VLDB 2026 Research / reviewers in the wild / expert
Pier Paolo Tricomi
dblp:273/9534
· DBLP profile ↗
10ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0003-1600-835XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Beats to Breaches: How Offensive AI Infers Sensitive User Information from Playlists
Stefano Cecconello, Mauro Conti, Luca Pajola, Luca Pasa, Pier Paolo Tricomi |
EuroS&P | 5 |
| 2025 | Elephant in the Room: Dissecting and Reflecting on the Evolution of Online Social Network ResearchabstractBillions of individuals engage with Online Social Networks (OSN) daily. The owners of OSN try to meet the demands of their end-users while complying with business necessities. Such necessities may, however, lead to the adoption of restrictive data access policies that hinder research activities from "external"' scientists---who may, in turn, resort to other means (e.g., rely on static datasets) for their studies. Given the abundance of literature on OSN, we - as academics - should take a step back and reflect on what we have done so far, after having written thousands of papers on OSN. This is the first paper that provides a holistic outlook to the entire body of research that focused on OSN - since the seminal work by Acquisti and Gross (2006). First, we search through over 1 million peer-reviewed publications, and derive 13,842 papers that focus on OSN: we organize the metadata of these works in the Minerva-OSN dataset, the first of its kind - which we publicly release. Next, by analyzing Minerva-OSN, we provide factual evidence elucidating trends and aspects that deserve to be brought to light - such as the predominant focus on Twitter or the difficulty in obtaining OSN data. Finally, as a constructive step to guide future research, we carry out an expert survey (n=50) with established scientists in this field, and coalesce suggestions to improve the status quo - such as an increased involvement of OSN owners. Our findings should inspire a reflection to "rescue" research on OSN. Doing so would improve the overall OSN ecosystem, benefiting both their owners and end-users - and, hence, our society. Luca Pajola, Saskia Laura Schröer, Pier Paolo Tricomi, Mauro Conti, Giovanni Apruzzese |
ICWSM | 3 |
| 2024 | Climbing the Influence Tiers on TikTok: A Multimodal StudyabstractCorporate social media analysts break influencers into five tiers of increasing importance: Nano, Micro, Mid, Macro, and Mega. We perform a comprehensive study of TikTok influencers with two goals: (i) what factors distinguish influencers in each of these tiers from the adjacent tier(s)? (ii) of the features influencers can directly control ("actionable" features), which ones are most impactful to reach the next tier? We build and release a novel TikTok dataset featuring over 230K videos from 5000 influencers - 1000 from each tier. The dataset includes video details such as likes, facial action units, emotions, and music information derived from Spotify. Access to the videos is facilitated through provided URLs and hydration code. To find the most important features that distinguish influencers in a tier from those in the next tier up, we thoroughly analyze traditional features (e.g., profile information) and text, audio, and video features using statistical methods and ablation testing. Our classifiers achieve F1-scores over 80%. The most impactful actionable features are traditional and video features, including enhancing video pleasure, quality, and emphasizing facial expressions. Finally, we collect and release a YouTube Shorts dataset to conduct a comparative analysis, aiming to identify similarities and differences between the two platforms. Pier Paolo Tricomi, Saurabh Kumar 0007, Mauro Conti, V. S. Subrahmanian |
ICWSM | 1 |
| 2023 | Social Honeypot for Humans: Luring People Through Self-managed Instagram Pages
Sara Bardi, Mauro Conti, Luca Pajola, Pier Paolo Tricomi |
ACNS (1) | 4 |
| 2023 | Attribute Inference Attacks in Online Multiplayer Video Games: A Case Study on DOTA2abstractDid you know that over 70 million of Dota2 players have their ingame data freely accessible?What if such data is used in malicious ways?This paper is the first to investigate such a problem.Motivated by the widespread popularity of video games, we propose the first threat model for Attribute Inference Attacks (AIA) in the Dota2 context.We explain how (and why) attackers can exploit the abundant public data in the Dota2 ecosystem to infer private information about its players.Due to lack of concrete evidence on the efficacy of our AIA, we empirically prove and assess their impact in reality.By conducting an extensive survey on ∼500 Dota2 players spanning over 26k matches, we verify whether a correlation exists between a player's Dota2 activity and their real-life.Then, after finding such a link (𝑝 < 0.01 and 𝜌 > 0.3), we ethically perform diverse AIA.We leverage the capabilities of machine learning to infer real-life attributes of the respondents of our survey by using their publicly available in-game data.Our results show that, by applying domain expertise, some AIA can reach up to 98% precision and over 90% accuracy.This paper hence raises the alarm on a subtle, but concrete threat that can potentially affect the entire competitive gaming landscape.We alerted the developers of Dota2. Pier Paolo Tricomi, Lisa Facciolo, Giovanni Apruzzese, Mauro Conti |
CODASPY | 1 |
| 2023 | Are We All in a Truman Show? Spotting Instagram Crowdturfing through Self-TrainingabstractInfluencer Marketing generated $16 billion in 2022. Usually, the more popular influencers are paid more for their collaborations. Thus, many services were created to boost profiles' popularity metrics through bots or fake accounts. However, real people recently started participating in such boosting activities using their real accounts for monetary rewards, generating ungenuine content that is extremely difficult to detect. To date, no works have attempted to detect this new phenomenon, known as crowdturfing (CT), on Instagram. In this work, we propose the first Instagram CT engagement detector. Our algorithm leverages profiles' characteristics through semi-supervised learning to spot accounts involved in CT activities. Compared to the supervised approaches used so far to identify fake accounts, semi-supervised models can exploit huge quantities of unlabeled data to increase performance. We purchased and studied 1293 CT profiles from 11 providers to build our self-training classifier, which reached 95% F1-score. We tested our model in the wild by detecting and analyzing CT engagement from 20 mega-influencers (i.e., with more than one million followers), and discovered that more than 20 % was artificial. We analyzed the CT profiles and comments, showing that it is difficult to detect these activities based solely on their generated content. Pier Paolo Tricomi, Sousan Tarahomi, Christian Cattai, Mauro Conti |
ICCCN | 1 |
| 2023 | BLUFADER: Blurred face detection & recognition for privacy-friendly continuous authenticationabstractAuthentication and de-authentication phases should occur at the beginning and end of secure user sessions, respectively. A secure session requires the user to pass the former, but the latter is often underestimated or ignored. Unattended or dangling sessions expose users to well-known Lunchtime Attacks. To mitigate this threat, researchers focused on automated de-authentication systems, either as a stand-alone mechanism or as a result of continuous authentication failures. Unfortunately, no single approach offers security, privacy, and usability. Face-recognition methods, for example, may be suitable for security and usability, but they violate user privacy by continuously recording their actions and surroundings. In this work, we propose BLUFADER, a novel continuous authentication system that takes advantage of blurred face detection and recognition to fast, secure, and transparent de-authenticate users, preserving their privacy. We obfuscate a webcam with a physical blur layer and use deep learning algorithms to perform face detection and recognition continuously. To evaluate BLUFADER’s practicality, we collected two datasets formed by 30 recruited subjects (users) and thousands of physically blurred celebrity photos. The de-authentication system was trained and evaluated using the former, while the latter was used to appraise the privacy and increase variance at training time. To guarantee the privacy-preserving effectiveness of the selected physical blurring filter, we show that state-of-the-art deblurring models are not able to revert our physical blur. Further, we demonstrate that our approach outperforms state-of-the-art methods in detecting blurred faces, achieving up to 95% accuracy. Moreover, BLUFADER effectively de-authenticates users up to 100% accuracy in under 3 seconds, while satisfying security, privacy, and usability requirements. Last, our continuous authentication face recognition module based on Siamese Neural Network preventively protect users from adversarial attacks, enhancing the overall system security. Matteo Cardaioli, Mauro Conti, Gabriele Orazi, Pier Paolo Tricomi, Gene Tsudik |
Pervasive Mob. Comput. | 4 |
| 2022 | Privacy-Friendly De-authentication with BLUFADE: Blurred Face DetectionabstractIdeally, secure user sessions should start and end with authentication and de-authentication phases, respectively. While the user must pass the former to start a secure session, the latter’s importance is often ignored or underestimated. Dangling or unattended sessions expose users to well-known Lunchtime Attacks. To mitigate this threat, the research community focused on automated de-authentication systems. Unfortunately, no single approach offers security, privacy, and usability. For instance, although facial recognition-based methods might be a good fit for security and usability, they violate user privacy by constantly recording the user and the surrounding environment.In this work, we propose BLUFADE, a fast, secure, and transparent de-authentication system that takes advantage of blurred faces to preserve user privacy. We obfuscate a webcam with a physical blur layer and use deep learning algorithms to perform face detection continuously. To assess BLUFADE‘s practicality, we collected two datasets formed by 30 recruited subjects (users) and thousands of physically blurred celebrity photos. The former was used to train and evaluate the deauthentication system performances, the latter to assess the privacy and to increase variance in training data. We show that our approach outperforms state-of-the-art methods in detecting blurred faces, achieving up to 95% accuracy. Furthermore, we demonstrate that BLUFADE effectively de-authenticates users up to 100% accuracy in under 3 seconds, while satisfying security, privacy, and usability requirements. Matteo Cardaioli, Mauro Conti, Pier Paolo Tricomi, Gene Tsudik |
PerCom | 3 |
| 2020 | DE-auth of the Blue! Transparent De-authentication Using Bluetooth Low Energy Beacon
Mauro Conti, Pier Paolo Tricomi, Gene Tsudik |
ESORICS (1) | 2 |
| 2020 | PvP: Profiling Versus Player! Exploiting Gaming Data for Player Recognition
Mauro Conti, Pier Paolo Tricomi |
ISC | 2 |