VLDB 2026 Research / reviewers in the wild / expert
Vivek Balachandran
dblp:124/8510
· DBLP profile ↗
17ranked-venue papers
7as first author
8since 2021 · last 2026
0000-0003-4847-7150ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 7 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Protecting Quantum Circuits Through Compiler-Resistant Obfuscation
Pradyun Parayil, Amal Raj, Vivek Balachandran |
ACNS (1) | 3 |
| 2024 | A-COPILOT: Android Covert Operation for Private Information Lifting and OTP Theft: A study on how Malware Masquerading as Legitimate Applications compromise Security and PrivacyabstractThis paper investigates an underexplored avenue of cybersecurity threats in mobile computing, with a particular focus on the Android platform, which, due to its open nature and widespread adoption, is a fertile ground for cyber threats. We present a Proof-of-Concept (PoC) Android application that, while ostensibly benign, can execute covert malicious operations by exploiting the process of permission granted. Specifically, the app manipulates accessibility permissions to autonomously acquire additional permissions needed for executing unauthorized activities without the user's knowledge. The research outlines conditions for minimal detection risk, leveraging the times when users are less likely to interact with their devices. The study provides a deeper understanding of the abuse potential of Android's accessibility features and highlights the critical need for comprehensive security measures to counteract such exploitations. Joseph Guan Quan Lim, Zhen Yu Kwok, Isaac Soon, Jun Xian Yong, Samuel Song Yuhao, Siti Halilah Binte Rosley, Vivek Balachandran |
CODASPY | 7 |
| 2022 | Using Adversarial Defences Against Image Classification CAPTCHAabstractCAPTCHAs are widely used today as a reliable method to set up a Turing test to discern between humans and computers. With the improvements in AI technology, many AI hard problems could now be solved with new techniques, for example, better Optical Character Recognition models. This work highlights the possibility of using adversarial defences techniques such as Spatial smoothing and JPEG compression to defeat image classification CAPTCHAs. Shawn Chua, Kai Yuan Tay, Melissa Wan Jun Chua, Vivek Balachandran |
CODASPY | 4 |
| 2022 | Towards Robust Detection of PDF-based MalwareabstractWith the indisputable prevalence of PDFs, several studies into PDF malware and their evasive variants have been conducted to test the robustness of ML-based PDF classifier frameworks, Hidost and Mimicus. As heavily documented, the fundamental difference between them is that Hidost investigates the logical structure of PDFs, while Mimicus detects malicious indicators through their structural features. However, there exists techniques to mutate such features such that malicious PDFs are able to bypass these classifiers. In this work, we investigated three known attacks: Mimicry, Mimicry+, and Reverse Mimicry to compare how effective they are in evading classifiers in Hidost and Mimicus. The results shows that Mimicry and Mimicry+ are effective in bypassing models in Mimicus but not in Hidost, while Reverse Mimicy is effective against both models in Mimicus and Hidost. Kai Yuan Tay, Shawn Chua, Melissa Wan Jun Chua, Vivek Balachandran |
CODASPY | 4 |
| 2021 | Quantum Obfuscation: Quantum Predicates with Entangled qubitsabstractIn this paper we discuss developing opaque predicates with the help of quantum entangled qubits. These opaque predicates obfuscate classical control flow in hybrid quantum-classical systems. The idea is to use a pair of entangled qubits, one at compile-time and one in the compiled code at runtime to create opaque predicates. We make use of the CHSH game (John Clauser, Michael Horne, Abner Shimony, and Richard Holt) to get consensus about the value of a qubit at runtime, whose value can be predicted at compile time with high probability due to quantum properties. The paper discusses designing opaque predicate that relies on the quantum behavior of the entangled qubits and quantum measurements. The obfuscation produced by this technique maintain only a semantic accuracy of 85.35% when one entangled pair of qubits are used. However, we show that the accuracy can be improved to 100% by introducing additional entangled qubit pairs. Vivek Balachandran |
CODASPY | 1 |
| 2021 | Neutralizing Hostile Drones with Surveillance DronesabstractIn this paper we discuss a technique to safeguard specific airspace from intruding drones with the help of surveillance drones. The idea is to use multiple surveillance drones to patrol through the area looking for suspicious flying objects. The surveillance drones are trained to identify permissible drones in the area and hostile drones using image recognition algorithms. Once a hostile drone is detected the surveillance drones surround it making it difficult to maneuver. In the meantime, our automated drone attack framework launches cyber-attacks against the hostile drone to bring it down. Vivek Balachandran, Melissa Wan Jun Chua |
CODASPY | 1 |
| 2021 | Blockchain-based Proof of Existence (PoE) Framework using Ethereum Smart ContractsabstractIn recent years, Blockchain, underpinned by distributed ledger technology (DLT) has been touted as the next disruptive technology with the potential to revolutionise various industry verticals and horizontals. Plagiarism and Intellectual Property Infringements of copyrights of artifacts, trade secrets, etc., are often fought in courts of law. There is an inherent need to adduce reliable evidence to establish a prima facie tort case or even beyond. In this paper we aim to leverage on the Blockchain technology to provide a digital transformation in the post-Covid world by offering a new platform to aid in the protection of one's intellectual property rights through a Proof of Existence (PoE) framework using Ethereum smart contracts. We have developed a seamless web platform to allow users experience a simple yet secure Proof of Existence (PoE) service by allowing the users to (i) certify, (ii) manage and (iii) view their documents securely through a digital portfolio. This PoE service leverages on the Blockchain characteristics to provide a reliable and transparent means to record a tamper-proof evidence of copyright information with timestamp as proof of existence for all its transactions through smart contracts. Lim Wei Ming Shawn, Purnima Murali Mohan, Peter Kok Keong Loh, Vivek Balachandran |
CODASPY | 4 |
| 2021 | Distributed ledger technology: Its evolutionary path and the road ahead
Arif Perdana, D. Alastair Robb, Vivek Balachandran, Fiona H. Rohde |
Inf. Manag. | 3 |
| 2020 | DRAT: A Drone Attack Tool for Vulnerability AssessmentabstractDrones are usually associated with the military but in recent times, they are also used for public and commercial interests such as transporting of goods, communications, agriculture, disaster mitigation and environment preservation. However, like any system, drones have vulnerabilities that can be exploited which can jeopardise a drone's operation and may lead to loss of lives, property and money. Thus drones deployed must be carefully evaluated and selected. Pen-testing is a way to assess the vulnerabilities of drones but it may require multiple commands, files or scripts. In this work, we propose a tool to allow easy pen-testing and assessment of drones. Vulnerability assessment of the DJI Mavic 2 Pro is discussed extensively as well. Future work includes addressing the vulnerabilities of other drones and expanding the tool to conduct pen-testing on other drones. Mohammad Shameel bin Mohammad Fadilah, Vivek Balachandran, Peter Kok Keong Loh, Melissa Wan Jun Chua |
CODASPY | 2 |
| 2020 | GRAMAC: A Graph Based Android Malware Classification MechanismabstractAndroid malware analysis has been an active area of research as the number and types of Android malwares have increased dramatically. Most of the previous works have used permission based model, behavioral analysis, and code analysis to identify the family of a malware. Code Analysis are weak against obfuscated approach, it does not include real time execution of the application. Behavioral analysis captures the runtime behavior but is weak when it comes to obfuscated applications. Permission based model only uses manifest files for analysing malwares. In this paper, we propose a novel graph signature based malware classification mechanism . The proposed graph signature uses sensitive API calls to capture the flow of control which helps to find a caller-callee relationship between the sensitive APIs and the nodes incident on them. A dataset of graph signatures of widely known malware families are then created. A new application's graph signature is compared with graph signatures in the dataset and the application is classified into the respective malware family or declared as goodware/unknown. Experiments with 15 malware families from the AMD dataset and a total of 400 applications gave an average accuracy of 0.97 with an error rate of 0.03. Devyani Vij, Vivek Balachandran, Tony Thomas, Roopak Surendran |
CODASPY | 2 |
| 2018 | Effectiveness of Android Obfuscation on Evading Anti-malwareabstractObfuscation techniques have been conventionally used for legitimate applications, including preventing application reverse engineering, tampering and protecting intellectual property. A malware author could also leverage these benign techniques to hide their malicious intents and evade anti-malware detection. As variants of known malware have been regularly found on the Google Play Store, transformed malware attacks are a real problem that security solutions today need to address. It has been proven that mainstream security tools installed on smartphones are mainly signature-based; our work focuses on evaluating the efficiency of a composite of obfuscation techniques in evading anti-malware detection. We further verified the trend of transformed malware in evading detection, with a larger and more updated database of known malware. This is also the first work to-date that presents the instability of some anti-malware tools (AMTs) against obfuscated malware. This work also proved that current mainstream AMTs do not build up resilience against obfuscation methods, but instead try to update the signature database on created variants. Melissa Wan Jun Chua, Vivek Balachandran |
CODASPY | 2 |
| 2018 | AEON: Android Encryption based ObfuscationabstractAndroid applications are vulnerable to reverse engineering which could result in tampering and repackaging of applications. Even though there are many off the shelf obfuscation tools that hardens Android applications, they are limited to basic obfuscation techniques. Obfuscation techniques that transform the code segments drastically are difficult to implement on Android because of the Android runtime verifier which validates the loaded code. In this paper, we introduce a novel obfuscation technique, Android Encryption based Obfuscation (AEON), which can encrypt code segments and perform runtime decryption during execution. The encrypted code is running outside of the normal Android virtual machine, in an embeddable Java source interpreter and thereby circumventing the scrutiny of Android runtime verifier. Our obfuscation technique works well with Android source code and Dalvik bytecode. D. Geethanjali, Tan Li Ying, Melissa Wan Jun Chua, Vivek Balachandran |
CODASPY | 4 |
| 2016 | Control flow obfuscation for Android applications
Vivek Balachandran, Sufatrio, Darell J. J. Tan, Vrizlynn L. L. Thing |
Comput. Secur. | 1 |
| 2014 | Function Level Control Flow Obfuscation for Software SecurityabstractSoftware released to the user has the risk of reverse engineering attacks. Software control flow obfuscation is one of the techniques used to make the reverse engineering of software programs harder. Control flow obfuscation, obscures the control flow of the program so that it is hard for an analyzer to decode the logic of the program. In this paper, we propose an obfuscation algorithm which obscures the control flow across functions. In our method code fragments from each function is stripped from the original function and is stored in another function. Each function will be having code fragments from different functions, thereby creating a function level shuffled version of the original program. Control flow is obscured between and within the function by this method. Experimental results indicate that the algorithm performs well against automated attacks. Vivek Balachandran, Wee Keong Ng, Sabu Emmanuel |
CISIS | 1 |
| 2014 | Obfuscation by code fragmentation to evade reverse engineeringabstractSoftware distributed can be reverse engineered using software analyzing tools, thereby letting an adversary understand the logic of the program and finding the vulnerabilities in the program. Control flow obfuscation is one of the techniques that can obscure the program so that the reverse engineering tools get an erroneous result while analyzing the program. In this paper, we propose a binary obfuscation algorithm that makes it difficult to reverse engineer the programs. The basic idea is to fragment the binary code by moving instruction sets from various parts of the program to a new code block. The control flow, to and from the new code block, is camouflaged using dynamic instruction modification during runtime. Experimental results indicate that the algorithm performs well against reverse engineering attacks by standard tools. Vivek Balachandran, Sabu Emmanuel, Wee Keong Ng |
SMC | 1 |
| 2013 | Software Protection with Obfuscation and Encryption
Vivek Balachandran, Sabu Emmanuel |
ISPEC | 1 |
| 2013 | Potent and Stealthy Control Flow Obfuscation by Stack Based Self-Modifying CodeabstractSoftware code released to the user has the risk of reverse engineering attacks. Software obfuscation techniques can be employed to make the reverse engineering of software programs harder. In this paper, we propose a potent, stealthy, and cost-effective algorithm to obfuscate software programs. The main idea of the algorithm is to remove control flow information from the code area and hide them in the data area. During execution time, these instructions are reconstructed, thereby preserving the semantics of the program. Experimental results indicate that the algorithm performs well against static and dynamic attacks. Also the obfuscated program is hard to be differentiated from normal binary programs demonstrating the obfuscations good stealth measure. Vivek Balachandran, Sabu Emmanuel |
IEEE Trans. Inf. Forensics Secur. | 1 |