Abhinav Kumar 0007

dblp:115/6458-7 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0001-5291-040XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Privacy Analysis of Oblivious DNS over HTTPS: a Website Fingerprinting Study
abstract
As our digital presence expands, safeguarding private data and preserving online privacy becomes paramount. Thus, motivating the development of secure DNS systems, such as DNS over TLS or HTTPS. The vulnerability of these protocols against privacy attacks has led to the development of the Oblivious DNS-over-HTTPS (ODoH) protocol. Nevertheless, the extent of ODoH’s effectiveness in protecting clients’ privacy is still unknown. This study investigates ODoH resiliency against website fingerprinting attacks in the open-world setting. We deploy an ODoH testbed on GENI for data collection and employ deep learning techniques such as ensemble learning for data analysis. Our findings reveal that a passive adversary can identify targeted websites using ODoH traces with an accuracy of 94%. Additionally, we analyze the impact of various factors, including clients’ locations, available resolvers, and time stability, on the attack’s success. Finally, we prototype a mitigation strategy and demonstrate its effectiveness in safeguarding clients privacy.
Mohammad Amir Salari, Abhinav Kumar 0007, Federico Rinaudi, Reza Tourani, Alessio Sacco, Flavio Esposito
DSN2
2025 Persistent Backdoor Attacks in Continual Learning
Abhinav Kumar 0007, Reza Tourani
USENIX Security Symposium2
2024 A Generative Framework for Low-Cost Result Validation of Machine Learning-as-a-Service Inference
abstract
The growing popularity of Machine Learning (ML) has led to its deployment in various sensitive domains, which has resulted in significant research focused on ML security and privacy. However, in some applications, such as Augmented/Virtual Reality, integrity verification of the outsourced ML tasks is more critical-a facet that has not received much attention. Existing solutions, such as multi-party computation and proof-based systems, impose significant computation overhead, which makes them unfit for real-time applications. We propose Fides, a novel framework for real-time integrity validation of ML-as-a-Service (MLaaS) inference. Fides features a novel and efficient distillation technique-Greedy Distillation Transfer Learning-that dynamically distills and fine-tunes a space and compute-efficient verification model for verifying the corresponding service model while running inside a trusted execution environment. Fides features a client-side attack detection model that uses statistical analysis and divergence measurements to identify, with a high likelihood, if the service model is under attack. Fides also offers a re-classification functionality that predicts the original class whenever an attack is identified. We devised a generative adversarial network framework for training the attack detection and re-classification models. The evaluation shows that Fides achieves an accuracy of up to 98% for attack detection and 94% for re-classification.
Abhinav Kumar 0007, Miguel A. Guirao Aguilera, Reza Tourani, Satyajayant Misra
AsiaCCS1
2023 IoT Sentinel: Correlation-based Attack Detection, Localization, and Authentication in IoT Networks
abstract
Security issues have become one of the major challenges for Internet-of-Things (IoT) networks. To overcome this challenge, the recent commonly-used approaches mainly focus on conducting encryption on IoT communication or performing continuous authentication for IoT devices by using pre-shared credentials (e.g., passcode and wireless channel signatures). However, these mechanisms are deemed insufficient, in part, due to the increasing number of data breaches and the recent proliferation of sensitive IoT devices and applications. We present IoT Sentinel - a novel security system that explores the correlation between IoT devices to effectively and efficiently secure IoT networks. Specifically, our system (i) detects potential attacks, (ii) localizes the attacker, and (iii) conducts dynamic implicit authentication at the same time. Moreover, instead of requiring full physical-layer access to IoT devices for finegrained measurement of the wireless signal, IoT Sentinel uses only coarse packet-level device correlation information to secure IoT networks with negligible overhead to the network. Thus, making our approach compatible with existing constrained IoT devices. We extensively evaluate the efficacy of IoT Sentinel in different scenarios and settings. The experiment results show that our approach achieves around 96% attack detection accuracy, more than 70% attacker localization accuracy, and around 100% device authentication accuracy.
Dianshi Yang, Abhinav Kumar 0007, Stuart Ray, Wei Wang 0190, Reza Tourani
ICCCN2