VLDB 2026 Research / reviewers in the wild / expert
Aritra Dhar
dblp:118/3376
· DBLP profile ↗
14ranked-venue papers
5as first author
3since 2021 · last 2025
0000-0002-3023-9368ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 2 since 2021Computer networks · 2Software engineering, systems software and programming languages · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AC-LoRA: (Almost) Training-Free Access Control Aware Multi-Modal LLMsabstractCorporate LLMs are gaining traction for efficient knowledge dissemination and management within organizations.
However, as current LLMs are vulnerable to leaking sensitive information, it has proven difficult to apply them in settings where strict access control is necessary.
To this end, we design AC-LoRA, an end-to-end system for access control-aware corporate LLM chatbots that maintains a strong information isolation guarantee.
AC-LoRA maintains separate LoRA adapters for permissioned datasets, along with the document embedding they are finetuned on.
AC-LoRA retrieves a precise set of LoRA adapters based on the similarity score with the user query and their permission.
This similarity score is later used to merge the responses if more than one LoRA is retrieved, without requiring any additional training for LoRA routing.
We provide an end-to-end prototype of AC-LoRA, evaluate it on two datasets, and show that AC-LoRA matches
or even exceeds the performance of state-of-the-art LoRA mixing techniques while providing strong isolation guarantees.
Furthermore, we show that AC-LoRA design can be directly applied to different modalities. Lara Magdalena Lazier, Aritra Dhar, Vasilije Stambolic, Lukas Cavigelli |
NeurIPS | 2 |
| 2025 | Guardain: Protecting Emerging Generative AI Workloads on Heterogeneous NPUabstractDriven by recent advances in large language models (LLMs), generative AI applications have become the dominant workload for the modern cloud. Specialized hardware accelerators, such as GPUs, NPUs, and TPUs, play a key role in AI adoption due to their superior performance over general-purpose CPUs. AI models and the data are often highly sensitive and come from mutually distrusting parties. Existing industry-standard CPU-based TEEs, such as Intel SGX or AMD SEV, do not adequately protect these accelerators. Device-TEEs like Nvidia-CC only address tightly coupled CPU-GPU systems with a proprietary solution requiring TEE on the host CPU side. On the other hand, existing academic proposals target specific CPU-TEE platforms. To address this gap, we propose Guardain,a confidential computing architecture for discrete NPU devices that requires no trust in the host system. Guardainsecures data, model parameters, and operator binaries through authenticated encryption. Guardainuses delegation-based memory semantics to ensure isolation from the host software stack, while task attestation guarantees strong model integrity. Our G Uardainimplementation and evaluation with state-of-the-art LLMs such as Llama2 and Llama3 shows that Guardainintroduces minimal overhead with no changes in the AI software stack. Aritra Dhar, Clément Thorens, Lara Magdalena Lazier, Lukas Cavigelli |
SP | 1 |
| 2024 | Confidential Computing with Heterogeneous Devices at Cloud-ScaleabstractCloud-centric workloads increasingly leverage domain-specific accelerators (DSAs) such as GPU, NPU, FPGA, etc., to achieve massive speedup over general-purpose CPUs. These workloads compute sensitive data; furthermore, the programs can be proprietary business secrets such as high-performance AI models. Therefore, several confidential cloud solutions have recently emerged to protect against the attacker-controlled software stack (OS/VMM) and the cloud service providers or CSPs themselves. CPU-centric trusted execution environments, or TEEs, have been around for decades and are deployed commercially. However, despite some recent proposals, most nodes lack TEE capability and, therefore, are unprotected against malicious CSP and software stack.We address this gap by proposing a new dedicated hardware module, the security controller (SC), that acts as the TEE proxy for the legacy non-TEE DSA nodes in a data center across racks. SC enforces access control and attestation mechanisms and protects the non-TEE nodes even from a physical attacker. This way, SC enables new-generation TEE-enabled nodes and legacy non-TEE nodes to be used in a data center simultaneously while ensuring security. We implement and synthesize SC hardware and evaluate it with real-world cloud-centric workloads with heterogeneous DSAs. Our evaluation shows that, on average, SC introduces 1.5-5% overhead while running AI, Redis, and file system workloads and scales well with an increasing number of DSA nodes (up to 2236 concurrent NPUs running CNNs). Aritra Dhar, Supraja Sridhara, Shweta Shinde, Srdjan Capkun, Renzo Andri |
ACSAC | 1 |
| 2020 | ProximiTEE: Hardened SGX Attestation by Proximity VerificationabstractIntel SGX enables protected enclaves on untrusted computing platforms. An important part of SGX is its remote attestation mechanism that allows a remote verifier to check that the expected enclave was correctly initialized before provisioning secrets to it. However, SGX attestation is vulnerable to relay attacks where the attacker, using malicious software on the target platform, redirects the attestation and therefore the provisioning of confidential data to a platform that he physically controls. Although relay attacks have been known for a long time, their consequences have not been carefully examined. In this paper, we analyze relay attacks and show that redirection increases the adversary's abilities to compromise the enclave in several ways, enabling for instance physical and digital side-channel attacks that would not be otherwise possible. Aritra Dhar, Ivan Puddu, Kari Kostiainen, Srdjan Capkun |
CODASPY | 1 |
| 2020 | ProtectIOn: Root-of-Trust for IO in Compromised Platforms
Aritra Dhar, Enis Ulqinaku, Kari Kostiainen, Srdjan Capkun |
NDSS | 1 |
| 2020 | Snappy: Fast On-chain Payments with Practical Collaterals
Vasilios Mavroudis, Karl Wüst, Aritra Dhar, Kari Kostiainen, Srdjan Capkun |
NDSS | 3 |
| 2019 | Development of UAV Based Glacial Lake Outburst Monitoring SystemabstractA reliable and accurate glacial monitoring system is being developed with the help of a UAV and high-resolution camera on board. GPS is another major part of system which will help to collect information on glacier melting using reflectrometry principle and complement the information of aerial view of the lake formed due to glacier melting. The information gathered in that way helps the existing human habitat in the vicinity of the glacial lake from Glacial lake Outburst Flood (GLOF), a serious event of North East Indian Himalayan region. The information gathered in that way and generated warning signal are then transmitted to android application which exploits the data for the real time monitoring of the glacier melting as well as increase of area of the lake formed due to glacier melting. Swastika Chakraborty, Chimila Sherpa, Lipika Karn, Saurabh Das, Nirmal Rai, Anirban Patra, Aritra Dhar, Arnav Sadhu, Baishali Gautam, Anindita Singh |
IGARSS | 7 |
| 2019 | Deniable Upload and Download via Passive Participation
David M. Sommer 0001, Aritra Dhar, Luka Malisa, Esfandiar Mohammadi, Daniel Ronzani, Srdjan Capkun |
NSDI | 2 |
| 2018 | METIS: Resource and Context-Aware Monitoring of Finite State Properties
Garvita Allabadi, Aritra Dhar, Ambreen Bashir, Rahul Purandare |
RV | 2 |
| 2017 | CoverUp: Privacy Through "Forced" Participation in Anonymous Communication NetworksabstractMany privacy-enhancing technologies, in particular anonymous communication networks (ACNs) as a key building block, suffer from a lack of a sufficient number of participants. Without high user participation, ACNs are vulnerable to traffic analysis attacks. The only ACN with a high number of participants (around 1.5 million users) is Tor. Yet, Tor is prone to traffic analysis attacks traffic pattern attacks. While other ACNs have been proposed that are even secure against global attackers, they are not scalable and suffer from a low number of participants, since even a perfect ACN can at most hide a user among all participating users. These ACNs are in a vicious circle: the lack of participants leads to low degree of anonymity, and a low degree of anonymity makes these ACNs unattractive for users. In this work, we break this vicious cycle by studying the question: Can an anonymous communication network be strengthened by "forced" participation? What privacy guarantees and performance can such an ACN provide? We develop CoverUp, a system that "forces" visitors of highly accessed websites (entry servers) to become involuntary participants of an ACN. CoverUp triggers users to participate in a centralized, constant-rate mix by leveraging basic functionality of their browsers to execute (JavaScript) code served by the entry servers. Candidates for entry servers could be universities or news sites. They would let a distinct CoverUp server provide (via an iframe) JavaScript code to the end-users' browsers, which in turn makes them participate in the ACN via a mix server. Visitors of these entry servers' websites become (involuntary) participants of an ACN, creating cover traffic for voluntary participants. For voluntary participants, we developed a browser extension that renders their CoverUp requests indistinguishable from the cover traffic of involuntary participants. David M. Sommer 0001, Aritra Dhar, Luka Malisa, Esfandiar Mohammadi, Daniel Ronzani, Srdjan Capkun |
AsiaCCS | 2 |
| 2017 | ROTE: Rollback Protection for Trusted Execution
Sinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar, David M. Sommer 0001, Arthur Gervais, Ari Juels, Srdjan Capkun |
USENIX Security Symposium | 4 |
| 2015 | CLOTHO: saving programs from malformed strings and incorrect string-handlingabstractSoftware is susceptible to malformed data originating from untrusted sources. Occasionally the programming logic or constructs used are inappropriate to handle the varied constraints imposed by legal and well-formed data. Consequently, softwares may produce unexpected results or even crash. In this paper, we present CLOTHO, a novel hybrid approach that saves such softwares from crashing when failures originate from malformed strings or inappropriate handling of strings. CLOTHO statically analyses a program to identify statements that are vulnerable to failures related to associated string data. CLOTHO then generates patches that are likely to satisfy constraints on the data, and in case of failures produces program behavior which would be close to the expected. The precision of the patches is improved with the help of a dynamic analysis. We have implemented CLOTHO for the JAVA String API, and our evaluation based on several popular open-source libraries shows that CLOTHO generates patches that are semantically similar to the patches generated by the programmers in the later versions. Additionally, these patches are activated only when a failure is detected, and thus CLOTHO incurs no runtime overhead during normal execution, and negligible overhead in case of failures. Aritra Dhar, Rahul Purandare, Mohan Dhawan, Suresh Rangaswamy |
ESEC/SIGSOFT FSE | 1 |
| 2013 | Connecting, scaling and securing RS code and TD based KPDs in WSNs: deterministic mergingabstractKey management, one of the most challenging problems in Wireless Sensor Network (WSN) has been efficiently addressed using Key Predistribution (KPD) schemes. This paper analyzes a localized KPD based on the Transversal Design (TD) design or Reed Solomon (RS) codes schemes; later two shown to be similar. They lack full direct communications among their constituent nodes and so, rely on multi-hop involving other nodes reducing the overall efficiency of the system. The communication issue for TD or RS and hence the localized KPD gets resolved by Deterministic Merging of exactly two nodes. The weakness of `selective node attack' of the merged designs, similar to their original KPDs, is overcome by invoking the novel trick of Sarkar \emph{et al.} Simulation results confirm that the various network parameters of the proposed schemes improves significantly over a random counterpart among other existing schemes. Pinaki Sarkar, Brijesh Kumar Rai, Aritra Dhar |
MobiHoc | 3 |
| 2012 | 100% Connectivity for Location Aware Code Based KPD in Clustered WSN: Merging Blocks
Samiran Bag, Aritra Dhar, Pinaki Sarkar |
ISC | 2 |