The University of Southampton

Federica Paci

Academic Staff

Federica joined Electronics and Computer as Lecturer in Cyber Security in February 2015.  She received a PhD in Information Technology from the University of Milan in February 2008. Her PhD thesis focused on access control in service oriented architecture. She was post doctoral fellow at the Computer Science Department of Purdue University and at the Department of Information Engineering and Computer Science of the University of Trento. She published more than 60 contributions as papers in international conferences and journals, and chapters in international books. She also co-authored the book  Security for Web Services and Service Oriented Architectures edited by Springer


Research interests

Federica main research interests are in the area of data security and privacy with particular focus on access control for service-oriented applications, privacy-aware access control in social network, and privacy-preserving digital identity management. Her recent research interests focus on cloud computing security and empirical security.



MSc Computer Science, University of Milan (2004)

PhD in Information Technology, University of Milan (2008)


de Gramatica, Martina, Labunets, Katsiaryna, Massacci, Fabio, Paci, Federica and Tedeschi, Alessandra, (2015) The role of catalogues of threats and security controls in security risk assessment: an empirical study with ATM professionals Fricker, Samuel A. and Schneider, Kurt (eds.) At Requirements Engineering: Foundation for Software Quality (REFSQ), Germany. , pp. 98-114. (doi:10.1007/978-3-319-16101-3_7).

Paci, Federica and Zannone, Nicola (2015) Preventing information inference in access control At SACMAT 15 - 20th ACM Symposium on Access Control Models and Technologies, Austria. 01 - 03 Jun 2015. , pp. 87-97. (doi:10.1145/2752952.2752971).

Akeel, Fatmah, Salehi Fathabadi, Asieh, Paci, Federica, Gravell, Andy and Wills, Gary (2016) Formal modelling of data integration systems security policies Data Science and Engineering, 1, (3), pp. 139-148. (doi:10.1007/s41019-016-0016-y).

Sethi, Aneesha, Paci, Federica and Wills, Gary (2017) EEVi – framework for evaluating the effectiveness of visualization in cyber-security At The 11th International Conference for Internet Technology and Secured Transactions (ICITST-2016), Spain. 05 - 07 Dec 2016. 6 pp, pp. 340-345. (doi:10.1109/ICITST.2016.7856726).

Costante, Elisa, Paci, Federica and Zannone, Nicola (2013) Privacy-aware web service composition and ranking At 2013 IEEE International Conference on Web services (ICWS), United States. 08 Jun - 03 Jul 2013. , pp. 131-138. (doi:10.1109/ICWS.2013.27).

Labunets, Katsyarina, Massacci, Fabio, Paci, Federica and Tran, Le Minh Sang (2013) An experimental comparison of two risk-based security methods At 2013 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), United States. 10 - 11 Oct 2013. 10 pp. (doi:10.1109/ESEM.2013.29).

Labunets, Katsiaryna, Massacci, Fabio, Paci, Federica, Marczak, Sabrina and Moreira de Oliveira, Flavio (2017) Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representations Empirical Software Engineering, pp. 1-42. (doi:10.1007/s10664-017-9502-8).

Ferdous, Sadek, Margheri, Andrea, Paci, Federica and Sassone, Vladimiro (2017) Decentralised runtime monitoring for access control systems in cloud federations , Southampton, GB University of Southampton 11pp.

Labunets, Katsyarina, Massacci, Fabio and Paci, Federica (2016) On the equivalence between graphical and tabular representations for security risk assessment At 23rd Internationational Working Conference on Requirements Engineering: Foundations of Software Quality, Germany. 02 - 03 Feb 2017.

Sethi, Aneesha, Paci, Federica and Wills, Gary (2016) EEVi –Framework and Guidelines to Evaluate the Effectiveness of Cyber-Security Visualization the International Journal of Intelligent Computing Research (IJICR), 7, (4), pp. 761-770. (ijicr.2042.4655.2016.0094).

Alansari, Shorouq, Paci, Federica and Sassone, Vladimiro (2017) A distributed access control system for cloud federations At IEEE International Conference on Distributed Computing, Atlanta, United States. 05 - 08 Jun 2017. 6 pp.

Alansari, Shorouq, Paci, Federica, Margheri, Andrea and Sassone, Vladimiro (2017) Privacy-preserving access control in cloud federations At IEEE International Conference on Cloud Computing 2017, Honolulu, United States. 25 - 30 Jun 2017. 4 pp.

Gadyatskaya, Olga, Labunets, Katsiaryna and Paci, Federica (2016) Towards empirical evaluation of automated risk assessment methods At 11th International Conference on Risks and Security of Internet and Systems,, Roscoff, France. 05 - 07 Sep 2016. 9 pp.


Share this profile FacebookGoogle+TwitterWeibo

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.