VLDB 2026 Research / reviewers in the wild / expert
Giorgio Giacinto
dblp:52/3657
· DBLP profile ↗
67ranked-venue papers
11as first author
16since 2021 · last 2026
0000-0002-5759-3017ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 11 since 2021Artificial intelligence and machine learning · 24 · 11 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 12 · 2 first-authorComputer networks · 5 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Analysis of Modern Web Security Vulnerabilities Inside WebAssembly Applications
Lorenzo Corrias, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ICISSP (1) | 4 |
| 2026 | Race against time: investigating the factors that influence web race condition exploitsabstractRace conditions (RC) pose a critical security threat to web applications by exploiting the non-deterministic behavior of multithreaded request handling. This can lead to unpredictable outcomes such as data corruption, Time of Check to Time of Use (TOCTOU) vulnerabilities, and deadlocks. While previous research has identified poor design practices that contribute to RC vulnerabilities, no existing studies have explored the factors that influence the severity or impact of race conditions. This paper introduces a comprehensive methodology for testing and quantifying how different variables affect the exploitability of race conditions in vulnerable web servers, providing a framework for future research to investigate this issue more thoroughly. In addition, we present an experimental evaluation of our methodology under various conditions. Specifically, we examine six RC exploitation tools using four different attack techniques across both HTTP/1.1 and HTTP/2 protocols. To provide a complete overview of race conditions across all HTTP versions, we also introduce the first race condition attack tool for HTTP/3, named QUICker. Furthermore, we assess how the choice of database management systems and programming languages used in web application deployment can affect susceptibility to race condition attacks. This study offers key insights into how these factors influence the exploitability of RC vulnerabilities. Federico Loi, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Giorgio Giacinto |
Comput. Secur. | 5 |
| 2026 | An Assessment of the Overlooked Dangers of Template EnginesabstractTemplate engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development. Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
ACM Trans. Web | 3 |
| 2025 | Evaluation of Resource-Aware HTTP/3 Proxies for Smuggling Resilience in IoT EnvironmentsabstractThe growing integration of IoT devices into Edge and Fog infrastructures, alongside the increasing adoption of low-latency QUIC-based protocols like HTTP/3, has intensified the need for lightweight, resource-efficient security mechanisms to counter emerging threats such as request smuggling. Within this context, proxy-based architectures offer an optimal trade-off to strengthen network security while accommodating the limited computational capacity of IoT devices. In this direction, this paper presents a comprehensive experimental evaluation of the impact of different proxies for HTTP/3 services on resource usage when deployed on platforms such as the Raspberry Pi (RPi), considering diverse traffic patterns, operational conditions, and device configurations. The results highlight that proxies can achieve a promising balance between security and resource overhead, confirming their viability for integration into distributed IoT-based Edge and Fog networks. Lorenzo Pisu, Giovanni Pettorru, Leonardo Regano, Davide Maiorca, Giorgio Giacinto, Marco Martalò |
GLOBECOM | 5 |
| 2025 | Analysis and Detection of Android Stegomalware: the Impact of the Loading StageabstractDue to the increasing use of advanced offensive techniques, the mitigation of Android malware is an urgent need.An emerging attack trend exploits steganography to conceal malicious payloads within applications to make attacks stealthier.Even if works on "stegomalware" are starting to emerge, they primarily focus on the multimedia part of the attack chain, i.e., on how to detect hidden data in images or videos.Therefore, this work aims at understanding whether the loading stage required for the extraction of cloaked information can generate detection signatures.To this aim, we develop a proofof-concept implementation, which has been repacked within a real Android application and tested against several malware detection engines provided by VirusTotal.To anticipate possible offensive campaigns, we also performed tests by considering threat actors able to obfuscate the bytecode of the loader or the entire APK.Results indicate that standard tools are not ready to face stegomalware targeting Android applications.Therefore, we provide indications on how to improve forensics and attribution phases for Android malware endowed with information hiding capabilities. Diego Soi, Silvia Lucia Sanna, Giacomo Benedetti, Angelica Liguori, Leonardo Regano, Luca Caviglione, Giorgio Giacinto |
IH&MMSec | 7 |
| 2025 | {{alert('CSTI')}}: Large-Scale Detection of Client-Side Template InjectionabstractTemplate engines are software components that enable the creation of reusable HTML elements containing special keywords that can dynamically alter the page’s rendering based on the presented data. This technology is widely used in server-side applications and frameworks, and in recent years, it has also gained adoption on the client side through JavaScript frameworks and libraries. Client-Side Template Injection (CSTI) is a vulnerability that occurs when user input is reflected inside a template and rendered as part of it, allowing attackers to inject malicious instructions. This can trick the template engine into executing arbitrary JavaScript code, potentially leading to Cross-Site Scripting (XSS). Despite the widespread adoption of template engines in production websites, a comprehensive study of their characteristics remains absent. In our study, we begin by providing an overview of the main features of template engines, highlighting attributes that play a crucial role in escalating CSTI to XSS. We then use these extracted characteristics to develop a systematic methodology for detecting CSTI vulnerabilities. Based on this methodology, we create an automatic CSTI detection tool, CSTI-Alert. By running CSTI-Alert on the Tranco top 1 million domains, we identify 532 CSTI-vulnerable domains, with 72% directly leading to XSS through GET parameters or CSRF. Finally, we discuss potential approaches to defend against CSTI based on the result of semi-automatic exploitability analysis. Lorenzo Pisu, Davide Balzarotti, Davide Maiorca, Giorgio Giacinto |
RAID | 4 |
| 2025 | DroidReach++: Exploring the reachability of native code in android applications
Luca Borzacchiello, Matteo Cornacchia, Davide Maiorca, Giorgio Giacinto, Emilio Coppa |
Comput. Secur. | 4 |
| 2025 | HO-FMN: Hyperparameter optimization for fast minimum-norm attacksabstractGradient-based attacks are a primary tool to evaluate robustness of machine-learning models. However, many attacks tend to provide overly-optimistic evaluations as they use fixed loss functions, optimizers, step-size schedulers, and default hyperparameters. In this work, we tackle these limitations by proposing a parametric variation of the well-known fast minimum-norm attack algorithm, whose loss, optimizer, step-size scheduler, and hyperparameters can be dynamically adjusted. We re-evaluate 12 robust models, showing that our attack finds smaller adversarial perturbations without requiring any additional tuning. This also enables reporting adversarial robustness as a function of the perturbation budget, providing a more complete evaluation than that offered by fixed-budget attacks, while remaining efficient. We release our open-source code at https://github.com/pralab/HO-FMN . • We improve minimum-norm attacks using different losses, optimizers, and schedulers. • We leverage hyperparameter optimization to improve the attack performance. • We compute full robustness-perturbation curves with a single, effective attack. Raffaele Mura, Giuseppe Floris, Luca Scionis, Giorgio Piras, Maura Pintor, Ambra Demontis, Giorgio Giacinto, Battista Biggio, Fabio Roli |
Neurocomputing | 7 |
| 2025 | Adversarial pruning: A survey and benchmark of pruning methods for adversarial robustnessabstractRecent work has proposed neural network pruning techniques to reduce the size of a network while preserving robustness against adversarial examples, i.e., well-crafted inputs inducing a misclassification. These methods, which we refer to as adversarial pruning methods, involve complex and articulated designs, making it difficult to analyze the differences and establish a fair and accurate comparison. In this work, we overcome these issues by surveying current adversarial pruning methods and proposing a novel robustness-oriented taxonomy to categorize them based on two main dimensions: the pipeline , defining when to prune; and the specifics , defining how to prune. We then highlight the limitations of current empirical analyses and propose a novel, fair evaluation benchmark to address them. We finally conduct an empirical re-evaluation of current adversarial pruning methods and discuss the results, highlighting the shared traits of top-performing adversarial pruning methods, as well as common issues. We welcome contributions in our publicly-available benchmark at https://github.com/pralab/AdversarialPruningBenchmark . Giorgio Piras, Maura Pintor, Ambra Demontis, Battista Biggio, Giorgio Giacinto, Fabio Roli |
Pattern Recognit. | 5 |
| 2024 | HTTP/3 will not Save you from Request Smuggling: A Methodology to Detect HTTP/3 Header (mis)ValidationsabstractHTTP/3 will be the new de-facto standard for communication in web applications. Despite its increasing integration into modern browsers, its security properties have not yet been fully investigated. A significant problem is represented by request smuggling attacks, which may constitute a critical issue concerning web applications’ security and privacy, leading to critical consequences such as cache poisoning, session hijacking, and Denial Of Service (DOS). This category of attacks is particularly interesting as it involves abusing the characteristics of the HTTP protocol to manipulate and craft malicious requests that the server will misinterpret, creating desynchronizations between the frontend and the backend. In this paper, we present the first taxonomy of request smuggling attacks in HTTP/3. Specifically, we focus on conversion and validation issues observed in HTTP/2 that can persist in HTTP/3 environments. Since these attacks depend on how proxies parse incoming requests, we also present a methodology to discover possible header validation issues that can cause request smuggling in proxies and frameworks. Finally, we apply this methodology to four proxies and a Python framework, finding various incoherences in their ways to parse malformed requests. Our work aims to underscore the importance of vigilance in current and future applications utilizing HTTP/3 protocols to mitigate potential security risks. Despite the limited availability of libraries and frameworks supporting HTTP/3 at the present moment, its rapid adoption calls for consideration and analysis of its security. Lorenzo Pisu, Federico Loi, Davide Maiorca, Giorgio Giacinto |
NCA | 4 |
| 2024 | Do You Trust Your Device? Open Challenges in IoT Security AnalysisabstractSeveral critical contexts, such as healthcare, smart cities, drones, transportation, and agriculture, nowadays rely on IoT, or more in general embedded, devices that require comprehensive security analysis to ensure their integrity before deployment. Security concerns are often related to vulnerabilities that result from inadequate coding or undocumented features that may create significant privacy issues for users and companies. Current analysis methods, albeit dependent on complex tools, may lead to superficial assessments due to compatibility issues, while authoritative entities struggle with specifying feasible firmware analysis requests for manufacturers within operational contexts. This paper urges the scientific community to collaborate with stakeholders—manufacturers, vendors, security analysts, and experts—to forge a cooperative model that clarifies manufacturer contributions and aligns analysis demands with operational constraints. Aiming at a modular approach, this paper highlights the crucial need to refine security analysis, ensuring more precise requirements, balanced expectations, and stronger partnerships between vendors and analysts. To achieve this, we propose a threat model based on the feasible interactions of actors involved in the security evaluation of a device, with a particular emphasis on the responsibilities and necessities of all entities involved. Lorenzo Binosi, Pietro Mazzini, Alessandro Sanna, Michele Carminati, Giorgio Giacinto, Riccardo Lazzeretti, Stefano Zanero, Mario Polino, Emilio Coppa, Davide Maiorca |
SECRYPT | 5 |
| 2024 | Bringing Binary Exploitation at Port 80: Understanding C Vulnerabilities in WebAssemblyabstractWebAssembly (Wasm) has emerged as a novel approach for integrating binaries into web applications starting from various programming languages such as C, Rust and Python. Despite the numerous claims about its memory safety, issues such as buffer overflow, format strings, use after free, and integer overflow have resurfaced within Wasm. These vulnerabilities can be used to impact web application security, potentially leading to critical issues like Cross-Site Scripting (XSS) and Remote Code Execution (RCE). Our work aims to demonstrate how memory-related vulnerabilities in C codes, when compiled into Wasm, can be exploited for XSS and RCE. Our methodology proposes proof of concepts related to exploiting important stack- and heap-based vulnerabilities. In particular, we demonstrate for the first time that specific vulnerabilities (such as format string) can be effectively employed to achieve arbitrary read and write in Wasm contexts. Our results pose serious concerns about the reliability of Wasm in terms of memory safety, which we believe should be addressed in the next releases. Emmanuele Massidda, Lorenzo Pisu, Davide Maiorca, Giorgio Giacinto |
SECRYPT | 4 |
| 2024 | Enhancing android malware detection explainability through function call graph APIsabstractNowadays, mobile devices are massively used in everyday activities. Thus, they contain sensitive data targeted by threat actors like bank accounts and personal information. Through the years, Machine Learning approaches have been proposed to identify malicious Android applications, but recent research highlights the need for better explanations for model decisions, as existing ones may not be related to the app’s malicious functionalities. This paper proposes an explainable approach based on static analysis to detect Android malware. The novelty lies in the specific analysis conducted to select and extract the features (i.e., APIs taken from the DEX Call Graph) that immediately provide meaningful explanations of the model functionality, thus allowing a significant correlation of the malware behavior with its family. Moreover, since we contain the number and type of features, the distinct impacts of each one appear more evident. The attained results show that it is possible to reach comparable results (in terms of accuracy) to existing state-of-the-art models while providing easy-to-understand explanations, which may yield significant insights into the malicious functionalities of the samples. Diego Soi, Alessandro Sanna, Davide Maiorca, Giorgio Giacinto |
J. Inf. Secur. Appl. | 4 |
| 2022 | Extended Abstract: Effective Call Graph Fingerprinting for the Analysis and Classification of Windows Malware
Francesco Meloni, Alessandro Sanna, Davide Maiorca, Giorgio Giacinto |
DIMVA | 4 |
| 2022 | Reach Me if You Can: On Native Vulnerability Reachability in Android Apps
Luca Borzacchiello, Emilio Coppa, Davide Maiorca, Andrea Columbu, Camil Demetrescu, Giorgio Giacinto |
ESORICS (3) | 6 |
| 2022 | A Longitudinal Study of Cryptographic API: A Decade of Android MalwareabstractCryptography has been extensively used in Android applications to guarantee secure communications, conceal critical data from reverse engineering, or ensure mobile users' privacy. Various system-based and third-party libraries for Android provide cryptographic functionalities, and previous works mainly explored the misuse of cryptographic API in benign applications. However, the role of cryptographic API has not yet been explored in Android malware. This paper performs a comprehensive, longitudinal analysis of cryptographic API in Android malware. In particular, we analyzed 603 937 Android applications (half of them malicious, half benign) released between 2012 and 2020, gathering more than 1 million cryptographic API expressions. Our results reveal intriguing trends and insights on how and why cryptography is employed in Android malware. For instance, we point out the widespread use of weak hash functions and the late transition from insecure DES to AES. Additionally, we show that cryptography-related characteristics can help to improve the performance of learning-based systems in detecting malicious applications. Adam Janovsky, Davide Maiorca, Dominik Macko, Vashek Matyas, Giorgio Giacinto |
SECRYPT | 5 |
| 2020 | Adversarial Detection of Flash Malware: Limitations and Open Issues
Davide Maiorca, Ambra Demontis, Battista Biggio, Fabio Roli, Giorgio Giacinto |
Comput. Secur. | 5 |
| 2020 | Convolutional neural networks for relevance feedback in content based image retrievalabstractAbstract Given the great success of Convolutional Neural Network (CNN) for image representation and classification tasks, we argue that Content-Based Image Retrieval (CBIR) systems could also leverage on CNN capabilities, mainly when Relevance Feedback (RF) mechanisms are employed. On the one hand, to improve the performances of CBIRs, that are strictly related to the effectiveness of the descriptors used to represent an image, as they aim at providing the user with images similar to an initial query image. On the other hand, to reduce the semantic gap between the similarity perceived by the user and the similarity computed by the machine, by exploiting an RF mechanism where the user labels the returned images as being relevant or not concerning her interests. Consequently, in this work, we propose a CBIR system based on transfer learning from a CNN trained on a vast image database, thus exploiting the generic image representation that it has already learned. Then, the pre-trained CNN is also fine-tuned exploiting the RF supplied by the user to reduce the semantic gap. In particular, after the user’s feedback, we propose to tune and then re-train the CNN according to the labelled set of relevant and non-relevant images. Then, we suggest different strategies to exploit the updated CNN for returning a novel set of images that are expected to be relevant to the user’s needs. Experimental results on different data sets show the effectiveness of the proposed mechanisms in improving the representation power of the CNN with respect to the user concept of image similarity. Moreover, the pros and cons of the different approaches can be clearly pointed out, thus providing clear guidelines for the implementation in production environments. Lorenzo Putzu, Luca Piras 0001, Giorgio Giacinto |
Multim. Tools Appl. | 3 |
| 2019 | PowerDrive: Accurate De-obfuscation and Analysis of PowerShell Malware
Denis Ugarte, Davide Maiorca, Fabrizio Cara, Giorgio Giacinto |
DIMVA | 4 |
| 2019 | On the effectiveness of system API-related information for Android ransomware detection
Michele Scalas, Davide Maiorca, Francesco Mercaldo, Corrado Aaron Visaggio, Fabio Martinelli, Giorgio Giacinto |
Comput. Secur. | 6 |
| 2019 | Yes, Machine Learning Can Be More Secure! A Case Study on Android Malware DetectionabstractTo cope with the increasing variability and sophistication of modern attacks, machine learning has been widely adopted as a statistically-sound tool for malware detection. However, its security against well-crafted attacks has not only been recently questioned, but it has been shown that machine learning exhibits inherent vulnerabilities that can be exploited to evade detection at test time. In other words, machine learning itself can be the weakest link in a security system. In this paper, we rely upon a previously-proposed attack framework to categorize potential attack scenarios against learning-based malware detection tools, by modeling attackers with different skills and capabilities. We then define and implement a set of corresponding evasion attacks to thoroughly assess the security of Drebin, an Android malware detector. The main contribution of this work is the proposal of a simple and scalable secure-learning paradigm that mitigates the impact of evasion attacks, while only slightly worsening the detection rate in the absence of attack. We finally argue that our secure-learning approach can also be readily applied to other malware detection tasks. Ambra Demontis, Marco Melis, Battista Biggio, Davide Maiorca, Daniel Arp, Konrad Rieck, Igino Corona, Giorgio Giacinto, Fabio Roli |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2017 | IntelliAV: Toward the Feasibility of Building Intelligent Anti-malware on Android Devices
Mansour Ahmadi, Angelo Sotgiu, Giorgio Giacinto |
CD-MAKE | 3 |
| 2017 | DroidSieve: Fast and Accurate Classification of Obfuscated Android MalwareabstractWith more than two million applications, Android marketplaces require automatic and scalable methods to efficiently vet apps for the absence of malicious threats. Recent techniques have successfully relied on the extraction of lightweight syntactic features suitable for machine learning classification, but despite their promising results, the very nature of such features suggest they would unlikely--on their own--be suitable for detecting obfuscated Android malware. To address this challenge, we propose DroidSieve, an Android malware classifier based on static analysis that is fast, accurate, and resilient to obfuscation. For a given app, DroidSieve first decides whether the app is malicious and, if so, classifies it as belonging to a family of related malware. Guillermo Suarez-Tangil, Santanu Kumar Dash 0001, Mansour Ahmadi, Johannes Kinder, Giorgio Giacinto, Lorenzo Cavallaro |
CODASPY | 5 |
| 2017 | Multimodal Retrieval with Diversification and Relevance Feedback for Tourist Attraction ImagesabstractIn this article, we present a novel framework that can produce a visual description of a tourist attraction by choosing the most diverse pictures from community-contributed datasets, which describe different details of the queried location. The main strength of the proposed approach is its flexibility that permits us to filter out non-relevant images and to obtain a reliable set of diverse and relevant images by first clustering similar images according to their textual descriptions and their visual content and then extracting images from different clusters according to a measure of the user’s credibility. Clustering is based on a two-step process, where textual descriptions are used first and the clusters are then refined according to the visual features. The degree of diversification can be further increased by exploiting users’ judgments on the results produced by the proposed algorithm through a novel approach, where users not only provide a relevance feedback but also a diversity feedback. Experimental results performed on the MediaEval 2015 “Retrieving Diverse Social Images” dataset show that the proposed framework can achieve very good performance both in the case of automatic retrieval of diverse images and in the case of the exploitation of the users’ feedback. The effectiveness of the proposed approach has been also confirmed by a small case study involving a number of real users. Duc-Tien Dang-Nguyen, Luca Piras 0001, Giorgio Giacinto, Giulia Boato, Francesco G. B. De Natale |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2016 | Novel Feature Extraction, Selection and Fusion for Effective Malware Family ClassificationabstractModern malware is designed with mutation characteristics, namely polymorphism and metamorphism, which causes an enormous growth in the number of variants of malware samples. Categorization of malware samples on the basis of their behaviors is essential for the computer security community, because they receive huge number of malware everyday, and the signature extraction process is usually based on malicious parts characterizing malware families. Microsoft released a malware classification challenge in 2015 with a huge dataset of near 0.5 terabytes of data, containing more than 20K malware samples. The analysis of this dataset inspired the development of a novel paradigm that is effective in categorizing malware variants into their actual family groups. This paradigm is presented and discussed in the present paper, where emphasis has been given to the phases related to the extraction, and selection of a set of novel features for the effective representation of malware samples. Features can be grouped according to different characteristics of malware behavior, and their fusion is performed according to a per-class weighting paradigm. The proposed method achieved a very high accuracy ($\approx$ 0.998) on the Microsoft Malware Challenge dataset. Mansour Ahmadi, Dmitry Ulyanov, Stanislav Semenov, Mikhail Trofimov, Giorgio Giacinto |
CODASPY | 5 |
| 2016 | Evaluating Analysis Tools for Android Apps: Status Quo and Robustness Against ObfuscationabstractThe recent past has shown that Android smartphones became the most popular target for malware authors. Malware families offer a variety of features that allow, among the others, to steal arbitrary data and to cause significant monetary losses. This circumstances led to the development of many different analysis methods that are aimed to assess the absence of potential harm or malicious behavior in mobile apps. In return, malware authors devised more sophisticated methods to write mobile malware that attempt to thwart such analyses. In this work, we briefly describe assumptions analysis tools rely on to detect malicious content and behavior. We then present results of a new obfuscation framework that aims to break such assumptions, thus modifying Android apps to avoid them being analyzed by the targeted systems. We use our framework to evaluate the robustness of static and dynamic analysis systems for Android apps against such transformations. Teemu Rytilahti, Davide Maiorca, Marcel Winandy, Giorgio Giacinto, Thorsten Holz |
CODASPY | 5 |
| 2016 | Who Are You? A Statistical Approach to Measuring User Authenticity
David Mandell Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio, Giorgio Giacinto |
NDSS | 5 |
| 2015 | Yet Another Cybersecurity Roadmapping MethodologyabstractIn this paper we describe the road mapping methodology we developed in the context of the Cyber ROAD EU FP7 project, whose aim is to develop a research roadmap for cybercrime and cyber terrorism. To this aim we built on state-of-the-art methodologies and available guidelines, including related projects, and adapted them to the peculiarities of our road mapping subject. In particular, its distinctive feature is that cybercrime and cyber terrorism co-evolve with their contextual environment (i.e., Technology, society, politics and economy), which poses specific challenges to a road mapping effort. Our approach can become a best practice in the field of cyber security, and can be also generalised to phenomena that exhibit a similar, strong co-evolution with their contextual environment. We aim to describe here the road mapping methodology that will lead to the roadmap but not the roadmap itself (this one being, incidentally, still under construction at the time of writing this paper). Davide Ariu, Luca Didaci, Giorgio Fumera, Enrico Frumento, Federica Freschi, Giorgio Giacinto, Fabio Roli |
ARES | 6 |
| 2015 | 2020 Cybercrime Economic Costs: No Measure No SolutionabstractGovernments needs reliable data on crime in order to both devise adequate policies, and allocate the correct revenues so that the measures are cost-effective, i.e., The money spent in prevention, detection, and handling of security incidents is balanced with a decrease in losses from offences. The analysis of the actual scenario of government actions in cyber security shows that the availability of multiple contrasting figures on the impact of cyber-attacks is holding back the adoption of policies for cyber space as their cost-effectiveness cannot be clearly assessed. The most relevant literature on the topic is reviewed to highlight the research gaps and to determine the related future research issues that need addressing to provide a solid ground for future legislative and regulatory actions at national and international levels. Jart Armin, Bryn Thompson, Davide Ariu, Giorgio Giacinto, Fabio Roli, Piotr Kijewski |
ARES | 4 |
| 2015 | On the Robustness of Mobile Device Fingerprinting: Can Mobile Users Escape Modern Web-Tracking Mechanisms?abstractClient fingerprinting techniques enhance classical cookie-based user tracking to increase the robustness of tracking techniques. A unique identifier is created based on characteristic attributes of the client device, and then used for deployment of personalized advertisements or similar use cases. Whereas fingerprinting performs well for highly customized devices (especially desktop computers), these methods often lack in precision for highly standardized devices like mobile phones. Thomas Hupperich, Davide Maiorca, Marc Kührer, Thorsten Holz, Giorgio Giacinto |
ACSAC | 5 |
| 2015 | A Structural and Content-based Approach for a Precise and Robust Detection of Malicious PDF FilesabstractDuring the past years, malicious PDF files have become a serious threat for the security of modern computer systems. They are characterized by a complex structure and their variety is considerably high. Several solutions have been academically developed to mitigate such attacks. However, they leveraged on information that were extracted from either only the structure or the content of the PDF file. This creates problems when trying to detect non-Javascript or targeted attacks. In this paper, we present a novel machine learning system for the automatic detection of malicious PDF documents. It extracts information from both the structure and the content of the PDF file, and it features an advanced parsing mechanism. In this way, it is possible to detect a wide variety of attacks, including non-Javascript and parsing-based ones. Moreover, with a careful choice of the learning algorithm, our approach provides a significantly higher accuracy compared to other static analysis techniques, especially in the presence of adversarial malware manipulation. Davide Maiorca, Davide Ariu, Igino Corona, Giorgio Giacinto |
ICISSP | 4 |
| 2015 | A hybrid approach for retrieving diverse social images of landmarksabstractIn this paper, we present a novel method that can produce a visual description of a landmark by choosing the most diverse pictures that best describe all the details of the queried location from community-contributed datasets. The main idea of this method is to filter out non-relevant images at a first stage and then cluster the images according to textual descriptors first, and then to visual descriptors. The extraction of images from different clusters according to a measure of user's credibility, allows obtaining a reliable set of diverse and relevant images. Experimental results performed on the MediaEval 2014 “Retrieving Diverse Social Images” dataset show that the proposed approach can achieve very good performance outperforming state-of-art techniques. Duc-Tien Dang-Nguyen, Luca Piras 0001, Giorgio Giacinto, Giulia Boato, Francesco G. B. De Natale |
ICME | 3 |
| 2015 | User-driven Nearest Neighbour Exploration of Image Archives
Luca Piras 0001, Deiv Furcas, Giorgio Giacinto |
ICPRAM (1) | 3 |
| 2015 | Stealth attacks: An extended insight into the obfuscation effects on Android malware
Davide Maiorca, Davide Ariu, Igino Corona, Marco Aresu, Giorgio Giacinto |
Comput. Secur. | 5 |
| 2015 | DLLMiner: structural mining for malware detectionabstractAbstract Existing anti‐malware products usually use signature‐based techniques as their main detection engine. Although these methods are very fast, they are unable to provide effective protection against newly discovered malware or mutated variant of old malware. Heuristic approaches are the next generation of detection techniques to mitigate the problem. These approaches aim to improve the detection rate by extracting more behavioral characteristics of malware. Although these approaches cover the disadvantages of signature‐based techniques, they usually have a high false positive, and evasion is still possible from these approaches. In this paper, we propose an effective and efficient heuristic technique based on static analysis that not only detect malware with a very high accuracy, but also is robust against common evasion techniques such as junk injection and packing. Our proposed system is able to extract behavioral features from a unique structure in portable executable, which is called dynamic‐link library dependency tree, without actually executing the application. Copyright © 2015 John Wiley & Sons, Ltd. Masoud Narouei, Mansour Ahmadi, Giorgio Giacinto, Hassan Takabi, Ashkan Sami |
Secur. Commun. Networks | 3 |
| 2013 | Looking at the bag is not enough to find the bomb: an evasion of structural methods for malicious PDF files detectionabstractPDF files have proved to be excellent malicious-code bearing vectors. Thanks to their flexible logical structure, an attack can be hidden in several ways, and easily deceive protection mechanisms based on file-type filtering. Recent work showed that malicious PDF files can be accurately detected by analyzing their logical structure, with excellent results. In this paper, we present and practically demonstrate a novel evasion technique, called reverse mimicry, that can easily defeat such kind of analysis. We implement it using real samples and validate our approach by testing it against various PDF malware detectors proposed so far. Finally, we highlight the importance of developing systems robust to adversarial attacks and propose a framework to strengthen PDF malware detection against evasion. Davide Maiorca, Igino Corona, Giorgio Giacinto |
AsiaCCS | 3 |
| 2013 | Passive-aggressive Online Learning for Relevance Feedback in Content based Image Retrieval
Luca Piras 0001, Giorgio Giacinto, Roberto Paredes |
ICPRAM | 2 |
| 2013 | Evasion Attacks against Machine Learning at Test Time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, Fabio Roli |
ECML/PKDD (3) | 7 |
| 2013 | Scalable fine-grained behavioral clustering of HTTP-based malware
Roberto Perdisci, Davide Ariu, Giorgio Giacinto |
Comput. Networks | 3 |
| 2013 | Adversarial attacks against intrusion detection systems: Taxonomy, solutions and open issues
Igino Corona, Giorgio Giacinto, Fabio Roli |
Inf. Sci. | 2 |
| 2012 | SuStorID: A multiple classifier system for the protection of web services
Igino Corona, Roberto Tronci, Giorgio Giacinto |
ICPR | 3 |
| 2012 | Synthetic pattern generation for imbalanced learning in image retrieval
Luca Piras 0001, Giorgio Giacinto |
Pattern Recognit. Lett. | 2 |
| 2012 | Early Detection of Malicious Flux Networks via Large-Scale Passive DNS Traffic AnalysisabstractIn this paper, we present FluxBuster, a novel passive DNS traffic analysis system for detecting and tracking malicious flux networks. FluxBuster applies large-scale monitoring of DNS traffic traces generated by recursive DNS (RDNS) servers located in hundreds of different networks scattered across several different geographical locations. Unlike most previous work, our detection approach is not limited to the analysis of suspicious domain names extracted from spam emails or precompiled domain blacklists. Instead, FluxBuster is able to detect malicious flux service networks in-the-wild, i.e., as they are "accessed” by users who fall victim of malicious content, independently of how this malicious content was advertised. We performed a long-term evaluation of our system spanning a period of about five months. The experimental results show that FluxBuster is able to accurately detect malicious flux networks with a low false positive rate. Furthermore, we show that in many cases FluxBuster is able to detect malicious flux domains several days or even weeks before they appear in public domain blacklists. Roberto Perdisci, Igino Corona, Giorgio Giacinto |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | A Study on the Evaluation of Relevance Feedback in Multi-tagged Image DatasetsabstractThis paper proposes a study on the evaluation of relevance feedback approaches when a multi-tagged dataset is available. The aim of this study is to verify how the relevance feedback works in a real-word scenario, i.e. by taking into account the multiple concepts represented by the query image. To this end, we first assessed how relevance feedback mechanisms adapt the search when the same image is used for retrieving different concepts. Then, we investigated the scenarios in which the same image is used for retrieving multiple concepts. The experimental results shows that relevance feedback can effectively focus the search according to the user's feedback even if the query image provides a rough example of the target concept. We also propose two performance measures aimed at comparing the accuracy of retrieval results when the same image is used as a prototype for a number of different concepts. Roberto Tronci, Luisa Falqui, Luca Piras 0001, Giorgio Giacinto |
ISM | 4 |
| 2011 | HMMPayl: An intrusion detection system based on Hidden Markov Models
Davide Ariu, Roberto Tronci, Giorgio Giacinto |
Comput. Secur. | 3 |
| 2010 | Unbalanced learning in content-based image classification and retrievalabstractNowadays very large archives of digital images can be easily produced thanks to the availability of digital cameras as standalone devices, or embedded into a number of portable devices. Each personal computer is typically a repository for thousands of images, while the Internet can be seen as a very large repository. One of the most severe problems in the classification and retrieval of images from very large repositories is the very limited number of elements belonging to each semantic class compared to the number of images in the repository. As a consequence, an even smaller fraction of images per semantic class can be used as training set in a classification problem, or as a query in a content-based image retrieval problem. In this paper we propose a technique aimed at artificially increasing the number of examples in the training set in order to improve the learning capabilities, reducing the unbalance between the semantic class of interest, and all other images. The proposed approach is tailored to classification and relevance feedback techniques based on the Nearest-Neighbor paradigm. A number of new points in the feature space are created based on the available training patterns, so that they better represent the distribution of the semantic class of interest. These new points are created according to the k-NN paradigm, and take into account both relevant and non-relevant images with respect to the semantic class of interest. The proposed approach allows increasing the generalization capability of NN techniques, and mitigates the risk of classifier over-training on few patterns. Reported experiments show the effectiveness of the proposed technique in Content-Based Image Retrieval tasks, where the Nearest-Neighbor approach is used to exploit user's relevance feedback. The improvement in precision and recall gained in one feature space allows also to outperform the improvement in performances attained by combining different feature spaces. Luca Piras 0001, Giorgio Giacinto |
ICME | 2 |
| 2010 | A Score Decidability Index for Dynamic Score CombinationabstractIn two-class problems, the combination of the outputs (scores) of an ensemble of classifiers is widely used to attain high performance. Dynamic combination techniques that estimate the combination parameters on a pattern per pattern basis, usually provide better performance than those of static combination techniques. In this paper, we propose an Index of Decidability derived from the Wilcoxon-Mann-Whitney statistic, that is used to estimate the combination parameters. Reported results on a multimodal biometric dataset show the effectiveness of the proposed dynamic combination mechanisms in terms of misclassification errors. Carlo Lobrano, Roberto Tronci, Giorgio Giacinto, Fabio Roli |
ICPR | 3 |
| 2010 | One-class classification for oil spill detection
Attilio Gambardella, Giorgio Giacinto, Maurizio Migliaccio, Andrea Montali |
Pattern Anal. Appl. | 2 |
| 2009 | HMM-Web: A Framework for the Detection of Attacks Against Web ApplicationsabstractNowadays, the web-based architecture is the most frequently used for a wide range of internet services, as it allows to easily access and manage information and software on remote machines. The input of web applications is made up of queries, i.e. sequences of pairs attributelarrvalue. A wide range of attacks exploits web application vulnerabilities, typically derived from input validation flaws. In this work we propose a new formulation of query analysis through Hidden Markov Models (HMM) and show that HMM are effective in detecting a wide range of either known or unknown attacks on web applications. In addition, despite previous works, we explicitly address the problem related to the presence of noise (i.e., attacks) in the training set. Finally, we show that performance can be increased when a sequence of symbols is modelled by an ensemble of HMM. Experimental results on real world data, show the effectiveness of the proposed system in terms of very high detection rates and low false alarm rates. Igino Corona, Davide Ariu, Giorgio Giacinto |
ICC | 3 |
| 2009 | McPAD: A multiple classifier system for accurate payload-based anomaly detection
Roberto Perdisci, Davide Ariu, Prahlad Fogla, Giorgio Giacinto, Wenke Lee |
Comput. Networks | 4 |
| 2009 | Designing multiple biometric systems: Measures of ensemble effectiveness
Roberto Tronci, Giorgio Giacinto, Fabio Roli |
Eng. Appl. Artif. Intell. | 2 |
| 2008 | Dynamic score combination of binary expertsabstractThe combination of experts is used to improve the performance of a classification system. In this paper we propose three dynamic score combination techniques that embed the selection and the fusion approach for combining experts. The proposed techniques are designed to combine binary experts that output a score measuring the degree of similarity to the positive class. Reported results on two biometric dataset show the effectiveness of the proposed techniques in terms of AUC and EER. Roberto Tronci, Giorgio Giacinto, Fabio Roli |
ICPR | 2 |
| 2008 | On the Mathematical Formulation of the SAR Oil-Spill Observation ProblemabstractA novel approach to oil-spill classification, based on the paradigm of one-class classification, is proposed. Basically, a classifier is trained using only examples of oil-spills, instead of using oil-spills and look-alikes, as in two-class approaches. In addition, as a large number of candidate features have been considered in the literature, a feature selection algorithm, to objectively select the most effective subset, is proposed. Results on two case study datasets are reported to validate the proposed approach. Attilio Gambardella, Giorgio Giacinto, Maurizio Migliaccio |
IGARSS (3) | 2 |
| 2006 | Alarm clustering for intrusion detection systems in computer networks
Roberto Perdisci, Giorgio Giacinto, Fabio Roli |
Eng. Appl. Artif. Intell. | 2 |
| 2005 | A study on the performances of dynamic classifier selection based on local accuracy estimation
Luca Didaci, Giorgio Giacinto, Fabio Roli, Gian Luca Marcialis |
Pattern Recognit. | 2 |
| 2004 | Instance-Based Relevance Feedback for Image RetrievalabstractHigh retrieval precision in content-based image retrieval can be attained by adopting relevance feedback mechanisms. These mechanisms require that the user judges the quality of the results of the query by marking all the retrieved images as being either relevant or not. Then, the search engine exploits this information to adapt the search to better meet user's needs. At present, the vast majority of proposed relevance feedback mechanisms are formulated in terms of search model that has to be optimized. Such an optimization involves the modification of some search parameters so that the nearest neighbor of the query vector contains the largest number of relevant images. In this paper, a different approach to relevance feedback is proposed. After the user provides the first feedback, following retrievals are not based on k- nn search, but on the computation of a relevance score for each image of the database. This score is computed as a function of two distances, namely the distance from the nearest non-relevant image and the distance from the nearest relevant one. Images are then ranked according to this score and the top k images are displayed. Reported results on three image data sets show that the proposed mechanism outperforms other state-of-the-art relevance feedback mechanisms. Giorgio Giacinto, Fabio Roli |
NIPS | 1 |
| 2004 | Bayesian relevance feedback for content-based image retrieval
Giorgio Giacinto, Fabio Roli |
Pattern Recognit. | 1 |
| 2003 | Fusion of multiple classifiers for intrusion detection in computer networks
Giorgio Giacinto, Fabio Roli, Luca Didaci |
Pattern Recognit. Lett. | 1 |
| 2001 | Design of effective neural network ensembles for image classification purposes
Giorgio Giacinto, Fabio Roli |
Image Vis. Comput. | 1 |
| 2001 | Dynamic classifier selection based on multiple classifier behaviour
Giorgio Giacinto, Fabio Roli |
Pattern Recognit. | 1 |
| 2001 | An approach to the automatic design of multiple classifier systems
Giorgio Giacinto, Fabio Roli |
Pattern Recognit. Lett. | 1 |
| 2000 | A Theoretical Framework for Dynamic Classifier SelectionabstractThe common operation mechanism of multiple classifier systems is the combination of classifier outputs. Some researchers have pointed out the potentialities of "dynamic classifier selection" as an alternative operation mechanism. However, such potentialities have been motivated so far by experimental results and qualitative arguments. This paper provides a theoretical framework for dynamic classifier selection. To this end, dynamic classifier selection is placed in the general framework of statistical decision theory and it is showed that, under some assumptions, the optimal Bayes classifier can be obtained by the selection of non-optimal classifiers. Giorgio Giacinto, Fabio Roli |
ICPR | 1 |
| 2000 | Design of Effective Multiple Classifier Systems by Clustering of ClassifiersabstractIn the field of pattern recognition, multiple classifier systems based on the combination of outputs of a set of different classifiers have been proposed as a method for the development of high performance classification systems. Previous work clearly showed that multiple classifier. Systems are effective only if the classifiers forming them make independent errors. Therefore, the fundamental need for methods aimed to design "error-independent" classifiers is currently acknowledged. In the paper, an approach to the automatic design of multiple classifier systems is proposed. Given an initial large set of classifiers, our approach is aimed at selecting the subset formed by the most error-independent classifiers. Reported results on the classification of multisensor remote-sensing images show that this approach allows to design effective multiple classifier systems. Giorgio Giacinto, Fabio Roli, Giorgio Fumera |
ICPR | 1 |
| 2000 | Unsupervised Learning of Neural Network Ensembles for Image ClassificationabstractIn the field of pattern recognition, the combination of an ensemble of neural networks has been proposed as an approach to the development of high performance image classification systems. However, previous work clearly showed that such image classification systems are effective only if the neural networks forming them make different errors. Therefore, the fundamental need for methods aimed to design ensembles of "error-independent" networks is currently acknowledged. In this paper, an approach to the automatic design of effective neural network ensembles is proposed. Given an initial large set of neural networks, our approach is aimed to select the subset formed by the most error-independent nets. Reported results on the classification of multisensor remote-sensing images show that this approach allows one to design effective neural network ensembles. Giorgio Giacinto, Fabio Roli, Giorgio Fumera |
IJCNN (3) | 1 |
| 2000 | Reject option with multiple thresholds
Giorgio Fumera, Fabio Roli, Giorgio Giacinto |
Pattern Recognit. | 3 |
| 2000 | Combination of neural and statistical algorithms for supervised classification of remote-sensing image
Giorgio Giacinto, Fabio Roli, Lorenzo Bruzzone |
Pattern Recognit. Lett. | 1 |
| 1997 | Application of neural networks and statistical pattern recognition algorithms to earthquake risk evaluation
Giorgio Giacinto, R. Paolucci, Fabio Roli |
Pattern Recognit. Lett. | 1 |