VLDB 2026 Research / reviewers in the wild / expert
Mahya Morid Ahmadi
dblp:295/8603
· DBLP profile ↗
4ranked-venue papers
4as first author
4since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Camo-DNN: Layer Camouflaging to Protect DNNs against Timing Side-Channel AttacksabstractExtracting the architecture of layers of a given deep neural network (DNN) through hardware-based side channels allows adversaries to steal its intellectual property and even launch powerful adversarial attacks on the target system. In this work, we propose Camo $D N N$, an obfuscation method for DNNs that forces all the layers in a given network to have similar execution traces, preventing attack models from differentiating between the layers. Towards this, Camo DNN performs various layer-obfuscation operations, e.g., layer branching layer deepening, etc., to alter the run-time traces while maintaining the functionality. Camo-DNN deploys an evolutionary algorithm to find the best combination of obfuscation operations in terms of maximizing the security level while maintaining a user-provided latency overhead budget Our experiments show that state-of-the-art side-channel architecture stealing attacks cannot extract the architecture of DNN protected by Camo-DNN accurately. Further, we highlight that the adversarial attack on our obfuscated DNNs are unsuccessful. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IOLTS | 1 |
| 2023 | ShapeShifter: Protecting FPGAs from Side-Channel Attacks with Isofunctional Heterogeneous ModulesabstractCloud service providers are interested in deploying multi-tenant Field-Programmable Gate Arrays (FPGAs) for virtualized computation platforms. A primary concern towards such shared FPGA platforms is ensuring the security of critical applications (such as encryption cores) against hardware-based attacks, such as remote power Side-Channel Attacks (SCAs) intended to steal secret assets like encryption keys. To address this issue, we propose ShapeShifter, a novel defense methodology based on design diversity that generates isofunctional variants of the target application at the design stage using different synthesis, placement, and routing procedures. ShapeShifter leverages the dynamic partial reconfiguration feature of modern FPGAs to exchange the variants at run-time, causing dynamic variations in the power trace (vertical obfuscation) and introducing misalignment in the time domain (horizontal obfuscation) to thwart SCAs. ShapeShifter successfully thwarts the Correlation Power Analysis (CPA) attack on an Advanced Encryption Standard (AES) implementation, ensuring unsuccessful key byte recovery for up to$10\times$more traces. It also decreases the CPA value by$0.69\times$, reducing the attacker's confidence in key recovery. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IOLTS | 1 |
| 2023 | FPGA-Patch: Mitigating Remote Side-Channel Attacks on FPGAs using Dynamic Patch GenerationabstractWe propose FPGA-Patch, the first-of-its-kind defense that leverages automated program repair concepts to thwart power side-channel attacks on cloud FPGAs. FPGA-Patch generates isofunctional variants of the target hardware by injecting faults and finding transformations that eliminate failure. The obtained variants display different hardware characteristics, ensuring a maximal diversity in power traces once dynamically swapped at run-time. Yet, FPGA-Patch forces the variants to have enough similarity, enabling bitstream compression and minimizing dynamic exchange costs. Considering AES running on AMD/Xilinx FPGA, FPGA-Patch increases the attacker's effort by three orders of magnitude, while preserving the performance of AES and a minimal area overhead of 14.2%. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
ISLPED | 1 |
| 2022 | NeuroUnlock: Unlocking the Architecture of Obfuscated Deep Neural NetworksabstractThe advancements of deep neural networks (DNNs) have led to their deployment in diverse settings, including safety and security-critical applications. As a result, the characteristics of these models (e.g., the architecture of layers and weight values/distributions) have become sensitive intellectual properties that require protection from malicious users. Extracting the architecture of a DNN through leaky side-channels (e.g., memory access) allows adversaries to (i) clone the model (i.e., build proxy models with similar accuracy profiles), and (ii) craft adversarial attacks. DNN obfuscation thwarts side-channel-based architecture stealing (SCAS) attacks by altering the run-time traces of a given DNN while preserving its functionality. In this work, we expose the vulnerability of state-of-the-art DNN obfuscation methods (based on predictable and reversible modifications employed in a given DNN architecture) to these attacks. We present NeuroUnlock, a novel SCAS attack against obfuscated DNNs. Our NeuroUnlock employs a sequence-to-sequence model that learns the obfuscation procedure and automatically reverts it, thereby recovering the original DNN architecture. We demonstrate the effectiveness of NeuroUnlock by recovering the architecture of 200 randomly generated and obfuscated DNNs running on the Nvidia RTX 2080 TI graphics processing unit (GPU). Moreover, NeuroUnlock recovers the architecture of various other obfuscated (and publicly available) DNNs, such as the VGG-11, VGG-13, ResNet-20, and ResNet-32 networks. After recovering the architecture, NeuroUnlock automatically builds a near-equivalent DNN with only a 1.4% drop in the testing accuracy. We further show that launching a subsequent adversarial attack on the recovered DNNs boosts the success rate of the adversarial attack by 51.7% in average compared to launching it on the obfuscated versions. Additionally, we propose a novel methodology for DNN obfuscation, ReDLock, which eradicates the deterministic nature of the obfuscation and achieves 2.16 x more resilience to the NeuroUnlock attack. We release the NeuroUnlock and the ReDLock as open-source frameworks 1 1 https://github.com/Mahya-Ahmadi/NeuroUnlock. Mahya Morid Ahmadi, Lilas Alrahis, Alessio Colucci, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IJCNN | 1 |