Mobile-IoT security
MITHRAS
A dynamic-analysis framework that emulates IoT firmware, connects it to a real mobile companion app and captures execution traces across both sides of the ecosystem
Read the paper ↗AI for Software Engineering · Mobile Security & Privacy · Software Assurance
I develop AI-supported methods for testing, repairing and assuring software systems, with research spanning mobile vulnerability identification and exploitation, privacy-preserving Android systems, Mobile-IoT security, program analysis and hardware-rooted integrity verification. My work combines static and dynamic analysis, reinforcement learning and reproducible runtime evidence
I work across the software stack, from mobile applications to emulated firmware and hardware-rooted integrity, building methods that can be evaluated, replayed and reproduced
Mobile-IoT security
A dynamic-analysis framework that emulates IoT firmware, connects it to a real mobile companion app and captures execution traces across both sides of the ecosystem
Read the paper ↗Reliable hardware identity
Security protocols for IoT-device attestation and integrity verification, investigating stable hardware behaviour as a Physical Unclonable Function under real-world drift
Cross-platform analysis
A modular black-box static analyser for compiled Android and iOS applications, combining control-flow extraction and inter-procedural taint analysis across 77 vulnerability classes
Read the paper ↗Privacy-preserving systems
On-device anonymisation and Android virtualisation techniques that let users transform analytics data before it leaves their phone
Read the latest paper ↗Peer-reviewed work and publicly available research only. Use the filters to browse by output type
Francesco Pagano, Mariano Ceccato, Alessio Merlo, Paolo Tonella
Francesco Pagano, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Alessio Merlo, Giorgio Giacinto
Francesco Pagano, Mariano Ceccato, Alessio Merlo, Paolo Tonella
Luca Ferrari, Francesco Pagano, Luca Verderame, Alessio Merlo
Giacomo Longo, Francesco Lupia, Alessio Merlo, Francesco Pagano, Enrico Russo
Francesco Pagano, Luca Verderame, Enrico Russo, Alessio Merlo
Francesco Pagano
ProgrammeSecurity, Risk, and Vulnerability, Cybersecurity and Reliable AI curriculum
SupervisorsAlessio Merlo, Mariano Ceccato, and Paolo Tonella
External reviewers and committee membersSteven Arzt, Riccardo Scandariato, and Thorsten Holz
Francesco Pagano, Luca Verderame, Alessio Merlo
Francesco Pagano, Antonio Ruggia, Luca Verderame, Alessio Merlo
Francesco Pagano, Andrea Romdhana, Davide Caputo, Luca Verderame, Alessio Merlo
Davide Caputo, Francesco Pagano, Giovanni Bottino, Luca Verderame, Alessio Merlo
Francesco Pagano, Luca Verderame, Alessio Merlo
Workshop organisation, programme committees, artifact evaluation and peer review across software engineering and security
Co-initiator, co-organiser and Program Co-Chair of a workshop on transparency, reliability and assurance in automation and AI-assisted software engineering
Visit the RASE 2026 websiteESORICS 2026 · Rome
SAFER 2026 @ ARES · Linköping
SAFER 2025 @ ARES · Ghent
ACSAC 2024 · Honolulu
EuroSys 2023 · Rome
Selected implementations developed across my work on mobile privacy, application analysis and automated testing, with links to the available project repositories
An Android application that gives users per-app control over analytics data and anonymises personal, device and behavioural information before transmission
A research framework that protects and virtualises Android applications while anonymising Firebase Analytics events at runtime, with integrity controls and a Deep Reinforcement Learning testing pipeline
A modular and extensible black-box static application security testing tool that analyses compiled Android and iOS packages and produces unified vulnerability reports
The implementation supporting the gray-box penetration-testing approach that uses mobile companion apps and deep reinforcement learning to target vulnerability sinks in IoT devices
Conference talks, research presentations and my PhD defence. Each deck opens in a dedicated read-only viewer, and the presentation page also offers the original PowerPoint file for download
My teaching connects conceptual foundations with practical work in cybersecurity, mobile development, privacy and multimedia systems
Cybersecurity education
Lectures and hands-on cybersecurity challenges at the University of Verona node. I previously joined the programme as a competitor and reached the national Attack/Defense final with the University of Genoa team
University of Verona · 2026Course lecturer
Co-taught a 12-credit master’s course combining images, video, sound and 3D animation into one practical application
University of Verona · 2024/25Teaching assistant
Led practical sessions on anonymisation algorithms and guided students from first mobile-app concept to implementation
University of Genoa · 2021 to 2025Master’s and bachelor’s projects in IoT attestation, PUF-based integrity, mobile privacy, Android virtualisation and mobile application development
Slides and supporting materials from university courses, professional training, seminars and independently developed teaching activities, organised into complete learning units
Capture the Flag competitions are a long-running part of how I sharpen practical security skills, collaborate under pressure and stay close to the techniques used to analyse and exploit real systems
CTF player
I compete with the University of Genoa CTF team in Jeopardy and Attack/Defense events, with a particular interest in reverse engineering, binary exploitation and team-based problem solving
Visit ZenHackCompetitor
Selected for the 20-student University of Genoa team and then among the six students representing the university in the national Attack/Defense CTF final
Tutor
I now teach and support students through lectures, laboratories and practical cybersecurity challenges at the Verona node
University of Verona
AI for software engineering and assurance · NEUROPULSSoftware Institute, USI
Research with Paolo Tonella in LuganoUniversity of Genoa
Security, Risk, and VulnerabilityCsecLab, University of Genoa
Blockchain-enabled agricultural servicesI am always glad to exchange ideas around software security, automated testing, mobile-IoT ecosystems and reproducible research