VLDB 2026 Research / reviewers in the wild / expert
M. Sazadur Rahman
dblp:244/8762 · also Mohammad Sazadur Rahman
· DBLP profile ↗
14ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-1045-9785ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 14 · 4 first-author · 13 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Redefining Tradition: An Active Watermarking Approach for IP Protection in SoCsabstractGlobalization of the System-on-Chip (SoC) supply chain has resulted in increased intellectual property (IP) piracy, illegal reuse, and tampering by malicious actors. In response to these challenges, IP watermarking presents itself as a promising solution to protect against these risks; however, traditional methods rely heavily on labor-intensive manual tests by verification engineers and fail to account for the potential threat posed by malicious SoC design houses. To overcome these challenges and improve the efficiency of the watermark verification process while safeguarding against possible attacks, we developedActiWateas an innovative watermarking approach that not only provides proof of authorship but also prevents unauthorized usage of an IP. Using an automatic self-verification technique, the watermark establishes communication with various peripherals within the SoC. The versatility and effectiveness ofActiWatehave been proven through extensive experiments on multiple SoCs with diverse components and peripherals, including the testing of watermarking and the verification of various IPs. Moreover, we discuss the inclusion of this multiple serialized verification in more case studies and results, as well as analyzing prominent security threats, including reverse engineering attacks. Zahin Ibnat, Mridha Md Mashahedur Rahman, M. Sazadur Rahman, Jingbo Zhou 0002, Farimah Farahmandi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | PSCMark: Power Side Channel-based Watermarking for SoC IPs Using Clock GatesabstractIntellectual property (IP) core reuse serves as a key factor to the rapid development of modern system-on-chips (SoCs) by minimizing time-to-market and manufacturing cost. However, it is crucial to prevent security risks such as IP piracy and over-use while allowing IP reuse. IP watermarking is a viable solution to safeguard the copyright of IP cores through their unique identification. In this article, we introduce PSCMark as an innovative technique for authenticating IPs through the power side-channel characteristic using clock gates. PSCMark seamlessly incorporates a power signature with minimal alterations to the IP core. This is accomplished by leveraging the existing clock gates to alter the dynamic power consumption within the IP (in an SoC) based on a specified challenge. This sharp variation in power attributes upon watermark activation facilitates IP authentication in SoC. Our experimental results show that PSCMark can be robustly/effectively verified, even with the interference emanating from the rest of the functional cores in complex SoCs. We evaluate our technique on several SoC benchmarks of varying size (i.e., MIPS, openMSP430, OR1200) and demonstrate its effectiveness in proving IP ownership with high detection resolution. We also provide silicon validation by implementing PSCMark across these benchmarks using the Artix-7 FPGA board. Furthermore, PSCMark ensures a subtle and obfuscated watermarking of IP cores, enhancing its resistance to detection, removal, or modification. Upoma Das, M. Sazadur Rahman, Akshay Kulkarni, Mark Tehranipoor, Farimah Farahmandi |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2024 | SeeMLess: Security Evaluation of Logic Locking using Machine Learning oriented EstimationabstractAlthough logic locking has been widely known as a promising countermeasure against intellectual property (IP) piracy and overproduction risks, it has been challenged by different attack breeds over the years. Attacks on logic locking, either algorithmic or structural, have been always known as a time-consuming resource-intensive effort. For instance, the Boolean satisfiability (SAT) attack might take weeks to be completed. In this paper, we introduce SeeMLess, a first-of-its-kind ML framework for the security evaluation of logic locking, design and locking agnostic. SeeMLess leverages feature sets computed from different aspects, graph-based, functional, propositional, etc. to accurately estimate the attack time with no attacks running. Our experimental results, on a case study over the SAT attack, show the trained model on a dataset of 5K+ designs locked by various techniques, where SeeMLess achieves <?TeX $\sim 95\%$?> Math 1 accuracy in predicting the time of the attack, offering valuable insights into the locking mechanism effectiveness pre-implementation. Bulbul Ahmed, M. Sazadur Rahman, Kimia Zamiri Azar, Farimah Farahmandi, Fahim Rahman, Mark Tehranipoor |
ACM Great Lakes Symposium on VLSI | 2 |
| 2023 | ActiWate: Adaptive and Design-agnostic Active Watermarking for IP Ownership in Modern SoCsabstractWatermarking offers a viable solution to combat IP piracy and illegal re-use. However, watermarking verification techniques rely heavily on manual testing by verification engineers and ignore the possibility of having a rogue SoC design house. To automate the watermarking-based verification process and to be against wider attacks (e.g., rogue design house), this paper presents ActiWate, which conducts automatic self-verification by communicating with various peripherals within the SoC. Showing its resilience against removal and spoofing attacks, ActiWate is architectured to be an IP/SoC-agnostic watermarking and our experiments demonstrate its versatility by implementing it on multiple RISC-V SoCs with different components/peripherals. Zahin Ibnat, M. Sazadur Rahman, Mridha Md Mashahedur Rahman, Hadi Mardani Kamali, Mark Tehranipoor, Farimah Farahmandi |
DAC | 2 |
| 2023 | EvoLUTe: Evaluation of Look-Up-Table-based Fine-Grained IP RedactionabstractRecent studies on intellectual property (IP) protection techniques demonstrate that engaging embedded reconfigurable components (e.g., eFPGA redaction) would be a promising approach to concealing the functional and structural information of the security-critical design. However, detailed investigation reveals that such techniques suffer from almost prohibited overhead in terms of area, power, delay, and testability. In this paper, we introduce EvoLUTe, a distinct and significantly more fine-grained redaction methodology using smaller reconfigurable components (such as look-up-tables (LUTs)). In EvoLUTe, we examine both eFPGA-based and LUT-based design spaces, demonstrating that a novel cone-based and fine-grained universal function modeling approach using LUTs is capable of providing the same degree of resiliency at a much lower area/power/delay and testability costs. Rui Guo 0010, M. Sazadur Rahman, Hadi Mardani Kamali, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
DATE | 2 |
| 2023 | PSC-Watermark: Power Side Channel Based IP Watermarking Using Clock GatesabstractWith the ever-increasing re-use of intellectual property (IP) cores in modern system-on-chips (SoCs), it is crucial to prevent security risks such as IP piracy and overuse. Considering that IP watermarking is a potential solution to the copyright protection of IP cores, this paper proposes PSC-Watermark as a power side-channel-based IP authentication methodology using clock gates. PSC-Watermark embeds a power signature with very minimal modification to the IP core. It is done by reusing the existing clock gates to modify the dynamic power consumption inside the IP (in an SoC) based on an applied challenge, and it generates a unique power trace that works as a signature of the IP. Our experimental results show that this power signature can be robustly/effectively verified, even with the interferences emanating from the rest of the functional cores in complex SoCs. We evaluate our technique on several benchmarks of varying size (i.e., MIPS, openMSP430, or1200) in the presence of multiple non-watermarked cores operating in parallel and obtain > 90% confidence rate in proving the ownership of each watermarked IP core. Furthermore, the IP cores are watermarked in a subtle and obfuscated way with < 4% overhead, which makes the proposed technique hard to detect, remove or modify. Upoma Das, M. Sazadur Rahman, N. Nalla Anandakumar, Kimia Zamiri Azar, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
ETS | 2 |
| 2023 | Metrics-to-Methods: Decisive Reverse Engineering Metrics for Resilient Logic LockingabstractAs logic locking becomes more sophisticated and new technologies emerge (e.g., laser probing for failure analysis), the statement "logic locking is dead" will become more common. While recent studies have investigated the possibility of defining a security metric(s) for logic locking, none are sufficient against all threat models and potential future threats. In this paper, we first examine the quantitative and qualitative metrics as a MUST for logic locking. Then, by establishing a bridge between metrics and the potential methods, we introduce a compound-style logic locking that can meet the criteria needed for logic locking based on the defined metrics. M. Sazadur Rahman, Kimia Zamiri Azar, Farimah Farahmandi, Hadi Mardani Kamali |
ACM Great Lakes Symposium on VLSI | 1 |
| 2023 | CAPEC: A Cellular Automata Guided FSM-based IP Authentication SchemeabstractThe ever-increasing propensity for intellectual property (IP) reuse has reduced the design productivity gap in the supply chain. As a consequence, protecting IPs has become more difficult since IP vendors now make their IPs more flexible so that they can be reused in other designs for greater profits. This has made IP piracy and infringement easier than ever. IP watermarking can detect IP piracy and infringement and it has been an active research topic for the past decade. Various watermarking techniques have been discussed in the literature that embed circuitry into IP to provide proof of ownership. But, in most RT-level watermarking methods, the watermarking circuit is separate from IP functionality and can be easily identified and tampered with. In this paper, we propose CAPEC, a Cellular Automata (CA) guided watermarking technique that embeds watermarking circuits into the don’t care states of the FSM. The watermarking function is a set of configurable CA rules tightly coupled with the functional states of the FSM. CAPEC generates a signature in a challenge-response-based protocol, is resistant to identification, tampering, and removal attacks, and has minimal overhead. We also analyze and evaluate the efficiency of the technique and its resilience to different attacks for varying challenge size and CA rules. After watermarking different benchmarks, the watermark overhead was found to be negligible and formal verification proved no changes to the functional circuit. Mridha Md Mashahedur Rahman, M. Sazadur Rahman, Rasheed Kibria, Mike Borza, Bandy Reddy, Adam Cron, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
VTS | 2 |
| 2023 | iPROBE: Internal Shielding Approach for Protecting Against Front-Side and Back-Side Probing AttacksabstractFocused ion beam (FIB) has emerged as one of the most prevalent integrated circuit (IC) editing techniques in the past decade, greatly assisting post-silicon debugging and failure analysis. However, the confidentiality of security assets on electronic devices is gravely threatened by FIB-based probing attacks because of the FIB’s fine-grained milling and deposition capabilities on silicon die. Although numerous solutions, such as active shields and analog sensors have been proposed, they either incur prohibitively high overhead or suffer from low reliability, failing to provide protection against such threats in a feasible manner. In this article, we propose a FIB-aware framework, iPROBE, as a set of computer-aided design (CAD) utilities to quantify the threats of FIB attacks on the target layout from both front-side and back-side at the pre-silicon stage. The subsequent shield nets/layer place-and-route are completely automated by iPROBE to minimize the quantified FIB vulnerability metric, so-called exposed area (EA), allowing users to achieve the optimal security level at a cost of minimal performance degradation, extra design efforts, and time consumption. Our experimental results show that the EA of security-critical nets, i.e., vulnerable regions inside the physical layout, to front-side and back-side probing attacks can be fully eliminated at low FIB aspect ratios with only 3% timing and area overhead. Moreover, we validate the results through the FIB experiments on a fabricated test chip covering both baseline and iPROBE-protected AES implementations at 65nm technology node, further demonstrating the effectiveness of iPROBE. Minyan Gao, M. Sazadur Rahman, Nitin Varshney, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | O'clock: lock the clock via clock-gating for SoC IP protectionabstractExisting logic locking techniques can prevent IP piracy or tampering. However, they often come at the expense of high overhead and are gradually becoming vulnerable to emerging deobfuscation attacks. To protect SoC IPs, we propose O'Clock, a fully-automated clock-gating-based approach that 'locks the clock' to protect IPs in complex SoCs. O'Clock obstructs data/control flows and makes the underlying logic dysfunctional for incorrect keys by manipulating the activity factor of the clock tree. O'Clock has minimal changes to the original design and no change to the IC design flow. Our experimental results show its high resiliency against state-of-the-art de-obfuscation attacks (e.g., oracle-guided SAT, unrolling-/BMC-based SAT, removal, and oracle-less machine learning-based attacks) at negligible power, performance, and area (PPA) overhead. M. Sazadur Rahman, Rui Guo 0010, Hadi Mardani Kamali, Fahim Rahman, Farimah Farahmandi, Mohamed Abdel-Moneum, Mark Tehranipoor |
DAC | 1 |
| 2022 | RTL-FSMx: Fast and Accurate Finite State Machine Extraction at the RTL for Security ApplicationsabstractAt the early stage of the design process, many security vulnerability assessment solutions require fast and precise extraction of the finite state machines (FSMs) present in the register-transfer level (RTL) description of the design. FSMs should be accurately extracted for watermark insertion, fault injection assessment of control paths in a system-on-chip (SoC), information leakage assessment, control-flow reverse engineering in RTL abstraction, logic obfuscation, etc. However, it is quite unfortunate that, as of today, existing state-of-the-art synthesis tools cannot provide accurate and reliable extraction of all FSMs from the provided high-level RTL code. Precise identification of all FSM state registers and the pure combinational state transition logic described in the RTL code with numerous registers and other combinational logic makes it quite challenging to develop such a solution. In this paper, we propose a framework named RTL-FSMx to extract FSMs from high-level RTL codes written in Verilog HDL. RTL-FSMx utilizes node-based analysis on the abstract syntax tree (AST) representation of the RTL code to isolate FSM state registers from other registers. RTL-FSMx automatically extracts state transition graphs (STGs) for each of the detected FSM state registers and additional information of the extracted FSMs. Experimental results on a large number of benchmark circuits demonstrate that RTL-FSMx accurately recovers all control FSMs from RTL codes with various complexity and size within just a few seconds. Rasheed Kibria, M. Sazadur Rahman, Farimah Farahmandi, Mark Tehranipoor |
ITC | 2 |
| 2021 | LL-ATPG: Logic-Locking Aware Test Using Valet Keys in an Untrusted EnvironmentabstractThe ever-increasing cost and complexity of cutting-edge manufacturing and test processes have migrated the semiconductor industry towards a globalized business model. With many untrusted entities involved in the supply chain located across the globe, original intellectual property (IP) owners face threats such as IP theft/piracy, tampering, counterfeiting, reverse engineering, and overproduction. Logic locking has emerged as a promising solution to protect integrated circuits (ICs) against supply chain vulnerabilities. It inserts key gates to corrupt circuit functionality for incorrect key inputs. A logic-locked chip test can be performed either before or after chip activation (becoming unlocked) by loading the unlocking key into the on-chip tamperproof memory. However, both pre-activation and post-activation tests suffer from lower test coverage, higher test cost, and critical security vulnerabilities. To address the shortcomings, we propose LL-ATPG, a logic-locking aware test method that applies a set of valet (dummy) keys based on a target test coverage to perform manufacturing test in an untrusted environment. LL-ATPG achieves high test coverage and minimizes test time overhead when testing the logic-locked chip before activation without sharing the unlocking key. We perform security analysis of LL-ATPG and experimentally demonstrate that sharing the valet keys with the untrusted foundry does not create additional vulnerability for the underlying locking method. M. Sazadur Rahman, Henian Li, Rui Guo 0010, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ITC | 1 |
| 2021 | Security Assessment of Dynamically Obfuscated Scan Chain Against Oracle-guided AttacksabstractLogic locking has emerged as a promising solution to protect integrated circuits against piracy and tampering. However, the security provided by existing logic locking techniques is often thwarted by Boolean satisfiability (SAT)-based oracle-guided attacks. Criteria for successful SAT attacks on locked circuits include: (i) the circuit under attack is fully combinational, or (ii) the attacker has scan chain access. To address the threat posed by SAT-based attacks, we adopt the dynamically obfuscated scan chain (DOSC) architecture and illustrate its resiliency against the SAT attacks when inserted into the scan chain of an obfuscated design. We demonstrate, both mathematically and experimentally, that DOSC exponentially increases the resiliency against key extraction by SAT attack and its variants. Our results show that the mathematical estimation of attack complexity correlates to the experimental results with an accuracy of 95% or better. Along with the formal proof, we model DOSC architecture to its equivalent combinational circuit and perform SAT attack to evaluate its resiliency empirically. Our experiments demonstrate that SAT attack on DOSC-inserted benchmark circuits timeout at minimal test time overhead, and while DOSC requires less than 1% area and power overhead. M. Sazadur Rahman, Adib Nahiyan, Fahim Rahman, Saverio Fazzari, Kenneth Plaks, Farimah Farahmandi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2020 | Defense-in-depth: A recipe for logic locking to prevail
M. Tanjidur Rahman, M. Sazadur Rahman, Shahin Tajik, Waleed Khalil, Farimah Farahmandi, Domenic Forte, Navid Asadizanjani, Mark Tehranipoor |
Integr. | 2 |