Publications
Scientific output
35 publications across journals, conferences, and workshops in software engineering, reliability, and cybersecurity.
Journal articles
-
Reading between the Lines: Context-Aware AI-based Generation of Software ExploitsEmpirical Software Engineering, Springer, 31(3), Article 60, 2026
-
cAPTure dataset: How fast can you detect APT threats?Computer Networks, Elsevier, vol. 287, 112570, 2026
-
CGP-Tuning: Structure-Aware Soft Prompt Tuning for Code Vulnerability DetectionIEEE Transactions on Software Engineering, vol. 51, pp. 2533–2548, 2025
-
Enhancing Robustness of AI Offensive Code Generators via Data AugmentationEmpirical Software Engineering, Springer, 30(1), Article 7, 2025
-
DeVAIC: A Tool for Security Assessment of AI-Generated CodeInformation and Software Technology, Elsevier, 2025
-
Automating the Correctness Assessment of AI-Generated Code for Security ContextsJournal of Systems and Software, Elsevier, 2024
-
AI Code Generators for Security: Friend or Foe?IEEE Security & Privacy, vol. 22, no. 5, pp. 73–81, 2024
-
Who Evaluates the Evaluators? On Automatic Metrics for Assessing AI-Based Offensive Code GeneratorsExpert Systems with Applications, Elsevier, 225, 120073, 2023
-
Run-Time Failure Detection via Non-Intrusive Event Analysis in a Large-Scale Cloud Computing PlatformJournal of Systems and Software, Elsevier, 198, 111611, 2023
-
Can We Generate Shellcodes via Natural Language? An Empirical StudyAutomated Software Engineering, Springer, 2022
-
Enhancing the Analysis of Software Failures in Cloud Computing Systems with Deep LearningJournal of Systems and Software, Elsevier, 181, 111043, 2021
-
Fault Injection Analytics: A Novel Approach to Discover Failure Modes in Cloud-Computing SystemsIEEE Transactions on Dependable and Secure Computing, vol. 19, no. 3, pp. 1476–1491, 2020
International conferences
-
How Bad Can a Bug Get? An Empirical Analysis of Software Failures in the OpenStack Cloud Computing PlatformACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE 2019), pp. 200–211
-
Will It Break in Production? Metric-Driven Prediction of Residual Defects in Python Systems56th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2026), Charlotte, NC, USA, pp. 772–785
-
Human-written vs. AI-generated Code: A Large-Scale Study of Defects, Vulnerabilities, and ComplexityIEEE 36th International Symposium on Software Reliability Engineering (ISSRE 2025)
-
Quality In, Quality Out: Investigating Training Data's Role in AI Code GenerationIEEE/ACM International Conference on Program Comprehension (ICPC 2025)
-
Enhancing AI-based Generation of Software Exploits with Contextual InformationIEEE 35th International Symposium on Software Reliability Engineering (ISSRE 2024)
-
Vulnerabilities in AI Code Generators: Exploring Targeted Data Poisoning AttacksIEEE/ACM International Conference on Program Comprehension (ICPC 2024)
-
EVIL: Exploiting Software via Natural LanguageIEEE International Symposium on Software Reliability Engineering (ISSRE 2021)
-
ProFiPy: Programmable Software Fault Injection as-a-ServiceIEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2020), pp. 364–372
-
Enhancing Failure Propagation Analysis in Cloud Computing SystemsIEEE International Symposium on Software Reliability Engineering (ISSRE 2019), pp. 139–150
-
Creation and Use of a Representative Dataset for Advanced Persistent Threats DetectionInternational Conference on Computer Safety, Reliability, and Security (SAFECOMP 2025), pp. 51–66
-
PyResBugs: A Dataset of Residual Python Bugs for Natural Language-Driven Fault InjectionIEEE/ACM International Conference on AI Foundation Models and Software Engineering (FORGE 2025)
-
FailViz: A Tool for Visualizing Fault Injection Experiments in Distributed SystemsEuropean Dependable Computing Conference (EDCC 2019), pp. 145–148
Workshops
-
Drivers of Secure and Correct Code: A Factorial Study of Size, Pre-Training, and Data Quality56th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W 2026), Charlotte, NC, USA, pp. 70–76
-
Securing AI Code Generation Through Automated Pattern-Based PatchingIEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W 2025)
-
Generative AI in Cybersecurity: Generating Offensive Code from Natural LanguageIEEE/IFIP International Conference on Dependable Systems and Networks Supplemental Volume (DSN-S 2025)
-
Neural Fault Injection: Generating Software Faults from Natural LanguageIEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W 2024)
-
DDOSHIELD-IoT: A Testbed for Simulating and Lightweight Detection of IoT Botnet DDoS AttacksIEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W 2024)
-
The Power of Words: Generating PowerShell Attacks from Natural LanguageUSENIX Workshop on Offensive Technologies (WOOT 2024)
-
Simulation Environment for the Evaluation of Lightweight Intrusion Detection SystemsIEEE International Symposium on Software Reliability Engineering Workshops (ISSREW 2023), pp. 132–135
-
Can NMT Understand Me? Towards Perturbation-Based Evaluation of NMT Models for Code GenerationInternational Workshop on Natural Language-based Software Engineering (NLBSE 2022)
-
Shellcode_IA32: A Dataset for Automatic Shellcode GenerationWorkshop on Natural Language Processing for Programming (NLP4Prog 2021), pp. 58–64
-
Towards Runtime Verification via Event Stream Processing in Cloud Computing InfrastructuresInternational Conference on Service-Oriented Computing (ICSOC 2020), pp. 162–175
-
Enhancing the Analysis of Error Propagation and Failure Modes in Cloud SystemsIEEE International Symposium on Software Reliability Engineering Workshops (ISSREW 2018), pp. 140–141
PhD thesis
-
Fault Injection for Cloud Computing Systems: From Failure Mode Analysis to Run-Time Failure DetectionPhD Thesis, University of Naples Federico II, 2022