Javad Bahrami

dblp:121/6185 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
10since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 3 first-author · 6 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 FAMOUS: Fault Attack Mitigation via Exploiting Invariances in Deep Neural Networks
abstract
Implementing Deep Neural Networks (DNNs) in hardware is essential due to rising Power-Performance-Area (PPA) demands and the limitations of GPUs in meeting them. However, such accelerators are vulnerable to Fault Injection Attacks (FIAs), such as those induced by laser illumination or Rowhammer. FAMOUS protects against FIAs by exploiting invariances in DNNs—particularly permutation invariance—by dynamically swapping convolutional channels and linear layer connections during runtime. This misleads attackers aiming to corrupt critical weights that significantly impact model output. We evaluate FAMOUS on transformer models (ViT-tiny and ViT-small) across multiple datasets. Even with 100 faults injected into essential weights, accuracy drops are minimal (≈4.7 and 0.02 points on ImageNet-1k), compared to severe drops (59 and 70 points) without protection. CNNs also benefit from FAMOUS, though to a lesser extent.
Javad Bahrami, Parsa Nooralinejad, Hamed Pirsiavash, Naghmeh Karimi
ITC1
2025 TIGER: TrIaGing KEy Refreshing Frequency via Digital Sensors
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Javad Bahrami, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
SECRYPT4
2024 Digital Twin Integrity Protection in Distributed Control Systems
abstract
The notion of Cyber-Physical Systems (CPS) reflects real-time control applications that are realized through distributed coordination among multiple modules. Such coordination is founded on frequent exchange of status and sensor data among the various modules so that actuation decisions are made autonomously. The formation of digital twins has emerged as an effective methodology where data-driven models are employed to enable effective decision making. Hence, the accuracy of these models become very critical for system stability; no wonder data forgery is a major threat for CPS where an attacker strives to inject faulty data to degrade the digital twin of one or multiple modules. Such an attack could be taking the form of impersonating a component, or manipulating/replaying status update packets. This paper proposes an effective scheme for mitigating such a threat by employing hardware-based fingerprinting primitives, namely, Physically Unclonable Functions (PUFs). The proposed PUF-based Integrity protection of digital Twins (PIT) scheme, ensures the authenticity of data sources, and the freshness and integrity of the shared status. PIT is validated using analysis and prototype implementation on an FPGA.
Mohammad Ebrahimabadi, Javad Bahrami, Mohamed F. Younis, Naghmeh Karimi
CCNC2
2024 Securing ISW Masking Scheme Against Glitches
abstract
Ishai-Sahai-Wagner (ISW) masking scheme has been proposed in literature to protect cryptographic circuitries against side-channel analysis attacks. Although provably secure from a theoretical standpoint, its hardware implementation may not be secure as such security proof holds true if the gates are only evaluated after all of their inputs are available, yet such requirement is not met in hardware as the gates are evaluated as soon as any single input of them is changed. This paper provides a repair for ISW to address its security concern and prevent the key recovery. Our method is based on inserting artificial delays and/or “refreshing” on some sensitive paths to ensure that the underlying combinational gates are evaluated in the order expected by the ISW rationale. We verify the security of our proposed structure by leakage detection. Our solution is called E-ISW standing for Enhanced-ISW.
Sofiane Takarabt, Javad Bahrami, Mohammad Ebrahimabadi, Sylvain Guilley, Naghmeh Karimi
DATE2
2024 Digital Twin Based Topology Fingerprinting for Detecting False Data Injection Attacks in Cyber-Physical Systems
abstract
A Cyber-Physical System (CPS) employs intercon-nected sensing and actuation modules and applies distributed control strategies. With the major advances in communication technology, the CPS design methodology is getting broadly adopted, including in safety and mission-critical applications. The incorporation of digital twins within a CPS facilitates localized decision-making by the individual control modules within the system in a timely manner without risking stability and performance. However, cyberattacks could be detrimental when false data is injected to degrade the accuracy of the underlying digital twins so that a CPS module takes non-optimal or even risky action that causes application failure. This paper proposes a novel approach for detecting such an attack scenario through a combination of a predictive data model and a topology fingerprinting scheme. Specifically, we employ a recurrent neural network (RNN) to predict the next state (data) for the individual modules and use it to reason about the periodic updates provided by these modules. Then, we apply a data-driven fingerprinting scheme that characterizes the inter-module interaction to infer and classify anomalies based on the module-provided data. The validation results using a dataset of a smart power grid application demonstrate the effectiveness of our approach.
Javad Bahrami, Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi
ICC1
2024 FAT-RABBIT: Fault-Aware Training towards Robustness AgainstBit-flip Based Attacks in Deep Neural Networks
abstract
Machine learning and in particular deep learning is used in a broad range of crucial applications. Implementing such models in custom hardware can be highly beneficial thanks to their low power and computation latency compared to GPUs. However, an error in their output can lead to disastrous outcomes. An adversary may force misclassification in the model’s outcome by inducing a number of bit-flips in the targeted locations; thus declining the accuracy. To fill the gap, this paper presents FAT-RABBIT, a cost-effective mechanism designed to mitigate such threats by training the model such that there would be few weights that can be highly impactful in the outcome; thus reducing the sensitivity of the model to the fault injection attacks. Moreover, to increase robustness against bit-wise large perturbations, we propose an optimization scheme so-called M-SAM. We then augment FAT-RABBIT with the M-SAM optimizer to further bolster model accuracy against bit-flipping fault attacks. Notably, these approaches incur no additional hardware overhead. Our experimental results demonstrate the robustness of FAT-RABBIT and its augmented version, called Augmented FAT-RABBIT, against such attacks.
Hossein Pourmehrani, Javad Bahrami, Parsa Nooralinejad, Hamed Pirsiavash, Naghmeh Karimi
ITC2
2023 Special Session: Security Verification & Testing for SR-Latch TRNGs
abstract
Secure chips implement cryptographic algorithms and protocols to ensure self-protection (e.g., firmware authenticity) as well as user data protection (e.g., encrypted data storage). In turn, cryptography needs to defer to incorruptible sources of entropy to implement their functions according to their mandatory usage guidance. Typically, keys, nonces, initialization vectors, tweaks, etc. shall not be guessed by attackers. In practice, True Random Number Generators (TRNGs) are in charge of producing such sensitive elements.Fully aware of the central role of TRNGs in the proper implementation of security in chips, stakeholders have been formalizing the requirements recently. The methods to strengthen such requirements are manifold. In this paper, we discuss and apply three of them by targeting the Set-Reset Latch TRNG which is an alternative to Ring-Oscillator (RO) TRNGs as it provides faster throughputs. The first method concerns the confidence in the TRNG being random enough. It explores how the TRNG properties can be reliably predicted by simulation, compared to real silicon experiments. The second aspect dealt with in this paper is the assessment of the TRNG properties over time, i.e., considering the impact of aging in the TRNG properties. Such knowledge is important as secure chips are expected to be in service for a long period, and it would be detrimental to the service they render if the quality of the entropy they deliver would be declining over time. Eventually, the third aspect of this paper is the timely detection of unforeseen failures or malevolent attacks. The mitigation lies in leveraging "health tests" launched prior to using random numbers.This paper focuses on a particular type of TRNG that is not prone to biasing by attackers: it is the so-called Set-Reset Latch (SR-latch) TRNG and exploits a race condition in an arbitration gate. Such kind of TRNG is of great practical interest as an alternative design compared to the mainstream "Ring Oscillator" TRNG, and it is also very amenable to analyses by various sorts of simulations aiming at properly characterizing its security in various operational environments.
Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
VTS1
2022 Leakage Power Analysis in Different S-Box Masking Protection Schemes
abstract
Internet-of- Things (IoT) devices are natural targets for side-channel attacks. Still, side-channel leakage can be com-plex: its modeling can be assisted by statistical tools. Projection of the leakage into an orthonormal basis allows to understand its structure, typically linear (1st-order leakage) or non-linear (sometimes referred to as glitches). In order to ensure cryptosystems protection, several masking methods have been published. Unfortunately, they follow different strategies; thus it is hard to compare them. Namely, ISW is constructive, GLUT is systematic, RSM is a low-entropy version of GLUT, RSM-ROM is a further optimization aiming at balancing the leakage further, and TI aims at avoiding, by design, the leakage arising from the glitches. In practice, no study has compared these styles on an equal basis. Accordingly, in this paper, we present a consistent methodology relying on a Walsh-Hadamard transform in this respect. We consider different masked implementations of substitution boxes of PRESENT algorithm, as this function is the most leaking in symmetric cryptography. We show that ISW is the most secure among the considered masking implementations. For sure, it takes strong advantage of the knowledge of the PRESENT substitution box equation. Tabulated masking schemes appear as providing a lesser amount of security compared to unprotected counterparts. The leakage is assessed over time, i.e., considering device aging which contributes to mitigate the leakage differently according to the masking style.
Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
DATE1
2022 On the Practicality of Relying on Simulations in Different Abstraction Levels for Pre-silicon Side-Channel Analysis
abstract
International audience
Javad Bahrami, Mohammad Ebrahimabadi, Sofiane Takarabt, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
SECRYPT1
2022 Special Session: On the Reliability of Conventional and Quantum Neural Network Hardware
abstract
Neural Networks (NNs) are being extensively used in critical applications such as aerospace, healthcare, autonomous driving, and military, to name a few. Limited precision of the underlying hardware platforms, permanent and transient faults injected unintentionally as well as maliciously, and voltage/temperature fluctuations can potentially result in malfunctions in NNs with consequences ranging from substantial reduction in the network accuracy to jeopardizing the correct prediction of the network in worst cases. To alleviate such reliability concerns, this paper discusses the state-of-the-art reliability enhancement schemes that can be tailored for deep learning accelerators. We will discuss the errors associated with the hardware implementation of Deep-Learning (DL) algorithms along with their corresponding countermeasures. An in-field self-test methodology with a high test coverage is introduced, and an accurate high-level framework, so-called FIdelity, is proposed that enables the designers to evaluate DL accelerators in presence of such errors. Then, a state-of-the-art robustness-preserving training algorithm based on the Hessian Regularization is introduced. This algorithm alleviates the perturbations during inference time with negligible degradation in the accuracy of the network. Finally, Quantum Neural Networks (QNNs) and the methods to make them resilient against a variety of vulnerabilities such as fault injection, spatial and temporal variations in Qubits, and noise in QNNs are discussed.
Mehdi Sadi, Yi He 0010, Yanjing Li, Mahabubul Alam, Satwik Kundu, Swaroop Ghosh, Javad Bahrami, Naghmeh Karimi
VTS7