Educational goals and objectives

Cybersecurity is an interdisciplinary field of study that has established itself in recent years as an evolution of the more traditional information security field. Classic problems in information security (such as software security, systems security, network security, cryptography, etc.) have been joined by other aspects that aim to grasp the complexity of modern threats and security concerns emerging in digital transformation processes: security of cyber-physical infrastructures, data governance, business resilience and human rights. For these reasons, cybersecurity today represents a research area with important multidisciplinary aspects, ranging from purely technological IT issues to aspects related to the control of data and information flows in complex socio-technical systems operating in a variety of settings such as healthcare, e-government, digital business, finance, logistics and energy. Cybersecurity also provides a promising field for advancing theories in many disciplines such as computer science, information systems, management, innovation, regulation and strategy. In fact, through critical reflections on emerging phenomena related to cybersecurity, scholars can challenge accepted views and underlying ideological and onto-epistemic assumptions to generate new theoretical insights from the empirical evidences.

The PhD in cybersecurity aims to train:
1) researchers capable of operating both in academia and in public and private research institutions for the development of new technologies and methodologies for cybersecurity;
2) specialists of the highest professional level with engineering and managerial skills capable of introducing technological and methodological innovation within the main application sectors of cybersecurity.

The multidisciplinary nature of this field of study is well represented by the composition of the doctoral college which leverages expert professors from multiple scientific sectors.

The research areas of main interest for the doctorate are:
- Systems security
- Software security
- Hardware security
- Network security
- Cryptography
- Cyber ​​risk management
- Data privacy and security
- Security governance
- Security in supply chains
- Security operations
- Economics of cybersecurity
- High-reliable organizing
- Information warfare

These issues are also addressed in their application to specific sectors such as the financial one, TLC, critical infrastructures, cloud services, e-government, health, manufacturing.

* Dopo la pubblicazione del bando sono state formalizzate 4 borse finanziate dall'AGENZIA PER LA CYBERSICUREZZA NAZIONALE su specifiche tematiche: 1) "YOSO MPC at Scale" - Supervisore: Prof. Daniele Venturi - Abstract: Secure Multiparty Computation (MPC) allows mutually distrustful parties to jointly compute a function on their inputs privately, revealing only the output. This project aims to develop new MPC protocols for massively distributed contexts with dynamic participation, such as blockchains and machine learning. The emerging YOSO framework, where participants only engage briefly, allows lower-resource parties to contribute, democratizing private computation. Current YOSO protocols, however, have limitations, such as requiring a strong honest majority and being inefficient for specific tasks. The project seeks to design more efficient YOSO protocols for concrete functions, tolerating higher corruption thresholds.; 2) "Modelli di binary similarity per la rivelazioni di vulnerabilità in firmware e binari resistenti ad attacchi avversari" - Supervisore: Prof. Giuseppe Antonio Di Luna - Abstract: The Internet of Things (IoT) revolution is introducing many smart devices into various sectors, but they often lack security due to firmware vulnerabilities, posing risks to users and society. This research project aims to use neural networks to identify vulnerabilities in real software, optimize their performance, and enhance their resilience to adversarial attacks. The project will focus on comparing current models, evaluating their resistance to attacks, and developing a robust binary similarity model over three years.; 3) "Attacchi e Sicurezza nei Foundation Models" - Supervisore: Prof. Giuseppe Francesco Italiano - Abstract: Foundation Models (FMs) are versatile machine learning models used in applications like image recognition, medical diagnosis, and generative AI. They leverage deep learning, are trained on vast datasets, and are complex, making them vulnerable to various security threats. This research aims to understand and mitigate these vulnerabilities, focusing on adversarial attacks, data poisoning, and prompt injection, to ensure the models' reliability and safety.; 4) "SPoND: Security and Privacy of Networks of Drones" - Supervisore: Prof. Riccardo Lazzeretti - Abstract: Unmanned Aircraft Vehicles (UAVs), or drones, are significantly impacting the European economy and society due to their versatility, technological advancements, and cost reductions. Initially developed for military purposes, drones have gained popularity in commercial and public sectors, and their use is expected to grow in areas like transport and services. The project aims to address security and privacy issues in drone networks with innovative solutions such as secure cooperation protocols, device identification and authorization, detection of compromised devices, and dynamic firmware analysis.
Themes, curriculum and specific competence

Admission Procedure

Qualifications assessment The admission committee assigns to each candidate a maximum score of 60 points. Scores are assigned according to the following evaluation criteria:
- up to 30 points for the evaluation of the curriculum (including the academic career and any other qualifications), the letters of recommendations supporting the candidate (max 2 letters) and the publications presented by the candidate;
- up to 30 points for the research proposal submitted by the candidate. In particular, the commission evaluates the description of the state of the art, the originality and the innovative nature of the proposal, the clarity and completeness of the objectives, the methodologies and the potential results, the relevance of the proposal with respect to the topics and objectives of the Ph.D. program. Candidates obtaining a minimum score of 36/60 in the evaluation of qualifications and of the research proposal are admitted to the oral interview.

Oral interview The admission committee assigns a maximum of 60 points to each candidate admitted to the interview. The interview is in English, and is aimed at assessing the candidates' knowledge, skills, and aptitude to carry out research in the scientific areas of Cybersecurity. The interview also includes a discussion of the research proposal prepared by the candidate and of personal motivations for applying for a Ph. D. position. The duration of the interview is at most 45 minutes (the presentation of the research proposal by the candidate must be no longer than 15 minutes; slides are allowed). The minimum overall score for admission to the Ph.D. in Cybersecurity is 72/120.
Required documentation

The research proposal must be written in English in accordance with the following template:

Applicant's first name ......... last name ............... Proposal title: ............
Area (select at most two areas of interest from the following list) [ ] System security
[ ] Software security
[ ] Hardware security
[ ] Network security
[ ] Cryptography
[ ] Cyber risk management
[ ] Data security and privacy
[ ] Security governance
[ ] Supply chain security
[ ] Security operations
[ ] Cybersecurity economy
[ ] Highly-reliable organisations
[ ] Disinformation
[ ] Other (specify): .....

***Summary of proposal***
(maximum 1000 characters, including spaces)
Brief summary of the research project, highlighting problem statement, motivations, objectives, original content.

***State of the art of the research field***
(maximum 2.000 characters, including spaces)

***Research objectives, content, and methodology***
(maximum 8.000 characters, including spaces)
Detailed description of the research project, emphasising original and innovative aspects and scientific relevance.

***Results, impact, and benefits***
(maximum 8.000 characters, including spaces)
Detailed description of the expected results, advancements, impacts and benefits.
