| 2026 | SP | LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services. | Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal, Stefano Calzavara, Ben Stock |
| 2025 | DSN | Less is More: Boosting Coverage of Web Crawling through Adversarial Multi-Armed Bandit. | Lorenzo Cazzaro, Stefano Calzavara, Maksim Kovalkov, Aleksei Stafeev, Giancarlo Pellegrino |
| 2025 | EDBT | Watermarking Decision Tree Ensembles. | Stefano Calzavara, Lorenzo Cazzaro, Donald Gera, Salvatore Orlando |
| 2025 | WWW | Dynamic Security Analysis of JavaScript: Are We There Yet? | Stefano Calzavara, Samuele Casarin, Riccardo Focardi |
| 2025 | SP | Verifiable Boosted Tree Ensembles. | Stefano Calzavara, Lorenzo Cazzaro, Claudio Lucchese, Giulio Ermanno Pibiri |
| 2023 | CCS | Verifiable Learning for Robust Tree Ensembles. | Stefano Calzavara, Lorenzo Cazzaro, Giulio Ermanno Pibiri, Nicola Prezza |
| 2023 | CCS | You Call This Archaeology? Evaluating Web Archives for Reproducible Web Security Measurements. | Florian Hantke, Stefano Calzavara, Moritz Wilhelm, Alvise Rabitti, Ben Stock |
| 2021 | AsiaCCS | AMEBA: An Adaptive Approach to the Black-Box Evasion of Machine Learning Models. | Stefano Calzavara, Lorenzo Cazzaro, Claudio Lucchese |
| 2021 | NDSS | Reining in the Web's Inconsistencies with Site Policy. | Stefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens, Ben Stock |
| 2021 | SP | The Remote on the Local: Exacerbating Web Attacks Via Service Workers Caches. | Marco Squarcina, Stefano Calzavara, Matteo Maffei |
| 2020 | ESORICS | Certifying Decision Trees Against Evasion Attacks by Program Analysis. | Stefano Calzavara, Pietro Ferrara, Claudio Lucchese |
| 2020 | ESORICS | Bulwark: Holistic and Verified Security Monitoring of Web Protocols. | Lorenzo Veronese, Stefano Calzavara, Luca Compagna |
| 2020 | NDSS | Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies. | Sebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis, Ben Stock |
| 2019 | CIKM | Adversarial Training of Gradient-Boosted Decision Trees. | Stefano Calzavara, Claudio Lucchese, Gabriele Tolomei |
| 2019 | ESORICS | Testing for Integrity Flaws in Web Sessions. | Stefano Calzavara, Alvise Rabitti, Alessio Ragazzo, Michele Bugliesi |
| 2019 | FORTE | Semantically Sound Analysis of Content Security Policies. | Stefano Calzavara, Alvise Rabitti, Michele Bugliesi |
| 2019 | SP | Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem. | Stefano Calzavara, Riccardo Focardi, Mats Nemec, Alvise Rabitti, Marco Squarcina |
| 2018 | WWW | Surviving the Web: A Journey into Web Session Security. | Stefano Calzavara, Riccardo Focardi, Marco Squarcina, Mauro Tempesta |
| 2016 | CCS | Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the Wild. | Stefano Calzavara, Alvise Rabitti, Michele Bugliesi |
| 2015 | ESOP | Fine-Grained Detection of Privilege Escalation Attacks on Browser Extensions. | Stefano Calzavara, Michele Bugliesi, Silvia Crafa, Enrico Steffinlongo |
| 2014 | ICISS | Client Side Web Session Integrity as a Non-interference Property. | Wilayat Khan, Stefano Calzavara, Michele Bugliesi, Willem De Groef, Frank Piessens |
| 2014 | WWW | Quite a mess in my cookie jar!: leveraging machine learning to protect web authentication. | Stefano Calzavara, Gabriele Tolomei, Michele Bugliesi, Salvatore Orlando |
| 2013 | FORTE | Lintent: Towards Security Type-Checking of Android Applications. | Michele Bugliesi, Stefano Calzavara, Alvise Span |