Debasmita Dey

dblp:254/9404 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0002-9327-6545ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 POSTER: Small but Secure: Distilling SecAlign Defense on Edge LLMs via On-Policy RL
abstract
Large language models (LLMs) deployed on edge devices (smart-phones, IoT) require small parameters for efficiency, but state-of-the-art prompt injection defenses like SecAlign only work effectively at 8B+ parameters, leaving edge deployments vulnerable. We address this gap by transferring SecAlign's defense properties to 1B edge LLMs through on-policy distillation with reinforcement learning (RL). During on-policy distillation, the student models learn from their own failure modes and is inexpensive to train and evaluate rather than imitating teacher generated responses. The student generates responses to prompt-injected inputs and learns from teacher-guided preferences using importance sampling with negative reverse KL divergence as an advantage function. Through experiments on 1B Llama model, our on-policy RL distillation approach dramatically outperforms standard knowledge distillation with reduced attack success rate, and achieves comparable performance to 8B SecAlign teacher model with Llama backbone, enabling effective compression of state-of-the-art defenses to edge LLMs.
Debasmita Dey, Arkajyoti Mitra
AsiaCCS1
2025 iQUIC: An intelligent framework for defending QUIC connection ID-based DoS attack using advantage actor-critic RL
abstract
QUIC (Quick UDP Internet Connections) is a relatively recent transport layer protocol that Google deployed and implemented for the first time in 2012. The key aspect of this protocol is that it is faster than TCP, more secure than UDP , and more efficient regarding resource usage. It has been adopted by some Internet-based applications, viz., YouTube, Gmail, etc. Recent advancements in 5G/6G communication technology have enabled the integration of QUIC with many real-time applications. One of the drawbacks in the design of the QUIC protocol is its vulnerability against attacks related to connection ID, and a recent attack of this type is the retire connection ID stuffing attack . This attack leads to a denial of service (DoS) condition, thus hindering network operations and services. Few preventive solutions have been proposed, but they focus on closing the connection after detecting an attack scenario, which results in service disruption . In this paper, we attempted to render flexibility to this rigid security defense mechanism situation by proposing iQUIC , an intelligent framework to configure a network condition monitoring QUIC server. The framework inputs the network data to a local Advantage Actor–Critic (A2C) Reinforcement Learning (RL) engine to support decision-making regarding accepting/rejecting a request from a client or issuing a warning signal to it. The framework also enables the server to stochastically suspend connections with the client(s) following in ϵ -greedy approach after a predefined observation window. To replicate a real-world QUIC-enabled network, we devised a small QUIC network consisting of two clients and a server and generated substantial QUIC traffic by implementing a U-Net-based GAN (Generative Adversarial Network) model from scratch. A simulation-based performance evaluation demonstrates that the QUIC server powered by the actor–critic RL learns to make optimal decisions with time.
Debasmita Dey, Nirnay Ghosh
Comput. Secur.1
2025 HessianAuth: A Secure and Efficient Authentication Mechanism for Resource-Constrained IoT Networks
Debasmita Dey, Nirnay Ghosh
Peer Peer Netw. Appl.1
2024 iTRPL: An intelligent and trusted RPL protocol based on Multi-Agent Reinforcement Learning
Debasmita Dey, Nirnay Ghosh
Ad Hoc Networks1