Angelica Liguori

dblp:263/6386 · DBLP profile ↗
← Back
18ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0001-9402-7375ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 11 · 5 first-author · 10 since 2021Databases, data management, data science and information retrieval · 5 · 4 first-author · 5 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MalARN: An Adversarial Reconstruction Network for Improving Detection of Evolving Malware
Francesco Pasqualatto, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Giuseppe Manco 0001, Ettore Ritacco, Antonino Rullo
ISMIS4
2026 Seeing the invisible: Detection of stealth DoS attacks using variational U-Net-like models
abstract
The increasing sophistication of cyberattacks targeting companies and organizations continues to challenge the effectiveness of modern defense systems. Among these threats, slow Denial-of-Service (slow DoS) attacks are particularly difficult to detect, as they rely on evasion strategies that add significant complexity to cybersecurity efforts. Modern intrusion detection systems, especially those based on deep learning, have become essential tools in combating such attacks. However, their performance is often hindered by challenges such as limited data availability, noisy inputs, and the presence of out-of-distribution samples. Furthermore, their dependence on large labeled datasets makes detecting subtle or rare attack patterns particularly challenging. To overcome these limitations, this work proposes a novel unsupervised deep learning framework for detecting slow DoS attacks. The proposed approach incorporates a customized preprocessing pipeline to improve input data quality and leverages a sparse variational U-Net-like architecture for robust anomaly identification. Extensive experiments conducted on three real-world datasets demonstrate the ability of the framework to accurately and efficiently detect slow DoS attacks, highlighting its robustness, generalizability, and practical suitability for deployment in operational environments.
Enrico Cambiaso, Francesco Folino, Massimo Guarascio 0001, Angelica Liguori, Antonino Rullo
J. Inf. Secur. Appl.4
2026 FuDGE: Modeling full dynamic graph evolution
abstract
Research in neural generative models for dynamic networks is constantly evolving, and sophisticated solutions have been exploited to characterize the long-term evolution of temporal graphs. Despite the efforts in the literature, state-of-the-art models face the problem of handling changes in the graph structure by relying on prior knowledge, compromising the model’s flexibility. In this paper, we propose a graph-size invariant probabilistic generative model, named $$\textrm{FuDGE}$$ , Fully Dynamic Graph Evolution, for predicting the graph evolution through step-wise changes in the graph structure. $$\textrm{FuDGE}$$ can generate evolving graphs by exploring the whole node space, thus ensuring fast and effective generation. We evaluate $$\textrm{FuDGE}$$ on real and synthetic benchmark datasets and compare its performance against state-of-the-art competitors. The results demonstrate that our approach offers a competitive advantage in generation and prediction quality compared to existing literature. The code is publicly available at https://github.com/FuDGE2023/fudge .
Angelica Liguori, Simone Mungari, Ettore Ritacco, Edoardo Serra, Giuseppe Manco 0001
J. Intell. Inf. Syst.1
2026 A deep learning-based approach for stegomalware sanitization in digital images
abstract
Abstract Malware is increasingly endowed with steganographic mechanisms for concealing malicious data to avoid detection or bypass security measures. As a result, an emerging wave of threats named stegomalware has started to rise. Among the various approaches, real-world stegomalware primarily hides information within digital images, for instance, to retrieve additional payloads or configuration data. Unfortunately, developing attack-agnostic mitigation tools is difficult, especially due to the tight relation between the image format and the steganographic technique. Therefore, this paper presents an autoencoder-based approach to perform sanitization , i.e., to disrupt the malicious content hidden in images without altering their visual quality. For this purpose, we used an enhanced U-Net-like neural architecture, and we compared our idea against other mechanisms, including JPG transcoding and simple addition of Gaussian noise. Results obtained by considering different hiding patterns and realistic payloads showcased the effectiveness of our approach. Moreover, the U-Net-based sanitization solution prevents the recovery of the payload while preserving the original image quality and reducing risks arising from side-channel attacks.
Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione
J. Intell. Inf. Syst.1
2026 Automated Membership Inference via Prompt-Based Attacks in Generative Models
Daniela Gallo, Angelica Liguori, Ettore Ritacco, Luca Caviglione, Fabrizio Durante, Giuseppe Manco 0001
Mach. Learn.2
2026 DALEK: combining deep active learning and explanations methods for fake news detection on COVID-19
Carmela Comito, Massimo Guarascio 0001, Angelica Liguori, Francesco Sergio Pisani
Neural Comput. Appl.3
2025 Analysis and Detection of Android Stegomalware: the Impact of the Loading Stage
abstract
Due to the increasing use of advanced offensive techniques, the mitigation of Android malware is an urgent need.An emerging attack trend exploits steganography to conceal malicious payloads within applications to make attacks stealthier.Even if works on "stegomalware" are starting to emerge, they primarily focus on the multimedia part of the attack chain, i.e., on how to detect hidden data in images or videos.Therefore, this work aims at understanding whether the loading stage required for the extraction of cloaked information can generate detection signatures.To this aim, we develop a proofof-concept implementation, which has been repacked within a real Android application and tested against several malware detection engines provided by VirusTotal.To anticipate possible offensive campaigns, we also performed tests by considering threat actors able to obfuscate the bytecode of the loader or the entire APK.Results indicate that standard tools are not ready to face stegomalware targeting Android applications.Therefore, we provide indications on how to improve forensics and attribution phases for Android malware endowed with information hiding capabilities.
Diego Soi, Silvia Lucia Sanna, Giacomo Benedetti, Angelica Liguori, Leonardo Regano, Luca Caviglione, Giorgio Giacinto
IH&MMSec4
2025 Modeling events and interactions through temporal processes: A survey
abstract
In real-world scenarios, numerous phenomena generate a series of events that occur in continuous time. Point processes provide a natural mathematical framework for modeling these event sequences. In this comprehensive survey, we aim to explore probabilistic models that capture the dynamics of event sequences through temporal processes. We revise the notion of event modeling and provide the mathematical foundations that underpin the existing literature on this topic. To structure our survey effectively, we introduce an ontology that categorizes the existing approaches considering three horizontal axes: modeling , inference and estimation , and application . We conduct a systematic review of the existing approaches, with a particular focus on those leveraging deep learning techniques. Finally, we delve into the practical applications where these proposed techniques can be harnessed to address real-world problems related to event modeling. Additionally, we provide a selection of benchmark datasets that can be employed to validate the approaches for point processes.
Angelica Liguori, Luciano Caroprese, Marco Minici, Bruno M. Veloso, Francesco Spinnato, Mirco Nanni, Giuseppe Manco 0001, João Gama 0001
Neurocomputing1
2025 Breaking domain barriers: mixture of experts for cross-domain fake news detection
abstract
Social media have become a key tool for rapidly spreading information worldwide, amplifying the risks of misinformation and fake news. This is also intensified by the fact that fake news covers a wide range of topics across multiple domains. Machine learning, particularly language models, offers a promising solution for detecting fake news. However, a major limitation of existing methods is their inability to classify instances from new or unseen domains. To tackle this issue, we introduce MERMAID, a mixture of experts approach that leverages the knowledge from different specialized models to classify examples from unknown domains. Each expert is initially trained on a specific known domain and then fine-tuned using data from other known domains. A model merging procedure is then applied to combine related experts, reducing the number of models required for predicting instances from unknown domains. In addition, our approach can effectively be used in few-shot learning scenarios, where a small amount of data from the target/unknown domain is available during training. Experiments on five benchmark datasets demonstrate the effectiveness of our method in both zero-shot and few-shot learning settings.
Angelica Liguori, Francesco Sergio Pisani, Carmela Comito, Massimo Guarascio 0001, Giuseppe Manco 0001
Mach. Learn.1
2024 No Country for Leaking Containers: Detecting Exfiltration of Secrets Through AI and Syscalls
abstract
Containers offer lightweight execution environments for implementing microservices or cloud-native applications. Owing to their ubiquitous diffusion jointly with the complex interplay of hardware, computing, and network resources, effectively enforcing container security is a difficult task. Specifically, runtime detection of threats poses many challenges since container images are often immutable, and many malware deploys obfuscation or elusive mechanisms. Therefore, in this work, we propose a deep-learning-based approach for identifying the presence of two containers colluding to covertly leak secret information. In more detail, we consider a threat actor trying to exfiltrate a 4,096-bit private TLS key via five different covert channels. To decide whether containers are colluding for leaking data, the deep learning model is fed with statistical indicators of the syscalls, which are built starting from simple counters. Results indicate the effectiveness of our approach, even if some adjustments are needed to reduce the number of false positives.
Marco Zuppelli, Massimo Guarascio 0001, Luca Caviglione, Angelica Liguori
ARES4
2024 Beyond the Horizon: Using Mixture of Experts for Domain Agnostic Fake News Detection
Carmela Comito, Massimo Guarascio 0001, Angelica Liguori, Giuseppe Manco 0001, Francesco Sergio Pisani
DS (2)3
2024 Siamese Networks for Unsupervised Failure Detection in Smart Industry
Angelica Liguori, Ettore Ritacco, Giuseppe Benvenuto, Salvatore Iiritano, Giuseppe Manco 0001, Massimiliano Ruffolo
ISMIS1
2024 Erasing the Shadow: Sanitization of Images with Malicious Payloads Using Deep Autoencoders
Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione
ISMIS1
2024 Learning autoencoder ensembles for detecting malware hidden communications in IoT ecosystems
abstract
Abstract Modern IoT ecosystems are the preferred target of threat actors wanting to incorporate resource-constrained devices within a botnet or leak sensitive information. A major research effort is then devoted to create countermeasures for mitigating attacks, for instance, hardware-level verification mechanisms or effective network intrusion detection frameworks. Unfortunately, advanced malware is often endowed with the ability of cloaking communications within network traffic, e.g., to orchestrate compromised IoT nodes or exfiltrate data without being noticed. Therefore, this paper showcases how different autoencoder-based architectures can spot the presence of malicious communications hidden in conversations, especially in the TTL of IPv4 traffic. To conduct tests, this work considers IoT traffic traces gathered in a real setting and the presence of an attacker deploying two hiding schemes (i.e., naive and “elusive” approaches). Collected results showcase the effectiveness of our method as well as the feasibility of deploying autoencoders in production-quality IoT settings.
Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli
J. Intell. Inf. Syst.4
2024 Robust anomaly detection via adversarial counterfactual generation
abstract
Abstract The capability to devise robust outlier and anomaly detection tools is an important research topic in machine learning and data mining. Recent techniques have been focusing on reinforcing detection with sophisticated data generation tools that successfully refine the learning process by generating variants of the data that expand the recognition capabilities of the outlier detector. In this paper, we propose $$\textrm{ARN}$$ ARN , a semi-supervised anomaly detection and generation method based on adversarial counterfactual reconstruction. $$\textrm{ARN}$$ ARN exploits a regularized autoencoder to optimize the reconstruction of variants of normal examples with minimal differences that are recognized as outliers. The combination of regularization and counterfactual reconstruction helps to stabilize the learning process, which results in both realistic outlier generation and substantially extended detection capability. In fact, the counterfactual generation enables a smart exploration of the search space by successfully relating small changes in all the actual samples from the true distribution to high anomaly scores. Experiments on several benchmark datasets show that our model improves the current state of the art by valuable margins because of its ability to model the true boundaries of the data manifold.
Angelica Liguori, Ettore Ritacco, Francesco Sergio Pisani, Giuseppe Manco 0001
Knowl. Inf. Syst.1
2022 Ensembling Sparse Autoencoders for Network Covert Channel Detection in IoT Ecosystems
Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli
ISMIS4
2021 Adversarial Regularized Reconstruction for Anomaly Detection and Generation
abstract
We propose ARN, a semisupervised anomaly detection and generation method based on adversarial reconstruction. ARN exploits a regularized autoencoder to optimize the reconstruction of variants of normal examples with minimal differences, that are recognized as outliers. The combination of regularization and adversarial reconstruction helps to stabilize the learning process, which results in both realistic outlier generation and substantial detection capability. Experiments on several benchmark datasets show that our model improves the current state-of-the-art by valuable margins because of its ability to model the true boundaries of the data manifold.
Angelica Liguori, Giuseppe Manco 0001, Francesco Sergio Pisani, Ettore Ritacco
ICDM1
2020 Deep Autoencoder Ensembles for Anomaly Detection on Blockchain
Francesco Scicchitano, Angelica Liguori, Massimo Guarascio 0001, Ettore Ritacco, Giuseppe Manco 0001
ISMIS2