VLDB 2026 Research / reviewers in the wild / expert
Nirnimesh Ghose
dblp:205/2229
· DBLP profile ↗
14ranked-venue papers
6as first author
10since 2021 · last 2025
0000-0003-2138-5977ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 3 since 2021Security and privacy · 5 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Securing Smart Meter Communication with an Ensemble Fingerprinting FrameworkabstractAdvanced Metering Infrastructure (AMI) comprises several smart meters (SM) that use wireless technologies such as ZigBee to exchange data and commands between each other and the backend systems. The wireless broadcast nature and smart meters' physical vulnerability make them prone to cyberattacks like spoofing, masquerading, and man-in-the-middle. This paper addresses the secret-free smart meter identification challenge in AMI systems, focusing on the widely used Zigbee communication standard. Specifically, we introduce an ensemble device fingerprinting framework, integrating the physical and the medium access control (MAC) layer with multiple machine learning models (Convolutional Neural Network, Logistic Regression, and Decision Tree). Our analysis shows that the ensemble framework outperforms individual fingerprinting models, with a mean accuracy of 83.33 %. Fahmida Afrin, Venkat Sai Suman Lamba Karanam, Byrav Ramamurthy, Nirnimesh Ghose |
CCNC | 4 |
| 2025 | SARP: Spatial Agnostic Radio Fingerprinting with Pseudo-LabelingabstractDeep-learning radio fingerprinting is not robust against spatial variations, where a neural network trained on location A does not perform well over RF signals from location B. We promote the robustness of deep-learning radio fingerprinting against spatial variations by synergizing Complex-Valued Neural Networks (CVNNs) and pseudo-labeling. Compared to existing solutions, we leverage pseudo-labeling to fine-tune a CVNN without needing labeled RF signals from a new location. We collect large-scale real-world datasets across different locations. We conduct comprehensive evaluations of these datasets with multiple complex-valued activation functions. Our experimental results significantly improve the accuracy of radio fingerprinting when training data and test data are from two different locations (e.g., increasing accuracy from 40.0% to 62.8%). Fahmida Afrin, Boyang Wang 0007, Nirnimesh Ghose |
CCNC | 4 |
| 2025 | Gradient Boost Enhanced Artificial Immune System Algorithm for Adaptive DDoS Attack Detection in IoTabstractDistributed Denial of Service attacks (DDoS) targeting the Internet of Things (IoT) remain a pervasive cybersecurity challenge. Biologically inspired solutions have shown promise for DDoS attack detection. For example, the human immune system has inspired various Artificial Immune System (AIS) solutions for anomaly detection. In this paper, we address the challenges of DDoS detection in IoT by proposing a Gradient boost regression and Adam-optimized Negative Selection Algorithm (GANSA). We show that the proposed algorithm is effective and can adapt to changes in network traffic patterns, thereby accurately detecting known and unknown DDoS attacks. We evaluate the proposed system against state-of-the-art machine learning DDoS detection algorithms (e.g., CNN, SVM). We show that the proposed system achieves a low false positive rate (0.0003) and near-perfect detection accuracy (0.99), F1 score (0.99), and MCC (0.97) while adapting to incoming network traffic in real-time. Sayed Abualia, Anna Wisniewska, Nirnimesh Ghose |
ICC | 3 |
| 2024 | Reciprocal Altruism as a Rogue Node Detection Mechanism in Dynamic Spectrum Access NetworksabstractThe rapid increase in wireless devices as society embraces the Internet of Things (loT) has led to saturation of wireless channels. To alleviate congestion in wireless bands, dynamic spectrum access utilizing software defined radio has emerged as a promising solution. In dynamic spectrum access, unlicensed users are allowed to access licensed channels when the license holder is idle. As unlicensed users compete over limited resources, coexistence challenges arise. In this article, we propose a bio-inspired approach to tackle rogue nodes who decide to use more than their fair share of resources. The proposed scheme builds on reciprocal altruism where unlicensed users sacrifice immediate reward by voluntarily relinquishing their band to benefit other unlicensed users transmitting in the band, with the expectation that the behavior will be reciprocated in the future. We show that the reciprocal behavior can be utilized to detect rogue nodes in the system with perfect accuracy. We achieve this in a decentralized manner with minimum communication overhead. Truc Duong, Anna Wisniewska, Nirnimesh Ghose |
CCNC | 3 |
| 2024 | ZITA: Zero-Interaction Two-Factor Authentication Using Contact Traces and In-Band Proximity VerificationabstractTwo-factor authentication (TFA) provides an additional layer of protection to commonly-occurring password breaches. However, existing TFA methods, often involve special hardware interfaces, or require human effort which is prone to errors and acts as an adoption detractor for older adults and novice technology users. To address these limitations, we propose a zero-interaction, two-factor authentication (ZITA) protocol. In ZITA, the first factor is implemented using the conventional username and password methods. The second factor is completed without any human effort provided that the user is not accessing the service from an unregistered public device and a designated secondary device is physically co-present. To automate the second factor, ZITA exploits the long-term contact between the login device and the secondary device such as a smartphone. Moreover, to thwart man-in-the-middle and co-located attacks, ZITA incorporates a proximity verification test that relies on the randomness of ambient RF signals. Compared with other zero-effort TFA protocols, ZITA remains secure against advanced threats and does not require out-of-band sensors such as microphones, speakers, or photoplethysmography (PPG) sensors. Nirnimesh Ghose, Kaustubh Gupta, Loukas Lazos, Ming Li 0003, Ziqi Xu 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | RADTEC: Re-authentication of IoT Devices with Machine LearningabstractThe use of Internet of Things (IoT) devices is higher than ever and is growing rapidly. Many IoT devices are manufactured by home appliance manufacturers where security and privacy is not the foremost concern. There does not exist a strict authentication method that verifies the identity of the device. This allows any rogue IoT device to authenticate and spoof various IoT device activities using compromised credentials. This paper addresses the issue by introducing a novel method for re- and continuous authentication utilizing a device-type classification as a new identity paradigm. We present RADTEC: a protocol for authenticating a device in a network by leveraging machine learning to classify the type of an IoT device attempting to connect to the network with an accuracy of over 95% in less than 0.65 milliseconds. We investigate multiple machine learning classifiers to infer the types of IoT devices and use them to develop a stricter and more efficient method for authentication. Kaustubh Gupta, Nirnimesh Ghose, Boyang Wang 0007 |
CCNC | 2 |
| 2023 | VET: Autonomous Vehicular Credential Verification Using Trajectory and Motion Vectors
Ebuka Oguchi, Nirnimesh Ghose |
SecureComm (2) | 2 |
| 2022 | PoF: Proof-of-Following for Vehicle Platoons
Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Loukas Lazos, Ming Li 0003, Nirnimesh Ghose |
NDSS | 6 |
| 2022 | In-Band Secret-Free Pairing for COTS Wireless DevicesabstractMany IoT devices lack the necessary interfaces (keyboards, screens) for entering passwords or changing default ones. For these devices, bootstrapping trust can be challenging. We address the problem of device pairing in the absence of any shared secrets. Pairing is a two-phase process that requires mutual authentication between the two parties and the agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose a secret-free and in-band trust establishment protocol that achieves the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. As compared to the state-of-the-art, our protocol does not require any hardware/firmware modification to the devices, or any out-of-band channels, but can be applied to any COTS device. Furthermore, our protocol is resistant to active signal manipulations attacks that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by exploiting hard-to-forge signal propagation laws. We perform extensive theoretical analysis to verify the security of the proposed protocol. In addition, we validate our theoretical results with experiments using COTS devices and USRP radios. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | Robust deep-learning-based radio fingerprinting with fine-tuningabstractMinute hardware imperfections in the radio-frequency circuitry of a wireless device can be leveraged as a unique fingerprint. Radio fingerprinting is a way of distinguishing a device from others of the same type at the physical layer by utilizing these hardware imperfections. Recent studies proposed to utilize deep learning over raw I/Q data for the purpose of radio fingerprinting and achieve high accuracy. Unfortunately, deep-learning-based radio finger-printing is not robust over I/Q data across different days due to significant changes in wireless channels. This study proposes to leverage fine-tuning to improve the robustness of radio fingerprinting in a cross-day scenario, where training and test I/Q data are from different days. Our experimental results suggest that transfer learning is a promising approach for robust deep-learning-based radio fingerprinting in practice. Nirnimesh Ghose, Boyang Wang 0007 |
WISEC | 3 |
| 2018 | SFIRE: Secret-Free-in-band Trust Establishment for COTS Wireless DevicesabstractWe address the problem of trust establishment between wireless devices that do not share any prior secrets. This includes the mutual authentication and agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose SFIRE, a secret-free trust establishment protocol that allows the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. Compared to the state-of-the-art, SFIRE does not require any out-of-band channels, special hardware, or firmware modification, but can be applied to any COTS device. Moreover, SFIRE is resistant to the most advanced active signal manipulations that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by using the RSS fluctuation patterns to build a robust “RSS authenticator”. We perform extensive experiments using COTS devices and USRP radios and verify the validity of the proposed protocol. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
INFOCOM | 1 |
| 2018 | Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation AttacksabstractIn this paper, we address the fundamental problem of securely bootstrapping a group of wireless devices to a hub, when none of the devices share prior associations (secrets) with the hub or between them. This scenario aligns with the secure deployment of body area networks, IoT, medical devices, industrial automation sensors, autonomous vehicles, and others. We develop VERSE, a physical-layer group message integrity verification primitive that effectively detects advanced wireless signal manipulations that can be used to launch man-in-the-middle (MitM) attacks over wireless. Without using shared secrets to establish authenticated channels, such attacks are notoriously difficult to thwart and can undermine the authentication and key establishment processes. VERSE exploits the existence of multiple devices to verify the integrity of the messages exchanged within the group. We then use VERSE to build a bootstrapping protocol, which securely introduces new devices to the network. Compared to the state-of-the-art, VERSE achieves in-band message integrity verification during secure pairing using only the RF modality without relying on out-of-band channels or extensive human involvement. It guarantees security even when the adversary is capable of fully controlling the wireless channel by annihilating and injecting wireless signals. We study the limits of such advanced wireless attacks and prove that the introduction of multiple legitimate devices can be leveraged to increase the security of the pairing process. We validate our claims via theoretical analysis and extensive experimentations on the USRP platform. We further discuss various implementation aspects such as the effect of time synchronization between devices and the effects of multipath and interference. Note that the elimination of shared secrets, default passwords, and public key infrastructures effectively addresses the related key management challenges when these are considered at scale. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | Secure Physical Layer VotingabstractDistributed wireless networks often employ voting to perform critical network functions such as fault-tolerant data fusion, cooperative sensing, and reaching consensus. Voting is implemented by sending messages to a fusion center or via direct message exchange between participants. However, the delay overhead of message-based voting can be prohibitive when numerous participants have to share the wireless channel in sequence, making it impractical for time-critical applications. In this paper, we propose a fast PHY-layer voting scheme called PHYVOS, which significantly reduces the delay for collecting and tallying votes. In PHYVOS, wireless devices transmit their votes simultaneously by exploiting the subcarrier orthogonality of OFDM and without explicit messaging. Votes are realized by injecting energy to pre-assigned subcarriers. We show that PHYVOS is secure against adversaries that attempt to manipulate the voting outcome. Security is achieved without employing cryptography-based authentication and message integrity schemes. We analytically evaluate the voting robustness as a function of PHY-layer parameters. We extend PHYVOS to operate in ad hoc groups, without the assistance of a fusion center. We discuss practical implementation challenges related to multi-device frequency and time synchronization and present a prototype implementation of PHYVOS on the USRP platform. We complement the implementation with larger scale simulations. Nirnimesh Ghose, Bocan Hu, Yan Zhang 0019, Loukas Lazos |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | HELP: Helper-Enabled In-Band Device Pairing Resistant Against Signal Cancellation
Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
USENIX Security Symposium | 1 |