VLDB 2026 Research / reviewers in the wild / expert
Francesco Cerasuolo
dblp:74/11245
· DBLP profile ↗
12ranked-venue papers
7as first author
11since 2021 · last 2026
0009-0000-6476-8092ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 4 first-author · 9 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cross-network transferability of AI-based network intrusion detection systems in heterogeneous Internet of Things environmentsabstractThe rapid expansion of Internet of Things (IoT) ecosystems has amplified the demand for robust cybersecurity solutions, with Artificial Intelligence (AI)-based Network Intrusion Detection System (NIDS) emerging as a promising component of modern defense strategies. Despite their strong performance when trained and evaluated on traffic collected within the same IoT environment, a critical open question remains: can these systems transfer effectively when deployed in different IoT networks? In this work, we present a comprehensive experimental study evaluating the cross-network transferability of AI-based NIDS built using Machine Learning (ML) and Deep Learning (DL), including attention-based architectures. Our analysis spans eight heterogeneous IoT network environments, represented by publicly available datasets. Specifically, we ( i ) assess attack-level transferability across networks, ( i i ) quantify the impact of feature informativeness on cross-network performance, ( i i i ) leverage eXplainable Artificial Intelligence (XAI) to interpret decisions in cross-network scenarios, ( i v ) investigate design principles for universal NIDS, and ( v ) evaluate edge-device deployment feasibility. Our findings provide systematic insight into the limits of AI-driven NIDS. Notably, cross-network transferability is highly variable and strongly influenced by attack semantics and dataset characteristics: volumetric attacks transfer effectively, whereas others remain dataset-dependent. Transferability benefits from generalizable feature design and multi-domain training, yet universal robustness remains challenging. Finally, while edge deployment is feasible from a memory perspective, Convolutional Neural Network (CNN) architectures offer substantially lower inference latency than Transformers on resource-constrained devices. Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè |
Comput. Networks | 1 |
| 2026 | A Federated and Incremental Network Intrusion Detection System for IoT Emerging ThreatsabstractEnsuring network security is increasingly challenging, especially in the Internet of Things (IoT) domain, where threats are diverse, rapidly evolving, and often device-specific. Hence, Network Intrusion Detection Systems (NIDSs) require(i)being trained on network traffic gathered in different collection points to cover the attack traffic heterogeneity,(ii)continuously learning emerging threats (viz., 0-day attacks), and(iii)be able to take attack countermeasures as soon as possible. In this work, we aim to improve Artificial Intelligence (AI)-based NIDS design & maintenance by integrating Federated Learning (FL) and Class Incremental Learning (CIL). Specifically, we devise a Federated Class Incremental Learning (FCIL) framework–suited for early-detection settings—that supports decentralized and continual model updates, investigating the non-trivial intersection of FL algorithms with state-of-the-art CIL techniques to enable scalable, privacy-preserving training in highly non-IID environments. We evaluate FCIL on three IoT datasets across different client scenarios to assess its ability to learn new threats and retain prior knowledge. The experiments assess potential key challenges in generalization and few-sample training, and compare NIDS performance to monolithic and centralized baselines. Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Explainable federated class incremental learning for Encrypted Network Traffic classificationabstractNetwork traffic has experienced substantial growth in recent years, requiring the implementation of more advanced techniques for effective management. In this context, Traffic Classification (TC) helps in successfully handling the network by identifying what is flowing through it. Nowadays, data-driven approaches—viz., Machine Learning (ML) and Deep Learning (DL)—are widely employed to address this task. However, these approaches struggle to keep pace with the ever-changing nature of traffic due to the introduction of new or updated services/apps and exhibit a decision-making process not interpretable. Furthermore, network traffic can vary significantly by geographic area , requiring a decentralized privacy-preserving approach to update classifiers collaboratively. In this work, we propose a Federated Class Incremental Learning (FCIL) framework that integrates Class Incremental Learning (CIL) and Federated Learning (FL) for network TC while incorporating a comprehensive eXplainable Artificial Intelligence (XAI) methodology, tackling the challenges of updating traffic classifiers, managing the geographic diversity of traffic along with data privacy, and interpreting the decision-making process, respectively. To assess our proposal, we leverage two publicly available encrypted network traffic datasets. Our findings uncover that, in small networks, fewer synchronizations facilitate retaining old knowledge, while larger networks reveal an approach-dependent pattern, yet still exhibiting good retention performance. Moreover, in both small and larger networks, frequent updates enhance the assimilation of new information . Notably, B i C + is the most effective approach in small networks (i.e., 2 clients) while i C a R L + performs best in larger networks (i.e., 10 clients), obtaining 82% and 79% F1 on C E S N E T - T L S 2 2 , respectively. Leveraging XAI techniques, we analyze the effect of incorporating a per-client bias correction layer. By integrating sample-based and attribution-based explanations, we provide detailed insights into the decision-making process of FCIL approaches . Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè |
Comput. Networks | 2 |
| 2025 | Attack-adaptive network intrusion detection systems for IoT networks through class incremental learningabstractThe advent of the Internet of Things (IoT) has ushered in an era of unprecedented connectivity and convenience, enabling everyday objects to gather and share data autonomously, revolutionizing industries, and improving quality of life. However, this interconnected landscape poses cybersecurity challenges, as the expanded attack surface exposes vulnerabilities ripe for exploitation by malicious actors. The surge in network attacks targeting IoT devices underscores the urgency for robust and evolving security measures. Class Incremental Learning (CIL) emerges as a dynamic strategy to address these challenges, empowering Machine Learning (ML) and Deep Learning (DL) models to adapt to evolving threats while maintaining proficiency in detecting known ones. In the context of IoT security, characterized by the constant emergence of novel attack types, CIL offers a powerful means to enhance Network Intrusion Detection Systems (NIDS) resilience and network security. This paper aims to investigate how CIL methods can support the evolution of NIDS within IoT networks ( i ) by evaluating both attack detection and classification tasks — optimizing hyperparameters associated with the incremental update or to the traffic input definition—and ( i i ) by addressing also key research questions related to real-world NIDS challenges —such as the explainability of decisions, the robustness to perturbation of traffic inputs, and scenarios with a scarcity of new-attack samples. Leveraging 4 recently-collected and comprehensive IoT attack datasets , the study aims to evaluate the effectiveness of CIL techniques in classifying 0-day attacks. Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè |
Comput. Networks | 1 |
| 2025 | Adaptable, incremental, and explainable network intrusion detection systems for internet of things
Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè |
Eng. Appl. Artif. Intell. | 1 |
| 2025 | Mapping the Landscape of Generative AI in Network Monitoring and ManagementabstractGenerative Artificial Intelligence (GenAI) models such as LLMs, GPTs, and Diffusion Models have recently gained widespread attention from both the research and the industrial communities. This survey explores their application in network monitoring and management, focusing on prominent use cases, as well as challenges and opportunities. We discuss how network traffic generation and classification, network intrusion detection, networked system log analysis, and network digital assistance can benefit from the use of GenAI models. Additionally, we provide an overview of the available GenAI models, datasets for large-scale training phases, and platforms for the development of such models. Finally, we discuss research directions that potentially mitigate the roadblocks to the adoption of GenAI for network monitoring and management. Our investigation aims to map the current landscape and pave the way for future research in leveraging GenAI for network monitoring and management. Giampaolo Bovenzi, Francesco Cerasuolo, Domenico Ciuonzo, Davide Di Monda, Idio Guarino, Antonio Montieri, Valerio Persico, Antonio Pescapè |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Explainable Few-Shot Class Incremental Learning for Mobile Network Traffic ClassificationabstractMobile Traffic Classification (TC) increasingly relies on Machine Learning (ML) and Deep Learning (DL) to enhance network management. Yet, these methods face challenges in (i) classifying new apps, (ii) handling data scarcity from frequent app releases/updates, and (iii) explaining their decisions due to their opaqueness. Class Incremental Learning (CIL) and Few-Shot Learning (FSL) enable to quickly update models and learn with very limited data, respectively, while eXplainable AI (XAI) enhances decision transparency. In this work, we merge CIL and FSL to update models with new apps under few sample constraints. First, we introduce SWEET, a CIL-originated approach that flexibly accommodates different few-sample scenarios via adaptive traffic augmentation. Second, we devise an XAI methodology based on visualization-, sample-, and attribution-based techniques to explore practical incremental learning. We evaluate both contributions on the public mobile traffic dataset MIRAGE19. Francesco Cerasuolo, Giampaolo Bovenzi, Vincenzo Spadari, Domenico Ciuonzo, Antonio Pescapè |
GLOBECOM | 1 |
| 2024 | An MLOps Framework for Explainable Network Intrusion Detection with MLflowabstractThe surge in network traffic has required advanced techniques to ensure network security. Network Intrusion Detection Systems (NIDSs), which increasingly employ Machine Learning (ML) and Deep Learning (DL) methodologies, play a pivotal role in this task by continuously monitoring network traffic patterns and identifying suspicious activities. To address the complexities of developing ML- and DL-based NIDS, MLOps tools have been designed to optimize model deployment, monitoring, and management in production environments, streamlining model development. These tools enable efficient experimentation, version management, and logging of artifacts for network administrators and data scientists. In this work, we design a framework powered by MLflow to manage the ML pipeline from data handling to results visualization. To show the effectiveness of our framework, we conducted an experimental campaign on 4 broadly used security datasets (viz. NSL-KDD, IoT-23, Kitsune, and TON_IoT) performing crucial tasks for intrusion detection, namely anomaly detection, binary misuse detection, and multiclass misuse detection. Vincenzo Spadari, Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè |
ISCC | 2 |
| 2024 | MEMENTO: A novel approach for class incremental learning of encrypted trafficabstractIn the ever-changing digital environment, ensuring the ongoing effectiveness of traffic analysis and security measures is crucial. Therefore, Class Incremental Learning (CIL) in encrypted Traffic Classification (TC) is essential for adapting to evolving network behaviors and the rapid development of new applications. However, the application of CIL techniques in the TC domain is not straightforward, usually leading to unsatisfactory performance figures. Specifically, the improvement goal is to reduce forgetting on old apps and increase the capacity in learning new ones, in order to improve overall classification performance— reducing the drop from a model “trained-from-scratch”. The contribution of this work is the design of a novel fine-tuning approach called MEMENTO, which is obtained through the careful design of different building blocks: memory management, model training, and rectification strategies. In detail, we propose the application of traffic biflows augmentation strategies to better capitalize on old apps biflows, we introduce improvements in the distillation stage, and we design a general rectification strategy that includes several existing proposals. To assess our proposal, we leverage two publicly-available encrypted network traffic datasets, i.e., MIRAGE19 and CESNET-TLS22. As a result, on both datasets MEMENTO achieves a significant improvement in classifying new apps (w.r.t. the best-performing alternative, i.e., BiC) while maintaining stable performance on old ones. Equally important, MEMENTO achieves satisfactory overall TC performance, filling the gap toward a trained-from-scratch model and offering a considerable gain in terms of time (up to 10× speed-up) to obtain up-to-date and running classifiers. The experimental evaluation relies on a comprehensive performance evaluation workbench for CIL proposals, which is based on a wider set of metrics (as opposed to the existing literature in TC). Francesco Cerasuolo, Alfredo Nascita, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001 |
Comput. Networks | 1 |
| 2023 | Adaptive Intrusion Detection Systems: Class Incremental Learning for IoT Emerging ThreatsabstractIn the evolving landscape of Internet of Things (IoT) security, the need for continuous adaptation of defenses is critical. Class Incremental Learning (CIL) can provide a viable solution by enabling Machine Learning (ML) and Deep Learning (DL) models to $( i)$ learn and adapt to new attack types (0-day attacks), $( ii)$ retain their ability to detect known threats, (iii) safeguard computational efficiency (i.e. no full re-training). In IoT security, where novel attacks frequently emerge, CIL offers an effective tool to enhance Intrusion Detection Systems (IDS) and secure network environments. In this study, we explore how CIL approaches empower DL-based IDS in IoT networks, using the publicly-available IoT-23 dataset. Our evaluation focuses on two essential aspects of an IDS: $( a)$ attack classification and $( b)$ misuse detection. A thorough comparison against a fully-retrained IDS, namely starting from scratch, is carried out. Finally, we place emphasis on interpreting the predictions made by incremental IDS models through eXplainable AI (XAI) tools, offering insights into potential avenues for improvement. Francesco Cerasuolo, Giampaolo Bovenzi, Christian Marescalco, Francesco Cirillo, Domenico Ciuonzo, Antonio Pescapè |
IEEE Big Data | 1 |
| 2022 | A Comparison of Machine and Deep Learning Models for Detection and Classification of Android Malware TrafficabstractWith the increasing popularity of mobile-app services, malicious software is increasing as well. Accordingly, the interest of the scientific community in Machine and Deep Learning solutions for detecting and classifying malware traffic is growing. In this work, we provide a fair assessment of the performance of a number of data-driven strategies to detect and classify Android malware traffic. Three models are taken into account (Decision Tree, Random Forest, and 1-D Convolutional Neural Network) considering both flat (i.e. non-hierarchical) and hierarchical approaches. The experimental analysis performed using a state-of-art dataset (CIC-AAGM2017) reports that Random Forest exhibits the best performance in a flat setup, while moving to a hierarchical approach could cause significant variation in precision and recall. Such results push for further investigating advanced hierarchical setups and learning schemes. Giampaolo Bovenzi, Francesco Cerasuolo, Antonio Montieri, Alfredo Nascita, Valerio Persico, Antonio Pescapè |
ISCC | 2 |
| 2012 | Visualization with a New Visual Metaphor for Hierarchical and Stratified Temporal Domain
Francesco Cerasuolo, Francesco Cutugno, Vincenza Anna Leano |
W2GIS | 1 |