EDBT 2026 Demo / reviewers in the wild / expert
Mohammed Shayan
dblp:116/4653
· DBLP profile ↗
15ranked-venue papers
11as first author
3since 2021 · last 2023
0000-0001-5454-1927ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 9 first-author · 1 since 2021Software engineering, systems software and programming languages · 5 · 4 first-authorSecurity and privacy · 3 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | FuncTeller: How Well Does eFPGA Hide Functionality?
Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab, Yiorgos Makris, Jeyavijayan Rajendran |
USENIX Security Symposium | 2 |
| 2021 | How Secure Are Checkpoint-Based Defenses in Digital Microfluidic Biochips?abstractA digital microfluidic biochip (DMFB) is a miniaturized laboratory capable of implementing biochemical protocols. Fully integrated DMFBs consist of a hardware platform, controller, and network connectivity, making it a cyber-physical system (CPS). A DMFB CPS is being advocated for safety-critical applications, such as medical diagnosis, drug development, and personalized medicine. Hence, the security of a DMFB CPS is of immense importance to their successful deployment. Recent research has made progress in devising corresponding defense mechanisms by employing so-called checkpoints (CPs). Existing solutions either rely on probabilistic security analysis that does not consider all possible actions an attacker may use to overcome an applied CP mechanism or rely on exhaustive monitoring of DMFB at all time-steps during the assay execution. For devising a defense scheme that is guaranteed to be secure, an exact analysis of the security of a DMFB is needed. This is not available in the current state-of-the-art. In this article, we address this issue by developing an exact method, which uses the deductive power of satisfiability solvers to verify whether a CP-based defense thwarts the execution of an attack. We demonstrate the usefulness of the proposed method by showcasing two applications on practical bioassays: 1) security analysis of various checkpointing strategies and 2) derivation of a counterexample-guided fool-proof secure CP scheme. Mohammed Shayan, Sukanta Bhattacharjee, Robert Wille, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | Thwarting Bio-IP Theft Through Dummy-Valve-Based ObfuscationabstractResearchers develop bioassays following rigorous experimentation in the lab that involves considerable fiscal and highly-skilled-person-hour investment. Previous work shows that a bioassay implementation can be reverse-engineered by using images or video and control signals of the biochip. Hence, techniques must be devised to protect the intellectual property (IP) rights of the bioassay developer. This study is the first step in this direction and it makes the following contributions: (1) it introduces the use of a dummy valve as a security primitive to obfuscate bioassay implementations; (2) it shows how dummy valves can be used to obscure biochip building blocks such as multiplexers and mixers; (3) it presents design rules and security metrics to design and measure obfuscation. In our preliminary work, we presented the concept through the use of sieve-valve as a dummy-valve. However, sieve-valves are difficult to fabricate. To overcome fabrication complexities, we propose a novel multi-height-valve as an obfuscation primitive. Moreover, we showcase the suitability of multi-height-valve for obfuscation through COMSOL simulations. We demonstrate the practicality of the proposal by fabricating an obfuscated biochip using multi-height valves. We assess the cost-security trade-offs associated with this solution and study the practical implications of dummy-valve based obfuscation on real-life biochips. Mohammed Shayan, Sukanta Bhattacharjee, Ajymurat Orozaliev, Yong-Ak Song, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Microfluidic Trojan Design in Flow-based BiochipsabstractMicrofluidic technologies find application in various safety-critical fields such as medical diagnostics, drug research, and cell analysis. Recent work has focused on security threats to microfluidic-based cyberphysical systems and defenses. So far the threat analysis has been limited to the cases of tampering with control software/hardware, which is common to most cyberphysical control systems in general; in a sense, such an approach is not exclusive to microfluidics. In this paper, we present a stealthy attack paradigm that uses characteristics exclusive to the microfluidic devices - a microfluidic trojan. The proposed trojan payload is a valve whose height has been perturbed to vary its pressure response. This trojan can be triggered in multiple ways based on time or specific operations. These triggers can occur naturally in a bioassay or added into the controlling software. We showcase the trojan application in carrying out practical attacks -contamination, parameter-tampering and denial-of-service - on a real-life bioassay implementation. Further, we present guidelines to launch stealthy attacks and to counter them. Mohammed Shayan, Sukanta Bhattacharjee, Yong-Ak Song, Krishnendu Chakrabarty, Ramesh Karri |
DATE | 1 |
| 2020 | Toward Secure Checkpointing for Micro-Electrode-Dot-Array BiochipsabstractBiochemical experiments, such as diagnostics must be precise and trusted, and provide quick time to results. This has been enabled by automated digital microfluidics; however, it also exposes these experiments to security threats. Previous work has shown that the critical challenge in securing digital microfluidic devices is the lack of sensing resources. The micro-electrode-dot-array (MEDA) is a next-generation digital microfluidic biochip platform that supports fine-grained control and real-time sensing of droplet movements. These capabilities permit continuous monitoring and checkpoint (CP)-based validation of assay execution on MEDA. This article presents a class of “shadow attacks” that abuse the timing slack in the assay execution. State-of-the-art CP-based validation techniques cannot expose the shadow operations. We overcome this limitation by introducing extra CPs in the assay execution at time instances when the assay is prone to shadow attacks. We achieve this by identifying the conditions that enable shadow attacks. We use these conditions to minimize the number of CPs required to guarantee the correctness of bioassay implementation. Our simulation results confirm the effectiveness and practicality of the defense. Mohammed Shayan, Tung-Che Liang, Sukanta Bhattacharjee, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2020 | Secure Assay Execution on MEDA Biochips to Thwart Attacks Using Real-Time SensingabstractDigital microfluidic biochips (DMFBs) have emerged as a promising platform for DNA sequencing, clinical chemistry, and point-of-care diagnostics. Recent research has shown that DMFBs are susceptible to various types of malicious attacks. Defenses proposed thus far only offer probabilistic guarantees of security due to the limitation of on-chip sensor resources. A micro-electrode-dot-array (MEDA) biochip is a next-generation DMFB that enables the real-time sensing of on-chip droplet locations, which are captured in the form of a droplet-location map. We propose a security mechanism that validates assay execution by reconstructing the sequencing graph (i.e., the assay specification) from the droplet-location maps and comparing it against the golden sequencing graph. We prove that there is a unique (one-to-one) mapping from the set of droplet-location maps (over the duration of the assay) to the set of possible sequencing graphs. Any deviation in the droplet-location maps due to an attack is detected by this countermeasure because the resulting derived sequencing graph is not isomorphic to the original sequencing graph. We highlight the strength of the security mechanism by simulating attacks on real-life bioassays. We also address the concern that the proposed mechanism may raise false alarms when some fluidic operations are executed on MEDA biochips. To avoid such false alarms, we propose an enhanced sensing technique that provides fine-grained sensing for the security mechanism. Tung-Che Liang, Mohammed Shayan, Krishnendu Chakrabarty, Ramesh Karri |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2019 | Execution of provably secure assays on MEDA biochips to thwart attacksabstractDigital microfluidic biochips (DMFBs) have emerged as a promising platform for DNA sequencing, clinical chemistry, and point-of-care diagnostics. Recent research has shown that DMFBs are susceptible to various types of malicious attacks. Defenses proposed thus far only offer probabilistic guarantees of security due to the limitation of on-chip sensor resources. A micro-electrode-dot-array (MEDA) biochip is a next-generation DMFB that enables the sensing of on-chip droplet locations, which are captured in the form of a droplet-location map. We propose a security mechanism that validates assay execution by reconstructing the sequencing graph (i.e., the assay specification) from the droplet-location maps and comparing it against the golden sequencing graph. We prove that there is a unique (one-to-one) mapping from the set of droplet-location maps (over the duration of the assay) to the set of possible sequencing graphs. Any deviation in the droplet-location maps due to an attack is detected by this countermeasure because the resulting derived sequencing graph is not isomorphic to the original sequencing graph. We highlight the strength of the security mechanism by simulating attacks on real-life bioassays. Tung-Che Liang, Mohammed Shayan, Krishnendu Chakrabarty, Ramesh Karri |
ASP-DAC | 2 |
| 2019 | High-Level Synthesis of Benevolent TrojansabstractHigh-Level Synthesis (HLS) allows designers to create a register transfer level (RTL) description of a digital circuit starting from its high-level specification (e.g., C/C++/SystemC). HLS reduces engineering effort and design-time errors, allowing the integration of additional features. This study introduces an approach to generate benevolent Hardware Trojans (HT) using HLS. Benevolent HTs are Intellectual Property (IP) watermarks that borrow concepts from well-known malicious HTs to ward off piracy and counterfeiting either during the design flow or in fielded integrated circuits. Benevolent HTs are difficult to detect and remove because they are intertwined with the functional units used to implement the IP. Experimental results testify to the suitability of the approach and the limited overhead. Christian Pilato, Kanad Basu, Mohammed Shayan, Francesco Regazzoni 0001, Ramesh Karri |
DATE | 3 |
| 2019 | Desieve the Attacker: Thwarting IP Theft in Sieve-Valve-based BiochipsabstractResearchers develop bioassays following rigorous experimentation in the lab that involves considerable fiscal and highly-skilled-person-hour investment. Previous work shows that a bioassay implementation can be reverse engineered by using images or video and control signals of the biochip. Hence, techniques must be devised to protect the intellectual property (IP) rights of the bioassay developer. This study is the first step in this direction and it makes the following contributions: (1) it introduces use of a sieve-valve as a security primitive to obfuscate bioassay implementations; (2) it shows how sieve-valves can be used to obscure biochip building blocks such as multiplexers and mixers; (3) it presents design rules and security metrics to design and measure obfuscated biochips. We assess the cost-security trade-offs associated with this solution and demonstrate practical sieve-valve based obfuscation on real-life biochips. Mohammed Shayan, Sukanta Bhattacharjee, Yong-Ak Song, Krishnendu Chakrabarty, Ramesh Karri |
DATE | 1 |
| 2019 | Can Multi-Layer Microfluidic Design Methods Aid Bio-Intellectual Property Protection?abstractResearchers develop bioassays by rigorously experimenting in the lab. This involves significant fiscal and skilled person-hour investment. A competitor can reverse engineer a bioassay implementation by imaging or taking a video of a biochip when in use. Thus, there is a need to protect the intellectual property (IP) rights of the bioassay developer. We introduce a novel 3D multilayer-based obfuscation to protect a biochip against reverse engineering. Mohammed Shayan, Sukanta Bhattacharjee, Yong-Ak Song, Krishnendu Chakrabarty, Ramesh Karri |
IOLTS | 1 |
| 2019 | Security Assessment of Micro-Electrode-Dot-Array BiochipsabstractDigital microfluidic biochips (DMFBs) are versatile, reconfigurable systems for manipulating discrete fluid droplets. Building on the success of DMFBs, platforms based on “sea-of-electrodes,” the micro-electrode-dot-array (MEDA), has been proposed to further increase scalability and reconfigurability. Research has shown that DMFBs are susceptible to actuation tampering attacks which alter control signals and result in fluid manipulation; such attacks have yet to be studied in the context of MEDA biochips. In this paper, we assess the security of MEDA biochips under such attacks, and further argue that it is inherently a more secure platform than traditional DMFBs. First, we identify a new class of actuation tampering attacks specific to MEDA biochips: the micro-droplet attack. We show that this new attack is stealthy as it produces a subtler difference in results compared to traditional DMFBs. We then illustrate our findings through a case study of an MEDA biochip implementing a glucose measurement assay. Second, we enumerate the system features required to secure an MEDA biochip against actuation tampering attacks and show that these features are naturally implemented in MEDA. Mohammed Shayan, Jack Tang, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2019 | Bio-Protocol Watermarking on Digital Microfluidic BiochipsabstractAdvancements in digital microfluidic biochip (DMFB) technologies are paving the way for low-cost and automated platforms for implementing bio-protocols. However, the deployment of DMFBs outside of controlled settings will make them vulnerable to intellectual property (IP) theft. Bio-protocol development requires large investments for cross-domain innovations in biochemical analysis, microfluidics, and cyberphysical systems. We propose a watermarking technique for bio-protocol IP protection-a first in microfluidics-that hierarchically embeds a secret signature across these domains. Such a signature can be exclusively attributed to the owner (like a hash). The proposed solution takes into account the inherent variability in domain-specific parameters such as mixing ratio, sensor calibration, and incubation time. We describe watermarking techniques of varying complexities for different bio-protocol steps. These include watermarking for bio-protocol synthesis parameters and the cyberphysical systems control path parameters. A watermarking scheme based on integer linear programming is proposed for the sample-preparation step of a bio-protocol. The practicality of our solution is demonstrated through case studies involving an immunoassay and several mixing ratios required in the sample-preparation process of bio-protocols. The effectiveness of this approach is evaluated through various security metrics: proof of ownership score, the probability of successful tampering of the watermark, and the probability of coincidence. We also analyze the integrity of the watermark against various possible attacks: brute force search, the insertion of a new watermark, and the watermarking of more parameters. Mohammed Shayan, Sukanta Bhattacharjee, Jack Tang, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Toward Secure Microfluidic Fully Programmable Valve Array BiochipsabstractThe fully programmable valve array (FPVA) is a general-purpose programmable flow-based microfluidic platform, akin to the VLSI field-programmable gate array (FPGA). FPVAs are dynamically reconfigurable and, hence, are suitable in a broad spectrum of applications involving immunoassays and cell analysis. Since these applications are safety critical, addressing security concerns is vital for the success and adoption of FPVAs. This study evaluates the security of FPVA biochips. We show that FPVAs are vulnerable to malicious operations similar to digital and flow-based microfluidic biochips. FPVAs are further prone to new classes of attacks-tunneling and deliberate aging. This study establishes security metrics and describes possible attacks on real-life bioassays. Furthermore, we study the use of machine learning (ML) techniques to detect and classify attacks based on the golden and real-time biochip state. In order to boost the classifier's performance, we propose a smart checkpointing mechanism. Experimental results are presented to showcase: 1) best-fit ML model classifier; 2) performance of different tradeoffs in checkpointing; and 3) effectiveness of the proposed smart checkpointing scheme. Mohammed Shayan, Sukanta Bhattacharjee, Yong-Ak Song, Krishnendu Chakrabarty, Ramesh Karri |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2018 | Shadow attacks on MEDA biochipsabstractThe Micro-electrode-dot-array (MEDA) is a next-generation digital microfluidic biochip (DMFB) platform that supports fine-grained control and real-time sensing of droplet movements. These capabilities permit continuous monitoring and checkpoint-based validation of assay execution on MEDA. This paper presents a class of “shadow attacks” that abuse the timing slack in the assay execution. State-of-the-art checkpoint-based validation techniques cannot expose the shadow operations. We develop a defense that introduces extra checkpoints in the assay execution at time instances when the assay is prone to shadow attacks. Experiments confirm the effectiveness and practicality of the defense. Mohammed Shayan, Sukanta Bhattacharjee, Tung-Che Liang, Jack Tang, Krishnendu Chakrabarty, Ramesh Karri |
ICCAD | 1 |
| 2012 | SEU tolerant robust memory cell designabstractThe implementation of semiconductor circuits and systems in nano-technology makes it possible to achieve high speed, lower voltage level and smaller area. The unintended and undesirable result of this scaling is that it makes integrated circuits susceptible to soft errors normally caused by alpha particle or neutron hits. These events of radiation strike resulting into bit upsets referred to as single event upsets(SEU), become increasingly of concern for the reliable circuit operation in the field. Storage elements are worst hit by this phenomenon. As we further scale down, there is greater interest in reliability of the circuits and systems, apart from the performance, power and area aspects. In this paper we propose an improved 12T SEU tolerant SRAM cell design. The proposed SRAM cell is economical in terms of area overhead. It is easy to fabricate as compared to earlier designs. Simulation results show that the proposed cell is highly robust, as it does not flip even for a transient pulse with 62 times the Qcritof a standard 6T SRAM cell. Mohammed Shayan, Virendra Singh, Adit D. Singh, Masahiro Fujita 0004 |
IOLTS | 1 |