Publications
2026
TypeMap: Content-Type Segmentation for Mixed Text
Martin Dallinger, Yanick Fratantonio, Luca Invernizzi
ACM Workshop on Artificial Intelligence and Security (AISec), 2026
TRIAGE-CPG: A Cross-Model Study of Budgeted Static Malware Triage with Large Language Models
Paul-Andrei Sava, Alexander Küchler, Daniel Kowatsch, Bernhard Grill, Yanick Fratantonio, Luca Invernizzi
ACM Workshop on Artificial Intelligence and Security (AISec), 2026
From Payload to Plugin: Web-Scale Ecosystem Attribution of JavaScript Injection Campaigns
Ravindu De Silva, Nicholas Shao, Yigitcan Kaya, Mingxuan Yao, Yanick Fratantonio, Luca Invernizzi, Christopher Kruegel, Giovanni Vigna
ACM Conference on Computer and Communications Security (CCS), 2026
ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?
Zhun Wang, Nico Schiller, Hongwei Li, Srijiith Sesha Narayana, Milad Nasr, Nicholas Carlini, Xiangyu Qi, Eric Wallace, Elie Bursztein, Luca Invernizzi, Kurt Thomas, Yan Shoshitaishvili, Wenbo Guo, Jingxuan He, Thorsten Holz, Dawn Song
arXiv, 2026
1 citationHoneyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
Mark Vero, Fabian Kaczmarczyck, Ivan Petrov, Ilia Shumailov, Jamie Hayes, Niels Heinen, Tianqi Fan, Luca Invernizzi, Martin Vechev
arXiv, 2026
2025
Evaluating the robustness of a production malware detection system to transferable adversarial attacks
Milad Nasr, Yanick Fratantonio, Luca Invernizzi, Ange Albertini, Loua Farah, Alex Petit-Bianco, Andreas Terzis, Kurt Thomas, Elie Bursztein, Nicholas Carlini
ACM SIGSAC Conference on Computer and Communications Security, 2025
2 citationsGoogle announces Sec-Gemini v1, a new experimental cybersecurity model
E Burzstein, M Tishchenko
April, 2025
2 citations2024
Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context
Machel Reid, Nikolay Savinov, Denis Teplyashin, Dmitry Lepikhin, Timothy Lillicrap, et al. (606 authors)
arXiv, 2024
4222 citationsMagika: AI-Powered Content-Type Detection
Yanick Fratantonio, Luca Invernizzi, Loua Farah, Kurt Thomas, Marina Zhang, Ange Albertini, Francois Galilee, Giancarlo Metitieri, Julien Cretin, Alex Petit-Bianco, David Tao, Elie Bursztein
International Conference on Software Engineering (ICSE), 2024
13 citationsGive and take: An end-to-end investigation of giveaway scam conversion rates
Enze Liu, George Kappos, Eric Mugnier, Luca Invernizzi, Stefan Savage, David Tao, Kurt Thomas, Geoffrey M Voelker, Sarah Meiklejohn
ACM Internet Measurement Conference (IMC), 2024
13 citationsSedpack - Scalable and efficient dataset library
Karel Král, Jean-Michel Picod, Luca Invernizzi, Elie Bursztein
Open Tools Interfaces and Metrics for Implementation Security Testing (OPTIMIST 2024), 2024
2023
Generalized power attacks against crypto hardware using long-range deep learning
Elie Bursztein, Luca Invernizzi, Karel Král, Daniel Moghimi, Jean-Michel Picod, Marina Zhang
arXiv, 2023
30 citations2022
Hybrid Post-Quantum Signatures in Hardware Security Keys
Diana Ghinea, Fabian Kaczmarczyck, Jennifer Pullman, Julien Cretin, Stefan Kölbl, Rafael Misoczki, Picod Jean-Michel, Luca Invernizzi, Elie Bursztein
ACNS Workshop on Secure Cryptographic Implementation, 2022
37 citations2020
Spotlight: Malware Lead Generation at Scale
Fabian Kaczmarczyck, Bernhard Grill, Luca Invernizzi, Jennifer Pullman, Cecilia M. Procopiuc, David Tao, Borbala Benko, Elie Bursztein
Annual Computer Security Applications Conference (ACSAC), 2020
12 citations2019
Protecting accounts from credential stuffing with password breach alerting
Kurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan, Patrick Gage Kelley, Luca Invernizzi, Borbala Benko, Tadek Pietraszek, Sarvar Patel, Dan Boneh, Elie Bursztein
USENIX Security Symposium, 2019
218 citationsFive years of the right to be forgotten
Theo Bertram, Elie Bursztein, Stephanie Caro, Hubert Chao, Rutledge Chin Feman, Peter Fleischer, Albin Gustafsson, Jess Hemerly, Chris Hibbert, Luca Invernizzi, Lanah Kammourieh Donnelly, Jason Ketover, Jay Laefer, Paul Nicholas, Yuan Niu, Harjinder Obhi, David Price, Andrew Strait, Kurt Thomas, Al Verney
ACM SIGSAC Conference on Computer and Communications Security, 2019
66 citationsServerless Cybersecurity Training
Luca Invernizzi, Elie Bursztein
TDCommons, 2019
2018
Tracking ransomware end-to-end
Danny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi, Elie Bursztein, Kylie McRoberts, Jonathan Levin, Kirill Levchenko, Alex C Snoeren, Damon McCoy
IEEE Symposium on Security and Privacy (S&P), 2018
351 citationsThree years of the Right to be Forgotten
Theo Bertram, Elie Bursztein, Stephanie Caro, Hubert Chao, Rutledge Chin Feman, Peter Fleischer, Albin Gustafsson, Jess Hemerly, Chris Hibbert, Luca Invernizzi, LK Donnelly, J Ketover, Jay Laefer, Paul Nicholas, Yuan Niu, Harjinder Obhi, David Price, Andrew Strait, Kurt Thomas, Al Verney
ArXiv, 2018
24 citations2017
Understanding the mirai botnet
Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, Yi Zhou
USENIX security symposium (USENIX Security 17), 2017
3483 citationsData Breaches, Phishing, or Malware?: Understanding the Risks of Stolen Credentials
Kurt Thomas, Frank Li, Ali Zand, Jacob Barrett, Juri Ranieri, Luca Invernizzi, Yarik Markov, Oxana Comanescu, Vijay Eranti, Angelika Moscicki, et al
ACM SIGSAC Conference on Computer and Communications Security, 2017
404 citationsGossip: Automatically identifying malicious domains from mailing list discussions
Cheng Huang, Shuang Hao, Luca Invernizzi, Jiayong Liu, Yong Fang, Christopher Kruegel, Giovanni Vigna
ACM on Asia Conference on Computer and Communications Security (AsiaCCS), 2017
24 citations2016
Cloak of Visibility: Detecting When Machines Browse A Different Web
Luca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu, Jean-Michel Picod, Elie Bursztein
IEEE Security and Privacy (S&P), 2016
142 citations2015
What the app is that? deception and countermeasures in the android user interface
Antonio Bianchi, Jacopo Corbetta, Luca Invernizzi, Yanick Fratantonio, Christopher Kruegel, Giovanni Vigna
IEEE Symposium on Security and Privacy (S&P), 2015
238 citationsBaredroid: Large-scale analysis of android apps on real devices
Simone Mutti, Yanick Fratantonio, Antonio Bianchi, Luca Invernizzi, Jacopo Corbetta, Dhilung Kirat, Christopher Kruegel, Giovanni Vigna
Annual Computer Security Applications Conference (ACSAC), 2015
102 citationsDetecting malware infestations in large-scale networks
Luca Invernizzi, Stanislav Miskovic, Ruben Torres, Sabyasachi Saha, Christopher Kruegel, Antonio Nucci, Sung-Ju Lee, Giovanni Vigna
US Patent, 2015
58 citationsDetecting the stealthy distribution of malicious and abusive content online
Luca Invernizzi
Thesis, 2015
2014
Nazca: Detecting Malware Distribution in Large-Scale Networks.
Luca Invernizzi, Stanislav Miskovic, Ruben Torres, Christopher Kruegel, Sabyasachi Saha, Giovanni Vigna, Sung-Ju Lee, Marco Mellia
Annual Network and Distributed Systems Security (NDSS), 2014
203 citationsTen Years of {iCTF}: The Good, The Bad, and The Ugly
Giovanni Vigna, Kevin Borgolte, Jacopo Corbetta, Adam Doupe, Yanick Fratantonio, Luca Invernizzi, Dhilung Kirat, Yan Shoshitaishvili
USENIX Summit on Gaming Games and Gamification in Security Education (3GSE 14), 2014
91 citationsDo you feel lucky? A large-scale analysis of risk-rewards trade-offs in cyber security
Yan Shoshitaishvili, Luca Invernizzi, Adam Doupe, Giovanni Vigna
Annual ACM Symposium on Applied Computing (ACSAC), 2014
18 citationsEyes of a human, eyes of a program: Leveraging different views of the web for analysis and detection
Jacopo Corbetta, Luca Invernizzi, Christopher Kruegel, Giovanni Vigna
Research in Attacks Intrusions and Defenses (RAID), 2014
14 citationsResearch in Attacks, Intrusions and Defenses
Angelos Stavrou, Herbert Bos, Georgios Portokalidis
Springer International Publishing, 2014
2 citations2012
You are what you include: large-scale evaluation of remote javascript inclusions
Nick Nikiforakis, Luca Invernizzi, Alexandros Kapravelos, Steven Van Acker, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna
ACM conference on Computer and communications security, 2012
427 citationsEVILSEED: A Guided Approach to Finding Malicious Web Pages
Luca Invernizzi, UC Santa Barbara, Stefano Benvenuti, Marco Cova, Paolo Milani Comparetti, Christopher Kruegel, Giovanni Vigna
IEEE Symposium on Security & Privacy (S&P) and AT&T NYU CSAW best security paper '12 finalist, 2012
262 citationsMessage In A Bottle: Sailing Past Censorship
Luca Invernizzi, Christopher Kruegel, Giovanni Vigna
Annual Computer Security Applications Conference (ACSAC) and in HotPETS12 (workshop), 2012
50 citations2011
A geometric approach to trajectory design for an autonomous underwater vehicle: Surveying the bulbous bow of a ship
Ryan N Smith, Dario Cazzaro, Luca Invernizzi, Giacomo Marani, Song K Choi, Monique Chyba
Acta Applicandae Mathematicae, 2011
11 citations2010
Geometric control for autonomous underwater vehicles: overcoming a thruster failure
Michael Andonian, Dario Cazzaro, Luca Invernizzi, Monique Chyba, Sergio Grammatico
IEEE Conference on Decision and Control (CDC), 2010
17 citationsTrajectory design for autonomous underwater vehicles for basin exploration
Monique Chyba, D Cazzaro, L Invernizzi, M Andonian
International Conference on Computer and IT Applications in the Maritime Industries (COMPIT), 2010
5 citationsOpen Source
2024
WaseFire
WaseFire is a platform to build secure firmware in a usable way.
2023
UniSim
Package for efficiently computing similarity, performing fuzzy matching, deduplicating datasets, and clustering data.
2019
Keras Tuner
Tom O’Malley, Elie Bursztein, James Long, François Chollet, Haifeng Jin, Luca Invernizzi, G de Marmiesse, Y Fu, J Podivìn, F Schäfer
Research Areas
AI-generated summary of my research areas for a quick overview:
Machine Learning Security
Applying ML/AI to security problems like malware detection, file-type identification (Magika), side-channel analysis (SCAAML/GPAM), and abuse/fraud detection (CoinPolice, Giveaway Scams).
System and Network Security
Securing computer systems and networks, including large-scale malware analysis and distribution detection (Nazca, EvilSeed), vulnerability analysis (e.g., outdated libraries), botnet analysis (Mirai), and Android security.
Hardware Security
Analyzing and securing hardware components, focusing on side-channel vulnerabilities in cryptographic hardware (SCAAML/GPAM), security key architectures, post-quantum cryptography implementations, and secure firmware.
Privacy and Abuse Prevention
Protecting user privacy online and combating web abuse. Includes research on credential stuffing risks, cryptojacking, large-scale scam detection, and analysis of privacy policies like the "Right to be Forgotten".
Censorship Resistance
Developing and analyzing techniques to bypass internet censorship and ensure free communication.
Robotics / Autonomous Systems
Earlier work focused on control strategies for autonomous systems, particularly autonomous underwater vehicles (AUVs).