VLDB 2026 Research / reviewers in the wild / expert
Samuele Pasini
dblp:36/4119
· DBLP profile ↗
5ranked-venue papers
2as first author
2since 2021 · last 2026
0000-0002-7900-3727ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Evaluating and improving the robustness of security attack detectors generated by LLMsabstractAbstract Large Language Models (LLMs) are increasingly used in software development to generate functions, such as attack detectors , that implement security requirements. A key challenge is ensuring the LLMs have enough knowledge to address specific security requirements, such as information about existing attacks. For this, we propose an approach integrating Retrieval Augmented Generation (RAG) and Self-Ranking into the LLM pipeline. RAG enhances the robustness of the output by incorporating external knowledge sources, while the Self-Ranking technique, inspired by the concept of Self-Consistency, generates multiple reasoning paths and creates ranks to select the most robust detector. Our extensive empirical study targets code generated by LLMs to detect two prevalent injection attacks in web security: Cross-Site Scripting (XSS) and SQL injection (SQLi). Results show a significant improvement in detection performance while employing RAG and Self-Ranking, with an increase of up to 71%pt (on average 37%pt) and up to 43%pt (on average 6%pt) in the F2-Score for XSS and SQLi detection, respectively. Samuele Pasini, Jinhan Kim, Tommaso Aiello, Rocío Cabrera Lozoya, Antonino Sabetta, Paolo Tonella |
Empir. Softw. Eng. | 1 |
| 2026 | Cross-site scripting adversarial attacks based on deep reinforcement learning: Evaluation and extension studyabstractCross-site scripting (XSS) poses a significant threat to web application security. While Deep Learning (DL) has shown remarkable success in detecting XSS attacks, it remains vulnerable to adversarial attacks due to the discontinuous nature of the mapping between the input (i.e., the attack) and the output (i.e., the prediction of the model whether an input is classified as XSS or benign). These adversarial attacks employ mutation-based strategies for different components of XSS attack vectors, allowing adversarial agents to iteratively select mutations to evade detection. Our work replicates a state-of-the-art XSS adversarial attack, highlighting threats to validity in the reference work and extending it towards a more effective evaluation strategy. Moreover, we introduce an XSS Oracle to mitigate these threats. The experimental results show that our approach achieves an escape rate above 96% when the threats to validity of the replicated technique are addressed. Samuele Pasini, Gianluca Maragliano, Jinhan Kim, Paolo Tonella |
J. Syst. Softw. | 1 |
| 2009 | Facing crosscutting concerns in a middleware for pervasive Service compositionabstractThe emerging, ubiquitous Internet of Services scenario discloses a radical change in the process of content creation and service consumption. Thus, platforms for service and content provisioning should cope with several issues concerning mobility, context awareness and content adaptation. However, traditional programming paradigms, though proving their effectiveness in mastering a good separation of concerns, fall short when it comes to capture concerns that span and orthogonally crosscut several system components. In service-oriented architecture models that face the extremely dynamical and ever-changing above scenario, it is common and usual an undesirable tangling of functionalities which induces poor flexibility, accuracy and consistency. This paper investigates how an innovative and emerging methodology, Aspect-Oriented Programming, can address these issues in a middleware platform for ubiquitous dynamic context-driven service provisioning and configuration. We also distill some design principles and implementation details of the reengineering activities we accomplished. Antonio Corradi, Fulvio Di Marco, Stefano Monti, Samuele Pasini |
ISCC | 4 |
| 2008 | A user-centric composition model for the Internet of ServicesabstractIn the modern Internet of services scenarios, users need to create, share and access contents and services in extremely personalized ways and by means of heterogeneous devices and interaction channels. The most promising architectural solutions to cope with such dynamic and ever-growing scenario adopt a service oriented approach and leverage service composition platforms to flexibly arrange new value-added services made up of basic off-the-shelf components. Though, current solutions for service composition target rather static scenarios and scarcely support today's dynamic Web, where new services and contents continually become available to satisfy novel user needs and service compositions may become obsolete and need reconfiguration. We propose a novel composition model that aims at being extremely flexible and extensible, yet remaining easily usable by hiding complexity to users. Antonio Corradi, Enrico Lodolo, Stefano Monti, Samuele Pasini |
ISCC | 4 |
| 2006 | Middleware for Automatic Dynamic Reconfiguration of Context-Driven ServicesabstractIn the emerging ubiquitous Internet scenario users require to access services and contents from anywhere, at anytime and with any device. Due to this requirement, platforms for service and content provisioning have to address several problems related to the new issues of mobility, multimodality, context awareness and content adaptation. However, current ubiquitous service provisioning platforms still suffer a main drawback: they often underestimate platform logic complexity when multiple ubiquity features should be provided. As a result, the proposed solutions lack a unified approach to the ubiquity issues and provide only limited sets of features. We claim that an integrated and comprehensive solution can stem from a simplicity principle: our approach pushes ubiquity features outside the core middleware layer, by keeping only management and coordination responsibilities. That succeeds in making the middleware design clearer and neater. In this paper we present the key architectural aspects of our middleware platform for ubiquitous dynamic context-driven service provisioning and reconfiguration. We also provide implementation details and description of typical use cases our platform successfully realizes. Maurelio Boari, Enrico Lodolo, Stefano Monti, Samuele Pasini |
ISCC | 4 |