Marcello Maugeri

dblp:328/9091 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-6585-5494ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 RTE4SDC at the ICST 2026 Tool Competition - Self-Driving Car Testing Track
Marcello Maugeri, PingChen Lin, Aryan Pasikhani
ICST1
2025 Poster: Machine Learning for Vulnerability Detection as Target Oracle in Automated Fuzz Driver Generation
Gianpietro Castiglione, Marcello Maugeri, Giampaolo Bella
DIMVA (1)2
2025 LibAFLstar: Fast and State-Aware Protocol Fuzzing
Cristian Daniele, Timme Bethe, Marcello Maugeri, Andrea Continella, Erik Poll
ESORICS (3)3
2025 BenGQL: An Extensible Benchmarking Framework for Automated GraphQL Testing
abstract
GraphQL APIs provide a unified endpoint for retrieving and uploading data in a web application. Due to its efficient data-fetching strategy, which allows for the retrieval of only the required data, GraphQL is gaining popularity. Its software nature necessitates robust testing, both functional and non-functional. As automated testing tools, including load testers and fuzzers, are developed to assess GraphQL APIs, they lack a common set of case studies for rigorous evaluation and comparison.To address this gap, we present BenGQL, a benchmarking framework containing 23 representative open-source GraphQL server applications, spanning different underlying engines and schema complexities. BenGQL provides an extensible infrastructure for running testing tools against these case studies, enabling developers and researchers to: (i) execute testing tools against the same case studies, (ii) analyse and compare results using custom analysis modules, and (iii) extend the benchmark with new case studies, tools, or metrics.The ultimate goal of BenGQL is to foster more rigorous, reproducible research in automated GraphQL testing by providing both the case studies and the infrastructure for running experiments. As a consequence, we release the source code at https://github.com/marcellomaugeri/BenGQL, inviting other researchers to contribute. A video demonstration is also available at https://youtu.be/wZ06Xxa_Koo.
Abenezer Angamo, Marcello Maugeri
ASE2
2025 KrakQL: LLM-Guided Blind Introspection of GraphQL Schemas
Marcello Maugeri, Abenezer Angamo, Giampaolo Bella
SSBSE1
2024 Fuzzing Matter(s): A White Paper for Fuzzing the Matter Protocol
Marcello Maugeri
ICISSP1
2023 Evaluating the Fork-Awareness of Coverage-Guided Fuzzers
abstract
Contains fulltext : 290606.pdf (Publisher’s version ) (Open Access)
Marcello Maugeri, Cristian Daniele, Giampaolo Bella, Erik Poll
ICISSP1
2022 Embedded fuzzing: a review of challenges, tools, and solutions
abstract
Abstract Fuzzing has become one of the best-established methods to uncover software bugs. Meanwhile, the market of embedded systems, which binds the software execution tightly to the very hardware architecture, has grown at a steady pace, and that pace is anticipated to become yet more sustained in the near future. Embedded systems also benefit from fuzzing, but the innumerable existing architectures and hardware peripherals complicate the development of general and usable approaches, hence a plethora of tools have recently appeared. Here comes a stringent need for a systematic review in the area of fuzzing approaches for embedded systems, which we term “embedded fuzzing” for brevity. The inclusion criteria chosen in this article are semi-objective in their coverage of the most relevant publication venues as well as of our personal judgement. The review rests on a formal definition we develop to represent the realm of embedded fuzzing. It continues by discussing the approaches that satisfy the inclusion criteria, then defines the relevant elements of comparison and groups the approaches according to how the execution environment is served to the system under test. The resulting review produces a table with 42 entries, which in turn supports discussion suggesting vast room for future research due to the limitations noted.
Max Eisele, Marcello Maugeri, Rachna Shriwas, Christopher Huth, Giampaolo Bella
Cybersecur.2