VLDB 2026 Research / reviewers in the wild / expert
Francesco Ardizzon
dblp:268/1623
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0001-6066-7550ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Challenge-Response to Authenticate Drone Communications: A Game Theoretic ApproachabstractAs drones are increasingly used in various civilian applications, the security of drone communications is a growing concern. In this context, we propose novel strategies for challengeresponse physical layer authentication (CR-PLA) of drone messages. The ground receiver (verifier) requests the drone to move to a defined position (challenge), and authenticity is verified by checking whether the corresponding measured channel gain (response) matches the expected statistic. In particular, the challenge is derived from a mixed strategy obtained by solving a zero-sum game against the intruder, which in turn decides its own positions. In addition, we derive the optimal strategy for multiround authentication, where the CR-PLA procedure is iterated over several rounds. We also consider the energy minimization problem, where legitimate users want to minimize the energy consumption without compromising the security performance of the protocol. The performance of the proposed scheme is tested in terms of both security and energy consumption through numerical simulations, considering different protocol parameters, different scenarios (urban and rural), different drone altitudes, and also in the context of drone swarms. Mattia Piana, Francesco Ardizzon, Stefano Tomasin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Physical Layer-Based Device Fingerprinting for Wireless Security: From Theory to PracticeabstractThe identification of the devices from which a message is received is part of security mechanisms to ensure authentication in wireless communications. Conventional authentication approaches are cryptography-based, which, however, are usually computationally expensive and not adequate in the Internet of Things (IoT), where devices tend to be low-cost and with limited resources. This paper provides a comprehensive survey of physical layer-based device fingerprinting, which is an emerging device authentication for wireless security. In particular, this article focuses on hardware impairment-based identity authentication and channel features-based authentication. They are passive techniques that are readily applicable to legacy IoT devices. Their intrinsic hardware and channel features, algorithm design methodologies, application scenarios, and key research questions are extensively reviewed here. The remaining research challenges are discussed, and future work is suggested that can further enhance the physical layer-based device fingerprinting. Junqing Zhang, Francesco Ardizzon, Mattia Piana, Guanxiong Shen, Stefano Tomasin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Channel-Based Key Generation for Secure Underwater Acoustic CommunicationsabstractTo protect underwater acoustic communications from interception, the exchange of encryption keys is necessary. Since underwater devices can be compromised, generating keys on site is a better option than predefined keys. In this paper, we present a solution that utilizes the characteristics of the underwater acoustic channel impulse response (CIR), which is highly variable in both space and time, while ensuring consistency between the communicating nodes (Alice and Bob). To compensate for temporal variations, the key is calculated from the CIR feature’s distribution parameters, while the hard key is determined using a K-means strategy. To achieve key agreement, we exploit the long propagation delay in the underwater CIR and let Alice and Bob transmit simultaneously while their packets fly past each other. Due to the channel’s reciprocity, this simultaneous transmission ensures that the same CIR is estimated at both ends of the communication link. Simulation and sea experiment results show that it is possible to extract at least three times as many secret bits as we would with a uniform quantizer. The results show a high matching rate between Alice and Bob and a high Hamming distance to Eve’s key. For reproducibility, we share the CIRs from the sea trials. Roee Diamant, Paolo Casari, Francesco Ardizzon, Stefano Tomasin, Benjamin Sherlock, Thomas Corner, Jeffrey A. Neasham |
IEEE Trans. Wirel. Commun. | 3 |
| 2024 | A RNN-based approach to physical layer authentication in underwater acoustic networks with mobile devicesabstractUnderwater acoustic communications are becoming a popular solution for underwater data communications and telemetry, making the authentication of transmitted data a necessity. In this paper, we propose a physical-layer authentication strategy for underwater acoustic networks (UWANs) with mobile devices. Such a scenario is more challenging than classical authentication scenarios in static networks, because the mobility of the receiver and/or transmitter implies that channel conditions slowly change over time. Thus, we cannot rely on the statistics of channel features to be stationary. In our proposed strategy, we assume that the receiver can rely on a set of sensors. We first extract a set of channel features, to be used to track the channel evolution over time. We then develop a long short-term memory (LSTM)-based approach, where at each step the sensors predict future feature values based on a learned model and on previously observed feature values. Next, each sensor computes the prediction error and passes it on to the actual receiver, which makes a decision on the signal authenticity through a generalized likelihood ratio test (GLRT). We model different classes of attacks and test them using simulation data obtained via the Bellhop ray tracing software. Numerical results show that our authentication mechanism successfully distinguishes between legitimate and impersonating transmitters, even when considering challenging attacking scenarios where the attacker can successfully mimic the channels between the legitimate transmitter and the sensors. Francesco Ardizzon, Paolo Casari, Stefano Tomasin |
Comput. Networks | 1 |
| 2024 | On Mixing Authenticated and Non-Authenticated Signals Against GNSS SpoofingabstractAnti-spoofing techniques for current global navigation satellite systems (GNSS) authenticate signals on a single band and from a single system. However, nowadays commercial GNSS receivers commonly calculate the position, velocity, and time (PVT) solution by simultaneously utilizing signals from multiple constellations and bands, with a substantial enhancement in both accuracy and availability. Therefore, anti-spoofing techniques have recently been proposed that mix authenticated and non-authenticated signals to increase performance without sacrificing security. In this paper, we formalize the models of such signal mixture-based authentication checks. We propose a spoofing attack generating a fake signal that leads the victim to a target PVT solution, undetected. We analytically relate the degrees of freedom of the attacker in manipulating the victim’s solution to both the employed security checks and the number of open non-authenticated signals that can be tampered with by the attacker. The performance of the considered attack strategies are tested on an experimental dataset. Finally, we assess the limits of PVT-based GNSS authentication checks where both authenticated and non-authenticated signals are used. Francesco Ardizzon, Laura Crosara, Stefano Tomasin, Nicola Laurenti |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Worst-Case Spoofing Attack and Robust Countermeasure in Satellite Navigation SystemsabstractThe threat of signal spoofing attacks against global navigation satellite system (GNSS) has grown in recent years and has motivated the study of anti-spoofing techniques. However, defense methods have been designed only against specific attacks. This paper introduces a general model of the spoofing attack framework in GNSS, from which optimal attack and defense strategies are derived. We consider a scenario with a legitimate receiver (Bob) testing if the received signals come from multiple legitimate space vehicles (Alice) or from an attack device (Eve). We first derive the optimal attack strategy against a Gaussian transmission from Alice, by minimizing an outer bound on the achievable error probability region of the spoofing detection test. Then, framing the spoofing and its detection as an adversarial game, we show that the Gaussian transmission and the corresponding optimal attack constitute a Nash equilibrium. Lastly, we consider the case of practical modulation schemes for Alice and derive the generalized likelihood ratio test. Numerical results validate the analytical derivations and show that the bound on the achievable error region is representative of the actual performance. Laura Crosara, Francesco Ardizzon, Stefano Tomasin, Nicola Laurenti |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Secret Key Generation From Route Propagation Delays for Underwater Acoustic NetworksabstractWith the growing use of underwater acoustic communications and the recent adoption of standards in this field, it is becoming increasingly important to secure messages against eavesdroppers. In this paper, we focus on a physical-layer security solution to generate sequences of random bits (keys) between two devices (Alice and Bob) belonging to an underwater acoustic network (UWAN); the key must remain secret to a passive eavesdropper (Eve) not belonging to the UWAN. Our method is based on measuring the propagation delay of the underwater acoustic channel over multiple hops of the UWAN: this harvests the randomness in the UWAN topology and turns the slow sound propagation in water into an advantage against eavesdropping. Our key generation protocol includes a route discovery handshake, whereby all UWAN devices at intermediate hops accumulate their message processing delays. This enables Alice and Bob to compute the actual propagation delays along each route and to map such information to a sequence of bits. Finally, from these bit sequences, Alice and Bob obtain a secret key. We analyze the performance of the protocol theoretically and assess it via extensive simulations and field experiments. Roee Diamant, Stefano Tomasin, Francesco Ardizzon, Davide Eccher, Paolo Casari |
IEEE Trans. Inf. Forensics Secur. | 3 |