EDBT 2026 Demo / reviewers in the wild / expert
Marco Di Gennaro 0001
dblp:274/5335-1
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0008-1415-4787ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the (In)Security of Loading Machine Learning ModelsabstractThe rise of model sharing through frameworks and dedicated hubs makes Machine Learning significantly more accessible. Despite its benefits, loading shared models exposes users to underexplored security risks, while security awareness remains limited among both practitioners and developers. To enable a more security-conscious approach in Machine Learning model sharing, in this paper, we evaluate the security posture of frameworks and hubs, assess whether security-oriented mechanisms offer real protection, and survey how users perceive the security narratives surrounding model sharing. Our evaluation shows that most frameworks and hubs address security risks partially at best, often by shifting responsibility to the user. More concerningly, our analysis of frameworks advertising security-oriented settings and complete model sharing uncovered multiple 0-day vulnerabilities enabling arbitrary code execution. Through this analysis, we show that, despite the recent narrative, securely loading Machine Learning models is far from being a solved problem and cannot be guaranteed by the file format used for sharing. Our survey shows that the security narrative leads users to consider security-oriented settings as trustworthy, despite the weaknesses shown in this work. From this, we derive suggestions to strengthen the security of model-sharing ecosystems. Gabriele Digregorio, Marco Di Gennaro 0001, Stefano Zanero, Stefano Longari, Michele Carminati |
SP | 2 |
| 2025 | PackHero: A Scalable Graph-Based Approach for Efficient Packer Identification
Marco Di Gennaro 0001, Mario D'Onghia, Mario Polino, Stefano Zanero, Michele Carminati |
DIMVA (2) | 1 |
| 2025 | TimberStrike: Dataset Reconstruction Attack Revealing Privacy Leakage in Federated Tree-Based SystemsabstractFederated Learning has emerged as a privacy-oriented alternative to centralized Machine Learning, enabling collaborative model training without direct data sharing. While extensively studied for neural networks, the security and privacy implications of tree-based models remain underexplored. This work introduces TimberStrike, an optimization-based dataset reconstruction attack targeting horizontally federated tree-based models. Our attack, carried out by a single client, exploits the discrete nature of decision trees by using split values and decision paths to infer sensitive training data from other clients. We evaluate TimberStrike on State-of-the-Art federated gradient boosting implementations across multiple frameworks, including Flower, NVFlare, and FedTree, demonstrating their vulnerability to privacy breaches. On a publicly available stroke prediction dataset, TimberStrike consistently reconstructs between 73.05% and 95.63% of the target dataset across all implementations. We further analyze Differential Privacy, showing that while it partially mitigates the attack, it also significantly degrades model performance. Our findings highlight the need for privacy-preserving mechanisms specifically designed for tree-based Federated Learning systems, and we provide preliminary insights into their design. Marco Di Gennaro 0001, Giovanni De Lucia, Stefano Longari, Stefano Zanero, Michele Carminati |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | A Federated Learning Platform as a Service for Advancing Stroke Management in European Clinical CentersabstractThe rapid evolution of artificial intelligence (AI) technologies holds transformative potential for the healthcare sector. In critical situations requiring immediate decision-making, healthcare professionals can leverage machine learning (ML) algorithms to prioritize and optimize treatment options, thereby reducing costs and improving patient outcomes. However, the sensitive nature of healthcare data presents significant challenges in terms of privacy and data ownership, hindering data availability and the development of robust algorithms. Federated Learning (FL) addresses these challenges by enabling collaborative training of ML models without the exchange of local data. This paper introduces a novel FL platform designed to support the configuration, monitoring, and management of FL processes. This platform operates on Platform-as-a-Service (PaaS) principles and utilizes the Message Queuing Telemetry Transport (MQTT) publish-subscribe protocol. Considering the production readiness and data sensitivity inherent in clinical environments, we emphasize the security of the proposed FL architecture, addressing potential threats and proposing mitigation strategies to enhance the platform's trustworthiness. The platform has been successfully tested in various operational environments using a publicly available dataset, highlighting its benefits and confirming its efficacy. Diogo Reis Santos, Albert Sund Aillet, Antonio Boiano, Usevalad Milasheuski, Lorenzo Giusti, Marco Di Gennaro 0001, Sanaz Kianoush, Luca Barbieri, Monica Nicoli, Michele Carminati, Alessandro Redondi, Stefano Savazzi, Luigi Serio |
HealthCom | 6 |
| 2024 | A Secure and Trustworthy Network Architecture for Federated Learning Healthcare ApplicationsabstractFederated Learning (FL) has emerged as a promising approach for privacy-preserving machine learning, particu-larly in sensitive domains such as healthcare. In this context, the TRUSTroke project aims to leverage FL to assist clinicians in ischemic stroke prediction. This paper provides an overview of the TRUSTroke FL network infrastructure. The proposed archi-tecture adopts a client-server model with a central Parameter Server (PS). We introduce a Docker-based design for the client nodes, offering a flexible solution for implementing FL processes in clinical settings. The impact of different communication pro-tocols (HTTP or MQTT) on FL network operation is analyzed, with MQTT selected for its suitability in FL scenarios. A control plane to support the main operations required by FL processes is also proposed. The paper concludes with an analysis of security aspects of the FL architecture, addressing potential threats and to increase trustworthiness. Antonio Boiano, Marco Di Gennaro 0001, Luca Barbieri, Michele Carminati, Monica Nicoli, Alessandro Redondi, Usevalad Milasheuski, Sanaz Kianoush, Stefano Savazzi, Albert Sund Aillet, Diogo Reis Santos, Luigi Serio |
WiMob | 2 |
| 2022 | DeepThought: A Reputation and Voting-Based Blockchain Oracle
Marco Di Gennaro 0001, Lorenzo Italiano, Giovanni Meroni, Giovanni Quattrocchi |
ICSOC | 1 |