VLDB 2026 Research / reviewers in the wild / expert
Simone Magnani
dblp:313/5857
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-4957-3577ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | INTELLECT: From federated training to resource-aware cyber threat detection
Simone Magnani, Liubov Nedoshivina, Roberto Doriguzzi Corin, Stefano Braghin, Domenico Siracusa |
Comput. Networks | 1 |
| 2024 | Online Learning and Model Pruning Against Concept Drifts in Edge DevicesabstractThe proliferation of Internet of Things sensors has driven the adoption of the edge computing paradigm, which prioritizes processing the data close to the source to minimize data transfer to cloud servers, reduce latency, and enhance privacy and robustness. However, edge computing environments present limited computational power, storage capacity, and a non-negligible risk of cyber-attacks.This paper tackles the challenges of deploying Intrusion and/or Anomaly Detection Systems (I/ADSs) at the network’s edge, particularly for environments with evolving network attack patterns (concept drift). To this aim, we propose a methodology that leverages both Neural Network (NN) pruning and online learning. We empirically evaluate the proposed methodology under attack scenarios with concept drift in network traffic, where adaptation to new data trends is crucial. We also demonstrate that NN pruning leads to more energy-efficient and lightweight I/ADSs, which can be adopted also in devices with strict resource requirements. Simone Magnani, Seshu Tirupathi, Roberto Doriguzzi Corin, Liubov Nedoshivina, Stefano Braghin, Domenico Siracusa |
NetSoft | 1 |
| 2023 | Pruning Federated Learning Models for Anomaly Detection in Resource-Constrained EnvironmentsabstractThe evolving complexity of modern IT infrastructures has paved the way for malicious actors to exploit a wide array of vulnerabilities that can compromise the integrity of these systems. Monitoring complex IT systems is expensive and often requires dedicated infrastructure for deploying Intrusion and/or Anomaly Detection Systems. Moreover, ML-based solutions need large training sets, which add to the overall cost. To tackle these challenges we present INTELLECT, a novel approach to Intrusion and/or Anomaly Detection System, which leverages Federated Learning and model pruning techniques to cooperatively train high-accuracy models using distributed datasets and derive a fleet of lightweight models, which can be deployed without incurring additional costs for dedicated infrastructure. INTELLECT expands on the state-of-the-art techniques for feature selection, model pruning, and model distillation to create an interconnected pipeline. We empirically demonstrate the effectiveness of the methodology on benchmark datasets, and we present guidelines for the deployment in production systems. Simone Magnani, Stefano Braghin, Ambrish Rawat, Roberto Doriguzzi Corin, Mark Purcell, Domenico Siracusa |
IEEE Big Data | 1 |
| 2023 | Enhancing Network Intrusion Detection: An Online Methodology for Performance AnalysisabstractMachine learning models have been extensively proposed for classifying network flows as benign or malicious, either in-network or at the endpoints of the infrastructure. Typically, the performance of such models is assessed by evaluating the trained model against a portion of the available dataset. However, in a production scenario, these models are fed by a monitoring stage that collects information from flows and provides inputs to a filtering stage that eventually blocks malicious traffic. To the best of our knowledge, no work has analysed the entire pipeline, focusing on its performance in terms of both inputs (i.e., the information collected from each flow) and outputs (i.e., the system’s ability to prevent an attack from reaching the application layer).In this paper, we propose a methodology for evaluating the effectiveness of a Network Intrusion Detection System (NIDS) by placing the model evaluation test alongside an online test that simulates the entire monitoring-detection-mitigation pipeline. We assess the system’s outputs based on different input configurations, using state-of-the-art detection models and datasets. Our results highlight the importance of inputs for the throughput of the NIDS, which can decrease by more than 50% with heavier configurations. Furthermore, our research indicates that relying solely on the performance of the detection model may not be enough to evaluate the effectiveness of the entire NIDS process. Indeed, even when achieving near-optimal False Negative Rate (FNR) values (e.g., 0.01), a substantial amount of malicious traffic (e.g., 70%) may still successfully reach its target. Simone Magnani, Roberto Doriguzzi Corin, Domenico Siracusa |
NetSoft | 1 |
| 2022 | On increasing password security awareness using a serious gameabstractPasswords are the base of almost all authentication systems. Hence, it is essential that users choose strong passwords, to prevent attackers from guessing them by using the most common passwords. In this paper, we present a serious game developed with the aim of increasing the awareness of players on the (in)security of passwords. It has been developed using standard web technologies and employing the MEAN stack. To gain points, players have to guess which of the two proposed passwords is the most used one. Our prototype has three different game modalities both single and multi-player. A preliminary evaluation session has been conducted to evaluate the effectiveness of our prototype and its usability. Giovanni Delnevo, Luca Deluigi, Davide Evangelisti, Simone Magnani |
CCNC | 4 |
| 2022 | Towards Application-Aware Provisioning of Security Services with KubernetesabstractIn network security, Network Function Virtualization can be exploited to implement flexible security services tailored to specific user needs. However, in practice this is hard to achieve due to the limitations of reference software platforms, such as Kubernetes, which are designed to orchestrate cloud-native services. In this work, we complement Kubernetes with a state-of-the-art algorithm for application-aware provisioning of security services. We demonstrate that the proposed solution improves basic provisioning mechanisms, such as the default Kubernetes scheduler, in terms of Quality of Service and security guarantees for the users. Roberto Doriguzzi Corin, Silvio Cretti, Tiziana Catena, Simone Magnani, Domenico Siracusa |
NetSoft | 4 |