VLDB 2026 Research / reviewers in the wild / expert
Flavio Toffalini
dblp:88/9958
· DBLP profile ↗
18ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-7114-5640ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 5 first-author · 12 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem
Sergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin, Simon Resch, Khaled Yakdan, Thorsten Holz, Flavio Toffalini |
SP | 8 |
| 2026 | RemOTA: Remote attestation for detecting use-after-free in low-power microcontrollersabstractIn this paper, we introduce RemOTA , a novel remote attestation protocol to capture dynamic memory allocations and uses in microcontroller embedded systems, enabling detection of use-after-free errors. RemOTA performs a precomputation analysis to identify a minimal set of key points in the control flow graph, called checkpoints, which serve as boundaries enclosing sequences of pointer operations that occur along the same execution path. These checkpoints allow the grouping of multiple pointer usages into larger, semantically meaningful units, enabling efficient and targeted instrumentation. This approach is particularly effective in resource-constrained environments, as it minimizes runtime overhead while offloading verification to a remote server. RemOTA incorporates a remote verifier that receives information from the executing firmware and replicates instructions to dynamically reconstruct pointer usage and emulate memory state, allowing lightweight use-after-free detection. Through the evaluation of real-world firmware on an STM32 microcontroller, RemOTA demonstrates high precision 100% with low overhead, geometric mean 4.47% on the tested dataset. Its scalability and efficiency make RemOTA a practical solution for securing resource-constrained embedded devices in production environments. Matteo Zoia, Mirco Picca, Davide Rusconi, Andrea Monzani, Flavio Toffalini, Danilo Bruschi, Andrea Lanzi |
Comput. Secur. | 5 |
| 2025 | Sourcerer: Channeling the void
Nicolas Badoux, Flavio Toffalini, Mathias Payer |
DIMVA (1) | 2 |
| 2025 | type++: Prohibiting Type Confusion with Inline Type Information
Nicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias Payer |
NDSS | 2 |
| 2025 | DUMPLING: Fine-grained Differential JavaScript Engine Fuzzing
Liam Wachter, Julian Gremminger, Christian Wressnegger, Mathias Payer, Flavio Toffalini |
NDSS | 5 |
| 2025 | TLBlur: Compiler-Assisted Automated Hardening against Controlled Channels on Off-the-Shelf Intel SGX Platforms
Daan Vanoverloop, Andrés Sánchez, Flavio Toffalini, Frank Piessens, Mathias Payer, Jo Van Bulck |
USENIX Security Symposium | 3 |
| 2023 | Crystallizer: A Hybrid Path Analysis Framework to Aid in Uncovering Deserialization VulnerabilitiesabstractApplications use serialization and deserialization to exchange data. Serialization allows developers to exchange messages or perform remote method invocation in distributed applications. However, the application logic itself is responsible for security. Adversaries may abuse bugs in the deserialization logic to forcibly invoke attacker-controlled methods by crafting malicious bytestreams (payloads). Crystallizer presents a novel hybrid framework to automatically uncover deserialization vulnerabilities by combining static and dynamic analyses. Our intuition is to first over-approximate possible payloads through static analysis (to constrain the search space). Then, we use dynamic analysis to instantiate concrete payloads as a proof-of-concept of a vulnerability (giving the analyst concrete examples of possible attacks). Our proof-of-concept focuses on Java deserialization as the imminent domain of such attacks. We evaluate our prototype on seven popular Java libraries against state-of-the-art frameworks for uncovering gadget chains. In contrast to existing tools, we uncovered 41 previously unknown exploitable chains. Furthermore, we show the real-world security impact of Crystallizer by using it to synthesize gadget chains to mount RCE and DoS attacks on three popular Java applications. We have responsibly disclosed all newly discovered vulnerabilities. Prashast Srivastava, Flavio Toffalini, Kostyantyn Vorobyov, François Gauthier 0001, Antonio Bianchi, Mathias Payer |
ESEC/SIGSOFT FSE | 2 |
| 2023 | ViDeZZo: Dependency-aware Virtual Device FuzzingabstractA virtual machine interacts with its host environment through virtual devices, driven by virtual device messages, e.g., I/O operations. By issuing crafted messages, an adversary can exploit a vulnerability in a virtual device to escape the virtual machine, gaining host access. Even though hundreds of bugs in virtual devices have been discovered, coverage-based virtual device fuzzers hardly consider intra-message dependencies (a field in a virtual device message may be dependent on another field) and inter-message dependencies (a message may depend on a previously issued message), thus resulting in limited scalability or efficiency.ViDeZZo, our new dependency-aware fuzzing framework for virtual devices, overcomes the limitations of existing virtual device fuzzers by annotating intra-message dependencies with a lightweight grammar, and by self-learning inter-message dependencies with new mutation rules. Specifically, ViDeZZo annotates message dependencies and applies three categories of message mutators. This approach avoids heavy manual effort to analyze specifications and speeds up the slow exploration by satisfying dependencies, resulting in a scalable and efficient fuzzer that boosts bug discovery in virtual devices.In our evaluation, ViDeZZo covers two hypervisors, four architectures, five device categories, and 28 virtual devices, and reaches competitive coverage faster. Moreover, ViDeZZo successfully finds 24 existing and 28 new bugs across diverse bug types. We are actively engaging with the community with 7 of our submitted patches already accepted. Qiang Liu 0034, Flavio Toffalini, Yajin Zhou, Mathias Payer |
SP | 2 |
| 2023 | WarpAttack: Bypassing CFI through Compiler-Introduced Double-FetchesabstractCode-reuse attacks are dangerous threats that attracted the attention of the security community for years. These attacks aim at corrupting important control-flow transfers for taking control of a process without injecting code. Nowadays, the combinations of multiple mitigations (e.g., ASLR, DEP, and CFI) drastically reduced this attack surface, making running code-reuse exploits more challenging.Unfortunately, security mitigations are combined with compiler optimizations, that do not distinguish between security-related and application code. Blindly deploying code optimizations over code-reuse mitigations may undermine their security guarantees. For instance, compilers may introduce double-fetch vulnerabilities that lead to concurrency issues such as Time-Of-Check to Time-Of-Use (TOCTTOU) attacks.In this work, we propose a new attack vector, called WarpAttack, that exploits compiler-introduced double-fetch optimizations to mount TOCTTOU attacks and bypass code-reuse mitigations. We study the mechanism underlying this attack and present a practical proof-of-concept exploit against the last version of Firefox. Additionally, we propose a lightweight analysis to locate vulnerable double-fetch code (with 3% false positives) and conduct research over six popular applications, five operating systems, and four architectures (32 and 64 bits) to study the diffusion of this threat. Moreover, we study the implication of our attack against six CFI implementations. Finally, we investigate possible research lines for addressing this threat and propose practical solutions to be deployed in existing projects. Jianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao 0001, Mathias Payer |
SP | 3 |
| 2023 | FISHFUZZ: Catch Deeper Bugs by Throwing Larger Nets
Han Zheng 0006, Zezhong Ren, He Wang 0014, Chunjie Cao, Yuqing Zhang 0001, Flavio Toffalini, Mathias Payer |
USENIX Security Symposium | 8 |
| 2022 | Designing a Provenance Analysis for SGX EnclavesabstractSGX enclaves are trusted user-space memory regions that ensure isolation from the host, which is considered malicious. However, enclaves may suffer from vulnerabilities that allow adversaries to compromise their trustworthiness. Consequently, the SGX isolation may hinder defenders from recognizing an intrusion. Ideally, to identify compromised enclaves, the owner should have privileged access to the enclave memory and a policy to recognize the attack. Most importantly, these operations should not break the SGX properties. Flavio Toffalini, Mathias Payer, Jianying Zhou 0001, Lorenzo Cavallaro |
ACSAC | 1 |
| 2022 | Evocatio: Conjuring Bug Capabilities from a Single PoCabstractThe popularity of coverage-guided greybox fuzzers has led to a tsunami of security-critical bugs that developers must prioritize and fix. Knowing the capabilities a bug exposes (e.g., type of vulnerability, number of bytes read/written) enables prioritization of bug fixes. Unfortunately, understanding a bug's capabilities is a time consuming process, requiring (a) an understanding of the bug's root cause, (b) an understanding how an attacker may exploit the bug, and (c) the development of a patch mitigating these threats. This is a mostly-manual process that is qualitative and arbitrary, potentially leading to a misunderstanding of the bug's capabilities. Zhiyuan Jiang, Shuitao Gan, Adrian Herrera, Flavio Toffalini, Lucio Romerio, Chaojing Tang, Manuel Egele, Chao Zhang 0008, Mathias Payer |
CCS | 4 |
| 2021 | SnakeGX: A Sneaky Attack Against SGX Enclaves
Flavio Toffalini, Mariano Graziano, Mauro Conti, Jianying Zhou 0001 |
ACNS (1) | 1 |
| 2020 | ASAINT: a spy App identification system based on network trafficabstractSpy app is a class of malware for mobile devices that allows an adversary to steal sensitive information. Detecting spy apps is challenging because they do not rely on classic malware techniques, for instance, they use standard services to store stolen data, and do not perform privileges escalation on the victim phone. Thus, their behavior is generally closer to the benign apps and poses new challenges for their detection. Mauro Conti, Giulio Rigoni, Flavio Toffalini |
ARES | 3 |
| 2019 | Careful-Packing: A Practical and Scalable Anti-Tampering Software Protection enforced by Trusted ComputingabstractEnsuring the correct behaviour of an application is a critical security issue. One of the most popular ways to modify the intended behaviour of a program is to tamper its binary. Several solutions have been proposed to solve this problem, including trusted computing and anti-tampering techniques. Both can substantially increase security, and yet both have limitations. In this work, we propose an approach which combines trusted computing technologies and anti-tampering techniques, and that synergistically overcomes some of their inherent limitations. In our approach critical software regions are protected by leveraging on trusted computing technologies and cryptographic packing, without introducing additional software layers. To illustrate our approach we implemented a secure monitor which collects user activities, such as keyboard and mouse events for insider attack detection. We show how our solution provides a strong anti-tampering guarantee with a low overhead: around 10 lines of code added to the entire application, an average execution time overhead of 5.7% and only 300KB of memory allocated for the trusted module. Flavio Toffalini, Martín Ochoa, Jun Sun 0001, Jianying Zhou 0001 |
CODASPY | 1 |
| 2019 | ScaRR: Scalable Runtime Remote Attestation for Complex Systems
Flavio Toffalini, Eleonora Losiouk, Andrea Biondo, Jianying Zhou 0001, Mauro Conti |
RAID | 1 |
| 2019 | Practical static analysis of context leaks in Android applicationsabstractSummary Android native applications, written in Java and distributed in APK format, are widely used in mobile devices. Their specific pattern of use lets the operating system control the creation and destruction of resources, such as activities and services (contexts). Programmers are not supposed to interfere with such life cycle events. Otherwise, contexts might be leaked, ie, they will never be deallocated from memory, or be deallocated late, leading to memory exhaustion and frozen applications. In practice, it is easy to write incorrect code, which hinders garbage collection of contexts and leads to context leakages. In this work, we present a novel static analysis method that finds context leaks in Android code. We apply this analysis to APKs translated into Java bytecode. We provide a formal analysis of our algorithms and suggest further research directions for improving precision by combining different approaches. We discuss the results of a large number of experiments with our analysis, which reveal context leaks in many widely used applications from the Android marketplace. This shows the practical usefulness of our technique and its superiority w.r.t. the well‐known Lint and Infer static analysis tools. We estimate the amount of memory saved by the collection of the leaks found and explain, experimentally, where programmers often go wrong and limitations of our tool. Such lessons could be used for designing of a sound or more powerful static analysis tool. This work can be considered as a practical application of software analysis techniques to solve practical problems. Flavio Toffalini, Jun Sun 0001, Martín Ochoa |
Softw. Pract. Exp. | 1 |
| 2016 | Google Dorks: Analysis, Creation, and New Defenses
Flavio Toffalini, Maurizio Abbà, Damiano Carra, Davide Balzarotti |
DIMVA | 1 |