VLDB 2026 Research / reviewers in the wild / expert
Amir Rahmati
dblp:125/0358
· DBLP profile ↗
25ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0001-7361-1898ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Systems, architecture and hardware · 3 · 1 first-authorComputer networks · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Proteus: A Practical Framework for Privacy-Preserving Device LogsabstractDevice logs are essential for forensic investigations, enterprise monitoring, and fraud detection; however, they often leak personally identifiable information (PII) when exported for third-party analysis. Existing approaches either fail to minimize PII exposure across all stages of log collection and analysis or sacrifice data fidelity, resulting in less effective analysis. We present Proteus, a privacy-preserving device logging framework that enables forensic analysis without disclosing plaintext PII or compromising fidelity, even when facing adversaries with access to multiple snapshots of the log files. To achieve this, Proteus proposes a two-layer scheme that employs keyed-hash pseudonymization of PII fields and time-rotating encryption with ratcheted ephemeral keys to prevent multi-snapshot correlation. For controlled sharing, clients export ratchet states that grant time-bounded access, permitting decryption of pseudonymized tokens that enable linkage and timeline reconstruction without exposing the underlying PII. Subsequent ratchet rotations ensure forward secrecy, while DICE-based attestation authenticates device provenance. We implement Proteus as a transparent extension to Android’s logcat and evaluate it across three generations of hardware. Our results demonstrate a median latency of 0.2 ms per message and an average per-PII-field size overhead of only 97.1 bytes. Sanket Goutam, Hunter Kippen, Michael Grace, Amir Rahmati |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | On User Privacy in MNO: Machine Unlearning Techniques for Data Compliance and SecurityabstractArtificial Intelligence (AI) integration in network management has significantly improved Quality of Experience (QoE) and achieved high availability, reaching 99.99% uptime with an aim to meet the five 9s standard in Next Generation Networks. Utilizing Closed Loop Automation (CLA) within the management plane, AI-driven systems dynamically allocate network resources based on real-time user data. However, the shift to automated management introduces privacy concerns, as retained user data may violate the GDPR's “right to be forgotten” requirement. To address this, we propose a machine unlearning framework for precise data removal in Deep Neural Network (DNN) models that is fully integrated into the CLA. This framework ensures compliant data deletion requests while preserving model performance. Our experiments demonstrate the framework's effectiveness by preserving the model's accuracy on validation data by 79.38 % compared to the existing benchmark methods of 57.0048 %, underscoring its potential in secure, privacy-aware network management. The update is tested on model forecasting Internet usage from a telecommunications dataset and achieves a low complexity while maintaining the model's accuracy over a validation dataset. The method provides a reasonable time to run for the 7 million parameter model. Its ease of integration within the network management plane allows operators to reach compliance with the Data Acts. Emanuel Figetakis, Amir Rahmati |
ICC | 3 |
| 2025 | The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment ScamsabstractGovernments and regulatory bodies have recognized investment scams as a prevalent form of cryptocurrency fraud. These scams typically use professional-looking websites to lure unsuspecting victims with promises of unrealistically high returns. In this paper, we introduce Crimson, a distributed system designed to continuously detect cryptocurrency investment scam websites as they are created in the wild. During the first 8 months of 2024, Crimson processed approximately 6 billion domain names and classified 43,572 unique cryptocurrency investment scam websites in real-time. Beyond detection, we provide insights into the design and infrastructure of these websites that can help users recognize scam patterns and assist hosting providers in detecting and blocking such sites. Furthermore, we investigate the inclusion of our detected scam websites in block-lists used by popular web browsers and applications, finding that the vast majority of these websites were absent. On the financial side, by analyzing the transactions incoming to scammer wallets on 6.7% of the sites detected by Crimson, we observe an estimated lower bound of 2.04M USD in losses due to cryptocurrency investment scams. Abisheka Pitumpe, Xigao Li, Amir Rahmati, Nick Nikiforakis |
WWW | 4 |
| 2024 | Fast Koopman Surrogate Falsification Using Linear Relaxations and Weights
Stanley Bak, Abdelrahman Hekal, Niklas Kochdumper, Ethan Lew, Andrew Mata, Amir Rahmati |
ATVA (2) | 6 |
| 2024 | Falsification using Reachability of Surrogate Koopman ModelsabstractBlack-box falsification problems are most often solved by numerical optimization algorithms. In this work, we propose an alternative approach, where simulations are used to construct a surrogate model for the system dynamics using data-driven Koopman operator linearization. Since the dynamics of the Koopman model are linear, the reachable set of states can be computed and combined with an encoding of the signal temporal logic specification in a mixed-integer linear program (MILP). To determine the next sample, an MILP solver computes the least robust trajectory inside the reachable set of the surrogate model. The trajectory’s initial state and input signal are then executed on the original black-box system, where the specification is either falsified or additional simulation data is generated that we use to retrain the surrogate Koopman model and repeat the process. Stanley Bak, Sergiy Bogomolov, Abdelrahman Hekal, Niklas Kochdumper, Ethan Lew, Andrew Mata, Amir Rahmati |
HSCC | 7 |
| 2024 | Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms
Xigao Li, Amir Rahmati, Nick Nikiforakis |
NDSS | 2 |
| 2024 | Biosignal Authentication Considered Harmful Today
Veena Krish, Nicola Paoletti, Milad Kazemi, Scott A. Smolka, Amir Rahmati |
USENIX Security Symposium | 5 |
| 2023 | Erebus: Access Control for Augmented Reality Systems
Yoonsang Kim, Sanket Goutam, Amir Rahmati, Arie E. Kaufman |
USENIX Security Symposium | 3 |
| 2023 | Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability ScanningabstractWeb vulnerability scanners (WVS) are an indispensable tool for penetration testers and developers of web applications, allowing them to identify and fix low-hanging vulnerabilities before they are discovered by attackers. Unfortunately, malicious actors leverage the very same tools to identify and exploit vulnerabilities in third-party websites. Existing research in the WVS space is largely concerned with how many vulnerabilities these tools can discover, as opposed to trying to identify the tools themselves when they are used illicitly. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
WWW | 3 |
| 2022 | Accelerating Certified Robustness Training via Knowledge TransferabstractTraining deep neural network classifiers that are certifiably robust against adversarial attacks is critical to ensuring the security and reliability of AI-controlled systems. Although numerous state-of-the-art certified training methods have been developed, they are computationally expensive and scale poorly with respect to both dataset and network complexity. Widespread usage of certified training is further hindered by the fact that periodic retraining is necessary to incorporate new data and network improvements. In this paper, we propose Certified Robustness Transfer (CRT), a general-purpose framework for reducing the computational overhead of any certifiably robust training method through knowledge transfer. Given a robust teacher, our framework uses a novel training loss to transfer the teacher’s robustness to the student. We provide theoretical and empirical validation of CRT. Our experiments on CIFAR-10 show that CRT speeds up certified robustness training by 8× on average across three different architecture generations while achieving comparable robustness to state-of-the-art methods. We also show that CRT can scale to large-scale datasets like ImageNet. Pratik Vaishnavi, Kevin Eykholt, Amir Rahmati |
NeurIPS | 3 |
| 2022 | Transferring Adversarial Robustness Through Robust Representation Matching
Pratik Vaishnavi, Kevin Eykholt, Amir Rahmati |
USENIX Security Symposium | 3 |
| 2021 | Good Bot, Bad Bot: Characterizing Automated Browsing ActivityabstractAs the web keeps increasing in size, the number of vulnerable and poorly-managed websites increases commensurately. Attackers rely on armies of malicious bots to discover these vulnerable websites, compromising their servers, and exfiltrating sensitive user data. It is, therefore, crucial for the security of the web to understand the population and behavior of malicious bots.In this paper, we report on the design, implementation, and results of Aristaeus, a system for deploying large numbers of "honeysites", i.e., websites that exist for the sole purpose of attracting and recording bot traffic. Through a seven-month-long experiment with 100 dedicated honeysites, Aristaeus recorded 26.4 million requests sent by more than 287K unique IP addresses, with 76,396 of them belonging to clearly malicious bots. By analyzing the type of requests and payloads that these bots send, we discover that the average honeysite received more than 37K requests each month, with more than 50% of these requests attempting to brute-force credentials, fingerprint the deployed web applications, and exploit large numbers of different vulnerabilities. By comparing the declared identity of these bots with their TLS handshakes and HTTP headers, we uncover that more than 86.2% of bots are claiming to be Mozilla Firefox and Google Chrome, yet are built on simple HTTP libraries and command-line tools. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
SP | 3 |
| 2020 | Valve: Securing Function Workflows on Serverless Computing PlatformsabstractServerless Computing has quickly emerged as a dominant cloud computing paradigm, allowing developers to rapidly prototype event-driven applications using a composition of small functions that each perform a single logical task. However, many such application workflows are based in part on publicly-available functions developed by third-parties, creating the potential for functions to behave in unexpected, or even malicious, ways. At present, developers are not in total control of where and how their data is flowing, creating significant security and privacy risks in growth markets that have embraced serverless (e.g., IoT). Pubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace, Amir Rahmati, Adam Bates 0001 |
WWW | 5 |
| 2020 | An Intent-Based Automation Framework for Securing Dynamic Consumer IoT InfrastructuresabstractConsumer IoT networks are characterized by heterogeneous devices with diverse functionality and programming interfaces. This lack of homogeneity makes the integration and secure management of IoT infrastructures a daunting task for users and administrators. In this paper, we introduce VISCR, a Vendor-Independent policy Specification and Conflict Resolution engine that enables intent-based conflict-free policy specification and enforcement in IoT environments. VISCR converts the topology of the IoT infrastructure into a tree-based abstraction and translates existing policies from heterogeneous vendor-specific programming languages, such as Groovy-based SmartThings, OpenHAB, IFTTT-based templates, and MUD-based profiles, into a vendor-independent graph-based specification. These are then used to automatically detect rogue policies, policy conflicts, and automation bugs. We evaluated VISCR using a dataset of 907 IoT apps, programmed using heterogeneous automation specifications, in a simulated smart-building IoT infrastructure. In our experiments, among 907 IoT apps, VISCR exposed 342 of IoT apps as exhibiting one or more violations, while also running 14.2x faster than the state-of-the-art tool (Soteria). VISCR detected 100% of violations reported by Soteria while also detecting new types of violations in 266 additional apps. Vasudevan Nagendra, Arani Bhattacharya, Vinod Yegneswaran, Amir Rahmati, Samir Ranjan Das |
WWW | 4 |
| 2018 | Robust Physical-World Attacks on Deep Learning Visual ClassificationabstractRecent studies show that the state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples, resulting from small-magnitude perturbations added to the input. Given that that emerging physical systems are using DNNs in safety-critical situations, adversarial examples could mislead these systems and cause dangerous situations. Therefore, understanding adversarial examples in the physical world is an important step towards developing resilient learning algorithms. We propose a general attack algorithm, Robust Physical Perturbations (RP2), to generate robust visual adversarial perturbations under different physical conditions. Using the real-world case of road sign classification, we show that adversarial examples generated using RP2 achieve high targeted misclassification rates against standard-architecture road sign classifiers in the physical world under various environmental conditions, including viewpoints. Due to the current lack of a standardized testing method, we propose a two-stage evaluation methodology for robust physical adversarial examples consisting of lab and field tests. Using this methodology, we evaluate the efficacy of physical adversarial manipulations on real objects. With a perturbation in the form of only black and white stickers, we attack a real stop sign, causing targeted misclassification in 100% of the images obtained in lab settings, and in 84.8% of the captured video frames obtained on a moving vehicle (field test) for the target classifier. Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li 0026, Amir Rahmati, Chaowei Xiao, Atul Prakash 0001, Tadayoshi Kohno, Dawn Song |
CVPR | 5 |
| 2018 | Decentralized Action Integrity for Trigger-Action IoT Platforms
Earlence Fernandes, Amir Rahmati, Jaeyeon Jung, Atul Prakash 0001 |
NDSS | 2 |
| 2018 | ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem
Jing (Dave) Tian, Grant Hernandez, Joseph I. Choi, Vanessa Frost, Christie Ruales, Patrick Traynor, Hayawardh Vijayakumar, Lee Harrison, Amir Rahmati, Michael Grace, Kevin R. B. Butler |
USENIX Security Symposium | 9 |
| 2017 | Heimdall: A Privacy-Respecting Implicit Preference Collection FrameworkabstractMany of the everyday decisions a user makes rely on the suggestions of online recommendation systems. These systems amass implicit (e.g.,location, purchase history, browsing history) and explicit (e.g.,reviews, ratings) feedback from multiple users, produce a general consensus, and provide suggestions based on that consensus. However, due to privacy concerns, users are uncomfortable with implicit data collection, thus requiring recommendation systems to be overly dependent on explicit feedback. Unfortunately, users do not frequently provide explicit feedback. This hampers the ability of recommendation systems to provide high-quality suggestions. We introduce Heimdall, the first privacy-respecting implicit preference collection framework that enables recommendation systems to extract user preferences from their activities in a privacy respecting manner. The key insight is to enable recommendation systems to run a collector on a user's device and precisely control the information a collector transmits to the recommendation system back-end. Heimdall introduces immutable blobs as a mechanism to guarantee this property. We implemented Heimdall on the Android platform and wrote three example collectors to enhance recommendation systems with implicit feedback. Our performance results suggest that the overhead of immutable blobs is minimal, and a user study of 166 participants indicates that privacy concerns are significantly less when collectors record only specific information--a property that Heimdall enables. Amir Rahmati, Earlence Fernandes, Kevin Eykholt, Xinheng Chen, Atul Prakash 0001 |
MobiSys | 1 |
| 2017 | ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
Yunhan Jia, Qi Alfred Chen, Shiqi Wang 0002, Amir Rahmati, Earlence Fernandes, Z. Morley Mao, Atul Prakash 0001 |
NDSS | 4 |
| 2016 | Towards Comprehensive Repositories of OpinionsabstractDespite the popularity of recommendation services (such as Yelp, Healthgrades, and Angie’s List), for a majority of entities listed on these services, one has to rely on opinions shared by a few users. We argue that this paucity of reviews for most entities stems from the fact that the vast majority of users largely consume opinions shared by others but seldom post reviews themselves. Therefore, leveraging the trend that services are increasingly accessed from a client-side app rather than over the Web, we propose augmenting recommendation services to implicitly infer any user’s opinions based on observations of the user’s activities. Implicit inference of many of a user’s recommendations are feasible due to the rich sensory capabilities of smartphones and wearables as well as the digital footprints left behind by many activities in the physical world. However, implicit inference of opinions is inherently uncertain and automated sharing of inferences raises significant privacy and security concerns. In this paper, we discuss how to tackle these challenges so that users looking for recommendations can draw upon a more comprehensive set of opinions than is the case today. Han Zhang 0037, Kasra Edalat Nejad, Amir Rahmati, Harsha V. Madhyastha |
HotNets | 3 |
| 2016 | FlowFence: Practical Data Protection for Emerging IoT Application Frameworks
Earlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato, Mauro Conti, Atul Prakash 0001 |
USENIX Security Symposium | 3 |
| 2016 | Persistent Clocks for Batteryless Sensing DevicesabstractSensing platforms are becoming batteryless to enable the vision of the Internet of Things, where trillions of devices collect data, interact with each other, and interact with people. However, these batteryless sensing platforms—that rely purely on energy harvesting—are rarely able to maintain a sense of time after a power failure. This makes working with sensor data that is time sensitive especially difficult. We propose two novel, zero-power timekeepers that use remanence decay to measure the time elapsed between power failures. Our approaches compute the elapsed time from the amount of decay of a capacitive device, either on-chip Static Random-Access Memory (SRAM) or a dedicated capacitor. This enables hourglass-like timers that give intermittently powered sensing devices a persistent sense of time. Our evaluation shows that applications using either timekeeper can keep time accurately through power failures as long as 45s with low overhead. Josiah D. Hester, Nicole Tobias, Amir Rahmati, Lanny Sitanayah, Daniel E. Holcomb, Kevin Fu, Wayne P. Burleson, Jacob Sorber |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2015 | Probable cause: the deanonymizing effects of approximate DRAMabstractApproximate computing research seeks to trade-off the accuracy of computation for increases in performance or reductions in power consumption. The observation driving approximate computing is that many applications tolerate small amounts of error which allows for an opportunistic relaxation of guard bands (e.g., clock rate and voltage). Besides affecting performance and power, reducing guard bands exposes analog properties of traditionally digital components. For DRAM, one analog property exposed by approximation is the variability of memory cell decay times. Amir Rahmati, Matthew Hicks, Daniel E. Holcomb, Kevin Fu |
ISCA | 1 |
| 2015 | Reliable Physical Unclonable Functions Using Data Retention Voltage of SRAM CellsabstractPhysical unclonable functions (PUFs) are circuits that produce outputs determined by random physical variations from fabrication. The PUF studied in this paper utilizes the variation sensitivity of static random access memory (SRAM) data retention voltage (DRV), the minimum voltage at which each cell can retain state. Prior work shows that DRV can uniquely identify circuit instances with 28% greater success than SRAM power-up states that are used in PUFs [1]. However, DRV is highly sensitive to temperature, and until now this makes it unreliable and unsuitable for use in a PUF. In this paper, we enable DRV PUFs by proposing a DRV-based hash function that is insensitive to temperature. The new hash function, denoted DRV-based hashing (DH), is reliable across temperatures because it utilizes the temperature-insensitive ordering of DRVs across cells, instead of using the DRVs in absolute terms. To evaluate the security and performance of the DRV PUF, we use DRV measurements from commercially available SRAM chips, and use data from a novel DRV prediction algorithm. The prediction algorithm uses machine learning for fast and accurate simulation-free estimation of any cell's DRV, and the prediction error in comparison to circuit simulation has a standard deviation of 0.35 mV. We demonstrate the DRV PUF using two applications-secret key generation and identification. In secret key generation, we introduce a new circuit-level reliability knob as an alternative to error correcting codes. In the identification application, our approach is compared to prior work and shown to result in a smaller false-positive identification rate for any desired true-positive identification rate. Xiaolin Xu 0001, Amir Rahmati, Daniel E. Holcomb, Kevin Fu, Wayne P. Burleson |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2012 | TARDIS: Time and Remanence Decay in SRAM to Implement Secure Protocols on Embedded Devices without Clocks
Amir Rahmati, Mastooreh Salajegheh, Daniel E. Holcomb, Jacob Sorber, Wayne P. Burleson, Kevin Fu |
USENIX Security Symposium | 1 |