Dario Stabili

dblp:193/3101 · DBLP profile ↗
← Back
18ranked-venue papers
4as first author
13since 2021 · last 2025
0000-0001-6850-334XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Digital forensics and information hiding · 33% Network security · 33% Cyber-physical and IoT security · 33%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Embedded and real-time systems · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cyber-physical and IoT security
CAN bus reverse engineering
0.412019
READ: Reverse Engineering of Automotive Data Frames · IEEE Trans. Inf. Forensics Secur. 2019
Digital forensics and information hiding
digital forensics
0.412019
READ: Reverse Engineering of Automotive Data Frames · IEEE Trans. Inf. Forensics Secur. 2019
Network security
traffic analysis
0.412019
READ: Reverse Engineering of Automotive Data Frames · IEEE Trans. Inf. Forensics Secur. 2019
Embedded and real-time systems
cyber-physical system platforms
0.112019
READ: Reverse Engineering of Automotive Data Frames · IEEE Trans. Inf. Forensics Secur. 2019
Embedded and real-time systems › cyber-physical system platforms
in-vehicle networks
0.112019
READ: Reverse Engineering of Automotive Data Frames · IEEE Trans. Inf. Forensics Secur. 2019

Methods — techniques the papers use, named apart from their topics

signal extraction · 0.8frame classification · 0.8
YearPublicationVenuePosition
2025 Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial Attacks
abstract
Graph Neural Networks (GNNs) represent a promising solution for Machine Learning (ML) based Network Intrusion Detection Systems (NIDS), thanks to their ability to leverage both network flow features and topological patterns. While GNN classifiers demonstrate superior robustness against feature-based adversarial attacks compared to other ML detectors, they remain vulnerable to structural adversarial attacks, where an attacker perturbs the underlying network graph topology by injecting edges or inserting nodes. Such attacks pose a realistic and severe threat, undermining the reliability of GNN-based NIDS in practical deployments. While countermeasures have been proposed in the literature, they often rely on assumptions that are unrealistic in real-world cybersecurity scenarios. In this paper, we propose a defense framework based on adversarial training to strengthen GNN-based NIDS against structural attacks. We generate adversarial samples by strategically replacing the source and destination nodes in benign network flows, thereby efficiently mimicking edge injection attacks. We evaluate our approach on two widely used datasets (CTU-13 and TON-IoT) using EGraphSAGE as the base GNN classifier. Experimental results show that our approach produces hardened detectors with superior detection performance on clean graphs and enhanced robustness against structural adversarial attacks.
Dimitri Galli, Andrea Venturi, Dario Stabili, Mauro Andreolini, Mirco Marchetti
NCA3
2025 That's what you signed for: evaluating user perception about privacy data in infotainment systems
abstract
The growing integration of data-driven technologies in automotive infotainment systems has heightened privacy concerns, yet user awareness remains limited. This study investigates how perceptions of privacy evolve following an intervention designed to raise awareness about data collection practices in these systems. A survey of 932 participants, structured in pre- and post-intervention phases, highlights significant changes in the prioritization of infotainment system features. Through paired statistical analysis and reliability validation, we observe a marked increase in the perceived importance of privacy-related aspects, particularly data precision and collection frequency. Our results underline the potential of targeted interventions to reshape consumer attitudes, emphasizing the need for enhanced transparency in automotive data management practices.
Francesco Faenza, Dario Stabili, Luca Ferretti, Mirco Marchetti
VTC2025-Fall2
2025 RADAR: a Radio-based Analytics for Dynamic Association and Recognition of pseudonyms in VANETs
abstract
This paper presents RADAR, a tracking algorithm for vehicles participating in Cooperative Intelligent Transportation Systems (C-ITS) that exploits multiple radio signals emitted by a modern vehicle to break privacy-preserving pseudonym schemes deployed in VANETs. This study shows that by combining Dedicated Short Range Communication (DSRC) and Wi-Fi probe request messages broadcast by the vehicle, it is possible to improve tracking over standard de-anonymization approaches that only leverage DSRC, especially in realistic scenarios where the attacker does not have full coverage of the entire vehicle path. The experimental evaluation compares three different metrics for pseudonym and Wi-Fi probe identifier association (Count, Statistical RSSI, and Pearson RSSI), demonstrating that the Pearson RSSI metric is better at tracking vehicles under pseudonym-changing schemes in all scenarios and against previous works. As an additional contribution to the state-of-the-art, we publicly release all implementations and simulation scenarios used in this work [1].
Giovanni Gambigliani Zoccoli, Filip Valgimigli, Dario Stabili, Mirco Marchetti
VTC2025-Fall3
2024 HackCar: a test platform for attacks and defenses on a cost-contained automotive architecture
abstract
In this paper, we introduce the design of HackCar, a testing platform for replicating attacks and defenses on a generic automotive system without requiring access to a complete vehicle. This platform empowers security researchers to illustrate the consequences of attacks targeting an automotive system on a realistic platform, facilitating the development and testing of security countermeasures against both existing and novel attacks. The HackCar platform is built upon an F1−10thmodel, to which various automotive-grade microcontrollers are connected through automotive communication protocols. This solution is crafted to be entirely modular, allowing for the creation of diverse test scenarios. Researchers and practitioners can thus develop innovative security solutions while adhering to the constraints of automotive-grade microcontrollers. We showcase our design by comparing it with a real, licensed, and unmodified vehicle. Additionally, we analyze the behavior of the HackCar in both an attack-free scenario and a scenario where an attack on in-vehicle communication is deployed.
Dario Stabili, Filip Valgimigli, Edoardo Torrini, Mirco Marchetti
IV1
2024 RealCAN: bringing real-time capabilities to canplayer
abstract
In this paper we present RealCAN, a real-time capable extension of the canplayer tool available in can-utils, a collection of utilities for interacting with Controller Area Network bus systems on Linux-based operating systems. In particular, RealCAN addresses the main limitation of working with fixed time intervals while replaying previously collected CAN traces with the canplayer tool, allowing developers, engineers and researchers to replay CAN traffic data by maintaining the original time difference between consecutive messages. Performance benchmarks of RealCAN demonstrate its effectiveness in meeting strict timing requirements for critical applications in both simulated environment and real CAN test setups.
Giovanni Gambigliani Zoccoli, Dario Stabili, Mirco Marchetti
VTC Fall2
2024 Performance Comparison of Timing-Based Anomaly Detectors for Controller Area Network: A Reproducible Study
abstract
This work presents an experimental evaluation of the detection performance of eight different algorithms for anomaly detection on the Controller Area Network (CAN) bus of modern vehicles based on the analysis of the timing or frequency of CAN messages. This work solves the current limitations of related scientific literature, which is based on a private dataset and lacks open implementations and a detailed description of the detection algorithms. These drawbacks prevent the reproducibility of published results, making it impossible to compare a novel proposal against related work, thus hindering the advancement of science. This article solves these issues by publicly releasing implementations and labeled datasets and by describing unbiased experimental comparisons.
Francesco Pollicino, Dario Stabili, Mirco Marchetti
ACM Trans. Cyber Phys. Syst.2
2023 Are VANETs pseudonyms effective? An experimental evaluation of pseudonym tracking in adversarial scenario
abstract
With the increasing adoption of Vehicular Ad Hoc Networks (VANETs) for the development of Cooperative Intelligent Transportation Systems (C-ITS) many concerns regarding privacy and anonymity in VANETs have been raised by security researchers and practitioners, highlighting the need for effective mechanisms to protect sensitive information exchanged by connected vehicles. One of the first concerns is related to the vehicle’s identifier, a field contained in the messages sent from the vehicle and that can be used to track the vehicle across the infrastructure, with consequent severe implications on the privacy of the driver. Consequently, VANET communications leverage short-lived pseudonyms instead of persistent vehicle’s identifiers, aiming to enhance the privacy of the vehicle. Pseudonym change schemes proposed in the literature are effective in masking the real sender of a given message, but they do not guarantee privacy against attackers that can monitor and correlate multiple messages among themselves. This paper evaluates 5 different pseudonym change mechanisms against a realistic threat model. Our results demonstrate that it is possible for a realistic attacker to reliably track multiple vehicles, with minor differences across different pseudonym change schemes.
Giovanni Gambigliani Zoccoli, Dario Stabili, Mirco Marchetti
VTC Fall2
2023 A multidisciplinary detection system for cyber attacks on Powertrain Cyber Physical Systems
Dario Stabili, Raffaele Romagnoli, Mirco Marchetti, Bruno Sinopoli, Michele Colajanni
Future Gener. Comput. Syst.1
2022 Comparison of Machine Learning-based anomaly detectors for Controller Area Network
abstract
This paper presents a comparative analysis of different Machine Learning-based detection algorithms designed for Controller Area Network (CAN) communication on three different datasets. This work focuses on addressing the current limitations of related scientific literature, related to the quality of the publicly available datasets and to the lack of public implementations of the detection solutions presented in literature. Since these issues are preventing the reproducibility of published results and their comparison with novel detection solutions, we remark that it is necessary that all security researchers working in this field start to address them properly to advance the current state-of-the-art in CAN intrusion detection systems. This paper strives to solve these issues by presenting a comparison of existing works on publicly available datasets.
Andrea Venturi, Dario Stabili, Francesco Pollicino, Emanuele Bianchi, Mirco Marchetti
NCA2
2022 SixPack v2: enhancing SixPack to avoid last generation misbehavior detectors in VANETs
abstract
This paper proposes SixPack v2, an enhanced version of the SixPack attack that allows to evade even state-of-the-art misbehavior detection systems. As the original SixPack, SixPack v2 is a dynamic attack targeting other C-ITS entities by simulating the sudden activation of the braking system with consequent activation of the Anti-lock Braking System. SixPack v2 achieves better evasion by improving the main phases of the attack (FakeBrake, Recovery, and Rejoin) through a novel path-reconstruction algorithm that generates a more realistic representation of the real vehicle trajectory. We experimentally evaluate the evasion capabilities of SixPack v2 using the F2MD framework on the LuSTMini city scenario, and we compared the detection performance of the F2MD framework on both versions of SixPack. Results show that SixPack v2 evades detection with a significantly higher likelihood with respect to the initial version of the attack, even against the latest version of F2MD.
Gabriele Gambigliani Zoccoli, Francesco Pollicino, Dario Stabili, Mirco Marchetti
NCA3
2022 On the effectiveness of BSM communications in V2V emergency scenarios
abstract
Cooperative Intelligent Transportation Systems (CITS) improve driving experience and safety through secure Vehicular Ad-hoc NETworks (VANETs) that satisfy strict security and performance constraints. The use of Vehicle-to-Vehicle (V2V) communications to improve safety in emergency scenarios is already considered in the relevant standards. However, there is a lack of scientific efforts to evaluate and compare the effectiveness of these solutions. This paper improves the state of the art by providing an assessment of the effectiveness of V2V communications in reducing the travel time and safety–relevant events of emergency vehicles. The assessment is based on realistic simulation taking into account real road networks, traffic intensity, and all constraints of V2V communications.
Francesco Pollicino, Dario Stabili, Mirco Marchetti
VTC Spring2
2021 Accountable and privacy-aware flexible car sharing and rental services
abstract
The transportation sector is undergoing rapid changes to reduce pollution and increase life quality in urban areas. One of the most effective approaches is flexible car rental and sharing to reduce traffic congestion and parking space issues. In this paper, we envision a flexible car sharing framework where vehicle owners want to make their vehicles available for flexible rental to other users. The owners delegate the management of their vehicles to intermediate services under certain policies, such as municipalities or authorized services, which manage the due infrastructure and services that can be accessed by users. We investigate the design of an accountable solution that allow vehicles owners, who want to share their vehicles securely under certain usage policies, to control that delegated services and users comply with the policies. While monitoring users behavior, our approach also takes care of users privacy, preventing tracking or profiling procedures by other parties. Existing approaches put high trust assumptions on users and third parties, do not consider users' privacy requirements, or have limitations in terms of flexibility or applicability. We propose an accountable protocol that extends standard delegated authorizations and integrate it with Security Credential Management Systems (SCMS), while considering the requirements and constraints of vehicular networks. We show that the proposed approach represents a practical approach to guarantee accountability in realistic scenarios with acceptable overhead.
Francesco Pollicino, Luca Ferretti, Dario Stabili, Mirco Marchetti
NCA3
2021 SixPack: Abusing ABS to avoid Misbehavior detection in VANETs
abstract
This paper presents SixPack, a cyber attack to VANET communications that is able to go undetected by the current state-of-the-art anomaly detectors. The SixPack attack is a dynamic attack conducted by an insider attacker who modifies the content of the Basic Safety Messages to pretend a sudden activation of the braking system with the consequent activation of the Anti-lock Braking System, and create a fake representation of the vehicle. The attacker then rejoins the fake representation of the vehicle with the real one, avoiding the current state-of-the-art anomaly detectors. We experimentally evaluated the evasion capabilities of the SixPack attack using the F2MD test framework on the LuST and LuSTMini city scenarios, demonstrating the ability of the attacker to generate a high percentage of false positives that prevent the attack from being detected consistently.
Francesco Pollicino, Dario Stabili, Giampaolo Bella, Mirco Marchetti
VTC Spring2
2020 An experimental analysis of ECQV implicit certificates performance in VANETs
abstract
Emerging Cooperative Intelligent Transportation Systems (C-ITS) enable improved driving experience and safety guarantees, but require secure Vehicular Ad-hoc NETworks (VANETs) that must comply to strict performance constraints. Specialized standards have been defined to these aims, such as the IEEE 1609.2 that uses network-efficient cryptographic protocols to reduce communication latencies. The reduced latencies are achieved through a combination of the Elliptic Curve Qu-Vantstone (ECQV) implicit certificate scheme and the Elliptic Curve Digital Signature Algorithm (ECDSA), to guarantee data integrity and authenticity. However, literature lacks implementations and evaluations for vehicular systems. In this paper, we consider the IEEE 1609.2 standard for secure VANETs and investigate the feasibility of ECQV and ECDSA schemes when deployed in C-ITSs. We propose a prototype implementation of the standard ECQV scheme to evaluate its performance on automotive-grade hardware. To the best of our knowledge, this is the first open implementation of the scheme for constrained devices that are characterized by low computational power and low memory. We evaluate its performance against C-ITS communication latency constraints and show that, although even highly constrained devices can support the standard, complying with stricter requirements demands for higher computational resources.
Francesco Pollicino, Dario Stabili, Luca Ferretti, Mirco Marchetti
VTC Fall2
2019 Detection of Missing CAN Messages through Inter-Arrival Time Analysis
abstract
Recent cyber-attacks to real vehicles demonstrated the risks related to connected vehicles, and spawned several research effort aimed at proposing algorithms and architectural solutions to improve the security of these vehicles. Most of the documented attacks to the connected vehicles require the injection of maliciously forged messages to subvert the normal behaviour of the electronic microcontrollers. More recently, researchers discovered that by abusing error isolation mechanisms of the Controller Area Network (CAN), one of the protocols deployed for in-vehicle networking, it is possible to isolate a microcontroller from the vehicle internal network (namely bus-off attack), with possible severe implication on both safety and security. This vulnerability has already been exploited for gaining remote control of a vehicle, by driving a targeted microcontroller in bus-off and impersonating it through the injection of malicious messages on the CAN bus. This paper strives to counter bus-off attacks by proposing an algorithm for the detection of missing messages from the in- vehicle CAN bus. Bus-off attacks to in-vehicle network are simulated by removing messages from valid CAN traces recorded from an unmodified licensed vehicle. Experimental evaluations of our proposal and comparisons with previous work demonstrate that the proposed algorithms outperforms other detection algorithms, achieving almost perfect detection (F-score equal or near to 1.0) across different tests.
Dario Stabili, Mirco Marchetti
VTC Fall1
2019 READ: Reverse Engineering of Automotive Data Frames
abstract
Security analytics and forensics applied to in-vehicle networks are growing research areas that gained relevance after recent reports of cyber-attacks against unmodified licensed vehicles. However, the application of security analytics algorithms and tools to the automotive domain is hindered by the lack of public specifications about proprietary data exchanged over in-vehicle networks. Since the controller area network (CAN) bus is the de-facto standard for the interconnection of automotive electronic control units, the lack of public specifications for CAN messages is a key issue. This paper strives to solve this problem by proposing READ: a novel algorithm for the automatic Reverse Engineering of Automotive Data frames. READ has been designed to analyze traffic traces containing unknown CAN bus messages in order to automatically identify and label different types of signals encoded in the payload of their data frames. Experimental results based on CAN traffic gathered from a licensed unmodified vehicle and validated against its complete formal specifications demonstrate that the proposed algorithm can extract and classify more than twice the signals with respect to the previous related work. Moreover, the execution time of signal extraction and classification is reduced by two orders of magnitude. Applications of READ to CAN messages generated by real vehicles demonstrate its usefulness in the analysis of CAN traffic.
Mirco Marchetti, Dario Stabili
IEEE Trans. Inf. Forensics Secur.2
2018 Analyses of Secure Automotive Communication Protocols and Their Impact on Vehicles Life-Cycle
abstract
Modern vehicles are complex cyber physical systems where communication protocols designed for physically isolated networks are now employed to connect Internet-enabled devices. This unforeseen increase in connectivity creates novel attack surfaces, and exposes safety-critical functions of the vehicle to cyber attacks. As standard security solutions are not applicable to vehicles due to resource constraints and compatibility issues, research is proposing tailored approaches to cope with existing systems and to design next generations vehicles. In this paper we focus on solutions based on cryptographic protocols to protect in-vehicle communications and prevent unauthorized manipulation of the vehicle behaviors. Existing proposals consider vehicles as monolithic systems and evaluate performance and costs of the proposed solutions without considering the complex life-cycle of automotive components and the multifaceted automotive ecosystem that includes a large number of actors. The main contribution of this paper is a study of the impact of security solutions by considering vehicles life-cycle. We model existing proposals and highlight their impacts on vehicles production and maintenance operations by taking into consideration interactions among multiple players. Finally, we give insights on the requirements of architectures for secure intra-vehicular protocols.
Dario Stabili, Luca Ferretti, Mirco Marchetti
SMARTCOMP1
2017 Anomaly detection of CAN bus messages through analysis of ID sequences
abstract
This paper proposes a novel intrusion detection algorithm that aims to identify malicious CAN messages injected by attackers in the CAN bus of modern vehicles. The proposed algorithm identifies anomalies in the sequence of messages that flow in the CAN bus and is characterized by small memory and computational footprints, that make it applicable to current ECUs. Its detection performance are demonstrated through experiments carried out on real CAN traffic gathered from an unmodified licensed vehicle.
Mirco Marchetti, Dario Stabili
Intelligent Vehicles Symposium2