Pierluigi Locatelli

dblp:249/3443 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-7084-7923ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 5 first-author · 7 since 2021
YearPublicationVenuePosition
2026 Demo: Re-designing MAC Spoofing for Transparent MITM Attacks Using Linux Network Namespaces
abstract
In wired networks, Medium Access Control (MAC) spoofing is a well-known and extensively studied class of network security attacks in which an adversary impersonates a legitimate host by falsifying its MAC address. Despite existing defense stan- dards, such attacks remain relevant in contemporary networks. MAC spoofing can enable Man-In-The-Middle (MITM) attacks, allowing an attacker to intercept and inject traffic while posing as the victim whose MAC address has been compromised. Despite its conceptual simplicity, implementing a fully transparent MAC spoofing MITM attack is non-trivial. Existing techniques fail to maintain transparency from the victim’s perspective and may disrupt connectivity. While traffic interception is relatively straightforward, injecting traffic on behalf of the victim without affecting the victim’s normal operation is more challenging. Achieving such transparency typically requires custom code and specialized libraries that may lack portability across platforms or operate in user space rather than kernel space, thereby imposing performance limitations. This demo presents an implementation of a MAC spoofing-based MITM attack that enables transparent interception and injection of packets while impersonating the victim, without requiring custom code. The approach operates entirely in kernel space, leveraging Linux networking names- paces, and ensures complete transparency to both the victim host and its communication endpoint.
Pietro Spadaccino, Stefano Servillo, Pierluigi Locatelli, Francesca Cuomo
INFOCOM3
2025 Dyn-WNTR: Dynamic Network Adaptive Extension for Hydraulic Simulations with WNTR
Pierluigi Locatelli, Tiziana Cattai, Simone Palumbo, Francesca Cuomo
Networking1
2025 Realistic Traffic Modeling and Performance Evaluation of a Blockchain-Enabled LoRaWAN
abstract
In the Internet of Things (IoT) scenario, two of the most important innovations in recent years are Edge Computing and Low Power technologies, like LoRaWAN. Edge Computing facilitates computations to be executed in proximity to users, delivering advantages such as reduced response times, optimized bandwidth usage, and enhanced scalability for IoT applications. On the other hand, LoRaWAN stands out as an IoT communication technology engineered for secure, low data-rate transmissions with high energy efficiency. However, implementing the edge computing paradigm into LoRaWAN presents challenges due to its centralized cloud-based architecture, which conflicts with the principles of edge computing. In previous years, proposals have emerged to decentralize LoRaWAN and integrate it at the edge level. However, these proposals often result in the creation of new protocols that diverge from the standard LoRaWAN framework and are not backward compatible. Furthermore, existing proposals are typically tested on arbitrary testbeds and traffic conditions, failing to account for the diverse applications and traffic characteristics inherent in real-world scenarios. In this study, we enhance and refine DeLoRaN, our system architecture facilitating the decentralized operation of LoRaWannetworks at the edge layer, where network control operations are executed at the gateway level. Additionally, we develop and present a data-driven traffic model for LoRaWAN that reflects real-world scenarios, derived from extensive capturing of LoRaWantraffic over several months. This model leverages packets from devices across multiple networks and serves diverse applications not under our direct control. Using this model, we validate the performance of DeLoRaN by simulating device traffic generation based on our data-driven realistic model.
Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo
WCNC1
2025 Detection and Mitigation of Jamming Attacks in LoRaWan Using Machine Learning
abstract
The security and efficiency of low-power wide area networks (LPWANs) for connecting an ever-growing number of IoT devices, expected to exceed 40 billion by 2030, are becoming increasingly important. LoRaWAN, a leading LPWAN technology, enables long-range, low-power communications but remains susceptible to jamming attacks that degrade network performance at the physical layer. This paper introduces a robust framework for detecting and mitigating jamming in LoRaWAN networks using comprehensive threat modeling and machine learning-based countermeasures. The framework simulates two types of jamming attacks: a channel-oblivious jammer, which transmits continuously to randomly interfere with channels, and a channel-aware jammer, which selectively disrupts active transmissions. We evaluate LoRaWAN's resilience through extended simulations in the ns-3 module, adapted for jamming scenarios. Additionally, we provide a high-precision LSTM-based detection model to identify jamming patterns and a mitigation strategy to counteract the channel-oblivious jammer, including an automatic restoration process for returning devices to normal operation post-disruption. The proposed framework enhances network robustness against jamming, showing that ML-based detection significantly reduces disruptions.
Stefano Di Pinto, Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo
WCNC2
2024 DeLoRaN: Decentralize LoRaWAN Network Server Through Blockchain
abstract
LoRaWAN networks have become popular for enabling long-range, low-power connectivity in Internet of Things (IoT) applications. Traditional LoRa Wannetworks typically rely on a centralized architecture, which may pose limitations regarding scalability, reliability, and adaptability. In contrast, decentralized LoRaWAN networks offer a compelling alternative with several distinct features. This study explores the advantages of decentralized LoRaWAN networks over their centralized counterparts and presents DeLoRaN, a completely decentralized and fully compatible LoRaWAN network. Firstly, a decentralized network architecture enhances the availability of services by leveraging multiple copies of a LoRaWAN Network Server (NS), here called Network Controller, thereby eliminating the single points of failure. Secondly, the decentralized nature of the network improves data availability and integrity by utilizing shared and decentralized ledgers, such as blockchain technology. This ensures that data remains accessible and tamper-proof even in the presence of malicious actors or network failures. Thirdly, a decentralized network strengthens resilience by tolerating faulty or malicious nodes through the consensus mechanisms employed by the Network Controller. To prove our point, we present an implementation of our distributed approach and test it in different scenarios, to appreciate performance and scalability of DeLoRaN when compared to a centralized approach.
Pierluigi Locatelli, Francesca Cuomo
WCNC1
2023 Device discovery and tracing in the Bluetooth Low Energy domain
abstract
Bluetooth Low Energy (BLE) is a pervasive wireless technology all around us today. It is included in most commercial consumer electronic devices manufactured in the last years, and billions of BLE-enabled devices are produced every year, mostly wearable or portable ones like smartphones, smartwatches, and smartbands. The success of BLE as a cornerstone in the Internet of Things (IoT) and consumer electronics is both an advantage, enabling short range, low cost, and low power consumption wireless communications, and a disadvantage, from a security and privacy standpoint. BLE exposes packets that enable a potential attacker to detect, enquire and fingerprint actual devices despite manufacturers’ attempts to avoid detection and tracking. Medium Access Control (MAC) address randomization was introduced in the BLE standard to solve some of these issues. In this paper we discuss how to detect and fingerprint BLE devices, basing our analysis and data collection on interactions allowed by the standard. In our study, we propose the Bluetooth Low Energy Nodes Detect, Enquire, (and) Recognition (BLENDER) framework for enumerating and fingerprinting BLE devices for crowd monitoring and recognition purposes, based on four different strategies used to analyze BLE-enabled devices. We will show that it is possible to associate BLE randomized MAC addresses to actual devices. We will then describe a proof of concept for large-scale data collection. In addition, to determine the spots where the stations could be optimally positioned, we created a synthetic dataset based on mobility models and then we emulated the BLENDER approach. The latter allowed training Machine Learning models to predict the expected number of devices appearing at any particular position, day, and hour.
Pierluigi Locatelli, Massimo Perri, Daniel Mauricio Jimenez Gutierrez, Andrea Lacava, Francesca Cuomo
Comput. Commun.1
2021 Hijacking Downlink Path Selection in LoRaWAN
abstract
With the rise of the IoT, many protocols have been developed in order to fulfill the need for a wireless connectivity that assures energy efficiency and low-data rates. LoRaWAN is certainly one of the most widely used protocols. The LoRaWAN 1.1 specification aims to fix some serious security vulnerabilities in the 1.0 specification, however there still exist critical points to address. In this paper, we identify an attack that can affect LoRaWAN 1.0 and 1.1 networks, which hijacks the downlink path from the Network Server to an End Device. The attack exploits the deduplication procedure and the gateway selection during a downlink scheduling by the Network Server, which is in general implementation-dependent. The attack scheme has been proven to be easy to implement, not requiring physical layer-specific operations such as signal jamming, and could target many LoRaWAN devices at once. We discuss the implications of this attack and identify the possible mitigations that could be adopted by network providers to address this vulnerability.
Pierluigi Locatelli, Pietro Spadaccino, Francesca Cuomo
GLOBECOM1