Ivica Nikolic

dblp:18/2551 · DBLP profile ↗
← Back
39ranked-venue papers
8as first author
5since 2021 · last 2025
0000-0001-9578-4837ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 7 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2025 Model Provenance Testing for Large Language Models
abstract
Large language models are increasingly customized through fine-tuning and other adaptations, creating challenges in enforcing licensing terms and managing downstream impacts such as protecting intellectual property or identifying vulnerabilities. We address this challenge by developing a framework for testing model provenance. Our approach is based on the key observation that real-world model derivations preserve significant similarities in model outputs that can be detected through statistical analysis. Using only black-box access to models, we employ multiple hypothesis testing to compare model similarities against a baseline established by unrelated models. On two comprehensive real-world benchmarks spanning models from 30M to 4B parameters and comprising over 600 models, our tester achieves 90-95% precision and 80-90% recall in identifying derived models. These results demonstrate the viability of systematic provenance verification in production environments even when only API access is available.
Ivica Nikolic, Teodora Baluta, Prateek Saxena
NeurIPS1
2023 Unforgeability in Stochastic Gradient Descent
abstract
Stochastic Gradient Descent (SGD) is a popular training algorithm, a cornerstone of modern machine learning systems. Several security applications benefit from determining if SGD executions are forgeable, i.e., whether the model parameters seen at a given step are obtainable by more than one distinct set of data samples. In this paper, we present the first attempt at proving impossibility of such forgery. We furnish a set of conditions, which are efficiently checkable on concrete checkpoints seen during training runs, under which checkpoints are provably unforgeable at that step. Our experiments show that the conditions are somewhat mild and hence always satisfied at checkpoints sampled in our experiments. Our results sharply contrast prior findings at a high level: We show that checkpoints we find to be provably unforgeable have been deemed to be forgeable using the same methodology and experimental setup suggested in prior work. This discrepancy arises because of unspecified subtleties in definitions. We experimentally confirm that the distinction matters, i.e., small errors amplify during training to produce significantly observable difference in final models trained. We hope our results serve as a cautionary note on the role of algebraic precision in forgery definitions and related security arguments.
Teodora Baluta, Ivica Nikolic, Racchit Jain, Divesh Aggarwal, Prateek Saxena
CCS2
2023 User-Customizable Transpilation of Scripting Languages
abstract
A transpiler converts code from one programming language to another. Many practical uses of transpilers require the user to be able to guide or customize the program produced from a given input program. This customizability is important for satisfying many application-specific goals for the produced code such as ensuring performance, readability, ease of exposition or maintainability, compatibility with external environment or analysis tools, and so on. Conventional transpilers are deterministic rule-driven systems often written without offering customizability per user and per program. Recent advances in transpilers based on neural networks offer some customizability to users, e.g. through interactive prompts, but they are still difficult to precisely control the production of a desired output. Both conventional and neural transpilation also suffer from the "last mile" problem: they produce correct code on average, i.e., on most parts of a given program, but not necessarily for all parts of it. We propose a new transpilation approach that offers fine-grained customizability and reusability of transpilation rules created by others, without burdening the user to understand the global semantics of the given source program. Our approach is mostly automatic and incremental, i.e., constructs translation rules needed to transpile the given program as per the user's guidance piece-by-piece. Users can rely on existing transpilation rules to translate most of the program correctly while focusing their effort locally, only on parts that are incorrect or need customization. This improves the correctness of the end result. We implement the transpiler as a tool called DuoGlot, which translates Python to Javascript programs, and evaluate it on the popular GeeksForGeeks benchmarks. DuoGlot achieves 90% translation accuracy and so it outperforms all existing translators (both handcrafted and neural-based), while it produces readable code. We evaluate DuoGlot on two additional benchmarks, containing more challenging and longer programs, and similarly observe improved accuracy compared to the other transpilers.
Bo Wang 0146, Aashish Kolluri, Ivica Nikolic, Teodora Baluta, Prateek Saxena
Proc. ACM Program. Lang.3
2021 Refined Grey-Box Fuzzing with Sivo
Ivica Nikolic, Radu Mantu, Shiqi Shen, Prateek Saxena
DIMVA1
2021 The Deoxys AEAD Family
Jérémy Jean, Ivica Nikolic, Thomas Peyrin, Yannick Seurin
J. Cryptol.2
2020 OHIE: Blockchain Scaling Made Simple
abstract
Many blockchain consensus protocols have been proposed recently to scale the throughput of a blockchain with available bandwidth. However, these protocols are becoming increasingly complex, making it more and more difficult to produce proofs of their security guarantees. We propose a novel permissionless blockchain protocol OHIE which explicitly aims for simplicity. OHIE composes as many parallel instances of Bitcoin's original (and simple) backbone protocol as needed to achieve excellent throughput. We formally prove the safety and liveness properties of OHIE. We demonstrate its performance with a prototype implementation and large-scale experiments with up to 50,000 nodes. In our experiments, OHIE achieves linear scaling with available bandwidth, providing about 4-10Mbps transaction throughput (under 8-20Mbps per-node available bandwidth configurations) and at least about 20x better decentralization over prior works.
Ivica Nikolic, Ruomu Hou, Prateek Saxena
SP2
2019 Exploiting the laws of order in smart contracts
abstract
We investigate a family of bugs in blockchain-based smart contracts, which we dub event-ordering (or EO) bugs. These bugs are intimately related to the dynamic ordering of contract events, i.e. calls of its functions, and enable potential exploits of millions of USD worth of crypto-coins. Previous techniques to detect EO bugs have been restricted to those bugs that involve just one or two event orderings. Our work provides a new formulation of the general class of EO bugs arising in long permutations of such events by using techniques from concurrent program analysis. The technical challenge in detecting EO bugs in blockchain contracts is the inherent combinatorial blowup in path and state space analysis, even for simple contracts. We propose the first use of partial-order reduction techniques, using automatically extracted happens-before relations along with several dynamic symbolic execution optimizations. We build EthRacer, an automatic analysis tool that runs directly on Ethereum bytecode and requires no hints from users. It flags 8% of over 10, 000 contracts analyzed, providing compact event traces (witnesses) that human analysts can examine in only a few minutes per contract. More than half of the flagged contracts are likely to have unintended behaviour.
Aashish Kolluri, Ivica Nikolic, Ilya Sergey, Aquinas Hobor, Prateek Saxena
ISSTA2
2019 Combining PUF with RLUTs: A Two-party Pay-per-device IP Licensing Scheme on FPGAs
abstract
With the popularity of modern FPGAs, the business of FPGA specific intellectual properties (IP) is expanding rapidly. This also brings in the concern of IP protection. FPGA vendors are making serious efforts toward IP protection, leading to standardization schemes like IEEE P1735. However, efficient techniques to prevent unauthorized overuse of IP still remain an open question. In this article, we propose a two-party IP protection scheme combining the re-configurable look-up table primitive of modern FPGAs with physically unclonable functions (PUF). The proposed scheme works with the assumption that the FPGA vendor provides the assurance of confidentiality and integrity of the developed IP. The proposed scheme is considerably lightweight compared to existing schemes, prevents overuse, and does not involve FPGA vendors or trusted third parties for IP licensing. The validation of the proposed scheme is done on MCNC’91 benchmark and third-party IPs like AES and lightweight MIPS processors.
Debapriya Basu Roy, Shivam Bhasin, Ivica Nikolic, Debdeep Mukhopadhyay
ACM Trans. Embed. Comput. Syst.3
2018 Finding The Greedy, Prodigal, and Suicidal Contracts at Scale
abstract
Smart contracts---stateful executable objects hosted on blockchains like Ethereum---carry billions of dollars worth of coins and cannot be updated once deployed. We present a new systematic characterization of a class of trace vulnerabilities, which result from analyzing multiple invocations of a contract over its lifetime. We focus attention on three example properties of such trace vulnerabilities: finding contracts that either lock funds indefinitely, leak them carelessly to arbitrary users, or can be killed by anyone. We implemented Maian, the first tool for specifying and reasoning about trace properties, which employs interprocedural symbolic analysis and concrete validator for exhibiting real exploits. Our analysis of nearly one million contracts flags 34, 200 (2, 365 distinct) contracts vulnerable, in 10 seconds per contract. On a subset of 3, 759 contracts which we sampled for concrete validation and manual analysis, we reproduce real exploits at a true positive rate of 89%, yielding exploits for 3, 686 contracts. Our tool finds exploits for the infamous Parity bug that indirectly locked $200 million US worth in Ether, which previous analyses failed to capture.
Ivica Nikolic, Aashish Kolluri, Ilya Sergey, Prateek Saxena, Aquinas Hobor
ACSAC1
2017 How to Use Metaheuristics for Design of Symmetric-Key Primitives
Ivica Nikolic
ASIACRYPT (3)1
2017 SAT-based Cryptanalysis of Authenticated Ciphers from the CAESAR Competition
abstract
We investigate six authenticated encryption schemes (ACORN, ASCON-128a, ICEPOLE-128a, Ketje Jr, MORUS, and NORX-32) from the CAESAR competition. We aim at state recovery attacks using a SAT solver as a main tool. Our analysis reveals that these schemes, as submitted to CAESAR, provide strong resistance against SAT-based state recoveries. To shed a light on their security margins, we also analyse modified versions of these algorithms, including round-reduced variants and versions with higher security claims. Our attacks on such variants require only a few known plaintext-ciphertext pairs and small memory requirements (to run the SAT solver), whereas time complexity varies from very practical (few seconds on a desktop PC) to 'theoretical' attacks.
Ashutosh Dhar Dwivedi, Milos Kloucek, Pawel Morawiecki, Ivica Nikolic, Josef Pieprzyk, Sebastian Wójtowicz
SECRYPT4
2016 A New Algorithm for the Unbalanced Meet-in-the-Middle Problem
Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (1)1
2016 Efficient Design Strategies Based on the AES Round Function
Jérémy Jean, Ivica Nikolic
FSE2
2016 Extended meet-in-the-middle attacks on some Feistel constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001
Des. Codes Cryptogr.3
2015 Refinements of the k-tree Algorithm for the Generalized Birthday Problem
Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (2)1
2015 Internal Differential Boomerangs: Practical Analysis of the Round-Reduced Keccak- f f Permutation
Jérémy Jean, Ivica Nikolic
FSE2
2015 Rotational Cryptanalysis of ARX Revisited
Dmitry Khovratovich, Ivica Nikolic, Josef Pieprzyk, Przemyslaw Sokolowski, Ron Steinfeld
FSE2
2014 Meet-in-the-Middle Attacks on Generic Feistel Constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (1)3
2014 Low Probability Differentials and the Cryptanalysis of Full-Round CLEFIA-128
Sareh Emami, San Ling, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang
ASIACRYPT (1)3
2014 Tweaks and Keys for Block Ciphers: The TWEAKEY Framework
abstract
We propose the TWEAKEY framework with goal to unify the design of tweakable block ciphers and of block ciphers resistant to related-key attacks. Our framework is simple, extends the key-alternating construction, and allows to build a primitive with arbitrary tweak and key sizes, given the public round permutation (for instance, the AES round). Increasing the sizes renders the security analysis very difficult and thus we identify a subclass of TWEAKEY , that we name STK , which solves the size issue by the use of finite field multiplications on low hamming weight constants. Overall, this construction allows a significant increase of security of well-known authenticated encryptions mode like Θ CB3 from birthday-bound security to full security, where a regular block cipher was used as a black box to build a tweakable block cipher. Our work can also be seen as advances on the topic of secure key schedule design.
Jérémy Jean, Ivica Nikolic, Thomas Peyrin
ASIACRYPT (2)2
2014 Analysis of BLAKE2
Jian Guo 0001, Pierre Karpman, Ivica Nikolic, Lei Wang 0031, Shuang Wu 0004
CT-RSA3
2014 Colliding Keys for SC2000-256
Alex Biryukov, Ivica Nikolic
Selected Areas in Cryptography2
2014 Practical Cryptanalysis of PAES
Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography2
2014 Rotational Rebound Attacks on Reduced Skein
Dmitry Khovratovich, Ivica Nikolic, Christian Rechberger
J. Cryptol.2
2013 Complementing Feistel Ciphers
Alex Biryukov, Ivica Nikolic
FSE2
2013 Security Analysis of PRINCE
Jérémy Jean, Ivica Nikolic, Thomas Peyrin, Lei Wang 0031, Shuang Wu 0004
FSE2
2013 Cryptanalysis of Round-Reduced \mathttLED
Ivica Nikolic, Lei Wang 0031, Shuang Wu 0004
FSE1
2011 Second-Order Differential Collisions for Reduced SHA-256
Alex Biryukov, Mario Lamberger, Florian Mendel, Ivica Nikolic
ASIACRYPT4
2011 Search for Related-Key Differential Characteristics in DES-Like Ciphers
Alex Biryukov, Ivica Nikolic
FSE2
2011 Boomerang Attacks on BLAKE-32
Alex Biryukov, Ivica Nikolic, Arnab Roy 0005
FSE2
2010 Rotational Rebound Attacks on Reduced Skein
Dmitry Khovratovich, Ivica Nikolic, Christian Rechberger
ASIACRYPT2
2010 Automatic Search for Related-Key Differential Characteristics in Byte-Oriented Block Ciphers: Application to AES, Camellia, Khazad and Others
Alex Biryukov, Ivica Nikolic
EUROCRYPT2
2010 Rotational Cryptanalysis of ARX
Dmitry Khovratovich, Ivica Nikolic
FSE2
2009 Rebound Attack on the Full Lane Compression Function
Krystian Matusiewicz, María Naya-Plasencia, Ivica Nikolic, Yu Sasaki 0001, Martin Schläffer
ASIACRYPT3
2009 Distinguisher and Related-Key Attack on the Full AES-256
Alex Biryukov, Dmitry Khovratovich, Ivica Nikolic
CRYPTO3
2009 Speeding up Collision Search for Byte-Oriented Hash Functions
Dmitry Khovratovich, Alex Biryukov, Ivica Nikolic
CT-RSA3
2009 Cryptanalysis of the LAKE Hash Family
Alex Biryukov, Praveen Gauravaram, Jian Guo 0001, Dmitry Khovratovich, San Ling, Krystian Matusiewicz, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang
FSE7
2009 Meet-in-the-Middle Attacks on SHA-3 Candidates
Dmitry Khovratovich, Ivica Nikolic, Ralf-Philipp Weinmann
FSE2
2008 Collisions for Step-Reduced SHA-256
Ivica Nikolic, Alex Biryukov
FSE1