VLDB 2026 Research / reviewers in the wild / expert
Mehdi Karimibiuki
dblp:13/11438
· DBLP profile ↗
7ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-2995-7354ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Feed-Forward Controller-Based Recovery for Robotic Vehicles From Physical AttacksabstractRobotic Vehicles (RV) rely extensively on sensor inputs to operate autonomously. Physical attacks such as sensor tampering and spoofing can feed erroneous sensor measurements to deviate RVs from their course and result in mission failures. In this paper, we present a Feed-Forward Controller based framework for automatically recovering RVs from physical attacks. We use machine learning (ML) to design an attack resilient Feed-Forward Controller (FFC), which runs in tandem with the RV's primary controller and monitors it. Under attacks, the FFC takes over from the RV's primary controller to recover the RV, and allows the RV to complete its mission successfully. Our evaluation on 6 RV systems including 3 real RVs shows that our proposed framework prevents crashes and allows RVs to complete their missions successfully despite attacks in 86% of the cases. Further, we propose designs to streamline the implementation of the FFC-based recovery and its application in new RV systems. Pritam Dash, Guanpeng Li, Zitao Chen 0001, Mehdi Karimibiuki, Karthik Pattabiraman |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Diagnosis-guided Attack Recovery for Securing Robotic Vehicles from Sensor Deception AttacksabstractSensors are crucial for perception and autonomous operation in robotic vehicles (RV). Unfortunately, RV sensors can be compromised by physical attacks such as sensor tampering or spoofing. In this paper, we present DeLorean, a unified framework for attack detection, attack diagnosis, and recovering RVs from sensor deception attacks (SDA). DeLorean can recover RVs even from strong SDAs in which the adversary targets multiple heterogeneous sensors simultaneously. We propose a novel attack diagnosis technique that inspects the attack-induced errors under SDAs, and identifies the targeted sensors using causal analysis. DeLorean then uses historic state information to selectively reconstruct physical states for compromised sensors, enabling targeted attack recovery under single or multi-sensor SDAs. We evaluate DeLorean on four real and two simulated RVs under SDAs targeting various sensors, and we find that it successfully recovers RVs from SDAs in 93% of the cases. Pritam Dash, Guanpeng Li, Mehdi Karimibiuki, Karthik Pattabiraman |
AsiaCCS | 3 |
| 2021 | PID-Piper: Recovering Robotic Vehicles from Physical AttacksabstractRobotic Vehicles (RV) rely extensively on sensor inputs to operate autonomously. Physical attacks such as sensor tampering and spoofing can feed erroneous sensor measurements to deviate RVs from their course and result in mission failures. In this paper, we present PID-Piper, a novel framework for automatically recovering RVs from physical attacks. We use machine learning (ML) to design an attack resilient Feed-Forward Controller (FFC), which runs in tandem with the RV's primary controller and monitors it. Under attacks, the FFC takes over from the RV's primary controller to recover the RV, and allows the RV to complete its mission successfully. Our evaluation on 6 RV systems including 3 real RVs shows that PID-Piper achieves high accuracy in emulating the RV's controller, in the absence of attacks, with no false positives. Further, PID-Piper allows RVs to complete their missions successfully despite attacks in 83% of the cases, while incurring low performance overheads. Pritam Dash, Guanpeng Li, Zitao Chen 0001, Mehdi Karimibiuki, Karthik Pattabiraman |
DSN | 4 |
| 2021 | Are you for Real? Authentication in Dynamic IoT SystemsabstractDynamic Internet-of-Things (IoT) systems are nonlinear cyber-physical systems that move around and operate in the physical environment under the control of stability laws in the cyber world. An example of such systems are Unmanned Aerial Vehicles (UAV s), or drones. In this environment, fake nodes can masquerade themselves as real nodes, to fool the command and control functions that can target resource management and lead to Denial-of-Service (DoS) attacks. In this paper, we present a novel authentication framework to identify fake nodes from the real ones by deriving and monitoring the stability function. More specifically, we exploit the Lyapunov stability function to validate the authenticity of a drone's physical behavior. We use training traces from real nodes to derive the stability function, then use it to authenticate traces at runtime. Our technique is implemented in a tool called Phoenix. We evaluate Phoenix with a system simulator as well as a real-world drone. We find that Phoenix takes about 50 ms to distinguish fake from real nodes, achieves a recall rate of over 96% and a precision rate of 95%, and can foil even determined attackers with limited computational resources. Mehdi Karimibiuki, Karthik Pattabiraman, André Ivanov |
PRDC | 1 |
| 2019 | Out of control: stealthy attacks against robotic vehicles protected by control-based techniquesabstractRobotic vehicles (RVs) are cyber-physical systems that operate in the physical world under the control of software functions. They are increasing in adoption in many industrial sectors. RVs rely on sensors and actuators for system operations and navigation. Control algorithm based estimation techniques have been used in RVs to minimize the effects of noisy sensors, prevent faulty actuator output, and recently, in detecting attacks against RVs. In this paper, we propose three kinds of attacks to evade the control-based detection techniques and cause RVs to malfunction. We also propose automated algorithms for performing the attacks without requiring the attacker to expend significant effort or know specific details of the RV, making the attacks applicable to a wide range of RVs. We demonstrate these attacks on ArduPilot simulators and two real RVs (a drone and a rover) in the presence of an Intrusion Detection System (IDS) using control estimation models to monitor the runtime behavior of the system. We find that the control models are incapable of detecting our stealthy attacks, and that the attacks can have significant adverse impact on the RV's mission (e.g., cause the RV to crash or deviate from its target significantly). Pritam Dash, Mehdi Karimibiuki, Karthik Pattabiraman |
ACSAC | 2 |
| 2018 | DynPolAC: Dynamic Policy-Based Access Control for IoT SystemsabstractIn the near future, Internet-of-Things (IoT) systems will be comprised of autonomous, highly interactive and moving objects that require frequent handshakes to exchange information in time intervals of seconds. Examples of such systems are drones and self-driving cars. In these scenarios, data integrity, confidentiality, and privacy protection are of critical importance. Further, updates need to be processed quickly and with low overheads due to the systems' resource-constrained nature. This paper proposes Dynamic Policy-based Access Control (DynPolAC) as a model for protecting information in such systems. We construct a new access control policy language that satisfies the properties of highly dynamic IoT environments. Our access control engine is comprised of a rule parser and a checker to process policies and update them at run-time with minimum service disruption. DynPolAC achieves more than 7x performance improvements when compared to previously proposed methods for authorization on resource-constrained IoT platforms, and achieves more than 3x faster response times overall. Mehdi Karimibiuki, Ekta Aggarwal, Karthik Pattabiraman, André Ivanov |
PRDC | 1 |
| 2013 | Post-Silicon Code Coverage for Multiprocessor System-on-Chip DesignsabstractEffective techniques for post-silicon validation are required to better evaluate functional correctness of increasingly complex multi and many-core SoCs. However, there is little data evaluating the coverage of post-silicon validation efforts on industrial-scale designs. In this paper, we address this knowledge gap by instrumenting a nontrivial SoC with on-chip coverage monitors to measure the coverage achieved by typical post-silicon validation tests, such as booting the operating system (OS). We compare coverage achieved pre and post-silicon, and also measure the area overhead required to monitor post-silicon coverage. Our results show that the typical test of booting the OS often achieves high coverage, well correlated to what is achieved by pre-silicon directed tests, but in some blocks the coverage can be low or markedly different between pre and post-silicon, highlighting the importance of post-silicon validation in general and post-silicon coverage measurement in particular. Kyle Balston, Mehdi Karimibiuki, Alan J. Hu, André Ivanov, Steve Wilton |
IEEE Trans. Computers | 2 |