VLDB 2026 Research / reviewers in the wild / expert
Shuvalaxmi Dass
dblp:262/0775
· DBLP profile ↗
6ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0001-9254-8134ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HYDRA: A Hybrid Heuristic-Guided Deep Representation Architecture for Predicting Latent Zero-Day Vulnerabilities in Patched FunctionsabstractSoftware security testing, particularly when enhanced with deep learning models, has become a powerful approach for improving software quality, enabling faster detection of known flaws in source code. However, many approaches miss post-fix latent vulnerabilities that remain even after patches typically due to incomplete fixes or overlooked issues may later lead to zero-day exploits. In this paper, we propose HYDRA, a Hybrid heuristic-guided Deep Representation Architecture for predicting latent zero-day vulnerabilities in patched functions that combines rule-based heuristics with deep representation learning to detect latent risky code patterns that may persist after patches. It integrates static vulnerability rules, GraphCodeBERT embeddings, and a Variational Autoencoder (VAE) to uncover anomalies often missed by symbolic or neural models alone. We evaluate HYDRA in an unsupervised setting on patched functions from three diverse real-world software projects: Chrome, Android, and ImageMagick. Our results show HYDRA predicts 13.7%, 20.6%, and 24% of functions from Chrome, Android, and ImageMagick respectively as containing latent risks, including both heuristic matches and cases without heuristic matches (None) that may lead to zero-day vulnerabilities. It outperforms baseline models that rely solely on regex-derived features or their combination with embeddings, uncovering truly risky code variants that largely align with known heuristic patterns. These results demonstrate HYDRA’s capability to surface hidden, previously undetected risks, advancing software security validation and supporting proactive zero-day vulnerabilities discovery. Mohammad Farhad, Sabbir Rahman, Shuvalaxmi Dass |
AST | 3 |
| 2023 | Towards Privacy Preserving Financial Fraud DetectionabstractFederated Learning (FL) has gained prominence in fields where safeguarding data privacy is of utmost importance, presenting a valuable approach for the detection of credit card or financial fraud. The detection of fraud in credit card transactions, as well as other digitized financial activities, plays a pivotal role in upholding the integrity of financial transactions, safeguarding the assets of individuals and businesses, and contributing to a more secure and trustworthy financial environment. The field of machine learning and deep learning is continuously advancing, offering promising solutions for bolstering fraud prevention and minimizing financial losses. Nevertheless, in situations where data owners are hesitant to share their data due to privacy regulations, security concerns, or the sensitive nature of the information involved, a privacy-preserving machine learning technique like FL can significantly enhance fraud detection. FL achieves this by harnessing the collective strength of multiple institutions' data without compromising the privacy of individual users. The re-search presented in this paper leverages the advantages of FL for financial fraud detection. The proposed FL model outperformed a conventional neural network in terms of precision, accuracy, loss and recall when identifying instances of financial fraud. Stephanie Abanilla, Moitrayee Chatterjee, Shuvalaxmi Dass |
ICMLA | 3 |
| 2021 | Attack Prediction using Hidden Markov ModelabstractIt is important to predict any adversarial attacks and their types to enable effective defense systems. Often it is hard to label such activities as malicious ones without adequate analytical reasoning. We propose the use of Hidden Markov Model (HMM) to predict the family of related attacks. Our proposed model is based on the observations often agglomerated in the form of log files and from the target or the victim’s perspective. We have built an HMM-based prediction model and implemented our proposed approach using Viterbi algorithm, which generates a sequence of states corresponding to stages of a particular attack. As a proof of concept and also to demonstrate the performance of the model, we have conducted a case study on predicting a family of attacks called Action Spoofing. Shuvalaxmi Dass, Prerit Datta, Akbar Siami Namin |
COMPSAC | 1 |
| 2020 | A Sensitivity Analysis of Evolutionary Algorithms in Generating Secure ConfigurationsabstractThe growth of Cyber-physical Systems (CPS) has been increased in recent years. This has led to the coupling of highly complex cyber-physical components. With the integration of such complex components, new security challenges have emerged. Studies involving security issues in CPS have been quite difficult to be generalized due to the presence of heterogeneity and the diversity of the CPS components. These systems are subject to various vulnerabilities, threats and attacks, as a consequence of complex versions of CPS being introduced over time. This paper deals with vulnerabilities caused due to improper configurations in the software component of cyber-physical systems. Evolutionary algorithms such as Genetic Algorithms (GA) and Particle Swarm Optimization (PSO) can be employed to adequately test the underlying software for certain categories of vulnerabilities. This paper provides a detailed sensitivity analysis of these evolutionary algorithms in order to find out whether changing parameters involved in tuning these algorithms affect the overall performance. This analysis is based on the estimate of the number of generation of secure vulnerability pattern vectors under the variation of different parameters. The results indicate that while there is no evidence of influential parameters in Genetic Algorithms (i.e., mutation rate and population size), changes in the parameters involved in Particle Swarm Optimization algorithms (i.e., velocity rate and fitness range) have some positive impacts on the number of secure configurations generated. Shuvalaxmi Dass, Akbar Siami Namin |
IEEE BigData | 1 |
| 2020 | Evolutionary Algorithms for Vulnerability CoverageabstractWe present a novel idea on adequacy testing called "vulnerability coverage." The introduced coverage measure examines the underlying software for the presence of certain classes of vulnerabilities often found in the National Vulnerability Database (NVD) website. The thoroughness of the test input generation procedure is performed through the adaptation of evolutionary algorithms namely Genetic Algorithms (GA) and Particle Swarm Optimization (PSO). The methodology utilizes the Common Vulnerability Scoring System (CVSS), a free and open industry standard for assessing the severity of computer system security vulnerabilities, as a fitness measure for test inputs generation. The outcomes of these evolutionary algorithms are then evaluated in order to identify the vulnerabilities that match a class of vulnerability patterns for testing purposes. Shuvalaxmi Dass, Akbar Siami Namin |
COMPSAC | 1 |
| 2020 | Ensemble Random Forests Classifier for Detecting Coincidentally Correct Test CasesabstractThe performance of coverage-based fault localization greatly depends on the quality of test cases being executed. These test cases execute some lines of the given program and determine whether the underlying tests are passed or failed. In particular, some test cases may be well-behaved (i.e., passed) while executing faulty statements. These test cases, also known as coincidentally correct test cases, may negatively influence the performance of the spectra-based fault localization and thus be less helpful as a tool for the purpose of automated debugging. In other words, the involvement of these coincidentally correct test cases may introduce noises to the fault localization computation and thus cause in divergence of effectively localizing the location of possible bugs in the given code. In this paper, we propose a hybrid approach of ensemble learning combined with a supervised learning algorithm namely, Random Forests (RF) for the purpose of correctly identifying test cases that are mislabeled to be the passing test cases. A cost-effective analysis of flipping the test status or trimming (i.e., eliminating from the computation) the coincidental correct test cases is also reported. Shuvalaxmi Dass, Xiaozhen Xue, Akbar Siami Namin |
COMPSAC | 1 |