Christian Esposito 0001

dblp:89/6036 · also Christian Carmine Esposito, Christiancarmine Esposito · DBLP profile ↗
← Back
70ranked-venue papers
29as first author
29since 2021 · last 2026
0000-0002-0085-0748ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 16 · 7 first-author · 2 since 2021Computer networks · 9 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 6 · 5 first-author · 2 since 2021Security and privacy · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Evaluating Effective Quantum PUF Circuits for Authentication Applications
abstract
As quantum technologies advance, ensuring secure authentication of quantum devices has become increasingly important. Existing methods, often relying on stored cryptographic keys, are vulnerable to physical and side-channel attacks. Quantum Physical Unclonable Functions (QPUFs) offer a promising alternative by leveraging quantum phenomena such as superposition, entanglement, and quantum noise to produce unique, unclonable responses. However, many existing QPUF designs are based on simulations or report only idealized, best-case results. This work presents and evaluates a set of QPUF circuits on IBM’s real quantum hardware, assessing their performance in terms of instability, randomness, and uniqueness to identify the most effective configurations. Our results show that specific configurations can achieve a positive balance between stability and device distinguishability, reaching 0.05 instability, 0.48 uniqueness, and 0.75 randomness. These findings provide a solid foundation for implementing robust authentication protocols tailored for quantum devices in real-world settings.
Franco Cirillo, Christian Esposito 0001
CCNC2
2026 Cross-MAC IDS for Denial-of-Sleep Detection in Wireless Sensor Networks
Davide Amoruso, Biagio Boi, Christian Esposito 0001
ISORC3
2025 Anomaly-Based Intrusion Detection System Using ESP32-WROOM-DA
Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito 0001
AINA (2)4
2025 Intrusion Detection System Based on Quantum Generative Adversarial Network
Franco Cirillo, Christian Esposito 0001
ICAART (1)2
2025 User-Centric and Privacy-Preserving Attribute-Based Authentication in Healthcare Systems Leveraging zk-SNARKs and Soulbound Tokens
abstract
Digital health services for disease diagnosis, followup, and patient empowerment manage data that belongs to a special class of personal information, according to the General Data Protection Regulation (GDPR). For this reason, user authentication and access control are among the key security measures suggested for their protection. However, in the medical context, it is crucial to balance security and privacy support with timeliness and ease of access, which requires innovative solutions. This manuscript introduces an innovative approach leveraging Soulbound Tokens (SBTs) and Zero-Knowledge Proofs (ZKPs), particularly zk-SNARKs, to provide a privacy-aware mechanism for patient authentication in the medical domain. SBTs are utilized within an Attribute-Based Access Control (ABAC) model, ensuring that only eligible patients can access specific medical treatments. In a treatment-specific model, an SBT is issued for each diagnosis, allowing precise control but increasing management complexity. Alternatively, in a diagnosis-categorybased model, SBTs are grouped by diagnostic categories. This reduces the number of tokens and optimizes the space in the patient's wallet but sacrifices some precision in the information. Results demonstrate the timeliness of the proposed approach, with an average time of 6.82s for the release of an SBT and a maximum on-chain verification time of 15.04ms, showcasing their future adoption in a real-time environment, such as the medical context.
Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito 0001
ISORC4
2025 Engineering SRAM-PUF on Arduino microcontroller
abstract
The emergence of the Internet of Things (IoT) enables both people and devices to access services, data, and actuator control from remote locations, even spanning thousands of miles. Ensuring authentication, communication integrity, and confidentiality for IoT devices is essential for systems security and still an open challenge too. In this context, Physical Unclonable Functions (PUFs) have gained significant attention due to their ability to generate stable, tamper-resistant, and random fingerprints that can be successfully exploited to provide cryptography keys or to implement authentication schemes. However, PUFs necessitate dedicated hardware, making them costly and available only in specific designs, thereby impeding their broader adoption. In this paper, we enable the usage of static random access memory (SRAM)-based PUF on Arduino UNO device, an open-source board implemented upon an ATMega328P, without requiring special hardware. We analyze SRAM PUF quality parameters and how to reconstruct a reliable cryptography key by engineering a fuzzy extractor. Additionally, we design a secure bootloader as root-of-trust and, as a case study, we detail how to authenticate Arduino Sketches and how to implement an authentication scheme.
Mario Barbareschi, Franco Cirillo, Christian Esposito 0001, Nicola Mazzocca
J. Syst. Archit.3
2024 User Experience and Security in Digital Health Applications: Results from a Rapid Review
abstract
In recent years, a growing interest has been in the adoption of medical web or mobile applications or more in general applications in the digital health (DHEAL) field. These applications are designed for a wide range of users, from novice to expert and also end-users with and without disabilities, without adequately considering their unique software security needs. In this short paper, we present the results of a Rapid Review (RR) to identify existing approaches and methods to assess User Experience (UX), usability, accessibility and/or security in DHEAL applications. This RR has been conducted in the context of a research project (“DHEAL-COM Digital Health Solutions in Community Medicine). Among the others, the objective of DHEAL-COM is to delve into the complex relationship between UX (and its variants, like usability and accessibility) and security, i.e., to understand to what extent the principle of acceptability in security is taken into account when developing DHEAL applications. The outcomes of our RR should provide evidence to the stakeholders involved in the DHEAL-COM project and to researchers and practitioners who work in the DHEAL context. The findings of our RR emerge from 39 papers and can be summarized as follows: (i) there are several methods to assess usability; (ii) the most common methods are focused only on common usability aspects and in a few cases these methods concerns accessibility and credibility of the content; (iii) there are several methods to assess security and most of them are dictated by legislative rules; (iv) although the difficulty in finding a compromise between usability and security is clear in many cases, there are neither solutions nor approaches to deal with both of them.
Pietro Cassieri, Franco Cirillo, Christian Esposito 0001, Giuseppe Scanniello
SEAA3
2024 SRAM-PUF Authentication Schemes Empowered with Blockchain on Resource-Constrained Microcontrollers
abstract
The pervasive presence of Internet of Things (IoT) devices across diverse critical industrial contexts underscores the crucial role of authentication mechanisms to protect applications from misuses and violations. Those authentication schemes not relying on passwords are built by using cryptography protocols so as to achieve high security levels. However, their efficacy relies on the confidentiality of cryptographic keys and has limitations when implemented on resource-constrained devices. This paper introduces a novel approach to devise an authentication scheme without relying on the storage of keys in device memory and without the presence of a centralised entity. We develop a lightweight mutual authentication scheme utilizing Static Random Access Memory (SRAM)-Physical Unclonable Function (PUF), which leverage on the inherent randomness of SRAM obtained during its manufacturing process to create keys. The proposed solution is further fortified by blockchain technology that is used to provide a decentralised management authority. By incorporating decentralization, scalability, freshness, and non-repudiation, this research contributes to the advancement of secure authentication protocols for IoT-enabled critical industrial applications.
Mario Barbareschi, Franco Cirillo, Christian Esposito 0001
ISORC3
2024 Decentralized Identity Management and Privacy-Enhanced Federated Learning for Automotive Systems: A Novel Framework
abstract
Federated Learning (FL) has revolutionized collaborative machine learning by decentralizing data processing, enhancing the efficiency of traditional Machine Learning (ML) approaches, and mitigating privacy concerns associated with data exchange. Despite these advantages, security challenges persist, particularly in securely transmitting model updates within vehicular networks and authenticating nodes participating in the protocol. This paper presents an innovative framework that addresses authentication and mobility challenges in automotive systems through the integration of Decentralized Identity Management (IdM) and FL. Highlighting the need for robust authentication in automotive systems, the research concurrently explores avenues to optimize FL performance within this specific context. Through the incorporation of a decentralized authentication mechanism and the establishment of synchronization means, our proposed framework ensures security and synchronization in the transmission of model weights. This comprehensive solution paves the way for notable advancements in collaborative ML in highly dense and distributed contexts, such as the vehicular networks.
Biagio Boi, Marco De Santis, Christian Esposito 0001
ISORC3
2024 Enhancing Security in User-Centered Authentication Using KERI
abstract
In the context of the widespread adoption of user-centric authentication methods, safeguarding the confidentiality of private keys during the exchange of credentials has become a critical concern. Key Event Receipt Infrastructure (KERI), distinguished by its distinctive design focusing on key events and receipts, aligns seamlessly with the ethos of user-centric authentication, eschewing the necessity for blockchain integration. This research leverages the architectural model of KERI to discern potential implications within the contemporary landscape of Self-Sovereign Identity (SSI) ecosystems, thereby contributing to the evolution of identity management practices. The need for this research arises from the recognition that while SSI obviates the need for central authorities, thereby augmenting privacy and security, the imperative to preserve and securely store private keys persists. Our primary findings confirm that the integration of KERI within the SSI ecosystem provides a more resilient protocol for authentication by preventing the exchange of any kind of key used for the generation of the proof. This approach aims to prevent attacks in line with the principles of decentralization and trustlessness inherent in blockchain technologies. This research contributes to the expanding body of literature devoted to security and access management within the dynamic realm of user-centric applications and authentication.
Biagio Boi, Marco De Santis, Christian Esposito 0001
PDP3
2024 Editorial: Artificial intelligence in biomedical big data and digital healthcare
Kiho Lim, Christian Esposito 0001, Tian Wang 0001, Chang Choi
Future Gener. Comput. Syst.2
2024 The convergence of Digital Twins and Distributed Ledger Technologies: A systematic literature review and an architectural proposal
abstract
In recent years, the emerging Digital Twin (DT) technology is playing a key role in fostering the transition towards the Industry 4.0. DTs, representing virtual replicas of physical objects, products or processes established thanks to a bidirectional continuous flow of information between the physical and the virtual world, are currently adopted in multiple domains such as manufacturing, aerospace, automotive, energy, construction, smart cities and smart mobility, etc.. DTs live together with the physical system they replicate, receiving the same data and often triggering specific control actions that directly impact on the real system status. When dealing with DTs of complex Cyber-Physical Systems (CPSs), the data sources may be heterogeneous and untrustworthy, which requires the DT to be able to address security issues related to data in transit from/to the physical twin and data at rest. A possible way to address these data security issues consists in adopting Distributed Ledger Technologies (DLTs) which provide several security guarantees on data through cryptographic hashing techniques. In this work, we present a three-fold contribution: (i) we discuss the results of a Systematic Literature Review (SLR) on the state-of-the-art of the research related to the integration between DLT and Digital Twins, aimed at clarifying relevant aspects such as, among others, what is the favourite DLT choice in existing proposals or what is the type of DT-related information to store on-chain; (ii) leveraging the SLR results and other related research, we propose an architectural framework for the integration of DT and DLTs (more specifically, blockchains); (iii) we validate the proposed architecture by means of two proof-of-concept implementations leveraging different technological stacks and taking into account two different operational scenarios. Finally, we conduct a requirements coverage analysis and compare the PoCs through a coverage matrix.
Alessandra Somma, Alessandra De Benedictis, Christian Esposito 0001, Nicola Mazzocca
J. Netw. Comput. Appl.3
2023 Decentralized Authentication in Microservice Architectures with SSI and DID in Blockchain
abstract
Microservice architectures aim at high modularity, reuse, and efficiency of code by structuring applications as a collection of services that are independently deployable, loosely coupled, and organized around business capabilities. As they are starting to be used in sensitive applications, security has started to be a priority, where authentication is one of the first protection means to be offered to developers by those products supporting microservice development. However, the available authentication solutions in these products are highly centralized, leveraging JSON Web Token (JWT) or related standards. This poses a serious issue in meeting the recent privacy legal obligations. In this paper, we propose a solution for integrating a decentralized blockchain-based authentication solution within the context of Istio, which is a service mesh supporting microservice developments. The usage of a Smart Contract, in combination with Decentralized Identifiers (DIDs) and JWT, paves the way for a concrete and fully decentralized revocation system without adding overhead or modification to existing microservices.
Biagio Boi, Christian Esposito 0001
CloudCom2
2023 Self-Sovereign Identity (SSI) Attribute-Based Web Authentication
Biagio Boi, Marco De Santis, Christian Esposito 0001
SECRYPT3
2023 Detecting malicious reviews and users affecting social reviewing systems: A survey
Christian Esposito 0001, Vincenzo Moscato, Giancarlo Sperlì
Comput. Secur.1
2022 Help From Above: UAV-Empowered Network Resiliency in Post-Disaster Scenarios
abstract
Natural and man-made disasters have often consequences on service availability in a wireless access network, provoking a progressively degraded performance or even the lack of connectivity. However, given the growing importance of situation awareness, telehealth, and advanced rescue teams coordination services for the affected population, it is key to restore these services in a timely fashion, while guaranteeing the required QoS levels. To this end, UAV-mounted base stations have been recently proposed as a key instrument to achieve this goal. Nonetheless, this gives rise to the key issue of how to deploy them in a resource efficient manner, in a post-disaster context typically characterized by lack of infrastructure support and of power supply. In this work, we tackle the issue of how to jointly optimize drones deployment and user association in a QOS aware manner to efficiently cater for coverage holes and QoS degradation in a cellular network after a disaster. We formulate a network optimization problem, and we provide a two-step genetic algorithm which iteratively tunes UAV position, base station transmit power and user association in order to minimize the number of employed drones. Initial results on a realistic measurement based scenario show that our approach is able to effectively minimize the number of deployed drones while achieving a target minimum QoS.
Christian Esposito 0001, Gianluca Rizzo
CCNC1
2022 On Attacks To Federated Learning and a Blockchain-empowered Protection
abstract
Federated learning has been increasingly studied to cope with the scalability and privacy issues characterizing current and upcoming large-scale infrastructures, such as the Internet of Things, 5G networks, vehicular applications, and so on. This approach partitions the data storage and AI model training in a series of local learners, whose results are aggregated by a central server and then redistributed back to the learners to have a trained global model. However, despite avoiding outsourcing sensitive data to cloud-hosted services and fragmenting the workload for data processing, such a decentralized learning approach lays the overall solution open to various kinds of attacks, able to fully compromise the accuracy of the obtained global model. This study aims to quantitatively assess the impact of two widely-recognized attacks against federated learning and propose a tentative protection means by using blockchain.
Christian Esposito 0001, Giancarlo Sperlì, Vincenzo Moscato, Zhongliang Zhao
CCNC1
2022 Energy-Optimal RAN Configurations for SWIPT IoT
abstract
Internet of Things (IoT) devices often have batteries of limited capacity, which are not easily replaced or recharged. This implies very short device lifetimes, and calls for a very careful device configuration to achieve the optimal trade-off between performance and power consumption. SWIPT (Simultaneous Wireless Information and Power Transfer) deals with this problem by harvesting energy at IoT devices from the received RF signals. Studying the efficiency of SWIPT in dealing with the energy and data transfer demands of IoT nodes leads to a number of open issues. In this paper, we devise an analytical model based on stochastic geometry for a SWIPT radio access network with a dense population of IoT users. With our model, it is possible to accurately study the impact of the system parameters on the key system performance indicators, while accounting in a realistic manner for device performance, and for the statistics of time scheduling at base stations. This allows us to understand (not without some surprise) what are the most effective strategies to minimize energy consumption in a SWIPT network, and what is their potential for energy savings.
Gianluca Rizzo, Marco Ajmone Marsan, Christian Esposito 0001
WiOpt3
2022 Smart Unmanned Aerial Vehicles as base stations placement to improve the mobile network operations
Zhongliang Zhao, Pedro Cumino, Christian Esposito 0001, Meng Xiao 0002, Denis do Rosário, Torsten Braun, Eduardo Cerqueira, Susana Sargento
Comput. Commun.3
2022 Graph-powered learning for social networks
Zhipeng Cai 0001, Christian Esposito 0001, Tooska Dargahi, Chaokun Wang
Neurocomputing2
2022 Introduction to Special Issue on Misinformation, Fake News and Rumor Detection in Low-Resource Languages
abstract
introduction Share on Introduction to Special Issue on Misinformation, Fake News and Rumor Detection in Low-Resource Languages Authors: Akshi Kumar View Profile , Christian Esposito View Profile , Dimitrios A. Karras View Profile Authors Info & Claims ACM Transactions on Asian and Low-Resource Language Information ProcessingVolume 21Issue 1January 2022 Article No.: 1epp 1–3https://doi.org/10.1145/3505588Online:24 December 2021Publication History 0citation247DownloadsMetricsTotal Citations0Total Downloads247Last 12 Months247Last 6 weeks39 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Akshi Kumar 0001, Christian Esposito 0001, Dimitris A. Karras
ACM Trans. Asian Low Resour. Lang. Inf. Process.2
2022 Adaptive Optimization Method in Digital Twin Conveyor Systems via Range-Inspection Control
abstract
The automated conveyor system, as the core component in the modern manufacturing world, has gained lots of attention from researchers. To optimize the operation of the conveyor system, range-inspection control (RIC) has been considered an efficient strategy to bring this conventional technology to an intelligent level. Various algorithms have been put into use to achieve optimal control. However, the current methodologies are only focusing on control optimization, not scaled into the smart manufacturing framework. The schema of alignment and corporation between the physical and virtual spaces for the system remains an important problem. Therefore, the work in this article aims for an effective framework of implementation between the physical and virtual stations in an automated conveyor system. Since increasingly more application scenarios rely on the digital twin (DT) technology to realize the integration of physical and virtual systems, we proposed the DT automated conveyor system (DT-ACS) that constructs the road map to implement the RIC-based conveyor system under the background of a smart factory. Besides, profit-sharing-based deep Q-networks (PDQNs) have been proposed to cope with the RIC optimization problem. The robustness and efficiency of the proposed PDQN were evaluated via sets of experiments. The discussion and conclusion are presented at last accordingly.Note to Practitioners—This article aims to propose a strategy of control optimization for conveyor-based manufacturing systems under the digital twin (DT) framework. The conveyor system can be flexible to control the running flows to avoid overloading workstations. Due to the complex environment in the production line, the range that is able to be inspected and the capacity of the reserve area can be considerably diverse among the workstations. To maximally evaluate our framework, we set a comparatively complex environment for the experiments. Nevertheless, to obtain practically ideal performance under other circumstances, the parameters should be precisely tested and fine-tuned with simulation in advance.
Tian Wang 0002, Jiaxiang Cheng, Yi Yang 0043, Christian Esposito 0001, Hichem Snoussi, Fei Tao 0001
IEEE Trans Autom. Sci. Eng.4
2022 Trustworthiness Evaluation-Based Routing Protocol for Incompletely Predictable Vehicular Ad Hoc Networks
abstract
Incompletely predictable vehicular ad hoc networks is a type of networks where vehicles move in a certain range or just in a particular tendency, which is very similar to some circumstances in reality. However, how to route in such type of networks more efficiently according to the node motion characteristics and related historical big data is still an open issue. In this paper, we propose a novel routing protocol named trustworthiness evaluation-based routing protocol (TERP). In our protocol, trustworthiness of each individual is calculated by the cloud depending on the attribute parameters uploaded by the corresponding vehicle. In addition, according to the trustworthiness provided by the cloud, vehicles in the network choose reliable forward nodes and complete the entire route. The analysis shows that our protocol can effectively improve the fairness of the trustworthiness judgement. In the simulation, our protocol has a good performance in terms of the packet delivery ratio, normalized routing overhead and average end-to-end delay.
Jian Shen 0001, Chen Wang 0015, Aniello Castiglione, Dengzhi Liu, Christian Esposito 0001
IEEE Trans. Big Data5
2022 Trustworthiness Assessment of Users in Social Reviewing Systems
abstract
Social Networks represent a cornerstone of our daily life, where the so-called social reviewing systems (SRSs) play a key role in our daily lives and are used to access data typically in the form of reviews. Due to their importance, social networks must be trustworthy and secure, so that their shared information can be used by the people without any concerns, and must be protected against possible attacks and misuses. One of the most critical attacks against the reputation system is represented by mendacious reviews. As this kind of attacks can be conducted by legitimate users of the network, a particularly powerful solution is to exploit trust management, by assigning a trust degree to users, so that people can weigh the gathered data based on such trust degrees. Trust management within the context of SRSs is particularly challenging, as determining incorrect behaviors is subjective and hard to be fully automatized. Several attempts in the current literature have been proposed; however, such an issue is still far from been completely resolved. In this study, we propose a solution against mendacious reviews that combines fuzzy logic and the theory of evidence by modeling trust management as a multicriteria multiexpert decision making and exploiting the novel concept of time-dependent and content-dependent crown consensus. We empirically proved that our approach outperforms the main related works approaches, also in dealing with sockpuppet attacks.
Christian Esposito 0001, Vincenzo Moscato, Giancarlo Sperlì
IEEE Trans. Syst. Man Cybern. Syst.1
2021 Data Mining for Animal Health to Improve Human Quality of Life: Insights from a University Veterinary Hospital
Oscar Tamburis, Elio Masciari, Christian Esposito 0001, Gerardo Fatone
DATA3
2021 An intelligent system for focused crawling from Big Data sources
Ida Bifulco, Stefano Cirillo, Christian Esposito 0001, Roberta Guadagni, Giuseppe Polese
Expert Syst. Appl.3
2021 Blockchain-based authentication and authorization for smart city applications
Christian Esposito 0001, Massimo Ficco, Brij B. Gupta
Inf. Process. Manag.1
2021 Evolutionary game theoretical on-line event detection over tweet streams
Rocco Di Girolamo, Christian Esposito 0001, Vincenzo Moscato, Giancarlo Sperlì
Knowl. Based Syst.2
2021 NeuCheck: A more practical Ethereum smart contract security analysis tool
abstract
Summary Ethereum is one of the currently popular trading platform, where any one can exchange, buy, or sell cryptocurrencies. Smart contract, a computer program, can help Ethereum to encode rules or scripts for processing transactions. Because the smart contract usually handles large number of cryptocurrencies worth billions of dollars apiece, its security has gained considerable attention. In this paper, we first investigate the security of smart contracts running on the Ethereum and introduce several new security vulnerabilities that allow adversaries to exploit and gain financial benefits. Then, we propose a more practical smart contract analysis tool termed NeuCheck, in which we introduce the syntax tree in the syntactical analyzer to complete the transformation from source code to intermediate representation, and then adopt the open source library working with XML to analyze such tree. We have built a prototype of NeuCheck for Ethereum and evaluate it with over 52 000 existing Ethereum smart contracts. The results show that (1) our new documented vulnerabilities are prevalent; (2) NeuCheck improves the analysis speed by at least 17.2 times compared to other popular analysis tools (eg, Securify and Mythril; and (3) allows for cross‐platform deployment.
Ning Lu 0005, Christian Esposito 0001
Softw. Pract. Exp.5
2020 Trust Is in the Air: A New Adaptive Method to Evaluate Mobile Wireless Networks
Alexandra Mihaita Mocanu, Bogdan-Costel Mocanu, Christian Esposito 0001, Florin Pop
ICTSS3
2020 Robust Decentralised Trust Management for the Internet of Things by Using Game Theory
Christian Esposito 0001, Oscar Tamburis, Xin Su 0002, Chang Choi
Inf. Process. Manag.1
2020 Distributed Group Key Management for Event Notification Confidentiality Among Sensors
abstract
There is an increasing involvement of the Internet of Things (IoT) in many of our daily activities, with the aim of improving their efficiency and effectiveness. We are witnessing the advent of smart cities, in which IoT is exploited to improve the management of a city's assets, as well as smart factories, where IoT is paving the way for the forth industrial revolution. These applications and many other ones imply several non-functional requirements to be satisfied by the adopted IoT solution, where security assumes paramount importance. Secure communications among the IoT nodes are strongly needed due to the use of wireless technologies that are easy to eavesdrop, in order to steal valuable information. Accordingly, confidentiality is a fundamental prerequisite, but the existing solutions based on transport-level encryption are ineffective, while the ones with application-level encryption may be too expensive in terms of energy consumption. In this work, we propose a series of solutions and methods to achieve confidentiality with end-to-end guarantees, by using group-based keys within the context of a clustered and distributed key management framework. We have implemented such solutions on top of TinyOS, and assessed their achievable quality by means of the TOSSIM simulator.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Dependable Secur. Comput.1
2020 Security Log Analysis in Critical Industrial Systems Exploiting Game Theoretic Feature Selection and Evidence Combination
abstract
Critical industrial systems have become profitable targets for cyber-attackers. Practitioners and administrators rely on a variety of data sources to develop security situation awareness at runtime. In spite of the advances in security information and event management products and services for handling heterogeneous data sources, analysis of proprietary logs generated by industrial systems keeps posing many challenges due to the lack of standard practices, formats, and threat models. This article addresses log analysis to detect anomalies, such as failures and misuse, in a critical industrial system. We conduct our study with a real-life system by a top leading industry provider in the air traffic control domain. The system emits massive volumes of highly-unstructured proprietary textual logs at runtime. We propose to extract quantitative metrics from logs and to detect anomalies by means of game theoretic feature selection and evidence combination. Experiments indicate that the proposed approach achieves high precision and recall at small tuning efforts.
Marcello Cinque, Christian Esposito 0001, Antonio Pecchia
IEEE Trans. Ind. Informatics2
2020 Editorial: IEEE Transactions on Sustainable Computing, Special Issue on Cryptography and Data Security in Sustainable Computing (Part 1)
abstract
The papers in this special section focus on cryptography and data security in sustainable computing.
Karl Andersson 0001, Xiaofeng Chen 0001, Christian Esposito 0001, Eric Rondeau
IEEE Trans. Sustain. Comput.3
2020 Editorial: IEEE Transactions on Sustainable Computing, Special Issue on Cryptography and Data Security in Sustainable Computing (Part 2)
abstract
The papers in the second part of this special issue focus on cryptography and data security in sustainable computing.
Karl Andersson 0001, Xiaofeng Chen 0001, Christian Esposito 0001, Eric Rondeau
IEEE Trans. Sustain. Comput.3
2019 An Effective Retrieval Approach for Documents Related to Past Civil Engineering Projects
abstract
During the practice of a public administration or a company, a large volume of documents are typically produced. The recent dematerialization efforts have been pushing the way for a digital form of these documents, so as to make their management more efficient and cost-saving. But, traditional document management systems entail many non-value adding activities, such as printing, transport and archiving these documents, making the retrieval of information extremely cumbersome, especially by users without a computer science degree. The research community is putting a lot of attention to realize effective and easy-to-use search capabilities over these large number of digital/digitalized documents. This paper investigates such a problem within the context of a document management system for past civil engineering projects, and proposes an applied solution to offer advanced document retrieval capabilities without demanding a strong background in computer science by presenting a proof-of.concept implemented within the context of the PROBIM project.
Christian Esposito 0001, Oscar Tamburis
WETICE1
2019 On Data Sovereignty in Cloud-Based Computation Offloading for Smart Cities Applications
abstract
Smart city applications are increasingly popular due to their potential to improve quality of life in an urbanized society, and such applications typically leverage on cloud computing for data and computation offloading from the sensing infrastructure. Despite the capability of achieving scalability and flexibility, the use of cloud computing imposes inherent security and privacy concerns regarding data analysis and exchange, as well as legal implications. For example, data in a smart city application being outsourced to the cloud and/or exchanged among sensing devices may be accessible to users located in a different jurisdiction or subsequently reside in a data center in a different jurisdiction. There may be conflicting privacy protection and disclosure laws among these jurisdictions/locations; thus, limiting the widespread adoption of smart city applications. Restricting the data flow for such applications is not viable since it may cause inefficiencies, although there are situations requiring to limit the data access to selected geographical locations. Therefore, we propose addressing this issue by using a location-dependent cryptographic approach, and we integrate such an approach within the context of cloud-based smart city applications.
Christian Esposito 0001, Aniello Castiglione, Flavio Frattini, Marcello Cinque, Yanjiang Yang, Kim-Kwang Raymond Choo
IEEE Internet Things J.1
2019 CNN-based anti-spoofing two-tier multi-factor authentication system
Salman Khan 0004, Tanveer Hussain 0001, Khan Muhammad 0001, Arun Kumar Sangaiah, Aniello Castiglione, Christian Esposito 0001, Sung Wook Baik
Pattern Recognit. Lett.7
2019 An Edge Intelligence Empowered Recommender System Enabling Cultural Heritage Applications
abstract
Recommender systems are increasingly playing an important role in our life, enabling users to find “what they need” within large data collections and supporting a variety of applications, from e-commerce to e-tourism. In this paper, we present a Big Data architecture supporting typical cultural heritage applications. On the top of querying, browsing, and analyzing cultural contents coming from distributed and heterogeneous repositories, we propose a novel user-centered recommendation strategy for cultural items suggestion. Despite centralizing the processing operations within the cloud, the vision of edge intelligence has been exploited by having a mobile app (Smart Search Museum) to perform semantic searches and machine-learning-based inference so as to be capable of suggesting museums, together with other items of interest, to users when they are visiting a city, exploiting jointly recommendation techniques and edge artificial intelligence facilities. Experimental results on accuracy and user satisfaction show the goodness of the proposed application.
Xin Su 0002, Giancarlo Sperlì, Vincenzo Moscato, Antonio Picariello, Christian Esposito 0001, Chang Choi
IEEE Trans. Ind. Informatics5
2018 Information theoretic-based detection and removal of slander and/or false-praise attacks for robust trust management with Dempster-Shafer combination of linguistic fuzzy terms
abstract
Summary Critical systems are progressively abandoning the traditional isolated and closed architectures, and adopting more federated solutions, in order to deal with orchestrated decision making within large‐scale infrastructures. Such an increasing connectivity and the possibility of dynamically integrate constituents in a seamless manner by means of a decoupling middleware solution are causing the flouring of novel and previously unseen security threats, such as internal attacks conducted by camouflaged and/or compromised federated systems. Trust management is the most efficient way for dealing with such attacks, so that each constituent computes a trust degree of the other interacting ones based on the direct experiences and of collected reputation scores. An adversary may negatively affect the overall process with false reputations, which must not be considered when estimating a trust degree. Our work combines a multi‐criteria linguistic fuzzy term formulation of the trust degree with the concept of entropy for measuring the divergence of certain scores from the other ones and to avoid to consider them during reputation aggregation. A set of experiments have been conducted in order to measure the quality and effectiveness of the presented approach.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.1
2018 On the optimal tuning and placement of FEC codecs within multicasting trees for resilient publish/subscribe services in edge-IoT architectures
Christian Esposito 0001, Andrea Bruno, Giuseppe Cattaneo, Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2018 A coral-reefs and Game Theory-based approach for optimizing elastic cloud resource allocation
Massimo Ficco, Christian Esposito 0001, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.2
2018 Power domain NOMA to support group communication in public safety networks
Xin Su 0002, Aniello Castiglione, Christian Esposito 0001, Chang Choi
Future Gener. Comput. Syst.3
2018 Loss-Tolerant Event Communications Within Industrial Internet of Things by Leveraging on Game Theoretic Intelligence
abstract
Internet of Things (IoT) is one of the key technologies paving the way for the next industrial revolution named as Industry 4.0, since it promises to realize smarter factories by optimizing costs and productivity. Traditionally, the adopted communication protocols among the sensors are required to manage the large scale of the infrastructure in terms on the high number of interconnected nodes and the massive volume of exchanged data. However, due to the key role of those Industrial IoT in exchanging business critical data, such protocols need to also provide high resiliency guarantees to the message exchange, with as few delivery misses as possible. The publish/subscribe interaction pattern and the protocol implementing it are a technically sound approach for achieving scalability and elasticity, thanks to their intrinsic decoupling among the interacting nodes. However, they are often unsuitable in their current form, because they provide only best-effort delivery guarantees, or they adopt naive solutions to achieve resilient communication, especially when wireless networks are used. This paper presents a clustered lightweight gossiping algorithm for resilient event based communications among the sensors, without requiring a pre-deployed brokering infrastructure supporting the adopted publish/subscribe protocol. A simulation-based assessment has been performed in order to empirically show the improvements in terms of successfully delivered notification without the excessive costs of the state-of-the-art solutions available in the literature.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Huimin Lu 0001
IEEE Internet Things J.1
2018 Building a network embedded FEC protocol by using game theory
Christian Esposito 0001, Arcangelo Castiglione, Francesco Palmieri 0002, Massimo Ficco
Inf. Sci.1
2018 Interoperable, dynamic and privacy-preserving access control for cloud data storage when integrating heterogeneous organizations
Christian Esposito 0001
J. Netw. Comput. Appl.1
2018 Event-based sensor data exchange and fusion in the Internet of Things environments
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco, Ciprian Dobre, George V. Iordache, Florin Pop
J. Parallel Distributed Comput.1
2018 Advanced services for efficient management of smart farms
George-Alexandru Musat, Madalin Colezea, Florin Pop, Catalin Negru, Mariana Mocanu, Christian Esposito 0001, Aniello Castiglione
J. Parallel Distributed Comput.6
2018 Integrity for an Event Notification Within the Industrial Internet of Things by Using Group Signatures
abstract
In the last years, several academic research efforts have focused on security requirements, threat models, and attack taxonomies concerning the application of the Internet of Things (IoT) in critical systems. Since such systems are strongly data intensive, it is of pivotal importance to provide integrity for the messages moving throughout the IoT infrastructure by means of publish/subscribe services. Integrity provisioning in industrial IoT scenarios has received marginal attention with respect to other primary security features. The existing solutions are lacking the needed focus on the peculiarities of the event notification and on the demand introduced by resource-constrained devices. This work contributes by applying group signatures so as to avoid managing certificates, violating the spatial decoupling, or implying an excessive resource usage. A proof-of-concept prototype of the proposed solution has been realized for platforms based on TinyOS, and simulations with TOSSIM have been conducted in order to empirically assess its performance and effectiveness.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Ind. Informatics1
2018 Securing Collaborative Deep Learning in Industrial Applications Within Adversarial Scenarios
abstract
Several industries in many different domains are looking at deep learning as a way to take advantage of the insights in their data, to improve their competitiveness, to open up novel business possibilities, or to resolve the problem that thought to be impossible to tackle. The large scale of the systems where deep learning is applied and the need of preserving the privacy of the used data have imposed a shift from the traditional centralized deployment to a more collaborative one. However, this has opened up several vulnerabilities caused by compromised nodes and inputs, with traditional crypto primitives and access control models exploited to offer protection means. Providing security can be costly in terms of higher energy consumption, calling for a wise use of these protection means. This paper exploits game theory to model interactions among collaborative deep learning nodes and to decide when using actions to support security enhancements.
Christian Esposito 0001, Xin Su 0002, Shadi A. Aljawarneh, Chang Choi
IEEE Trans. Ind. Informatics1
2017 A Trust Application in Participatory Sensing: Elder Reintegration
Alexandra Mihaita Mocanu, Ciprian Dobre, Florin Pop, Bogdan-Costel Mocanu, Valentin Cristea, Christian Esposito 0001
GPC6
2017 Secure crisis information sharing through an interoperability framework among first responders: The SECTOR practical experience
abstract
The increasing occurrence of large scale disasters calls out for a collaborative approach to crisis management, where multiple and heterogeneous organizations of first responders are deployed within the damaged area and must interact with each others in order to cooperate in the damage assessment and recovery actions. Such an approach requires a suitable communication platform to allow these organizations to exchange crisis information among their members, despite their heterogeneity. Current research is investigating such point and several solutions have been proposed; however, there are other key requirements that such a platform needs to address in order to be successfully used in practical cases. Among these requirements, security plays a key role. This paper introduces the issue of confidential and private communications for platforms supporting collaborative crisis management, and identifies a possible solution developed within the context of the EU-funded project named SECTOR.
Marcello Cinque, Domenico Cotroneo, Christian Esposito 0001, Mario Fiorentino
WiMob3
2017 A secure and resilient cross-domain SIP solution for MANETs using dynamic clustering and joint spatial and temporal redundancy
abstract
Summary In this paper, we extend our earlier work (where we presented a cross‐domain Session Initiation Protocol solution for mobile ad hoc networks using dynamic clustering) to handle packet losses affecting wireless networks and deal with outbound requests using reputation method. The (extended) solution is designed also to avoid the inherent shortcomings associated with centralized approaches (e.g. single point of failure). Using simulations, we evaluate the extended solution under different conditions. Findings from the evaluations demonstrate the utility of our solution. Copyright © 2016 John Wiley & Sons, Ltd.
Ala' F. A. Aburumman, Wei Jye Seo, Christian Esposito 0001, Aniello Castiglione, Md. Rafiqul Islam 0001, Kim-Kwang Raymond Choo
Concurr. Comput. Pract. Exp.3
2017 A collaborative clinical analysis service based on theory of evidence, fuzzy linguistic sets and prospect theory and its application to craniofacial disorders in infants
Arcangelo Castiglione, Raffaele Pizzolante, Christian Esposito 0001, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.3
2017 Improving the gossiping effectiveness with distributed strategic learning (Invited paper)
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.1
2017 Trust management for distributed heterogeneous systems by using linguistic term sets and hierarchies, aggregation operators and mechanism design
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.1
2017 Layered multicast for reliable event notification over large-scale networks
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Inf. Sci.1
2017 Signaling game based strategy for secure positioning in wireless sensor networks
Christian Esposito 0001, Chang Choi
Pervasive Mob. Comput.1
2016 Smart Cloud Storage Service Selection Based on Fuzzy Logic, Theory of Evidence and Game Theory
abstract
Cloud platforms encompass a large number of storage services that can be used to manage the needs of customers. Each of these services, offered by a different provider, is characterized by specific features, limitations and prices. In presence of multiple options, it is crucial to select the best solution fitting the customer requirements in terms of quality of service and costs. Most of the available approaches are not able to handle uncertainty in the expression of subjective preferences from customers, and can result in wrong (or sub-optimal) service selections in presence of rational/selfish providers, exposing untrustworthy indications concerning the quality of service levels and prices associated to their offers. In addition, due to its multi-objective nature, the optimal service selection process results in a very complex task to be managed, when possible, in a distributed way, for well-known scalability reasons. In this work, we aim at facing the above challenges by proposing three novel contributions. The fuzzy sets theory is used to express vagueness in the subjective preferences of the customers. The service selection is resolved with the distributed application of fuzzy inference or Dempster-Shafer theory of evidence. The selection strategy is also complemented by the adoption of a game theoretic approach for promoting truth-telling ones among service providers. We present empirical evidence of the proposed solution effectiveness through properly crafted simulation experiments.
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Computers1
2015 A knowledge-based platform for Big Data analytics based on publish/subscribe services and stream processing
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Knowl. Based Syst.1
2014 An event-based notification approach for the delivery of patient medical information
Christian Esposito 0001, Mario Ciampi, Giuseppe De Pietro
Inf. Syst.1
2014 Calibrating Indoor Positioning Systemswith Low Efforts
abstract
Recently, the positioning techniques based on the IEEE 802.11 signal strength are becoming the dominant solutions in the mobile device localization within indoor scenarios. Such solutions are characterized by two main pitfalls that compromise their effective usage in real application environments. First, during the calibration, a large amount of manual effort is required for acquiring a massive collection of training samples. Second, the positioning accuracy is directly related to the deployment of the wireless access points into the workspace, which is extremely time-consuming and requires human intervention. This paper presents an approach to reduce the manual calibration and to optimize the positioning accuracy, by selecting the best deployment schema of the wireless access points. The approach has been implemented in a tool, which uses an analytical signal propagation model to build the radio map of a given workspace, and exploits a multi-objective genetic algorithm to identify the best access points placement pattern that fits the required accuracy. A detailed experimental campaign is presented in order to show the benefits achievable by the proposed approach.
Massimo Ficco, Christian Esposito 0001, Aniello Napolitano
IEEE Trans. Mob. Comput.2
2014 Reliable and Timely Event Notification for Publish/Subscribe Services Over the Internet
abstract
The publish/subscribe paradigm is gaining attention for the development of several applications in wide area networks (WANs) due to its intrinsic time, space, and synchronization decoupling properties that meet the scalability and asynchrony requirements of those applications. However, while the communication in a WAN may be affected by the unpredictable behavior of the network, with messages that can be dropped or delayed, existing publish/subscribe solutions pay just a little attention to addressing these issues. On the contrary, applications such as business intelligence, critical infrastructures, and financial services require delivery guarantees with strict temporal deadlines. In this paper, we propose a framework that enforces both reliability and timeliness for publish/subscribe services over WAN. Specifically, we combine two different approaches: gossiping, to retrieve missing packets in case of incomplete information, and network coding, to reduce the number of retransmissions and, consequently, the latency. We provide an analytical model that describes the information recovery capabilities of our algorithm and a simulation-based study, taking into account a real workload from the Air Traffic Control domain, which evidences how the proposed solution is able to ensure reliable event notification over a WAN within a reasonable bounded time window.
Christian Esposito 0001, Marco Platania, Roberto Beraldi
IEEE/ACM Trans. Netw.1
2013 On reliability in publish/subscribe services
Christian Esposito 0001, Domenico Cotroneo, Stefano Russo 0001
Comput. Networks1
2012 Leveraging Power of Transmission for Range-Free Localization of Tiny Sensors
Marcello Cinque, Christian Esposito 0001, Flavio Frattini
W2GIS2
2012 On data dissemination for large-scale complex critical infrastructures
Marcello Cinque, Catello Di Martino, Christian Esposito 0001
Comput. Networks3
2011 Automatic Robustness Assessment of DDS-Compliant Middleware
abstract
The next generation of critical systems requires an efficient, scalable and robust data dissemination infrastructure. Middleware solutions compliant with the novel OMG standard, called Data Distribution Service (DDS), are being traditionally used for architecting large-scale systems, because they well meet the requirements of scalability, seamless decoupling and fault tolerance. Due to such features, industrial practitioners are enforcing the adoption of such middleware solutions also within the context of critical systems. However, these systems pose serious dependability requirements, which in turn demand DDS compliant products also to realize reliable data dissemination in different and heterogeneous contexts. Hence, assessing the supported reliability degree and proposing improvement strategies becomes crucial and requires a clear understanding of DDS compliant middleware failing behavior. This paper illustrates an innovative tool to automatically evaluate the robustness of DDS-compliant middleware based on a fault injection technique. Specifically, experiments have been conducted on an actual implementation of the DDS standard, by means of injecting a set of proper invalid inputs through its API and analyzing the achieved outcomes.
Aniello Napolitano, Gabriella Carrozza, Antonio Bovenzi, Christian Esposito 0001
PRDC4
2010 Reliable Event Dissemination over Wide-Area Networks without Severe Performance Fluctuations
abstract
Publish/subscribe middleware is being increasingly used to devise large-scale critical systems. Although several reliable publish/subscribe solutions have been proposed, none of them properly address the problem of assuring message dissemination even if network omissions happen without breaking any temporal constraints. In order to fill this gap, we have investigated how to guarantee a resilient and timely event dissemination despite of message losses. The contribution of this paper is on proposing a FEC approach, where encoding functionality is placed at the root and on a subset of interior nodes in the multicast tree, combined to a gossiping algorithm. Simulation-based experiments demonstrate that the proposed approach allows all the interested subscribers to receive all the published messages and the adopted resiliency mean does not affect the timeliness of the multicast protocol.
Christian Esposito 0001, Domenico Cotroneo, Stefano Russo 0001
ISORC1
2009 Calibrating RSS-Based Indoor Positioning Systems
abstract
Location estimation based on received signal strength (RSS) is the prevalent method in indoor positioning. For RSS-based methods a massive collection of training RSS samples is needed to calibrate the positioning system and to achieve a high positioning quality. The quality of these methods is directly related to the placement of the wireless sensors in the workspace and the radio map used to compute the user location. Traditionally deploying the reference points and building the radio map require human intervention and are extremely time-consuming. In this paper we aim to reduce these manual calibration efforts. We propose an automatic approach both to build a radio map in the given environment and to assess the best system calibration that fits the required positioning quality. The approach has been tested on the most used radio frequency-based technologies, i.e., IEEE 802.11 and Bluetooth.
Christian Esposito 0001, Domenico Cotroneo, Massimo Ficco
WiMob1
2008 Performance assessment of OMG compliant data distribution middleware
abstract
Event-driven architectures (EDAs) are widely used to make distributed mission critical software systems more- efficient and scalable. In the context of EDAs, data distribution service (DDS) is a recent standard by the object management group that offers a rich support for quality- of-service and balances predictable behavior and implementation efficiency. The DDS specification does not outline how messages are delivered, so several architectures are nowadays available. This paper focuses on performance assessment of OMG DDS-compliant middleware technologies. It provides three contributions to the study of evaluating the performance of DDS implementations: 1) describe the challenges to be addressed; 2) propose possible solutions; 3) define a representative workload scenario for evaluating the performance and scalability of DDS platforms. At the end of the paper, a case study of DDS performance assessment, performed with the proposed benchmark, is presented.
Christian Esposito 0001, Stefano Russo 0001, Dario Di Crescenzo
IPDPS1