EDBT 2026 Demo / reviewers in the wild / expert
Gianluca De Stefano
dblp:376/3400
· DBLP profile ↗
4ranked-venue papers
0as first author
4since 2021 · last 2025
0009-0006-1454-2574ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Web and mobile security · 67% Privacy and data protection · 33% | |
| Human-computer interaction and pervasive computing
1 paper |
Usability and user experience research · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 3 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
web application security |
0.9 | 1 | 2025 | YuraScanner: Leveraging LLMs for Task-driven Web App Scanning · NDSS 2025 |
Web and mobile security
web vulnerability scanning |
0.9 | 1 | 2025 | YuraScanner: Leveraging LLMs for Task-driven Web App Scanning · NDSS 2025 |
Program analysis
dynamic analysis |
0.3 | 1 | 2025 | YuraScanner: Leveraging LLMs for Task-driven Web App Scanning · NDSS 2025 |
Methods — techniques the papers use, named apart from their topics
rationale classification · 1.7large-scale telemetry analysis · 1.7large language model · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design PatternsabstractModern web applications use features like camera and geolocation for personalized experiences, requiring user permission via browser prompts.To explain these requests, applications provide rationales-contextual information on why permissions are needed.Despite their importance, little is known about how often rationales appear on the web or their influence on user decisions.This paper presents the first large-scale study of how the web ecosystem handles permission rationales, covering three areas: (i) identifying webpages that use permissions, (ii) detecting and classifying permission rationales, and (iii) analyzing their attributes to understand their impact on user decisions.We examined over 770K webpages from Chrome telemetry, finding 3.6K unique rationale texts and 749 rationale UIs across 85K pages.We extracted key rationale attributes and assessed their effect on user behavior by cross-referencing them with Chrome telemetry data.Our findings reveal nine key insights, providing the first evidence of how different rationales affect user decisions. Yusra Elbitar, Soheil Khodayari, Marian Harbach, Gianluca De Stefano, Balazs Engedy, Giancarlo Pellegrino, Sven Bugiel |
CHI | 4 |
| 2025 | YuraScanner: Leveraging LLMs for Task-driven Web App Scanning
Aleksei Stafeev, Tim Recktenwald, Gianluca De Stefano, Soheil Khodayari, Giancarlo Pellegrino |
NDSS | 3 |
| 2024 | Uncovering the Role of Support Infrastructure in Clickbait PDF CampaignsabstractClickbait PDFs, an entry point for multiple Web attacks, are distributed via SEO poisoning and rank high in search results due to being massively uploaded on abused or compromised websites. The central role of these hosts in the distribution of clickbait PDFs remains understudied, and it is unclear whether attackers differentiate the types of hosting for PDF uploads, how long they rely on hosts, and how affected parties respond to abuse. To address this, we conducted real-time analyses on hosts, collecting data on 4,648,939 clickbait PDFs served by 177,835 hosts over 17 months. Our results revealed a diverse infrastructure, with hosts falling into three main hosting types. We also identified at scale the presence of eight software components which facilitate file uploads and which are likely exploited for clickbait PDF distribution. We contact affected parties to report the misuse of their resources via a large-scale vulnerability notification. While we observed some effectiveness in terms of number of cleaned-up PDFs following the notification, long-term improvement in this infrastructure remained insignificant. This finding raises questions about the hosting providers' role in combating abuse and the actual impact of vulnerability notifications. Giada Stivala, Gianluca De Stefano, Andrea Mengascini, Mariano Graziano, Giancarlo Pellegrino |
EuroS&P | 2 |
| 2024 | Adversarial mimicry attacks against image splicing forensics: An approach for jointly hiding manipulations and creating false detectionsabstractThe term “mimicry attack” has been coined in computer security and used in adversarial machine learning: an attacker observes what a machine-learning system has learned and adjusts the malicious input so that it mimics a benign input. In this paper we extend this concept to image forensics, to allow an attacker modifying a manipulated image so that it appears pristine when analyzed by a target forensic detector. Recent work has shown that such attacks can be executed against detectors based on deep networks for hiding image tampering. We do more than that: our mimicry attack can force the target detector to identify arbitrary fictitious manipulations, while hiding the true ones. Accordingly, the user of the forensic detector is completely misled. From a methodological viewpoint, the proposed attack artificially alters the detector-specific intermediate representations according to the pixel distribution in the manipulated image, by applying a gradient-based optimization process. Experimental tests on different data sets and detectors demonstrate that our approach succeeds in jointly hiding manipulated areas and arbitrarily adding new ones, favorably comparing with the state-of-the-art in the first task. Giulia Boato, Francesco G. B. De Natale, Gianluca De Stefano, Cecilia Pasquini, Fabio Roli |
Pattern Recognit. Lett. | 3 |