VLDB 2026 Research / reviewers in the wild / expert
Gaurav Varshney
dblp:73/4883
· DBLP profile ↗
15ranked-venue papers
6as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-author · 3 since 2021Computer networks · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Poster: Evading Visual Phish Detectors via Intelligent Visual TransformationsabstractVisual similarity based phishing detectors form a primary defense against credential harvesting attacks by comparing webpage appearance with legitimate references. These systems assume that brand specific visual cues such as layout structure, logo placement, and color themes are stable and difficult to replicate. We demonstrate that this assumption can be systematically violated. We present an automated, template level phishing website generation framework that produces visually realistic login pages for arbitrary brands using only the target URL. By preserving brand consistent visual cues while varying the layout and placement of credential collection elements through HTML and CSS manipulation, the framework generates phishing pages that evade visual similarity based detection. Using this approach, we curate a dataset of 1,230 phishing login pages across 123 brands and evaluate them against three state-of-the-art(SoTA) detectors: Phishlntention, PhishPedia, and an Earth Mover's Distance (EMD) based detector. The generated samples achieve up to 100% evasion against Phishlntention and the EMD based detector, and 95% evasion against PhishPedia. Rina Mishra, Gaurav Varshney, Chandan Singh, Palak Arora |
AsiaCCS | 2 |
| 2026 | BLAKE: BLE-based lightweight authentication and key-exchange via PUF
Chandranshu Gupta, Gaurav Varshney |
Ad Hoc Networks | 2 |
| 2025 | Poster: Lightweight PUF-based Authentication and Key-exchange for Offline Smart Home IoT DevicesabstractIoT-enabled smart home devices communicating through protocols like BLE or Zigbee, often constrained by limited computational resources and lack of direct internet connectivity, face significant authentication challenges. Traditional cryptographic methods such as Public-Key Infrastructure (PKI) or Identity-Based Encryption (IBE) impose heavy computational overheads, making them unsuitable for resource-constrained IoT environments. To address these issues, we propose a novel lightweight authentication protocol leveraging Physical Unclonable Functions (PUFs), utilizing smart-phones as intermediaries to facilitate secure communication with a trusted server. Our scheme avoids the overhead of maintaining large Challenge-Response Pair (CRP) databases and eliminates complex operations like Elliptic Curve cryptography and digital certificates (X.509). Experiments on an ESP32-based testbed demonstrate significant efficiency improvements over existing protocols, confirming the practicality of our lightweight approach for resource-constrained IoT environments. Chandranshu Gupta, Gaurav Varshney |
MobiCom | 2 |
| 2025 | Poster Abstract: SRAM PUF-Based Logic Locking for Secure Authentication and IP ProtectionabstractThis paper proposes a novel security framework that integrates Logic locking with intrinsic SRAM PUFs for simultaneous user authorization and hardware authentication. By leveraging stable SRAM cell responses, the approach eliminates external key storage, deriving unlocking keys through a structured transformation process. Experimental validation on ESP32 devices demonstrates high intra-device response consistency and distinct inter-device signatures. This unified mechanism ensures that only authorized users can access the system and only authenticated ICs can function, mitigating risks of overproduction and external attacks. The results establish SRAM PUFs as a lightweight, efficient, and tamper-resistant solution for secure key derivation. Chandranshu Gupta, Gaurav Kumar 0001, Satyadev Ahlawat, Gaurav Varshney |
SenSys | 5 |
| 2025 | A login page transparency and visual similarity-based zero-day phishing defense protocol
Gaurav Varshney, Akanksha Raj, Divya Sangwan, Alsharif Abuadbba, Rina Mishra, Yansong Gao 0001 |
Comput. Secur. | 1 |
| 2025 | Spoofed Email Based Cyberattack Detection Using Machine LearningabstractCyberattacks on e-mails are of different types, but the most pervasive and ubiquitous are spoofing attacks. Our approach uses memory forensics to extract e-mail headers from live memory to perform an e-mail header investigation to identify spoofing attacks. We have identified the research gaps and advanced our work to achieve better results. In this paper, we have made two significant improvements. First is URL validation module that uses a novel technique of checking each captured URL with an MX record and e-mail URL features. This scheme is fast, and reduces the total time from 35 sec to 27 sec. Second, spoofed e-mail detection is ameliorated by applying an ML model built using two novel e-mail header fields (BIMI and X-FraudScore) and four authentication header fields (SPF, DKIM, DMARC, and ARC). This enhances the spoofed e-mail detection accuracy from 96.15% to 97.57% with low false positives. Sanjeev Shukla, Manoj Misra, Gaurav Varshney |
J. Comput. Inf. Syst. | 3 |
| 2024 | Anti-phishing: A comprehensive perspective
Gaurav Varshney, Rahul Kumawat, Vijay Varadharajan, Udaya Kiran Tupakula, Chandranshu Gupta |
Expert Syst. Appl. | 1 |
| 2023 | An improved authentication scheme for BLE devices with no I/O capabilities
Chandranshu Gupta, Gaurav Varshney |
Comput. Commun. | 2 |
| 2022 | Forensic Analysis and Detection of Spoofing Based Email Attack Using Memory Forensics and Machine Learning
Sanjeev Shukla, Manoj Misra, Gaurav Varshney |
SecureComm | 3 |
| 2021 | Pseudo-Biometric Identity Framework: Achieving Self-Sovereignity for Biometrics on BlockchainabstractMost authentication schemes are centralized or managed by large federated giants. Often data stored in such third parties is highly susceptible to hacks, leaks, cross-matching, selling, and various privacy-invading attacks. Biometric credentials are extremely sensitive as unlike other credentials they cannot be renewed if compromised. This work proposes a blockchain based framework that allows secure, transparent, and privacy-preserving biometric authentication. Instead of storing biometric data in a centralized database they are decentralized and managed using DID and DID documents. It allows a user to posses self-sovereign and revocable pseudo-biometric identities that enables complete control over its biometric identity information, completely anonymous trans-actions, and the right to be forgotten. The pseudo-biometric acts extra protecting by imparting one-way transforms to original biometric and making is absolutely safe to onboard. The scheme is analyzed for performance under various operating scenarios. Prince Mishra, Vishwas Modanwal, Harkeerat Kaur, Gaurav Varshney |
SMC | 4 |
| 2020 | Secure and User Efficient EAP-based Authentication Protocol for IEEE 802.11 Wireless LANsabstractWireless Local Area Networks (WLANs) have experienced significant growth in the last two decades due to the extensive use of wireless devices. Security (especially authentication) is a staple concern as the wireless medium is accessible to everybody. Extensible Authentication Protocol (EAP) is the widely used authentication framework in WLANs to secure communication. The authentication mechanism designed on EAP is called EAP method. There are numerous EAP based and nonEAP based authentication protocols for WLANs, but there is no protocol that fulfills all the security requirements, as mentioned in RFC-4017 and other additional requirements like perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. Hence, it is fair to infer that there is an impelling need to design a protocol that can meet all the security requirements. In this paper, we propose a secure and user efficient EAP-based authentication protocol for IEEE 802.11 WLANs. The proposed protocol has been formally validated by BAN logic and the AVISPA tool [18]. The simulation results depict that the proposed protocol achieves all security requirements, as mentioned in RFC-4017 along with perfect forward secrecy, Denial-of-service (DoS) attack protection, and lightweight computation. The proposed protocol outperforms the existing protocols in terms of computation cost by reducing the computation cost by ≈ 99.9956%, 99.991%, 27.27%, 22.705% in comparison to EAP-TLS, EAP-TTLS, EAP-Ehash, EAP-SELUA, respectively. Keywords-AP, AS, AVISPA, BAN, EAP, WLANs. Awaneesh Kumar Yadav, Manoj Misra, Madhusanka Liyanage, Gaurav Varshney |
MASS | 4 |
| 2018 | A Metapolicy Framework for Enhancing Domain Expressiveness on the Internet
Gaurav Varshney, Pawel Szalachowski |
SecureComm (2) | 1 |
| 2018 | Secure authentication scheme to thwart RT MITM, CR MITM and malicious browser extension based phishing attacks
Gaurav Varshney, Manoj Misra, Pradeep K. Atrey |
J. Inf. Secur. Appl. | 1 |
| 2016 | A phish detector using lightweight search features
Gaurav Varshney, Manoj Misra, Pradeep K. Atrey |
Comput. Secur. | 1 |
| 2016 | A survey and classification of web phishing detection schemesabstractAbstract Phishing is a fraudulent technique that is used over the Internet to deceive users with the goal of extracting their personal information such as username, passwords, credit card, and bank account information. The key to phishing is deception. Phishing uses email spoofing as its initial medium for deceptive communication followed by spoofed websites to obtain the needed information from the victims. Phishing was discovered in 1996, and today, it is one of the most severe cybercrimes faced by the Internet users. Researchers are working on the prevention, detection, and education of phishing attacks, but to date, there is no complete and accurate solution for thwarting them. This paper studies, analyzes, and classifies the most significant and novel strategies proposed in the area of phished website detection, and outlines their advantages and drawbacks. Furthermore, a detailed analysis of the latest schemes proposed by researchers in various subcategories is provided. The paper identifies advantages, drawbacks, and research gaps in the area of phishing website detection that can be worked upon in future research and developments. The analysis given in this paper will help academia and industries to identify the best anti‐phishing technique. Copyright © 2016 John Wiley & Sons, Ltd. Gaurav Varshney, Manoj Misra, Pradeep K. Atrey |
Secur. Commun. Networks | 1 |