| 2025 | RE | A First Appraisal of NIS2 and CRA Compliance Leveraging Open Source Tools. | Giovanni Corti, Gianluca Sassetti, Amir Sharif, Serena Elisa Ponta, Matteo Rizzi, Pietro De Matteis, Luca Piras, Roberto Carbone, Silvio Ranise |
| 2025 | SACMAT | Relying on Trust to Balance Protection and Performance in Cryptographic Access Control. | Simone Brunello, Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
| 2025 | SECRYPT | Enhancing National Digital Identity Systems: A Framework for Institutional and Technical Harm Prevention Inspired by Microsoft's Harms Modeling. | Giovanni Corti, Gianluca Sassetti, Amir Sharif, Roberto Carbone, Silvio Ranise |
| 2023 | DBSEC | Control is Nothing Without Trust a First Look into Digital Identity Wallet Trends. | Zahra Ebadi Ansaroudi, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
| 2023 | DBSEC | Assurance, Consent and Access Control for Privacy-Aware OIDC Deployments. | Gianluca Sassetti, Amir Sharif, Giada Sciarretta, Roberto Carbone, Silvio Ranise |
| 2022 | DBSEC | End-to-End Protection of IoT Communications Through Cryptographic Enforcement of Access Control Policies. | Stefano Berlato, Umberto Morelli, Roberto Carbone, Silvio Ranise |
| 2021 | DBSEC | Automated Risk Assessment and What-if Analysis of OpenID Connect and OAuth 2.0 Deployments. | Salimeh Dashti, Amir Sharif, Roberto Carbone, Silvio Ranise |
| 2021 | SECRYPT | Cryptographic Enforcement of Access Control Policies in the Cloud: Implementation and Experimental Assessment. | Stefano Berlato, Roberto Carbone, Silvio Ranise |
| 2020 | CCS | Exploring Architectures for Cryptographic Access Control Enforcement in the Cloud for Fun and Optimization. | Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
| 2020 | ESORICS | Micro-Id-Gym: A Flexible Tool for Pentesting Identity Management Protocols in the Wild and in the Laboratory. | Andrea Bisegna, Roberto Carbone, Giulio Pellizzari, Silvio Ranise |
| 2020 | ESORICS | Automated and Secure Integration of the OpenID Connect iGov Profile in Mobile Native Applications. | Amir Sharif, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
| 2019 | ESORICS | MuFASA: A Tool for High-level Specification and Analysis of Multi-factor Authentication Protocols. | Federico Sinigaglia, Roberto Carbone, Gabriele Costa, Silvio Ranise |
| 2017 | SAFECOMP | PolEnA: Enforcing Fine-grained Permission Policies in Android. | Gabriele Costa, Federico Sinigaglia, Roberto Carbone |
| 2017 | SECRYPT | Strong Authentication for e-Banking: A Survey on European Regulations and Implementations. | Federico Sinigaglia, Roberto Carbone, Gabriele Costa |
| 2016 | NDSS | Attack Patterns for Black-Box Security Testing of Multi-Party Web Applications. | Avinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca Compagna |
| 2016 | SECRYPT | Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution. | Giada Sciarretta, Alessandro Armando, Roberto Carbone, Silvio Ranise |
| 2015 | ICST | Security Threat Identification and Testing. | Roberto Carbone, Luca Compagna, Annibale Panichella, Serena Elisa Ponta |
| 2014 | SACMAT | Attribute based access control for APIs in spring security. | Alessandro Armando, Roberto Carbone, Eyasu Getahun Chekole, Silvio Ranise |
| 2014 | TACAS | SATMC: A SAT-Based Model Checker for Security-Critical Systems. | Alessandro Armando, Roberto Carbone, Luca Compagna |
| 2013 | NSS | Formal Modeling and Automatic Security Analysis of Two-Factor and Two-Channel Authentication Protocols. | Alessandro Armando, Roberto Carbone, Luca Zanetti |
| 2012 | TACAS | The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures. | Alessandro Armando, Wihem Arsac, Tigran Avanesov, Michele Barletta, Alberto Calvi, Alessandro Cappai, Roberto Carbone, Yannick Chevalier, Luca Compagna, Jorge Cullar, Gabriel Erzse, Simone Frau, Marius Minea, Sebastian Mdersheim, David von Oheimb, Giancarlo Pellegrino, Serena Elisa Ponta, Marco Rocchetto, Michal Rusinowitch, Mohammad Torabi Dashti, Mathieu Turuani, Luca Vigan |
| 2012 | TAP | From Model-Checking to Automated Testing of Security Protocols: Bridging the Gap. | Alessandro Armando, Giancarlo Pellegrino, Roberto Carbone, Alessio Merlo, Davide Balzarotti |
| 2011 | Middleware | Deploy, Adjust and Readjust: Supporting Dynamic Reconfiguration of Policy Enforcement. | Gabriela Gheorghe, Bruno Crispo, Roberto Carbone, Lieven Desmet, Wouter Joosen |
| 2011 | SEC | From Multiple Credentials to Browser-Based Single Sign-On: Are We More Secure? | Alessandro Armando, Roberto Carbone, Luca Compagna, Jorge Cullar, Giancarlo Pellegrino, Alessandro Sorniotti |
| 2010 | ICST | Model-Checking Driven Security Testing of Web-Based Applications. | Alessandro Armando, Roberto Carbone, Luca Compagna, Keqin Li, Giancarlo Pellegrino |
| 2008 | CCS | Formal analysis of SAML 2.0 web browser single sign-on: breaking the SAML-based single sign-on for google apps. | Alessandro Armando, Roberto Carbone, Luca Compagna, Jorge Cullar, Llanos Tobarra |