Carlo Mazzocca

dblp:302/2432 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0001-8949-2221ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 7 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems
Esteban Luques, Carlo Mazzocca, Güliz Seray Tuncay, A. Selcuk Uluagac
EuroS&P2
2026 On the Detectability of Active Gradient Inversion Attacks in Federated Learning
abstract
One of the key advantages of Federated Learning (FL) is its ability to collaboratively train a Machine Learning (ML) model while keeping clients' data on-site. However, this can create a false sense of security. Despite not sharing private data increases the overall privacy, prior studies have shown that gradients exchanged during the FL training remain vulnerable to Gradient Inversion Attacks (GIAs). These attacks allow reconstructing the clients' local data, breaking the privacy promise of FL. GIAs can be launched by either a passive or an active server. In the latter case, a malicious server manipulates the global model to facilitate data reconstruction. While effective, earlier attacks falling under this category have been demonstrated to be detectable by clients, limiting their real-world applicability. Recently, novel active GIAs have emerged, claiming to be far stealthier than previous approaches. This work provides the first comprehensive analysis of these claims, investigating four state-of-the-art GIAs. We propose novel lightweight client-side detection techniques, based on statistically improbable weight structures and anomalous loss and gradient dynamics. Extensive evaluation across several configurations demonstrates that our methods enable clients to effectively detect active GIAs without any modifications to the FL training protocol.
Vincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella, Mario Vento
SP3
2025 Compact and Selective Disclosure for Verifiable Credentials
abstract
Self-Sovereign Identity (SSI) is a novel identity model that empowers individuals with full control over their data, enabling them to choose what information to disclose, with whom, and when. This paradigm is rapidly gaining traction worldwide, supported by numerous initiatives such as the European Digital Identity (EUDI) Regulation or Singapore's National Digital Identity (NDI). For instance, by 2026, the EUDI Regulation will enable all European citizens to seamlessly access services across Europe using Verifiable Credentials (VCs). A key feature of SSI is the ability to selectively disclose only specific claims within a credential, enhancing the privacy protection of the identity owner. This paper proposes a novel mechanism designed to achieve Compact and Selective Disclosure for VCs (CSD-JWT). Our method leverages a cryptographic accumulator to encode claims within a credential into a unique, compact representation. We implemented CSD-JWT as an open-source solution and extensively evaluated its performance under various conditions. CSD-JWT provides significant memory savings, lowering usage by up to 46% compared to the state-of-the-art. It also minimizes network overhead by producing remarkably smaller Verifiable Presentations (VPs), with size reduction from 27% to 93%. Such features make CSD-JWT especially well-suited for resource-constrained devices, including hardware wallets designed for managing credentials.
Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac
ACSAC2
2025 Federated Unlearning in Healthcare: Why It Matters
abstract
In healthcare scenarios, privacy poses significant challenges due to the sensitivity of patient data. Federated Learning (FL) has emerged as a promising solution to unlock their potential while maintaining compliance with privacy-preserving regulations. It enables data contributors to train a global model without sharing raw data. However, FL introduces complexities in complying with the right to be forgotten, a fundamental principle of the European General Data Protection Regulation (GDPR). This right ensures clients can request the removal of their influence from the global model. Unfortunately, the intrinsic decentralized nature of FL makes retraining the model from scratch and Machine Unlearning (MU) methods unfeasible. This challenge has led to Federated Unlearning (FU), which aims to efficiently remove a client’s influence through post-processing the global model. FU ensures the unlearned model performs as if the forgotten data were never seen while minimizing performance degradation on other data. As unlearning strategies typically require multiple rounds to restore model performance on retained data, this paper investigates the natural attenuation of a client’s contributions over time without FU algorithms. We use the ProstateMRI dataset, a real-world federated healthcare dataset that naturally exhibits feature heterogeneity across parties. We evaluate metrics such as loss, accuracy, and Membership Inference Attacks (MIAs). Our findings highlight the necessity of FU methods to ensure compliance with privacy regulations and effectively erase client contributions from the global model. Code available at: https://github.com/alessiomora/medical federated unlearning
Alessio Mora, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista
IJCNN2
2025 SoK: Gradient Inversion Attacks in Federated Learning
Vincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella, Mario Vento
USENIX Security Symposium3
2025 VESPACE: A verifiable blockchain-based data space solution to empower the data economy
abstract
In the rapidly evolving data economy, the ability to securely and efficiently share data between organizations has become paramount, unlocking new opportunities for innovation and growth. In this context, different initiatives have worked on conceptual proposals and enabling technological building blocks, addressing design aspects of data spaces. However, the current landscape lacks practical implementations and integration of secure data-sharing primitives supporting a decentralized data ecosystem. To this end, we conduct an analysis of previous efforts and initiatives, identifying gaps. We then introduce VESPACE , a blockchain-based platform for data spaces that enables participants to selectively and securely share verifiable data with authorized users while maintaining control over their access. Our framework incorporates data sovereignty principles implemented through Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and blockchain technology, qualifying decentralized identity and access control as key features to establish user trust in decentralized data ecosystems. We present a prototype system implementation of VESPACE , evaluating the design choices, showcasing the feasibility of our proposal. • We analyze standards and projects to guide verifiable, auditable data space design • We propose VESPACE , a verifiable data space aligned with FAIR and SSI principles. • We evaluate a prototype to assess the scalability of the implemented security primitives.
Andrea Roberta Costagliola, Carlo Mazzocca, Armir Bujari, Rebecca Montanari, Paolo Bellavista
Comput. Commun.2
2025 Benchmarking Selective Disclosure Mechanisms for Verifiable Credentials: A Systematic Comparison for Security and Privacy
abstract
In a world where digitalization isreshapingevery aspect of society, digital identity has become more crucial than ever to establish trust and accountability across all entities, whether human, organizational, or machine-based. Numerous initiatives are emerging worldwide, such as the United States mobile driver’s license (mDLs) and Singapore’s National Digital Identity (NDI). In May 2024, the European Union introduced Regulation 2024/1183, establishing the European Digital Identity Framework. By 2026, this framework will provide all European citizens with a European Digital Identity Wallet (EUDIW), allowing them to access both online and offline public and private services while maintaining full control over their data. Individuals can selectively disclose only the required information to access services. However, the current EUDIW design relies on Selective Disclosure for JSON Web Token (SD-JWT), which does not fully meet the privacy requirements outlined in the regulation. This paper presents a comprehensive comparison of the main selective disclosure mechanisms. Specifically, we identify relevant threat models, formalize associated security and privacy properties, and assess the extent to which existing mechanisms satisfy these properties in mitigating the identified threats. Furthermore, we introduce an open-source benchmark that evaluates multiple selective disclosure across key performance indicators, including computational latency, bandwidth consumption, and storage requirements.
Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac
IEEE Trans. Inf. Forensics Secur.2
2025 Federated Unlearning: A Survey on Methods, Design Guidelines, and Evaluation Metrics
abstract
Federated learning (FL) enables collaborative training of a machine learning (ML) model across multiple parties, facilitating the preservation of users' and institutions' privacy by maintaining data stored locally. Instead of centralizing raw data, FL exchanges locally refined model parameters to build a global model incrementally. While FL is more compliant with emerging regulations such as the European General Data Protection Regulation (GDPR), ensuring the right to be forgotten in this context-allowing FL participants to remove their data contributions from the learned model-remains unclear. In addition, it is recognized that malicious clients may inject backdoors into the global model through updates, e.g., to generate mispredictions on specially crafted data examples. Consequently, there is the need for mechanisms that can guarantee individuals the possibility to remove their data and erase malicious contributions even after aggregation, without compromising the already acquired "good" knowledge. This highlights the necessity for novel federated unlearning (FU) algorithms, which can efficiently remove specific clients' contributions without full model retraining. This article provides background concepts, empirical evidence, and practical guidelines to design/implement efficient FU schemes. This study includes a detailed analysis of the metrics for evaluating unlearning in FL and presents an in-depth literature review categorizing state-of-the-art FU contributions under a novel taxonomy. Finally, we outline the most relevant and still open technical challenges, by identifying the most promising research directions in the field.
Nicolò Romandini, Alessio Mora, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista
IEEE Trans. Neural Networks Learn. Syst.3
2024 Certifying IoT Data with Verifiable Credentials
abstract
The Internet of Things (IoT) is a major contributor to the vast amount of data generated worldwide, significantly impacting the big data market. However, this data holds value only when utilized for insights and applications. Many organizations hesitate to use third-party data due to concerns about accuracy, reliability, and integrity. Enhancing trustworthiness in data is crucial to unlock their full potential, especially in critical domains such as healthcare where erroneous data can have severe consequences. The Identity of Things (IDoT) paradigm addresses this need by identifying trustworthy devices using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), offering promising solutions for digital identification. Although DIDs and VCs have primarily been used for mutual trust and access control, their potential for data certification in IoT remains underexplored. This paper is the first to investigate the feasibility of IoT devices to use VCs for certifying data. We evaluated devices with varying capabilities, focusing on the latency, computing, and storage requirements for issuing VCs. Our findings demonstrate that IoT devices can issue VCs with up to 100 claims in less than 90 ms, with storage requirements growing linearly and remaining below 4 KB. Using VCs for data certification does not introduce significant computational overhead, suggesting its practicality for IoT environments.
Carlo Mazzocca, Stefano Allevi, Rebecca Montanari
NCA1
2024 EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks
Carlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca Montanari
USENIX Security Symposium1
2024 DIVA: A DID-based reputation system for secure transmission in VANETs using IOTA
abstract
Today’s advancement in Vehicular Ad-hoc Networks (VANET) constitutes a cornerstone in ensuring traffic safety in Intelligent Transportation Systems (ITS). In this context, vehicle-to-vehicle (V2V) communications are a pivotal enabler for road safety, traffic optimization, and pedestrian protection. However, V2V communications lack effective and efficient security solutions that can adequately ensure the trustworthiness of the source of the transmitted content. In this work, we originally propose DIVA, i.e., a Decentralized Identifier-based reputation system for secure transmission in VAnets. In particular, we claim the suitability of utilizing IOTA, a Direct Acyclic Graph (DAG)-based ledger, to securely store reputation scores and of leveraging Decentralized Identifiers (DIDs) to identify participating vehicles. DIVA also incorporates and implements a reputation algorithm that computes reputation scores by analyzing both safety and non-safety messages, exchanged among vehicles and Road Side Units (RSUs) in compliance with the related European Telecommunications Standards Institute (ETSI) standards. Thus, DIVA can effectively identify malicious contributors and decrease their reputation scores. The reported experimental results clearly show the feasibility and effectiveness of DIVA, by working on an extended and comprehensive dataset of realistic V2V messages; the dataset has been made openly accessible to the research community, also to increase result reproducibility.
Angelo Feraudo, Nicolò Romandini, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista
Comput. Networks3
2024 Secure software development and testing: A model-based methodology
abstract
Modern industries widely rely upon software and IT services, in a context where cybercrime is rapidly spreading in more and more sectors. Unfortunately, despite greater general awareness of security risks and the availability of security tools that can help to cope with those risks, many organizations (especially medium/small-size ones) still lag when it comes to building security into their services. This is mainly due to the limited security skills of common developers/IT project managers and to the typically high costs of security procedures. In fact, while automated tools exist to perform code analysis, vulnerability scanning, or security testing, the manual intervention of security experts is still required not only for security analysis and design, but also to configure and elaborate the output of the security testing tools. In this paper, we propose a novel secure software development methodology aimed at supporting developers from security design to security testing, suitable for integration within modern DevOps pipelines according to a DevSecOps (or SecDevOps) approach. The proposed methodology leverages a model-based process that enables identifying existing threats, selecting appropriate countermeasures to enforce, and verify their mitigation effectiveness through both static assessment procedures and targeted security tests. To demonstrate our approach's feasibility and concretely illustrate the devised activities, we provide a step-by-step description of the whole process concerning a containerized microservice-based application case study. In addition, we discuss the application of the proposed methodology, in its threat modeling and security testing phases, to a well-known vulnerable web application widely used for security training purposes, to illustrate that we can identify most of the existing vulnerabilities and determine appropriate test plans to assess and mitigate such vulnerabilities.
Valentina Casola, Alessandra De Benedictis, Carlo Mazzocca, Vittorio Orbinato
Comput. Secur.3
2024 Enabling Federated Learning at the Edge through the IOTA Tangle
abstract
The proliferation of Internet of Things (IoT) devices, generating massive amounts of heterogeneous distributed data, has pushed toward edge cloud computing as a promising paradigm to bring cloud capabilities closer to data sources. In many cases of practical interest, centralized Machine Learning (ML) approaches can hardly be employed due to high communication costs, low reliability, legal restrictions, and scalability issues. Therefore, Federated Learning (FL) is emerging as a promising distributed ML approach that enables models to be trained on remote devices using their local data. However, “traditional” FL solutions still present open technical challenges, such as single points of failure and lack of trustworthiness among participants. To address these open challenges, some researchers have started to propose leveraging blockchain technologies. However, the adoption of blockchain for FL at the edge is limited by several factors nowadays, such as long waiting times for transaction confirmation and high energy consumption. In this work, we conduct an original and comprehensive analysis of the key design challenges to address towards an efficient implementation of FL at the edge, and analyze how Distributed Ledger Technologies (DLTs) can be employed to overcome them. Then, we present a novel architecture that enables FL at the edge by leveraging the IOTA Tangle, a next-generation DLT whose data structure is a directed acyclic graph (DAG), and the InterPlanetary File System (IPFS) to store and share partial models. Experimental results demonstrate the feasibility and efficiency of our proposed solution in real-world deployment scenarios.
Carlo Mazzocca, Nicolò Romandini, Rebecca Montanari, Paolo Bellavista
Future Gener. Comput. Syst.1
2024 A secure and privacy preserved infrastructure for VANETs based on federated learning with local differential privacy
Hajira Batool, Adeel Anjum, Abid Khan, Stefano Izzo, Carlo Mazzocca, Gwanggil Jeon
Inf. Sci.5
2023 Federated Learning Meets Blockchain: a Power Consumption Case Study
abstract
Federated learning (FL) is emerging as the most promising approach to collaboratively train a machine learning (ML) model on a common task without centralizing data. During each FL round, participants locally train a partial model with its on-premises data. Such models are subsequently aggregated to derive a global one. How these partial models are combined is a primary concern. Traditional approaches usually rely on a parameter server that introduces many weaknesses such as single point of failure, lack of trustworthiness among unknown participants, and incapacity to handle the traffic generated from millions of devices. Thus, to overcome such concerns, blockchain has recently been proposed as a valuable solution to improve the robustness of FL approaches. The full-blown benefits of using blockchain enable tackling the limits of centralized servers. However, energy consumption is still one of the significant factors inhibiting its widespread due to the current discussions on climate change and sustainability. Recently, a growing number of research works have been focusing on integrating FL and blockchain, nevertheless, adequate analysis and estimate of their energy and power consumption are often lacking. This paper presents an estimate of the power consumption of FlowChain, an architecture that integrates FL with blockchain to simplify the use of FL. Experimental results demonstrate that the overall power consumption significantly depends on the ML model adopted.
Nicolò Romandini, Carlo Mazzocca, Rebecca Montanari
PDP2
2023 TruFLaaS: Trustworthy Federated Learning as a Service
abstract
The increasing availability of data generated by Internet of Things (IoT) and Industrial Internet of Things (IIoT) devices, as well as privacy and law regulations, have significantly boosted the interest in collaborative machine learning (ML) approaches. In this direction, we claim federated learning (FL) as a promising ML paradigm where participants collaboratively train a global model without outsourcing on-premises data. However, setting up and using FL can be extremely costly and time-consuming. To effectively promote the adoption of FL in real-world scenarios, while limiting the overhead and knowledge of the underlying technology, service providers should offer federated learning as a service (FLaaS). One of the major concerns while designing an architecture that provides FLaaS is achieving trustworthiness among involved typically unknown participants. This article presents a blockchain-based architecture that achieves Trustworthy federated learning as a service (TruFLaaS). Our solution provides trustworthiness among 3rd-party organizations by leveraging blockchain, smart contracts, and a decentralized oracle network. Specifically, during each FL round, the service provider supplies a sample, without overlapping, of its validation set to validate all partial models submitted by clients. By doing so, poor models, which tend to degrade performance or introduce malicious backdoors, are identified and discarded. Due to the transparency of the blockchain, not changing the validation set would enable participants to forge a malicious partial model that passes the validation phase. We evaluate our approach over two well-known IIoT datasets: the reported experimental results show that TruFLaaS outperforms the state-of-the-art literature solutions in the field.
Carlo Mazzocca, Nicolò Romandini, Matteo Mendula, Rebecca Montanari, Paolo Bellavista
IEEE Internet Things J.1
2023 Machine Learning Insights for Behavioral Data Analysis Supporting the Autonomous Vehicles Scenario
abstract
The advent of the digital innovation era is changing service, use, and resources management paradigms, offering a wide range of new and essential opportunities. In particular, the advent of the Internet of Things (IoT), i.e., the ability to connect individual objects to the Internet, also capable of communicating autonomously, has its particular declination on the connected vehicle. It is combined with the potential of advanced sensors placed pervasively on vehicles, which offer multifunctional monitoring capabilities of the entire system: from individual components up to the whole vehicle, including driver behavior and conditions and many exogenous parameters to the vehicle (road and weather conditions, congestion, risk situations, changes to mobility plans, etc.). In this perspective, machine learning (ML) models can transform raw data into new knowledge; they can contribute in an innovative way to define and suggest decisions, strategies, and criteria for resource use. Nowadays, most intelligent mobility projects also integrate artificial intelligence (AI) and ML solutions. In this article, we present and discuss the application of unsupervised learning techniques on a vehicular IoT data set. The main goal is to generate new knowledge about a geographical zone by analyzing historical drivers behavioral data. The autonomous vehicle’s framework can exploit the generated valuable insights to optimize the routes and prevent critical issues.
Edoardo Prezioso, Fabio Giampaolo, Carlo Mazzocca, Armir Bujari, Valeria Mele, Flora Amato
IEEE Internet Things J.3
2023 FRAMH: A Federated Learning Risk-Based Authorization Middleware for Healthcare
abstract
Modern healthcare systems operate in highly dynamic environments requiring adaptable access control mechanisms. Access to sensitive data and medical equipment should be granted or denied according to the current health situation of the patient. To handle the need for adaptable access control of healthcare scenarios, we propose a novel model that allows dynamic access control decisions based on the context characterizing the source, type of access request, patient, and estimated risk corresponding to the conditions of the patient. Estimating patient status risk requires analyzing vital physiological data whose availability is growing, thanks to the widespread diffusion of the Internet of Medical Things (IoMT) devices. Inferring the patient health status risk through machine learning (ML) techniques is possible, but to achieve better accuracy, the training phase requires the aggregation of vast amounts of data from different sources. This aggregation could be difficult or even impossible due to organization regulations and privacy laws. To address these issues, this article proposes a novel federated learning risk-based authorization middleware for healthcare (FRAMH) that supports risk-based access control to deal with changing and unforeseen medical situations. Our solution infers the risk of health status through a federated learning (FL) approach enriched with blockchain to avoid the weaknesses of centralized servers. The implemented prototype and a large set of experimental results demonstrate the advantages of FL in estimating the risk in healthcare scenarios. Through this approach, even a medical institution with a limited dataset can achieve a satisfying risk estimation and efficient access control enforcement.
Carlo Mazzocca, Nicolò Romandini, Michele Colajanni, Rebecca Montanari
IEEE Trans. Comput. Soc. Syst.1
2022 A Fully Decentralized Architecture for Access Control Verification in Serverless Environments
abstract
Serverless computing is a novel paradigm that has been widely adopted, in recent years, across many sectors due to its fine-grained scalability and fast time-to-market. This paradigm aims at offloading users from heavy burden tasks including those related to authentication and authorization. However, existing security mechanisms provided by cloud providers do not seem to be adequate to completely secure serverless platforms. In particular, typical access control solutions rely either on centralized authorization services or implement access control verification within the business logic. These approaches respectively degrade system performance and lead to security issues derived from the tight coupling among code and authorization verification. In this paper, we present a solution to address these problems with a fully decentralized architecture integrating access control verification in serverless environments. We implemented a prototype of the proposed architecture and evaluated its performance under different load conditions. Experiments show that our proposal outperforms other approaches.
Andrea Sabbioni, Carlo Mazzocca, Michele Colajanni, Rebecca Montanari, Antonio Corradi
ISCC2