VLDB 2026 Research / reviewers in the wild / expert
Nisha Panwar
dblp:141/6261
· DBLP profile ↗
27ranked-venue papers
6as first author
11since 2021 · last 2025
0000-0002-7179-5213ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 1 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Spark: Smart Building Fire Prediction And Risk AnalysisabstractThis paper develops Spark - a novel algorithm for predicting fire spread in smart buildings. Spark leverages prior information about the building (e.g., room flammability, structural layout, and occupant distribution) together with real-time multimodal sensing data from static sensors (e.g., temperature sensors, smoke detectors, and embedded structural monitoring devices), dynamic sensors (e.g., drones and robots), and human sensors such as firefighters. By continuously integrating these heterogeneous information streams, Spark produces a realtime and adaptive prediction of fire spread. Specifically, Spark classifies rooms into risk zones (e.g., safe, vulnerable, and critical) using a clustering algorithm. Anik Pramanik, Nisha Panwar, Laramie V. Potts, Jainam Shah, Shantanu Sharma 0001 |
NCA | 3 |
| 2024 | WiFi Traffic Inspection for Obscured Devices
Maksuda Rabeya, Nisha Panwar |
NCA | 2 |
| 2024 | Prism: Privacy-Preserving and Verifiable Set Computation Over Multi-Owner Secret Shared Outsourced DatabasesabstractPrivate set computation over multi-owner databases is an important problem with many applications — the most well studied of which is private set intersection (PSI). This paper proposesPrism, a secret-sharing based approach to compute private set operations (i.e., intersection and union, as well as aggregates such as count, sum, average, maximum, minimum, and median) over outsourced databases belonging to multiple owners.Prismenables data owners to pre-load the data onto non-colluding servers and exploits the additive and multiplicative properties of secret-shares to compute the above-listed operations.Prismtakes (at most) two rounds of communication between non-colluding servers (storing the secret-shares) and the querier for executing the above-mentioned operations, resulting in a very efficient implementation.Prismalso supports result verification techniques for each operation to detect malicious adversaries. Experimental results show thatPrismscales both in terms of the number of data owners and database sizes, to which prior approaches do not scale. Shantanu Sharma 0001, Yin Li 0001, Sharad Mehrotra, Nisha Panwar, Peeyush Gupta, Dhrubajyoti Ghosh |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Information-Theoretically Secure and Highly Efficient Search and Row RetrievalabstractInformation-theoretic or unconditional security provides the highest level of security --- independent of the computational capability of an adversary. Secret-sharing techniques achieve information-theoretic security by splitting a secret into multiple parts (called shares ) and storing the shares across non-colluding servers. However, secret-sharing-based solutions suffer from high overheads due to multiple communication rounds among servers and/or information leakage due to access-patterns ( i.e. , the identity of rows satisfying a query) and volume ( i.e. , the number of rows satisfying a query). We propose S 2 , an information-theoretically secure approach that uses both additive and multiplicative secret-sharing, to efficiently support a large class of selection queries involving conjunctive, disjunctive, and range conditions. Two major contributions of S 2 are: ( i ) a new search algorithm using additive shares based on fingerprints, which were developed for string-matching over cleartext; and ( ii ) two row retrieval algorithms: one is based on multiplicative shares and another is based on additive shares. S 2 does not require communication among servers storing shares and does not reveal any information to an adversary based on access-patterns and volume. Shantanu Sharma 0001, Yin Li 0001, Sharad Mehrotra, Nisha Panwar, Komal Kumari, Swagnik Roychoudhury |
Proc. VLDB Endow. | 4 |
| 2022 | QUEST: Privacy-Preserving Monitoring of Network Dataabstract[J1C2 Presentation Abstract at IEEE SERVICES 2021 for IEEE Transactions on Services Computing DOI 10.1109/TSC.2022.3166802] Shantanu Sharma 0001, Sharad Mehrotra, Nisha Panwar, Nalini Venkatasubramanian, Peeyush Gupta, Guoxi Wang |
SERVICES | 3 |
| 2022 | IoT Notary: Attestable Sensor Data Capture in IoT EnvironmentsabstractContemporary IoT environments, such as smart buildings, require end-users to trust data-capturing rules published by the systems. There are several reasons why such a trust is misplaced—IoT systems may violate the rules deliberately or IoT devices may transfer user data to a malicious third-party due to cyberattacks, leading to the loss of individuals’ privacy or service integrity. To address such concerns, we propose IoT Notary , a framework to ensure trust in IoT systems and applications. IoT Notary provides secure log sealing on live sensor data to produce a verifiable “proof-of-integrity,” based on which a verifier can attest that captured sensor data adhere to the published data-capturing rules. IoT Notary is an integral part of TIPPERS, a smart space system that has been deployed at the University of California, Irvine to provide various real-time location-based services on the campus. We present extensive experiments over real-time WiFi connectivity data to evaluate IoT Notary , and the results show that IoT Notary imposes nominal overheads. The secure logs only take 21% more storage, while users can verify their one day’s data in less than 2 s even using a resource-limited device. Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian, Mamadou H. Diallo, Ardalan Amiri Sani |
ACM Trans. Internet Things | 1 |
| 2022 | Obscure: Information-Theoretically Secure, Oblivious, and Verifiable Aggregation Queries on Secret-Shared Outsourced DataabstractDespite exciting progress on cryptography, secure and efficient query processing over outsourced data remains an open challenge. We develop a communication-efficient and information-theoretically secure system, entitledObscurefor aggregation queries with conjunctive or disjunctive predicates, using secret-sharing.Obscureis strongly secure (i.e., secure regardless of the computational-capabilities of an adversary) and prevents the network, as well as, the (adversarial) servers to learn the user’s queries, results, or the database. In addition,Obscureprovides additional security features, such as hiding access-patterns (i.e., hiding the identity of the tuple satisfying a query) and hiding query-patterns (i.e., hiding which two queries are identical). Also,Obscuredoes not require any communication between any two servers that store the secret-shared data before/during/after the query execution. Moreover, our techniques deal with the secret-shared data that is outsourced by a single or multiple database owners, as well as, allows a user, which may not be the database owner, to execute the query over secret-shared data. We further develop (non-mandatory) privacy-preserving result verification algorithms that detect malicious behaviors, and experimentally validate the efficiency ofObscureon large datasets, the size of which prior approaches of secret-sharing or multi-party computation systems have not scaled to. Peeyush Gupta, Yin Li 0001, Sharad Mehrotra, Nisha Panwar, Shantanu Sharma 0001, Sumaya Almanee |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2022 | Quest: Privacy-Preserving Monitoring of Network Data: A System for Organizational Response to PandemicsabstractMost modern organizations today support network infrastructure to provide ubiquitous network coverage at their premises. Such a network infrastructure consisting of a set of access points deployed at different locations in buildings can be used to support coarse-level localization of individuals, who connect to the infrastructure using their mobile devices. This paper describes a system, entitledQuestthat supports a variety of applications (e.g., identifying hotspot regions, finding people who are potentially exposed to a condition such as COVID-19, occupancy count of a region/floor/building) based on network data to empower organizations to maintain safety at their workplace/premises.Questbuilds the above functionalities while fully protecting the privacy of individuals.Questincorporates computationally- and information-theoretically-secure protocols that prevent adversaries from gaining knowledge of an individual's location history (based on WiFi data). We describe the architecture, design choices, and implementation of the proposed security/privacy techniques inQuest. We, also, validate the practicality ofQuestand evaluate it thoroughly via an actual campus-scale deployment at our organization over a very large dataset of over 50M rows. Shantanu Sharma 0001, Sharad Mehrotra, Nisha Panwar, Nalini Venkatasubramanian, Peeyush Gupta, Guoxi Wang |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | PRISM: Private Verifiable Set Computation over Multi-Owner Outsourced DatabasesabstractThis paper proposes Prism, a secret sharing based approach to compute private set operations (i.e., intersection and union), as well as aggregates over outsourced databases belonging to multiple owners. Prism enables data owners to pre-load the data onto non-colluding servers and exploits the additive and multiplicative properties of secret-shares to compute the above-listed operations in (at most) two rounds of communication between the servers (storing the secret-shares) and the querier, resulting in a very efficient implementation. Also, Prism does not require communication among the servers and supports result verification techniques for each operation to detect malicious adversaries. Experimental results show that Prism scales both in terms of the number of data owners and database sizes, to which prior approaches do not scale. Yin Li 0001, Dhrubajyoti Ghosh, Peeyush Gupta, Sharad Mehrotra, Nisha Panwar, Shantanu Sharma 0001 |
SIGMOD Conference | 5 |
| 2021 | Integrity Verification for Streaming IoT Applications with a Minimalist Logging Scheme
Shuangsheng Lou, Nisha Panwar, Gagan Agrawal |
SMARTCOMP | 2 |
| 2021 | CANOPY: A Verifiable Privacy-Preserving Token Ring-Based Communication Protocol for Smart HomesabstractThis article focuses on the new privacy challenges that arise in smart homes. Specifically, the article focuses on inferring the user’s activities—which may, in turn, lead to the user’s privacy—via inferences through device activities and network traffic analysis. We develop techniques that are based on a cryptographically secure token circulation in a ring network consisting of smart home devices to prevent inferences from device activities, via device workflow , i.e., inferences from a coordinated sequence of devices’ actuation. The solution hides the device activity and corresponding channel activities, thus preserving the individual’s activities. We also extend our solution to deal with a large number of devices and devices that produce large-sized data by implementing parallel rings. Our experiments also evaluate the performance in terms of communication overheads of the proposed approach and the obtained privacy. Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2020 | Obscure: Information-Theoretically Secure, Oblivious, and Verifiable Aggregation QueriesabstractWe develop a secret-sharing-based prototype, entitled Obscure that provides communication-efficient and information-theoretically secure algorithms for aggregation queries using multi-party computation (MPC). The query execution algorithms over secret-shared data are developed to deal with an honest but curious, as well as, a malicious server by providing result verification algorithms. Obscure prevents an adversary to know the data, the query, and the tuple-identity satisfying the query. Peeyush Gupta, Yin Li 0001, Sharad Mehrotra, Nisha Panwar, Shantanu Sharma 0001 |
CODASPY | 4 |
| 2020 | IoT Expunge: Implementing Verifiable Retention of IoT DataabstractThe growing deployment of Internet of Things (IoT) systems aims to ease the daily life of end-users by providing several value-added services. However, IoT systems may capture and store sensitive, personal data about individuals in the cloud, thereby jeopardizing user-privacy. Emerging legislation, such as California's CalOPPA and GDPR in Europe, support strong privacy laws to protect an individual's data in the cloud. One such law relates to strict enforcement of data retention policies. This paper proposes a framework, entitled IoT Expunge that allows sensor data providers to store the data in cloud platforms that will ensure enforcement of retention policies. Additionally, the cloud provider produces verifiable proofs of its adherence to the retention policies. Experimental results on a real-world smart building testbed show that IoT Expunge imposes minimal overheads to the user to verify the data against data retention policies. Nisha Panwar, Shantanu Sharma 0001, Peeyush Gupta, Dhrubajyoti Ghosh, Sharad Mehrotra, Nalini Venkatasubramanian |
CODASPY | 1 |
| 2020 | Proxy Signcryption Scheme for Vehicle Infrastructure Immune to Randomness Leakage and Setup AttacksabstractWe propose a proxy signcryption scheme for a multi-party setting, resistant to randomness leakage and setup attacks. Our scheme is an alternative to typical constructions, based on a double Schnorr signature approach, where the linear combination of long term secrets and ephemeral random values occurs both at the initiator and proxy nodes. Our scheme is provably secure in a new stronger model, where the adversary can control the randomness of both parties. Moreover, our proposition is well suited for networks of many independent and moving nodes; especially modern railway infrastructure and vehicle-to-vehicle/infrastructure (V2X) environments, where a broad range of devices with potentially weak computational power and inadequate randomness, is used. Early benchmarks and performance analysis from our proof of concept implementation, suggest that nodes, which use regular Schnorr based schemes, could be successfully upgraded to our more secure alternative construction. Collected timings are still at the acceptable level, proving the applicability of our scheme in modern railway and V2X environments. Lukasz Krzywiecki, Hannes Salin, Nisha Panwar, Mykola Pavlov |
NCA | 3 |
| 2020 | Security and Privacy Aspects in 5G NetworksabstractThe future mobile 5G networks are envisioned to support billions of devices, higher data rate, and omnipresent connectivity, with the help of a diverse set of technologies, e.g., network densification, mMIMO, mm-Wave, full-duplex radios, network slicing, visual-light communication, cognitive radio networks, device-to-device communications, machine-to-machine communications, and satellite-based communication. While 5G will assist in a wide range of applications, heterogeneous devices and technologies impose significant threats to 5G networks as compared to the previous generation of the communication networks. In this article, we discuss the need of new security techniques for 5G networks and the key research challenges related to security/privacy in 5G networks. Nisha Panwar, Shantanu Sharma 0001 |
NCA | 1 |
| 2019 | Verifiable Round-Robin Scheme for Smart HomesabstractAdvances in sensing, networking, and actuation technologies have resulted in the IoT wave that is expected to revolutionize all aspects of modern society. This paper focuses on the new challenges of privacy that arise in IoT in the context of smart homes. Specifically, the paper focuses on preventing the user's privacy via inferences through channel and in-home device activities. We propose a method for securely scheduling the devices while decoupling the device and channels activities. The proposed solution avoids any attacks that may reveal the coordinated schedule of the devices, and hence, also, assures that inferences that may compromise individual's privacy are not leaked due to device and channel level activities. Our experiments also validate the proposed approach, and consequently, an adversary cannot infer device and channel activities by just observing the network traffic. Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian |
CODASPY | 1 |
| 2019 | Signature Based Authentication for Ephemeral Setup Attacks in Vehicular Sensor NetworksabstractIn this paper, we focus on the communication security perspective for connected vehicles that can be categorized into: V2V (Vehicle to Vehicle), V2I (Vehicle to Infrastructure - such as with road side units or a cloud) and the internal vehicle network connections. V2V and V2I improve driving safety and comfort through the dissemination of critical warning messages. We propose a scheme resistant to ephemeral key leakage attacks that imposes pre-computation threat with respect to the static secret key. In particular, the pseudorandom generators that are implemented into the hardware are non-verifiable with respect to sustaining the true randomness while choosing ephemeral keys. We present a formal security model in which the adversary has power to inject ephemeral values of her choice to the protocol and still cannot deduce the static secret keys. Lukasz Krzywiecki, Patryk Koziel, Nisha Panwar |
NCA | 3 |
| 2019 | IoT Notary: Sensor Data Attestation in Smart EnvironmentabstractContemporary IoT environments, such as smart buildings, require end-users to trust data-capturing rules published by the systems. There are several reasons why such a trust is misplaced - IoT systems may violate the rules deliberately or IoT devices may transfer user data to a malicious third-party due to cyberattacks, leading to the loss of individuals' privacy or service integrity. To address such concerns, we propose IoT Notary, a framework to ensure trust in IoT systems and applications. IoT Notary provides secure log sealing on live sensor data to produce a verifiable `proof-of-integrity,' based on which a verifier can attest that captured sensor data adheres to the published data-capturing rules. IoT Notary is an integral part of TIPPERS, a smart space system that has been deployed at UCI to provide various real-time location-based services in the campus. IoT Notary imposes nominal overheads for verification, thereby users can verify their data of one day in less than two seconds. Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian, Mamadou H. Diallo, Ardalan Amiri Sani |
NCA | 1 |
| 2019 | Obscure: Information-Theoretic Oblivious and Verifiable Aggregation QueriesabstractDespite extensive research on cryptography, secure and efficient query processing over outsourced data remains an open challenge. We develop communication-efficient and information-theoretically secure algorithms for privacy-preserving aggregation queries using multi-party computation (MPC). Specifically, query processing techniques over secret-shared data outsourced by single or multiple database owners are developed. These algorithms allow a user to execute queries on the secret-shared database and also prevent the network and the (adversarial) clouds to learn the user's queries, results, or the database. We further develop (non-mandatory) privacy-preserving result verification algorithms that detect malicious behaviors, and experimentally validate the efficiency of our approach over large datasets, the size of which prior approaches to secret-sharing or MPC systems have not scaled to. Peeyush Gupta, Yin Li 0001, Sharad Mehrotra, Nisha Panwar, Shantanu Sharma 0001, Sumaya Almanee |
Proc. VLDB Endow. | 4 |
| 2018 | Trustworthy Privacy Policy Translation in Untrusted IoT EnvironmentsabstractInternet of Thing (IoT) systems, such as smart buildings and smart cities, provide services to users (individuals and organizations) in various aspect of our lives. To provide such services, IoT systems need to handle data captured from multiple devices/sensors, and translation of data processing policies agreed by users (high-level) into commands for devices (device-level). The underlying assumption is that users trust IoT systems in honoring their policies. However, this trust assumption is incorrectly positioned since IoT systems may not be honest or may fall victim to cyberattacks. We address such concerns by providing mechanisms to help in ensuring trust and accountability at the time of translating a contract (agreed and signed policies). The objective of the proposed scheme is two fold, (1) translation of contracts from a high-level to device-level, (2) attestation of the translation. We have implemented the proposed scheme for contract translation and attestation of translation as a module and integrated it with the TIPPERS system (our IoT testbed under development). The results of our experiments highlight the feasibility of our proposed schemes. Mamadou H. Diallo, Nisha Panwar, Roberto Yus, Sharad Mehrotra |
IoTBDS | 2 |
| 2018 | Privacy-oriented dependency via deniable SIGMA protocol
Lukasz Krzywiecki, Kamil Kluczniak, Patryk Koziel, Nisha Panwar |
Comput. Secur. | 4 |
| 2017 | Dynamic attribute based vehicle authentication
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001 |
Wirel. Networks | 3 |
| 2016 | Peripheral authentication for autonomous vehiclesabstractWe propose a peripheral authentication scheme for autonomous vehicles. A mutual authentication protocol is required to secure every peripheral device access to a vehicle. Specifically, we present a vehicle to peripheral device authentication scheme. In addition, our three way handshake scheme for vehicle to keyfob authentication scheme based on generalized peripheral authentication scheme has been proposed. The vehicle to keyfob authentication scheme is adapted and improved with an additional attribute verification of the keyfob holder. Conventionally, vehicle to keyfob authentication is realized through a challenge-response verification protocol. An authentic coupling between the vehicle identity and the keyfob avoids any illegal access to the vehicle. However, these authentication messages can be relayed by an active adversary, thereby, can amplify the actual distance between the authentic vehicle and the keyfob. Eventually, through this malicious relaying an adversary can possibly get access to the vehicle, without any effort to generate or decode the crypto credentials. Our solution is a two party, three way handshake scheme with proactive and reactive commitment verification. Conceptually, our solution is different than the distance bounding protocols that requires multiple rounds of round trip delay measurement. Shlomi Dolev, Nisha Panwar |
NCA | 2 |
| 2016 | Optical PUF for Non-Forwardable Vehicle Authentication
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001 |
Comput. Commun. | 3 |
| 2016 | Vehicle authentication via monolithically certified public key and attributes
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001 |
Wirel. Networks | 3 |
| 2015 | Optical PUF for Non Forwardable Vehicle AuthenticationabstractModern vehicles are configured to exchange warning messages through IEEE 1609 Dedicated Short Range Communication (DSRC) over IEEE 802.11p Wireless Access in Vehicular Environment (WAVE). Essentially, these warning messages must associate an authentication factor such that the verifier authenticates the message origin via visual binding. Interestingly, the existing vehicle communication incorporates the message forward-ability as a requested feature for numerous applications. On the contrary, the vehicle security infrastructure is vulnerable to message forwarding i.e., Messages seem to originate from a malicious vehicle (due to non-detectable message relaying) instead of the actual message sender. We introduce the non forward-able authentication to avoid an adversary coalition attack scenario. These messages should be identifiable with respect to the immediate sender at every hop. We propose to utilize immediate optical response verification in association with the authenticated key exchange over radio channel. These optical responses are generated through hardware means, i.e., A certified Physically Unclonable Function (PUF) device embedded on the front and rear of the vehicle. Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001 |
NCA | 3 |
| 2014 | Dynamic Attribute Based Vehicle AuthenticationabstractIn the near future, vehicles will establish a spontaneous connection over a wireless radio channel, coordinating actions and information. Security infrastructure is most important in such a hazardous scope of vehicles communication for coordinating actions and avoiding accidents on the roads. One of the first security issues that need to be established is authentication. Vehicle authentication with visual binding prior to establishing a wireless radio channel of communication is useful only when the vehicles possess unique visual attributes. These vehicle static attributes (e.g., Licence number, brand and color) are certified together with the vehicle public key. Therefore, we consider the case of multiple malicious vehicles with identical visual static attributes. Apparently, dynamic attributes (e.g., Location and direction) can uniquely define a vehicle and can be utilized to resolve the true identity of vehicles. However, unlike static attributes, dynamic attributes cannot be signed by a trusted authority beforehand. We propose an approach to verify the coupling between non-certified dynamic attributes and certified static attributes on an auxiliary communication channel, for example, a modulated laser beam. Furthermore, we illustrate that the proposed approach can be used to facilitate the usage of existing authentication protocols such as NAXOS, in the new scope of ad-hoc vehicle networks. Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001 |
NCA | 3 |