Asmita 0001

dblp:364/7717-1 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0002-5626-1985ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Llm4mcu-Onto: Leveraging Llms for Automated Ontology Generation From Microcontroller Reference Manual
abstract
This research addresses the challenges faced by firmware developers, security researchers, and enthusiasts who work with low-level microcontroller (MCU) documentation, which often spans hundreds of complex pages. Current structured approaches, such as System View Description (SVD), are widely used but suffer from manual, labor-intensive creation processes and inconsistent vendor adherence to CMSIS-SVD standards. We propose an automated solution using Large Language Models (LLMs) integrated with Retrieval-Augmented Generation (RAG), capable of effectively parsing and extracting structured information, including text, tables, and images from MCU reference manuals/ datasheets. To mitigate hallucination issues inherent in LLMs, we fine-tuned models using a dataset derived from CMSIS-SVD files, which we will open-source for community benefit. We also experimented with few-shot models. Additionally, we developed a standardized structured ontology that is automatically populated with information extracted through LLM assistance from the reference manuals of the corresponding MCUs. Our approach was evaluated using OpenAI's GPT-4o under one-shot, few-shot, and fine-tuning scenarios, all incorporating RAG. We also experimented with the open-source LLM model CodeLlama. The results highlight substantial improvements in automatically extracting peripheral details and information from MCU reference manuals. Thus, it helps reduce manual effort and time. The key contribution of our work lies in the tailored adaptation of existing AI techniques to address the specific challenges of embedded systems documentation. We perform standardized ontology creation and multimodal parsing. We leverage RAG with MCU-specific finetuning and few-shot learning to generate structured information from hundreds of pages of MCU documentation. This opens the door to potential applications such as more accurate firmware code generation and reverse engineering for security analysis.
Asmita 0001, Grisha Bandodkar, Sujan Ghimire, Shaurya Srivastav, Soheil Salehi, Houman Homayoun
ICCD1
2024 Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita 0001, Yaroslav Oliinyk, Michael Scott, Ryan Tsang, Chongzhou Fang, Houman Homayoun
USENIX Security Symposium1
2024 Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu 0006, Ruoyu Zhang 0002, Ruijie Fang, Asmita 0001, Ryan Tsang, Najmeh Nazari, Han Wang 0020, Houman Homayoun
USENIX Security Symposium7
2024 FFXE: Dynamic Control Flow Graph Recovery for Embedded Firmware Binaries
Ryan Tsang, Asmita 0001, Doreen Joseph, Soheil Salehi, Prasant Mohapatra, Houman Homayoun
USENIX Security Symposium2
2023 Leveraging Firmware Reverse Engineering for Stealthy Sensor Attacks via Binary Modification
abstract
The number of Internet of Things (IoT) devices has increased dramatically to the point where they pervade our daily life. These connected devices are equipped with a variety of sensors for applications ranging from simple thermostats to critical medical devices. These devices often directly interact with people and usually lack proper security measures, thus they have become ideal targets for attackers. Herein, we propose Cunning Sensor Attack via Firmware Reverse-Engineering (unSAFE), which is a novel and stealthy sensor attack that attempts to corrupt sensor data by targeting the device’s Power Management IC (PMIC) configuration in firmware. The proposed unSAFE explores a class of vulnerabilities in which firmware is used to launch a physical attack against a device’s peripherals utilizing power management units as a vector. Our proposed technique consists of reverse-engineering the binary code running on bare-metal IoT devices and targeting the functions that control the PMIC configurations. We demonstrate our attack by modifying the firmware binary to alter the PMIC’s output voltage and evaluate it by measuring the changes in the output of the targeted sensors. We demonstrate that supplying a sensor with an incorrect voltage or current configuration can cause data corruption, which can go unnoticed and might have direct repercussions on real-world systems. Moreover, we discuss the stealthy nature of our attack and the fact that it can evade detection during functional testing as it does not change the overall functionality of IoT devices. Finally, we provide potential mitigation suggestions to address this vulnerability.
Sutej Kulkarni, Ryan Tsang, Asmita 0001, Houman Homayoun, Soheil Salehi
ICCD3
2022 FANDEMIC: Firmware Attack Construction and Deployment on Power Management Integrated Circuit and Impacts on IoT Applications
Ryan Tsang, Doreen Joseph, Asmita 0001, Soheil Salehi, Nadir Carreon, Prasant Mohapatra, Houman Homayoun
NDSS3