VLDB 2026 Research / reviewers in the wild / expert
Pietro Spadaccino
dblp:242/4691
· DBLP profile ↗
10ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0002-5920-680XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Demo: Re-designing MAC Spoofing for Transparent MITM Attacks Using Linux Network NamespacesabstractIn wired networks, Medium Access Control (MAC) spoofing is a well-known and extensively studied class of network security attacks in which an adversary impersonates a legitimate host by falsifying its MAC address. Despite existing defense stan- dards, such attacks remain relevant in contemporary networks. MAC spoofing can enable Man-In-The-Middle (MITM) attacks, allowing an attacker to intercept and inject traffic while posing as the victim whose MAC address has been compromised. Despite its conceptual simplicity, implementing a fully transparent MAC spoofing MITM attack is non-trivial. Existing techniques fail to maintain transparency from the victim’s perspective and may disrupt connectivity. While traffic interception is relatively straightforward, injecting traffic on behalf of the victim without affecting the victim’s normal operation is more challenging. Achieving such transparency typically requires custom code and specialized libraries that may lack portability across platforms or operate in user space rather than kernel space, thereby imposing performance limitations. This demo presents an implementation of a MAC spoofing-based MITM attack that enables transparent interception and injection of packets while impersonating the victim, without requiring custom code. The approach operates entirely in kernel space, leveraging Linux networking names- paces, and ensures complete transparency to both the victim host and its communication endpoint. Pietro Spadaccino, Stefano Servillo, Pierluigi Locatelli, Francesca Cuomo |
INFOCOM | 1 |
| 2026 | Edgent: Towards an Agentic AI Framework for eBPF-Based Service Deployment and Orchestration at the EdgeabstractThe evolution towards 6G edge-cloud ecosystems demands autonomous, intent-based network management to handle unprecedented infrastructure complexity. While Large Language Models offer promising capabilities for translating high-level user intents into network configurations, current monolithic approaches suffer from cognitive overload, hallucinations, and a profound inability to safely execute low-level data plane mutations. To bridge this gap, we introduce Edgent, a novel framework that integrates hierarchical Agentic AI with Extended Berkeley Packet Filter technologies via the Model Context Protocol. Edgent utilizes a state-driven Supervisor, enhanced by Retrieval-Augmented Generation, to decompose abstract human intents into deterministic execution graphs and dynamically delegate tasks to domain-specific worker agents. We empirically validate the framework by autonomously deploying a distributed, in-kernel DDoS mitigation pipeline across scaled containerized topologies containing up to 85 nodes. Extensive evaluations demonstrate high orchestration reliability; notably, even heavily quantized Small Language Models (e.g., 4B parameters) achieve near-perfect zero-shot execution and 100% overall task completion through autonomous error recovery. Finally, latency and resource profiling confirm that the multi-agent framework can be efficiently driven by fully localized models compatible with orchestration tasks directly within resource-constrained edge environments, therefore this work positions Edgent as a pragmatic step toward the realization of zero-touch nextgeneration networks. Raffaele Di Tommaso, Gianluca Davoli, Pietro Spadaccino, Walter Cerroni |
NetSoft | 3 |
| 2026 | SPARQ: An Optimization Framework for the Distribution of AI-Intensive Applications Under Non-Linear Delay ConstraintsabstractNext-generation real-time compute-intensive applications, such as extended reality, multi-user gaming, and autonomous transportation, are increasingly composed of heterogeneous AI-intensive functions with diverse resource requirements and stringent latency constraints. While recent advances have enabled very efficient algorithms for joint service placement, routing, and resource allocation for increasingly complex applications, current models fail to capture the non-linear relationship between delay and resource usage that becomes especially relevant in AI-intensive workloads. In this paper, we extend thecloud network flowoptimization framework to support queueing-delay-aware orchestration of distributed AI applications over edge-cloud infrastructures. We introduce two execution models, Guaranteed-Resource (GR) and Shared-Resource (SR), that more accurately capture how computation and communication delays emerge from system-level resource constraints. These models incorporate M/M/1 and M/G/1 queue dynamics to represent dedicated and shared resource usage, respectively. The resulting optimization problem is non-convex due to the non-linear delay terms. To overcome this, we develop SPARQ, an iterative approximation algorithm that decomposes the problem into two convex sub-problems, enabling joint optimization of service placement, routing, and resource allocation under nonlinear delay constraints. The modeling approach is validated against real-world data. Simulation results demonstrate that the SPARQ not only offers a more faithful representation of system delays, but also substantially improves resource efficiency and the overall cost-delay tradeoff compared to existing state-of-the-art methods. Pietro Spadaccino, Paolo Di Lorenzo, Sergio Barbarossa, Antonia M. Tulino, Jaime Llorca |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | Realistic Traffic Modeling and Performance Evaluation of a Blockchain-Enabled LoRaWANabstractIn the Internet of Things (IoT) scenario, two of the most important innovations in recent years are Edge Computing and Low Power technologies, like LoRaWAN. Edge Computing facilitates computations to be executed in proximity to users, delivering advantages such as reduced response times, optimized bandwidth usage, and enhanced scalability for IoT applications. On the other hand, LoRaWAN stands out as an IoT communication technology engineered for secure, low data-rate transmissions with high energy efficiency. However, implementing the edge computing paradigm into LoRaWAN presents challenges due to its centralized cloud-based architecture, which conflicts with the principles of edge computing. In previous years, proposals have emerged to decentralize LoRaWAN and integrate it at the edge level. However, these proposals often result in the creation of new protocols that diverge from the standard LoRaWAN framework and are not backward compatible. Furthermore, existing proposals are typically tested on arbitrary testbeds and traffic conditions, failing to account for the diverse applications and traffic characteristics inherent in real-world scenarios. In this study, we enhance and refine DeLoRaN, our system architecture facilitating the decentralized operation of LoRaWannetworks at the edge layer, where network control operations are executed at the gateway level. Additionally, we develop and present a data-driven traffic model for LoRaWAN that reflects real-world scenarios, derived from extensive capturing of LoRaWantraffic over several months. This model leverages packets from devices across multiple networks and serves diverse applications not under our direct control. Using this model, we validate the performance of DeLoRaN by simulating device traffic generation based on our data-driven realistic model. Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo |
WCNC | 2 |
| 2025 | Detection and Mitigation of Jamming Attacks in LoRaWan Using Machine LearningabstractThe security and efficiency of low-power wide area networks (LPWANs) for connecting an ever-growing number of IoT devices, expected to exceed 40 billion by 2030, are becoming increasingly important. LoRaWAN, a leading LPWAN technology, enables long-range, low-power communications but remains susceptible to jamming attacks that degrade network performance at the physical layer. This paper introduces a robust framework for detecting and mitigating jamming in LoRaWAN networks using comprehensive threat modeling and machine learning-based countermeasures. The framework simulates two types of jamming attacks: a channel-oblivious jammer, which transmits continuously to randomly interfere with channels, and a channel-aware jammer, which selectively disrupts active transmissions. We evaluate LoRaWAN's resilience through extended simulations in the ns-3 module, adapted for jamming scenarios. Additionally, we provide a high-precision LSTM-based detection model to identify jamming patterns and a mitigation strategy to counteract the channel-oblivious jammer, including an automatic restoration process for returning devices to normal operation post-disruption. The proposed framework enhances network robustness against jamming, showing that ML-based detection significantly reduces disruptions. Stefano Di Pinto, Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo |
WCNC | 3 |
| 2025 | Estimating autonomous system risk levels by analyzing IXP route server RIBabstractThe security of Border Gateway Protocol (BGP) operations at Internet Exchange Points (IXPs) is critical to ensuring the integrity of data exchanges between Internet Service Providers (ISPs). A key challenge in BGP is its trust-based route sharing, which introduces vulnerabilities that attackers can exploit to hijack or disrupt traffic. While mechanisms like Internet Routing Registries (IRRs) and the Resource Public Key Infrastructure (RPKI) have been developed to mitigate these risks, their effectiveness is often undermined by inherent design flaws that limit their reliability. This paper presents a novel tool designed to address these security gaps in IXP infrastructures. By analyzing the Routing Information Base (RIB) of an IXP’s route server, the tool identifies possible prefix hijacking attacks. These prefixes serve as input for calculating a Risk Level metric for each Autonomous System (AS), offering IXP operators insights into anomalous behaviors. The effectiveness of the metric is validated through its application to well-known attack scenarios. Finally, we showcase the application of this tool through an analysis of real-world data from the route server of a major Italian IXP. Stefano Servillo, Pietro Spadaccino, Flavio Luciani, Francesca Cuomo |
Comput. Commun. | 2 |
| 2023 | Analysis and emulation of BGP hijacking eventsabstractBorder Gateway Protocol (BGP) is the standard protocol used for inter-domain routing in the Internet. Since it was designed without built-in security mechanisms, nowadays it results in being vulnerable to various security issues. Although countermeasures exist to secure BGP sessions, they are not widely used due to lack of knowledge and complexity of the setup. The aim of this paper is to raise awareness about routing security in BGP, to provide a methodology to deepen the analysis of BGP incidents and a tool to reproduce them in a sandbox environment, to better understand how these issues arise and why it is crucial to have security countermeasures in place. The paper examines a recent BGP incident in March 2022, where a Russian ISP hijacked an IP prefix belonging to Twitter. A comprehensive analysis of the incident is performed, including how it spread throughout the Internet and presenting the powerful toolkit used for the analysis. In the last section, the paper explains the usage and the potentiality of the tool KathBGPBuilder, which can recreate a real BGP deployment with minimal manual configuration using open data collected from RIPEstat. This tool can be utilized to experiment and recreate real BGP incidents, or to test security mechanisms. Pietro Spadaccino, Sara Bruzzese, Francesca Cuomo, Flavio Luciani |
NOMS | 1 |
| 2022 | Privacy monitoring of LoRaWAN devices through traffic stream analysisabstractLoRaWAN is a wireless technology developed to transmit over long distances using low power. It runs over the proprietary LoRa radio modulation and provides fundamental IoT requirements such as bi-directional communication, end-to-end security, key management, mobility, and localization services. Despite LoRaWAN guarantees confidentiality and integrity of application payload, the wireless nature of the medium causes that an eavesdropper, listening to the network communications, can collect non-encrypted information stored in the packets. In particular, it can obtain two sensible metadata elements, called DevAddress e DevEUI. Since the association between these elements can involve privacy issues, LoRaWAN forces endpoints to expose their DevEUI only during the association procedure to avoid the association with the corresponding DevAddress. In the first part of this work, we prove how an adversary can link them nevertheless. Then we explain the consequences for the privacy of devices and users that joined the network and propose PIVOT (Privacy-Monitoring), an analyzer system for LoRaWAN that detects in real-time vulnerable endpoints. Furthermore, we explain how the metrics used in PIVOT can support the operator in applying adequate countermeasures. Finally, we test our scheme on a simulated LoRaWAN application and examine the results obtained. Francesco Terenzi, Pietro Spadaccino, Francesca Cuomo |
WoWMoM | 2 |
| 2022 | Discovery privacy threats via device de-anonymization in LoRaWANabstractThis is a PDF file of an article that has undergone enhancements after acceptance, such as the addition of a cover page and metadata, and formatting for readability, but it is not yet the definitive version of record.This version will undergo additional copyediting, typesetting and review before it is published in its final form, but we are providing this version to give early visibility of the article.Please note that, during the production process, errors may be discovered which could affect the content, and all legal disclaimers that apply to the journal pertain. Pietro Spadaccino, Domenico Garlisi, Francesca Cuomo, Giorgio Pillon, Patrizio Pisani |
Comput. Commun. | 1 |
| 2021 | Hijacking Downlink Path Selection in LoRaWANabstractWith the rise of the IoT, many protocols have been developed in order to fulfill the need for a wireless connectivity that assures energy efficiency and low-data rates. LoRaWAN is certainly one of the most widely used protocols. The LoRaWAN 1.1 specification aims to fix some serious security vulnerabilities in the 1.0 specification, however there still exist critical points to address. In this paper, we identify an attack that can affect LoRaWAN 1.0 and 1.1 networks, which hijacks the downlink path from the Network Server to an End Device. The attack exploits the deduplication procedure and the gateway selection during a downlink scheduling by the Network Server, which is in general implementation-dependent. The attack scheme has been proven to be easy to implement, not requiring physical layer-specific operations such as signal jamming, and could target many LoRaWAN devices at once. We discuss the implications of this attack and identify the possible mitigations that could be adopted by network providers to address this vulnerability. Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo |
GLOBECOM | 2 |