Tommaso Caiazzi

dblp:267/2788 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
14since 2021 · last 2026
0009-0007-2852-6310ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 PANACEA: A Model-Based Framework for Self-Protecting Systems
Stefano Iannucci, Emiliano Casalicchio, Francesco Guerra 0001, Sara Pederzoli, Matteo Paganelli, Tommaso Caiazzi, Simone Albero
COMPSAC6
2026 Aggregate Local, Sync Global: A Hierarchical Approach to Efficient Geo-Distributed LLM Training
Francesco De Luca, Francesco De Nadai, Mariano Scazzariello, Tommaso Caiazzi, Alireza Farshin, Marco Chiesa, Giuseppe Di Battista
INFOCOM4
2026 Queue-Mem: Energy-Efficient Hardware Storage for Advanced Network Function Acceleration
Mariano Scazzariello, Tommaso Caiazzi, Hamid Ghasemirahni, Dejan Kostic, Marco Chiesa
NSDI2
2026 From attack trees to timed stochastic games: A novel intrusion response approach
abstract
Most dynamic Intrusion Response Systems (IRSs) use models to characterize the attack patterns and the dynamics of the protected system. They are typically based on some mathematical framework and require a low-level modeling activity that is often difficult and error-prone, even for the experienced end-user. Furthermore, most of the model-based approaches proposed so far do not structurally include the notion of time, which is necessary to model non-instantaneous defense and attack actions. In this paper, we introduce a novel methodology for the automatic generation of IRSs based on Timed Competitive Stochastic Games from augmented Attack-Defense Trees (ADT), a formalism that is commonly used to represent attack patterns and to build IRSs based on a static mapping between attack and response. We formally and empirically prove that: (i) using a static mapping between attack and response or selecting the action with the immediate minimum cost to counter the attack without long-term planning leads to an underestimation of the defense cost; (ii) the total defense cost of a defense policy obtained with an IRS based on the proposed methodology is lower than or equal to the defense cost that can be obtained with an IRS based on static mapping; (iii) not considering time leads to an underestimation of the defense cost. We then perform experiments showing the scalability of the proposed approach in terms of planning time and memory usage.
Tommaso Caiazzi, Stefano Iannucci, Valerio Marini, Matteo Foschi, Riccardo Torlone
Comput. Secur.1
2025 Leveraging Semi-Supervised Learning to Reduce Labeled Data Requirements in Intrusion Detection
abstract
Deep learning-based intrusion detection systems often depend on large labeled datasets and generating such data is both costly and sometimes impractical. To overcome this limitation, we propose a hybrid learning approach built on a transformer architecture. Our method integrates a self-supervised pretraining phase, where the model is trained to reconstruct noised segments of input traffic data from unlabeled sequences, with a supervised fine-tuning stage that requires only a fraction of labeled data. Our experiments demonstrate the effectiveness of this hybrid approach, achieving up to 98.8% of the performance of the supervised models using 50% of the labeled data. Index Terms—Intrusion Detection, Hybrid Learning
Simone Albero, Tommaso Caiazzi, Stefano Iannucci, Paolo Merialdo, Riccardo Torlone
COMPSAC2
2025 A Novel Architecture for Cyber-Resilient Self-Protecting Systems Based on Blockchain
abstract
Self-Protecting Systems (SPS) rely on an autonomic manager to detect and mitigate cyber threats. However, a major challenge in SPS design is ensuring the security of the autonomic manager itself, as its compromise could lead to complete control of the system by an attacker. In this work, we propose a cyber-resilient SPS architecture that leverages permissioned blockchain technology to enhance the trustworthiness of both Intrusion Detection (ID) and Intrusion Response (IR). The proposed architecture is technology-agnostic and adaptable to various ID and IR techniques. We implement a prototype using Quorum and a smart contract and evaluate its performance in terms of overhead and scalability. Experimental results show that the proposed architecture is technically feasible and that it introduces a minimal overhead with respect to non-smart contract-based transactions, and that it can be used on production systems with high event rates despite the inherent scalability issues deriving from the usage of the chosen blockchain technology.
Tommaso Caiazzi, Stefano Iannucci, Valerio Marini, Diego Pennino, Maurizio Pizzonia, Riccardo Torlone
COMPSAC1
2025 SRv6 Meets DetNet: A New Behavior for Low Latency and High Reliability
abstract
The rise of new applications, such as interactive remote presence, online gaming, and video-assisted remote control of industrial machinery, necessitates enhanced requirements in terms of throughput and delay stability. Many efforts have been made to address these needs, with Deterministic Networking (DetNet) being one such initiative. DetNet aims to guarantee delivery with low latency and minimal jitter, ensuring high reliability and performance for time-sensitive applications. However, DetNet applicability in real-world scenarios is limited due to the need of a lower-layer protocol supporting resource reservation procedures (e.g., MPLS), and the lack of publicly available implementations. In this work, we present SRv6 Live-Live, an easy-to-deploy and highly scalable implementation of DetNet functions using the Segment Routing over IPv6 (SRv6) model. The SRv6 Live-Live behavior replicates packets of a selected flow across multiple paths at the ingress of the SRv6 domain and drops redundant replicas at the egress. After discussing insights about the paths’ selection strategy, we provide a SRv6 Live-Live implementation for programmable data planes using P4. We also propose the use of SRv6 Live-Live for best path selection at line rate, in SD-WAN scenarios. The main results obtained in the extensive performance evaluation are that SRv6 Live-Live preserves the throughput in case of congestion and reduces the tail end-to-end delay with a marginal impact on best-effort flows.
Marco Polverini, Antonio Cianfrani, Tommaso Caiazzi, Mariano Scazzariello
IEEE J. Sel. Areas Commun.3
2024 Deliberately Congesting a Switch for Better Network Functions Performance
abstract
Traditional wisdom suggests maintaining minimal occupancy in the port queues of network devices to prevent packet delays or drops en route to their destination. In this paper, however, we explore the unconventional idea of deliberately congesting the queues of a network device to enhance the performance of a Network Function (NF) deployment. The key intuition behind this approach is to utilize the existing memory available in the switch queues to store packet payloads while their headers are processed on an external NF processor. We present two techniques for congesting a port on a switch: i) self-clocking packet recirculation, which recirculates packets within the switch to automatically achieve the correct queuing delay, and ii) a proportional controller using multicast forwarding, which adjusts the rate of packet forwarding based on the level of congestion. We evaluate our approaches both in simulations and a prototype.
Mariano Scazzariello, Tommaso Caiazzi, Marco Chiesa
ICNP2
2024 Achieving Best-path Selection at Line Rate through the SRv6 Live-Live Behavior
abstract
The network programming model of the Segment Routing (SRv6) architecture offers the possibility to define new functions aiming at improving the network performance. In this paper we introduce SRv6 Live-Live, a new behavior for the SRv6 data plane. SRv6 Live-Live is based on two primitives: i) traffic duplication, performed at the ingress node, and ii) the traffic de-duplication, executed at the egress node. The proposed behavior is suitable for the service provisioning of traffic flows having stringent requirements in terms of reliability, low delay and high throughput. Our preliminary performance evaluation, conducted in an emulated environment and realized by using a prototype implementation based on P4, shows that SRv6 Live-Live enhances the performance of the selected traffic flows in challenging network scenarios, characterized by high level of packet corruption/loss and large values of bandwidth-delay products.
Marco Polverini, Antonio Cianfrani, Tommaso Caiazzi, Mariano Scazzariello, Ahmed Abdelsalam, Clarence Filsfils, Pablo Camarillo
NOMS3
2023 Nesting Containers for Faithful Datacenters Emulations
abstract
Datacenters are a critical part of the Internet infrastructure as they guarantee efficient deployment of a wide range of services. Since a considerable amount of datacenter failures is caused by software bugs and configuration errors, the management and testing of these networks is a crucial task. In this field, emulation-based digital twins have proven their effectiveness. To faithfully emulate the typical three layers hierarchy, composed of physical servers, virtual machines, and containers, the support for nested virtualization is a fundamental requirement. Further, the emulation of hyper-scale datacenters needs to leverage on horizontal scaling over a cluster of nodes. Existing container-based proposals do not meet both requirements. On the contrary, existing VM-based proposals meet such requirements, but they need complex configurations and high resource demands. We propose a container-based framework to faithfully emulate datacenters. This is a fundamental building block for designing datacenter digital twins, that would allow testing of real software implementations in a lightweight, scalable, and easily configurable environment.
Tommaso Caiazzi, Mariano Scazzariello, Samuele Quinzi, Lorenzo Ariemma, Maurizio Patrignani, Giuseppe Di Battista
NOMS1
2023 A High-Speed Stateful Packet Processing Approach for Tbps Programmable Switches
Mariano Scazzariello, Tommaso Caiazzi, Hamid Ghasemirahni, Tom Barbette, Dejan Kostic, Marco Chiesa
NSDI2
2022 Sibyl: a Framework for Evaluating the Implementation of Routing Protocols in Fat-Trees
abstract
Several data centers adopt fat-tree topologies, where high bisection bandwidth is achieved by interconnecting commodity hardware and by using specific routing solutions. These solutions, which include protocol implementations and configurations, are difficult to evaluate and test both for the density of fat-trees and for the complexity of the protocols. Also, since most issues show up only when a fault happens, it is unfeasible to perform such tests in a production environment. Additionally, the lack of standard testing procedures motivates an effort in developing solutions for such a critical task. In this paper, we propose a methodology devised for testing fat-tree routing protocol implementations. It adopts a wall-clock independent method to establish metrics, which permits normalizing the results of different routing protocol implementations independently from the execution environment. The methodology is implemented by Sibyl, a software framework developed to perform repeatable tests on arbitrary fat-tree topologies automatically. Sibyl also provides a set of tools to analyze the results and investigate implementation behaviors. We evaluate the methodology and Sibyl in three use cases. Such use cases witness a wide spectrum of situations where Sibyl is effective for analyzing, comparing, developing, and debugging routing protocol implementations.
Tommaso Caiazzi, Mariano Scazzariello, Leonardo Alberro, Lorenzo Ariemma, Eduardo Grampín, Giuseppe Di Battista
NOMS1
2021 MRT#: a Fast Multi-Threaded MRT Parser
Lorenzo Ariemma, Mariano Scazzariello, Tommaso Caiazzi
IM3
2021 VFTGen: a Tool to Perform Experiments in Virtual Fat Tree Topologies
Tommaso Caiazzi, Mariano Scazzariello, Lorenzo Ariemma
IM1
2020 Kathará: A Lightweight Network Emulation System
abstract
In computer networks, tests to ensure the correct behaviour of network equipment or protocols are often required. Because of the high cost of physical hardware, these tests are always performed in a virtual environment. Kathará is a network emulation system which accurately reproduces the behaviour of a real system. It can exploit several virtualization technologies leveraging on its modularity. Lately, Kathará has been rewritten to overcome some implementation limitations and performance issues. This paper presents the Kathará model and its new architecture, demonstrating its value, comparing its scalability and performance with Netkit (another state-of-the-art tool for network emulation) and with the previous version of Kathará.
Mariano Scazzariello, Lorenzo Ariemma, Tommaso Caiazzi
NOMS3