Marco De Vincenzi

Postdoctoral Associate, New York University — Secure Systems Lab.
Cybersecurity: Software supply chain security, Authentication for Cyber-Physical Systems (CPS).

Lab 370 Jay St, Brooklyn (New York)
email md6796 [at] nyu [dot] edu
elsewhere Google Scholar / GitHub

Research

Software supply chain security

Software depends on packages, build systems and repositories that are rarely inspected end to end. We work on cryptographically verifiable attestations and SBOMs that make this chain auditable and secure.

Authentication for vehicles and infrastructure

V2X communications let participants exchange messages without necessarily knowing who is physically behind them. We develop context-based and multi-channel authentication to bind messages to their physical origin, formally verify the protocols and explore additional identity factors.

Funded projects

2024–2027 SBOMit NSF POSE: Phase II: Building an Open-Source Ecosystem to Secure Software Bills of Materials.
2026 NSOC — NYU Software Supply Chain Security Operations Center. DTCC Research Program / NYU Center for Cybersecurity. Continuous monitoring of package ecosystems. Lead author of the funded proposal.

Selected publications

  1. Contextualizing Security and Privacy of Software-Defined Vehicles: A Literature Review and Industry Perspectives. ACM Computing Surveys, 2026.
  2. Vehicular Communication Security: Multi-Channel and Multi-Factor Authentication. IEEE Transactions on Vehicular Technology, 75(2), 2026.
  3. CARBUROS: A Formally Verified Authentication Protocol for V2X Communications. IEEE Access, 13, 2025.
  4. A Systematic Review on Security Attacks and Countermeasures in Automotive Ethernet. ACM Computing Surveys, 56(6), 2024.
  5. A privacy-preserving solution for intelligent transportation systems: Private driver DNA. IEEE Transactions on Intelligent Transportation Systems 24 (1), 2022.

Full list on Google Scholar.


Disclosures

Firmware vulnerabilities.

CVE-2023-26243Firmware decryption leaks keys, enabling custom firmware installation
CVE-2023-26244Signature bypass in firmware update via AppDMClient
CVE-2023-26245Version check bypass allows arbitrary firmware installation
CVE-2023-26246Signature check bypass enables installation of custom firmware

Background

2026–New York University (USA) — Postdoctoral Associate, Secure Systems Lab, Prof. Justin Cappos
2021–2026IIT — CNR, Pisa (Italy) — Research Scientist, Trust Security and Privacy unit
2024–2025Arizona State University ASU (USA) — Visiting Researcher, ARC Lab, Prof. Dajiang Suo
2023–2024Massachusetts Institute of Technology MIT (USA) — Visiting Researcher, Auto-ID Lab, Prof. Sanjay Sarma
2022–2026Ph.D. Computer Science, CNR / University of Pisa (Italy)
2021–2022Postgraduate Master in Cybersecurity & Critical Infrastructure Protection, University of Genoa (Italy)
2018–2020M.Sc. Data Science & Business Informatics, University of Pisa (Italy)
2015–2021Tier-1 Automotive supplier — Technical Operations

News

2026Program committee, USENIX VehicleSec ’26
Mar 2026Started at NYU Tandon, Secure Systems Lab