Postdoctoral Research Fellow · University of Verona

Francesco Pagano

AI for Software Engineering · Mobile Security & Privacy · Software Assurance

I develop AI-supported methods for testing, repairing and assuring software systems, with research spanning mobile vulnerability identification and exploitation, privacy-preserving Android systems, Mobile-IoT security, program analysis and hardware-rooted integrity verification. My work combines static and dynamic analysis, reinforcement learning and reproducible runtime evidence

Based inVerona, Italy
PhDComputer EngineeringSecurity, Risk, and Vulnerability
Selected research

Systems that turn analysis into evidence

I work across the software stack, from mobile applications to emulated firmware and hardware-rooted integrity, building methods that can be evaluated, replayed and reproduced

01

Mobile-IoT security

MITHRAS

A dynamic-analysis framework that emulates IoT firmware, connects it to a real mobile companion app and captures execution traces across both sides of the ecosystem

Firmware emulationExecution tracingFSE 2025
Read the paper
02

Reliable hardware identity

NEUROPULS

Security protocols for IoT-device attestation and integrity verification, investigating stable hardware behaviour as a Physical Unclonable Function under real-world drift

Device attestationPUFsHorizon Europe
03

Cross-platform analysis

SEBASTiAn

A modular black-box static analyser for compiled Android and iOS applications, combining control-flow extraction and inter-procedural taint analysis across 77 vulnerability classes

Static analysisMobile securitySoftwareX
Read the paper
04

Privacy-preserving systems

HideDroid family

On-device anonymisation and Android virtualisation techniques that let users transform analytics data before it leaves their phone

Data anonymisationVirtualisationPrivacy
Read the latest paper
Research output

Publications

Peer-reviewed work and publicly available research only. Use the filters to browse by output type

12 visible outputs
2026
Journal articleJSS

Multi-Agent Deep Reinforcement Learning for Penetration Testing of IoT Devices Through Their Mobile Companion App

Francesco Pagano, Mariano Ceccato, Alessio Merlo, Paolo Tonella

2026
Public preprintarXiv

Obfuscating Code Vulnerabilities Against Static Analysis in JavaScript Code

Francesco Pagano, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Alessio Merlo, Giorgio Giacinto

2025
Conference paperFSE Companion

MITHRAS: A Dynamic Analysis Framework for the Mobile-IoT Ecosystem

Francesco Pagano, Mariano Ceccato, Alessio Merlo, Paolo Tonella

2025
Conference paperEuroS&PW

The OWApp Benchmark: An OWASP-Compliant Vulnerable Android App Dataset

Luca Ferrari, Francesco Pagano, Luca Verderame, Alessio Merlo

2025
Journal articleInformation Sciences

A Data Anonymization Methodology for Security Operations Centers

Giacomo Longo, Francesco Lupia, Alessio Merlo, Francesco Pagano, Enrico Russo

2025
Journal articleComputers & Electrical Engineering

MarvelHideDroid: Reliable on-the-fly Data Anonymization Based on Android Virtualization

Francesco Pagano, Luca Verderame, Enrico Russo, Alessio Merlo

2025
Doctoral thesisUniversity of GenoaMarch 2025

Dealing with Security and Privacy Challenges in Android Through App Code Analysis

Francesco Pagano

ProgrammeSecurity, Risk, and Vulnerability, Cybersecurity and Reliable AI curriculum

SupervisorsAlessio Merlo, Mariano Ceccato, and Paolo Tonella

External reviewers and committee membersSteven Arzt, Riccardo Scandariato, and Thorsten Holz

2024
Conference paperIFIP SEC

Obfuscating Code Vulnerabilities Against Static Analysis in Android Apps

Francesco Pagano, Luca Verderame, Alessio Merlo

2023
Conference paperMobiSec

VirtualHideDroid: User Data Anonymization Through Virtualization Techniques

Francesco Pagano, Antonio Ruggia, Luca Verderame, Alessio Merlo

2023
Journal articleSoftwareX

SEBASTiAn: A Static and Extensible Black-box Application Security Testing Tool for iOS and Android Applications

Francesco Pagano, Andrea Romdhana, Davide Caputo, Luca Verderame, Alessio Merlo

2022
Journal articleIEEE TDSC

You Can’t Always Get What You Want: Towards User-Controlled Privacy on Android

Davide Caputo, Francesco Pagano, Giovanni Bottino, Luca Verderame, Alessio Merlo

2021
Journal articleJoWUA

Understanding Fuchsia Security

Francesco Pagano, Luca Verderame, Alessio Merlo

Academic service

Contributing to the research community

Workshop organisation, programme committees, artifact evaluation and peer review across software engineering and security

Workshop organisationASE 2026 · Munich
RASE

Reliable and trustworthy Automated Software Engineering

Co-initiator, co-organiser and Program Co-Chair of a workshop on transparency, reliability and assurance in automation and AI-assisted software engineering

Visit the RASE 2026 website
Organised with Gregorio Dalia, Leonardo Regano, Corrado Visaggio, Sebastiano Panichella, Andrea Di Sorbo and Alessandro Sanna
2026

Program Committee

ESORICS 2026 · Rome

2026

Program Committee

SAFER 2026 @ ARES · Linköping

2025

Program Committee

SAFER 2025 @ ARES · Ghent

2024

Artifacts Evaluation Committee

ACSAC 2024 · Honolulu

2023

Shadow Program Committee

EuroSys 2023 · Rome

Journal reviewing
IEEE TSEIEEE TDSCIEEE TIFSComputers & SecurityJournal of Systems and SoftwareInformation and Software TechnologySoftwareXComputer Standards & Interfaces
Open-source tools

Research tools and prototypes

Selected implementations developed across my work on mobile privacy, application analysis and automated testing, with links to the available project repositories

HDAndroid · Privacy

HideDroid

An Android application that gives users per-app control over analytics data and anonymises personal, device and behavioural information before transmission

AndroidData anonymisationLocal differential privacy
HideDroid stars on GitHub HideDroid forks on GitHub
MHAndroid · Virtualisation

MarvelHideDroid

A research framework that protects and virtualises Android applications while anonymising Firebase Analytics events at runtime, with integrity controls and a Deep Reinforcement Learning testing pipeline

Android virtualisationRuntime anonymisationDynamic testing
SBPython · Static analysis

SEBASTiAn

A modular and extensible black-box static application security testing tool that analyses compiled Android and iOS packages and produces unified vulnerability reports

Android and iOSSASTExtensible plugins
SEBASTiAn stars on GitHub SEBASTiAn forks on GitHub
MIPython · Deep reinforcement learning

MITHRAS

The implementation supporting the gray-box penetration-testing approach that uses mobile companion apps and deep reinforcement learning to target vulnerability sinks in IoT devices

IoT penetration testingMulti-agent DRLTest generation
Teaching & mentoring

Helping students build, test and question technology

My teaching connects conceptual foundations with practical work in cybersecurity, mobile development, privacy and multimedia systems

01

Cybersecurity education

CyberChallenge.IT Tutor

Lectures and hands-on cybersecurity challenges at the University of Verona node. I previously joined the programme as a competitor and reached the national Attack/Defense final with the University of Genoa team

University of Verona · 2026
02

Course lecturer

Informatics & Multimedia Production

Co-taught a 12-credit master’s course combining images, video, sound and 3D animation into one practical application

University of Verona · 2024/25
03

Teaching assistant

Privacy & Mobile Programming

Led practical sessions on anonymisation algorithms and guided students from first mobile-app concept to implementation

University of Genoa · 2021 to 2025
Supervision

Thesis co-advising

Master’s and bachelor’s projects in IoT attestation, PUF-based integrity, mobile privacy, Android virtualisation and mobile application development

Master’s · VeronaMaster’s · GenoaBachelor’s · Genoa
CTF & hands-on security

Security practice beyond the research lab

Capture the Flag competitions are a long-running part of how I sharpen practical security skills, collaborate under pressure and stay close to the techniques used to analyse and exploit real systems

ZenHack logo Genoa · Since 2020

CTF player

ZenHack

I compete with the University of Genoa CTF team in Jeopardy and Attack/Defense events, with a particular interest in reverse engineering, binary exploitation and team-based problem solving

Reverse engineeringBinary exploitationJeopardyAttack/Defense
Visit ZenHack
2020

Competitor

CyberChallenge.IT national final

Selected for the 20-student University of Genoa team and then among the six students representing the university in the national Attack/Defense CTF final

2026

Tutor

CyberChallenge.IT · University of Verona

I now teach and support students through lectures, laboratories and practical cybersecurity challenges at the Verona node

Current CyberChallenge.IT programme
Academic path

From mobile privacy to connected-system assurance

2025 to present

Postdoctoral Research Fellow

University of Verona

AI for software engineering and assurance · NEUROPULS
2023 to 2024

Visiting PhD Student

Software Institute, USI

Research with Paolo Tonella in Lugano
2021 to 2025

PhD in Computer Engineering

University of Genoa

Security, Risk, and Vulnerability
Cybersecurity and Reliable AI curriculum
2021

Research Fellow

CsecLab, University of Genoa

Blockchain-enabled agricultural services
Let’s connect

Interested in secure software systems, AI-assisted assurance or research collaboration?

I am always glad to exchange ideas around software security, automated testing, mobile-IoT ecosystems and reproducible research