Shubham Malaviya

dblp:291/4512 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-9615-5693ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Poster: Impulse in the Clickstream: Behavioral Insights from Browsing History
abstract
Phishing attacks often exploit user impulsivity, leading to reflexive clicks on malicious links without proper evaluation. While prior research has explored phishing awareness, there remains a gap in understanding impulsive clicking behavior. In this study, we present a novel approach to characterize clicking impulsivity using browser history data. Our session-level analysis reveals that user's impulsive clicking behavior is situational and context dependent. Our findings offer actionable insights for adaptive security interventions based on real-time user behavior.
Shubham Malaviya, Anuj Bagad, Manish Shukla 0001, Sachin Lodha
CCS1
2024 Poster: Context-Based Effective Password Detection in Plaintext
abstract
From an enterprise perspective, storage of passwords in plaintext on a computer hard disk is a serious concern. Such password storage practice helps a malicious agent to do privilege escalation, install a backdoor, disable critical monitoring tools, and allow them to laterally move within organization's network. Considering the exploitability of the plaintext password stored on a storage device, it is imperative for an organization to identify such files and safeguard them without causing disruption to a user's work routine. In this work, we present a context-based password discovery solution for plaintext that performs multi-step context discovery for reducing false positives and negatives. Moreover, we protect all the identified files using an on-the-fly user authentication layer, which helps in preventing automated or command-line-based access to sensitive content in case of a cyberattack.
Manish Shukla 0001, Shubham Malaviya, Sachin Lodha
CCS2
2024 Poster: Unmasking Label Errors: A need for Robust Cybersecurity Benchmarks
abstract
Cyber Threat Intelligence (CTI) utilizes information from various sources, necessitating high-quality labeled datasets for effective application of machine learning. Our study addresses the often-overlooked issue of labeling errors in cybersecurity benchmarks, resulting in the creation of D-LADDER++, a curated version of the recently published LADDER dataset. We evaluated the performance of both an open-source model (Microsoft Phi-3) and a closed-source model (Google Gemini) on D-LADDER++. We assessed their zero-shot and few-shot capabilities and fine-tuned the Phi-3 model for enhanced adaptability. Our assessment of the impact of test errors on model performance emphasizes the critical need for robust benchmarks in cybersecurity to ensure accurate model evaluation and selection.
Shubham Malaviya, Manish Shukla 0001, Saurabh Anand, Sachin Lodha
CCS1
2024 CompFreeze : Combining Compacters and Layer Freezing for Enhanced Pre-Trained Language Model
abstract
Leveraging vast datasets from various security tools and sources for training AI models in cybersecurity offers significant potential to learn better representations of real-world behavior. However, data drift and labeled data scarcity are major challenges leading to frequent and costly model updates and the risk of overfitting. To address these issues, we introduce CompFreeze, a parameter-efficient fine-tuning technique combining compacters and layer freezing strategies. We evaluate the effectiveness of CompFreeze on three pre-trained models in the cybersecurity domain across various downstream tasks. We demonstrate that with significantly less trainable parameters, CompFreeze performs on par with full model fine-tuning while taking less training time. We have performed comprehensive experimental analysis involving investigating the impact of different learning rates and varying the number of compacter modules integrated into models, offering an in-depth analysis of the trade-off between accuracy and inference time.
Saurabh Anand, Shubham Malaviya, Manish Shukla 0001, Sachin Lodha
PST2