Selected as one of six fellows in the inaugural M3 cohort, an AI security research fellowship for senior security professionals run by Constellation, Kairos and AI Security Bootcamp (AISB). Will develop a self-directed project addressing an open problem in AI security, with peer review and feedback from field experts.
Founding Member & Senior Cybersecurity Research Engineer
CybPass Ltd., Sheffield, United Kingdom (Remote)
Led development of a proof-of-concept for an AI management product based on ISO/IEC 42001. The PoC demonstrated the product’s technical feasibility and supported the startup’s early-stage development ahead of its spin-out from The University of Sheffield. Translated ISO/SAE 21434 clauses covering Threat Analysis and Risk Assessment (TARA) into technical requirements for an automotive security product.
Led successful applications to DRIVE35 Mobilise and Cyber Runway Grow, a government-backed accelerator delivered by Plexal. The Mobilise project secured up to £173,500 to develop a tool for assessing the safety and security of AI systems and producing evidence for compliance with industry requirements.
Designed and developed a MetaDrive-based benchmark for training Reinforcement Learning attackers and evaluating adversarial manoeuvre attacks against autonomous-driving policies. Published the paper at USENIX VehicleSec'26 and released the benchmark as
.
Doctoral Researcher, Software Security
University of Catania, Catania, Italy
Formalised the fork-awareness property to characterise a fundamental limitation of coverage-guided fuzzing when the software under test (SUT) comprises multiple processes. Identified the limitation through an evaluation of 14 fuzzers.
Designed ForkFuzz, a fork-aware coverage-guided fuzzer built in C on top of Honggfuzz. It uses the Linux ptrace system call to monitor the process tree.
Co-designed LibAFLstar, a stateful protocol fuzzer built with Rust and LibAFL, and led target integration and experimental evaluation across six FTP, RTSP and HTTP implementations. Built the evaluation infrastructure with Docker and reconstructed the RTSP and HTTP state models through RFC analysis and network traffic captured with Wireshark. LibAFLstar ran over 30× faster and achieved 1.4× more coverage than AFLNet and ChatAFL on average.
Designed BenGQL, a benchmarking platform built with Bash and Docker for evaluating automated testing approaches across GraphQL applications. Designed KrakQL, a multi-agent tool built with Google ADK for blind GraphQL schema introspection. Across seven applications, KrakQL improved schema coverage by 140% while using 134× fewer HTTP requests than the state-of-the-art baseline.
AI & Data Engineer (Contract)
University of Catania, Department of Political and Social Sciences, Catania, Italy
Developed a Python document-processing pipeline using Mistral OCR and LangGraph-based LLM agents to extract and structure multilingual parliamentary questions and answers from historical scans of the Official Journal of the European Union, including French-only editions dating back to the 1950s.
Curated a dataset of more than 80,000 structured parliamentary questions for EUQuest, a PRIN 2022 project funded through the EU’s NextGenerationEU programme (CUP E53D23006720006), combining automated processing with targeted manual correction of OCR and extraction errors.
AI Agent Researcher (Contract)
RNDM, Manchester, United Kingdom (Remote)
Led the design and development of a LangGraph-based multi-agent system for DeFi lending-protocol analytics. Built the supporting data pipeline and Neo4j knowledge graph for GraphRAG retrieval.
Evaluated LLM-based time-series forecasting against established statistical models for DeFi interest-rate optimisation and found no reliable performance advantage.
Research Engineer, PECS Project
University of Catania, Catania, Italy
Developed the successful team proposal for the PECS project as part of the nas.inf research group, securing €117,000 through NGI TrustChain Open Call #2.
Reviewed Federated Learning (FL) approaches for automotive applications, then designed and implemented a user-empowered FL prototype using Flower, Python, Kotlin, Android Automotive and TensorFlow Lite, allowing users to opt out of distributed model training.
Evaluated the prototype on an engine-fault classification case study using EngineFaultDB. Published the resulting paper at IEEE Blockchain 2024 and released the implementation as
.
Visiting PhD Student
King's College London, London, United Kingdom
Conducted research under the supervision of Prof. Fabio Pierazzi on black-box security testing for GraphQL APIs using Deep Reinforcement Learning and fuzzing. Co-designed and developed Wendigo, a black-box approach that uses Proximal Policy Optimisation (PPO) and the target GraphQL schema to discover Denial-of-Service queries.
Evaluated Wendigo against EvoMaster, a state-of-the-art fuzzing tool for GraphQL APIs. Published the paper at the IEEE Workshop on Deep Learning Security and Privacy (DLSP), co-located with IEEE S&P 2024, and released the implementation as
.
Software Engineer & Technical Project Manager
Helpcode, Genoa, Italy (Remote)
Conceived, developed and launched a Flutter educational platform for The Water Code, enabling students aged 10 to 14 to apply computational thinking to environmental challenges. Built the backend using Firebase Authentication, Cloud Functions, Cloud Storage and a
.
Wrote the concept and proposal for the platform component of The Water Code, a €699,933 AICS-funded project delivered by a consortium of 10 organisations. Managed the development work and coordinated the graphic designer and storyteller using Jira.
Cybersecurity Programme Coordinator & Instructor
CINI Cybersecurity Lab UNICT Hub, Catania, Italy
Coordinated the University of Catania hub of CyberChallenge.IT, Italy’s national cybersecurity training and Capture-the-Flag (CTF) programme. Managed communications with central organisers, 5-7 tutors, classroom logistics and programme delivery for 25 participants per annual cohort.
Taught practical modules in Cryptography and Network Security, covering attacks against symmetric and asymmetric cryptographic schemes, network traffic and protocol analysis with Wireshark, and deployment of Docker containers for the local CTF infrastructure.
Research Engineer (Internship)
Robert Bosch GmbH, Renningen, Germany
Developed a coverage-guided fuzzing harness for shared-memory IPC, integrating Honggfuzz with QEMU user-mode plugins that intercepted system calls associated with POSIX and System V shared memory.
Applied the harness to Eclipse iceoryx and uncovered undisclosed bugs in RouDi, its central daemon for shared-memory management and service discovery. Passed the findings to the development team for triage and documented the work in the MSc dissertation “Shared Memory Fuzzing”.
Founding Member & Mobile Software Engineer
Codedix, Catania, Italy
Developed and released three native and cross-platform mobile applications for iOS and Android using Swift, Objective-C, Kotlin, Flutter and Dart. Applied MVC architecture and integrated Firebase services (Auth, Firestore, Cloud Storage).
Worked directly with clients to translate requirements into production releases and helped build Codedix’s initial mobile application portfolio before the company was incorporated.
Research Intern
Robert Bosch GmbH, Renningen, Germany (Remote)
Conducted a systematic review of 42 embedded-systems fuzzing papers and their associated tools, comparing techniques that tested software on physical hardware, emulated its execution environment, or abstracted hardware interactions.
Analysed selected techniques, documented their strengths and limitations, and contributed to the comparative table and identification of research gaps. Co-authored the resulting review, published in the Q1 Springer Nature journal Cybersecurity.
Teaching Assistant
University of Catania, Catania, Italy
Delivered in-depth lessons in the following modules: Programming Fundamentals: core programming concepts and problem-solving techniques (30 hours, Sep 2020); Programming 2: Object-Oriented Programming and Data Structures in C++, Complexity and Sorting Algorithms (30 hours, Sep 2020 and 25 hours, Mar-Jul 2024); Internet Security: fundamental security properties, protocols, firewall configuration, and malware taxonomy (25 hours, Apr-Jun 2021); and Fundamentals of Computer Science: Formal Languages, Computational Models, and Logic (25 hours, Mar-Jul 2024).
Education
PhD in Computer Science
University of Catania, Italy
Dissertation Title: Automation Challenges and Solutions in Coverage-Guided Fuzzing of Multiprocess Software Systems.
Erasmus+ Exchange Programme
University College Dublin, Ireland
Completed the following modules as an Erasmus+ exchange student: Deep Learning (COMP47650), Secure Software Engineering (COMP47910), Data Science in Python (COMP41680), Mobile App Dev - Cocoa Touch (COMP47390), and Advances in Wireless Networking (COMP40660).
MSc Computer Science
University of Catania, Italy
Thesis Title: Shared Memory Fuzzing. (Grade 110/110 with honours)
BSc Computer Science
University of Catania, Italy
Thesis Title: 3DCP Dynamic Domotic Device Configuration Protocol and Smart Hub. (Grade: 110/110 with honours)