Marco Zanella

dblp:140/0821 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 3 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Computer networks · 1Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Exact Robustness Certification of k-Nearest Neighbors
abstract
Robustness guarantees are essential for deploying machine learning models in security-critical environments where adversarial attacks pose a serious threat. While extensive progress has been made in certifying (deep) neural networks, nonparametric models such as k-Nearest Neighbors (k-NN) have been less investigated, despite their interpretability and usage in high-assurance settings. Prior certification methods for k-NN provide sound but incomplete guarantees, leaving many genuinely robust inputs uncertified. This work introduces a sound and complete certification framework for k-NN classifiers, offering exact robustness guarantees against adversarial perturbations. Our approach combines hypercube space decomposition with a novel graph-theoretic analysis based on an adversarial proximity precedence graph, enabling full coverage of adversarial regions. Extensive evaluation on widely used datasets demonstrates that our exact methodology significantly improves certification rates over existing techniques while maintaining scalability. By closing the gap between soundness and completeness, our framework advances the security guarantees of k-NN models and contributes to the broader goal of provably robust machine learning in adversarial settings.
Francesco Ranzato, Ahmad Shakeel, Marco Zanella
CCS3
2025 Generating Synthetic Data with Large Language Models for Low-Resource Sentence Retrieval
Davide Caffagni, Federico Cocchi, Anna Mambelli, Fabio Tutrone, Marco Zanella, Marcella Cornia, Rita Cucchiara
TPDL5
2024 Abstract Interpretation-Based Feature Importance for Support Vector Machines
Abhinandan Pal, Francesco Ranzato, Caterina Urban, Marco Zanella
VMCAI (1)4
2024 Robustness verification of k-nearest neighbors by abstract interpretation
abstract
Abstract We study the certification of stability properties, such as robustness and individual fairness, of the k-nearest neighbor algorithm (kNN). Our approach leverages abstract interpretation, a well-established program analysis technique that has been proven successful in verifying several machine learning algorithms, notably, neural networks, decision trees, and support vector machines. In this work, we put forward an abstract interpretation-based framework for designing a sound approximate version of the kNN algorithm, which is instantiated to the interval and zonotope abstractions for approximating the range of numerical features. We show how this abstraction-based method can be used for stability, robustness, and individual fairness certification of kNN. Our certification technique has been implemented and experimentally evaluated on several benchmark datasets. These experimental results show that our tool can formally prove the stability of kNN classifiers in a precise and efficient way, thus expanding the range of machine learning models amenable to robustness certification.
Nicolò Fassina, Francesco Ranzato, Marco Zanella
Knowl. Inf. Syst.3
2023 Robustness Certification of k-Nearest Neighbors
abstract
We study the certification of stability properties, such as robustness and individual fairness, of the k-Nearest Neighbor algorithm (kNN). Our approach leverages abstract interpretation, a well-established program analysis technique that has been proven successful in verifying several machine learning algorithms, notably, neural networks, decision trees, and support vector machines. In this work, we put forward an abstract interpretation-based framework for designing a sound approximate version of the kNN algorithm, which is instantiated to the interval and zonotope abstractions for approximating the range of numerical features. We show how this abstraction-based method can be used for stability, robustness, and individual fairness certification of kNN. Our certification technique has been implemented and experimentally evaluated on several benchmark datasets. These experimental results show that our tool can formally prove the stability of kNN classifiers in a precise and efficient way, thus expanding the range of machine learning models amenable to robustness certification.
Nicolò Fassina, Francesco Ranzato, Marco Zanella
ICDM3
2021 Fairness-Aware Training of Decision Trees by Abstract Interpretation
abstract
We study the problem of formally verifying individual fairness of decision tree ensembles, as well as training tree models which maximize both accuracy and individual fairness. In our approach, fairness verification and fairness-aware training both rely on a notion of stability of a classifier, which is a generalization of the standard notion of robustness to input perturbations used in adversarial machine learning. Our verification and training methods leverage abstract interpretation, a well-established mathematical framework for designing computable, correct, and precise approximations of potentially infinite behaviors. We implemented our fairness-aware learning method by building on a tool for adversarial training of decision trees. We evaluated it in practice on the reference datasets in the literature on fairness in machine learning. The experimental results show that our approach is able to train tree models exhibiting a high degree of individual fairness with respect to the natural state-of-the-art CART trees and random forests. Moreover, as a by-product, these fairness-aware decision trees turn out to be significantly compact, which naturally enhances their interpretability.
Francesco Ranzato, Caterina Urban, Marco Zanella
CIKM3
2021 Genetic adversarial training of decision trees
abstract
We put forward a novel learning methodology for ensembles of decision trees based on a genetic algorithm that is able to train a decision tree for maximizing both its accuracy and its robustness to adversarial perturbations. This learning algorithm internally leverages a complete formal verification technique for robustness properties of decision trees based on abstract interpretation, a well-known static program analysis technique. We implemented this genetic adversarial training algorithm in a tool called MetaSilvae and we experimentally evaluated it on some standard reference datasets used in adversarial training. The experimental results show that MetaSilvae is able to train robust models that compete with and often improve on the current state-of-the-art of adversarial training of decision trees while being much more compact and therefore interpretable and efficient tree models.
Francesco Ranzato, Marco Zanella
GECCO2
2020 Abstract Interpretation of Decision Tree Ensemble Classifiers
Francesco Ranzato, Marco Zanella
AAAI2
2019 Service Function Chaining: a lightweight container-based management and orchestration plane
abstract
The increase in the amount of traffic with heterogeneous QoS requirements poses several challenges to end-to-end service provisioning. Network resource management and service differentiation are two crucial functionalities employed by service providers, proven essential in order to meet the end user requirements. In particular, application-driven networking has emerged as a viable alternative embodying the potential of enabling specific flow optimizations meeting application-specific requirements. In this context, Service Function Chaining (SFC) is seen as an enabling technology for the flexible management of specific service/application traffic. In this paradigm the network functions are seen as an ordered chain of interconnected functions handling traffic delivery (data plane), control and management. In this article we present a work in progress of a virtualized, container-based testbed with orchestration and management capabilities supporting service chains.
Armir Bujari, Claudio E. Palazzi, Davide Polonio, Marco Zanella
CCNC4
2019 Robustness Verification of Support Vector Machines
Francesco Ranzato, Marco Zanella
SAS2
2018 Invertible Linear Transforms of Numerical Abstract Domains
Francesco Ranzato, Marco Zanella
SAS2
2017 Multipong: A multiplayer ad-hoc version of Pong
abstract
Mobile games have come to revolutionize the mobile handset and gaming industry, pushing chip vendors to compete in order to provide better and better graphics capabilities by means of dedicated processors. This capability coupled with the sensing and communication ability offered by smartphones, provides the developers with the building blocks for innovative gaming solutions. In particular, multiplayer mobile games could exploit context and proximity information, providing an added value to the gaming experience. In this context, we present the design and analysis of a modern mobile and multiplayer version of the classic Pong game. In addition to the classic interaction model through remote server(s), players could interact and play locally by exploiting ad-hoc connectivity offered by the Wi-Fi Direct technology.
Marco Begolo, Sebastiano Valle, Marco Zanella, Armir Bujari, Ombretta Gaggi, Claudio E. Palazzi
ISCC3
2013 Benchmarking GPUs with a Parallel Lattice-Boltzmann Code
abstract
Accelerators are an increasingly common option to boost performance of codes that require extensive number crunching. In this paper we report on our experience with NVIDIA accelerators to study fluid systems using the Lattice Boltzmann (LB) method. The regular structure of LB algorithms makes them suitable for processor architectures with a large degree of parallelism, such as recent multi- and many-core processors and GPUs; however, the challenge of exploiting a large fraction of the theoretically available performance of this new class of processors is not easily met. We consider a state-of-theart two-dimensional LB model based on 37 populations (a D2Q37 model), that accurately reproduces the thermo-hydrodynamics of a 2D-fluid obeying the equation-of-state of a perfect gas. The computational features of this model make it a significant benchmark to analyze the performance of new computational platforms, since critical kernels in this code require both high memory-bandwidth on sparse memory addressing patterns and floating-point throughput. In this paper we consider two recent classes of GPU boards based on the Fermi and Kepler architectures; we describe in details all steps done to implement and optimize our LB code and analyze its performance first on single- GPU systems, and then on parallel multi-GPU systems based on one node as well as on a cluster of many nodes; in the latter case we use CUDA-aware MPI as an abstraction layer to assess the advantages of advanced GPU-to-GPU communication technologies like GPUDirect. On our implementation, aggregate sustained performance of the most compute intensive part of the code breaks the 1 double-precision Tflops barrier on a single-host system with two GPUs.
Jiri Kraus, Marcello Pivanti, Sebastiano Fabio Schifano, Raffaele Tripiccione, Marco Zanella
SBAC-PAD5