VLDB 2026 Research / reviewers in the wild / expert
Nikhil Chawla
dblp:221/1528
· DBLP profile ↗
9ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0003-3454-6135ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Uncovering Software-Based Power Side-Channel Attacks on Apple M1/M2 SystemsabstractTraditionally, power side-channel analysis requires physical access to the target device, as well as specialized devices to measure the power consumption with enough precision. Recently research has shown that on x86 platforms, on-chip power meter capabilities exposed to a software interface might be used for power side-channel attacks without physical access. In this paper, we show that such software-based power side-channel attack is also applicable on Apple silicon (e.g., M1/M2 platforms), exploiting the System Management Controller (SMC) and its power-related keys, which provides access to the on-chip power meters through a software interface to user space software. We observed data-dependent power consumption reporting from such SMC keys and analyzed the correlations between the power consumption and the processed data. Our work also demonstrated how an unprivileged user mode application successfully recovers bytes from an AES encryption key from a cryptographic service supported by a kernel mode driver in MacOS. We have also studied the feasibility of performing frequency throttling side-channel attack on Apple silicon. Furthermore, we discuss the impact of software-based power side-channels in the industry, possible countermeasures, and the overall implications of software interfaces for modern on-chip power management systems. Nikhil Chawla, Chen Liu 0013, Abhishek Chakraborty 0001, Igor Chervatyuk, Thais Moreira Hamasaki, Ke Sun 0018, Henrique Kawakami |
DAC | 1 |
| 2022 | Frequency Throttling Side-Channel AttackabstractModern processors dynamically control their operating frequency to optimize resource utilization, maximize energy savings, and conform to system-defined constraints. If, during the execution of a software workload, the running average of any electrical or thermal parameter exceeds its corresponding predefined threshold value, the power management architecture will reactively adjust CPU frequency to ensure safe operating conditions. In this paper, we demonstrate how such power management-based frequency throttling activity forms a source of timing side-channel information leakage, which can be exploited by an attacker to infer secret data even from a constant-cycle victim workload. The proposed frequency throttling side-channel attack can be launched by both kernel-space and user-space attackers, thus compromising security guarantees provided by isolation boundaries. We validate our attack methodology across different systems and threat models by performing experiments on a constant-cycle implementation of AES algorithm based on AES-NI instructions. The results of our experimental evaluations demonstrate that the attacker can successfully recover all bytes of an AES key by measuring encryption execution times. Finally, we discuss different options to mitigate the threat posed by frequency throttling side-channel attacks, as well as their advantages and disadvantages. Chen Liu 0013, Abhishek Chakraborty 0001, Nikhil Chawla, Neer Roggel |
CCS | 3 |
| 2021 | Towards Improving the Trustworthiness of Hardware based Malware Detector using Online Uncertainty EstimationabstractHardware-based Malware Detectors (HMDs) using Machine Learning (ML) models have shown promise in detecting malicious workloads. However, the conventional black-box based machine learning (ML) approach used in these HMDs fail to address the uncertain predictions, including those made on zero-day malware. The ML models used in HMDs are agnostic to the uncertainty that determines whether the model “knows what it knows,” severely undermining its trustworthiness. We propose an ensemble-based approach that quantifies uncertainty in predictions made by ML models of an HMD, when it encounters an unknown workload than the ones it was trained on. We test our approach on two different HMDs that have been proposed in the literature. We show that the proposed uncertainty estimator can detect > 90% of unknown workloads for the Power-management based HMD, and conclude that the overlapping benign and malware classes undermine the trustworthiness of the Performance Counter-based HMD. Nikhil Chawla, Saibal Mukhopadhyay |
DAC | 2 |
| 2021 | Securing IoT Devices Using Dynamic Power Management: Machine Learning ApproachabstractThe shift in paradigm from cloud computing toward edge has resulted in faster response times, a more secure and energy-efficient edge. Internet-of-Things (IoT) devices form a vital part of the edge, but despite legions of benefits it offers, increasing vulnerabilities and escalation in malware generation has rendered them insecure. Software-based approaches are prominent in malware detection, but they fail to meet the requirements for IoT devices. Dynamic power management (DPM) is architecture agnostic and inherently pervasive component existing in all low-power IoT devices. In this article, we demonstrate dynamic voltage and frequency scaling (DVFS) states form a signature pertinent to an application, and its runtime variations comprise of features essential for securing IoT devices against malware attacks. We have demonstrated this proof of concept by performing experimental analysis on a Snapdragon 820 mobile processor, hosting the Android operating system (OS). We developed a supervised machine learning model for application classification and malware identification by extracting features from the DVFS states time series. The experimental results show$> 0.7~F1$score in classifying different android benchmarks and >0.88 in classifying benign and malware applications when evaluated across different DVFS governors. We also performed power measurements under different governors to evaluate power-security aware governor. We have observed higher detection accuracy and lower power dissipation under settings of the ondemand governor. Nikhil Chawla, Monodeep Kar, Saibal Mukhopadhyay |
IEEE Internet Things J. | 1 |
| 2021 | Machine Learning in Wavelet Domain for Electromagnetic Emission Based Malware AnalysisabstractThis paper presents a signal processing and machine learning (ML) based methodology to leverage Electromagnetic (EM) emissions from an embedded device to remotely detect a malicious application running on the device and classify the application into a malware family. We develop Fast Fourier Transform (FFT) based feature extraction followed by Support Vector Machine (SVM) and Random Forest (RF) based ML models to detect a malware. We further propose methods to learn characteristic behavior of different malwares from EM traces to reveal similarities to known malware families and improve efficiency of malware analysis. We propose to use Discrete Wavelet Transform (DWT) based feature extraction from spectrograms of EM side-channel traces and perform ML on the extracted features to learn fine-grained patterns of malware families. The experimental demonstration on Open-Q 820 development platform demonstrate 0.99 F1score in detecting malware and 0.88 F1score in uniquely classifying malwares among 8 malware family evaluated using Support Vector Machines (SVM) and Random Forest (RF) Machine Learning(ML) models. We also demonstrate capability of proposed framework in identifying new unknown applications with 0.99 recall and unknown malware family with 0.87 recall. Nikhil Chawla, Saibal Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | BiasP: a DVFS based exploit to undermine resource allocation fairness in linux platformsabstractDynamic Voltage and Frequency Scaling (DVFS) plays an integral role in reducing the energy consumption of mobile devices, meeting the targeted performance requirements at the same time. We examine the security obliviousness of CPUFreq, the DVFS framework in Linux-kernel based systems. Since Linux-kernel based operating systems are present in a wide array of applications, the high-level CPUFreq policies are designed to be platform-independent. Using these policies, we present BiasP exploit, which restricts the allocation of CPU resources to a set of targeted applications, thereby degrading their performance. The exploit involves detecting the execution of instructions on the CPU core pertinent to the targeted applications, thereafter using CPUFreq policies to limit the available CPU resources available to those instructions. We demonstrate the practicality of the exploit by operating it on a commercial smartphone, running Android OS based on Linux-kernel. We can successfully degrade the User Interface (UI) performance of the targeted applications by increasing the frame processing time and the number of dropped frames by up to 200% and 947% for the animations belonging to the targeted-applications. We see a reduction of up to 66% in the number of retired instructions of the targeted-applications. Furthermore, we propose a robust detector which is capable of detecting exploits aimed at undermining resource allocation fairness through malicious use of the DVFS framework. Nikhil Chawla, Saibal Mukhopadhyay |
ISLPED | 2 |
| 2019 | Mitigating Power Supply Glitch based Fault Attacks with Fast All-Digital Clock Modulation CircuitabstractThis paper experimentally demonstrates that an on-chip integrated fast all-digital clock modulation (F-ADCM) circuit can be used as a countermeasure against supply glitch and temperature variations-based fault injection attacks (FIA). The F-ADCM circuit modulates clock edges in presence of DC/transient supply glitches and temperature variations to ensure correct operation of the underlying cryptographic circuit. With a testchip manufactured in 130nm CMOS process, we first demonstrate an inexpensive methodology to conduct a fault attack on hardware implementation of a 128-bit advanced encryption standard (AES) engine using externally controlled supply glitches. Next, we show that with F-ADCM circuit, it is no longer possible to inject supply/temperature glitch-based faults even after 10 million encryptions across varying operating conditions. Moreover, in extreme operating conditions, the F-ADCM circuit doesn't generate any clock edges, leading to complete failure of the AES encryption, indicating no exploitable faults are present. Monodeep Kar, Nikhil Chawla, Saibal Mukhopadhyay |
DATE | 3 |
| 2019 | Application Inference using Machine Learning based Side Channel AnalysisabstractThe proliferation of ubiquitous computing requires energy-efficient as well as secure operation of modern processors. Side channel attacks are becoming a critical threat to security and privacy of devices embedded in modern computing infrastructures. Unintended information leakage via physical signatures such as power consumption, electromagnetic emission (EM) and execution time have emerged as a key security consideration for SoCs. Also, information published on purpose at user privilege level accessible through software interfaces results in software-only attacks. In this paper, we used a supervised learning based approach for inferring applications executing on android platform based on features extracted from EM side-channel emissions and software exposed dynamic voltage frequency scaling (DVFS) states. We highlight the importance of machine learning based approach in utilizing these multi-dimensional features on a complex SoC, against profiling-based approaches. We also show that learning the instantaneous frequency states polled from on-board frequency driver (cpufreq) is adequate to identify a known application and flag potentially malicious unknown application. The experimental results on benchmarking applications running on ARMv8 processor in Snapdragon 820 board demonstrates early detection of these apps in 700 ms, and atleast 85% accuracy in detecting unknown applications. Overall, the highlight is to utilize a low-complexity path to application inference attacks through learning instantaneous frequency states pattern of CPU core. Nikhil Chawla, Monodeep Kar, Saibal Mukhopadhyay |
IJCNN | 1 |
| 2019 | Energy Efficient and Side-Channel Secure Cryptographic Hardware for IoT-Edge NodesabstractDesign of ultralightweight but secure encryption engine is a key challenge for Internet-of-Things edge devices. This paper explores the system level design space for an ultralow power image sensor node for secure communication and proposes an optimized datapath architecture for 128-bit SIMON (SIMON128), a lightweight block cipher, for minimal performance, power, and area overheads with increased level of side-channel security. Various datapath architectures for SIMON are explored for simultaneously increasing energy-efficiency and resistance to power-based side-channel analysis (PSCA) attacks. Alternative datapath architectures are implemented on ASIC (15 nm CMOS) and field programmable gate array (FPGA) (Spartan-6, 45 nm) to perform power, performance, and area analysis. We show that, although a bitserial datapath minimizes area and power, a round unrolled datapath provides 80× higher energy-efficiency and 143× higher performance, compared to the baseline bitserial design. Moreover, the PSCA measurements performed using Sakura-G board with Spartan-6 FPGA, demonstrate that a 6-round unrolled datapath improves minimum-traces-to-disclosure for correlation power analysis (CPA) by at least 384× over baseline bitserial design with no successful CPA even with 500000 measurements. Finally, application to the image-sensor node demonstrates that optimized unrolled SIMON128 can provide equivalent performance to AES128 at lower area, higher energy efficiency, and improved side channel security. Nikhil Chawla, Jong Hwan Ko, Monodeep Kar, Saibal Mukhopadhyay |
IEEE Internet Things J. | 2 |