Daniele Francesco Santamaria

dblp:163/2143 · DBLP profile ↗
← Back
7ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0002-4273-6521ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021Theory of computation · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Meta-Reasoning Agents Based on Narrative-Driven Inference for Mitigating Privacy Risks in Multimodal Settings
abstract
The increasing integration of intelligent systems into everyday life has amplified concerns about privacy in Human-Computer Interaction, particularly with the advent of Large Language Models (LLMs) capable of multimodal reasoning. These models, while powerful, have demonstrated vulnerabilities to privacy attacks and unintentional data leakage, especially in contexts involving visual data interpretation. In this work, we propose a novel methodology for privacy-aware planning in autonomous agents by combining image-based analysis with narrative-driven inference. Our approach is embodied in IMMAGENE, a Belief-Desire-Intention (BDI) framework that employs meta-reasoning over textual descriptions of images to inhibit the execution of agent plans when privacy risks are detected. Leveraging a cross-cultural dataset annotated for privacy sensitivity, IMMAGENE learns to identify privacy-threatening content in a cognitively grounded way. We demonstrate that, for the mentioned tasks, the proposed method largely outperforms standalone LLM-based classification in zero-shot settings. Our approach paves the way to safer data handling practices for agents that not only reason effectively in multimodal settings but also incorporate privacy-preserving mechanisms at the core of their decision-making processes.
Fabio Longo, Misael Mongiovì, Daniele Francesco Santamaria
ECAI3
2025 Human-Artificial Intelligent Threat Modelling in the Automotive Domain
abstract
We develop a comprehensive threat model for the automotive domain. It is accomplished by means of a novel, multilevel research methodology that leverages Human-Artificial Intelligence (HAI). Given the inherent complexity of threat modelling and the challenges in ensuring its completeness, the methodology combines the complementary strengths of human analysis with large language models over four phases. Each phase is structured as a sequence of two or three refinement levels so that each level iteratively enhances prior results through either human or artificial intelligence. The first phase focuses on modelling the system under analysis to establish a clear and structured baseline. The second phase addresses the elicitation of assets and associated threats, followed by a third phase in which mitigation strategies are designed. The fourth and final phase ensures that mitigation is augmented to explicitly incorporate Zero Trust, Pseudonymisation, and Data Minimisation within the context of the automotive domain. The methodology maintains its multilevel HAI structure across all phases, thereby fostering a dynamic validation loop between expert knowledge and machine-driven inference, ultimately enhancing both accuracy and coverage of the resulting threat model.
Giampaolo Bella, Gianpietro Castiglione, Sergio Esposito, Mirko Giuseppe Mangano, Giacomo Pampallona, Mario Raciti, Salvatore Riccobene, Daniele Francesco Santamaria
IOLTS8
2025 SecOnto: Ontological Representation of Security Directives
abstract
The current digital landscape demands robust security requirements and, for doing so, the institutions enact complex security directives to protect the citizens and the infrastructures, particularly in the European Union. These directives aim to safeguard data and harmonise security across the European region, and institutions must navigate this evolving legal landscape in order to implement and keep up-to-date the prescribed security measures. However, understanding and implementing these directives towards full compliance can be difficult and expensive. Ontological representation can be employed to represent and operationalise such security directives, ultimately contributing to the effectiveness and efficiency of the compliance process. Ontologies in fact promote a structured approach to represent knowledge, making the applicable directives more simply understandable by humans and more readily processable by machines. This article introduces SecOnto, a novel methodology for representing security directives as ontologies. SecOnto breaks down the process of transforming the juridical language of modern security directives into full-fledged ontologies by means of five semi-automated steps: Preprocessing, Interpretation, Structuring, Representation and Verification. Each step is described and validated by means of operational examples based upon Directive 2022/2555 of the European Parliament and of the Council of the European Union on security of network and information systems, better known as NIS 2.
Gianpietro Castiglione, Giampaolo Bella, Daniele Francesco Santamaria
Comput. Secur.3
2025 Guiding cybersecurity compliance: An ontology for the NIS 2 directive
abstract
Security compliance constitutes a significant source of concern for many corporate decision-makers due to its complexity and cost. These may be due, first and foremost, to the style of juridical language, which is often challenging to translate into concrete operational procedures. To facilitate such a translation and ultimately optimise the compliance effort, this article presents “NIS2Onto”, an Web Ontology Language (OWL) ontology designed to translate the Network and Information Security Directive version 2 (NIS 2) into an ontological format aimed to favour unambiguous understanding and security operations of cybersecurity professionals, legal experts, and all organisational stakeholders. Through the semantic representation of the NIS 2 entities, relationships, and security measures, NIS2Onto enables automated compliance verification, streamlined risk assessments, and effective policy implementation. Our evaluation employs both metrical and qualitative analysis through a real case study to witness the robustness and practical applicability of NIS2Onto. The ontology not only supports the accurate interpretation of complex legal texts but also aids in systematically enforcing cybersecurity measures. Furthermore, the extensibility of NIS2Onto allows for integration with other regulatory frameworks, thereby fostering a comprehensive and unified approach to cybersecurity governance.
Gianpietro Castiglione, Daniele Francesco Santamaria, Giampaolo Bella, Laura Brisindi, Gaetano Puccia
Comput. Secur.2
2023 Towards Grammatical Tagging for the Legal Language of Cybersecurity
abstract
Legal language can be understood as the language typically used by those engaged in the legal profession and, as such, it may come both in spoken or written form. Recent legislation on cybersecurity obviously uses legal language in writing, thus inheriting all its interpretative complications due to the typical abundance of cases and sub-cases as well as to the general richness in detail. This paper faces the challenge of the essential interpretation of the legal language of cybersecurity, namely of the extraction of the essential Parts of Speech (POS) from the legal documents concerning cybersecurity.
Gianpietro Castiglione, Giampaolo Bella, Daniele Francesco Santamaria
ARES3
2021 An Improved Set-based Reasoner for the Description Logic 𝒟ℒD4, ×
abstract
We present a KE-tableau-based implementation of a reasoner for a decidable fragment of (stratified) set theory expressing the description logic 𝒟ℒ〈4LQSR,×〉(D) (𝒟ℒD4,×, for short). Our application solves the main TBox and ABox reasoning problems for 𝒟ℒD4,×. In particular, it solves the consistency and the classification problems for 𝒟ℒD4,×-knowledge bases represented in set-theoretic terms, and a generalization of the Conjunctive Query Answering problem in which conjunctive queries with variables of three sorts are admitted. The reasoner, which extends and improves a previous version, is implemented in C++. It supports 𝒟ℒD4,×-knowledge bases serialized in the OWL/XML format and it admits also rules expressed in SWRL (Semantic Web Rule Language).
Domenico Cantone, Marianna Nicolosi Asmundo, Daniele Francesco Santamaria
Fundam. Informaticae3
2020 A Set-theoretic Approach to Reasoning Services for the Description Logic 𝒟ℒD4, ×
abstract
In this paper we consider the most common TBox and ABox reasoning services for the description logic 𝒟ℒ〈4LQSR,x〉(D) ( 𝒟 ℒ D 4,× , for short) and prove their decidability via a reduction to the satisfiability problem for the set-theoretic fragment 4LQSR. 𝒟 ℒ D 4,× is a very expressive description logic. It combines the high scalability and efficiency of rule languages such as the SemanticWeb Rule Language (SWRL) with the expressivity of description logics. In fact, among other features, it supports Boolean operations on concepts and roles, role constructs such as the product of concepts and role chains on the left-hand side of inclusion axioms, role properties such as transitivity, symmetry, reflexivity, and irreflexivity, and data types. We further provide a KE-tableau-based procedure that allows one to reason on the main TBox and ABox reasoning tasks for the description logic 𝒟 ℒ D 4,× . Our algorithm is based on a variant of the KE-tableau system for sets of universally quantified clauses, where the KE-elimination rule is generalized in such a way as to incorporate the γ-rule. The novel system, called KEγ-tableau, turns out to be an improvement of the system introduced in [1] and of standard first-order KE-tableaux [2]. Suitable benchmark test sets executed on C++ implementations of the three mentioned systems show that in several cases the performances of the KEγ-tableau-based reasoner are up to about 400% better than the ones of the other two systems.
Domenico Cantone, Marianna Nicolosi Asmundo, Daniele Francesco Santamaria
Fundam. Informaticae3