Diksha Shukla

dblp:149/2214 · DBLP profile ↗
← Back
12ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0002-3740-8793ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 6 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021
YearPublicationVenuePosition
2026 Delta-LLaVA: Base-then-Specialize Alignment for Token-Efficient Vision-Language Models
abstract
Multimodal Large Language Models (MLLMs) combine visual and textual representations to enable rich reasoning capabilities. However, the high computational cost of processing dense visual tokens remains a major bottleneck. A critical component in this pipeline is the visual projector, which bridges the vision encoder and the language model. Standard designs often employ a simple multi-layer perceptron for direct token mapping, but this approach scales poorly with high-resolution inputs, introducing significant redundancy. We present Delta-LLaVA, a token-efficient projector that employs a low-rank DeltaProjection to align multi-level vision features into a compact subspace before further interaction. On top of this base alignment, lightweight Transformer blocks act as specialization layers, capturing both global and local structure under constrained token budgets. Extensive experiments and ablations demonstrate that this base-then-specialize design yields consistent gains across multiple benchmarks with only 144 tokens, highlighting the importance of token formation prior to scaling interaction capacity. With Delta-LLaVA, inference throughput improves by up to 55%, while end-to-end training accelerates by nearly 4-5 × in pretraining and over 1.5 × in finetuning, highlighting the dual benefits of our design in both efficiency and scalability.
Mohamad Zamini, Diksha Shukla
WACV2
2025 Cognitive and Memory-Driven EEG-Based Authentication: A Multi-Session Approach to Secure Biometric Systems
abstract
Biometric authentication systems face significant challenges due to the vulnerability of traditional methods like passwords and fingerprints to theft or imitation. Electroencephalography (EEG)-based authentication presents a promising alternative by using unique brainwave patterns. This study introduces a novel EEG-based authentication system that utilizes cognitive and memory-related stimuli to elicit distinct brainwave responses. By incorporating multi-session data collection, the system effectively accounts for temporal variability. Additionally, advanced feature extraction techniques capture spatial, temporal, and spectral characteristics, enhancing authentication accuracy. A comprehensive feature engineering pipeline is employed, evaluating various classifiers across different stimuli types. Findings reveal that memory-related tasks, particularly word recognition, consistently generate the most reliable EEG responses. Among the classifiers tested, Logistic Regression demonstrates the highest effectiveness. The system achieves robust performance across multiple sessions, demonstrating its potential for practical real-world deployment. These findings lay a solid foundation for advancing EEG-based biometric authentication, paving the way for more secure and practical implementations in both research and applied settings.
Soudabeh Bolouri, Diksha Shukla
FG2
2025 Head Movement Biometrics for Continuous Authentication in Virtual Reality
abstract
This paper presents an approach for continuous user authentication in VR using head movement biometrics, utilizing bilateral head position data from the stereoscopic rendering systems of VR headsets. Our method employs a 1D Convolutional Neural Network (CNN) with a specialized feature extractor designed to capture the temporal head movement patterns, head impulse movements, pose stabilization behaviors, and frequency-domain characteristics from bilateral head velocities. We evaluated the system using 30 participants who performed door-opening and walking tasks across two sessions, separated by 17 days. The system achieved an average Equal Error Rate (EER) of 2.9% for door-opening tasks, 8.3% for walking tasks, and 5.67% in activity-invariant scenarios, when an authentication decision was made ≈ every 0.3 seconds after an initial 14-second calibration period.
Paul Gyreyiri, Diksha Shukla
VRST2
2024 HM-Auth: Redefining User Authentication in Immersive Virtual World Through Hand Movement Signatures
abstract
In the realm of Virtual Reality (VR), passwords and pins are primary methods of user authentication for application and device access. Despite the well-documented security vulnerabilities associated with knowledge-based authentication methods, VR devices persist in utilizing them for user authentication. Due to these security vulnerabilities in existing authentication systems on VR devices, there is an increasing demand for more secure and robust authentication methods in the VR ecosystem. In this paper, we introduce HM-Auth, a user-authentication system that verifies a user's identity by leveraging the intrinsic hand movement signatures while users type predefined text on their VR screen. Experiments conducted on the hand movement patterns of 30 volunteer participants demonstrate that our Siamese Networks-based-HM-Auth model could achieve high intra-user and low inter-user similarity scores. The HM-Auth system effectively controls false acceptance by employing our symmetric rejection method, achieving a low False Acceptance Rate (FAR) of 0.08 at a False Reject Rate (FRR) of 0. The experimental analysis results highlight the HM-Auth's potential as a promising and secure authentication approach that is crafted for immersive environments.
Sindhu Reddy Kalathur Gopal, Paul Gyreyiri, Diksha Shukla
FG3
2023 Hidden Reality: Caution, Your Hand Gesture Inputs in the Immersive Virtual World are Visible to All!
Sindhu Reddy Kalathur Gopal, Diksha Shukla, James David Wheelock, Nitesh Saxena
USENIX Security Symposium2
2021 Press @$@$ to Login: Strong Wearable Second Factor Authentication via Short Memorywise Effortless Typing Gestures
abstract
The use of wearable devices (e.g., smartwatches) in two factor authentication (2FA) is fast emerging, as wearables promise better usability compared to smartphones. Still, the current deployments of wearable 2FA have significant usability and security issues. Specifically, one-time PIN-based wearable 2FA (PIN-2FA) requires noticeable user effort to open the app and copy random PINs from the wearable to the login terminal's (desktop/laptop) browser. An alternative approach, based on one-tap approvals via push notifications (Tap-2FA), relies upon user decision making to thwart attacks and is prone to skip-through. Both approaches are also vulnerable to traditional phishing attacks. To address this security-usability tension, we introduce a fundamentally different design of wearable 2FA, called SG-2FA, involving wrist-movement “seamless gestures” captured near transparently by the second factor wearable device while the user types a very short special sequence on the browser during the login process. The typing of the special sequence creates a wrist gesture that when identified correctly uniquely associates the login attempt with the device's owner. The special sequence can be fixed (e.g., “${@}{\$}{@}{\$}$”), does not need to be a secret, and does not need to be memorized (could be simply displayed on the browser). This design improves usability over PIN-2FA since only this short sequence has to be typed as part of the login process (no interaction with or diversion of attention to the wearable and copying of random PINs is needed). It also greatly improves security compared to Tap-2FA since the attacker can not succeed in login unless the user's wrist is undergoing the exact same gesture at the exact same time. Moreover, the approach is phishing-resistant and privacy-preserving (unlike behavioral biometrics). Our results show that SG-2FA incurs only minimal errors in both benign and adversarial settings based on appropriate parameterizations.
Prakash Shrestha, Nitesh Saxena, Diksha Shukla, Vir V. Phoha
EuroS&P3
2021 Concealable Biometric-based Continuous User Authentication System An EEG Induced Deep Learning Model
abstract
This paper introduces a lightweight, low-cost, easy-to-use, and unobtrusive continuous user authentication system based on concealable biometric signals. The proposed authentication model continuously verifies a user’s identity throughout the user session while s/he watches a video or performs free-text typing on his/her desktop/laptop keyboard. The authentication model utilizes unobtrusively recorded electroencephalogram (EEG) signals and learns the user’s unique biometric signature based on his/her brain activity.Our work has multifold impact in the area of EEG-based authentication: (1) a comprehensive study and a comparative analysis of a wide range of extracted features are presented. These features are categorized based on the EEG electrodes placement position on the user’s head, (2) an optimal feature subset is constructed using a minimal number of EEG electrodes, (3) a deep neural network-based user authentication model is presented that utilizes the constructed optimal feature subset, and (4) a detailed experimental analysis on a publicly available EEG dataset of 26 volunteer participants is presented.Our experimental results show that the proposed authentication model could achieve an average Equal Error Rate (EER) of 0.137%. Although a thorough analysis on a larger pool of subjects must be performed, our results show the viability of low-cost, lightweight EEG-based continuous user authentication systems.
Sindhu Reddy Kalathur Gopal, Diksha Shukla
IJCB2
2021 A Temporal Memory-based Continuous Authentication System
abstract
With the emerging use of technology, verifying a user’s identity continuously throughout a device’s usage has become increasingly important. This paper proposes an authentication system that unobtrusively verifies a user’s identity continuously, based on his/her hand movement patterns captured using accelerometer, while a user performs free-text typing. Our model validates a user’s identity with a verification decision in every ≈ 20ms interval. The authentication model utilizes a short temporal memory of size M of a user’s hand movement patterns. Experiments on different values of M suggests that the model shows an improved and consistent performance by increasing the size of the temporal memory of a user’s hand movement patterns to M ≈ 300ms.The authentication system requires only a user’s hand movement signals in order to authenticate a user on a device. Experiments on the hand movement patterns of 27 volunteer participants, captured using motion sensors of a Sony Smartwatch while they performed free-text typing on a desktop/laptop device, show that our model could achieve an average authentication accuracy of 99.8% with an average False Accept Rate (FAR) of 0.0003 and an average False Reject Rate (FRR) of 0.0034.
Sindhu Reddy Kalathur Gopal, Diksha Shukla
IJCB2
2019 Stealing Passwords by Observing Hands Movement
abstract
The use of mobile phones in public places opens up the possibilities of remote side channel attacks on these devices. We present a video-based side channel attack to decipher passwords on mobile devices. Our method uses short video clips ranging from 5 to 10 s each, which can be taken unobtrusively from a distance and do not require the keyboard or the screen of the phone to be visible. By relating the spatiotemporal movements of the user's hand during typing and an anchor point on any visible part of the phone, we predict the typed password with high accuracy. The results on a dataset of 375 short videos of password entry process on a Samsung Galaxy S4 phone show an exponential reduction in the search space compared to a random guess. For each key-press corresponding to a character in the passwords, our method was able to reduce the search space to an average of 2-3 keys compared to ~30 keys if one has to guess the key randomly. Thus, this paper reaffirms threats to smartphone users' conventional login in public places and highlights the threats in scenarios such as hiding the screen that otherwise gives the impression of being safe to the users.
Diksha Shukla, Vir V. Phoha
IEEE Trans. Inf. Forensics Secur.1
2017 Continuous user authentication via unlabeled phone movement patterns
abstract
In this paper, we propose a novel continuous authentication system for smartphone users. The proposed system entirely relies on unlabeled phone movement patterns collected through smartphone accelerometer. The data was collected in a completely unconstrained environment over five to twelve days. The contexts of phone usage were identified using k-means clustering. Multiple profiles, one for each context, were created for every user. Five machine learning algorithms were employed for classification of genuine and impostors. The performance of the system was evaluated over a diverse population of 57 users. The mean equal error rates achieved by Logistic Regression, Neural Network, kNN, SVM, and Random Forest were 13.7%, 13.5%, 12.1%, 10.7%, and 5.6% respectively. A series of statistical tests were conducted to compare the performance of the classifiers. The suitability of the proposed system for different types of users was also investigated using the failure to enroll policy.
Rajesh Kumar 0016, Partha Pratim Kundu, Diksha Shukla, Vir V. Phoha
IJCB3
2016 Toward Robotic Robbery on the Touch Screen
abstract
Despite the tremendous amount of research fronting the use of touch gestures as a mechanism of continuous authentication on smart phones, very little research has been conducted to evaluate how these systems could behave if attacked by sophisticated adversaries. In this article, we present two Lego-driven robotic attacks on touch-based authentication: a population statistics--driven attack and a user-tailored attack. The population statistics--driven attack is based on patterns gleaned from a large population of users, whereas the user-tailored attack is launched based on samples stolen from the victim. Both attacks are launched by a Lego robot that is trained on how to swipe on the touch screen. Using seven verification algorithms and a large dataset of users, we show that the attacks cause the system’s mean false acceptance rate (FAR) to increase by up to fivefold relative to the mean FAR seen under the standard zero-effort impostor attack. The article demonstrates the threat that robots pose to touch-based authentication and provides compelling evidence as to why the zero-effort attack should cease to be used as the benchmark for touch-based authentication systems.
Abdul Serwadda, Vir V. Phoha, Rajesh Kumar 0016, Diksha Shukla
ACM Trans. Inf. Syst. Secur.5
2014 Beware, Your Hands Reveal Your Secrets!
abstract
Research on attacks which exploit video-based side-channels to decode text typed on a smartphone has traditionally assumed that the adversary is able to leverage some information from the screen display (say, a reflection of the screen or a low resolution video of the content typed on the screen). This paper introduces a new breed of side-channel attack on the PIN entry process on a smartphone which entirely relies on the spatio-temporal dynamics of the hands during typing to decode the typed text. Implemented on a dataset of 200 videos of the PIN entry process on an HTC One phone, we show, that the attack breaks an average of over 50% of the PINs on the first attempt and an average of over 85% of the PINs in ten attempts. Because the attack can be conducted in such a way not to raise suspicion (i.e., since the adversary does not have to direct the camera at the screen), we believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information. As users conduct more and more of their computing transactions on mobile devices in the open, the paper calls for the community to take a closer look at the risks posed by the now ubiquitous camera-enabled devices.
Diksha Shukla, Rajesh Kumar 0016, Abdul Serwadda, Vir V. Phoha
CCS1