EDBT 2026 Demo / reviewers in the wild / expert
Stefano Longari
dblp:252/6392
· DBLP profile ↗
13ranked-venue papers
2as first author
13since 2021 · last 2026
0000-0002-7533-4510ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the (In)Security of Loading Machine Learning ModelsabstractThe rise of model sharing through frameworks and dedicated hubs makes Machine Learning significantly more accessible. Despite its benefits, loading shared models exposes users to underexplored security risks, while security awareness remains limited among both practitioners and developers. To enable a more security-conscious approach in Machine Learning model sharing, in this paper, we evaluate the security posture of frameworks and hubs, assess whether security-oriented mechanisms offer real protection, and survey how users perceive the security narratives surrounding model sharing. Our evaluation shows that most frameworks and hubs address security risks partially at best, often by shifting responsibility to the user. More concerningly, our analysis of frameworks advertising security-oriented settings and complete model sharing uncovered multiple 0-day vulnerabilities enabling arbitrary code execution. Through this analysis, we show that, despite the recent narrative, securely loading Machine Learning models is far from being a solved problem and cannot be guaranteed by the file format used for sharing. Our survey shows that the security narrative leads users to consider security-oriented settings as trustworthy, despite the weaknesses shown in this work. From this, we derive suggestions to strengthen the security of model-sharing ecosystems. Gabriele Digregorio, Marco Di Gennaro 0001, Stefano Zanero, Stefano Longari, Michele Carminati |
SP | 4 |
| 2025 | Linux Hurt Itself in Its Confusion! Exploiting Out-of-Memory Killer for Confusion Attacks via Heuristic Manipulation
Lorenzo Bossi, Daniele Mammone, Michele Carminati, Stefano Zanero, Stefano Longari |
DIMVA (2) | 5 |
| 2025 | Poster: FedBlockParadox - A Framework for Simulating and Securing Decentralized Federated Learning
Gabriele Digregorio, Francesco Bleggi, Federico Caroli, Michele Carminati, Stefano Zanero, Stefano Longari |
DIMVA (2) | 6 |
| 2025 | SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?
Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati, Stefano Zanero, Hodaya Binyamini, Gal Engelberg, Daniel Klein 0003, Giancarlo Guizzardi, Marco Caselli, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Thijs van Ede |
USENIX Security Symposium | 3 |
| 2025 | TimberStrike: Dataset Reconstruction Attack Revealing Privacy Leakage in Federated Tree-Based SystemsabstractFederated Learning has emerged as a privacy-oriented alternative to centralized Machine Learning, enabling collaborative model training without direct data sharing. While extensively studied for neural networks, the security and privacy implications of tree-based models remain underexplored. This work introduces TimberStrike, an optimization-based dataset reconstruction attack targeting horizontally federated tree-based models. Our attack, carried out by a single client, exploits the discrete nature of decision trees by using split values and decision paths to infer sensitive training data from other clients. We evaluate TimberStrike on State-of-the-Art federated gradient boosting implementations across multiple frameworks, including Flower, NVFlare, and FedTree, demonstrating their vulnerability to privacy breaches. On a publicly available stroke prediction dataset, TimberStrike consistently reconstructs between 73.05% and 95.63% of the target dataset across all implementations. We further analyze Differential Privacy, showing that while it partially mitigates the attack, it also significantly degrades model performance. Our findings highlight the need for privacy-preserving mechanisms specifically designed for tree-based Federated Learning systems, and we provide preliminary insights into their design. Marco Di Gennaro 0001, Giovanni De Lucia, Stefano Longari, Stefano Zanero, Michele Carminati |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Assessing the Resilience of Automotive Intrusion Detection Systems to Adversarial ManipulationabstractThe security of modern vehicles has become increasingly important, with the controller area network (CAN) bus serving as a critical communication backbone for various electronic control units (ECUs). The absence of robust security measures in CAN, coupled with the increasing connectivity of vehicles, makes them susceptible to cyberattacks. While intrusion detection systems (IDSs) have been developed to counter such threats, they are not foolproof. Adversarial attacks, particularly evasion attacks, can manipulate inputs to bypass detection by IDSs. This article extends our previous work by investigating the feasibility and impact of gradient-based adversarial attacks performed with different degrees of knowledge against automotive IDSs. We consider three scenarios: white-box (attacker with full system knowledge), grey-box (partial system knowledge), and—the more realistic—black-box (no knowledge of the IDS’s internal workings or data). We evaluate the effectiveness of the proposed attacks against state-of-the-art IDSs on two publicly available datasets. Additionally, we study the effect of the adversarial perturbation on the attack impact and evaluate real-time feasibility by precomputing evasive payloads for timed injection based on bus traffic. Our results demonstrate that, besides attacks being challenging due to the automotive domain constraints, their effectiveness is strongly dependent on the dataset quality, the target IDS, and the attacker’s degree of knowledge. Stefano Longari, Paolo Cerracchio, Michele Carminati, Stefano Zanero |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2025 | Swarm: A Distributed Ledger-based Framework to Enhance Air Traffic Control Security Using ADS-B ProtocolabstractIn aviation, safety is paramount, with air traffic control (ATC) playing a crucial role in monitoring aircraft to prevent collisions and manage traffic flows. In response to increasing air traffic, a renewal process has been initiated. This includes deploying the automatic dependent surveillance-broadcast (ADS-B) communications protocol, which aims to enhance surveillance precision and increase the number of aircraft that can be handled simultaneously. This transition is transforming ATC from a radar-based system to a more advanced satellite-based global positioning system (GPS) location tracking system. However, due to its inherently open design, the ADS-B protocol lacks critical security features such as authentication, necessitating the adoption of additional security measures to mitigate potential cyber-attacks. To address these vulnerabilities, this work introduces Swarm, an innovative distributed ledger-based framework, built on top of the ADS-B protocol and aimed at enhancing the security of air traffic control (ATC) while avoiding single points of failure. Swarm can be integrated into existing ATC infrastructure without requiring any modifications to the ADS-B protocol. We evaluate Swarm through rigorous and realistic attack scenarios, using real-world aviation data, demonstrating its capability to enhance the security of the aviation domain. Gabriele Digregorio, Edoardo Saputelli, Stefano Longari, Michele Carminati, Stefano Zanero |
ACM Trans. Priv. Secur. | 3 |
| 2024 | BOTQUAS: Blockchain-based Solutions for Trustworthy Data Sharing in Sustainable and Circular EconomyabstractMonitoring business processes within complex supply chains demands efficient data collection and analytics tailored to diverse phenomena. Traditional centralized solutions face limitations in adapting to the dynamic nature of supply chains. This calls for distributed solutions which break the usual architectural assumption to have a central entity in charge of collecting, integrating and offering tools for the analysis. This project, embedded in a larger initiative called MICS, proposes an inno-vative distributed monitoring solution integrating blockchain for a trustworthy and efficient data analytics strategy that preserves data sovereignty in complex collaborative environments. Leveraging the cloud -edge continuum, the solution aims to ensure secure data exchange, adherence to agreements, and real-time analytics. Expected outcomes include an innovative federated architecture, 5G slice management solutions, an adversarial analysis of supply chain security, and a proof-of-concept implementation of the blockchain-based data flow tracking system. These developments aim to enhance the reliability, security, and efficiency of supply chain monitoring in dynamic industrial environments. Alberto Amico, Vincenzo Apicella, Devis Bianchini, Alberto Butera, Matteo Cesana, Gabriele Digregorio, Massimiliano Garda, Valentina Gatteschi, Corrado Innamorati, Francesco Leotta, Stefano Longari, Maria Rosa Pizzo, Pierluigi Plebani, Noemi Romani, Letizia Tanca, Andrea Vitaletti, Stefano Zanero |
SEAA | 11 |
| 2024 | Evaluating the Impact of Privacy-Preserving Federated Learning on CAN Intrusion DetectionabstractThe challenges derived from the data-intensive nature of machine learning in conjunction with technologies that enable novel paradigms such as V2X and the potential offered by 5G communication, allow and justify the deployment of Federated Learning (FL) solutions in the vehicular intrusion detection domain. In this paper, we investigate the effects of integrating FL strategies into the machine learning-based intrusion detection process for on-board vehicular networks. Accordingly, we propose a FL implementation of a state-of-the-art Intrusion Detection System (IDS) for Controller Area Network (CAN), based on LSTM autoencoders. We thoroughly evaluate its detection efficiency and communication overhead, comparing it to a centralized version of the same algorithm, thereby presenting it as a feasible solution. Gabriele Digregorio, Elisabetta Cainazzo, Stefano Longari, Michele Carminati, Stefano Zanero |
VTC Spring | 3 |
| 2023 | CANova: A hybrid intrusion detection framework based on automatic signal classification for CANabstractOver the years, vehicles have become increasingly complex and an attractive target for malicious adversaries. This raised the need for effective and efficient Intrusion Detection Systemss (IDSs) for onboard networks able to work with the stringent requirements and the heterogeneity of information transmitted on the Controller Area Network. While state-of-the-art solutions are effective in detecting specific types of anomalies and work on a subset of the CAN signals, no single method can perform better than the others on all types of attacks, particularly if they need to provide predictions to comply with the domain’s real-time constraints. In this paper, we present CANova, a modular framework that exploits the characteristics of the different Controller Area Network (CAN) packets to select the Intrusion Detection Systemss (IDSs) that better fits them. In particular, it uses flow- and payload-based IDSs to analyze the packets’ content and arrival time. We evaluate CANova by comparing its performance against state-of-the-art Intrusion Detection Systemss (IDSs) for in-vehicle network and a comprehensive set of synthetic and real attacks in real-world CAN datasets. We demonstrate that our approach can achieve good performances in terms of detection, false positive rates, and temporal performances. Alessandro Nichelini, Carlo Alberto Pozzoli, Stefano Longari, Michele Carminati, Stefano Zanero |
Comput. Secur. | 3 |
| 2022 | CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksabstractCurrent research in the automotive domain has proven the limitations of the Controller Area Network (CAN) protocol from a security standpoint. Application-layer attacks, which involve the creation of malicious packets, are deemed feasible from remote but can be easily detected by modern Intrusion Detection Systems (IDSs). On the other hand, more recent link-layer attacks are stealthier and possibly more disruptive but require physical access to the bus. In this paper, we present CANflict, a software-only approach that allows reliable manipulation of the CAN bus at the data link layer from an unmodified microcontroller, overcoming the limitations of state-of-the-art works. We demonstrate that it is possible to deploy stealthy CAN link-layer attacks from a remotely compromised ECU, targeting another ECU on the same CAN network. To do this, we exploit the presence of pin conflicts between microcontroller peripherals to craft polyglot frames, which allows an attacker to control the CAN traffic at the bit level and bypass the protocol's rules. We experimentally demonstrate the effectiveness of our approach on high-, mid-, and low-end microcontrollers, and we provide the ground for future research by releasing an extensible tool that can be used to implement our approach on different platforms and to build CAN countermeasures at the data link layer. Alvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino, Stefano Zanero |
CCS | 2 |
| 2022 | GOLIATH: A Decentralized Framework for Data Collection in Intelligent Transportation SystemsabstractIntelligent Transportation Systems (ITSs) technology has advanced during the past years, and it is now used for several applications that require vehicles to exchange real-time data, such as in traffic information management. Traditionally, road traffic information has been collected using on-site sensors. However, crowd-sourcing traffic information from onboard sensors or smartphones has become a viable alternative. State-of-the-art solutions currently follow a centralized model where only the service provider has complete access to the collected traffic data and represent a single point of failure and trust. In this paper, we proposeGOLIATH, a blockchain-based decentralized framework that runs on the In-Vehicle Infotainment (IVI) system to collect real-time information exchanged between the network’s participants. Our approach mitigates the limitations of existing crowd-sourcing centralized solutions by guaranteeing trusted information collection and exchange, fully exploiting the intrinsic distributed nature of vehicles. We demonstrate its feasibility in the context of vehicle positioning and traffic information management. Each vehicle participating in the decentralized network shares its position and neighbors’ ones in the form of a transaction recorded on the ledger, which uses a novel consensus mechanism to validate it. We design the consensus mechanism resilient against a realistic set of adversaries that aim to tamper or disable the communication. We evaluate the proposed framework in a simulated (but realistic) environment, which considers different threats and allows showing its robustness and safety properties. Davide Maffiola, Stefano Longari, Michele Carminati, Mara Tanelli, Stefano Zanero |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2021 | CANnolo: An Anomaly Detection System Based on LSTM Autoencoders for Controller Area NetworkabstractAutomotive security has gained significant traction in the last decade thanks to the development of new connectivity features that have brought the vehicle from an isolated environment to an externally facing domain. Researchers have shown that modern vehicles are vulnerable to multiple types of attacks leveraging remote, direct and indirect physical access, which allow attackers to gain control and affect safety-critical systems. Conversely, Intrusion Detection Systems (IDSs) have been proposed by both industry and academia to identify attacks and anomalous behaviours. In this article, we propose CANnolo, an IDS based on Long Short-Term Memory (LSTM)-autoencoders to identify anomalies in Controller Area Networks (CANs). During a training phase, CANnolo automatically analyzes the CAN streams and builds a model of the legitimate data sequences. Then, it detects anomalies by computing the difference between the reconstructed and the respective real sequences. We experimentally evaluated CANnolo on a set of simulated attacks applied over a real-world dataset. We show that our approach outperforms the state-of-the-art model by improving the detection rate and precision. Stefano Longari, Daniel Humberto Nova Valcarcel, Mattia Zago, Michele Carminati, Stefano Zanero |
IEEE Trans. Netw. Serv. Manag. | 1 |