VLDB 2026 Research / reviewers in the wild / expert
Sachin Shetty
dblp:82/2803 · also Sachin S. Shetty
· DBLP profile ↗
133ranked-venue papers
5as first author
79since 2021 · last 2026
0000-0002-8789-0610ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 3 first-author · 27 since 2021Security and privacy · 17 · 5 since 2021Systems, architecture and hardware · 9 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 3 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-scale Graph Neural Network for Low-SNR Wireless Signal ClassificationabstractAccurate waveform identification, especially at low SNRs, remains an open challenge; both classical hypothesis-test detectors and modern deep neural networks degrade sharply as SNR falls. We address this with a graph-neural approach that converts each noisy in-phase/quadrature (IQ) segment into a multi-scale temporal graph: every sample becomes a node linked to neighbors at multiple lags (±1,±2,±4,±8) and to feature-space k-nearest neighbors. Each node carries a six-channel feature vector $\left[ {I,Q,|x|,\phi ,\delta \phi ,|x{|^2}} \right]$ designed to surface subtle patterns masked by noise. A hybrid CNN-GNN then performs classification: a 1D convolutional front-end learns local temporal embeddings, followed by a deep residual GNN with interleaved GCN and GATv2 layers to propagate information over the graph. We use Jumping Knowledge (JK) aggregation to preserve multi-hop and shallow cues, and an attention-based readout to emphasize the most informative nodes. On a synthetic four-class dataset (LTE, 5G NR, Radar, noise) at −10dB average SNR, the proposed model attains 91.3% test accuracy, exceeding strong baselines. This demonstrates substantial performance gains over conventional CNNs and deep learning classifiers in the low-SNR regime. Fahmida Afrin, Neda Moghim, Safdar Hussain Bouk, Sandip Roy 0001, Sachin Shetty |
CCNC | 5 |
| 2026 | QuantOnion: Quantum assisted Onion Routing for Trusted Data Sharing underlying 6G networks
Pronaya Bhattacharya, Nishat Mahdiya Khan, Sandip Roy 0001, Sachin Shetty, G. Thippa Reddy |
ICC | 4 |
| 2026 | FedSplitKAN: A Federated Split Temporal KAN Framework for Bandwidth-Latency Optimization over Edge-IoT Networks
Sai Sriram Gonthina, Sandip Roy 0001, Pronaya Bhattacharya, Sachin Shetty, G. Thippa Reddy |
ICC | 4 |
| 2026 | Q-SAFe: Quantum-Safe Agentic Federated Learning Scheme for Telemedicine Edge Networks
Nishat Mahdiya Khan, Pronaya Bhattacharya, Sandip Roy 0001, Sachin Shetty, G. Thippa Reddy, Stella Bvuma, Rutvij H. Jhaveri |
ICC | 4 |
| 2026 | An Agentic AI Control Plane for 6G Network Slice Orchestration, Monitoring, and Trading
Eranga Bandara, Ross Gore, Sachin Shetty, Ravi Mukkamala, Tharaka Mawanane Hewa, Abdul Rahman, Xueping Liang, Safdar Hussain Bouk, Peter Foytik, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 3 |
| 2026 | ASTRIDE: A Security Threat Modeling Platform for Agentic-AI ApplicationsabstractAI agent-based systems are becoming increasingly integral to modern software architectures, enabling autonomous decision-making, dynamic task execution, and multimodal interactions through large language models (LLMs). However, these systems introduce novel and evolving security challenges, including prompt injection attacks, context poisoning, model manipulation, and opaque agent-to-agent communication, that are not effectively captured by traditional threat modeling frameworks. In this paper, we introduce ASTRIDE, an automated threat modeling platform purpose-built for AI agent-based systems. ASTRIDE extends the classical STRIDE framework by introducing a new threat category, A for AI Agent-Specific Attacks, which encompasses emerging vulnerabilities such as prompt injection, unsafe tool invocation, and reasoning subversion, unique to agent-based applications. To automate threat modeling, ASTRIDE combines a consortium of fine-tuned vision-language models (VLMs) with the OpenAI-gpt-oss reasoning LLM to perform end-to-end analysis directly from visual agent architecture diagrams, such as data flow diagrams(DFDs). LLM agents orchestrate the end-to-end threat modeling automation process by coordinating interactions between the VLM consortium and the reasoning LLM. Our evaluations demonstrate that ASTRIDE provides accurate, scalable, and explainable threat modeling for next-generation intelligent systems. To the best of our knowledge, ASTRIDE is the first framework to both extend STRIDE with AI-specific threats and integrate fine-tuned VLMs with a reasoning LLM to fully automate diagram-driven threat modeling in AI agent-based applications. Eranga Bandara, Amin Hass, Sachin Shetty, Ravi Mukkamala, Ross Gore, Sachini Rajapakse, Xueping Liang, Safdar Hussain Bouk |
IWCMC | 3 |
| 2026 | Deep-RF - An Agentic AI Framework for RF Signal Classification and Real-Time 5G O-RAN Attack Detection
Eranga Bandara, Neda Moghim, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 4 |
| 2026 | MAC-Unlearn: A Differentially Private Federated Edge Unlearning Framework to secure MAC De-randomization
Samyak Jain, Pronaya Bhattacharya, Sudip Chatterjee 0001, Sandip Roy 0001, G. Thippa Reddy, Sachin Shetty |
IWCMC | 6 |
| 2026 | TimeWrap: A Time-Lock Protocol for Secure Agentic Coordination in 6G uRLLC Networks
Nishat Mahdiya Khan, Pronaya Bhattacharya, Sandip Roy 0001, G. Thippa Reddy, Sachin Shetty |
IWCMC | 5 |
| 2026 | QuantRIC: A Hybrid Quantum-Classical Framework for Predictive ISAC-RIS Orchestration in 6G O-RAN
Nishat Mahdiya Khan, Pronaya Bhattacharya, Rekha Vig, Sandip Roy 0001, G. Thippa Reddy, Sachin Shetty |
IWCMC | 6 |
| 2026 | Disentanglement under Stress: Limits of Entropy-based Aleatoric and Epistemic Uncertainty Estimation in Bayesian Deep Learning
Nishat Ara Nipa, Mohammed Hamza Chao, Sachin Shetty |
IWCMC | 3 |
| 2026 | Performance Evaluation of 5G Authentication Protocols: A Testbed-Based Comparison of 5G-AKA and EAP-AKA′
Valentina Walters N. Teboh, Peter Foytik, Safdar Hussain Bouk, Sachin Shetty |
IWCMC | 4 |
| 2026 | Adversarial Attack Resilient Computational Modeling for Person Re-Identification in Visual IoT ApplicationsabstractAs edge computing devices for Internet of Things (IoT) applications become more capable, the demand for data driven deep neural network (DNN) based algorithms grows. However, this leads to increased model vulnerability to adversarial attack. The Visual Internet of Things (VIoT), a subdomain of IoT, has great need for methods to improve robustness of algorithms to such attacks, along with person Re-Identification (Re-ID) through 3-dimensional (3-D) skeleton-based gait-analysis. For other domains, either adversarial training or synthetic data augmentation has shown to improve model performance in benign and adversarial attack cases. However, a combined approach that leverages both for robust classification in IoT has yet to be studied for 3-D skeleton based Re-ID. Additionally, assessment of 3-D skeleton-based Re-ID model vulnerability to adversarial attacks along with methods to improve robustness against such attacks are critical literature gaps. This work seeks to address these gaps by proposing an adversarial attack tolerant computational framework for 3-D skeleton-based Re-ID. Our approach, for the first time in the literature, leverages both synthetic data augmentation using a Generative Adversarial Network (GAN) and adversarial training through transfer learning of 3-D skeleton data on a Convolutional Neural Network (CNN) for person Re-ID. We evaluate the robustness of our method against seven popular adversarial attacks across four unique Re-ID 3-D skeleton datasets. We demonstrate how our method responds to varying amounts of real data and study the viability of our method for deployment on edge devices. Our findings show the proposed approach improves test accuracy in both the benign and adversarial case. Our method is deployable to small and inexpensive edge devices popular in IoT like the Raspberry Pi microcomputer. Joseph Zalameda, Megan A. Witherow, DeMarcus Edwards, Sachin Shetty, Danda B. Rawat, Khan M. Iftekharuddin |
IEEE Internet Things J. | 4 |
| 2025 | Llama-Recipe - Fine-Tuned Meta's Llama LLM, PBOM and NFT Enabled 5G Network-Slice Orchestration and End-to-End Supply-Chain Verification PlatformabstractModern 5G networks offer a network-sliced infrastructure where each network slice contains a dedicated 5G core software service layer. The 5G core software services in each slice shares common core network resources to meet specific customer needs. A primary challenge in 5G network slicing involves resource sharing and efficient network slice orchestration. Container-based methodologies, including tools like Docker and Kubernetes, have become popular for orchestrating 5G network slice services and managing configurations in microservices-based cloud-native service deployment. However, despite their utility, these tools present significant challenges. Their complexity often necessitates dedicated DevOps teams for effective management, while configuration management can prove arduous, and end-to-end supply chain oversight is lacking. To address these challenges, this paper introduces “Llama-Recipe,” a cloud-native 5G-core service deployment and orchestration platform integrating Generative AI, SBOM, PBOM and NFT. 5G-core service configurations across different network slices are represented as “HOCON (Human-Optimized Config Object Notation)” config objects adhering to the GitOps paradigm. Leveraging custom-trained Meta's Llama2 LLM, Llama-Recipe generates the Kubernetes manifests for network-sliced 5G-core services based on the defined HOCON configurations. The generated Kubernetes manifests of the 5G-core services are deployed in designated Kubernetes clusters utilizing GitOps tools (e.g., ArgoCD), ensuring seamless and automated deployment processes. Additionally, Llama-Recipe introduced a novel mechanism to handle end-to-end supply chain verification of 5G-core software services using Software-Bill of Materials (SBOM) and Pipeline-Bill of Materials (PBOM). SBOMs track all the dependencies and PBOMs facilitate the comprehensive tracking of end-to-end supply chain data for 5G-core software services, enhancing transparency and security. These PBOMs are also generated using the fine-tuned Meta's Llama-2 LLM and are encoded as NFT tokens with a novel NFT token schema. This schema enables easy verification and validation of supply-chain data during deployments, thus helping to prevent various supply-chain attacks. To fine-tune the Meta's Llama2 LLM, we've undertaken a meticulous training process, collaborating with Qlora to transform a 4-bit quantized pre-trained language model into Low-Rank Adapters(LoRA). The effectiveness of the Llama-Recipe is demonstrated through a real-world test-bed deployment in a sliced network scenario, utilizing multiple 5G cores (i.e., Open5GS) across Ericsson's new Radio Access Network (RAN). Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Sandip Roy 0001, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
CCNC | 3 |
| 2025 | SLM-FARL: Small Language Model Driven Federated Reinforcement Multi-Agentic Framework underlying 6G Edge NetworksabstractEmerging sixth-generation (6G) edge networks demand intelligent, scalable, and privacy-preserving learning systems that support real-time decision-making and natural language-driven control. In addition to training, these systems must also support federated unlearning (FU), the ability to selectively remove user data without full model retraining. However, existing federated learning (FL) and FU frameworks lack adaptability, require manual hyperparameter tuning, and are ill-suited for dynamic, resource-constrained environments. To address these challenges, we propose SLM-FARL, a hierarchical multi-agent deep reinforcement learning (MARL) framework that integrates small language models (SLMs) with FL and FU processes for autonomous, privacy-compliant learning aligned with user-level data removal demands. We implement a customized MAPPO algorithm to enable stable and adaptive policy updates across distributed SLM agents, orchestrated by a central LLM controller that supports human-in-the-loop interaction. To ensure real-time responsiveness and deployment efficiency, we incorporate SLM optimization techniques such as quantization and knowledge distillation, reducing model size and latency while maintaining performance. The proposed framework is evaluated on the UCI Adult dataset using 120 clients and demonstrates up to 15.78% higher FL-FU accuracy compared to baseline methods. The MAPPO Loss decreased by 90.12% indicates highly effective MARL convergence and Policy Entropy drop by 84.31% shows it confident policy decisions. The KD demonstrated an overall 17.56% improved performance over other model compression techniques. Thus, these metrics affirms the robustness and adapt-ability of our proposed SLM-FARL framework. Nishat Mahdiya Khan, Pronaya Bhattacharya, Sandip Roy 0001, Sachin Shetty, G. Thippa Reddy, Gautam Srivastava 0001 |
GLOBECOM | 4 |
| 2025 | A Unified Blockchain-based Framework for Decentralized Collaborative Transfer Learning using Adaptive IncentivizationabstractTransfer learning, a method that influences pretrained models to improve performance on new tasks, faces several data privacy, security, and scalability challenges when applied in decentralized environments. Recently, there have been few attempts to integrate blockchain technology with a transfer-learning approach. However, these classical blockchainbased non-collaborative transfer learning models face significant challenges, including poor scalability, security vulnerability, lack of data diversity, and inefficient incentive structures, thereby hindering the effectiveness and efficiency of the transfer learning process. This paper presents a unified framework that utilizes decentralized blockchain technology for collaborative transfer learning. The framework enables secure model sharing within a collaborative learning environment, supported by incentive mechanisms while maintaining model integrity and providing context protection. We perform extensive experimental studies with eight well-known large-scale and fine-grained image datasets. After initial transfer learning, incorporating collaborative learning via the decentralized blockchain network yielded promising results. The global model, after aggregating contributions from all entities, shows an impressive 6.8 % to 10.0 % accuracy improvement compared to individual baseline models. For blockchain implementation, we use the Rahasak blockchain as the ledger and its Aplos platform for a customized smart contract interface. Rahasak-CA, the certificate authority of the Rahasak blockchain, stores the digital certificates of peers in the transfer learning process. The system was deployed using Docker and Kubernetes, and evaluated on the proposed testbed. Amit Chakraborty, Sandip Roy 0001, Sayyed Farid Ahamed, Eranga Bandara, Bikash Chandra Singh, Sachin Shetty |
ICC | 6 |
| 2025 | A Quantum-Classical Approach Multimodal Cardiac Health PredictionabstractThis paper presents a new innovative system that helps doctors detect two serious health problems: fetal distress during pregnancy and irregular heartbeats (arrhythmia). Our system utilizes both classical and quantum machine learning to enhance our understanding of health data, such as heart rate signals. The model converts patient data into quantum signals, processes them using a specialized type of neural network that remains stable even with messy data, and makes predictions quickly and accurately. To protect patient privacy, the system utilizes federated learning, which enables hospitals to train the model without sharing patient data. We tested the system on two real medical datasets and achieved high accuracy is $89 \%$ for UCI FHR data set and $\mathbf{9 1. 6 7 \%}$ for UCI arrhythmia data set. It also made predictions in under 60 milliseconds, making it fast enough for realtime use in hospitals or wearable devices. This approach could lead to safer and more innovative tools for detecting early health problems. Mahmudul Hasan 0020, Mahbubul Arefin Noman, Sachin Shetty, Peter Foytik |
ISNCC | 3 |
| 2025 | Evaluating Query Efficiency and Accuracy of Transfer Learning-based Model Extraction Attack in Federated LearningabstractFederated Learning (FL) is a collaborative learning framework designed to protect client data, yet it remains highly vulnerable to Intellectual Property (IP) threats. Model extraction (ME) attack poses a significant risk to Machine-Learning-as-a-Service (MLaaS) platforms, enabling attackers to replicate confidential models by querying Black-Box (without internal insight) APIs. Despite FL’s privacy-preserving goals, its distributed nature makes it particularly susceptible to such attacks. This paper examines the vulnerability of the FL-based victim model to two types of model extraction attacks. For various federated clients built under NVFlare platform, we implemented ME attack across two deep-learning architectures and three image datasets. We evaluate the proposed ME attack performance using various metrics, including accuracy, fidelity, and KL divergence. The experiments show that for various FL clients, the accuracy and fidelity of the extraction model are closely related to the size of the attack query set. Additionally, we explore a transfer learning-based approach where pre-trained models serve as the starting point for the extraction process. The results indicate that the accuracy and fidelity of the fine-tuned pre-trained extraction models are notably higher, particularly with smaller query sets, highlighting potential advantages for attackers. Sayyed Farid Ahamed, Sandip Roy 0001, Soumya Banerjee 0001, Marc Vucovich, Kevin Choi, Abdul Rahman, Alison Hu, Edward Bowen, Sachin Shetty |
IWCMC | 9 |
| 2025 | RESTRAIN: Reinforcement Learning-Based Secure Framework for Trigger-Action IoT EnvironmentabstractInternet of Things (IoT) platforms with trigger-action capability allow event conditions to trigger actions in IoT devices autonomously by creating a chain of interactions. Adversaries exploit this chain of interactions to maliciously inject fake event conditions into IoT hubs, triggering unauthorized actions on target IoT devices to implement remote injection attacks. Existing defense mechanisms focus mainly on the verification of event transactions using physical event fingerprints to enforce security policies to block unsafe event transactions. These approaches are designed to provide offline defense against injection attacks. The state-of-the-art online defense mechanisms offer real-time defense, but extensive dependency on the inference of attack impacts on the IoT network limits the generalization capability of these approaches. In this paper, we propose a platform-independent multi-agent online defense system, namely RESTRAIN, to counter remote injection attacks at runtime. RESTRAIN allows the defense agent to profile attack actions at runtime and leverages reinforcement learning to optimize a defense policy that complies with the security requirements of the IoT network. The experimental results show that the defense agent effectively takes real-time defense actions against complex and dynamic remote injection attacks and maximizes the security gain with minimal computational overhead. Md. Morshed Alam, Lokesh Das, Sandip Roy 0001, Sachin Shetty, Weichao Wang |
IWCMC | 4 |
| 2025 | VindSec-Llama - Fine-Tuned Meta's Llama-3 LLM, Federated Learning, Blockchain and PBOM-enabled Data Security Architecture for Wind Energy Data PlatformsabstractCurrent wind energy data platforms face significant challenges in securing and managing extensive data from both offshore and onshore wind farms. These challenges include vulnerabilities to cyber-attacks, data tampering, breaches, complex data-sharing issues due to privacy concerns and regulatory compliance, and a lack of scalability and flexibility in analytical tools for real-time data processing. This paper proposes a novel multilayered data security architecture, termed "VindSec-Llama," to address these challenges. It integrates Generative AI, blockchain, federated learning, and Pipeline Bill of Materials (PBOM) to enhance data analytics, model development, and security across several layers, including Infrastructure, Data Lake, Federated Learning, MLOps, Data Provenance, and LLM. Each layer is designed to meet specific functional requirements, such as handling large datasets, facilitating secure federated learning, automating risk management, and ensuring data provenance and traceability. The platform, deployable in server environments (cloud or on-premises), complies with the Risk Management Framework (RMF) guidelines and security standards. It features a blockchain-enabled, coordinator-less federated learning system to enhance data privacy and security by enabling the development of privacy-preserving machine learning models with data from different wind farms. Automation plays a pivotal role throughout VindSec-Llama, with Meta’s custom-trained Llama-3 LLM used for generating remediation scripts in the Infrastructure Layer and for producing PPBOM in the MLOps Layer. The Llama-3 LLM has been quantized and fine-tuned using Qlora to ensure optimal performance on consumer-grade hardware. The MLOps pipeline setup, a critical functionality of VindSec-Llama, ensures seamless integration and deployment of machine learning models, embodying best practices in continuous integration and delivery. This setup is geared towards maximizing security, compliance, and operational efficiency. A prototype of the platform has been implemented within a wind-energy testbed with the collaboration of Department of Energy US, illustrating its practical applications and benefits. Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Sastry Kompella, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 3 |
| 2025 | Bassa-Llama - Fine-Tuned Meta's Llama LLM, Blockchain and NFT Enabled Real-Time Network Attack Detection Platform for Wind Energy Power PlantsabstractLarge Language Models (LLMs) are widely recognized for their applications in natural language processing tasks, but their potential extends far beyond traditional use cases. This paper introduces "Bassa-Llama," a novel platform that harnesses LLMs for predictive tasks in the realm of network security. Specifically, we propose a platform for real-time network attack detection in Wind Power Plants, leveraging a fine-tuned version of Meta’s Llama-3 LLM alongside blockchain and NFT-based data storage. Using a network PCAP dataset containing both malicious and benign packets, we fine-tune the Llama-3 LLM, with Quantized Low-Rank Adapter (QLoRA), to detect anomalies in network traffic. This approach ensures optimal performance on consumer-grade hardware while significantly enhancing the model’s ability to accurately analyze PCAP data and identify attack patterns. The end-to-end orchestration of the real-time network attack detection flow for Wind Power Plants is fully automated through blockchain smart contracts, and NFTs for storing identified attack data from the PCAP. To the best of our knowledge, this research represents the first effort to utilize a fine-tuned LLM for real-time network attack detection tasks. The results highlight the transformative potential of combining fine-tuned LLMs with blockchain and NFTs to build robust and secure network defense systems for Wind Power Plants. A prototype of the proposed platform was developed in collaboration with the U.S. Department of Energy, utilizing a simulated Wind Power Plant as a testbed. Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Sastry Kompella, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 3 |
| 2025 | P2Q-ASB: PUF-Secured Post Quantum Aggregate Signature Scheme using Public Blockchain for e-Healthcare SystemsabstractThe convergence of diverse wireless technologies inside a unified e-healthcare platform has opened up several vulnerabilities to cyber threats. To assure data integrity and reduce system overhead, aggregate signature methods provide a convenient way to combine multiple message signatures into a single compact signature. However, classical aggregate signature schemes are vulnerable to quantum threats and device impersonation attacks. To mitigate the research gap, in this paper, we leverage the benefits of Physical Unclonable Function (PUF) and public blockchain to propose a quantum-safe latticebased aggregate signature scheme (P2Q-ABS). The security of P2Q-ASB is based on the difficulty of the Ring Learning-withError (Ring-LWE) problem. The proposed P2Q-ASB scheme is a unified approach that protects IoMT devices with PUFs, provides quantum-resistant aggregate signatures, and stores electronic medical records in a blockchain-based distributed ledger. We provide a testbed implementation of lattice-based signatures for single and group messages. Moreover, we show the blockchain simulation results for various blocks mined and transactions per block. Security and performance analysis shows that P2Q-ASB offers enhanced security measures and facilitates more efficiency when compared to current state-of-the-art methodologies. Soumya Banerjee 0001, Sandip Roy 0001, Sachin Shetty |
IWCMC | 3 |
| 2025 | RADEP: A Resilient Adaptive Defense Framework Against Model Extraction AttacksabstractMachine Learning as a Service (MLaaS) enables users to leverage powerful machine learning models through cloud-based APIs, offering scalability and ease of deployment. However, these services are vulnerable to model extraction attacks, where adversaries repeatedly query the application programming interface (API) to reconstruct a functionally similar model, compromising intellectual property and security. Despite various defense strategies being proposed, many suffer from high computational costs, limited adaptability to evolving attack techniques, and a reduction in performance for legitimate users. In this paper, we introduce a Resilient Adaptive Defense Framework for Model Extraction Attack Protection (RADEP), a multifaceted defense framework designed to counteract model extraction attacks through a multi-layered security approach. RADEP employs progressive adversarial training to enhance model resilience against extraction attempts. Malicious query detection is achieved through a combination of uncertainty quantification and behavioral pattern analysis, effectively identifying adversarial queries. Furthermore, we develop an adaptive response mechanism that dynamically modifies query outputs based on their suspicion scores, reducing the utility of stolen models. Finally, ownership verification is enforced through embedded watermarking and backdoor triggers, enabling reliable identification of unauthorized model use. Experimental evaluations demonstrate that RADEP significantly reduces extraction success rates while maintaining high detection accuracy with minimal impact on legitimate queries. Extensive experiments show that RADEP effectively defends against model extraction attacks and remains resilient even against adaptive adversaries, making it a reliable security framework for MLaaS models. Amit Chakraborty, Sayyed Farid Ahamed, Sandip Roy 0001, Soumya Banerjee 0001, Kevin Choi, Abdul Rahman, Alison Hu, Edward Bowen, Sachin Shetty |
IWCMC | 9 |
| 2025 | Securing Next-Generation Wireless Networks Against Native GenAI Attacks: An Evidence-Theoretic ApproachabstractIntelligent poisoning attacks will pose fundamental challenges for sixth-generation (6G) wireless network security due to the massive deployment of native AI in radio units as well as in core networks. Network metrics and parameters, which are inherently uncertain, can become susceptible to intelligent poisoning through native generative AI (GenAI) mechanisms. In this paper, GenAI-driven intelligent attacks in wireless networks are investigated in order to understand their impact and severity by using uncertainty-informed root cause analysis. Then, a new approach for mitigating GenAI-driven attacks is proposed through the use of trustworthy service aggregation. First, a joint decision problem is formulated for generating intelligent adversarial attacks, understanding uncertain attack severity, and mitigating them in wireless networks. Second, a novel evidencetheoretic trustworthy AI (ET-TAI) framework is developed to address the formulated problem by understanding the root-cause of the native GenAI-driven intelligent attack and establishing defense in wireless networks. In particular, the proposed ET-TAI framework enables a narrow GenAI scheme that is designed to penetrate intelligent adversarial attacks in wireless networks’ metrics and parameters. Then a Dempster–Shafer-based mechanism that is deployed to capture the uncertain behavior of those intelligent attacks through prior evidence to quantify the trust for further mitigation. Extensive experimental analysis shows the proposed ET-TAI framework’s efficacy in understanding the trust in GenAI-driven intelligent poisoning attacks on network parameters and metrics by quantifying root causes and mitigating rates. Results show that the GenAI can penetrate intelligent poisoning attacks with high reconstruction capabilities of 95% for downlink services. Md. Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Marco A. Gamarra, Walid Saad 0001, Zhu Han 0001, Sachin Shetty |
IWCMC | 7 |
| 2025 | Uncertainty Aware Indoor Localization: Deep Learning Regression for Predicting Mobile Device LocationsabstractIndoor localization plays a critical role in a myriad of applications, including navigation, tracking, and smart building management. However, the dynamic characteristics of the indoor environment compounded with challenges stemming from factors such as signal attenuation and multipath propagation make it difficult to estimate the positioning coordinates much more challenging. This study uses three Received Signal Strength Indicator (RSSI) based indoor localization datasets to integrate uncertainty quantification methodologies into deep learning models. The objective is to design a robust, low-complexity approach for predicting location coordinates while emphasizing explainability and reliability through uncertainty evaluation. We assess the performance of three prominent uncertainty quantification techniques evaluating them using metrics such as Prediction Interval Coverage Probability (PICP), Mean Prediction Interval Width (MPIW), and Negative Log-Likelihood (NLL), with a focus on ensuring both robustness and transparency in uncertainty estimation. Our results indicate that the Deep Ensemble model with SimpleNet provides the most reliable performance, capturing uncertainty through model averaging and excelling in explainability and robustness. By integrating uncertainty quantification into deep learning algorithms, we aimed to enhance the robustness and dependability of indoor localization systems, facilitating more informed decision-making and improved performance in real-world scenarios. Nishat Ara Nipa, Sachin Shetty |
IWCMC | 2 |
| 2025 | Native AI-based Predictive Operational Resiliency in Cyber-Physical Energy SystemsabstractOperational resiliency becomes a key requirement to prevent critical recall of distributed energy resources (DER) in Cyber-Physical Energy Systems (CPES). Thus, CPES requires methods and metrics to observe and understand the potential faults of unwanted cyber-physical events. This paper introduces a new Native-AI-driven predictive maintenance framework to ensure the operational resiliency of CPES. First, a system model is designed to capture operational states such as normal, service mode, and faults by observing the operational behavior of DERs. Second, a predictive maintenance framework is proposed and developed by introducing a dual-method feature selection mechanism while the features of critical recall states are selected by tailored Gini and permutation-based importance metrics. Third, the predictive model is designed by leveraging tree-based models that utilize cyclical temporal encoding and lag features, while a Long Short-Term Memory (LSTM) family models employ sequence learning with normalized temporal and angular representations. Finally, the proposed framework can achieve up to 99.97% Critical Recall detection accuracy with an average of 82.5%. As a result, this work advances AI-driven predictive maintenance by reducing downtime by 15–30% in simulated scenarios. Sushmitha Halli Sudhakara, Md. Shirajum Munir, Mostafizur Rahman, Sachin Shetty |
IWCMC | 4 |
| 2025 | Secure Cloud-Storage-Based Big Data Analytics Scheme for Intelligent Vehicles EnvironmentabstractThe Internet of Vehicles (IoV) is a system designed to enhance transportation efficiency and safety by facilitating communication and data exchange among vehicles, infrastructure, and other devices. In IoV, vehicles, roadside units (RSUs), and cloud servers (CSs) are interconnected for seamless communication and data exchange. However, sharing data among various IoV entities poses significant security threats, including privacy breaches, data manipulation, and unauthorized access. These threats can compromise personal information, cause system malfunctions, and endanger the safety of vehicle occupants and other road users. To address these challenges, this article proposes a secure transfer mechanism for data sharing among IoV entities and a framework for secure big data analytics, where the data collected from vehicles undergoes secure analysis at the big data analytics center. Experimental evaluation, along with security and performance analysis, demonstrates that the proposed approach ensures secure data transfer between IoV entities and secure big data analytics in the CS. Prakash Tekchandani, Soumya Banerjee 0001, Ashok Kumar Das, Shantanu Pal, Sachin Shetty |
IEEE Internet Things J. | 6 |
| 2025 | Designing Secure Location-Based Authenticated Key Agreement Mechanism in Maritime Internet of Vessels for Big Data AnalyticsabstractMaritime communication, critical for global oceanic trade, faces challenges and opportunities with advancements in Information and Communication Technology (ICT). Traditional methods are susceptible to interception due to open channels, limited authentication, jamming, and other security risks. Securing vessel movements and locations in Internet of Vessels (IoV) is essential to prevent unauthorized data interception and tampering during transmission. We propose a ship authentication method using location-based secure keys to ensure the confidentiality of a vessel’s whereabouts. The proposed scheme’s robustness is validated through formal and informal security analyses, and formal verification using the Scyther automated verification tool, demonstrating its effectiveness against potential attacks in maritime networks. Comparative studies indicate that utilizing location-based keys maintains anonymity and untraceability without imposing significant computational or communication burdens. Experimental findings from comprehensive big data analytics and simulations using NS3 validate the scheme’s feasibility and performance. Anusha Vangala, Ashok Kumar Das, Neeraj Kumar 0001, Mohammed J. F. Alenazi, Sachin Shetty |
IEEE Internet Things J. | 6 |
| 2025 | Blockchain-Inspired Trust Management in Cognitive Radio Networks with Cooperative Spectrum Sensing
Mahsa Mahvash, Neda Moghim, Mahdieh Amiri, Sachin Shetty |
Pervasive Mob. Comput. | 5 |
| 2024 | SliceGPT - OpenAI GPT-3.5 LLM, Blockchain and Non-Fungible Token Enabled Intelligent 5G/6G Network Slice Broker and MarketplaceabstractThe main challenges in the 5G/6G network slicing are resource sharing, network slice orchestration, and network optimization in the 5G ecosystem. This paper proposes a novel architecture for a dynamic network slice broker and marketplace named “SliceGPT” that leverages Custom-Trained OpenAI GPT-3.5 LLM, blockchain and NFTs to enable collaboration between different stakeholders in the 5G ecosystem to address these challenges. The platform enables different stakeholders in 5G network slicing (e.g., cloud providers, network operators, RAN providers, and transport network providers) to share and rent their resources to create customized network slices that meet the specific requirements of 5G applications. The orchestration of network slices is managed through blockchain smart contracts, and the resulting network slices are encoded as NFT tokens and made available for purchase in a decentralized NFT marketplace. Customers can select and purchase the network slices that best meet their needs by paying either crypto or flat currency. Revenue generated through the sale of network slices is distributed among different providers, facilitating a fair and efficient marketplace. Intelligent network slice optimization is accomplished through the utilization of a custom-trained GPT-3.5 LLM(which powers the ChatGPT). This LLM can generate valuable insights and recommendations from extensive network datasets, contributing to the optimization of network slices for enhanced performance and efficiency. A prototype of SliceGPT has been implemented with FreedomFi 5G gateway, OpenAirInterface 5G core, OpenAI GPT-3.5-turbo model, LlamaIndex and Langchain. To the best of our knowledge, this is the very first research endeavor to incorporate the GPT LLMs for optimizing 5G/6G network slicing, Eranga Bandara, Peter Foytik, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
CCNC | 3 |
| 2024 | Predicting Downlink Retransmissions in 5G Networks Using Deep Learningabstract5G networks are expected to provide high-speed, low-latency, and reliable connectivity to support various applications such as autonomous vehicles, smart cities, and the Internet of Things (IoT). However, the performance of 5G networks can be affected by several factors such as interference, congestion, signal attenuation, or attacks, which can lead to packet loss and retransmissions. Retransmissions in the network may be seen as an essential measure to improve network reliability, but a high retransmission rate may indicate issues that can help network operators mitigate possible service disruptions or threats to network users. A deep learning-based approach has been proposed to predict downlink retransmissions in 5G networks, achieving as much as 5%- 15% improvement over traditional prediction algorithms. Safdar Hussain Bouk, Omoniwa Babatunji, Sachin Shetty |
CCNC | 3 |
| 2024 | Self-Sovereign Identity Management in Ship-Based 5G-Devices Use CaseabstractThis paper takes a view on the identity management system in 5G using self-sovereign identity (SSI) solutions. It focuses on the use case of quasi-static and mobile devices that require a good connection on an isolated ship. The identities need to be self-managed when the ship is disconnected at sea, and the newly created identities need to be resolved when the ship regains connection. An overview of the decentralized / distributed identity management in 5G along with the call flows is presented in this paper. Furthermore, we highlight its impact on the large-scale device identity management process and its interoperability with minimum alterations in the current 5G identity management system. This work explores the security benefits of the decentralized property of SSI and measures the performance difference in merging identities with disconnected parts of the system. The results focus on three main measures of 5G identity management systems that include control overhead, verification delay, and identity reconciliation. The paper presents the costs/benefits to the SSI solution compared to centralized identity management systems. Peter Foytik, Safdar Hussain Bouk, Gustave Anderson, Sachin Shetty |
CCNC | 4 |
| 2024 | A Decentralized Smart Grid Communication Framework Using SDN-Enabled BlockchainabstractThe smart grid revolution has brought numerous benefits to the energy sector, such as improved efficiency, increased renewable energy integration, and enhanced grid management. The reliance on digital communication within smart grid systems has introduced new security challenges that must be addressed to ensure reliable and secure operation. The existing communication infrastructure often lacks the necessary security measures to protect against cyber threats, which leads to potential vulnerabilities and privacy breaches. This paper presents a novel approach to enhancing smart grid communication by integrating Software-Defined Networking (SDN) and Blockchain technology. Therefore, the proposed work aims to address the specific communication needs of smart grids, which require secure and real-time data exchange between various grid components, including power generation units, substations, distribution networks, and end consumers. The proposed framework provides data integrity, communication and network security, and controller privacy. Uttam Ghosh, Laurent Njilla, Sachin Shetty, Charles A. Kamhoua |
CCNC | 3 |
| 2024 | Performance Analysis of Indoor 5G NR SystemsabstractThe advent of 5G technology holds transformative potential, reshaping industries with its improved connectivity and communication. In this research paper, we conduct a thorough analysis of the performance and capabilities of an indoor 5G network within a controlled lab environment. Utilizing an Amarisoft Callbox as the 5G core, in conjunction with a Remote Radio Head (RRH) and user equipment (UEs), we evaluate network performance across downlink, and uplink transmissions, considering TCP and UDP protocols between the gNodeB and UE. Our examination encompasses essential metrics such as latency, data rate, and CPU usage, providing valuable insights into the system's suitability for diverse applications. Bikash Chandra Singh, Sachin Shetty, Praneet Chivate, Alex Alenberg, Peter Woodward |
CCNC | 2 |
| 2024 | Advancing Healthcare: Innovative ML Approaches for Improved Medical Imaging in Data-Constrained EnvironmentsabstractHealthcare industries face challenges when experiencing rare diseases due to limited samples. Artificial Intelligence (AI) communities overcome this situation to create synthetic data which is an ethical and privacy issue in the medical domain. This research introduces the CAT-U-Net framework as a new approach to overcome these limitations, which enhances feature extraction from medical images without the need for large datasets. The proposed framework adds an extra concatenation layer with downsampling parts, thereby improving its ability to learn from limited data while maintaining patient privacy. To validate, the proposed framework’s robustness, different medical conditioning datasets were utilized including COVID-19, brain tumors, and wrist fractures. The framework achieved nearly 98% reconstruction accuracy, with a Dice coefficient close to 0.946. The proposed CAT-U-Net has the potential to make a big difference in medical image diagnostics in settings with limited data. Al Amin, Kamrul Hasan 0008, Saleh Zein-Sabatto, Sachin Shetty, Imtiaz Ahmed 0001, Tariqul Islam 0001 |
GLOBECOM | 5 |
| 2024 | Secure Location-based Authenticated Key Establishment Scheme for Maritime CommunicationabstractMaritime communication helps vessels and ports plan their movements, exchange environmental information, and communicate among themselves. The vessels' movement and changing location are critical to keep them secure from data interception and data tampering by unauthorized parties during transmission. To secure maritime communication, we propose a novel lightweight authentication scheme sensitive to the current ship location. We assess the effectiveness of the proposed protocol in defending against a range of security threats while keeping communication and computation costs low, and meeting the desired security and functional requirements of anonymity and untraceability. The detailed security analysis using the widely accepted Scyther tool demonstrates that location-based keys as proposed in our protocol are secure against location inference and spoofing attacks among others. Anusha Vangala, Ashok Kumar Das, Neeraj Kumar 0001, Sachin Shetty, Sajal K. Das 0001 |
ICC | 5 |
| 2024 | A Zero Trust Framework for Realization and Defense Against Generative AI Attacks in Power GridabstractUnderstanding the potential of generative AI (GenAI)-based attacks on the power grid is a fundamental challenge that must be addressed in order to protect the power grid by realizing and validating risk in new attack vectors. In this paper, a novel zero trust framework for a power grid supply chain (PGSC) is proposed. This framework facilitates early detection of potential GenAI-driven attack vectors (e.g., replay and protocol-type attacks), assessment of tail risk-based stability measures, and mitigation of such threats. First, a new zero trust system model of PGSC is designed and formulated as a zero-trust problem that seeks to guarantee for a stable PGSC by realizing and defending against GenAI-driven cyber attacks. Second, in which a domain-specific generative adversarial networks (GAN)-based attack generation mechanism is developed to create a new vulnerability cyberspace for further understanding that threat. Third, tail-based risk realization metrics are developed and implemented for quantifying the extreme risk of a potential attack while leveraging a trust measurement approach for continuous validation. Fourth, an ensemble learning-based bootstrap aggregation scheme is devised to detect the attacks that are generating synthetic identities with convincing user and distributed energy resources device profiles. Experimental results show the efficacy of the proposed zero trust framework that achieves an accuracy of 95.7% on attack vector generation, a risk measure of 9.61% for a 95% stable PGSC, and a 99% confidence in defense against GenAI-driven attack. Md. Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Walid Saad 0001, Zhu Han 0001, Sachin Shetty |
ICC | 6 |
| 2024 | WedaGPT - Generative-AI (with Custom-Trained Meta's Llama2 LLM), Blockchain, Self Sovereign Identity, NFT and Model Card Enabled Indigenous Medicine PlatformabstractTraditional and indigenous medicine, deeply rooted in ancient traditions and wisdom, plays a crucial role in global healthcare and cultural identity. These practices provide treatments for illnesses such as cancer and bone injuries, which often lack effective remedies in Western medicine. However, these valuable systems face challenges like potential knowledge loss, undervaluation of practitioners’ expertise, and the risk of fraud due to the absence of credential verification mechanisms. In this research, we introduce "WedaGPT," a Generative AI-enabled platform that utilizes a custom-trained Meta’s Llama2 Large Language Model (LLM), Blockchain, self-sovereign identity (SSI), Non-Fungible Tokens (NFTs), and model cards to share traditional medical knowledge and address these issues. WedaGPT creates a collaborative ecosystem connecting doctors, medicine providers, therapists, patients, and technology experts, all committed to preserving and advancing traditional healing practices. This platform enables secure and transparent contributions from all stakeholders to patient well-being. Ancient medical recipe books are translated into English and digitized into PDF formats to enrich the platform’s knowledge base. These texts are used to fine-tune the Llama2 LLM, which has been quantized and optimized with Qlora for performance on consumer-grade hardware. Through a chat-based interface in the SSI-enabled mobile wallet, users can interact with the LLM and access detailed information on treatments, recipes, prescriptions, and healing methods. Additionally, users can consult remotely with doctors who prescribe treatments through this wallet. A key feature of WedaGPT is transforming ancient medicinal recipes into NFT tokens for sale on NFT marketplaces, giving traditional knowledge digital authenticity and economic value. Revenue from these sales is distributed among platform contributors, promoting equitable ownership and recognition. Medical recipe data, including treatment histories and physician details, are encapsulated in Model Cards and securely stored on the blockchain. This system offers mechanisms to verify doctors and treatments in a privacy-preserving way, potentially reducing fraud and medication errors. Eranga Bandara, Peter Foytik, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
ISCC | 3 |
| 2024 | Enhancing Sentiment Analysis with Attention Mechanism and Bayesian-Lipschitz Recurrent Neural NetworksabstractIn medical chatbots and other healthcare domains, government agencies and other essential industries use sentiment analysis for public safety, improving the service quality of products, and other necessary purposes. Sometimes, the data is noisy, ambiguous, and contains mixed sentiments, where different parts of the text may convey different emotions, creating a problem in adequately detecting the sentiment. We proposed a novel recurrent neural network called the Bayesian-Lipschitz RNN with an attention mechanism to address these challenges. The Bayesian approach manages noisy and ambiguous data by representing uncertainty and avoiding overfitting. At the same time, the attention mechanism focuses on the most relevant parts of the text, effectively capturing context and mixed sentiments. Then, the Lipschitz Recurrent Neural Networks (LRNN), based on hidden-to-hidden matrices, are employed and constructed using a symmetric-skew decomposition scheme. The hidden-to-hidden matrices are used to update the hidden state and this hidden state is used to predict the sentiment, mitigate the vanishing gradient and stability issues, and got accuracy with 92.45 %. Mahmudul Hasan 0020, Sachin Shetty, Peter Foytik |
ISNCC | 2 |
| 2024 | EM-PAD: An Effective Mechanism for Phishing Attack DetectionabstractIn the present era, the increasing number of network devices and ubiquitous computing leads to the flow of enormous amounts of data traffic, including sensitive and confidential information, on the internet and carrying out commercial and banking transactions online. This gives cybercriminals an opportunity to launch an attack like phishing to steal confidential information from the user and gain unauthorized access. This can be mitigated by the help of an intelligent machine learning-based phishing detection system, which can detect potential phishing attacks and take appropriate action. In this paper, we have addressed this major cyber issue and proposed a machine learning-based phishing detection scheme (in short, EM-PAD), which is trained on a benchmark dataset and evaluated on standard metrics: F1-score and Accuracy. The proposed model is compared with different existing schemes based on Accuracy, indicating that it has outperformed them with remarkable results. Aakash, Saksham Mittal, Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Mohsen Guizani |
IWCMC | 6 |
| 2024 | AKM-FCCI: Secure Authentication and Key Management Mechanism for Fog Computing-Based IoT-Driven Critical InfrastructureabstractCritical infrastructure refers to the key systems, assets, and facilities, whether they are physical or virtual, that are necessary for the overall functioning of a country. As our reliance on technology and networked systems continues to expand, so does the significance of taking precautions to protect critical infrastructure from being compromised by cyberattacks. We need some security schemes to secure the communication happening in the critical infrastructure devices. Therefore, in this paper, we focus on the design of an authentication and key establishment scheme, which is used in the critical infrastructure to secure its data transmissions. A secure authentication and key management mechanism for fog computing-based IoT-driven critical infrastructures (in short, AKM-FCCI) is proposed in the paper. We then provide the network model and threat model of the proposed AKM-FCCI to explain its deployment and organization of devices and servers. The threat model further explains the various threats of this communication environment. In addition, the security analysis of AKM-FCCI is presented to demonstrate that it is secure against the many different kinds of attacks that could be launched against it. The comparisons demonstrate that the performance of AKM-FCCI is superior to that of the other currently used schemes. In addition to that, it offers a high level of security and utility. Therefore, the proposed AKM-FCCI is appropriate for use in protecting critical infrastructure equipment against a wide variety of threats. Vijay Karnatak, Neha Tripathi, Mohammad Wazid, Ashok Kumar Das, Mohsen Guizani, Sachin Shetty |
IWCMC | 7 |
| 2024 | Detecting Attacks and Optimizing Routes in Radio-frequency Networks Using Machine Learning and Graph TheoryabstractIn the context of the widespread use of Radio Frequency (RF) communication networks as in electronic warfare, ensuring security and optimization has become increasingly important. This study investigates methods for detecting attacks and determining optimal routes within RF networks. In this paper, we investigate a novel framework that can proactively detect attacks in RF-based Electronic Warfare (EW), find the signal blockage to install anti-jammer and recommend an optimal path for mission success. First, we propose a logistic regression-based machine learning (ML) mechanism to train a model to differentiate between attack signals vs normal communications. Second, we devise a state–action–reward–state–action (SARSA)-based reinforcement learning (RL) scheme to find an end-to-end path for reaching to RF-enabled mission target. Third, we have A* to restore connectivity by deploying anti-jammers in optimal places. Finally, we have used a real-world Electronic Warfare (EW) dataset to evaluate the proposed framework. Our experiment shows that the proposed logistic regression produces reasonably accurate attack detection, with 98% correct classification. Further, we have achieved higher accuracy in path planning with our RL agent, where normalized Euclidean distance error between 0.1 to 0.3 as compared to the optimal distance. These results showcase the feasibility of integrating machine learning and graph theory to enhance the security and optimization of RF networks. Manjushree Muralidhara, Md. Shirajum Munir, Sravanthi Proddatoori, Sachin Shetty, Kimberly Gold |
NetSoft | 4 |
| 2024 | User preference-aware content caching strategy for video delivery in cache-enabled IoT networks
Mostafa Taghizade Firouzjaee, Kamal Jamshidi, Neda Moghim, Sachin Shetty |
Comput. Networks | 4 |
| 2024 | TriAssetRank: Ranking Vulnerabilities, Exploits, and Privileges for Countermeasures PrioritizationabstractNetwork defence practices have no standardized mechanism for determining the priority of threat events. Prioritization of cyber vulnerabilities intends to make network administrators focus on the most critical points within the system to mitigate potential damages produced by attackers. More likely, in managing vulnerabilities, current approaches always focus on the common vulnerability exposures (CVE), which are not the only existing vulnerabilities in a network. Also, while the Common Vulnerability Scoring System (CVSS) effectively scores individual vulnerabilities, it fails to consider the relationships between them but considers each vulnerability in isolation. Existing research, such as the ‘AssetRank’ algorithm, has made progress in exploring these relationships. Building on this foundation, in this paper we propose TriAssetRank, a tripartite ranking algorithm that evaluates three key elements within a logical attack graph: vulnerabilities, privileges, and potential attack exploits. Since each node type has its unique characteristics and potential impact on the system’s security, we rank them in concert, taking into account the dependencies between nodes in the attack graph. The proposed ranking scheme computes a numerical value for each node based on its type, which is a clear indication of how valuable it is to a potential attacker. Several tests on various model networks have empirically validated the effectiveness of the algorithm, which enables organizations to prioritize countermeasures by identifying the most critical vulnerabilities, exploits, and privilege escalation risks, allowing efficient allocation of resources to mitigate high-impact threats and reduce overall risk exposure effectively. Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Wilson Ejuh Geh, Frederica Free-Nelson, Sachin Shetty, Charles A. Kamhoua |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Multi-Timescale Actor-Critic Learning for Computing Resource Management With Semi-Markov Renewal Process MobilityabstractThis paper studies artificial intelligence (AI) aided communication and computing resource allocation in a vehicular network that supports blockchain-enabled video streaming. Our study aims to improve the operating efficiency and to maximize the transcoding rewards for blockchain based vehicular networks. Our resource allocation policy considers the vehicular mobility, which is modelled with a highly-realistic Semi-Markov renewal process, as well as the real-time video service delay constraints. We propose a multi-timescale actor-critic-reinforcement learning framework to tackle these grand challenges. We also develop a prediction model for the vehicular mobility by using analysis and classical machine learning, which alleviates the heavy signaling and computation overheads due to the vehicular movement. A mobility-aware reward estimation for the large timescale model is then proposed to mitigate the complexity due to the large action space. Finally, numerical results are presented to illustrate the developed theoretical findings in this paper and the significant performance gains due to our proposed multi-timescale framework. Le Thanh Tan, Martin Reisslein, Sachin Shetty |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | An Authentication and Key Management Framework for Secure and Intelligent Transportation of Internet of Space ThingsabstractInternet of Space Things (IoST), also known as CubeSats, elaborates the uses and functionalities of traditional Internet of Things (IoT) by not only providing a constantly available satellite back-haul network, but also by providing real-time satellite-captured data. IoST can be applied for various applications, like weather forecasting, navigation, satellite phone, satellite TV, satellite Internet, radio, military, and many more. It requires support of mechanisms of Intelligent Transportation System (ITS). In an IoST communication environment, the communication among various users, satellite access points, ground stations, and smart IoT devices occur through insecure channels, i.e., Internet. Due the transmission of data over an insecure channel, various potential attacks are possible. Due to the existence of various attacks, the important data of IoST may be altered or revealed. To mitigate these issues, an authentication and key management framework for secure and intelligent transportation of IoST has been proposed (in short, SAKM-IoST). Through the proposed SAKM-IoST, a legitimate user can access the data of ground station in a secure way. The security analysis reveals that SAKM-IoST is resilient against a variety of potential threats and attacks. Additionally, SAKM-IoST’s performance is compared with other approaches that are similar in nature. It has been noted that SAKM-IoST offers robust security, in addition to extra functional characteristics. Therefore, SAKM-IoST seems to be more suitable for its deployment in the critical applications of the IoST as compared to other competing approaches. Mohammad Wazid, Ashok Kumar Das, Sachin Shetty |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | A centralized delay-sensitive hierarchical computation offloading in fog radio access networks
Samira Taheri, Neda Moghim, Naser Movahhedinia, Sachin Shetty |
J. Supercomput. | 4 |
| 2023 | Multiclass Classification Approaches for Intrusion Detection in IoT-Driven Aerial Computing EnvironmentabstractAerial Computing is one of the applications of Internet of Things (IoT) which makes use of autonomous aerial devices, such as drones and unmanned aerial vehicles (UAVs). The ubiquitous nature of IoT and aerial computing is poised to revolutionize our daily lives by enabling seamless real-time information sharing among interconnected objects. However, ensuring the safety and security of such network is crucial in preventing potential threats and attacks. The purpose of this study is to develop a sophisticated intrusion detection system that is effective, efficient, and intelligent using complex machine learning models trained on relevant intrusion detection datasets. In this article, the multiclass classification approaches for intrusion detection in IoT-driven aerial computing environment are presented (in short, MCA-IDAC). In the comparative study, it has been observed that proposed MCA-IDAC performs significantly better than the other existing competing schemes, in terms of important performance parameters. Saksham Mittal, Mohammad Wazid, Devesh Pratap Singh, Ashok Kumar Das, Sachin Shetty |
GLOBECOM | 6 |
| 2023 | Cyber Resilience Measurement Through Logical Attack Graph AnalysisabstractTo improve resilience, it is crucial to quantify or measure it. Measurement techniques usually base their measure on critical functionality, which is unfortunately not mission-centric. Also, methods of measurement over time can not tackle the fact that a system may have different consecutive missions at different intervals of time. We propose a method to measure the cyber-resilience of any complex network by analyzing how the business process varies against adversity effort. Both efforts of the attacker and the impact on the business process are obtained by leveraging the vulnerabilities CVSS score of attack paths extracted from a generated attack graph. We finally obtain a numerical value for cyber resilience by calculating the area under the curve of business process against attacker effort. Experimentation shows that the proposed framework suits the absorption, recovery, and adaptation abilities of cyber resilience. This also helps designers to analyze which type of vulnerabilities leads to the worst resilience case, thereby making critical decisions to improve cyber resilience. Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Frederica Free-Nelson, Sachin Shetty, Wilson Ejuh Geh, Charles A. Kamhoua |
ICC | 4 |
| 2023 | Blockchain, NFT, Federated Learning and Model Cards enabled UAV Surveillance System for 5G/6G Network Sliced EnvironmentabstractIn recent years, the use of UAVs has expanded to various applications such as surveillance, disaster response, agriculture, and delivery. However, traditional UAV monitoring systems rely on direct communication between the UAV and the ground pilot, which has several limitations such as limited range, poor reliability, and susceptibility to interference. To overcome these limitations, there has been significant interest in integrating UAVs into cellular networks such as 5G/6G network slicing. The flexibility of network slicing allows UAVs to operate on different slices based on their communication needs, which can improve their performance and efficiency. However, integrating UAVs into network slicing also poses several challenges, such as managing communication and permissions of UAVs and base stations, access control of UAVs, and identity management of UAVs. To address these challenges, we propose a blockchain, Non-Fungible Token(NFT), Federated Learning(FL), and Zero-Trust(ZT) security-enabled UAV monitoring platform for 5G/6G network sliced environments. We propose a novel approach in which UAVs are represented as NFT tokens within the platform. This innovative representation allows for enhanced security and trust in the system, aligning with the principles of the Zero-Trust security model, which assumes no implicit trust in any network component or user. Furthermore, we propose a FL system that operates on top of the blockchain, which can analyze data from multiple UAVs across different network slices. Our proposed FL system uses coordinator-less models, which eliminates the attacks of a centralized coordinator. As a use case, we consider a scenario where our proposed system detects anomaly communications of UAVs and identifies attack surfaces via analyzing network traffic data of UAVs using FL. The 5G system testbed implemented with FreedomFi 5G gateway and Indoor Radio Cell. Eranga Bandara, Sachin Shetty, Peter Foytik, Abdul Rahman, Ravi Mukkamala, Xueping Liang, Nadini Sahabandu |
ISNCC | 2 |
| 2023 | Sentiment Analysis With Lipschitz Recurrent Neural NetworksabstractAt present, sentiment analysis is used in almost every sector. In medical chatbots and other healthcare domains, government agencies and other essential industries use sentiment analysis for public safety, improving the service quality of products, and other necessary purposes. A large amount of data is required to analyze and briefly overview any product, movie, or comment. This is a challenging task to determine the sentiment from plain text. However, researchers use Natural Language Processing (NLP) to do this task accurately. Our model is based on the Lipschitz Recurrent Neural Networks (LRNN), which analyzed the IMBD dataset. The ultimate goal was to reduce the vanishing gradient problem and find the best accuracy number and a good number of evaluation metrics. The LRNN is based on hidden-to-hidden matrices, which update the hidden state, and this hidden state is used to predict the sentiment with reasonable accuracy. Finally, we got 86.75 % accuracy. Mahmudul Hasan 0020, Sachin Shetty |
ISNCC | 2 |
| 2023 | U-Net Based Disaster Damage Detection Through Semantic SegmentationabstractSatellite image analysis of natural disasters is critical for effective emergency response, relief planning, and disaster prevention. They can provide a comprehensive view of the affected area allowing for quick and accurate assessments of the extent of damage by providing critical information on the disaster's development. Semantic segmentation is believed to be one of the best techniques to capture pixel-wise information in computer vision. In this work, we will be using U-Net-based architectures to address the building localization and damage detection of the complex Xview2 dataset. We propose a generic algorithm that is not constrained by the nature of the disaster and can be deployed to various classes of disaster types with slight modifications. Nishat Ara Nipa, Yan Lu 0007, Sachin Shetty |
ISNCC | 3 |
| 2023 | Transmission Power Control for Interference Reduction in Cellular D2D NetworksabstractInterference is one of the most critical issues in the cellular Device-to-Device (D2D) networks. The sharing of radio resources in cellular and D2D communications offers spectrum efficiency advantages for the cellular network. However, resource sharing also introduces interference, leading to a reduction in the quality of service experienced by users. In this paper, we propose an adversarial Multi-Armed Bandit learning-based transmission Power Control method called MAB-PC for both cellular and D2D transmitters. The objective of this method is to ensure the minimum service quality for users, considering the minimum spectral efficiency and maximum block error rate. Additionally, to address the conflicting objectives of D2D and cellular communications, MAB-PC is modeled as a Pareto optimization problem for D2D transmitters. MAB-PC is a distributed method that minimizes signaling overhead and relies solely on local Channel State Information (CSI). The effectiveness of the proposed method is evaluated based on reliability, total data rate, spectral efficiency, block error rate, and outage probability, demonstrating superior performance compared to its counterpart. Mehrdad Sadehvand, Neda Moghim, Behrouz Shahgholi Ghahfarokhi, Sachin Shetty |
ISNCC | 4 |
| 2023 | Vehicular Safety Revolution: A Cutting-Edge Communication Paradigm for Accident PreventionabstractAn estimated 1.3 million individuals every year pass away in crashes involving cars. A comprehensive vehicular communication system is necessary given the worrisome increase in daily accidents brought on by the spike in the number of vehicles using our roadways. The creation of a fresh communication paradigm with an accident prevention focus was motivated by this need. The research presented here offers an extensive system that uses cutting-edge technology to coordinate dynamic interactions between nearby vehicles. A sophisticated inter-vehicle communication network aided by radio frequency (RF) technology forms the basis of this breakthrough. By enabling vehicles to exchange vital warnings and data, this network fosters a cooperative environment for accident prevention. Each vehicle also has a Visible-Light Communications (VLC) module, which was carefully engineered to identify accidents and transmit realtime accident information to all connected vehicles. Sidheswar Routray, Amrit Suman, Preetam Suman, Sasmita Padhy, Pushpita Chatterjee, Sachin Shetty |
MobiHoc | 6 |
| 2023 | Quantum-Enabled Blockchain for Data Processing and Management in Smart Cities
Uttam Ghosh, Debashis Das, Pushpita Chatterjee, Sachin Shetty |
WoWMoM | 4 |
| 2023 | Decentralizing Cyber Physical Systems for Resilience: An Innovative Case Study from A Cybersecurity Perspective
Xueping Liang, Charalambos Konstantinou, Sachin Shetty, Eranga Bandara, Ruimin Sun |
Comput. Secur. | 3 |
| 2023 | Securing Age-of-Information (AoI)-Enabled 5G Smart Warehouse Using Access Control SchemeabstractLow-power wireless sensor networks (WSNs) and Internet of Things (IoT) have great impact for the real-time applications in future 5th generation (5G) mobile networks due to the wireless-powered communication technologies. The Age of Information (AoI) plays a crucial performance metric in an IoT-enabled real-time smart warehouse application, where the freshness of the aggregated data is very important. However, wireless medium communication among the beacon nodes and the user equipments (tracking nodes) gives an opportunity to an adversary not only to eavesdrop the data but also to corrupt the data by means of deleting, modifying or inserting malicious information during communication among the entities involved in the smart warehouse environment. To mitigate these issues, we design a security scheme for AoI-enabled 5G smart warehouse through an access control mechanism, where the secure communication among the beacon nodes and the tracking nodes will take place by mutual device authentication and key agreement process. The fresh data collected at the enterprise cloud is then used for big data analytics for better predictions and analysis, such as optimal device scheduling so that the data becomes very fresh. The rigorous security analysis and comparative study show that the proposed mechanism has significantly better security and comparable communication and computational costs as compared to the relevant schemes. In addition, through the real-time testbed experiments, we show that the proposed scheme is practical in 5G smart warehouse context. Ashok Kumar Das, Sandip Roy 0001, Eranga Bandara, Sachin Shetty |
IEEE Internet Things J. | 4 |
| 2023 | Neuro-Symbolic Explainable Artificial Intelligence Twin for Zero-Touch IoE in Wireless NetworkabstractExplainable artificial intelligence (XAI) twin systems will be a fundamental enabler of zero-touch network and service management (ZSM) for sixth-generation (6G) wireless networks. Thus, a reliable XAI twin system becomes essential to discretizing the physical behavior of the Internet of Everything (IoE) and identifying the reasons behind that behavior for enabling ZSM. To address the challenges of extensible, modular, and stateless management functions in ZSM, a novel neuro-symbolic XAI twin framework is proposed that to enable trustworthy ZSM for a wireless IoE. The proposed neuro-symbolic XAI twin framework consists of two learning systems: 1) implicit learner that acts as an unconscious learner in physical space and 2) explicit leaner that can exploit symbolic reasoning based on implicit learner decisions and prior evidence. The physical space of the XAI twin executes a neural-network-driven multivariate regression to capture the time-dependent wireless IoE environment while determining unconscious decisions of IoE service aggregation, such as uplink, downlink, and service provisioning. Subsequently, the virtual space of the XAI twin constructs a directed acyclic graph (DAG)-based Bayesian network that can infer a symbolic reasoning score over unconscious decisions through a first-order probabilistic language model. Furthermore, a Bayesian multiarm bandit-based learning problem is proposed for reducing the gap between the expected explained score and the current obtained score of the proposed neuro-symbolic XAI twin. Experimental results show that the proposed neuro-symbolic XAI twin can achieve around 96.26% accuracy while guaranteeing from 18% to 44% more trust score in terms of reasoning and closed-loop automation. Md. Shirajum Munir, Kitae Kim 0001, Apurba Adhikary, Walid Saad 0001, Sachin Shetty, Seong-Bae Park, Choong Seon Hong |
IEEE Internet Things J. | 5 |
| 2023 | AISCM-FH: AI-Enabled Secure Communication Mechanism in Fog Computing-Based HealthcareabstractFog computing-based Internet of Things (IoT) architecture is useful for various types of delay efficient network communications and services, like digital healthcare. However, there are privacy and security issues with the fog computing-based healthcare systems, which can further increase the risk of leakage of sensitive healthcare data. Therefore, a security mechanism, such as access control for fog computing-based healthcare systems, is needed to protect its data against various potential attacks. Moreover, the blockchain technology can be used to solve the digital healthcare’s data integrity related problems. The use of Artificial Intelligence (AI) further makes the system more effective in case of prediction of health related diseases. In this paper, an AI-enabled secure communication mechanism in fog computing-based healthcare system (in short, AISCM-FH) has been proposed. The security analysis of the proposed AISCM-FH is provided using the standard random oracle model and also with the heuristic (non-mathematical) security analysis. A pragmatic study determines the impact of the proposed AISCM-FH on key performance indicators. Moreover, we include a detailed performance comparison of AISCM-FH with other relevant existing schemes to show that it has low communication and computation costs, and provides superior security and extra functionality attributes as compared to those for other competing existing approaches. Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Mohsen Guizani |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Deception for Characterizing Adversarial Strategies in Complex Networked SystemsabstractThere is a need for systematic characterization of complex networked systems involving friendly forces and opponent forces to understand the adversary opportunities and capabilities to cause harm and develop counter-strategies that would minimize the adversarial impact. Specifically, we need the ability to quantify the incurred cost (cost of protecting friendly forces) and induced cost (opponent cost to cause damage to friendly systems). In this paper, we address the problem of characterizing adversarial strategies and develop a suite of metrics that quantify the opportunity and capability of the adversary. We also propose a deception strategy that would force the opponent to redirect away from mission-critical systems by optimally placing decoy nodes and thereby expending opponent resources with little gain. Our adversary strategy characterization involves an integrated graph theoretic and Bayesian network that tracks lateral propagation of adversaries in a complex networked sys-tem. Our deception strategy is devised by a Partially Observable Monte Carlo Planning (POMCP) Framework that provides a sequence of actions that force an attacker to be redirected to a decoy network with high probability. Md Ali Reza Al Amin, Peter Foytik, Sachin Shetty, Jessica Dorismond, Marco A. Gamarra |
CCNC | 3 |
| 2022 | Bassa-ML - A Blockchain and Model Card Integrated Federated Learning Provenance PlatformabstractFederated learning is a collaborative/distributed machine learning system which is designed to address the privacy issues in centralized machine learning systems. The transparency and provenance of a machine learning model are important aspects of federated learning systems since they impact peoples’ lives in various domains (e.g., from healthcare to personal finance to employment). However, most of the existing federated learning systems deal with centralized coordinators which are vulnerable to attacks and privacy breaches. Also, they do not provide any standard transparency and provenance mechanisms for the resulting models. In this paper, we propose a blockchain and Model Card-based integrated federated learning system "Bassa-ML" providing enhanced transparency and trust for the models. Model parameter sharing, local model generation, model averaging, and model sharing functions are implemented using smart contracts. The generated models, model training information, and model reports are stored in the blockchain ledger as Model Card Objects. This results in enhanced transparency and auditability to the federated learning process. Eranga Bandara, Sachin Shetty, Abdul Rahman, Ravi Mukkamala, Juan Zhao 0003, Xueping Liang |
CCNC | 2 |
| 2022 | Anonymous Jamming Detection in 5G with Bayesian Network Model Based Inference AnalysisabstractJamming and intrusion detection are some of the most important research domains in 5G that aim to maintain use-case reliability, prevent degradation of user experience, and avoid severe infrastructure failure or denial of service in mission-critical applications. This paper introduces an anonymous jamming detection model for 5G and beyond based on critical signal parameters collected from the radio access and core network’s protocol stacks on a 5G testbed. The introduced system leverages both supervised and unsupervised learning to detect jamming with high-accuracy in real time, and allows for robust detection of unknown jamming types. Based on the given types of jamming, supervised instantaneous detection models reach an Area Under the Curve (AUC) within a range of 0.964 to 1 as compared to temporal-based long short-term memory (LSTM) models that reach AUC within a range of 0.923 to 1. The need for data annotation effort and the required knowledge of a vocabulary of known jamming limits the usage of the introduced supervised learning-based approach. To mitigate this issue, an unsupervised auto-encoder-based anomaly detection is also presented. The introduced unsupervised approach has an AUC of 0.987 with training samples collected without any jamming or interference and shows resistance to adversarial training samples within certain percentage. To retain transparency and allow domain knowledge injection, a Bayesian network model based causation analysis is further introduced. Ying Wang 0113, Shashank Jere, Soumya Banerjee 0001, Lingjia Liu 0001, Sachin Shetty, Shehadi Dayekh |
HPSR | 5 |
| 2022 | Predictive Cyber Defense Remediation against Advanced Persistent Threat in Cyber-Physical SystemsabstractAdvanced Persistent Threat (APT) has dramatically changed the landscape of cybersecurity. APT is carried out by stealthy, continuous, sophisticated, and well-funded attack processes for long-term malicious gain thwarting most current defense mechanisms. There is a need for a defense strategy that continuously combats APT over a long time-span in imper-fect/incomplete information on attacker's actions. We propose the stochastic evolutionary game model to simulate the dynamic adversary to address this need in this work. We add the player's rationality parameter c to the Logit Quantal Response Dynamics (LQ RD) model to quantify the cognitive differences of real-world players. We propose an optimal decision-making plan by calculating the stable evolutionary equilibrium that balances a trade-off between defense cost and benefit. Cases studies conducted on Energy Delivery Systems (EDS) indicate that the proposed method can help the defender predict possible attack action, select the related optimal cyber defense remediation over time, and gain the maximum defense payoff. Kamrul Hasan 0008, Sachin Shetty, Tariqul Islam 0001, Imtiaz Ahmed 0001 |
ICCCN | 2 |
| 2022 | Generalized Adversarial and Hierarchical Co-occurrence Network based Synthetic Skeleton Generation and Human Identity RecognitionabstractHuman skeleton data provides a compact, low noise representation of relative joint locations that may be used in human identity and activity recognition. Hierarchical Co-occurrence Network (HCN) has been used for human activity recognition because of its ability to consider correlation between joints in convolutional operations in the network. HCN shows good identification accuracy but requires a large number of samples to train. Acquisition of this large-scale data can be time consuming and expensive, motivating synthetic skeleton data generation for data augmentation in HCN. We propose a novel method that integrates an Auxiliary Classifier Generative Adversarial Network (AC-GAN) and HCN hybrid framework for Assessment and Augmented Identity Recognition for Skeletons (AAIRS). The proposed AAIRS method performs generation and evaluation of synthetic 3-dimensional motion capture skeleton videos followed by human identity recognition. Synthetic skeleton data produced by the generator component of the AC-GAN is evaluated using an Inception Score-inspired realism metric computed from the HCN classifier outputs. We study the effect of increasing the percentage of synthetic samples in the training set on HCN performance. Before synthetic data augmentation, we achieve 74.49% HCN performance in 10-fold cross validation for 9-class human identification. With a synthetic-real mixture of 50%-50%, we achieve 78.22% mean accuracy, significantly$(\mathrm{p} < 0.05)$outperforming the baseline HCN performance. The proposed framework demonstrates the feasibility of combining a synthetic data generation architecture with hierarchical co-occurrence feature learning for human identity recognition. Joseph Zalameda, Brady Kruse, Alexander M. Glandon, Megan A. Witherow, Sachin Shetty, Khan M. Iftekharuddin |
IJCNN | 5 |
| 2022 | Skunk - A Blockchain and Zero Trust Security Enabled Federated Learning Platform for 5G/6G Network SlicingabstractThe network slicing in 5G/6G mobile networks enables billions of connected devices to transmit data at higher rates than ever before. The high number of devices and the huge data rates result in configuration complexities and complex security management. Machine learning techniques could play a key role in managing these system complexities. While feder-ated learning (FL) has recently been proposed as an emerging paradigm to build privacy-preserving machine learning models, many of the existing systems involve centralized coordinators which are known to be vulnerable to attacks and privacy breaches. In addition, current FL models have weak support for transparency and provenance mechanisms. In this paper, we propose a Blockchain-based, Zero-trust Security-enabled Federated Learning system “Skunk” to address privacy and data provenance requirements. The proposed federated learning system also supports the requirements of 5G/6G networks. The sharding-based architecture in the blockchain enables the deployment of Skunk in 5G/6G network slice environments. As a use case of Skunk, we have considered a scenario with IoT device attacks in a 5G/6G network. The proposed FL models detect such attacks in the 5G/6G network sliced environment. Eranga Bandara, Xueping Liang, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Wee Keong Ng |
SECON | 3 |
| 2022 | Assessing the Quality of Differentially Private Synthetic Data for Intrusion Detection
Md Ali Reza Al Amin, Sachin Shetty, Valerio Formicola, Martin Otto 0002 |
SecureComm | 2 |
| 2022 | Moose: A Scalable Blockchain Architecture for 5G Enabled IoT with Sharding and Network Slicingabstract5G network slicing enables IoT networks to connect billions of heterogeneous objects providing high quality of service, high network capacity, and enhanced system throughput. Despite all these advantages, there are some major challenges to be addressed including decentralization, transparency, data interoperability, network privacy and security, and network slice orchestration, data provenance, and management. Blockchain technologies have the potential to offer innovative solutions to overcome these challenges. However, in the context of 5G enabled scalable IoT applications, integrating 5G with blockchain platforms could pose challenges to 5G’s goals such as high transaction throughput, high scalability, and real-time transaction processing, sharding-based consensus, network slice management and provenance. In this paper, "Moose," a blockchain platform, to overcome these challenges is proposed. It supports sharding based consensus in the blockchain network. It integrates a network slice orchestration library with smart contracts to manage and schedule network slices. As a use-case, Moose is integrated with a 5G-supported IoT device identity monitoring system on a network sliced environment. The performance results from the implemented system indicate that the proposed system indeed overcomes the aforementioned challenges. Eranga Bandara, Sachin Shetty, Abdul Rahman, Ravi Mukkamala, Xueping Liang |
WCNC | 2 |
| 2022 | Artificial intelligence-aided privacy preserving trustworthy computation and communication in 5G-based IoT networks
Le Thanh Tan, Sachin Shetty |
Ad Hoc Networks | 2 |
| 2022 | Guest Editorial Special Issue on Secure Data Analytics for Emerging Internet of ThingsabstractThe rapid developments in hardware, software, and communication technologies have facilitated the spread of interconnected sensors, actuators, and heterogeneous devices such as single board computers, which collect and exchange a large amount of data to offer a new class of advanced services characterized by being available anywhere, at any time, and for anyone. This ecosystem is widely referred to as the Internet of Things (IoT). In the past years, the number of deployments both for sensor networks and the IoT grew significantly. This continuous and exponential growth is facilitated by investments and research activities originating from industry, academia, and governments while the penetration of these technologies is also driven by the high technology acceptance rates of both consumers and technologists across disciplines. Such networks collect, store, and exchange a large volume of heterogeneous data. Nevertheless, their rapid and widespread deployment, along with their participation in the provisioning of potentially critical services (e.g., safety applications, healthcare, and manufacturing) raise numerous issues related to the security, data analysis, and energy awareness of the performed operations and provided services. Sachin Shetty, Jhing-Fa Wang, Uttam Ghosh, Schahram Dustdar |
IEEE Internet Things J. | 1 |
| 2022 | TACAS-IoT: Trust Aggregation Certificate-Based Authentication Scheme for Edge-Enabled IoT SystemsabstractThe Internet of Things (IoT) is a network of interconnected, Internet-connected items (i.e., smart devices) that can collect and transmit data across a wireless network without the need for human intervention. IoT enables the systems to have higher efficiency and dependability in their day-to-day operations due to its strong focus on machine-to-machine (M2M) connectivity, big data, and machine learning. While IoT has many advantages over traditional techniques, it also has a number of security and privacy concerns. Trust is a belief in the competence of a device (computing machine) to act dependably, securely and reliably in some specific context. In an M2M (one IoT device to other IoT device) communication, trust is accomplished by making the use of cryptographic operations (i.e., digital signatures and electronic certificates). Various security threats and attacks have been launched on IoT connectivity in recent years. A trust mechanism is necessary to ensure the quality of collaborative service behaviors and to build confidence between IoT devices. As a result, how to create an effective trust computing mechanism has become an emerging topic in IoT. Therefore, we provide the design of a novel trust-aggregation-based authentication scheme for secure communication of edge-enabled IoT (in short, TACAS-IoT). The security analysis shows that TACAS-IoT is secured against a variety of attacks. Moreover, TACAS-IoT delivers greater security and capabilities with less communication and computation overheads, according to the performance comparison. Finally, a practical implementation of TACAS-IoT is provided in order to assess its impact on the key performance parameters. Mohammad Wazid, Ashok Kumar Das, Sachin Shetty |
IEEE Internet Things J. | 3 |
| 2022 | A Unified Health Information System Framework for Connecting Data, People, Devices, and SystemsabstractThe COVID-19 pandemic has heightened the necessity for pervasive data and system interoperability to manage healthcare information and knowledge. There is an urgent need to better understand the role of interoperability in improving the societal responses to the pandemic. This paper explores data and system interoperability, a very specific area that could contribute to fighting COVID-19. Specifically, the authors propose a unified health information system framework to connect data, systems, and devices to increase interoperability and manage healthcare information and knowledge. A blockchain-based solution is also provided as a recommendation for improving the data and system interoperability in healthcare. Wu He, Justin Zhang 0001, Huanmei Wu, Sachin Shetty |
J. Glob. Inf. Manag. | 5 |
| 2021 | Dealing with the Domain Name Abuse: Issues and ApproachesabstractTo facilitate their worldwide access, online resources such as websites, mobile apps as well as email addresses would generally utilize domain names to label their logical locations on the Internet. Meanwhile, people who want to visit somewhere over the Internet would also tend to resort to a specific domain name first. Therefore, domain names are virtually playing an essential role during the interacting procedure between humans and online resources. However, domain names could sometimes be exploited maliciously and involved into some unexpected scenarios such as phishing, spamming, and harmful content distributing. We refer to these kinds of exploitation here as domain name abuse. Due to the explosive growth over the past years, domain name abuse has been drawing plenty of attentions both from academic and industrial areas. However, we note that there still exist a range of fundamental yet vital issues that have not been well addressed so far. In this paper, we conduct a comprehensive reexamination towards some of these major issues as well as relevant approaches regarding domain name abuse handling, and try further to set forth some of our own responses and corresponding updates towards them. We believe that these issues and relevant approaches could lead to extensive impact towards further progress in this area, and our work would help the community to deal with domain name abuse in a more accountable and practical manner. Xuebiao Yuchi, Zhiwei Yan, Kejun Dong, Guanggang Geng, Sachin Shetty |
EUC | 6 |
| 2021 | ATTL: An Automated Targeted Transfer Learning with Deep Neural NetworksabstractSuccess of machine learning algorithms hinges on access to labeled dataset. Obtaining a labeled dataset is an expensive, challenging and time-consuming process, leading to the development of transfer learning (TL) methodology. TL incorporates gained knowledge from a previously trained source model into specific yet similar task models with limited data domain coverage. In this paper, we propose an automated targeted transfer learning (ATTL) method to resolve the transferability between source and target with minimal data requirements. The ATTL method decides how much target data is essential for model training, along with selected source data, to obtain the skateholder's specified performance metrics. The ATTL framework optimizes the system to select minimal target data based on two approaches: combinatorial coverage and adaptive selection methodology, along with specific source data for fine-tuning given a pre-trained source model. We evaluated the ATTL method on the Kaggle's ‘planes in satellite imagery’ dataset and the results identified that acquiring a small number of intentionally well-chosen samples from the target environment can achieve model performance of 97% in comparison to the baseline transfer learning accuracy of 92%. Sayyed Farid Ahamed, Priyanka Aggarwal, Sachin Shetty, Erin Lanus, Laura J. Freeman |
GLOBECOM | 3 |
| 2021 | A Blockchain and Self-Sovereign Identity Empowered Digital Identity PlatformabstractMost of the existing identity systems are built on top of centralized storage systems. Storing identity data on these types of centralized storage platforms(e.g cloud storage, central servers) becomes a major privacy concern since various types of attacks and data breaches can happen. With this research, we are proposing blockchain and self-sovereign identity based digital identity (KYC - Know Your Customer) platform “Casper” to address the issues on centralized identity systems. “Casper ” is an Android/iOS based mobile identity wallet application that combines the integration of blockchain and a self-sovereign identity-based approach. Unlike centralized identity systems, the actual identities of the customer/users are stored in the customers’ mobile wallet application. The proof of these identities is stored in the blockchain-based decentralized storage as a self-sovereign identity proof. Casper platforms’ Self-Sovereign Identity(SSI)-based system provides a Zero Knowledge Proof(ZKP) mechanism to verify the identity information. Casper platform can be adopted in various domains such as healthcare, banking, government organization etc. As a use case, we have discussed building a digital identity wallet for banking customers with the Casper platform. Casper provides a secure, decentralized and ZKP verifiable identity by using blockchain and SSI based approach. It addresses the common issues in centralized/cloud-based identity systems platforms such as the lack of data immutability, lack of traceability, centralized control etc. Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Kasun De Zoysa |
ICCCN | 4 |
| 2021 | Blockchain and Self-Sovereign Identity Empowered Cyber Threat Information Sharing PlatformabstractCyber threat information (CTI) sharing involves processes of the collection, analysis and sharing of cyber threat information among multiple organizations. CTI is highly sensitive and inadvertent access can harm an organisation’s reputation. Moreover, CTI sharing may also inadvertently advertise a vulnerability that may be present in the organisation’s infrastructure. Therefore, preserving the privacy and anonymity of the CTI participants is critical. This paper proposes "Siddhi", a blockchain and Self-Sovereign Identity(SSI) enabled CTI platform that will realize traceability, anonymization and data provenance in a scalable fashion. Siddhi is equipped with SSI-enabled mobile wallet to ensure anonymous reporting of threat information and supports TAXII and STIX standards for exchanging the threat information between participants in the blockchain network. Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty |
SMARTCOMP | 4 |
| 2021 | Tikiri - Towards a lightweight blockchain for IoT
Eranga Bandara, Deepak K. Tosh, Peter Foytik, Sachin Shetty, Nalin Ranasinghe, Kasun De Zoysa |
Future Gener. Comput. Syst. | 4 |
| 2021 | Leveraging Intel SGX to enable trusted and privacy preserving membership service in distributed ledgers
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
Int. J. Inf. Comput. Secur. | 2 |
| 2021 | A blockchain empowered and privacy preserving digital contact tracing platform
Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Crissie Hall, Daniel Bowden, Nalin Ranasinghe, Kasun De Zoysa |
Inf. Process. Manag. | 4 |
| 2021 | Rahasak - Scalable blockchain architecture for enterprise applications
Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Nalin Ranasinghe, Kasun De Zoysa |
J. Syst. Archit. | 4 |
| 2020 | Integrating Mission-Centric Impact Assessment to Operational Resiliency in Cyber-Physical SystemsabstractDeveloping mission-centric impact assessment techniques to address cyber resiliency in the cyber-physical systems (CPSs) requires integrating system inter-dependencies to the risk and resilience analysis process. Generally, network administrators utilize attack graphs to estimate possible consequences in a networked environment. Attack graphs lack to incorporate the operations-specific dependencies. Localizing the dependencies among operational missions, tasks, and the hosting devices in a large-scale CPS is also challenging. In this work, we offer a graphical modeling technique to integrate the mission-centric impact assessment of cyberattacks by relating the effect to the operational resiliency by utilizing a combination of the logical attack graph and mission impact propagation graph. We propose formal techniques to compute cyberattacks' impact on the operational mission and offer an optimization process to minimize the same, having budgetary restrictions. We also relate the effect to the system functional operability. We illustrate our modeling techniques using a SCADA (supervisory control and data acquisition) case study for the cyber-physical power systems. We believe our proposed method would help evaluate and minimize the impact of cyber attacks on CPS's operational missions and, thus, enhance cyber resiliency. Md Ariful Haque, Sachin Shetty, Charles A. Kamhoua, Kimberly Gold |
GLOBECOM | 2 |
| 2020 | Modeling Mission Impact of Cyber Attacks on Energy Delivery Systems
Md Ariful Haque, Sachin Shetty, Charles A. Kamhoua, Kimberly Gold |
SecureComm (2) | 2 |
| 2019 | Modeling Stepping Stone Attacks with Constraints in Cyber InfrastructureabstractMost cyber attacks involve an attacker launching a multi-stage attack by exploiting a sequence of hosts. This multistage attack generates a chain of "stepping stones" from the origin to target. The choice of stepping stones is a function of the degree of exploitability, the impact, attacker's capability, masking origin location, and intent. In this paper, we model and analyze scenarios wherein an attacker employs multiple strategies to choose stepping stones. The problem is modeled as an Adjacency Quadratic Shortest Path using dynamic vulnerability graphs with multi-agent dynamic system approach. Using this approach, the shortest stepping stone attack with maximum node degree and the shortest stepping stone attack with maximum impact are modeled and analyzed. Marco A. Gamarra, Sachin Shetty, David M. Nicol, Laurent Njilla, Oscar R. González |
GLOBECOM | 2 |
| 2019 | Towards Optimal Cyber Defense Remediation in Energy Delivery SystemsabstractPrioritized cyber defense remediation plan is critical for effective risk management in Energy Delivery System (EDS). Due to the complexity of EDS in terms of heterogeneous nature blending Information Technology (IT) and Operation Technology (OT) and Industrial Control System (ICS), scale and critical processes tasks, prioritized remediations should be applied gradually to protect critical assets. In this work, we propose a methodology for prioritized cyber risk remediation plan by detecting and evaluating paths to critical nodes in EDS. We propose critical nodes characteristics evaluation based on nodes' architectural positions, measure of centrality based on nodes' connectivity and frequency of network traffic, as well as the controlled amount of electrical power. The paper also examines the relationship between cost models of budget allocation for removal of vulnerabilities on critical nodes and its impact on gradual readiness. The proposed cost models were empirically validated in an actual network ICS test-bed computing nodes criticality. Two cost models were examined, and although varied, we concluded the lack of correlation between types of cost models to most damageable attack path and critical nodes readiness. Kamrul Hasan 0008, Sachin Shetty, Sharif Ullah, Amin Hassanzadeh, Ethan Hadar |
GLOBECOM | 2 |
| 2019 | Dual Redundant Cyber-Attack Tolerant Control Systems Strategy for Cyber-Physical SystemsabstractIn this paper, a cyber-attack tolerant control strategy for embedded controllers in a cyber-physical system is presented. A dual redundant control architecture that combines two identical controllers that are switched periodically between active and restart modes is proposed. The strategy is addressed to mitigate the impact due to corruption of the controller software by an adversary. We analyze the impact of the resetting and restarting the controller software and performance of switching process. The minimum requirements in the control design, for effective mitigation of cyber-attacks to the control software, that implies a "fast" switching period is provided. The simulation results demonstrate the effectiveness of the proposed strategy when the time to fully reset and restart the controller is faster than the time taken by adversary to compromise the controller. The results also provide insights into the stability and safety regions and the factors that determine the effectiveness of the proposed strategy. Marco A. Gamarra, Sachin Shetty, Oscar R. González, Laurent Njilla, Marcus Pendleton, Charles A. Kamhoua |
ICC | 2 |
| 2019 | Online Cyber Deception System Using Partially Observable Monte-Carlo Planning Framework
Md Ali Reza Al Amin, Sachin Shetty, Laurent Njilla, Deepak K. Tosh, Charles A. Kamhoua |
SecureComm (2) | 2 |
| 2019 | Cyber Threat Analysis Based on Characterizing Adversarial Behavior for Energy Delivery System
Sharif Ullah, Sachin Shetty, Anup Nayak, Amin Hassanzadeh, Kamrul Hasan 0008 |
SecureComm (2) | 2 |
| 2019 | Security risk assessment for SDN-enabled smart grids
Hellen Maziku, Sachin Shetty, David M. Nicol |
Comput. Commun. | 2 |
| 2019 | Transfer learning for detecting unknown network attacksabstractNetwork attacks are serious concerns in today’s increasingly interconnected society. Recent studies have applied conventional machine learning to network attack detection by learning the patterns of the network behaviors and training a classification model. These models usually require large labeled datasets; however, the rapid pace and unpredictability of cyber attacks make this labeling impossible in real time. To address these problems, we proposed utilizing transfer learning for detecting new and unseen attacks by transferring the knowledge of the known attacks. In our previous work, we have proposed a transfer learning-enabled framework and approach, called HeTL, which can find the common latent subspace of two different attacks and learn an optimized representation, which was invariant to attack behaviors’ changes. However, HeTL relied on manual pre-settings of hyper-parameters such as relativeness between the source and target attacks. In this paper, we extended this study by proposing a clustering-enhanced transfer learning approach, called CeHTL, which can automatically find the relation between the new attack and known attack. We evaluated these approaches by stimulating scenarios where the testing dataset contains different attack types or subtypes from the training set. We chose several conventional classification models such as decision trees, random forests, KNN, and other novel transfer learning approaches as strong baselines. Results showed that proposed HeTL and CeHTL improved the performance remarkably. CeHTL performed best, demonstrating the effectiveness of transfer learning in detecting new network attacks. Juan Zhao 0003, Sachin Shetty, Jan Wei Pan, Charles A. Kamhoua, Kevin A. Kwiat |
EURASIP J. Inf. Secur. | 2 |
| 2019 | AKM-IoV: Authenticated Key Management Protocol in Fog Computing-Based Internet of Vehicles DeploymentabstractInternet of Vehicles (IoV) is an intelligent application of Internet of Things (IoT) in smart transportation that takes intelligent commitments to the passengers to improve traffic safety and efficiency, and generate a more enjoyable driving and riding environment. Fog cloud-based IoV is another variant of mobile cloud computing where vehicular cloud and Internet can co-operate in more effective way in IoV. However, more increasing dependence on wireless communication, control, and computing technology makes IoV more dangerous to prospective attacks. For secure communication among vehicles, road-side units, fog and cloud servers, we design a secure authenticated key management protocol in fog computing-based IoV deployment, called AKM-IoV. In the designed AKM-IoV, after mutual authentication between communicating entities in IoV they establish session keys for secure communications. AKM-IoV is tested for its security analysis using the formal security analysis under the widely accepted real-or-random (ROR) model, informal, and formal security verification using the broadly accepted automated validation of Internet security protocols and applications (AVISPAs) tool. The practical demonstration of AKM-IoV is shown using the NS2 simulation. In addition, a detailed comparative study is conducted to show the efficiency and functionality and security features supported by AKM-IoV as compared to other existing recent protocols. Mohammad Wazid, Palak Bagga, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park 0005 |
IEEE Internet Things J. | 4 |
| 2018 | CloudPoS: A Proof-of-Stake Consensus Design for Blockchain Integrated CloudabstractMaintaining data provenance in cloud in a tamper-resistant manner that cannot be breached by malicious parties is a necessity from the current security standpoint. Blockchain technology has emerged as a secure solution to store and share information by offering an immutable distributed ledger service. Its effectiveness hinges on the infrastructure supporting the distributed ledger and consensus protocol that governs the validity of entries in the Blockchain. Hence, Blockchain can be a potential candidate to implement data provenance; however, traditional cryptocurrency-based consensus models become a bottleneck in the cloud environment. Therefore, in this paper, we propose a Blockchain based data provenance architecture (BlockCloud) that incorporates a proof-of-stake (PoS)-based consensus protocol (CloudPoS) for securely recording the data operations occurring in cloud environment. The critical operational phases of the protocol are discussed in depth, which leverages the cloud users' cyber infrastructure resources. A cloud-based testbed environment is created using a local cluster of physical machines managed by Xen hypervisor. Resource elasticity is enabled using Kubernetes setup that interacts with the dockerized containers, which emulate as peers in the Blockchain network. We then evaluate the effectiveness of the protocol in a simulated environment and conduct performance tests of the proposed consensus. Deepak K. Tosh, Sachin Shetty, Peter Foytik, Charles A. Kamhoua, Laurent Njilla |
IEEE CLOUD | 2 |
| 2018 | Analysis of Stepping Stone Attacks in Dynamic Vulnerability GraphsabstractVulnerability graphs have been employed as an effective tool for analyzing exploitability and impact of chain of exploits in networked environments. The attack graphs are created by a chain of "stepping stones" from the attacker origin to the desired target. The stepping stones not only provide the intermediate steps to reach the target, but also make it difficulty to identify the attacker's true location. In this paper, we model and analyze stepping stones in dynamic vulnerability graphs. Most analysis based on attack graph assume that the graph edges and weights remain constant during the attacker's attempt to propagate through the network. We propose a biased min- consensus technique for dynamic graphs with switching topology as a distributed technique to determine the attach paths with more probable stepping-stones in dynamic vulnerability graphs. We use min-plus algebra to determine necessary and sufficient convergence conditions. A necessary condition for convergence to the shortest path in the switching topology case is provided. Marco A. Gamarra, Sachin Shetty, David M. Nicol, Oscar Gonazlez, Charles A. Kamhoua, Laurent Njilla |
ICC | 2 |
| 2018 | Cyber Resilience Framework for Industrial Control Systems: Concepts, Metrics, and InsightsabstractIn this paper, we have analyzed the resilience property of industrial control systems (ICS) in the events of cyberattacks using subjective approach. We are proposing a comprehensive cyber resilience framework for the ICS by decomposing the resilience metric into a hierarchy of several sub-metrics. These metrics form a tree structure that has the potential to capture qualitative information about system's security and resilience posture and can be used as a high-level framework to identify where modeling and analysis are needed to be carried out. We present a brief description of resilient ICS characteristics and a cyber resilience assessment model for ICS. Finally, we present the cyber resilience metrics formulation methods and an illustration of resilience metrics calculation using Analytical Hierarchy Process (AHP). Our resilience framework can serve as a platform for a multi-criteria decision aid and help technical experts in identifying the gap in the study of ICS resilience. Md Ariful Haque, Gael Kamdem De Teyou, Sachin Shetty, Bheshaj Krishnappa |
ISI | 3 |
| 2018 | Towards a Reliable and Accountable Cyber Supply Chain in Energy Delivery System Using Blockchain
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Yafei Ji, Danyi Li |
SecureComm (2) | 2 |
| 2018 | A Reliable Data Provenance and Privacy Preservation Architecture for Business-Driven Cyber-Physical Systems Using BlockchainabstractCyber-physical systems (CPS) including power systems, transportation, industrial control systems, etc. support both advanced control and communications among system components. Frequent data operations could introduce random failures and malicious attacks or even bring down the whole system. The dependency on a central authority increases the risk of single point of failure. To establish an immutable data provenance scheme for CPS, the authors adopt blockchain and propose a decentralized architecture to assure data integrity. In business-driven CPS, end users are required to share their personal information with multiple third parties. To prevent data leakage and preserve user privacy, the authors isolate and feed different information retrieval requests using tokens specifically generated for each type of request. Providing both traceability of data operations, and unlinkability of end user activities, a robust blockchain-based CPS is prototyped. Evaluation indicates the architecture is capable of assured data provenance validation and user privacy preservation at a low overhead. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Juan Zhao 0003, Danyi Li, Jihong Liu |
Int. J. Inf. Secur. Priv. | 2 |
| 2017 | An SDN Based Framework for Guaranteeing Security and Performance in Information-Centric Cloud NetworksabstractCloud data centers are critical infrastructures to deliver cloud services. Although security and performance of cloud data centers have been well studied in the past, their networking aspects are overlooked. Current network infrastructures in cloud data centers limit the ability of cloud provider to offer guaranteed cloud network resources to users. In order to ensure security and performance requirements as defined in the service level agreement (SLA) between cloud user and provider, cloud providers need the ability to provision network resources dynamically and on the fly. The main challenge for cloud provider in utilizing network resource can be addressed by provisioning virtual networks that support information centric services by separating the control plane from the cloud infrastructure. In this paper, we propose an sdn based information centric cloud framework to provision network resources in order to support elastic demands of cloud applications depending on SLA requirements. The framework decouples the control plane and data plane wherein the conceptually centralized control plane controls and manages the fully distributed data plane. It computes the path to ensure security and performance of the network. We report initial experiment on average round-trip delay between consumers and producers. Uttam Ghosh, Pushpita Chatterjee, Deepak K. Tosh, Sachin Shetty, Kaiqi Xiong, Charles A. Kamhoua |
CLOUD | 4 |
| 2017 | Man in the Cloud (MITC) Defender: SGX-Based User Credential Protection for Synchronization Applications in Cloud Computing PlatformabstractIn cloud environment, client user credential protection is a critical security capability that is target of adversarial attacks, especially, in cloud file synchronization applications. Among the various adversarial attacks, MITC (Man in the Cloud) attack on commercial cloud storage applications has emerged as a critical threat because it is easy to launch and hard to detect. In this paper, we propose MITC Defender, a hardware-based defense system capable of protecting client user credentials using Intel Software Guard Extensions (SGX) and preventing against four different types of MITC attack in cloud environment. By adopting Intel SGX security features such as sealing and attestation, MITC Defender can securely seal user credentials locally and easily unseal user credentials, when verifications are needed, in a Trusted Execution Environment (TEE). We implement MITC Defender on an open source platform OpenSGX and evaluate the performance and potential overhead. Our evaluation results show that MITC Defender is effective on defense against MITC attack and other security threats with a low cost. Xueping Liang, Sachin Shetty, Lingchen Zhang, Charles A. Kamhoua, Kevin A. Kwiat |
CLOUD | 2 |
| 2017 | ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and AvailabilityabstractCloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 2 |
| 2017 | Security Implications of Blockchain Cloud with Analysis of Block Withholding AttackabstractThe blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations. Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 2 |
| 2017 | Cross layer attacks on GSM mobile networks using software defined radiosabstractThe ubiquitous adoption of cellular technologies, such as, Long Term Evolution (LTE) and Wide-band Code Division Multiple Access (WCDMA) has not diminished the impact of Global System for Mobile communication (GSM) technologies. Despite 20 years of deployment, GSM still poses significant security threats to its users due to adversaries exploiting protocol vulnerabilities. In this paper, we present an attack which leverages cross-layer information from network or data link layers to craft an attack vector targeting the physical layer. The cross-layer attack provides attacker sufficient knowledge to specifically target cells, control channels, and mobile stations (MS) with minimal investment of communication and energy resources. We have designed and implemented an experimental testbed, which comprises of, software defined radios (SDR) (USRP and gnuradio), open source GSM channel sniffer (gr-gsm), and distributed processing engine (Apache Spark). The experimental testbed will also facilitate cloning a base transceiver station (BTS) which will benefit from availability of cross-layer information to create customized attack vectors. The cross-layer attack capability on our experimental testbed provides a cost effective scheme to achieve desired benefits with optimal usage of communication and energy resources. Experimental results shows that the testbed can be used to successfully attack multiple mobile stations with minimal usage of power resources. Kamrul Hasan 0008, Sachin Shetty, Taiwo Oyedare |
CCNC | 2 |
| 2017 | Towards a Trusted and Privacy Preserving Membership Service in Distributed Ledger Using Intel Software Guard Extensions
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
ICICS | 2 |
| 2017 | Towards Decentralized Accountability and Self-sovereignty in Healthcare Systems
Xueping Liang, Sachin Shetty, Juan Zhao 0003, Daniel Bowden, Danyi Li, Jihong Liu |
ICICS | 2 |
| 2017 | Integrating blockchain for data sharing and collaboration in mobile healthcare applicationsabstractEnabled by mobile and wearable technology, personal health data delivers immense and increasing value for healthcare, benefiting both care providers and medical research. The secure and convenient sharing of personal health data is crucial to the improvement of the interaction and collaboration of the healthcare industry. Faced with the potential privacy issues and vulnerabilities existing in current personal health data storage and sharing systems, as well as the concept of self-sovereign data ownership, we propose an innovative user-centric health data sharing solution by utilizing a decentralized and permissioned blockchain to protect privacy using channel formation scheme and enhance the identity management using the membership service supported by the blockchain. A mobile application is deployed to collect health data from personal wearable devices, manual input, and medical devices, and synchronize data to the cloud for data sharing with healthcare providers and health insurance companies. To preserve the integrity of health data, within each record, a proof of integrity and validation is permanently retrievable from cloud database and is anchored to the blockchain network. Moreover, for scalable and performance considerations, we adopt a tree-based data processing and batching method to handle large data sets of personal health data collected and uploaded by the mobile platform. Xueping Liang, Juan Zhao 0003, Sachin Shetty, Jihong Liu, Danyi Li |
PIMRC | 3 |
| 2016 | Robust cooperative beamforming against steering vector uncertainty in cognitive radio networksabstractTransmit beamforming is one of the promising ways of accessing spectrum in an underlay cognitive radio network (CRN). In this paper, a robust cooperative transmit beamforming scheme is proposed for a mobile (or stationary) secondary receiver in a CRN where steering vector available at the distributed transmitters is error prone. The solution to the beamforming problem is based on stochastic optimization theory. Specifically, the proposed beamforming scheme achieves the following three objectives: i) probability of large-than-a-threshold for received power in the direction of the secondary receiver is maximized; ii) probabilities of less-than-a-threshold for received interference power in the direction of primary receivers are bounded; and iii) transmit power along the directions of the moving secondary receiver is forced to be uniform so as to ensure the same quality of service. Our simulation results demonstrate that the proposed robust cooperative beamformer can achieve noticeable bit-error-rate reductions for primary users as compared to the non-robust approach, where inaccuracy in the estimation of the steering vector is not considered, while ensuring almost the same quality of communication for the secondary user. Md Monzurul Alam, Sudeep Bhattarai, Sachin Shetty |
CCNC | 4 |
| 2016 | Polarized beamforming for enhanced countermeasure of wireless jamming attacksabstractDue to the open and shared nature, wireless communication systems are vulnerable to jamming attacks. Beamforming is a promising technique to counteract the impact of jamming attacks. However, when the location of the desired signal is close to that of the jamming signal, the performance of the traditional anti-jamming beamformer that uses isotropic antenna elements is significantly degraded due to the indistinguishable signals and interferences in the space domain. In this paper, an enhanced countermeasure method for jamming attacks has been proposed by using the polarized beamforming with a planar array. By integrating both polarization and space information, the proposed beamformer is able to suppress the interference that is close to the desired signal. The beamformer is designed using the Linearly Constrained Minimum Variance (LCMV) criterion. The analytical expression of the steering vectors is derived for far-field propagation. The Bit Error Rate (BER) performance of the proposed jamming defense system is examined. Simulation results show a significant performance improvement of the proposed anti-jamming system even when the desired signals and interferences are coming from the same direction. Ali Aldarraji, Sachin Shetty |
IPCCC | 3 |
| 2016 | Hierarchical Random Graph Based Network Diversity Modeling for the CloudabstractRecently, network diversity based security metrics is attracting researcher's interests. Several efforts have been devoted into the network diversity modeling, for the purpose of evaluating network robustness against potential attacks. The current network diversity modeling procedure commonly uses traditional network resource graph abstraction method, which is not scalable enough when coping with extreme large sized network environments, especially for the cloud network. In this paper, we introduce the hierarchical network resource graph abstraction method into the network modeling procedure. Specifically, the network resource information such as network topology and host resource can be abstracted within separated layers of the hierarchy. Compared with traditional method, simulation results show that our proposed method can improve the scalability of the network diversity modeling procedure significantly. Xuebiao Yuchi, Sachin Shetty |
SERVICES | 2 |
| 2016 | Towards Network-Topology Aware Virtual Machine Placement in Cloud DatacentersabstractNetwork aware resource allocation aims to ensure the performance of users' applications as well as the efficiency of overall resource usage inside the cloud datacenter. However, the cloud datacenter's interior topology information as well as the user's customized demands are commonly not considered during current resource allocating procedures. In this paper, we propose an optimized network aware resource allocation procedure, in which the network topology factors of the datacenter are introduced to minimize the communication latency between VMs as well as overall network costs. Furthermore, the user's personalized requirements as well as the datacenter's nature in resource heterogeneity are also considered during this procedure to make it more practical. Simulation results demonstrate that our approach can improve the resource allocation procedure's efficiency significantly. Xuebiao Yuchi, Sachin Shetty |
SERVICES | 2 |
| 2015 | A Testbed Using USRP(TM) and LabView(R) for Dynamic Spectrum Access in Cognitive Radio NetworksabstractDynamic spectrum access is regarded as a backbone for cognitive radio networks where unlicensed secondary users (SUs) access spectrum opportunistically which is licensed to licensed primary users (PUs). SUs are required to identify the idle bands and use them dynamically without creating any harmful interference to PUs. In dynamic spectrum access for peer-to-peer based communications, SU transmitter and its intended SU receiver must use common channel to communicate. Note that the fixed common control channel could not be viable in case of jamming attacks and wideband regime. Thus in this paper, we present a test bed using Universal Software Radio Peripheral (NI USRP) devices. We use Lab View® and MATLAB® scripting extensions to program NI USRP devices for peer-to-peer communications. Once SU transmitter and receiver pair knows idle channels, they use one of the best idle channels to communicate. We study sequential channel scanning and quorum based rendezvous methods without using any common control channels. These two schemes are compared in terms of their performance for finding suitable channel. Test bed is developed to test these schemes. Numerical results are presented obtained from test bed. Nimish Sharma, Danda B. Rawat, Bhed Bahadur Bista, Sachin Shetty |
AINA | 4 |
| 2015 | POSTER: Toward Energy-Wasting Misbehavior Detection Platform with Privacy Preservation in Building Energy UseabstractEnergy-wasting behavior is a big concern as it wastes around 1/3 of all energy consumption in buildings. Current solutions to address this issue either rarely offer privacy preservation or cannot satisfy occupants' comfort in an acceptable level. In this paper, we first propose an energy-wasting behavior detection platform. Based on that, we address a couple of privacy-related challenges in our platform through utilizing functional encryption to hide video data and by introducing noise disturbance which is mixed with metering data e.g. A/C power consumption signatures. In a privacy framework we proposed, we further quantify the privacy leakage by a set of theoretical models e.g. Hidden Markov model and differential privacy. Since our paper is still at its start phase, we plan to further extend our privacy evaluation model, assess privacy leakage on real-world dataset and accomplish experiments and we wish it could inspire colleagues' interests in this area. Depeng Li 0002, Sachin Shetty |
CCS | 2 |
| 2015 | Achievable Rate and Outage Probability of Cognitive Radio with Finite-Alphabet Inputs under Imperfect Spectrum SensingabstractIn this paper, we propose an effective method to calculate the average achievable rate and outage probability of a practical cognitive radio (CR) link with finite-alphabet inputs under imperfect spectrum sensing in fast and slow Rayleigh fading, respectively. In the considered CR system, the secondary user (SU) senses and dynamically exploits the spectrum pool via dynamic frequency hopping. Since spectrum sensing is not perfect, miss-detection occurs. Under this event, the interference emerged from collisions due to the simultaneous spectrum access of both primary and cognitive users leads to a non-Gaussian CR link. This makes it very challenging to evaluate the information theoretical limits, especially when finite-alphabet inputs are used. To overcome such challenge, we first introduce a simple method to calculate the instantaneous differential entropy of the channel output for a given fading gain using Laguerre-Gauss quadrature formulas. Using this result, we propose a piece-wise linear curve fitting (PLCF)-based method to calculate the average output entropy and outage probability, respectively. It is then demonstrated that the average achievable rate in fast fading and the outage probability in slow fading of the considered CR channel can be calculated effectively to achieve any predetermined accuracy level for a given finite-alphabet input. Anh D. Le, Nghi H. Tran, Sachin Shetty, Shivakumar Sastry |
VTC Spring | 3 |
| 2015 | Secrecy capacity of the full-duplex AF relay wire-tap channel under residual self-interferenceabstractThis paper studies a wire-tap channel in which a source node wants to communicate securely to a destination node in the presence of an eavesdropper and under the aid of an amplify-and-forward (AF) relay operating in full-duplex (FD) mode. The residual self-interference due to FD transmission is explicitly taken into account. The secrecy capacity and the respective optimal power allocation schemes for this system are examined under both individual and joint power constraints. At first, the related optimization problems are shown to be quasi-concave. As such, the globally optimal solution exists and is unique. Due to the non-linearity of the derivative, we apply a simple bisection method for root finding and obtain a simple expression for the optimal power allocation scheme. To further provide some insight on the solutions, we apply the method of dominant balance to analyze the capacity and power allocations in different high power regions. It is then demonstrated that full relay power is only needed when the power at the relay is sufficiently small compared to the power at the source. Comparisons with half-duplex (HD) relaying also revealed that FD can achieve a significantly higher secrecy capacity. Finally, numerical results are presented to confirm the optimality of the solutions. Cuong Dang, Leonardo Jiménez Rodríguez, Nghi H. Tran, Sachin Shetty, Shivakumar Sastry |
WCNC | 4 |
| 2015 | Cloud-assisted GPS-driven dynamic spectrum access in cognitive radio vehicular networks for transportation cyber physical systemsabstractTransportation Cyber Physical Systems (CPS) are expected to rely on robust wireless communication networks for real-time feedback for controlling these systems. The IEEE 802.11p based Dedicated Short Range Communication (DSRC) standard has been proposed for vehicular communications that has 7 channels. However, these channels could be easily congested resulting in delay and unreliable communications when vehicle density is high. In this paper, we present a cloud-assisted global positioning system (GPS)-driven dynamic spectrum access framework for transportation CPS. To provide reliable communications, we assume that each vehicle is equipped with two transceivers: one transceiver (always connected to the internet using e.g., 4G link) queries spectrum database and/or can serve as a GPS through an application (app), and the other transceiver/radio switches channels and adapts to suitable transmit parameters for vehicular communications to avoid any harmful interference to primary users (PUs). Each vehicle calculates the best route to its destination using GPS and finds the set of idle channels along the route. Furthermore, each vehicle periodically checks the spectrum database throughout the route to get most updated spectrum opportunities. We present performance evaluation of the proposed approach with the help numerical results obtained from simulations. Danda B. Rawat, Swetha Reddy Lenkala, Nimish Sharma, Bhed Bahadur Bista, Sachin Shetty |
WCNC | 5 |
| 2015 | Achievable rates and outage probability of cognitive radio with dynamic frequency hopping under imperfect spectrum sensingabstractIn this study, the authors propose simple methods to evaluate the achievable rates and outage probability of a cognitive radio (CR) link that takes into account the imperfectness of spectrum sensing. In the considered system, the CR transmitter and receiver correlatively sense and dynamically exploit the spectrum pool via dynamic frequency hopping. Under imperfect spectrum sensing, false‐alarm and miss‐detection occur which cause impulsive interference emerged from collisions due to the simultaneous spectrum access of primary and cognitive users. That makes it very challenging to evaluate the achievable rates. By first examining the static link where the channel is assumed to be constant over time, they show that the achievable rate using a Gaussian input can be calculated accurately through a simple series representation. In the second part of this study, they extend the calculation of the achievable rate to wireless fading environments. To take into account the effect of fading, they introduce a piece‐wise linear curve fitting‐based method to approximate the instantaneous achievable rate curve as a combination of linear segments. It is then demonstrated that the ergodic achievable rate in fast fading and the outage probability in slow fading can be calculated to achieve any given accuracy level. Anh D. Le, Sanjeewa P. Herath, Nghi H. Tran, Trung Quang Duong, Sachin Shetty |
IET Commun. | 5 |
| 2014 | RootkitDet: Practical End-to-End Defense against Kernel Rootkits in a Cloud Environment
Lingchen Zhang, Sachin Shetty, Peng Liu 0005, Jiwu Jing |
ESORICS (2) | 2 |
| 2014 | Game Theoretic Dynamic Spectrum Access in Cloud-Based Cognitive Radio NetworksabstractRadio Frequency (RF) resource allocation in a Cognitive Radio Network (CRN) is considerably constrained by its limited power, memory and computational capacity. With the emergence of cloud computing platforms, CRN has the potential to mitigate these constraints by leveraging the vast storage and computational capacity. In this paper, we proposed a game theoretic approach for resource allocation in cloud-base cognitive radio network. The proposed algorithm leverages the geolocation of secondary users and idle licensed bands to facilitate dynamic spectrum access to secondary users. Furthermore, the active secondary users adapt their transmit power using game theoretic approach in distributed manner based on the network condition in terms of estimated average packet error rate while satisfying the Quality-of-Service (QoS) in terms of signal-to-interference-plus-noise ratio. To control greedy secondary users in distributed power control game, we introduce a manager through a Stackelberg power adaptation game. Simulation results are presented to demonstrate the performance of the proposed radio resource management algorithm. Danda B. Rawat, Sachin Shetty, Khurram Raza |
IC2E | 2 |
| 2014 | Cloud-assisted dynamic spectrum access for VANET in transportation cyber-physical systemsabstractVehicular networking is regarded as a backbone for transportation cyber-physical systems (CPS). In this paper, we propose a cloud-assisted dynamic spectrum access in vehicular networks where vehicles search the spectrum database for idle channels. Each vehicle queries spectrum database periodically (every other time/distance unit or so) for a route computed by GPS to find idle channels. When two vehicles are within the communication range, they setup a communication link in a channel and exchange their data with the help of software defined radios. The performance of the proposed approach is evaluated with the help of numerical results obtained from simulations. Danda B. Rawat, Swetha Reddy Lenkala, Nimish Sharma, Sachin Shetty |
IPCCC | 4 |
| 2014 | Enhancing connectivity for spectrum-agile Vehicular Ad hoc NETworks in fading channelsabstractIn Vehicular Ad hoc NETwork (VANET) safety applications, connectivity among vehicles is important to disseminate the upcoming traffic information (e.g., warning messages generated by a source vehicle that detects an accident) to other following vehicles to notify drivers in a timely manner. Because of the highly dynamic VANET topology and the short transmission range mandated for Dedicated Short Range Communication (DSRC) by Federal Communications Commission (FCC), communication links among vehicles are short-lived especially in sparse vehicular density, making the task of establishing (through connection setup process) and maintaining the communications for fast-moving vehicles difficult. Furthermore, when a fixed transmission range is used in dynamically changing VANET, network could be easily suffered by a “broadcast-storm” in dense vehicular density while vehicles in VANET could be disconnected frequently in sparse vehicular density. In addition, when communication channels are overcrowded in VANET, vehicles should be able to switch from one radio frequency (RF) bands to another to make robust communication using spectrum-agile wireless environment. In this paper, we study the connectivity for spectrum-agile VANET in fading channels. Specifically, connectivity enhancement for vehicle-to-vehicle communications for vehicles traveling in opposite directions and for vehicles traveling in same direction is investigated using mathematical analysis and simulation results. Performance of the proposed approach is evaluated using numerical and simulation results. Danda B. Rawat, Sachin Shetty |
Intelligent Vehicles Symposium | 2 |
| 2013 | Security Risk Assessment of Cloud CarrierabstractCloud computing based delivery model has been adopted by end-users and enterprises to reduce IT costs and complexities. The ability to offload user software and data to cloud data centers has raised many security and privacy concerns over the cloud computing model. Significant research efforts have focused on hyper visor security and low-layer operating system implementations in cloud data centers. Unfortunately, the role of cloud carrier in the security and privacy of user software and data has not been well studied. Cloud carrier represents the wide area network that provides the connectivity and transport of cloud services between cloud consumers and cloud providers. In this paper, we present a risk assessment framework to study the security risk of the cloud carrier between cloud consumers and cloud providers. The risk assessment framework leverages the National Vulnerability Database (NVD) to examine the security vulnerabilities of operating systems of routers within the cloud carrier. This framework provides quantifiable security metrics for cloud carrier, which enables cloud consumers to establish the quality of security services among cloud providers. Such security metric information is very useful in the Service Level Agreement (SLA) negotiation between a cloud consumer and a cloud provider. It can be also be used to build a tool to verify SLA compliance. Furthermore, we implement this framework for the cloud carriers of Amazon Web Services and Windows Azure Platform. Our experiments show that the security risks of cloud carriers on these two commercial clouds are significantly different. This finding provides guidance for a network provider to improve the security of cloud carriers. Swetha Reddy Lenkala, Sachin Shetty, Kaiqi Xiong |
CCGRID | 2 |
| 2013 | Waiting Probability Analysis for Dynamic Spectrum Access in Cognitive Radio NetworksabstractCognitive radio networking is emerging paradigm for future generation wireless networks in which cognitive radio users (also known as secondary users) dynamically access the RF spectrum opportunistically without creating harmful interference to primary users. In this paper, the waiting probability of secondary users in the cognitive radio network is analyzed. We consider a cognitive radio network where multiple secondary users (SUs) contend for spectrum access using time division multiple access over idle primary user (PU) channels. Using queue dynamics as Poisson driven stochastic process, we characterize the waiting probability of secondary users. Generally speaking, in practical systems, secondary users of cognitive radio network would have no knowledge of activities of other users, thus the probability of being idle or contention probabilities of SUs' in cognitive radio network have to be assigned according to the available local information. Our focus is on SUs waiting probability analysis, for which a systematic understanding is lacking. Simulation results show that the use of multiple channels and/or multiple slots leads to significant delay reduction and transmission fairness. Danda B. Rawat, Bhed Bahadur Bista, Sachin Shetty, Gongjun Yan |
CISIS | 3 |
| 2013 | Toward a Real-Time Cloud Auditing ParadigmabstractThe amount of computing done in the cloud is greatly increasing. The decentralized nature of the cloud, however, makes it difficult for individuals to ensure that the computation is being done correctly. Thus, the concept of "cloud auditing" has appeared. As applications in the cloud become more sensitive, the need for auditing systems to provide rapid analysis and quick responses also increases. Machine learning algorithms can be employed for the purposes of providing audit data. Few of these algorithms can be done in an online fashion, however. In this work, we examine one such online machine learning algorithm, and describe how it might be employed in a distributed computing environment. Robert Nix, Murat Kantarcioglu, Sachin Shetty |
SERVICES | 3 |
| 2013 | Auditing and Analysis of Network Traffic in Cloud EnvironmentabstractCloud computing allows users to remotely store their data into the cloud and provides on-demand applications and services from a shared pool of configurable computing resources. The security of the outsourced data in the cloud is dependent on the security of the cloud computing system and network. Though, there have been numerous efforts on securing data on the cloud computing system, evaluation of data security on the network between cloud provider and its users is still a very challenging task. The audit of the cloud computing system and network will provide insights on the security and performance of VMs and the operating system on multiple data centers and the intra-cloud network managed by cloud providers and the wide-area network between the cloud user and cloud provider. Thus, network traffic analysis for cloud auditing is of critical importance so that users can resort to an external audit party to verify the data security on the network between cloud provider and its users. This paper presents the following key technologies required to analyze network traffic in the cloud computing environment: IP geolocation of network devices between cloud provider and its users, monitoring the data security of the cloud network path, and online mining of massive cloud auditing logs generated by cloud network traffic. Sachin Shetty |
SERVICES | 1 |
| 2012 | Mining Concept Drifting Network Traffic in Cloud Computing EnvironmentsabstractAnomaly-based network Intrusion Detection Systems (IDS)model patterns of normal activity and detect novel network attacks. However, these systems depend on the availability of the systems normal traffic pattern profile. But the statistical fingerprint of the normal traffic pattern can change and shift over a period of time due to changes in operational or user activity at the networked site or even system updates. The changes in normal traffic patterns over time lead to concept drift. Some changes can be temporal, cyclical and can be short-lived or they can last for longer periods of time. Depending on a number of factors the speed at which the change in traffic patterns occurs can also be variable, ranging from near instantaneous to the change occurring over the span of numerous months. These changes in traffic patterns are a cause of concern for IDSs as they can lead to a significant increase in false positive rates, thereby reducing the overall system performance. In order to improve the reliability of the IDS, there is a need for an automated mechanism to detect valid traffic changes and avoid inappropriate ad hoc responses. ROC curves have historically been used to evaluate the accuracy of IDSs. ROC curves generated using fixed, time-invariant classification thresholds do not characterize the best accuracy that an IDS can achieve in presence of concept-drifting network traffic. In this paper, we present integrated supervised machine learning and control theoretic model (especially for clouds) for detecting concept drift in network traffic patterns. The model comprises of an online support vector machine based classifier (incremental anomaly based detection), a Kullback-Leiblerdivergence based relative entropy measurement scheme (quantifying concept drift) and feedback control engine (adapting ROC thresholding). In our proposed system, any intrusion activity will cause significant variations, thereby causing a large error, while a minor aberration in the variations(concept drift) will not be immediately reported as alert. Sai Kiran Mukkavilli, Sachin Shetty |
CCGRID | 2 |
| 2012 | Assessing network path vulnerabilities for secure cloud computingabstractIn recent times, cloud computing based delivery model has been proven to reduce enterprise IT costs and complexities. In contrast to traditional enterprise IT solution, the cloud computing model moves the application software and data to remote servers in large datacenters, which raise many security challenges. One of the critical challenges is the inability to characterize the cloud network's impact on the cloud security and performance guarantees. In this paper, we analyze the degree of security provided by the network to data sharing applications deployed in cloud environments that span administrative and network domains. Our analysis is based on examining the security level of network applications on routers which lie between cloud subscriber and cloud provider. Our preliminary results confirm that the majority of the routers are plagued by insecure network protocols, leading to vulnerable routers. These results confirm our hypothesis that the security of the network infrastructure needs to be upgraded to assure the protection of information exchange between the cloud subscriber and cloud provider. Sachin Shetty, Nicholas Luna, Kaiqi Xiong |
ICC | 1 |
| 2012 | Feature and Signal Enhancement for Robust Speaker Identification of G.729 Decoded Speech
Kalpesh Raval, Ravi Prakash Ramachandran, Sachin Shetty, Brett Y. Smolenski |
ICONIP (5) | 3 |
| 2012 | Open-ended design and performance evaluation of a biometric speaker identification systemabstractIt is very important that biometrics education, particularly at the undergraduate level, keeps pace with the rapidly growing global market. This paper describes a senior level project in speech biometrics that fits in a variety of courses in order to reach out to many students. The project has broad learning outcomes, namely, enhanced application of math skills, software implementation skills, interest in biometrics, ability to carry out open-ended design and communication skills. Assessment results based on the analysis of the success of the students (refereed publications and enrolling in graduate programs), student surveys related to the learning outcomes and a target versus control group survey show that the project was successful. Ravi Prakash Ramachandran, Robi Polikar, Kevin D. Dahm, Sachin Shetty |
ISCAS | 4 |
| 2011 | Special issue on information dissemination and new services in P2P systems
Min Song 0002, Sachin Shetty, Wenbin Jiang 0001, E. K. Park |
Peer-to-Peer Netw. Appl. | 2 |
| 2010 | Control-Free Dynamic Spectrum Access for Cognitive Radio NetworksabstractDynamic spectrum access (DSA) promises to resolve spectrum scarcity and low spectrum utilization caused by today's static spectrum access (SSA) policy. In DSA, secondary users dynamically search and access spectrum bands that are temporarily unused by primary users. In this paper, we propose a control-free DSA algorithm for cognitive radio networks (CRN). Our algorithm enables each CRN node to select its operation band without coordination and exchange of control messages with neighbors. The contribution of our algorithm is that such an independently selected band can reach neighbors with high probability, while streamlining control complexity and overhead in DSA. We develop an analytical model to evaluate performance. Numerical results show that our control-free DSA algorithm can achieve very good performance. Chunsheng Xin, Min Song 0002, Liangping Ma, Sachin Shetty, Chien-Chung Shen |
ICC | 4 |
| 2010 | Blind channel estimation based robust physical layer key generation in MIMO networksabstractAn emerging area of interest in wireless security is the generation of secret encryption keys by leveraging the features of the physical propagation channel. The shared randomness of the wireless channel between two legitimate nodes in a communication network is exploited to provide strong secrecy. The secret keys are generated based on fluctuations or evolution of the wireless channel state. However, to the best of our knowledge, little work has been performed on algorithms to exploit the increased randomness available to wireless nodes equipped with MIMO antennas. In this paper, we present a practical key generation scheme for MIMO channels based on quantization performed on blind channel estimates. Our schemes generate random keys for transmitter and receiver by simultaneously quantizing the blind channel estimates. Our schemes are simulated for a realistic fading channel model, and performance metrics for error rate and efficiency are provided. Ravi Prakash Ramachandran, Sachin Shetty |
ISCAS | 2 |
| 2010 | Using Hidden Markov Model to detect rogue access pointsabstractAbstract One of the most challenging security concerns for network administrators is the presence of rogue access points (RAPs). The challenge is to detect and disable a RAP before it poses a serious security risk. In this paper, we propose a statistical based approach to detect RAPs using a Hidden Markov Model (HMM), which is applied to passively measure packet‐header data collected at a gateway router. The main idea is to process the sequence of packet traces in order to distinguish the normal packets from the abnormal ones. Our approach utilizes variations in packet inter‐arrival time to differentiate between authorized access points and RAPs. We used the inter‐arrival time of a packet as a distinguishing parameter because it varies drastically for a normal activity and an intrusive activity. We developed our HMM by analyzing Denial of Service (DoS) attacks of 802.11 based wireless local area networks. Our trained HMM can detect the presence of a RAP promptly within a second with extreme accuracy (very low false positive and false negative ratios are obtained). The success of our approach lies in the fact that it leverages knowledge about the behavior of the traffic characteristics of 802.11 based wireless local area networks and the properties of DoS attacks. Experiments were also performed to improve the accuracy of our HMM model. Our approach is scalable and non‐intrusive, requiring little deployment cost and effort, and is easy to manage and maintain. Copyright © 2010 John Wiley & Sons, Ltd. Gayathri Shivaraj, Min Song 0002, Sachin Shetty |
Secur. Commun. Networks | 3 |
| 2009 | A Learning-based Multiuser Opportunistic Spectrum Access Approach in Unslotted Primary NetworksabstractOpportunistic spectrum access presents a new approach to wireless spectrum utilization and management. In this paper, we propose a non-cooperative based OSA approach: learning-based approach to allow multiple secondary users to achieve maximal throughput in an unslotted opportunistic spectrum access (OSA) network. In this approach, collisions among secondary users are taken into consideration while making channel sensing decisions. Spectrum maps for secondary users are estimated based on occurrence of collisions. Our approach allows secondary users to achieve maximal throughput by seeking independent spectrum opportunities without exchanging any control information among secondary users. Numerical results show that the learning-based approach obtains near-optimal performance in most of the scenarios. Sachin Shetty, Min Song 0002, Chunsheng Xin, E. K. Park |
INFOCOM | 1 |
| 2009 | PLL Based Time Synchronization in Wireless Sensor NetworksabstractTime synchronization is a key component in numerous wireless sensor network applications. Most of the current software based time synchronization approaches suffer from communication overhead and lack of scalability. In this paper, we propose a hardware based approach based on voltage controlled crystal oscillator and phase locked loop techniques to achieve and maintain sub microsecond level time synchronization. Our approach does not require any exchange of synchronization messages with neighboring nodes. Performance evaluations in Matlab demonstrate sub microsecond accuracy and robustness to infrequent loss of WWVB signal. The principle advantages of our solution is scalability, accuracy, and low communication overhead. Sachin Shetty, George Simmons, Min Song 0002 |
RTCSA | 2 |
| 2007 | Coexistence of IEEE 802.11b and Bluetooth: An Integrated Performance Analysis
Min Song 0002, Sachin Shetty, Deepthi Gopalpet |
Mob. Networks Appl. | 2 |
| 2003 | Evolutionary Programming in a Distributed Packet Scheduling Architecture
Min Song 0002, Sachin Shetty, Weiying Zhu |
CAINE | 2 |
| 2001 | A windowing condition for characterization of finite signals from spectral phase or magnitudeabstractReconstruction of a signal from its spectral phase or magnitude is in general an ill-posed problem. Various conditions restricting the class of signals under consideration have been shown to be sufficient to regularize the problem so that a unique or essentially unique signal corresponds to any given spectral magnitude or spectral phase function. This paper shows that a finite discrete-time signal is characterized by its spectral magnitude (or phase) and the spectral magnitude (or phase) of an ancillary signal obtained by windowing the original signal. Sachin Shetty, John N. McDonald, Douglas Cochran |
ICASSP | 1 |