Alessandro Brighente

dblp:196/4896 · DBLP profile ↗
← Back
61ranked-venue papers
18as first author
53since 2021 · last 2026
0000-0001-6138-2995ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 4 first-author · 25 since 2021Computer networks · 21 · 7 first-author · 17 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FivGeeFuzz : Authorization-Aware API Fuzzing of 5G Core Service-Based Interfaces
Riccardo Preatoni, Alessandro Brighente, Mauro Conti, Cristina Nita-Rotaru
ACNS (3)3
2026 Fooling the Deception: On The Feasibility of Detecting Chaff Bugs
abstract
Chaff bugs are non-exploitable vulnerabilities injected into software to deceive attackers and complicate vulnerability triage. While previous work demonstrated the feasibility of injecting chaff bugs, questions remain regarding their detectability and realism. In this paper, we propose two different approaches to detect chaff bugs using static and dynamic binary analysis techniques. We design and implement static detection rules based on known chaff bug design, whereas we leverage dynamic taint analysis to observe runtime behaviors such as anomalous data liveness and computational simplicity. Across eight binaries, our static analysis achieved a detection rate of approximately 95.7%, highlighting the effectiveness of structural pattern recognition when prior design assumptions are known. Dynamic analysis revealed that chaff bugs significantly alter data liveness characteristics compared to clean binaries. Our results demonstrate that while chaff bugs are detectable under informed analysis, achieving simultaneous realism, non-exploitability, and stealth remains an open challenge for future research. We also highlight promising directions such as adaptive, input-sensitive chaff bug designs and more resilient dynamic analysis frameworks.
Alessandro Brighente, Mauro Conti, Sitora Salaeva
AsiaCCS1
2026 Triad-GAN: Feature-Level Generative Adversarial Network for Multi-Receiver Radio Frequency Fingerprint Identification
Shuo Wang 0035, Junqing Zhang, Jiahuai Mao, Alessandro Brighente, Guanxiong Shen, Mauro Conti
ICC4
2026 Electric Vehicles Security and Privacy: Challenges, Solutions, and Future Needs
abstract
Electric Vehicles (EVs) share common technologies with classic fossil-fueled cars, but they also employ novel technologies and components (e.g., Charging System and Battery Management System) that create an unexplored attack surface for malicious users. Although several contributions in the literature explored cybersecurity aspects of particular components of the EV ecosystem (e.g., charging infrastructure), there is still no contribution to the holistic cybersecurity of EVs and their related technologies from a Cyber-Physical System (CPS) perspective. In this article, we provide the first in-depth study of the Security and Privacy (S&P) threats associated with the EV ecosystem. We analyze the threats associated with both the EV and the different charging solutions. Focusing on the CPS paradigm, we provide a detailed analysis of all the processes that an attacker might exploit to affect the S&P of both drivers and the infrastructure. To address the highlighted threats, we present possible solutions that might be implemented. We also provide an overview of possible future directions to guarantee the S&P of the EV ecosystem. Based on our analysis, we stress the need for EV-specific cybersecurity solutions to help both vehicle owners and infrastructure deployers securing the EV ecosystem.
Alessandro Brighente, Mauro Conti, Denis Donadel, Radha Poovendran, Federico Turrin, Jianjing Zhou
ACM Trans. Cyber Phys. Syst.1
2026 Obfuscated Location Disclosure for Remote ID Enabled Drones
abstract
The Remote ID (RID) regulation recently introduced by several aviation authorities worldwide (including the US and EU) forces commercial drones to regularly (max. every second) broadcast plain-text messages on the wireless channel, providing information about the drone identifier and current location, among others. Although these regulations increase the accountability of drone operations and improve traffic management, they allow malicious users to track drones via the disclosed information, possibly leading to drone capture and severe privacy leaks. In this paper, we propose Obfuscated Location disclOsure for RID-enabled drones (OLO-RID), a solution modifying and extending the RID regulation while preserving drones' location privacy. Rather than disclosing the actual drone's location, drones equipped with OLO-RID disclose a differentially private obfuscated location. OLO-RID also extends RID messages with encrypted location information, accessible only by authorized entities and valuable to obtain the current drone's location in safety-critical use cases. We design, implement, and deploy OLO-RID on a Raspberry Pi 3 and release the code of our implementation as open-source. We also perform an extensive performance assessment of the runtime overhead of our solution in terms of processing, communication, memory, and energy consumption. We show that OLO-RID can generate RID messages on a constrained device in less than 0.16 s while also requiring a minimal energy toll on a relevant device ($0.0236\%$of energy for a DJI Mini 2). We also evaluate the utility of the proposed approach in the context of three reference use cases involving the drones' location usage, demonstrating minimal performance degradation when trading off location privacy and utility for next-generation RID-compliant drone ecosystems.
Alessandro Brighente, Mauro Conti, Matthijs Schotsman, Savio Sciancalepore
IEEE Trans. Dependable Secur. Comput.1
2026 Step Into Balance: A Consistency-Aware and Loose Homophily Guided Generative Method for Class-Imbalanced Graphs
abstract
Graph Neural Networks (GNNs) have demonstrated remarkable success in various scenarios. However, their impressive performance is under the assumption of class balance (i.e., equal training sample distribution across various categories). Once trapped in the class-imbalanced issue, the GNN-based models typically under-represent the minority ones, resulting in decreased performance compared to balanced graphs. A promising solution is to balance the graph in a generative manner. However, the existing studies overlook the consistency between the synthesized sample and its corresponding class. Furthermore, the homophily assumption (i.e., like attracts like) undermines the topological diversity of graphs, thereby complicating the capability of models to capture the true distribution and boundaries of the categories. To this end, we propose aConsistency-Aware andLooseHomophily guided generative method for class-imbalanced graphs, namelyGraphCALH. Specifically, we design a consistency-aware feature synthesis method to balance the node- wise characteristics and the class- wise commonality for the synthesized samples. Moreover, we devise a loose homophily guided topology modeling method to enrich the topological diversity and simplify category boundaries. The experimental results on eleven class-imbalanced datasets demonstrate that the proposed GraphCALH outperforms ten state-of-the-art methods. The source code of this work will be uploaded to Github.
Gen Liu 0001, Zhongying Zhao 0001, Chao Li 0022, Qingtian Zeng, Shuo Wang 0035, Alessandro Brighente, Mauro Conti
IEEE Trans. Knowl. Data Eng.6
2025 SHIELD: Scalable and Holistic Evaluation Framework for ML-Based 5G Jamming Detection
Aya Moheddine, Valeria Loscrì, Alessandro Brighente, Mauro Conti
ARES (1)4
2025 The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
Giacomo Benedetti, Serena Cofano, Alessandro Brighente, Mauro Conti
ACNS (2)3
2025 CANTXSec: A Deterministic Intrusion Detection and Prevention System for CAN Bus Monitoring ECU Activations
Denis Donadel, Kavya Balasubramanian, Alessandro Brighente, Bhaskar Ramasubramanian, Mauro Conti, Radha Poovendran
ACNS (2)3
2025 AWOSE: Probabilistic State Model for Consensus Algorithms' Fuzzing Frameworks
Tannishtha Devgun, Gulshan Kumar, Rahul Saha, Alessandro Brighente, Mauro Conti
AsiaCCS4
2025 GANSec: Enhancing Supervised Wireless Anomaly Detection Robustness Through Tailored Conditional GAN Augmentation
Shuo Wang 0035, Valeria Loscrì, Alessandro Brighente, Mauro Conti, Romain Rouvoy
ESORICS (1)4
2025 Your Car Tells Me Where You Drove: A Novel Path Inference Attack via CAN Bus and OBD-II Data
abstract
During police investigations, the possibility of extracting coordinates data of a vehicle without relying on GPS is vital because the targets may know about possible bugs using this technology and take action against them. To this aim, extracting non-encrypted data from the Controller Area Network (CAN) provides a valid solution for officers. Indeed, CAN exchanges non-encrypted data, including physical information about the car’s movement. In this paper, we present On Path Diagnostic - Intrusion & Inference (OPD-II), a novel path inference attack leveraging a physical car model and a map matching algorithm to infer the path driven by a car based on CAN bus data. Unlike available attacks, our approach only requires the attacker to know the initial location and heading of the victim’s car and is not limited by the availability of training data, road configurations, or the need to access other victim’s devices (e.g., smartphones). We implement our attack on a set of four different cars and a total number of 59 tracks in different road and traffic scenarios. We achieve an average 95.75% accuracy in reconstructing the coordinates of the recorded path by leveraging a dynamic map matching algorithm that outperforms other state-of-the-art proposals while removing their set of assumptions.
Tommaso Bianchi, Alessandro Brighente, Mauro Conti, Andrea Valori
EuroS&P2
2025 Endless Subscriptions: Open RAN is Open to RIC E2 Subscription Denial of Service Attacks
abstract
Telecommunication services are essential in ensuring the operation of numerous critical infrastructures. While mobile network security increased with the advancement of generations, emerging concepts such as the Open Radio Access Network (O-RAN) are transforming the traditional operation of Radio Access Networks (RANs). Novel concepts and technologies are finding their way into RANs with a focus on softwareization and virtualization. This increases the overall attack surface and introduces new attack vectors not necessarily found in traditional RANs. This paper shows that Denial of Service (DoS) attacks leveraging subscription mechanisms can compromise O-RAN implementations. We present a novel DoS attack targeting the Near Real-Time (Near-RT) RAN Intelligent Controller (RIC). By deploying a malicious xApp, we demonstrate how an adversary can flood the Near-RT RIC with excessive subscription requests, leading to service disruption. This attack exploits the lack of rate-limiting mechanisms within the Service Model (SM), a critical component of the Near-RT RIC responsible for handling E2 subscription requests. We systematically evaluate various attack scenarios and investigate the underlying vulnerabilities exposed. Furthermore, we propose and assess countermeasures to safeguard publicly accessible O-RAN systems from such threats.
Felix Klement, Alessandro Brighente, Anup Kiran Bhattacharjee, Stefano Cecconello, Fernando A. Kuipers, Georgios Smaragdakis, Mauro Conti, Stefan Katzenbeisser 0001
EuroS&P2
2025 Capodoglio: Tackling Multi-Armed Bandit Jamming Attacks
abstract
Jamming attacks present a significant security threat to wireless networks by exploiting the open wireless medium, causing not only a denial-of-service, but also overloading the network and interfering with signals. The jamming attack can enable more sophisticated disruptions, such as protocol-aware and learning-based jamming, where adversaries transmit selectively upon detecting legitimate network activity, and this selective transmission conserves attacker resources and complicates detection. Channel hopping is widely adopted as a mitigation strategy, allowing networks to move away from interfered channels dynamically. However, recent studies have demonstrated that intelligent jammers, such as the Multi-Armed Bandit (MAB)-based attack, can effectively learn and predict channel hopping patterns, thereby continuously jamming communications and severely degrading network performance. Designing robust countermeasures against such intelligent jamming remains an open and critical challenge. In this paper, we analyze a kind of MAB-based attack methodology and propose two refined variants employing online and offline paradigms. To counteract these advanced threats, we introduce three defense strategies: (i) speeding up, which modifies the frequency of channel-hopping decisions to avoid the jammer’s attack, (ii) deploying a helper node, diversify the communication patterns to affect the attacker’s learning process, and (iii) employing a mirror Multi-Armed Bandit (mirror MAB) approach to predict and bypass channels of highest jamming probability. Comprehensive evaluations demonstrate the effectiveness of our proposed defenses, significantly mitigating MAB-based attacks. Specifically, our strategies achieve a PDR exceeding 90% under persistent attack conditions, while effectively preserving robust and dynamic channel hopping behaviors.
Shuo Wang 0035, Alessandro Brighente, Valeria Loscrì, Junqing Zhang, Mauro Conti
TrustCom2
2025 Evaluation of Post-Quantum Key Encapsulation Methods in 5G Core Network
abstract
The fifth generation of mobile networks (5G) is among the critical infrastructures whose security and privacy requirements are paramount. Compared to previous generations, 5G leverages a service-based architecture where many Network Functions (NF), i.e., the set of microservices on which is based the architecture, need secure communication means. NFs can communicate using HTTP2, and despite not being required by the standard, they can use Transport Layer Protocol (TLS) to ensure data integrity and authentication across the network. However, with the expected arrival of quantum computers in the near future, traditional cryptographic algorithms are under significant threat. With the recent run for post-quantum standardization, the NIST selected possible candidate algorithms. However, no study evaluates whether such algorithms would be applicable in the 5G core without significant performance degradation. In this paper, we perform the first assessment of the feasibility of using post-quantum secure Key Encapsulation Mechanism (KEM) for the 5G core network. To this aim, we implemented and compared the performances of five algorithms among those selected during the NIST standardization process. We adapted those algorithms to implement them in a standalone 5G core implemented via Open5GS, and tested their performance when performing user registration. Our results show that the KY-BER768 achieves comparable performance to TLS in terms of UE registration time and CPU utilization, thus being a candidate solution to improve the security posture of the 5G core.
Alessandro Corsi, Savas Gür, Alessandro Brighente, Mauro Conti
WCNC3
2025 $L^{2}S^{2}C^{2}$: Lattice-based Lightweight Scheme for Secure Communication in Controller Area Networks
abstract
The Controller Area Network (CAN) is a standard bus-based communication protocol for reliable Cyber-Physical Systems. For instance, in cars, around 100 Electronic Control Units (ECUs) are connected via CAN. Recent news proves that attackers can easily connect external devices to the CAN bus and gain control over ECUs communications, have access to the car, and possibly steal it. Despite the existing literature on authentication protocols designed for CAN buses, no existing work currently tackles the further threat imposed by the growing interest and developments of quantum computing. In this paper, we propose$L^{2}S^{2}C^{2}$, a novel post-quantum authentication protocol that leverages Physically Unclonable Functions (PUF) and Lattice-based Cryptography (LBC). The usage of PUF in$L^{2}S^{2}C^{2}$ensures low storage cost, while the lattice-based formulation ensures resistance to quantum attacks. _$\lrcorner \mathrm{r}^{2}S^{2}C^{2}$is resistant to different types of attacks such as replay, false message injection, plain text, collision, ML attacks, man-in-the-middle, impersonation, sybil, denial-of-service, and bus-off, other than quantum attacks. The performance analysis results reveal that$L^{2}S^{2}C^{2}$ensures improved security and reliability than the state-of-the-art.
Harsha Vasudev, Alessandro Brighente, Mauro Conti
WCNC2
2025 Ghost of the Navigator: Spoofing Attack Against Direction-of-Arrival Estimation
abstract
Direction of Arrival (DOA) estimation has been widely studied and applied in real-life systems. However, little attention has been given to the risk posed by attackers trying to hide real targets or create fake ones. This poses a serious security and safety concern, as such attacks could lead to system failures or accidents. In this paper, we proposeDOA spoofing, the first physical layer attack that exploits the semantic gap between DOA estimation outputs and the existing physical location of targets to spoof the perceived sources’ location. We consider two scenarios:i)the attacker wants to create ghost targets at desired locations while being undetected, andii)the attacker wants to change the DOA estimated at the receiver for a target victim. To evaluate the effectiveness of DOA spoofing, we test it against several widely used and well-established DOA estimation algorithms. Via extensive numerical simulations, we demonstrate that in both scenarios the attacker can spoof DOA estimates at the receiver while not being detected among the targets. To the best of our knowledge, this paper presents the first study to examine the impact of DOA attacks on the behavior of radar perception models. Therefore, although not providing a real-life testbed due to the challenges of implementing a non-commercial multi-antenna system, our contribution exposes novel threats thanks to the use of algorithms and models commonly used in real-life DOA estimation.
Saiqin Xu, Alessandro Brighente, Baixiao Chen, Mauro Conti, Shuai Peng
IEEE Internet Things J.2
2025 Identity-Based Authentication for On-Demand Charging of Electric Vehicles
abstract
Dynamic wireless power transfer provides a means for charging Electric Vehicles (EVs) while driving, avoiding stopping to charge and hence fostering their widespread adoption. Researchers have devoted much effort over the last decade to providing a reliable infrastructure for potential users to improve their comfort and time management. Due to the severe security and performance system requirements, the different schemes proposed in the last years lack a unified protocol involving the modern architecture model with merged authentication and billing processes. Furthermore, they require the continuous interaction of the trusted entity during the process, increasing the delay in communication and reducing security due to a large number of message exchanges. This article proposes a secure, computationally lightweight, unified protocol for fast authentication and billing that provides on-demand dynamic charging to deal with all the computational and security comprehensively with additional usability for the customers. The protocol employs an ID-based public encryption scheme to manage mutual authentication and pseudonyms to preserve the user's identity across multiple charging processes. Compared to state-of-the-art authentication protocols, our proposal provides on-demand service and public critical infrastructure security without impacting performances with around 7 ms, close to the most straightforward scheme available.
Surudhi Asokraj, Tommaso Bianchi, Alessandro Brighente, Mauro Conti, Radha Poovendran
IEEE Trans. Dependable Secur. Comput.3
2025 CANLP: Intrusion Detection for Controller Area Networks Using Natural Language Processing and Embedded Machine Learning
abstract
The Controller Area Network (CAN) protocol is the most widely used standard in the automotive industry for in-vehicle networks. However, the CAN protocol lacks essential security features such as encryption and message authentication. Absence of such security features has been shown to make the vehicle network vulnerable to exploits by an adversary. Although multiple types of intrusion detection systems (IDS) have been developed for CAN, it can be difficult to deploy them in real-time with low latency. Further, many of these IDSs are unable to isolate specific CAN frames on which an attack has been mounted, which makes it challenging to design defense mechanisms. In this paper, we develop CANLP, a Natural Language Processing (NLP)-based intrusion detection system to determine whether each transmitted message originated from a legitimate ECU or an adversary. CANLP uses Term Frequency-Inverse Document Frequency (TF-IDF), a NLP technique to discern complex features associated with CAN data and trains machine learning models to identify three types of attacks- fuzzing, spoofing, and masquerade. When an attack is detected, CANLP identifies the malicious CAN frame, which is important for developing resilient systems. Extensive experiments on 4 publicly available vehicle network datasets (which represent data collected from over three vehicle makes and four models) show that CANLP performs attack classification with high F1-scores of 0.9974. We also show that CANLP can be deployed for attack detection on resource-constrained hardware through implementation using RaspberryPi and experiments on a testbed with latency as low as$\lt \text{0.05}~ms$, making it suitable for real-world automotive applications such as fleet monitoring within the same vehicle class.
Kavya Balasubramanian, Adithya Gowda Baragur, Denis Donadel, Dinuka Sahabandu, Alessandro Brighente, Bhaskar Ramasubramanian, Mauro Conti, Radha Poovendran
IEEE Trans. Dependable Secur. Comput.5
2025 Channel-Robust RF Fingerprint Identification for Multi-Antenna 5G User Equipments
abstract
Radio frequency fingerprint (RFF) is a promising solution for realizing secure and efficient device identification. However, the accuracy of currently existing solutions suffer from multipath effects in practical scenarios. In this paper, we provide a robust RFF identification method that leverages channel state information (CSI) feedback to counteract the effect of the channel on the extracted RFF features. A straightforward zero-forcing (ZF) equalization fails to fully decouple RF impairments from the channel, making conventional approaches ineffective. To overcome this challenge, we utilize the potential of multi-antenna and introduce a new device-specific feature called Relative-RFF (R-RFF), which represents the relation between different RF chains in a multi-antenna transmitter. We propose an enhanced ZF post-equalization algorithm to eliminate the multipath channels and preserve the users’ R-RFF to the greatest extent. We evaluate the robustness of R-RFF under various channel conditions and noise levels and the performance of R-RFF in terms of identification accuracy under different channel scenarios. The results show that the proposed R-RFF method can achieve an identification accuracy of 91.2% for 70 devices in tapped delay line channel with a signal-to-noise ratio (SNR) of 30 dB.
Hongyi Luo, Guyue Li, Alessandro Brighente, Mauro Conti, Yuexiu Xing, Aiqun Hu, Xianbin Wang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 EPUF: An Entropy-Derived Latency-Based DRAM Physical Unclonable Function for Lightweight Authentication in Internet of Things
abstract
Physical Unclonable Functions (PUFs) are hardware-based mechanisms that exploit inherent manufacturing variations to generate unique identifiers for devices. Dynamic Random Access Memory (DRAM) has emerged as a promising medium for implementing PUFs, providing a cost-effective solution without the need for additional circuitry. This makes DRAM PUFs ideal for use in resource-constrained environments such as Internet of Things (IoT) networks. However, current DRAM PUF implementations often either disrupt host system functions or produce unreliable responses due to environmental sensitivity. In this paper, we present EPUF, a novel approach to extracting random and unique features from DRAM cells to generate reliable PUF responses. We leverage bitmap images of binary DRAM values and their entropy features to enhance the robustness of our PUF. Through extensive real-world experiments, we demonstrate that EPUF is approximately 1.7 times faster than existing solutions, achieves 100% reliability, produces features with 47.79% uniqueness, and supports a substantial set of Challenge-Response Pairs (CRPs). These capabilities make EPUF a powerful tool for DRAM PUF-based authentication. Based on EPUF, we then propose a lightweight authentication protocol that not only offers superior security features but also surpasses state-of-the-art authentication schemes in terms of communication overhead and computational efficiency.
Fatemeh Najafi, Masoud Kaveh, Mohammad Reza Mosavi, Alessandro Brighente, Mauro Conti
IEEE Trans. Mob. Comput.4
2025 PriVeriFL: Privacy-Preserving and Aggregation-Verifiable Federated Learning
abstract
Federated learning provides a collaborative way to build machine learning models without sharing private data. However, attackers might infer private information from model updates submitted by participants, and the aggregator might maliciously forge the final aggregation results. Federated learning still faces data privacy and aggregation integrity challenges. In this paper, we combine inference attacks and information theory to analyze the sensitivity of different bits of model parameters. We conclude that not all bits of model parameters will leak privacy. This realization inspires us to propose a novel low-expansion homomorphic aggregation scheme based on Paillier homomorphic encryption (PHE) for safeguarding participants’ data privacy. Building upon this, we develop PriVeriFL-A, a privacy-preserving and aggregation-verifiable federated learning scheme that combines homomorphic hash function and signature. To prevent collusion attacks between the aggregator and malicious participants, we further improve our PHE-based scheme into a threshold PHE-based one, named PriVeriFL-B. Compared with the privacy-preserving federated learning scheme based on classic PHE, PriVeriFL-A reduces the communication overhead to 1.65%, and the encryption/decryption computation overhead to 0.88%. Both PriVeriFL-A and PriVeriFL-B can effectively verify the integrity of the global model, while maintaining an almost negligible communication overhead for integrity verification and protecting the privacy of participants’ data.
Lulu Wang 0015, Mirko Polato, Alessandro Brighente, Mauro Conti, Lei Zhang 0009, Lin Xu 0010
IEEE Trans. Serv. Comput.3
2024 FaultGuard: A Generative Approach to Resilient Fault Prediction in Smart Electrical Grids
Emad Efatinasab, Francesco Marchiori, Alessandro Brighente, Mirco Rampazzo, Mauro Conti
DIMVA3
2024 GAN-GRID: A Novel Generative Attack on Smart Grid Stability Prediction
Emad Efatinasab, Alessandro Brighente, Mirco Rampazzo, Nahal Azadi, Mauro Conti
ESORICS (1)2
2024 Physical Layer Authentication for Distributed RIS (DRIS) Enabled VLC Systems
abstract
The introduction of Reflective Intelligent Surfaces (RIS) brings significant advancements in communication systems, such as increased capacity, communication secrecy, and novel physical layer-based authentication schemes. Besides Radio Frequency (RF) communications, RISs also benefit Visible Light Communications (VLC). Indeed, recent results showed that it is possible to increase the communication secrecy of VLC systems by leveraging RISs and their reconfiguration capabilities. However, no solution exists to authenticate a transmitter at the physical layer in VLC systems. Despite the existence of RIS-based Physical Layer Authentication (PLA) schemes in the RF domain, the geometrical behaviour of VLC channels renders these solutions not trivially portable to VLC systems. This paper proposes the first physical layer-based authentication scheme for VLC systems. The legitimate transmitter leverages a time-slotted communication to send a certain number of pre-agreed challenges to the receiver. Although an attacker might be able to replicate some of these challenges, the probability of correctly guessing all of them is very low. As an enabling component of our scheme, we propose the novel Distributed RIS (DRIS) concept, i.e., a RIS whose Reflecting Elements (RE) are spread over a wider area than traditional RISs. Thanks to DRIS, we increase the spatial diversity of the VLC channel model available at the transmitter, breaking hence the limits imposed by the symmetries of the widely accepted geometrical VLC channel. We validate our scheme via numerical simulations and compare our results with those obtained with a similar scheme implemented with a conventional RIS. We show that thanks to Distributed Reflective Intelligent Surface (DRIS), we achieve 10–3probability of false alarm and 10–1probability of misdetection with and Signal-to-Noise Ratio (SNR) of 10dB, while classical Reflective Intelligent Surface (RIS) achieve 0.7 probability of false alarm and 0.5 probability of misdetection for the same SNR value. DRIS represents a significant improvement for physical layer-based authentication schemes in VLC, paving the way for further research on the subject.
Alessandro Brighente, Saiqin Xu, Simone Soderi, Mauro Conti
ICC1
2024 Penetration Testing of 5G Core Network Web Technologies
abstract
Thanks to technologies such as virtual network function the Fifth Generation (5G) of mobile networks dynamically allocate resources to different types of users in an on-demand fashion. Virtualization extends up to the 5G core, where software-defined networks and network slicing implement a customizable environment. These technologies can be controlled via application programming interfaces and web technologies, inheriting hence their security risks and settings. An attacker exploiting vulnerable implementations of the 5G core may gain privileged control of the network assets and disrupt its availability. However, there is currently no security assessment of the web security of the 5G core network. In this paper, we present the first security assessment of the 5G core from a web security perspective. We use the STRIDE threat modeling approach to define a complete list of possible threat vectors and associated attacks. Thanks to a suite of security testing tools, we cover all of these threats and test the security of the 5G core. In particular, we test the three most relevant open-source 5G core implementations, i.e., Open5GS, Free5Gc, and OpenAir Interface. Our analysis shows that all these cores are vulnerable to at least two of our identified attack vectors, demanding increased security measures in the development of future 5G core networks.
Filippo Giambartolomei, Marc Barcelo, Alessandro Brighente, Aitor Urbieta, Mauro Conti
ICC3
2024 Securing the Open RAN Infrastructure: Exploring Vulnerabilities in Kubernetes Deployments
abstract
In this paper, we investigate the security implications of virtualized and software-based Open Radio Access Network (RAN) systems, specifically focusing on the architecture proposed by the O-RAN ALLIANCE and O-Cloud deployments based on the O-RAN Software Community (OSC) stack and infrastructure. Our key findings are based on a thorough security assessment and static scanning of the OSC Near Real-Time RAN Intelligent Controller (RIC) cluster. We highlight the presence of potential vulnerabilities and misconfigurations in the Kubernetes infrastructure supporting the RIC, also due to the usage of outdated versions of software packages, and provide an estimation of their criticality using various deployment auditing frameworks (e.g., MITRE ATT&CK and the NSA CISA). In addition, we propose methodologies to minimize these issues and harden the Open RAN virtualization infrastructure. These encompass the integration of security evaluation methods into the deployment process, implementing deployment hardening measures, and employing policy-based control for RAN components. We emphasize the need to address the problems found in order to improve the overall security of virtualized Open RAN systems.
Felix Klement, Alessandro Brighente, Michele Polese, Mauro Conti, Stefan Katzenbeisser 0001
NetSoft2
2024 Reduce to the MACs - Privacy Friendly Generic Probe Requests
Johanna Ansohn McDougall, Alessandro Brighente, Anne Kunstmann, Niklas Zapatka, Hannes Federrath
SEC2
2024 Privacy-Preserving Data Aggregation with Public Verifiability Against Internal Adversaries
Marco Palazzo, Florine W. Dekker, Alessandro Brighente, Mauro Conti, Zekeriya Erkin
USENIX Security Symposium3
2024 DynamiQS: Quantum Secure Authentication for Dynamic Charging of Electric Vehicles
abstract
Dynamic Wireless Power Transfer (DWPT) is a novel technology that allows charging an electric vehicle while driving thanks to a dedicated road infrastructure. DWPT's capabilities in automatically establishing charging sessions and billing without users' intervention make it prone to cybersecurity attacks. Hence, security is essential in preventing fraud, impersonation, and user tracking. To this aim, researchers proposed different solutions for authenticating users. However, recent advancements in quantum computing jeopardize classical public key cryptography, making currently existing solutions in DWPT authentication nonviable. To avoid the resource burden imposed by technology upgrades, it is essential to develop post-quantum-resistant solutions. In this paper, we propose DynamiQS, the first post-quantum secure authentication protocol for dynamic wireless charging. DynamiQS is privacy-preserving and secure against attacks on the DWPT. We leverage an Identity-Based Encryption with Lattices in the Ring Learning With Error framework. Furthermore, we show the possibility of using DynamiQS in a real environment, leveraging the results of cryptographic computation on real constrained devices and simulations. DynamiQS reaches a total time cost of around 281 ms, which is practicable in dynamic charging settings (car and charging infrastructure).
Tommaso Bianchi, Alessandro Brighente, Mauro Conti
WISEC2
2024 EDIT: A data inspection tool for smart contracts temporal behavior modeling and prediction
abstract
Modeling and predicting the behavior of nodes and users in blockchains provide opportunities for business strategy optimization. Indeed, the number of interactions of a node is strictly related to its balance and its prediction may be used for analytics purposes and investment strategies. However, the amount and diversity of information stored on the blockchain demand advanced tools for the modeling and analysis of blockchain data. Such tools should be able to capture the dynamicity and interaction of multiple independent actors, considering a large number of variables and dynamic interaction graph topologies. This is exacerbated by the use of smart contracts, programs stored in blockchain blocks that bring automation to blockchain’s operations and thus increasing the variability of the resulting interaction graphs. Existing modeling methodologies are unable to keep track of all these details, as they are not able to capture the temporal variability of the network. In this paper, we propose a novel framework for modeling and predicting the behavior of smart contracts on a blockchain. We propose the concept of temporal smart contracts networks, i.e., graphs representing the temporal evolution of interactions and data flow. Our framework allows the creation of temporal smart contract networks with different granularity levels by considering different interaction patterns between smart contracts, externally owned accounts, and internal transactions. Thanks to these graphs, we are able to model features such as the node in degree and amount of ether received by a smart contract, which are directly related to its behavior. We incorporate our modeling approach in Ethereum Data Inspection Tool (EDIT), a novel tool able to model interactions and predict them based on historical data. We test different machine learning models to predict features extracted by EDIT, hence allowing for the prediction of the overall behavior of the smart contract. We test EDIT on the Ethereum blockchain and model several temporal smart contracts networks, which represent the interactions and the data flow resulting from about 4 000 000 consecutive blocks. The evaluation of different real case studies shows that the proposed framework is able to predict, with a mean absolute error close to 1%, the evolution of several interesting properties (e.g., amount of received ether) related to both accounts and smart contracts.
Andrea De Salve, Alessandro Brighente, Mauro Conti
Future Gener. Comput. Syst.2
2024 Security and Privacy of Smart Waste Management Systems: A Cyber-Physical System Perspective
abstract
Smart waste management systems (SWMSs) represent a fundamental technology to efficiently manage the waste management and disposal process. Indeed, they provide means to efficiently manage the collection process, optimize resources, and foster the adoption of recycling policies. These systems are increasingly more connected and equipped with communication and sensing capabilities. Currently, the research on SWMSs security only focuses on the communication part. However, SWMSs may be subject to different cyber–physical threats due to the interconnection of information and operational technologies. In this article, we investigate the security and privacy issues of SWMSs from a cyber–physical system perspective. To provide a clear understanding of the possible threats, we first provide an overview of the current state of the art on SWMSs implementations. We then review the attacks and security measures proposed in the literature, showing that they solely focus on communication technologies. Then, we provide a thorough overview of all possible cyber–physical threats toward SWMSs. Our analysis shows that SWMSs are still vulnerable to a large number of threats impacting both the system’s and the users’ security, privacy, and safety.
Alessandro Brighente, Mauro Conti, Gabriele Di Renzone, Giacomo Peruzzi, Alessandro Pozzebon
IEEE Internet Things J.1
2024 Light-YOLOv5: A Lightweight Drone Detector for Resource-Constrained Cameras
abstract
Critical infrastructures (CIs), such as military bases and airports, are putting a lot of attention into defending against attacks delivered via drones by deploying drone detection systems. However, the CI area might be very large, with no-fly zones extending to regions where it might not be possible to deploy a power line for resourceful cameras. To this aim, the CI might deploy an Internet of Things (IoT)-based surveillance camera system to capture drone images. However, these IoT cameras are resource-constrained devices that cannot support the currently available detectors. In this article, we propose Light-YOLOv5, a lightweight image-based drone detector for resource-constrained cameras. We make targeted improvements to YOLOv5, including the replacement of the backbone network, the introduction of the transformer module, and the design of a parallel mixed efficient attention module (PEAM). We show that our modifications allow for reduced network size while achieving better classification than other state-of-the-art solutions. To prove these claims, we expanded an already available data set of blurred drone images by adding clear images of aircraft and birds. Since airplanes and birds are easily confused as drones by image classifiers, our addition proves the effectiveness of our solution. Experiments show that Light-YOLOv5 can achieve a very good tradeoff between performance (74.8% mAP) and efficiency (170 FPS). Compared to YOLOv5, Light-YOLOv5 improves mAP by 4.1%, reduces the number of network parameters by 15.7%, can perform detection at 170 frames per second (FPS), and achieves an average accuracy rate of 93.8%.
Alessandro Brighente, Mauro Conti
IEEE Internet Things J.3
2024 EVScout2.0: Electric Vehicle Profiling through Charging Profile
abstract
Electric Vehicles (EVs) represent a green alternative to traditional fuel-powered vehicles. To enforce their widespread use, both the technical development and the security of users shall be guaranteed. Users’ privacy represents a possible threat that impairs the adoption of EVs. In particular, recent works showed the feasibility of identifying EVs based on the current exchanged during the charging phase. In fact, while the resource negotiation phase runs over secure communication protocols, the signal exchanged during the actual charging contains features peculiar to each EV. In what is commonly known as profiling, a suitable feature extractor can associate such features to each EV. In this article, we propose EVScout2.0 , an extended and improved version of our previously proposed framework to profile EVs based on their charging behavior. By exploiting the current and pilot signals exchanged during the charging phase, our scheme can extract features peculiar for each EV, hence allowing their profiling. We implemented and tested EVScout2.0 over a set of real-world measurements considering over 7,500 charging sessions from a total of 137 EVs. In particular, numerical results show the superiority of EVScout2.0 with respect to the previous version. EVScout2.0 can profile EVs, attaining a maximum of 0.88 for both recall and precision scores in the case of a balanced dataset. To the best of the authors’ knowledge, these results set a new benchmark for upcoming privacy research for large datasets of EVs.
Alessandro Brighente, Mauro Conti, Denis Donadel, Federico Turrin
ACM Trans. Cyber Phys. Syst.1
2024 RANGO: A Novel Deep Learning Approach to Detect Drones Disguising from Video Surveillance Systems
abstract
Video surveillance systems provide means to detect the presence of potentially malicious drones in the surroundings of critical infrastructures. In particular, these systems collect images and feed them to a deep-learning classifier able to detect the presence of a drone in the input image. However, current classifiers are not efficient in identifying drones that disguise themselves with the image background, e.g., hiding in front of a tree. Furthermore, video-based detection systems heavily rely on the image’s brightness, where darkness imposes significant challenges in detecting drones. Both these phenomena increase the possibilities for attackers to get close to critical infrastructures without being spotted and hence be able to gather sensitive information or cause physical damages, possibly leading to safety threats. In this article, we propose RANGO, a drone detection arithmetic able to detect drones in challenging images where the target is difficult to distinguish from the background. RANGO is based on a deep learning architecture that exploits a Preconditioning Operation (PREP) that highlights the target by the difference between the target gradient and the background gradient. The idea is to highlight features that will be useful for classification. After PREP, RANGO uses multiple convolution kernels to make the final decision on the presence of the drone. We test RANGO on a drone image dataset composed of multiple already-existing datasets to which we add samples of birds and planes. We then compare RANGO with multiple currently existing approaches to show its superiority. When tested on images with disguising drones, RANGO attains an increase of 6.6% mean Average Precision (mAP) compared to YOLOv5 solution. When tested on the conventional dataset, RANGO improves the mAP by approximately 2.2%, thus confirming its effectiveness also in the general scenario.
Yun-Feng Ren, Alessandro Brighente, Mauro Conti
ACM Trans. Intell. Syst. Technol.3
2024 Secure Source Identification Scheme for Revocable Instruction Sharing in Vehicle Platoon
abstract
The secure transmission of instructions among vehicles in a platoon is one of the most essential needs for a vehicle platoon. Despite the existence of cryptographic methods to securely share instructions, instruction sharing is still subject to forgery, tampering, and denial-of-service attacks. Therefore, it is urgent to find a solution to perform data source identification to filter out irrelevant information (not instructions) while ensuring the authenticity of encrypted instructions is urgent to address. In addition, immediate revocation of credentials is also a crucial requirement for a vehicle platoon when an authorized vehicle member misbehaves. In this paper, we propose the first Secure Source Identification Scheme for Revocable Instruction Sharing (SI-RIS) to securely simultaneously achieve bilateral fine-grained access control, data source identification, immediate vehicle user revocation, and efficient encryption in vehicle platoons. Specifically, our SI-RIS solution supports fine-grained access control for both the sender and receiver over the encrypted instructions. As a result, only authorized correspondents are able to access the commands. Furthermore, upon identification of malicious members in the platoon, our SI-RIS provides an efficient direct vehicle user revocation mechanism capable of immediate revocation credentials without affecting other vehicles. We prove the security of our SI-RIS via rigorous mathematical security proof. Moreover, performance evaluation and comparisons illustrate the feasibility and practicability of SI-RIS for vehicle platoon.
Yanan Zhao 0002, Haiyang Yu 0002, Yuhao Liang, Alessandro Brighente, Mauro Conti, Jianfei Sun, Yilong Ren
IEEE Trans. Intell. Transp. Syst.4
2024 Multi-RIS Aided VLC Physical Layer Security for 6G Wireless Networks
abstract
Recent studies highlighted the advantages of Visible Light Communication (VLC) over radio technology for future 6G networks. Thanks to the use of Reflective Intelligent Surfaces (RISs), researchers showed that is possible to guarantee communication secrecy in a VLC network where the adversary location is unknown. However, the problem of authenticating the transmitter with a low-complexity physical layer solution while guaranteeing communication secrecy is still open. This paper proposes a novel multi-RIS architecture to guarantee source authentication, communication secrecy, and integrity in a VLC scenario. We leverage the intuition that a signal transmitted by users located in different positions will undergo a different propagation path to discriminate between the legitimate intended transmitter and an attacker. To increase the channel's variability and reduce the chances that an adversary might be able to replicate it, we leverage the reconfiguration capabilities of RIS. We derive a statistical characterization of the non-line-of-sight VLC channel, representing the light reflected by RIS elements. Via numerical simulations, we show that the channel variability combined with the configurability capabilities of RISs provide sufficient statistics to authenticate the legitimate transmitter at the physical layer.
Simone Soderi, Alessandro Brighente, Saiqin Xu, Mauro Conti
IEEE Trans. Mob. Comput.2
2024 Enabling Low Sidelobe Secret Multicast Transmission for mmWave Communication: An Integrated Oblique Projection Approach
abstract
The protection of multicast transmission with optimized secrecy in millimeter-wave (mmWave) communication is still an open problem. In this paper, we propose a low sidelobe secret multicast transmission scheme in mmWave communication based on physical layer security techniques. By utilizing oblique projection, we jointly adopt the directional modulation (DM) and the artificial noise (AN) to achieve secret multicast transmission at low computational costs, without jeopardizing the low sidelobe transmitting pattern. Specifically, considering the constraint of multibeam with the channel knowledge of all target users, a primary transmitting weight vector of the base station (BS) is designed to achieve a low sidelobe transmitting pattern. Then, in each symbol period, the transmitting weight vector of the BS is updated by performing a linear transformation on the primary weight vector with a transformation matrix, which is obtained from the oblique projection matrices of all the target users’ channel vectors. In this way, without deteriorating the primary weight vector’s low sidelobe transmitting pattern, the obtained transmitting weight vector synthesizes the expected symbols at the target users and adds randomness to the eavesdroppers at undesired directions. Finally, the simulations demonstrate that our proposed scheme achieves outstanding communication performance for the target users at low computational costs, while keeping the high symbol error rates at the undesired directions.
Jianbing Ni, Meng Li 0006, Alessandro Brighente, Mauro Conti
IEEE Trans. Wirel. Commun.4
2023 Evaluation of Channel Hopping Strategies Against Smart Jamming Attacks
abstract
Channel hopping is a well-known methodology to dynamically allocate frequency resources to nodes in wireless communication systems. The aim of channel hopping is to mitigate possible interference issues caused by both legitimate and malicious users. The state-of-the-art channel hopping-based jamming mitigation techniques are becoming increasingly smart by using game theory or machine learning. However, we show in this paper that, although the victim may employ smart channel hopping strategies, these are not always effective in mitigating attacks. In this paper, we implement an effective jamming attack strategy to impair the effectiveness of channel hopping mitigation strategies. We test our attack on a testbed network composed by real devices, and test its effectiveness against three mitigation strategies: i) incremental channel hopping, ii) random channel hopping, and iii) smart channel hopping. We show that, by implementing our attack, an attacker can reduce the number of successfully transmitted packets by at least 28.5%, even against the smart channel hopping strategy,
Emilie Bout, Valentin Bout, Alessandro Brighente, Mauro Conti, Valeria Loscrì
ICC3
2023 LoVe is in the Air - Location Verification of ADS-B Signals using Distributed Public Sensors
abstract
The Automatic Dependant Surveillance-Broadcast (ADS-B) message scheme was designed without any authentication or encryption of messages in place. It is therefore easily possible to attack it, e.g., by injecting spoofed messages or modifying the transmitted Global Navigation Satellite System (GNSS) coordinates. In order to verify the integrity of the received information, various methods have been suggested, such as multilateration, the use of Kalman filters, group certification, and many others. However, solutions based on modifications of the standard may be difficult and too slow to be implemented due to legal and regulatory issues. A vantage far less explored is the location verification using public sensor data. In this paper, we propose LoVe, a lightweight message verification approach that uses a geospatial indexing scheme to evaluate the trustworthiness of publicly deployed sensors and the ADS-B messages they receive. With LoVe, new messages can be evaluated with respect to the plausibility of their reported coordinates in a location privacy-preserving manner, while using a datadriven and lightweight approach. By testing our approach on two open datasets, we show that LoVe achieves very low false positive rates (between 0 and 0.001 06) and very low false negative rates (between 0.000 65 and 0.003 34) while providing a real-time compatible approach that scales well even with a large sensor set. Compared to currently existing approaches, LoVe neither requires a large number of sensors, nor for messages to be recorded by as many sensors as possible simultaneously in order to verify location claims. Furthermore, it can be directly applied to currently deployed systems thus being backward compatible.
Johanna Ansohn McDougall, Alessandro Brighente, Willi Großmann, Ben Ansohn McDougall, Joshua Stock, Hannes Federrath
ICC2
2023 Beware of Pickpockets: A Practical Attack against Blocking Cards
abstract
Today, we rely on contactless smart cards to perform several critical operations (e.g., payments and accessing buildings). Attacking smart cards can have severe consequences, such as losing money or leaking sensitive information. Although the security protections embedded in smart cards have evolved over the years, those with weak security properties are still commonly used. Among the different solutions, blocking cards are affordable devices to protect smart cards. These devices are placed close to the smart cards, generating a noisy jamming signal or shielding them. Whereas vendors claim the reliability of their blocking cards, no previous study has ever focused on evaluating their effectiveness.
Marco Alecci, Luca Attanasio, Alessandro Brighente, Mauro Conti, Eleonora Losiouk, Hideki Ochiai, Federico Turrin
RAID3
2023 QEVSEC: Quick Electric Vehicle SEcure Charging via Dynamic Wireless Power Transfer
abstract
Dynamic Wireless Power Transfer (DWPT) can be used for on-demand recharging of Electric Vehicles (EV) while driving. However, DWPT raises numerous security and privacy concerns. Recently, researchers demonstrated that DWPT systems are vulnerable to adversarial attacks. In an EV charging scenario, an attacker can prevent the authorized customer from charging, obtain a free charge by billing a victim user and track a target vehicle. State-of-the-art authentication schemes relying on centralized solutions are either vulnerable to various attacks or have high computational complexity, making them unsuitable for a dynamic scenario. In this paper, we propose Quick Electric Vehicle SEcure Charging (QEVSEC), a novel, secure, and efficient authentication protocol for the dynamic charging of EVs. Our idea for QEVSEC originates from multiple vulnerabilities we found in the state-of-the-art protocol that allows tracking of user activity and is susceptible to replay attacks. Based on these observations, the proposed protocol solves these issues and achieves lower computational complexity by using only primitive cryptographic operations in a very short message exchange. QEVSEC provides scalability and a reduced cost in each iteration, thus lowering the impact on the power needed from the grid.
Tommaso Bianchi, Surudhi Asokraj, Alessandro Brighente, Mauro Conti, Radha Poovendran
VTC2023-Spring3
2023 BARON: Base-Station Authentication Through Core Network for Mobility Management in 5G Networks
abstract
Fifth-generation (5G) cellular communication networks are being deployed on applications beyond mobile devices, including vehicular networks and industry automation. Despite their increasing popularity, 5G networks, as defined by the Third Generation Partnership Project (3GPP), have been shown to be vulnerable against fake base station (FBS) attacks. An adversary carrying out an FBS attack emulates a legitimate base station by setting up a rogue base station. This enables the adversary to control the connection of any user equipment that (inadvertently) connects with the rogue base station. Such an adversary can gather sensitive information belonging to the user. While there is a large body of work focused on the development of tools to detect FBSs, the user equipment will continue to remain vulnerable to an FBS attack. In this paper, we propose BARON, a defense methodology to enable user equipment to determine whether a target base station that it is connecting to is legitimate or rogue. BARON accomplishes this by ensuring that the user receives an authentication token from the target base station which can be computed only by a legitimate and trusted entity. As a consequence, receiving such an authentication token from a base station ensures legitimacy of the base station. We evaluate BARON through extensive experiments on the handover process between base stations in 5G networks. Our experimental results show that BARON introduces an overhead of less than 1% during handover completion, which is 10000× lower than the overhead reported by a state-of-the-art method. BARON is also effective in thwarting an FBS attack and quickly recovering connection to a legitimate base station.
Alessandro Lotto, Vaibhav Singh 0002, Bhaskar Ramasubramanian, Alessandro Brighente, Mauro Conti, Radha Poovendran
WISEC4
2023 Guest Editorial: Cyber-Physical Threats and Solutions for Autonomous Transportation Systems
abstract
The rapid evolution of technology has radically changed our everyday lives from multiple points of view. Systems and devices are nowadays more interconnected and capable of taking autonomous decisions without or with limited human intervention. Among the others, transportation systems are populated by smart and interconnected vehicles that need to communicate with each other and with critical infrastructures to orchestrate traffic and mobility. Such vehicles are equipped with multiple modules, which are sensing or communication devices that help the vehicle in assessing its well-being besides providing the basic information to be shared for the orchestration in the overall network. Transportation systems are hence operated through multiple technologies that need to cooperate to provide efficient delivery of goods and human mobility, as well as to provide security in the overall network. The latter task is complicated by the fact that vehicles autonomously drive and cooperate in the network without human intervention. In fact, thanks to the self-regulating capacity of the modules deployed both inside each vehicle and in the network infrastructure, vehicles do not need to be actively and fully driven by humans as in the past but require minimum intervention to mitigate extreme cases. The level of human intervention depends on the specific architecture and solution but is generally very limited. The overall transportation network can be therefore represented by a cyber--physical system, where a large number of sensors, actuators, and multiple technologies are connected and exchange information.
Alessandro Brighente, Mauro Conti, Radha Poovendran, Jianying Zhou 0001
IEEE Trans. Ind. Informatics1
2023 Authenticating Drone-Assisted Internet of Vehicles Using Elliptic Curve Cryptography and Blockchain
abstract
The inclusion of drones in Internet of Vehicles (IoV) is a current trend that presents significant trade-offs. On the one hand, Unmanned Aerial Vehicles (UAVs) provide advantages such as enabling ground communications also when physical obstacles limit the connectivity. On the other hand, they increase the attack surface. For instance, physical attacks on drones provide the attacker with credentials that can be used to inject bogus information into the IoV network, thus jeopardizing not only security but also users’ safety. In this scenario, authentication plays a fundamental role to guarantee security. It is however fundamental to develop authentication protocols that can, at the same time, protect ground users’ data and prevent attacks to drones. However, currently available authentication schemes cannot guarantee security in case of attacks to drones. In this paper, we propose a Blockchain-supported authentication protocol for Drone-assisted IoV using Elliptic curve cryptography (BDIVE). Compared to existing authentication protocols, we extend the threat model from an honest-but-curious drone to active attacks against drones.BDIVEprovides both energy-efficiency, traceability, and accountability thanks to the use of blockchain at the Trusted Authority (TA). Using Burrow-Abadi–Needham (BAN) logic, we analyze and prove the security of mutual authentication inBDIVE. We also prove the security ofBDIVEagainst several attacks by implementing it in AVISPA. To assess its scalability and energy efficiency, we implementBDIVEusing Omnetpp with its Castalia simulator. The comparison ofBDIVEwith currently existing authentication protocols, shows that it reduces the energy consumption up to 70% and the computational cost up to 68%, while providing resistance to previously unconsidered attack vectors.
Mohamed A. El-Zawawy, Alessandro Brighente, Mauro Conti
IEEE Trans. Netw. Serv. Manag.2
2022 FOLPETTI: A Novel Multi-Armed Bandit Smart Attack for Wireless Networks
abstract
Channel hopping provides a defense mechanism against jamming attacks in large scale Internet of Things (IoT) networks. However, a sufficiently powerful attacker may be able to learn the channel hopping pattern and efficiently predict the channel to jam.
Emilie Bout, Alessandro Brighente, Mauro Conti, Valeria Loscrì
ARES2
2022 Hide and Seek: Privacy-Preserving and FAA-compliant Drones Location Tracing
abstract
Due to the frequent unauthorized invasions by commercial drones to Critical Infrastructures (CIs), the US-based Federal Avionics Administration (FAA) recently published a new specification, namely RemoteID. Such a rule requires all drones to broadcast information about their identity and location, to allow for immediate invasion attribution and counter-actions. However, the enforcement of such a rule poses severe concerns on drones’ operators, especially in terms of location privacy and tracking threats. Indeed, by simply receiving wireless signals, an adversary could know the precise drone location, track it, and infer sensitive information.
Alessandro Brighente, Mauro Conti, Savio Sciancalepore
ARES1
2022 VLC Physical Layer Security through RIS-aided Jamming Receiver for 6G Wireless Networks
abstract
Visible Light Communication (VLC) is one the most promising enabling technology for future 6G networks to over-come Radio-Frequency (RF)-based communication limitations thanks to a broader bandwidth, higher data rate, and greater efficiency. However, from the security perspective, VLCs suffer from all known wireless communication security threats (e.g., eavesdropping and integrity attacks). For this reason, security re-searchers are proposing innovative Physical Layer Security (PLS) solutions to protect such communication. Among the different solutions, the novel Reflective Intelligent Surface (RIS) technology coupled with VLCs has been successfully demonstrated in recent work to improve the VLC communication capacity. However, to date, the literature still lacks analysis and solutions to show the PLS capability of RIS-based VLC communication. In this paper, we combine watermarking and jamming prim-itives through the Watermark Blind Physical Layer Security (WBPLSec) algorithm to secure VLC communication at the physical layer. Our solution leverages RIS technology to improve the security properties of the communication. By using an opti-mization framework, we can calculate RIS phases to maximize the WBPLSec jamming interference schema over a predefined area in the room. In particular, compared to a scenario without RIS, our solution improves the performance in terms of secrecy capacity without any assumption about the adversary's location. We validate through numerical evaluations the positive impact of RIS-aided solution to increase the secrecy capacity of the legitimate jamming receiver in a VLC indoor scenario. Our results show that the introduction of RIS technology extends the area where secure communication occurs and that by increasing the number of RIS elements the outage probability decreases.
Simone Soderi, Alessandro Brighente, Federico Turrin, Mauro Conti
SECON2
2022 SETCAP: Service-Based Energy-Efficient Temporal Credential Authentication Protocol for Internet of Drones
Mohamed A. El-Zawawy, Alessandro Brighente, Mauro Conti
Comput. Networks2
2022 An IoT Inventory Before Deployment: A Survey on IoT Protocols, Communication Technologies, Vulnerabilities, Attacks, and Future Research Directions
Ankur O. Bang, Udai Pratap Rao, Andrea Visconti, Alessandro Brighente, Mauro Conti
Comput. Secur.4
2022 Interference Prediction for Low-Complexity Link Adaptation in Beyond 5G Ultra-Reliable Low-Latency Communications
abstract
Traditional link adaptation (LA) schemes in cellular network must be revised for networks beyond the fifth generation (b5G), to guarantee the strict latency and reliability requirements advocated by ultra reliable low latency communications (URLLC). In particular, a poor error rate prediction potentially increases retransmissions, which in turn increase latency and reduce reliability. In this paper, we present an interference prediction method to enhance LA for URLLC. To develop our prediction method, we propose a kernel based probability density estimation algorithm, and provide an in depth analysis of its statistical performance. We also provide a low complexity version, suitable for practical scenarios. The proposed scheme is compared with state-of-the-art LA solutions over fully compliant 3rd generation partnership project (3GPP) calibrated channels, showing the validity of our proposal.
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca, Silvio Mandelli, Stefano Tomasin
IEEE Trans. Wirel. Commun.1
2021 Tell Me How You Re-Charge, I Will Tell You Where You Drove To: Electric Vehicles Profiling Based on Charging-Current Demand
Alessandro Brighente, Mauro Conti, Izza Sadaf
ESORICS (1)1
2021 Greedy Maximum- Throughput Grant-Free Random Access For Correlated IoT Traffic
abstract
In fifth-generation (5G) and beyond cellular networks, grant-free random access (RA) is useful to reduce latency in uplink. We consider a scenario wherein time is split into frames, divided into slots, and machine-type devices (MTDs) are assigned a slot in each frame for possible transmission. Packet generations at the MTDs are correlated, potentially increasing collisions. We propose a slot allocation scheme based on the observations of successes and collisions in previous frames, aiming at maximizing the cell throughput at each frame. The RA scheme is modeled as a hidden Markov model (HMM), taking into account the joint packet generation statistics. We then propose a greedy algorithm that iteratively assigns slots to users. We compare the performance of the proposed greedy maximum throughput (GMT) with existing literature solutions, and confirm that a high cell throughput is achieved.
Federico Moretto, Alessandro Brighente, Stefano Tomasin
VTC Fall2
2020 Interference Distribution Prediction for Link Adaptation in Ultra-Reliable Low-Latency Communications
abstract
The strict latency and reliability requirements of ultra-reliable low-latency communications (URLLC) use cases are among the main drivers in fifth generation (5G) network design. Link adaptation (LA) is considered to be one of the bottlenecks to realize URLLC. In this paper, we focus on predicting the signal to interference plus noise ratio at the user to enhance the LA. Motivated by the fact that most of the URLLC use cases with most extreme latency and reliability requirements are characterized by semi-deterministic traffic, we propose to exploit the time correlation of the interference to compute useful statistics needed to predict the interference power in the next transmission. This prediction is exploited in the LA context to maximize the spectral efficiency while guaranteeing reliability at an arbitrary level. Numerical results are compared with state of the art interference prediction techniques for LA. We show that exploiting time correlation of the interference is an important enabler of URLLC.
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca
VTC Spring1
2020 Estimation of Wideband Dynamic mmWave and THz Channels for 5G Systems and Beyond
abstract
Millimeter wave (mmWave) wideband channels in a multiple-input multiple-output (MIMO) transmission are described by a sparse set of impulse responses in the angle-delay, or space-time (ST), domain. These characteristics will be even more prominent in the THz band used in future systems. We consider two approaches for channel estimation: compressed-sensing (CS), exploiting the sparsity in the angular/delay domain, and low-rank (LR), exploiting the algebraic structure of channel matrix. Both approaches share several commonalities, and this paper provides for the first time i) a comparison of the two approaches, and ii) new versions of CS and LR methods that significantly improve performance in terms of mean squared error (MSE), computational complexity, and latency. We derive the asymptotic MSE bound for any estimator of the ST-MIMO multipath channels with invariant angles/delays and time-varying fading, with unknown angle/delay diversity order: the bound also accounts for the degradation introduced by sub-optimal separable channel models. We will show that in the considered scenarios both CS and LR approaches attain the bound. Our performance assessment over ideal and 3rdgeneration partnership project (3GPP) channel models, suitable for the fifth-generation (5G) and beyond of cellular networks, shows the trade-off obtained by the methods over various metrics: i) CS methods are converging faster than the LR methods, both attaining the asymptotic MSE bound; ii) the CS methods depend on the array manifold, while LR methods are independent of the array calibration; iii) CS solutions are more complex than LR solutions.
Alessandro Brighente, Mattia Cerutti, Monica Nicoli, Stefano Tomasin, Umberto Spagnolini
IEEE J. Sel. Areas Commun.1
2020 Modular Hybrid Beamforming for mmWave Fixed Wireless Access
abstract
Fixed wireless access has been spreading recently as a complement to wired or fiber solutions, and its implementation on millimeter waves has attracted attention for its potentially high data rates, achievable also in densely populated areas. New hardware and software solutions are needed to overcome various technical issues at those frequencies. We propose a novel modular hybrid beamforming (MHB) architecture, whereby, in receive mode, each module comprises a set of antennas connected to fixed analog beamformers, in turn connected by configurable switches to a smaller set of radio frequency chains. The outputs of all modules are then jointly processed by a digital beamformer. In particular, an MHB performing discrete Fourier transform beamforming for uniform linear arrays is studied. We address the problems of a) switch configuration, b) power allocation and digital beamformer design, and c) channel estimation. For both a) and b) we target the maximization of the total weighted spectral efficiency (WSE) under power and per-user average spectral efficiency (SE) constraints, and we propose greedy efficient solutions. For c) we propose a multistage scheme. We assess the MHB performance in terms of WSE, estimation accuracy, estimation overhead, and computational complexity, and compare them with existing solutions in literature.
Alessandro Brighente, Jonathan Gambini, Stefano Tomasin
IEEE Trans. Commun.1
2019 Location-Verification and Network Planning via Machine Learning Approaches
abstract
In-region location verification (IRLV) in wireless networks is the problem of deciding if user equipment (UE) is transmitting from inside or outside a specific physical region (e.g., a safe room). The decision process exploits the features of the channel between the UE and a set of network access points (APs). We propose a solution based on machine learning (ML) implemented by a neural network (NN) trained with the channel features (in particular, noisy attenuation values) collected by the APs for various positions both inside and outside the specific region. The output is a decision on the UE position (inside or outside the region). By seeing IRLV as an hypothesis testing problem, we address the optimal positioning of the APs for minimizing either the area under the curve (AUC) of the receiver operating characteristic (ROC) or the cross entropy (CE) between the NN output and ground truth (available during the training). In order to solve the minimization problem we propose a two-stage particle swarm optimization (PSO) algorithm. We show that for a long training and a NN with enough neurons the proposed solution achieves the performance of the Neyman-Pearson (N-P) lemma.
Alessandro Brighente, Francesco Formaggio, Marco Centenaro, Giorgio Maria Di Nunzio, Stefano Tomasin
WiOpt1
2019 Machine Learning for In-Region Location Verification in Wireless Networks
abstract
In-region location verification (IRLV) aims at verifying whether a user is inside a region of interest (ROI). In wireless networks, IRLV can exploit the features of the channel between the user and a set of trusted access points. In practice, the channel feature statistics is not available and we resort to machine learning (ML) solutions for IRLV. We first show that solutions based on either neural networks (NNs) or support vector machines (SVMs) with typical loss functions are Neyman-Pearson (N-P)-optimal at learning convergence for sufficiently complex learning machines and large training datasets. For a finite training, ML solutions are more accurate than the N-P test based on estimated channel statistics. Then, as estimating channel features outside the ROI may be difficult, we consider one-class classifiers, namely auto-encoder NNs and one-class SVMs which, however, are not equivalent to the generalized likelihood ratio test (GLRT), typically replacing the N-P test in the one-class problem. Numerical examples support the results in realistic wireless networks, with channel models including path-loss, shadowing, and fading.
Alessandro Brighente, Francesco Formaggio, Giorgio Maria Di Nunzio, Stefano Tomasin
IEEE J. Sel. Areas Commun.1
2019 Power Allocation for Non-Orthogonal Millimeter Wave Systems With Mixed Traffic
abstract
We consider the problem of power allocation for the down-link of a 5G cellular system operating in the mm-wave band and serving two sets of users: fix-rate (FR) users (transmitting data at fixed rate), typically seen in device-to-device communications, and variable-rate (VR) users (that can change their transmission data rate), typically requiring high data rate services. The power allocation objective is the maximization of the spectral efficiency of VR users while ensuring that FR users get the required rate. In contrast with the existing literature on power allocation, we exploit the sparsity of the virtual mm-wave channel matrix, obtained by applying fixed discrete-Fourier transform beamformers at both the transmitter and the receiver. Exploiting the channel partial orthogonality, users are first grouped based on the mutual interference and then the power is allocated among and within groups.
Alessandro Brighente, Stefano Tomasin
IEEE Trans. Wirel. Commun.1
2017 Centralized and Distributed Sparsification for Low-Complexity Message Passing Algorithm in C-RAN Architectures
abstract
Cloud radio access network (C-RAN) is a promising technology for fifth-generation (5G) cellular systems. However the burden imposed by the huge amount of data to be collected (in the uplink) from the radio remote heads (RRHs) and processed at the base band unit (BBU) poses serious challenges. In order to reduce the computation effort of minimum mean square error (MMSE) receiver at the BBU the Gaussian message passing (MP) together with a suitable sparsification of the channel matrix can be used. In this paper we propose two sets of solutions, either centralized or distributed ones. In the centralized solutions, we propose different approaches to sparsify the channel matrix, in order to reduce the complexity of MP. However these approaches still require that all signals reaching the RRH are conveyed to the BBU, therefore the communication requirements among the backbone network devices are unaltered. In the decentralized solutions instead we aim at reducing both the complexity of MP at the BBU and the requirements on the RRHs-BBU communication links by pre-processing the signals at the RRH and convey a reduced set of signals to the BBU.
Alessandro Brighente, Stefano Tomasin
VTC Fall1
2017 Beamforming and Scheduling for mmWave Downlink Sparse Virtual Channels with Non-Orthogonal and Orthogonal Multiple Access
abstract
We consider the problem of scheduling and power allocation for the downlink of a 5G cellular system operating in the millimeter wave (mmWave) band and serving two sets of users: fix-rate (FR) users typically seen in device-to-device (D2D) communications, and variable-rate (VR) users, or high data rate services. The scheduling objective is the weighted sum-rate of both FR and VR users, and the constraints ensure that active FR users get the required rate. The weights of the objective function provide a trade-off between the number of served FR users and the resources allocated to VR users. For mmWave channels the virtual channel matrix obtained by applying fixed discrete-Fourier transform (DFT) beamformers at both the transmitter and the receiver is sparse. This results into a sparsity of the resulting multiple access channel, which is exploited to simplify scheduling, first establishing an interference graph among users and then grouping users according to their orthogonality. The original scheduling problem is solved using a graph-coloring algorithm on the interference graph in order to select sub-sets of orthogonal VR users. Two options are considered for FR users: either they are chosen orthogonal to VR users or non-orthogonal. A waterfilling algorithm is then used to allocate power to the FR users.
Alessandro Brighente, Stefano Tomasin
VTC Fall1