VLDB 2026 Research / reviewers in the wild / expert
Atul Prakash 0001
dblp:p/AtulPrakash
· DBLP profile ↗
87ranked-venue papers
5as first author
18since 2021 · last 2026
0000-0002-4907-3687ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 5 since 2021Artificial intelligence and machine learning · 15 · 11 since 2021Human-computer interaction and ubiquitous computing · 13 · 3 first-authorSoftware engineering, systems software and programming languages · 12Systems, architecture and hardware · 7 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 7 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Taming Data Challenges in ML-based Security Tasks Using Generative AIabstractMachine learning-based supervised classifiers are widely used for security tasks, and their improvement has been largely focused on algorithmic advancements. Data challenges that negatively impact the performance of these classifiers have received limited attention. We address the following research question: Can developments in Generative AI (GenAI) address data challenges and improve classifier performance? We propose augmenting training datasets with synthetic data generated using GenAI techniques to improve classifier generalization. We evaluate this approach across 7 diverse security tasks using 6 state-of-the-art GenAI methods and introduce a novel GenAI scheme called Nimai that enables highly controlled data synthesis. We find that GenAI techniques can significantly improve the performance of security classifiers, achieving improvements of up to 32.6% even in severely data-constrained settings (only ~180 training samples). Furthermore, we demonstrate that GenAI can facilitate rapid adaptation to concept drift post-deployment, requiring minimal labeling in the adjustment process. Despite successes, our study finds that some GenAI schemes struggle to initialize (train and produce data) on certain security tasks. We also identify characteristics of specific tasks, such as noisy labels, overlapping class distributions, and sparse feature vectors, which hinder performance boost using GenAI. We believe that our study will drive the development of future GenAI tools designed for security tasks. Shravya Kanchi, Neal Mangaokar, Aravind Cheruvu, Sifat Muhammad Abdullah, Shirin Nilizadeh, Atul Prakash 0001, Bimal Viswanath |
AsiaCCS | 6 |
| 2025 | ELFS: Label-Free Coreset Selection with Proxy Training DynamicsabstractHigh-quality human-annotated data is crucial for modern deep learning pipelines, yet the human annotation process is both costly and time-consuming. Given a constrained human labeling budget, selecting an informative and representative data subset for labeling can significantly reduce human annotation effort. Well-performing state-of-the-art (SOTA) coreset selection methods require ground truth labels over the whole dataset, failing to reduce the human labeling burden. Meanwhile, SOTA label-free coreset selection methods deliver inferior performance due to poor geometry-based difficulty scores. In this paper, we introduce ELFS (Effective Label-Free Coreset Selection), a novel label-free coreset selection method. ELFS significantly improves label-free coreset selection by addressing two challenges: 1) ELFS utilizes deep clustering to estimate training dynamics-based data difficulty scores without ground truth labels; 2) Pseudo-labels introduce a distribution shift in the data difficulty scores, and we propose a simple but effective double-end pruning method to mitigate bias on calculated scores. We evaluate ELFS on four vision benchmarks and show that, given the same vision encoder, ELFS consistently outperforms SOTA label-free baselines. For instance, when using SwAV as the encoder, ELFS outperforms D2 by up to 10.2% in accuracy on ImageNet-1K. We make our code publicly available on GitHub. Haizhong Zheng, Elisa Tsai, Yifu Lu, Brian R. Bartoldson, Bhavya Kailkhura, Atul Prakash 0001 |
ICLR | 7 |
| 2025 | Test-Time Canonicalization by Foundation Models for Robust PerceptionabstractPerception in the real world requires robustness to diverse viewing conditions. Existing approaches often rely on specialized architectures or training with predefined data augmentations, limiting adaptability. Taking inspiration from mental rotation in human vision, we propose FoCal, a test-time robustness framework that transforms the input into the most typical view. At inference time, FoCal explores a set of transformed images and chooses the one with the highest likelihood under foundation model priors. This test-time optimization boosts robustness while requiring no retraining or architectural changes. Applied to models like CLIP and SAM, it significantly boosts robustness across a wide range of transformations, including 2D and 3D rotations, contrast and lighting shifts, and day-night changes. We also explore potential applications in active vision. By reframing invariance as a test-time optimization problem, FoCal offers a general and scalable approach to robustness. Our code is available at: https://github.com/sutkarsh/focal . Utkarsh Singhal, Ryan Feng, Stella X. Yu, Atul Prakash 0001 |
ICML | 4 |
| 2025 | What Really is a Member? Discrediting Membership Inference via PoisoningabstractMembership inference tests aim to determine whether a particular data point was included in a language model's training set. However, recent works have shown that such tests often fail under the strict definition of membership based on exact matching, and have suggested relaxing this definition to include semantic neighbors as members as well. In this work, we show that membership inference tests are still *unreliable* under this relaxation - it is possible to poison the training dataset in a way that causes the test to produce incorrect predictions for a target point. We theoretically reveal a trade-off between a test’s accuracy and its robustness to poisoning. We also present a concrete instantiation of this poisoning attack and empirically validate its effectiveness. Our results show that it can degrade the performance of existing tests to well below random. Neal Mangaokar, Ashish Hooda, Bradley A. Malin, Kassem Fawaz, Somesh Jha, Atul Prakash 0001, Amrita Roy Chowdhury 0001 |
NeurIPS | 7 |
| 2025 | Harmful Terms and Where to Find Them: Measuring and Modeling Unfavorable Financial Terms and Conditions in Shopping Websites at ScaleabstractTerms and conditions for online shopping websites often contain terms that can have significant financial consequences for customers. Despite their impact, there is currently no comprehensive understanding of the types and potential risks associated with unfavorable financial terms. Furthermore, there are no publicly available detection systems or datasets to systematically identify or mitigate these terms. In this paper, we take the first steps toward solving this problem with three key contributions. Elisa Tsai, Neal Mangaokar, Boyuan Zheng 0002, Haizhong Zheng, Atul Prakash 0001 |
WWW | 5 |
| 2024 | PRP: Propagating Universal Perturbations to Attack Large Language Model Guard-RailsabstractNeal Mangaokar, Ashish Hooda, Jihye Choi, Shreyas Chandrashekaran, Kassem Fawaz, Somesh Jha, Atul Prakash. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Neal Mangaokar, Ashish Hooda, Jihye Choi, Shreyas Chandrashekaran, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
ACL (1) | 7 |
| 2024 | Leveraging Hierarchical Feature Sharing for Efficient Dataset Condensation
Haizhong Zheng, Shutong Wu, Bhavya Kailkhura, Z. Morley Mao, Chaowei Xiao, Atul Prakash 0001 |
ECCV (24) | 7 |
| 2024 | CALICO: Self-Supervised Camera-LiDAR Contrastive Pre-training for BEV PerceptionabstractPerception is crucial in the realm of autonomous driving systems, where bird's eye view (BEV)-based architectures have recently reached state-of-the-art performance. The desirability of self-supervised representation learning stems from the expensive and laborious process of annotating 2D and 3D data. Although previous research has investigated pretraining methods for both LiDAR and camera-based 3D object detection, a unified pretraining framework for multimodal BEV perception is missing. In this study, we introduce CALICO, a novel framework that applies contrastive objectives to both LiDAR and camera backbones. Specifically, CALICO incorporates two stages: point-region contrast (PRC) and region-aware distillation (RAD). PRC better balances the region- and scene-level representation learning on the LiDAR modality and offers significant performance improvement compared to existing methods. RAD effectively achieves contrastive distillation on our self-trained teacher model. CALICO's efficacy is substantiated by extensive evaluations on 3D object detection and BEV map segmentation tasks, where it delivers significant performance improvements. Notably, CALICO outperforms the baseline method by 10.5\% and 8.6\% on NDS and mAP. Moreover, CALICO boosts the robustness of multimodal 3D object detection against adversarial attacks and corruption. Additionally, our framework can be tailored to different backbones and heads, positioning it as a promising approach for multimodal BEV perception. Haizhong Zheng, Qingzhao Zhang 0001, Atul Prakash 0001, Z. Morley Mao, Chaowei Xiao |
ICLR | 4 |
| 2024 | Modeling and Detecting Internet Censorship Events
Elisa Tsai, Ram Sundara Raman, Atul Prakash 0001, Roya Ensafi |
NDSS | 3 |
| 2024 | Learn To be Efficient: Build Structured Sparsity in Large Language ModelsabstractLarge Language Models (LLMs) have achieved remarkable success with their billion-level parameters, yet they incur high inference overheads. The emergence of activation sparsity in LLMs provides a natural approach to reduce this cost by involving only parts of the parameters for inference. However, existing methods only focus on utilizing this naturally formed activation sparsity in a post-training setting, overlooking the potential for further amplifying this inherent sparsity. In this paper, we hypothesize that LLMs can learn to be efficient by achieving more structured activation sparsity. To achieve this, we introduce a novel training algorithm, Learn-To-be-Efficient (LTE), designed to train efficiency-aware LLMs to learn to activate fewer neurons and achieve a better trade-off between sparsity and performance. Furthermore, unlike SOTA MoEfication methods, which mainly focus on ReLU-based models, LTE can also be applied to LLMs like LLaMA using non-ReLU activations. Extensive evaluation on language understanding, language generation, and instruction tuning tasks show that LTE consistently outperforms SOTA baselines. Along with our hardware-aware custom kernel implementation, LTE reduces LLaMA2-7B inference latency by 25% at 50% sparsity. Haizhong Zheng, Xiaoyan Bai, Xueshen Liu, Z. Morley Mao, Beidi Chen, Fan Lai 0001, Atul Prakash 0001 |
NeurIPS | 7 |
| 2024 | D4: Detection of Adversarial Diffusion Deepfakes Using Disjoint EnsemblesabstractDetecting diffusion-generated deepfake images remains an open problem. Current detection methods fail against an adversary who adds imperceptible adversarial perturbations to the deepfake to evade detection. In this work, we propose Disjoint Diffusion Deepfake Detection (D4), a deepfake detector designed to improve black-box adversarial robustness beyond de facto solutions such as adversarial training. D4 uses an ensemble of models over disjoint subsets of the frequency spectrum to significantly improve adversarial robustness. Our key insight is to leverage a redundancy in the frequency domain and apply a saliency partitioning technique to disjointly distribute frequency components across multiple models. We formally prove that these disjoint ensembles lead to a reduction in the dimensionality of the input subspace where adversarial deepfakes lie, thereby making adversarial deepfakes harder to find for black-box attacks. We then empirically validate the D4 method against several black-box attacks and find that D4 significantly outperforms existing state-of-the-art defenses applied to diffusion-generated deepfake detection. We also demonstrate that D4 provides robustness against adversarial deepfakes from unseen data distributions as well as unseen generative techniques. Ashish Hooda, Neal Mangaokar, Ryan Feng, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
WACV | 6 |
| 2023 | Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box AttacksabstractRecent work has proposed stateful defense models (SDMs) as a compelling strategy to defend against a black-box attacker who only has query access to the model, as is common for online machine learning platforms. Such stateful defenses aim to defend against black-box attacks by tracking the query history and detecting and rejecting queries that are "similar" and thus preventing black-box attacks from finding useful gradients and making progress towards finding adversarial attacks within a reasonable query budget. Recent SDMs (e.g., Blacklight and PIHA) have shown remarkable success in defending against state-of-the-art black-box attacks. In this paper, we show that SDMs are highly vulnerable to a new class of adaptive black-box attacks. We propose a novel adaptive black-box attack strategy called Oracle-guided Adaptive Rejection Sampling (OARS) that involves two stages: (1) use initial query patterns to infer key properties about an SDM's defense; and, (2) leverage those extracted properties to design subsequent query patterns to evade the SDM's defense while making progress towards finding adversarial inputs. OARS is broadly applicable as an enhancement to existing black-box attacks - we show how to apply the strategy to enhance six common black-box attacks to be more effective against current class of SDMs. For example, OARS-enhanced versions of black-box attacks improved attack success rate against recent stateful defenses from almost 0% to to almost 100% for multiple datasets within reasonable query budgets. Ryan Feng, Ashish Hooda, Neal Mangaokar, Kassem Fawaz, Somesh Jha, Atul Prakash 0001 |
CCS | 6 |
| 2023 | Coverage-centric Coreset Selection for High Pruning Rates
Haizhong Zheng, Fan Lai 0001, Atul Prakash 0001 |
ICLR | 4 |
| 2023 | Concept-based Explanations for Out-of-Distribution DetectorsabstractOut-of-distribution (OOD) detection plays a crucial role in ensuring the safe deployment of deep neural network (DNN) classifiers. While a myriad of methods have focused on improving the performance of OOD detectors, a critical gap remains in interpreting their decisions. We help bridge this gap by providing explanations for OOD detectors based on learned high-level concepts. We first propose two new metrics for assessing the effectiveness of a particular set of concepts for explaining OOD detectors: 1) detection completeness, which quantifies the sufficiency of concepts for explaining an OOD-detector's decisions, and 2) concept separability, which captures the distributional separation between in-distribution and OOD data in the concept space. Based on these metrics, we propose an unsupervised framework for learning a set of concepts that satisfy the desired properties of high detection completeness and concept separability, and demonstrate its effectiveness in providing concept-based explanations for diverse off-the-shelf OOD detectors. We also show how to identify prominent concepts contributing to the detection results, and provide further reasoning about their decisions. Jihye Choi, Jayaram Raghuram, Ryan Feng, Jiefeng Chen 0001, Somesh Jha, Atul Prakash 0001 |
ICML | 6 |
| 2022 | GRAPHITE: Generating Automatic Physical Examples for Machine-Learning Attacks on Computer Vision SystemsabstractThis paper investigates an adversary's ease of attack in generating adversarial examples for real-world scenarios. We address three key requirements for practical attacks for the real-world: 1) automatically constraining the size and shape of the attack so it can be applied with stickers, 2) transform-robustness, i.e., robustness of a attack to environmental physical variations such as viewpoint and lighting changes, and 3) supporting attacks in not only white-box, but also black-box hard-label scenarios, so that the adversary can attack proprietary models. In this work, we propose GRAPHITE, an efficient and general framework for generating attacks that satisfy the above three key requirements. GRAPHITE takes advantage of transform-robustness, a metric based on expectation over transforms (EoT), to automatically generate small masks and optimize with gradient-free optimization. GRAPHITE is also flexible as it can easily trade-off transform-robustness, perturbation size, and query count in black-box settings. On a GTSRB model in a hard-label black-box setting, we are able to find attacks on all possible 1,806 victim-target class pairs with averages of 77.8% transform-robustness, perturbation size of 16.63% of the victim images, and 126K queries per pair. For digital-only attacks where achieving transform-robustness is not a requirement, GRAPHITE is able to find successful small-patch attacks with an average of only 566 queries for 92.2% of victim-target pairs. GRAPHITE is also able to find successful attacks using perturbations that modify small areas of the input image against PatchGuard, a recently proposed defense against patch-based attacks. Ryan Feng, Neal Mangaokar, Jiefeng Chen 0001, Earlence Fernandes, Somesh Jha, Atul Prakash 0001 |
EuroS&P | 6 |
| 2022 | A Large-scale Investigation into Geodifferences in Mobile Apps
Renuka Kumar, Apurva Virkud, Ram Sundara Raman, Atul Prakash 0001, Roya Ensafi |
USENIX Security Symposium | 4 |
| 2021 | MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient EstimationabstractHigh quality Machine Learning (ML) models are often considered valuable intellectual property by companies. Model Stealing (MS) attacks allow an adversary with blackbox access to a ML model to replicate its functionality by training a clone model using the predictions of the target model for different inputs. However, best available existing MS attacks fail to produce a high-accuracy clone without access to the target dataset or a representative dataset necessary to query the target model. In this paper, we show that preventing access to the target dataset is not an adequate defense to protect a model. We propose MAZE – a data-free model stealing attack using zeroth-order gradient estimation that produces high-accuracy clones. In contrast to prior works, MAZE uses only synthetic data created using a generative model to perform MS.Our evaluation with four image classification models shows that MAZE provides a normalized clone accuracy in the range of 0.90× to 0.99×, and outperforms even the recent attacks that rely on partial data (JBDA, clone accuracy 0.13× to 0.69×) and on surrogate data (KnockoffNets, clone accuracy 0.52× to 0.97×). We also study an extension of MAZE in the partial-data setting, and develop MAZE-PD, which generates synthetic data closer to the target distribution. MAZE-PD further improves the clone accuracy (0.97× to 1.0×) and reduces the query budget required for the attack by 2×-24×. Sanjay Kariyappa, Atul Prakash 0001, Moinuddin K. Qureshi |
CVPR | 2 |
| 2021 | Protecting DNNs from Theft using an Ensemble of Diverse Models
Sanjay Kariyappa, Atul Prakash 0001, Moinuddin K. Qureshi |
ICLR | 2 |
| 2020 | Efficient Adversarial Training With Transferable Adversarial ExamplesabstractAdversarial training is an effective defense method to protect classification models against adversarial attacks. However, one limitation of this approach is that it can require orders of magnitude additional training time due to high cost of generating strong adversarial examples during training. In this paper, we first show that there is high transferability between models from neighboring epochs in the same training process, i.e., adversarial examples from one epoch continue to be adversarial in subsequent epochs. Leveraging this property, we propose a novel method, Adversarial Training with Transferable Adversarial Examples (ATTA), that can enhance the robustness of trained models and greatly improve the training efficiency by accumulating adversarial perturbations through epochs. Compared to state-of-the-art adversarial training methods, ATTA enhances adversarial accuracy by up to 7.2% on CIFAR10 and requires 12~14x less training time on MNIST and CIFAR10 datasets with comparable model robustness. Haizhong Zheng, Ziqi Zhang 0004, Juncheng Gu, Honglak Lee, Atul Prakash 0001 |
CVPR | 5 |
| 2020 | Security Analysis of Unified Payments Interface and Payment Apps in India
Renuka Kumar, Sreesh Kishore, Atul Prakash 0001 |
USENIX Security Symposium | 4 |
| 2018 | Robust Physical-World Attacks on Deep Learning Visual ClassificationabstractRecent studies show that the state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples, resulting from small-magnitude perturbations added to the input. Given that that emerging physical systems are using DNNs in safety-critical situations, adversarial examples could mislead these systems and cause dangerous situations. Therefore, understanding adversarial examples in the physical world is an important step towards developing resilient learning algorithms. We propose a general attack algorithm, Robust Physical Perturbations (RP2), to generate robust visual adversarial perturbations under different physical conditions. Using the real-world case of road sign classification, we show that adversarial examples generated using RP2 achieve high targeted misclassification rates against standard-architecture road sign classifiers in the physical world under various environmental conditions, including viewpoints. Due to the current lack of a standardized testing method, we propose a two-stage evaluation methodology for robust physical adversarial examples consisting of lab and field tests. Using this methodology, we evaluate the efficacy of physical adversarial manipulations on real objects. With a perturbation in the form of only black and white stickers, we attack a real stop sign, causing targeted misclassification in 100% of the images obtained in lab settings, and in 84.8% of the captured video frames obtained on a moving vehicle (field test) for the target classifier. Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li 0026, Amir Rahmati, Chaowei Xiao, Atul Prakash 0001, Tadayoshi Kohno, Dawn Song |
CVPR | 7 |
| 2018 | Decentralized Action Integrity for Trigger-Action IoT Platforms
Earlence Fernandes, Amir Rahmati, Jaeyeon Jung, Atul Prakash 0001 |
NDSS | 4 |
| 2017 | Heimdall: A Privacy-Respecting Implicit Preference Collection FrameworkabstractMany of the everyday decisions a user makes rely on the suggestions of online recommendation systems. These systems amass implicit (e.g.,location, purchase history, browsing history) and explicit (e.g.,reviews, ratings) feedback from multiple users, produce a general consensus, and provide suggestions based on that consensus. However, due to privacy concerns, users are uncomfortable with implicit data collection, thus requiring recommendation systems to be overly dependent on explicit feedback. Unfortunately, users do not frequently provide explicit feedback. This hampers the ability of recommendation systems to provide high-quality suggestions. We introduce Heimdall, the first privacy-respecting implicit preference collection framework that enables recommendation systems to extract user preferences from their activities in a privacy respecting manner. The key insight is to enable recommendation systems to run a collector on a user's device and precisely control the information a collector transmits to the recommendation system back-end. Heimdall introduces immutable blobs as a mechanism to guarantee this property. We implemented Heimdall on the Android platform and wrote three example collectors to enhance recommendation systems with implicit feedback. Our performance results suggest that the overhead of immutable blobs is minimal, and a user study of 166 participants indicates that privacy concerns are significantly less when collectors record only specific information--a property that Heimdall enables. Amir Rahmati, Earlence Fernandes, Kevin Eykholt, Xinheng Chen, Atul Prakash 0001 |
MobiSys | 5 |
| 2017 | ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
Yunhan Jia, Qi Alfred Chen, Shiqi Wang 0002, Amir Rahmati, Earlence Fernandes, Z. Morley Mao, Atul Prakash 0001 |
NDSS | 7 |
| 2017 | Ensuring Authorized Updates in Multi-user Database-Backed Applications
Kevin Eykholt, Atul Prakash 0001, Barzan Mozafari |
USENIX Security Symposium | 2 |
| 2016 | Security Analysis of Emerging Smart Home ApplicationsabstractRecently, several competing smart home programming frameworks that support third party app development have emerged. These frameworks provide tangible benefits to users, but can also expose users to significant security risks. This paper presents the first in-depth empirical security analysis of one such emerging smart home programming platform. We analyzed Samsung-owned SmartThings, which has the largest number of apps among currently available smart home platforms, and supports a broad range of devices including motion sensors, fire alarms, and door locks. SmartThings hosts the application runtime on a proprietary, closed-source cloud backend, making scrutiny challenging. We overcame the challenge with a static source code analysis of 499 SmartThings apps (called SmartApps) and 132 device handlers, and carefully crafted test cases that revealed many undocumented features of the platform. Our key findings are twofold. First, although SmartThings implements a privilege separation model, we discovered two intrinsic design flaws that lead to significant overprivilege in SmartApps. Our analysis reveals that over 55% of SmartApps in the store are overprivileged due to the capabilities being too coarse-grained. Moreover, once installed, a SmartApp is granted full access to a device even if it specifies needing only limited access to the device. Second, the SmartThings event subsystem, which devices use to communicate asynchronously with SmartApps via events, does not sufficiently protect events that carry sensitive information such as lock codes. We exploited framework design flaws to construct four proof-of-concept attacks that: (1) secretly planted door lock codes, (2) stole existing door lock codes, (3) disabled vacation mode of the home, and (4) induced a fake fire alarm. We conclude the paper with security lessons for the design of emerging smart home programming frameworks. Earlence Fernandes, Jaeyeon Jung, Atul Prakash 0001 |
IEEE Symposium on Security and Privacy | 3 |
| 2016 | FlowFence: Practical Data Protection for Emerging IoT Application Frameworks
Earlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato, Mauro Conti, Atul Prakash 0001 |
USENIX Security Symposium | 6 |
| 2015 | Decomposable Trust for Android ApplicationsabstractCurrent operating system designs require applications (apps) to implicitly place trust in a large amount of code. Taking Android as an example, apps must trust both the kernel as well as privileged userspace services that consist of hundreds of thousands of lines of code. Malware apps, on the other hand, aim to exploit any vulnerabilities in the above large trusted base to escalate their privileges. Once malware escalates its privileges, additional attacks become feasible, such as stealing credentials by scanning memory pages or intercepting user interactions of sensitive apps, e.g., those used for banking or health management. This paper introduces a novel mechanism, called Anception, that strategically deprivileges a significant portion of the kernel and system services, moving them to an untrusted container, thereby significantly reducing the attack surface for privilege escalation available to malware. Anception supports unmodified apps, running on a modified Android kernel. It achieves performance close to native Android on several popular macro benchmarks and provides security against many types of known Android root exploits. Earlence Fernandes, Ajit Aluri, Alexander Crowell, Atul Prakash 0001 |
DSN | 4 |
| 2015 | Practical Always-on Taint Tracking on Mobile Devices
Justin Paupore, Earlence Fernandes, Atul Prakash 0001, Sankardas Roy, Xinming Ou |
HotOS | 3 |
| 2013 | Expose: Discovering Potential Binary Code Re-useabstractThe use of third-party libraries in deployed applications can potentially put an organization's intellectual property at risk due to licensing restrictions requiring disclosure or distribution of the resulting software. Binary applications that are statically linked to buggy version(s) of a library can also provide malware with entry points into an organization. While many organizations have policies to restrict the use of third-party software in applications, determining whether an application uses a restricted library can be difficult when it is distributed as binary code. Compiler optimizations, function inlining, and lack of symbols in binary code make the task challenging for automated techniques. On the other hand, semantic analysis techniques are relatively slow. Given a library and a set of binary applications, we propose Expose, a tool that combines symbolic execution using a theorem prover, and function-level syntactic matching techniques to achieve both performance and high quality rankings of applications. Higher rankings indicate a higher likelihood of re-using the library's code. Expose ranked applications that used two libraries at or near the top, out of 2,927 and 128 applications respectively. Expose detected one application that was not detected by another scanner to use some functions in one of the libraries. In addition, Expose ranked applications correctly for different versions of a library, and when different compiler options were used. Expose analyzed 97.68% and 99.48% of the applications within five and 10 minutes respectively. Beng Heng Ng, Atul Prakash 0001 |
COMPSAC | 2 |
| 2012 | Adaptive semi-private email aliasesabstractControlling spam remains a significant challenge. One primary cause of the spam problem is the way in which email addresses are typically used. To provide a fixed address at which they can be reached, most users treat their email IDs as permanent and only abandon them in rare circumstances. As a result, once a user's email address leaks to spammers, it is nearly impossible to entirely prevent them from sending messages to the user's inbox. Users usually has no recourse if they wish to retract the release of an email address to a certain party. Beng Heng Ng, Alexander Crowell, Atul Prakash 0001 |
AsiaCCS | 3 |
| 2011 | Distilling critical attack graph surface iteratively through minimum-cost SAT solvingabstractIt has long been recognized that it can be tedious and even infeasible for system administrators to figure out critical security problems residing in full attack graphs, even for small-sized enterprise networks. Therefore a trade-off between analysis accuracy and efficiency needs to be made to achieve a reasonable balance between completeness of the attack graph and its usefulness. In this paper, we provide an approach to attack graph distillation, so that the user can control the amount of information presented by sifting out the most critical portion of the full attack graph. The user can choose to see only the k most critical attack paths, based on specified severity metrics, e.g. the likelihood for an attacker to carry out certain exploit on certain machine and the chance of success. We transform an dependency attack graph into a Boolean formula and assign cost metrics to attack variables in the formula, based on the severity metrics. We then apply Minimum-Cost SAT Solving (MCSS) to find the most critical path in terms of the least cost incurred for the attacker to deploy multi-step attacks leading to certain crucial assets in the network. An iterative process inspired by Counter Example Guided Abstraction and Refinement (CEGAR) is designed to efficiently guide the MCSS to render solutions that contain a controlled number of realistic attack paths, forming a critical attack graph surface. Our method can distill critical attack graph surfaces from the full attack graphs generated for moderate-sized enterprise networks in only several minutes. Experiments on various sized network scenarios show that even for a small-sized critical attack graph surface (around 15% the size of the original full attack graph), the calculated risk metrics are good approximation of the values computed with the full attack graph, meaning the distilled critical attack graph surface is able to capture the crucial security problems in an enterprise network for further in-depth analysis. Xinming Ou, Atul Prakash 0001, Karem A. Sakallah |
ACSAC | 4 |
| 2010 | Fighting Phishing with Trusted EmailabstractPhishing is the combination of social engineering and technical exploits designed to convince a victim to provide personal information, usually for the monetary gain of the attacker (phisher). Attempts to stop phishing by preventing a user from interacting with a malicious web site have shown to be ineffective. We introduce a method to aid in the prevention of phishing by combining automatic and transparent email signing with an email client plugin. The plugin can detect unsigned spoofed messages. In this manner, the user is prevented (or at least discouraged) from visiting malicious web sites, thus stopping the data-gathering phase of the phishing attack before it begins. We describe the system, implementation, weaknesses, and our ongoing user experiments. Jordan Crain, Lukasz Opyrchal, Atul Prakash 0001 |
ARES | 3 |
| 2010 | A Study on Latent VulnerabilitiesabstractSoftware code reuse has long been touted as a reliable and efficient software development paradigm. Whilst this practice has numerous benefits, it is inherently susceptible to latent vulnerabilities. Source code which is re-used without being patched for various reasons may result in vulnerable binaries, despite the vulnerabilities being made publicly known. To aggravate matters, crackers have access to information on these vulnerabilities as well. Defenders need to ensure all loopholes are patched, while attackers need just one such loophole. In this work, we define latent vulnerabilities, and study the prevalence of the problem. This provides us the motivation, and an insight into the future work to be done in solving the problem. Our results show that unpatched source files which are more than one year old are commonly used in the latest operating systems. In fact, several of these files are more than ten years old. We explore the premises of using symbols in identifying binaries and conclude that they are insufficient in solving the problem. Additionally, we discuss two possible approaches to solve the problem. Beng Heng Ng, Atul Prakash 0001 |
SRDS | 3 |
| 2010 | Bringing the field into the lab: supporting capture and replay of contextual data for the design of context-aware applicationsabstractWhen designing context-aware applications, it is difficult to for designers in the studio or lab to envision the contextual conditions that will be encountered at runtime. Designers need a tool that can create/re-create naturalistic contextual states and transitions, so that they can evaluate an application under expected contexts. We have designed and developed RePlay: a system for capturing and playing back sensor traces representing scenarios of use. RePlay contributes to research on ubicomp design tools by embodying a structured approach to the capture and playback of contextual data. In particular, RePlay supports: capturing naturalistic data through Capture Probes, encapsulating scenarios of use through Episodes, and supporting exploratory manipulation of scenarios through Transforms. Our experiences using RePlay in internal design projects illustrate its potential benefits for ubicomp design. Mark W. Newman, Mark S. Ackerman, Atul Prakash 0001, Zhenan Hong, Jacob Mandel |
UIST | 4 |
| 2009 | Ensemble: Community-Based Anomaly Detection for Popular Applications
Feng Qian 0001, Zhiyun Qian, Z. Morley Mao, Atul Prakash 0001 |
SecureComm | 4 |
| 2009 | Quantifying Information Leaks in Outbound Web TrafficabstractAs the Internet grows and network bandwidth continues to increase, administrators are faced with the task of keeping confidential information from leaving their networks. Todaypsilas network traffic is so voluminous that manual inspection would be unreasonably expensive. In response, researchers have created data loss prevention systems that check outgoing traffic for known confidential information. These systems stop naive adversaries from leaking data, but are fundamentally unable to identify encrypted or obfuscated information leaks. What remains is a high-capacity pipe for tunneling data to the Internet. We present an approach for quantifying information leak capacity in network traffic. Instead of trying to detect the presence of sensitive data-an impossible task in the general case--our goal is to measure and constrain its maximum volume. We take advantage of the insight that most network traffic is repeated or determined by external information, such as protocol specifications or messages sent by a server. By filtering this data, we can isolate and quantify true information flowing from a computer. In this paper, we present measurement algorithms for the Hypertext Transfer Protocol (HTTP), the main protocol for Web browsing. When applied to real Web browsing traffic, the algorithms were able to discount 98.5% of measured bytes and effectively isolate information leaks. Kevin Borders, Atul Prakash 0001 |
SP | 2 |
| 2009 | Protecting Confidential Data on Personal Computers with Storage Capsules
Kevin Borders, Eric Vander Weele, Billy Lau, Atul Prakash 0001 |
USENIX Security Symposium | 4 |
| 2008 | Social networks and context-aware spamabstractSocial networks are popular for online communities. This paper evaluates the risk of sophisticated context-aware spam that could result from information sharing on social networks and discusses potential mitigation strategies. Unlike normal spam, context-aware spam would likely have a high click-through rate due to exploitation of authentic social connections. Context-aware spam could lead to more insidious attacks that try to install malware or steal passwords. In this paper, we analyzed Facebook, a popular social networking website. Our goal was to determine how many users were vulnerable to context-aware attack email and understand aspects of Facebook's design that make such attacks possible. We also classified different kinds of email attacks based on certain pieces of data such as birthdays, lists of friends, wall posts, and user news feeds. We analyzed Facebook starting from a single university e-mail address to calculate the number of users who would be vulnerable to each type of attack. We found that a hacker could send sophisticated context-aware email to approximately 85% of users. Furthermore, our analysis shows that people with private profiles are almost equally vulnerable to a subset of attacks. Finally, we discuss defense strategies. Some strategies would require users to coordinate their privacy policies with each other. We also suggest design improvements for social networks that may help reduce exposure to context-aware attack email. Garrett Brown, Travis Howe, Micheal Ihbe, Atul Prakash 0001, Kevin Borders |
CSCW | 4 |
| 2008 | Prism: Providing Flexible and Fast Filesystem Cloning Service for Virtual Servers
Xin Zhao 0016, Kevin Borders, Atul Prakash 0001 |
Middleware | 3 |
| 2008 | Analyzing websites for user-visible security design flawsabstractAn increasing number of people rely on secure websites to carry out their daily business. A survey conducted by Pew Internet states 42% of all internet users bank online. Considering the types of secure transactions being conducted, businesses are rigorously testing their sites for security flaws. In spite of this testing, some design flaws still remain that prevent secure usage. In this paper, we examine the prevalence of user-visible security design flaws by looking at sites from 214 U.S. financial institutions. We specifically chose financial websites because of their high security requirements. We found a number of flaws that may lead users to make bad security decisions, even if they are knowledgeable about security and exhibit proper browser use consistent with the site's security policies. To our surprise, these design flaws were widespread. We found that 76% of the sites in our survey suffered from at least one design flaw. This indicates that these flaws are not widely understood, even by experts who are responsible for web security. Finally, we present our methodology for testing websites and discuss how it can help systematically discover user-visible security design flaws. Laura Falk, Atul Prakash 0001, Kevin Borders |
SOUPS | 2 |
| 2008 | Towards Quantification of Network-Based Information Leaks via HTTP
Kevin Borders, Atul Prakash 0001 |
HotSec | 2 |
| 2007 | Spector: Automatically Analyzing Shell CodeabstractDetecting the presence of buffer overflow attacks in network messages has been a major focus. Only knowing whether a message contains an attack, however, is not always enough to mitigate the threat. It may also be critical to know what it does. Unfortunately, shell code is written in low-level assembly language, and can be obfuscated. The current method of analyzing shell code, manual reverse engineering, is time-consuming, requires significant expertise, and would be nearly impossible for a wide-scale polymorphic attack. In this paper, we introduce Spector, a symbolic execution engine that extracts meaningful high-level actions from shell code. Spector's high-level output helps facilitate attack mitigation and classification of different payloads that have the same behavior. To evaluate Spector, we tested it with over 23,000 unique payloads. It identified eleven different classes of shell code, and processed all the payloads in just over three hours. Spector also successfully classified polymorphic instances of the same shell code. Kevin Borders, Atul Prakash 0001, Mark Zielinski |
ACSAC | 2 |
| 2007 | Securing Network Input via a Trusted Input Proxy
Kevin Borders, Atul Prakash 0001 |
HotSec | 2 |
| 2007 | Using a virtual machine to protect sensitive Grid resourcesabstractAbstract Most Grid systems rely on their operating systems (OSs) to protect their sensitive files and networks. Unfortunately, modern OSs are very complex and it is difficult to completely avoid intrusions. Once intruders compromise the OS and gain system privilege, they can easily disable or bypass the OS security protections. This paper proposes a secure virtual Grid system, SVGrid, to protect sensitive system resources. SVGrid works by isolating Grid applications in Grid virtual machines. The Grid virtual machines' filesystem and network services are moved into a dedicated monitor virtual machine. All file and network accesses are forced to go through this monitor virtual machine, where SVGrid checks request parameters and only accepts the requests that comply with security rules. Because SVGrid enforces security policy in the isolated monitor virtual machine, it can continue to protect sensitive files and networks even if a Grid virtual machine is compromised. We tested SVGrid against attacks on Grid virtual machines. SVGrid was able to prevent all of them from accessing files and networks maliciously. We also evaluated the performance of SVGrid and found that performance cost was reasonable considering the security benefits of SVGrid. Furthermore, the experimental results show that the virtual remote procedure call mechanism proposed in this paper significantly improves system performance. Copyright © 2006 John Wiley & Sons, Ltd. Xin Zhao 0016, Kevin Borders, Atul Prakash 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2006 | Introduction to the talking points projectabstractNo abstract available. Scott Gifford, Jim Knox, Jonathan James, Atul Prakash 0001 |
ASSETS | 4 |
| 2006 | Securing sensitive content in a view-only file systemabstractOne of the most fundamental problems in computer security is protecting sensitive digital information from unauthorized disclosure. There are a number of challenges, such as spyware, removable media, and mobile devices, which make this a very hard problem. The problem becomes even more difficult when the adversary is somebody who is authorized to view the data. This is what is commonly referred to as an insider information leak. Insider leaks often occur out of malice, but sometimes are just due to plain negligence, as was the case with a recent leak of 26 million U.S. veterans' names, birth dates, and social security numbers. Current systems make an attempt to protect against this type of disclosure, but use rudimentary techniques that can be easily bypassed by a knowledgeable attacker. Examples include disabling "print" and "save" menu options within an application or scanning network traffic for signatures of known sensitive content. This paper examines a new method for protecting sensitive content from unauthorized disclosure, a View-Only File System (VOFS). VOFS relies on trusted computing primitives and virtual machine (VM) technology to provide a much greater level of security than current systems. In VOFS, a secure virtual machine on the client authenticates itself with a content provider and downloads sensitive data. Before allowing the user to view the data in his or her non-secure VM, the VOFS client disables non-essential device output. This prevents the user, or any malicious software, from printing, uploading, or stealing the sensitive content. When the user is done viewing a sensitive file, VOFS will reset the machine to previous state and resume normal device activity. Our goal is to provide near-seamless access to view-only files, while at the same time securing them from unauthorized digital replication. This paper presents the initial design, development plan, and evaluation plan for VOFS. Kevin Borders, Xin Zhao 0016, Atul Prakash 0001 |
Digital Rights Management Workshop | 3 |
| 2006 | Siren: Catching Evasive Malware (Short Paper)abstractWith the growing popularity of anomaly detection systems, which is due partly to the rise in zero-day attacks, a new class of threats have evolved where the attacker mimics legitimate activity to blend in and avoid detection. We propose a new system called Siren that injects crafted human input alongside legitimate user activity to thwart these mimicry attacks. The crafted input is specially designed to trigger a known sequence of network requests, which Siren compares to the actual traffic. It then flags unexpected messages as malicious. Using this method, we were able to detect ten spyware programs that we tested, many of which attempt to blend in with user activity. This paper presents the design, implementation, and evaluation of the Siren activity injection system, as well as a discussion of its potential limitations Kevin Borders, Xin Zhao 0016, Atul Prakash 0001 |
S&P | 3 |
| 2006 | Enforcing provisioning and authorization policy in the Antigone systemabstractPrior works in communication security policy have focused on general-purpose policy languages and evaluation algorithms. However, because the supporting frameworks often defer enforcement, the correctness of a realization of these policies in softwar Patrick D. McDaniel, Atul Prakash 0001 |
J. Comput. Secur. | 2 |
| 2006 | Methods and limitations of security policy reconciliationabstractA security policy specifies session participant requirements. However, existing frameworks provide limited facilities for the automated reconciliation of participant policies. This paper considers the limits and methods of reconciliation in a general-purpose policy model. We identify an algorithm for efficient two-policy reconciliation and show that, in the worst-case, reconciliation of three or more policies is intractable. Further, we suggest efficient heuristics for the detection and resolution of intractable reconciliation. Based upon the policy model, we describe the design and implementation of the Ismene policy language. The expressiveness of Ismene, and indirectly of our model, is demonstrated through the representation and exposition of policies supported by existing policy languages. We conclude with brief notes on the integration and enforcement of Ismene policy within the Antigone communication system. Patrick D. McDaniel, Atul Prakash 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2005 | CPOL: high-performance policy evaluationabstractPolicy enforcement is an integral part of many applications. Policies are often used to control access to sensitive information. Current policy specification languages give users fine-grained control over when and how information can be accessed, and are flexible enough to be used in a variety of applications. Evaluation of these policies, however, is not optimized for performance. Emerging applications, such as real-time enforcement of privacy policies in a sensor network or location-aware computing environment, require high throughput. Our experiments indicate that current policy enforcement solutions are unable to deliver the level of performance needed for such systems, and limit their overall scalability. To deal with the need for high-throughput evaluation, we propose CPOL, a flexible C++ framework for policy evaluation. CPOL is designed to evaluate policies as efficiently as possible, and still maintain a level of expressiveness comparable to current policy languages. CPOL achieves its performance goals by efficiently evaluating policies and caching query results (while still preserving correctness). To evaluate CPOL, we ran a simulated workload of users making privacy queries in a location-sensing infrastructure. CPOL was able to handle policy evaluation requests two to six orders of magnitude faster than a MySql implementation and an existing policy evaluation system. We present the design and implementation of CPOL, a high-performance policy evaluation engine, along with our testing methodology and experimental results. Kevin Borders, Xin Zhao 0016, Atul Prakash 0001 |
CCS | 3 |
| 2004 | Web tap: detecting covert web trafficabstractAs network security is a growing concern, system administrators lock down their networks by closing inbound ports and only allowing outbound communication over selected protocols such as HTTP. Hackers, in turn, are forced to find ways to communicate with compromised workstations by tunneling through web requests. While several tools attempt to analyze inbound traffic for denial-of-service and other attacks on web servers, Web Tap's focus is on detecting attempts to send significant amounts of information out via HTTP tunnels to rogue Web servers from within an otherwise firewalled network. A related goal of Web Tap is to help detect spyware programs, which often send out personal data to servers using HTTP transactions and may open up security holes in the network. Based on the analysis of HTTP traffic over a training period, we designed filters to help detect anomalies in outbound HTTP traffic using metrics such as request regularity, bandwidth usage, inter-request delay time, and transaction size. Subsequently, Web Tap was evaluated on several available HTTP covert tunneling programs as well as a test backdoor program, which creates a remote shell from outside the network to a protected machine using only outbound HTTP transactions. Web Tap's filters detected all the tunneling programs tested after modest use. Web Tap also analyzed the activity of approximately thirty faculty and students who agreed to use it as a proxy server over a 40 day period. It successfully detected a significant number of spyware and aware programs. This paper presents the design of Web Tap, results from its evaluation, as well as potential limits to Web Tap's capabilities. Kevin Borders, Atul Prakash 0001 |
CCS | 2 |
| 2002 | Methods and Limitations of Security Policy ReconciliationabstractA security policy is a means by which participant session requirements are specified. However, existing frameworks provide limited facilities for the automated reconciliation of participant policies. This paper considers the limits and methods of reconciliation in a general-purpose policy model. We identify an algorithm for efficient two-policy reconciliation, and show that, in the worst-case, reconciliation of three or more policies is intractable. Further, we suggest efficient heuristics for the detection and resolution of intractable reconciliation. Based upon the policy model, we describe the design and implementation of the Ismene policy language. The expressiveness of Ismene, and indirectly of our model, is demonstrated through the representation and exposition of policies supported by existing policy languages. We conclude with brief notes on the integration and enforcement of Ismene policy within the Antigone communication system. Patrick D. McDaniel, Atul Prakash 0001 |
S&P | 2 |
| 2001 | Secure Distribution of Events in Content-Based Publish Subscribe Systems
Lukasz Opyrchal, Atul Prakash 0001 |
USENIX Security Symposium | 2 |
| 2000 | Developing adaptive groupware applications using a mobile component frameworkabstractA need exists to develop groupware systems that adapt to available resources and support user mobility. This paper presents DACIA, a system that provides mechanisms for building such groupware applications. Using DACIA, components of a groupware application can be moved to different hosts during execution, while maintaining communication connectivity with groupware services and other users. DACIA provides mechanisms that simplify building groupware for domains where users are mobile. New collaboration features can be also more easily implemented. DACIA is also applicable to non-mobile environments. We show its applicability to building groupware applications that can be reconfigured at run-time to adapt to changing user demands and resource constraints, for example, by relocating services or introducing new services. This paper describes the architecture of DACIA and its use in building adaptable groupware systems. Radu Litiu, Atul Prakash 0001 |
CSCW | 2 |
| 1999 | Stateful Group Communication ServicesabstractReliable group multicasts provide a nice abstraction for communicating data reliably among group members and have been used for a variety of applications. In this paper we present Corona, a group communication service for building collaboration tools and reliable data dissemination services in Web-based environments, where clients connect independently of other clients and are not necessarily connected to the group multicast services all the time. The key features of Corona are: (1) the shared state of a group consists of a set of objects shared collectively among group members; (2) Corona supports multiple state transfer policies to accommodate clients with different needs and resources; (3) the communication service provides the current group state or state updates to new clients even when other clients are not available; (4) the service supports persistent groups that tolerate client failures and leaves. We show that the overhead incurred by the multicast service in managing each group's shared state has little impact on the latency seen by the clients or the server throughput. We also show that the multicast service does not have to be aware of the client-specific semantics of the objects in the group's state. Radu Litiu, Atul Prakash 0001 |
ICDCS | 2 |
| 1999 | Antigone: A Flexible Framework for Secure Group Communication
Patrick D. McDaniel, Atul Prakash 0001, Peter Honeyman |
USENIX Security Symposium | 2 |
| 1999 | Flexible Control of Downloaded Executable ContentabstractWe present a security architecture that enables system and application a ccess control requirements to be enforced on applications composed from downloaded executable content. Downloaded executable content consists of messages downloaded from remote hosts that contain executables that run, upon receipt, on the downloading principal's machine. Unless restricted, this content can perform malicious actions, including accessing its downloading principal's private data and sending messages on this principal's behalf. Current security architectures for controlling downloaded executable content (e.g., JDK 1.2) enable specification of access control requirements for content based on its provider and identity. Since these access control requirements must cover every legal use of the class, they may include rights that are not necessary for a particular application of content. Therefore, using these systems, an application composed from downloaded executable content cannot enforce its access control requirements without the addition of application-specific security mechanisms. In this paper, we define an access control model with the following properties: (1) system administrators can define system access control requirements on applications and (2) application developers can use the same model to enforce application access control requirements without the need for ad hoc security mechanisms. This access control model uses features of role-based access control models to enable (1) specification of a single role that applies to multiple application instances; (2) selection of a content's access rights based on the content's application and role in the application; (3) consistency maintained between application state and content access rights; and (4) control of role administration. We detail a system architecture that uses this access control model to implement secure collaborative applications. Lastly, we describe an implementation of this architecture, called the Lava security architecture. Trent Jaeger, Atul Prakash 0001, Jochen Liedtke, Nayeem Islam |
ACM Trans. Inf. Syst. Secur. | 2 |
| 1999 | Data Management Issues and Trade-Offs in CSCW SystemsabstractSubstantial interest has developed in recent years in building computer systems that support cooperative work among groups without the need for physical proximity. This paper examines some of the difficult data management issues in designing systems for computer-supported cooperative work (CSCW). Specifically, we consider an example CSCW system to support large-scale team science over the Internet: the Collaboratory Builder's Environment. We discuss the issues of managing shared data in such systems, reducing information overload and providing group awareness and access control. We discuss several promising approaches to these issues. We point out where a significant gap remains in addressing the requirements of such systems and where designers have to make design trade-offs that can be difficult to evaluate. Finally, we discuss several open issues for future work. Atul Prakash 0001, Hyong Sop Shim, Jang Ho Lee |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1998 | Tolerating Client and Communication Failures in Distributed Groupware SystemsabstractIf a groupware system is to be effectively used, especially over a wide area network such as the Internet, where the quality of networking and computing resources are unpredictable, it should allow clients to tolerate client, link, and server failures. In particular, clients should be able to join groups and transfer groups' current state in the presence of most client and link failures. In order to reduce usage overhead, disconnected clients should also be able to rejoin groups without having to restart from scratch. Furthermore, lock management and group membership should tolerate transient failures in the system. We introduce the notion of stateful group communication, which frees clients of administrative management of shared application state and allows fault tolerant group join, state transfer, and rejoin. Stateful group communication is incorporated in Corona, a general purpose, group communication service provider. In order to allow groups to tolerate transient failures, Corona also provides locks with grace period and group membership notification services that are based on client connection status. We present and discuss Corona's fault tolerant services. Hyong Sop Shim, Atul Prakash 0001 |
SRDS | 2 |
| 1998 | Concurrency Control and View Notification Algorithms for Collaborative Replicated ObjectsabstractThis paper describes algorithms for implementing a high-level programming model for synchronous distributed groupware applications. In this model, several application data objects may be atomically updated, and these objects automatically maintain consistency with their replicas using an optimistic algorithm. Changes to these objects may be optimistically or pessimistically observed by view objects by taking consistent snapshots. The algorithms for both update propagation and view notification are based upon optimistic guess propagation principles adapted for fast commit by using primary copy replication techniques. The main contribution of the paper is the synthesis of these two algorithmic techniques-guess propagation and primary copy replication-for implementing a framework that is easy to program to and is well suited for the needs of groupware applications. Robert E. Strom, Guruduth Banavar, Kevan Miller, Atul Prakash 0001 |
IEEE Trans. Computers | 4 |
| 1997 | Providing Flexible Services for Managing Shared State in Collaborative Systems
Hyong Sop Shim, Robert W. Hall, Atul Prakash 0001, Farnam Jahanian |
ECSCW | 3 |
| 1997 | Concurrency Control and View Notification Algorithms for Collaborative Replicated ObjectsabstractThis paper describes algorithms for implementing a high-level programming model for synchronous distributed groupware applications. In this model, several application data objects may be atomically updated, and these objects automatically maintain consistency with their replicas using an optimistic algorithm. Changes to these objects may be optimistically or pessimistically observed by view objects by taking consistent snapshots. The algorithms for both update propagation and view notification are based upon optimistic guess propagation principles, adapted for fast commit by using primary copy replication techniques. The main contribution of the paper is the synthesis of these two algorithmic techniques-guess propagation and primary copy replication-for implementing a framework that is easy to program and is well suited for the needs of groupware applications. Robert E. Strom, Guruduth Banavar, Kevan Miller, Atul Prakash 0001 |
ICDCS | 4 |
| 1996 | Corona: A Communication Service for Scalable, Reliable Group Collaboration SystemsabstractArticle Corona: a communication service for scalable, reliable group collaboration systems Share on Authors: Robert W. Hall Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MIView Profile , Amit Mathur Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MIView Profile , Farnam Jahanian Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MIView Profile , Atul Prakash Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MIView Profile , Craig Rassmussen Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MI Software Systems Research Laboratory, Department of Electrical Engineering and Computer Science, The University of Michigan, Ann Arbor, MIView Profile Authors Info & Claims CSCW '96: Proceedings of the 1996 ACM conference on Computer supported cooperative workNovember 1996 Pages 140–149https://doi.org/10.1145/240080.240238Online:16 November 1996Publication History 44citation628DownloadsMetricsTotal Citations44Total Downloads628Last 12 Months14Last 6 weeks2 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Robert W. Hall, Amit G. Mathur, Farnam Jahanian, Atul Prakash 0001, Craig Rassmussen |
CSCW | 4 |
| 1996 | Supporting Multi-User, Multi-Applet Workspaces in CBEabstractOur experience with Internet-based scientific collaboratories indicates that they need to be user-extensible, allow users to add tools and objects dynamically to shared workspaces, permit users to move work dynamically between private and shared workspaces, and be easily accessible over a network.We present the software architecture of an environment, called CBE, for building collaboratories to meet such needs.CBE provides user-extensibility by allowing a collaborator to be constructed as a coordinated collection of group-swam applets.To support dynamic reconfiguration of shared workspaces and to allow access over the Internet, CBE uses the metaphor of rooms as the high-level grouping mechanism for applets and users.Rooms may contain applets, users, and arbitrary data objects.Rooms can be used for both asynchronous and synchronous collaboration because their state persists across synchronous sessions.Room participants may have different roles in a room (such as administrator, member and observer), with appropriate access rights.A prototype of the model has been implemented in Java and can be run from a Java-enabled Web browser. Jang Ho Lee, Atul Prakash 0001, Trent Jaeger, Gwobaw Wu |
CSCW | 2 |
| 1996 | Building Systems That Flexibly Download Executable Content
Trent Jaeger, Atul Prakash 0001 |
USENIX Security Symposium | 2 |
| 1996 | A Query Algebra for Program DatabasesabstractQuerying source code is an essential aspect of a variety of software engineering tasks such as program understanding, reverse engineering, program structure analysis and program flow analysis. In this paper, we present and demonstrate the use of an algebraic source code query technique that blends expressive power with query compactness. The query framework of Source Code Algebra (SCA) permits users to express complex source code queries and views as algebraic expressions. Queries are expressed on an extensible, object-oriented database that stores program source code. The SCA algebraic approach offers multiple benefits such as an applicative query language, high expressive power, seamless handling of structural and flow information, clean formalism and potential for query optimization. We present a case study where SCA expressions are used to query a program in terms of program organization, resource flow, control flow, metrics and syntactic structure. Our experience with an SCA-based prototype query processor indicates that an algebraic approach to source code queries combines the benefits of expressive power and compact query formulation. Santanu Paul, Atul Prakash 0001 |
IEEE Trans. Software Eng. | 2 |
| 1995 | Implementation of a discretionary access control model for script-based systemsabstractPowerful applications can be implemented using command scripts. A command script is a program written by one user, called a writer, and made available to another user, called the reader, who executes the script. For instance, command scripts could be used by Mosaic, the popular World-wide Web browsing tool, to provide fancy interfaces to services, such as banking, shopping, etc. However, the use of command scripts presents a serious security problem. A command script is run with the reader's access rights, so a writer can use a command script to gain unauthorized access to the reader's data and applications. Existing solutions to the problem either severely restrict I/O capability of scripts, limiting the range of applications that can be supported, or permit all I/O to scripts, potentially compromising the security of the reader's data. We define a discretionary access control model that permits users to flexibly limit the access rights of the processes that execute a command script. We use this model in a prototype system that safely executes command scripts available from Mosaic. Trent Jaeger, Atul Prakash 0001 |
CSFW | 2 |
| 1995 | The Session Capture and Replay Paradigm for Asynchronous Collaboration
Nelson R. Manohar, Atul Prakash 0001 |
ECSCW | 2 |
| 1995 | Computer Supported Cooperative Work: New Challenges or Old Problems (Panel)
Tom Rodden, Paul Dourish, Lennart E. Fahlén, Christopher Greenhalgh, Atul Prakash 0001, John Riedl |
ICDCS | 5 |
| 1995 | Dealing with Synchronization and Timing Variability in the Playback of Interactive Session RecordingsabstractNo abstract available. Nelson R. Manohar, Atul Prakash 0001 |
ACM Multimedia | 2 |
| 1995 | Representation and Adaptation of Organization Coordination Knowledge for Autonomous Agent Systems
Trent Jaeger, Atul Prakash 0001 |
SEKE | 2 |
| 1995 | Program view generation and change analysis using attributed dependency graphsabstractAbstract Software maintenance is usually the most expensive phase of the software life‐cycle. Program understanding and impact‐of‐change analysis are two of the major activities during this phase. In this paper, we describe attributed program dependency graphs (APDGs), a model to store information derived from the program source code and ease construction of tools for software maintenance. We show how the model can be used for interactive view generation and doing two kinds of impact‐of‐change analysis—incremental and comparison‐oriented. Incremental change analysis uses APDGs and a Rule Base to provide a way for the user to analysis the effect of proposed well‐defined changes. Comparison‐oriented change analysis allows a user to generate structural semantic differences between two versions of a subsystem after an arbitrary sequence of changes. We also introduce SCAN, a prototype collection of loosely integrated tools based on the APDG model and describe our experiences with the system. Ratib Al-Zoubi, Atul Prakash 0001 |
J. Softw. Maintenance Res. Pract. | 2 |
| 1994 | Support for the File System Security Requirements of Computational E-Mail SystemsabstractComputational e-mail systems, which allow mail messages to contain command scripts that automatically execute upon receipt, can be used as a basis for building a variety of collaborative applications. However, their use also presents a serious security problem because a command script from a sender may access/modify receiver's private files or execute applications on receiver's behalf. Existing solutions to the problem either severely restrict I/O capability of scripts, limiting the range of applications that can be supported over computational e-mail, or permit all I/O to scripts, potentially compromising the security of the receiver's files. Our model, called the intersection model of security, permits I/O for e-mail from trusted senders but without compromising the security of private files. We describe two implementations of our security model: an interpreter-level implementation and an operating systems-level implementation. We discuss the tradeoffs between the two implementations and suggest directions for future work. Trent Jaeger, Atul Prakash 0001 |
CCS | 2 |
| 1994 | DistView: Support for Building Efficient Collaborative Applications Using Replicated ObjectsabstractThe ability to share synchronized views of interactions with an application is critical to supporting synchronous collaboration. This paper suggests a simple synchronous collaboration paradigm in which the sharing of the views of user/application interactions occurs at the window level within a multi-user, multi-window application. The paradigm is incorporated in a toolkit, DistView, that allows some of the application windows to be shared at a fine-level of granularity, while still allowing other application windows to be private. The toolkit is intended for supporting synchronous collaboration over wide-area networks. To keep bandwidth requirements and interactive response time low in such networks, DistView uses an object-level replication scheme, in which the applicaton and interface objects that need to be shared among users are replicated. We discuss the design of DistView and present our preliminary experience with a prototype version of the system. Atul Prakash 0001, Hyong Sop Shim |
CSCW | 1 |
| 1994 | Querying Source Code Using an Algebraic Query LanguageabstractQuerying and analyzing source code interactively is a critical task in reverse engineering and program understanding. Current source code query systems lack sufficient formalism and offer limited query capabilities. We introduce the formal framework of Source Code Algebra (SCA), and outline a source code query system based on it. SCA provides a formal data model for source code, an algebraic expression-based query language, and opportunities for query optimization. An algebraic model of source code addresses the issues of conceptual integrity, expressive power, and performance of a source code query system within a unified framework.> Santanu Paul, Atul Prakash 0001 |
ICSM | 2 |
| 1994 | A Framework for Automatic Improvement of Workflows to Meet Performance GoalsabstractBusiness performance improvement is arguably the most important factor in the development or reengineering of a business information system. We present a framework that, given a model of a business information system and a performance goal, helps determine the modifications required in the model in order to meet the performance goal. The framework includes: an executable system model based on workflows, triggers, and execution resources; an execution environment that measures system performance; improvement operators that can modify the system model; and an automatic improvement mechanism that uses AI search techniques to guide the modification of the system model to meet a performance goal.> Trent Jaeger, Atul Prakash 0001, Masayuki Ishikawa |
ICTAI | 2 |
| 1994 | Protocols for Integrated Audio and Shared Windows in Collaborative SystemsabstractThis paper describes the architecture and protocols for integrating real-time audio and shared windows in computer-supported cooperative work (CSCW) environments. Such applications require that actions on shared windows be synchronized with accompanying audio. We give a characterization of this synchronization problem and propose an architecture for handling audio-enhanced cooperative work. We present a protocol for synchronizing the audio stream and window-event streams and evaluate its performance. Amit G. Mathur, Atul Prakash 0001 |
ACM Multimedia | 2 |
| 1994 | Supporting Queries on Source Code: a Formal FrameworkabstractQuerying source code interactively for information is a critical task in reverse engineering of software. However, current source code query systems succeed in handling only small subsets of the wide range of queries possible on code, trading generality and expressive power for ease of implementation and practicality. We attribute this to the absence of clean formalisms for modeling and querying source code. In this paper, we present an algebraic framework (Source Code Algebra or SCA) that forms the basis of our source code query system. The benefits of using SCA include the integration of structural and flow information into a single source code data model, the ability to process high-level source code queries (command-line, graphical, relational, or pattern-based) by expressing them as equivalent SCA expressions, the use of SCA itself as a powerful low-level source code query language, and opportunities for query optimization. We present the SCA’s data model and operators and show that a variety of source code queries can be easily expressed using them. An algebraic model of source code addresses the issues of conceptual integrity, expressive power, and performance of a source code query system within a unified framework. Santanu Paul, Atul Prakash 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 1994 | A Framework for Undoing Actions in Collaborative SystemsabstractThe ability to undo operations is a standard feature in most single-user interactive applications. We propose a general framework for implementing undo in collaborative systems. The framework allows users to reverse their own changes individually, taking into account the possibility of conflicts between different users' operations that may prevent an undo. The proposed framework has been incorporated into DistEdit, a toolkit for building group text editors. Based on our experience with DistEdit's undo facilities, we discuss several issues that need to be taken into account in using the framework, in order to ensure that a reasonable undo behavior is provided to users. We show that the framework is also applicable to single-user systems, since the operations to undo can be selected not just on the basis of who performed them, but by any appropriate criterion, such as the document region in which the operations occurred or the time interval in which the operations were carried out. Atul Prakash 0001, Michael J. Knister |
ACM Trans. Comput. Hum. Interact. | 1 |
| 1994 | A Framework for Source Code Search Using Program PatternsabstractFor maintainers involved in understanding and reengineering large software, locating source code fragments that match certain patterns is a critical task. Existing solutions to the problem are few, and they either involve manual, painstaking scans of the source code using tools based on regular expressions, or the use of large, integrated software engineering environments that include simple pattern-based query processors in their toolkits. We present a framework in which pattern languages are used to specify interesting code features. The pattern languages are derived by extending the source programming language with pattern-matching symbols. We describe SCRUPLE, a finite state machine-based source code search tool, that efficiently implements this framework. We also present experimental performance results obtained from a SCRUPLE prototype, and the user interface of a source code browser built on top of SCRUPLE.> Santanu Paul, Atul Prakash 0001 |
IEEE Trans. Software Eng. | 2 |
| 1992 | Undoing Actions in Collaborative WorkabstractDue to lack of full awareness of other users' intentions, the possibility of inadvertent mistakes is higher in collaborative work, and yet most current collaborative systems fail to provide adequate facilities for undoing actions. This limitation occurs because undo facilities of single-user systems do not readily apply to collaborative systems. In this paper, we propose a general framework for undoing actions in collaborative software systems. The framework takes into account the possibility of conflicts between different users' actions that may prevent a normal undo. The framework also allows selection of actions to undo based on who performed them, where they occurred, or any other appropriate criteria. 1 Introduction The ability to reverse, or undo, the effects of previous actions has become a common feature in modern application software. This ability is particularly valuable in collaborative applications, but it is technically much more difficult to implement than in a single-us... Atul Prakash 0001, Michael J. Knister |
CSCW | 1 |
| 1990 | DistEdit: A Distributed Toolkit for Supporting Multiple Group EditorsabstractThe purpose of our project is to provide toolkits for building applications that support collaboration between people in distributed environments. In this paper, we describe one such toolkit, called DistEdit, that can be used to build interactive group editors for distributed environments. This toolkit has the ability to support different editors simultaneously and provides a high degree of fault-tolerance against machine crashes. To evaluate the toolkit, we modified two editors to make use of the toolkit. The resulting editors allow users to take turns at making changes while other users observe the changes as they occur. We give an evaluation of the toolkit based on the development and use of these editors. Michael J. Knister, Atul Prakash 0001 |
CSCW | 2 |
| 1990 | The Evolution Support Environment SystemabstractThe evolution support environment (ESE) system, which provides a framework for capturing and making available semantic information about software components of an evolving software system, is described. The goal in the design of the ESE system was to provide integrated support for management of software architecture configuration, life-cycle configuration, and version control. Software architecture configuration management allows tracking of interconnections among software components that make up a system. Life-cycle management allows traceability among specifications, design, code, and test cases during software development. Adding version control allows specific versions of software objects and their associated objects, such as specifications and test cases, to be retrieved. The authors' experience with the use of the system is discussed.> C. V. Ramamoorthy, Yutaka Usuda, Atul Prakash 0001, Wei-Tek Tsai |
IEEE Trans. Software Eng. | 3 |
| 1988 | Hierarchical Distributed SimulationsabstractRunning simulations in a distributed manner by decentralizing the advancement of clock potentially allows significant speedup. However, because time may not advance at the same rate in the target system and the testbed system, deadlocks that do not occur in the target system can occur during distributed simulation. Previous approaches to deadlock resolution incur either high computation overhead through centralized coordination or high communication overhead through a fully distributed solution. Hierarchical decentralized algorithms that take advantage of the locality of these deadlocks are presented. Overheads associated with time advancement are computed analytically, so that appropriate clustering policies can be designed.> Atul Prakash 0001, C. V. Ramamoorthy |
ICDCS | 1 |
| 1988 | Support for Reusability in GenesisabstractGenesis is a software-engineering-based programming environment geared to support big software projects. The authors first discuss a reusability-driven development methodology that advocates software development based on reusability considerations. Then, they discuss the tools and techniques provided in Genesis to support this methodology. Techniques are suggested for improving the retrievability, composability, and understandability of software resources. Retrievability is improved by use of ESL (entity specification language) for tying resources through attributes and relations. Composability is improved through a mechanism called functional composition that provides considerably more generality than Unix pipes for composing programs. Understandability is improved by the use of program abstractors.> C. V. Ramamoorthy, Vijay K. Garg, Atul Prakash 0001 |
IEEE Trans. Software Eng. | 3 |
| 1986 | Programming in the LargeabstractIt is asserted that ad-hoc programming techniques do not work in the development of big software systems. The programs faced in developing large software include starting from fuzzy and incomplete requirements; enforcing a methodology on the developers; coordinating multiple programmers and managers; achieving desired reliability and performance in the system; managing a multitude of resources in a meaningful way; and completing the system within a limited time frame. The authors examine some of the trends in requirement specification; life cycle modeling; programming environments; design tools; and other software engineering areas for tackling the above problems. The authors suggest several phase-independent and phase-dependent techniques for programming in the large. It is shown how research in automatic programming, knowledge-based systems, metrics, and programming environments can make a significant difference in the ability to develop large systems. C. V. Ramamoorthy, Vijay K. Garg, Atul Prakash 0001 |
IEEE Trans. Software Eng. | 3 |