VLDB 2026 Research / reviewers in the wild / expert
Rajesh Kumar 0012
dblp:30/5688-12
· DBLP profile ↗
8ranked-venue papers
6as first author
6since 2021 · last 2026
0000-0002-8151-4673ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Event-centric semantic alignment of vulnerabilities with adversarial attack techniques
Swapnil Pandey, Tanmay Joshi, Rajesh Kumar 0012 |
Appl. Intell. | 3 |
| 2024 | PALM: A framework to identify novel attacks in an e-commerce systemabstractThe widespread adoption of e-commerce and its lucrative, decentralized, multi-agent nature have made these systems vulnerable to cyber-attacks. Traditional signature-based approaches have been successful in detecting instances of fraud, however, they continue to struggle against unknown attacks. To this end, we present PALM, a framework that bridges the data-oriented process mining community with model-based security engineering with an aim to detect novel cyber-exploit automatically from a given event-log. It relies on the insight that security attacks on digital infrastructures seek to modify the system behaviour inducing unsafe states. Consequently, we propose an approach to represent the behaviour of the system and establish a signature-based attack database that can be used to predict unseen exploits. Building on the success of process-mining community, our framework first discovers a Petri Net model automatically from an event-log using the "Inductive Miner (IM)" algorithm. Next we, explicitly map the system features onto the discovered Petri-Net. Subsequently, the Petri-Net model is trained over contextual attack signatures. This step is crucial for capturing the nuances of system dynamics and identifying potential vulnerabilities or attack surfaces that may be exploited by malicious actors. Graph Convolution Network is then employed to look for malicious feature correlations and information flows, indicating a likelihood of a link between unconnected neighbouring nodes. Using a sample event-log, we test the efficacy of our framework, achieving 83.33% accuracy and an AUC-ROC of 0.9186, signifying its potential in identifying novel attack paths. Rajesh Kumar 0012, Swapnil Pandey, Debanshu Das |
PRDC | 1 |
| 2023 | A methodology for resilient safety-critical infrastructures using statistical model checkingabstractEngineering safety-critical infrastructures for continuous operation is a challenging task. With increasingly integration and automation, these systems are overwhelmingly exposed to disruptions - arising from both accidental causes and malicious threats. In this paper, we report on our work on developing quan-titative risk assessment methods to ensue such infrastructures remain resilient to disruptions. Our approach involves building the quantitative domain models to carry: a) continuous risk analysis - estimating the likelihood of system disruption and quantify its damaging impact. b) identify the most crucial system components to keep the system operational. c) dictating optimal incident response strategies. Technically, we model the system in a compositional manner by building and composing stochastic timed automaton of each system component. Along with metrics of interest, these models are fed to the statistical model checker of UPPAAL SMC. Metrics of interest are disruption scenarios in the system model. A scenario is encoded in a variant of temporal logic for its use in the model checker. We use a realistic industrial case-study of steam-boiler system to showcase the methodology. Rajesh Kumar 0012, Nitish Yadav |
APSEC | 1 |
| 2023 | Realistic Attacks with Realistic Attackers: An Information-Security Risk Analysis of an Automatic Metering InfrastructureabstractCyber-physical system such as automatic metering infrastructure (AMI) are overly complex infrastructures. With myriad stakeholders, real-time constraints, heterogeneous platforms and component dependencies, a plethora of attacks possibilities arise. Despite the best of available technology countermeasures and compliance standards, security practitioners struggle to protect their infrastructures. At the same time, it is important to note that not all attacks are same in terms of their likelihood of occurrence and impact. Hence, it is important to rank the various attacks and perform scenario analysis to have an objective decision on security countermeasures. In this paper, we make a comprehensive security risk analysis of AMI, both qualitatively and quantitatively. Qualitative analysis is performed by ranking the attacks in terms of sensitivity and criticality. Quantitative analysis is done by arranging the attacks as an attack tree and performing Bayesian analysis. Typically, state-of-the-art quantitative security risk analysis suffers from data scarcity. We acknowledge the aforementioned problem and circumvent it by using standard vulnerability database. Different from state-of-the-art surveys on the subject, which captures the big picture, our work is geared to is provide the prioritized baselines in addressing most common and damaging attacks. Rajesh Kumar 0012, Ishan Rai, Krish Vora, Mithil Shah |
IECON | 1 |
| 2022 | Co-engineering Safety-Security Using Statistical Model Checking
Rajesh Kumar 0012, Siddhant Singh, Bhavesh Narra, Rohan Kela |
FORTE | 1 |
| 2022 | What changed in the cyber-security after COVID-19?
Rajesh Kumar 0012, Chirag Vachhani, Nitish Yadav |
Comput. Secur. | 1 |
| 2018 | Effective Analysis of Attack Trees: A Model-Driven ApproachabstractAttack trees (ATs) are a popular formalism for security analysis, and numerous variations and tools have been developed around them. These were mostly developed independently, and offer little interoperability or ability to combine various AT features. We present ATTop, a software bridging tool that enables automated analysis of ATs using a model-driven engineering approach. ATTop fulfills two purposes: 1. It facilitates interoperation between several AT analysis methodologies and resulting tools (e.g., ATE, ATCalc, ADTool 2.0), 2. it can perform a comprehensive analysis of attack trees by translating them into timed automata and analyzing them using the popular model checker Uppaal , and translating the analysis results back to the original ATs. Technically, our approach uses various metamodels to provide a unified description of AT variants. Based on these metamodels, we perform model transformations that allow to apply various analysis methods to an AT and trace the results back to the AT domain. We illustrate our approach on the basis of a case study from the AT literature. Rajesh Kumar 0012, Stefano Schivo, Enno Ruijters, Bugra M. Yildiz, David Huistra, Jacco Brandt, Arend Rensink, Mariëlle Stoelinga |
FASE | 1 |
| 2017 | How to Efficiently Build a Front-End Tool for UPPAAL: A Model-Driven Approach
Stefano Schivo, Bugra M. Yildiz, Enno Ruijters, Christopher Gerking, Rajesh Kumar 0012, Stefan Dziwok, Arend Rensink, Mariëlle Stoelinga |
SETTA | 5 |