Institution profile

University of Cagliari

Academic institutioneurope · it
Official website
Research library120linked papers
Opportunities0open roles
Selected work

Representative Papers

A Neural Rejection System Against Universal Adversarial Perturbations in Radio Signal Classification

Dec 01, 2021Global Communications Conference

Universal adversarial perturbations (UAPs) severely degrade the robustness of deep classifiers for radio-frequency (RF) signals. Method: This paper proposes a neural rejection system that operates without modifying the original classifier. It introduces, for the first time in the RF domain, a neural rejection mechanism leveraging white-box UAP generation, confidence thresholding, and feature consistency verification to construct a lightweight, real-time adversarial sample detection and rejection module. The approach decouples detection from classification while preserving the original model architecture. Contribution/Results: Evaluated on multiple public RF datasets, the system reduces UAP attack success rates by over 60% and improves secure classification accuracy by more than 35%, significantly enhancing both model robustness and practical deployability.

2 citations1 influentialRead paper

Over-parameterization and Adversarial Robustness in Neural Networks: An Overview and Empirical Analysis

Jun 14, 2024arXiv.org

Prior studies report contradictory findings on how over-parameterization affects neural network adversarial robustness, partly due to inconsistent attack evaluation protocols. Method: We propose a unified empirical framework that jointly assesses both the reliability of mainstream adversarial attacks (e.g., PGD, FGSM) and model robustness under controlled experimental conditions, incorporating attack effectiveness diagnostics and rigorous ablation via controlled variables. Contribution/Results: Our analysis reveals—empirically for the first time—that prior conclusions attributing reduced robustness to over-parameterization are partially confounded by unreliable attacks. When validated, effective attacks are employed, over-parameterized networks consistently exhibit significantly enhanced adversarial robustness, with statistically significant and reproducible gains across diverse settings. This work resolves a key conceptual controversy and establishes a robust empirical foundation confirming over-parameterization as a genuine robustness-enhancing factor.

2 citationsRead paper

When Life Gives You AI, Will You Turn It Into A Market for Lemons? Understanding How Information Asymmetries About AI System Capabilities Affect Market Outcomes and Adoption

Jan 29, 2026

This study addresses the severe information asymmetry in the AI consumer market, which impedes users’ ability to identify low-quality systems, suppresses adoption, and undermines market efficiency. Through a simulated market experiment, the research systematically manipulates both the prevalence of low-quality AI systems and the depth of information disclosure, integrating behavioral experiments with Bayesian decision modeling to examine how information asymmetry affects user adoption decisions. The findings provide the first experimental evidence that moderate partial disclosure of system quality effectively mitigates the “lemons problem” in AI markets, significantly improving user decision quality and overall market efficiency. These results offer both theoretical grounding and practical guidance for designing effective information disclosure mechanisms in AI product markets.

1 citationsRead paper
Recent publications

Latest Papers

GitSkills: A Dataset of Agent Skills on GitHub

Aug 11, 2026

This study addresses the lack of systematic empirical research on the authoring, reuse, and maintenance of agent skills for large language models in GitHub repositories. To bridge this gap, we introduce GitSkills, a novel dataset comprising 3,797,117 SKILL.md files collected from 282,200 public repositories. After deduplication via content hashing, the dataset contains 1,877,981 unique skills, each preserving its full textual content, YAML front matter, directory structure, and associated repository metadata. GitSkills is the first large-scale, systematically curated collection of agent skills written in natural language, released in SQLite format to support reproducible research. It establishes a foundational resource for empirical studies at the intersection of software engineering and AI agents, enabling multidimensional analyses of skill adoption, reuse patterns, evolution, provenance, and security.

0 citationsRead paper

The Transformer Revolution, Part 1: Dynamic Processing through Output- Weight Interconnections

Aug 04, 2026

This work challenges the prevailing view of large language models as mere “stochastic parrots” by introducing the Sequence-level Interactive Dynamic Parallel Processing (SIDPP) framework, which conceptualizes Transformers as systems that dynamically generate transformation parameters from input prompts to perform concept-to-concept mappings. The framework incorporates an output-weight interconnection mechanism that reveals a strong prompt sensitivity—where dynamic processing capacity intensifies with longer prompts—and suggests a potential correspondence with human cortical language processing. Experimental results demonstrate that such dynamic processing can contribute comparably to, or even surpass, static processing in model performance. These findings not only open new avenues for model interpretability and controllability but also provide theoretical foundations for developing compact, efficient architectures and advancing our understanding of human language cognition.

0 citationsRead paper

Architectural Backdoors in Vision-Language Model Supply Chains via Representation Steering

Jul 28, 2026

This work addresses the security risks posed by widely reused, third-party visual language model (VLM) components in the AI supply chain, which constitute critical trust boundaries vulnerable to backdoor attacks. The paper introduces the first architecture-based, representation-guided backdoor mechanism that embeds trigger-controlled additive perturbations into intermediate representations—without contaminating training data or altering input prompts—to enable stealthy manipulation of downstream behaviors. This approach requires no retraining and successfully induces integrity violations, safety bypasses, and ranking biases across diverse tasks such as visual question answering, text-to-image generation, and retrieval, while preserving normal performance on clean inputs. The findings highlight the previously underappreciated risk that shared model artifacts can carry concealed, malicious logic.

0 citationsRead paper