VLDB 2026 Research / reviewers in the wild / expert
Samaikya Valluripally
dblp:193/7761
· DBLP profile ↗
9ranked-venue papers
3as first author
6since 2021 · last 2023
0000-0003-4365-7136ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Detection of Security and Privacy Attacks Disrupting User Immersive Experience in Virtual Reality Learning EnvironmentsabstractVirtual Reality Learning Environments (VRLEs) are a new form of immersive environments which are integrated with wearable devices for delivering distance learning content in a collaborative manner in e.g.,special education,surgical training. Gaining unauthorized access to these connected devices can cause security, privacy attacks (SP) that adversely impacts the user immersive experience (UIX). In this article, we identify potential SP attack surfaces that impact the application usability and immersion experience, and propose a novel anomaly detection method to detect attacks before the UIX can be disrupted. Specifically, we apply: (i) machine learning techniques such as amulti-label KNN classificationalgorithm to detect anomaly events of network-based attacks that include potential threat scenarios ofDoS (packet tampering, packet drop, packet duplication), and (ii) statistical analysis techniques that use a combination of boolean and threshold functions (Z-scores) to detect an anomaly related to application-based attacks (Unauthorized access). We demonstrate the effectiveness of our proposed anomaly detection method using a VRLE application case study viz., vSocial, specifically designed for teaching youth with learning impediments about social cues and interactions. Based on our detection results, we validate the impact of network and application based SP attacks on the VRLE UIX. Samaikya Valluripally, Benjamin Frailey, Brady Kruse, Boonakij Palipatana, Roland Oruche, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Modeling and Defense of Social Virtual Reality Attacks Inducing CybersicknessabstractSocial Virtual Reality Learning Environments (VRLE) offer a new medium for flexible and immersive learning environments with geo-distributed users. Ensuring user safety in VRLE application domains such as education, flight simulations, military training is of utmost importance. Specifically, there is a need to study the impact of “immersion attacks” (e.g., chaperone attack, occlusion) and other types of attacks/faults (e.g., unauthorized access, network congestion) that may cause user safety issues (i.e., inducing ofcybersickness). In this article, we present a novel framework to quantify the security, privacy issues triggered via immersion attacks and other types of attacks/faults. By using a real-world social VRLE viz., vSocial and creating a novel attack-fault tree model, we show that such attacks can induce undesirable levels of cybersickness. Next, we convert these attack-fault trees into stochastic timed automata (STA) representations to perform statistical model checking for a given attacker profile. Using this model checking approach, we determine the most vulnerable threat scenarios that can trigger high occurrence cases of cybersickness for VRLE users. Lastly, we show the effectiveness of our attack-fault tree modeling by incorporating suitable design principles such ashardening,diversity,redundancyandprinciple of least privilegeto ensure user safety in a VRLE session. Samaikya Valluripally, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | A Networked Social Virtual Reality Learning Environment Platform for Special EducationabstractDelivering curriculum using desktop-based virtual learning environment (VLE) technologies in a collaborative group setting has been shown to reduce the social skill limitations of students with learning disabilities. However, the lack of the immersiveness and effective generalization of acquiring knowledge and skills among students remains a critical challenge in the interactive tools used in current VLEs. In this paper, we present a networked social virtual reality learning environment (VRLE) system viz., vSocial that has been redesigned based on iterative user feedback and developed in order to leverage the latest advances in integration of smart devices such as VR headsets for virtual content delivery. We describe a comparative study to evaluate technology trade-offs in the development process of transitioning from a VLE to a VRLE, from both technological and user (e.g., student/instructor) perspectives. Lastly, we outline open issues in using VRLEs which include: system complexity, emotion recognition, cybersickness and system sustainability. Roland Oruche, Vaibhav Akashe, Samaikya Valluripally, Aniket Gulhane, Prasad Calyam, Janine Stichter, Zhihai He |
LCN | 3 |
| 2021 | vSocial: a cloud-based system for social virtual reality learning environment applications in special education
Sai Shreya Nuguri, Prasad Calyam, Roland Oruche, Aniket Gulhane, Samaikya Valluripally, Janine Stichter, Zhihai He |
Multim. Tools Appl. | 5 |
| 2021 | Multi-Cloud Performance and Security Driven Federated Workflow ManagementabstractFederated multi-cloud resource allocation for data-intensive application workflows is generally performed based on performance or quality of service (i.e., QSpecs) considerations. At the same time, end-to-end security requirements of these workflows across multiple domains are considered as an afterthought due to lack of standardized formalization methods. Consequently, diverse/heterogenous domain resource and security policies cause inter-conflicts between application's security and performance requirements that lead to sub-optimal resource allocations. In this paper, we present a joint performance and security-driven federated resource allocation scheme for data-intensive scientific applications. In order to aid joint resource brokering among multi-cloud domains with diverse/heterogenous security postures, we first define and characterize a data-intensive application's security specifications (i.e., SSpecs). Then we describe an alignment technique inspired by Portunes Algebra to homogenize the various domain resource policies (i.e., RSpecs) along an application's workflow lifecycle stages. Using such formalization and alignment, we propose a near optimal cost-aware joint QSpecs-SSpecs-driven, RSpecs-compliant resource allocation algorithm for multi-cloud computing resource domain/location selection as well as network path selection. We implement our security formalization, alignment, and allocation scheme as a framework, viz., “OnTimeURB” and validate it in a multi-cloud environment with exemplar data-intensive application workflows involving distributed computing and remote instrumentation use cases with different performance and security requirements. Matthew Dickinson, Saptarshi Debroy, Prasad Calyam, Samaikya Valluripally, Yuanxun Zhang, Ronny Bazan Antequera, Trupti Joshi, Tommi A. White, Dong Xu 0002 |
IEEE Trans. Cloud Comput. | 4 |
| 2021 | On QoE-Oriented Cloud Service Orchestration for Application ProvidersabstractNew virtualization technologies allow Infrastructure Providers (InPs) to lease their resources to Application Service Providers (ASPs) for highly scalable delivery of cloud services to end-users. However, existing literature lacks knowledge on Quality of Experience (QoE)-oriented cloud service orchestration algorithms that can guide ASPs on how to plan their budget to enhance satisfactory QoE delivery to end-users. In contrast to the InP's cloud service orchestration, the ASP's orchestration should not rely on expensive infrastructure control mechanisms such as Software-Defined Networking (SDN), or require aprioriknowledge on the number of services to be instantiated and their anticipated placement location within InP's infrastructure. In this paper, we address this issue of delivering satisfactory user QoE by synergistically optimizing both ASP's management and data planes. The optimization within the ASP management planefirst maximizes Service Level Objective (SLO) coverage of users when application services are being deployed, and are not yet operational. The optimization of the ASP data plane then enhances satisfactory user QoE delivery when applications services are operational with real user access. Our evaluation of QoE-oriented algorithms using realistic numerical simulations, real-world cloud testbed experiments with actual users and ASP case studies show notably improved performance over existing cloud service orchestration solutions. D. Yu. Chemodanov, Prasad Calyam, Samaikya Valluripally, Huy Trinh, Jon Patman, Kannappan Palaniappan |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | Attack Trees for Security and Privacy in Social Virtual Reality Learning EnvironmentsabstractSocial Virtual Reality Learning Environment (VRLE) is a novel edge computing platform for collaboration amongst distributed users. Given that VRLEs are used for critical applications (e.g., special education, public safety training), it is important to ensure security and privacy issues. In this paper, we present a novel framework to obtain quantitative assessments of threats and vulnerabilities for VRLEs. Based on the use cases from an actual social VRLE viz., vSocial, we first model the security and privacy using the attack trees. Subsequently, these attack trees are converted into stochastic timed automata representations that allow for rigorous statistical model checking. Such an analysis helps us adopt pertinent design principles such as hardening, diversity and principle of least privilege to enhance the resilience of social VRLEs. Through experiments in a vSocial case study, we demonstrate the effectiveness of our attack tree modeling with a reduction of 26% in probability of loss of integrity (security) and 80% in privacy leakage (privacy) in before and after scenarios pertaining to the adoption of the design principles. Samaikya Valluripally, Aniket Gulhane, Reshmi Mitra, Khaza Anuarul Hoque, Prasad Calyam |
CCNC | 1 |
| 2019 | Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment ApplicationsabstractSocial Virtual Reality based Learning Environments (VRLEs) such as vSocial render instructional content in a three-dimensional immersive computer experience for training youth with learning impediments. There are limited prior works that explored attack vulnerability in VR technology, and hence there is a need for systematic frameworks to quantify risks corresponding to security, privacy, and safety (SPS) threats. The SPS threats can adversely impact the educational user experience and hinder delivery of VRLE content. In this paper, we propose a novel risk assessment framework that utilizes attack trees to calculate a risk score for varied VRLE threats with rate and duration of threats as inputs. We compare the impact of a well-constructed attack tree with an adhoc attack tree to study the trade-offs between overheads in managing attack trees, and the cost of risk mitigation when vulnerabilities are identified. We use a vSocial VRLE testbed in a case study to showcase the effectiveness of our framework and demonstrate how a suitable attack tree formalism can result in a more safer, privacy-preserving and secure VRLE system. Aniket Gulhane, Akhil Vyas, Reshmi Mitra, Roland Oruche, Gabriela Hoefer, Samaikya Valluripally, Prasad Calyam, Khaza Anuarul Hoque |
CCNC | 6 |
| 2016 | End-to-End Security Formalization and Alignment for Federated Workflow ManagementabstractTraditionally, the allocation and dynamic adaptation of federated cyberinfrastructure resources residing across multiple domains for data-intensive application workflows have been performance or quality of service-centric (i.e., QSpecs), often compromising the end-to-end security requirements of scientific workflows. Lack of standardized formalization methods of the workflows' end-to-end security requirements, and diverse/heterogenous domain resource and security policies make inter-conflict characterization between application's security and performance requirements non-trivial, and leads to sub-optimal resource allocation. In this paper, we present a joint security and performance-driven federated resource allocation and adaptation scheme to define and characterize a data-intensive scientific application's security specifications (i.e., SSpecs). In order to aid security-driven resource brokering among domains with diverse security postures, we describe an alignment technique inspired by Portunes Algebra to combine domain-specific resource policies (i.e., RSpecs) along the application workflow life cycle. We use standardized guidelines that help in compute/storage resource domain/location selection as well as network path selection based on both application QSpecs and SSpecs. We implement our security formalization and alignment methods as a framework, viz., "OnTimeURB" and apply it on an exemplar Distributed Computing workflow to show the benefits of joint QSpecs-SSpecs-driven, RSpecs-compliant federated workflow management. Matthew Dickinson, Saptarshi Debroy, Prasad Calyam, Samaikya Valluripally, Yuanxun Zhang, Trupti Joshi, Dong Xu 0002 |
CLOUD | 4 |