VLDB 2026 Research / reviewers in the wild / expert
Marco Zambianco
dblp:270/9947
· DBLP profile ↗
9ranked-venue papers
8as first author
7since 2021 · last 2025
0000-0001-5152-5454ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Proactive Decoy Selection Scheme for Cyber Deception using MITRE ATT&CK
Marco Zambianco, Claudio Facchinetti, Domenico Siracusa |
Comput. Secur. | 1 |
| 2025 | Disruption-Aware Microservice Re-Orchestration for Cost-Efficient Multi-Cloud DeploymentsabstractMulti-cloud environments enable a cost-efficient scaling of cloud-native applications across geographically distributed virtual nodes with different pricing models. In this context, the resource fragmentation caused by frequent changes in the resource demands of deployed microservices, along with the allocation or termination of new and existing microservices, increases the deployment cost. Therefore, re-orchestrating deployed microservices on a cheaper configuration of multi-cloud nodes offers a practical solution to restore the cost efficiency of deployment. However, the rescheduling procedure causes frequent service interruptions due to the continuous termination and rebooting of the containerized microservices. Moreover, it may potentially interfere with and delay other deployment operations, compromising the stability of the running applications. To address this issue, we formulate a multi-objective integer linear programming (ILP) problem that computes a microservice rescheduling solution capable of providing minimum deployment cost without significantly affecting the service continuity. At the same time, the proposed formulation also preserves the quality of service (QoS) requirements, including latency, expressed through microservice co-location constraints. Additionally, we present a heuristic algorithm to approximate the optimal solution, striking a balance between cost reduction and service disruption mitigation. We integrate the proposed approach as a custom plugin of the Kubernetes (K8s) scheduler. Results reveal that our approach significantly reduces multi-cloud deployment costs and service disruptions compared to the benchmark schemes, while ensuring QoS requirements are consistently met. Marco Zambianco, Silvio Cretti, Domenico Siracusa |
IEEE Trans. Serv. Comput. | 1 |
| 2024 | Demo: Cloud-native Cyber Deception with DeceptoabstractThe disaggregation of monolithic applications in containerized microservices inevitably weaken their security posture. In this context, leveraging the cloning feature of containerized environments, we propose Decepto, a software platform that integrates a high-interaction cyber deception mechanism within cloud-native applications using Kubernetes (K8s). In particular, our deception solution automatically generates decoys as clones of production microservices and deploys them to look like legitimate microservices. Attackers that unknowingly interact with such deceptive artifacts are reliably detected and monitored. In this work, we first present Decepto technical implementation, then we demonstrate its functionalities and related computational performance overhead emulating a practical attack scenario on a real K8s cluster. Daniele Santoro, Marco Zambianco, Claudio Facchinetti, Domenico Siracusa |
ISCC | 2 |
| 2024 | Resource-Aware Cyber Deception for Microservice-Based ApplicationsabstractCyber deception can be a valuable addition to traditional cyber defense mechanisms, especially for modern cloud-native environments with a fading security perimeter. However, pre-built decoys used in classical computer networks are not effective in detecting and mitigating malicious actors due to their inability to blend with the variety of applications in such environments. On the other hand, decoys cloning the deployed microservices of an application can offer a high-fidelity deception mechanism to intercept ongoing attacks within production environments. However, to fully benefit from this approach, it is essential to use a limited amount of decoy resources and devise a suitable cloning strategy to minimize the impact on legitimate services performance. Following this observation, we formulate a non-linear integer optimization problem that maximizes the number of attack paths intercepted by the allocated decoys within a fixed resource budget. Attack paths represent the attacker's movements within the infrastructure as a sequence of violated microservices. We also design a heuristic decoy placement algorithm to approximate the optimal solution and overcome the computational complexity of the proposed formulation. We evaluate the performance of the optimal and heuristic solutions against other schemes that use local vulnerability metrics to select which microservices to clone as decoys. Our results show that the proposed allocation strategy achieves a higher number of intercepted attack paths compared to these schemes while requiring approximately the same number of decoys. Marco Zambianco, Claudio Facchinetti, Roberto Doriguzzi Corin, Domenico Siracusa |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | A Learning Approach for Production-Aware 5G Slicing in Private Industrial NetworksabstractIndustrial scenarios comprise multiple devices executing periodic, mutually-dependent tasks with challenging communications requirements. 5G technology and RAN slicing make it possible to accommodate such requirements. The predictability of the environment can be exploited to improve the network efficiency and performance. We leverage Deep Reinforcement Learning to design a "production-aware" agent based on the Deep Deterministic Policy Gradient algorithm. The proposed scheme combines production and network information to select the spectrum configuration of each slice. In details, by exploiting the knowledge about the upcoming production tasks, the agent can effectively predict the required per-slice spectrum consumption in order to boost the service provisioning reliability and limit the spectrum over-provisioning. We compare the performance of this approach with a "production-unaware" agent and with the optimal spectrum allocation. Simulations show how our solution provides a per-slice reliability in terms of meeting the latency requirements higher than the one provided by the "production-unaware" agent. Moreover, it ensures a tight approximation of the optimal slice spectrum allocation. Marco Zambianco, Alessandro Lieto, Ilaria Malanchini, Giacomo Verticale |
ICC | 1 |
| 2022 | A reinforcement learning agent for mixed-numerology interference-aware slice spectrum allocation with non-deterministic and deterministic traffic
Marco Zambianco, Giacomo Verticale |
Comput. Commun. | 1 |
| 2021 | Intelligent multi-branch allocation of spectrum slices for inter-numerology interference minimization
Marco Zambianco, Giacomo Verticale |
Comput. Networks | 1 |
| 2020 | Spectrum Allocation for Network Slices with Inter-Numerology Interference using Deep Reinforcement LearningabstractNetwork slicing and mixed-numerology schemes are essential technologies to efficiently accommodate different services in 5G radio access networks (RAN). To fully take advantage of these techniques, the design of spectrum slicing policies needs to account for the limited availability of the radio resources as well as the inter-numerology interference generated by slices employing different numerologies. In this context, we formulate a binary non-convex problem that maximizes the aggregate capacity of multiple network slices. The resulting spectrum allocation minimizes the inter-numerology interference under the frequent channel fluctuations characterizing the various users. To address the computational complexity of the designed objective function, we leverage deep reinforcement learning (DRL) to design a model-free solution computation. In detail, the trained centralized DRL agent exploits the channel fading statistic in order to provide a spectrum allocation that minimizes the inter-numerology interference. Results reveal that the proposed DRL scheme achieves performance that is comparable to the optimal one. It also outperforms a baseline scheme that statically allocate the radio resources. Marco Zambianco, Giacomo Verticale |
PIMRC | 1 |
| 2020 | Interference Minimization in 5G Physical-Layer Network SlicingabstractThe interference resulting from densification of access points and the coexistence of different numerologies within the same spectrum severely hinders inter-slice isolation. We propose a slice allocation policy that enforces inter-slice isolation by minimizing the inter-slice interference suffered by each virtual operator. In detail, we design a binary quadratic non-convex optimization problem that minimizes i) the inter-slice interference generated by interfering base stations and ii) the inter-slice interference generated by the multiplexing of spectrum slices having different numerologies. We also provide a heuristic algorithm to render the solution scalable in practical scenarios. We assess the performance of both approaches by evaluating the signal-to-interference-plus-noise ratio (SINR) associated to each slice through simulations. Results reveal that the heuristic algorithm provides a solution comparable with the optimal one on different minimization scenarios. Moreover, a considerable SINR improvement is observed with respect to a base-line scheme that does not account for inter-slice interference. Marco Zambianco, Giacomo Verticale |
IEEE Trans. Commun. | 1 |