Marco Anisetti

dblp:63/5370 · DBLP profile ↗
← Back
64ranked-venue papers
33as first author
29since 2021 · last 2026
0000-0002-5438-9467ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 10 · 8 first-author · 7 since 2021Artificial intelligence and machine learning · 8 · 3 since 2021Computer networks · 8 · 4 first-author · 4 since 2021Systems, architecture and hardware · 7 · 5 first-author · 5 since 2021Databases, data management, data science and information retrieval · 7 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
YearPublicationVenuePosition
2026 Non-functional certification of edge-computing satellite systems
abstract
Satellite telecommunication networks are playing an increasingly pivotal role in modern communication infrastructures, owing to their expansive coverage, high reliability, and growing capabilities in computing, storage, and bandwidth. In response to evolving market demands, mobile network operators are progressively integrating satellite systems with edge-cloud computing platforms to deliver advanced networking functionalities within a unified architecture. This integration places strong demands on the non-functional assessment (e.g., reliability, availability, and resource efficiency) of satellite-based edge nodes, introducing unprecedented challenges due to their unique operational constraints. In this paper, we propose a lightweight certification framework tailored for satellite computing systems, designed to assess and validate the non-functional posture of satellite edge networks. Our approach explicitly addresses the distinctive characteristics of satellite environments, including intermittent connectivity and constrained resource availability. We validate the proposed scheme through a realistic testbed implementation, modeling a 5G-enabled satellite edge node based on the Tiansuan satellite constellation, an experimental platform jointly developed by Beijing University of Posts and Telecommunications, Spacety, and Peking University.
Filippo Berto, Marco Anisetti, Qiyang Zhang 0001, Shangguang Wang, Claudio A. Ardagna
Comput. Networks2
2026 Vulnerability-Aware Secure Service Deployment in Cloud-Edge Continuum
abstract
Software weaknesses and vulnerabilities are continuously discovered and rapidly evolving. Their direct and indirect interference with the business process workflow execution is neither fully understood nor addressed by the current literature. The strict control of the vulnerability footprint of the landing platform before cloud/web service workflow execution is nowadays largely used as a prevention measure in order to improve execution trustworthiness. The vulnerability footprint governance is exacerbated by the cloud, where a common execution platform hosting (vulnerable) services is shared between different tenants. The paper proposes a service workflow deployment solution tailored for Edge-Cloud Continuum, made of different landing platforms showing different peculiarities. The proposed solution is capable of finding a suitable deployment recipe for a given workflow by i) evaluating the vulnerability footprint of each platform, ii) computing the set of candidate deployment platforms, iii) finding the optimal deployment solution, and iv) migrating already deployed workflows in case the vulnerability requirement is no longer satisfied. Each workflow can be associated with a set of requirements to be satisfied by our deployment solution, like the maximum level of vulnerability footprint accepted. Each workflow deployment contributes to the vulnerability footprint of the landing platform involved.
Ruslan Bondaruc, Nicolas Schnepf, Rémi Badonnel, Claudio A. Ardagna, Marco Anisetti
IEEE Trans. Netw. Serv. Manag.5
2025 A Framework for Data Quality and Protection Management in Service-Based Data Pipelines
Antongiacomo Polimeno, Marco Luzzara, Marco Anisetti, Claudio A. Ardagna, Chirine Ghedira
ICWS3
2025 ML Assurance in 6G-Enabled Edge-Cloud Continuum Workflows
abstract
The modern edge-cloud continuum data intensive workflows are increasingly based on 6G edge nodes in order to spread their diffusion relying on public network and enhanced by the use of machine learning (ML) models in order to extend their capabilities. Data intensive workflows are also glowingly used in critical scenarios such as health and IoT. In these scenarios, guarantees on the model prediction quality and on the model non-functional properties (e.g., model confidentiality), are nowadays requested in order to comply with regulations such as the EU AI Act. Although the traditional CIA (Confidentiality, Integrity, Availability) triad are largely considered as the minimal non-functional properties to be guaranteed for a given system, they cannot be applied as such in the context of ML models. In this paper we identify the shortcomings of the conventional definition of CIA, provides novel ML-specific definitions for the CIA non-functional properties and develops an assurance methodology to evaluate them on the target models and provide relevant guarantees. The paper presents an experimental evaluation based on a realistic MLOps pipeline aimed to demonstrate its feasibility and effectiveness and is based on the novel definition of ML model integrity Non-Functional Property.
Marco Anisetti, Claudio A. Ardagna, Filippo Berto, Alex Della Bruna
WCNC1
2025 Protecting machine learning from poisoning attacks: A risk-based approach
abstract
The ever-increasing interest in and widespread diffusion of Machine Learning (ML)-based applications has driven a substantial amount of research into offensive and defensive ML. ML models can be attacked from different angles: poisoning attacks, the focus of this paper, inject maliciously crafted data points in the training set to modify the model behavior; adversarial attacks maliciously manipulate inference-time data points to fool the ML model and drive the prediction of the ML model according to the attacker’s objective. Ensemble-based techniques are among the most relevant defenses against poisoning attacks and replace the monolithic ML model with an ensemble of ML models trained on different (disjoint) subsets of the training set. They assign data points to the training sets of the models in the ensemble (routing) randomly or using a hash function, assuming that evenly distributing poisoned data points positively influences ML robustness. Our paper departs from this assumption and implements a risk-based ensemble technique where a risk management process is used to perform a smart routing of data points to the training sets. An extensive experimental evaluation demonstrates the effectiveness of the proposed approach in terms of its soundness, robustness, and performance.
Nicola Bena, Marco Anisetti, Ernesto Damiani, Chan Yeob Yeun, Claudio A. Ardagna
Comput. Secur.2
2025 Continuous Management of Machine Learning-Based Application Behavior
abstract
Modern applications are increasingly driven by Machine Learning (ML) models whose non-deterministic behavior is affecting the entire application life cycle from design to operation. The pervasive adoption of ML is urgently calling for approaches that guarantee a stable non-functional behavior of ML-based applications over time and across model changes. To this aim, non-functional properties of ML models, such as privacy, confidentiality, fairness, and explainability, must be monitored, verified, and maintained. Existing approaches mostly focus oni)implementing solutions for classifier selection according to the functional behavior of ML models,ii)finding new algorithmic solutions, such as continuous re-training. In this paper, we propose a multi-model approach that aims to guarantee a stable non-functional behavior of ML-based applications. An architectural and methodological approach is provided to compare multiple ML models showing similar non-functional properties and select the model supporting stable non-functional behavior over time according to (dynamic and unpredictable) contextual changes. Our approach goes beyond the state of the art by providing a solution that continuously guarantees a stable non-functional behavior of ML-based applications, is ML algorithm-agnostic, and is driven by non-functional properties assessed on the ML models themselves. It consists of a two-step process working during application operation, wheremodel assessmentverifies non-functional properties of ML models trained and selected at development time, andmodel substitutionguarantees continuous and stable support of non-functional properties. We experimentally evaluate our solution in a real-world scenario focusing on non-functional property fairness.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Ernesto Damiani, Paolo G. Panero
IEEE Trans. Serv. Comput.1
2024 MUSA: A Platform for Data-Intensive Services in Edge-Cloud Continuum
Marco Anisetti, Claudio A. Ardagna, Massimo Banzi, Filippo Berto, Ruslan Bondaruc, Ernesto Damiani, Alessandro Pedretti, Arianna Pisati, Antonio Retico
AINA (5)1
2024 A Methodology for Web Cache Deception Vulnerability Discovery
abstract
In recent years, the use of caching techniques in web applications has increased significantly, in line with their expanding user base. The logic of web caches is closely tied to the application logic, and misconfigurations can lead to security risks, including the unauthorized access of private information and session hijacking. In this study, we examine Web Cache Deception as a technique for attacking web applications. We develop a solution for discovering vulnerabilities that expands upon and encompasses prior research in the field. We conducted an experimental evaluation of the attack’s efficacy against real-world targets, and present a new attack vector via web-client-based email services.
Filippo Berto, Francesco Minetti, Claudio A. Ardagna, Marco Anisetti
CLOSER4
2024 A Transparent Certification Scheme Based on Blockchain for Service-Based Systems
abstract
Modern service-based systems are characterized by applications composed of heterogeneous services provided by multiple, untrusted providers, and deployed along the (multi-) cloud-edge continuum. This scenario of increasing pervasiveness, complexity, and multi-party service recruitment urgently calls for solutions to increase applications privacy and security, on the one hand, and guarantee that applications behave as expected and support a given set of non-functional requirements, on the other hand. Certification schemes became the widespread means to answer this call, but they still build on old-fashioned assumptions that hardly hold in today’s services world. They assume that all actors involved in a certification process are trusted "by definition", meaning that certificates are supposed to be correct and be safely usable for decision-making, such as certification-based service selection and composition. In this paper, we depart from such unrealistic assumptions and define the first certification scheme that is completely transparent to the involved actors and significantly more resistant to misbehavior (e.g., collusion). We design a blockchain-based architecture to support our scheme, redefining the actors and their roles. The quality and performance of our scheme are evaluated in a case study scenario.
Nicola Bena, Marco Pedrinazzi, Marco Anisetti, Omar Hasan, Lionel Brunie
ICWS3
2024 A structure and texture revealing retinex model for low-light image enhancement
Qilei Li, Marco Anisetti, Gwanggil Jeon, Mingliang Gao 0001
Multim. Tools Appl.3
2023 QoS-Aware Deployment of Service Compositions in 5G-Empowered Edge-Cloud Continuum
abstract
Nowadays, modern service compositions are increasingly adopted in critical scenarios where advanced Quality of Services (QoS) such as low latency, security, and privacy are fundamental. The landing platforms for the deployment of such compositions are progressively becoming capable to offer capabil-ities that support such advanced QoS requests (e.g., low latency via 5G network slice) spanning the Edge-Cloud Continuum. Actual deployment solutions focus mainly on resource allocation (i.e., CPU, memory, and storage), falling short of addressing advanced QoS and unleashing the true potential of the Edge-Cloud Continuum. In this paper, we present an automatic QoS-aware deployment solution for composed services in the Edge-Cloud Continuum. It compares QoS requests on the service composition with the capabilities of a given continuum in order to find, generate and execute suitable deployment recipes. Our preliminary experimental evaluation demonstrates the feasibility of our solution in a realistic scenario.
Marco Anisetti, Filippo Berto, Ruslan Bondaruc
CLOUD1
2023 Continuous Certification of Non-functional Properties Across System Changes
Marco Anisetti, Claudio A. Ardagna, Nicola Bena
ICSOC (1)1
2023 Lightweight Behavior-Based Malware Detection
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Vincenzo Giandomenico, Gabriele Gianini
MEDES1
2023 FPANet: feature pyramid attention network for crowd counting
Wenzhe Zhai, Mingliang Gao 0001, Qilei Li, Gwanggil Jeon, Marco Anisetti
Appl. Intell.5
2023 An assurance process for Big Data trustworthiness
abstract
Modern (industrial) domains are based on large digital ecosystems where huge amounts of data and information need to be collected, shared, and analyzed by multiple actors working within and across organizational boundaries. This data-driven ecosystem poses strong requirements on data management and data analysis, as well as on data protection and system trustworthiness. However, although Big Data has reached its functional maturity and represents a key enabler for enterprises to compete in the global market, the assurance and trustworthiness of Big Data computations (e.g., security, privacy) are still in their infancy. While functionally appealing, Big Data does not provide a transparent environment with clear non-functional properties, impairing the users’ ability to evaluate its behavior and clashing with modern data-privacy regulations. In this paper, we present a novel assurance process for Big Data, which evaluates the Big Data pipelines, and the Big Data ecosystem underneath, to provide a comprehensive measure of their trustworthiness. To the best of our knowledge, this approach is the first attempt to address the general problem of Big Data trustworthiness in an holistic way. We experimentally evaluate our solution in a real Big Data Analytics-as-a-Service environment, first presenting a detailed walkthrough evaluation, and then showing its feasibility and negligible performance overhead (i.e., approx 1 min).
Marco Anisetti, Claudio A. Ardagna, Filippo Berto
Future Gener. Comput. Syst.1
2023 A Multilayer Deep Learning Approach for Malware Classification in 5G-Enabled IIoT
abstract
5G is becoming the foundation for the Industrial Internet of Things (IIoT) enabling more effective low-latency integration of artificial intelligence and cloud computing in a framework of a smart and intelligent IIoT ecosystems enhancing the entire industrial procedure. However, it also increases the functional complexities of the underlying control system and introduces new powerful attack vectors leading to severe security and data privacy risks. Malware attacks are starting targeting weak but highly connected IoT devices showing the importance of security and privacy in this scenario. This article designs a 5G-enabled system, consisted in a deep learning based architecture aimed to classify malware attacks on the IIoT. Our methodology is based on an image representation of the malware and a convolutional neural networks that is designed to differentiate various malware attacks. The proposed architecture extracts complementary discriminative features by combining multiple layers achieving 97% of accuracy.
Imran Ahmed 0002, Marco Anisetti, Awais Ahmad 0001, Gwanggil Jeon
IEEE Trans. Ind. Informatics2
2023 Multi-Dimensional Certification of Modern Distributed Systems
abstract
The cloud computing has deeply changed how distributed systems are engineered, leading to the proliferation of ever/evolving and complex environments, where legacy systems, microservices, and nanoservices coexist. These services can severely impact on individuals' security and safety, introducing the need of solutions that properly assess and verify their correct behavior. Security assurance stands out as the way to address such pressing needs, with certification techniques being used to certify that a given service holds some non/functional properties. However, existing techniques build their evaluation on software artifacts only, falling short in providing a thorough evaluation of the non/functional properties under certification. In this paper, we present a multi/dimensional certification scheme where additional dimensions model relevant aspects (e.g., programming languages and development processes) that significantly contribute to the quality of the certification results. Our multi/dimensional certification enables a new generation of service selection approaches capable to handle a variety of user's requirements on the full system life cycle, from system development to its operation and maintenance. The performance and the quality of our approach are thoroughly evaluated in several experiments.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena
IEEE Trans. Serv. Comput.1
2023 On the Robustness of Random Forest Against Untargeted Data Poisoning: An Ensemble-Based Approach
abstract
Machine learning is becoming ubiquitous. From finance to medicine, machine learning models are boosting decision/making processes and even outperforming humans in some tasks. This huge progress in terms of prediction quality does not however find a counterpart in the security of such models and corresponding predictions, where perturbations of fractions of the training set (poisoning) can seriously undermine the model accuracy. Research on poisoning attacks and defenses received increasing attention in the last decade, leading to several promising solutions aiming to increase the robustness of machine learning. Among them, ensemble-based defenses, where different models are trained on portions of the training set and their predictions are then aggregated, provide strong theoretical guarantees at the price of a linear overhead. Surprisingly, ensemble-based defenses, which do not pose any restrictions on the base model, have not been applied to increase the robustness of random forest models. The work in this paper aims to fill in this gap by designing and implementing a novel hash-based ensemble approach that protects random forest against untargeted, random poisoning attacks. An extensive experimental evaluation measures the performance of our approach against a variety of attacks, as well as its sustainability in terms of resource consumption and performance, and compares it with a traditional monolithic model based on random forest. A final discussion presents our main findings and compares our approach with existing poisoning defenses targeting random forests.
Marco Anisetti, Claudio A. Ardagna, Alessandro Balestrucci, Nicola Bena, Ernesto Damiani, Chan Yeob Yeun
IEEE Trans. Sustain. Comput.1
2022 A DevSecOps-based Assurance Process for Big Data Analytics
abstract
Today big data pipelines are increasingly adopted by service applications representing a key enabler for enterprises to compete in the global market. However, the management of non-functional aspects of the big data pipeline (e.g., security, privacy) is still in its infancy. As a consequence, while functionally appealing, the big data pipeline does not provide a transparent environment, impairing the users’ ability to evaluate its behavior. In this paper, we propose a security assurance methodology for big data pipelines grounded on the DevSecOps development paradigm to increase trustworthiness allowing reliable security and privacy by design. Our methodology models and annotates big data pipelines with non-functional requirements verified by assurance checks ensuring requirements to hold along with the pipeline lifecycle. The performance and quality of our methodology are evaluated in a real walkthrough analytics scenario.
Marco Anisetti, Nicola Bena, Filippo Berto, Gwanggil Jeon
ICWS1
2022 Inter-rater Agreement Based Risk Assessment Scheme for ICT Corporates
Roberto Cassata, Gabriele Gianini, Marco Anisetti, Valerio Bellandi, Ernesto Damiani, Alessandro Cavaciuti
KES-IDT3
2022 Orchestration of data-intensive pipeline in 5G-enabled Edge Continuum
abstract
Nowadays there is an increasing trend in the volume and velocity of data, typically consumed by data-intensive AI/ML-based services, requiring a larger diffusion of more effective Edge computing approaches. In addition, we are experiencing an increment of critical applications using an increasing volume of sensitive data and requiring advanced security and privacy protections. 5G Edge technology can foster a more diffused Edge computing adoption but several challenges in terms of interoperability. Handling data-intensive pipelines on the 5Genabled Edge continuum, considering specific QoS requirements including security and privacy, is still in its infancy. In this paper, we propose an initial solution for deploying a data-intensive pipeline in a 5G-enabled Edge continuum satisfying specific QoS requirements. Our approach is based on a QoS-aware meta orchestration modeling of a given pipeline and an orchestration builder generating deployable Edge-specific orchestrations. In this paper, we also present an initial walkthrough scenario in the context of a wet lab analysis pipeline to be deployed on the 5G-enabled Edge continuum.
Marco Anisetti, Filippo Berto, Massimo Banzi
SERVICES1
2022 An IoT-based human detection system for complex industrial environment with deep learning architectures and transfer learning
abstract
Artificial intelligence (AI), combined with the Internet of Things (IoT), plays a beneficial role in various fields, including intelligent surveillance applications. With IoT and 5G advancement, intelligent sensors, and devices in the surveillance environment collect large amounts of data in the form of videos and images. These collected data require intelligent information processing solutions, help analyze the recorded videos and images to detect and identify various objects in the scene, particularly humans. In this study, an automated human detection system is presented for a complex industrial environment, in which people are monitored/detected from a top view perspective. A top view is usually preferred because it can provide sufficient coverage and enough visibility of a scene. This study demonstrates the applications, efficiency, and effectiveness of deep learning architectures, that is, Faster Region Convolutional Neural Network (Faster R-CNN), Single Shot MultiBox Detector (SSD), and You Only Look Once (YOLOv3), with transfer learning. Experimental results reveal that with additional training and transfer learning, the performance of all detection architectures is significantly improved. The detection results are also compared using the same data set. The deep learning architectures achieve promising results with maximum true-positive rate of 93%, 94%, and 94% for Faster-RCNN, SSD, and YOLOv3, respectively. Furthermore, a detailed study is performed on output results that highlight challenges and probable future trends.
Imran Ahmed 0002, Marco Anisetti, Gwanggil Jeon
Int. J. Intell. Syst.2
2022 A Modelling Framework for Evidence-Based Public Health Policy Making
abstract
It is widely recognised that the process of public health policy making (i.e., the analysis, action plan design, execution, monitoring and evaluation of public health policies) should be evidenced based, and supported by data analytics and decision-making tools tailored to it. This is because the management of health conditions and their consequences at a public health policy making level can benefit from such type of analysis of heterogeneous data, including health care devices usage, physiological, cognitive, clinical and medication, personal, behavioural, lifestyle data, occupational and environmental data. In this paper we present a novel approach to public health policy making in a form of an ontology, and an integrated platform for realising this approach. Our solution is model-driven and makes use of big data analytics technology. More specifically, it is based on public health policy decision making (PHPDM) models that steer the public health policy decision making process by defining the data that need to be collected, the ways in which they should be analysed in order to produce the evidence useful for public health policymaking, how this evidence may support or contradict various policy interventions (actions), and the stakeholders involved in the decision-making process. The resulted web-based platform has been implemented using Hadoop, Spark and HBASE, developed in the context of a research programme on public health policy making for the management of hearing loss called EVOTION, funded by the Horizon 2020.
Marios Prasinos, Ioannis Basdekis, Marco Anisetti, George Spanoudakis, Dimitris Koutsouris, Ernesto Damiani
IEEE J. Biomed. Health Informatics3
2022 A Security Certification Scheme for Information-Centric Networks
abstract
Information-Centric Networking is an emerging alternative to host-centric networking designed for large-scale content distribution and stricter privacy requirements. Recent research on Information-Centric Networking focused on the protection of the network from attacks targeting the content delivery protocols, while assuming genuine content can always be retrieved from trustworthy nodes. In this paper, we depart from the assumption of the trustworthiness of network nodes and propose a novel certification methodology for information-centric networks that supports continuous security verification of non-functional properties. Our methodology provides a complete and detailed view of the network security status, increasing the trustworthiness of the network and its services. The proposed approach builds on an enhanced certification model capturing the evolution of the system over time. It also defines certification services that fully integrate with existing networks to collect evidence on the target of certification and carry out the certification process. It finally proposes two certification processes, centralized and decentralized, balancing the impact on the network and the system performance. Efficiency, performance, and soundness of our approach are experimentally evaluated in a simulated Named Data Networking (NDN) network targeting property availability.
Marco Anisetti, Claudio A. Ardagna, Filippo Berto, Ernesto Damiani
IEEE Trans. Netw. Serv. Manag.1
2021 An Assurance-Based Risk Management Framework for Distributed Systems
abstract
The advent of cloud computing and Internet of Things (IoT) has deeply changed the design and operation of IT systems, affecting mature concepts like trust, security, and privacy. The benefits in terms of new services and applications come at a price of new fundamental risks, and the need of adapting risk management frameworks to properly understand and address them. While research on risk management is an established practice that dates back to the 90s, many of the existing frameworks do not even come close to address the intrinsic complexity and heterogeneity of modern systems. They rather target static environments and monolithic systems thus undermining their usefulness in real-world use cases. In this paper, we present an assurance-based risk management framework that addresses the requirements of risk management in modern distributed systems. The proposed framework implements a risk management process integrated with assurance techniques. Assurance techniques monitor the correct behavior of the target system, that is, the correct working of the mechanisms implemented by the organization to mitigate the risk. Flow networks compute risk mitigation and retrieve the residual risk for the organization. The performance and quality of the framework are evaluated in a simulated industry 4.0 scenario.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Andrea Foppiani
ICWS1
2021 Dynamic and Scalable Enforcement of Access Control Policies for Big Data
abstract
The conflict between the need of protecting and sharing data is hampering the spread of big data applications. Security and privacy assurance is required to protect data owners, while data access and sharing are fundamental to implement smart big data solutions. In this context, access control systems can assume a central role in balancing data protection and data sharing. However, existing access control solutions are not general and scalable enough to address the software and technological complexity of big data ecosystems, being unable to support such a dynamic and collaborative environment. In this paper, we propose an access control system that enforces access to data in a distributed, multi-party big data environment. It is based on data annotations and secure data transformations performed at ingestion time. We show the feasibility of our approach in the smart city domain using an Apache-based big data engine.
Marco Anisetti, Claudio A. Ardagna, Chiara Braghin, Ernesto Damiani, Antongiacomo Polimeno, Alessandro Balestrucci
MEDES1
2021 A trust assurance technique for Internet of things based on human behavior compliance
abstract
Summary The advent of the Internet of things (IoT) has radically changed the way in which computations and communications are carried out. People are just becoming another component of IoT environments, and in turn, IoT environments are becoming a mixture of platforms, software, services, things, and people. The price we pay for such dynamic and powerful environment is an intrinsic uncertainty and low trustworthiness due to its opaque perimeter, the multitude of different data sources with unknown providers, and uncertain responsibilities. Trustworthiness of observables collected by smart devices (from minuscle sensors to bigger machines) is fundamental to build a chain of trust on a decision process taken according to these observables. Some assurance solutions evaluate the quality of collected data, although they are difficult to apply in IoT environments for performance and cost reasons. In this paper, we take a different approach and put forward the idea that, in many cases, the behavior of people owning smart devices can contribute to the evaluation of the trustworthiness of collected data and, in turn, of the whole decision process. We therefore define an assurance methodology based on data analytics evaluating the compliance of people to behavioral policies. The more people behavior is compliant, the higher the trustworthiness of data collected through their smart devices.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Alessandro Sala
Concurr. Comput. Pract. Exp.1
2021 Image enhancement in embedded devices for internet of things
abstract
Summary This paper proposes a new color interpolation method which can be used in embedded devices for IoT system. In this work, we use regression approach for generating and designing filters to restore color image. The filters are designed with four sizes, 5x5 training filter, 7x7 training filter, 9x9 training filter, and 11x11 training filter. The obtained filters are tested in 25 LC dataset to assess the performance. Experimental results inform that the proposed filters provide outstanding performance when they are compared with conventional methods. As compared with the other methods, the proposed filters produce the best average interpolation performance both objectively and visually.
Gwanggil Jeon, Kitsuchart Pasupa, Marco Anisetti, Awais Ahmad 0001
Concurr. Comput. Pract. Exp.3
2021 Image super-resolution via enhanced multi-scale residual network
Xiaomin Yang, Marco Anisetti, Rongzhu Zhang, Marcelo Keese Albertini, Kai Liu 0012
J. Parallel Distributed Comput.3
2020 A Methodology for Non-Functional Property Evaluation of Machine Learning Models
abstract
The pervasive diffusion of Machine Learning (ML) in many critical domains and application scenarios has revolutionized implementation and working of modern IT systems. The behavior of modern systems often depends on the behavior of ML models, which are treated as black boxes, thus making automated decisions based on inference unpredictable. In this context, there is an increasing need of verifying the non-functional properties of ML models, such as, fairness and privacy, to the aim of providing certified ML-based applications and services. In this paper, we propose a methodology based on Multi-Armed Bandit for evaluating non-functional properties of ML models. Our methodology adopts Thompson sampling, Monte Carlo Simulation, and Value Remaining. An experimental evaluation in a real-world scenario is presented to prove the applicability of our approach in evaluating the fairness of different ML models.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Paolo G. Panero
MEDES1
2020 A trusted medical image super-resolution method based on feedback adaptive weighted dense network
Lihui Chen 0002, Xiaomin Yang, Gwanggil Jeon, Marco Anisetti, Kai Liu 0012
Artif. Intell. Medicine4
2020 Cost-effective deployment of certified cloud composite services
abstract
The advent of cloud computing has radically changed the concept of distributed environments, where services can now be composed and reused at high rates. Today, service composition in the cloud is driven by the need of providing stable QoS, where non-functional properties of composite services are proven over time and composite services continuously adapt to both functional and non-functional changes of the component services. This scenario introduces substantial costs on the cloud providers that go beyond the cost of deploying component services, and require to consider the costs of continuously verifying non-functional properties of composite and component services. In this paper, we propose a cost-effective approach to certification-based cloud service composition. This approach is based, on one side, on a portable certification process for the cloud evaluating non-functional properties of composite services and, on the other side, on a cost-evaluation methodology aimed to produce the service composition that minimizes the total cost paid by the cloud providers, taking into account both deployment and certification/verification costs. Our service composition approach is driven by certificates awarded to single services and by a fuzzy-based cost evaluation methodology, and assumes certified properties as must-have requirements for service selection and composition.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi, Gwanggil Jeon
J. Parallel Distributed Comput.1
2020 I3D: a new dataset for testing denoising and demosaicing algorithms
Cristian Bonanomi, Simone Balletti, Michela Lecca, Marco Anisetti, Alessandro Rizzi, Ernesto Damiani
Multim. Tools Appl.4
2020 Artificial intelligence in deep learning algorithms for multimedia analysis
Gwanggil Jeon, Marco Anisetti, Ernesto Damiani, Burak Kantarci
Multim. Tools Appl.2
2020 A Semi-Automatic and Trustworthy Scheme for Continuous Cloud Service Certification
abstract
Traditional assurance solutions for software-based systems rely on static verification techniques and assume continuous availability of trusted third parties. With the advent of cloud computing, these solutions become ineffective since services/applications are flexible, dynamic, and change at runtime, at high rates. Although several assurance approaches have been defined, cloud requires a step-change moving current assurance techniques to fully embrace the cloud peculiarities. In this paper, we provide a rigorous and adaptive assurance technique based on certification, towards the definition of a transparent and trusted cloud ecosystem. It aims to increase the confidence of cloud customers that every piece of the cloud (from its infrastructure to hosted applications) behaves as expected and according to their requirements. We first present a test-based certification scheme proving non-functional properties of cloud-based services. The scheme is driven by non-functional requirements defined by the certification authority and by a model of the service under certification. We then define an automatic approach to verification of consistency between requirements and models, which is at the basis of the chain of trust supported by the certification scheme. We also present a continuous certificate life cycle management process including both certificate issuing and its adaptation to address contextual changes. Finally, we describe our certification framework and an experimental evaluation of its performance, quality, applicability, and practical usability in a real industrial scenario, which considers Engineering Ingegneria Informatica S.p.A. ENGpay online payment system.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi
IEEE Trans. Serv. Comput.1
2019 RTRD: Real-Time Route Discovery for Urban Scenarios Using Internet of Things
abstract
A rapid development has been seen in the Vehicular ad hoc networks (VANETs) because of their applicability and significance in the fields of traffic management, road monitoring and safety, infotainment, and on-demand services. Route planning in vehicular networks based on efficient collection of real-time data can effectively mitigate traffic congestion problems in urban areas. Furthermore, real-time data is shared by using an effective sharing mechanism to avoid redundancy of the collected information. However, dynamic route replanning and effective sharing mechanisms based on real-time data are still challenging problems. Therefore, based on the aforementioned constraints, this paper describes a route discovery technique that uses real time data collected from various vehicles using the Internet of Things. The proposed scheme is based on the novel data dissemination technique for information sharing among the roadside units. RTRD is comprised of VANETs, vehicular traffic servers, and a 5G-based cellular system of public transportation. By considering the traffic congestion in urban areas, the optimal path is calculated to re-plan routes based on the k shortest path algorithm, and a load balancing technique is adopted to avoid further congestion.
Sadia Din, Awais Ahmad 0001, Anand Paul 0001, Marco Anisetti, Gwanggil Jeon, Muhammad Imran 0001, Nidal Nasser
GLOBECOM4
2019 A Continuous Certification Methodology for DevOps
abstract
The cloud paradigm has revolutionized the way in which software systems are designed, managed, and maintained. With the advent of the microservice architecture, this trend was brought to the extreme, pushing the whole software development process towards unification of software development (Dev) and software operation (Ops). This rapid evolution has not immediately found counterparts in assurance techniques, where the evaluation of the non-functional behavior of a software system and of the software development process are completely decoupled. In this paper, we put forward the idea that next-generation assurance techniques, and more specifically certification techniques, must evaluate a software system throughout the whole development process. To this aim, we define a continuous certification scheme for DevOps that evaluates the software artifacts produced at each stage of the development process. We then present the assurance framework managing our certification scheme and experimentally evaluate the continuous certification scheme in a real DevOps scenario.
Marco Anisetti, Claudio A. Ardagna, Filippo Gaudenzi, Ernesto Damiani
MEDES1
2019 Improving Hearing Healthcare with Big Data Analytics of Real-Time Hearing Aid Data
abstract
Modern hearing aids are not simple passive sound enhancers, but rather complex devices that can log (via smartphones) multivariate real-time data from the acoustic environment of a user. In the evotion project (http://h2020evotion.eu) such hearing aids are integrated with a Big Data analytics platform to bring about ecologically valid evidence to support the hearing healthcare sector. Here, we present the background of the Big Data analytics platform and demonstrate that modeling of longitudinally sampled data from hearing aids can support clinical investigations with hypotheses about hearing aid usage prognosis, and support public health decision-making within the hearing healthcare sector by simulation techniques. We found, that distinct characteristics of the acoustic environment significantly modulate how hearing impaired individuals use their hearing aids. Higher sound levels and an increased sound diversity but degraded signal quality all predicts more minutes of use per hour. By simulation, we show that a projected increase in the overall sound levels by 10dB followed by a 4dB increase in noise exposure will increase the need for hearing aid use by an additional 1 hour/day across a population of hearing impaired hearing aid users.
Jeppe Høy Christensen, Niels Henrik Pontoppidan, Marco Anisetti, Valerio Bellandi, Marco Cremonini
SERVICES3
2019 Test-Based Security Certification of Composite Services
abstract
The diffusion of service-based and cloud-based systems has created a scenario where software is often made available as services, offered as commodities over corporate networks or the global net. This scenario supports the definition of business processes as composite services, which are implemented via either static or runtime composition of offerings provided by different suppliers. Fast and accurate evaluation of services’ security properties becomes then a fundamental requirement and is nowadays part of the software development process. In this article, we show how the verification of security properties of composite services can be handled by test-based security certification and built to be effective and efficient in dynamic composition scenarios. Our approach builds on existing security certification schemes for monolithic services and extends them towards service compositions. It virtually certifies composite services, starting from certificates awarded to the component services. We describe three heuristic algorithms for generating runtime test-based evidence of the composite service holding the properties. These algorithms are compared with the corresponding exhaustive algorithm to evaluate their quality and performance. We also evaluate the proposed approach in a real-world industrial scenario, which considers ENGpay online payment system of Engineering Ingegneria Informatica S.p.A. The proposed industrial evaluation presents the utility and generality of the proposed approach by showing how certification results can be used as a basis to establish compliance to Payment Card Industry Data Security Standard.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Gianluca Polegri
ACM Trans. Web1
2018 Moon Cloud: A Cloud Platform for ICT Security Governance
abstract
Cybersecurity is the second emergency in Europe just after the climate changes. Everyday most of the small, medium and big enterprises are under attack. This scenario requires, on one side, new security solutions protecting ICT systems against misbehaviors/malicious attacks and, on the other side, a continuous assurance process evaluating the system robustness against new threats. In this paper we present Moon Cloud, a Cloud PaaS solution providing customizable assurance based on compliance for ICT systems, including public and private cloud systems and IoT environments. We also present a concrete security assessment carried out in a real scenario.
Marco Anisetti, Claudio A. Ardagna, Filippo Gaudenzi, Ernesto Damiani, Nicla Diomede, Patrizio Tufarolo
GLOBECOM1
2018 Modeling time, probability, and configuration constraints for continuous cloud service certification
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Nabil El Ioini, Filippo Gaudenzi
Comput. Secur.1
2018 Real-time image processing systems using fuzzy and rough sets techniques
Gwanggil Jeon, Marco Anisetti, Ernesto Damiani, Olivier Monga
Soft Comput.2
2017 A Security Benchmark for OpenStack
abstract
The cloud computing paradigm entails a radical change in IT provisioning, which must be understood and correctly applied especially when security requirements are considered. Security requirements do not cover anymore just the application itself, but involve the whole cloud supply chain from the hosting infrastructure to the final applications. This scenario requires, on one side, new security mechanisms protecting the cloud against misbehaviors/malicious attacks and, on the other side, a continuous and adaptive assurance process evaluating the observed cloud security behavior against the expected one. In this paper, we focus on the evaluation of the security assurance of OpenStack, a major open source cloud infrastructure. We first define a security benchmark for OpenStack, inspired by Center for Internet Security (CIS) benchmark for cloud infrastructures. We then present a platform, called Moon Cloud, for cloud security assurance evaluation, showing an application of our benchmark and platform to the in-production OpenStack deployment of the University of Milan.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi
CLOUD1
2017 Effects of avatar character performances in virtual reality dramas used for teachers' education
abstract
Virtual reality drama has the benefit of enhancing immersion, which was lacking in original e-Learning systems. Moreover, dangerous and expensive educational content can be replaced by stimulating users’ interest. In this study, we investigate the effects of avatar performance in virtual reality drama. The hypothesis that the psychical distance between virtual characters and their viewers changes according to the size of video shots is tested with an autonomic nervous system function test. Eighty-four college students were randomly assigned to three groups. Virtual reality drama is used to train teachers concerning school bullying prevention, and deals with the dialogue between teachers and students. Group 1 was provided with full-shot video clips, Group 2 was shown various clips from full shots to extreme close-ups, and Group 3 was provided with close-up shots. We found that the virtual reality drama viewers’ levels of stimulation changed in relation to the size of the shots. The R-R (between P wave and P wave) intervals of the electrocardiograms (ECGs, bio-signal feedback) became significantly narrower as the shot size became smaller.
Pyoung Won Kim, Yang Sook Shin, Byoung Hoon Ha, Marco Anisetti
Behav. Inf. Technol.4
2017 Lossless compression for aurora spectral images using fast online bi-dimensional decorrelation method
Wanqiu Kong, Jiaji Wu, Zejun Hu, Marco Anisetti, Ernesto Damiani, Gwanggil Jeon
Inf. Sci.4
2017 Computational intelligence for multimedia and industrial applications
Gwanggil Jeon, Ernesto Damiani, Marco Anisetti
Multim. Tools Appl.3
2017 An interval type-2 fuzzy active contour model for auroral oval segmentation
Jiao Shi, Jiaji Wu, Marco Anisetti, Ernesto Damiani, Gwanggil Jeon
Soft Comput.3
2017 Hadoop-Based Intelligent Care System (HICS): Analytical Approach for Big Data in IoT
abstract
The Internet of Things (IoT) is increasingly becoming a worldwide network of interconnected things that are uniquely addressable, via standard communication protocols. The use of IoT for continuous monitoring of public health is being rapidly adopted by various countries while generating a massive volume of heterogeneous, multisource, dynamic, and sparse high-velocity data. Handling such an enormous amount of high-speed medical data while integrating, collecting, processing, analyzing, and extracting knowledge constitutes a challenging task. On the other hand, most of the existing IoT devices do not cooperate with one another by using the same medium of communication. For this reason, it is a challenging task to develop healthcare applications for IoT that fulfill all user needs through real-time monitoring of health parameters. Therefore, to address such issues, this article proposed a Hadoop-based intelligent care system (HICS) that demonstrates IoT-based collaborative contextual Big Data sharing among all of the devices in a healthcare system. In particular, the proposed system involves a network architecture with enhanced processing features for data collection generated by millions of connected devices. In the proposed system, various sensors, such as wearable devices, are attached to the human body and measure health parameters and transmit them to a primary mobile device (PMD). The collected data are then forwarded to intelligent building (IB) using the Internet where the data are thoroughly analyzed to identify abnormal and serious health conditions. Intelligent building consists of (1) a Big Data collection unit (used for data collection, filtration, and load balancing); (2) a Hadoop processing unit (HPU) (composed of Hadoop distributed file system (HDFS) and MapReduce); and (3) an analysis and decision unit. The HPU, analysis, and decision unit are equipped with a medical expert system, which reads the sensor data and performs actions in the case of an emergency situation. To demonstrate the feasibility and efficiency of the proposed system, we use publicly available medical sensory datasets and real-time sensor traffic while identifying the serious health conditions of patients by using thresholds, statistical methods, and machine-learning techniques. The results show that the proposed system is very efficient and able to process high-speed WBAN sensory data in real time.
M. Mazhar Rathore, Anand Paul 0001, Awais Ahmad 0001, Marco Anisetti, Gwanggil Jeon
ACM Trans. Internet Techn.4
2016 Locally estimated heterogeneity property and its fuzzy filter application for deinterlacing
Gwanggil Jeon, Marco Anisetti, Lei Wang 0018, Ernesto Damiani
Inf. Sci.2
2016 Real-time signal processing in embedded systems
Marco Anisetti, Ernesto Damiani, Albert Dipanda, Gwanggil Jeon
J. Syst. Archit.1
2016 Bayer Demosaicking With Polynomial Interpolation
abstract
Demosaicking is a digital image process to reconstruct full color digital images from incomplete color samples from an image sensor. It is an unavoidable process for many devices incorporating camera sensor (e.g., mobile phones, tablet, and so on). In this paper, we introduce a new demosaicking algorithm based on polynomial interpolation-based demosaicking. Our method makes three contributions: calculation of error predictors, edge classification based on color differences, and a refinement stage using a weighted sum strategy. Our new predictors are generated on the basis of on the polynomial interpolation, and can be used as a sound alternative to other predictors obtained by bilinear or Laplacian interpolation. In this paper, we show how our predictors can be combined according to the proposed edge classifier. After populating three color channels, a refinement stage is applied to enhance the image quality and reduce demosaicking artifacts. Our experimental results show that the proposed method substantially improves over the existing demosaicking methods in terms of objective performance (CPSNR, S-CIELAB ΔE*, and FSIM), and visual performance.
Jiaji Wu, Marco Anisetti, Wei Wu 0002, Ernesto Damiani, Gwanggil Jeon
IEEE Trans. Image Process.2
2015 Toward Security and Performance Certification of Open Stack
abstract
Cloud users and service providers are increasingly concerned about the management of their data and the behavior of the applications they use/own once stored/deployed in the cloud. They therefore ask for enhanced assurance solutions, which partially mitigate the new risks and threats they are facing. Among existing solutions, certification has been widely adopted as a preferable approach to increase trust in the cloud. In this paper, after briefly discussing our test-based certification scheme for the cloud, we show a real certification process aimed to certify Open Stack, an open source IaaS solution for managing infrastructure resources. In particular, we first describe the testing activities executed to certify Open Stack for security and performance properties. We then illustrate the obtained results and the outcomes of the certification process.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi, Roberto Veca
CLOUD1
2013 Security Certification of Composite Services: A Test-Based Approach
abstract
Accurate and lightweight evaluation of web service security properties is a key problem, especially when business processes are dynamically built by composing atomic services provided by different suppliers at runtime. In this paper, we tackle this problem by proposing a security certification approach that virtually certifies a composite service for a set of security properties, starting from certificates awarded to the component services.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani
ICWS1
2013 A test-based security certification scheme for web services
abstract
The Service-Oriented Architecture (SOA) paradigm is giving rise to a new generation of applications built by dynamically composing loosely coupled autonomous services. Clients (i.e., software agents acting on behalf of human users or service providers) implementing such complex applications typically search and integrate services on the basis of their functional requirements and of their trust in the service suppliers. A major issue in this scenario relates to the definition of an assurance technique allowing clients to select services on the basis of their nonfunctional requirements and increasing their confidence that the selected services will satisfy such requirements. In this article, we first present an assurance solution that focuses on security and supports a test-based security certification scheme for Web services. The certification scheme is driven by the security properties to be certified and relies upon a formal definition of the service model. The evidence supporting a certified property is computed using a model-based testing approach that, starting from the service model, automatically generates the test cases to be used in the service certification. We also define a set of indexes and metrics that evaluate the assurance level and the quality of the certification process. Finally, we present our evaluation toolkit and experimental results obtained applying our certification solution to a financial service implementing the Interactive Financial eXchange (IFX) standard.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Francesco Saonara
ACM Trans. Web1
2012 A Low-Cost Security Certification Scheme for Evolving Services
abstract
Security certification schemes for Service-Oriented Architecture (SOA) extend service specifications with the evidence that a service supports a set of security properties and provides a given level of assurance. However, services are subject to continuous refinements, and uncontrolled changes can easily invalidate existing certification results and require re-certification from scratch, with high costs and overheads on service providers. In this paper, we present an approach to manage the impact of service evolution on security certification. Our approach aims to support the incremental certification of evolving services and re-use, as much as possible, the certification evidence available from older certificates in the release of a new certificate.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani
ICWS1
2012 Landmark-assisted location and tracking in outdoor mobile network
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Ernesto Damiani, Mario Döller, Florian Stegmaier, Tilmann Rabl, Harald Kosch, Lionel Brunie
Multim. Tools Appl.1
2011 Augmented reality technologies, systems and applications
Julie Carmigniani, Borko Furht, Marco Anisetti, Paolo Ceravolo, Ernesto Damiani, Misa Ivkovic
Multim. Tools Appl.3
2011 Map-Based Location and Tracking in Multipath Outdoor Mobile Networks
abstract
Technical enhancements of mobile technologies are paving the way to the definition of high-quality and accurate geolocation solutions based on data collected and managed by GSM/3G networks. We present a technique that provides geolocation and mobility prediction both at network and service level, does not require any change to the existing mobile network infrastructure, and is entirely performed on the mobile network side, making it more robust than other positioning systems with respect to location spoofing and other terminal-based security threats. Our approach is based on a novel database correlation technique over Received Signal Strength Indication (RSSI) data, and provides a geolocation and tracking technique based on advanced map- and mobility-based filtering. The performance of the geolocation algorithm has been carefully validated by an extensive experimentation, carried out on real data collected from the mobile network antennas of a complex urban environment.
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Ernesto Damiani, Salvatore Reale
IEEE Trans. Wirel. Commun.1
2010 Using incentive schemes to alleviate supply chain risks
abstract
This paper describes a methodology and toolkit for the analysis of risks due to insiders' dysfunctional behavior in supply chains. It shows how risk analysis techniques based on value models [15] can incorporate the design and distribution of incentives as a risk-alleviation technique. Some important new functionalities of our SCRS (Supply Chain Risk Simulator v1 [14]) tool are presented. Such functionalities allow for (i) import/export of value models and (ii) execution of incentive-aware risk analysis. Functionality (i) fully integrates the SCRS tool with the e3-value tool suite, increasing synergy with existing value model toolkits. Functionality (ii) substantially extends the original palette of techniques for risk analysis and alleviation. Finally, the paper presents the results of an extensive experimentation of our methodology and simulation tool taking into account different combinations of incentive schemes and simulation options.
Marco Anisetti, Ernesto Damiani, Fulvio Frati, Stelvio Cimato, Gabriele Gianini
MEDES1
2009 Designing of a type-2 fuzzy logic filter for improving edge-preserving restoration of interlaced-to-progressive conversion
Gwanggil Jeon, Marco Anisetti, Valerio Bellandi, Ernesto Damiani, Jechang Jeong
Inf. Sci.2
2009 Fuzzy rough sets hybrid scheme for motion and scene complexity adaptive deinterlacing
Gwanggil Jeon, Marco Anisetti, Donghyung Kim, Valerio Bellandi, Ernesto Damiani, Jechang Jeong
Image Vis. Comput.2
2009 Concept of Linguistic Variable-Based Fuzzy Ensemble Approach: Application to Interlaced HDTV Sequences
abstract
This paper addresses the problem of edge restoration in digital images. Taking advantage of an ensemble approach, multiple type-1 fuzzy filters are combined to reach a decision. The fuzzy logic concept for linguistic variables and possibility theory is discussed with regard to knowledge representation and inference procedures. To improve conventional deinterlacing issues, we adopt type-1 fuzzy set concepts to design a weight-measuring approach. We demonstrate that the fuzzy ensemble approach model is well suited to image processing and provide case studies in the video-deinterlacing field. In our proposed method, five fuzzy membership functions (MFs) of linguistic variable-based fuzzy logic filters are derived from the type-1 (a.k.a. ordinary or primary) fuzzy MF. The weight-measuring process of our proposed model is used to assign weights to six candidate deinterlaced pixels (CDPs) that are interpolated according to edge direction. The use of a different MF for each direction allows the filter to characterize each pixel variation influence independently, according to its direction. The weights from all MFs are multiplied with the CDPs. The results of the empirical trials clearly show that the proposed system can successfully deal with several image types containing motion or detail elements.
Gwanggil Jeon, Marco Anisetti, Valerio Bellandi, Ernesto Damiani, Jechang Jeong
IEEE Trans. Fuzzy Syst.2
2007 Anomalies Detection in Mobile Network Management Data
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Elisa Bernardoni, Ernesto Damiani, Salvatore Reale
DASFAA1
2006 Psychology-Aware Video-Enabled Workplace
Marco Anisetti, Valerio Bellandi, Ernesto Damiani, Fabrizio Beverina, Maria Rita Ciceri, Stefania Balzarotti
UIC1