VLDB 2026 Research / reviewers in the wild / expert
Patrick Cronin
dblp:131/5969
· DBLP profile ↗
10ranked-venue papers
5as first author
3since 2021 · last 2022
0000-0003-2091-4830ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 2 first-authorSecurity and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Time-Print: Authenticating USB Flash Drives with Novel Timing FingerprintsabstractUniversal Serial Bus (USB) ports are a ubiquitous feature in computer systems and offer a cheap and efficient way to provide power and data connectivity between a host and peripheral devices. Even with the rise of cloud and off-site computing, USB has played a major role in enabling data transfer between devices. Its usage is especially prevalent in high-security environments where systems are ‘air-gapped’ and not connected to the Internet. However, recent research has demonstrated that USB is not nearly as secure as once thought, with different attacks showing that modified firmware on USB mass storage devices can compromise a host system. While many defenses have been proposed, they require user interaction, advanced hardware support (incompatible with legacy devices), or utilize device identifiers that can be subverted by an attacker. In this paper, we present Time-Print, a novel timing-based fingerprinting method, for identifying USB mass storage devices. We create a fingerprint by timing a series of read operations from different locations on a drive, as the timing variations are unique enough to identify individual USB devices. Time-Print is low overhead, completely software-based, and does not require any extra or specialized hardware. To validate the efficacy of Time-Print, we examine more than 40 USB flash drives and conduct experiments in multiple authentication scenarios. The experimental results show that Time-Print can (1) identify known/unknown brand/model USB devices with greater than 99.5% accuracy, (2) identify seen/unseen devices of the same brand/model with 95% accuracy, and (3) classify USB devices from the same brand/model with an average accuracy of 98.7%. Patrick Cronin, Xing Gao 0001, Haining Wang 0001, Chase Cotton |
SP | 1 |
| 2021 | An Exploration of ARM System-Level Cache and GPU Side ChannelsabstractAdvanced RISC Machines (ARM) processors have recently gained market share in both cloud computing and desktop applications. Meanwhile, ARM devices have shifted to a more peripheral based design, wherein designers attach a number of coprocessors and accelerators to the System-on-a-Chip (SoC). By adopting a System-Level Cache, which acts as a shared cache between the CPU-cores and peripherals, ARM attempts to alleviate the memory bottleneck issues that exist between data sources and accelerators. This paper investigates emerging security threats introduced by this new System-Level Cache. Specifically, we demonstrate that the System-Level Cache can still be exploited to create a cache occupancy channel to accurately fingerprint websites. We redesign and optimize the attack for various browsers based on the ARM cache design, which can significantly reduce the attack duration while increasing accuracy. Moreover, we introduce a novel GPU contention channel in mobile devices, which can achieve similar accuracy to the cache occupancy channel. We conduct a thorough evaluation by examining these attacks across multiple devices, including iOS, Android, and MacOS with the new M1 MacBook Air. The experimental results demonstrate that (1) the System-Level Cache based website fingerprinting technique can achieve promising accuracy in both open (up to 90%) and closed (up to 95%) world scenarios, and (2) our GPU contention channel is more effective than the CPU cache channel on Android devices. Patrick Cronin, Xing Gao 0001, Haining Wang 0001, Chase Cotton |
ACSAC | 1 |
| 2021 | Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information Leakage
Patrick Cronin, Xing Gao 0001, Chengmo Yang, Haining Wang 0001 |
USENIX Security Symposium | 1 |
| 2020 | A Crowd-Based Explosive Detection System with Two-Level Feedback Sensor CalibrationabstractLarge, open, public events, such as marathons and festivals, have always presented a unique safety challenge. These sprawling events, which can take up entire city blocks or stretch for many miles, can draw tens to hundreds of thousands of spectators and in some cases have open admission. As it is impracticable to guarantee the subjection of every event-goer to a security screening, we propose a crowd-based explosive detection system that uses a multitude of low-cost ChemFET sensors which are distributed to attendees. As the sensors offer limited accuracy, we further propose a server-based decision-making framework that utilizes a two-level feedback loop between the sensors and the server and explores spatial and temporal locality of the collected data to overcome the inherent low-accuracy of individual sensors. We thoroughly explore two distinct detection schemes, stressing their performance under a myriad of conditions, thus showing that such a crowd-based detection system comprised of low-cost and low-accuracy sensors can deliver high detection accuracy with minimal false positives. Chengmo Yang, Patrick Cronin, Agamyrat Agambayev, Sule Ozev, A. Enis Çetin, Alex Orailoglu |
ICCAD | 2 |
| 2019 | Covert Data Exfiltration Using Light and Power ChannelsabstractAs the Internet of Things (IoT) continues to expand into every facet of our daily lives, security researchers have warned of its myriad security risks. While denial-of-service attacks and privacy violations have been at the forefront of research, covert channel communications remain an important concern. Utilizing a Bluetooth controlled light bulb, we demonstrate three separate covert channels, consisting of current utilization, luminosity and hue. To study the effectiveness of these channels, we implement exfiltration attacks using standard off-the-shelf smart bulbs and RGB LEDs at ranges of up to 160 feet. We analyze the identified channels for throughput, generality and stealthiness, and report transmission speeds of up to 832 bps. Patrick Cronin, Charles Gouert, Dimitris Mouris, Nektarios Georgios Tsoutsos, Chengmo Yang |
ICCD | 1 |
| 2018 | A collaborative defense against wear out attacks in non-volatile processorsabstractWhile the Internet of Things (IoT) keeps advancing, its full adoption is continually blocked by power delivery problems. One promising solution is Non-Volatile (NV) processors, which harvest energy for themselves and employ a NV memory hierarchy. This allows them to perform computations when power is available, checkpoint and hibernate when power is scarce, and resume their work at a later time. However, utilizing NV memory creates new security vulnerabilities in the form of wear out attacks in the register file. This paper explores the dangers of this design oversight and proposes a mitigation strategy that takes advantage of the unique properties and operating characteristics of NV processors. The proposed defense integrates the power management unit and a two-level register rotation approach, which improves NV processor endurance by 30.1x in attack situations and an average of 7.1x in standard workloads. Patrick Cronin, Chengmo Yang, Yongpan Liu |
DAC | 1 |
| 2016 | A mutual auditing framework to protect IoT against hardware TrojansabstractInternet-of-Things (IoT), wherein sensor nodes of different types are used to monitor different objects, are expected to be used in many critical domains. However, hardware Trojans, which are malicious modifications implanted in individual nodes, may utilize the wireless connection facility to leak confidential information or to collude with each other to cause catastrophic failures in the IoT. To defend against these types of network-level threats, our goal is to develop a lightweight framework to monitor communications in the IoT. Instead of relying on a centralized data center to monitor the behavior of all the nodes, we propose to exploit vendor diversity among the nodes to build a distributed framework wherein nodes monitor the trustworthiness of their neighbors. This mutual auditing scheme is able to detect any attempt to leak information or collude with other malicious nodes, thus constructing trustworthy communication channels between untrustworthy nodes. Chen Liu 0013, Patrick Cronin, Chengmo Yang |
ASP-DAC | 2 |
| 2016 | Routing path reuse maximization for efficient NV-FPGA reconfigurationabstractNon-Volatile memory-based FPGAs (NV-FPGAs) are expected to replace traditional SRAM-based FPGAs to achieve higher scalability and lower power consumption. Yet the slow write performance of NVMs not only challenges FPGA reconfiguration speed and overhead but also constrains the programming cycles of FPGAs. To efficiently configure switch boxes, the majority component of an FPGA, this paper proposes a routing path reuse technique. Technical contributions include a mathematical reconfiguration cost model of routing resources, a reuse-aware routing algorithm, as well as the incorporation of the proposed algorithm into the standard VTR CAD tool. Experiments on standard MCNC benchmarks show that the proposed scheme is able to achieve as much as 40% path reuse rate and reduce as much as 34.0% configuration cost for routing resources. Patrick Cronin, Chengmo Yang, Jingtong Hu |
ASP-DAC | 2 |
| 2015 | Fine-tuning CLB placement to speed up reconfigurations in NVM-based FPGAsabstractNon-volatile memories (NVMs) outperform traditional SRAMs in terms of low power consumption, high capacity, near-zero power-on delay, and high error-resistance. Researchers have demonstrated the possibilities of implementing FPGA building blocks with various types of NVMs. However, NVMs also bring several new design challenges to FPGAs: the slow write performance of NVM may degrade FPGA (re)configuration speed, while the limited write endurance of NVM constrains the number of times that the FPGA can be (re)configured. Unfortunately, none of these NVM features are taken into consideration in current FPGA synthesis tools, which have been optimized solely for SRAM-based FPGAs. To tackle this limitation, we propose to make the FPGA placement process aware of the slow and costly NVM writes. Our contributions are three-fold: We first construct mathematical models to characterize reconfiguration costs in NVM-based FPGAs. Second, we identify three types of flexibilities that can be exploited to reduce the reconfiguration cost. Finally, we present three approaches for designers to fine-tune the placement process to balance the reconfiguration cost and traditional timing and routability constraints according to their needs. The proposed algorithms are incorporated in Verilog-to-Routing (VTR) CAD tool. Experiments on standard MCNC benchmark circuits show that our approach eliminates up to 67% NVM writes during the reconfiguration process, thus effectively improving the performance and endurance of NVM-based FPGAs. Patrick Cronin, Chengmo Yang, Jingtong Hu |
FPL | 2 |
| 2015 | Non-volatile memories in FPGAs: Exploiting logic similarity to accelerate reconfiguration and increase programming cyclesabstractNon-volatile memory (NVM) technologies have been known for their advantages of large capacity, low energy consumption, high error-resistance, and near-zero power-on delay. It is expected that they will replace traditional SRAM as FPGA reconfigurable blocks. While NVMs promise FPGAs with more reconfigurable resources, lower power consumption, and higher resilience to power interruptions, they also impose two new design challenges: the slow write performance of NVMs may degrade FPGA reconfiguration speed, while their limited write endurance constrains FPGA programming cycles. To overcome these challenges, we propose a similarity driven approach to reduce reconfiguration cost in NVM-based FPGAs. When synthesizing a new design, its similarity to the design currently on the FPGA is characterized by taking both LUT contents and CLB-level topology into consideration. The reconfiguration cost minimization problem is formulated as a bipartite graph matching problem and solved optimally. Experiments on standard circuit benchmarks show that the proposed algorithms eliminate more than 57.4% of NVM writes during the reconfiguration process, thus effectively improving performance and endurance of NVM-based FPGAs. Patrick Cronin, Chengmo Yang, Jingtong Hu |
VLSI-SoC | 2 |