VLDB 2026 Research / reviewers in the wild / expert
Praveen Gauravaram
dblp:53/6480
· DBLP profile ↗
26ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0001-9135-2930ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 7 first-author · 12 since 2021Systems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Setup Once, Secure Always: A Single-Setup Secure Federated Learning Aggregation Protocol with Forward and Backward Secrecy for Dynamic UsersabstractFederated Learning (FL) enables multiple users to collaboratively train a machine learning model without sharing raw data, making it suitable for privacy-sensitive applications. However, local model or weight updates can still leak sensitive information. Secure aggregation protocols mitigate this risk by ensuring that only the aggregated updates are revealed. Among these, single-setup secure aggregation protocols, where key generation and exchange occur only once, are the most efficient due to reduced communication and computation overhead. However, existing single-setup secure aggregation protocols often lack support for dynamic user participation and do not provide strong privacy guarantees such as forward and backward secrecy. Nazatul Haque Sultan, Yan Bo, Yansong Gao 0001, Seyit Ahmet Çamtepe, Arash Mahboubi, Hang Thanh Bui, Muhammad Aufeef Chauhan, Hamed Aboutorab, Michael Bewong, Praveen Gauravaram, Dinesh Kumar Singh, Md. Rafiqul Islam 0001, Alsharif Abuadbba |
AsiaCCS | 10 |
| 2025 | Enhancing Physical Security in Smart Environments with Ambient IntelligenceabstractSmart environments are increasingly equipped with interconnected digital systems to manage access and physical security. However, traditional authentication methods, typically restricted to static checkpoints, fail to provide persistent assurance once entry is granted, leaving facilities vulnerable to credential misuse, tailgating, and unauthorised movement. This paper presents the Continuous Authentication Platform (CAP), a modular, multi-modal framework developed within the RAAISE project to enable continuous and context-aware verification across dynamic facility zones. CAP integrates heterogeneous off-the-shelf sensors, including NFC, RFID, biometric, motion, and WiFi positioning units, which collectively support persistent user tracking and real-time access enforcement. The platform’s architecture couples distributed sensing and edge processing with a centralised intelligence layer for event correlation and policy-driven decision-making. A live testbed deployment at Deakin University was used to evaluate CAP’s performance under realistic operational conditions. Results from functional trials demonstrate CAP’s ability to detect credential misuse, prevent tailgating, and maintain authentication continuity with sub-second responsiveness. These findings underscore CAP’s potential as a scalable, privacy-aligned foundation for next-generation smart facility security systems. Ashish Nanda, Robin Doss, Fokke Heikamp, Abhi Kumar, Haftu Tasew Reda, Adnan Anwar, Zubair A. Baig, Praveen Gauravaram, Debi Prasad Pati, Salil S. Kanhere, Mohan Baruwal Chhetri |
TrustCom | 8 |
| 2024 | Towards Availability of Strong Authentication in Remote and Disruption-Prone Operational Technology EnvironmentsabstractImplementing strong authentication methods in a network requires stable connectivity between the service providers deployed within the network (i.e., applications that users of the network need to access) and the Identity and Access Management (IAM) server located at the core segment of the network. This becomes challenging when it comes to Operational Technology (OT) systems deployed in a remote area, as they often get disconnected from the core segment of the network owing to unavoidable network disruptions. As a result, weak authentication methods and shared credential approaches are still adopted in these OT environments, exposing system vulnerabilities to increasingly sophisticated cyber threats. In this work, we propose a solution to enable highly available multi-factor authentication (MFA) services for OT environments. The proposed solution is based on Proof-of-Possession (PoP) tokens generated by an IAM server for registered users. The tokens are securely linked to user-specific parameters (e.g., physical security keys, biometrics, PIN, etc.), enabling strong user authentication (during disconnection time) through token validation. We deployed the Tamarin Prover software-based toolkit to verify security of the proposed authentication scheme. For performance evaluation, we implemented the designed solution in real-world settings. The results of our analysis and experiments confirm the efficacy of the proposed solution. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Divyans Mahansaria, Debi Prasad Pati, Praveen Gauravaram, Lei Pan 0002, Keshav Sood |
ARES | 6 |
| 2024 | POSTER: Addressing the Privacy by Use Challenges in Verifiable Credential based Digital WalletsabstractThe concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity. However, the inability of users to make optimal decisions in relation to the use of VC results in privacy risks. To address this gap in VC technology, we present game-theoretic models for optimising the privacy of users and simultaneously ensuring minimum disclosure of PII in line with privacy safeguards around CDR and GDPR expectations around anonymity and unlinkability and demonstrate these properties through a digital credential wallet (DCW). The developed technology will deliver a novel DCW which embeds decision-making ability to quantify, benchmark and recommend the optimal usage of credentials that are held within the DCW. Jongkil Jeong, Lu-Xing Yang, Robin Doss, Praveen Gauravaram, Zoe Wang, Mohamed Almorsy, Ashish Nanda, Keerthivasan Viswanathan |
AsiaCCS | 4 |
| 2024 | Privacy Preservation in Service Operations by Minimizing Sensitive Data ExposureabstractIn IT service operations such as service help desk, the primary task is to resolve customer queries satisfactorily within the stipulated service level agreements (SLA). These customer queries, referred to as tickets often contain sensitive and non-sensitive information. The disclosure of sensitive information even to an authorized agents is a privacy concern and could increase the risk of insider threat. In this work, we propose a framework to restrict the data exposure to authorized agents in such IT service operations. To facilitate privacy-enabled service operations, we assess the risk associated with the disclosure of attributes using its vulnerability and provide a masking strategy to reduce the data exposure. However, fully masking the key attributes within the ticket could hinder the resolution time and potentially lead to SLA violations. To overcome this, we propose an optimization model for partial masking which takes into consideration the attribute vulnerability and privacy requirement of an application, to minimize the overall data exposure. We provide an illustration on how this masking schemes can be implemented. Rishabh Kumar, Sutapa Mondal, Mangesh S. Gharote, Praveen Gauravaram, Sachin Lodha |
PST | 5 |
| 2024 | The Value of Strong Identity and Access Management for ICS/OT SecurityabstractAs the integration of digital technologies with Industrial Control Systems (ICS) and Operational Technology (OT) continues to deepen, these systems increasingly become targets for sophisticated cyber attacks. These attacks not only threaten the operational integrity but also pose significant risks to national security and public safety. In this paper, we provide insights into the value of ICS/OT security solutions that are based on Identity and Access Management (IAM). Beginning with presenting an abstraction model for typical ICS/OT attacks, the paper systematically outlines the main stages of an attack and the corresponding vectors employed by adversaries. Drawing from the MITRE ATT&CK framework tailored for ICS, the paper quantifies the extent to which IAM-based mitigation approaches can strengthen defense-in-depth mechanisms against cyber threats targeting ICS/OT environments. Our findings show that there are modern attack vectors that can only be mitigated through robust IAM solutions. Moreover, we found that while advanced techniques such as firewall and gateway-based intelligent threat detection play a significant role in safeguarding I CS/OT, they are insufficient on their own to address several attack vectors in ICS/OT environments. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Praveen Gauravaram, Debi Prasad Pati, Divyans Mahansaria, Keshav Sood, Lei Pan 0002 |
PST | 4 |
| 2024 | Contextual Transformer-based Node Embedding for Vulnerability Detection using Graph LearningabstractAutomated source code vulnerability detection using code graphs has seen major improvements in recent years, however one critical, but oft-overlooked, element of this problem is producing embeddings for graph nodes. Before graph-based classifiers can be used for vulnerability detection, the nodes in the graph must first be given vector representations. Graphlearning models propagate information from these embeddings through the graph before classification, and so the initial states of these embeddings are vital for all subsequent learning. While a variety of solutions to this problem have been proposed in existing literature, this is typically not the focus of these works. We propose a novel node embedding strategy for graph-based vulnerability discovery, which takes advantage of richly-learned information about the code contained in each node. We also implement and test several existing node embedding strategies, comparing them to each other and our new strategy under a standard graph-learning architecture. We find that our strategy outperforms existing methods by 10.47-50.70%. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 4 |
| 2024 | A Graph-Based Approach for Software Functionality Classification on the Web
Yinhao Jiang, Michael Bewong, Arash Mahboubi, Sajal Halder, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, Praveen Gauravaram, Minhui Xue 0001 |
WISE (5) | 8 |
| 2024 | Agriculture 4.0 and beyond: Evaluating cyber threat intelligence sources and techniques in smart farming ecosystemsabstractThe digitisation of agriculture, integral to Agriculture 4.0, has brought significant benefits while simultaneously escalating cybersecurity risks. With the rapid adoption of smart farming technologies and infrastructure, the agricultural sector has become an attractive target for cyberattacks. This paper presents a systematic literature review that assesses the applicability of existing cyber threat intelligence (CTI) techniques within smart farming infrastructures (SFIs). We develop a comprehensive taxonomy of CTI techniques and sources, specifically tailored to the SFI context, addressing the unique cyber threat challenges in this domain. A crucial finding of our review is the identified need for a virtual Chief Information Security Officer (vCISO) in smart agriculture. While the concept of a vCISO is not yet established in the agricultural sector, our study highlights its potential significance. The implementation of a vCISO could play a pivotal role in enhancing cybersecurity measures by offering strategic guidance, developing robust security protocols, and facilitating real-time threat analysis and response strategies. This approach is critical for safeguarding the food supply chain against the evolving landscape of cyber threats. Our research underscores the importance of integrating a vCISO framework into smart farming practices as a vital step towards strengthening cybersecurity. This is essential for protecting the agriculture sector in the era of digital transformation, ensuring the resilience and sustainability of the food supply chain against emerging cyber risks. Hang Thanh Bui, Hamed Aboutorab, Arash Mahboubi, Yansong Gao 0001, Nazatul Haque Sultan, Muhammad Aufeef Chauhan, Mohammad Zavid Parvez, Michael Bewong, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Seyit Ahmet Çamtepe, Praveen Gauravaram, Dinesh Kumar Singh, Muhammad Ali Babar 0001, Shihao Yan |
Comput. Secur. | 12 |
| 2024 | Privacy-Preserving Probabilistic Data Encoding for IoT Data AnalysisabstractThe widespread integration of the Internet of Things (IoT) is crucial in advancing sustainable development. IoT service providers actively collect user data for analysis using sophisticated Deep Learning (DL) algorithms. This enables the extraction of valuable insights for business intelligence and improving service quality. However, as these datasets contain sensitive personal information, there is a risk of privacy breaches when DL models are employed. This vulnerability may result in Membership Inference Attacks (MIA), potentially leading to the unauthorized disclosure of highly sensitive data. Therefore, developing an efficient and privacy-preserving data analysis system for IoT is imperative. Recent research has highlighted the effectiveness of utilizing Bloom Filter (BF)-encoding in conjunction with Differential Privacy (DP) for safeguarding privacy during data analysis. Given its attributes of low complexity and high utility, this approach proves effective, particularly in resource-constrained IoT domains. With this in mind, we propose a novel framework for privacy-preserving IoT data analysis based on BF-encoded data. Our research introduces an innovative BF-encoding technique combined with Local Differential Privacy (LDP), capable of efficiently encoding various types of IoT data (such as facial images and smart-meter data) while maintaining privacy when integrated into DL algorithms for downstream analysis. Experimental results demonstrate that our BF-encoded data surpasses the utility of standard BF-encoded data when utilized in DL algorithms for downstream tasks, showcasing an approximate 30% improvement in classification accuracy. Furthermore, we assess the privacy of these DL models against MIA, revealing that attackers can only make random guesses with an accuracy of approximately 50%. Zakia Zaman, Wanli Xue, Praveen Gauravaram, Wen Hu 0001, Jiaojiao Jiang 0001, Sanjay K. Jha |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Weak-Key Analysis for BIKE Post-Quantum Key Encapsulation MechanismabstractThe evolution of quantum computers poses a serious threat to contemporary public-key encryption (PKE) schemes. To address this impending issue, the National Institute of Standards and Technology (NIST) is currently undertaking the Post-Quantum Cryptography (PQC) standardization project intending to evaluate and subsequently standardize the suitable PQC scheme(s). One such attractive approach, called Bit Flipping Key Encapsulation (BIKE), has entered the final round of the competition. Despite having some attractive features, the IND-CCA security of BIKE depends on the average decoder failure rate (DFR), a higher value of which can facilitate a particular type of side-channel attack. Although BIKE adopts the Black-Grey-Flip (BGF) decoder that offers a negligible DFR, the effect of weak-keys on the average DFR has not been fully investigated. In this paper, we implement the BIKE scheme, and then through extensive experiments show that the weak-keys can be a potential threat to IND-CCA security of the BIKE scheme and thus need attention from the relevant research community. We also propose a key-check algorithm that can potentially supplement the BIKE mechanism and prevent users from adopting weak-keys. Mohammad Reza Nosouhi, Syed Wajid Ali Shah, Lei Pan 0002, Yevhen Zolotavkin, Ashish Nanda, Praveen Gauravaram, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | The SAir-IIoT Cyber Testbed as a Service: A Novel Cybertwins Architecture in IIoT-Based Smart AirportsabstractRapid technological advancements have resulted in increasingly more efficient and lightweight devices that, coupled with low-power and wide-range wireless connectivity, have given rise to Industrial Internet of Things (IIoT) systems. As a result, the concept of intelligent environments was developed, such as smart airports, where ubiquitous sensors seamlessly cooperate through several types of communication technologies, such as WiFi, BLE, ZigBEE and 5G, enable the collection of data and the dynamic adaption of the system to changing circumstances. However, along with certain benefits, such as augmented communication, enhanced business processes and improved efficiency, IIoT introduces new vulnerabilities, enabling cyber-attackers to compromise not only the digital infrastructure of IIoT architecture-enabled smart airports, but also affecting their physical assets. In this paper, we present a novel smart airport cybertwins security-oriented IIoT testbed, named SAir-IIoT, which comprises multiple heterogeneous IIoT devices and communication protocols, organised into distinct zones, automatically interconnected with each other, that can be remotely accessed as-a-service. To the best of our knowledge, this is the first cybertwins security-oriented testbed that enables researchers and practitioners to remotely practice attack and defence scenarios in smart airport IIoT environments. Additionally, we introduce a new data management technique for dynamically collecting, analysing and tagging heterogeneous data from diverse data sources including IIoT devices and network flows. Finally, we compare SAir-IIoT with other IIoT-based testbeds, revealing its complexity and effectiveness to evaluate new cyber security methods. Nickolaos Koroniotis, Nour Moustafa, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | SCEVD: Semantic-enhanced Code Embedding for Vulnerability DiscoveryabstractSource code vulnerability detection is a major goal in security research. In recent years, deep learning methods have been applied to this end, however the task of embedding code into vector representations as input for deep learning models has yet to be definitively solved. The use of graphs, specifically Abstract Syntax Trees and Code Property Graphs, is a promising research direction for this task, however learning from graphs grows prohibitively computationally expensive for large graphs. No close examination of intelligent ways to prune this input to only vulnerability-relevant information has yet been performed. Additionally, most existing works focus largely on structural information from graphs, often neglecting information contained within the nodes themselves. We address these gaps in the prior research by proposing SCEVD: a deep learning model for vulnerability discovery which utilises semantic information to intelligently select features in source code graphs for learning. It uses information contained within code graph nodes, as well as information about their relationships with one another to select the code graph features which are most relevant to code vulnerability. We implement SCEVD and conduct experiments using the SARD Juliet test suite, finding that we are able to improve vulnerability discovery results using this process of semantic-enhanced code graph feature selection. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 4 |
| 2021 | A Deep Learning-based Penetration Testing Framework for Vulnerability Identification in Internet of Things EnvironmentsabstractThe Internet of Things (IoT) paradigm has displayed tremendous growth in recent years, resulting in innovations like Industry 4.0 and smart environments that provide improvements to efficiency, management of assets and facilitate intelligent decision making. However, these benefits are offset by considerable cybersecurity concerns that arise due to inherent vulnerabilities, which hinder IoT-based systems' Confidentiality, Integrity, and Availability. Security vulnerabilities can be detected through the application of penetration testing, and specifically, a subset of the information-gathering stage, known as vulnerability identification. Yet, existing penetration testing solutions can not discover zero-day vulnerabilities from IoT environments, due to the diversity of generated data, hardware constraints, and environmental complexity. Thus, it is imperative to develop effective penetration testing solutions for the detection of vulnerabilities in smart IoT environments. In this paper, we propose a deep learning-based penetration testing framework, namely Long Short-Term Memory Recurrent Neural Network-Enabled Vulnerability Identification (LSTM-EVI). We utilize this framework through a novel cybersecurity-oriented testbed, which is a smart airport-based testbed comprised of both physical and virtual elements. The framework was evaluated using this testbed and on real-time data sources. Our results revealed that the proposed framework achieves about 99% detection accuracy for scanning attacks, outperforming other four peer techniques. Nickolaos Koroniotis, Nour Moustafa, Benjamin P. Turnbull, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
TrustCom | 5 |
| 2020 | SmartPatch: a patch prioritization framework for SCADA chain in smart gridabstractSupervisory Control and Data Acquisition (SCADA) systems are the industrial control systems and operational infrastructure that can monitor and control the electricity grid. Electricity grids are increasingly transforming from the one-directional way of generating, transmitting, and distributing electricity to smart grids that are multi-directional in the way they monitor, automate, and remotely operate the power sector. SCADA systems are increasingly under cyber attacks illustrating growing vulnerabilities to the smart grids. The U.S. power industry notes the importance of SCADA chain cyber risks and the need to take proactive measures (timely patching of vulnerabilities) to mitigate the risks. However, not all vulnerabilities are always exploited by attackers; and not all vulnerabilities can be patched in resource-constrained scenarios. Therefore, the patch sequence needs to be strategic and efficient. Geeta Yadav, Praveen Gauravaram, Arun Kumar Jindal |
MobiCom | 2 |
| 2019 | LSB: A Lightweight Scalable Blockchain for IoT security and anonymity
Ali Dorri, Salil S. Kanhere, Raja Jurdak, Praveen Gauravaram |
J. Parallel Distributed Comput. | 4 |
| 2017 | Performance Analysis of Sorting of FHE Data: Integer-Wise Comparison vs Bit-Wise ComparisonabstractIn this paper, we present the exact method for an integer-wise comparison technique in FHE domain using polynomial interpolaion and analyze the performance against bit-wise comparison techniques. We observe that even though the integer-wise comparison requires only one ciphertext unit for integer in contrast to l ciphertext units for an l-bit integer for bit-wise comparison, bit-wise comparison schemes have better performance due to less multiplicative depth of the comparison circuit. Our analysis shows that bit-wise comparison based on depth optimized circuits have O(log(l)) multiplicative depth, where as the integer-wise comparison has O(l) multiplicative depth and bit-wise comparison based on two's complement arithmetic techniques has O(l) multiplicative depth. We have evaluated the performance of odd-even merge sort and direct sort by considering all the three above stated comparison techniques on FHE data using HElib library and analyzed their complexities. Harika Narumanchi, Dishant Goyal, Nitesh Emmadi, Praveen Gauravaram |
AINA | 4 |
| 2016 | Building indifferentiable compression functions from the PGV compression functions
Praveen Gauravaram, Nasour Bagheri, Lars R. Knudsen |
Des. Codes Cryptogr. | 1 |
| 2012 | Security Analysis of Randomize-Hash-then-Sign Digital Signatures
Praveen Gauravaram, Lars R. Knudsen |
J. Cryptol. | 1 |
| 2011 | Improved Security Analysis of Fugue-256 (Poster)
Praveen Gauravaram, Lars R. Knudsen, Nasour Bagheri, Lei Wei 0001 |
ACISP | 1 |
| 2010 | On the Collision and Preimage Resistance of Certain Two-Call Hash Functions
Nasour Bagheri, Praveen Gauravaram, Majid Naderi, Søren S. Thomsen |
CANS | 2 |
| 2009 | On Randomizing Hash Functions to Strengthen the Security of Digital Signatures
Praveen Gauravaram, Lars R. Knudsen |
EUROCRYPT | 1 |
| 2009 | Cryptanalysis of the LAKE Hash Family
Alex Biryukov, Praveen Gauravaram, Jian Guo 0001, Dmitry Khovratovich, San Ling, Krystian Matusiewicz, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang |
FSE | 2 |
| 2008 | Linear-XOR and Additive Checksums Don't Protect Damgård-Merkle Hashes from Generic Attacks
Praveen Gauravaram, John Kelsey |
CT-RSA | 1 |
| 2008 | Side Channel Analysis of Some Hash Based MACs: A Response to SHA-3 Requirements
Praveen Gauravaram, Katsuyuki Okeya |
ICICS | 1 |
| 2006 | Constructing Secure Hash Functions by Enhancing Merkle-Damgård Construction
Praveen Gauravaram, William Millan, Ed Dawson, Kapali Viswanathan |
ACISP | 1 |