EDBT 2026 Demo / reviewers in the wild / expert
Paolo Palmieri 0001
dblp:99/9960-1
· DBLP profile ↗
22ranked-venue papers
6as first author
14since 2021 · last 2026
0000-0002-9819-4880ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 5 first-author · 10 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HEALTH-DP: A Framework for Health Data De-Anonymization Risk Assessment and Mitigation with Differential PrivacyabstractPrivacy protection is a significant challenge in the computation of personal data, especially when data (e.g. health-related) is considered sensitive under relevant regulations. Although anonymization is widely applied, adversaries can still de-anonymize data through sophisticated attacks. Risks are particularly severe for health datasets, such as genomics or physiological data, due to their inherent uniqueness. Differential privacy (DP) has emerged as a strong privacy-preservation technique. However, current approaches to its implementation remain theoretical (and thus not directly linked to actual risks) or specific to a single context, and lack inclusive pathways for different stakeholders in the medical environment. This paper presents a comprehensive framework to address these limitations, combining a systematic study of re-identification attacks and practical risk assessment with DP implementation. The framework incorporates the parties’ roles, threat pre-assessment, known attacks and DP integration. An adaptive mitigation strategy within a structured flow and logical process ensures wide coverage of different requirements. Furthermore, we validate the framework by applying central DP (CDP) to a heart-attack prediction dataset as an initial case study for a future broader end-to-end implementation. The framework provides a roadmap for implementing DP based on evaluating re-identification risks and data governance requirements, and gives stakeholders actionable guidance for safer data use. Hamza Aguelal, Akasha Shafiq, Paolo Palmieri 0001 |
ICISSP (1) | 3 |
| 2025 | ECG De-Anonymization: Real-World Risks and a Privacy-by-Design Mitigation StrategyabstractThe growing use of patient data in research underscores its value (for instance, in training AI). It also highlights the need for strong anonymization when health datasets are released publicly due to the risk of de-anonymization attacks. Electrocardiograms (ECG) are widely used, and real patient data have been openly released anonymously. However, ECGs are susceptible to linkage attacks, raising concerns around privacy, non-compliance with regulations such as the General Data Protection Regulation (GDPR), and loss of trust in digital healthcare. In this paper, we present a novel lightweight de-anonymization linkage attack on ECGs, and discuss benchmarking routes and an inclusive privacy protection framework that can be used in mitigating de-anonymization risks. The proposed matching attack leverages Convolutional Neural Networks (CNN)-based and ECGspecific features, and was tested on three open datasets: ECGID, MIMIC-IV and MIT-BIH. Unlike authentication-focused works, our study evaluates re-identification from an adversarial perspective, quantifying the risk on anonymized datasets based on metrics that establish a benchmarking baseline. Experimental results demonstrate an average matching accuracy of 97.22%, and nearly 100% for the best result, on the MIT-BIH dataset, for which previous results exist in the literature. Our results are substantially higher than the previous best-performing attack, which achieved an 81.9% accuracy. Consistent results on the two other datasets demonstrate the generality of our approach. The attack emphasizes evaluating de-anonymization risks before publicly releasing datasets. Based on our findings, we formalize recommendations into a new privacy-by-design framework resilient against real-world de-anonymization attacks, including inclusive processes to guide stakeholders in assessing requirements and offering insights into privacy metrics and improvement axes. Hamza Aguelal, Paolo Palmieri 0001 |
CBMS | 2 |
| 2025 | CCSW '25: Cloud Computing Security WorkshopabstractThe 16th Cloud Computing Security Workshop (CCSW '25), co-located with the ACM Conference on Computer and Communications Security (CCS '25), was held in Taipei on October 17, 2025. It featured six full papers on various aspects of security and privacy of cloud environments, including recent advances in security testing and intrusion detection enabled by artificial intelligence, advanced cryptography for the outsourcing of data and computation, and secure coding and networking. The program was enriched by two distinguished keynote speakers: Dr. Tianwei Zhang and Dr. Matthias Kannwischer. The complete CCSW '25 workshop proceedings can be found at: https://dl.acm.org/citation.cfm?id=3733812 Paolo Palmieri 0001, Shivam Bhasin |
CCS | 1 |
| 2025 | De-Anonymization of Health Data: A Survey of Practical Attacks, Vulnerabilities and ChallengesabstractHealth data ranks among the most sensitive personal information disclosing serious details about individuals. Although anonymization is used, vulnerabilities persist, leading to de-anonymization and privacy risks highlighted by regulations like the General Data Protection Regulation (GDPR). This survey examines de-anonymization attacks on health datasets, focusing on methodologies employed, data targeted, and the effectiveness of current anonymization practices. Unlike previous surveys that lack consensus on essential empirical questions, we provide a comprehensive summary of practical attacks, offering a more logical perspective on real-world risk. Our investigation systematically categorizes these practical attacks, revealing insights into suc cess rates, generality and reproducibility, new analytics used, and the specific vulnerabilities they exploit. The study covers health-related datasets, including medical records, genomic data, electrocardiograms (ECGs), and neuroimaging, highlighting the need for more robust anonymization. Significant challenges remain in the literature despite existing reviews. We advocate for stronger data safeness by improving anonymization methods and advancing research on de-anonymization and assessment within healthcare. Hamza Aguelal, Paolo Palmieri 0001 |
ICISSP (2) | 2 |
| 2025 | Tutorial: The Energy Cost of Privacy and SecurityabstractSecurity and privacy are key enablers (and often also a legal requirement) for a number of applications, including smart grid and smart cities, health care, data analytics, and personalized services. Because of this, research in the domain of security and privacy-preserving techniques is progressing at high pace. However, if on the one side the research community devoted large attention to the study of more efficient algorithms and the design of more efficient architectures implementing them, on the other, the energy cost and the energy implications of the use of these technologies have not yet been explored in the needed depth, with the majority of literature focusing on block ciphers. This tutorial exposes the community to the main current research results and best practices in this research area, and aims to foster the exchange of ideas between all the involved stakeholders. The tutorial presents the background and latest achievements in the field of energy assessment and reduction for security and privacy-preserving primitives. This tutorial covers the needed background on security algorithms, discusses their energy consumption, and presents, by means of relevant examples, how to design and implement security primitives that achieve a limited energy footprint. In particular, the focus is on two families of security primitives: block ciphers and privacy-preserving primitives. The tutorial introduces the basic concepts and the main algorithms belonging to these families, discusses recent advances in the domain, and presents in detail the energy consumption of these technologies and in their applications such as machine learning. Further, the tutorial will show optimizations that have been proposed to minimize the energy footprint of security primitives, with a particular focus on block ciphers, discussing also the design of lightweight and low-energy cryptographic algorithms. The tutorial concludes discussing open problems, limitations, and possible research directions. The tutorial is divided into three sections and will begin with a talk providing a detailed introduction of the needed concepts, to allow attendees not familiar with the topic to be able to successfully follow the whole tutorial. More in details, the sections are: • "Introduction to Security Primitives and Privacy Preserving Technologies". This talk will introduce the audience to the security primitives and the relevant privacy preserving technologies and protocols, [1] that will be analyzed in the rest of the tutorial. • "Energy Assessment of Security Primitives". This talk summarizes current research in energy assessment [2] of security primitives, reporting the method used to assess them and presenting literature result on the energy consumption of security primitives. The talk will conclude presenting open problems and future research directions. • "Energy Efficient Design and Implementation of Security Primitives". This talk reviews the strategies that have been applied to security primitives to reduce their energy consumption and presents the algorithms that have been designed, since the beginning, to achieve a limited energy footprint [3] , [4] . The talk will conclude presenting open problems and future research directions. Ayse K. Coskun, Paolo Palmieri 0001, Francesco Regazzoni 0001 |
ISLPED | 2 |
| 2025 | Securing Snapshot Pruning in IOTA Tangle 2.0: A Cooperative Deep Reinforcement Learning Approach for Edge-Cloud Smart Meter Networks
Basker Palaniswamy, Paolo Palmieri 0001 |
SecureComm (5) | 2 |
| 2025 | Quantum secure threshold password authenticated key exchange scheme for VANETabstractAbstract Vehicle ad hoc networks (VANETs) enable efficient communication for enhanced safety and convenience. However, due to their open network environment, VANETs are highly vulnerable to attacks, including eavesdropping and vehicle impersonation. Therefore, authentication and data confidentiality are the basic security requirements, achieved through vehicle authentication and establishing secure channels using a shared secret key $$({\textbf{sk}})$$ ( sk ) . The Password-Authenticated Key Exchange (PAKE) protocol generates a high-entropy $${\textbf{sk}}$$ sk using a simple password. However, the traditional PAKE scheme stores passwords on a single server, significantly increasing vulnerability to offline dictionary attacks. To mitigate this, the threshold PAKE scheme distributes the password among multiple servers, avoiding a single point of failure. In this paper, we present a novel threshold PAKE protocol that enables a vehicle to authenticate with the authentication server while keeping the password secret. In particular, we integrate a threshold public key encryption scheme and an asymmetric key consensus (AKC) mechanism for password authentication and key exchange. The password is encrypted using the public key of distributed decryption servers, and a threshold number of these servers collaboratively decrypt and verify it. After verification, the vehicle and authentication server establish a $${\textbf{sk}}$$ sk using an AKC mechanism. Our scheme is proven secure against chosen ciphertext attacks, based on the decision module learning with error assumption, resists offline dictionary attacks, provides password and key secrecy, and mutual authentication. Additionally, it achieves transparency by ensuring vehicles communicate only with the authentication server. Performance analysis shows our protocol achieves enhanced efficiency with minimal communication rounds, reduced computational costs, and faster execution compared to existing solutions. Alia Umrani, Paolo Palmieri 0001 |
Cybersecur. | 2 |
| 2024 | CCSW 2024 - Cloud Computing Security WorkshopabstractThe CCSW workshop aims to bring together researchers and practitioners to explore all aspects of security in cloud-centric and outsourced computing. In CCSW 2024, based on the papers that have been accepted, the workshop is focused on applied cryptographic schemes and protocols for the cloud, cloud-based leakage related attacks and their countermeasures, trusted computing technology in clouds, binary analysis of software for cloud protection, network security mechanisms using AI anomaly detection as well as security for emerging cloud programming models (like extended Berkeley Packet Filter, eBPF, programs). Throughout the years, the workshop particularly encourages novel paradigms and controversial ideas not covered by traditional cloud security research, serving as a fertile ground for creative debate and interaction in security-sensitive areas of computing impacted by cloud technologies. The workshop received 20 submissions, 15 of which passed through a thorough review process of at least 3 reviewers, and 7 of them were accepted for publication and presentation. Apostolos P. Fournaris, Paolo Palmieri 0001 |
CCS | 2 |
| 2024 | SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data SpaceabstractIn this paper, we present the SECURED project11Funded in part by the European Union (EU), Grant Agreement no. 10109571. Views and opinions expressed are those of the authors and do not necessarily reflect those of the EU or the Health and Digital Executive Agency. Neither the EU nor the granting authority are responsible for them., aimed at improving privacy-preserving processing of data in the health domain. The technologies developed in the project will be demonstrated in four health-related use cases and with the involvement of SME's selected through an open funding call. Francesco Regazzoni 0001, Gergely Ács, Albert Zoltan Aszalos, Christos Avgerinos, Nikolaos Bakalos, Josep Lluís Berral, Joppe W. Bos, Marco Brohet, Andrés G. Castillo, Gareth T. Davies, Stefanos Florescu, Pierre-Elisée Flory, Alberto Gutierrez-Torre, Evangelos Haleplidis, Alice Héliou, Sotiris Ioannidis, Alexander El-Kady, Katarzyna Kapusta, Konstantina Karagianni, Pieter Kruizinga, Kyrian Maat, Zoltán Ádám Mann, Kalliopi Mastoraki, SeoJeong Moon, Maja Nisevic, Balazs Pejo, Kostas Papagiannopoulos, Vassilis Paliouras, Paolo Palmieri 0001, Francesca Palumbo, Juan Carlos Pérez Baun, Péter Pollner, Eduard Porta-Pardo, Luca Pulina, Muhammad Ali Siddiqi, Daniela Spajic, Christos Strydis, George Tasopoulos, Vincent Thouvenot, Christos Tselios, Apostolos P. Fournaris |
DATE | 29 |
| 2024 | Anonymous Multi-Receiver Certificateless Hybrid Signcryption for Broadcast CommunicationabstractConfidentiality, authentication, and anonymity are fundamental security requirements in broadcast communication achievable by Digital Signature (DS), encryption, and Pseudo-Identity (PID) techniques. Signcryption, particularly hybrid signcryption, offers both DS and encryption more efficiently than “sign-then-encrypt”, with lower computational and communication costs. This paper proposes an Anonymous Multi-receiver Certificateless Hybrid Signcryption (AMCLHS) scheme for secure broadcast communication. AMCLHS combines public-key cryptography and symmetric key to achieve confidentiality, authentication, and anonymity. We provide a simple and efficient construction of a multi-recipient Key Encapsulation Mechanism (mKEM) to create a symmetric session key. This key, with the sender’s private key, is used in Data Encapsulation Mechanism (DEM) to signcrypt the message, ensuring confidentiality and authentication. The scheme generates identical ciphertext for multiple recipients while maintaining their anonymity by assigning a PID to each user. Security notions are demonstrated for indistinguishability against chosen-ciphertext attack using the elliptic curve computational diffie-hellman assumption in the random oracle model and existential unforgeability against chosen message attack under elliptic curve diffie-hellman assumption. The AMCLHS scheme operates in a multireceiver certificateless environment, preventing the key escrow problem. Comparative analysis shows that our scheme is computationally efficient, provides optimal communication cost, and simultaneously ensures confidentiality, authentication, anonymity, non-repudiation, and forward security. Alia Umrani, Apurva K. Vangujar, Paolo Palmieri 0001 |
ICISSP | 3 |
| 2024 | A Cryptographic Protocol for Efficient Mutual Location Privacy Through Outsourcing in Indoor Wi-Fi LocalizationabstractDigital services and applications are increasingly requiring location information from users to provide personalized services. However, disclosing one’s location introduces significant privacy risks, as location traces are highly unique and can be used to infer additional sensitive data. While location-based services were once restricted to outdoor spaces, given the lack of GPS signal indoors, a growing number of applications rely on Wi-Fi to provide indoor localization. Indoor localization can impact privacy to an even greater degree, as most of our daily activities occur indoors. Therefore, several indoor privacy protocols have been proposed, focusing on protecting the user’s location. However, the problem of mutual location privacy, that is, the protection of both the user’s privacy and the service provider’s location database, has not been addressed, particularly against malicious (active) adversaries. In addressing this gap, this paper presents an efficient and privacy-preserving cryptographic protocol for indoor localization. Our protocol hides the user’s location, while also protecting the service provider’s location map and areas of interest against malicious users. Furthermore, the protocol outsources most of the user-side heavy computation to a third-party cloud server, which does not need to be trusted by the parties as it remains oblivious to both user’s location and the provider’s database throughout the computations. Compared to leading solutions in the literature, including [1], [2], our protocol is the first to provide security against malicious users. Additionally, it significantly reduces the user computation and communication overhead (of up to 99%), making it potentially the first practicable scheme in resource-constrained mobile and IoT environments. Samuel N. Eshun, Paolo Palmieri 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Agent-based blockchain model for robust authentication and authorization in IoT-based healthcare systems
Hind Idrissi, Paolo Palmieri 0001 |
J. Supercomput. | 2 |
| 2023 | Deep Learning-Based Rotational-XOR Distinguishers for AND-RX Block Ciphers: Evaluations on Simeck and Simon
Amirhossein Ebrahimi, David Gérault, Paolo Palmieri 0001 |
SAC | 3 |
| 2021 | Introduction to the special issue on privacy and security for location-based services and devices
Luca Calderoni, Paolo Palmieri 0001, Constantinos Patsakis |
J. Inf. Secur. Appl. | 2 |
| 2019 | A privacy-preserving protocol for indoor wi-fi localizationabstractLocation-aware applications have witnessed massive worldwide growth in recent years due to the introduction and advancement of smartphones. Most of these applications rely on the Global Positioning System (GPS) which is not available in indoor environments. As a result, Wi-Fi fingerprinting is becoming increasingly popular as an alternative as it allows localizing users in indoor environments, has lower power consumption, and is also more economical as it does not require a dedicated sensor other than a Wi-Fi card. The technique allows a service provider (SP) to construct a Wi-Fi database (called radio map) that can be used as a reference point to localize a user. However, this process does not preserve the user privacy, as the location can only be computed interactively with the SP. The service provider may also reveal sensitive information on the indoor space (e.g. the building map) to the user. Thus, we need an indoor localization protocol that addresses the privacy of both parties. In this paper, we present a privacy-preserving cryptographic protocol for indoor Wi-Fi localization, that prevents the SP from learning the exact location of the user outside of certain pre-defined sensitive areas, while keeping the SP's database secure. Thus, both parties cannot learn anything about each other's input beyond the implicit output revealed. Samuel N. Eshun, Paolo Palmieri 0001 |
CF | 2 |
| 2018 | Hash-based signatures for the internet of things: position paperabstractWhile numerous digital signature schemes exist in the literature, most real-world system rely on RSA-based signature schemes or on the digital signature algorithm (DSA), including its elliptic curve cryptography variant ECDSA. Paolo Palmieri 0001 |
CF | 1 |
| 2018 | Probabilistic Properties of the Spatial Bloom Filters and Their Relevance to Cryptographic ProtocolsabstractThe classical Bloom filter data structure is a crucial component of hundreds of cryptographic protocols. It has been used in privacy preservation and secure computation settings, often in conjunction with the (somewhat) homomorphic properties of ciphers such as Paillier's. In 2014, a new data structure extending and surpassing the capabilities of the classical Bloom filter has been proposed. The new primitive, called spatial Bloom filter (SBF) retains the hash-based membership-query design of the Bloom filter, but applies it to elements from multiple sets. Since its introduction, the SBF has been used in the design of cryptographic protocols for a number of domains, including location privacy and network security. However, due to the complex nature of this probabilistic data structure, its properties had not been fully understood. In this paper, we address this gap in knowledge and we fully explore the probabilistic properties of the SBF. In doing so, we define a number of metrics (such as emersion and safeness) useful in determining the parameters needed to achieve certain characteristics in a filter, including the false positive probability and inter-set error rate. This will in turn enable the design of more efficient cryptographic protocols based on the SBF, opening the way to their practical application in a number of security and privacy settings. Luca Calderoni, Paolo Palmieri 0001, Dario Maio |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Preserving Context Privacy in Distributed Hash Table Wireless Sensor Networks
Paolo Palmieri 0001 |
ICICS | 1 |
| 2015 | Location privacy without mutual trust: The spatial Bloom filter
Luca Calderoni, Paolo Palmieri 0001, Dario Maio |
Comput. Commun. | 2 |
| 2014 | Spatial Bloom Filters: Enabling Privacy in Location-Aware Applications
Paolo Palmieri 0001, Luca Calderoni, Dario Maio |
Inscrypt | 1 |
| 2011 | Secure Two-Party Computation over a Z-Channel
Paolo Palmieri 0001, Olivier Pereira |
ProvSec | 1 |
| 2010 | Building Oblivious Transfer on Channel Delays
Paolo Palmieri 0001, Olivier Pereira |
Inscrypt | 1 |