Massimiliano Albanese

dblp:01/5345 · DBLP profile ↗
← Back
42ranked-venue papers
23as first author
16since 2021 · last 2026
0000-0002-2675-5810ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 8 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 9 · 6 first-author · 2 since 2021Artificial intelligence and machine learning · 5 · 3 first-author · 2 since 2021Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 4 first-authorComputer networks · 3 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Layer-Wise Diagnostic Probing to Enhance Selectivity in Machine Unlearning
Anudeep Vurity, Zhisheng Yan, Massimiliano Albanese
ICPR (14)3
2026 Evaluating Machine Unlearning in Fingerphoto Presentation Attack Detection
Anudeep Vurity, Zhisheng Yan, Massimiliano Albanese
ICPR (14)3
2026 Optimizing IDS rule placement via set covering with capacity constraints
Domenico Ditale, Massimiliano Albanese, Preetam Mukherjee 0001
Comput. Secur.3
2025 CyberMALT: Machine Learning-Assisted Traffic Analysis for Cyber Threat Detection and Classification
abstract
Traditional methods for identifying and mitigating cyber attacks are becoming inadequate due to ever-increasing volumes of network traffic, the complexity of modern cyber threats, and the use of encryption to protect payloads. This paper presents CyberMALT, a novel approach designed to address these challenges through machine learning-assisted analysis of traffic metadata, which provides valuable insights into network behavior without examining payloads. Our proposed solution utilizes a two-stage approach. First, we employ unsupervised machine learning techniques to study typical network behavior. This initial stage allows CyberMALT to establish a baseline understanding of typical traffic characteristics, enabling it to identify deviations indicative of potential threats. Leveraging this knowledge, CyberMALT computes an anomaly score for each observed traffic instance, thereby pinpointing suspicious activity for further investigation. In the second stage of processing, these identified anomalies undergo a comprehensive analysis to classify the types of attacks accurately and efficiently and rule out false positives. By leveraging machine learning for traffic metadata analysis, CyberMALT offers a proactive and adaptive solution for cyber threat detection and classification. Our experiments demonstrate the effectiveness of CyberMALT in identifying and classifying diverse cyber threats while minimizing false positives, thus enhancing the security posture of networked systems.
Domenico Ditale, Massimiliano Albanese, Kun Sun 0001, Jianli Pan
CCNC2
2024 Utilizing Online Learning for Both Defense and DoS Attacks in CPS: A Repeated Game Approach
abstract
We study the security aspects of remote state estimation within Cyber-Physical Systems (CPSs), where a sensor transmits its measurements to a remote state estimator over a multi-channel wireless link amidst a Denial-of-Service (DoS) attack. Existing literature primarily focuses on sensor defense schemes against non-adaptive DoS attackers, relying on prior knowledge of the attacker’s strategy alongside limited channel sensing capabilities. These studies assume either stationary or heuristic behavior from one party while exploring countermeasures from the other. To relax this constraint, we propose that both sensors and attackers employ online learning-based policies to select channels for packet transmission and for emitting jamming signals, respectively. We formulate the problem as an online learning-based repeated two-player constant-sum game, aiming to examine the stability of the remote state estimator. First, we show that both the sensor’s and attacker’s channel selection strategies adapt to each other, resulting in mutually optimal responses in the infinite-horizon scenario. Furthermore, we establish the asymptotic stability condition of the remote state estimator with respect to the number of wireless communication channels and the CPS critical value. Finally, we extend our analysis to scenarios where the DoS attacker targets more than one channel simultaneously, identifying the function by which the estimator’s stability region contracts as the number of attacked channels increases. Through extensive numerical evaluations under various CPS parameters, we analyze the mutual behavior of both entities and validate our analytical findings.
Amir Alipour-Fanid, Thabet Kacem, Monireh Dabaghchian, Massimiliano Albanese
GLOBECOM4
2024 CVE2CWE: Automated Mapping of Software Vulnerabilities to Weaknesses Based on CVE Descriptions
Massimiliano Albanese, Olutola Adebiyi, Frank Onovae
SECRYPT1
2024 DISC: A Dataset for Information Security Classification
Elijah Bass, Massimiliano Albanese, Marcos Zampieri
SECRYPT2
2024 Classifying Human-Generated and AI-Generated Election Claims in Social Media
Alphaeus Dmonte, Marcos Zampieri, Kevin Lybarger, Massimiliano Albanese, Genya Coulter
SECRYPT4
2024 Improving the Efficiency of Intrusion Detection Systems by Optimizing Rule Deployment Across Multiple IDSs
Massimiliano Albanese, Preetam Mukherjee 0001, Amir Alipour-Fanid
SECRYPT2
2024 Resilience and performance quantification of dynamic reconfiguration
Sarah Alhozaimy, Daniel A. Menascé, Massimiliano Albanese
Future Gener. Comput. Syst.3
2023 Towards Usable Scoring of Common Weaknesses
Olutola Adebiyi, Massimiliano Albanese
SECRYPT2
2023 A framework for designing vulnerability metrics
Massimiliano Albanese, Ibifubara Iganibo, Olutola Adebiyi
Comput. Secur.1
2022 A Formal Model for Credential Hopping Attacks
Massimiliano Albanese, Karin Johnsgard, Vipin Swarup
ESORICS (1)1
2022 Mason Vulnerability Scoring Framework: A Customizable Framework for Scoring Common Vulnerabilities and Weaknesses
Ibifubara Iganibo, Massimiliano Albanese, Kaan Turkmen, Thomas R. Campbell, Marc Mosko
SECRYPT2
2021 Vulnerability Metrics for Graph-based Configuration Security
Ibifubara Iganibo, Massimiliano Albanese, Marc Mosko, Eric Bier, Alejandro E. Brito
SECRYPT2
2021 Performance Modeling of Moving Target Defenses with Reconfiguration Limits
abstract
Moving Target Defense (MTD) has recently emerged as a game changer in the security landscape due to its proven potential to introduce asymmetric uncertainty that gives the defender a tactical advantage over the attacker. Many different MTD techniques have been developed, but, despite the huge progress made in this area, critical gaps still exist with respect to the problem of studying and quantifying the cost and benefits of deploying MTDs. In fact, all existing techniques address a very narrow set of attack vectors, and, due to the lack of shared metrics, it is difficult to quantify and compare multiple techniques. Building on our preliminary work in this field, we propose a quantitative analytic model for assessing the resource availability and performance of MTDs, and a method for maximizing a utility function that captures the tradeoffs between security and performance. The proposed model generalizes our previous model and can be applied to a wider range of MTDs and operational scenarios to improve availability and performance by imposing limits on the maximum number of resources that can be in the process of being reconfigured. The analytic results are validated by simulation and experimentation, confirming the accuracy of our model.
Warren Connell, Daniel A. Menascé, Massimiliano Albanese
IEEE Trans. Dependable Secur. Comput.3
2020 Security and trust in cloud application life-cycle management
Massimiliano Albanese, Alessandra De Benedictis, Douglas Dyllon Jeronimo de Macedo, Fabrizio Messina
Future Gener. Comput. Syst.1
2018 MTD 2018: 5th ACM Workshop on Moving Target Defense (MTD)
abstract
The objective of the 5th ACM Workshop on Moving Target Defense (MTD 2018) - held in Toronto, Canada on October 15, 2018, in conjunction with the 24th ACM Conference on Computer and Communications Security (ACM CCS 2018) - is to bring together researchers from academia, government, and industry to discuss novel randomization, diversification, and dynamism techniques for improving the security of computer systems and network, and new metric and analytical frameworks to assess and quantify the effectiveness of MTD techniques. As in previous editions, the 2018 workshop offers a forum to discuss the challenges and opportunities that such defenses provide. We have assembled an exciting and diverse program including nine refereed papers and one invited keynote talk that will provide participants with a vibrant and thought-provoking set of ideas and insights.
Massimiliano Albanese, Dijiang Huang
CCS1
2018 Measuring the Effectiveness of Network Deception
abstract
Cyber reconnaissance is the process of gathering information about a target network for the purpose of compromising systems within that network. Network-based deception has emerged as a promising approach to disrupt attackers' reconnaissance efforts. However, limited work has been done so far on measuring the effectiveness of network-based deception. Furthermore, given that Software-Defined Networking (SDN) facilitates cyber deception by allowing network traffic to be modified and injected on-the-fly, understanding the effectiveness of employing different cyber deception strategies is critical. In this paper, we present a model to study the reconnaissance surface of a network and model the process of gathering information by attackers as interactions with a cyber defensive system that may use deception. To capture the evolution of the attackers' knowledge during reconnaissance, we design a belief system that is updated by using a Bayesian inference method. For the proposed model, we present two metrics based on KL-divergence to quantify the effectiveness of network deception. We tested the model and the two metrics by conducting experiments with a simulated attacker in an SDN-based deception system. The results of the experiments match our expectations, providing support for the model and proposed metrics.
Shridatt Sugrim, Sridhar Venkatesan, Jason A. Youzwak, C. Jason Chiang, Ritu Chadha, Massimiliano Albanese, Hasan Çam
ISI6
2017 A Framework for Moving Target Defense Quantification
Warren Connell, Massimiliano Albanese, Sridhar Venkatesan
SEC2
2016 Network Diversity: A Security Metric for Evaluating the Resilience of Networks Against Zero-Day Attacks
abstract
Diversity has long been regarded as a security mechanism for improving the resilience of software and networks against various attacks. More recently, diversity has found new applications in cloud computing security, moving target defense, and improving the robustness of network routing. However, most existing efforts rely on intuitive and imprecise notions of diversity, and the few existing models of diversity are mostly designed for a single system running diverse software replicas or variants. At a higher abstraction level, as a global property of the entire network, diversity and its effect on security have received limited attention. In this paper, we take the first step toward formally modeling network diversity as a security metric by designing and evaluating a series of diversity metrics. In particular, we first devise a biodiversity-inspired metric based on the effective number of distinct resources. We then propose two complementary diversity metrics, based on the least and the average attacking efforts, respectively. We provide guidelines for instantiating the proposed metrics and present a case study on estimating software diversity. Finally, we evaluate the proposed metrics through simulation.
Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese
IEEE Trans. Inf. Forensics Secur.5
2014 Modeling Network Diversity for Evaluating the Robustness of Networks against Zero-Day Attacks
Lingyu Wang 0001, Mengyuan Zhang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese
ESORICS (2)5
2014 Keeping Intruders at Large - A Graph-theoretic Approach to Reducing the Probability of Successful Network Intrusions
abstract
It is well known that not all intrusions can be prevented and additional lines of defense are needed to deal with intruders. However, most current approaches use honeynets relying on the assumption that simply attracting intruders into honeypots would thwart the attack. In this paper, we propose a different and more realistic approach, which aims at delaying intrusions, so as to control the probability that an intruder will reach a certain goal within a specified amount of time. Our method relies on analyzing a graphical representation of the computer network’s logical layout and an associated probabilistic model of the adversary’s behavior. We then artificially modify this representation by adding “distraction clusters” – collections of interconnected virtual machines – at key points of the network in order to increase complexity for the intruders and delay the intrusion. We study this problem formally, showing it to be NP-hard and then provide an approximation algo- rithm that exhibits several useful properties. Finally, we present experimental results obtained on a prototypal implementation of the proposed framework.
Paulo Shakarian, Damon Paulo, Massimiliano Albanese, Sushil Jajodia
SECRYPT3
2014 A probabilistic framework for jammer identification in MANETs
Massimiliano Albanese, Alessandra De Benedictis, Sushil Jajodia, Don J. Torrieri
Ad Hoc Networks1
2014 Discovering the Top-k Unexplained Sequences in Time-Stamped Observation Data
abstract
There are numerous applications where we wish to discover unexpected activities in a sequence of time-stamped observation data--for instance, we may want to detect inexplicable events in transactions at a website or in video of an airport tarmac. In this paper, we start with a known set $({\cal A})$ of activities (both innocuous and dangerous) that we wish to monitor. However, in addition, we wish to identify "unexplained" subsequences in an observation sequence that are poorly explained (e.g., because they may contain occurrences of activities that have never been seen or anticipated before, i.e., they are not in $({\cal A})$). We formally define the probability that a sequence of observations is unexplained (totally or partially) w.r.t. $({\cal A})$. We develop efficient algorithms to identify the top-$(k)$ Totally and partially unexplained sequences w.r.t. $({\cal A})$. These algorithms leverage theorems that enable us to speed up the search for totally/partially unexplained sequences. We describe experiments using real-world video and cyber-security data sets showing that our approach works well in practice in terms of both running time and accuracy.
Massimiliano Albanese, Cristian Molinaro, Fabio Persia, Antonio Picariello, V. S. Subrahmanian
IEEE Trans. Knowl. Data Eng.1
2013 Measuring Trust in Big Data
Massimiliano Albanese
ICA3PP (2)1
2013 An Efficient Approach to Assessing the Risk of Zero-Day Vulnerabilities
Massimiliano Albanese, Sushil Jajodia, Anoop Singhal, Lingyu Wang 0001
SECRYPT1
2013 Fast Activity Detection: Indexing for Temporal Stochastic Automaton-Based Activity Models
abstract
Today, numerous applications require the ability to monitor a continuous stream of fine-grained data for the occurrence of certain high-level activities. A number of computerized systems-including ATM networks, web servers, and intrusion detection systems-systematically track every atomic action we perform, thus generating massive streams of timestamped observation data, possibly from multiple concurrent activities. In this paper, we address the problem of efficiently detecting occurrences of high-level activities from such interleaved data streams. A solution to this important problem would greatly benefit a broad range of applications, including fraud detection, video surveillance, and cyber security. There has been extensive work in the last few years on modeling activities using probabilistic models. In this paper, we propose a temporal probabilistic graph so that the elapsed time between observations also plays a role in defining whether a sequence of observations constitutes an activity. We first propose a data structure called “temporal multiactivity graph” to store multiple activities that need to be concurrently monitored. We then define an index called Temporal Multiactivity Graph Index Creation (tMAGIC) that, based on this data structure, examines and links observations as they occur. We define algorithms for insertion and bulk insertion into the tMAGIC index and show that this can be efficiently accomplished. We also define algorithms to solve two problems: the “evidence” problem that tries to find all occurrences of an activity (with probability over a threshold) within a given sequence of observations, and the “identification” problem that tries to find the activity that best matches a sequence of observations. We introduce complexity reducing restrictions and pruning strategies to make the problem-which is intrinsically exponential-linear to the number of observations. Our experiments confirm that tMAGIC has time and space complexity linear to the size of the input, and can efficiently retrieve instances of the monitored activities.
Massimiliano Albanese, Andrea Pugliese 0001, V. S. Subrahmanian
IEEE Trans. Knowl. Data Eng.1
2013 A Multimedia Recommender System
abstract
The extraordinary technological progress we have witnessed in recent years has made it possible to generate and exchange multimedia content at an unprecedented rate. As a consequence, massive collections of multimedia objects are now widely available to a large population of users. As the task of browsing such large collections could be daunting, Recommender Systems are being developed to assist users in finding items that match their needs and preferences. In this article, we present a novel approach to recommendation in multimedia browsing systems, based on modeling recommendation as a social choice problem. In social choice theory, a set of voters is called to rank a set of alternatives, and individual rankings are aggregated into a global ranking. In our formulation, the set of voters and the set of alternatives both coincide with the set of objects in the data collection. We first define what constitutes a choice in the browsing domain and then define a mechanism to aggregate individual choices into a global ranking. The result is a framework for computing customized recommendations by originally combining intrinsic features of multimedia objects, past behavior of individual users, and overall behavior of the entire community of users. Recommendations are ranked using an importance ranking algorithm that resembles the well-known PageRank strategy. Experiments conducted on a prototype of the proposed system confirm the effectiveness and efficiency of our approach.
Massimiliano Albanese, Antonio d'Acierno, Vincenzo Moscato, Fabio Persia, Antonio Picariello
ACM Trans. Internet Techn.1
2012 Time-efficient and cost-effective network hardening using attack graphs
abstract
Attack graph analysis has been established as a powerful tool for analyzing network vulnerability. However, previous approaches to network hardening look for exact solutions and thus do not scale. Further, hardening elements have been treated independently, which is inappropriate for real environments. For example, the cost for patching many systems may be nearly the same as for patching a single one. Or patching a vulnerability may have the same effect as blocking traffic with a firewall, while blocking a port may deny legitimate service. By failing to account for such hardening interdependencies, the resulting recommendations can be unrealistic and far from optimal. Instead, we formalize the notion of hardening strategy in terms of allowable actions, and define a cost model that takes into account the impact of interdependent hardening actions. We also introduce a near-optimal approximation algorithm that scales linearly with the size of the graphs, which we validate experimentally.
Massimiliano Albanese, Sushil Jajodia, Steven Noel
DSN1
2012 A Probabilistic Framework for Localization of Attackers in MANETs
Massimiliano Albanese, Alessandra De Benedictis, Sushil Jajodia, Paulo Shakarian
ESORICS1
2011 Scalable Analysis of Attack Scenarios
Massimiliano Albanese, Sushil Jajodia, Andrea Pugliese 0001, V. S. Subrahmanian
ESORICS1
2011 Finding "Unexplained" Activities in Video
abstract
Consider a video surveillance application that monitors some location. The application knows a set of activity models (that are either normal or abnormal or both), but in addition, the application wants to find video segments that are unexplained by any of the known activity models - these unexplained video segments may correspond to activities for which no previous activity model existed. In this paper, we formally define what it means for a given video segment to be unexplained (totally or partially) w.r.t. a given set of activity models and a probability threshold. We develop two algorithms - FindTUA and FindPUA - to identify Totally and Partially Unexplained Activities respectively, and show that both algorithms use important pruning methods. We report on experiments with a prototype implementation showing that the algorithms both run efficiently and are accurate.
Massimiliano Albanese, Cristian Molinaro, Fabio Persia, Antonio Picariello, V. S. Subrahmanian
IJCAI1
2010 Modeling recommendation as a social choice problem
abstract
In the classical theory of social choice, a set of voters is called to rank a set of alternatives and a social ranking of the alternatives is generated. In this paper, we model recommendation in the context of browsing systems as a social choice problem, where the set of voters and the set of alternatives both coincide with the set of objects in the data collection. We then propose an importance ranking method that strongly resembles the well known PageRank ranking system, and takes into account both the browsing behavior of the users and the intrinsic features of the objects in the collection. We apply the proposed approach in the context of multimedia browsing systems and show that it can generate effective recommendations and can scale well for large data collections.
Massimiliano Albanese, Antonio d'Acierno, Vincenzo Moscato, Fabio Persia, Antonio Picariello
RecSys1
2010 A multimedia recommender integrating object features and user behavior
Massimiliano Albanese, Angelo Chianese, Antonio d'Acierno, Vincenzo Moscato, Antonio Picariello
Multim. Tools Appl.1
2010 PADS: A Probabilistic Activity Detection Framework for Video Data
abstract
There is now a growing need to identify various kinds of activities that occur in videos. In this paper, we first present a logical language called Probabilistic Activity Description Language (PADL) in which users can specify activities of interest. We then develop a probabilistic framework which assigns to any subvideo of a given video sequence a probability that the subvideo contains the given activity, and we finally develop two fast algorithms to detect activities within this framework. OffPad finds all minimal segments of a video that contain a given activity with a probability exceeding a given threshold. In contrast, the OnPad algorithm examines a video during playout (rather than afterwards as OffPad does) and computes the probability that a given activity is occurring (even if the activity is only partially complete). Our prototype Probabilistic Activity Detection System (PADS) implements the framework and the two algorithms, building on top of existing image processing algorithms. We have conducted detailed experiments and compared our approach to four different approaches presented in the literature. We show that-for complex activity definitions-our approach outperforms all the other approaches.
Massimiliano Albanese, Rama Chellappa, Naresh P. Cuntoor, Vincenzo Moscato, Antonio Picariello, V. S. Subrahmanian, Octavian Udrea
IEEE Trans. Pattern Anal. Mach. Intell.1
2008 A Constrained Probabilistic Petri Net Framework for Human Activity Detection in Video
abstract
Recognition of human activities in restricted settings such as airports, parking lots and banks is of significant interest in security and automated surveillance systems. In such settings, data is usually in the form of surveillance videos with wide variation in quality and granularity. Interpretation and identification of human activities requires an activity model that a) is rich enough to handle complex multi-agent interactions, b) is robust to uncertainty in low-level processing and c) can handle ambiguities in the unfolding of activities. We present a computational framework for human activity representation based on Petri nets. We propose an extension-Probabilistic Petri Nets (PPN)-and show how this model is well suited to address each of the above requirements in a wide variety of settings. We then focus on answering two types of questions: (i) what are the minimal sub-videos in which a given activity is identified with a probability above a certain threshold and (ii) for a given video, which activity from a given set occurred with the highest probability? We provide the PPN-MPS algorithm for the first problem, as well as two different algorithms (naive PPN-MPA and PPN-MPA) to solve the second. Our experimental results on a dataset consisting of bank surveillance videos and an unconstrained TSA tarmac surveillance dataset show that our algorithms are both fast and provide high quality results.
Massimiliano Albanese, Rama Chellappa, Naresh P. Cuntoor, Vincenzo Moscato, Antonio Picariello, V. S. Subrahmanian, Octavian Udrea
IEEE Trans. Multim.1
2008 A Constrained Probabilistic Petri Net Framework for Human Activity Detection in Video
abstract
Recognition of human activities in restricted settings such as airports, parking lots and banks is of significant interest in security and automated surveillance systems. In such settings, data is usually in the form of surveillance videos with wide variation in quality and granularity. Interpretation and identification of human activities requires an activity model that a) is rich enough to handle complex multi-agent interactions, b) is robust to uncertainty in low-level processing and c) can handle ambiguities in the unfolding of activities. We present a computational framework for human activity representation based on Petri nets. We propose an extension—Probabilistic Petri Nets (PPN)—and show how this model is well suited to address each of the above requirements in a wide variety of settings. We then focus on answering two types of questions: (i) what are the minimal sub-videos in which a given activity is identified with a probability above a certain threshold and (ii) for a given video, which activity from a given set occurred with the highest probability? We provide the PPN-MPS algorithm for the first problem, as well as two different algorithms (naive PPN-MPA and PPN-MPA) to solve the second. Our experimental results on a dataset consisting of bank surveillance videos and an unconstrained TSA tarmac surveillance dataset show that our algorithms are both fast and provide high quality results.
Massimiliano Albanese, Rama Chellappa, Naresh P. Cuntoor, Vincenzo Moscato, Antonio Picariello, V. S. Subrahmanian, Octavian Udrea
IEEE Trans. Multim.1
2007 Detecting Stochastically Scheduled Activities in Video
Massimiliano Albanese, Vincenzo Moscato, Antonio Picariello, V. S. Subrahmanian, Octavian Udrea
IJCAI1
2007 Story creation from heterogeneous data sources
Marat Fayzullin, V. S. Subrahmanian, Massimiliano Albanese, Carmine Cesarano 0001, Antonio Picariello
Multim. Tools Appl.3
2006 The priority curve algorithm for video summarization
Massimiliano Albanese, Marat Fayzullin, Antonio Picariello, V. S. Subrahmanian
Inf. Syst.1
2004 A Formal Model for Video Shot Segmentation and its Application via Animate Vision
Massimiliano Albanese, Angelo Chianese, Vincenzo Moscato, Lucio Sansone
Multim. Tools Appl.1