VLDB 2026 Research / reviewers in the wild / expert
Federico Turrin
dblp:247/4992
· DBLP profile ↗
12ranked-venue papers
0as first author
12since 2021 · last 2026
0000-0001-5660-2447ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Computer networks · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Electric Vehicles Security and Privacy: Challenges, Solutions, and Future NeedsabstractElectric Vehicles (EVs) share common technologies with classic fossil-fueled cars, but they also employ novel technologies and components (e.g., Charging System and Battery Management System) that create an unexplored attack surface for malicious users. Although several contributions in the literature explored cybersecurity aspects of particular components of the EV ecosystem (e.g., charging infrastructure), there is still no contribution to the holistic cybersecurity of EVs and their related technologies from a Cyber-Physical System (CPS) perspective. In this article, we provide the first in-depth study of the Security and Privacy (S&P) threats associated with the EV ecosystem. We analyze the threats associated with both the EV and the different charging solutions. Focusing on the CPS paradigm, we provide a detailed analysis of all the processes that an attacker might exploit to affect the S&P of both drivers and the infrastructure. To address the highlighted threats, we present possible solutions that might be implemented. We also provide an overview of possible future directions to guarantee the S&P of the EV ecosystem. Based on our analysis, we stress the need for EV-specific cybersecurity solutions to help both vehicle owners and infrastructure deployers securing the EV ecosystem. Alessandro Brighente, Mauro Conti, Denis Donadel, Radha Poovendran, Federico Turrin, Jianjing Zhou |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2026 | Replica-Based Moving Target Defense Against Injection Attacks in Software-Defined Industrial Control SystemsabstractRecent incidents have demonstrated the increasing vulnerability of Industrial Control Systems (ICSs) to sophisticated and targeted attacks orchestrated by adversaries with high motivation, resources, and domain knowledge. Among these threats, False Data Injection (FDI) attacks have emerged as one of the main security threats to ICSs, involving the deliberate manipulation or injection of false data into the control system to deceive or disrupt operations. FDI attacks pose a significant risk due to their high capacity of concealment and ability to evade intrusion detection systems that rely on accurate ICS models. In this paper, we presentdefclon, a novel Software-Defined Networking (SDN)-based Moving Target Defense (MTD) approach against FDI attacks.Defclonproactively replicates network packets across multiple network paths and adaptively selects a single path using a signaling game model to reach the destination end-device. We demonstrate the effectiveness of our approach through simulations, numerical analysis, and experiments on ICS network traffic and topologies. Experimental results show thatdefclonis able to not only mitigate the effects of FDI attacks, but also to introduce different levels of uncertainty without degrading network performance, significantly increasing the difficulty for adversaries to gather information and launch attacks. Xabier Etxezarreta, Federico Turrin, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | EVScout2.0: Electric Vehicle Profiling through Charging ProfileabstractElectric Vehicles (EVs) represent a green alternative to traditional fuel-powered vehicles. To enforce their widespread use, both the technical development and the security of users shall be guaranteed. Users’ privacy represents a possible threat that impairs the adoption of EVs. In particular, recent works showed the feasibility of identifying EVs based on the current exchanged during the charging phase. In fact, while the resource negotiation phase runs over secure communication protocols, the signal exchanged during the actual charging contains features peculiar to each EV. In what is commonly known as profiling, a suitable feature extractor can associate such features to each EV. In this article, we propose EVScout2.0 , an extended and improved version of our previously proposed framework to profile EVs based on their charging behavior. By exploiting the current and pilot signals exchanged during the charging phase, our scheme can extract features peculiar for each EV, hence allowing their profiling. We implemented and tested EVScout2.0 over a set of real-world measurements considering over 7,500 charging sessions from a total of 137 EVs. In particular, numerical results show the superiority of EVScout2.0 with respect to the previous version. EVScout2.0 can profile EVs, attaining a maximum of 0.88 for both recall and precision scores in the case of a balanced dataset. To the best of the authors’ knowledge, these results set a new benchmark for upcoming privacy research for large datasets of EVs. Alessandro Brighente, Mauro Conti, Denis Donadel, Federico Turrin |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2023 | OpenScope-sec: An ADS-B Simulator to Support the Security ResearchabstractAutomatic Dependent Surveillance–Broadcast (ADS-B) protocol is employed in air-ground communication systems to replace legacy radar-based air traffic control systems. However, despite being a recent technology, ADS-B communication does not include security measures. This exposes the communication to potential threats, including message spoofing or fake aircraft generation. To cope with such a security lack, the security community is actively proposing innovative solutions to protect ADS-B communication. However, testing and evaluating security frameworks is complex due to the limited number of simulators and the impossibility of conducting real-world experiments. Riccardo Cestaro, Mauro Conti, Elonora Mancini, Federico Turrin |
ARES | 4 |
| 2023 | Plug and Power: Fingerprinting USB Powered Peripherals via Power Side-channelabstractThe literature and the news regularly report cases of exploiting Universal Serial Bus (USB) devices as attack tools for malware injections and private data exfiltration. To protect against such attacks, security researchers proposed different solutions to verify the identity of a USB device via side-channel information (e.g., timing or electromagnetic emission). However, such solutions often make strong assumptions on the measurement (e.g., electromagnetic interference-free area around the device), on a device’s state (e.g., only at the boot or during specific actions), or are limited to one particular type of USB device (e.g., flash drive or input devices).In this paper, we present PowerID, a novel method to fingerprint USB peripherals based on their power consumption. PowerID analyzes the power traces from a peripheral to infer its identity and properties. We evaluate the effectiveness of our method on an extensive power trace dataset collected from 82 USB peripherals, including 35 models and 8 types. Our experimental results show that PowerID accurately recognizes a peripheral type, model, activity, and identity. Riccardo Spolaor, Federico Turrin, Mauro Conti, Xiuzhen Cheng |
INFOCOM | 3 |
| 2023 | Beware of Pickpockets: A Practical Attack against Blocking CardsabstractToday, we rely on contactless smart cards to perform several critical operations (e.g., payments and accessing buildings). Attacking smart cards can have severe consequences, such as losing money or leaking sensitive information. Although the security protections embedded in smart cards have evolved over the years, those with weak security properties are still commonly used. Among the different solutions, blocking cards are affordable devices to protect smart cards. These devices are placed close to the smart cards, generating a noisy jamming signal or shielding them. Whereas vendors claim the reliability of their blocking cards, no previous study has ever focused on evaluating their effectiveness. Marco Alecci, Luca Attanasio, Alessandro Brighente, Mauro Conti, Eleonora Losiouk, Hideki Ochiai, Federico Turrin |
RAID | 7 |
| 2023 | SENECAN: Secure KEy DistributioN OvEr CAN Through Watermarking and JammingabstractThe Control Area Network (CAN) represents the standard bus for intra-vehicular networks communication. Unfortunately, CAN was not designed to be a secure protocol. Communications over CAN do not take advantage of any security feature (e.g., cryptography and authentication), raising different vulnerabilities in critical applications. This lack of security is even more emphasized in recent CAN networks, which integrate remote connection capabilities (e.g., Bluetooth and WiFi). This insecurity-by-design led to the development of specific mechanisms to patch CAN vulnerabilities. Many proposed solutions rely on implementing optimized cryptographic primitives and assume that the cryptographic keys were previously shared among the different nodes during the production phase, omitting the issue related to keys distribution and update. We propose SENECAN, a solution that combines watermarking and wired jamming to secure the CAN bus's key distribution. Our solution leverages intentional interference and spread spectrum watermarking to achieve security properties such as confidentiality, integrity, authentication, and anti-replay. Compared to other works, SENECAN does not require any modification of the CAN protocol and system architecture. Instead, it requires an additional CAN transceiver and an initial transmission overhead. Finally, we tested the effectiveness and functioning of the SENECAN distribution schema in a real CAN environment. Simone Soderi, Riccardo Colelli, Federico Turrin, Federica Pascucci, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | EVExchange: A Relay Attack on Electric Vehicle Charging SystemabstractAbstract To support the increasing spread of Electric Vehicles (EVs), Charging Stations (CSs) are being installed worldwide. The new generation of CSs employs the Vehicle-To-Grid (V2G) paradigm by implementing novel standards such as the ISO 15118. This standard enables high-level communication between the vehicle and the charging column, helps manage the charge smartly, and simplifies the payment phase. This novel charging paradigm, which connects the Smart Grid to external networks (e.g., EVs and CSs), has not been thoroughly examined yet. Therefore, it may lead to dangerous vulnerability surfaces and new research challenges. In this paper, we present EVExchange , the first attack to steal energy during a charging session in a V2G communication: i.e., charging the attacker’s car while letting the victim pay for it. Furthermore, if reverse charging flow is enabled, the attacker can even sell the energy available on the victim’s car! Thus, getting the economic profit of this selling, and leaving the victim with a completely discharged battery. We developed a virtual and a physical testbed in which we validate the attack and prove its effectiveness in stealing the energy. To prevent the attack, we propose a lightweight modification of the ISO 15118 protocol to include a distance bounding algorithm. Finally, we validated the countermeasure on our testbeds. Our results show that the proposed countermeasure can identify all the relay attack attempts while being transparent to the user. Mauro Conti, Denis Donadel, Radha Poovendran, Federico Turrin |
ESORICS (1) | 4 |
| 2022 | ICSpot: A High-Interaction Honeypot for Industrial Control SystemsabstractHoneypots represent one of the most common solutions to study the adversaries’ movements and develop ad-hoc protection strategies. An effective honeypot can mimic a real system behavior and can be used to deceive the attacker and collect data related to his actions. However, current honeypots for Industrial Control Systems (ICSs) still lack realistic physical process simulation of the industrial network. Simulating an industrial process accurately while also enabling interaction with it is a complicated task. In this paper, we present ICSpot, the first ICS honeypot that addresses the current state-of-the-art limitations by integrating a physical process interaction. We developed our honeypot by leveraging different ad-hoc ICS tools resulting in a more completed and realistic solution. Then, we installed our honeypot on a local Internet Exchange Point and an AWS server, and we collected the interaction for 30 days. Finally, we report the finding related to the interaction collection and compare the results on the two installation points. Our results show that the physical process port we implemented is highly attractive to attackers. Mauro Conti, Francesco Trolese, Federico Turrin |
ISNCC | 3 |
| 2022 | VLC Physical Layer Security through RIS-aided Jamming Receiver for 6G Wireless NetworksabstractVisible Light Communication (VLC) is one the most promising enabling technology for future 6G networks to over-come Radio-Frequency (RF)-based communication limitations thanks to a broader bandwidth, higher data rate, and greater efficiency. However, from the security perspective, VLCs suffer from all known wireless communication security threats (e.g., eavesdropping and integrity attacks). For this reason, security re-searchers are proposing innovative Physical Layer Security (PLS) solutions to protect such communication. Among the different solutions, the novel Reflective Intelligent Surface (RIS) technology coupled with VLCs has been successfully demonstrated in recent work to improve the VLC communication capacity. However, to date, the literature still lacks analysis and solutions to show the PLS capability of RIS-based VLC communication. In this paper, we combine watermarking and jamming prim-itives through the Watermark Blind Physical Layer Security (WBPLSec) algorithm to secure VLC communication at the physical layer. Our solution leverages RIS technology to improve the security properties of the communication. By using an opti-mization framework, we can calculate RIS phases to maximize the WBPLSec jamming interference schema over a predefined area in the room. In particular, compared to a scenario without RIS, our solution improves the performance in terms of secrecy capacity without any assumption about the adversary's location. We validate through numerical evaluations the positive impact of RIS-aided solution to increase the secrecy capacity of the legitimate jamming receiver in a VLC indoor scenario. Our results show that the introduction of RIS technology extends the area where secure communication occurs and that by increasing the number of RIS elements the outage probability decreases. Simone Soderi, Alessandro Brighente, Federico Turrin, Mauro Conti |
SECON | 3 |
| 2021 | Assessing the Use of Insecure ICS Protocols via IXP Network Traffic AnalysisabstractModern Industrial Control Systems (ICSs) allow remote communication through the Internet using industrial protocols that were not designed to work with external networks. To understand security issues related to this practice, prior work usually relies on active scans by researchers or services such as Shodan. While such scans can identify publicly open ports, they cannot identify legitimate use of insecure industrial traffic. In particular, source-based filtering in Network Address Translation or Firewalls prevent detection by active scanning, but do not ensure that insecure communication is not manipulated in transit.In this work, we compare Shodan-only analysis with largescale traffic analysis at a local Internet Exchange Point (IXP), based on sFlow sampling. This setup allows us to identify ICS endpoints actually exchanging industrial traffic over the Internet. Besides, we are able to detect scanning activities and what other type of traffic is exchanged by the systems (i.e., IT traffic). We find that Shodan only listed less than 2% of hosts that we identified as exchanging industrial traffic, and only 7% of hosts identified by Shodan actually exchange industrial traffic. Therefore, Shodan does not allow to understand the actual use of insecure industrial protocols on the Internet and the current security practices in ICS communications. We show that 75.6% of ICS hosts still rely on unencrypted communications without integrity protection, leaving those critical systems vulnerable to malicious attacks. Giovanni Barbieri, Mauro Conti, Nils Ole Tippenhauer, Federico Turrin |
ICCCN | 4 |
| 2021 | USB powered devices: A survey of side-channel threats and countermeasuresabstractRecent technological innovations lead to the rise of a plethora of portable electronic devices such as smartphones, small household appliances, and other IoT devices. To power or recharge the battery of such devices, manufacturers identified in the ubiquitous Universal Serial Bus (USB) standard a convenient solution, as it enables both communication and energy supply. Unfortunately, the default trust on USB ports has been exploited by hackers to extract highly sensitive user data on such devices. Despite the efforts by security experts and manufacturers to detect and block this threat, an even more stealthy approach to undermine users privacy relies on side-channel attacks on the USB interface, such as electromagnetic emissions and power consumption. In this paper, we present a comprehensive survey of the state-of-the-art of side-channel analysis on the security of USB-powered devices. Differently from other surveys on USB-based attacks via the communication interface only, this survey considers research works that aim to infer or extract private information from the energy supply, the device itself, or unintentionally available functionalities. In particular, we consider this emergent trend of security work that was not previously considered in other surveys, such as the energy consumption and electromagnetic emission analyses, as well as Juice Filming Charging (JFC) attacks. We first analyze the physical properties of the side-channels and technical characteristics of such research work, we then summarize the countermeasures proposed in the state-of-the-art. Finally, we also identify some possible future directions to foster further research in this field. Riccardo Spolaor, Federico Turrin, Riccardo Bonafede, Mauro Conti |
High Confid. Comput. | 3 |