EDBT 2026 Demo / reviewers in the wild / expert
Stefano Galantucci
dblp:300/9314
· DBLP profile ↗
9ranked-venue papers
1as first author
9since 2021 · last 2026
0000-0002-3955-0478ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving robustness and explainability of PE malware classifiers using GAN-Generated Synthetic Adversarial examplesabstractAbstract Adversarial machine learning has exposed critical vulnerabilities in Artificial Intelligence-based Windows Portable Executable (PE) malware detection. A well-crafted small perturbation to a PE malware binary can cause it to be misclassified as goodware. Adversarial Training (AT) is one of the most effective defenses; however, it is not always sufficient alone and often suffers from the robustness–accuracy trade-off. This study proposes Adversarial Training with Synthetic Augmentation (ATS), a novel defense methodology that augments unrealistic synthetic adversarial examples into the standard adversarial training, produced using the Conditional Tabular GAN (CTGAN). The robustness and resilience of Random Forest, Light Gradient Boosting Machine (LightGBM), and Multilayer Perceptron (MLP) classifiers were evaluated against five realistic Windows PE adversarial attacks: Full DOS, EXTEND, SHIFT, FGSM-padding, and GAMMA. Results show that the ATS methodology consistently outperformed AT in enhancing robustness across all attacks and classifiers while maintaining or improving clean accuracy and F1-score. SHAP-based interpretability analysis further reveals that ATS reduces dependence on attack-sensitive low-level features and increases attention to stable PE features. Overall, ATS provides a model-agnostic enhancement to standard AT, effectively reducing false negatives without compromising clean accuracy. Malik Al-Essa, Felice Franchini, Stefano Galantucci, Muhammad Imran 0028, Giuseppe Pirlo |
Cybersecur. | 3 |
| 2025 | AMAKAN: Fully Interpretable Adaptive Multiscale Attention Through Kolmogorov-Arnold Networks
Felice Franchini, Stefano Galantucci |
DATA | 2 |
| 2025 | SIEVE: Generating a cybersecurity log dataset collection for SIEM event classificationabstractEffective cyber threat monitoring relies on deploying robust Security Information and Event Management (SIEM) systems. SIEM applications receive security events generated by different devices, systems, and applications. They should properly correlate them to identify potential cyber threats based on tactics, techniques, and procedures (TTP), bypassing other security mechanisms (e.g., firewall, IDS, etc.). Given that logs are primarily generated to notify relevant system events and activities in a human-readable format, supervised Natural Language Processing (NLP) techniques could be used to train models that complement conventional parsing methodologies by automatically suggesting event classification into pre-defined categories. Training such models requires a substantial amount of pre-classified (labeled) data of different types to provide the learning patterns and nuances needed to make accurate predictions. Since the number of security event datasets is scarce due to privacy or availability reasons, and the few publicly available ones are often limited in terms of event diversity, number of labels, or simply unfit for the task at hand, an effective synthetic dataset for training SIEM-related machine learning event classification algorithms could be very useful. For these reasons, this paper proposes the generation of a synthetic dataset specifically designed to train SIEM systems for log-type classification. This research paper, starting from an in-depth methodological analysis of the prominent Cybersecurity related datasets available in the liturature, introduces SIEVE (Siem Ingesting EVEnts), a synthetic dataset collection built from publicly available log samples using SPICE (Semantic Perturbation and Instantiation for Content Enrichment), a novel text augmentation and perturbation technique. SPICE is shown to be effective in generating realistic logs. Each instance of the dataset collection displays different levels of augmentation. Subsequent performance assessments were conducted through comprehensive benchmarking against various NLP classification models. Tests were conducted by training the classifiers using SIEVE and testing them on both the same SIEVE logs and real logs. The results of the experiments show that the best model among those tested is SVM (MaF1 0.9323 - 0.9737), which maintains its performance with slight degradation, even in tests on real logs (MaF1 0.9477 - 0.9636). BERT, on the other hand, performs better than SVM in most of the tests on SIEVE (MaF1 0.9528 - 0.9730) but does not show robustness when tested on real logs (MaF1 0.8864 - 0.9182). Pierpaolo Artioli, Vincenzo Dentamaro, Stefano Galantucci, Alessio Magrì, Gianluca Pellegrini, Gianfranco Semeraro |
Comput. Networks | 3 |
| 2025 | CNN-AutoMIC: Combining convolutional neural network and autoencoder to learn non-linear features for KNN-based malware image classificationabstractMalware refers to malicious software or a component of software intended for malicious purposes. The manual analysis and detection of malicious software is challenging due to its complexity. Thus, several automated solutions have become popular for real-time malware detection. A spread-out approach consists of generating images from the samples bytecode and giving them to convolutional neural networks (CNNs), which are used either as classifiers or feature extractors for further classification algorithms. These systems perform extremely well when trained and tested on partitions of the same dataset. However, cross-dataset tests and malware detection verification on emerging real-world samples are required in the real-world context. This is a crucial challenge when probing the robustness of the systems and models. This paper proposes CNN-AutoMIC,a robust automated approach to extract features from malware images. CNN-AutoMIC employs a specific CNN architecture to extract features, followed by an autoencoder-based compressor that reduces features to two fundamental components. The two-dimensional projection of these components is the basis of the predictions performed by the K-nearest neighbors (K-NN) algorithm. Moreover, the observable placement of new samples on the obtained scatter plot makes it possible to explain why the AI-based system produced a certain prediction. It was benchmarked against several CNN-based models and a Vision Transformer. They were trained on the Malevis dataset and cross-dataset evaluated on four different real-world datasets. CNN-AutoMIC outperformed the competitors for each classification performance metric, while requiring a reasonable training and prediction time. In addition, it achieves a promising Akaike information criterion (AIC) score, indicating its efficiency in terms of model complexity. Simone Andriani, Stefano Galantucci, Andrea Iannacone, Antonio Maci, Giuseppe Pirlo |
Comput. Secur. | 2 |
| 2025 | FOBICS: Assessing project security level through a metrics framework that evaluates DevSecOps performanceabstractIn today’s software development landscape, the DevSecOps approach has gained traction due to its focus on the software development process and bolstering security measures in projects, a task in light of the ever-evolving cybersecurity threats. This study aims to address the lack of metrics for quantitatively assessing its efficacy from both security and business logic perspectives. To tackle this issue, the research introduces the Framework of Business Index Concerning Security (FOBICS), a set of metrics designed to enable transparent evaluations of project security. FOBICS considers various perspectives relevant to DevSecOps practices. It includes factors such as project duration and financial outcomes, making it appealing for implementation in business settings. The effectiveness of FOBICS is validated theoretically and empirically via its application in two real-world projects: the results from these implementations show a correlation between FOBICS metrics and the security strategies employed as the development methodologies adopted by diverse teams throughout the projects. Hence, FOBICS emerges as a tool for assessing and continuously monitoring project security, offering insights into areas of strength and areas that may require enhancement. FOBICS is shown to be effective in assessing the level of DevSecOps implementation. The ease of calculating FOBICS metrics makes them easily interpretable and continuously verifiable. Moreover, FOBICS summarizes most of the other quantitative and qualitative metrics in the literature. • DevSecOps challenges were analysed to identify metrics to assess project performance • A framework of metrics is proposed. The degree of Security and Testing is evaluated • FOBICS is compared with other metrics, showing how it can summarize many of them • The framework is applied to two real projects and the values obtained are evaluated Alessandro Caniglia, Vincenzo Dentamaro, Stefano Galantucci, Donato Impedovo |
Inf. Softw. Technol. | 3 |
| 2024 | Automatic decision tree-based NIDPS ruleset generation for DoS/DDoS attacksabstractAs the occurrence of Denial of Service and Distributed Denial of Service (DoS/DDoS) attacks increases, the demand for effective defense mechanisms increases. Recognition of such anomalies in the computer network is commonly performed through network-based intrusion detection and prevention systems (NIDPSs). Although NIDPSs allow the interception of all known attacks, they are not robust to the continuing variation over time of DoS/DDoS anomalies. The machine learning (ML) paradigm provides algorithms that can effectively reduce concept drift due to the evolution of cyber threat data patterns. These methodologies can be exploited for creating effective rules suitable for popular NIDPS engines such as Suricata. This paper proposes a new algorithm called Anomaly2Sign, which automatically produces rules for Suricata through an automatic Decision Tree (DT)-based generation process. The DT is trained on both anomalous and legitimate traffic, allowing the generation process to select anomaly features that can be mapped within the generated rule structure. Additionally, the DT hyperparameters are tuned at execution time to generate a minimal ruleset capable of detecting the largest number of anomalous packets. The proposed algorithm achieves classification metrics in the range of 99.7%–99.9% using the BOUN-DoS and BUET-DDoS datasets, outperforming the compared ML classifiers, i.e., Logistic Regression, Support Vector Machine, and Multi-Layer Perceptron. Furthermore, the leveraged DT model requires a shorter training and prediction time than the previously cited benchmark classifiers. To enforce the selection of the DT model, an analysis of model complexity is undertaken, including the evaluation of the Akaike Information Criterion (AIC) score. As a result of such an evaluation, the DT model achieved the lowest AIC score among the compared approaches denoting its low complexity. Finally, Anomaly2Sign has been compared with Syrius, i.e., an alternative state-of-the-art automatic NIDPS rules generator, obtaining better performance for detection rate and execution time. Antonio Coscia, Vincenzo Dentamaro, Stefano Galantucci, Antonio Maci, Giuseppe Pirlo |
J. Inf. Secur. Appl. | 3 |
| 2023 | An innovative two-stage algorithm to optimize Firewall rule orderingabstractPacket classification activity performed by a FireWall (FW) introduces high latency in network communications due to the computation time required to check whether any packet matches one of the FW rules. Such a classification process is done by sequentially checking the list of rules until a match is found or the end of the list is reached. Given the complexity of FW rules in some environments, this latency could become relevant. This problem is addressed by ordering the list of FW rules to minimize the classification latency, where the rules with higher activation frequencies are placed accordingly starting from the top of the list. This is not always feasible because dependency constraints between rules could exist: swapping the positions of dependent rules results in a loss of the integrity of the implemented security policy. For this reason, the FW rule ordering problem belongs to the realm of constrained combinatorial optimization. This paper proposes a two-stage algorithm to address this problem. The first stage performs an innovative topological sorting algorithm aimed at finding an optimal ordering for the constrained rules, taking into account the fact that rule activation frequencies are influenced by inter-packet arrival time, which typically obeys Zipf's law. The second stage employs a genetic algorithm to find the optimal ordering of all rules within the list. The proposed approach is evaluated using different filtering lists of different complexity provided by ClassBench. A comparison with other state-of-the-art algorithms addressing the same problem is performed. Furthermore, the performance analysis is extended employing an exact optimization method. The results obtained show the effectiveness of the proposed algorithm in minimizing packet classification latency, while a short reordering time is required. Antonio Coscia, Vincenzo Dentamaro, Stefano Galantucci, Antonio Maci, Giuseppe Pirlo |
Comput. Secur. | 3 |
| 2023 | YAMME: a YAra-byte-signatures Metamorphic Mutation EngineabstractRecognition of known malicious patterns through signature-based systems is unsuccessful against malware for which no known signature exists to identify them. These include not only zero-day but also known malicious software able to self-replicate rewriting its own code leaving unaffected its execution, namely metamorphic malware. YARA is a popular malware analysis tool that uses the so-called YARA-rules, which are built to match malicious contents within files or network packets analyzed by an Anti-Virus engine. Sometimes such content is expressed in the form of a byte-signature, i.e., a sequence of operational machine-level code. However, these can be bypassed since malware obfuscation techniques can change these sequences, rewriting them in several equivalent forms. This paper presents YAMME, a YARA-byte-signatures Metamorphic Mutation Engine to strengthen rules against some malware obfuscation techniques deployed in metamorphic mutation engines. First, it rewrites YARA-bye-signatures in several equivalent ways, as a metamorphic mutation engine would do. Second, an optimization phase exploits the YARA-rules syntax constructs to provide several rules formats, making them suitable for different real-world application requirements. YAMME rules have been evaluated on MWOR, G2, NGVCK, and MetaNG datasets, resulting in a better detection rate than that achieved by YARA-rules generated through AutoYara. Furthermore, an analysis of computational overhead required by different YAMME rules formats validates the low impact introduced by the mutation engine at the YARA-rules level. Antonio Coscia, Vincenzo Dentamaro, Stefano Galantucci, Antonio Maci, Giuseppe Pirlo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | A Case Study of Navigation System Assistance with Safety Purposes in the Context of Covid-19 Pandemic
Stefano Galantucci, Paolo Giglio, Vincenzo Dentamaro, Giuseppe Pirlo |
INTERACT (5) | 1 |