EDBT 2026 Demo / reviewers in the wild / expert
J. Sukarno Mertoguno
dblp:07/3234
· DBLP profile ↗
17ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0003-0572-3737ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 1 first-author · 4 since 2021Security and privacy · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MOLE: Breaking GPU TEE with GPU-Embedded MCUabstractGraphics Processing Units (GPUs) are extensively used for applications such as machine learning, scientific computing, and graphics rendering. To protect sensitive data processed by GPUs, Trusted Execution Environments (TEEs) for GPUs have been proposed. GPU TEEs, built with hardware-based isolation primitives, can defend against high-privilege attackers like OS kernels. However, in this paper, we present MOLE, a novel attack that compromises the security of GPU TEEs on Arm Mali GPUs by exploiting the GPU-embedded Microcontroller Unit (MCU). By injecting malicious firmware into the MCU, an attacker can bypass GPU TEEs' security guarantees. We evaluated MOLE with state-of-the-art GPU TEE proposals under multiple real-world attack scenarios, such as in-GPU AES encryption and object detection tasks. Our evaluation shows that MOLE can successfully extract sensitive data or manipulate the computation results of GPU TEEs. We responsibly disclosed our findings to the authors of the affected GPU TEE proposals and received acknowledgments from all of them. Moreover, our findings prompted Arm to enhance the security of its GPU firmware supply chains. Hongyi Lu, Yunjie Deng 0001, J. Sukarno Mertoguno, Shuai Wang 0011, Fengwei Zhang |
CCS | 3 |
| 2025 | Iteration, Mother of Transferability: A Study of Black-Box Iterative Adversarial Attacks Across CNNs and Vision TransformersabstractDeep learning models have become central to many computer vision tasks, yet their vulnerability to adversarial attacks-particularly in black-box settings-remains a significant concern. Iterative attacks such as I-FGSM and PGD are commonly used to strengthen perturbations, but their ability to transfer across different architectures remains underexplored. In this paper, we present a systematic evaluation of adversarial transferability across both closely related architectures–Convolutional Neural Network (CNN) and Dilated CNN–and fundamentally different ones-CNN and Vision Transformer (ViT)-using both high-resolution (ANIMAL5) and low-resolution (FMNIST) datasets. To capture the impact of attack configuration, we vary the perturbation size$(\epsilon)$, step size ($\alpha$) and number of iterations. Our results show that iterative attacks tend to overfit to the source model and that their transferability decreases as the number of steps increases. This effect is further amplified when architectural differences such as dilation or attention mechanisms are present. Higher$\epsilon$values partially compensate for this drop in transferability, providing marginal improvement across settings. In addition, we show that increasing input resolution reduces transferability for CNN and Dilated CNN-based targets, whereas ViTs maintain strong transferability even from low-resolution inputs when global structure is preserved. These findings indicate that architectural generalization, rather than iterative strength alone, is a key driver of adversarial transferability. Michail S. Alexiou, Matthew S. Mickelson, J. Sukarno Mertoguno |
ICTAI | 4 |
| 2024 | Recognizing Binary Code Semantics Towards Achieving Software SegmentationabstractContinuous advancements in hardware capabilities and programming paradigms have enabled the progress of high-performance computing. The demand to adapt legacy codes, originally designed for earlier generations of computers, to the requirements of modern ones has spurred the development of code distillation techniques. These techniques are specifically designed to improve the performance and security of existing legacy software. However, the majority of legacy software is available only as binary executables, thus, creating difficulties in sustaining or updating them. This challenge necessitates specialized tools for binary analysis to extract key attributes that ensure the accurate translation of legacy software into optimized and secure versions, while preserving its original functionality. In this paper, a methodology named Spotlight is introduced for the identification of program semantics within binary code to facilitate precise distillation and translation. Spotlight operates on the Control-Flow graph representation of binary programs. It leverages a region-growing approach in conjunction with Graph Neural Networks to identify neighborhoods of basic blocks exhibiting attributes of (i) specific functionalities or (ii) parallelism. The present study is focused on four computational functionalities: (a) matrix multiplication, (b) breadth-first search, (c) sorting, and (d) K-means clustering. The evaluation results highlight Spotlight's effectiveness, demonstrating over 90 % accuracy in detecting the relevant computational functionality and identifying parallelism, both within and across different functionalities. Michail S. Alexiou, Zeezoo Ryu, Grace Abawe, J. Sukarno Mertoguno |
ICTAI | 4 |
| 2024 | Rapid Autonomy Transfer in Reinforcement Learning with a Single Pre- Trained CriticabstractReinforcement learning (RL) is a well-studied framework to solve complex decision-making problems in unknown environments. The actor-critic model in RL facilitates autonomy transfer by allowing agents to iteratively update their policies using ongoing dynamic evaluations of value functions via a critic. In this paper, we examine the impact of using different pretrained critics on the performance of actor-critic algorithms. First, in any single given environment, we show that a pretrained critic can be effective in reducing the duration of an initial training phase, thereby accelerating convergence by a factor of up to 2×. In this setting, we identify the critical range of the number of episodes for which a critic will need to be trained in order for it to be an effective pretrained critic. Second, we show that a critic trained in one environment enables transfer of autonomy by aiding learning of behaviors in a different, yet related environment. We carry out extensive experiments on a bipedal locomotion task in the MuJoCo physics engine to verify our hypotheses. Our results in this paper mark the first step towards demonstrating the role and impact of pretrained critics to achieve rapid autonomy transfer for complex reinforcement learning tasks while minimizing costs associated with retraining in new environments. M. Faraz Karim, Yunjie Deng 0001, Luyao Niu, Bhaskar Ramasubramanian, Michail S. Alexiou, Dinuka Sahabandu, Radha Poovendran, J. Sukarno Mertoguno |
ICTAI | 8 |
| 2024 | Experimentation and Implementation of the BFT++ Cyber-Attack Resilience Mechanism for Cyber-Physical SystemsabstractCyber-physical systems (CPS) are used in various safety-critical domains such as robotics, industrial manufacturing systems, and power systems. Faults and cyber attacks have been shown to cause safety violations, which can damage the system and endanger human lives. Traditional resiliency techniques fall short of protecting against cyber threats. In this article, we show how to extend resiliency to cyber resiliency for CPS using a specific combination of diversification, redundancy, and the physical inertia of the system. David R. Keppler, M. Faraz Karim, Matthew S. Mickelson, J. Sukarno Mertoguno |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2023 | POSTER: A Common Framework for Resilient and Safe Cyber-Physical System DesignabstractCyber-physical systems (CPS), which are often required to satisfy critical properties such as safety, have been shown to be vulnerable to exploits originating from cyber and/or physical sides. Recently, novel resilient architectures, which equip CPS with capabilities of recovering to normal operations, have been developed to guarantee the safety of CPS under cyber attacks. These resilient architectures utilize distinct mechanisms involving different parameters and are seemingly unrelated. Currently, the analysis and design methods of one novel resilient architecture for CPS are not readily applicable to one another. Consequently, evaluating the appropriateness and effectiveness of a set of candidate resilient architectures to a given CPS is currently impractical. In this poster, we report our progress on the development of a common framework for analyzing the safety and assessing recovery performance of two or more resilient architectures intended for CPS under attacks. We formulate a hybrid model as a common representation of resilient architectures. Our insight is that the resilient architectures have a shared set of discrete states, including vulnerable, under attack, unsafe, and recovery modes, which can be mapped to the discrete states of the unifying hybrid model. The hybrid model enables a unified safety analysis. We parameterize the required behaviors for the cyber and physical components in order to guarantee safety. The parameters then inform the development of metrics to measure the resilience of CPS. For CPS consisting of multiple heterogeneous components, we show that the effect of interconnections on the spatial and temporal parameters can be quantified efficiently, allowing a compositional approach to the safety verification of large-scale CPS. Luyao Niu, Andrew Clark 0001, J. Sukarno Mertoguno, Radha Poovendran |
AsiaCCS | 4 |
| 2023 | A Survey on Recent Advancements in Lightweight Generative Adversarial Networks, their Applications and DatasetsabstractGenerative Adversarial Networks (GANs) have garnered significant research attention owing to their revolutionary generator-vs-discriminator architecture, making them versatile for various domains, including medical, military, and computer vision applications. Nevertheless, their computationally demanding nature during training and inference restricts their widespread adoption on mobile and edge devices. In this study, the latest advancements are explored in lightweight GAN implementations, considering their unique characteristics and diverse applications. The objective is to identify modifications that can enhance the efficiency of GAN-based models without compromising their robustness and accuracy, both for specific use-cases and in a more general context. Additionally, a discussion is presented on the availability of datasets suitable for lightweight GAN training and evaluation, as well as potential research directions for the future. Michail S. Alexiou, J. Sukarno Mertoguno |
ICTAI | 2 |
| 2023 | VulChecker: Graph-based Vulnerability Localization in Source Code
Yisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann, Matthew Pruett, Evan Downing, J. Sukarno Mertoguno, Wenke Lee |
USENIX Security Symposium | 7 |
| 2023 | A Timing-Based Framework for Designing Resilient Cyber-Physical Systems under Safety ConstraintabstractCyber-physical systems (CPS) are required to satisfy safety constraints in various application domains such as robotics, industrial manufacturing systems, and power systems. Faults and cyber attacks have been shown to cause safety violations, which can damage the system and endanger human lives. Resilient architectures have been proposed to ensure safety of CPS under such faults and attacks via methodologies including redundancy and restarting from safe operating conditions. The existing resilient architectures for CPS utilize different mechanisms to guarantee safety, and currently, there is no common framework to compare them. Moreover, the analysis and design undertaken for CPS employing one architecture is not readily extendable to another. In this article, we propose a timing-based framework for CPS employing various resilient architectures and develop a common methodology for safety analysis and computation of control policies and design parameters. Using the insight that the cyber subsystem operates in one out of a finite number of statuses, we first develop a hybrid system model that captures CPS adopting any of these architectures. Based on the hybrid system, we formulate the problem of joint computation of control policies and associated timing parameters for CPS to satisfy a given safety constraint and derive sufficient conditions for the solution. Utilizing the derived conditions, we provide an algorithm to compute control policies and timing parameters relevant to the employed architecture. We also note that our solution can be applied to a wide class of CPS with polynomial dynamics and also allows incorporation of new architectures. We verify our proposed framework by performing a case study on adaptive cruise control of vehicles. Luyao Niu, Andrew Clark 0001, J. Sukarno Mertoguno, Radha Poovendran |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2023 | A Natural Language Processing Approach for Instruction Set Architecture IdentificationabstractBinary analysis of software is a critical step in cyber forensics applications such as program vulnerability assessment and malware detection. This involves interpreting instructions executed by software and often necessitates converting the software’s binary file data to assembly language. The conversion process requires information about the binary file’s target instruction set architecture (ISA). However, ISA information might not be included in binary files due to compilation errors, partial downloads, or adversarial corruption of file metadata. Machine learning (ML) is a promising methodology that can be used to identify the target ISA using binary data in the object code section of binary files. In this paper we propose a binary code feature extraction model to improve the accuracy and scalability of ML-based ISA identification methods. Our feature extraction model can be used in the absence of domain knowledge about the ISAs. Specifically, we adapt models from natural language processing (NLP) to i) identify successive byte patterns commonly observed in binary codes, ii) estimate the significance of each byte pattern to a binary file, and iii) estimate the relevance of each byte pattern in distinguishing between ISAs. We introduce character-level features of encoded binaries to identify fine-grained bit patterns inherent to each ISA. We evaluate our approach using two different datasets: binaries from 12 ISAs and 23 ISAs. Empirical evaluations show that using our byte-level features in ML-based ISA identification results in ~ 98% accuracy compared to the ~ 91% accuracy of state-of-the-art features based on byte-histograms and byte pattern signatures. We observe that character-level features allow reducing the size of the feature set by up to 16x while maintaining accuracy of ISA identification above 97%. Dinuka Sahabandu, J. Sukarno Mertoguno, Radha Poovendran |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2007 | An Integrated Video Compression, Encryption and Information Hiding Architecture based on the SCAN Algorithm and the Stretch TechnologyabstractSCAN is a class of formal languages for compression, encryption and information hiding. We have previously studied and reported separate hardware implementations of SCAN compression and encryption. This paper presents initial results on the design of a complete single-chip system for the SCAN compression, encryption and information hiding algorithm using the stretch technology with reconfigurable and fixed resources. The result is a simple, low cost, embeddable core combining all three operations seamlessly and the design was fully mapped to the stretch technology. Grigorios Chrysos 0001, Apostolos Dollas, Nikolaos G. Bourbakis, J. Sukarno Mertoguno |
FCCM | 4 |
| 2003 | A digital retina-like low-level vision processorabstractThis correspondence presents the basic design and the simulation of a low level multilayer vision processor that emulates to some degree the functional behavior of a human retina. This retina-like multilayer processor is the lower part of an autonomous self-organized vision system, called Kydon, that could be used on visually impaired people with a damaged visual cerebral cortex. The Kydon vision system, however, is not presented in this paper. The retina-like processor consists of four major layers, where each of them is an array processor based on hexagonal, autonomous processing elements that perform a certain set of low level vision tasks, such as smoothing and light adaptation, edge detection, segmentation, line recognition and region-graph generation. At each layer, the array processor is a 2D array of k/spl times/m hexagonal identical autonomous cells that simultaneously execute certain low level vision tasks. Thus, the hardware design and the simulation at the transistor level of the processing elements (PEs) of the retina-like processor and its simulated functionality with illustrative examples are provided in this paper. J. Sukarno Mertoguno, Nikolaos G. Bourbakis |
IEEE Trans. Syst. Man Cybern. Part B | 1 |
| 2002 | A knowledge-based expert system for automatic visual VLSI reverse-engineering: VLSI layout versionabstractThis paper presents a method of knowledge representation for very large scale integration (VLSI) chip design which provides the necessary information for abstraction from the physical design to gate-level logic through a high-level behavioral model. The representation scheme used by the ANTISTROFEAS system utilizes a hierarchical attributed graph structure which consists of incrementally abstracted design information for the VLSI system. This method of knowledge representation is well-suited to reverse-engineering of VLSI chips from the layer mask layout data, but is also applicable to applications at many levels of the design process including design rule checking, logic synthesis, design verification, and partitioning-compaction problems. The representation scheme is applicable to any VLSI technology, and is designed to take advantage of artificial intelligence. expert system techniques, by disassociating the representation and manipulation of the VLSI design data from the rules which govern its correctness and transformation for other usage. Nikolaos G. Bourbakis, A. Mogzadeh, J. Sukarno Mertoguno, Cris Koutsougeras |
IEEE Trans. Syst. Man Cybern. Part A | 3 |
| 2000 | A Retina-like Low Level Vision ArchitectureabstractPresents the basic design and the simulation of a low level multi-layer vision processor that emulates to some degree the functional behavior of a human retina. This retina-like multi-layer processor is the lower part of an autonomous self-organized vision system, called Kydon, which could be used on visually impaired people with a damaged visual cerebral cortex. The retina-like processor consists of four major layers, where each is an array processor that performs a certain set of low level vision tasks, such as smoothing and light adaptation, edge detection, segmentation, line recognition and region-graph generation. At each layer the array processor is a 2-D array of kxm hexagonal identical autonomous cells that simultaneously execute certain tasks. Thus, in this paper the hardware design and the entire simulation of the retina-like processor with illustrative examples are provided. J. Sukarno Mertoguno, Nikolaos G. Bourbakis |
BIBE | 1 |
| 1998 | Hermes Autonomous Vision System: The Flat Quadtree ModelabstractThis paper deals with the modeling of an extended quartet multiprocessor kernel used for the evaluation of the Hermes system. Hermes is a multiprocessor hybrid system architecture used as a machine vision system. The functionality of Hermes requires an asynchronous information flow upwards and downwards, where "orders"(in a form of code and data) go down and "abstracted" or processed picture information goes up along the system's hierarchy. Moreover, the overall functional behavior of the Hermes system can be considered as an extended quartet kernel in an abstracted manner. The extended quartet kernel studied here presents either a memory-to-memory (M-M) or a bus-to-bus (B-B) connectivity. The evaluation of these two kernel's configurations (M-M, B-B) defines that the structural design of the Hermes system will be based on the M-M scheme. When failures occur on the quartet kernel, however, the M-M scheme will be converted into a B-B one by using a failure recovery procedure. The evaluation of the quartet kernel configurations is based on a probabilistic model. Failures and recovery procedures on the quartet kernel are discussed and the performance evaluation of the kernel (under failures) is also provided. Nikolaos G. Bourbakis, Fotios Barlos, J. Sukarno Mertoguno |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 1995 | The VLSI design and implementation of the array processors of a multilayer vision system architectureabstractThis paper describes the VLSI design and simulation of the lower layer processors of the KYDON vision system. KYDON is a completely autonomous, hierarchical, multilayered image understanding system. The VLSI design of the individual components as well as the timing simulation results of the processor array have been presented. The system runs at 50 MHz and promises a high processing rate of 300 image frames/sec. Bhaskar Saha, J. Sukarno Mertoguno, Nikolaos G. Bourbakis |
ASAP | 2 |
| 1995 | Analysis of the learning model for KYDON systemabstractIn this paper, a learning model for an autonomous vision multi-layer architecture, called KYDON, is presented modeled and analyzed. This learning model uses a birth and death approach to derive the relationships among the parameters used in the learning characteristic function. In addition the two critical (deletion and saturation) points on the learning curve are evaluated. These points represent two extreme states on the learning process. The KYDON architecture consists of 'k' layers of array processors. The lowest layers consist of lower-level processing layers, and the rest consist of higher-level processing layers. The interconnectivity of the PEs in each array is based on a full hexagonal mesh structure. KYDON uses graph models to represent and process the knowledge, extracted from the image. The knowledge base of KYDON is distributed among its PE's. J. Sukarno Mertoguno, Nikolaos G. Bourbakis |
ICTAI | 1 |