VLDB 2026 Research / reviewers in the wild / expert
Marios O. Choudary
dblp:160/2124 · also Marios Omar Choudary, Omar Choudary 0001
· DBLP profile ↗
11ranked-venue papers
7as first author
0since 2021 · last 2019
0000-0003-0586-9592ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Hardware security and side channels · 29% Cryptographic protocols and secure computation · 23% Network security · 23% | |
| Computer graphics and multimedia
3 papers |
Virtual and augmented reality · 48% Multimedia systems and quality of experience · 26% Image and video processing · 26% | |
| Theoretical computer science
2 papers |
Information theory · 51% Computational geometry · 49% | |
| Computer networks
2 papers |
Transport protocols and congestion control · 80% Wireless sensing and localization · 20% |
Topics — the 14 heaviest of 19, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic protocols and secure computation
key exchange |
0.3 | 1 | 2018 | Secure Opportunistic Multipath Key Exchange · CCS 2018 |
Hardware security and side channels
side-channel attack |
0.3 | 1 | 2018 | Efficient, Portable Template Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Hardware security and side channels › side-channel attack › profiled side-channel attack
template attack |
0.3 | 1 | 2018 | Efficient, Portable Template Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Cryptographic primitives and cryptanalysis
security analysis |
0.3 | 1 | 2017 | Back to Massey: Impressively Fast, Scalable and Tight Security Evaluation Tools · CHES 2017 |
Network security › attack strategy
man-in-the-middle attack |
0.2 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Cryptographic protocols and secure computation
secure payment |
0.2 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Virtual and augmented reality › augmented reality
mobile augmented reality |
0.2 | 2 | 2009 | MARCH: mobile augmented reality for cultural heritage · ACM Multimedia 2009 Mobile guide applications using representative visualizations · ACM Multimedia 2008 |
Transport protocols and congestion control › multipath transport
multipath TCP |
0.1 | 1 | 2018 | Secure Opportunistic Multipath Key Exchange · CCS 2018 |
Cryptographic primitives and cryptanalysis › block cipher cryptanalysis
AES key recovery |
0.1 | 1 | 2018 | Efficient, Portable Template Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Cryptographic primitives and cryptanalysis
block cipher |
0.1 | 1 | 2018 | Efficient, Portable Template Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Image and video processing
real-time image processing |
0.1 | 1 | 2009 | MARCH: mobile augmented reality for cultural heritage · ACM Multimedia 2009 |
Information theory › estimation theory
entropy estimation |
0.1 | 1 | 2017 | Back to Massey: Impressively Fast, Scalable and Tight Security Evaluation Tools · CHES 2017 |
Authentication and access control › authentication
authentication protocols |
0.1 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Wireless sensing and localization › satellite navigation
GPS localization |
0.0 | 1 | 2008 | Mobile guide applications using representative visualizations · ACM Multimedia 2008 |
Methods — techniques the papers use, named apart from their topics
trust-on-first-use · 0.7multipath key exchange · 0.7pooled covariance matrices · 0.3fisher's linear discriminant analysis · 0.3dimensionality reduction · 0.3DC offset compensation · 0.3web adaptation system · 0.2multivariable test · 0.2protocol analysis · 0.2field experiment · 0.2thin-plate spline · 0.2thin plate spline · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Refinement of Massey Inequality : (To Nicolae Ţăpuş on his 70th birthday)abstractWe refine for the first time, the 25 year old result obtained by James L. Massey in Guessing and Entropy. Pantelimon George Popescu, Marios O. Choudary |
ISIT | 2 |
| 2018 | Secure Opportunistic Multipath Key ExchangeabstractThe security of today's widely used communication security protocols is based on trust in Certificate Authorities (CAs). However, the real security of this approach is debatable, since certificate handling is tedious and many recent attacks have undermined the trust in CAs. On the other hand, opportunistic encryption protocols such as Tcpcrypt, which are currently gaining momentum as an alternative to no encryption, have similar security to using untrusted CAs or self-signed certificates: they only protect against passive attackers. In this paper, we present a key exchange protocol, Secure Multipath Key Exchange (SMKEX), that enables all the benefits of opportunistic encryption (no need for trusted third parties or pre-established secrets), as well as proven protection against some classes of active attackers. Furthermore, SMKEX can be easily extended to a trust-on-first-use setting and can be easily integrated with TLS, providing the highest security for opportunistic encryption to date while also increasing the security of standard TLS. We show that SMKEX is made practical by the current availability of path diversity between different AS-es. We also show a method to create path diversity with encrypted tunnels without relying on the network topology. These allow SMKEX to provide protection against most adversaries for a majority of Alexa top 100 web sites. We have implemented SMKEX using a modified Multipath TCP kernel implementation and a user library that overwrites part of the socket API, allowing unmodified applications to take advantage of the security provided by SMKEX. Sergiu Costea, Marios O. Choudary, Doru Gucea, Björn Tackmann, Costin Raiciu |
CCS | 2 |
| 2018 | Efficient, Portable Template AttacksabstractTemplate attacks recover data values processed by tamper-resistant devices from side-channel waveforms, such as supply-current fluctuations (power analysis) or electromagnetic emissions. They first profile a device to generate multivariate statistics of the waveforms emitted for each of a set of known processed values, which then identify maximum-likelihood candidates of unknown processed values during an attack. We identify several practical obstacles arising in the implementation of template attacks, ranging from numerical errors to the incompatibility of templates across different devices, and propose and compare several solutions. We identify pooled covariance matrices and prior dimensionality reduction through Fisher's linear discriminant analysis as particularly efficient and effective, especially where many attack traces can be acquired. We evaluate alternative algorithms not only for the task of recovering key bytes from a hardware implementation of the Advanced Encryption Standard; we even reconstruct the value transferred by an individual byte-load instruction, with success rates reaching 85% (or a guessing entropy of less than a quarter bit remaining) after 1000 attack traces, thereby demonstrating direct eavesdropping of eight-bit parallel data lines. Using different devices during the profiling and attack phase can substantially reduce the effectiveness of template attacks. We demonstrate that the same problem can also occur across different measurement campaigns with the same device and that DC offsets (e.g., due to temperature drift) are a significant cause. We improve the portability of template parameters across devices by manipulating the DC content of the eigenvectors that form the projection matrix used for dimensionality reduction of the waveforms. Marios O. Choudary, Markus G. Kuhn |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Back to Massey: Impressively Fast, Scalable and Tight Security Evaluation Tools
Marios O. Choudary, Pantelimon George Popescu |
CHES | 1 |
| 2014 | Efficient Stochastic Methods: Profiled Attacks Beyond 8 Bits
Marios O. Choudary, Markus G. Kuhn |
CARDIS | 1 |
| 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play AttackabstractEMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered two serious problems: a widespread implementation flaw and a deeper, more difficult to fix flaw with the EMV protocol itself. The first flaw is that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this nonce. This exposes them to a "pre-play" attack which is indistinguishable from card cloning from the standpoint of the logs available to the card-issuing bank, and can be carried out even if it is impossible to clone a card physically. Card cloning is the very type of fraud that EMV was supposed to prevent. We describe how we detected the vulnerability, a survey methodology we developed to chart the scope of the weakness, evidence from ATM and terminal experiments in the field, and our implementation of proof-of-concept attacks. We found flaws in widely-used ATMs from the largest manufacturers. We can now explain at least some of the increasing number of frauds in which victims are refused refunds by banks which claim that EMV cards cannot be cloned and that a customer involved in a dispute must therefore be mistaken or complicit. The second problem was exposed by the above work. Independent of the random number quality, there is a protocol failure: the actual random number generated by the terminal can simply be replaced by one the attacker used earlier when capturing an authentication code from the card. This variant of the pre-play attack may be carried out by malware in an ATM or POS terminal, or by a man-in-the-middle between the terminal and the acquirer. We explore the design and implementation mistakes that enabled these flaws to evade detection until now: shortcomings of the EMV specification, of the EMV kernel certification process, of implementation testing, formal analysis, and monitoring customer complaints. Finally we discuss countermeasures. More than a year after our initial responsible disclosure of these flaws to the banks, action has only been taken to mitigate the first of them, while we have seen a likely case of the second in the wild, and the spread of ATM and POS malware is making it ever more of a threat. Mike Bond, Marios O. Choudary, Steven J. Murdoch, Sergei P. Skorobogatov, Ross J. Anderson |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Efficient Template Attacks
Marios O. Choudary, Markus G. Kuhn |
CARDIS | 1 |
| 2013 | Security Analysis and Decryption of Filevault 2
Marios O. Choudary, Felix Gröbert, Joachim Metz |
IFIP Int. Conf. Digital Forensics | 1 |
| 2009 | On the impact of sequence and time in rich media advertisingabstractNowadays, commercial websites use an increasing amount of rich media ads, since these ads grab users' attention more easily. Ad overloading has a counterproductive effect and we advocate a more parsimonious and finely-tuned use of ads. In this paper we stress the importance of using ads in the right sequence and at the right time. We also present how to use our web adaptation system for a classic web marketing multivariable test. The experimental results show the usefulness of optimizing banners' sequences and timing. Benoit Baccot, Marios O. Choudary, Romulus Grigoras, Vincent Charvillat |
ACM Multimedia | 2 |
| 2009 | MARCH: mobile augmented reality for cultural heritageabstractWe present MARCH, a complete solution for enhanced cultural heritage discovery using the mobile phone. Simply point the camera of a mobile device at prehistoric cave engravings. Then MARCH augments the captured images with the expert's drawings, highlighting in real time the animal engravings, which are almost impossible to observe with the naked eye. We have created a mobile augmented reality application which runs at 14 FPS for 320x240 frames on a Nokia N95 smartphone. We describe the optimizations and the requirements needed to obtain these results on mobile devices. Marios O. Choudary, Vincent Charvillat, Romulus Grigoras, Pierre Gurdjos |
ACM Multimedia | 1 |
| 2008 | Mobile guide applications using representative visualizationsabstractRecent developments of hardware capabilities on mobile devices have made Location Based Services(LBS) very popular. This triggered an increasing need of rich visual content in mobile guide applications.This paper presents two original approaches for using representative visualizations: artistic views which represent an arbitrary deformation made by an artist and perspective views(3D-like) obtained from 3D models. Both approaches are based on learning GPS-to-image relations. We show an efficient use of the thin-plate spline for registering GPS coordinates with images. We also show the implementation of our guiding system on two mobile platforms. Marios O. Choudary, Vincent Charvillat, Romulus Grigoras |
ACM Multimedia | 1 |