VLDB 2026 Research / reviewers in the wild / expert
Roberto Doriguzzi Corin
dblp:94/8851
· DBLP profile ↗
24ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0002-8001-7835ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 6 · 3 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | INTELLECT: From federated training to resource-aware cyber threat detection
Simone Magnani, Liubov Nedoshivina, Roberto Doriguzzi Corin, Stefano Braghin, Domenico Siracusa |
Comput. Networks | 3 |
| 2024 | Resource-Efficient Federated Learning for Network Intrusion DetectionabstractMaintaining up-to-date attack profiles is a critical challenge for Network Intrusion Detection Systems (NIDSs). State-of-the-art solutions based on Machine Learning (ML) algorithms often rely on public datasets, which can be outdated or anonymised, hindering their effectiveness in real-world scenarios. Collaborative learning tackles data limitations by enabling multiple parties to jointly train and update their NIDSs through sharing recent attack information. However, directly sharing network traffic data can compromise the participants’ privacy. Federated Learning (FL) addresses this concern: it allows participants to collaboratively improve their NIDS models by sharing only the trained model parameters, not the raw data itself. Nevertheless, recent studies have proven that the Federated Averaging (FedAvg) algorithm at the core of FL can be inefficient with heterogeneous and unbalanced datasets. A recent solution called FLAD addresses the limitations of FedAvg, resulting in higher accuracy of the final ML model on out-of-distribution data. This work focuses on the resource usage of the FL process, demonstrating the superiority of FLAD over FedAvg in computational efficiency and convergence time, showcasing its potential to enhance NIDS effectiveness. Roberto Doriguzzi Corin, Silvio Cretti, Domenico Siracusa |
NetSoft | 1 |
| 2024 | Online Learning and Model Pruning Against Concept Drifts in Edge DevicesabstractThe proliferation of Internet of Things sensors has driven the adoption of the edge computing paradigm, which prioritizes processing the data close to the source to minimize data transfer to cloud servers, reduce latency, and enhance privacy and robustness. However, edge computing environments present limited computational power, storage capacity, and a non-negligible risk of cyber-attacks.This paper tackles the challenges of deploying Intrusion and/or Anomaly Detection Systems (I/ADSs) at the network’s edge, particularly for environments with evolving network attack patterns (concept drift). To this aim, we propose a methodology that leverages both Neural Network (NN) pruning and online learning. We empirically evaluate the proposed methodology under attack scenarios with concept drift in network traffic, where adaptation to new data trends is crucial. We also demonstrate that NN pruning leads to more energy-efficient and lightweight I/ADSs, which can be adopted also in devices with strict resource requirements. Simone Magnani, Seshu Tirupathi, Roberto Doriguzzi Corin, Liubov Nedoshivina, Stefano Braghin, Domenico Siracusa |
NetSoft | 3 |
| 2024 | Introducing packet-level analysis in programmable data planes to advance Network Intrusion Detection
Roberto Doriguzzi Corin, Luis Augusto Dias Knob, Luca Mendozzi, Domenico Siracusa, Marco Savi |
Comput. Networks | 1 |
| 2024 | FLAD: Adaptive Federated Learning for DDoS attack detection
Roberto Doriguzzi Corin, Domenico Siracusa |
Comput. Secur. | 1 |
| 2024 | Resource-Aware Cyber Deception for Microservice-Based ApplicationsabstractCyber deception can be a valuable addition to traditional cyber defense mechanisms, especially for modern cloud-native environments with a fading security perimeter. However, pre-built decoys used in classical computer networks are not effective in detecting and mitigating malicious actors due to their inability to blend with the variety of applications in such environments. On the other hand, decoys cloning the deployed microservices of an application can offer a high-fidelity deception mechanism to intercept ongoing attacks within production environments. However, to fully benefit from this approach, it is essential to use a limited amount of decoy resources and devise a suitable cloning strategy to minimize the impact on legitimate services performance. Following this observation, we formulate a non-linear integer optimization problem that maximizes the number of attack paths intercepted by the allocated decoys within a fixed resource budget. Attack paths represent the attacker's movements within the infrastructure as a sequence of violated microservices. We also design a heuristic decoy placement algorithm to approximate the optimal solution and overcome the computational complexity of the proposed formulation. We evaluate the performance of the optimal and heuristic solutions against other schemes that use local vulnerability metrics to select which microservices to clone as decoys. Our results show that the proposed allocation strategy achieves a higher number of intercepted attack paths compared to these schemes while requiring approximately the same number of decoys. Marco Zambianco, Claudio Facchinetti, Roberto Doriguzzi Corin, Domenico Siracusa |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Pruning Federated Learning Models for Anomaly Detection in Resource-Constrained EnvironmentsabstractThe evolving complexity of modern IT infrastructures has paved the way for malicious actors to exploit a wide array of vulnerabilities that can compromise the integrity of these systems. Monitoring complex IT systems is expensive and often requires dedicated infrastructure for deploying Intrusion and/or Anomaly Detection Systems. Moreover, ML-based solutions need large training sets, which add to the overall cost. To tackle these challenges we present INTELLECT, a novel approach to Intrusion and/or Anomaly Detection System, which leverages Federated Learning and model pruning techniques to cooperatively train high-accuracy models using distributed datasets and derive a fleet of lightweight models, which can be deployed without incurring additional costs for dedicated infrastructure. INTELLECT expands on the state-of-the-art techniques for feature selection, model pruning, and model distillation to create an interconnected pipeline. We empirically demonstrate the effectiveness of the methodology on benchmark datasets, and we present guidelines for the deployment in production systems. Simone Magnani, Stefano Braghin, Ambrish Rawat, Roberto Doriguzzi Corin, Mark Purcell, Domenico Siracusa |
IEEE Big Data | 4 |
| 2023 | Enhancing Network Intrusion Detection: An Online Methodology for Performance AnalysisabstractMachine learning models have been extensively proposed for classifying network flows as benign or malicious, either in-network or at the endpoints of the infrastructure. Typically, the performance of such models is assessed by evaluating the trained model against a portion of the available dataset. However, in a production scenario, these models are fed by a monitoring stage that collects information from flows and provides inputs to a filtering stage that eventually blocks malicious traffic. To the best of our knowledge, no work has analysed the entire pipeline, focusing on its performance in terms of both inputs (i.e., the information collected from each flow) and outputs (i.e., the system’s ability to prevent an attack from reaching the application layer).In this paper, we propose a methodology for evaluating the effectiveness of a Network Intrusion Detection System (NIDS) by placing the model evaluation test alongside an online test that simulates the entire monitoring-detection-mitigation pipeline. We assess the system’s outputs based on different input configurations, using state-of-the-art detection models and datasets. Our results highlight the importance of inputs for the throughput of the NIDS, which can decrease by more than 50% with heavier configurations. Furthermore, our research indicates that relying solely on the performance of the detection model may not be enough to evaluate the effectiveness of the entire NIDS process. Indeed, even when achieving near-optimal False Negative Rate (FNR) values (e.g., 0.01), a substantial amount of malicious traffic (e.g., 70%) may still successfully reach its target. Simone Magnani, Roberto Doriguzzi Corin, Domenico Siracusa |
NetSoft | 2 |
| 2022 | Towards Application-Aware Provisioning of Security Services with KubernetesabstractIn network security, Network Function Virtualization can be exploited to implement flexible security services tailored to specific user needs. However, in practice this is hard to achieve due to the limitations of reference software platforms, such as Kubernetes, which are designed to orchestrate cloud-native services. In this work, we complement Kubernetes with a state-of-the-art algorithm for application-aware provisioning of security services. We demonstrate that the proposed solution improves basic provisioning mechanisms, such as the default Kubernetes scheduler, in terms of Quality of Service and security guarantees for the users. Roberto Doriguzzi Corin, Silvio Cretti, Tiziana Catena, Simone Magnani, Domenico Siracusa |
NetSoft | 1 |
| 2022 | A Digital Twin for the 5G Era: the SPIDER Cyber RangeabstractService providers, 5G network operators and, more generally, vertical industries face today a dangerous shortage of highly skilled cybersecurity experts. Along with the escalation and growing sophistication of cyber-attacks, 5G networks require the training of skilled and highly competent cyber forces. To meet these requirements, the SPIDER cyber range focuses specifically on 5G, and is based on three pillars, (i) cyber security assessment, (ii) training cyber security teams to defend against complex cyber-attack scenarios, and (iii) evaluation of cyber risk. The SPIDER cyber range replicates a customized 5G network, enabling the execution of cyber-exercises that take advantage of hands-on interaction in real time, the sharing of information between participants, and the gathering of feedback from network equipment, as well as the development and adaptation of advanced operational procedures. This aims to help 5G security professionals improve their ability to collaboratively manage and predict security incidents, complex attacks, and propagated vulnerabilities. The SPIDER cyber range is validated in two relevant use case scenarios aimed at demonstrating, in a realistic, measurable, and replicable way the transformations SPIDER will bring to the cybersecurity industry. Filippo Rebecchi, Antonio Pastor 0001, Alberto Mozo, Chiara Lombardo, Roberto Bruschi, Ilias Aliferis, Roberto Doriguzzi Corin, Panagiotis Gouvas, Antonio Álvarez Romero, Anna Angelogianni, Ilias Politis, Christos Xenakis |
WoWMoM | 7 |
| 2021 | Hybrid SDN evolution: A comprehensive survey of the state-of-the-artabstractSoftware-Defined Networking (SDN) is an evolutionary networking paradigm which has been adopted by large network and cloud providers, among which are Tech Giants. However, embracing a new and futuristic paradigm as an alternative to well-established and mature legacy networking paradigm requires a lot of time along with considerable financial resources and technical expertise. Consequently, many enterprises cannot afford it. A compromise solution then is a hybrid networking environment (a.k.a. Hybrid SDN (hSDN)) in which SDN functionalities are leveraged while existing traditional network infrastructures are acknowledged. Recently, hSDN has been seen as a viable networking solution for a diverse range of businesses and organizations. Accordingly, the body of literature on hSDN research has improved remarkably. On this account, we present this paper as a comprehensive state-of-the-art survey which expands upon hSDN from many different perspectives. Sajad Khorsandroo, Adrián Gallego Sánchez, Ali Saman Tosun, José M. Arco, Roberto Doriguzzi Corin |
Comput. Networks | 5 |
| 2020 | Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack DetectionabstractDistributed Denial of Service (DDoS) attacks are one of the most harmful threats in today's Internet, disrupting the availability of essential services. The challenge of DDoS detection is the combination of attack approaches coupled with the volume of live traffic to be analysed. In this paper, we present a practical, lightweight deep learning DDoS detection system called Lucid, which exploits the properties of Convolutional Neural Networks (CNNs) to classify traffic flows as either malicious or benign. We make four main contributions; (1) an innovative application of a CNN to detect DDoS traffic with low processing overhead, (2) a dataset-agnostic preprocessing mechanism to produce traffic observations for online attack detection, (3) an activation analysis to explain Lucid's DDoS classification, and (4) an empirical validation of the solution on a resource-constrained hardware platform. Using the latest datasets, Lucid matches existing state-of-the-art detection accuracy whilst presenting a 40x reduction in processing time, as compared to the state-of-the-art. With our evaluation results, we prove that the proposed approach is suitable for effective DDoS detection in resource-constrained operational environments. Roberto Doriguzzi Corin, Stuart Millar, Sandra Scott-Hayward, Jesús Martínez del Rincón, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Dynamic and Application-Aware Provisioning of Chained Virtual Security Network FunctionsabstractA promising area of application for Network Function Virtualization (NFV) is in network security, where chains of Virtual Security Network Functions (VSNFs), i.e., security-specific virtual functions such as firewalls or Intrusion Prevention Systems, can be dynamically created and configured to inspect, filter or monitor the network traffic. However, the traffic handled by VSNFs could be sensitive to specific network requirements, such as minimum bandwidth or maximum end-to-end latency. Therefore, the decision on which VSNFs should apply for a given application, where to place them and how to connect them, should take such requirements into consideration. Otherwise, security services could affect the quality of service experienced by customers. In this paper, we propose PESS (Progressive Embedding of Security Services), a solution to efficiently deploy chains of virtualised security functions based on the security requirements of individual applications and operators' policies, while optimizing resource utilization. We provide the PESS mathematical model and heuristic solution. Simulation results show that, compared to state-of-the-art application-agnostic VSNF provisioning models, PESS reduces computational resource utilization by up to 50%, in different network scenarios. This result ultimately leads to a higher number of provisioned security services and to up to a 40% reduction in end-to-end latency of application traffic. Roberto Doriguzzi Corin, Sandra Scott-Hayward, Domenico Siracusa, Marco Savi, Elio Salvadori |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | AADS: A Noise-Robust Anomaly Detection Framework for Industrial Control Systems
Maged AbdelAty, Roberto Doriguzzi Corin, Domenico Siracusa |
ICICS | 2 |
| 2017 | An effective swapping mechanism to overcome the memory limitation of SDN devicesabstractThanks to its 1-cycle lookup performance, the Ternary Content Addressable Memory (TCAM) is considered an essential hardware component for the deployment of high-performance Software-Defined Networks (SDN). Unfortunately, in many network scenarios, TCAMs can quickly fill due to their limited memory size, thus preventing the installation of new flow-rules and leading to inefficient traffic forwarding. This issue has already been addressed in computer programming, where Virtual Memory is offered to applications to mimic a much larger physical memory, by swapping memory pages to disk. In a previous work, we proposed and discussed the architecture of a Memory Management System (MMS) for SDN controllers that, like the analogous process for computer Operating Systems, optimizes the memory usage and prevents anomalies due to lack of memory space. This work proposes a memory swapping mechanism for SDN controllers, a function of the MMS which gives SDN applications the illusion of unlimited memory space in the forwarding devices, without requiring any hardware modification or changes in the control protocol. The paper discusses the memory swapping mechanism design, its implementation and proves its quality using real traffic traces, demonstrating lower TCAM memory utilization and potentially increased network performance in terms of end-to-end throughput. A prototype of the MMS is available for testing as an open source project. Antonio Marsico, Roberto Doriguzzi Corin, Domenico Siracusa |
IM | 2 |
| 2017 | Overcoming the memory limits of network devices in SDN-enabled data centersabstractIn extremely connected and dynamic environments, such as data centers, SDN network devices can be exploited to simplify the management of network provisioning. However, they leverage on TCAMs to implement the flow tables, i.e., on size-limited memories that can be quickly filled up when fine-grained traffic control is required, eventually preventing the installation of new forwarding rules. In this work, we demonstrate how this issue can be mitigated by means of a novel flow rule swapping mechanism. Specifically, we first show the negative effects of a full TCAM on a video streaming service provided by an SDN-enabled data center. Then, we show that our swapping mechanism helps in overcoming the inability to properly access a media content available in the data center, by temporarily moving the least matched flow rules from the TCAM to a larger memory outside the SDN device. Antonio Marsico, Roberto Doriguzzi Corin, Domenico Siracusa |
IM | 2 |
| 2016 | Reusability of software-defined networking applications: A runtime, multi-controller approachabstractThe Software-Defined Networking (SDN) ecosystem is still characterized by a multitude of different controller platforms, each with its own programming model, execution model, and capabilities. This creates a danger of a controller lock-in for both developers of SDN control applications and operators of SDN networks. Since no single controller platform appears to dominate the ecosystem for the foreseeable future, there is a need for portability of control applications between different platforms. We propose an architecture based on executing multiple instances of different controller platforms concurrently in a network to provide the SDN code the environment it was written for. It is built around a controller-independent network event routing element called Network Engine that provides composition and conflict resolution. Results obtained in realistic scenarios demonstrate the feasibility of the proposed approach, which increases both developer productivity and operational flexibility. A preliminary prototype of the architecture is available for testing as an open source project. Roberto Doriguzzi Corin, Pedro A. Aranda-Gutiérrez, Elisa Rojas, Holger Karl, Elio Salvadori |
CNSM | 1 |
| 2016 | Empowering network operating systems with memory management techniquesabstractSimilarly to computer operating systems which guarantee safe access to memory resources, Network Operating Systems shall grant SDN applications a reliable access to neatly organized flow table resources. This paper presents the architecture for a controller-agnostic Memory Management System and some of its functionalities that aim at improving flow table usage and preventing network misconfigurations. From the implementation perspective, this work discusses the applicability of the proposed system, a strategy to evaluate it and current open challenges. Roberto Doriguzzi Corin, Domenico Siracusa, Elio Salvadori, Arne Schwabe |
NOMS | 1 |
| 2016 | A non-disruptive automated approach to update SDN applications at runtimeabstractThe Memory Management Subsystem (MMS) provides automated services for SDN controllers that optimize the management of network devices' memory. Among other functions, it cleans the memory of network devices upon the update or the removal of SDN applications. The potential of this MMS function is demonstrated in a scenario where a critical security update for a network application would be otherwise ineffective. Antonio Marsico, Roberto Doriguzzi Corin, Matteo Gerola, Domenico Siracusa, Arne Schwabe |
NOMS | 2 |
| 2015 | NetIDE: Removing vendor lock-in in SDNabstractThe Software-Defined Networking (SDN) paradigm allows networking hardware to be made “malleable” and remotely manageable by the so-called SDN controllers. However, the current SDN landscape is extremely fragmented. Different open and closed source controller frameworks such as Open-Daylight [1], Ryu [2], Floodlight [3], etc. exist. Porting SDN applications from one such platform to another is practically impossible and so, SDN users like network operators face a situation where they are either confined to applications working for the platform of their choice, or forced to re-implement their solutions every time they encounter a new platform. Roberto Doriguzzi Corin, Elio Salvadori, Pedro A. Aranda-Gutiérrez, Christian Stritzke, Alec Leckey, Kevin Phemius, Elisa Rojas, Carmen Guerrero |
NetSoft | 1 |
| 2013 | Progressive virtual topology embedding in OpenFlow networks
Roberto Riggio, Francesco De Pellegrini, Elio Salvadori, Matteo Gerola, Roberto Doriguzzi Corin |
IM | 5 |
| 2011 | Generalizing Virtual Network Topologies in OpenFlow-Based NetworksabstractNetwork Virtualization (NV) is one of the most promising technique to enable innovation in today's network. A recent approach toward NV has been proposed through FlowVisor, whose aim is to leverage on the specific features of an OpenFlow-controlled network to share the same hardware forwarding plane among multiple logical networks. However, FlowVisor lacks some features to enable a full implementation of a NV architecture: the virtual topologies that can be established are restricted to subsets of the physical topology and it has no way for two slices to share flowspace and simultaneously prevent them from interfering with each other's traffic. In this work, an innovative system called ADVisor (ADvanced FlowVisor) which enhances FlowVisor while overcoming its major constraints is presented and a set of experimental results discussed to demonstrate its capability to provide an effective support toward a Network Virtualization architecture. Elio Salvadori, Roberto Doriguzzi Corin, Attilio Broglio, Matteo Gerola |
GLOBECOM | 2 |
| 2011 | Is there light at the ends of the tunnel? Wireless sensor networks for adaptive lighting in road tunnels
Matteo Zella, Michele Corrà, Leandro D'Orazio, Roberto Doriguzzi Corin, Daniele Facchin, Stefan Guna, Gian Paolo Jesi, Renato Lo Cigno, Luca Mottola, Amy L. Murphy, Massimo Pescalli, Gian Pietro Picco, Denis Pregnolato, Carloalberto Torghele |
IPSN | 4 |
| 2011 | Demonstrating generalized virtual topologies in an openflow networkabstractNo abstract available. Elio Salvadori, Roberto Doriguzzi Corin, Matteo Gerola, Attilio Broglio, Francesco De Pellegrini |
SIGCOMM | 2 |