VLDB 2026 Research / reviewers in the wild / expert
Francesca Naretto
dblp:276/3533
· DBLP profile ↗
12ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0003-1301-7787ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 3 since 2021Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Federated learning with multiple, intersectional and multiclass fairness guarantees under performance budgetsabstractMachine learning increasingly drives decisions in domains such as finance and healthcare, where ethical considerations, such as fairness, are central. In such contexts, ensuring fairness is essential, especially when decisions impact individuals and social groups. Federated learning ( FL ) provides a decentralized training paradigm, yet client heterogeneity and demographic imbalance can amplify disparities across subpopulations. Existing fairness-aware FL methods remain limited, often focusing on group fairness in binary classification and lacking explicit control over the trade-off between fairness and predictive performance. We introduce FedFairLAB , a FL method that enforces group, intersectional, and multiclass fairness simultaneously at both the local and global levels. A tunable performance budget allows practitioners to control how much predictive performance can be sacrificed to improve fairness. Experiments on six real-world datasets show that FedFairLAB substantially improves fairness while keeping models accurate and usable in realistic FL settings. Michele Fontana, Francesca Naretto, Anna Monreale |
Data Min. Knowl. Discov. | 2 |
| 2025 | Enhancing Local Explanations with GAN-Based Neighborhood GenerationabstractAbstract The growing deployment of Machine Learning models has increased the demand for interpretability, leading to the development of various explainability methods. Yet, each method has its strengths and limitations, making it challenging to identify a one-size-fits-all solution. This paper introduces , a multi-faceted and fast local explanation approach for tabular data. incorporates various explanation types (feature importances, rules, counterfactuals, exemplars, and counter-exemplars), offering a 360-degree model interpretability. also includes a dashboard with indicators for prediction reliability and explanation quality, such as fidelity and robustness. To ensure efficiency, uses GAN-generated synthetic data to approximate the original dataset and selects similar records to the target instance, avoiding costly on-demand neighborhood generation. Multiple local surrogate models are trained to capture different aspects of the data and black-box behavior. achieves higher fidelity than state-of-the-art methods, with improvements up to 95% on multiclass datasets. Luca Corbucci, Francesca Naretto, Anna Monreale |
DS | 2 |
| 2025 | Differentially Private FastSHAP for Federated Learning Model ExplainabilityabstractExplaining the reasoning behind black-box model predictions while preserving user privacy is a significant challenge. This becomes even more complex in Federated Learning, where legal constraints restrict the data that clients can share with external entities. In this paper, we introduce FastSHAP++, a method that adapts FastSHAP to explain Federated Learning trained models. Unlike existing approaches, FastSHAP++mitigates client privacy risks by incorporating Differential Privacy into the explanation process and preventing the exchange of sensitive information between clients and external entities. We evaluate the effectiveness of FastSHAP++testing it on three different datasets, and comparing the explanations with those produced by a centralized explainer with access to clients’ training data. Lastly, we study the impact of varying levels of Differential Privacy to analyse the trade-offs between privacy and the quality of the explanations. Valerio Bonsignori, Luca Corbucci, Francesca Naretto, Anna Monreale |
IJCNN | 3 |
| 2025 | Optimizing and Tuning Fairness in Machine Learning: An Augmented Lagrangian Method with a Performance Budget
Michele Fontana, Francesca Naretto, Anna Monreale |
ECML/PKDD (1) | 2 |
| 2024 | Balancing Act: Navigating the Privacy-Utility Spectrum in Principal Component AnalysisabstractA lot of research in federated learning is ongoing ever since it was proposed. Federated learning allows collaborative learning among distributed clients without sharing their raw data to a central aggregator (if it is present) or to other clients in a peer to peer architecture. However, each client participating in the federation shares their model information learned from their data with other clients participating in the FL process, or with the central aggregator. This sharing of information, however, makes this approach vulnerable to various attacks, including data reconstruction attacks. Our research specifically focuses on Principal Component Analysis (PCA), as it is a widely used dimensionality technique. For performing PCA in a federated setting, distributed clients share local eigenvectors computed from their respective data with the aggregator, which then combines and returns global eigenvectors. Previous studies on attacks against PCA have demonstrated that revealing eigenvectors can lead to membership inference and, when coupled with knowledge of data distribution, result in data reconstruction attacks. Consequently, our objective in this work is to augment privacy in eigenvectors while sustaining their utility. To obtain protected eigenvectors, we use k-anonymity, and generative networks. Through our experimentation, we did a complete privacy, and utility analysis of original and protected eigenvectors. For utility analysis, we apply HIERARCHICAL CLUSTERING, RANDOM FOREST regressor, and RANDOM FOREST classifier on the protected, and original eigenvectors. We got interesting results, when we applied HIERARCHICAL CLUSTERING on the original, and protected datasets, and eigenvectors. The height at which the clusters are merged declined from 250 to 150 for original, and synthetic version of CALIFORNIA-HOUSING data, respectively. For the k-anonymous version of CALIFORNIA-HOUSING data, the height lies between 150, and 250. To evaluate the privacy risks of the federated PCA system, we act as an attacker, and conduct a data reconstruction attack. Saloni Kwatra, Anna Monreale, Francesca Naretto |
SECRYPT | 3 |
| 2024 | Stable and actionable explanations of black-box models through factual and counterfactual rulesabstractAbstract Recent years have witnessed the rise of accurate but obscure classification models that hide the logic of their internal decision processes. Explaining the decision taken by a black-box classifier on a specific input instance is therefore of striking interest. We propose a local rule-based model-agnostic explanation method providing stable and actionable explanations. An explanation consists of a factual logic rule, stating the reasons for the black-box decision, and a set of actionable counterfactual logic rules, proactively suggesting the changes in the instance that lead to a different outcome. Explanations are computed from a decision tree that mimics the behavior of the black-box locally to the instance to explain. The decision tree is obtained through a bagging-like approach that favors stability and fidelity: first, an ensemble of decision trees is learned from neighborhoods of the instance under investigation; then, the ensemble is merged into a single decision tree. Neighbor instances are synthetically generated through a genetic algorithm whose fitness function is driven by the black-box behavior. Experiments show that the proposed method advances the state-of-the-art towards a comprehensive approach that successfully covers stability and actionability of factual and counterfactual explanations. Riccardo Guidotti, Anna Monreale, Salvatore Ruggieri, Francesca Naretto, Franco Turini, Dino Pedreschi, Fosca Giannotti |
Data Min. Knowl. Discov. | 4 |
| 2023 | EXPHLOT: EXplainable Privacy Assessment for Human LOcation TrajectoriesabstractAbstract Human mobility data play a crucial role in understanding mobility patterns and developing analytical services across various domains such as urban planning, transportation, and public health. However, due to the sensitive nature of this data, accurately identifying privacy risks is essential before deciding to release it to the public. Recent work has proposed the use of machine learning models for predicting privacy risk on raw mobility trajectories and the use of shap for risk explanation. However, applying shap to mobility data results in explanations that are of limited use both for privacy experts and end-users. In this work, we present a novel version of the Expert privacy risk prediction and explanation framework specifically tailored for human mobility data. We leverage state-of-the-art algorithms in time series classification, as Rocket and InceptionTime, to improve risk prediction while reducing computation time. Additionally, we address two key issues with shap explanation on mobility data: first, we devise an entropy-based mask to efficiently compute shap values for privacy risk in mobility data; second, we develop a module for interactive analysis and visualization of shap values over a map, empowering users with an intuitive understanding of shap values and privacy risk. Francesca Naretto, Roberto Pellungrini, Salvatore Rinzivillo, Daniele Fadda |
DS | 1 |
| 2023 | Agnostic Label-Only Membership Inference AttackabstractAbstract In recent years we are witnessing the diffusion of AI systems based on powerful Machine Learning models which find application in many critical contexts such as medicine and financial market. In such contexts, it is important to design Trustworthy AI systems while guaranteeing privacy protection. However, some attacks on the privacy of Machine Learning models have been designed to show the threats of exposing such models. Membership Inference is one of the simplest privacy threats faced by Machine Learning models. It is based on the assumption that an adversary, observing the confidence of the model prediction, can infer whether a particular record was used for training the classifier. A variant, called Label-Only attack, exploits the adversary’s knowledge of the training data statistics to infer the record membership without accessing the confidence score of the prediction. In this paper, we propose a variant of the Label-Only attack, called Aloa, which estimates the prediction confidence exploiting a mechanism that is completely agnostic to the input data distributions. In fact, it requires neither statistical knowledge of the data nor the type of variables. Experimental results show better performance of our attack with respect to the competitors. Anna Monreale, Francesca Naretto, Simone Rizzo |
NSS | 2 |
| 2023 | Benchmarking and survey of explanation methods for black box modelsabstractAbstract The rise of sophisticated black-box machine learning models in Artificial Intelligence systems has prompted the need for explanation methods that reveal how these models work in an understandable way to users and decision makers. Unsurprisingly, the state-of-the-art exhibits currently a plethora of explainers providing many different types of explanations. With the aim of providing a compass for researchers and practitioners, this paper proposes a categorization of explanation methods from the perspective of the type of explanation they return, also considering the different input data formats. The paper accounts for the most representative explainers to date, also discussing similarities and discrepancies of returned explanations through their visual appearance. A companion website to the paper is provided as a continuous update to new explainers as they appear. Moreover, a subset of the most robust and widely adopted explainers, are benchmarked with respect to a repertoire of quantitative metrics. Francesco Bodria, Fosca Giannotti, Riccardo Guidotti, Francesca Naretto, Dino Pedreschi, Salvatore Rinzivillo |
Data Min. Knowl. Discov. | 4 |
| 2021 | Privacy Risk Assessment of Individual Psychometric Profiles
Giacomo Mariani, Anna Monreale, Francesca Naretto |
DS | 3 |
| 2021 | A new approach for cross-silo federated learning and its privacy risksabstractFederated Learning has witnessed an increasing popularity in the past few years for its ability to train Machine Learning models in critical contexts, using private data without moving them. Most of the approaches in the literature are focused on mobile environments, where mobile devices contain the data of single users, and typically deal with images or text data. In this paper, we define HOLDA, a novel federated learning approach tailored for training machine learning models on data distributed over federated organizations hierarchically organized. Our method focuses on the generalization capabilities of the neural network models, providing a new mechanism for selecting their best weights. In addition, it is tailored for tabular data. We empirically test the performance of our approach on two different tabular datasets, showing excellent results in terms of performance and generalization capabilities. Then, we also tackle the problem of assessing the privacy risk of users represented in the training data. In particular, we empirically show, by attacking the HOLDA models with the Membership Inference Attack, that the privacy of the users in the training data may have high risk. Michele Fontana, Francesca Naretto, Anna Monreale |
PST | 2 |
| 2020 | Predicting and Explaining Privacy Risk Exposure in Mobility Data
Francesca Naretto, Roberto Pellungrini, Anna Monreale, Franco Maria Nardini, Mirco Musolesi |
DS | 1 |