VLDB 2026 Research / reviewers in the wild / expert
Matthew Rossi
dblp:293/9812
· DBLP profile ↗
14ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0001-6459-0810ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RIVER: An eBPF-based Runtime Verification Platform for Cyber-Physical Systems
Dario Facchinetti, Matthew Rossi, Zhenya Zhang 0001, Stefano Paraboschi, Paolo Arcaini |
ICST | 2 |
| 2025 | POSTER: Transparent Temporally-Specialized System Call Filters
Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
AsiaCCS | 1 |
| 2025 | POSTER: Policy-driven security-aware scheduling in Kubernetes
Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
AsiaCCS | 1 |
| 2025 | Secure Kubernetes Workload Deployment with Automated Enforcement of Cluster-Defined PoliciesabstractScheduling pods on separate physical nodes is a crucial strategy to isolate workloads with incompatible security requirements. In Kubernetes, this is enforced using metadata such as node selectors, affinity rules, and topology spread constraints, all manually defined by developers at resource creation. The aforementioned process is complex and prone to errors, frequently resulting in misconfigurations that expose systems to data breaches and regulatory violations. This paper proposes an approach to constrain scheduling using policies defined once at the cluster level and automatically evaluated by Kubernetes during each workload deployment. The advantages are (i) automatic rejection of uncompliant resource creation requests, (ii) streamlined support for executing multi-tenant workloads, and (iii) secure scheduling and deployment of workloads based on security requirements. To implement this solution, we integrate the native Kubernetes node-filtering capabilities with OPA Gatekeeper for policy enforcement. We demonstrate how this approach reliably enforces common corporate governance policies and analyze its performance advantage over isolation achieved solely through sandboxing. The experimental evaluation confirms the effectiveness of our proposal and the minimal overhead. Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
CloudCom | 1 |
| 2024 | Supporting Data Owner Control in IPFS NetworksabstractDecentralized storage architectures are emerging as valid complementary solutions to cloud-based storage services. InterPlanetary File System (IPFS) is one of the most well-known distributed file storage protocols with wide adoption, good performance, and a variety of applications built over it. However, IPFS does not natively support data confidentiality and its decentralized nature limits the ability of data owners to maintain control on their resources and to force their deletion. We propose Mix-IPFS, an approach that allows data owners to maintain control on their resources uploaded to IPFS, guaranteeing their confidentiality and supporting secure deletion. Mix-IPFS is based on AONT encryption, which has the nice property of preventing decryption if the whole ciphertext is not available. Data owners can permanently delete a resource by making a small portion of its encrypted representation unavailable. Our solution uses a virtual file system to guarantee transparency to data owners (i.e., they can operate on plaintext resources). The experimental evaluation shows that the overhead of our approach is negligible (less than 2% for both upload and access operations). Marco Abbadini 0001, Michele Beretta 0001, Sabrina De Capitani di Vimercati, Dario Facchinetti, Sara Foresti, Gianluca Oldani, Stefano Paraboschi, Matthew Rossi, Pierangela Samarati |
ICC | 8 |
| 2024 | Multi-Dimensional Flat Indexing for Encrypted DataabstractWe address the problem of indexing encrypted data outsourced to an external cloud server to support server-side execution of multi-attribute queries. Our approach partitions the dataset in groups with the same number of tuples, and associates all tuples in a group with the same combination of index values, so to guarantee protection against static inferences. Our indexing approach does not require any modifications to the server-side software stack, and requires limited storage at the client for query support. The experimental evaluation considers, for the storage of the encrypted and indexed dataset, both a relational database (PostgreSQL) and a key-value database (Redis). We carried out extensive experiments evaluating client-storage requirements and query performance. The experimental results confirm the efficiency of our solution. The proposal is supported by an open source implementation. Sabrina De Capitani di Vimercati, Dario Facchinetti, Sara Foresti, Gianluca Oldani, Stefano Paraboschi, Matthew Rossi, Pierangela Samarati |
IEEE Trans. Cloud Comput. | 6 |
| 2023 | POSTER: Leveraging eBPF to enhance sandboxing of WebAssembly runtimesabstractWebAssembly is a binary instruction format designed as a portable compilation target enabling the deployment of untrusted code in a safe and efficient manner. While it was originally designed to be run inside web browsers, modern runtimes like Wasmtime and WasmEdge can execute WebAssembly directly on various systems. In order to access system resources with a universal hostcall interface, a standardization effort named WebAssembly System Interface (WASI) is currently undergoing. With specific regard to the file system, runtimes must prevent hostcalls to access arbitrary locations, thus they introduce security checks to only permit access to a pre-defined list of directories. This approach not only suffers from poor granularity, it is also error-prone and has led to several security issues. In this work we replace the security checks in hostcall wrappers with eBPF programs, enabling the introduction of fine-grained per-module policies. Preliminary experiments confirm that our approach introduces limited overhead to existing runtimes. Marco Abbadini 0001, Michele Beretta 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
AsiaCCS | 5 |
| 2023 | Cage4Deno: A Fine-Grained Sandbox for Deno SubprocessesabstractDeno is a runtime for JavaScript and TypeScript that is receiving great interest by developers, and is increasingly used for the construction of back-ends of web applications. A primary goal of Deno is to provide a secure and isolated environment for the execution of JavaScript programs. It also supports the execution of subprocesses, unfortunately without providing security guarantees. Marco Abbadini 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
AsiaCCS | 4 |
| 2023 | Lightweight Cloud Application SandboxingabstractModern cloud applications can quickly grow to an elaborate and intricate tangle of services. In this scenario, paying attention to security aspects is important to mitigate the impact of incidents. Indeed, several research works and industrial standards recommend the integration of least privilege policies to prevent disruptions such as file system tampering. Unfortunately, technologies like containers virtualize file system resources with a volume-based approach, which may be overly coarse.In this work we address this problem proposing an approach that restrict application access to file system resources with a resource-based granularity. To this end, we develop a flexible and intuitive tool that relies on instrumentation to collect, merge, and audit the activity traces generated by any application component. We then demonstrate how this information is used to create fine-grained access policies, and introduce sandboxing using recent kernel security modules, strengthening the security boundary of the whole application. In the experimental evaluation we showcase the mitigation capabilities associated with our approach, and the low performance footprint. The proposal is associated with an open source implementation. Marco Abbadini 0001, Michele Beretta 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
CloudCom | 5 |
| 2023 | NatiSand: Native Code Sandboxing for JavaScript RuntimesabstractModern runtimes render JavaScript code in a secure and isolated environment, but when they execute binary programs and shared libraries, no isolation guarantees are provided. This is an important limitation, and it affects many popular runtimes including Node.js, Deno, and Bun [20, 61]. Marco Abbadini 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
RAID | 4 |
| 2023 | Scalable Distributed Data Anonymization for Large Datasetsabstract$\kappa $-Anonymity and$\ell $-diversity are two well-known privacy metrics that guarantee protection of the respondents of a dataset by obfuscating information that can disclose their identities and sensitive information. Existing solutions for enforcing them implicitly assume to operate in a centralized scenario, since they require complete visibility over the dataset to be anonymized, and can therefore have limited applicability in anonymizing large datasets. In this paper, we propose a solution that extends Mondrian (an efficient and effective approach designed for achieving$\kappa $-anonymity) for enforcing both$\kappa $-anonymity and$\ell $-diversity over large datasets in a distributed manner, leveraging the parallel computation of multiple workers. Our approach efficiently distributes the computation among the workers, without requiring visibility over the dataset in its entirety. Our data partitioning limits the need for workers to exchange data, so that each worker can independently anonymize a portion of the dataset. We implemented our approach providing parallel execution on a dynamically chosen number of workers. The experimental evaluation shows that our solution provides scalability, while not affecting the quality of the resulting anonymization. Sabrina De Capitani di Vimercati, Dario Facchinetti, Sara Foresti, Giovanni Livraga, Gianluca Oldani, Stefano Paraboschi, Matthew Rossi, Pierangela Samarati |
IEEE Trans. Big Data | 7 |
| 2021 | I Told You Tomorrow: Practical Time-Locked Secrets using Smart ContractsabstractA Time-Lock enables the release of a secret at a future point in time. Many approaches implement Time-Locks as cryptographic puzzles, binding the recovery of the secret to the solution of the puzzle. Since the time required to find the puzzle’s solution may vary due to a multitude of factors, including the computational effort spent, these solutions may not suit all scenarios. Enrico Bacis, Dario Facchinetti, Marco Guarnieri, Marco Rosa, Matthew Rossi, Stefano Paraboschi |
ARES | 5 |
| 2021 | Multi-dimensional indexes for point and range queries on outsourced encrypted dataabstractWe present an approach for indexing encrypted data stored at external providers to enable provider-side evaluation of queries. Our approach supports the evaluation of point and range conditions on multiple attributes. Protection against inferences from indexes is guaranteed by clustering tuples in boxes that are then mapped to the same index values, so to ensure collisions for individual attributes as well as their combinations. Our spatial-based algorithm partitions tuples to produce such a clustering in a way to ensure efficient query execution. Query translation and processing require the client to store a compact map. The experiments, evaluating query performance and client-storage requirements, confirm the efficiency enjoyed by our solution. Sabrina De Capitani di Vimercati, Dario Facchinetti, Sara Foresti, Gianluca Oldani, Stefano Paraboschi, Matthew Rossi, Pierangela Samarati |
GLOBECOM | 6 |
| 2021 | SEApp: Bringing Mandatory Access Control to Android Apps
Matthew Rossi, Dario Facchinetti, Enrico Bacis, Marco Rosa, Stefano Paraboschi |
USENIX Security Symposium | 1 |