Damiano Torre

dblp:96/7337 · DBLP profile ↗
← Back
15ranked-venue papers
12as first author
7since 2021 · last 2025
0000-0002-1656-3057ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 15 · 12 first-author · 7 since 2021
YearPublicationVenuePosition
2025 Toward Real-Time Intrusion Detection for Autonomous Vehicles: A Vision for Deep Learning-Based Security Frameworks
abstract
Background: AI-driven autonomous vehicles (AVs) combine machine learning, control systems, and embedded technologies, creating significant software engineering challenges, especially in securing cyber-physical systems. Intrusion Detection Systems (IDS) are essential for detecting anomalies and cyberattacks in real time, thereby safeguarding AV operations. Aims: This vision paper aims to design and implement deep learning-based IDSs specifically tailored for real-time anomaly detection in autonomous drones, cars, and robots. Method: The approach begins with the development of platform-specific taxonomies of AV software vulnerabilities and a formal threat model. Controlled experiments will then be conducted using both physical aerial and ground vehicles, as well as industrial-grade simulators, in network-connected and isolated environments to generate labeled datasets of AV anomalies. These datasets will be used to design, train, and customize IDSs for each AV platform, which will subsequently be deployed on physical devices for evaluation under realistic conditions. Results: The work is expected to produce comprehensive taxonomies of AV software vulnerabilities, multiple labeled datasets capturing both normal and compromised AV behaviors, and a set of validated, deployable IDS frameworks tailored to various AV platforms. Conclusions: This study addresses core empirical software engineering challenges, such as the sim-to-real transfer gap in machine learning, risks of overfitting in data-driven IDS models, and hardware-software integration complexities. The anticipated outcome is a robust family of IDS solutions that enhance AV security in dynamic operational environments.
Damiano Torre, Amirpasha Javid
ESEM1
2025 Toward Enhancing Privacy Preservation of a Federated Learning CNN Intrusion Detection System in IoT: Method and Empirical Study
abstract
Enormous risks and hidden dangers of information security exist in the applications of Internet of Things (IoT) technologies. To secure IoT software systems, software engineers have to deploy advanced security software such as Intrusion Detection Systems (IDS) that are able to keep track of how the IoT devices behave within the network and detect any malicious activity that may be occurring. Considering that IoT devices generate large amounts of data, Artificial Intelligence (AI) is often regarded as the best method for implementing IDS, thanks to AI’s high capability in processing large amounts of IoT data. To tackle these security concerns, specifically the ones tied to the privacy of data used in IoT systems, the software implementation of a Federated Learning (FL) method is often used to improve both privacy preservation (PP) and scalability in IoT networks. In this article, we present an FL IDS that leverages a 1-Dimensional Convolutional Neural Network (CNN) for efficient and accurate intrusion detection in IoT networks. To address the critical issue of PP in FL, we incorporate three techniques: Differential Privacy, Diffie–Hellman Key Exchange, and Homomorphic Encryption. To evaluate the effectiveness of our solution, we conduct experiments on seven publicly available IoT datasets: TON-IoT, IoT-23, BoT-IoT, CIC IoT 2023, CIC IoMT 2024, RT-IoT 2022, and EdgeIIoT. Our CNN-based approach achieves outstanding performance with an average accuracy, precision, recall, and F1-score of 97.31%, 95.59%, 92.43%, and 92.69%, respectively, across these datasets. These results demonstrate the effectiveness of our approach in accurately identifying and detecting intrusions in IoT networks. Furthermore, our experiments reveal that implementing all three PP techniques only incurs a minimal increase in computation time, with a 10% overhead compared to our solution without any PP mechanisms. This finding highlights the feasibility and efficiency of our solution in maintaining privacy while achieving high performance. Finally, we show the effectiveness of our solution through a comparison study with other recent IDS trained and tested on the same datasets we use.
Damiano Torre, Anitha Chennamaneni, JaeYun Jo, Gitika Vyas, Brandon Sabrsula
ACM Trans. Softw. Eng. Methodol.1
2023 Deep learning techniques to detect cybersecurity attacks: a systematic mapping study
Damiano Torre, Frantzy Mesadieu, Anitha Chennamaneni
Empir. Softw. Eng.1
2023 How consistency is handled in model-driven software engineering and UML: an expert opinion survey
Damiano Torre, Marcela Genero, Yvan Labiche, Maged Elaasar
Softw. Qual. J.1
2022 AI-Enabled Automation for Completeness Checking of Privacy Policies
abstract
Technological advances in information sharing have raised concerns about data protection. Privacy policies contain privacy-related requirements about how the personal data of individuals will be handled by an organization or a software system (e.g., a web service or an app). In Europe, privacy policies are subject to compliance with the General Data Protection Regulation (GDPR). A prerequisite for GDPR compliance checking is to verify whether the content of a privacy policy is complete according to the provisions of GDPR. Incomplete privacy policies might result in large fines on violating organization as well as incomplete privacy-related software specifications. Manual completeness checking is both time-consuming and error-prone. In this paper, we propose AI-based automation for the completeness checking of privacy policies. Through systematic qualitative methods, we first build two artifacts to characterize the privacy-related provisions of GDPR, namely a conceptual model and a set of completeness criteria. Then, we develop an automated solution on top of these artifacts by leveraging a combination of natural language processing and supervised machine learning. Specifically, we identify the GDPR-relevant information content in privacy policies and subsequently check them against the completeness criteria. To evaluate our approach, we collected 234 real privacy policies from the fund industry. Over a set of 48 unseen privacy policies, our approach detected 300 of the total of 334 violations of some completeness criteria correctly, while producing 23 false positives. The approach thus has a precision of 92.9% and recall of 89.8%. Compared to a baseline that applies keyword search only, our approach results in an improvement of 24.5% in precision and 38% in recall.
Orlando Amaral, Sallam Abualhaija, Damiano Torre, Mehrdad Sabetzadeh, Lionel C. Briand
IEEE Trans. Software Eng.3
2021 On systematically building a controlled natural language for functional requirements
abstract
Natural language (NL) is pervasive in software requirements specifications (SRSs). However, despite its popularity and widespread use, NL is highly prone to quality issues such as vagueness, ambiguity, and incompleteness. Controlled natural languages (CNLs) have been proposed as a way to prevent quality problems in requirements documents, while maintaining the flexibility to write and communicate requirements in an intuitive and universally understood manner. In collaboration with an industrial partner from the financial domain, we systematically develop and evaluate a CNL, named Rimay, intended at helping analysts write functional requirements. We rely on Grounded Theory for building Rimay and follow well-known guidelines for conducting and reporting industrial case study research. Our main contributions are: (1) a qualitative methodology to systematically define a CNL for functional requirements; this methodology is intended to be general for use across information-system domains, (2) a CNL grammar to represent functional requirements; this grammar is derived from our experience in the financial domain, but should be applicable, possibly with adaptations, to other information-system domains, and (3) an empirical evaluation of our CNL (Rimay) through an industrial case study. Our contributions draw on 15 representative SRSs, collectively containing 3215 NL requirements statements from the financial domain. Our evaluation shows that Rimay is expressive enough to capture, on average, 88% (405 out of 460) of the NL requirements statements in four previously unseen SRSs from the financial domain.
Alvaro Veizaga, Mauricio Alférez, Damiano Torre, Mehrdad Sabetzadeh, Lionel C. Briand
Empir. Softw. Eng.3
2021 Modeling data protection and privacy: application and experience with GDPR
Damiano Torre, Mauricio Alférez, Ghanem Soltana, Mehrdad Sabetzadeh, Lionel C. Briand
Softw. Syst. Model.1
2020 Leveraging natural-language requirements for deriving better acceptance criteria from models
abstract
In many software and systems development projects, analysts specify requirements using a combination of modeling and natural language (NL). In such situations, systematic acceptance testing poses a challenge because defining the acceptance criteria (AC) to be met by the system under test has to account not only for the information in the (requirements) model but also that in the NL requirements. In other words, neither models nor NL requirements per se provide a complete picture of the information content relevant to AC. Our work in this paper is prompted by the observation that a reconciliation of the information content in NL requirements and models is necessary for obtaining precise AC. We perform such reconciliation by devising an approach that automatically extracts AC-related information from NL requirements and helps modelers enrich their model with the extracted information. An existing AC derivation technique is then applied to the model that has now been enriched by the information extracted from NL requirements.
Alvaro Veizaga, Mauricio Alférez, Damiano Torre, Mehrdad Sabetzadeh, Lionel C. Briand, Elene Pitskhelauri
MoDELS3
2020 An AI-assisted Approach for Checking the Completeness of Privacy Policies Against GDPR
abstract
Privacy policies are critical for helping individuals make informed decisions about their personal data. In Europe, privacy policies are subject to compliance with the General Data Protection Regulation (GDPR). If done entirely manually, checking whether a given privacy policy complies with GDPR is both time-consuming and error-prone. Automated support for this task is thus advantageous. At the moment, there is an evident lack of such support on the market. In this paper, we tackle an important dimension of GDPR compliance checking for privacy policies. Specifically, we provide automated support for checking whether the content of a given privacy policy is complete according to the provisions stipulated by GDPR. To do so, we present: (1) a conceptual model to characterize the information content envisaged by GDPR for privacy policies, (2) an AI-assisted approach for classifying the information content in GDPR privacy policies and subsequently checking how well the classified content meets the completeness criteria of interest; and (3) an evaluation of our approach through a case study over 24 unseen privacy policies. For classification, we leverage a combination of Natural Language Processing and supervised Machine Learning. Our experimental material is comprised of 234 real privacy policies from the fund industry. Our empirical results indicate that our approach detected 45 of the total of 47 incompleteness issues in the 24 privacy policies it was applied to. Over these policies, the approach had eight false positives. The approach thus has a precision of 85% and recall of 96% over our case study.
Damiano Torre, Sallam Abualhaija, Mehrdad Sabetzadeh, Lionel C. Briand, Katrien Baetens, Peter Goes, Sylvie Forastier
RE1
2019 Using Models to Enable Compliance Checking Against the GDPR: An Experience Report
abstract
The General Data Protection Regulation (GDPR) harmonizes data privacy laws and regulations across Europe. Through the GDPR, individuals are able to better control their personal data in the face of new technological developments. While the GDPR is highly advantageous to individuals, complying with it poses major challenges for organizations that control or process personal data. Since no automated solution with broad industrial applicability currently exists for GDPR compliance checking, organizations have no choice but to perform costly manual audits to ensure compliance. In this paper, we share our experience building a UML representation of the GDPR as a first step towards the development of future automated methods for assessing compliance with the GDPR. Given that a concrete implementation of the GDPR is affected by the national laws of the EU member states, GDPR's expanding body of case law and other contextual information, we propose a two-tiered representation of the GDPR: a generic tier and a specialized tier. The generic tier captures the concepts and principles of the GDPR that apply to all contexts, whereas the specialized tier describes a specific tailoring of the generic tier to a given context, including the contextual variations that may impact the interpretation and application of the GDPR. We further present the challenges we faced in our modeling endeavor, the lessons we learned from it, and future directions for research.
Damiano Torre, Ghanem Soltana, Mehrdad Sabetzadeh, Lionel C. Briand, Yuri Auffinger, Peter Goes
MoDELS1
2018 UML diagram synthesis techniques: a systematic mapping study
abstract
Context: UML software development relies on different types of UML diagrams, which must be consistent with one another. UML Synthesis techniques suggest to generate diagram(s) from other diagram(s), thereby implicitly suggesting that input and output diagrams of the synthesis process be consistent with one another.
Damiano Torre, Yvan Labiche, Marcela Genero, Maria Teresa Baldassarre, Maged Elaasar
MiSE@ICSE1
2018 A systematic identification of consistency rules for UML diagrams
Damiano Torre, Yvan Labiche, Marcela Genero, Maged Elaasar
J. Syst. Softw.1
2014 On collecting and validating UML consistency rules: a research proposal
abstract
The main aim of my doctoral research is to create a comprehensive set of well-accepted consistency rules for UML diagrams that can be found in the literature, in reference textbooks or in the UML standard. Moreover, an important part of that aim will be the validation of the gathered UML consistency rules. This research will provide to the academic community and industrial organizations an extensive and detailed new base of knowledge about UML consistency rules which is a paramount topic in UML context. Therefore it will represent a sound starting point for all the researchers and designers involved in UML consistency.
Damiano Torre
EASE1
2014 UML consistency rules: a systematic mapping study
abstract
Context: The Unified Modeling Language (UML), with its 14 different diagram types, is the de-facto standard modeling language for object-oriented modeling and documentation. Since the various UML diagrams describe different aspects of one, and only one, software under development, they are not independent but strongly depend on each other in many ways. In other words, the UML diagrams describing a software product must be consistent. Inconsistencies between these diagrams may be a source of faults in software systems. It is therefore paramount that these inconsistencies be detected, analyzed and hopefully fixed.
Damiano Torre, Yvan Labiche, Marcela Genero
EASE1
2009 CQA-ENV: An Integrated Environment for the Continuous Quality Assessment of Software Artifacts
abstract
At present, the quality of software artefacts is an increasing concern for software development organizations. It is widely acknowledged that the quality of the software product that is finally implemented is influenced to an enormous extent by the quality of software artefacts (commonly models) that are produced throughout the software development process. Quality assessment and assurance techniques must therefore be applied from the early development stages onwards. The quality of the models is gaining even more relevance with the appearance of the Model Driven Development Model paradigm, which consists in the production of software as successive transformations of models. Although some methodologies for evaluating the quality of software artefacts do exist, all of them are isolated proposals, which focus on specific artefacts and apply specific assessment techniques. There is no generic and flexible methodology that allows the quality assessment of any kind of software artefact, regardless of type, much less a tool that supports it. When tackling this problem in this paper, we propose an integrated environment called “CQA-ENV”, consisting of a) Methodology for the continuous quality assessment of software artefacts, based on the ISO 14598 standard and other relevant proposals, 2) A set of tools that supports such methodology, which is composed of a vertical tool (CQA-Tool) that supports the methodology, along with several specific tools for the assessment of the different software artefacts. Current evaluation tools will also be able to be plugged into this generic tool. Moreover, the CQA-Tool provides a capacity for building a catalogue of assessment techniques that integrates available assessment techniques (e.g. metrics, checklists, modelling conventions, guidelines, etc.) for each software artefact. CQA-ENV can also be used by companies that offer software quality assessment services, especially for clients who are software development organisations, outsourcing software construction, thus obtaining an independent quality evaluation of the software products they acquire. Software development organisations that perform their own evaluation will be able to use it as well.
Damiano Torre, Belen Blasco, Marcela Genero, Mario Piattini
SoMeT1