EDBT 2026 Demo / reviewers in the wild / expert
Gabriele Lenzini
dblp:78/5724
· DBLP profile ↗
58ranked-venue papers
1as first author
20since 2021 · last 2026
0000-0001-8229-3270ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 40 · 1 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 9 · 8 since 2021Software engineering, systems software and programming languages · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Request a Note: How the Request Function Shapes X's Community Notes SystemabstractX's Community Notes is a crowdsourced fact-checking system. To improve its scalability, X introduced ``Request Community Note'' feature, enabling users to solicit fact-checks from contributors on specific posts. Yet, its implications for the system -- what gets checked, by whom, and with what quality -- remain unclear. Using 98,685 requested posts and their associated notes, we evaluate how requests shape the Community Notes system. We find that requested posts with higher GPT-estimated misleadingness and from authors with greater misinformation exposure are more likely to receive notes. Conversely, requested political posts (vs. non-political) are less likely to receive notes. We also observe partisan asymmetries: posts from Republicans are more likely to receive notes than those from Democrats. Although only 12% of requested posts receive request-fostered notes from top contributors, these notes are rated as more helpful and less polarized than others, partly reflecting top contributors' selective fact-checking of misleading posts. Our findings highlight both the limitations and promise of requests for scaling high-quality community-based fact-checking. Yuwei Chuai, Xin Yi 0001, Mohsen Mosleh, Gabriele Lenzini |
CHI | 6 |
| 2026 | Consensus Stability of Community Notes on XabstractCommunity-based fact-checking systems, such as Community Notes on X (formerly Twitter), aim to mitigate online misinformation by surfacing annotations judged helpful by contributors with diverse viewpoints. While prior work has shown that the platform's bridging-based algorithm effectively selects helpful notes at the time of display, little is known about how evaluations change after notes become visible. Using a large-scale dataset of 437,396 community notes and 35 million ratings from over 580,000 contributors, we examine the stability of helpful notes and the rating dynamics that follow their initial display. We find that 30.2% of displayed notes later lose their helpful status and disappear. Using interrupted time series models, we further show that note display triggers a sharp increase in rating volume and a significant shift in rating leaning, but these effects differ across rater groups. Contributors with viewpoints similar to note authors tend to increase supportive ratings, while dissimilar contributors increase negative ratings, producing systematic post-display polarization. Counterfactual analyses suggest that this post-display polarization, particularly from dissimilar raters, plays a substantial role in note disappearance. These findings highlight the vulnerability of consensus-based fact-checking systems to polarized rating behavior and suggest pathways for improving their resilience. Yuwei Chuai, Gabriele Lenzini, Nicolas Pröllochs |
WWW | 2 |
| 2026 | Secure authentication and traceability of physical objects
Mónica P. Arenas, Gabriele Lenzini, Mohammadamin Rakeei, Peter Y. A. Ryan, Marjan Skrobot, Maria Zhekova |
Comput. Secur. | 2 |
| 2026 | Poison to Detect: Detection of Targeted Overfitting in Federated LearningabstractFederated Learning (FL) enables collaborative model training among clients without centralising data, making it a widely adopted privacy enhancing technology (PET). Despite its privacy benefits, FL remains vulnerable to orchestrator-driven privacy attacks. In this paper, we study an underexplored threat in which a dishonest orchestrator intentionally manipulates the aggregation process to induce targeted overfitting in local models of specific clients. Although prior work focuses on reducing information leakage during training, we emphasise early client-side detection of targeted overfitting, allowing clients to disengage before significant harm occurs. To this end, we propose three detection techniques—label flipping, backdoor trigger injection, and model fingerprinting—which enable clients to verify the integrity of the global aggregation. We evaluated our methods across multiple datasets and attack scenarios. In single-client attacks, all three methods detect orchestrator-induced overfitting within 1–2 training rounds with F1 scores exceeding 0.7. Scalability experiments further show that detection effectiveness is influenced by cohort composition and method parameters. These results demonstrate that client-side integrity testing can provide early, effective, and scalable detection, supporting safer deployment of FL systems. Soumia Zohra El Mestari, Maciej Zuziak, Gabriele Lenzini |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Community Fact-Checks Trigger Moral Outrage in Replies to Misleading Posts on Social Mediaabstractpeer reviewed Yuwei Chuai, Anastasia Sergeeva, Gabriele Lenzini, Nicolas Pröllochs |
CHI | 3 |
| 2025 | Is Fact-Checking Politically Neutral? Asymmetries in How U.S. Fact-Checking Organizations Pick Up False Statements Mentioning Political ElitesabstractPolitical elites play an important role in the proliferation of online misinformation. However, an understanding of how fact-checking platforms pick up politicized misinformation for fact-checking is still in its infancy. Here, we conduct an empirical analysis of mentions of U.S. political elites within fact-checked statements. For this purpose, we collect a comprehensive dataset consisting of 35,014 true and false statements that have been fact-checked by two major fact-checking organizations (Snopes, PolitiFact) in the U.S. between 2008 and 2023, i.e., within an observation period of 15 years. Subsequently, we perform content analysis and explanatory regression modeling to analyze how veracity is linked to mentions of U.S. political elites in fact-checked statements. Our analysis yields the following main findings: (i) Fact-checked false statements are, on average, 20% more likely to mention political elites than true fact-checked statements. (ii) There is a partisan asymmetry such that fact-checked false statements are 88.1% more likely to mention Democrats, but 26.5% less likely to mention Republicans, compared to fact-checked true statements. (iii) Mentions of political elites in fact-checked false statements reach the highest level during the months preceding elections. (iv) Fact-checked false statements that mention political elites carry stronger other-condemning emotions and are more likely to be pro-Republican, compared to fact-checked true statements. In sum, our study offers new insights into understanding mentions of political elites in false statements on U.S. fact-checking platforms, and bridges important findings at the intersection between misinformation and politicization. Yuwei Chuai, Jichang Zhao, Nicolas Pröllochs, Gabriele Lenzini |
ICWSM | 4 |
| 2025 | Can Contributing More Put You at a Higher Leakage Risk? The Relationship Between Shapley Value and Training Data Leakage Risks in Federated LearningabstractFederated Learning (FL) is a crucial approach for training large-scale AI models while preserving data locality, eliminating the need for centralised data storage. In collaborative learning settings, ensuring data quality is essential, and in FL, maintaining privacy requires limiting the knowledge accessible to the central orchestrator, which evaluates and manages client contributions. Accurately measuring and regulating the marginal impact of each client’s contribution needs specialised techniques. This work examines the relationship between one such technique—Shapley Values—and a client’s vulnerability to Membership inference attacks (MIAs). Such a correlation would suggest that the contribution index could reveal high-risk participants, potentially allowing a malicious orchestrator to identify and exploit the most vulnerable clients. Conversely, if no such relationship is found, it would indicate that contribution metrics do not inherently expose information exploitable for powerful privacy attacks. Our empirical analysis in a cross-silo FL setting demonstrates that leveraging contribution metrics in federated environments does not substantially amplify privacy risks. Soumia Zohra El Mestari, Maciej Zuziak, Gabriele Lenzini, Salvatore Rinzivillo |
SECRYPT | 3 |
| 2025 | Remote secure object authentication: Secure sketches, fuzzy extractors, and security protocolsabstractCoating objects with microscopic droplets of liquid crystals makes it possible to identify and authenticate objects as if they had biometric-like features: this is extremely valuable as an anti-counterfeiting measure. How to extract features from images has been studied elsewhere, but exchanging data about features is not enough if we wish to build secure cryptographic authentication protocols . What we need are authentication tokens (i.e., bitstrings), strategies to cope with noise, always present when processing images , and solutions to protect the original features so that it is impossible to reproduce them from the tokens. Secure sketches and fuzzy extractors are the cryptographic toolkits that offer these functionalities, but they must be instantiated to work with the peculiar specific features extracted from images of liquid crystals. We show how this can work and how we can obtain uniform, error-tolerant, and random strings, and how they are used to authenticate liquid crystal coated objects. Our protocol reminds an existing biometric-based protocol, but only apparently. Using the original protocol as-it-is would make the process vulnerable to an attack that exploits certain physical peculiarities of our liquid crystal coatings. Instead, our protocol is robust against the attack. We prove all our security claims formally, by modeling and verifying in Proverif, our protocol and its cryptographic schemes. We implement and benchmark our solution, measuring both the performance and the quality of authentication . Mónica P. Arenas, Georgios Fotiadis, Gabriele Lenzini, Mohammadamin Rakeei |
Comput. Secur. | 3 |
| 2024 | "Who Knows? Maybe it Really Works": Analysing Users' Perceptions of Health Misinformation on Social MediaabstractHealth misinformation, defined as health-oriented information that contradicts empirically supported scientific findings, has become a significant concern on social media platforms. In response, platforms have implemented diverse design solutions to block such misinformation or alert users about its potential inaccuracies. However, there is limited knowledge about users’ perceptions of this specific type of misinformation and the actions that are necessary from both the platforms and the users themselves to mitigate its proliferation. This paper explores social media users’ (n = 22) perceptions of health misinformation. On the basis of our data, we identify specific types of health misinformation and align them with user-suggested countermeasures. We point to the critical demands for anti-misinformation solutions for health topics, emphasizing the transparency of information sources, immediate presentation of information, and clarity. Building on these findings, we propose a series of design recommendations to aid the future development of solutions aimed at counteracting misinformation. Huiyun Tang, Gabriele Lenzini, Samuel Greiff, Björn Rohles, Anastasia Sergeeva |
Conference on Designing Interactive Systems | 2 |
| 2024 | The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentabstractOrganizations rely on phishing interventions to enhance employees’ vigilance and safe responses to phishing emails that bypass technical solutions. While various resources are available to counteract phishing, studies emphasize the need for interactive and practical training approaches. To investigate the effectiveness of such an approach, we developed and delivered two anti-phishing trainings, group discussion and role-playing, at a European university. We conducted a pre-registered1 experiment (N = 105), incorporating repeated measures at three time points, a control group, and three in-situ phishing tests. Both trainings enhanced employees’ anti-phishing self-efficacy and support-seeking intention in within-group analyses. Only the role-playing training significantly improved support-seeking intention when compared to the control group. Participants in both trainings reported more phishing tests and demonstrated heightened vigilance to phishing attacks compared to the control group. We discuss practical implications for evaluating and improving phishing interventions and promoting safe responses to phishing threats within organizations. Xiaowei Chen 0013, Margault Sacré, Gabriele Lenzini, Samuel Greiff, Verena Distler, Anastasia Sergeeva |
CHI | 3 |
| 2024 | Can AI Help with the Formalization of Railway Cybersecurity Requirements?
Maurice H. ter Beek, Alessandro Fantechi, Stefania Gnesi, Gabriele Lenzini, Marinella Petrocchi |
ISoLA (1) | 4 |
| 2024 | Verifying Artifact Authenticity with Unclonable Optical Tagsabstractpeer reviewed Mónica P. Arenas, Gabriele Lenzini, Mohammadamin Rakeei, Peter Y. A. Ryan, Marjan Skrobot, Maria Zhekova |
SECRYPT | 2 |
| 2024 | Preserving data privacy in machine learning systemsabstractThe wide adoption of Machine Learning to solve a large set of real-life problems came with the need to collect and process large volumes of data, some of which are considered personal and sensitive, raising serious concerns about data protection. Privacy-enhancing technologies (PETs) are often indicated as a solution to protect personal data and to achieve a general trustworthiness as required by current EU regulations on data protection and AI. However, an off-the-shelf application of PETs is insufficient to ensure a high-quality of data protection, which one needs to understand. This work systematically discusses the risks against data protection in modern Machine Learning systems taking the original perspective of the data owners, who are those who hold the various data sets, data models, or both, throughout the machine learning life cycle and considering the different Machine Learning architectures. It argues that the origin of the threats, the risks against the data, and the level of protection offered by PETs depend on the data processing phase, the role of the parties involved, and the architecture where the machine learning systems are deployed. By offering a framework in which to discuss privacy and confidentiality risks for data owners and by identifying and assessing privacy-preserving countermeasures for machine learning, this work could facilitate the discussion about compliance with EU regulations and directives. We discuss current challenges and research questions that are still unsolved in the field. In this respect, this paper provides researchers and developers working on machine learning with a comprehensive body of knowledge to let them advance in the science of data protection in machine learning field as well as in closely related fields such as Artificial Intelligence. Soumia Zohra El Mestari, Gabriele Lenzini, Hüseyin Demirci |
Comput. Secur. | 2 |
| 2024 | Did the Roll-Out of Community Notes Reduce Engagement With Misinformation on X/Twitter?abstractDeveloping interventions that successfully reduce engagement with misinformation on social media is challenging. One intervention that has recently gained great attention is X/Twitter's Community Notes (previously known as "Birdwatch"). Community Notes is a crowdsourced fact-checking approach that allows users to write textual notes to inform others about potentially misleading posts on X/Twitter. Yet, empirical evidence regarding its effectiveness in reducing engagement with misinformation on social media is missing. In this paper, we perform a large-scale empirical study to analyze whether the introduction of the Community Notes feature and its roll-out to users in the U.S. and around the world have reduced engagement with misinformation on X/Twitter in terms of retweet volume and likes. We employ Difference-in-Differences (DiD) models and Regression Discontinuity Design (RDD) to analyze a comprehensive dataset consisting of all fact-checking notes and corresponding source tweets since the launch of Community Notes in early 2021. Although we observe a significant increase in the volume of fact-checks carried out via Community Notes, particularly for tweets from verified users with many followers, we find no evidence that the introduction of Community Notes significantly reduced engagement with misleading tweets on X/Twitter. Rather, our findings suggest that Community Notes might be too slow to effectively reduce engagement with misinformation in the early (and most viral) stage of diffusion. Our work emphasizes the importance of evaluating fact-checking interventions in the field and offers important implications to enhance crowdsourced fact-checking strategies on social media. Yuwei Chuai, Haoye Tian, Nicolas Pröllochs, Gabriele Lenzini |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2023 | Using Emotions and Topics to Understand Online Misinformation
Yuwei Chuai, Arianna Rossi 0001, Gabriele Lenzini |
ICWE | 3 |
| 2022 | Can We Formally Catch Cheating in E-exams?
Itzel Vázquez Sandoval, Gabriele Lenzini |
ICISSP | 2 |
| 2021 | "I am Definitely Manipulated, Even When I am Aware of it. It's Ridiculous!" - Dark Patterns from the End-User PerspectiveabstractOnline services pervasively employ manipulative designs (i.e., dark patterns) to influence users to purchase goods and subscriptions, spend more time on-site, or mindlessly accept the harvesting of their personal data. To protect users from the lure of such designs, we asked: are users aware of the presence of dark patterns? If so, are they able to resist them? By surveying 406 individuals, we found that they are generally aware of the influence that manipulative designs can exert on their online behaviour. However, being aware does not equip users with the ability to oppose such influence. We further find that respondents, especially younger ones, often recognise the ”darkness” of certain designs, but remain unsure of the actual harm they may suffer. Finally, we discuss a set of interventions (e.g., bright patterns, design frictions, training games, applications to expedite legal enforcement) in the light of our findings. Kerstin Bongard-Blanchy, Arianna Rossi 0001, Salvador Rivas, Sophie Doublet, Vincent Koenig, Gabriele Lenzini |
Conference on Designing Interactive Systems | 6 |
| 2021 | Cholesteric Spherical Reflectors as Physical Unclonable Identifiers in Anti-counterfeitingabstractCholesteric Spherical Reflectors (CSRs) are made of droplets of cholesteric liquid crystals (the same material under the screen of our mobile phones) but molded in a spherical shape and hardened into a solid. CSRs have a peculiar behavior when illuminated: they reflect light and produce unique optical patterns whose full display is hardly predictable. They have been argued to behave like an optical Physical Unclonable Function (PUF), therefore finding application in anti-counterfeiting, in particular for object authentication. However, a fundamental challenge remains open: to understand what makes each optical response unique and how to extract this identifying information reliably and repeatedly. We study the problem, and we design and discuss two pivotal procedures to build authentication protocols for objects coated with CSRs. We test the quality of our procedures against large data sets of pattern images: images from CSRs are used to calculate inter- and intra-distance; simulated patterns created artificially are used to measure security in terms of false positive ratio. Our procedures successfully cluster images coming from the same CSR, distinguishing them from images of different CSRs and decoys. Our work is one of the few that has studied procedures of information extraction for materials derived from CSRs. It advances the state of the art in this area, closing the gap between the research on optical PUFs and practical applications. Mónica P. Arenas, Hüseyin Demirci, Gabriele Lenzini |
ARES | 3 |
| 2021 | What's in a Cyber Threat Intelligence sharing platform?: A mixed-methods user experience investigation of MISPabstractThe ever-increasing scale and complexity of cyber attacks and cyber-criminal activities necessitate secure and effective sharing of cyber threat intelligence (CTI) among a diverse set of stakeholders and communities. CTI sharing platforms are becoming indispensable tools for cooperative and collaborative cybersecurity. Nevertheless, despite the growing research in this area, the emphasis is often placed on the technical aspects, incentives, or implications associated with CTI sharing, as opposed to investigating challenges encountered by users of such platforms. To date, user experience (UX) aspects remain largely unexplored. Borce Stojkovski, Gabriele Lenzini, Vincent Koenig, Salvador Rivas |
ACSAC | 2 |
| 2021 | A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security ResearchabstractUsable privacy and security researchers have developed a variety of approaches to represent risk to research participants. To understand how these approaches are used and when each might be most appropriate, we conducted a systematic literature review of methods used in security and privacy studies with human participants. From a sample of 633 papers published at five top conferences between 2014 and 2018 that included keywords related to both security/privacy and usability, we systematically selected and analyzed 284 full-length papers that included human subjects studies. Our analysis focused on study methods; risk representation; the use of prototypes, scenarios, and educational intervention; the use of deception to simulate risk; and types of participants. We discuss benefits and shortcomings of the methods, and identify key methodological, ethical, and research challenges when representing and assessing security and privacy risk. We also provide guidelines for the reporting of user studies in security and privacy. Verena Distler, Matthias Fassl, Hana Habib, Katharina Krombholz, Gabriele Lenzini, Carine Lallemand, Lorrie Faith Cranor, Vincent Koenig |
ACM Trans. Comput. Hum. Interact. | 5 |
| 2020 | Dual-use Research in Ransomware Attacks: A Discussion on Ransomware Defence Intelligenceabstractpeer reviewed Ziya Alper Genç, Gabriele Lenzini |
ICISSP | 2 |
| 2020 | Systematization of Threats and Requirements for Private Messaging with Untrusted Servers: The Case of e-Mailing and Instant Messagingabstractpeer reviewed Iraklis Symeonidis, Gabriele Lenzini |
ICISSP | 2 |
| 2020 | The DAPRECO Knowledge Base: Representing the GDPR in LegalRuleMLabstractThe DAPRECO knowledge base (D-KB) is a repository of rules written in LegalRuleML, an XML formalism designed to represent the logical content of legal documents. The rules represent the provisions of the General Data Protection Regulation (GDPR). The D-KB builds upon the Privacy Ontology (PrOnto) (Palmirani et al., 2018), which provides a model for the legal concepts involved in the GDPR, by adding a further layer of constraints in the form of if-then rules, referring either to standard first order logic implications or to deontic statements. If-then rules are formalized in reified I/O logic (Robaldo and Sun, 2017) and then codified in (LegalRuleML, 2019). To date, the D-KB is the biggest knowledge base in LegalRuleML freely available online at (Robaldo et al., 2019). Livio Robaldo, Cesare Bartolini, Gabriele Lenzini |
LREC | 3 |
| 2020 | The Framework of Security-Enhancing Friction: How UX Can Help Users Behave More SecurelyabstractA growing body of research in the usable privacy and security community addresses the question of how to best influence user behavior to reduce risk-taking. We propose to address this challenge by integrating the concept of user experience (UX) into empirical usable privacy and security studies that attempt to change risk-taking behavior. UX enables us to study the complex interplay between user-related, system-related and contextual factors and provides insights into the experiential aspects underlying behavior change, including negative experiences. Verena Distler, Gabriele Lenzini, Carine Lallemand, Vincent Koenig |
NSPW | 2 |
| 2020 | Transparency by design in data-informed research: A collection of information design patternsabstractOftentimes information disclosures describing personal data-gathering research activities are so poorly designed that participants fail to be informed and blindly agree to the terms, without grasping the rights they can exercise and the risks derived from their cooperation. To respond to the challenge, this article presents a series of operational strategies for transparent communication in line with legal-ethical requirements. These “transparency-enhancing design patterns” can be implemented by data controllers/researchers to maximize the clarity, navigability, and noticeability of the information provided and ultimately empower data subjects/research subjects to appreciate and determine the permissible use of their data. Arianna Rossi 0001, Gabriele Lenzini |
Comput. Law Secur. Rev. | 2 |
| 2020 | Qualifying and measuring transparency: A medical data system case study
Dayana Spagnuelo, Cesare Bartolini, Gabriele Lenzini |
Comput. Secur. | 3 |
| 2019 | A game of "Cut and Mouse": bypassing antivirus by simulating user inputsabstractTo protect their digital assets from malware attacks, most users and companies rely on anti-virus (AV) software. But AVs' protection is a full-time task and AVs are engaged in a cat-and-mouse game where malware, e.g., through obfuscation and polymorphism, denial of service attacks and malformed packets and parameters, try to circumvent AV defences or make them crash. On the other hand, AVs react by complementing signature-based with anomaly or behavioral detection, and by using OS protection, standard code, and binary protection techniques. Further, malware counter-act, for instance by using adversarial inputs to avoid detection, et cetera. This paper investigates two novel moves for the malware side. The first one consists in simulating mouse events to control AVs, namely to send them mouse "clicks" to deactivate their protection. We prove that many AVs can be disabled in this way, and we call this class of attacks Ghost Control. The second one consists in controlling high-integrity white-listed applications, such as Notepad, by sending them keyboard events (such as "copy-and-paste") to perform malicious operations on behalf of the malware. We prove that the anti-ransomware protection feature of some AVs can be bypassed if we use Notepad as a "puppet" to rewrite the content of protected files as a ransomware would do. Playing with the words, and recalling the cat-and-mouse game, we call this class of attacks Cut-and-Mouse. Ziya Alper Genç, Gabriele Lenzini, Daniele Sgandurra |
ACSAC | 2 |
| 2019 | On Deception-Based Protection Against Cryptographic Ransomware
Ziya Alper Genç, Gabriele Lenzini, Daniele Sgandurra |
DIMVA | 2 |
| 2019 | Accomplishing Transparency within the General Data Protection RegulationabstractTransparency is a user-centric principle proposed to empower users to hold data processors accountable for the usage and the processing of the user’s personal data. Accomplishing transparency may come with some resistance because it requires significant architectural changes, but it is mandatory by law under the recently approved General Data Protection Regulation. To help the transition, we systematically review what Transparency Enhancing Technologies can help to accomplish transparency in agreement with technical requirements that we elicited from the Regulation’s articles. We discuss our findings in the domain of medical data systems, where accomplishing transparency looks particularly controversial due to sensitivity of the personal medical data. Dayana Spagnuelo, Ana Ferreira 0001, Gabriele Lenzini |
ICISSP | 3 |
| 2019 | Towards a Lawful Authorized Access: A Preliminary GDPR-based Authorized AccessabstractThe General Data Protection Regulation (GDPR)'s sixth principle, Integrity and Confidentiality, dictates that personal data must be protected from unauthorised or unlawful processing. To this aim, we propose a systematic approach for authoring access control policies that are by-design aligned with the provisions of the GDPR. We exemplify it by considering realistic use cases. Cesare Bartolini, Said Daoudagh, Gabriele Lenzini, Eda Marchetti |
ICSOFT | 3 |
| 2018 | Experience Report: How to Extract Security Protocols' Specifications from C LibrariesabstractOften, analysts have to face a challenging situation when formally verifying the implementation of a security protocol: they need to build a model of the protocol from only poorly or not documented code, and with little or no help from the developers to better understand it. Security protocols implementations frequently use services provided by libraries coded in the C programming language; automatic tools for codelevel reverse engineering offer good support to comprehend the behavior of code in object-oriented languages but are ineffective to deal with libraries in C. Here we propose a systematic, yet human-dependent approach, which combines the capabilities of state-of-the-art tools in order to help the analyst to retrieve, step by step, the security protocol specifications from a library in C. Those specifications can then be used to create the formal model needed to carry out the analysis. Itzel Vázquez Sandoval, Gabriele Lenzini |
COMPSAC (2) | 2 |
| 2018 | No Random, No Ransom: A Key to Stop Cryptographic Ransomware
Ziya Alper Genç, Gabriele Lenzini, Peter Y. A. Ryan |
DIMVA | 2 |
| 2018 | A Security Analysis, and a Fix, of a Code-Corrupted Honeywords Systemabstractpeer reviewed Ziya Alper Genç, Gabriele Lenzini, Peter Y. A. Ryan, Itzel Vázquez Sandoval |
ICISSP | 2 |
| 2018 | Invalid certificates in modern browsers: A socio-technical analysisabstractThe authentication of a web server is a crucial procedure in the security of web browsing. It relies on certificate validation, a process that may require the participation of the user. Thus, the security of certificate validation is socio-technical as it depends on traditional security technology as well as on social elements such as cultural values, trust and human-computer interaction. This manuscript analyzes extensively the socio-technical security of certificate validation as carried out through today’s most popular browsers. First, we model processes, protocols and ceremonies that browsers run with servers and users as UML activity diagrams. We consider both classic and private browsing modes and focus on the certificate validation. We then translate each UML activity diagram to a CSP# model. The model is expanded with the LTL formalization of five socio-technical properties pivoted on user involvement with certificate validation. We automatically check whether the CSP# models are socio-technically secure against Man-in-the-Middle attacks using the PAT model checker. The findings turn out to be far from straightforward. From them, we state best-practice recommendations to browser vendors. Rosario Giustolisi, Giampaolo Bella, Gabriele Lenzini |
J. Comput. Secur. | 3 |
| 2017 | From Situation Awareness to Action: An Information Security Management Toolkit for Socio-technical Security Retrospective and Prospective Analysisabstractpeer reviewed Jean-Louis Huynen, Gabriele Lenzini |
ICISSP | 2 |
| 2017 | Privacy-Preserving Verifiability - A Case for an Electronic Exam ProtocolabstractWe introduce the notion of privacy-preserving verifiability for security protocols. It holds when a protocol admits a verifiability test that does not reveal, to the verifier that runs it, more pieces of information about the protocol’s execution than those required to run the test. Our definition of privacy-preserving verifiability is general and applies to cryptographic protocols as well as to human security protocols. In this paper we exemplify it in the domain of e-exams. We prove that the notion is meaningful by studying an existing exam protocol that is verifiable but whose verifiability tests are not privacy-preserving. We prove that the notion is applicable: we review the protocol using functional encryption so that it admits a verifiability test that preserves privacy according to our definition. We analyse, in ProVerif, that the verifiability holds despite malicious parties and that the new protocol maintains all the security properties of the original protocol, so proving that our privacy-preserving verifiability can be achieved starting from existing security Rosario Giustolisi, Vincenzo Iovino, Gabriele Lenzini |
SECRYPT | 3 |
| 2017 | Modelling Metrics for Transparency in Medical Systems
Dayana Spagnuelo, Cesare Bartolini, Gabriele Lenzini |
TrustBus | 3 |
| 2017 | Trustworthy exams without trusted parties
Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini, Peter Y. A. Ryan |
Comput. Secur. | 3 |
| 2016 | Comparing and Integrating Break-the-Glass and Delegation in Role-based Access Control for Healthcareabstractpeer reviewed Ana Ferreira 0001, Gabriele Lenzini |
ICISSP | 2 |
| 2016 | Patient-Centred Transparency Requirements for Medical Data Sharing Systems
Dayana Spagnuelo, Gabriele Lenzini |
WorldCIST (1) | 2 |
| 2015 | A Framework for Analyzing Verifiability in Traditional and Electronic Exams
Jannik Dreier, Rosario Giustolisi, Ali Kassem 0001, Pascal Lafourcade 0001, Gabriele Lenzini |
ISPEC | 5 |
| 2015 | Maybe Poor Johnny Really Cannot Encrypt: The Case for a Complexity Theory for Usable SecurityabstractPsychology and neuroscience literature shows the existance of upper bounds on the human capacity for executing cognitive tasks and for information processing. These bounds are where, demonstrably, people start experiencing cognitive strain and consequently committing errors in the tasks execution. We argue that the usable security discipline should scientifically understand such bounds in order to have realistic expectations about what people can or cannot attain when coping with security tasks. This may shed light on whether Johnny will be ever be able to encrypt. We propose a conceptual framework for evaluation of human capacities in security that also assigns systems to complexity categories according to their security and usability. From what we have initiated in this paper, we ultimately aim at providing designers of security mechanisms and policies with the ability to say: "This feature of the security mechanism X or this security policy element Y is inappropriate, because this evidence shows that it is beyond the capacity of its target community". Zinaida Benenson, Gabriele Lenzini, Daniela Oliveira 0001, Simon Edward Parkin, Sven Übelacker |
NSPW | 2 |
| 2015 | A Secure Exam Protocol Without Trusted Parties
Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini, Peter Y. A. Ryan |
SEC | 3 |
| 2015 | Can Transparency Enhancing Tools Support Patient's Accessing Electronic Health Records?
Ana Ferreira 0001, Gabriele Lenzini |
WorldCIST (1) | 2 |
| 2015 | Service security and privacy as a socio-technical problemabstractThe security and privacy of the data that users transmit, more or less deliberately, to modern services is an open problem. It is not solely limited to the actual Internet traversal, a sub-problem vastly tackled by consolidated research in security protocol design and analysis. By contrast, it enta ils much broader dimensions pertaining to how users approach technology and understand the risks for the data they enter. For example, users may express cautious or distracted personas depending on the service and the point in time; further, pre-established paths of practice may lead them to neglect the intrusive privacy policy offered by a service, or the outdated protections adopted by another. The approach that sees the service security and privacy problem as a socio-technical one needs consolidation. With this motivation, the article makes a threefold contribution. It reviews the existing literature on service security and privacy, especially from the socio-technical standpoint. Further, it outlines a general research methodology aimed at layering the problem appropriately, at suggesting how to position existing findings, and ultimately at indicating where a transdisciplinary task force may fit in. The article concludes with the description of the three challenge domains of services whose security and privacy we deem open socio-technical problems, not only due to their inherent facets but also to their huge number of users. Giampaolo Bella, Paul Curzon, Gabriele Lenzini |
J. Comput. Secur. | 3 |
| 2014 | Secure exams despite malicious managementabstractAn exam is a practise for assessing the knowledge of a candidate from an examination she takes. Exams are used in various contexts, such as in university tests and public competitions. We begin by identifying various security and privacy requirements that modern exams should meet, especially in the prospect of them being supported by information and communication technologies. These requirements extend well beyond ensuring authenticating the candidate and preventing her from cheating. Cheating is routinely enforced by invigilation by trusted parties, whereas we discuss that an exam should meet its security and privacy requirements against stronger threat models, including malicious exam authorities. Thus exams must be designed with the care normally devoted to security protocols, and in such a mindset we present WATA IV, a new protocol that meets our security and privacy requirements even when an exam manager is malicious. Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini |
PST | 3 |
| 2014 | Formal Analysis of Electronic ExamsabstractInternational audience Jannik Dreier, Rosario Giustolisi, Ali Kassem 0001, Pascal Lafourcade 0001, Gabriele Lenzini, Peter Y. A. Ryan |
SECRYPT | 5 |
| 2013 | Demonstrating a trust framework for evaluating GNSS signal integrityabstractThrough real-life experiments, it has been proved that spoofing is a practical threat to applications using the free civil service provided by Global Navigation Satellite Systems (GNSS). In this paper, we demonstrate a prototype that can verify the integrity of GNSS civil signals. By integrity we intuitively mean that civil signals originate from a GNSS satellite without having been artificially interfered with. Our prototype provides interfaces that can incorporate existing spoofing detection methods whose results are then combined into an overall evaluation of the signal's integrity, which we call integrity level. Considering the various security requirements from different applications, integrity levels can be calculated in many ways determined by their users. We also present an application scenario that deploys our prototype and offers a public central service -- localisation assurance certification. Through experiments, we successfully show that our prototype is not only effective but also efficient in practice. Xihui Chen, Carlo Harpes, Gabriele Lenzini, Miguel Martins, Sjouke Mauw, Jun Pang 0001 |
CCS | 3 |
| 2013 | What security for electronic exams?abstractElectronic exam systems are pieces of software employed in online educations to assess performances of students. However, both the security of the protocols they reply upon and a general understanding of the possible threats is still to be met. This manuscript outlines a Ph.D. research work wherein we attempt to shed some light in the area. We identify the phases composing a typical exam system, we comments on relevant security properties that should be preserved in the various phases, and we advances an informal though structured definitions of them. Rosario Giustolisi, Gabriele Lenzini, Giampaolo Bella |
CRiSIS | 2 |
| 2013 | A Trust Framework for Evaluating GNSS Signal IntegrityabstractThrough real-life experiments, it has been proved, not only in theory but also in practice, that civil signals of Global Navigation Satellite Systems (GNSS) can be spoofed. Consequently, a number of spoofing detection techniques have been proposed to verify the integrity of GNSS signals. In this paper, we develop a novel trust framework based on subjective logic to evaluate the integrity of received GNSS civil signals. We formally define signal integrity for the first time in the framework and use it to precisely characterise different spoofing detection methods. Our framework captures the uncertainty during the inference of signal integrity which has been largely ignored or not explicitly specified in the literature. Our framework also gives rise to several natural ways to combine the outputs of various spoofing detection methods on signal integrity. We validate our framework through experiments using both real and simulated signals and the results show that our framework is effective. Xihui Chen, Gabriele Lenzini, Miguel Martins, Sjouke Mauw, Jun Pang 0001 |
CSF | 2 |
| 2013 | Socio-technical formal analysis of TLS certificate validation in modern browsersabstractAuthenticating a web server is crucial to the security of web browsing. It relies on TLS certificate validation, a property whose enforcement may require getting the user involved. Thus, certificate validation is a socio-technical property - it relies on traditional security technology as well as on social elements such as cultural values, trust and human-computer interaction. Hence the need for an appropriate methodology to study certificate validation from a socio-technical perspective. Certificate validation as carried out through today's most popular browsers - Chrome, Internet Explorer, Firefox and Opera Mini - is first represented by means of UML activity diagrams. It is then translated into CSP#, and expanded with the LTL formalization of four socio-technical properties pivoted on user involvement with certificate validation. The properties are then checked automatically using the PAT model checker. The findings turn out to be far from straightforward and, most importantly, allowed for prototyping a basic methodology for the sociotechnical formal analysis of security properties. Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini |
PST | 3 |
| 2012 | A Group Signature Based Electronic Toll Pricing SystemabstractWith the prevalence of GNSS technologies, nowadays freely available for everyone, location-based vehicle services such as electronic tolling pricing systems and pay-as-you-drive services are rapidly growing. Because these systems collect and process travel records, if not carefully designed, they can threaten users' location privacy. Finding a secure and privacy-friendlysolution is a challenge for system designers. Besides location privacy, communication and computation overhead should be taken into account as well in order to make such systems widely adopted in practice. In this paper, we propose a new electronic toll pricing system based on group signatures. Our system preserves anonymity of users within groups, in addition to correctness and accountability. It also achieves a balance between privacy and overhead imposed upon user devices. Xihui Chen, Gabriele Lenzini, Sjouke Mauw, Jun Pang 0001 |
ARES | 2 |
| 2012 | Defending against insider threats and internal data leakageabstractIn the last decade, computer science researchers have beenworking hard to prevent attacks against the security ofinformation systems. Different adversary models haveincarnated the malicious entities against which researchershave defined security properties, identified securityvulnerabilities, and engineered security defenses. Theseadversaries were usually intruders, that is, outsiders tryingto break into a system’s defenses. Ilsun You, Gabriele Lenzini, Marek R. Ogiela, Elisa Bertino |
Secur. Commun. Networks | 2 |
| 2010 | Contextual Biometric-Based Authentication for Ubiquitous Services
Ileana Buhan, Gabriele Lenzini, Sasa Radomirovic |
UIC | 2 |
| 2008 | Trust Model for High Quality Recommendation
Gabriele Lenzini, Nabil Sahli, Henk Eertink |
SECRYPT | 1 |
| 2005 | Relating multiset rewriting and process algebras for security protocol analysisabstractWhen formalizing security protocols, different specification languages support very different reasoning methodologies, whose results are not directly or easily comparable. Therefore, establishing clear mappings among different frameworks is highly de Stefano Bistarelli, Iliano Cervesato, Gabriele Lenzini, Fabio Martinelli |
J. Comput. Secur. | 3 |
| 2000 | An Automatic SPIN Validation of a Safety Critical Railway Control SystemabstractThis paper describes an experiment informal specification and validation performed in the context of an industrial joint project. The project involved an Italian company working in the field of railway engineering, Ansaldobreda Segnalamento Ferroviario, and the CNR Institutes IEI and CNUCE of Pisa, Within the project two formal models have been developed describing different aspects of a safety-critical system used in the management of medium-large railway networks. Validation of safety and liveness properties has been performed on both models. Safety properties have been checked primarily in presence of Byzantine faults as well as of silent faults embedded in the models themselves. Liveness properties have been more focused on a communication protocol used within the system. Properties have been specified by means of assertions or temporal logical formulae. We used PROMELA as specification language, while the verification was performed using the verification tool suite SPIN. Stefania Gnesi, Diego Latella, Gabriele Lenzini, C. Abbaneo, Arturo M. Amendola, P. Marmo |
DSN | 3 |
| 2000 | A Formal Specification and Validation of a Critical System in Presence of Byzantine Errors
Stefania Gnesi, Diego Latella, Gabriele Lenzini, C. Abbaneo, Arturo M. Amendola, P. Marmo |
TACAS | 3 |