VLDB 2026 Research / reviewers in the wild / expert
Nader Sehatbakhsh
dblp:139/9042
· DBLP profile ↗
25ranked-venue papers
5as first author
18since 2021 · last 2026
0000-0001-7181-2258ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 5 first-author · 5 since 2021Computer networks · 8 · 8 since 2021Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Attest Like Software: Formally-Verified Software-Programmable Proof of Execution Architecture Using SoC FPGAsabstractProof of Execution (PoX) enables a remote verifier to confirm that a specific program executed fully, correctly, and without interference on a potentially compromised device. Existing PoX solutions typically rely on trusted execution environments (TEEs) or custom hardware extensions, which limit their applicability to legacy, cost-sensitive, or resource-constrained embedded platforms. Moreover, many prior designs compromise real-time availability by disabling interrupts, enforcing two-world execution models, or relying on heavyweight isolation mechanisms. These limitations make existing PoX approaches poorly suited for safety-critical cyber-physical systems (CPS), where timing guarantees and responsiveness are as important as security. Fatemeh Arkannezhad, Nader Sehatbakhsh |
FPGA | 2 |
| 2026 | LeakSEAL: Power Side-Channel Leakage Analysis and Mitigation for Secure Edge AI LearningabstractOn-chip learning enables machine learning models to be trained or updated directly on specialized hardware rather than on external CPUs or GPUs, offering lower latency, improved energy-efficiency, enhanced privacy, and real-time adaptability for edge devices. In Spiking Neural Networks (SNNs), this capability relies on dynamic synaptic weight adaptation, but such adaptability also introduces significant security risks. In this work, we demonstrate a power side-channel attack on a quantized SNN implemented on a CW305 FPGA platform using ChipWhisperer. Our analysis identifies consistent power leakage patterns associated with neuron update operations, allowing an attacker to infer internal model attributes without direct access to the model’s weights or inputs. We further perform Correlation Power Analysis (CPA) with a Hamming Weight leakage model to recover secret synaptic weights with high confidence using as few as 1,500 power traces. These results expose critical vulnerabilities in on-chip learning systems and SNN architectures, highlight realistic threats to IoT and edge applications, and motivate mitigation strategies at the software-hardware boundary, including secure design practices, cryptographic protections, and access control mechanisms, without significantly degrading performance. Veeramani Pugazhenthi, Md Muhtasim Alam Chowdhury, Sujan Ghimire, Harish Kumar Dharavath, Parsa Mirfasihi, Nader Sehatbakhsh, Pratik Satam, Soheil Salehi |
ACM Great Lakes Symposium on VLSI | 6 |
| 2026 | XR Devices Send WiFi Packets When They Should Not: Cross-Building Keylogging Attacks via Non-Cooperative Wireless Sensing
Christopher Vattheuer, Justin Feng, Hossein Khalili, Nader Sehatbakhsh, Omid Abari |
NDSS | 4 |
| 2026 | TIRA: Task-Based Intermittent Remote AttestationabstractIntermittent computing platforms powered by energy harvesting enable sustainable sensing and embedded intelligence in environments without reliable power. Recent advances support robust, task-based execution that tolerates frequent failures and ensures correct event-driven concurrency without the need for costly checkpointing. However, these systems lack basic security features, particularly remote attestation, undermining trust in adversarial or safety-critical settings. Fatemeh Arkannezhad, Nader Sehatbakhsh |
SenSys | 2 |
| 2026 | BISen: A Robust Framework for Efficient CNN Inference on Battery-Free Intelligent Sensory NodesabstractWe present BISen, a framework for efficient and reliable convolutional neural network (CNN) inference on battery-free, energy-harvesting IoT sensor nodes. Battery-powered deployments suffer from limited lifetimes, high replacement costs, and environmental impacts, problems that will intensify as IoT scales to billions of devices. Energy-harvesting nodes remove batteries but face intermittent power, resulting in frequent failures that corrupt the intermediate CNN state, require costly checkpointing and rollback, and amplify non-volatile memory (NVM) traffic under tight on-chip memory constraints, leaving little harvested energy for useful sensing and inference. BISen introduces a reactive intermittent execution model for CNN workloads on off-the-shelf ultra-low-power microcontrollers. An energy-aware state machine with a safe-stop mechanism halts execution before brownout, while selective checkpointing preserves only the minimal CNN state needed for forward progress. This enables seamless resumption across power cycles while sharply reducing NVM reads/writes and memory-access overheads. Across two commercial MCU+radio platforms, three real harvested power traces, and nine CNNs, BISen cuts NVM operations by up to 86.4%, reduces standby/load/store operations by up to 94.1%, 94.5%, and 90.7%, and improves sensing throughput by about 1.3−1.4× compared to a state-of-the-art reactive baseline under the same energy budget, enabling long-lived, battery-free, carbon-aware IoT deployments. Sepehr Tabrizchi, Shayan Gerami, Justin Feng, Nader Sehatbakhsh, David Z. Pan, Arman Roohi |
IEEE Trans. Computers | 4 |
| 2025 | Poster Abstract: RL-SEP: RL -Based S mart E xit Point Selection for Enhancing Energy Harvested System LongevityabstractRL-SEP is a reinforcement learning scheduler that optimizes neural network execution in energy-harvesting devices. By dynamically selecting quantization levels and early exit points, it improves active operation time by up to 11% over the reactive method while achieving 136% better accuracy-to-energy ratio and maintaining higher energy reserves. Testing on ResNet-18 and DenseNet-121 shows robust performance across various harvesting sources. Ali Shafiee Sarvestani, Sepehr Tabrizchi, Nader Sehatbakhsh, Arman Roohi |
SenSys | 3 |
| 2025 | Chimera: Creating Digitally Signed Fake Photos by Fooling Image Recapture and Deepfake Detectors
Alexander Vilesov, Jinghuai Zhang, Hossein Khalili, Achuta Kadambi, Nader Sehatbakhsh |
USENIX Security Symposium | 7 |
| 2024 | SCRIPT: A Multi-Objective Routing Framework for Securing Chiplet Systems against Distributed DoS AttacksabstractHeterogeneous 2.5D integration enables seamless integration of chiplets, hence reducing design time and costs. Concerns arise when dealing with untrustworthy chiplets, emphasizing the need for dependable Network-on-Interposer (NoI). This paper introduces SCRIPT, a secure routing framework to mitigate Distributed Denial-of-Service (DDoS) attacks in chiplet systems. SCRIPT obscures predictable paths exploited by attackers, disrupting orchestrated attacks. SCRIPT considers chiplet trust and criticality and employs a multi-objective optimization technique to enhance NoI performance and reliability. Evaluations show that SCRIPT enhances NoI security by at least 64% against DDoS attacks. Ebadollah Taheri, Pooya Aghanoury, Sudeep Pasricha, Mahdi Nikdast, Nader Sehatbakhsh |
ACM Great Lakes Symposium on VLSI | 5 |
| 2024 | LightPure: Realtime Adversarial Image Purification for Mobile Devices Using Diffusion ModelsabstractAutonomous mobile systems increasingly rely on deep neural networks for perception and decision-making. While effective, these systems are vulnerable to adversarial machine learning attacks where small perturbations in the input could significantly impact the outcome of the system. Common countermeasures include leveraging adversarial training and/or data or network transformation. Although widely used, the main drawback of these countermeasures is that they require full and invasive access to the classifiers, which are typically proprietary. Additionally, the cost of training or retraining is often prohibitively expensive for large models. To tackle this, purification models have recently been proposed. The aim is to incorporate a "purification" layer before classification, thereby eliminating the necessity to modify the classifier. Despite their effectiveness, state-of-the-art purification methods are compute-intensive, rendering them unsuitable for mobile systems where resources are constrained and large latency is not desired. Hossein Khalili, Vincent Li, Brandan Bright, Ali Payani, Ramana Rao Kompella, Nader Sehatbakhsh |
MobiCom | 7 |
| 2024 | RefreshChannels: Exploiting Dynamic Refresh Rate Switching for Mobile Device AttacksabstractMobile devices with dynamic refresh rate (DRR) switching displays have recently become increasingly common. For power optimization, these devices switch to lower refresh rates when idling, and switch to higher refresh rates when the content displayed requires smoother transitions. However, the security and privacy vulnerabilities of DRR switching have not been investigated properly. In this paper, we propose a novel attack vector called RefreshChannels that exploits DRR switching capabilities for mobile device attacks. Specifically, we first create a covert channel between two colluding apps that are able to stealthily share users' private information by modulating the data with the refresh rates, bypassing the OS sandboxing and isolation measures. Second, we further extend its applicability by creating a covert channel between a malicious app and either a phishing webpage or a malicious advertisement on a benign webpage. Our extensive evaluations on five popular mobile devices from four different vendors demonstrate the effectiveness and widespread impacts of these attacks. Finally, we investigate several countermeasures, such as restricting access to refresh rates, and find they are inadequate for thwarting RefreshChannels due to DDR's unique characteristics. Gaofeng Dong, Julian de Gortari Briseno, Akash Deep Singh, Justin Feng, Ankur Sarker, Nader Sehatbakhsh, Mani Srivastava 0001 |
MobiSys | 7 |
| 2024 | IDA: Hybrid Attestation with Support for Interrupts and TOCTOU
Fatemeh Arkannezhad, Justin Feng, Nader Sehatbakhsh |
NDSS | 3 |
| 2024 | Context-Aware Hybrid Encoding for Privacy-Preserving Computation in IoT DevicesabstractRecent years have witnessed a surge in hybrid IoT-cloud applications where an end user distributes the desired computation between the IoT and cloud nodes. While achieving significant speed up, the major caveat of this approach is data privacy. Privacy-preserving methods have received major attention in the past few years, mainly because they can potentially solve this issue. Among several proposals, methods based on dynamic encoding and perturbation offer flexibility and low overhead. However, they often consider a weak adversary model or overlook practical limitations, such as encoding latency and complexity. This work proposes a new privacy-preserving method to address these issues. The key contributions of this article are twofold. First, unlike state-of-the-art, it proposes a new approach based on evolutionary algorithms to systematically evaluate the robustness of the encoding algorithm against a large population of potential adversaries. Second, it develops a dynamic obfuscation strategy that balances latency requirements in a realistic IoT-cloud hybrid ecosystem and privacy demands. Additionally, our method offers a unique benefit: it can be used alone for privacy protection, or it can be integrated with most existing methods to enhance privacy and reduce latency. The applicability and effectiveness of our proposed methods are thoroughly evaluated using two popular deep neural networks in a real-world IoT-cloud setting. We study the impact of our approach on important metrics, such as accuracy and privacy. Our results show that our proposed method can improve the overall privacy of a given IoT-cloud hybrid ecosystem by more than 10% on average. Hossein Khalili, Hao-Jen Chien, Amin Hass, Nader Sehatbakhsh |
IEEE Internet Things J. | 4 |
| 2023 | Hybrid Obfuscation of Chiplet-Based SystemsabstractThe growing concern about offshore chip manufacturing has created considerable interest in solutions that can ensure the integrity and security of chips. Among various solutions, split manufacturing has received a lot of attention due to its security guarantees. With the recent emergence of new heterogeneous manufacturing technologies, including chiplet-based systems, there is a new opportunity for revisiting the design considerations for split manufacturing to fully exploit the opportunities presented by chiplet-based systems and improve various metrics, such as security, performance, and overhead.This work improves the state-of-the-art in secure chip manufacturing by proposing a new split manufacturing scheme. The key idea is to exploit the capabilities provided by chiplet integration technology for designing a new hybrid split manufacturing scheme that includes both vertical and horizontal splitting. Unlike existing vertical-only split manufacturing mechanisms, that target obfuscation of interconnections by splitting the design at a specific metallization layer into two portions, the proposed hybrid method increases trust by exploiting the chiplet paradigm shift, specifically, breaking the design into sub-designs, each represented by chiplets (independently fabricated), and obfuscating interconnections among them. The proposed obfuscation mechanism targets systems that exploit the chiplet technology to obtain important performance advantages, thus any chiplet-related overhead is not due to obfuscation. We evaluate our method using several experiments and compare it with the state-of-the-art using standard metrics, including area, power, delay, wirelength, and trust. Compared to conventional split manufacturing, our hybrid method achieves up to 245× higher trust, while exhibiting negligible overhead. Yousef Safari, Pooya Aghanoury, Subramanian S. Iyer, Nader Sehatbakhsh, Boris Vaisband |
DAC | 4 |
| 2023 | Resource-Aware DNN Partitioning for Privacy-Sensitive Edge-Cloud Systems
Aolin Ding, Amin Hass, Nader Sehatbakhsh, Saman A. Zonouz |
ICONIP (5) | 4 |
| 2023 | Everything has its Bad Side and Good Side: Turning Processors to Low Overhead Radios Using Side-ChannelsabstractSide-channels have traditionally been exploited as a means of uncovering sensitive information such as cryptographic keys from a computing device. In particular, past work has shown that electromagnetic (EM) radiation from a device’s processor and memory during the execution of code and data can be used by attackers to extract private information. In contrast, instead of considering side-channels and electromagnetic radiation as vulnerabilities, we see them as opportunities for wireless communication on resource-limited IoT devices. We present SideComm, a side-channel-based communication system that leverages processors’ EM side-channels to enable resource-limited IoT devices to wirelessly send their data without having any radios. The main advantage of this approach is completely eliminating the need for a conventional radio and antenna, which offers energy savings, simplicity, and flexibility for IoT devices. Our evaluation demonstrates SideComm’s ability to achieve a communication range of more than 10m (enabling ≥ 3 dB SNR at 15m) and to work in non-line-of-sight scenarios, such as around corners and through walls. We believe SideComm can enable increased connectivity for many resource-constrained IoT devices in smart environments. Justin Feng, Timothy Jacques, Omid Abari, Nader Sehatbakhsh |
IPSN | 4 |
| 2023 | Demo Abstract: Leveraging Side-Channels to Turn Processors into Low Overhead RadiosabstractTraditionally, side channels have been exploited to uncover sensitive information such as cryptographic keys from computing devices. An attacker can extract private information from a device’s processor and memory by using electromagnetic (EM) radiation while code and data are being executed. Rather than seeing side-channels and electromagnetic radiation as vulnerabilities, we consider them as potential wireless communication channels for resource-constrained devices. The main advantage of this approach is completely eliminating the need for a conventional radio and antenna, which offers energy savings, simplicity, and flexibility for resource-constrained devices. Justin Feng, Timothy Jacques, Omid Abari, Nader Sehatbakhsh |
IPSN | 4 |
| 2023 | Enc2: Privacy-Preserving Inference for Tiny IoTs via Encoding and EncryptionabstractPrivacy-preserving machine learning (PPML) techniques have allowed remote and private inference for resource-constrained internet-of-things (IoT) devices on the cloud. The main challenge in most of the existing PPML technologies is a severe slowdown in inference latency mainly due to the use of encryption during the computation. To combat this, an emerging method is to leverage encoding as an alternative. While this results in a significant speedup, it imposes the burden of encoding to the resource-constrained IoT/edge device. Despite being feasible for simple workloads where encoding is lightweight, devices with very limited computational capabilities face a tradeoff between latency and privacy when performing complex tasks. Hao-Jen Chien, Hossein Khalili, Amin Hass, Nader Sehatbakhsh |
MobiCom | 4 |
| 2021 | IDEA: Intrusion Detection through Electromagnetic-Signal Analysis for Critical Embedded and Cyber-Physical SystemsabstractWe propose a novel framework called IDEA that exploits electromagnetic (EM) side-channel signals to detect malicious activity on embedded and cyber-physical systems (CPS). IDEA first records EM emanations from an uncompromised reference device to establish a baseline of reference EM patterns. IDEA then monitors the target device's EM emanations. When the observed EM emanations deviate from the reference patterns, IDEA reports this as an anomalous or malicious activity. IDEA does not require any resource or infrastructure on, or any modification to, the monitored system itself. In fact, IDEA is isolated from the target device, and monitors the device without any physical contact. We evaluate IDEA by monitoring the target device while it is executing embedded applications with malicious code injections such as Distributed Denial of Service (DDoS), Ransomware and code modification. We further implement a control-flow hijack attack, an advanced persistent threat, and a firmware modification on three CPSs: an embedded medical device called SyringePump, an industrial Proportional-Integral-Derivative (PID) Controller, and a Robotic Arm, using a popular embedded system, Arduino UNO. The results demonstrate that IDEA can detect different attacks with excellent accuracy (AUC > 99.5%, and 100 percent detection with less than 1 percent false positives) from distances up to 3 m. Haider Adnan Khan, Nader Sehatbakhsh, Luong N. Nguyen, Robert Locke Callan, Arie Yeredor, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsabstractSide-channel attacks have become a serious security concern for computing systems, especially for embedded devices, where the device is often located in, or in proximity to, a public place, and yet the system contains sensitive information. To design systems that are highly resilient to such attacks, an accurate and efficient design-stage quantitative analysis of side-channel leakage is needed. For many systems properties (e.g., performance, power, etc.), cycle-accurate simulation can provide such an efficient-yet-accurate design-stage estimate. Unfortunately, for an important class of side-channels, electromagnetic emanations, such a model does not exist, and there has not even been much quantitative evidence about what level of modeling detail (e.g., hardware, microarchitecture, etc.) would be needed for high accuracy. This paper presents EMSim, an approach that enables simulation of the electromagnetic (EM) side-channel signals cycle-by-cycle using a detailed micro-architectural model of the device. To evaluate EMSim, we compare its signals against actual EM signals emanated from real hardware (FPGA-based RISC-V processor), and find that they match very closely. To gain further insights, we also experimentally identify how the accuracy of the simulation degrades when key microarchitectural features (e.g., pipeline stall, cache-miss, etc.) and other hardware behaviors (e.g., data-dependent switching activity) are omitted from the simulation model. We further evaluate how robust the simulation-based results are, by comparing them to real signals collected in different conditions (manufacturing, distance, etc.). Finally, to show the applicability of EMSim, we demonstrate how it can be used to measure side-channel leakage through simulation at design-stage. Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
HPCA | 1 |
| 2020 | A New Side-Channel Vulnerability on Modern Computers by Exploiting Electromagnetic Emanations from the Power Management UnitabstractThis paper presents a new micro-architectural vulnerability on the power management units of modern computers which creates an electromagnetic-based side-channel. The key observations that enable us to discover this sidechannel are: 1) in an effort to manage and minimize power consumption, modern microprocessors have a number of possible operating modes (power states) in which various sub-systems of the processor are powered down, 2) for some of the transitions between power states, the processor also changes the operating mode of the voltage regulator module (VRM) that supplies power to the affected sub-system, and 3) the electromagnetic (EM) emanations from the VRM are heavily dependent on its operating mode. As a result, these state-dependent EM emanations create a side-channel which can potentially reveal sensitive information about the current state of the processor and, more importantly, the programs currently being executed. To demonstrate the feasibility of exploiting this vulnerability, we create a covert channel by utilizing the changes in the processor's power states. We show how such a covert channel can be leveraged to exfiltrate sensitive information from a secured and completely isolated (air-gapped) laptop system by placing a compact, inexpensive receiver in proximity to that system. To further show the severity of this attack, we also demonstrate how such a covert channel can be established when the target and the receiver are several meters away from each other, including scenarios where the receiver and the target are separated by a wall. Compared to the state-of-the-art, the proposed covert channel has >3x higher bit-rate. Finally, to demonstrate that this new vulnerability is not limited to being used as a covert channel, we demonstrate how it can be used for attacks such as keystroke logging. Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
HPCA | 1 |
| 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic SignalsabstractCyber-physical systems (CPS) are controlling many critical and sensitive aspects of our physical world while being continuously exposed to potential cyber-attacks. These systems typically have limited performance, memory, and energy reserves, which limits their ability to run existing advanced malware protection, and that, in turn, makes securing them very challenging. To tackle these problems, this paper proposes, REMOTE, a new robust framework to detect malware by externally observing Electromagnetic (EM) signals emitted by an electronic computing device (e.g., a microprocessor) while running a known application, in real-time and with a low detection latency, and without any a priori knowledge of the malware. REMOTE does not require any resources or infrastructure on, or any modifications to, the monitored system itself, which makes REMOTE especially suitable for malware detection on resource-constrained devices such as embedded devices, CPSs, and Internet of Things (IoT) devices where hardware and energy resources may be limited. To demonstrate the usability of REMOTE in real-world scenarios, we port two real-world programs (an embedded medical device and an industrial PID controller), each with a meaningful attack (a code-reuse and a code-injection attack), to four different hardware platforms. We also port shellcode-based DDoS and Ransomware attacks to five different standard applications on an embedded system. To further demonstrate the applicability of REMOTE to commercial CPS, we use REMOTE to monitor a Robotic Arm. Our results on all these different hardware platforms show that, for all attacks on each of the platforms, REMOTE successfully detects each instance of an attack and has99.9 percent true positive rates) under all these conditions. We also compare REMOTE to prior work EDDIE [1] and SYNDROME [2], and demonstrate that these prior work are unable to achieve high accuracy under these variations. Nader Sehatbakhsh, Alireza Nazari, Monjur Alam, Frank Werner 0005, Yuanda Zhu, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Computers | 1 |
| 2020 | Communication Model and Capacity Limits of Covert Channels Created by Software ActivitiesabstractIt has been shown that digital and/or analog characteristics of electronic devices during executing programs can create a side-channel which an attacker can exploit to extract sensitive information such as cryptographic keys. When the attacker modifies the software application to exfiltrate sensitive information through a channel, this channel is called a covert channel. In this paper, we model this covert channel as a communication channel and derive upper and lower capacity bounds. Because the covert channels are not designed to transmit information, they are exposed not only to the errors created by the transmission, but also by varying the execution time of computer activities, and/or by insertions from other activities such as interrupts, stalls, etc. Combining all of these effects, we propose to model the covert channel as an insertion channel where the transmitted sequence is a pulse amplitude modulated signal with random pulse positions. Utilizing this model, we derive capacity bounds of the covert channel with random insertion and substitution due to the noise and jitter errors, and propose a receiver design that can correctly detect the computer-activity-created signals. To illustrate the severity of leakages, we perform experiments with high clock speed devices at some distance. Further, the theoretical derivations are compared to empirical results, and show good agreement. Baki Berkay Yilmaz, Nader Sehatbakhsh, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic SignalsabstractEstablishing trust for an execution environment is an important problem, and practical solutions for it rely on attestation, where an untrusted system (prover) computes a response to a challenge sent by the trusted system (verifier). The response typically is a checksum of the prover's program, which the verifier checks against expected values for a "clean" (trustworthy) system. The main challenge in attestation is that, in addition to checking the response, the verifier also needs to verify the integrity of the response computation. On higher-end processors, this integrity is verified cryptographically, using dedicated trusted hardware. On embedded systems, however, constraints prevent the use of such hardware support. Instead, a popular approach is to use the request-to-response time as a way to establish confidence. However, the overall request-to-response time provides only one coarse-grained measurement from which the integrity of the attestation is to be inferred, and even that is noisy because it includes the network latency and/or variations due to micro-architectural events. Thus, the attestation is vulnerable to attacks where the adversary has tampered with response computation, but the resulting additional computation time is small relative to the overall request-to-response time. Nader Sehatbakhsh, Alireza Nazari, Haider Adnan Khan, Alenka G. Zajic, Milos Prvulovic |
MICRO | 1 |
| 2017 | EDDIE: EM-Based Detection of Deviations in Program ExecutionabstractThis paper describes EM-Based Detection of Deviations in Program Execution (EDDIE), a new method for detecting anomalies in program execution, such as malware and other code injections, without introducing any overheads, adding any hardware support, changing any software, or using any resources on the monitored system itself. Monitoring with EDDIE involves receiving electromagnetic (EM) emanations that are emitted as a side effect of execution on the monitored system, and it relies on spikes in the EM spectrum that are produced as a result of periodic (e.g. loop) activity in the monitored execution. During training, EDDIE characterizes normal execution behavior in terms of peaks in the EM spectrum that are observed at various points in the program execution, but it does not need any characterization of the malware or other code that might later be injected. During monitoring, EDDIE identifies peaks in the observed EM spectrum, and compares these peaks to those learned during training. Since EDDIE requires no resources on the monitored machine and no changes to the monitored software, it is especially well suited for security monitoring of embedded and IoT devices. We evaluate EDDIE on a real IoT system and in a cycle-accurate simulator, and find that even relatively brief injected bursts of activity (a few milliseconds) are detected by EDDIE with high accuracy, and that it also accurately detects when even a few instructions are injected into an existing loop within the application. Alireza Nazari, Nader Sehatbakhsh, Monjur Alam, Alenka G. Zajic, Milos Prvulovic |
ISCA | 2 |
| 2016 | Spectral profiling: Observer-effect-free profiling by monitoring EM emanationsabstractThis paper presents Spectral Profiling, a new method for profiling program execution without instrumenting or otherwise affecting the profiled system. Spectral Profiling monitors EM emanations unintentionally produced by the profiled system, looking for spectral “spikes” produced by periodic program activity (e.g. loops). This allows Spectral Profiling to determine which parts of the program have executed at what time. By analyzing the frequency and shape of the spectral “spike”, Spectral Profiling can obtain additional information such as the per-iteration execution time of a loop. The key advantage of Spectral Profiling is that it can monitor a system as-is, without program instrumentation, system activity, etc. associated with the profiling itself, i.e. it completely eliminates the “Observer's Effect” and allows profiling of programs whose execution is performance-dependent and/or programs that run on even the simplest embedded systems that have no resources or support for profiling. We evaluate the effectiveness of Spectral Profiling by applying it to several benchmarks from MiBench suite on a real system, and also on a cycle-accurate simulator. Our results confirm that Spectral Profiling yields useful information about the runtime behavior of a program, allowing Spectral Profiling to be used for profiling in systems where profiling infrastructure is not available, or where profiling overheads may perturb the results too much (“Observer's Effect”). Nader Sehatbakhsh, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic |
MICRO | 1 |