VLDB 2026 Research / reviewers in the wild / expert
Michele Grisafi
dblp:326/7403
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0002-8284-6290ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TAGShield: Persistent Tagging for Robust Stack Memory Error Protection
Michele Grisafi, Carlo Ramponi, Mahmoud Ammar, Silviu Vlasceanu, Bruno Crispo |
AsiaCCS | 1 |
| 2025 | Bridging the Interoperability Gaps Among Trusted Architectures in MCUs
Sandro Pinto 0001, Daniel Oliveira 0003, Michele Grisafi, Emanuele Beozzo, Bruno Crispo |
ICICS (2) | 4 |
| 2024 | FLAShadow: A Flash-based Shadow Stack for Low-end Embedded SystemsabstractRuntime attacks are a rising threat to both low- and high-end systems with the spread of techniques such as Return-Oriented Programming (ROP), which aims at hijacking the control flow of vulnerable applications. Although several control flow integrity schemes have been proposed by both academia and the industry, the vast majority of them are not compatible with low-end embedded devices, especially the ones that lack hardware security features. In this article, we propose \(\sf {\textsc {FLAShadow}}\) , a secure shadow stack design and implementation for low-end embedded systems, relying on zero hardware security features. The key idea is to leverage a software-based memory isolation mechanism to establish an integrity-protected memory area on the Flash of the target device, where \(\sf {\textsc {FLAShadow}}\) can be securely maintained. \(\sf {\textsc {FLAShadow}}\) exclusively reserves a register for maintaining the integrity of the stack pointer and also depends on a minimal trusted runtime component to avoid trusting the compiler toolchain. We evaluate an open-source implementation of \(\sf {\textsc {FLAShadow}}\) for the MSP430 architecture, showing an average performance and memory overhead of 168.58% and 25.91%, respectively. While the average performance overhead is considered high, we show that it is application dependent and incurs less than 5% for some applications. Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
ACM Trans. Internet Things | 1 |
| 2022 | PISTIS: Trusted Computing Architecture for Low-end Embedded Systems
Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
USENIX Security Symposium | 1 |
| 2022 | MPI: Memory Protection for Intermittent ComputingabstractBatteryless devices harvest energy from sporadic ambient sources, enabling a wide range of long-lived, stand-alone, and environmentally-friendly sustainable applications. Software on these devices operates intermittently due to frequent power failures. Each power failure leads the device to lose its computational state that hinders the forward progress of computation and memory consistency. One solution to remedy this situation is to pair programs with checkpoints to save a snapshot of the intermediate program state to non-volatile memory before a power loss. Due to the lack of protection mechanisms in the state-of-the-art intermittent systems, checkpoints can be altered either by programmer errors or deliberately by an attacker. This situation leads to catastrophic effects since the program execution might be corrupted, and in turn, the device might malfunction. In this paper, we propose MPI, a memory protection mechanism for intermittent computing systems. In particular, MPI is a minimal intermittent-compliant trusted computing base acting as a hypervisor that fully manages and protects the underlying memory of a batteryless device. MPI enables a reliable and secure generation and restoration of checkpoints, maintaining their integrity and access control in the presence of remote software-based attacks without trusting the user program or requiring programmer intervention. Notable is that MPI neither requires hardware modifications nor depends on hardware features that might not exist in all batteryless platforms. Our experiments on a real batteryless platform show that MPI provides stronger security guarantees compared to the state-of-the-art approaches, with a comparable time and energy overhead. Michele Grisafi, Mahmoud Ammar, Kasim Sinan Yildirim, Bruno Crispo |
IEEE Trans. Inf. Forensics Secur. | 1 |