VLDB 2026 Research / reviewers in the wild / expert
Farshad Khorrami
dblp:94/5644
· DBLP profile ↗
69ranked-venue papers
5as first author
41since 2021 · last 2026
0000-0002-8418-004XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 34 · 4 first-author · 13 since 2021Artificial intelligence and machine learning · 30 · 4 first-author · 16 since 2021Security and privacy · 9 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Computer networks · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Effective Offensive Security LLM Agents: Hyperparameter Tuning, LLM as a Judge, and a Lightweight CTF BenchmarkabstractRecent advances in LLM agentic systems have improved the automation of offensive security tasks, particularly for Capture the Flag (CTF) challenges. We systematically investigate the key factors that drive agent success and provide a detailed recipe for building effective LLM-based offensive security agents. First, we present CTFJudge, a framework leveraging LLM as a judge to analyze agent trajectories and provide granular evaluation across CTF solving steps. Second, we propose a novel metric, CTF Competency Index (CCI) for partial correctness, revealing how closely agent solutions align with human-crafted gold standards. Third, we examine how LLM hyperparameters, namely temperature, top-p, and maximum token length, influence agent performance and automated cybersecurity task planning. For rapid evaluation, we present CTFTiny, a curated benchmark of 50 representative CTF challenges across binary exploitation, web, reverse engineering, forensics, and cryptography. Our findings identify optimal multi-agent coordination settings and lay the groundwork for future LLM agent research in cybersecurity. Minghao Shao, Nanda Rani, Kimberly Milner, Haoran Xi, Meet Udeshi, Saksham Aggarwal, Venkata Sai Charan Putrevu, Sandeep K. Shukla, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, Muhammad Shafique 0001 |
AAAI | 10 |
| 2026 | SCREAM: Secure Channels for Real-time Evaluation of Additive ManufacturingabstractAdditive Manufacturing (AM), also known as 3D printing, offers several advantages, including on-site production, enhanced throughput, and efficient use of raw materials. However, the rise in its usage has also led to an increase in potential threats that aim to disrupt the printing process. These attacks can subtly alter the design (CAD or STL) files or machine instructions (g-code), which can cause significant economic and reputational harm to the victim company. Current detection techniques, based on acoustic, magnetic, and accelerationbased side-channel analysis, have proven to be ineffective. Although power side-channel analysis is more effective than other means, it is expensive and not scalable. This paper proposes a novel detection method, SCREAM, that assumes the user has access to a trusted STL source and an untrusted g-code. SCREAM leverages the pulse trains sent to the motors to reconstruct the executing g-code. To ensure the safe and accurate execution of g-code, a three-level comparison is performed between recovered and untrusted g-code, as well as trusted STL ensuring successful detection of any anomalies present in the executing g-code. Our testing has shown that this method can detect a range of existing attacks on AM, including malicious firmware manipulation, FLAW3D, and Needle in a Haystack. Prithwish Basu Roy, Jason Blocklove, Mudit Bhargava, Hammond A. Pearce, Prashanth Krishnamurthy, Ozgur Sinanoglu, Nikhil Gupta 0002, Farshad Khorrami, Ramesh Karri |
AsiaCCS | 8 |
| 2026 | Sandbox-Enabled Digital Twin for Cyber-Physical Systems
Meet Udeshi, Md Raz, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
IOLTS | 5 |
| 2026 | MapleGrasp: Mask-guided Feature Pooling for Language-driven Efficient Robotic GraspingabstractRobotic manipulation of unseen objects via natural language commands remains challenging. Language driven robotic grasping (LDRG) predicts stable grasp poses from natural language queries and RGB-D images. We propose MapleGrasp, a novel framework that leverages maskguided feature pooling for efficient vision-language driven grasping. Our two-stage training first predicts segmentation masks from CLIP-based vision-language features. The second stage pools features within these masks to generate pixel-level grasp predictions, improving efficiency, and reducing computation. Incorporating mask pooling results in a 7% improvement over prior approaches on the OCID-VLG benchmark. Furthermore, we introduce RefGraspNet, an open-source dataset larger than existing alternatives, significantly enhancing model generalization for open-vocabulary grasping. MapleGrasp scores a strong grasping accuracy of 89% when compared with competing methods in the RefGraspNet benchmark. Our method achieves comparable performance to larger Vision-Language-Action models on the LIBERO benchmark, and shows significantly better generalization to unseen tasks. Experiments on a Franka arm demonstrate 73% success rate with unseen objects, surpassing baselines by 11%. Code and dataset is available here: https://github.com/vineet2104/MapleGrasp. Vineet Bhat, Naman Patel, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
WACV | 5 |
| 2026 | REMEND: Neural Decompilation for Reverse Engineering Math Equations from Binary ExecutablesabstractAnalysis of binary executables implementing mathematical equations can benefit from the reverse engineering of semantic information about the implementation. Traditional algorithmic reverse engineering tools either do not recover semantic information or rely on dynamic analysis and symbolic execution with high reverse engineering time. Algorithmic tools also require significant re-engineering effort to target new platforms and languages. Recently, neural methods for decompilation have been developed to recover human-like source code, but they do not extract semantic information explicitly. We develop REMEND, a neural decompilation framework to reverse engineer math equations from binaries to explicitly recover program semantics like dataflow and order of operations. REMEND combines a transformer encoder–decoder model for neural decompilation with algorithmic processing for enhanced symbolic reasoning necessary for math equations. REMEND is the first work to demonstrate that transformers for neural decompilation go beyond source code and reason about program semantics in the form of math equations. We train on a synthetically generated dataset containing multiple implementations and compilations of math equations to produce a robust neural decompilation model and demonstrate retargettability. REMEND obtains an accuracy of 89.8% to 92.4% across three Instruction Set Architectures (ISAs), three optimization levels, and two programming languages with a single trained model, extending the capability of state-of-the-art neural decompilers. We achieve high accuracy with a small model of up to 12 million parameters and an average execution time of 0.132 seconds per function. On a real-world dataset collected from open source programs, REMEND generalizes better than state-of-the-art neural decompilers despite being trained with synthetic data, achieving 8% higher accuracy. The synthetic and real-world datasets are provided at https://hf.co/udiboy1209/REMEND . Meet Udeshi, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
ACM Trans. Intell. Syst. Technol. | 4 |
| 2026 | RAZER: Robust Accelerated Zero-Shot 3-D Open-Vocabulary Panoptic Reconstruction With Spatio-Temporal AggregationabstractMapping and understanding complex 3D environments is fundamental to how autonomous systems perceive and interact with the physical world, requiring both precise geometric reconstruction and rich semantic comprehension. While existing 3D semantic mapping systems excel at reconstructing and identifying predefined object instances, they lack the flexibility to efficiently build semantic maps with open-vocabulary during online operation. Although recent vision-language models have enabled open-vocabulary object recognition in 2D images, they haven't yet bridged the gap to 3D spatial understanding. The critical challenge lies in developing a training-free unified system that can simultaneously construct accurate 3D maps while maintaining semantic consistency and supporting natural language interactions in real time. In this paper, we develop a zero-shot framework that seamlessly integrates GPU-accelerated geometric reconstruction with open-vocabulary vision-language models through online instance-level semantic embedding fusion, guided by hierarchical object association with spatial indexing. Our training-free system achieves superior performance through incremental processing and unified geometric-semantic updates, while robustly handling 2D segmentation inconsistencies. The proposed general-purpose 3D scene understanding framework can be used for various tasks including zero-shot 3D instance retrieval, segmentation, and object detection to reason about previously unseen objects and interpret natural language queries. Naman Patel, Prashanth Krishnamurthy, Farshad Khorrami |
IEEE Trans. Robotics | 3 |
| 2025 | RoboPEPP: Vision-Based Robot Pose and Joint Angle Estimation through Embedding Predictive Pre-TrainingabstractVision-Based pose estimation of articulated robots with unknown joint angles has applications in collaborative robotics and human-robot interaction tasks. Current frameworks use neural network encoders to extract image features and downstream layers to predict joint angles and robot pose. While images of robots inherently contain rich information about the robot’s physical structures, existing methods often fail to leverage it fully; therefore, limiting performance under occlusions and truncations. To address this, we introduce RoboPEPP, a method that fuses information about the robot’s physical model into the encoder using a masking-based self-supervised embedding-predictive architecture. Specifically, we mask the robot’s joints and pre-train an encoder-predictor model to infer the joints’ embeddings from surrounding unmasked regions, enhancing the encoder’s understanding of the robot’s physical model. The pre-trained encoder-predictor pair, along with joint angle and keypoint prediction networks, is then fine-tuned for pose and joint angle estimation. Random masking of input during fine-tuning and keypoint filtering during evaluation further improves robustness. Our method, evaluated on several datasets, achieves the best results in robot pose and joint angle estimation while being the least sensitive to occlusions and requiring the lowest execution time. The code is available at https://github.com/raktimgg/RoboPEPP. Raktim Gautam Goswami, Prashanth Krishnamurthy, Yann LeCun, Farshad Khorrami |
CVPR | 4 |
| 2025 | EnIGMA: Interactive Tools Substantially Assist LM Agents in Finding Security VulnerabilitiesabstractAlthough language model (LM) agents have demonstrated increased performance in multiple domains, including coding and web-browsing, their success in cybersecurity has been limited. We present *EnIGMA*, an LM agent for autonomously solving Capture The Flag (CTF) challenges. We introduce new tools and interfaces to improve the agent's ability to find and exploit security vulnerabilities, focusing on interactive terminal programs. These novel *Interactive Agent Tools* enable LM agents, for the first time, to run interactive utilities, such as a debugger and a server connection tool, which are essential for solving these challenges.
Empirical analysis on 390 CTF challenges across four benchmarks demonstrate that these new tools and interfaces substantially improve our agent's performance, achieving state-of-the-art results on NYU CTF, Intercode-CTF, and CyBench. Finally, we analyze data leakage, developing new methods to quantify it and identifying a new phenomenon we term *soliloquizing*, where the model self-generates hallucinated observations without interacting with the environment. Talor Abramovich, Meet Udeshi, Minghao Shao, Kilian Lieret, Haoran Xi, Kimberly Milner, Sofija Jancheska, John Yang 0002, Carlos E. Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique 0001, Karthik Narasimhan, Ramesh Karri, Ofir Press |
ICML | 10 |
| 2025 | MP-Nav: Enhancing Data Poisoning Attacks against Multimodal LearningabstractDespite the success of current multimodal learning at scale, its susceptibility to data poisoning attacks poses security concerns in critical applications. Attacker can manipulate model behavior by injecting maliciously crafted yet minute instances into the training set, stealthily mismatching distinct concepts. Recent studies have manifested the vulnerability by poisoning multimodal tasks such as Text-Image Retrieval (TIR) and Visual Question Answering (VQA). However, the current attacking method only rely on random choice of concepts for misassociation and random instance selections for injecting the poisoning noise, which often achieves the suboptimal effect and even risks failure due to the dilution of poisons by the large number of benign instances. This study introduces MP-Nav (Multimodal Poison Navigator), a plug-and-play module designed to evaluate and even enhance data poisoning attacks against multimodal models. MP-Nav operates at both the concept and instance levels, identifying semantically similar concept pairs and selecting robust instances to maximize the attack efficacy. The experiments corroborate MP-Nav can significantly improve the efficacy of state-of-the-art data poisoning attacks such as AtoB and ShadowCast in multimodal tasks, and maintain model utility across diverse datasets. Notably, this study underscores the vulnerabilities of multimodal models and calls for the counterpart defenses. Jingfeng Zhang, Prashanth Krishnamurthy, Naman Patel, Anthony Tzes, Farshad Khorrami |
ICML | 5 |
| 2025 | MultiTalk: Introspective and Extrospective Dialogue for Human-Environment-LLM AlignmentabstractLLMs have shown promising results in task planning due to their strong natural language understanding and reasoning capabilities. However, issues such as hallucinations, ambiguities in human instructions, environmental constraints, and limitations in the executing agent's capabilities often lead to flawed or incomplete plans. This paper proposes MultiTalk, an LLM-based task planning methodology that addresses these issues through a framework of introspective and extrospective dialogue loops. This approach helps ground generated plans in the context of the environment and the agent's capabilities, while also resolving uncertainties and ambiguities in the given task. These loops are enabled by specialized systems designed to extract and predict task-specific states, and flag mismatches or misalignments among the human user, the LLM agent, and the environment. Effective feedback pathways between these systems and the LLM planner foster meaningful dialogue. The efficacy of this methodology is demonstrated through its application to robotic manipulation tasks. Experiments and ablations highlight the robustness and reliability of our method, and comparisons with baselines further illustrate the superiority of MultiTalk in task planning for embodied agents. Project Website: https://llm-multitalk.github.io/ Venkata Naren Devarakonda, Ali Umut Kaypak, Shuaihang Yuan, Prashanth Krishnamurthy, Yi Fang 0006, Farshad Khorrami |
ICRA | 6 |
| 2025 | An Omnidirectional Non-Tethered Aerial Prototype with Fixed Uni-Directional ThrustersabstractThis paper presents the first worldwide functional prototype omnidirectional multi-rotor aerial vehicle with fixed uni-directional thrusters, with an on-board power source. An optimization algorithm computes the positions and orientations of the propellers in the body frame of the prototype to achieve the omnidirectional capability, while minimizing the platform's weight and the required thrust to hover at any orientation, in addition to other construction requirements. The effect of the aerodynamic interaction between the different propellers is identified experimentally, and the ensuing results are included in the optimization algorithm to avoid such interactions during flight. The prototype's performance is assessed in real experiments demonstrating the decoupling between the forces and moments of the drone, its ability to track concurrently independent positions and orientations, and its ability to hover at a fixed position while rotating. Mahmoud Hamandi, Abdullah Mohamed Ali, Konstantinos Kyriakopoulos, Anthony Tzes, Farshad Khorrami |
ICRA | 5 |
| 2025 | Experimental Evaluation of Safe Trajectory Planning for an Omnidirectional UAVabstractAutonomous aerial vehicles play a critical role in search and rescue operations, where navigation through cluttered and confined environments is essential. To this end, this paper presents a novel trajectory planning framework for omnidirectional drones that dynamically adjusts tracking velocity based on the platform’s proximity to obstacles, ensuring a balance between safety and efficiency in cluttered and challenging environments. The proposed approach generates a geometric path to the target location. At each waypoint, the minimum distance between the drone’s convex hull and surrounding obstacles is determined, allowing the computation of the velocity constraints. By slowing down near obstacles and accelerating in open spaces, the method enhances both safety and maneuverability. The framework is validated through real-world experiments using the OmniOcta UAV, demonstrating its ability to navigate through constrained spaces. Furthermore, we present an experimental study to investigate key sources of tracking deviations, including propeller dynamics and aerodynamic interactions near obstacles. Mahmoud Hamandi, Abdullah Mohamed Ali, Anthony Tzes, Farshad Khorrami |
IROS | 4 |
| 2025 | OSVI-WM: One-Shot Visual Imitation for Unseen Tasks using World-Model-Guided Trajectory GenerationabstractVisual imitation learning enables robotic agents to acquire skills by observing expert demonstration videos. In the one-shot setting, the agent generates a policy after observing a single expert demonstration without additional fine-tuning. Existing approaches typically train and evaluate on the same set of tasks, varying only object configurations, and struggle to generalize to unseen tasks with different semantic or structural requirements. While some recent methods attempt to address this, they exhibit low success rates on hard test tasks that, despite being visually similar to some training tasks, differ in context and require distinct responses. Additionally, most existing methods lack an explicit model of environment dynamics, limiting their ability to reason about future states. To address these limitations, we propose a novel framework for one-shot visual imitation learning via world-model-guided trajectory generation. Given an expert demonstration video and the agent’s initial observation, our method leverages a learned world model to predict a sequence of latent states and actions. This latent trajectory is then decoded into physical waypoints that guide the agent’s execution. Our method is evaluated on two simulated benchmarks and three real-world robotic platforms, where it consistently outperforms prior approaches, with over 30% improvement in some cases. Raktim Gautam Goswami, Prashanth Krishnamurthy, Yann LeCun, Farshad Khorrami |
NeurIPS | 4 |
| 2025 | CLIPScope: Enhancing Zero-Shot OOD Detection with Bayesian ScoringabstractDetection of out-of-distribution (OOD) samples is cru-cial for safe real-world deployment of machine learning models. Recent advances in vision language foundation models have made them capable of detecting OOD sam-ples without requiring in-distribution (ID) images. How-ever, these zero-shot methods often underperform as they do not adequately consider ID class likelihoods in their detection confidence scoring. Hence, we introduce CLIPScope, a zero-shot OOD detection approach that normalizes the confidence score of a sample by class likelihoods, akin to a Bayesian posterior update. Furthermore, CLIPScope incor-porates a novel strategy to mine OOD classes from a large lexical database. It selects class labels that are farthest and nearest to ID classes in terms of CLIP embedding distance to maximize coverage of OOD samples. We conduct ex-tensive ablation studies and empirical evaluations, demon-strating state of the art performance of CLIPScope across various OOD detection benchmarks. Code is available at https://github.com/ful001hao/CLIPScope. Hao Fu 0010, Naman Patel, Prashanth Krishnamurthy, Farshad Khorrami |
WACV | 4 |
| 2025 | FlashMix: Fast Map-Free LiDAR Localization via Feature Mixing and Contrastive-Constrained Accelerated TrainingabstractMap-free LiDAR localization systems accurately localize within known environments by predicting sensor position and orientation directly from raw point clouds, eliminating the need for large maps and descriptors. However, their long training times hinder rapid adaptation to new environments. To address this, we propose FlashMix, which uses a frozen, scene-agnostic backbone to extract local point descriptors, aggregated with an MLP mixer to predict sensor pose. A buffer of local descriptors is used to accelerate training by orders of magnitude, combined with metric learning or contrastive loss regularization of aggregated descriptors to improve performance and convergence. We evaluate FlashMix on various LiDAR localization benchmarks, examining different regularizations and aggregators, and demonstrating its effectiveness for rapid and accurate LiDAR localization in real-world scenarios. The code is available at https://github.com/raktimgg/FlashMix. Raktim Gautam Goswami, Naman Patel, Prashanth Krishnamurthy, Farshad Khorrami |
WACV | 4 |
| 2025 | Tamper-Proof Network Traffic Measurements on a NIC for Intrusion DetectionabstractCyber attacks can infect networked devices with rootkits that provide full-system access of the operating system to malicious actors. Rootkits can hide malicious network activity by tampering with network traffic monitoring on the host and interfere with the functioning of host-based intrusion detection systems (HIDS). Network interface cards (NICs) operate outside the host domain, so they cannot be tampered with easily by the rootkit. We present a framework that leverages the NIC to collect tamper-proof network traffic measurements for the HIDS. We provide two efficient implementations to collect measurements of high speed traffic (10Gbps), the Associative Table and the Count-Min Sketch. Our framework can collect reliably accurate measurements with negligible impact to network performance. The network throughput with measurement collection is within 99.5% of the throughput without collection. The implementation adds only 12 to 23 microseconds of latency. Meet Udeshi, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | On the (In)feasibility of ML Backdoor Detection as an Hypothesis Testing ProblemabstractWe introduce a formal statistical definition for the problem of backdoor detection in machine learning systems and use it to analyze the feasibility of such problems, providing evidence for the utility and applicability of our definition. The main contributions of this work are an impossibility result and an achievability result for backdoor detection. We show a no-free-lunch theorem, proving that universal (adversary-unaware) backdoor detection is impossible, except for very small alphabet sizes. Thus, we argue, that backdoor detection methods need to be either explicitly, or implicitly adversary-aware. However, our work does not imply that backdoor detection cannot work in specific scenarios, as evidenced by successful backdoor detection methods in the scientific literature. Furthermore, we connect our definition to the probably approximately correct (PAC) learnability of the out-of-distribution detection problem. Georg Pichler, Marco Romanelli 0002, Divya Prakash Manivannan, Prashanth Krishnamurthy, Farshad Khorrami, Siddharth Garg |
AISTATS | 5 |
| 2024 | Offramps: An FPGA-Based Intermediary for Analysis and Modification of Additive Manufacturing Control SystemsabstractCybersecurity threats in Additive Manufacturing (AM) are an increasing concern as AM adoption continues to grow. AM is now being used for parts in the aerospace, transportation, and medical domains. Threat vectors which allow for part compromise are particularly concerning, as any failure in these domains would have life-threatening consequences. A major challenge to investigation of AM part-compromises comes from the difficulty in evaluating and benchmarking both identified threat vectors as well as methods for detecting adversarial actions. In this work, we introduce a generalized platform for systematic analysis of attacks against and defenses for 3D printers. Our “OFFRAMPS” platform is based on the open-source 3D printer control board “RAMPS.“ Offramps allows analysis, recording, and modification of all control signals and I/O for a 3D printer. We show the efficacy of Offramps by presenting a series of case studies based on several Trojans, including ones identified in the literature, and show that Offramps can both emulate and detect these attacks, i.e., it can both change and detect arbitrary changes to the g-code print commands. Jason Blocklove, Md Raz, Prithwish Basu Roy, Hammond A. Pearce, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri |
DSN | 6 |
| 2024 | LipSim: A Provably Robust Perceptual Similarity MetricabstractRecent years have seen growing interest in developing and applying perceptual similarity metrics. Research has shown the superiority of perceptual metrics over pixel-wise metrics in aligning with human perception and serving as a proxy for the human visual system.
On the other hand, as perceptual metrics rely on neural networks, there is a growing concern regarding their resilience, given the established vulnerability of neural networks to adversarial attacks. It is indeed logical to infer that perceptual metrics may inherit both the strengths and shortcomings of neural networks.
In this work, we demonstrate the vulnerability of state-of-the-art perceptual similarity metrics based on an ensemble of ViT-based feature extractors to adversarial attacks. We then propose a framework to train a robust perceptual similarity metric called LipSim (Lipschitz Similarity Metric) with provable guarantees.
By leveraging 1-Lipschitz neural networks as the backbone, LipSim provides guarded areas around each data point and certificates for all perturbations within an $\ell_2$ ball. Finally, a comprehensive set of experiments shows the performance of LipSim in terms of natural and certified scores and on the image retrieval application. Sara Ghazanfari, Alexandre Araujo, Prashanth Krishnamurthy, Farshad Khorrami, Siddharth Garg |
ICLR | 4 |
| 2024 | Novel Quadratic Constraints for Extending LipSDP beyond Slope-Restricted ActivationsabstractRecently, semidefinite programming (SDP) techniques have shown great promise in providing accurate Lipschitz bounds for neural networks. Specifically, the LipSDP approach (Fazlyab et al., 2019) has received much attention and provides the least conservative Lipschitz upper bounds that can be computed with polynomial time guarantees. However, one main restriction of LipSDP is that its formulation requires the activation functions to be slope-restricted on $[0,1]$, preventing its further use for more general activation functions such as GroupSort, MaxMin, and Householder. One can rewrite MaxMin activations for example as residual ReLU networks. However, a direct application of LipSDP to the resultant residual ReLU networks is conservative and even fails in recovering the well-known fact that the MaxMin activation is 1-Lipschitz. Our paper bridges this gap and extends LipSDP beyond slope-restricted activation functions. To this end, we provide novel quadratic constraints for GroupSort, MaxMin, and Householder activations via leveraging their underlying properties such as sum preservation. Our proposed analysis is general and provides a unified approach for estimating $\ell_2$ and $\ell_\infty$ Lipschitz bounds for a rich class of neural network architectures, including non-residual and residual neural networks and implicit models, with GroupSort, MaxMin, and HouseHolder activations. Finally, we illustrate the utility of our approach with a variety of experiments and show that our proposed SDPs generate less conservative Lipschitz bounds in comparison to existing approaches. Patricia Pauli, Aaron J. Havens, Alexandre Araujo, Siddharth Garg, Farshad Khorrami, Frank Allgöwer, Bin Hu 0002 |
ICLR | 5 |
| 2024 | High-Dimensional Controller Tuning through Latent RepresentationsabstractIn this paper, we propose a method to automatically and efficiently tune high-dimensional vectors of controller parameters. The proposed method first learns a mapping from the high-dimensional controller parameter space to a lower dimensional space using a machine learning-based algorithm. This mapping is then utilized in an actor-critic framework using Bayesian optimization (BO). The proposed approach is applicable to complex systems (such as quadruped robots). In addition, the proposed approach also enables efficient generalization to different control tasks while also reducing the number of evaluations required while tuning the controller parameters. We evaluate our method on a legged locomotion application. We show the efficacy of the algorithm in tuning the high-dimensional controller parameters and also reducing the number of evaluations required for the tuning. Moreover, it is shown that the method is successful in generalizing to new tasks and is also transferable to other robot dynamics. Alireza Sarmadi, Prashanth Krishnamurthy, Farshad Khorrami |
ICRA | 3 |
| 2024 | A Control Barrier Function-based Motion Planning Scheme for a Quadruped RobotabstractA Control Barrier Function (CBF)-based motion planning algorithm is proposed. The algorithm explores an unknown environment to reach a target point, providing velocity commands to the robot controller module. CBFs, along with a circulation inequality are used to generate safe paths toward the goal while preventing collisions with obstacles. The proposed global navigation scheme is experimentally verified on a quadruped platform to demonstrate safe, collision-free exploration over long distances. Halil Utku Unlu, Vinicius Mariano Gonçalves, Dimitris Chaikalis, Anthony Tzes, Farshad Khorrami |
ICRA | 5 |
| 2024 | NYU CTF Bench: A Scalable Open-Source Benchmark Dataset for Evaluating LLMs in Offensive SecurityabstractLarge Language Models (LLMs) are being deployed across various domains today. However, their capacity to solve Capture the Flag (CTF) challenges in cybersecurity has not been thoroughly evaluated. To address this, we develop a novel method to assess LLMs in solving CTF challenges by creating a scalable, open-source benchmark database specifically designed for these applications. This database includes metadata for LLM testing and adaptive learning, compiling a diverse range of CTF challenges from popular competitions. Utilizing the advanced function calling capabilities of LLMs, we build a fully automated system with an enhanced workflow and support for external tool calls. Our benchmark dataset and automated framework allow us to evaluate the performance of five LLMs, encompassing both black-box and open-source models. This work lays the foundation for future research into improving the efficiency of LLMs in interactive cybersecurity tasks and automated task planning. By providing a specialized benchmark, our project offers an ideal platform for developing, testing, and refining LLM-based approaches to vulnerability detection and resolution. Evaluating LLMs on these challenges and comparing with human performance yields insights into their potential for AI-driven cybersecurity solutions to perform real-world threat management. We make our benchmark dataset open source to public https://github.com/NYU-LLM-CTF/NYUCTFBench along with our playground automated framework https://github.com/NYU-LLM-CTF/llmctfautomation. Minghao Shao, Sofija Jancheska, Meet Udeshi, Brendan Dolan-Gavitt, Haoran Xi, Kimberly Milner, Boyuan Chen 0004, Max Yin, Siddharth Garg, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, Muhammad Shafique 0001 |
NeurIPS | 11 |
| 2024 | REMaQE: Reverse Engineering Math Equations from ExecutablesabstractCybersecurity attacks on embedded devices for industrial control systems and cyber-physical systems may cause catastrophic physical damage as well as economic loss. This could be achieved by infecting device binaries with malware that modifies the physical characteristics of the system operation. Mitigating such attacks benefits from reverse engineering tools that recover sufficient semantic knowledge in terms of mathematical equations of the implemented algorithm. Conventional reverse engineering tools can decompile binaries to low-level code, but offer little semantic insight. This article proposes the REMaQE automated framework for reverse engineering of math equations from binary executables. Improving over state-of-the-art, REMaQE handles equation parameters accessed via registers, the stack, global memory, or pointers, and can reverse engineer equations from object-oriented implementations such as C++ classes. Using REMaQE, we discovered a bug in the Linux kernel thermal monitoring tool “tmon.” To evaluate REMaQE, we generate a dataset of 25,096 binaries with math equations implemented in C and Simulink. REMaQE successfully recovers a semantically matching equation for all 25,096 binaries. REMaQE executes in 0.48 seconds on average and in up to 2 seconds for complex equations. Real-time execution enables integration in an interactive math-oriented reverse engineering workflow. Meet Udeshi, Prashanth Krishnamurthy, Hammond A. Pearce, Ramesh Karri, Farshad Khorrami |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2024 | Privacy-Preserving Collaborative Learning Through Feature ExtractionabstractWe propose a framework in which multiple entities collaborate to build a machine learning model while preserving privacy of their data. The approach utilizes feature embeddings from shared/per-entity feature extractors transforming data into a feature space for cooperation between entities. We propose two specific methods and compare them with a baseline method. In Shared Feature Extractor (SFE) Learning, the entities use a shared feature extractor to compute feature embeddings of samples. In Locally Trained Feature Extractor (LTFE) Learning, each entity uses a separate feature extractor, and models are trained using concatenated features from all entities. As a baseline, in Cooperatively Trained Feature Extractor (CTFE) Learning, the entities train models by sharing raw data. Secure multi-party algorithms are utilized to train models without revealing data or features in plain text. We investigate the trade-offs among SFE, LTFE, and CTFE in regard to performance, privacy leakage (using an off-the-shelf membership inference attack), and computational cost. LTFE provides the most privacy, followed by SFE, and then CTFE. Computational cost is lowest for SFE and the relative speed of CTFE and LTFE depends on network architecture. CTFE and LTFE provide the best accuracy. We use three different datasets for evaluations. Alireza Sarmadi, Hao Fu 0010, Prashanth Krishnamurthy, Siddharth Garg, Farshad Khorrami |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Smooth Distances for Second-Order Kinematic Robot ControlabstractIn this paper, we propose an algorithm for computing a smoothed version of the distance between two objects. As opposed to the traditional Euclidean distance between two objects, which may not be differentiable, this smoothed distance is guaranteed to be differentiable. Differentiability is an important property in many applications, in particular in robotics, in which obstacle-avoidance schemes often rely on the derivative/Jacobian of the distance between two objects. We prove mathematical properties of this smoothed distance and of the algorithm for computing it, and show its applicability in robotics by applying it to a second order kinematic control framework, also proposed in this paper. The control framework using smooth distances was successfully implemented on a 7 DOF manipulator. Vinicius Mariano Gonçalves, Anthony Tzes, Farshad Khorrami, Philippe Fraisse |
IEEE Trans. Robotics | 3 |
| 2023 | An Integrated Testbed for Trojans in Printed Circuit Boards with Fuzzing CapabilitiesabstractThis paper showcases an all-in-one testing environment that combines Trojan detection and fuzzing capabilities for printed circuit boards using the OpenPLC “NYU Trojan Edition” and a dedicated Trojan detection framework. The demo system is self-contained and equipped with two OpenPLC-based boards (one with a Trojan and one without), and automated tools for inserting the Trojan and collecting side-channel data. We developed a graphical user interface for interactive Trojan selection, data visualization, and anomaly detection analysis. Prashanth Krishnamurthy, Hammond A. Pearce, Virinchi Roy Surabhi, Joshua Trujillo, Ramesh Karri, Farshad Khorrami |
IOLTS | 6 |
| 2023 | Comprehensive Reliability Analysis of 22nm FDSOI SRAM from Device Physics to Deep LearningabstractThis work investigates the joint impact of device variability and transistor aging on the data integrity of SRAM cells implemented using 22 FDSOI. Our analysis is based on well-calibrated TCAD simulations that reproduce measurements from a commercial 22nm FDSOI technology node. The calibrations are done against measurement data for both I-V characteristics and variability data. We perform error analysis for SRAMs during hold and read operations under three different scenarios: (i) Fresh: time-zero variation (PV) alone caused by manufacturing variability, (ii) Aged: combined impact of PV and aging-induced increase in the transistor threshold voltage ($V_{TH}$) at the room temperature, (iii) Aged@85°C: combined impact of PV and transistor aging but at an elevated temperature of 85°C. Further, we explore how SRAM errors are exacerbated when the voltage is scaled down due to the reductions in noise margins. All error analyses were accurately performed in TCAD mixed-mode simulations for a complete 6-T SRAM cell. Finally, to investigate further how such errors impact the system level, we explore the corresponding induced accuracy drop in Deep Neural Networks (DNNs). Different quantized NNs are studied, and their sensitivity to errors in weights and activations is also explored. We demonstrate that short-term aging (i.e., when aging effects are combined with voltage scaling) results in a noticeable accuracy drop when ResNet20 and ResNet18 DNN models are examined on the CIFAR100 and Imagenet datasets, respectively. Om Prakash 0007, Rodion Novkin, Virinchi Roy Surabhi, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami, Hussam Amrouch |
ISCAS | 6 |
| 2023 | Exploiting Connections between Lipschitz Structures for Certifiably Robust Deep Equilibrium ModelsabstractRecently, deep equilibrium models (DEQs) have drawn increasing attention from the machine learning community. However, DEQs are much less understood in terms of certified robustness than their explicit network counterparts. In this paper, we advance the understanding of certified robustness of DEQs via exploiting the connections between various Lipschitz network parameterizations for both explicit and implicit models. Importantly, we show that various popular Lipschitz network structures, including convex potential layers (CPL), SDP-based Lipschitz layers (SLL), almost orthogonal layers (AOL), Sandwich layers, and monotone DEQs (MonDEQ) can all be reparameterized as special cases of the Lipschitz-bounded equilibrium networks (LBEN) without changing the prescribed Lipschitz constant in the original network parameterization. A key feature of our reparameterization technique is that it preserves the Lipschitz prescription used in different structures. This opens the possibility of achieving improved certified robustness of DEQs via a combination of network reparameterization, structure-preserving regularization, and LBEN-based fine-tuning. We also support our theoretical understanding with new empirical results, which show that our proposed method improves the certified robust accuracy of DEQs on classification tasks. All codes and experiments are made available at \url{https://github.com/AaronHavens/ExploitingLipschitzDEQ}. Aaron J. Havens, Alexandre Araujo, Siddharth Garg, Farshad Khorrami, Bin Hu 0002 |
NeurIPS | 4 |
| 2023 | Towards better certified segmentation via diffusion modelsabstractThe robustness of image segmentation has been an important research topic in the past few years as segmentation models have reached production-level accuracy. However, like classification models, segmentation models can be vulnerable to adversarial perturbations, which hinders their use in critical-decision systems like healthcare or autonomous driving. Recently, randomized smoothing has been proposed to certify segmentation predictions by adding Gaussian noise to the input to obtain theoretical guarantees. However, this method exhibits a trade-off between the amount of added noise and the level of certification achieved. In this paper, we address the problem of certifying segmentation prediction using a combination of randomized smoothing and diffusion models. Our experiments show that combining randomized smoothing and diffusion models significantly improves certified robustness, with results indicating a mean improvement of 21 points in accuracy compared to previous state-of-the-art methods on Pascal-Context and Cityscapes public datasets. Our method is independent of the selected segmentation model and does not need any additional specialized training procedure. Othmane Laousy, Alexandre Araujo, Guillaume Chassagnon, Marie-Pierre Revel, Siddharth Garg, Farshad Khorrami, Maria Vakalopoulou |
UAI | 6 |
| 2023 | Golden-Free Robust Age Estimation to Triage Recycled ICsabstractNondestructive golden-free detection of recycled/counterfeit integrated circuits (ICs) is the focus of this article. This is achieved by estimating the functional/operational age of the IC. The age estimation method is based on exploiting short-term aging effects in advanced transistor technologies to induce bit errors at the IC’s output. Gate-level simulations are used to capture the impact of workload on short-term aging. In advanced technology nodes, including bulk CMOS at 45 nm or below and FinFET, combining transistor aging with ultrafast voltage scaling magnifies the effects of aging-induced degradation at high voltage when voltage scales to a lower level, causing short-term aging-based timing violations. These timing violations create bit errors at IC outputs. We employ the bit error patterns to build a machine learning (ML)-based nonlinear regression model to estimate the IC’s age. Our study confirms that short-term aging-induced output bit error patterns can be used to estimate long-term age of an IC. If the IC’s age is beyond a predefined threshold, it can be marked as recycled. Although this article considers the FinFET technology, the method applies to bulk CMOS advanced nodes at 45 nm or below. We model IC-to-IC variations taking into account the voltage scaling. We demonstrate the approach on two cryptographic ICs and the method accurately estimates the long-term age of an IC, facilitating recycled IC detection. Virinchi Roy Surabhi, Prashanth Krishnamurthy, Hussam Amrouch, Jörg Henkel, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2023 | Multi-Modal Side Channel Data Driven Golden-Free Detection of Software and Firmware TrojansabstractThis study explores data-driven detection of firmware/software Trojans in embedded systemswithoutgolden models. We consider embedded systems such as single board computers and industrial controllers. While prior literature considers side channel based anomaly detection, this study addresses the following central question: is anomaly detection feasible when using low-fidelity simulated data without using data from a known-good (golden) system? To study this question, we use data from a simulator-based proxy as a stand-in for unavailable golden data from a known-good system. Using data generated from the simulator, one-class classifier machine learning models are applied to detect discrepancies against expected side channel signal patterns and their inter-relationships. Side channels fused for Trojan detection include multi-modalside channelmeasurement data (such as Hardware Performance Counters, processor load, temperature, and power consumption). Additionally, fuzzing is introduced to increase detectability of Trojans. To experimentally evaluate the approach, we generate low-fidelity data using a simulator implemented with a component-based model and an information bottleneck based on Gaussian stochastic models. We consider example Trojans and show that fuzzing-aided golden-free Trojan detection is feasible using simulated data as a baseline. Prashanth Krishnamurthy, Virinchi Roy Surabhi, Hammond A. Pearce, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Differential Analysis of Triggers and Benign Features for Black-Box DNN Backdoor DetectionabstractThis paper proposes a data-efficient detection method for deep neural networks against backdoor attacks under a black-box scenario. The proposed approach is motivated by the intuition that features corresponding to triggers have a higher influence in determining the backdoored network output than any other benign features. To quantitatively measure the effects of triggers and benign features on determining the backdoored network output, we introduce five metrics. To calculate the five-metric values for a given input, we first generate several synthetic samples by injecting the input’s partial contents into clean validation samples. Then, the five metrics are computed by using the output labels of the corresponding synthetic samples. One contribution of this work is the use of a tiny clean validation dataset. Having the computed five metrics, five novelty detectors are trained from the validation dataset. A meta novelty detector fuses the output of the five trained novelty detectors to generate a meta confidence score. During online testing, our method determines if online samples are poisoned or not via assessing their meta confidence scores output by the meta novelty detector. We show the efficacy of our methodology through a broad range of backdoor attacks, including ablation studies and comparison to existing approaches. Our methodology is promising since the proposed five metrics quantify the inherent differences between clean and poisoned samples. Additionally, our detection method can be incrementally improved by appending more metrics that may be proposed to address future advanced attacks. Hao Fu 0010, Prashanth Krishnamurthy, Siddharth Garg, Farshad Khorrami |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Trojan Detection in Embedded Systems With FinFET TechnologyabstractThis study considers detecting Trojans in circuits using FinFET technology non-destructively, when a golden Integrated Circuit (IC) is unavailable. The method employs short-term aging effects in FinFET transistors and circuit overclocking to induce bit errors at the circuit outputs in conjunction with Machine Learning (ML) tools learning Trojan-free behavior. Short-term aging causes delays along multiple paths in the IC to vary dynamically, causing bit errors at circuit outputs. Overclocking enhances this in FinFET but is not necessary for bulk CMOS technology. We use bit error patterns at the output of the circuit to detect Trojans using an ML classifier trained on simulations of the Trojan-free circuit. The study shows efficacy of the method by using dynamic short-term aging-aware standard cell libraries with FinFET technology that are modeled by considering the dynamic short-term aging of each cell. Trojan detection is robust to chip-to-chip variations. We apply the technique on fourteen Trust-Hub Trojans. Our method detects Trojans with$>$95% accuracy. Trojan detection in FinFET technology is more challenging than in bulk CMOS because the voltage range for switching from a high to low value is smaller. Therefore we use overclocking. Virinchi Roy Surabhi, Prashanth Krishnamurthy, Hussam Amrouch, Jörg Henkel, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Computers | 6 |
| 2022 | Towards a New Thermal Monitoring Based Framework for Embedded CPS Device SecurityabstractThis article introduces a thermal side channel as a proxy for the behavior of embedded processors to detect changes in the behavior in a cyber-physical system. Such changes may be due to software/hardware attacks and altered processors. Since control system processes are periodic computations, the thermal side channels exhibit a temporal pattern. This enables the detection of altered code and changed device characteristics. We present a machine learning approach to estimate the activity of the embedded device from the time sequence of thermal images and show that deviations from expected behavior can be detected. The approach is validated on a multi-core processor running a periodic computational code. The infrared imager collects thermal imagery from the processor, which is cooled from the backside. Instead of an external imager, one can deploy a finite number of on-chip temperature sensors. This article shows that integrating on-chip temperature sensors allows robust real-time monitoring of the processor behavior. Finally, we offer a machine learning approach to optimally place the on-chip sensors to aid detection. Naman Patel, Prashanth Krishnamurthy, Hussam Amrouch, Jörg Henkel, Michael Shamouilian, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2022 | Overriding Autonomous Driving Systems Using Adaptive Adversarial BillboardsabstractThe success of deep neural networks (DNNs) has led to its increased deployment in various real-world applications, which provides strong incentives for motivated adversaries to manipulate the results and models generated by these algorithms. We present an automated, physically-realizable, dynamic adversarial attack to compromise an end-to-end trained DNN controlled autonomous vehicle. The attack is initiated by installing a billboard displaying videos on the roadside to incoming DNN controlled vehicles so that the vehicle tracks an adversary customized trajectory. The billboard contains an integrated camera to enable estimation of the pose of the approaching vehicle. The dynamic billboard images (i.e., a video) continuously adapt to the vehicle’s relative pose with respect to the billboard while being robust to variations in lighting, view angle, and weather. The attack’s effectiveness is shown on a recently developed off-the-shelf high-fidelity simulator, CARLA, for autonomous vehicles. CARLA utilizes an end-to-end learning-based autonomous navigation system. The proposed approach is applicable to other end-to-end trained autonomous cyber-physical systems. Naman Patel, Prashanth Krishnamurthy, Siddharth Garg, Farshad Khorrami |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Detecting Hardware Trojans in PCBs Using Side Channel LoopbacksabstractMalicious modifications to printed circuit boards (PCBs) are known as hardware Trojans. These may arise when malafide third parties alter PCBs premanufacturing or postmanufacturing and are a concern in safety-critical applications, such as industrial control systems. In this research, we examine how data-driven detection can be utilized to detect such Trojans at run-time. We develop a flexible and reconfigurable PCB test bed derived from the popular open-source programmable logic controller (PLC) platform “OpenPLC.” We then develop a Trojan detection framework, which utilizes and analyzes multimodal side channels (e.g., timing, magnetic signals, power, and hardware performance counters). We consider defender-configurable input/output (I/O) loopback test, comparison with design-document baselines, and magnetometer-aided monitoring of system behavior under defender-chosen excitations. Our approach can extend to golden-free environments. Golden (known-good) versions of the PCBs are assumed not available, but design information, datasheets, and component-level data are available. We demonstrate the efficacy of our approach on a range of Trojans instantiated in the test bed. Hammond A. Pearce, Virinchi Roy Surabhi, Prashanth Krishnamurthy, Joshua Trujillo, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2021 | Special Session: Machine Learning for Semiconductor Test and ReliabilityabstractWith technology scaling approaching atomic levels, IC test and diagnosis of complex System-on-Chips (SoCs) become overwhelming challenging. In addition, sustaining the reliability of transistors as well as circuits at such extreme feature sizes, for the entire projected lifetime, also become profoundly difficult. This holds even more when it comes to emerging technologies that go beyond convectional CMOS in which the underlying physics are not yet fully understood. In this special session paper, we describe the usage of machine learning in several test and reliability related areas. First, we demonstrate the vital role that machine learning can play in IC test showing the importance of explainability as a frontier for machine learning in IC test. Afterwards, we discuss how novel physics-informed neural networks can be employed to model electrostatic problems in VLSI designs. This is essential to mitigate the deleterious effects of of time dependent dielectric breakdown, which is the key source of reliability degradations. Finally, we discuss the major sources of reliability degradations at the transistor level in advanced technology nodes such as transistor aging phenomena and self-heating effects as well as we demonstrate how machine learning approaches can further help in developing reliable emerging technologies. Hussam Amrouch, Animesh Basak Chowdhury, Wentian Jin, Ramesh Karri, Farshad Khorrami, Prashanth Krishnamurthy, Ilia Polian, Victor M. van Santen, Benjamin Tan 0001, Sheldon X.-D. Tan |
VTS | 5 |
| 2021 | An approximate factorization approach to multi-jammer location and range estimation from peer-to-peer connectivity measurements
Prashanth Krishnamurthy, Farshad Khorrami |
Comput. Networks | 2 |
| 2021 | Explainable classification by learning human-readable sentences in feature subsets
Prashanth Krishnamurthy, Alireza Sarmadi, Farshad Khorrami |
Inf. Sci. | 3 |
| 2021 | Machine Learning for NetFlow Anomaly Detection With Human-Readable AnnotationsabstractWe propose a framework for anomaly detection in communication network logs along with automated extraction of human-readable annotations that explain the decision logic underlying each anomaly detection. For this purpose, we develop a machine learning methodology formulated in terms of a model comprised of an OR-combination of multiple Boolean logic based sentences. Each sentence is an empirically learned set of inequality conditions involving subsets of features. The feature set, which comprises the “alphabet” for human-readable annotations, is constructed using dynamic graph based spatio-temporal aggregation to extract human-understandable aggregates of network activity. These aggregates are constructed both in terms of computers (nodes in dynamic graph) and communications between computers (edges in dynamic graph). From the alphabet, the learned model identifies subsets of features that relate to each anomaly type and the combinations of conditions in terms of the feature subsets for detection of the specific anomaly type. Given a data point that the learned model detects as anomalous, the model identifies the specific features and their combinations related to the anomaly detection. These human-readable annotations provide a cyber-security analyst a transparent view into the decision logic underlying an anomaly detection. Prashanth Krishnamurthy, Farshad Khorrami, Steve Schmidt, Kevin Wright |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Anomaly Detection in Embedded Systems Using Power and Memory Side ChannelsabstractWe propose multi-modal anomaly detection in embedded systems using time-correlated measurements of power consumption and memory accesses. Time series of power consumption of the processor and memory accesses between L2 cache and memory bus under known-good conditions are used to train one-class support vector machine (SVM) and isolation forest classifiers. These side channels have complementary anomaly detection capabilities. Experiments on a high-fidelity processor emulator show that the method accurately detects anomalies. Virinchi Roy Surabhi, Prashanth Krishnamurthy, Siddharth Garg, Ramesh Karri, Farshad Khorrami |
ETS | 6 |
| 2020 | Exposing Hardware Trojans in Embedded Platforms via Short-Term AgingabstractWe demonstrate a novel technique that employs transistor short-term aging effects in integrated circuits (ICs) to detect hardware Trojans in embedded systems. In advanced technology nodes (≤ 45 nm), voltage scaling in combination with short-term aging opens doors for short-term degradations. The induced short-term degradations result in dynamic variation of delays along various paths within the IC. Aging degradation generated under fast voltage switching from high to low results in bit errors at the circuit output. Our experiments use short-term aging-aware standard cell libraries to show the effectiveness of short-term aging to detect hardware Trojans. We extract a rich set of features that capture bit error patterns at the outputs of the IC. We use a one class SVM-based classifier that uses these features to learn the distribution of bit errors at the outputs of a clean IC. We discern the deviation in the pattern of bit errors due to a Trojan in the IC from the baseline distribution. To reiterate, the method uses the model of a clean IC. Furthermore, it is robust against chip-to-chip variations. We illustrate the technique on six Trojans from Trust-Hub spanning two cryptographic chips and an embedded PIC microcontroller. Our approach detects Trojans with an accuracy ≥ 95%. It is easier to detect Trojans in an optimized-netlist circuit as more paths are close to the critical path. Even when the circuit is not optimized (i.e., when very few paths are close to the critical path), short-term aging plus mild overclocking can detect Trojans with high accuracy. Virinchi Roy Surabhi, Prashanth Krishnamurthy, Hussam Amrouch, Jörg Henkel, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2020 | A Theoretical Study of Hardware Performance Counters-Based Malware DetectionabstractMalware can range from simple adware to stealthy kernel control-flow modifying rootkits. Although anti-virus software is popular, an ongoing cat-and-mouse cycle of anti-virus development and malware that thwarts the anti-virus has ensued. More recently, trusted hardware-based malware detection techniques are being developed on the premise that it is easier to bypass software-based defenses than hardware-based counterparts. One such approach is the use of hardware performance counters (HPCs) to detect malware for Linux and Android platforms. This paper, for the first time, presents an analytical framework to investigate the security provided by HPC-based malware detection techniques. The HPC readings are periodically monitored over the duration of the program execution for comparison with a golden HPC reading. We develop a mathematical framework to investigate the probability of malware detection, when HPCs are monitored at a pre-determined sampling interval. In other words, given a program, a set of HPCs, and a sampling rate, the framework can be employed to analyze the probability of malware detection. Kanad Basu, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Anomaly Detection in Real-Time Multi-Threaded Processes Using Hardware Performance CountersabstractWe propose a novel methodology for real-time monitoring of software running on embedded processors in cyber-physical systems (CPS). The approach uses real-time monitoring of hardware performance counters (HPC) and applies to multi-threaded and interrupt-driven processes typical in programmable logic controller (PLC) implementation of real-time controllers. The methodology uses a black-box approach to profile the target process using HPCs. The time series of HPC measurements over a time window under known-good operating conditions is used to train a machine learning classifier. At run-time, this trained classifier classifies the time series of HPC measurements as baseline (i.e., probabilistically corresponding to a model learned from the training data) or anomalous. The baseline versus anomalous labels over successive time windows offer robustness against the stochastic variability of code execution on the embedded processor and detect code modifications. We demonstrate effectiveness of the approach on an embedded PLC in a hardware-in-the-loop (HITL) testbed emulating a benchmark industrial process. In addition, to illustrate the scalability of the approach, we also apply the methodology to a second PLC platform running a representative embedded control process. Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Stealthy Rootkits in Smart Grid ControllersabstractThis paper presents a stealthy and persistent attack on a Cyber-Physical System (CPS), namely the smart grid and a multi-layer approach to detect such an attack. The attack on the CPS controller uses a rootkit-based malware. When activated, the rootkit overwrites operator commands to the smart grid relays while evading detection by the operator control station. The rootkit sends valid replies to the operator while corrupting the controller operation through a dynamically loaded library, which is hidden by the rootkit. The attack persists even when the controller stops and restarts since the rootkit automatically restarts the process with the malicious library by using a background daemon, which the rootkit hides from user-space tools. Using a high-fidelity simulation of the smart grid CPS, we show that the attack drastically impacts the CPS, especially when the adversary strategically chooses the target relays to attack. We design an ensemble of detectors to detect the attack and uncover its persistence and insertion mechanisms. The detector uses measures such as hardware performance counters (HPCs), change detection in binary signatures, change detection in system calls, and detection of hidden processes and file system entries. Prashanth Krishnamurthy, Hossein Salehghaffari, Shiva Duraisamy, Ramesh Karri, Farshad Khorrami |
ICCD | 5 |
| 2019 | Adaptive Adversarial Videos on Roadside Billboards: Dynamically Modifying Trajectories of Autonomous VehiclesabstractDeep neural networks (DNNs) are being incorporated into various autonomous systems like self-driving cars and robots. However, there is a rising concern about the robustness of these systems because of their susceptibility to adversarial attacks on DNNs. Past research has established that DNNs used for classification and object detection are prone to attacks causing targeted misclassification. In this paper, we show the effectiveness of an adversarial dynamic attack on an end-to-end trained DNN controlling an autonomous vehicle. We launch the attack by installing a billboard on the roadside and displaying videos to approaching vehicles to cause the DNN controller in the vehicle to generate steering commands that cause, for example, unintended lane changes or motion off the road causing accidents. The billboard has an integrated camera estimating the pose of the on-coming vehicle. The approach enables dynamic adversarial perturbation that adapts to the relative pose of the vehicle and uses the dynamics of the vehicle to steer it along adversary-chosen trajectories while being robust to variations in view, lighting, and weather. We demonstrate the effectiveness of the attack on a recently published off-the-shelf end-to-end learning-based autonomous navigation system in a high-fidelity simulator, CARLA (CAR Learning to Act). The proposed approach may also be applied to other systems driven by an end-to-end trained network. Naman Patel, Prashanth Krishnamurthy, Siddharth Garg, Farshad Khorrami |
IROS | 4 |
| 2018 | Adversarial Learning-Based On-Line Anomaly Monitoring for Assured AutonomyabstractThe paper proposes an on-line monitoring framework for continuous real-time safety/security in learning-based control systems (specifically application to a unmanned ground vehicle). We monitor validity of mappings from sensor inputs to actuator commands, controller-focused anomaly detection (CFAM), and from actuator commands to sensor inputs, system-focused anomaly detection (SFAM). CFAM is an image conditioned energy based generative adversarial network (EBGAN) in which the energy based discriminator distinguishes between proper and anomalous actuator commands. SFAM is based on an action condition video prediction framework to detect anomalies between predicted and observed temporal evolution of sensor data. We demonstrate the effectiveness of the approach on our autonomous ground vehicle for indoor environments and on Udacity dataset for outdoor environments. Naman Patel, Apoorva Nandini Saridena, Anna Choromanska, Prashanth Krishnamurthy, Farshad Khorrami |
IROS | 5 |
| 2018 | Optimal Sensor Placement for Monitoring of Spatial NetworksabstractThe problem of optimal placement of sensors for monitoring a spatial network (e.g., a road network with moving ground targets or intruders) is considered in this paper. In particular, the optimization of locations of a set of sensors (that can each obtain measurements in a local region around the sensor location) is considered so as to maximize an overall sensor coverage metric defined over the spatial network. The sensor coverage optimality metric for spatial network coverage is based on a novel formulation of a sensor influence wave based on a spatiotemporal model of the measurement reach of a set of sensors given a spatial network topology, a probabilistic model of target movements on the network, and spatial weight maps that model the relative importance/utility of different locations in the spatial region. The sensor placement optimization is based on an iterative genetic algorithm for the optimization of a scalar metric computed from the spatial integration of the sensor influence wave. The efficacy of the proposed approach is demonstrated through simulation studies for several road network geometries. Note to Practitioners —This paper considers the problem of finding optimal locations for sensors for monitoring a spatial network for moving targets (e.g., a road network with moving ground targets or intruders). Sensor-based monitoring of a spatial region is relevant in a variety of applications (including, in general, such diverse application areas as traffic monitoring in transportation applications, intruder monitoring, surveillance, power systems monitoring, structural health monitoring, etc). This paper offers two primary novel aspects: an optimality metric formulation for target monitoring effectiveness on spatial networks and an iterative genetic algorithm-based method for optimization of the sensor placement configuration. The proposed approach enables addressing of multiple spatial criteria within a unified framework, including the probabilistic characterizations of spatial target movements over the network and the models of relative importance/utility of different locations/areas in the spatial region. Prashanth Krishnamurthy, Farshad Khorrami |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2018 | Process-Aware Covert Channels Using Physical Instrumentation in Cyber-Physical SystemsabstractWe propose using the analog emissions of physical instrumentation (e.g., actuators, sensors, and mechanical structures) in a cyber-physical system (CPS) to send or leak information without impacting the CPS process characteristics. We show that one can use the analog emissions as covert channels to send information to a remote receiver without altering the functioning of the CPS by considering the dynamics of the controller and its closed-loop characteristics. We demonstrate the control-theoretic approach using the Tennessee Eastman (TE) controller benchmark implemented in a hardware-in-the-loop simulator. Two feedback loops (out of 18) in the TE process are implemented on a programmable logic controller (PLC) driving a geared motor. Assuming that a malware has compromised this PLC, we show that the malware can use the acoustic emissions of a motor controlling a valve in a feedback control loop as a covert channel. This secret transmission over the covert acoustic channel can be done without affecting the stability, performance, and signal characteristics of the closed-loop process. An attacker can exfiltrate sensitive information, such as the proprietary gains or the thresholds used in the controller and the system passwords using covert channels. Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, David Paul-Pena, Hossein Salehghaffari |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Emerging (un-)reliability based security threats and mitigations for embedded systems: special sessionabstractThis paper addresses two reliability-based security threats and mitigations for embedded systems namely, aging and thermal side channels. Device aging can be used as a hardware attack vector by using voltage scaling or specially crafted instruction sequences to violate embedded processor guard bands. Short-term aging effects can be utilized to cause transient degradation of the embedded device without leaving any trace of the attack. (Thermal) side channels can be used as an attack vector and as a defense. Specifically, thermal side channels are an effective and secure way to remotely monitor code execution on an embedded processor and/or to possibly leak information. Although various algorithmic means to detect anomaly are available, machine learning tools are effective for anomaly detection. We will show such utilization of deep learning networks in conjunction with thermal side channels to detect code injection/modification representing anomaly. Hussam Amrouch, Prashanth Krishnamurthy, Naman Patel, Jörg Henkel, Ramesh Karri, Farshad Khorrami |
CASES | 6 |
| 2017 | TAINT: Tool for Automated INsertion of TrojansabstractTesting designs implemented in a Field Programmable Gate Array (FPGA) against hardware-based attacks requires one to inject numerous classes of vulnerabilities (e.g., hardware Trojans) into the FPGA based designs. We developed a Tool for Automated INsertion of Trojans (TAINT) providing numerous benefits. First, TAINT can evaluate FPGA based designs against known and unknown attacks. Second, TAINT can insert Trojans at different stages in the FPGA based design cycle such as the Register-Transfer Logic and the post-synthesis translate, map, and route. Moreover, TAINT offers fine-grained controls to a user to precisely insert Trojans in particular FPGA resources. Most importantly, TAINT can automate Trojan Testing. Our experiments will use TAINT to explore the attack spaces at the pre-and post-synthesis stages of a FPGA design. Vinayaka Jyothi, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri |
ICCD | 3 |
| 2017 | Sensor modality fusion with CNNs for UGV autonomous driving in indoor environmentsabstractWe present a novel end-to-end learning framework to enable ground vehicles to autonomously navigate unknown environments by fusing raw pixels from cameras and depth measurements from a LiDAR. A deep neural network architecture is introduced to effectively perform modality fusion and reliably predict steering commands even in the presence of sensor failures. The proposed network is trained on our own dataset, from LiDAR and a camera mounted on a UGV taken in an indoor corridor environment. Comprehensive experimental evaluation to demonstrate the robustness of our network architecture is performed to show that the proposed deep learning neural network is able to autonomously navigate in the corridor environment. Furthermore, we demonstrate that the fusion of the camera and LiDAR modalities provides further benefits beyond robustness to sensor failures. Specifically, the multimodal fused system shows a potential to navigate around static and dynamic obstacles and to handle changes in environment geometry without being trained for these tasks. Naman Patel, Anna Choromanska, Prashanth Krishnamurthy, Farshad Khorrami |
IROS | 4 |
| 2017 | Process-aware side channel monitoring for embedded control system securityabstractCyber-physical systems (CPS) are interconnections of heterogeneous hardware and software components (e.g., sensors, actuators, physical systems/processes, computational nodes and controllers, and communication subsystems). Increasing network connectivity of CPS computational nodes facilitates maintenance and on-demand reprogrammability and reduces operator workload. However, such increasing connectivity also raises the potential for cyber-attacks that attempt unauthorized modifications of run-time parameters or control logic in the computational nodes to hamper process stability or performance. In this paper, we analyze the effectiveness of real-time monitoring using digital and analog side channels. While analog side channels might not typically provide sufficient granularity to observe each iteration of a periodic loop in the code in the CPS device, the temporal averaging inherent to side channel sensory modalities enables observation of persistent changes to the contents of a computational loop through their resulting effect on the level of activity of the device. Changes to code can be detected by observing readings from side channel sensors over a period of time. Experimental studies are performed on an ARM-based single board computer. David Paul-Pena, Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami |
VLSI-SoC | 4 |
| 2016 | Machine learning-based defense against process-aware attacks on Industrial Control SystemsabstractThe modernization of Industrial Control Systems (ICS), primarily targeting increased efficiency and controllability through integration of Information Technologies (IT), introduced the unwanted side effect of extending the ICS cyber-security threat landscape. ICS are facing new security challenges and are exposed to the same vulnerabilities that plague IT, as demonstrated by the increasing number of incidents targeting ICS. Due to the criticality and unique nature of these systems, it is important to devise novel defense mechanisms that incorporate knowledge of the underlying physical model, and can detect attacks in early phases. To this end, we study a benchmark chemical process, and enumerate the various categories of attack vectors and their practical applicability on hardware controllers in a Hardware-In-The-Loop testbed. Leveraging the observed implications of the categorized attacks on the process, as well as the profile of typical disturbances, we follow a data-driven approach to detect anomalies that are early indicators of malicious activity. Anastasis Keliris, Hossein Salehghaffari, Brian R. Cairl, Prashanth Krishnamurthy, Michail Maniatakos, Farshad Khorrami |
ITC | 6 |
| 2015 | Low-profile crawling for humanoid motion in tight spacesabstractWhile humanoid robots and various associated algorithms for gait control and motion planning have been considered in the prior literature, the possibility of utilizing a low-profile crawling gait to operate in tight spaces (e.g., going under obstacles) has not been considered previously and enables new capabilities of the humanoid robot. In this paper, a new gait for humanoid robots is presented that enables humanoid motion in tight spaces that are vertically constrained. The gait is laterally symmetric and utilizes a cooperative motion of both the hands and feet. The addition of this gait expands the set of environments that can be handled by the humanoid robot. The efficacy of the proposed gait is demonstrated experimentally on a NAO humanoid robot. Griswald Brooks, Prashanth Krishnamurthy, Farshad Khorrami |
IROS | 3 |
| 2015 | Trunk stabilization of multi-legged robots using on-line learning via a NARX neural network compensatorabstractThe objective of this work is to achieve disturbance rejection and constant orientation of the trunk of a multi-legged robot. This is significant when payloads (such as cameras, optical systems, armaments) are carried by the robot. In particular, this paper presents an application of an on-line learning method to actively correct the open-loop gait generated by a central pattern generator (CPG) or a limit-cycle method. The learning method employed is based on a Nonlinear Autoregressive Neural Network with Exogenous inputs (NARX-NN)- a recurrent neural network architecture typically utilized for modeling nonlinear difference systems. A supervised learning approach is used to train the NARX-NN. The input to the neural network includes states of the robot legs, trunk attitude and attitude rates, and foot contact forces. The neural network is used to estimate the total torque imparted on the robot. The learned effects of the internal forces and disturbances are then applied in an inverse dynamics/computed torque controller, which is utilized to achieve a stable trunk (i.e., a constant orientation of the trunk). The efficacy of the proposed approach is shown in detailed simulation studies of a quadruped robot. Brian R. Cairl, Farshad Khorrami |
IROS | 2 |
| 2008 | Decentralized Inventory Control for Large-Scale Reverse Supply Chains: A Computationally Tractable ApproachabstractIn this paper, we consider a new inventory control technique for large-scale supply chains including repairs. The part flow is bidirectional with broken parts propagated upstream for repair. It is well known that available optimization techniques for inventory control for bidirectional stochastic supply chains are computationally intractable and also necessitate several simplifying assumptions. In contrast, the proposed approach is an adaptive scheme that scales well to practically interesting large-scale multi-item supply chains. Furthermore, practical issues such as stochastic transport delays, manufacturing times, and repair times and probabilistic characterization of part repair success are handled in a unified framework. The control scheme is based on a hierarchical two-level architecture that comprises an adaptive set point generator and a lower-level order-up-to policy. An application to aircraft supply chains involving multiple original equipment manufacturers (OEMs), depots, bases, squadrons, and planes is also investigated. Prashanth Krishnamurthy, Farshad Khorrami, David A. Schoenwald |
IEEE Trans. Syst. Man Cybern. Part C | 2 |
| 2007 | Control design for unmanned sea surface vehicles: hardware-in-the-loop simulator and experimental resultsabstractWe address the control design problem for stabilization and tracking of unmanned sea surface vehicles (USSVs). To this end, we describe the design and implementation of a high-accuracy real-time six degree-of-freedom (DOF) hardware-in-the-loop (HITL) simulation platform for use in development and evaluation of controllers for USSVs. The HITL platform incorporates a nonlinear dynamic model of the USSV, emulation of sensors and instrumentation onboard the USSV, and the actual hardware and software components used for control of the USSV in the experimental testbed. Detailed models of hydrodynamic effects, actuators including thrusters/propellers and control surfaces, and disturbances including ocean currents, waves, and wind are included in the dynamic simulation. The fidelity of the developed HITL simulator is demonstrated through comparisons with experimental data collected from a USSV. We also propose a nonlinear backstepping-based controller for stabilization and tracking for USSVs and present closed-loop results from HITL simulation and experimental testing. Prashanth Krishnamurthy, Farshad Khorrami, Tzer Leei Ng |
IROS | 2 |
| 2003 | TriM: an ultra-accurate high-speed six degree-of-freedom manipulator using linear motorsabstractIn this paper, we propose a novel six degree-of-freedom positioning system. This device is a tripod structure with inextensible limbs actuated at the base by two dimensional linear stepper motors (although other types of actuators may be utilized). The kinematics (both the direct and the inverse kinematics) and dynamics are presented in detail. The dynamics of the actuators (Sawyer motors) are also included in the dynamic modeling. We also carry out a kinematic optimization of the system parameters to maximize the manipulator workspace. The proposed manipulator achieves large range of motion in all the six degrees of freedom. Furthermore, high resolution and high speed motion may be achieved in all axes. Prashanth Krishnamurthy, Farshad Khorrami |
IROS | 2 |
| 1999 | Closed-Loop Control of a Base XY Stage with Rotational Degree-of-Freedom for a High-Speed Ultra-Accurate Manufacturing SystemabstractModeling and control of a high-speed ultra-accurate XY stage used in manufacturing systems is considered in this paper. The base XY stage is a two dimensional linear stepper (Sawyer) motor including a rotational (yaw) degree-of-freedom. Manufacturing systems based on Sawyer motors are widely used in wafer probing applications and in automated assembly. A Sawyer sensor is being integrated for measuring the motor's position, velocity and yaw rotation for closed-loop control purposes on our testbed at the CRRL. Utilizing results on robust control of nonlinear systems, an adaptive current-level controller is designed for the motor that renders the closed-loop system robust to a variety of uncertainties and disturbances. A detailed model of the motor that takes into account the significant uncertainties of the motor is used in the control design. The tracking error is shown to asymptotically converge to the origin. Simulation studies are presented to validate the controller performance. Hemant Melkote, Farshad Khorrami |
ICRA | 2 |
| 1994 | Vibration Suppression of Unknown Flexible Payloads Using a Wrist Mounted Force/Torque Sensor for Remote Manipulator SystemsabstractThe problem of control design for robotic arms manipulating unknown flexible payloads is considered. Control design based on neglecting the internal dynamics of the payload will result in degraded performance, increased task execution time, and even failure in performing tasks. At the same time, the characteristics of payloads to be handled vary with application. These considerations make it impractical to outfit the payload with sensors. A novel scheme utilizing a force/torque sensor at the wrist of the manipulator is introduced. A controller utilizing the wrist torque feedback from the sensor is designed as a function of parameters of the payload dynamics. An adaptive scheme for online identification of these parameters and adaptation of controller parameters is discussed. The scheme is implemented on a single-link manipulator carrying a flexible unknown payload. Experimental results validate the fact that the adaptive control maintains a robust performance for high speed slewing and varying payloads.> Sandeep Jain, Farshad Khorrami |
ICRA | 2 |
| 1994 | Utilization of Torque Wheels for Active Damping of Flexible ManipulatorsabstractUtilization of inertial actuators, such as torque wheels, for vibration damping of a single-link flexible manipulator is considered. The torque wheel is mounted at the end effector of the manipulator to provide a bending moment at the tip for vibration suppression and pointing purposes. The torque exerted by the torque wheel at the end-effector of the manipulator is achieved through controlling the velocity of the torque wheel. A decentralized control scheme is advocated in this paper for slewing and vibration suppression. The local loop around the torque wheel is closed through feedback of the accelerometer signal at the tip. Experimental results are provided to show the effectiveness of the proposed method for end-effector positioning of flexible-link manipulators. Although the experimental results reported are for a single-link flexible manipulator, the results are applicable to the multi-link case. It may be shown that the dynamics from the voltage input to the torque wheel mounted at the tip to the tip position is minimum phase and hence invertible given that an inner-loop controller has been applied to stabilize the rigid-body motion.> Farshad Khorrami, Alexander A. Gomez, Matthew Hills |
ICRA | 1 |
| 1994 | Fuzzy Based Adaptive Control for Flexible-Link Manipulators Actuated by PiezoceramicsabstractThis paper presents an adaptive control scheme based on a fuzzy logic algorithm and its application to end-effector positioning of flexible-link manipulators. Here, a fuzzy based adaptive controller is considered due to its simplicity and the fact that it does not require expressing the controller in terms of the system parameters, as it is necessary in the case of self-tuning regulators. This controller is based on a functional fuzzy model where the consequents are crisp functions represent controllers designed for different operating regimes. The premise is constituted by the fuzzy subsets corresponding to the process parameters estimated in real time. The effectiveness of this new scheme is verified on a clamped free beam and a single-line flexible arm instrumented with piezoceramic sensors and actuators. It is shown that robust performance may be achieved in face of large parameter variations.> Issam Zeinoun, Farshad Khorrami |
ICRA | 2 |
| 1994 | Experiments on rigid body-based controllers with input preshaping for a two-link flexible manipulatorabstractDynamics of multi-link flexible manipulators are highly nonlinear. Furthermore, the vibrational frequencies of these manipulators are configuration-dependent. Therefore, any feedforward or feedback algorithm has to deal with these frequency variations. In this paper, an inner-loop nonlinear controller based on feedback linearization of O(1) dynamics derived from an asymptotic expansion is utilized. It is shown that this control scheme significantly reduces the frequency variations due to the geometric configuration of the arm and cancels some of the nonlinearities due to Coriolis and centripetal effects. The advocated control law is compared and contrasted to an independent joint-based PD controller. However, since the aforementioned controllers are joint-based control schemes, significant vibrations are still induced at the end-effector. To this end, these control schemes are augmented with an input preshaper for vibration suppression. The objective is to preshape the reference input signals so that a vibration free output is achieved. The input preshaping scheme is shown to be effective when the plant dynamics are linear and time-invariant. These assumptions do not hold for the multi-link flexible manipulators as alluded to above. Application of an inner-loop nonlinear control to cancel some of the nonlinearities and to reduce configuration dependence of structural frequencies enhances the performance of the advocated input preshaping scheme or any other outer-loop linear control design. Experimental and simulation results for a two-link flexible manipulator are provided to validate the effectiveness of the advocated controllers.> Farshad Khorrami, Sandeep Jain, Anthony Tzes |
IEEE Trans. Robotics Autom. | 1 |
| 1992 | Experimental results on an inner/outer loop controller for a two-link flexible manipulatorabstractExperimental results for end-point positioning of multilink flexible manipulators are considered. This control strategy has been implemented on an experimental test-bed developed in the authors' Laboratory. The advocated approach is based on a two-stage control design. The first stage is an inner-loop nonlinear-based controller corresponding to the rigid body motion of the manipulator. The second stage is an outer control loop based on linear output LQR design. The outer-loop control design results in a nonconvex nonlinear optimization problem. A software package has been developed to solve this problem. The outer-loop controller enhances vibration damping and robustness of the closed-loop dynamics to parameter variations. The measurement utilized for vibration suppression is through an accelerometer attached at the end point of the manipulator.> Farshad Khorrami, Sandeep Jain |
ICRA | 1 |
| 1989 | A comparison of multiple time-scale analysis and overlapping decompositionsabstractTwo-level hierarchical systems are considered, and two different design methodologies, multiple-time-scale analysis and overlapping decompositions, are compared. The comparison is based on quadratic performance indices. It is demonstrated that, in general, the multiple-time-scale approach, produces better results whenever the time-scale parameter is small. However, the overlapping decompositions approach usually yields better controller designs as the time-scale parameter gets larger. An example of a mass-spring system is presented to illustrate the practical applications of the theoretical details discussed.> Altug Iftar, Farshad Khorrami |
IEEE Trans. Syst. Man Cybern. | 2 |
| 1988 | Perturbation methods in control of flexible link manipulatorsabstractThe resolution of the dynamics of flexible manipulators into rigid and flexible modes is considered. The decoupling is established on the single-link case by singular perturbation techniques. The flexural effects of the manipulator on its rigid-body motion are included by using the higher-order terms in the asymptotic expansion. The model used is the integro-partial-differential equation resulting from the extended Hamiltonian principle. Use of this model, rather than a finite-dimensional approximation, yields more insight and a more compact way of obtaining the higher-order terms that represent the coupling between the rigid and the flexure modes. Asymptotic perturbation techniques are utilized to generate a composite control law.> Farshad Khorrami, Ümit Özgüner |
ICRA | 1 |
| 1988 | Decentralized control of robot manipulators via state and proportional-integral feedbackabstractAsymptotic regulation to a constant set-point by state feedback, and PI (proportional integral) control is considered for n-link multibody systems. Global asymptotic stability of these regulators is shown using Lyapunov's direct methods. The main contribution is the exclusion of explicit gravity cancellation. The implication of the above is the ensuing robustness of the controllers to parameter and payload variations. Furthermore, it is shown that the controllers can be implemented in a decentralized manner at each joint despite the nonlinear interconnections among the joints.> Farshad Khorrami, Ümit Özgüner |
ICRA | 1 |