EDBT 2026 Demo / reviewers in the wild / expert
Maurantonio Caprolu
dblp:237/5281
· DBLP profile ↗
13ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0001-8237-0539ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 6 first-author · 8 since 2021Computer networks · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From DePIN Hype to Operational Reality: Assessing Centralization and Usage of Commercial dVPNsabstractDecentralized VPNs (dVPNs) are marketed as a flagship use case of Decentralized Physical Infrastructure Networks (DePIN): a fully decentralized, censorship-resistant alternative to traditional VPNs, where users route traffic through a global pool of independently operated exit nodes. However, despite claims of decentralization and “military-grade privacy”, little is known in both the white and the gray literature about the actual commercial dVPNs architecture, their true level of decentralization, and what they are used for. To fill these gaps, in this work, we present the first data-driven, operator-centric study of commercial dVPNs. We deploy several fully functional exit nodes worldwide on two prominent dVPN platforms, Mysterium and Sentinel. Via such nodes, we collect control-plane traffic, user traffic, and publicly available metadata to assess what an honest-but-curious operator can infer about systems' architecture, effective decentralization, and real-world usage. Our findings challenge the dominant narrative. Architecturally, both investigated dVPNs rely heavily on centralized orchestrators, often hosted on a handful of Cloud providers. These components constitute clear chokepoints, making the networks more fragile, censorable, and way less decentralized than their branding suggests. From a usage perspective, traffic relayed by our nodes is dominated by mainstream, commercially oriented activities rather than by censorship evasion or privacy-motivated uses. Overall, we show that current commercial dVPNs inherit many centralized features of traditional VPNs while shifting trust and liability onto a heterogeneous, legally shaky, and largely untrusted operator base. Bartan Oren, Maurantonio Caprolu, Savio Sciancalepore, Nicola Zannone, Roberto Di Pietro |
AsiaCCS | 2 |
| 2026 | Nominated Proof of Stake: A Reality Check
Maurantonio Caprolu, Elia Onofri, Omar Eldesouky, Roberto Di Pietro |
ICBC | 1 |
| 2026 | Toward estimating speculation in a cryptocurrency transaction network: The Polkadot case study
Maurantonio Caprolu, Roberto Di Pietro, Flavio Lombardi, Elia Onofri |
Comput. Networks | 1 |
| 2025 | NoBU: An effective and viable cyber-physical solution to thwart BadUSB attacks
Andrea Ciccotelli, Maurantonio Caprolu, Roberto Di Pietro |
AsiaCCS | 2 |
| 2025 | SoK: A Structured Analysis of Economic and Technical Stablecoin-Related Research
Ahmed Mahrous, Maurantonio Caprolu, Roberto Di Pietro |
ICBC | 2 |
| 2024 | Sharing Is (S)caring: Security and Privacy Issues in Decentralized Physical Infrastructure Networks (DePIN)
Maurantonio Caprolu, Simone Raponi, Roberto Di Pietro |
NSS | 1 |
| 2024 | Watch Nearby! Privacy Analysis of the People Nearby Service of TelegramabstractPeople Nearby is a service offered by Telegram that allows a user to discover other Telegram users, based only on geographical proximity. Nearby users are reported with a rough estimate of their distance from the position of the reference user, allowing Telegram to claim location privacy. In this paper, we systematically analyze the location privacy provided by Telegram to users of the People Nearby service. Through an extensive measurement campaign run by spoofing the user's location all over the world, we reverse-engineer the algorithm adopted by People Nearby to compute distances between users. Although the service protects against precise user localization, we demonstrate that location privacy is always lower than the one declared by Telegram (500~meters). Specifically, we discover that location privacy is a function of the geographical position of the user. Indeed, the radius of the location privacy area (localization error) spans between 400~meters (close to the equator) and 128~meters (close to the poles), with a difference of up to 75% (worst case) compared to what Telegram declares. After our responsible disclosure, Telegram updated the FAQ associated with the service. Finally, we provide some solutions and countermeasures that Telegram can implement to improve location privacy. In general, the reported findings highlight the significant privacy risks associated with the use of the People Nearby service. Maurantonio Caprolu, Savio Sciancalepore, Aleksandar Grigorov, Velyan Kolev, Gabriele Oligeri |
WISEC | 1 |
| 2023 | Understanding Polkadot Through Graph Analysis: Transaction Model, Network Properties, and Insights
Hanaa Abbas, Maurantonio Caprolu, Roberto Di Pietro |
FC | 2 |
| 2023 | Account Clustering in the Polkadot Network: Heuristic, Experiments, and InsightsabstractThis paper investigates, for the first time, user account clustering in the Polkadot network, one of the most innovative account-based altcoins in the market. To achieve this goal, we levereged the “deposit address reuse” heuristic on the Polkadot relay chain. In detail, we propose a novel deposit address detection methodology, combined with a general clustering strategy. To show the viability of our approach, we present a case study involving Binance and Kraken, the two major exchanges active in the Polkadot network. The analysis extends over a sensitive time window-starting from Polkadot genesis (May 2020) up to block 12,532,600 (October 2022). Thanks to the proposed methodology, we clustered more than 145,440 accounts belonging to exchanges, and more than 25,000 user accounts, representing around 25% of all the Binance/Kraken on-chain customers. The general applicability of our technique, the preliminary achieved results-showing both the viability and the value provided by our approach-, and the research hints discussed in the paper, also pave the way for further research in the field. Maurantonio Caprolu, Roberto Di Pietro |
ICBC | 1 |
| 2023 | Characterizing the 2022- Russo-Ukrainian Conflict Through the Lenses of Aspect-Based Sentiment Analysis: Dataset, Methodology, and Key FindingsabstractOnline social networks (OSNs) play a crucial role in modern society by supporting free expression, information sharing, and social movement organization. However, they are also the tool of choice to spread disinformation, hate speech, and support propaganda. As such, it is crucial to analyze OSNs, particularly during critical events such as elections, pandemics, and conflicts, when disinformation campaigns may seek to undermine the democratic values of a nation. This paper analyzes the general-public perception of the first phases of the 2022- Russo-Ukrainian conflict on Twitter. To this end, we developed a general methodology consisting of several steps. We built a dataset of 5.5+ million tweets related to the subject, generated by 1.8+ million unique users. Then, we cluster users into five categories, and combining statistical analysis and aspect-based sentiment analysis (ABSA), we quantitatively and qualitatively investigate the spread of information during the conflict. Our analysis revealed several important insights, including anomalies in the behavior of specific user categories and their sentiment trends and a spike in the daily account creation rate before the conflict. Other than being interesting on their own, our findings also have significant implications for future research on how disinformation campaigns are executed and on developing effective strategies to mitigate their impact. Maurantonio Caprolu, Alireza Sadighian, Roberto Di Pietro |
ICCCN | 1 |
| 2021 | Cryptomining makes noise: Detecting cryptojacking via Machine LearningabstractCryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area. Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro |
Comput. Commun. | 1 |
| 2020 | New Dimensions of Information Warfare: The Economic Pillar - Fintech and Cryptocurrencies
Maurantonio Caprolu, Stefano Cresci, Simone Raponi, Roberto Di Pietro |
CRiSIS | 1 |
| 2019 | FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDNabstractThe Software Defined Networking (SDN) paradigm decouples the logic module from the forwarding module on traditional network devices, bringing a wave of innovation to computer networks. Firewalls, as well as other security appliances, can largely benefit from this novel paradigm. Firewalls can be easily implemented by using the default OpenFlow rules, but the logic must reside in the control plane due to the dynamic nature of their rules that cannot be handled by data plane devices. This leads to a nonnegligible overhead in the communication channel between layers, as well as introducing an additional computational load on the control plane. To address the above limitations, we propose the architectural design of FORTRESS: a stateful firewall for SDN networks that leverages the stateful data plane architecture to move the logic of the firewall from the control plane to the data plane. FORTRESS can be implemented according to two different architectural designs: Stand-Alone and Cooperative, each one with its own peculiar advantages. We compare FORTRESS against FlowTracker, the state-of-the-art solution for SDN firewalling, and show how our solution outperforms the competitor in terms of the number of packets exchanged between the control plane and the data plane—we require 0 packets for the Stand-Alone architecture and just 4 for the Cooperative one. Moreover, we discuss how the adaptability, elegant and modular design, and portability of FORTRESS contribute to make it the ideal candidate for SDN firewalling. Finally, we also provide further research directions. Maurantonio Caprolu, Simone Raponi, Roberto Di Pietro |
Secur. Commun. Networks | 1 |