VLDB 2026 Research / reviewers in the wild / expert
Hari Venugopalan
dblp:257/7230
· DBLP profile ↗
6ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-7607-7256ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GlucOS: Security, correctness, and simplicity for automated insulin deliveryabstractWe present GlucOS, a novel system for trustworthy automated insulin delivery. Fundamentally, this paper is about a system we designed, implemented, and deployed on real humans and the lessons learned from our experiences. GlucOS introduces a novel architecture that allows users to personalize diabetes management using any predictive model (including ML) for insulin dosing while simultaneously protecting them against malicious models. We also introduce a novel holistic security mechanism that adapts to unprecedented changes to human physiology. We use formal methods to prove correctness of critical components and incorporate humans as part of our defensive strategy. Our evaluation includes both a real-world deployment with seven individuals and results from simulation to show that our techniques generalize. We highlight that our results are not from a lab study, with people using GlucOS to manage Type 1 Diabetes in their daily lives. Our results show that GlucOS maintains safety and improves glucose control even under attack conditions. This work demonstrates the potential for secure, personalized, automated healthcare systems. Our entire source code is available at this link. Hari Venugopalan, Shreyas Madhav Ambattur Vijayanand, Caleb Stanford, Stephanie Crossen, Samuel T. King |
MobiSys | 1 |
| 2025 | FP-Rowhammer: DRAM-Based Device Fingerprinting
Hari Venugopalan, Kaustav Goswami 0002, Zain ul Abi Din, Jason Lowe-Power, Samuel T. King, Zubair Shafiq |
AsiaCCS | 1 |
| 2025 | FP-Inconsistent: Measurement and Analysis of Fingerprint Inconsistencies in Evasive Bot TrafficabstractBrowser fingerprinting is used for bot detection. In response, bots have started altering their fingerprints to evade detection. We conduct the first large-scale evaluation to study whether and how altering fingerprints helps bots evade detection. To systematically investigate such evasive bots, we deploy a honey site that includes two anti-bot services (DataDome and BotD) and solicit bot traffic from 20 different bot services that purport to sell ''realistic and undetectable traffic.'' Across half a million requests recorded on our honey site, we find an average evasion rate of 52.93% against DataDome and 44.56% evasion rate against BotD. Our analysis of fingerprint attributes of evasive bots shows that they indeed alter their fingerprints. Moreover, we find that the attributes of these altered fingerprints are often inconsistent with each other. We propose FP-Inconsistent, a data-driven approach to detect such inconsistencies across space (two attributes in a given browser fingerprint) and time (a single attribute at two different points in time). Our evaluation shows that our approach can reduce the evasion rate of evasive bots by 44.95%-48.11% while maintaining a true negative rate of 96.84% on traffic from real users. Hari Venugopalan, Shaoor Munir, S. Shuaib Ahmed, Tangbaihe Wang, Samuel T. King, Zubair Shafiq |
IMC | 1 |
| 2021 | Doing good by fighting fraud: Ethical anti-fraud systems for mobile paymentsabstractApp builders commonly use security challenges, a form of step-up authentication, to add security to their apps. However, the ethical implications of this type of architecture has not been studied previously.In this paper, we present a large-scale measurement study of running an existing anti-fraud security challenge, Boxer, in real apps running on mobile devices. We find that although Boxer does work well overall, it is unable to scan effectively on devices that run its machine learning models at less than one frame per second (FPS), blocking users who use inexpensive devices.With the insights from our study, we design Daredevil, a new anti-fraud system for scanning payment cards that works well across the broad range of performance characteristics and hardware configurations found on modern mobile devices. Daredevil reduces the number of devices that run at less than one FPS by an order of magnitude compared to Boxer, providing a more equitable system for fighting fraud.In total, we collect data from 5,085,444 real devices spread across 496 real apps running production software and interacting with real users. Zain ul Abi Din, Hari Venugopalan, Adam Wushensky, Steven Liu, Samuel T. King |
SP | 2 |
| 2020 | Boxer: Preventing fraud by scanning credit cards
Zain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li, Weisu Yin, Haohui Mai, Yong Jae Lee, Steven Liu, Samuel T. King |
USENIX Security Symposium | 2 |
| 2019 | MultiLock: biometric-based graded authentication for mobile devicesabstractWhile traditionally smartphones have relied on methods such as a passcode or pattern-based authentication, biometric authentication techniques are gaining popularity. However current biometric methods are heavily dependent on various environmental factors. For example, face authentication methods depend on lighting conditions, camera shake and picture framing, while fingerprint scanning relies on finger placement. All of these variables can result in these systems becoming time-consuming for the user to use. To remedy these problems, we propose MultiLock, a passive, graded authentication system, which uses face authentication as a case study to propose a system that gives users access to their devices without requiring them to manually interact with the lock screen. Multi-Lock allows a user to categorize applications into various security bins based on their sensitivity. By doing so MultiLock can grant users access to different sensitivity applications, based on varying degrees of sureness that the device is being used by its rightful owner. Thus, allowing the device to be used even in adverse lighting conditions without hampering user experience. In our tests, MultiLock was able to grant access to users for 88% of the interactions on average, while passively running in the background. While we use face authentication as an example to demonstrate and propose MultiLock, our system can be used with any confidence based biometric system. Shravan Aras, Chris Gniady, Hari Venugopalan |
MobiQuitous | 3 |