Mattia Monga

dblp:32/6774 · DBLP profile ↗
← Back
30ranked-venue papers
0as first author
6since 2021 · last 2026
0000-0003-4852-0067ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 12 · 6 since 2021Software engineering, systems software and programming languages · 9Security and privacy · 6Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 2Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Epistemic Programming as a Scientific Field: Building a Community of Practice and an Interaction-Based Framework
abstract
Contains fulltext : 333701.pdf (Publisher’s version ) (Open Access)
Sven Hüsing, Line Have Musaeus, Michael E. Caspersen, Carsten Schulte 0001, Erik Barendsen, Natasa Grgurina, Matthias Hauswirth, Violetta Lonati, Murali Mani, Mattia Monga, Heidi Nobles, Scott J. Reckinger, Devin W. Silvia, Sören Sparmann
ITiCSE (2)10
2025 Playcards, Pasta and Rectangles: Teaching Information Representation and Data Encoding in 4th Grade
abstract
Information representation is a key concept in informatics, that involves representing real-world problems through symbolic encoding of data that can be automatically processed. Despite that, the presence and role of this concept in curricula, learning materials, and activities, is much less significant w.r.t. other informatics areas, as programming (coding) or algorithms. In this experience report we present a learning unit we designed, consisting of five two-hour lessons, that aims at introducing pupils to the fundamental concepts around information representation, and that we piloted in five fourth-grade classes. We also present and reflect upon the feedback asked of teachers, after the learning unit was concluded in their classes.
Arianna Boldi, Sara Capecchi, Violetta Lonati, Mattia Monga
ITiCSE (1)4
2024 To Be Or Not To Be . . . An Algorithm: The Notion According to Students and Teachers
abstract
We study how students and teachers conceptualize the notion of 'algorithm', a fundamental concept in computer science and computer science curricula. We analyze the work produced by CS students and teachers during a workshop conducted repeatedly over several years in some outreach activities for schools, computing education courses, and professional development opportunities for teachers. Participants were divided into groups, given some procedures written in natural language, and asked to decide together which of the procedures might be taken as algorithms. The procedures were purposely designed to present flaws or features that could activate discussion. After that, groups were asked to agree upon a definition of 'algorithm' and make its fundamental properties explicit. The activity triggered reflections around the idea of algorithm and its interpreter, going beyond stereotyped definitions, and leading participants to deepen their comprehension of the notion. We report on the aspects that were more debated by the groups, and those that were recurrent in the resulting definitions. We argue that this kind of activities should be offered more often both to students during their study career, and to teachers in professional development opportunities, to prompt them to reflect on computing foundations also in a non-technical, more holistic way.
Carlo Bellettini, Violetta Lonati, Mattia Monga, Anna Morpurgo
SIGCSE (1)3
2023 Davinci Goes to Bebras: A Study on the Problem Solving Ability of GPT-3
abstract
In this paper we study the problem-solving ability of the Large Language Model known as GPT-3 (codename DaVinci), by considering its performance in solving tasks proposed in the “Bebras International Challenge on Informatics and Computational Thinking”. In our experiment, GPT-3 was able to answer with a majority of correct answers about one third of the Bebras tasks we submitted to it. The linguistic fluency of GPT-3 is impressive and, at a first reading, its explanations sound coherent, on-topic and authoritative; however the answers it produced are in fact erratic and the explanations often questionable or plainly wrong. The tasks in which the system performs better are those that describe a procedure, asking to execute it on a specific instance of the problem. Tasks solvable with simple, one-step deductive reasoning are more likely to obtain better answers and explanations. Synthesis tasks, or tasks that require a more complex logical consistency get the most incorrect answers.
Carlo Bellettini, Michael Lodi, Violetta Lonati, Mattia Monga, Anna Morpurgo
CSEDU (2)4
2023 Learning Iteration for Grades 2-3: Puzzles vs. UMC in Code.org
abstract
In a project partially supported by research grant PANN20_00690 to Italy's CINI National Lab "Informatica e Scuola", we compared the effectiveness of two alternative instructional methods applied to scaffold the learning of iterations for children at grades 2-3. Eight university groups across the Country collaboratively run the project in two successive rounds throughout the year 2022. Teachers' feedback collected across the two rounds helped fine-tune the deployment of the interventions. The experiment results show that the two alternative interventions have measurable outcome differences in the short term.
Enrico Nardelli, Francesco Lacchia, Renzo Davoli, Michael Lodi, Marco Sbaraglia, Veronica Rossano, Enrica Gentile, Violetta Lonati, Mattia Monga, Anna Morpurgo, Luca Forlizzi, Giovanna Melideo, Sara Capecchi, Ilenia Fronza, Tullio Vardanega
SIGCSE (2)9
2022 Characterizing the Nature of Programs for educational purposes
abstract
Programming plays a paramount role in many educational policies and initiatives. However, the current focus on coding skills poses a risk of giving pupils an over simplistic and impoverished idea of what programming means and involves. Their experiences would be much more significant if learning were aimed at understanding the richness of the nature of programs. In fact, programs are strange creatures that escape simple definitions. They are real, in that they affect our real lives; they are abstract, in that they process abstract entities; and they are concrete, in that they take up space in digital devices memory, and can be copied, transferred, corrupted. Thus, understanding the multifaceted nature of programs is crucial knowledge for all citizens of the digital era, and a fundamental component of such an understanding is getting a sense of how programs are created and work (i.e., the programming process). To the best of our knowledge, there is no Nature of Programs framework (e.g., a set of statements that describe what the nature of programs is), that teachers and policy makers can use to shape their practice and targets. The goal of the WG is developing such a framework, by collecting and organizing contributions from CER, CS experts, and educators.
Violetta Lonati, Andrej Brodnik, Timothy C. Bell, Andrew Csizmadia, Liesbeth De Mol, Henry Hickman, Therese Keane, Claudio Mirolo, Mattia Monga, Matti Tedre
ITiCSE (2)9
2020 Assessing How Pre-requisite Skills Affect Learning of Advanced Concepts
abstract
Students often struggle with advanced computing courses, and comparatively few studies have looked into the reasons for this. It seems that learners do not master the most basic concepts, or forget them between courses. If so, remedial practice could improve learning, but instructors rightly will not use scarce time for this without strong evidence. Based on personal observation, program tracing seems to be an important pre-requisite skill, but there is yet little research that provides evidence for this observation. To investigate this, our group will create theory-based assessments on how tracing knowledge affects learning of advanced topics, such as data structures, algorithms, and concurrency. This working group will identify relevant concepts in advanced courses, then conceptually analyze their pre-requisites and where an imagined student with some tracing difficulties would encounter barriers. The group will use this theory to create instructor-usable assessments for advanced topics that also identify issues caused by poor pre-requisite knowledge. These assessments may then be used at the start and end of advanced courses to evaluate to what extent students' difficulties with the advanced course originate from poor pre-requisite knowledge.
Greg L. Nelson, Filip Strömbäck, Ari Korhonen, Ibrahim Albluwi, Marjahan Begum, Ben Blamey, Karen H. Jin, Violetta Lonati, Bonnie K. MacKellar, Mattia Monga
ITiCSE10
2019 How Pupils Solve Online Problems: An Analytical View
Carlo Bellettini, Violetta Lonati, Mattia Monga, Anna Morpurgo
CSEDU (2)3
2018 A Platform for the Italian Bebras
abstract
The Bebras International Challenge on Informatics and Computational Thinking is a contest open to pupils of all school levels (from primary up to upper secondary) based on tasks rooted on core informatics concepts, yet independent of specific previous knowledge such as for instance that acquired during curricular activities.This paper describes the design choices, the architecture, and the main features of the web-based platform used to carry out the Italian Bebras contest.This platform includes functionalities needed by students, teachers, and Bebras staff during the execution of the challenge, tools to support the preparation of tasks and the training of students, instruments to evaluate the results and analyse data collected during the challenge.The platform is online since 2015 and it has managed the participation of around 25,000 teams and a significant amount of training sessions.
Carlo Bellettini, Fabrizio Carimati, Violetta Lonati, Riccardo Macoratti, Dario Malchiodi, Mattia Monga, Anna Morpurgo
CSEDU (1)6
2017 Bebras as a Teaching Resource: Classifying the Tasks Corpus Using Computational Thinking Skills
abstract
We present a new classification method for Bebras tasks based on the ISTE/CSTA operational definition of computational thinking. The classification can be appreciated by teachers without a formal education in informatics and it helps in detecting the cognitive skills involved by tasks, and makes their educational potential more explicit.
Violetta Lonati, Dario Malchiodi, Mattia Monga, Anna Morpurgo
ITiCSE3
2016 A Security Game Model for Remote Software Protection
abstract
When a piece of software is loaded on an untrusted machine it can be analyzed by an attacker who could discover any secret information hidden in the code. Software protection by continuously updating the components deployed in an untrusted environment forces a malicious user to restart her or his analyses, thus reducing the time window in which the attack is feasible. In this setting, both the attacker and the defender need to know how to direct their(necessarily limited) efforts. In this paper, we analyze the problem from a game theoretical perspective in order to devise a rational strategy to decide when and which orthogonal updates have to be scheduled in order to minimize the security risks of tampering. We formalize the problem of protecting a set of software modules and we cast it as a game. Since the update strategy is observable by the attacker, we show that the Leader-Follower equilibrium is the proper solution concept for such a game and we describe the basic method to compute it.
Nicola Basilico, Andrea Lanzi, Mattia Monga
ARES3
2016 Distributed CTL model checking using MapReduce: theory and practice
abstract
Summary The recent extensive availability of ‘cloud’ computing platforms is very appealing for the formal verification community. In fact, these platforms represent a great opportunity to run massively parallel jobs and analyze ‘big data’ problems, although classical formal verification tools and techniques must undergo a deep technological transformation to take advantage of the available powerful architectures. A distributed approach to verification of computation tree logic formulas on very large state spaces is described. The approach exploits and integrates our parametric state–space builder, designed to ease the adoption of ‘big data’ platforms. The whole framework adopts aMAPREDUCEapproach as the core computational model and can be tailored to different modeling formalisms. This paper includes proofs of correctness, a short theoretical discussion about complexity, and reports a practical experience with some benchmarking Petri net models. The outcomes of several tests are presented, thus showing the convenience of the proposed approach. Copyright © 2015 John Wiley & Sons, Ltd.
Carlo Bellettini, Matteo Camilli, Lorenzo Capra, Mattia Monga
Concurr. Comput. Pract. Exp.4
2015 How Challenging are Bebras Tasks?: An IRT Analysis Based on the Performance of Italian Students
abstract
This paper analyses the results of the 2014 edition of the Italian Bebras/Kangourou contest, exploiting the Item Response Theory statistical methodology in order to infer the difficulty of each of the proposed tasks starting from the scores attained by the participants. Such kind of analysis, enabling the organizers of the contest to check whether or not the difficulty perceived by pupils was substantially different from that estimated by those who proposed the tasks, is important as a feedback in order to gain knowledge to be used both in ranking participants and in organizing future editions of the contest. We show how the proposed analysis essentially highlights that the 63% of tasks was perceived at the same level of difficulty estimated by those who proposed them, but a 37% of tasks were either easier or more difficult than expected.
Carlo Bellettini, Violetta Lonati, Dario Malchiodi, Mattia Monga, Anna Morpurgo, Mauro Torelli
ITiCSE4
2014 Informatics Education in Italian Secondary Schools
abstract
This article describes the state of informatics education in the Italian secondary schools, highlighting how the learning objectives set up by the Ministry of Education are difficult to meet, due to the fact that the subject is often taught by teachers not holding an informatics degree, the lack of suitable teaching material and the expectations of pupils and families, who tend to identify informatics with the use of computer applications.
Carlo Bellettini, Violetta Lonati, Dario Malchiodi, Mattia Monga, Anna Morpurgo, Mauro Torelli, Luisa Zecca
ACM Trans. Comput. Educ.4
2014 Security Games for Node Localization through Verifiable Multilateration
abstract
Most applications of wireless sensor networks (WSNs) rely on data about the positions of sensor nodes, which are not necessarily known beforehand. Several localization approaches have been proposed but most of them omit to consider that WSNs could be deployed in adversarial settings, where hostile nodes under the control of an attacker coexist with faithful ones. Verifiable multilateration (VM) was proposed to cope with this problem by leveraging on a set of trusted landmark nodes that act as verifiers. Although VM is able to recognize reliable localization measures, it allows for regions of undecided positions that can amount to the 40 percent of the monitored area. We studied the properties of VM as a noncooperative two-player game where the first player employs a number of verifiers to do VM computations and the second player controls a malicious node. The verifiers aim at securely localizing malicious nodes, while malicious nodes strive to masquerade as unknown and to pretend false positions. Thanks to game theory, the potentialities of VM are analyzed with the aim of improving the defender's strategy. We found that the best placement for verifiers is an equilateral triangle with edge equal to the power range $(R)$, and maximum deception in the undecided region is approximately $(0.27R)$. Moreover, we characterizedâin terms of the probability of choosing an unknown node to examine furtherâthe strategies of the players.
Nicola Basilico, Nicola Gatti 0001, Mattia Monga, Sabrina Sicari
IEEE Trans. Dependable Secur. Comput.3
2011 Seventh international workshop on software engineering for secure systems: (SESS 2011)
abstract
The 7th edition of the SESS workshop aims at providing a venue for software engineers and security researchers to exchange ideas and techniques. In fact, software is at core of most of the business transactions and its smart integration in an industrial setting may be the competitive advantage even when the core competence is outside the ICT field. As a result, the revenues of a firm depend directly on several complex software-based systems. Thus, stakeholders and users should be able to trust these systems to provide data and elaborations with a degree of confidentiality, integrity, and availability compatible with their needs. Moreover, the pervasiveness of software products in the creation of critical infrastructures has raised the value of trustworthiness and new efforts should be dedicated to achieve it. However, nowadays almost every application has some kind of security requirement even if its use is not to be considered critical.
Seok-Won Lee, Mattia Monga, Jan Jürjens
ICSE2
2010 The 6th International Workshop on Software Engineering for Secure Systems (SESS'10)
Seok-Won Lee, Mattia Monga, Jan Jürjens
ICSE (2)2
2010 Dynamic and transparent analysis of commodity production systems
abstract
We propose a framework that provides a programming interface to perform complex dynamic system-level analyses of deployed production systems. By leveraging hardware support for virtualization available nowadays on all commodity machines, our framework is completely transparent to the system under analysis and it guarantees isolation of the analysis tools running on top of it. Thus, the internals of the kernel of the running system needs not to be modified and the whole platform runs unaware of the framework. Moreover, errors in the analysis tools do not affect the running system and the framework. This is accomplished by installing a minimalistic virtual machine monitor and migrating the system, as it runs, into a virtual machine. In order to demonstrate the potentials of our framework we developed an interactive kernel debugger, named HyperDbg. HyperDbg can be used to debug any critical kernel component, and even to single step the execution of exception and interrupt handlers.
Aristide Fattori, Roberto Paleari, Lorenzo Martignoni, Mattia Monga
ASE4
2010 Special issue on software engineering for secure systems
Seok-Won Lee, Mattia Monga
Comput. Secur.2
2009 Synthesizing intensional behavior models by graph transformation
abstract
This paper describes an approach (SPY) to recovering the specification of a software component from the observation of its run-time behavior. It focuses on components that behave as data abstractions. Components are assumed to be black boxes that do not allow any implementation inspection. The inferred description may help understand what the component does when no formal specification is available. SPY works in two main stages. First, it builds a deterministic finite-state machine that models the partial behavior of instances of the data abstraction. This is then generalized via graph transformation rules. The rules can generate a possibly infinite number of behavior models, which generalize the description of the data abstraction under an assumption of ldquoregularityrdquo with respect to the observed behavior. The rules can be viewed as a likely specification of the data abstraction. We illustrate how SPY works on relevant examples and we compare it with competing methods.
Carlo Ghezzi, Andrea Mocci, Mattia Monga
ICSE3
2009 Special section on Software Engineering for Secure Systems (SESS '07)
Seok-Won Lee, Mattia Monga
Inf. Softw. Technol.2
2008 On Race Vulnerabilities in Web Applications
Roberto Paleari, Davide Marrone, Danilo Bruschi, Mattia Monga
DIMVA4
2007 Using a Stochastic Well-formed Net model for assessing a decentralized approach to configuration management
Carlo Bellettini, Lorenzo Capra, Mattia Monga
Perform. Evaluation3
2006 Detecting Self-mutating Malware Using Control-Flow Graph Matching
Danilo Bruschi, Lorenzo Martignoni, Mattia Monga
DIMVA3
2006 Software engineering for secure systems
abstract
No abstract available.
Danilo Bruschi, Bart De Win, Mattia Monga
ICSE3
2006 Interaction Analysis in Aspect-Oriented Models
abstract
Aspect-oriented concepts are currently introduced in all phases of the software development life cycle. However, the complexity of interactions among different aspects and between aspects and base entities may reduce the value of aspect-oriented separation of cross-cutting concerns. Some interactions may be intended or may be emerging behavior, while others are the source of unexpected inconsistencies. It is therefore desirable to detect inconsistencies as early as possible, preferably at the modeling level. We propose an approach for analyzing interactions and potential inconsistencies at the level of requirements modeling. We use a variant of UML to model requirements in a use case driven approach. Activities that are used to refine use cases are the join points to compose crosscutting concerns. The activities and their composition are formalized using the theory of graph transformation systems, which provides analysis support for detecting potential conflicts and dependencies between rule-based transformations. This theory is used to effectively reason about potential interactions and inconsistencies caused by aspect-oriented composition. The analysis is performed with the graph transformation tool AGG. The automatically analyzed conflicts and dependencies also serve as an additional view that helps in better understanding the potential behavior of the composed system
Katharina Mehner-Heindl, Mattia Monga, Gabriele Taentzer
RE2
2006 Supporting Cooperative Software Processes in a Decentralized and Nomadic World
abstract
Recent advances in wireless networks enable decentralized cooperative and nomadic work scenarios where mobile users can interact in performing some tasks without being permanently online. Scenarios where connectivity is transient and the network topology may change dynamically are considered. Connectivity among nodes does not require the support offered by a permanent infrastructure but may rely on ad hoc networking facilities. In this paper, a scenario in which a nomadic group of software engineers cooperate in developing an application is investigated. The proposed solution, however, is not software process specific but holds for other cases where shared documents are developed cooperatively by a number of interacting nomadic partners. Support tools for these groups are normally based on a client-server architecture, which appears to be unsuitable in highly dynamic environments. Peer-to-peer solutions, which do not rely on services provided by centralized servers, look more promising. This paper presents a fully decentralized cooperative infrastructure centered around peer-to-peer versioning system (PeerVerSy), a configuration management tool based on a peer-to-peer architecture, which supports cooperative services even when some of the collaborating nodes are offline. Some preliminary experiences gained from its use in a teaching environment are also discussed
Davide Balzarotti, Carlo Ghezzi, Mattia Monga
IEEE Trans. Syst. Man Cybern. Part A3
2005 Replay Attack in TCG Specification and Solution
abstract
We prove the existence of a flaw which we individuated in the design of the object-independent authorization protocol (OIAP), which represents one of the building blocks of the trusted platform module (TPM), the core of the trusted computing platforms (TPs) as devised by the trusted computing group (TCG) standards. In particular, we prove, also with the support of a model checker, that the protocol is exposed to replay attacks, which could be used for compromising the correct behavior of a TP We also propose a countermeasure to undertake in order to avoid such an attack as well as any replay attacks to the aforementioned protocol
Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi, Mattia Monga
ACSAC4
2005 Software engineering for secure systems
abstract
No abstract available
Danilo Bruschi, Bart De Win, Mattia Monga
ICSE3
2002 Supporting configuration management for virtual workgroups ini a peer-to-peer setting
abstract
In this paper we describe a configuration management tool suitable for the untethered scenarios typical in a mobile environment. The scenario envisions a number of homogeneous peers that are able to provide the same services, disconnect frequently from the net, and perform part of their work while disconnected. In these contexts the absence of a host is not the exceptional case, but rather the normal behavior. Thus, a traditional architecture based on a central repository exposes the system to failures when the server is unavailable. Instead, we build our system on a peer-to-peer middleware able to provide the abstraction of global virtual data structure, i.e., a data structure composed by all the data actually connected in a given instant. Thanks to this, we can exploit the service provided by the network even if relevant hosts are disconnected.
Davide Balzarotti, Carlo Ghezzi, Mattia Monga
SEKE3