EDBT 2026 Demo / reviewers in the wild / expert
Marco Simoni
dblp:327/1964
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0000-4170-503XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On-device derivation of IoT usage control policies: Automating U-XACML policy generation from natural language with LLMs in smart homes environmentsabstractIn this paper, we present a framework that integrates AI-based derivation of Access and Usage Control policies for IoT devices, using Large Language Models (LLMs) to automate the generation of policies from unstructured natural language commands. The framework employs a hybrid approach, combining LLMs with dedicated libraries to ensure efficient on-device execution. Our approach is based on a two-step process: first, a fine-tuned LLM converts user commands into structured JSON policy representations; then, a transformation module translates the JSON policies into fully compliant U-XACML policies. To ensure generality across different domains, we introduce a taxonomy-driven dataset creation, which enables policy creation for different environments such as smart homes, smart offices, and healthcare settings. Our evaluation demonstrates that the system achieves 93 % accuracy in policy generation and 91 % accuracy when handling ambiguous or noisy inputs. It also reaches 98 % agreement with expert-defined policies in real-world scenarios. Finally, on-device performance evaluations confirm the feasibility of running the model in practical settings, demonstrating reliable inference under constrained hardware conditions. Loay Alajramy, Marco Simoni, Marco Rasori, Andrea Saracino, Paolo Mori |
Future Gener. Comput. Syst. | 2 |
| 2026 | Concise thoughts: Impact of output length on LLM reasoning and cost
Sania Nayab, Giulio Rossolini, Marco Simoni, Andrea Saracino, Giorgio C. Buttazzo, Nicolamaria Manes, Fabrizio Giacomelli |
Inf. Sci. | 3 |
| 2025 | MATRIX: A Comprehensive Graph-Based Framework for Malware Analysis and Threat ResearchabstractThis paper presents MATRIX (Malware Analysis and Threat Research with STIX), a graph database for the comprehensive analysis and research of malware and threats. To provide a unified view of the threat landscape, MATRIX integrates data from major cybersecurity frameworks, including MITRE ATT&CK, DEF3ND, CAPEC, Malware Behavior Catalog (MBC), Metasploit, Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE). Developed in Neo4j using the Structured Threat Information Expression (STIXTM) standard, MATRIX includes more than 22,910 nodes and combines 14 STIX Domain Objects (SDOs) and 6 STIX Relationship Objects (SROs) to provide a detailed analysis of malware behavior, detection rules and defense strategies, making it a valuable tool for cybersecurity research. The system also integrates real-world malware reports and is automatically updated with data from sources such as VirusTotal, MalwareBazaar and VirusShare, supporting continuous and up-to-date threat analysis. We demonstrate its versatility through case studies comparing malware objectives and analyzing the impact of detection and mitigation. Marco Simoni, Andrea Saracino |
SECRYPT | 1 |
| 2024 | Cybersecurity with LLMs and RAGs: Challenges and Innovations
Marco Simoni, Andrea Saracino |
SecureComm (4) | 1 |
| 2023 | Graph-Based Android Malware Detection and Categorization through BERT TransformerabstractIn this paper, we propose a novel approach to Android malware analysis and categorization that leverages the power of BERT (Bidirectional Encoder Representations from Transformers) to classify API call sequences generated from Android API Call Graph. By utilizing the API Call Graph, our approach captures the intricate relationships and dependencies between API calls, enabling a deeper understanding of the behavior exhibited by Android malware. Our results show that our approach achieves high accuracy in classifying API call sequences as malicious or benign and the method provides a promising solution also for categorizing Android malware and can help mitigate the risks posed by malicious Android applications. Andrea Saracino, Marco Simoni |
ARES | 2 |