EDBT 2026 Demo / reviewers in the wild / expert
Enrico Mariconti
dblp:178/2014
· DBLP profile ↗
17ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0003-3005-8214ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SoK: A Privacy Framework for Security Research Using Social Media DataabstractThe use of social media data in research is common, spanning fields from computer science to social science, from human-computer interaction to law and criminology. However, social media data often contains personal and sensitive information. While prior work discusses the ethics of research using social media data, focusing on ethics broadly can be insufficient to unravel granular privacy risks and possible mitigations. Focusing on research papers that use social media data to study security-related topics, we systematically analyze 601 papers across 16 years, covering a wide array of academic disciplines. Our findings highlight a lack of transparency in reporting - only 35% of papers mention any considerations of data anonymization, availability, and storage. Applying Solove's taxonomy to classify the identified privacy risks in the social media setting, we observe that Solove's taxonomy was prescient in capturing aggregation risk, but the volume, timeliness, and micro details of data, combined with modern data science, yield risks beyond what was considered 20 years ago. We present the implications of our findings for various stakeholders: researchers, ethics boards, and publishing venues. While there are already signs of improvement, we posit that some small behavioral changes from the academic community may make a big difference in user privacy. Kyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran, Marilyne Ordekian, Enrico Mariconti, Yixin Zou, Marie Vasek |
SP | 6 |
| 2025 | 'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom
Sharad Agarwal, Emma Harvey, Enrico Mariconti, Guillermo Suarez-Tangil, Marie Vasek |
USENIX Security Symposium | 3 |
| 2025 | Systematic Literature Review: Anomaly Detection in Connected and Autonomous VehiclesabstractThis systematic literature review provides a structured and detailed overview of research on anomaly detection for connected and autonomous vehicles, focusing on the Artificial Intelligence methods employed, training approaches, and testing and evaluation techniques. The initial database search identified 2,160 articles, of which 203 were included in this review after rigorous screening and assessment. This study revealed that the most commonly used anomaly detection techniques employed are deep learning networks such as LSTM, CNN, and autoencoders, alongside one-class SVM. Most detection models were trained using real-world operational vehicle data, although anomalies, such as attacks and faults, were often injected artificially into the datasets. The models were evaluated primarily using five key evaluation metrics: recall, accuracy, precision, F1-score, and false positive rate. The most frequently used set of evaluation metrics for detection models were accuracy, precision, recall, and F1-score. The review makes several recommendations to improve future work related to anomaly detection models. It recommends providing comprehensive assessment of the anomaly detection models and emphasise the importance to share models publicly to facilitate collaboration within the research community and enable further validation. Recommendations also include the need for benchmarking datasets with predefined anomalies or cyberattacks (with comprehensive threat modelling) to test and improve the effectiveness of the proposed anomaly detection models. Future research should focus on the deployment of anomaly based detection in vehicles to evaluate their performance in real-world driving conditions, and explore systems using communication protocols beyond CAN, such as Ethernet and FlexRay. John Roar Ventura Solaas, Enrico Mariconti, Nilufer Tuptuk |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Short Paper: DeFi Deception - Uncovering the Prevalence of Rugpulls in Cryptocurrency Projects
Sharad Agarwal, Gilberto Atondo Siu, Marilyne Ordekian, Alice Hutchings, Enrico Mariconti, Marie Vasek |
FC (1) | 5 |
| 2023 | Breaking the structure of MaMaDroid
Harel Berger, Amit Dvir, Enrico Mariconti, Chen Hajaj |
Expert Syst. Appl. | 3 |
| 2022 | Shedding Light on the Targeted Victim Profiles of Malicious DownloadersabstractMalware affects millions of users worldwide, impacting the daily lives of many people as well as businesses. Malware infections are increasing in complexity and unfold over a number of stages. A malicious downloader often acts as the starting point as it fingerprints the victim’s machine and downloads one or more additional malware payloads. Although previous research was conducted on these malicious downloaders and their Pay-Per-Install networks, limited work has investigated how the profile of the victim machine, e.g., its characteristics and software configuration, affect the targeting choice of cybercriminals. Francois Labreche, Enrico Mariconti, Gianluca Stringhini |
ARES | 2 |
| 2022 | CERBERUS: Exploring Federated Prediction of Security EventsabstractModern defenses against cyberattacks increasingly rely on proactive approaches, e.g., to predict the adversary's next actions based on past events. Building accurate prediction models requires knowledge from many organizations; alas, this entails disclosing sensitive information, such as network structures, security postures, and policies, which might often be undesirable or outright impossible. Mohammad Naseri, Yufei Han 0001, Enrico Mariconti, Gianluca Stringhini, Emiliano De Cristofaro |
CCS | 3 |
| 2020 | BOTection: Bot Detection by Building Markov Chain Models of Bots Network BehaviorabstractBotnets continue to be a threat to organizations, thus various machine learning-based botnet detectors have been proposed. However, the capability of such systems in detecting new or unseen botnets is crucial to ensure its robustness against the rapid evolution of botnets. Moreover, it prolongs the effectiveness of the system in detecting bots, avoiding frequent and time-consuming classifier re-training. We present BOTection, a privacy-preserving bot detection system that models the bot network flow behavior as a Markov Chain. The Markov Chain state transitions capture the bots' network behavior using high-level flow features as states, producing content-agnostic and encryption resilient behavioral features. These features are used to train a classifier to first detect flows produced by bots, and then identify their bot families. We evaluate our system on a dataset of over 7M malicious flows from 12 botnet families, showing its capability of detecting bots' network traffic with 99.78% F-measure and classifying it to a malware family with a 99.09% F-measure. Notably, due to the modeling of general bot network behavior by the Markov Chains, BOTection can detect traffic belonging to unseen bot families with an F-measure of 93.03% making it robust against malware evolution. Bushra A. AlAhmadi, Enrico Mariconti, Riccardo Spolaor, Gianluca Stringhini, Ivan Martinovic |
AsiaCCS | 2 |
| 2019 | "You Know What to Do": Proactive Detection of YouTube Videos Targeted by Coordinated Hate AttacksabstractVideo sharing platforms like YouTube are increasingly targeted by aggression and hate attacks. Prior work has shown how these attacks often take place as a result of "raids," i.e., organized efforts by ad-hoc mobs coordinating from third-party communities. Despite the increasing relevance of this phenomenon, however, online services often lack effective countermeasures to mitigate it. Unlike well-studied problems like spam and phishing, coordinated aggressive behavior both targets and is perpetrated by humans, making defense mechanisms that look for automated activity unsuitable. Therefore, the de-facto solution is to reactively rely on user reports and human moderation. In this paper, we propose an automated solution to identify YouTube videos that are likely to be targeted by coordinated harassers from fringe communities like 4chan. First, we characterize and model YouTube videos along several axes (metadata, audio transcripts, thumbnails) based on a ground truth dataset of videos that were targeted by raids. Then, we use an ensemble of classifiers to determine the likelihood that a video will be raided with very good results (AUC up to 94%). Overall, our work provides an important first step towards deploying proactive systems to detect and mitigate coordinated hate attacks on platforms like YouTube. Enrico Mariconti, Guillermo Suarez-Tangil, Jeremy Blackburn, Emiliano De Cristofaro, Nicolas Kourtellis, Ilias Leontiadis, Jordi Luque Serrano, Gianluca Stringhini |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2019 | MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models (Extended Version)abstractAs Android has become increasingly popular, so has malware targeting it, thus motivating the research community to propose different detection techniques. However, the constant evolution of the Android ecosystem, and of malware itself, makes it hard to design robust tools that can operate for long periods of time without the need for modifications or costly re-training. Aiming to address this issue, we set to detect malware from a behavioral point of view, modeled as the sequence of abstracted API calls. We introduce M A M A D ROID , a static-analysis-based system that abstracts app’s API calls to their class, package, or family, and builds a model from their sequences obtained from the call graph of an app as Markov chains. This ensures that the model is more resilient to API changes and the features set is of manageable size. We evaluate M A M A D ROID using a dataset of 8.5K benign and 35.5K malicious apps collected over a period of 6 years, showing that it effectively detects malware (with up to 0.99 F-measure) and keeps its detection capabilities for long periods of time (up to 0.87 F-measure 2 years after training). We also show that M A M A D ROID remarkably overperforms D ROID APIM INER , a state-of-the-art detection system that relies on the frequency of ( raw ) API calls. Aiming to assess whether M A M A D ROID ’s effectiveness mainly stems from the API abstraction or from the sequencing modeling, we also evaluate a variant of it that uses frequency (instead of sequences), of abstracted API calls. We find that it is not as accurate, failing to capture maliciousness when trained on malware samples that include API calls that are equally or more frequently used by benign apps. Lucky Onwuzurike, Enrico Mariconti, Panagiotis Andriotis, Emiliano De Cristofaro, Gordon J. Ross, Gianluca Stringhini |
ACM Trans. Priv. Secur. | 2 |
| 2018 | Tiresias: Predicting Security Events Through Deep LearningabstractWith the increased complexity of modern computer attacks, there is a need for defenders not only to detect malicious activity as it happens, but also to predict the specific steps that will be taken by an adversary when performing an attack. However this is still an open research problem, and previous research in predicting malicious events only looked at binary outcomes (eg. whether an attack would happen or not), but not at the specific steps that an attacker would undertake. To fill this gap we present Tiresias xspace, a system that leverages Recurrent Neural Networks (RNNs) to predict future events on a machine, based on previous observations. We test Tiresias xspace on a dataset of 3.4 billion security events collected from a commercial intrusion prevention system, and show that our approach is effective in predicting the next event that will occur on a machine with a precision of up to 0.93. We also show that the models learned by Tiresias xspace are reasonably stable over time, and provide a mechanism that can identify sudden drops in precision and trigger a retraining of the system. Finally, we show that the long-term memory typical of RNNs is key in performing event prediction, rendering simpler methods not up to the task. Enrico Mariconti, Pierre-Antoine Vervier, Gianluca Stringhini |
CCS | 2 |
| 2018 | A Family of Droids-Android Malware Detection via Behavioral Modeling: Static vs Dynamic AnalysisabstractFollowing the increasing popularity of the mobile ecosystem, cybercriminals have increasingly targeted mobile ecosystems, designing and distributing malicious apps that steal information or cause harm to the device's owner. Aiming to counter them, detection techniques based on either static or dynamic analysis that model Android malware, have been proposed. While the pros and cons of these analysis techniques are known, they are usually compared in the context of their limitations e.g., static analysis is not able to capture runtime behaviors, full code coverage is usually not achieved during dynamic analysis, etc. Whereas, in this paper, we analyze the performance of static and dynamic analysis methods in the detection of Android malware and attempt to compare them in terms of their detection performance, using the same modeling approach.To this end, we build on MAMADROID, a state-of-the-art detection system that relies on static analysis to create a behavioral model from the sequences of abstracted API calls. Then, aiming to apply the same technique in a dynamic analysis setting, we modify CHIMP, a platform recently proposed to crowdsource human inputs for app testing, in order to extract API calls' sequences from the traces produced while executing the app on a CHIMP virtual device. We call this system AUNTIEDROID and instantiate it by using both automated (Monkey) and usergenerated inputs. We find that combining both static and dynamic analysis yields the best performance, with $F -$measure reaching 0.92. We also show that static analysis is at least as effective as dynamic analysis, depending on how apps are stimulated during execution, and investigate the reasons for inconsistent misclassifications across methods. Lucky Onwuzurike, Mário Almeida, Enrico Mariconti, Jeremy Blackburn, Gianluca Stringhini, Emiliano De Cristofaro |
PST | 3 |
| 2017 | Ex-Ray: Detection of History-Leaking Browser ExtensionsabstractWeb browsers have become the predominant means for developing and deploying applications, and thus they often handle sensitive data such as social interactions or financial credentials and information. As a consequence, defensive measures such as TLS, the Same-Origin Policy (SOP), and Content Security Policy (CSP) are critical for ensuring that sensitive data remains in trusted hands. Michael Weissbacher, Enrico Mariconti, Guillermo Suarez-Tangil, Gianluca Stringhini, William K. Robertson, Engin Kirda |
ACSAC | 2 |
| 2017 | MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models
Enrico Mariconti, Lucky Onwuzurike, Panagiotis Andriotis, Emiliano De Cristofaro, Gordon J. Ross, Gianluca Stringhini |
NDSS | 1 |
| 2017 | What's in a Name?: Understanding Profile Name Reuse on TwitterabstractUsers on Twitter are commonly identified by their profile names. These names are used when directly addressing users on Twitter, are part of their profile page URLs, and can become a trademark for popular accounts, with people referring to celebrities by their real name and their profile name, interchangeably. Twitter, however, has chosen to not permanently link profile names to their corresponding user accounts. In fact, Twitter allows users to change their profile name, and afterwards makes the old profile names available for other users to take. Enrico Mariconti, Jeremiah Onaolapo, Syed Sharique Ahmad, Nicolas Nikiforou, Manuel Egele, Nick Nikiforakis, Gianluca Stringhini |
WWW | 1 |
| 2016 | What's Your Major Threat? On the Differences between the Network Behavior of Targeted and Commodity MalwareabstractThis work uses statistical classification techniques to learn about the different network behavior patterns demonstrated by targeted malware and generic malware. Targeted malware is a recent type of threat, involving bespoke software that has been created to target a specific victim. It is considered a more dangerous threat than generic malware, because a targeted attack can cause more serious damage to the victim. Our work aims to automatically distinguish between the network activity generated by the two types of malware, which then allows samples of malware to be classified as being either targeted or generic. For a network administrator, such knowledge can be important because it assists to understand which threats require particular attention. Because a network administrator usually manages more than an alarm simultaneously, the aim of the work is particularly relevant. We set up a sandbox and infected virtual machines with malware, recording all resulting malware activity on the network. Using the network packets produced by the malware samples, we extract features to classify their behavior. Before performing classification, we carefully analyze the features and the dataset to study all their details and gain a deeper understanding of the malware under study. Our use of statistical classifiers is shown to give excellent results in some cases, where we achieved an accuracy of almost 96% in distinguishing between the two types of malware. We can conclude that the network behaviors of the two types of malicious code are very different. Enrico Mariconti, Jeremiah Onaolapo, Gordon J. Ross, Gianluca Stringhini |
ARES | 1 |
| 2016 | What Happens After You Are Pwnd: Understanding the Use of Leaked Webmail Credentials in the Wild
Jeremiah Onaolapo, Enrico Mariconti, Gianluca Stringhini |
Internet Measurement Conference | 2 |