VLDB 2026 Research / reviewers in the wild / expert
Sergio Esposito
dblp:314/6129
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Human-Artificial Intelligent Threat Modelling in the Automotive DomainabstractWe develop a comprehensive threat model for the automotive domain. It is accomplished by means of a novel, multilevel research methodology that leverages Human-Artificial Intelligence (HAI). Given the inherent complexity of threat modelling and the challenges in ensuring its completeness, the methodology combines the complementary strengths of human analysis with large language models over four phases. Each phase is structured as a sequence of two or three refinement levels so that each level iteratively enhances prior results through either human or artificial intelligence. The first phase focuses on modelling the system under analysis to establish a clear and structured baseline. The second phase addresses the elicitation of assets and associated threats, followed by a third phase in which mitigation strategies are designed. The fourth and final phase ensures that mitigation is augmented to explicitly incorporate Zero Trust, Pseudonymisation, and Data Minimisation within the context of the automotive domain. The methodology maintains its multilevel HAI structure across all phases, thereby fostering a dynamic validation loop between expert knowledge and machine-driven inference, ultimately enhancing both accuracy and coverage of the resulting threat model. Giampaolo Bella, Gianpietro Castiglione, Sergio Esposito, Mirko Giuseppe Mangano, Giacomo Pampallona, Mario Raciti, Salvatore Riccobene, Daniele Francesco Santamaria |
IOLTS | 3 |
| 2025 | A case of smart devices that compromise home cybersecurityabstractThe importance of cybersecurity is widely acknowledged as paramount for virtually every computerized application domain. Not only is it concerned with the protection of digital assets and resources from illegitimate use, but it is also essential to people’s privacy, for example for shielding their personal data, and even to their safety, for example for safeguarding the functioning of devices that may potentially harm humans. This article investigates the extent to which cybersecurity is properly ensured of IoT devices (also commonly termed smart devices ) which are modern, that is, trendy at present, then also inexpensive, hence useful to evaluate a price-cybersecurity ratio, and, finally, commonly used. While it is clear that innumerable such devices exist, the findings reported below focus on the case of the Tapo ecosystem by TP-Link, which features cheap Amazon best sellers at present. Our findings suggest that effective Vulnerability Assessment and Penetration Testing sessions can be carried out on such devices by following the PETIoT kill chain. Findings also demonstrate that as many as six devices of the TAPO ecosystem suffer four previously unknown (so called zero-day ) vulnerabilities, which we filed as four CVEs on MITRE’s public database. Following Responsible Disclosure with TP-Link, vulnerabilities were publicly disclosed only after the vendor released appropriate fixes. All vulnerabilities were found using freeware, requiring over 600 lines of exploitation code. Davide Bonaventura, Sergio Esposito, Giampaolo Bella |
Comput. Secur. | 2 |
| 2024 | Modelling the privacy landscape of the Internet of VehiclesabstractWithin the dynamic realm of Intelligent Transportation Systems (ITS), the Internet of Vehicles (IoV) marks a significant paradigm shift. IoV is an interconnected network of vehicles, infrastructures, and the Internet, driven by wireless communication technologies. This paper dissects the privacy landscapes of ITS and IoV, exploring gaps and redundancies in standards and academic literature. We do so by leveraging European Telecommunications Standards Institute (ETSI) ITS G5 standards and IoV analyses from literature, and building two relational models to depict said privacy landscapes. A macroscopic analysis reveals structural and thematic differences: ITS, governed by established standards, has a robust structure, while IoV, in its nascent stage, lacks formalisation. A detailed analysis highlights challenges in data collection, sharing, and privacy policies. As ITS transitions to IoV, increasing data volume demands enhanced privacy safeguards. Addressing these challenges requires collaborative efforts to develop comprehensive privacy policies, prioritise user awareness, and integrate privacy-by-design principles. This paper offers insights into navigating the evolving landscape of transportation technologies, laying the groundwork for privacy-preserving ITS and IoV ecosystems. Ruben Cacciato, Mario Raciti, Sergio Esposito, Giampaolo Bella |
ARES | 3 |
| 2024 | The IoT Breaches Your Household AgainabstractDespite their apparent simplicity, devices like smart light bulbs and electrical plugs are often perceived as exempt from rigorous security measures. However, this paper challenges this misconception, uncovering how vulnerabilities in these seemingly innocuous devices can expose users to significant risks. This paper extends the findings outlined in previous work, introducing a novel attack scenario. This new attack allows malicious actors to obtain sensitive credentials, including the victim's Tapo account email and password, as well as the SSID and password of her local network. Furthermore, we demonstrate how these findings can be replicated, either partially or fully, across other smart devices within the same IoT ecosystem, specifically those manufactured by Tp-Link. Our investigation focused on the Tp-Link Tapo range, encompassing smart bulbs (Tapo L530E, Tapo L510E V2, and Tapo L630), a smart plug (Tapo P100), and a smart camera (Tapo C200). Utilizing similar communication protocols, or slight variants thereof, we found that the Tapo L530E, Tapo L510E V2, and Tapo L630 are susceptible to complete exploitation of all attack scenarios, including the newly identified one. Conversely, the Tapo P100 and Tapo C200 exhibit vulnerabilities to only a subset of attack scenarios. In conclusion, by highlighting these vulnerabilities and their potential impact, we aim to raise awareness and encourage proactive steps towards mitigating security risks in smart device deployment. Davide Bonaventura, Sergio Esposito, Giampaolo Bella |
SECRYPT | 2 |
| 2023 | Protecting Voice-Controllable Devices Against Self-Issued Voice CommandsabstractSelf-issued voice commands leverage the voice-controllable device’s internal speaker to issue malicious voice commands to the device itself. These attacks are a class of voice spoofing attacks particularly challenging to protect from, as it is very hard for a countermeasure solution to infer whether the command comes from an external entity or from the device itself. In this paper, we propose a countermeasure against self-issued voice commands by training a Twin Neural Network to recognise the differences between what is being played and what is being recorded by the voice-controllable device. In fact, these audios are very similar in case of voice command self-issue attacks and different in case of legitimate commands. We start with a security and usability trade-off analysis of countermeasures against voice spoofing attacks, by describing different classes of synthesised voice commands that need to be blocked or allowed, depending on the necessities of the user. Then, we present our solution to protect voice-controllable devices from self-issued commands and show that it correctly classifies commands in the benign (real-user) and malign (self-issued) categories 97% of the times on average. We compare this result with state-of-the-art anomaly detection techniques as a baseline and show that our solution outperforms them. Furthermore, we instantiate our countermeasure on three different classes of devices to measure its performance, and we find that the additional overhead is negligible. Finally, we measure the usability impact of our solution when users interact with the tested device under different conditions, showing that our solution is resistant to environmental changes and regardless of the identity of the user issuing the commands. Sergio Esposito, Daniele Sgandurra, Giampaolo Bella |
EuroS&P | 1 |
| 2023 | Smart Bulbs Can Be Hacked to Hack into Your HouseholdabstractThe IoT is getting more and more pervasive. Even the simplest devices, such as a light bulb or an electrical plug, are made "smart" and controllable by our smartphone. This paper describes the findings obtained by applying the PETIoT kill chain to conduct a Vulnerability Assessment and Penetration Testing session on a smart bulb, the Tapo L530E by Tp-Link, currently best seller on Amazon Italy. We found that four vulnerabilities affect the bulb, two of High severity and two of Medium severity according to the CVSS v3.1 scoring system. In short, authentication is not well accounted for and confidentiality is insufficiently achieved by the implemented cryptographic measures. In consequence, an attacker who is nearby the bulb can operate at will not just the bulb but all devices of the Tapo family that the user may have on her Tapo account. Moreover, the attacker can learn the victim's Wi-Fi password, thereby escalating his malicious potential considerably. The paper terminates with an outline of possible fixes. Davide Bonaventura, Sergio Esposito, Giampaolo Bella |
SECRYPT | 2 |
| 2022 | ALEXA VERSUS ALEXA: Controlling Smart Speakers by Self-Issuing Voice CommandsabstractWe present ALEXA VERSUS ALEXA (AvA), a novel attack that leverages audio files containing voice commands and audio reproduction methods in an offensive fashion, to gain control of Amazon Echo devices for a prolonged amount of time. AvA leverages the fact that Alexa running on an Echo device correctly interprets voice commands originated from audio files even when they are played by the device itself -- i.e., it leverages a command self-issue vulnerability. Hence, AvA removes the necessity of having a rogue speaker in proximity of the victim's Echo, a constraint that many attacks share. With AvA, an attacker can self-issue any permissible command to Echo, controlling it on behalf of the legitimate user. We have verified that, via AvA, attackers can control smart appliances within the household, buy unwanted items, tamper linked calendars and eavesdrop on the user. We also discovered two additional Echo vulnerabilities, which we call Full Volume and Break Tag Chain. The Full Volume increases the self-issue command recognition rate, by doubling it on average, hence allowing attackers to perform additional self-issue commands. Break Tag Chain increases the time a skill can run without user interaction, from eight seconds to more than one hour, hence enabling attackers to setup realistic social engineering scenarios. By exploiting these vulnerabilities, the adversary can self-issue commands that are correctly executed 99% of the times and can keep control of the device for a prolonged amount of time. We reported these vulnerabilities to Amazon via their vulnerability research program, who rated them with a Medium severity score. In addition, we discuss the results of a set of tests performed on three voluntary Echo-equipped households to verify the feasibility of AvA in real scenarios, finding that the attack remains undetected and operative in most cases. Finally, to assess limitations of AvA on a larger scale, we provide the results of a survey performed on a study group of 18 users, and we show that most of the limitations against AvA are hardly used in practice. Sergio Esposito, Daniele Sgandurra, Giampaolo Bella |
AsiaCCS | 1 |