VLDB 2026 Research / reviewers in the wild / expert
Aanchal Malhotra
dblp:146/7951
· DBLP profile ↗
6ranked-venue papers
2as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AMM-based DEX on the XRP LedgerabstractAutomated Market Maker (AMM)-based Decentralized Exchanges (DEXs) are crucial in Decentralized Finance (DeFi), but Ethereum implementations suffer from high transaction costs and price synchronization challenges. To address these limitations, we compare the XRP Ledger (XRPL)-AMM-Decentralized Exchange (DEX), a protocol-level implementation, against a Generic AMM-based DEX (G-AMM-DEX) on Ethereum, akin to Uniswap’s V2 AMM implementation, through agent-based simulations using real market data and multiple volatility scenarios generated via Geometric Brownian Motion (GBM). Results demonstrate that the XRPL-AMM-DEX achieves superior price synchronization, reduced slippage, and improved returns due to XRPL’s lower fees and shorter block times, with benefits amplifying during market volatility. The integrated Continuous Auction Mechanism (CAM) further mitigates impermanent loss by redistributing arbitrage value to Liquidity Providers (LPs). To the best of our knowledge, this study represents the first comparative analysis between protocol-level and smart contract AMM-based DEX implementations and the first agent-based simulation validating theoretical auction mechanisms for AMM-based DEXs. Walter Hernandez Cruz, Firas Dahi, Yebo Feng, Jiahua Xu 0002, Aanchal Malhotra, Paolo Tasca |
ICBC | 5 |
| 2024 | The AMMazing Frontrunner: Practical Frontrunning on the XRP Ledger Automated Market MakerabstractOften referred to as A Dark Forest, Ethereum is home to predatory trading bots that prey on user transactions. Frontrunning is made simpler on Ethereum as builders & validators are incentivised to process the highest fee transactions first. One suggested mitigation strategy is to process transactions in a pseudo-random order, preventing frontrunners from predictably affecting transaction execution order. XRP Ledger, one of the oldest blockchains to use pseudorandom ordering, is launching an Automated Market Maker. This study investigates whether frontrunning techniques commonly observed in Ethereum Automated Market Makers are feasible on the XRP Ledger Automated Market Maker. In summary, our findings demonstrate that with minor adjustments, the conventional Sandwich Attack is feasible. Additionally, we unveil a distinctive attack facilitated by the integration with the Close Limit Order Book. Vytautas Tumas, Aanchal Malhotra |
ICBC | 2 |
| 2017 | A Universally Composable Treatment of Network TimeabstractThe security of almost any real-world distributed system today depends on the participants having some "reasonably accurate" sense of current real time. Indeed, to name one example, the very authenticity of practically any communication on the Internet today hinges on the ability of the parties to accurately detect revocation of certificates, or expiration of passwords or shared keys.,,However, as recent attacks show, the standard protocols for determining time are subvertible, resulting in wide-spread security loss. Worse yet, we do not have security notions for network time protocols that (a) can be rigorously asserted, and (b) rigorously guarantee security of applications that require a sense of real time.,,We propose such notions, within the universally composable (UC) security framework. That is, we formulate ideal functionalities that capture a number of prevalent forms of time measurement within existing systems. We show how they can be realized by real-world protocols, and how they can be used to assert security of time-reliant applications — specifically, certificates with revocation and expiration times. This allows for relatively clear and modular treatment of the use of time consensus in security-sensitive systems.,,Our modeling and analysis are done within the existing UC framework, in spite of its asynchronous, event-driven nature. This allows incorporating the use of real time within the existing body of analytical work done in this framework. In particular it allows for rigorous incorporation of real time within cryptographic tools and primitives. Ran Canetti, Kyle Hogan, Aanchal Malhotra, Mayank Varia |
CSF | 3 |
| 2016 | Attacking the Network Time Protocol
Aanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon Goldberg |
NDSS | 1 |
| 2015 | Practical IBE Secure under CBDH - Encrypting Without PairingabstractSince the discovery of identity based cryptography, a number of identity based encryption schemes were reported in the literature. Although a few schemes were proposed after its introduction, the first efficient identity based encryption scheme was proposed by Dan Boneh and Matthew K. Franklin in 2001. This encryption scheme uses Weil pairing on elliptic curves during both encryption and decryption process. In this paper, we propose a new identity based encryption scheme and prove its security in the random oracle model. There are two highlighting features in our scheme. First, it does not employ bilinear pairing computation during the encryption process. Second, our scheme does not require full domain hashing, which makes our scheme more practical and efficiently implementable. Moreover, we prove the security of our scheme by reducing it to the well known Computational Bilinear Diffie-Hellman problem. We first prove the security of our scheme in weaker security notion i.e. we prove our scheme to be IND-CPA secure. Then using Fujisaki Okamoto transformation, we convert our scheme to IND-CCA secure version. S. Sree Vivek, S. Sharmila Deva Selvi, Aanchal Malhotra, C. Pandu Rangan |
SECRYPT | 3 |
| 2014 | RPKI vs ROVER: comparing the risks of BGP security solutionsabstractBGP, the Internet's interdomain routing protocol, is highly vulnerable to routing failures that result from unintentional misconfigurations or deliberate attacks. To defend against these failures, recent years have seen the adoption of the Resource Public Key Infrastructure (RPKI), which currently authorizes 4% of the Internet's routes. The RPKI is a completely new security infrastructure (requiring new servers, caches, and the design of new protocols), a fact that has given rise to some controversy. Thus, an alternative proposal has emerged: Route Origin Verification (ROVER}, which leverages the existing reverse DNS (rDNS) and DNSSEC to secure the interdomain routing system. Both RPKI and ROVER rely on a hierarchy of authorities to provide trusted information about the routing system. Recently, however, it has been argued that the misconfigured, faulty or compromised RPKI authorities introduce new vulnerabilities in the routing system, which can take IP prefixes offline. Meanwhile, the designers of ROVER claim that it operates in a "fail-safe mode", where "[o]ne could completely unplug a router verification application at any time and Internet routing would continue to work just as it does today". There has been debate in Internet community mailing lists about the pros and cons of both approaches. This poster therefore compares the impact of ROVER failures to those of the RPKI, in a threat model that covers misconfigurations, faults or compromises of their trusted authorities. Aanchal Malhotra, Sharon Goldberg |
SIGCOMM | 1 |