VLDB 2026 Research / reviewers in the wild / expert
Michael Clifford
dblp:51/793
· DBLP profile ↗
11ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-8316-4929ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Heat is On: Understanding and Mitigating Vulnerabilities of Thermal Image Perception in Autonomous Systems
S. Hrushikesh Bhupathiraju, Shaoyuan Xie, Michael Clifford, Qi Alfred Chen, Takeshi Sugawara 0001, Sara Rampazzi |
NDSS | 3 |
| 2026 | To Go or Not to Go: Shedding Light on Traffic Light Signal Manipulation and Defense StrategiesabstractConnected autonomous vehicles must accurately detect, and adhere, to traffic light signals to ensure safe and efficient traffic flow. Misinterpretation of traffic lights can result in potential safety issues for drivers and pedestrians. Recent work demonstrated attacks that projected structured light patterns onto vehicle cameras, causing traffic signs and traffic light color misinterpretation. In this work, we characterize a novel vulnerability of traffic light physical structures that can be exploited by attackers to deceive recognition systems. When visible and invisible laser light is projected onto traffic lights, it is scattered by its internal reflectors. To a vehicle’s camera, the reflected light appears the same as a genuine light source, resulting in dangerous red and green traffic light status misclassifications. We evaluate our attack against three state-of-the-art traffic light recognition models and show successful misclassification up to 25 m from the target traffic light. Furthermore, the attack succeeds both in daytime and nighttime conditions both in static and moving vehicle scenarios up to 10 km/h speed. To mitigate this threat, we propose a detection system based on light texture patterns that achieve 100% TPR and 1.8% FPR in our real-world scenarios. S. Hrushikesh Bhupathiraju, Takami Sato, Michael Clifford, Takeshi Sugawara 0001, Qi Alfred Chen, Sara Rampazzi |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2025 | FACE: Faithful Automatic Concept ExtractionabstractInterpreting deep neural networks through concept-based explanations offers a bridge between low-level features and high-level human-understandable semantics. However, existing automatic concept discovery methods often fail to align these extracted concepts with the model’s true decision-making process, thereby compromising explanation faithfulness. In this work, we propose FACE (Faithful Automatic Concept Extraction), a novel framework that combines Non-negative Matrix Factorization (NMF) with a Kullback-Leibler (KL) divergence regularization term to ensure alignment between the model’s original and concept-based predictions. Unlike prior methods that operate solely on encoder activations, FACE incorporates classifier supervision during concept learning, enforcing predictive consistency and enabling faithful explanations. We provide theoretical guarantees showing that minimizing the KL divergence bounds the deviation in predictive distributions, thereby promoting faithful local linearity in the learned concept space. Systematic evaluations on ImageNet, COCO, and CelebA datasets demonstrate that FACE outperforms existing methods across faithfulness and sparsity metrics. Dipkamal Bhusal, Michael Clifford, Sara Rampazzi, Nidhi Rastogi |
NeurIPS | 2 |
| 2024 | PASA: Attack Agnostic Unsupervised Adversarial Detection Using Prediction & Attribution Sensitivity AnalysisabstractDeep neural networks for classification are vulnerable to adversarial attacks, where small perturbations to input samples lead to incorrect predictions. This susceptibility, combined with the black-box nature of such networks, limits their adoption in critical applications like autonomous driving. Feature-attribution-based explanation methods provide relevance of input features for model predictions on input samples, thus explaining model decisions. However, we observe that both model predictions and feature attributions for input samples are sensitive to noise. We develop a practical method for this characteristic of model prediction and feature attribution to detect adversarial samples. Our method, PASA, requires the computation of two test statistics using model prediction and feature attribution and can reliably detect adversarial samples using thresholds learned from benign samples. We validate our lightweight approach by evaluating the performance of PASA on varying strengths of FGSM, PGD, BIM, and CW attacks on multiple image and non-image datasets. On average, we outperform state-of-the-art statistical unsupervised adversarial detectors on CIFAR-10 and ImageNet by 14% and 35% ROC-AUC scores, respectively. Moreover, our approach demonstrates competitive performance even when an adversary is aware of the defense mechanism. Dipkamal Bhusal, Md Tanvirul Alam, Monish Kumar Manikya Veerabhadran, Michael Clifford, Sara Rampazzi, Nidhi Rastogi |
EuroS&P | 4 |
| 2024 | Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign Perception
Takami Sato, S. Hrushikesh Bhupathiraju, Michael Clifford, Takeshi Sugawara 0001, Qi Alfred Chen, Sara Rampazzi |
NDSS | 3 |
| 2023 | SoK: Modeling Explainability in Security Analytics for Interpretability, Trustworthiness, and UsabilityabstractInterpretability, trustworthiness, and usability are key considerations in high-stake security applications, especially when utilizing deep learning models. While these models are known for their high accuracy, they behave as black boxes in which identifying important features and factors that led to a classification or a prediction is difficult. This can lead to uncertainty and distrust, especially when an incorrect prediction results in severe consequences. Thus, explanation methods aim to provide insights into the inner working of deep learning models. However, most explanation methods provide inconsistent explanations, have low fidelity, and are susceptible to adversarial manipulation, which can reduce model trustworthiness. This paper provides a comprehensive analysis of explainable methods and demonstrates their efficacy in three distinct security applications: anomaly detection using system logs, malware prediction, and detection of adversarial images. Our quantitative and qualitative analysis1 reveals serious limitations and concerns in state-of-the-art explanation methods in all three applications. We show that explanation methods for security applications necessitate distinct characteristics, such as stability, fidelity, robustness, and usability, among others, which we outline as the prerequisites for trustworthy explanation methods. Dipkamal Bhusal, Rosalyn Shin, Ajay Ashok Shewale, Monish Kumar Manikya Veerabhadran, Michael Clifford, Sara Rampazzi, Nidhi Rastogi |
ARES | 5 |
| 2022 | Autonomous Vehicle Security: Composing Attack, Defense, and Policy SurfacesabstractAn attack surface enumerates resources accessible to an attacker for cyber attacks on a system. These resources are: methods that can be called as part of an attack; channels that an attacker outside the system can use to get to a system’s interface; and untrusted data that an attacker can use in conjunction with the system’s programs and channels. Historically, a system’s attacks surface has provided a metric on the vulnerability of a system, in part to compare two systems’ exposure to attack. Michael Clifford, Miriam Heller, Karl N. Levitt, Matt Bishop |
NSPW | 1 |
| 2022 | Local perception and BSM based misbehavior detection in Intelligent Transportation SystemabstractAn intelligent transportation system aims to provide various traffic safety and navigation services, and mainly relies on local perception and vehicular communication technologies. However, the vehicular communication technologies can be a target of wide range of attacks including position falsification, Sybil and denial-of-service (DoS) attacks which can lead to disastrous traffic accidents and jams. As a viable solution, misbehavior detection systems can be used in vehicular networks. Different from other works, in this paper, we propose a misbehavior detection system that utilizes both local perception and basic safety messages (BSM). Our work shows the methodology for generating realistic vehicular network data sets that include both local perception and BSM. In addition, we compare and show that the propose scheme is better compared to the previous scheme utilizing only beacon information for accurately identifying misbehavior in intelligent transportation system. Sohan Gyawali, Takayuki Shimizu, Hongsheng Lu, Michael Clifford, John B. Kenney, Yi Qian 0001 |
VTC Fall | 4 |
| 2003 | Miracle Cures and Toner Cartridges: Finding Solutions to the Spam Problem
Michael Clifford, Daniel Faigin, Matt Bishop, Tasneem G. Brutch |
ACSAC | 1 |
| 2002 | Networking in The Solar Trust Model: Determining Optimal Trust Paths in a Decentralized Trust NetworkabstractThe Solar Trust Model provides a method by which the sender of a message can be authenticated, and the level of trust that can be placed in the sender of the message or the message itself can be computed The model works even if there is no prior relationship between the sender and receiver of the message. The Solar Trust Model overcomes a variety of limitations inherent in the design of other trust models and public key infrastructures. This paper presents a variety of enhancements and formalizations to the basic concepts of the model. In addition, this paper provides a set of algorithms that can be used to determine all of the possible trusted paths along which a message can be sent from a sender to recipient and the optimal choice of paths from a selection of paths. The paper also presents algorithms for reducing the network load produced by the model through piggybacking, path caching, and load distribution techniques. Michael Clifford |
ACSAC | 1 |
| 1998 | The Solar Trust Model: Authentication Without LimitationabstractThe PEM and PGP/X.509 authentication models and the Biba Integrity Model have limitations inherent in their design that diminish their practicality in real world applications. The ICE-TEL trust model addresses some of these difficulties, and introduces a few new limitations. The Common Security Services Manager's Trust Policy Interface Specification provides the guidelines with which new trust policies may be encoded, but does not implement an actual policy. This paper describes a new model that permits both the identity of the sender of a message, and the trustworthiness of the sender of the message to be determined. The model works regardless of whether or not the message was signed by a certificate authority with which the recipient has a relationship. The model can be implemented without changing the format of certificates that are currently in use, and could be used as a module in a broader security framework, such as the Common Security Services Manager. Michael Clifford, C. Lavine, Matt Bishop |
ACSAC | 1 |