VLDB 2026 Research / reviewers in the wild / expert
Sunpreet S. Arora
dblp:118/1516 · also Sunpreet Singh Arora
· DBLP profile ↗
15ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0001-9761-3580ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The 2FA Illusion: Uncovering Weak Links of Web Account Access in the WildabstractSingle-factor authentication (1FA) and two-factor authentication (2FA) for secure and reliable website account access have become everyday tasks for most users. However, the complexity of integrating 1FA, 2FA, and password reset mechanisms makes real-world deployments challenging to navigate, leaving key questions about their implications for account security and accessibility unanswered. In this paper, we present a comprehensive investigation into the deployment of 1FA, 2FA, and password reset mechanisms across 50 major websites in six industries. By formally modeling account access and password reset patterns and applying Karnaugh maps for logical optimization, we uncover surprising consequences of current integrations of authentication mechanisms. We present key findings on the implications of modern authentication integrations for account security and accessibility, highlighting both the overestimated strengths and overlooked weaknesses of current deployments. Our research aims to provide a valuable and practical understanding of real-world authentication deployments for advancing web authentication practices. Ke Coby Wang, Sunpreet S. Arora, Michael K. Reiter |
ACSAC | 2 |
| 2025 | A Composability Analysis Framework for Web3 Wallet Recovery MechanismsabstractModern Web3 wallets offer hybrid recovery solutions that combine multiple key recovery methods to balance security, availability, and usability. These methods include secret sharing of wallet private keys, encrypted cloud storage, and smart contract-based advanced recovery functionalities. However, such combined approaches can introduce new attack vectors that are not present in standalone recovery solutions. In this work, we propose a formal security analysis frame-work for blockchain/Web3 wallet designs with key or asset recovery functionalities. To assess whether a wallet design is secure, our framework considers several factors, including user availability and responsiveness to malicious actions, co-custodianship with external parties, the total value of assets managed by the wallet, and the reputation of the entities chosen by the user to facilitate spending or recovery functionalities. Through probabilistic model checking, our framework identifies the conditions under which a wallet design remains secure. We also include two examples of Web3 wallet designs with composite recovery mechanisms (inspired by existing designs) to demonstrate the effectiveness of our framework. Panagiotis Chatzigiannis, Ke Coby Wang, Sunpreet S. Arora, Mohsen Minaei |
SP | 3 |
| 2025 | Detecting Compromise of Passkey Storage on the Cloud
Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Ke Coby Wang |
USENIX Security Symposium | 2 |
| 2024 | Compact: Approximating Complex Activation Functions for Secure ComputationabstractSecure multi-party computation (MPC) techniques can be used to provide data privacy when users query deep neural network (DNN) models hosted on a public cloud. State-of-the-art MPC techniques can be directly leveraged for DNN models that use simple activation functions (AFs) such as ReLU. However, these techniques are ineffective and/or inefficient for the complex and highly non-linear AFs used in cutting-edge DNN models. We present Compact, which produces piece-wise polynomial approximations of complex AFs to enable their efficient use with state-of-the-art MPC techniques. Compact neither requires nor imposes any restriction on model training and results in near-identical model accuracy. To achieve this, we design Compact with input density awareness, and use an application specific simulated annealing type optimization to generate computationally more efficient approximations of complex AFs. We extensively evaluate Compact on four different machine-learning tasks with DNN architectures that use popular complex AFs silu, gelu, and mish. Our experimental results show that Compact incurs negligible accuracy loss while being 2x-5x computationally more efficient than state-of-the-art approaches for DNN models with large number of hidden layers. Our work accelerates easy adoption of MPC techniques to provide user data privacy even when the queried DNN models consist of a number of hidden layers, and trained over complex AFs. Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Peter Rindal, Maliheh Shirvanian |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Beating Attackers At Their Own Games: Adversarial Example Detection Using Adversarial Gradient DirectionsabstractAdversarial examples are input examples that are specifically crafted to deceive machine learning classifiers. State-of-the-art adversarial example detection methods characterize an input example as adversarial either by quantifying the magnitude of feature variations under multiple perturbations or by measuring its distance from estimated benign example distribution. Instead of using such metrics, the proposed method is based on the observation that the directions of adversarial gradients when crafting (new) adversarial examples play a key role in characterizing the adversarial space. Compared to detection methods that use multiple perturbations, the proposed method is efficient as it only applies a single random perturbation on the input example. Experiments conducted on two different databases, CIFAR-10 and ImageNet, show that the proposed detection method achieves, respectively, 97.9% and 98.6% AUC-ROC (on average) on five different adversarial attacks, and outperforms multiple state-of-the-art detection methods. Results demonstrate the effectiveness of using adversarial gradient directions for adversarial example detection. Yuhang Wu 0002, Sunpreet S. Arora, Hao Yang 0007 |
AAAI | 2 |
| 2021 | Adversarial Example Detection Using Latent Neighborhood GraphabstractDetection of adversarial examples with high accuracy is critical for the security of deployed deep neural network-based models. We present the first graph-based adversarial detection method that constructs a Latent Neighborhood Graph (LNG) around an input example to determine if the input example is adversarial. Given an input example, selected reference adversarial and benign examples (represented as LNG nodes in Figure 1) are used to capture the local manifold in the vicinity of the input example. The LNG node connectivity parameters are optimized jointly with the parameters of a graph attention network in an end-to-end manner to determine the optimal graph topology for adversarial example detection. The graph attention network is used to determine if the LNG is derived from an adversarial or benign input example. Experimental evaluations on CIFAR-10, STL-10, and ImageNet datasets, using six adversarial attack methods, demonstrate that the proposed method outperforms state-of-the-art adversarial detection methods in white-box and gray-box settings. The proposed method is able to successfully detect adversarial examples crafted with small perturbations using unseen attacks. Ahmed Abusnaina, Yuhang Wu 0002, Sunpreet S. Arora, Fei Wang 0062, Hao Yang 0007, David Mohaisen |
ICCV | 3 |
| 2021 | Practical Speech Re-use Prevention in Voice-driven ServicesabstractVoice-driven services (VDS) are being used in a variety of applications ranging from smart home control to payments using digital assistants. The input to such services is often captured via an open voice channel, e.g., using a microphone, in an unsupervised setting. One of the key operational security requirements in such setting is the freshness of the input speech. We present AEOLUS, a security overlay that proactively embeds a dynamic acoustic nonce at the time of user interaction, and detects the presence of the embedded nonce in the recorded speech to ensure freshness. We demonstrate that acoustic nonce can (i) be reliably embedded and retrieved, and (ii) be non-disruptive (and even imperceptible) to a VDS user. Optimal parameters (acoustic nonce’s operating frequency, amplitude, and bitrate) are determined for (i) and (ii) from a practical perspective. Experimental results show that AEOLUS yields 0.5% FRR at 0% FAR for speech re-use prevention upto a distance of 4 meters in three real-world environments with different background noise levels. We also conduct a user study with 120 participants, which shows that the acoustic nonce does not degrade overall user experience for 94.16% of speech samples, on average, in these environments. AEOLUS can therefore be used in practice to prevent speech re-use and ensure the freshness of speech input. Yangyong Zhang, Sunpreet S. Arora, Maliheh Shirvanian, Guofei Gu |
RAID | 2 |
| 2018 | Universal 3D Wearable Fingerprint Targets: Advancing Fingerprint Reader EvaluationsabstractWe present the design and manufacturing of high-fidelity universal 3D fingerprint targets, which can be imaged on a variety of fingerprint sensing technologies, namely, capacitive, contact optical, and contactless optical. Universal 3D fingerprint targets enable, for the first time, not only a repeatable and controlled evaluation of fingerprint readers but also the ability to conduct fingerprint reader interoperability studies. Fingerprint reader interoperability refers to how robust fingerprint recognition systems are to variations in the images acquired by different types of fingerprint readers. To build universal 3D fingerprint targets, we adopt a molding and casting framework consisting of: 1) digital mapping of fingerprint images to a negative mold; 2) CAD modeling a scaffolding system to hold the negative mold; 3) fabricating the mold and scaffolding system with a high resolution 3D printer; 4) producing or mixing a material with similar electrical, optical, and mechanical properties to that of the human finger; and 5) fabricating a 3D fingerprint target using controlled casting. Our experiments conducted with personal identity verification and Appendix F certified optical (contact and contactless) and capacitive fingerprint readers demonstrate the usefulness of universal 3D fingerprint targets for controlled and repeatable fingerprint reader evaluations and also fingerprint reader interoperability studies. Joshua J. Engelsma, Sunpreet S. Arora, Anil K. Jain 0001, Nicholas G. Paulter Jr. |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Gold Fingers: 3D Targets for Evaluating Capacitive ReadersabstractWith capacitive fingerprint readers being increasingly used for access control as well as for smartphone unlock and payments, there is a growing interest among metrology agencies (e.g., the National Institute of Standards and Technology) to develop standard artifacts (targets) and procedures for repeatable evaluation of capacitive readers. We present our design and fabrication procedures to create conductive 3D targets (gold fingers) for capacitive readers. Wearable 3D targets with known feature markings (e.g., fingerprint ridge flow and ridge spacing) are first fabricated using a high-resolution 3D printer. A sputter coating process is subsequently used to deposit a thin layer (~300 nm) of conductive materials (titanium and gold) on 3D printed targets. The wearable gold finger targets are used to evaluate a PIV-certified single-finger capacitive reader as well as small-area capacitive readers embedded in smartphones and access control terminals. In additional, we show that a simple procedure to create 3D printed spoofs with conductive carbon coating is able to successfully spoof a PIV-certified single-finger capacitive reader as well as a capacitive reader embedded in an access control terminal. Sunpreet S. Arora, Anil K. Jain 0001, Nicholas G. Paulter Jr. |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Fingerprint Recognition of Young ChildrenabstractIn 1899, Galton first captured ink-on-paper fingerprints of a single child from birth until the age of 4.5 years, manually compared the prints, and concluded that “the print of a child at the age of 2.5 years would serve to identify him ever after.” Since then, ink-on-paper fingerprinting and manual comparison methods have been superseded by digital capture and automatic fingerprint comparison techniques, but only a few feasibility studies on child fingerprint recognition have been conducted. Here, we present the first systematic and rigorous longitudinal study that addresses the following questions: (1) Do fingerprints of young children possess the salient features required to uniquely recognize a child? (2) If so, at what age can a child's fingerprints be captured with sufficient fidelity for recognition? (3) Can a child's fingerprints be used to reliably recognize the child as he ages? For this paper, we collected fingerprints of 309 children (0-5 years old) four different times over a one year period. We show, for the first time, that fingerprints acquired from a child as young as 6-h old exhibit distinguishing features necessary for recognition, and that state-of-the-art fingerprint technology achieves high recognition accuracy (98.9% true accept rate at 0.1% false accept rate) for children older than six months. In addition, we use mixed-effects statistical models to study the persistence of child fingerprint recognition accuracy and show that the recognition accuracy is not significantly affected over the one year time lapse in our data. Given rapidly growing requirements to recognize children for vaccination tracking, delivery of supplementary food, and national identification documents, this paper demonstrates that fingerprint recognition of young children (six months and older) is a viable solution based on available capture and recognition technology. Anil K. Jain 0001, Sunpreet S. Arora, Kai Cao 0001, Lacey Best-Rowden, Anjoo Bhatnagar |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Giving Infants an Identity: Fingerprint Sensing and RecognitionabstractThere is a growing demand for biometrics-based recognition of children for a number of applications, particularly in developing countries where children do not have any form of identification. These applications include tracking child vaccination schedules, identifying missing children, preventing fraud in food subsidies, and preventing newborn baby swaps in hospitals. Our objective is to develop a fingerprint-based identification system for infants (age range: 0-12 months)1. Our ongoing research has addressed the following issues: (i) design of a compact, comfortable, high-resolution (>1,000 ppi) fingerprint reader; (ii) image enhancement algorithms to improve quality of infant fingerprint images; and (iii) collection of longitudinal infant fingerprint data to evaluate identification accuracy over time. This collaboration between Michigan State University, Dayalbagh Educational Institute, Saran Ashram Hospital, Agra, India and NEC Corporation, has demonstrated the feasibility of recognizing infants older than 4 weeks using fingerprints. Anil K. Jain 0001, Sunpreet S. Arora, Lacey Best-Rowden, Kai Cao 0001, Prem Sewak Sudhish, Anjoo Bhatnagar, Yoshinori Koda |
ICTD | 2 |
| 2016 | Design and Fabrication of 3D Fingerprint TargetsabstractStandard targets are typically used for structural (white-box) evaluation of fingerprint readers, e.g., for calibrating imaging components of a reader. However, there is no standard method for behavioral (black-box) evaluation of fingerprint readers in operational settings where variations in finger placement by the user are encountered. The goal of this research is to design and fabricate 3D targets for repeatable behavioral evaluation of fingerprint readers. 2D calibration patterns with known characteristics (e.g., sinusoidal gratings of pre-specified orientation and frequency, and fingerprints with known singular points and minutiae) are projected onto a generic 3D finger surface to create electronic 3D targets. A state-of-the-art 3D printer (Stratasys Objet350 Connex) is used to fabricate wearable 3D targets with materials similar in hardness and elasticity to the human finger skin. The 3D printed targets are cleaned using 2M NaOH solution to obtain evaluation-ready 3D targets. Our experimental results show that: 1) features present in the 2D calibration pattern are preserved during the creation of the electronic 3D target; 2) features engraved on the electronic 3D target are preserved during the physical 3D target fabrication; and 3) intra-class variability between multiple impressions of the physical 3D target is small. We also demonstrate that the generated 3D targets are suitable for behavioral evaluation of three different (500/1000 ppi) PIV/Appendix F certified optical fingerprint readers in the operational settings. Sunpreet S. Arora, Kai Cao 0001, Anil K. Jain 0001, Nicholas G. Paulter Jr. |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Recognizing infants and toddlers using fingerprints: Increasing the vaccination coverageabstractOne of the major goals of most national, international and non-governmental health organizations is to eradicate the occurrence of vaccine-preventable childhood diseases (e.g., polio). Without a high vaccination coverage in a country or a geographical region, these deadly diseases take a heavy toll on children. Therefore, it is important for an effective immunization program to keep track of children who have been immunized and those who have received the required booster shots during the first 4 years of life to improve the vaccination coverage. Given that children, as well as the adults, in low income countries typically do not have any form of identification documents which can be used for this purpose, we address the following question: can fingerprints be effectively used to recognize children from birth to 4 years? We have collected 1,600 fingerprint images (500 ppi) of 20 infants and toddlers captured over a 30-day period in East Lansing, Michigan and 420 fingerprints of 70 infants and toddlers at two different health clinics in Benin, West Africa. We devised the following strategies to improve the fingerprint recognition accuracy when comparing the acquired fingerprints against an extended gallery database of 32,768 infant fingerprints collected by VaxTrac in Benin: (i) upsample the acquired fingerprint image to facilitate minutiae extraction, (ii) match the query print against templates created from each enrollment impression and fuse the match scores, (iii) fuse the match scores of the thumb and index finger, and (iv) update the gallery with fingerprints acquired over multiple sessions. A rank-1 (rank-10) identification accuracy of 83.8% (89.6%) on the East Lansing data, and 40.00% (48.57%) on the Benin data is obtained after incorporating these strategies when matching infant and toddler fingerprints using a commercial fingerprint SDK. This is an improvement of about 38% and 20%, respectively, on the two datasets without using the proposed strategies. A state-of-the-art latent finger-print SDK achieves an even higher rank-1 (rank-10) identification accuracy of 98.97% (99.39%) and 67.14% (71.43%) on the two datasets, respectively, using these strategies; an improvement of about 23% and 24%, respectively, on the two datasets without using the proposed strategies. Anil K. Jain 0001, Kai Cao 0001, Sunpreet S. Arora |
IJCB | 3 |
| 2014 | 3D Fingerprint PhantomsabstractOne of the critical factors prior to deployment of any large scale biometric system is to have a realistic estimate of its matching performance. In practice, evaluations are conducted on the operational data to set an appropriate threshold on match scores before the actual deployment. These performance estimates, though, are restricted by the amount of available test data. To overcome this limitation, use of a large number of 2D synthetic fingerprints for evaluating fingerprint systems had been proposed. However, the utility of 2D synthetic fingerprints is limited in the context of testing end-to-end fingerprint systems which involve the entire matching process, from image acquisition to feature extraction and matching. For a comprehensive evaluation of fingerprint systems, we propose creating 3D fingerprint phantoms (phantoms or imaging phantoms are specially designed objects with known properties scanned or imaged to evaluate, analyze, and tune the performance of various imaging devices) with known characteristics (e.g., type, singular points and minutiae) by (i) projecting 2D synthetic fingerprints with known characteristics onto a generic 3D finger surface and (ii) printing the 3D fingerprint phantoms using a commodity 3D printer. Preliminary experimental results show that the captured images of the 3D fingerprint phantoms can be successfully matched to the 2D synthetic fingerprint images (from which the phantoms were generated) using a commercial fingerprint matcher. This demonstrates that our method preserves the ridges and valleys during the 3D fingerprint phantom creation process ensuring that the synthesized 3D phantoms can be utilized for comprehensive evaluations of fingerprint systems. Sunpreet S. Arora, Kai Cao 0001, Anil K. Jain 0001, Nicholas G. Paulter Jr. |
ICPR | 1 |
| 2014 | Latent Fingerprint Matching: Performance Gain via Feedback from Exemplar PrintsabstractLatent fingerprints serve as an important source of forensic evidence in a court of law. Automatic matching of latent fingerprints to rolled/plain (exemplar) fingerprints with high accuracy is quite vital for such applications. However, latent impressions are typically of poor quality with complex background noise which makes feature extraction and matching of latents a significantly challenging problem. We propose incorporating top-down information or feedback from an exemplar to refine the features extracted from a latent for improving latent matching accuracy. The refined latent features (e.g. ridge orientation and frequency), after feedback, are used to re-match the latent to the top K candidate exemplars returned by the baseline matcher and resort the candidate list. The contributions of this research include: (i) devising systemic ways to use information in exemplars for latent feature refinement, (ii) developing a feedback paradigm which can be wrapped around any latent matcher for improving its matching performance, and (iii) determining when feedback is actually necessary to improve latent matching accuracy. Experimental results show that integrating the proposed feedback paradigm with a state-of-the-art latent matcher improves its identification accuracy by 0.5-3.5 percent for NIST SD27 and WVU latent databases against a background database of 100k exemplars. Sunpreet S. Arora, Eryun Liu, Kai Cao 0001, Anil K. Jain 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |