EDBT 2026 Demo / reviewers in the wild / expert
Marta Catillo
dblp:255/7160
· DBLP profile ↗
19ranked-venue papers
17as first author
16since 2021 · last 2026
0000-0002-5025-7969ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 8 first-author · 7 since 2021Software engineering, systems software and programming languages · 4 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Similarity Is Not Enough: Issues with Adversarial Perturbations of Traffic Features against Intrusion Detection Systems
Marta Catillo, Antonio Pecchia, Umberto Villano |
ICISSP (1) | 1 |
| 2025 | USB-IDS-TC: A Flow-Based Intrusion Detection Dataset of DoS Attacks in Different Network Scenarios
Marta Catillo, Antonio Pecchia, Umberto Villano |
ICISSP (1) | 1 |
| 2025 | Topic Modeling for Graph-Based Analysis of Fake News DiffusionabstractFake news diffusion is a primary driver of misinformation. Analyzing deliberately false and misleading content is tough because social media platforms make it incredibly easy to create and spread huge amounts of information quickly. The intricate dynamics of fake news propagation demand the availability of ready-to-use frameworks for its analysis. This paper explores the automatic topic identification component of SPREADSHOT, a graph-based method designed to analyze fake news dissemination by examining two key factors: spreaders and topics. When it comes to news content, fake news frequently revolves around rapidly evolving topics due to its strong connection to current events. Consequently, topic modeling has gained significant traction for analyzing news articles. In our analysis, we explore two distinct topic modeling techniques: Latent Dirichlet Allocation (LDA) and BERTopic. While both offer valuable insights, we carefully justify which of these two techniques is best suited for integration into the SPREADSHOT framework for topic modeling. Pasquale Avella, Carmela Bernardo, Marta Catillo, Antonio Pecchia, Francesco Vasca, Umberto Villano |
WETICE | 3 |
| 2024 | Towards realistic problem-space adversarial attacks against machine learning in network intrusion detectionabstractCurrent trends in network intrusion detection systems (NIDS) capitalize on the extraction of features from network traffic and the use of up-to-date machine and deep learning techniques to infer a detection model; in consequence, NIDS can be vulnerable to adversarial attacks. Differently from the plethora of contributions that apply (and misuse) feature-level attacks envisioned in application domains far from NIDS, this paper proposes a novel approach to adversarial attacks, which consists in a realistic problem-space perturbation of the network traffic. The perturbation is achieved through a traffic control utility. Experiments are based on normal and Denial of Service traffic in both legitimate and adversarial conditions, and the application of four popular techniques to learn the NIDS models. The results highlight the transferability of the adversarial examples generated by the proposed problem-space attack as well as the effectiveness at inducing traffic misclassifications across the NIDS models obtained. Marta Catillo, Antonio Pecchia, Antonio Repola, Umberto Villano |
ARES | 1 |
| 2024 | DEFEDGE: Threat-Driven Security Testing and Proactive Defense Identification for Edge-Cloud Systems
Valentina Casola, Marta Catillo, Alessandra De Benedictis, Felice Moretta, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
AINA (5) | 2 |
| 2024 | Exploring the effect of training-time randomness on the performance of deep neural networks for intrusion detection
Marta Catillo, Antonio Pecchia, Umberto Villano |
Soft Comput. | 1 |
| 2024 | Successful intrusion detection with a single deep autoencoder: theory and practice
Marta Catillo, Antonio Pecchia, Umberto Villano |
Softw. Qual. J. | 1 |
| 2023 | A Case Study with CICIDS2017 on the Robustness of Machine Learning against Adversarial Attacks in Intrusion DetectionabstractIntrusion detection systems (IDS) play a key role to assure security properties of modern computer networks. IDS are often based on machine and deep learning techniques; as such, IDS are vulnerable to various forms of adversarial attacks. This paper presents an initial case study on the robustness of machine learning for network intrusion detection against adversarial attacks. Experiments are based on a recent fix of the widely-used CICIDS2017 benchmark dataset, two well-known machine learning techniques for intrusion detection (i.e., deep autoencoders and decision trees), and the virtual adversarial method (VAM) to generate the adversarial examples. Based on the data and experiments at hand, the results provide many interesting findings on the robustness of the IDS models assessed. The autoencoder-based IDS is more robust to evasion rather than overstimulation. On the contrary, the decision tree is vulnerable to evasion; moreover, changes to the learning parameters can strongly affect the robustness of the decision tree against the VAM attack. Marta Catillo, Andrea Del Vecchio, Antonio Pecchia, Umberto Villano |
ARES | 1 |
| 2023 | Traditional vs Federated Learning with Deep Autoencoders: a Study in IoT Intrusion DetectionabstractSecurity of Internet of Things (IoT) devices and networks is a primary concern. Many intrusion detection systems (IDS) proposals in the IoT leverage machine and deep learning algorithms to learn models that can be used to discriminate normal behaviors from intrusions. Due to the dynamicity and scale of modern IoT networks, it is hard to learn and maintain one separate IDS model per device; on the other hand, the Cloud-Edge-IoT architecture allows learning a single IDS model (instead of many separate models). This paper compares two paradigms, i.e., traditional and federated, to learn a single IDS model atop the traffic of different IoT devices. The former assumes the availability of an all-in-one training dataset at a unique learning node; the latter aggregates the outcomes of independent learning procedures executed on individual training datasets hosted by different nodes. The experiments are done with a well-established public benchmark of nine IoT devices and the use of deep autoencoders. In the experiment and dataset at hand, federated learning lead to an increase of the false positive rate of six devices compared to the traditional scenario. Such an increase was balanced by a narrower variability of the false positive rate across all the devices and a mitigation of potential overfitting. Marta Catillo, Antonio Pecchia, Umberto Villano |
CloudCom | 1 |
| 2023 | CPS-GUARD: Intrusion detection for cyber-physical systems and IoT devices using outlier-aware deep autoencodersabstractDetecting attacks to Cyber-Physical Systems (CPSs) is of utmost importance, due to their increasingly frequent use in many critical assets. Intrusion detection in CPSs and other domains, such as the Internet of Things, is often addressed through machine and deep learning. However, many existing proposals tend to favor the application of complex detection models over the usability in real-world operations. This paper presents CPS-GUARD, a novel intrusion detection approach based on a single semi-supervised autoencoder and a technique to set the threshold used to discriminate normal operations from attacks. The technique is outlier-aware, in that it relies on outlier detection to mitigate inherent imperfections of the training data. CPS-GUARD is evaluated by means of direct experiments with normal and intrusion data points pertaining to individual sensing devices, an HTTP server and four full-fledged systems, including CPSs. Experiments are based on a wide spectrum of attacks available in six state-of-the-art datasets. The intrusion detection results of CPS-GUARD are within 0.949-1.000 recall, 0.961-0.999 precision and 0.006-0.027 false positive rate depending on the specific system. The results are competitive with other existing intrusion detection methods. The evaluation is complemented by a comparative study on alternative threshold selection and outlier detection techniques. Marta Catillo, Antonio Pecchia, Umberto Villano |
Comput. Secur. | 1 |
| 2022 | Botnet Detection in the Internet of Things through All-in-one Deep AutoencodingabstractIn the past years Internet of Things (IoT) has received increasing attention by academia and industry due to the potential use in several human activities; however, IoT devices are vulnerable to various types of attacks. Many existing intrusion detection proposals in the IoT leverage complex machine learning architectures, which may provide one separate model per device or per attack. These solutions are not suited to the dynamicity and scale of modern IoT environments. This paper proposes an initial analysis of the problem in the context of deep autoencoders and the detection of botnet attacks. Our findings, obtained by means of the N-BaIoT dataset, indicate that it is relatively easy to achieve impressive detection results by training-testing separate and minimal deep autoenconders on the top of the data individual IoT devices. More important, our all-in-one deep autoencoding proposal, which consists in training a single model with the benign traffic collected from different IoT devices, allows to preserve the overall detection performance obtained through separate autoencoders. The all-in-one model can pave the way for more scalable intrusion detection solutions in the context of IoT. Marta Catillo, Antonio Pecchia, Umberto Villano |
ARES | 1 |
| 2022 | AutoLog: Anomaly detection by deep autoencoding of system logs
Marta Catillo, Antonio Pecchia, Umberto Villano |
Expert Syst. Appl. | 1 |
| 2022 | No more DoS? An empirical study on defense techniques for web server Denial of Service mitigation
Marta Catillo, Antonio Pecchia, Umberto Villano |
J. Netw. Comput. Appl. | 1 |
| 2022 | Transferability of machine learning models learned from public intrusion detection datasets: the CICIDS2017 case study
Marta Catillo, Andrea Del Vecchio, Antonio Pecchia, Umberto Villano |
Softw. Qual. J. | 1 |
| 2021 | On the Quality of Network Flow Records for IDS Evaluation: A Collaborative Filtering Approach
Marta Catillo, Andrea Del Vecchio, Antonio Pecchia, Umberto Villano |
ICTSS | 1 |
| 2021 | Demystifying the role of public intrusion datasets: A replication study of DoS network traffic data
Marta Catillo, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
Comput. Secur. | 1 |
| 2020 | A case study on the representativeness of public DoS network traffic data for cybersecurity researchabstractThe availability of ready-to-use public security datasets is fostering measurement-driven research by a wide community of academics and practitioners. Recent trends in this area put forth a substantial body of literature on anomaly and attack detection on the top of public labelled datasets. Much of this literature blindly reuses existing datasets by overlooking the cybersecurity facets of the network traffic therein, in terms of its real impact on service availability and performance of operations. Marta Catillo, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
ARES | 1 |
| 2020 | Measurement-Based Analysis of a DoS Defense Module for an Open Source Web Server
Marta Catillo, Antonio Pecchia, Umberto Villano |
ICTSS | 1 |
| 2020 | Auto-scaling Applications in the Cloud by Simple Indexes with Complex LoadsabstractApplications executed in the cloud can exploit its elasticity features, varying dynamically the amount of leased resources so as to adapt to load variations and to guarantee quality of service. As auto-scaling has implications on execution costs, making optimal scaling choices is of paramount importance. This paper presents an analysis method based on offline benchmarking and simple models that allows to evaluate performance indexes useful to define scaling policies to be used by auto-scalers. The proposed approach relies on a fixed set of benchmarks, to be executed off-line and a set of models that enable prediction of the same performance indexes under different workload conditions, enabling the analyst to perform parameter analysis when defining an auto-scaling policy. Marta Catillo, Luciano Ocone, Massimiliano Rak, Umberto Villano |
WETICE | 1 |