Health Informatics | 2 |
| 2022 | Bus Passenger Load Prediction: Challenges from an Industrial Experience
Flora Amato, Sergio Di Martino, Nicola Mazzocca, Davide Nardone, Franca Rocco di Torrepadula, Paolo Sannino |
W2GIS | 3 |
| 2021 | Security-Aware Deployment Optimization of Cloud-Edge Systems in Industrial IoTabstractCloud computing, edge computing, and the Internet of Things are significantly changing from the original architectural models with pure provisioning of virtual resources (and services) to a transparent and adaptive hosting environment, where cloud providers, as well as “on-premise” resources and end nodes, fully realize the “everything-as-a-service” provisioning concept. The optimal design of these architectures, including the selection of optimal services to acquire, is not trivial in the cloud-edge context due to the involvement of a variable number and the type of available resources offerings and to the impact on cost, performance, and other relevant features such as security, almost never considered. This article presents a novel formalization of the cloud-edge allocation problem for the industrial IoT context. The proposed optimization process takes explicitly into account two critical aspects that are often overlooked in similar approaches, namely, the new cloud-edge on-demand service offerings model for the allocation of resources and the impact on the deployed application, in terms of cost, performance, and security policies actually implemented. An efficient yet suboptimal deterministic solver is also presented and compared with a linear programming one. Results are the same in 86% of the cases on the considered data set while our solver is orders of magnitude faster than the linear one. Valentina Casola, Alessandra De Benedictis, Sergio Di Martino, Nicola Mazzocca, Luigi L. L. Starace |
IEEE Internet Things J. | 4 |
| 2021 | Advancing synthesis of decision tree-based multiple classifier systems: an approximate computing case studyabstractAbstract So far, multiple classifier systems have been increasingly designed to take advantage of hardware features, such as high parallelism and computational power. Indeed, compared to software implementations, hardware accelerators guarantee higher throughput and lower latency. Although the combination of multiple classifiers leads to high classification accuracy, the required area overhead makes the design of a hardware accelerator unfeasible, hindering the adoption of commercial configurable devices. For this reason, in this paper, we exploit approximate computing design paradigm to trade hardware area overhead off for classification accuracy. In particular, starting from trained DT models and employing precision-scaling technique, we explore approximate decision tree variants by means of multiple objective optimization problem, demonstrating a significant performance improvement targeting field-programmable gate array devices. Mario Barbareschi, Salvatore Barone, Nicola Mazzocca |
Knowl. Inf. Syst. | 3 |
| 2021 | On the Adoption of Physically Unclonable Functions to Secure IIoT DevicesabstractThe growing convergence among information and operation technology worlds in modern Industrial Internet of Things (IIoT) systems is posing new security challenges, requiring the adoption of novel security mechanisms involving light architectures and protocols to cope with IIoT devices resource constraints. In this article, we investigate the adoption of physically unclonable functions (PUFs) in the IIoT context, and propose the design of a PUF-based architecture (Pseudo-PUF), obtained by suitably combining a weak PUF and an encryption module, that can be successfully adopted to implement advanced security primitives while meeting the existing requirements of IIoT devices in terms of cost and resource demand. To demonstrate the feasibility of our proposal, we analyzed the overall quality of different Pseudo-PUF instances with respect to well-known PUF quality metrics, and found that it is possible to obtain good results with a negligible impact on the devices, thus making our approach suited to IIoT deployments. Mario Barbareschi, Valentina Casola, Alessandra De Benedictis, Erasmo La Montagna, Nicola Mazzocca |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | A Security and Privacy Validation Methodology for e-Health Systemsabstracte-Health applications enable one to acquire, process, and share patient medical data to improve diagnosis, treatment, and patient monitoring. Despite the undeniable benefits brought by the digitization of health systems, the transmission of and access to medical information raises critical issues, mainly related to security and privacy. While several security mechanisms exist that can be applied in an e-Health system, they may not be adequate due to the complexity of involved workflows, and to the possible inherent correlation among health-related concepts that may be exploited by unauthorized subjects. In this article, we propose a novel methodology for the validation of security and privacy policies in a complex e-Health system, that leverages a formal description of clinical workflows and a semantically enriched definition of the data model used by the workflows, in order to build a comprehensive model of the system that can be analyzed with automated model checking and ontology-based reasoning techniques. To validate the proposed methodology, we applied it to two case studies, subjected to the directives of the EU GDPR regulation for the protection of health data, and demonstrated its ability to correctly verify the fulfillment of desired policies in different scenarios. Flora Amato, Valentina Casola, Giovanni Cozzolino, Alessandra De Benedictis, Nicola Mazzocca, Francesco Moscato 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2020 | An abstract reasoning architecture for privacy policies monitoring
Flora Amato, Luigi Coppolino, Salvatore D'Antonio, Nicola Mazzocca, Francesco Moscato 0001, Luigi Sgaglione |
Future Gener. Comput. Syst. | 4 |
| 2020 | An OSLC-based environment for system-level functional testing of ERTMS/ETCS controllers
Roberto Nardone, Stefano Marrone 0001, Ugo Gentile, Aniello Amato, Gregorio Barberio, Massimo Benerecetti, Renato De Guglielmo, Beniamino Di Martino, Nicola Mazzocca, Adriano Peron, Gaetano Pisani, Luigi Velardi, Valeria Vittorini |
J. Syst. Softw. | 9 |
| 2019 | PUF-Enabled Authentication-as-a-Service in Fog-IoT SystemsabstractFog-IoT systems enable to distribute computing, control, storage, and networking functions closer to edge devices, in order to improve efficiency and reduce latency. In order to cope with the multitude of security issues raised by the lack of centralized control and by the exposure of user sensitive data, suitable security solutions must be devised to protect data and thwart malicious attempts to compromise and take control over communication. In this paper, we propose a mutual authentication scheme relying upon the adoption of Physically Unclonable Functions (PUFs), which enables fog nodes and resource-constrained IoT devices to mutually prove their respective identities during communication, while meeting the existing low resource consumption requirements. The scheme is partially offered in an as-a-service fashion, thanks to the adoption of a cloud automation framework that facilitates its set-up on fog nodes. Mario Barbareschi, Alessandra De Benedictis, Erasmo La Montagna, Antonino Mazzeo, Nicola Mazzocca |
WETICE | 5 |
| 2019 | A PUF-based mutual authentication scheme for Cloud-Edges IoT systems
Mario Barbareschi, Alessandra De Benedictis, Erasmo La Montagna, Antonino Mazzeo, Nicola Mazzocca |
Future Gener. Comput. Syst. | 5 |
| 2019 | A model-driven approach for vulnerability evaluation of modern physical protection systems
Annarita Drago, Stefano Marrone 0001, Nicola Mazzocca, Roberto Nardone, Annarita Tedesco, Valeria Vittorini |
Softw. Syst. Model. | 3 |
| 2018 | Automatic generation of formal models for diagnosability of DESabstractThis paper aims at defining a model-driven approach for the diagnosability analysis of discrete event systems (DES). The proposed approach can be adopted during the design of modern control systems, in which many sensors and actuators are employed and the diagnosability of faults within a certain delay could be an issue. The proposal represents a first step towards an automatic model-driven process which derive formal models from a complete high-level specification of DESs. The specification activity of our approach relies on the Dynamic STate Machine (DSTM) formalism, a new language that extends state machines with dynamic instantiation, interrupts and asynchronous communication. The paper will describe how we can automatically derive Petri net and Promela models from the high-level DSTM specification. The former model can be used to apply diagnosability analysis approaches proposed in the DES community, while the latter can be used to apply model checking techniques. An application of the proposed model-driven approach is described by deriving both a PN and a Promela model for the well-known railway level crossing benchmark. Roberto Nardone, Gianmaria De Tommasi, Nicola Mazzocca, Alfredo Pironti 0002, Valeria Vittorini |
ETFA | 3 |
| 2018 | A Model-Based Evaluation Methodology for Smart Energy SystemsabstractThe huge amount of data collected everyday for different purposes by a multitude of smart devices enables the delivery of added-value services to end-users by means of smart applications. Among them, the applications devoted to optimizing the energy consumption through smart power grids are gaining more and more attention due to their impact on both the environment and the costs for the users. The design and evaluation of Smart Energy systems is very complex due to the heterogeneity of involved devices and technologies, and to the high variability of energy production and consumption profiles. In this regard, in this paper we propose a model-based methodology for the evaluation of Smart Energy systems, which merges system modeling and cognitive computing techniques to obtain a representation of the systems' behavior that takes into account a data-driven characterization of the workload and of the overall context. Such a representation allows to estimate properties of interest in different operative conditions, and can be profitably used to make design choices and to tune the application behavior during operation based on collected data. In order to demonstrate the effectiveness of our proposal, we present an example Smart Energy system modeled by means of the Stochastic Activity Network (SAN) formalism, and we show how it is possible to perform several analyses on the system configuration by means of model simulations. Alessandra De Benedictis, Nicola Mazzocca, Roberto Nardone, Salvatore Venticinque |
SMARTCOMP | 2 |
| 2018 | Model driven design and evaluation of security level in orchestrated cloud services
Flora Amato, Nicola Mazzocca, Francesco Moscato 0001 |
J. Netw. Comput. Appl. | 2 |
| 2018 | A PUF-based hardware mutual authentication protocol
Mario Barbareschi, Alessandra De Benedictis, Nicola Mazzocca |
J. Parallel Distributed Comput. | 3 |
| 2017 | Dynamic state machines for modelling railway control systems
Massimo Benerecetti, Renato De Guglielmo, Ugo Gentile, Stefano Marrone 0001, Nicola Mazzocca, Roberto Nardone, Adriano Peron, Luigi Velardi, Valeria Vittorini |
Sci. Comput. Program. | 5 |
| 2015 | An integrated framework for securing semi-structured health records
Flora Amato, Giuseppe De Pietro, Massimo Esposito, Nicola Mazzocca |
Knowl. Based Syst. | 4 |
| 2014 | A Semantic Support for Testing Activities of Safety-Critical Embedded SystemsabstractTesting is a relevant activity for the development life-cycle of Safety Critical Embedded systems. In particular much effort is spent for design of test cases, where natural language description of system requirements must be translated into test scripts, which must automatically executed to check correctness and achievement of target service levels. Semantic and text analysis are used here to support developers for the management of test documents to speedup and improve the testing definition phase. Facilities for both advanced classification, indexing and discovery of test documents are provided. Alessio Venticinque, Nicola Mazzocca, Salvatore Venticinque |
CISIS | 2 |
| 2014 | Traffic dynamics and vulnerability in hypercube communication networksabstractIn this paper we introduce the hypercube topology and show effects over the performance of communication networks in term of throughput and average lifetime. Hypercube network structures have been proposed as effective topologies to increase the network performance. We test this hypothesis by considering appropriate nonlinear traffic generation models and comparing the performance of hypercube networks with that of other network topologies which were already studied in the literature. We show that the hypercube network structure presents better features combining some of the advantages of regular lattices with those of other more complex network structures. Mario di Bernardo, Elisa Maini, Antonio Manzalini, Nicola Mazzocca |
ISCAS | 4 |
| 2014 | The dynamic placement of virtual network functionsabstractThis paper addresses the problem of managing highly dynamic network and service environments, where virtual nodes and virtual links are created and destroyed depending on traffic volumes, service requests, or high-level goals such as reduction in energy consumption. This problem will be one of the main technical challenges to be faced in the evolution towards Future Networks (FN). Emerging paradigms such as Software Defined Networks (SDN) and Network Function Virtualization (NfV) are concrete steps towards infrastructures where network functions and services will be executed as applications in ensembles of virtual machines (VMs) hosted in pervasive standard hardware resources located across a network. The paper argues that in order to manage these virtual infrastructures there is a need to introduce high-level systems orchestration. The paper describes an architecture based on an orchestrater that ensures the automatic placement of the virtual nodes and the allocation of network services on them, supported by a monitoring system that collects and reports on the behaviour of the resources. The orchestrater manages the creation and removal of the virtual nodes, as well as configuring, monitoring, running and stopping software on them. As a proof of these concepts, a distributed orchestrater prototype has been designed, implemented and tested with the results of different placement algorithms presented. Stuart Clayman, Elisa Maini, Alex Galis, Antonio Manzalini, Nicola Mazzocca |
NOMS | 5 |
| 2014 | ASP-based optimized mapping in a simulink-to-MPSoC design flow
Alessandro Cilardo, Dario Socci, Nicola Mazzocca |
J. Syst. Archit. | 3 |
| 2014 | Towards Model-Driven V&V assessment of railway control systems
Stefano Marrone 0001, Francesco Flammini, Nicola Mazzocca, Roberto Nardone, Valeria Vittorini |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2013 | Performance Evaluation of Video Analytics for Surveillance On-Board Trains
Valentina Casola, Mariana Esposito, Francesco Flammini, Nicola Mazzocca, Concetta Pragliola |
ACIVS | 4 |
| 2013 | Efficient and scalable OpenMP-based system-level designabstractIn this work we present an experimental environment for electronic system-level design based on the OpenMP programming paradigm. Fully compliant with the OpenMP standard, the environment allows the generation of heterogeneous hardware/software systems exhibiting good scalability with respect to the number of threads and limited performance overheads. Based on well-established OpenMP benchmarks, the paper also presents some comparisons with high-performance software implementations as well as with previous proposals oriented to pure hardware translation. The results confirm that the proposed approach achieves improved results in terms of both efficiency and scalability. Alessandro Cilardo, Luca Gallo, Antonino Mazzeo, Nicola Mazzocca |
DATE | 4 |
| 2013 | Design space exploration for high-level synthesis of multi-threaded applications
Alessandro Cilardo, Luca Gallo, Nicola Mazzocca |
J. Syst. Archit. | 3 |
| 2013 | Exploiting Vulnerabilities in Cryptographic Hash Functions Based on Reconfigurable HardwareabstractCryptanalysis, i.e., the study of methods for breaking cryptographic algorithms, can greatly benefit from hardware acceleration as a key aspect enabling high-performance attacks. This work investigates the new opportunities inherently provided by a particular class of hardware technologies, i.e., reconfigurable hardware devices, addressing the cryptanalysis of the SHA-1 hash function as a case study. We show how hardware reconfiguration enables some unexplored approaches such as algorithm and architecture exploration, as well as on-the-fly system specialization relying on hardware programmability. We also identify some new cryptanalysis methods, including two novel techniques for SHA-1 cryptanalysis called interbit constraints and constraint relaxation. Relying on the proposed approaches, we designed an FPGA-based platform targeting 71- and 75-round versions of SHA-1. Under the same cost budget, the estimated times for a collision achieved by the platform are at least one order of magnitude lower than other solutions based on high-end supercomputing facilities, reaching the highest performance/cost ratio for SHA-1 collision search and providing a striking confirmation of the impact of hardware reconfigurability. Alessandro Cilardo, Nicola Mazzocca |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | CloSe: A Cloud SaaS for Semantic Document CompositionabstractNowadays a large number of companies world-wide has moved their applications in the cloud, exploiting a lot of types of functions, such as customer relationship management, human resources, accounting and document sharing. In this work we propose "'CloSe"', a cloud system for document composition, which offers editing/composing aiding services by exploiting semantic based technology. Close is the evolution, in cloud technology, of a monolithic system architecture for document processing, based on semantic methodologies, that we have developed in the past years. We intend to migrate our system procedures to the Internet Cloud technology that guarantees several advantages in terms of usability, scalability and fault tolerance. The proposed system will help the users in the process of writing documents, exploiting information and data contained in apposite document bases, collected from heterogeneous sources, in order to suggest proper fragments to be inserted into the document. We have produced a system prototype that realizes semantic retrieval functionalities, in order to assist the specialist and generic user in the document composition aiding activities. Moreover we have reported some experimental results that we have carried out for evaluating the impact of the system on enhancing user effort in composing documents by suggesting appropriate document segments, which encouraged us to extend the system in the cloud. Flora Amato, Antonino Mazzeo, Nicola Mazzocca, Sara Romano |
CISIS | 3 |
| 2012 | Model-Driven V&V Processes for Computer Based Control Systems: A Unifying Perspective
Francesco Flammini, Stefano Marrone 0001, Nicola Mazzocca, Roberto Nardone, Valeria Vittorini |
ISoLA (2) | 3 |
| 2012 | Solution Workflows for Model-Based Analysis of Complex SystemsabstractThe development and analysis of increasingly complex systems require the intensive use of models and of sophisticated approaches to systems modeling. This paper focuses on workflows supporting the solution of complex, composed, formal models used to study and/or develop real-world systems. The workflows we deal with orchestrate multiple distributed tools and applications in order to provide the user with a powerful, composed solution environment. The aim is to automate and reproduce analysis and simulation tasks starting from a high level, graph-based description of the model to be solved. This paper thus introduces solution workflows and presents the Solution Process Definition Language (SPDL) for the specification of solution workflows processes. One of the key elements of SPDL is its formal semantics, which allow for unambiguous specification of its constructs and validation of the workflows. A workflow pattern analysis of SPDL is also provided. SPDL and its execution environment, the OsMoSys framework, are then applied to a homeland security scenario. The OsMoSys framework and the SPDL language provide a practical contribution to the applicability of model engineering techniques by enabling the semiautomatic solution of complex models. Francesco Moscato 0001, Valeria Vittorini, Flora Amato, Antonino Mazzeo, Nicola Mazzocca |
IEEE Trans Autom. Sci. Eng. | 5 |
| 2011 | Augmenting Surveillance System Capabilities by Exploiting Event Correlation and Distributed Attack Detection
Francesco Flammini, Nicola Mazzocca, Alfio Pappalardo, Concetta Pragliola, Valeria Vittorini |
ARES | 2 |
| 2011 | A Semantic-based Document Processing Framework: A Security PerspectiveabstractThe coexistence of different formats and physical supports to store data is one of the main open issues in document management systems, in particular, the presence of unstructured data represents a huge limitation for the elaboration and analysis of many documents and processes. At this aim we are exploiting the adoption of different techniques to analyze texts and automatically extract relevant information, concepts or complex relations, in this paper we proposed a general framework for data transformation and implemented such model trough an architecture based on semantic analysis. The analysis that can be performed on data has many different applications, in this paper we illustrate an interesting perspective related on how to enforce a fine grained access control on sensitive data that are in capsulated in unstructured, monolithic files. We also presented a case study for the formalization and protection of e-health medical records. Flora Amato, Valentina Casola, Nicola Mazzocca, Sara Romano |
CISIS | 3 |
| 2011 | Petri Net Modelling of Physical Vulnerability
Francesco Flammini, Stefano Marrone 0001, Nicola Mazzocca, Valeria Vittorini |
CRITIS | 3 |
| 2011 | Revisiting Application-Dependent Test for FPGA DevicesabstractFPGA testing poses a number of challenges related to both the complexity of the device under test and the opportunities introduced by its support to hardware reconfiguration. Application-dependent testing (ADT) provides an effective answer to these challenges. The study presented in this paper identifies some limitations of state-of-the-art ADT approaches, which prevent a complete coverage for bridging faults and the practical applicability of the algorithms for test configuration generation. The work also introduces a set of new techniques that enabled us to overcome these limitations and effectively extend previous methodologies for ADT. Alessandro Cilardo, Carmelo Lofiego, Antonino Mazzeo, Nicola Mazzocca |
ETS | 4 |
| 2011 | An Integrated Approach for Availability and QoS Evaluation in Railway Systems
Antonino Mazzeo, Nicola Mazzocca, Roberto Nardone, Luca D'Acierno, Bruno Montella, Vincenzo Punzo, Egidio Quaglietta, Immacolata Lamberti, Pietro Marmo |
SAFECOMP | 2 |
| 2010 | Securing a tiered re-taskable sensing systemabstractSensor Networks are widely used in several application domains thanks to their data acquisition and data processing capabilities. They are well suited to a multitude of monitoring and surveillance applications and are often involved in mission-critical tasks, thus making security a primary concern. Many architectures and protocols have been proposed to address this issue, mainly based on cryptographic operations, but it still represents an open research area: such techniques in fact, to be effective, often require complex computations and a large amount of dedicated resources, which are not available on sensor platforms according to the existing technology. Nevertheless, if considering tiered sensor networks, where tiny motes coexist with more powerful nodes, it is possible to perform some complex and efficient security schemes by exploiting the different capabilities of such nodes. In this paper we present an secure architectural proposal of the Tenet system, a tiered re-taskable sensor network architecture. Specifically, we have integrated some security library into the Tenet architecture in order to implement a hybrid cryptosystem. The latter combines symmetric and asymmetric cryptographic schemes to benefit of the security provided by asymmetric protocols and the better performance of symmetric ones. Alessandra De Benedictis, Andrea Gaglione, Nicola Mazzocca |
IAS | 3 |
| 2009 | Automatic instantiation of abstract tests on specific configurations for large critical control systemsabstractAbstract Computer‐based control systems have grown in size, complexity, distribution and criticality. In this paper a methodology is presented to perform an ‘abstract testing’ of such large control systems in an efficient way: an abstract test is specified directly from system functional requirements and has to be instantiated in more test runs to cover a specific configuration, comprising any number of control entities (sensors, actuators and logic processes). Such a process is usually performed by hand for each installation of the control system, requiring a considerable time effort and being an error‐prone verification activity. To automate a safe passage from abstract tests, related to the so‐called generic software application, to any specific installation, an algorithm is provided, starting from a reference architecture and a state‐based behavioural model of the control software. The presented approach has been applied to a railway interlocking system, demonstrating its feasibility and effectiveness in several years of testing experience. Copyright © 2008 John Wiley & Sons, Ltd. Francesco Flammini, Nicola Mazzocca, Antonio Orazzo |
Softw. Test. Verification Reliab. | 2 |
| 2008 | Testing Complex Safety-Critical Systems in SOA ContextabstractDue to its simplicity and ease of application, testing is the main technique by which complex safety-critical systems can be verified in order to find both omission and commission bugs. Strict requirements on such systems, joined to the necessity to re-execute the test set in the regression testing campaign, provokes a test case set and testing time explosion that can be tackled only by means of the use of parallel independent testing environments. Parallelism in such environments is not easy to accomplish due to the heterogeneity of processes, methodologies and tools. Service Oriented Architecture (SOA) is a key factor in the development of an organic modelling and execution methodology in order to build a heterogeneous and distributed environment that supports a system testing. In this paper we propose an adoption of a classical SOA reference architecture in order to address the build of such an environment for safety-critical control systems. Moreover we provide indications on the integration of SOA specific architecture components with existing centralized testing environments providing an example in signalling railway control systems. Renato Donini, Stefano Marrone 0001, Nicola Mazzocca, Antonio Orazzo, Domenico Papa, Salvatore Venticinque |
CISIS | 3 |
| 2008 | Quantitative Security Risk Assessment and Management for Railway Transportation Infrastructures
Francesco Flammini, Andrea Gaglione, Nicola Mazzocca, Concetta Pragliola |
CRITIS | 3 |
| 2008 | A Study on Multiformalism Modeling of Critical Infrastructures
Francesco Flammini, Valeria Vittorini, Nicola Mazzocca, Concetta Pragliola |
CRITIS | 3 |
| 2008 | Virtual Scan Chains for Online Testing of FPGA-based Embedded SystemsabstractWhile techniques for offline testing of FPGAs, either manufacturing-oriented or application-oriented, are today relatively mature, in critical applications such as avionics, space, and even numerous commercial products it is often necessary to perform online testing. In this paper, we present a technique for online testing of digital designs implemented on an FPGA. The approach enables application-oriented testing, in that it covers the subset of the FPGA which is actually used for the implemented design, and considers scenarios where the FPGA component is a part of a larger embedded system. The proposed approach is in fact based on a software framework, which acts as an abstraction layer for reconfigurable hardware resources. Essentially, the framework exposes to software applications a Register-Transfer Level view of the underlying hardware, allowing test procedures to be implemented as software programs. Our approach is especially advantageous when memory is a constraint, the case of many embedded systems. As proved by experimental results, in fact, test procedures turn out to be very compact and much more memory-efficient than conventional approaches relying on static sets of FPGA testing configurations to be stored in system memory. Alessandro Cilardo, Nicola Mazzocca, Luigi Coppolino |
DSD | 2 |
| 2008 | Self-optimization of secure web services
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
Comput. Commun. | 3 |
| 2007 | Static evaluation of Certificate Policies for GRID PKIs interoperabilityabstractValidating an end-entity X.509 digital certificate prior to authorizing it for using a resource into the computational grid has become a widely studied topic due to its importance for security. A more comprehensive validation process involves not only a real-time check on the credential's status, but also an evaluation of the trust level applicable to its certification authority. Nowadays policy management authorities (PMAs) gather grid CAs fulfilling a minimum set of requirements defined in an authentication profile thus guaranteeing a trusted interoperability environment for grid projects. Currently this is a manual process that only results in a binary decision (the CA is able to become part of the PMA or not), however in practice, different CAs offer different security levels. In this paper we present ways to apply the reference evaluation methodology (REM) to automatically obtain the security level of a CA. The described process is based on the building of a formalized policy template for grid certificate policies. This methodology has been used to evaluate the security level offered by a set of EUGridPMA's CAs; the obtained results are then conveyed to relying parties using an infrastructure composed of CertiVeR's validation service and the Open GRid Ocsp (OGRO) middleware for the Globus Toolkit 4, thus providing enough information for a comprehensive certificate validation decision Valentina Casola, Nicola Mazzocca, Jesus Luna, Oscar Manso, Manuel Medina |
ARES | 2 |
| 2007 | Building Autonomic and Secure Service Oriented Architectures with MAWeS
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
ATC | 3 |
| 2007 | Interoperable Grid PKIs Among Untrusted Domains: An Architectural Proposal
Valentina Casola, Jesus Luna, Oscar Manso, Nicola Mazzocca, Manuel Medina, Massimiliano Rak |
GPC | 4 |
| 2007 | A policy-based evaluation framework for Quality and Security in Service Oriented ArchitecturesabstractIn dynamic cooperative architectures that are based on services (SOA), customers are not only interested in service functionalities, but also in their quality, such as performance, cost, reliability, security and so on. In this scenario, models, techniques and tools supporting the selection of the best service are needed. In this paper, we propose an evaluation framework that includes a flexible quality meta-model for formalising customer and provider views of quality, and a decisional model defining a systematic approach for comparing offered and requested quality of services. We also illustrate the applicability of the framework in a Web service (WS) scenario. Valentina Casola, Anna Rita Fasolino, Nicola Mazzocca, Porfirio Tramontana |
ICWS | 3 |
| 2007 | Automatic Analysis of Control Flow inWeb Services Composition ProcessesabstractComposition of web services is of great interest to support business-to-business collaboration and provide value added services with desired properties or capabilities. Nevertheless, the standard languages used to create business processes from composite web services lack of formal definition of their semantics and tools to support the analysis of a business process. In this paper we provide a practical approach to formal verification of BPEL4WS executable processes. A syntax-driven operational semantics for BPEL4WS is introduced and an automatic verifier is presented in order to perform a semantic analysis of the flow constructs used in the definition of BPEL4WS processes. Giusy Di Lorenzo, Francesco Moscato 0001, Nicola Mazzocca, Valeria Vittorini |
PDP | 3 |
| 2007 | A policy-based methodology for security evaluation: A Security Metric for Public Key InfrastructuresabstractThe security of complex infrastructures depends on many technical and organizational issues that need to be properly addressed by a security policy. For purpose of our discussion, we define a security policy as a document that states what is and what is not allowed in a system during normal operation; it consists of a set of rules that could be expressed in formal, semi-formal or very informal language. In many contexts, a system can be considered secure and trustworthy if the policy enforced by its security administrator is trustworthy too; from this standpoint it is possible to evaluate the system security by evaluating its policy. In this paper we present a policy-based methodology to formalize and compare policies, and a Security Metric to evaluate the security level that a system is able to grant. All the steps of the methodology will be illustrated with an operative approach, by directly applying it to a real case study: the semi-automated Cross Certification among Public Key Infrastructures. Valentina Casola, Antonino Mazzeo, Nicola Mazzocca, Valeria Vittorini |
J. Comput. Secur. | 3 |
| 2006 | Web Services Composition and Delivery Using a Mobile Agents Based InfrastructureabstractThe integration of Web services and software agents brings new opportunities and helps in defining new kinds of services too. A very interesting approach comes from the adoption of "mobile agents" to design and develop a service oriented architecture that supports the access to distributed services by heterogeneous handheld devices. This paper describes the functional model and the architecture design of a platform for services composition and delivery. Mobile agents are able to access and compose services accessing them by standard interfaces. User authentication, service discovery and publication, personalization are other provided facilities. Technological interoperability is provided by Web services technology. Code mobility is exploited to reconfigure the server platform moving agents to the available nodes, or to reconfigure the user devices providing it with the needed client software Rocco Aversa, Beniamino Di Martino, Nicola Mazzocca, Salvatore Venticinque |
ISPDC | 3 |
| 2006 | MAGDA: A Mobile Agent based Grid Architecture
Rocco Aversa, Beniamino Di Martino, Nicola Mazzocca, Salvatore Venticinque |
J. Grid Comput. | 3 |
| 2006 | Elliptic Curve Cryptography EngineeringabstractIn recent years, elliptic curve cryptography (ECC) has gained widespread exposure and acceptance, and has already been included in many security standards. Engineering of ECC is a complex, interdisciplinary research field encompassing such fields as mathematics, computer science, and electrical engineering. In this paper, we survey ECC implementation issues as a prominent case study for the relatively new discipline of cryptographic engineering. In particular,we show that the requirements of efficiency and security considered at the implementation stage affect not only mere low-level, technological aspects but also, significantly, higher level choices, ranging from finite field arithmetic up to curve mathematics and protocols. Alessandro Cilardo, Luigi Coppolino, Nicola Mazzocca, Luigi Romano |
Proc. IEEE | 3 |
| 2005 | A Novel Unified Architecture for Public-Key CryptographyabstractWe propose a fully-parallel, bit-sliced unified architecture designed to perform modular multiplication/exponentiation and GF(2/sup M/) multiplication as the core operations of RSA and EC cryptography. The architecture uses a radix-2 Montgomery technique for modular arithmetic, and a radix-4 MSD-first approach for GF(2/sup M/) multiplication. To the best of our knowledge, it is the first unified proposal based on such a hybrid approach. The architecture structure is bit-sliced and is highly regular, modular, and scalable, as virtually any datapath length can be obtained at a linear cost in terms of hardware resources and no costs in terms of critical path. Our proposal outperforms all similar unified architectures found in the technical literature in terms of clock count and critical path. The architecture has been implemented on a field-programmable gate array (FPGA) device. A highly compact and efficient design was obtained taking advantage of the architectural characteristics. Alessandro Cilardo, Antonino Mazzeo, Nicola Mazzocca, Luigi Romano |
DATE | 3 |
| 2005 | Workflow Pattern Analysis in Web Services Orchestration: The BPEL4WS Example
Francesco Moscato 0001, Nicola Mazzocca, Valeria Vittorini, Giusy Di Lorenzo, Paola Mosca, Massimo Magaldi |
HPCC | 2 |
| 2005 | Reconfigurable systems self-healing using mobile hardware agentsabstractTechnology constantly follows the needs of the marketplace. The current trend of producing digitally-aware environments keeps growing, and it is very likely that in the future we will be surrounded by many heterogeneous devices which communicate each other through distributed and wireless interfaces. We will see a new society of digital systems, whose individuals will be ubiquitous and heterogeneous systems interacting together and providing high productivity and great flexibility. Two technologies seem to be emerging to support this new paradigm: mobile data agents to handle the complexity and heterogeneity of networked infrastructures, and real-time reconfigurable systems to implement flexible, adaptable, and high performance individuals. This paper analyzes how the innovative aspects of these new technologies could be exploited to implement innovative and efficient test and repair strategies Alfredo Benso, Alessandro Cilardo, Nicola Mazzocca, Liviu Miclea, Paolo Prinetto, Szilárd Enyedi |
ITC | 3 |
| 2005 | A hierarchical distributed-shared memory parallel Branch & Bound application with PVM and OpenMP for multiprocessor clusters
Rocco Aversa, Beniamino Di Martino, Nicola Mazzocca, Salvatore Venticinque |
Parallel Comput. | 3 |
| 2004 | A tamper resistant hardware accelerator for RSA cryptographic applications
Giacinto Paolo Saggese, Luigi Romano, Nicola Mazzocca, Antonino Mazzeo |
J. Syst. Archit. | 3 |
| 2004 | The OsMoSys approach to multi-formalism modeling of systems
Valeria Vittorini, Mauro Iacono, Nicola Mazzocca, Giuliana Franceschinis |
Softw. Syst. Model. | 3 |
| 2003 | FPGA-Based Implementation of a Serial RSA Processor
Antonino Mazzeo, Luigi Romano, Giacinto Paolo Saggese, Nicola Mazzocca |
DATE | 4 |
| 2003 | An FPGA-Based Performance Analysis of the Unrolling, Tiling, and Pipelining of the AES Algorithm
Giacinto Paolo Saggese, Antonino Mazzeo, Nicola Mazzocca, Antonio G. M. Strollo |
FPL | 3 |
| 2003 | A Case Study of Application Analytical Modeling in Heterogeneous Computing Environments: Cholesky Factorization in a NOW
Rocco Aversa, Nicola Mazzocca, Umberto Villano |
J. Supercomput. | 2 |
| 2002 | A Technique for FPGA Synthesis Driven by Automatic Source Code Analysis and Transformations
Beniamino Di Martino, Nicola Mazzocca, Giacinto Paolo Saggese, Antonio G. M. Strollo |
FPL | 2 |
| 2002 | Building a dependable system from a legacy application with CORBA
Domenico Cotroneo, Nicola Mazzocca, Luigi Romano, Stefano Russo 0001 |
J. Syst. Archit. | 2 |
| 2002 | Efficient model checking of properties of a distributed application: a multimedia case studyabstractAbstract A system supporting video on demand is modeled in the process calculus CCS (Calculus of Communicating Systems), while some properties are expressed in a temporal logic and verified by means of the model checkers of the North Carolina Concurrency Workbench. This application was chosen as a case study to evaluate the usefulness of a methodology, by means of which a property is checked on reduced models obtained issuing abstractions of the system on the basis of the formula. Experimental results are shown and discussed. Copyright © 2001 John Wiley & Sons, Ltd. Nicola Mazzocca, Antonella Santone, Gigliola Vaglini, Valeria Vittorini |
Softw. Test. Verification Reliab. | 1 |
| 2001 | Secure Access to Personalized Web ServicesabstractIn the recent years, Web systems have undergone dramatic changes, since they evolved from plain publishing-oriented facilities to sophisticated service providers. The article describes a practical experience in the provision of limited exposure services on the Web. In particular, the paper illustrates functions and procedures for requesting, issuing, and installing digital certificates, which are used to access the services provided by a Web portal. Digital certificates are an effective means for authenticating users in a networked environment. Users who participate in the experiments can install their personal certificate on their favourite browser and enter personalized service areas. Giovanni Battista Barone, N. Margarita, Antonino Mazzeo, Nicola Mazzocca, Luigi Romano |
PRDC | 4 |
| 2001 | Parallel program analysis and restructuring by detection of point-to-point interaction patterns and their transformation into collective communication constructs
Beniamino Di Martino, Antonino Mazzeo, Nicola Mazzocca, Umberto Villano |
Sci. Comput. Program. | 3 |
| 2000 | Dependability analysis of transmission techniques for MPEG-2 streamsabstractThis paper presents some redundancy-based transmission strategies, suitable for MPEG (Moving Picture Experts Group) coded multimedia streams. We focus on version 2 of the standard, which is a major compression scheme for distributed VoD (Video on Demand) systems. In such systems, multimedia data transmitted from a server to a client, is to be delivered and rendered within pre-defined time constraints. Typical values range between 100 to 200 ms. Due to these constraints, developing effective redundancy and transmission mechanisms is not a simple task. The effectiveness of the suggested schemes is evaluated, under varying fault rates and network load conditions. The evaluation is done via simulated fault-injection, i.e. by simulating the behavior of the system while faults are injected to its individual components. In particular, we concentrated on the impact-on the quality of the delivered service-of transient faults in the communication infrastructure. Luigi Romano, Nicola Mazzocca, Antonio Coronato, Giuseppe De Pietro |
PRDC | 2 |
| 2000 | Reducing Parallel Program Simulation Complexity by Static Analysis
Rocco Aversa, Beniamino Di Martino, Nicola Mazzocca, Umberto Villano |
J. Supercomput. | 3 |
| 1999 | A Simulated Fault Injection Tool for Dependable VoD Application DesignabstractThis work presents a simulation-based tool for dependability-oriented design of Video on Demand (VoD) applications. The tool is organized in a layered architecture, so that simulation models can be built and detailed according to a hierarchical and modular approach. The higher layer, namely the Application Level, provides a variety of objects to rapidly model fundamental components typically found in most VoD systems. The lower level, namely the Network Level, consists of the basic building blocks needed to represent the communication infrastructure of a distributed system. The paper illustrates how to combine the tool's built-in objects, in order to construct a simulated model of a generic multimedia application. Some of the potentialities of the tool are then demonstrated by performing dependability evaluation of a real VoD system prototype. Fault injection experiments are conducted on a simulated model of DiVA, a distributed architecture for VoD applications, currently under development at the University of Naples. Luigi Romano, G. Capuozzo, Antonino Mazzeo, Nicola Mazzocca |
PRDC | 4 |
| 1998 | Formal Specification of Concurrent Systems: A Structured ApproachabstractCSP and Petri Nets are powerful formalisms for the specification and the analysis of concurrent systems. We present an approach to their integration to take advantage of both formalisms. In particular the GSPN class is used to address dependability and real-time aspects. In this paper an algorithmic transformation from a trace-based specification of a concurrent system to a Petri Net model is described. Causal dependencies between behaviours of the system components are introduced in the net model through the definition of external assumptions. The steps of the integration are illustrated by applying them to an unmanned transportation problem. Antonino Mazzeo, Nicola Mazzocca, Stefano Russo 0001, Carlo Savy, Valeria Vittorini |
Comput. J. | 2 |
| 1998 | Efficiency measurements in heterogeneous distributed computing systems: from theory to practiceabstractThis paper addresses the problem of the measurement of efficiency in heterogeneous distributed computing systems. After a discussion on the unsuitability of the traditional notion of efficiency for such systems, a new efficiency metric (generalized efficiency) is introduced by finding the analytical expression of the maximum speedup that can be achieved for a given problem in a heterogeneous system. Generalized efficiency takes into account the heterogeneity of computing resources and is consistent with the definition commonly used for homogeneous systems. The main characteristics of this metric are illustrated, and the problem of performing practical measurements is dealt with thoroughly. Four case studies exploring the whole spectrum of heterogeneous computing systems and of possible classes of applications are presented. Finally, the proposal is compared to related work, and the utility and the limits of generalized efficiency are discussed. © 1998 John Wiley & Sons, Ltd. Antonino Mazzeo, Nicola Mazzocca, Umberto Villano |
Concurr. Pract. Exp. | 2 |
| 1998 | Developing Applications for Heterogeneous Computing Environments Using Simulation: A Case Study
Rocco Aversa, Antonino Mazzeo, Nicola Mazzocca, Umberto Villano |
Parallel Comput. | 3 |
| 1997 | Formal methods integration for the specification of dependable distributed systems
Nicola Mazzocca, Stefano Russo 0001, Valeria Vittorini |
J. Syst. Archit. | 1 |
| 1997 | A Systematic Approach to the Petri Net Based Specification of Concurrent Systems
Antonino Mazzeo, Nicola Mazzocca, Stefano Russo 0001, Valeria Vittorini |
Real Time Syst. | 2 |
| 1995 | Performance analysis of distributed memory computers with parallel node architecture
Giulio Iannello, Antonino Mazzeo, Nicola Mazzocca |
J. Syst. Softw. | 3 |
| 1994 | Communication Workload Analysis for Symmetric Concurrent Systems
Giulio Iannello, Nicola Mazzocca |
J. Parallel Distributed Comput. | 2 |
| 1994 | On the Computation of Performance Characteristics of Concurrent Programs Using GSPNs
Gianfranco Balbo, Susanna Donatelli, Giuliana Franceschinis, Antonino Mazzeo, Nicola Mazzocca, Marina Ribaudo |
Perform. Evaluation | 5 |