EDBT 2026 Demo / reviewers in the wild / expert
Shameek Bhattacharjee
dblp:13/10522
· DBLP profile ↗
40ranked-venue papers
12as first author
20since 2021 · last 2025
0000-0003-3596-9447ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 11 since 2021Artificial intelligence and machine learning · 10 · 8 since 2021Security and privacy · 8 · 6 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Enhancing AI Competency in e-Science with Immersive Learning ExperiencesabstractMembers of the Western Michigan Transformative Interdisciplinary Human+AI Research Group have been engaged in two consecutive NSF-funded projects to promote AI readiness in diverse STEM disciplines. Putting equal emphasis on theory and practice, our goal is to instill knowledge and competency in safe, secure, and reliable AI across a wide range of learners from high school students through to university students and practitioners who wish to upskill. The second project that is currently underway has a specific focus on machine-assisted processing of massive data. This presentation focuses on the development of immersive learning experiences. Irene Kahvazadeh, Steve Carr 0001, Ajay Gupta 0001, Shameek Bhattacharjee |
eScience | 5 |
| 2025 | Coordinated Thermal Safety Attack and Defense on EV Battery Management SystemsabstractBattery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks. Moayad Altawalbeh, Richard T. Meyer, Shameek Bhattacharjee |
SMARTCOMP | 3 |
| 2024 | A Unified Time Series Analytics based Intrusion Detection Framework for CAN BUS AttacksabstractModern smart vehicles have a Controller Area Network (CAN) that supports intra-vehicle communication between intelligent Electronic Control Units (ECUs). The CAN is known to be vulnerable to various cyber attacks. In this paper, we propose a unified framework that can detect multiple types of cyber attacks (viz., Denial of Service, Fuzzy, Impersonation) affecting the CAN. Specifically, we construct a feature by observing the timing information of CAN packets exchanged over the CAN bus network over partitioned time windows to construct a low dimensional representation of the entire CAN network as a time series latent space. Then, we apply a two tier anomaly based intrusion detection model that keeps track of short term and long term memory of deviations in the initial time series latent space, to create a 'stateful latent space'. Then, we learn the boundaries of the benign stateful latent space that specify the attack detection criterion. To find hyper-parameters of our proposed model, we formulate a preference based multi-objective optimization problem that optimizes security objectives tailored for a network-wide time series anomaly based intrusion detector by balancing trade-offs between false alarm count, time to detection, and missed detection rate. We use real benign and attack datasets collected from a Kia Soul vehicle to validate our framework and show how our performance outperforms existing works. Maisha Maliha, Shameek Bhattacharjee |
CODASPY | 2 |
| 2024 | Intent-Driven Data Falsification Attack on Collaborative IoT-Edge EnvironmentsabstractCollaborative IoT-edge environments, although effective in hosting latency-sensitive applications, are fundamentally vulnerable to data falsification attacks that can potentially impact key system performance objectives. In this paper, we explore and propose an intent-driven energy data falsification attack model for collaborative IoT-edge environments and shed light on the attack's impact on system performance. Our primary contribution lies in developing key intuitions and systemization of threat landscape for attacks with selfish and malicious intents that target one or many key system performance objectives, viz., overall system energy-efficiency and end-to-end latency of hosted applications. The proposed attack model is evaluated, optimized, and validated through ‘testbed-in-the-loop’ simulations. The results demonstrate that depending on selfish and malicious intents, the proposed attack model can achieve upto 50% increase in energy savings for the compromised IoT devices, accelerate battery drainage of non-compromised devices, and ensure upto 61% success in violating application latency requirements. Shima Yousefi, Shameek Bhattacharjee, Saptarshi Debroy |
SEC | 2 |
| 2024 | Early Detection of Driving Maneuvers for Proactive Congestion PreventionabstractRoad traffic congestion affects not only the commute delay but also a city's overall social, economic, and environmental growth. Existing approaches for road congestion mitigation primarily adopt a reactive approach by detecting congestion after it occurs and recommending alternate routes to the vehicles, which fails to prevent congestion cascading. In contrast, we propose a pervasive platform called ProCon that proactively infers the driving micro-behaviors that can contribute to congestion formation and assist the drivers in avoiding such maneuvers in real-time during the navigation. Thorough evaluations over multiple real-life and simulated datasets indicate that ProCon can reduce congestion for more than 60% of the scenarios on average while significantly reducing the travel time of the vehicles. Debasree Das, Shameek Bhattacharjee, Sandip Chakraborty 0001, Bivas Mitra, Sajal K. Das 0001 |
PerCom | 2 |
| 2024 | On the Role of Re-Descending M-Estimators in Resilient Anomaly Detection for Smart Living CPSabstractAnomaly-based attack detection methods that rely on learning the benign profile of operation are commonly used for identifying data falsification attacks and faults in cyber-physical systems. However, most works do not assume the presence of attacks while training the anomaly detectors- and their impact on eventual anomaly detection performance during the test set. Some robust learning methods overcompensate mitigation which leads to increased false positives in the absence of attacks/threats during training. To achieve this balance, this paper proposes a framework to enhance the robustness of previous anomaly detection frameworks in smart living applications, by introducing three profound design changes for threshold learning of time series anomaly detectors:(1) Tukey biweight loss function instead of square loss function (2) adding quantile weights to regression errors of Tukey (3) modifying the definition of empirical cost function from MSE to the harmonic mean of quantile weighted Tukey losses. We show that these changes mitigate performance degradation in anomaly detectors caused by untargeted poisoning attacks during training- while is simultaneously able to prevent false alarms in the absence of such training set attacks. We evaluate our work using a proof of concept that uses state-of-the-art anomaly detection in smart living CPS that detects false data injection in smart metering. Sahar Abedzadeh, Shameek Bhattacharjee |
SMARTCOMP | 2 |
| 2024 | Science of Cyber Physical Security in Smart Living CPS ApplicationsabstractThe vision behind community-scale smart living applications is to use sensor- actuator devices, the so-called Internet of Things (IoT), to generate sensing data that provide situational awareness of the physical world to improve the quality of human life at the city scale. Examples applications include smart transportation, customer and distribution layers of the smart grid metering, smart water networks, etc. The effects of threats such cyber-attacks, device/network faults and malfunctions, unsafe events, typically manifest themselves as anomalies that need to be promptly detected. However, there are unique challenges in anomaly detection for smart living : (1) behavioral randomness of humans creates dynamic spatiotemporal variations in data patterns making it difficult to learn the profile of benign behavior leading to unusable false alarm frequencies; (2) High non-linearity, non-IID data, random evolving patterns, cause traditional anomaly detection/learning methods to lose detection sensitivity; (3) smart living sensing data often have privacy and individual device profiling concerns; (4) unlabeled threats present while learning benign profile. Sajal K. Das 0001, Shameek Bhattacharjee |
SMARTCOMP | 2 |
| 2024 | Message from BITS 2024 Co-Chairs and Technical Program Co-Chairs; SMARTCOMP 2024abstractIt is our great pleasure to welcome you to the 8th IEEE International Workshop on Big Data and IoT Security in Smart Computing (BITS 2024) co-located with the 10th IEEE International Conference on Smart Computing (SMARTCOMP 2024). This year, the BITS 2024 is held in person in Osaka, Japan. Sajal K. Das 0001, Hayato Yamana, Keiichi Yasumoto, Shameek Bhattacharjee |
SMARTCOMP | 4 |
| 2024 | Scalable Pythagorean Mean-based Incident Detection in Smart Transportation SystemsabstractModern smart cities need smart transportation solutions to quickly detect various traffic emergencies and incidents in the city to avoid cascading traffic disruptions. To materialize this, roadside units and ambient transportation sensors are being deployed to collect speed data that enables the monitoring of traffic conditions on each road segment. In this article, we first propose a scalable data-driven anomaly-based traffic incident detection framework for a city-scale smart transportation system. Specifically, we propose an incremental region growing approximation algorithm for optimal Spatio-temporal clustering of road segments and their data; such that road segments are strategically divided into highly correlated clusters. The highly correlated clusters enable identifying a Pythagorean Mean-based invariant as an anomaly detection metric that is highly stable under no incidents but shows a deviation in the presence of incidents. We learn the bounds of the invariants in a robust manner such that anomaly detection can generalize to unseen events, even when learning from real noisy data. Second, using cluster-level detection, we propose a folded Gaussian classifier to pinpoint the particular segment in a cluster where the incident happened in an automated manner. We perform extensive experimental validation using mobility data collected from four cities in Tennessee and compare with the state-of-the-art ML methods to prove that our method can detect incidents within each cluster in real-time and outperforms known ML methods. Mohammad Jaminur Islam, Jose Paolo Talusan, Shameek Bhattacharjee, Francis Tiausas, Abhishek Dubey, Keiichi Yasumoto, Sajal K. Das 0001 |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2024 | Noise Resilient Learning for Attack Detection in Smart Grid PMU InfrastructureabstractFalsified data from compromised Phasor Measurement Units (PMUs) in a smart grid induce Energy Management Systems (EMS) to have an inaccurate estimation of the state of the grid, disrupting various operations of the power grid. Moreover, the PMUs deployed at the distribution layer of a smart grid show dynamic fluctuations in their data streams, which make it extremely challenging to design effective learning frameworks for anomaly based attack detection. In this paper, we propose a noise resilient learning framework for anomaly based attack detection specifically for distribution layer PMU infrastructure, that show real time indicators of data falsifications attacks while offsetting the effect of false alarms caused by the noise. Specifically, we propose a feature extraction framework that uses some Pythagorean Means of the active power from a cluster of PMUs, reducing multi-dimensional nature of the PMU data streams via quick Big Data summarization. We also propose a robust and noise resilient methodology for learning thresholds based on generalized robust estimation theory of our invariant feature. We experimentally validate our approach and demonstrate improved reliability performance using two completely different datasets collected from real distribution level PMU infrastructures. Prithwiraj Roy, Shameek Bhattacharjee, Sahar Abedzadeh, Sajal K. Das 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Detection of False Data Injection in Smart Water Metering InfrastructureabstractSmart water metering (SWM) infrastructure collects real-time water usage data that is useful for automated billing, leak detection, and forecasting of peak periods. Cyber/physical attacks can lead to data falsification on water usage data. This paper proposes a learning approach that converts smart water meter data into a Pythagorean mean-based invariant that is highly stable under normal conditions but deviates under attacks. We show how adversaries can launch deductive or camouflage attacks in the SWM infrastructure to gain benefits and impact the water distribution utility. Then, we apply a two-tier approach of stateless and stateful detection, reducing false alarms without significantly sacrificing the attack detection rate. We validate our approach using real-world water usage data of 92 households in Alicante, Spain for varying attack scales and strengths and prove that our method limits the impact of undetected attacks and expected time between consecutive false alarms. Our results show that even for low-strength, low-scale deductive attacks, the model limits the impact of an undetected attack to only C0.2199375 and for high-strength, low-scale camouflage attack, the impact of an undetected attack was limited to C1.434375 Ayanfeoluwa Oluyomi, Shameek Bhattacharjee, Sajal K. Das 0001 |
SMARTCOMP | 2 |
| 2023 | HPRoP: Hierarchical Privacy-preserving Route Planning for Smart CitiesabstractRoute Planning Systems (RPS) are a core component of autonomous personal transport systems essential for safe and efficient navigation of dynamic urban environments with the support of edge-based smart city infrastructure, but they also raise concerns about user route privacy in the context of both privately owned and commercial vehicles. Numerous high-profile data breaches in recent years have fortunately motivated research on privacy-preserving RPS, but most of them are rendered impractical by greatly increased communication and processing overhead. We address this by proposing an approach called Hierarchical Privacy-Preserving Route Planning (HPRoP), which divides and distributes the route-planning task across multiple levels and protects locations along the entire route. This is done by combining Inertial Flow partitioning, Private Information Retrieval (PIR), and Edge Computing techniques with our novel route-planning heuristic algorithm. Normalized metrics were also formulated to quantify the privacy of the source/destination points ( endpoint location privacy ) and the route itself ( route privacy ). Evaluation on a simulated road network showed that HPRoP reliably produces routes differing only by ≤ 20% in length from optimal shortest paths, with completion times within ∼ 25 seconds, which is reasonable for a PIR-based approach. On top of this, more than half of the produced routes achieved near-optimal endpoint location privacy (∼ 1.0) and good route privacy (≥ 0.8). Francis Tiausas, Keiichi Yasumoto, Jose Paolo Talusan, Hayato Yamana, Hirozumi Yamaguchi, Shameek Bhattacharjee, Abhishek Dubey, Sajal K. Das 0001 |
ACM Trans. Cyber Phys. Syst. | 6 |
| 2022 | Active Learning Augmented Folded Gaussian Model for Anomaly Detection in Smart TransportationabstractSmart transportation networks have become instrumental in smart city applications with the potential to enhance road safety, improve the traffic management system and driving experience. A Traffic Message Channel (TMC) is an IoT device that records the data collected from the vehicles and forwards it to the Road Side Units (RSUs). This data is further processed and shared with the vehicles to inquire the fastest route and incidents that can cause significant delays. The failure of the TMC sensors can have adverse effects on the transportation network. In this paper, we propose a Gaussian distribution based trust scoring model to identify anomalous TMC devices. Then we propose a semi-supervised active learning approach that reduces the manual labeling cost to determine the threshold to classify the honest and malicious devices. Extensive simulation results using real-world vehicular data from Nashville are provided to verify the accuracy of the proposed method. Venkata Praveen Kumar Madhavarapu, Prithwiraj Roy, Shameek Bhattacharjee, Sajal K. Das 0001 |
ICC | 3 |
| 2022 | Privacy-Preserving Data Falsification Detection in Smart Grids using Elliptic Curve Cryptography and Homomorphic EncryptionabstractIn an advanced metering infrastructure (AMI), the electric utility collects power consumption data from smart meters to improve energy optimization and provides detailed information on power consumption to electric utility customers. However, AMI is vulnerable to data falsification attacks, which organized adversaries can launch. Such attacks can be detected by analyzing customers' fine-grained power consumption data; however, analyzing customers' private data violates the customers' privacy. Although homomorphic encryption-based schemes have been proposed to tackle the problem, the disadvantage is a long execution time. This paper proposes a new privacy-preserving data falsification detection scheme to shorten the execution time. We adopt elliptic curve cryptography (ECC) based on homomorphic encryption (HE) without revealing customer power consumption data. HE is a form of encryption that permits users to perform computations on the encrypted data without decryption. Through ECC, we can achieve light computation. Our experimental evaluation showed that our proposed scheme successfully achieved 18 times faster than the CKKS scheme, a common HE scheme. Sanskruti Joshi, Ruixiao Li, Shameek Bhattacharjee, Sajal K. Das 0001, Hayato Yamana |
SMARTCOMP | 3 |
| 2022 | Look-Up Table based FHE System for Privacy Preserving Anomaly Detection in Smart GridsabstractIn advanced metering infrastructure (AMI), the customers' power consumption data is considered private but needs to be revealed to data-driven attack detection frameworks. In this paper, we present a system for privacy-preserving anomaly-based data falsification attack detection over fully homomorphic encrypted (FHE) data, which enables computations required for the attack detection over encrypted individual customer smart meter's data. Specifically, we propose a homomorphic look-up table (LUT) based FHE approach that supports privacy preserving anomaly detection between the utility, customer, and multiple partied providing security services. In the LUTs, the data pairs of input and output values for each function required by the anomaly detection framework are stored to enable arbitrary arithmetic calculations over FHE. Furthermore, we adopt a private information retrieval (PIR) approach with FHE to enable approximate search with LUTs, which reduces the execution time of the attack detection service while protecting private information. Besides, we show that by adjusting the significant digits of inputs and outputs in our LUT, we can control the detection accuracy and execution time of the attack detection, even while using FHE. Our experiments confirmed that our proposed method is able to detect the injection of false power consumption in the range of 11–17 secs of execution time, depending on detection accuracy. Ruixiao Li, Shameek Bhattacharjee, Sajal K. Das 0001, Hayato Yamana |
SMARTCOMP | 2 |
| 2021 | A Diversity Index based Scoring Framework for Identifying Smart Meters Launching Stealthy Data Falsification AttacksabstractA challenging problem in Advanced Metering Infrastructure (AMI) of smart grids is the identification of smart meters under the control of a stealthy adversary, that inject very low margins of stealthy data falsification. The problem is challenging due to wide legitimate variation in both individual and aggregate trends in real world power consumption data, making such stealthy attacks unrecognizable by existing approaches. In this paper, via proposed modified diversity index scoring metric, we propose a novel information-theory inspired data driven device anomaly classification framework to identify compromised meters launching low margins of stealthy data falsification attacks. Specifically, we draw a parallelism between the effects of data falsification attacks and ecological balance disruptions and identify required mathematical modifications in existing Renyi Entropy and Hill's Diversity Entropy measures. These modifications such as expected self-similarity with weighted abundance shifts across various temporal scales, and diversity order are appropriately embedded in our resulting framework. The resulting diversity index score is used to classify smart meters launching additive, deductive, and alternating switching attack types with high sensitivity (as low as 100W) compared to the existing works that perform poorly at margins of false data below 400W. Our proposed theory is validated with two different real smart meter datasets from USA and Ireland. Experimental results demonstrate successful detection sensitivity from very low to high margins of false data, thus reducing undetectable strategy space of attacks in AMI for an adversary having complete knowledge of our method. Shameek Bhattacharjee, Venkata Praveen Kumar Madhavarapu, Sajal K. Das 0001 |
AsiaCCS | 1 |
| 2021 | User-centric Distributed Route Planning in Smart Cities based on Multi-objective OptimizationabstractThe realization of edge-based cyber-physical systems (CPS) poses important challenges in terms of performance, robustness, security, etc. This paper examines a novel approach to providing a user-centric adaptive route planning service over a network of Road Side Units (RSUs) in smart cities. The key idea is to adaptively select routing task parameters such as privacy-cloaked area sizes and number of retained intersections to balance processing time, privacy protection level, and route accuracy for privacy-augmented distributed route search while also handling per-query user preferences. This is formulated as an optimization problem with a set of parameters giving the best result for a set of queries given system constraints. Processing Throughput, Privacy Protection, and Travel Time Accuracy were developed as the objective functions to be balanced. A Multi-Objective Genetic Algorithm based technique (NSGA-II) is applied to recover a feasible solution. The performance of this approach was then evaluated using traffic data from Osaka, Japan. Results show good performance of the approach in balancing the aforementioned objectives based on user preferences. Francis Tiausas, Jose Paolo Talusan, Yu Ishimaki, Hayato Yamana, Hirozumi Yamaguchi, Shameek Bhattacharjee, Abhishek Dubey, Keiichi Yasumoto, Sajal K. Das 0001 |
SMARTCOMP | 6 |
| 2021 | Resilience Against Bad Mouthing Attacks in Mobile Crowdsensing Systems via Cyber DeceptionabstractMobile Crowdsensing System (MCS) applications deploy rating feedback mechanisms to help quantify the trustworthiness of published events which over time improve decision accuracy and establish user reputation. In this paper, we first show that factors such as sparseness, inherent error probabilities of rating feedback labelers, and prior knowledge of the event trust scoring models, can be used by strategic adversaries to hijack the feedback labeling mechanism itself with bad mouthing attacks. Then, we propose a randomized rating sub-sampling technique inspired from moving target defense and cyber deception to mitigate the degradation in the resulting event trust scores of truthful events. We offer a game theoretic strategy under various knowledge levels of an adversary and the MCS in regards to picking an optimal sub-sample size for bad mouthing attacks and event trust calculations respectively, by using a vehicular crowdsensing as a proof-of-concept. Prithwiraj Roy, Shameek Bhattacharjee, Hussein Alsheakh, Sajal K. Das 0001 |
WOWMOM | 2 |
| 2021 | Detection and Forensics against Stealthy Data Falsification in Smart Metering InfrastructureabstractFalse power consumption data injected from compromised smart meters in Advanced Metering Infrastructure (AMI) of smart grids is a threat that negatively affects both customers and utilities. In particular, organized and stealthy adversaries can launch various types of data falsification attacks from multiple meters using smart or persistent strategies. In this paper, we propose a real time, two tier attack detection scheme to detect orchestrated data falsification under a sophisticated threat model in decentralized micro-grids. The first detection tier monitors whether the Harmonic to Arithmetic Mean Ratio of aggregated daily power consumption data is outside a normal range known as safe margin. To confirm whether discrepancies in the first detection tier is indeed an attack, the second detection tier monitors the sum of the residuals (difference) between the proposed ratio metric and the safe margin over a frame of multiple days. If the sum of residuals is beyond a standard limit range, the presence of a data falsification attack is confirmed. Both the `safe margins' and the `standard limits' are designed through a `system identification phase', where the signature of proposed metrics under normal conditions are studied using real AMI micro-grid data sets from two different countries over multiple years. Subsequently, we show how the proposed metrics trigger unique signatures under various attacks which aids in attack reconstruction and also limit the impact of persistent attacks. Unlike metrics such as CUSUM or EWMA, the stability of the proposed metrics under normal conditions allows successful real time detection of various stealthy attacks with ultra-low false alarms. Shameek Bhattacharjee, Sajal K. Das 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Attack Context Embedded Data Driven Trust Diagnostics in Smart Metering InfrastructureabstractSpurious power consumption data reported from compromised meters controlled by organized adversaries in the Advanced Metering Infrastructure (AMI) may have drastic consequences on a smart grid’s operations. While existing research on data falsification in smart grids mostly defends against isolated electricity theft, we introduce a taxonomy of various data falsification attack types, when smart meters are compromised by organized or strategic rivals. To counter these attacks, we first propose a coarse-grained and a fine-grained anomaly-based security event detection technique that uses indicators such as deviation and directional change in the time series of the proposed anomaly detection metrics to indicate: (i) occurrence, (ii) type of attack, and (iii) attack strategy used, collectively known as attack context . Leveraging the attack context information, we propose three attack response metrics to the inferred attack context: (a) an unbiased mean indicating a robust location parameter; (b) a median absolute deviation indicating a robust scale parameter; and (c) an attack probability time ratio metric indicating the active time horizon of attacks. Subsequently, we propose a trust scoring model based on Kullback-Leibler (KL) divergence, that embeds the appropriate unbiased mean, the median absolute deviation, and the attack probability ratio metric at runtime to produce trust scores for each smart meter. These trust scores help classify compromised smart meters from the non-compromised ones. The embedding of the attack context, into the trust scoring model, facilitates accurate and rapid classification of compromised meters, even under large fractions of compromised meters, generalize across various attack strategies and margins of false data. Using real datasets collected from two different AMIs, experimental results show that our proposed framework has a high true positive detection rate, while the average false alarm and missed detection rates are much lesser than 10% for most attack combinations for two different real AMI micro-grid datasets. Finally, we also establish fundamental theoretical limits of the proposed method, which will help assess the applicability of our method to other domains. Shameek Bhattacharjee, Venkata Praveen Kumar Madhavarapu, Simone Silvestri, Sajal K. Das 0001 |
ACM Trans. Priv. Secur. | 1 |
| 2020 | Real Time Stream Mining based Attack Detection in Distribution Level PMUs for Smart GridsabstractReliable automation of smart grids depends on decisions based on situational awareness extracted via real time system monitoring and accurate state estimation. The Phasor Measurement Units (PMU) at distribution and transmission layers of the smart grid provide high velocity real time information on voltage and current magnitudes and angles in a three phase electrical grid. Naturally, the authenticity of the PMU data is of utmost operational importance. Data falsification attacks on PMU data can cause the Energy Management Systems (EMS) to take wrong decisions, potentially having drastic consequences on the power grid's operation. The need for an automated data falsification attack detection and isolation is key for EMS protection from PMU data falsification. In this paper, we propose an automated distributed stream mining approach to time series anomaly based attack detection that identifies attacks while distinguishing from legitimate changes in PMU data trends. Specifically, we provide a real time learning invariant that reduces the multi-dimensional nature of the PMU data streams for quick big data summarization using a Pythagorean means of the active power from a cluster of PMUs. Thereafter, we propose a methodology that learns thresholds of the invariant automatically, to prove the predictive power of distinguishing between small attacks versus legitimate changes. Extensive simulation results using real PMU data are provided to verify the accuracy of the proposed method. Prithwiraj Roy, Shameek Bhattacharjee, Sajal K. Das 0001 |
GLOBECOM | 2 |
| 2020 | Towards a Unified Trust Framework for Detecting IoT Device Attacks in Smart HomesabstractTrust in Smart Home (SH) Internet of Things (IoT) technologies is a primary concern for consumers, which is preventing the widespread adoption of smart home services. Additionally, the variety of IoT devices and cyber attacks make it hard to build a generic attack detection framework for smart home IoT devices. In this paper, we present a roadmap towards building a unified approach towards establishing trust scores as an indicator of the security status of an IoT device in a smart home that works across multiple attacks and device types/protocols. Specifically, we first introduce artificial reasoning inspired evidence collection approach by introducing a small set of factors that are affected significantly if a smart home IoT device is under attack. Thereafter, we propose an explainable trust scoring model that maps the device level evidence into trust scores in a way that produces lower trust scores when devices are under attack. Specifically, the trust model involves an Augmented Bayesian Belief based Model embedded with novel non-linear weighing functions; explicitly designed to account for the severity of the attack, probabilistic discounting of parts of the evidence caused by benign changes, thus explaining our success. For evaluation of the framework, we use two real datasets that contain a variety of actual cyber-attacks and benign traffic from seven different smart home IoT devices. Our evaluation seeks to investigate the generality of our framework across multiple datasets, with various classes of IoT devices and cyber attacks. Hussein Alsheakh, Shameek Bhattacharjee |
MASS | 2 |
| 2020 | QnQ: Quality and Quantity Based Unified Approach for Secure and Trustworthy Mobile CrowdsensingabstractA major challenge in mobile crowdsensing applications is the generation of false (or spam) contributions resulting from selfish and malicious behaviors of users, or wrong perception of an event. Such false contributions induce loss of revenue owing to undue incentivization, and also affect the operational reliability of the applications. To counter these problems, we propose an event-trust and user-reputation model, called QnQ, to segregate different user classes such as honest, selfish, or malicious. The resultant user reputation scores, are based on both `quality' (accuracy of contribution) and `quantity' (degree of participation) of their contributions. Specifically, QnQ exploits a rating feedback mechanism for evaluating an event-specific expected truthfulness, which is then transformed into a robust quality of information (QoI) metric to weaken various effects of selfish and malicious user behaviors. Eventually, the QoIs of various events in which a user has participated are aggregated to compute his reputation score, which in turn is used to judiciously disburse user incentives with a goal to reduce the incentive losses of the CS application provider. Subsequently, inspired by cumulative prospect theory (CPT), we propose a risk tolerance and reputation aware trustworthy decision making scheme to determine whether an event should be published or not, thus improving the operational reliability of the application. To evaluate QnQ experimentally, we consider a vehicular crowdsensing application as a proof-of-concept. We compare QoI performance achieved by our model with Jøsang's belief model, reputation scoring with Dempster-Shafer based reputation model, and operational (decision) accuracy with expected utility theory. Experimental results demonstrate that QnQ is able to better capture subtle differences in user behaviors based on both quality and quantity, reduces incentive losses, and significantly improves operational accuracy in presence of rogue contributions. Shameek Bhattacharjee, Nirnay Ghosh, Vijay Kumar Shah, Sajal K. Das 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | A Diverse Band-Aware Dynamic Spectrum Access Network Architecture for Delay-Tolerant Smart City ApplicationsabstractAccording to the Smart City Council, an adequate telecommunications infrastructure is vital for the success of businesses, industries as well as residents of Smart cities. However, currently available standard and cellular technologies, such as 3/4G, GSM (Global System for Mobile Communications) and LTE (Long-Term Evolution), are rapidly reaching their limit mainly due to increased traffic demand. Such limitations are only going to worsen in the next years, due to the advent of Internet of Things technologies that are expected to interconnect billions of devices to the Internet. In this paper, we propose a novel network architecture that supports several delay-tolerant (non-real-time) Smart city applications and services (e.g., gathering air pollution information), and therefore, a promising approach to address the burdening of increased traffic demand to Smart city's legacy standard and cellular communication infrastructure. The proposed architecture is based on an innovative diverse band-aware Dynamic Spectrum Access (d-DSA) paradigm, that allows a certain wireless device to opportunistically access idle channels in multiple licensed/unlicensed spectrum bands. d-DSA radio devices are mounted on Smart city's urban vehicles (e.g., taxis) that act as mobile routers to gather, carry, and forward various types of data traffic. This results in a time-varying and unpredictable delay-tolerant network (DTN) where each node can access whitespace channels and transmit in multiple spectrum bands. Given lack of research in efficient routing schemes for such d-DSA DTN networks, we propose a distributed and lightweight d-DSA aware Geographical Routing (dDSA-GR) protocol, that utilizes a weighted linear metric for selecting a suitable spectrum band, and classic georouting principle for choosing next hop node in the path route between any node pair in d-DSA DTNs. Results on realistic traces based on the map of Lexington, KY, USA, show that our dDSA-GR routing protocol outperforms baseline approaches in terms of network delay, message delivery ratio, and energy efficiency, under all considered scenarios. Vijay Kumar Shah, Brian Luciano, Simone Silvestri, Shameek Bhattacharjee, Sajal K. Das 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | A Prospect Theoretic Approach for Trust Management in IoT Networks Under Manipulation AttacksabstractAs Internet of Things (IoT) and Cyber-Physical systems become more ubiquitous in our daily lives, it necessitates the capability to measure the trustworthiness of the aggregate data from such systems to make fair decisions. However, the interpretation of trustworthiness is contextual and varies according to the risk tolerance attitude of the concerned application. In addition, there exist varying levels of uncertainty associated with an evidence upon which a trust model is built. Hence, the data integrity scoring mechanisms require some provisions to adapt to different risk attitudes and uncertainties. In this article, we propose a prospect theoretic framework for data integrity scoring that quantifies the trustworthiness of the collected data from IoT devices in the presence of adversaries who try to manipulate the data. In our proposed method, we consider an imperfect anomaly monitoring mechanism that tracks the transmitted data from each device and classifies the outcome (trustworthiness of data) as not compromised, compromised, or undecided . These outcomes are conceptualized as a multinomial hypothesis of a Bayesian inference model with three parameters. These parameters are then used for calculating a utility value via prospect theory to evaluate the reliability of the aggregate data at an IoT hub. In addition, to take into account different risk attitudes, we propose two types of fusion rule at IoT hub—optimistic and conservative. Furthermore, we put forward asymmetric weighted moving average scheme to measure the trustworthiness of aggregate data in presence of On-Off attacks. The proposed framework is validated using extensive simulation experiments for both uniform and On-Off attacks. We show how trust scores vary under a variety of system factors like attack magnitude and inaccurate detection. In addition, we measure the trustworthiness of the aggregate data using the well-known expected utility theory and compare the results with that obtained by prospect theory. The simulation results reveal that prospect theory quantifies trustworthiness of the aggregate data better than expected utility theory. Mehrdad Salimitari, Shameek Bhattacharjee, Mainak Chatterjee, Yaser P. Fallah |
ACM Trans. Sens. Networks | 2 |
| 2019 | Smart Transportation Delay and Resiliency Testbed Based on Information Flow of Things MiddlewareabstractEdge and Fog computing paradigms are used to process big data generated by the increasing number of IoT devices. These paradigms have enabled cities to become smarter in various aspects via real-time data-driven applications. While these have addressed some flaws of cloud computing some challenges remain particularly in terms of privacy and security. We create a testbed based on a distributed processing platform called the Information flow of Things (IFoT) middleware. We briefly describe a decentralized traffic speed query and routing service implemented on this framework testbed. We configure the testbed to test countermeasure systems that aim to address the security challenges faced by prior paradigms. Using this testbed, we investigate a novel decentralized anomaly detection approach for time-sensitive distributed smart transportation systems. Jose Paolo Talusan, Francis Tiausas, Keiichi Yasumoto, Michael Wilbur, Geoffrey Pettet, Abhishek Dubey, Shameek Bhattacharjee |
SMARTCOMP | 7 |
| 2019 | A Decentralized Approach for Real Time Anomaly Detection in Transportation NetworksabstractInternet of Things (IoT), edge/fog computing, and the cloud are fueling rapid development in smart connected cities. Given the increasing rate of urbanization, the advancement of these technologies is a critical component of mitigating demand on already constrained transportation resources. Smart transportation systems are most effectively implemented as a decentralized network, in which traffic sensors send data to small low-powered devices called Roadside Units (RSUs). These RSUs host various computation and networking services. Data driven applications such as optimal routing require precise real-time data, however, data-driven approaches are susceptible to data integrity attacks. Therefore we propose a multi-tiered anomaly detection framework which utilizes spare processing capabilities of the distributed RSU network in combination with the cloud for fast, real-time detection. In this paper we present a novel real time anomaly detection framework. Additionally, we focus on implementation of our framework in smart-city transportation systems by providing a constrained clustering algorithm for RSU placement throughout the network. Extensive experimental validation using traffic data from Nashville, TN demonstrates that the proposed methods significantly reduce computation requirements while maintaining similar performance to current state of the art anomaly detection methods. Michael Wilbur, Abhishek Dubey, Bruno Leão, Shameek Bhattacharjee |
SMARTCOMP | 4 |
| 2018 | Towards Fast and Semi-supervised Identification of Smart Meters Launching Data Falsification AttacksabstractCompromised smart meters sending false power consumption data in Advanced Metering Infrastructure (AMI) may have drastic consequences on the smart grid»s operation. Most existing defense models only deal with electricity theft from individual customers (isolated attacks) using supervised classification techniques that do not offer scalable or real time solutions. Furthermore, the cyber and interconnected nature of AMIs can also be exploited by organized adversaries who have the ability to orchestrate simultaneous data falsification attacks after compromising several meters, and also have more complex goals than just electricity theft. In this paper, we first propose a real time semi-supervised anomaly based consensus correction technique that detects the presence and type of smart meter data falsification, and then performs a consensus correction accordingly. Subsequently, we propose a semi-supervised consensus based trust scoring model, that is able to identify the smart meters injecting false data. The main contribution of the proposed approach is to provide a practical framework for compromised smart meter identification that (i) is not supervised (ii) enables quick identification (iii) scales classification error rates better for larger sized AMIs; (iv) counters threats from both isolated and orchestrated attacks; and (v) simultaneously works for a variety of data falsification types. Extensive experimental validation using two real datasets from USA and Ireland, demonstrates the ability of our proposed method to identify compromised meters in near real time across different datasets. Shameek Bhattacharjee, Aditya Thakur 0002, Sajal K. Das 0001 |
AsiaCCS | 1 |
| 2018 | Designing Green Communication Systems for Smart and Connected Communities via Dynamic Spectrum AccessabstractSmart and connected communities (SCCs) are emerging as a novel paradigm that allows the community residents to be connected with surrounding environments through smart technologies. However, there remain important challenges to fully exploit the potential of SCCs in improving societal well-being and prosperity. In particular, there is a need for designing green communication systems that are also capable of providing high quality of service (QoS) to distribute and collect information to and from SCCs. However, simultaneously satisfying both of these criteria is difficult due to varying demands posed by heterogeneous sensing modalities, lack of dedicated infrastructure in rural/sub-urban areas, and certain sustainability constraints. While low-power short-range technologies often fail to achieve high QoS, using 3G or 4G technologies (LTE, LTE-A, GSM) for SCCs will eventually face spectrum scarcity and cross technology interference. In recent times, Dynamic spectrum access (DSA) has been proposed as a solution to overcome policy constraints and improve spectrum scarcity by spectrum sharing. In this article, we show that harnessing DSA in the context of SCCs can also achieve notable benefits in terms of energy efficiency and sustainability. Specifically, we propose a novel architecture for designing sustainable SCCs using a small-scale DSA-enabled overlay network that improves end-to-end energy efficiency of the network while guaranteeing QoS. We also propose a dynamic spectrum band selection approach that intelligently matches any message requirement to a suitable band type by exploiting distinct electro-magnetic characteristics of various bands. Since data generated in SCCs are typically valuable only when delivered within a certain hard (or soft ) deadline, we formulate a linear optimization problem for determining the most energy-efficient path that ensures a delivery time within the hard deadline. After proving that such a problem is NP-Hard, we propose an exact pseudo-polynomial time dynamic programming algorithm to solve it followed by a polynomial time greedy heuristic. Additionally, we formulate a non-linear optimization problem to find the optimal path when the message delivery time is defined as a soft deadline and extend our greedy heuristic to handle soft deadlines. Compared to the homogeneous band access approaches that opportunistically access free channels within a given spectrum band, our extensive simulation study shows that the proposed dynamic multi-band selection approach significantly improves the achievable energy efficiency while meeting various hard and soft deadlines. Vijay Kumar Shah, Shameek Bhattacharjee, Simone Silvestri, Sajal K. Das 0001 |
ACM Trans. Sens. Networks | 2 |
| 2017 | Statistical Security Incident Forensics against Data Falsification in Smart Grid Advanced Metering InfrastructureabstractCompromised smart meters reporting false power consumption data in Advanced Metering Infrastructure (AMI) may have drastic consequences on a smart grid's operations. Most existing works only deal with electricity theft from customers. However, several other types of data falsification attacks are possible, when meters are compromised by organized rivals. In this paper, we first propose a taxonomy of possible data falsification strategies such as additive, deductive, camouflage and conflict, in AMI micro-grids. Then, we devise a statistical anomaly detection technique to identify the incidence of proposed attack types, by studying their impact on the observed data. Subsequently, a trust model based on Kullback-Leibler divergence is proposed to identify compromised smart meters for additive and deductive attacks. The resultant detection rates and false alarms are minimized through a robust aggregate measure that is calculated based on the detected attack type and successfully discriminating legitimate changes from malicious ones. For conflict and camouflage attacks, a generalized linear model and Weibull function based kernel trick is used over the trust score to facilitate more accurate classification. Using real data sets collected from AMI, we investigate several trade-offs that occur between attacker's revenue and costs, as well as the margin of false data and fraction of compromised nodes. Experimental results show that our model has a high true positive detection rate, while the average false alarm rate is just 8%, for most practical attack strategies, without depending on the expensive hardware based monitoring. Shameek Bhattacharjee, Aditya Thakur 0002, Simone Silvestri, Sajal K. Das 0001 |
CODASPY | 1 |
| 2017 | Quality of Information in Mobile Crowdsensing: Survey and Research ChallengesabstractSmartphones have become the most pervasive devices in people’s lives and are clearly transforming the way we live and perceive technology. Today’s smartphones benefit from almost ubiquitous Internet connectivity and come equipped with a plethora of inexpensive yet powerful embedded sensors, such as an accelerometer, a gyroscope, a microphone, and a camera. This unique combination has enabled revolutionary applications based on the mobile crowdsensing paradigm, such as real-time road traffic monitoring, air and noise pollution, crime control, and wildlife monitoring, just to name a few. Differently from prior sensing paradigms, humans are now the primary actors of the sensing process, since they become fundamental in retrieving reliable and up-to-date information about the event being monitored. As humans may behave unreliably or maliciously, assessing and guaranteeing Quality of Information (QoI) becomes more important than ever. In this article, we provide a new framework for defining and enforcing the QoI in mobile crowdsensing and analyze in depth the current state of the art on the topic. We also outline novel research challenges, along with possible directions of future work. Francesco Restuccia 0001, Nirnay Ghosh, Shameek Bhattacharjee, Sajal K. Das 0001, Tommaso Melodia |
ACM Trans. Sens. Networks | 3 |
| 2015 | Bayesian inference based decision reliability under imperfect monitoringabstractReliability of a cooperative decision mechanism is critical for the proper and accurate functioning of a networked decision system. However, adversaries may choose to compromise the inputs from different sets of components that comprise the system. Often times, the monitoring mechanisms fail to accurately detect compromised inputs; hence cannot categorize all inputs into polarized decisions: compromised or not compromised. In this paper, we propose a Bayesian inference model based on multinomial evidence to quantify reliability for a cooperative decision process as a function of beliefs associated with observations from the imperfect monitoring mechanism. We propose two reliability models: an optimistic one for a normal system and a conservative one for a mission critical system. We also provide an entropy measure that reflects the certainty or uncertainty on the calculated reliability of the decision process. Through simulation, we show how the reliability and its corresponding entropy changes as the accuracy of the underlying monitoring mechanism improves1. Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat, Charles A. Kamhoua |
IM | 1 |
| 2014 | Trust based channel preference in cognitive radio networks under collaborative selfish attacksabstractSecondary spectrum data falsification (SSDF) is a common attack in cognitive radio networks, where dishonest nodes share spurious local sensing data. This behavior misleads the collective inference on spectrum occupancy. The situation is more aggravated when a collaborative SSDF attack is launched by a coalition of selfish nodes. Defense against such collaborative attacks is difficult with popularly used voting based inference models. This paper proposes a method based on Bayesian inference that indicates how much the collective decision on a channel's occupancy can be trusted. Using an anomaly monitoring technique, we check if the reports sent by a node match with the expected occupancy and classify the outcomes into three categories: i) if there is a match, ii) if there is a mismatch, and iii) if it cannot be decided. Based on the measured observations over time, we estimate the parameters of the hypothesis of match and mismatch events using a multinomial Bayesian based inference. We quantitatively define the trust as the difference between the posterior beliefs associated with matches and that of mismatches. The posterior beliefs are updated based on a weighted average of the prior information on the belief itself and the recently observed data. We conduct simulation experiments that show that the proposed trust model is able to distinguish the attacked channels from the non-attacked ones. Also, a node is able to rank the channels based on how trustworthy the inference on a channel is. We are also able to show that attacked channels have significantly lower trust values than channels that are not. Shameek Bhattacharjee, Mainak Chatterjee |
PIMRC | 1 |
| 2013 | Utilizing misleading information for cooperative spectrum sensing in cognitive radio networksabstractIn cognitive radio networks, the radios continuously scan the radio spectrum and create a spectrum usage report. Due to channel uncertainty, there are inaccuracies in these reports. Oftentimes, the radios share and fuse the observed data in order to increase the accuracy of the spectrum usage. However, malicious nodes tend to send false information (i.e., attack) in order to mislead the construction of the spectrum usage report. In this paper, we use a trust model to evaluate the trustworthiness of every node and use the trust values to effectively fuse the information from all nodes. A node compares the information sent by a neighboring node with the predicted information. Based on the ratio of matches (or mismatches), the neighboring node is assigned a trust value. Then, we propose a log-weighted metric utilizing trust values to distinguish malicious nodes from others. Subsequently, we propose threshold based Selective Inversion (SI) fusion and Complete Inversion (CI) fusion to effectively combine not only the information sent by honest nodes but also utilize misleading information sent by malicious nodes. We also propose a combination of the two inversion schemes. We compare the performance of the inversion based fusion schemes with blind and trust-based fusions. Results reveal better performance for inversion based fusion schemes for various intensities of attack. We also conduct simulations to evaluate the optimal thresholds that are used for invoking the inversion based fusion schemes. Shameek Bhattacharjee, Saptarshi Debroy, Mainak Chatterjee, Kevin A. Kwiat |
ICC | 1 |
| 2013 | Vulnerabilities in cognitive radio networks: A survey
Shameek Bhattacharjee, Shamik Sengupta, Mainak Chatterjee |
Comput. Commun. | 1 |
| 2013 | Collaborative jamming and collaborative defense in cognitive radio networks
Wenjing Wang 0006, Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat |
Pervasive Mob. Comput. | 2 |
| 2012 | An effective use of spectrum usage estimation for IEEE 802.22 networksabstractIEEE 802.22 networks consist of base stations and consumer premise equipments (CPEs) where the base station in each cell opportunistically accesses and allocates (uplink and downlink) channels to all the CPEs in its cell. Information on white space (unused primary channels) availability is reported by the CPEs to the base stations. Thus, a base station's effectiveness to allocate channels are based on its ability to gauge the spectrum usage at various locations. In this paper, we propose a channel usage estimation framework where a base station uses the spectrum reports from other neighboring base stations to estimate the spectrum usage scenario at any arbitrary location within its cell. Our estimation framework is based on Shepard's interpolation technique for irregular points. We propose a channel allocation scheme that minimizes interference among CPEs and maximizes white space utilization. Through simulation experiments, we demonstrate the accuracy of the estimation technique, utilization of the available spectrum, and efficiency of allocation scheme. We also show that our scheme achieves very low false positives and no false negatives. Finally, we show that the optimal number of base stations that need to be consulted is in accordance with Shepard's bounds1. Saptarshi Debroy, Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat |
WCNC | 2 |
| 2011 | Performance based channel allocation in IEEE 802.22 networksabstractThe main challenge in resource allocation in cognitive radio based IEEE 802.22 networks is the absence of predefined control channels. Moreover, the fleeting nature of the available spectrum also hinders the communication as the radios must relinquish the acquired channels once the primary users of those channels return. In this paper, we propose a performance metrics based data channel allocation scheme for IEEE 802.22 networks where the base station allocates interference free channels to the consumer premise equipments using a spectrum map. The base station creates the spectrum map by using the raw spectrum usage data that are shared by a small subset of consumer premise equipments. The usage data are fused at the base station using a modified version of Shepard's interpolation technique. We construct a continuous and differentiable spatial distribution of spectrum usage that the base station consults to estimate the spectrum occupancy vector at any arbitrary location in its cell. Such spectrum usage is then utilized to proactively evaluate some key network and radio performance metrics which in turn help allocating the best candidate channel to a given consumer premise equipment ensuring highest achievable performance. Saptarshi Debroy, Shameek Bhattacharjee, Mainak Chatterjee |
PIMRC | 2 |
| 2011 | Trust computation through anomaly monitoring in distributed cognitive radio networksabstractThe open philosophy of cognitive radio networks makes them vulnerable to various types of attacks which compromises the efficiency of these networks. One such attack is the Spectrum Sensing Data Falsification (SSDF) attack where malicious nodes report false spectrum occupancy data to others which when used leads to inference that is far from the true spectrum occupancy. Thus, there is a need to identify the malicious nodes or at least find the trustworthiness of nodes such that the data sent by malicious nodes could be filtered out. This paper proposes a scheme for trust based fusion by monitoring anomalies in advertised spectrum usage reports by secondary nodes. Such monitoring leads to evaluation of trust of a node by its neighbors. The calculated trust is then used to determine if a neighbor node's advertised data could be used for fusion or not. We provide a heuristic trust threshold for nodes to disregard malicious nodes while fusing the data, which holds good for any probability of attack. To validate our model we conduct extensive simulation experiments. Our results show that majority of the nodes are able to fuse data with greater accuracy for various probabilities or intensities of attack. We also compare our results with blind fusion scheme and observe improvement in accuracy of fusion from individual nodes' as well as overall network's perspective. We also report a very counter-intuitive observation: at lower probabilities of attack, a malicious node's contribution to the overall gain in cooperation is more than the damage done. Shameek Bhattacharjee, Saptarshi Debroy, Mainak Chatterjee |
PIMRC | 1 |
| 2011 | Trust based fusion over noisy channels through anomaly detection in cognitive radio networksabstractByzantine attacks have been identified as one of the key vulnerabilities in cognitive radio networks, where malicious nodes advertise false spectrum occupancy data in a cooperative environment. In such cases, the resultant fused data is very different from the actual scenario. Thus, there is a need to identify the malicious nodes or at least find the trustworthiness of nodes such that the data sent by malicious nodes could be filtered out. The process is complicated by presence of noise in the channel which makes it harder to distinguish anomalies caused by malicious activity and those caused due to unreliable noisy channels. Shameek Bhattacharjee, Saptarshi Debroy, Mainak Chatterjee, Kevin A. Kwiat |
SIN | 1 |