Sujan Kumar Saha

dblp:23/7613 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 5 first-author · 3 since 2021Systems, architecture and hardware · 9 · 9 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 GEmFuzz: Uncovering System-Level Vulnerabilities in SoCs via Emulation-Based Grey-Box Fuzzing
abstract
Security verification of modern System-on-Chip (SoC) designs is becoming increasingly challenging due to the growing integration of third-party IPs and the complexity of hardware-software (HW/SW) interactions. This escalating complexity broadens the attack surface, leading to a higher number of potential vulnerabilities and longer detection times. Consequently, verification engineers face increasing pressure to ensure robust security within tight development schedules. Traditional techniques such as formal verification and information flow tracking often suffer from poor scalability, state space explosion, and significant manual effort, necessitating expert-level design knowledge. Fuzzing-based methodologies, while promising, typically rely on the availability of a golden reference model and struggle to scale effectively, which limits their applicability. Furthermore, the increasing intricacy of HW/SW stacks in modern SoCs introduces new classes of system-level vulnerabilities that remain largely unaddressed by existing approaches. To address these challenges, we propose GEmFuzz, a hardware emulation-based greybox fuzzing framework for SoC security verification. GEmFuzz uses a hardware emulation server to run the design under test (DUT) at near real-time speed, effectively addressing the scalability challenges. Also, it leverages a cost-function-guided fuzzer to generate intelligent input patterns for system-level vulnerability detection. We evaluate GEmFuzz on a RISC-V-based SoC and demonstrate its effectiveness in detecting a set of known system-level vulnerabilities. Additionally, it identifies two previously unknown vulnerabilities, highlighting the capability and promise of the proposed framework.
Shuvagata Saha, Ahmed Alhurubi, Tanvir Rahman, Hasan Al Shaikh, Sujan Kumar Saha, Farimah Farahmandi, Mark Tehranipoor
ASP-DAC5
2026 LAsset: An LLM-assisted Security Asset Identification Framework for System-on-Chip (SoC) Verification
abstract
The growing complexity of modern system-on-chip (SoC) and IP designs is making security assurance difficult day by day. One of the fundamental steps in the pre-silicon security verification of a hardware design is the identification of security assets, as it substantially influences downstream security verification tasks, such as threat modeling, security property generation, and vulnerability detection. Traditionally, assets are determined manually by security experts, requiring significant time and expertise. To address this challenge, we present LAsset, a novel automated framework that leverages large language models (LLMs) to identify security assets from both hardware design specifications and register-transfer level (RTL) descriptions. The framework performs structural and semantic analysis to identify intra-module primary and secondary assets and derives inter-module relationships to systematically characterize security dependencies at the design level. Experimental results show that the proposed framework achieves high classification accuracy, reaching up to 90% recall rate in SoC design, and 93% recall rate in IP designs. This automation in asset identification significantly reduces manual overhead and supports a scalable path forward for secure hardware development.
Md. Ajoad Hasan, Dipayan Saha, Khan Thamid Hasan, Nashmin Alam, Azim Uddin, Sujan Kumar Saha, Mark Tehranipoor, Farimah Farahmandi
DATE6
2026 BengHWR: A robust handwritten word recognizer in Bengali
Moumita Moitra, Sujan Kumar Saha
Pattern Recognit.2
2026 OdiSR-TL: An ASR System in Odia Language Using Transfer Learning and Pre-trained Models
abstract
This article presents the Automatic Speech Recognition (ASR) system we developed for Odia. Odia is the primary language of the Indian state of Odisha, and lacks sufficient annotated speech corpora. However, some other languages have larger publicly available speech resources. Therefore, we employed Transfer Learning for the development. First, we build monolingual pre-trained models using Bengali, Hindi, and English resources. Then, we used the pre-trained models along with the Odia data to develop the ASR model using a Residual Refinement Learning (RRL) network. This transfer learning model performs better than the baseline model. Certain multilingual pre-trained models, such as Whisper-small and Wav2Vec2.0 XLSR-53, have been quite popular in various speech processing tasks. We also employed those models in the Odia ASR task and found that they improve the performance. Furthermore, we propose a hybrid transfer learning technique where two pre-trained models are combined. There, the Whisper-small and Wav2Vec2.0 are combined with the RRL framework. The proposed hybrid transfer learning model outperformed all the previous models. The final model achieved a word error rate (WER) of 1.15 and a character error rate (CER) of 0.14, which is significantly better than the existing Odia ASR systems. The superiority of the proposed model is also tested by implementing several systems and datasets on other Indian languages on a unified platform.
Malay Kumar Majhi, Sujan Kumar Saha
ACM Trans. Asian Low Resour. Lang. Inf. Process.2
2025 EmFIA: A Novel Emulation-based Fault Injection Vulnerability Assessment Framework at RTL Level
abstract
Fault-injection attacks (FIA) intentionally disrupt circuit behavior allowing adversaries to bypass safety mechanisms, disrupt system functionality, or extract sensitive information, thereby posing severe risks to the security and reliability of modern System-on-Chips (SoCs). However, pre-silicon security assessments targeting FIA predominantly rely on gate-level simulation or late-stage layout analysis, which are slow, limited in coverage, and often fail to capture realistic operating conditions—leaving critical vulnerabilities undetected until post-silicon stages. To address these limitations, we propose EmFIA, an emulation-driven register-transfer level (RTL) fault injection assessment framework designed to analyze security-critical vulnerabilities against FIA. EmFIA systematically analyzes securitycritical signals in a design by modeling the faults in hardware emulation platform, inserting SystemVerilog assertions, and monitoring security property violations. Demonstrated on a RISC-V SoC and standalone AES-128 and RSA-128 cores, EmFIA enables rapid exploration of fault scenarios, achieving speedups of several orders of magnitude compared to exhaustive gate-level simulation. EmFIA provides designers with fast, property-aware security insight early in the design cycle, significantly strengthening hardware resilience prior to fabrication.
Tanvir Rahman, Shuvagata Saha, Sujan Kumar Saha, Farimah Farahmandi, Mark Tehranipoor
VLSI-SoC3
2025 Cultivating Security: Debug Authentication for Ensuring the Security of SoC's Root of Trust
abstract
Hardware-assisted debugging provides the necessary infrastructure for developers to closely monitor program behaviors at the microarchitectural level in a system-on-chip (SoC). However, debug infrastructure jeopardizes the security of the system by providing a backdoor for accessing crucial assets embedded in the system because of the inevitable increase in observability. While trusted execution environments (TEE) provide an extra level of security and isolate design assets, the security implication of hardware debug integration on TEEs has not been investigated. In this paper, we introduce a multi-level bidirectional access authentication mechanism over the debug module that defines the minimum number of privilege levels needed and the access details at each level so that debug users are authorized and blocked from accessing assets private to other entities. Trust is established by exchanging certificates both from the debugger and SoC sides to implement a bidirectional authorization platform in order to restrict the debugger’s access to SoC assets as well as prevent the debugger’s test data from being accessed by an SoC impersonator through emulation. We provide a prototype of the debug authentication platform on RISC-V architecture that proves the small overhead of the approach while staying compatible with traditional debug efforts.
Arash Vafaei, Sujan Kumar Saha, Mark Tehranipoor, Farimah Farahmandi
VLSI-SoC2
2025 BugWhisperer: Fine-Tuning LLMs for SoC Hardware Vulnerability Detection
abstract
The current landscape of system-on-chips (SoCs) security verification faces challenges due to manual, labor-intensive, and inflexible methodologies. These issues limit the scalability and effectiveness of security protocols, making bug detection at the Register-Transfer Level (RTL) difficult. This paper proposes a new framework named BugWhisperer that utilizes a specialized, fine-tuned Large Language Model (LLM) to address these challenges. By enhancing the LLM’s hardware security knowledge and leveraging its capabilities for text inference and knowledge transfer, this approach automates and improves the adaptability and reusability of the verification process. We introduce an open-source, fine-tuned LLM specifically designed for detecting security vulnerabilities in SoC designs. Our findings demonstrate that this tailored LLM effectively enhances the efficiency and flexibility of the security verification process. Additionally, we introduce a comprehensive hardware vulnerability database that supports this work and will further assist the research community in enhancing the security verification process.
Shams Tarek, Dipayan Saha, Sujan Kumar Saha, Farimah Farahmandi
VTS3
2025 Multi-Tenant Cloud FPGA: A Survey on Security, Trust, and Privacy
abstract
With the growing demand for enhanced performance and scalability in cloud applications and systems, data center architectures are evolving to incorporate heterogeneous computing fabrics that leverage CPUs, GPUs, and FPGAs. Unlike traditional processing platforms like CPUs and GPUs, FPGAs offer the unique ability for hardware reconfiguration at runtime, enabling improved and tailored performance, flexibility, and acceleration. FPGAs excel at executing large-scale search optimization, acceleration, and signal processing tasks while consuming low power and minimizing latency. Major public cloud providers, such as Amazon, Huawei, Microsoft, Alibaba, and others, have already begun integrating FPGA-based cloud acceleration services into their offerings. Although FPGAs in cloud applications facilitate customized hardware acceleration, they also introduce new security challenges that demand attention. Granting cloud users the capability to reconfigure hardware designs after deployment may create potential vulnerabilities for malicious users, thereby jeopardizing entire cloud platforms. In particular, multi-tenant FPGA services, where a single FPGA is divided spatially among multiple users, are highly vulnerable to such attacks. This article examines the security concerns associated with multi-tenant cloud FPGAs, provides a comprehensive overview of the related security, privacy and trust issues, and discusses forthcoming challenges in this evolving field of study.
Muhammed Kawser Ahmed, Max Panoff, Joel Mandebi, Sujan Kumar Saha, Erman Nghonda, Peter Mbua, Christophe Bobda
ACM Trans. Reconfigurable Technol. Syst.4
2024 TDM: Time and Distance Metric for Quantifying Information Leakage Vulnerabilities in SoCs
abstract
Protecting assets against information leakage is crucial to ensure System-on-Chip (SoC) security. This paper introduces a Time and Distance-based security metric (TDM) to assess information leakage risks across hardware Intellectual Properties (IPs) in SoC architectures. TDM quantifies both asset exposure time and spatial proximity to external threats, identifying vulnerable locations and critical timings. Using graph-based analysis, we map data flow, evaluating risk based on how long and how closely sensitive data resides near output ports. Applied to five open-source designs, TDM effectively enhances SoC security by measuring susceptibility to threats.
Avinash Ayalasomayajula, Henian Li, Hasan Al Shaikh, Sujan Kumar Saha, Farimah Farahmandi
ICCD4
2024 SAP: Silicon Authentication Platform for System-on-Chip Supply Chain Vulnerabilities
abstract
The increasing complexity of system-on-chip (SoC) designs, prompted by the integration of additional functionalities, has led to a reliance on global sources in the SoC supply chain. This reliance introduces security concerns, including intellectual property (IP) theft, unauthorized usage, counterfeiting, and overproduction of integrated circuits (ICs). While various design-for-trust measures have been explored in academic research, such as watermarking, IC metering, IC camouflaging, and hardware obfuscation, there is currently no holistic approach within the SoC framework to support these measures. Secure provisioning of security assets within the chip is also critical for these measures, requiring the establishment of secure communication channels and the authentication of the chip by authorized entities. Existing root-of-trust mechanisms primarily target software-level threats during in-field operations but fall short of adequately addressing supply chain threats and ensuring secure asset provisioning. This paper introduces the Silicon Authentication Platform (SAP) security IP, specifically designed to address security vulnerabilities within the SoC supply chain. SAP is tailored to authenticate SoC dies within untrusted environments, ensuring secure provisioning of security assets and chip authentication during in-field operations. This hardware-based, plug-and-play IP facilitates lightweight integration into SoC designs, establishing a secure perimeter around its assets to protect them from potential leakage. In addition, a comprehensive security analysis showcasing SAP's resilience against contemporary attack scenarios, with minimal impact on performance and area overhead, is also provided in this paper.
Md Sami Ul Islam Sami, Jingbo Zhou 0002, Sujan Kumar Saha, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor
ISPASS3
2024 Continuity in Security: Leveraging LLM for Translating Security Properties Across Hardware Designs
abstract
Systems on Chips (SoCs) are integral to modern devices, from consumer electronics to critical applications in healthcare, finance, and defense, housing various vital assets. Ensuring comprehensive security verification is crucial to protect these assets from diverse vulnerabilities. However, traditional security verification is time-consuming, and the rapid pace of market-driven design cycles demands new versions within tight time-to-market windows. Conducting exhaustive security verification from scratch for each new design iteration is both challenging and impractical. This paper introduces a novel framework leveraging large language models (LLMs) to translate security properties from legacy designs to new versions at the Register Transfer Level (RTL). By reusing existing verification efforts, this approach significantly reduces verification time while maintaining security continuity. Our methodology not only trans-lates but also extends and expands security properties to detect new vulnerabilities. Experimental results demonstrate substantial improvements in security continuity and vulnerability detection, advancing hardware security verification for evolving SoCs.
Bulbul Ahmed, Sujan Kumar Saha, Jingbo Zhou 0002, Sohrab Aftabjahani, Mark Tehranipoor, Farimah Farahmandi
VLSI-SoC2
2023 A Study on the Performance of Recurrent Neural Network based Models in Maithili Part of Speech Tagging
abstract
This article presents our effort in developing a Maithili Part of Speech (POS) tagger. Substantial effort has been devoted to developing POS taggers in several Indian languages, including Hindi, Bengali, Tamil, Telugu, Kannada, Punjabi, and Marathi; but Maithili did not achieve much attention from the research community. Maithili is one of the official languages of India, with around 50 million native speakers. So, we worked on developing a POS tagger in Maithili. For the development, we use a manually annotated in-house Maithili corpus containing 56,126 tokens. The tagset contains 27 tags. We train a conditional random fields (CRF) classifier to prepare a baseline system that achieves an accuracy of 82.67%. Then, we employ several recurrent neural networks (RNN)-based models, including Long-short Term Memory (LSTM), Gated Recurrent Unit (GRU), LSTM with a CRF layer (LSTM-CRF), and GRU with a CRF layer (GRU-CRF) and perform a comparative study. We also study the effect of both word embedding and character embedding in the task. The highest accuracy of the system is 91.53%.
Ankur Priyadarshi, Sujan Kumar Saha
ACM Trans. Asian Low Resour. Lang. Inf. Process.2
2021 Domain Isolation in FPGA-Accelerated Cloud and Data Center Applications
abstract
Cloud and data center applications increasingly leverage FPGAs because of their performance/watt benefits and flexibility advantages over traditional processing cores such as CPUs and GPUs. As the rising demand for hardware acceleration gradually leads to FPGA multi-tenancy in the cloud, there are rising concerns about the security challenges posed by FPGA virtualization. Exposing space-shared FPGAs to multiple cloud tenants may compromise the confidentiality, integrity, and availability of FPGA-accelerated applications. In this work, we present a hardware/software architecture for domain isolation in FPGA-accelerated clouds and data centers with a focus on software-based attacks aiming at unauthorized access and information leakage. Our proposed architecture implements Mandatory Access Control security policies from software down to the hardware accelerators on FPGA. Our experiments demonstrate that the proposed architecture protects against such attacks with minimal area and communication overhead.
Joel Mandebi, Sujan Kumar Saha, Christophe Bobda
ACM Great Lakes Symposium on VLSI2
2020 Towards the first Maithili part of speech tagger: Resource creation and system development
Ankur Priyadarshi, Sujan Kumar Saha
Comput. Speech Lang.2
2019 STGM: Spatio-Temporal GPU Management for Real-Time Tasks
abstract
Graphics Processing Units (GPUs) have been considered as a promising technology to address the high computational demands of real-time data-intensive applications. Today's embedded processors already offer on-chip GPUs, the use of which can greatly help satisfy the timing requirements of realtime tasks by accelerating their execution. However, existing GPU management schemes either underutilize the GPU due to strictly serialized execution or introduce non-deterministic delay caused by uncontrolled concurrent execution. In this paper, we present a spatial-temporal GPU management framework that controls the allocation and sharing of GPU's internal execution engines, e.g., streaming multiprocessors in Nvidia architectures, with analytical bounds. This approach allows multiple GPU-using tasks to simultaneously execute on the GPU, thereby improving GPU utilization and reducing the worst-case response time. Also, it can improve temporal isolation by allocating a portion of GPU execution engines to tasks for their exclusive use. We have examined the feasibility of our framework on two Nvidia GPUs: GTX970 and AGX Xavier. Experimental results with randomly-generated tasksets indicate that our framework yields a significant benefit in schedulability compared to the existing real-time GPU management approaches.
Sujan Kumar Saha, Yecheng Xiang, Hyoseung Kim 0001
RTCSA1
2012 A comparative study on feature reduction approaches in Hindi and Bengali named entity recognition
Sujan Kumar Saha, Pabitra Mitra, Sudeshna Sarkar
Knowl. Based Syst.1
2010 A composite kernel for named entity recognition
Sujan Kumar Saha, Shashi Narayan, Sudeshna Sarkar, Pabitra Mitra
Pattern Recognit. Lett.1
2009 Feature selection techniques for maximum entropy based biomedical named entity recognition
Sujan Kumar Saha, Sudeshna Sarkar, Pabitra Mitra
J. Biomed. Informatics1
2008 Word Clustering and Word Selection Based Feature Reduction for MaxEnt Based Hindi NER
Sujan Kumar Saha, Pabitra Mitra, Sudeshna Sarkar
ACL1
2008 A Hybrid Named Entity Recognition System for South and South East Asian Languages
Sujan Kumar Saha, Sanjay Chatterji, Sandipan Dandapat, Sudeshna Sarkar, Pabitra Mitra
IJCNLP1
2008 A Hybrid Feature Set based Maximum Entropy Hindi Named Entity Recognition
Sujan Kumar Saha, Sudeshna Sarkar, Pabitra Mitra
IJCNLP1