Anna Maria Mandalari

dblp:174/4807 · DBLP profile ↗
← Back
26ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0002-6715-101XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 2 first-author · 7 since 2021Security and privacy · 6 · 2 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 From Lookup to Lockdown: DNS Guidelines for Securing IoT Ecosystems
abstract
The Domain Name System (DNS) serves as a fundamental component of Internet infrastructure; however, its frequently overlooked role in consumer Internet of Things (IoT) ecosystems exposes significant security vulnerabilities and operational challenges. This paper analyzes DNS behavior in consumer IoT devices and reveals widespread inconsistencies that undermine operational efficiency, resilience, and security. We construct a representative testbed spanning a heterogeneous set of IoT devices and employ both passive traffic monitoring and active experimentation to identify vulnerabilities, including cache poisoning, predictable transaction IDs, non-randomized source ports, and limited adoption of secure DNS protocols such as DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Domain Name System Security Extensions (DNSSEC). We observe erratic operational patterns, such as excessive querying, poor adherence to TTL values, and overreliance on hard-coded resolvers, that amplify exposure to fingerprinting and denial-of-service attacks. Our findings demonstrate a concerning lack of standardized DNS practices across the IoT ecosystem. We conclude by proposing actionable guidelines to harden DNS handling in IoT devices and improve security, interoperability, and network stability as the consumer IoT landscape continues to expand.
Andrew Losty, Abhishek Kumar Mishra 0001, Mathieu Cunche, Anna Maria Mandalari
IEEE Internet Things J.4
2026 Catching Hackers by Watching Watts: A Measurement Study of Power-Only Attack Detection on Consumer IoT Devices
abstract
Security analysis of consumer Internet of Things (IoT) devices is increasingly constrained by limited visibility into encrypted traffic and closed firmware, which motivates the exploration of observable and privacy preserving external signals. Prior work has shown that adversarial activity can induce measurable changes in device power usage, indicating that power based intrusion detection is feasible, yet its stability and reliability under realistic operating conditions remain unclear. We address this gap through a systematic measurement study of 33 commercial IoT devices, collecting per second power traces and complete background traffic logs during idle operation and realistic active use under Denial of Service (DoS) and Reconnaissance attacks. Our analysis shows that power usage provides clear separation between benign and adversarial behavior in stable idle states, while legitimate activity introduces masking that varies across devices. We identify 4 behavioral regimes that describe how activity suppresses or alters attack related increments and analyze power stability and background traffic characteristics to explain the observed differences in detection strength. Our findings provide the first systematic large-scale characterization of when power-based detection remains reliable and when it degrades, highlighting the physical and network conditions that govern its robustness in realistic deployments.
Hashim Zia, Jiahui Qin, Sandra Deepthy Siby, Anna Maria Mandalari
IEEE Internet Things J.5
2025 ACCESS-FL: Agile Communication and Computation for Efficient Secure Aggregation in Stable Networks for FLaaS
abstract
Federated Learning (FL) enables privacy-preserving machine learning by allowing clients to collaboratively train models without sharing raw data. Federated Learning as a Service (FLaaS) extends this approach to cloud infrastructures. However, conventional secure aggregation protocols, such as Google's SecAgg and SecAgg+, introduce high computation and communication overheads, particularly in large-scale FLaaS deployments where client dropout rates are limited. To address these challenges, we propose ACCESS-FL, a lightweight, secure aggregation method designed for honest-but-curious FLaaS scenarios with stable network conditions. ACCESS-FL eliminates double masking, Shamir's Secret Sharing, and excessive encryption/decryption by creating shared secrets only between two peers per client, which reduces computation and communication complexity to constant$O(1)$and makes the algorithm independent of network size and comparable to standard FL. ACCESS-FL preserves privacy against inversion attacks and maintains model accuracy equivalent to the FL, SecAgg, and SecAgg+ protocols, proving that reducing overhead does not compromise learning performance and achieves communication and computation costs comparable to standard FL. Experimental evaluations on benchmark datasets (MNIST, FMNIST, and CIFAR-10) demonstrate lower overhead, making ACCESS-FL practical for service-based stable FLaaS applications such as healthcare analytics.
Niousha Nazemi, Omid Tavallaie, Shuaijun Chen, Anna Maria Mandalari, Kanchana Thilakarathna, Ralph Holz, Hamed Haddadi 0001, Albert Y. Zomaya
ICWS4
2025 Hacking Health: Unveiling Vulnerabilities in BLE-Enabled Wearable Sensor Nodes
abstract
The rise of the Internet of Medical Things (IoMT) in healthcare brings benefits like continuous monitoring, remote patient care, and data-driven treatments. However, it also poses cybersecurity risks. While prior research has investigated this issue, it has not looked at advanced wearable sensor nodes that use combination of Bluetooth Low Energy (BLE) with other wireless protocols. In this paper we conduct a blackbox audit of wearable sensor nodes for exploring vulnerabilities associated with them. We use a systematic auditing approach to (1) investigate whether security attacks are effective against wearable sensor nodes, (2) group the vulnerabilities based on susceptibility to certain types of attacks, and (3) provide an in-depth gap analysis of the devices’ security behaviour. We develop and release an approach for semi-automated wearable sensor nodes experimentation to reveal their response to common security threats. We perform hundreds of experiments using popular commercial wearable sensor nodes when deployed in an IoMT testbed. Our results indicate not only that these devices are vulnerable to common security attacks, but also their critical security gaps jeopardize patient safety and data integrity.
Mohammad Alhussan, Francesca Boem, Sara S. Ghoreishizadeh, Anna Maria Mandalari
ISCAS4
2025 Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants
Yash Vekaria, Aurelio Loris Canino, Jonathan Levitsky, Alex Ciechonski, Patricia Callejo, Anna Maria Mandalari, Zubair Shafiq
USENIX Security Symposium6
2025 A black-box assessment of authentication and reliability in consumer IoT devices
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri
Pervasive Mob. Comput.3
2024 Demo: From Eavesdropping to Exploitation: Exposing Vulnerabilities in BLE-Enabled Wearable Medical Devices
Mohammad Alhussan, Francesca Boem, Sara S. Ghoreishizadeh, Anna Maria Mandalari
EWSN4
2024 PhD School: From Eavesdropping to Exploitation: Exposing Vulnerabilities in BLE-Enabled Wearable Medical Devices
Mohammad Alhussan, Francesca Boem, Sara S. Ghoreishizadeh, Anna Maria Mandalari
EWSN4
2024 Poster: An Investigation of Matter Smart Home Mechanisms to Mitigate Denial-of-Service (DoS) Attacks
Andrew Losty, Anna Maria Mandalari
EWSN2
2024 PhD School: An Investigation of Matter Smart Home Mechanisms to Mitigate Denial-of-Service (DoS) Attacks
Andrew Losty, Anna Maria Mandalari
EWSN2
2024 Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs
abstract
Smart TVs implement a unique tracking approach called Automatic Content Recognition (ACR) to profile viewing activity of their users. ACR is a Shazam-like technology that works by periodically capturing the content displayed on a TV's screen and matching it against a content library to detect what content is being displayed at any given point in time. While prior research has investigated third-party tracking in the smart TV ecosystem, it has not looked into second-party ACR tracking that is directly conducted by the smart TV platform. In this work, we conduct a black-box audit of ACR network traffic between ACR clients on the smart TV and ACR servers. We use our auditing approach to systematically investigate whether (1) ACR tracking is agnostic to how a user watches TV (e.g., linear vs. streaming vs. HDMI), (2) privacy controls offered by smart TVs have an impact on ACR tracking, and (3) there are any differences in ACR tracking between the UK and the US. We perform a series of experiments on two major smart TV platforms: Samsung and LG. Our results show that ACR works even when the smart TV is used as a ''dumb'' external display, opting-out stops network traffic to ACR servers, and there are differences in how ACR works across the UK and the US.
Gianluca Anselmi, Yash Vekaria, Alexander D'Souza, Patricia Callejo, Anna Maria Mandalari, Zubair Shafiq
IMC5
2024 SunBlock: Cloudless Protection for IoT Systems
Vadim Safronov, Anna Maria Mandalari, Daniel J. Dubois, David R. Choffnes, Hamed Haddadi 0001
PAM (2)2
2024 Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices
abstract
Consumer Internet of Things (IoT) devices often leverage the local network to communicate with the corresponding companion app or other devices. This has benefits in terms of efficiency since it offloads the cloud. ENISA and NIST security guidelines underscore the importance of enabling default local communication for safety and reliability. Indeed, an IoT device should continue to function in case the cloud connection is not available. While the security of cloud-device connections is typically strengthened through the usage of standard protocols, local connectivity security is frequently overlooked. Neglecting the security of local communication opens doors to various threats, including replay attacks. In this paper, we investigate this class of attacks by designing a systematic methodology for automatically testing IoT devices vulnerability to replay attacks. Specifically, we propose a tool, named REPLIoT, able to test whether a replay attack is successful or not, without prior knowledge of the target devices. We perform thousands of automated experiments using popular commercial devices spanning various vendors and categories. Notably, our study reveals that among these devices, 51% of them do not support local connectivity, thus they are not compliant with the reliability and safety requirements of the ENISA/NIST guidelines. We find that 75% of the remaining devices are vulnerable to replay attacks with REPLIoT having a detection accuracy of 0.98-1. Finally, we investigate the possible causes of this vulnerability, discussing possible mitigation strategies.
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri
PerCom3
2024 Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?
abstract
Recent years have seen widespread adoption of consumer Internet of Things (IoT) devices, offering diverse benefits to end-users, from smart homes to healthcare monitoring, but raising serious privacy concerns. To address this, securing efforts, such as encrypting DNS, have been proposedIn this paper, we study the effectiveness of such measures in the specific context of ensuring IoT privacy. We introduce a device identification attack against DNS-over-HTTPS-enabled IoT devices. We conduct more than 25,000 automated experiments across 6 public DNS resolvers and find that the proposed attack can identify devices via DNS-over-HTTPS (DoH) traffic with a 0.98 balanced accuracy. We point out padding as a mitigation technique that reduces identification by a significant 33%. Additionally, we find that half of the evaluated DNS resolvers do not adhere to the relevant specification, substantially compromising user privacy.
Samuel Pélissier, Gianluca Anselmi, Abhishek Kumar Mishra 0001, Anna Maria Mandalari, Mathieu Cunche
TrustCom4
2023 Recovering Headerless Frames in LR-FHSS
Anna Maria Mandalari, Isabel Straw
EWSN2
2023 PRISM: Privacy Preserving Healthcare Internet of Things Security Management
abstract
Consumer healthcare Internet of Things (IoT) devices are gaining popularity in our homes and hospitals. These devices provide continuous monitoring at a low cost and can be used to augment high-precision medical equipment. However, major challenges remain in applying pre-trained global models for anomaly detection on smart health monitoring, for a diverse set of individuals that they provide care for. In this paper, we propose PRISM, an edge-based system for experimenting with in-home smart healthcare devices. We develop a rigorous methodology that relies on automated IoT experimentation. We use a rich real-world dataset from in-home patient monitoring from 44 households of People Living With Dementia (PLWD) over two years. Our results indicate that anomalies can be identified with accuracy up to 99% and mean training times as low as 0.88 seconds. While all models achieve high accuracy when trained on the same patient, their accuracy degrades when evaluated on different patients.
Savvas Hadjixenophontos, Anna Maria Mandalari, Hamed Haddadi 0001
ISCC2
2023 COPSEC: Compliance-Oriented IoT Security and Privacy Evaluation Framework
abstract
A rising number of Internet of Things (IoT) security and privacy threats have been documented over the last few years. However, IoT devices' domain designs are out-of-date and do not take into consideration the changing dangers associated with them. In this paper, we present COPSEC, a novel framework for evaluating whether IoT devices are compliant with security guidelines and privacy regulations. We extract metrics from existing guidelines and regulations and test them on a set of devices by performing hundreds of automated experiments. Our results indicate not only that these devices are not compliant with basic security guidelines, but also that their data collection operations may introduce privacy risks for the users that adopt them.
Gianluca Anselmi, Anna Maria Mandalari, Sara Lazzaro, Vincenzo De Angelis
MobiCom2
2023 Protected or Porous: A Comparative Analysis of Threat Detection Capability of IoT Safeguards
abstract
Consumer Internet of Things (IoT) devices are increasingly common, from smart speakers to security cameras, in homes. Along with their benefits come potential privacy and security threats. To limit these threats a number of commercial services have become available (IoT safeguards). The safeguards claim to provide protection against IoT privacy risks and security threats. However, the effectiveness and the associated privacy risks of these safeguards remains a key open question. In this paper, we investigate the threat detection capabilities of IoT safeguards for the first time. We develop and release an approach for automated safeguards experimentation to reveal their response to common security threats and privacy risks. We perform thousands of automated experiments using popular commercial IoT safeguards when deployed in a large IoT testbed. Our results indicate not only that these devices may be ineffective in preventing risks, but also their cloud interactions and data collection operations may introduce privacy risks for the households that adopt them.
Anna Maria Mandalari, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes
SP1
2023 Design, implementation and validation of a receiver-driven less-than-best-effort transport
abstract
LEDBAT++ is a congestion-control algorithm that implements a less-than-best-effort transport service. In this paper we present rLEDBAT, a purely receiver-based mechanism to implement LEDBAT++ for TCP. rLEDBAT enables a receiver to select some incoming traffic as less-than-best-effort, managing the capacity of the downlink. We describe the different mechanisms composing rLEDBAT that enable the execution of the LEDBAT++ congestion control algorithm at the receiver. We have implemented and experimentally tested rLEDBAT. We validate that the mechanisms incorporated by rLEDBAT at the receiver are indeed effective to implement a less-than-best-effort transport service at the receiver, as it performs similarly to the original sender-based LEDBAT++.
Marcelo Bagnulo, Alberto García-Martínez, Anna Maria Mandalari, Praveen Balasubramanian, Daniel Havey, Gabriel Montenegro
Comput. Networks3
2022 Measuring Roaming in Europe: Infrastructure and Implications on Users' QoE
abstract
“Roam like Home” is the initiative of the European Commission (EC) to end the levy of extra charges when roaming within the European region. As a result, people can use data services more freely across Europe. However, the implications of roaming solutions on network performance have not been carefully examined yet. This paper provides an in-depth characterization of the implications of international data roaming within Europe. We build a unique roaming measurement platform using 16 different mobile networks deployed in six countries across Europe. Using this platform, we measure different aspects of international roaming in 4G networks in Europe, including mobile network configuration, performance characteristics, and quality of experience. We find that operators adopt a common approach to implement roaming called Home-routed roaming (HR). This results in additional latency penalties of 60 ms or more, depending on geographical distance. This leads to worse browsing performance, with an increase in the metrics related to Quality of Experience (QoE) of users (Page Load time and Speed Index) in the order of 15-20 percent. We further analyze in isolation the impact of latency on QoE metrics and find that the penalty imposed by HR leads to a degradation on QoE metrics up to 150 percent in case of intercontinental roaming.
Anna Maria Mandalari, Andra Lutu, Ana Custura, Ali Safari Khatouni, Özgü Alay, Marcelo Bagnulo, Vaibhav Bajpai, Anna Brunström, Jörg Ott, Martino Trevisan, Marco Mellia, Gorry Fairhurst
IEEE Trans. Mob. Comput.1
2021 Blocking Without Breaking: Identification and Mitigation of Non-Essential IoT Traffic
abstract
Abstract Despite the prevalence of Internet of Things (IoT) devices, there is little information about the purpose and risks of the Internet traffic these devices generate, and consumers have limited options for controlling those risks. A key open question is whether one can mitigate these risks by automatically blocking some of the Internet connections from IoT devices, without rendering the devices inoperable. In this paper, we address this question by developing a rigorous methodology that relies on automated IoT-device experimentation to reveal which network connections (and the information they expose) are essential, and which are not. We further develop strategies to automatically classify network traffic destinations as either required (i.e., their traffic is essential for devices to work properly) or not, hence allowing firewall rules to block traffic sent to non-required destinations without breaking the functionality of the device. We find that indeed 16 among the 31 devices we tested have at least one blockable non-required destination, with the maximum number of blockable destinations for a device being 11. We further analyze the destination of network traffic and find that all third parties observed in our experiments are blockable, while first and support parties are neither uniformly required or non-required. Finally, we demonstrate the limitations of existing blocklists on IoT traffic, propose a set of guidelines for automatically limiting non-essential IoT traffic, and we develop a prototype system that implements these guidelines.
Anna Maria Mandalari, Daniel J. Dubois, Roman Kolcun, Muhammad Talha Paracha, Hamed Haddadi 0001, David R. Choffnes
Proc. Priv. Enhancing Technol.1
2020 A Haystack Full of Needles: Scalable Detection of IoT Devices in the Wild
abstract
Consumer Internet of Things (IoT) devices are extremely popular, providing users with rich and diverse functionalities, from voice assistants to home appliances. These functionalities often come with significant privacy and security risks, with notable recent large-scale coordinated global attacks disrupting large service providers. Thus, an important first step to address these risks is to know what IoT devices are where in a network. While some limited solutions exist, a key question is whether device discovery can be done by Internet service providers that only see sampled flow statistics. In particular, it is challenging for an ISP to efficiently and effectively track and trace activity from IoT devices deployed by its millions of subscribers---all with sampled network data.
Said Jawad Saidi, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes, Georgios Smaragdakis, Anja Feldmann
Internet Measurement Conference2
2020 When Speakers Are All Ears: Characterizing Misactivations of IoT Smart Speakers
abstract
Abstract Internet-connected voice-controlled speakers, also known as smart speakers, are increasingly popular due to their convenience for everyday tasks such as asking about the weather forecast or playing music. However, such convenience comes with privacy risks: smart speakers need to constantly listen in order to activate when the “wake word” is spoken, and are known to transmit audio from their environment and record it on cloud servers. In particular, this paper focuses on the privacy risk from smart speaker misactivations, i.e., when they activate, transmit, and/or record audio from their environment when the wake word is not spoken. To enable repeatable, scalable experiments for exposing smart speakers to conversations that do not contain wake words, we turn to playing audio from popular TV shows from diverse genres. After playing two rounds of 134 hours of content from 12 TV shows near popular smart speakers in both the US and in the UK, we observed cases of 0.95 misactivations per hour, or 1.43 times for every 10,000 words spoken, with some devices having 10% of their misactivation durations lasting at least 10 seconds. We characterize the sources of such misactivations and their implications for consumers, and discuss potential mitigations.
Daniel J. Dubois, Roman Kolcun, Anna Maria Mandalari, Muhammad Talha Paracha, David R. Choffnes, Hamed Haddadi 0001
Proc. Priv. Enhancing Technol.3
2019 Information Exposure From Consumer IoT Devices: A Multidimensional, Network-Informed Measurement Approach
abstract
Internet of Things (IoT) devices are increasingly found in everyday homes, providing useful functionality for devices such as TVs, smart speakers, and video doorbells. Along with their benefits come potential privacy risks, since these devices can communicate information about their users to other parties over the Internet. However, understanding these risks in depth and at scale is difficult due to heterogeneity in devices' user interfaces, protocols, and functionality.
Daniel J. Dubois, David R. Choffnes, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001
Internet Measurement Conference4
2019 "Sensing" the IoT network: Ethical capture of domestic IoT network traffic: poster abstract
abstract
As more and more devices are connected to the Internet-of-Things, often made by non-specialist companies or short-lived startups, the likelihood that these devices will be hacked and used for nefarious activity online increases. We seek to support non-expert users in managing the network behaviour of their IoT devices, and assisting them in handling the cases where those devices are hacked. To do so, we wish to enable anomaly detection at the network level, determining when a device starts behaving unusually. This requires capturing data about how devices behave in a diverse range of real deployments, not just lab environments.
Diana Andreea Popescu, Vadim Safronov, Poonam Yadav, Roman Kolcun, Anna Maria Mandalari, Hamed Haddadi 0001, Derek McAuley, Richard Mortier
SenSys5
2018 Experience: Implications of Roaming in Europe
abstract
"Roam like Home" is the initiative of the European Commission (EC) to end the levy of extra charges when roaming within the European region. As a result, people are able to use data services more freely across Europe. However, the implications roaming solutions have on performance have not been carefully examined. This paper provides an in-depth characterization of the implications of international data roaming within Europe. We build a unique roaming measurement platform using 16 different mobile networks deployed in six countries across Europe. Using this platform, we measure different aspects of international roaming in 3G and 4G networks, including mobile network configuration, performance characteristics, and content discrimination. We find that operators adopt common approaches to implementing roaming, resulting in additional latency penalties of ∼60 ms or more, depending on geographical distance. Considering content accessibility, roaming poses additional constraints that leads to only minimal deviations when accessing content in the original country. However, geographical restrictions in the visited country make the picture more complicated and less intuitive.
Anna Maria Mandalari, Andra Lutu, Ana Custura, Ali Safari Khatouni, Özgü Alay, Marcelo Bagnulo, Vaibhav Bajpai, Anna Brunström, Jörg Ott, Marco Mellia, Gorry Fairhurst
MobiCom1