Marino Miculan
Full Professor · Head & founder
Security of protocols and industrial systems, formal models of concurrency, bigraphs
Breaking and fixing real systems: security of protocols, networks and industrial devices, from formal verification to hands-on vulnerability research.
Autonomous and embedded systems are now part of factories, vehicles and critical infrastructures, where a single vulnerability can have physical consequences. Yet their security assessment is often less mature than that of traditional IT.
Research in the Cybersecurity area studies how to protect resources and information in these settings. On the formal side, we model and verify security protocols, such as multi-factor authentication schemes, to discover subtle flaws. On the practical side, we analyse real devices and networks together with industrial partners. This work has led to vulnerability disclosures such as CVE-2022-3203 and CVE-2023-40718.
The MADS lab hosts the Udine node of the Cybersecurity National Lab of CINI, the Italian National Inter-University Consortium for Informatics. Through the national lab we take part in training programmes for young talents, such as CyberChallenge.IT and CyberHighSchools. These programmes gave birth to MadrHacks, the ethical hacking team of the University of Udine.
Students in this area work with real hardware and real attack scenarios, in a lab environment and always following responsible disclosure practices.
Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026), CEUR Workshop Proceedings 4198 · CEUR-WS.org · 2026
@inproceedings{clmpm:itasec26,
groups = {cybersecurity},
author = {Coppo, Cristian and Longo, Francesco and Merlino, Giovanni and Puliafito, Antonio and Marino Miculan},
editor = {Davide Maiorca and Pierangela Samarati},
title = {Automatic Verification of Security Properties in Containerized {IoT} Applications via Bigraphical Modeling},
booktitle = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)},
location = {Cagliari, Italy, February 09-13, 2026},
series = {{CEUR} Workshop Proceedings},
volume = 4198,
publisher = {CEUR-WS.org},
year = 2026,
pdf = {https://ceur-ws.org/Vol-4198/paper59.pdf},
html = {https://ceur-ws.org/Vol-4198}
}Proceedings of the 23rd International Conference on Security and Cryptography - SECRYPT · SciTePress · 2026
@inproceedings{mpp:secrypt26,
groups = {cybersecurity},
author = {Marino Miculan and Matteo Paier and Jacopo Plozner},
title = {Experimental Evaluation of Lightweight Encryption Algorithms on 16-bit Microcontrollers},
booktitle = {Proceedings of the 23rd International Conference on Security and Cryptography - SECRYPT},
year = {2026},
publisher = {SciTePress},
organization = {INSTICC},
doi = {10.5220/0015189200004103},
html = {https://doi.org/10.5220/0015189200004103},
Pdf = {https://marino.miculan.org/assets/pdf/2026-SECRYPT.pdf},
}Software and Systems Modeling · 2026
@Article{PVM:sosym26,
groups = {cybersecurity},
author = {Paier, Matteo and Van Eeden, Roberto L. G. and Miculan, Marino},
title = {Formal modelling and verifying {eIDAS} multi-factor authentication with interface-based threat analysis},
journal = {Software and Systems Modeling},
year = {2026},
doi = {10.1007/s10270-026-01375-9},
html = {https://doi.org/10.1007/s10270-026-01375-9},
pdf = "https://link.springer.com/content/pdf/10.1007/s10270-026-01375-9.pdf",
selected = true,
}Proceedings of the 27th Italian Conference on Theoretical Computer Science (ICTCS 2026), CEUR Workshop Proceedings 4269 · CEUR-WS.org · 2026
@inproceedings{bpm:ictcs26,
groups = {cybersecurity},
author = {Baldo, Massimiliano and Paier, Matteo and Miculan, Marino},
title = {Policy Automata for Stateful Authorization},
booktitle = {Proceedings of the 27th Italian Conference on Theoretical Computer Science (ICTCS 2026)},
location = {Udine, Italy, September 07-09, 2026},
series = {{CEUR} Workshop Proceedings},
volume = 4269,
publisher = {CEUR-WS.org},
year = 2026,
pdf = {https://ceur-ws.org/Vol-4269/paper45.pdf},
html = {https://ceur-ws.org/Vol-4269}
}Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026), CEUR Workshop Proceedings 4198 · CEUR-WS.org · 2026
@inproceedings{efmd:itasec26,
groups = {cybersecurity},
author = {Ejeh, Dennis Glenn and Foresti, Gian Luca and Marino Miculan and De Nardin, Axel},
editor = {Davide Maiorca and Pierangela Samarati},
title = {{SA-SOINN}: A Self-Adaptive Neural Network for Continuous Intrusion Detection in Dynamic Environments},
booktitle = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)},
location = {Cagliari, Italy, February 09-13, 2026},
series = {{CEUR} Workshop Proceedings},
volume = 4198,
publisher = {CEUR-WS.org},
year = 2026,
pdf = {https://ceur-ws.org/Vol-4198/paper2.pdf},
html = {https://ceur-ws.org/Vol-4198}
}Journal of Software: Evolution and Process 38(8), pp. e70159 · 2026
@Article{lpmr:smr26,
groups = {cybersecurity},
author = {Lizzit, Michele and Pinzauti, Francesco and Miculan, Marino and Riccio, Vincenzo},
title = {Security Assessment of Private Package Repositories: An Experience on {Acc-Py} at {CERN}},
journal = {Journal of Software: Evolution and Process},
year = {2026},
volume = {38},
number = {8},
pages = {e70159},
doi = {10.1002/smr.70159},
html = {https://doi.org/10.1002/smr.70159},
pdf = {https://onlinelibrary.wiley.com/doi/pdf/10.1002/smr.70159},
issn = {2047-7473},
}Proceedings of the 31st ACM Symposium on Access Control Models and Technologies (SACMAT '26), pp. 205–216 · Association for Computing Machinery · 2026
@inproceedings{bdpm:sacmat26,
groups = {cybersecurity},
author = {Baldo, Massimiliano and Di Gianantonio, Pietro and Paier, Matteo and Miculan, Marino},
title = {Strobilus: Enriching {Cedar} with Stateful Policies},
booktitle = {Proceedings of the 31st {ACM} Symposium on Access Control Models and Technologies (SACMAT '26)},
location = {Waterloo, ON, Canada, July 08-10, 2026},
publisher = {Association for Computing Machinery},
year = 2026,
month = jul,
pages = {205--216},
doi = {10.1145/3750555.3811892},
html = {https://doi.org/10.1145/3750555.3811892},
pdf = {https://marino.miculan.org/assets/pdf/2026-SACMAT.pdf},
code = {https://github.com/strobilus-lang/strobilus-tinytodo-example},
isbn = {979-8-4007-2107-6},
selected = true,
}Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025), CEUR Workshop Proceedings 3962 · CEUR-WS.org · 2025
@inproceedings{bimpr:itasec25,
groups = {cybersecurity},
author = {Massimiliano Baldo and Ion, Fabio Ionut and Marino Miculan and Matteo Paier and Vincenzo Riccio},
editor = {Gabriele Costa and Rebecca Montanari and Michele Carminati and Giada Sciarretta},
title = {OWSM: Empowering Rego for Stateful Access Control},
booktitle = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025)},
location = {Bologna, Italy, February 3-8, 2025},
series = {{CEUR} Workshop Proceedings},
volume = 3962,
publisher = {CEUR-WS.org},
year = 2025,
pdf = {https://ceur-ws.org/Vol-3962/paper49.pdf},
html = {https://ceur-ws.org/Vol-3962}
}Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025), CEUR Workshop Proceedings 3962 · CEUR-WS.org · 2025
@inproceedings{gfmd:itasec25,
groups = {cybersecurity},
author = {Ejeh, Dennis Glenn and Foresti, Gian Luca and Marino Miculan and De Nardin, Axel},
editor = {Gabriele Costa and Rebecca Montanari and Michele Carminati and Giada Sciarretta},
title = {Real-Time Anomaly Detection in Docker Containers: A Continuous Learning Approach Using {SF-SOINN}},
booktitle = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025)},
location = {Bologna, Italy, February 3-8, 2025},
series = {{CEUR} Workshop Proceedings},
volume = 3962,
publisher = {CEUR-WS.org},
year = 2025,
pdf = {https://ceur-ws.org/Vol-3962/paper45.pdf},
html = {https://ceur-ws.org/Vol-3962}
}Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT, pp. 483-491 · SciTePress · 2024
@inproceedings{vepm:secrypt24,
groups = {cybersecurity},
author={Van Eeden, Roberto and Matteo Paier and Marino Miculan},
title={A Formal Analysis of {CIE} Level 2 Multi-Factor Authentication via {SMS OTP}},
booktitle={Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT},
year={2024},
pages={483-491},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012768300003767},
html = {https://doi.org/10.5220/0012768300003767},
isbn={978-989-758-709-2},
issn={2184-7711},
}Full Professor · Head & founder
Security of protocols and industrial systems, formal models of concurrency, bigraphs
MSc student, AI & Cybersecurity
MSc student, AI & Cybersecurity
Finding failures before users do: automated test generation and quality assurance for complex software, AI-based and self-adaptive systems.
Correct by construction: choreographic languages, types and formal models for coordinating fleets of autonomous, distributed agents.