EDBT 2026 Demo / reviewers in the wild / expert
Sarani Bhattacharya
dblp:130/3236
· DBLP profile ↗
19ranked-venue papers
5as first author
11since 2021 · last 2025
0000-0002-4190-2671ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 2 first-author · 9 since 2021Security and privacy · 7 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unified FPGA Design of Kyber and Dilithium with Provable Fault ToleranceabstractEfficient and secure hardware implementations of post-quantum cryptographic schemes are critical for real-world adoption. In this work, we propose a unified FPGA-based architecture for Kyber and Dilithium that combines flexibility, lightweight design, and fault tolerance. The architecture adopts a microcoded, programmable datapath supporting both schemes with minimal area overhead, enabling seamless integration of modules such as SHAKE, sampling, and coefficient rounding. To enhance resilience against propagation-based fault attacks-which exploit effective/ineffective fault behavior in public-domain computations-we embed a probabilistic verification mechanism using rejection sampling. This countermeasure transforms deterministic operations into cryptographically constrained probabilistic processes that remain efficient under normal conditions while significantly degrading under adversarial faults. The result is a robust and compact design that not only supports both a lattice-based KEM and signature scheme, but also provides the first unified fault countermeasure architecture for Kyber and Dilithium, maintaining low retry counts and minimal performance degradation in fault-free environments. Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ASAP | 3 |
| 2025 | "OOPS!": Out-Of-Band Remote Power Side-Channel Attacks on Intel SGX and TDXabstractPrior work shows that remote power attacks on Intel processors are possible through two Model Specific Registers (MSRs): MSR_PKG_Energy_Status and MSR_PPO_Energy_Status. In response, Intel introduced a defense: a bit in MSR IA32_MISC_PACKAGE_CTLS allows users to enable/disable “filtering” mechanism that adds additional noise to energy measurements to harden against power side-channel attacks. In this work, we demonstrate that “filtering” does not cover all possible avenues of measuring power. On Intel server-grade platforms, components like out-of-band management interface (OOB) exist which also expose telemetric information like inband energy consumption. For this, we first reverse engineer the protocol structure over which OOB communicates with in-band components. We then show how OOB allows read-only access to the Package Configuration Space (PCS) and note that energy readings through PCS are outside the scope of filtering. Using this, we establish remote power side-channels on Intel SGX and TDX operational on Intel Sapphire Rapids. We first construct a synchronization mechanism to align in-band execution with out-of-band measurements by leveraging deliberately disabled MSRs. We then use energy readings through OOB PCS to recover 2048-bit RSA keys from MbedTLS operational within in-band Intel SGX (with generic single-stepping assumption). Finally, we also leak AESNI keys from within in-band Intel TDX (without any single-step assumption). Prior to our work, the literature on side-channels has been focused on attacks leveraging in-band interfaces. Our work establishes the importance of evaluating confidential computing architectures against attack vectors that combine abilities of both in-band and out-of-band interfaces to achieve adversarial objectives (that both in-band and out-of-band interfaces cannot independently achieve). Nimish Mishra, Kislay Arya, Sarani Bhattacharya, Paritosh Saxena, Debdeep Mukhopadhyay |
DAC | 3 |
| 2025 | "Energon": Unveiling Transformers from GPU Power and Thermal Side-ChannelsabstractTransformers have become the backbone of many Machine Learning (ML) applications, including language translation, summarization, and computer vision. As these models are increasingly deployed in shared Graphics Processing Unit (GPU) environments via Machine Learning as a Service (MLaaS), concerns around their security grow. In particular, the risk of side-channel attacks that reveal architectural details without physical access remains under-explored, despite the high value of the proprietary models they target. This work to the best of our knowledge is the first to investigate GPU power and thermal fluctuations as side-channels and further exploit them to extract information from pre-trained transformer models. The proposed analysis shows how these side channels can be exploited at user-privilege to reveal critical architectural details such as encoder/decoder layer and attention head for both language and vision transformers. We demonstrate the practical impact by evaluating multiple language and vision pre-trained transformers which are publicly available. Through extensive experimental evaluations, we demonstrate that the attack model achieves a high accuracy of over 89% on average for model family identification and 100% for hyperparameter classification, in both single-process as well as noisy multi-process scenarios. Moreover, by leveraging the extracted architectural information, we demonstrate highly effective black-box transfer adversarial attacks with an average success rate exceeding 93%, underscoring the security risks posed by GPU side-channel leakage in deployed transformer models. Arunava Chaudhuri, Shubhi Shukla 0001, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 3 |
| 2025 | TREX-F: TRustability of Electronics using X-ray based FingerprintingabstractThe present-day electronic supply chain is infested with adversaries who threaten the integrity of electronic circuit boards and components. A major intent of such adversaries is to manufacture counterfeit printed circuit boards (PCBs). They infiltrate the supply chain with these forged PCBs, which closely mimic the original designs, albeit jeopardizing the business cycle of electronic design. In this work, we aim to restrict the circulation of tampered and counterfeit boards in the supply chain by leveraging the inherent physical deformities of authentic PCBs, which are difficult to replicate. Such anomalies include solder defects, material deposition, and microscopic irregularities unique to each PCB. These anomalies, though imperceivable to the human eye, can be captured at a specific angle under an X-ray microscope when imaged at appropriate orientations. Our proposed framework, TREX-F, comprises an image-based authentication protocol that defines unique fingerprints of each PCB by extracting such anomalies and converting them into quick-response and data-matrix codes. We construct device-specific templates from the X-ray computed tomography slices of the PCB samples by utilizing a combination of computer vision techniques, including Canny edge detection, contour detection, principal component analysis, and scale-invariant feature transform. As a case study, we validate our framework on Arduino UNO, Raspberry Pi 4 model B, and STM32F407G boards. TREX-F enables a sustainable electronics supply chain ecosystem, wherein end users can directly verify the authenticity of the procured PCBs with an average accuracy of ≥95% across all boards, and an average false acceptance rate (FAR) of 0.1 Tishya Sarma Sarkar, Shuvodip Maitra, Abhishek Chakraborty 0001, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 4 |
| 2025 | Systematic Evaluation of Randomized Cache Designs against Cache Occupancy
Anirban Chakraborty 0003, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya, Debdeep Mukhopadhyay |
USENIX Security Symposium | 4 |
| 2024 | A Practical Key-Recovery Attack on LWE-Based Key-Encapsulation Mechanism Schemes Using Rowhammer
Puja Mondal, Suparna Kundu, Sarani Bhattacharya, Angshuman Karmakar, Ingrid Verbauwhede |
ACNS (3) | 3 |
| 2024 | µLAM: A LLM-Powered Assistant for Real-Time Micro-architectural Attack Detection and MitigationabstractThe rise of microarchitectural attacks has necessitated robust detection and mitigation strategies to secure computing systems. Traditional tools, such as static and dynamic code analyzers and attack detectors, often fall short due to their reliance on predefined patterns and heuristics that lack the flexibility to adapt to new or evolving attack vectors. In this paper, we introduce for the first time a microarchitecture security assistant, built on OpenAI's GPT-3.5, which we refer to as μLAM. This assistant surpasses conventional tools by not only identifying vulnerable code segments but also providing context-aware mitigations, tailored to specific system specifications and existing security measures. Additionally, μLAM leverages real-time data from dynamic Hardware Performance Counters (HPCs) and system specifications to detect ongoing attacks, offering a level of adaptability and responsiveness that static and dynamic analyzers cannot match. Upasana Mandal, Shubhi Shukla 0001, Ayushi Rastogi, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 4 |
| 2023 | Are Randomized Caches Truly Random? Formal Analysis of Randomized-Partitioned CachesabstractCache based side-channel attacks exploit the fact that an adversary can setup the shared cache memory (the last level cache in modern systems) into a known state and detect any microarchitectural state changes made by the victim on the cache. Different mitigation techniques have been proposed in the literature that aims to mitigate these attacks by randomizing the address to cache location mappings. The security guarantees in these schemes are based on the degree of difficulty for an attacker to reliably determine the cache lines accessed by the victim within practical time settings. However, prior attacks have shown that newer and more improved algorithms can be envisaged that discover conflicting sets in the secured randomized caches. In this work, we first categorize different types of cache designs into four broad classes based on the extent of non-determinism and randomness of allocating an address in those caches. We then develop a mathematical framework to formally analyse the security implications of the randomized and partitioned cache designs in terms of collision probability, self-collision probability and size of the eviction set required to perform a successful eviction-based attack. We further empirically demonstrate set associative eviction on recently proposed randomization schemes called Mirage and Scattercache. Next, we propose two algorithms to generate efficient eviction set on these schemes and analytically evaluate the efficacy of our algorithms against the one proposed in the literature. Finally, we argue that mere randomization using a cryptographic primitive as used in popular schemes like Scattercache, CEASER-S, Mirage etc. does not provide the required randomness. Although the randomized-partitioned caches provide some resilience against eviction-set generation techniques, they are still vulnerable to eviction-based attacks. Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay |
HPCA | 2 |
| 2022 | Timed speculative attacks exploiting store-to-load forwarding bypassing cache-based countermeasuresabstractIn this paper, we propose a novel class of speculative attacks, called Timed Speculative Attacks (TSA), that does not depend on the state changes in the cache memory. Instead, it makes use of the timing differences that occur due to store-to-load forwarding. We propose two attack strategies - Fill-and-Forward utilizing correctly speculated loads, and Fill-and-Misdirect using mis-speculated load instructions. While Fill-and-Forward exploits the shared store buffers in a multi-threaded CPU core, the Fill-and-Misdirect approach exploits the influence of rolled back mis-speculated loads on subsequent instructions. As case studies, we demonstrate a covert channel using Fill-and-Forward and key recovery attacks on OpenSSL AES and Romulus-N Authenticated Encryption with Associated Data scheme using Fill-and-Misdirect approach. Finally, we show that TSA is able to subvert popular cache-based countermeasures for transient attacks. Anirban Chakraborty 0003, Nikhilesh Singh, Sarani Bhattacharya, Chester Rebeiro, Debdeep Mukhopadhyay |
DAC | 3 |
| 2021 | Exploring Micro-architectural Side-Channel Leakages through Statistical TestingabstractMicro-architectural side-channel leakage received a lot of attention due to their high impact on software security on complex out-of-order processors. These are extremely specialised threat models and can be only realised in practise with high precision measurement code, triggering micro-architectural behavior that leaks information. In this paper, we present a tool to support the inexperienced user to verify his code for side-channel leakage. We combine two very useful tools- statistical testing and hardware performance monitors to bridge this gap between the understanding of the general purpose users and the most precise speculative execution attacks. We first show that these event counters are more powerful than observing timing variabilities on an executable. We extend Dudect, where the raw hardware events are collected over the target executable, and leakage detection tests are incorporated on the statistics of observed events following the principles of non-specific t-tests. Finally, we show the applicability of our tool on the most popular speculative micro-architectural and data-sampling attack models. Sarani Bhattacharya, Ingrid Verbauwhede |
DATE | 1 |
| 2021 | Victims Can Be Saviors: A Machine Learning-based Detection for Micro-Architectural Side-Channel AttacksabstractMicro-architectural side-channel attacks are major threats to the most mathematically sophisticated encryption algorithms. In spite of the fact that there exist several defense techniques, the overhead of implementing the countermeasures remains a matter of concern. A promising strategy is to develop online detection and prevention methods for these attacks. Though some recent studies have devised online prevention mechanisms for some categories of these attacks, still other classes remain undetected. Moreover, to detect these side-channel attacks with minimal False Positives is a challenging effort because of the similarity of their behavior with computationally intensive applications. This article presents a generalized machine learning--based multi-layer detection technique that targets these micro-architectural side-channel attacks, while not restricting its attention only on a single category of attacks. The proposed mechanism gathers low-level system information by profiling performance counter events using Linux perf tool and then applies machine learning techniques to analyze the data. A novel approach using time-series analysis of the data is implemented to find out the correlation of the execution trace of the attack process with the secret key of encryption, which helps in dealing with False-Positives and unknown attacks. This article also provides a detailed theoretical analysis of the detection mechanism of the proposed model along with its security analysis. The experimental results show that the proposed method is superior to the state-of-the-art reported techniques with high detection accuracy, low False Positives, and low implementation overhead while being able to detect before the completion of the attack. Manaar Alam, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2020 | ExplFrame: Exploiting Page Frame Cache for Fault Analysis of Block CiphersabstractPage Frame Cache (PFC) is a purely software cache, present in modern Linux based operating systems (OS), which stores the page frames that were recently released by the processes running on a particular CPU. In this paper, we show that the page frame cache can be maliciously exploited by an adversary to steer the pages of a victim process to some pre-decided attacker-chosen locations in the memory. We practically demonstrate an end-to-end attack, ExplFrame, where an attacker having only user-level privilege is able to force a victim process's memory pages to vulnerable locations in DRAM and deterministically conduct Rowhammer to induce faults. As a case study, we induce single bit faults in the T-tables on OpenSSL (v1.1.1) AES using our proposed attack ExplFrame. We also propose an improvised fault analysis technique which can exploit any Rowhammer-induced bit-flips in the AES T-tables. Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay |
DATE | 2 |
| 2020 | Branch Prediction Attack on Blinded Scalar MultiplicationabstractIn recent years, performance counters have been used as a side channel source to monitor branch mispredictions, in order to attack cryptographic algorithms. However, the literature considers blinding techniques as effective countermeasures against such attacks. In this article, we present the first template attack on the branch predictor. We target blinded scalar multiplications with a side-channel attack that uses branch misprediction traces. Since an accurate model of the branch predictor is a crucial element of our attack, we first reverse-engineer the branch predictor. Our attack proceeds with a first online acquisition step, followed by an offline template attack with a template building phase and a template matching phase. During the template matching phase, we use a strategy we call Deduce & Remove, to first infer the candidate values from templates based on a model of the branch predictor, and subsequently eliminate erroneous observations. This last step uses the properties of the target blinding technique to remove wrong guesses and thus naturally provides error correction in key retrieval. In the later part of this article, we demonstrate a template attack on Curve1174 where the double-and-add always algorithm implementation is free from conditional branching on the secret scalar. In that case, we target the data-dependent branching based on the modular reduction operations of long integer multiplications. Such implementations still exist in open source software and can be vulnerable, even if top level safeguards like blinding are used. We provide experimental results on scalar splitting, scalar randomization, and point blinding to show that the secret scalar can be correctly recovered with high confidence. Finally, we conclude with recommendations on countermeasures to thwart such attacks. Sarani Bhattacharya, Clémentine Maurice, Shivam Bhasin, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 1 |
| 2019 | In-situ Extraction of Randomness from Computer Architecture Through Hardware Performance Counters
Manaar Alam, Astikey Singh, Sarani Bhattacharya, Kuheli Pratihar, Debdeep Mukhopadhyay |
CARDIS | 3 |
| 2018 | Utilizing Performance Counters for Compromising Public Key CiphersabstractHardware performance counters (HPCs) are useful artifacts for evaluating the performance of software implementations. Recently, HPCs have been made more convenient to use without requiring explicit kernel patches or superuser privileges. However, in this article, we highlight that the information revealed by HPCs can be also exploited to attack standard implementations of public key algorithms. In particular, we analyze the vulnerability due to the event branch miss leaked via the HPCs during execution of the target ciphers. We present an iterative attack that targets the key bits of 1,024-bit RSA and 256-bit ECC, whereas in the offline phase, the system’s underlying branch predictor is approximated by a theoretical predictor in the literature. Subsimulations are performed corresponding to each bit guess to classify the message space into distinct partitions based on the event branch misprediction and the target key bit value. In the online phase, branch mispredictions obtained from the hardware performance monitors on the target system reveal the secret key bits. We also theoretically prove that the probability of success of the attack is equivalent to the accurate modeling of the theoretical predictor to the underlying system predictor. In addition, we propose an improved version of the attack that requires fewer branch misprediction traces from the HPCs to recover the secret. Experimentations using both attack strategies have been provided on Intel Core 2 Duo, Core i3, and Core i5 platforms for 1,024-bit implementation of RSA and 256-bit scalar multiplication over the secp 256 r 1 curve followed by results on the effect of change of parameters on the success rate. The attack can successfully reveal the exponent bits and thus seeks attention to model secure branch predictors such that it inherently prevents information leakage. Sarani Bhattacharya, Debdeep Mukhopadhyay |
ACM Trans. Priv. Secur. | 1 |
| 2016 | Curious Case of Rowhammer: Flipping Secret Exponent Bits Using Timing Analysis
Sarani Bhattacharya, Debdeep Mukhopadhyay |
CHES | 1 |
| 2016 | SmashClean: A hardware level mitigation to stack smashing attacks in OpenRISCabstractBuffer overflow and stack smashing have been one of the most popular software based vulnerabilities in literature. There have been multiple works which have used these vulnerabilities to induce powerful attacks to trigger malicious code snippets or to achieve privilege escalation. In this work, we attempt to implement hardware level security enforcement to mitigate such attacks on OpenRISC architecture. We have analyzed the given exploits [5] in detail and have identified two major vulnerabilities in the exploit codes: memory corruption by non-secure memcpy() and return address modification by buffer overflow. We have individually addressed each of these exploits and have proposed a combination of compiler and hardware level modification to prevent them. The advantage of having hardware level protection against these attacks provides reliable security against the popular software level countermeasures. Manaar Alam, Debapriya Basu Roy, Sarani Bhattacharya, Vidya Govindan, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
MEMOCODE | 3 |
| 2016 | Template attack on SPA and FA resistant implementation of Montgomery ladderabstractHardware implementations of the well‐known Rivest–Shamir–Adleman (RSA) algorithm have been shown to be vulnerable to power and fault analysis (FA) attacks. To implement protected designs of RSA‐Chinese remainder theorem in embedded devices, like smart cards or RFIDs, the one needs to find solutions which require less computations as well as incurs low storage overheads. One such efficient scheme was proposed by Joye et al . in CHES'02 and it was claimed to be secure against both simple power analysis (SPA) and FA attacks. In this study, the authors demonstrate a template attack (TA) against Joye's countermeasure and show that the scheme can be broken with a low number of power traces. In addition, the authors report the experimental results of the proposed attack against an implementation of Joye's scheme on a Xilinx Microblaze soft‐core processor of SASEBO‐W standard side‐channel analysis board. The authors used least squares support vector machine (LS‐SVM) based binary classifiers to analyse the collected power traces. The authors also describe the potential threat posed by cache timing attacks on Joye's ladder in presence of a concurrently running spy process and outline a probable countermeasure to the posed attacks. Abhishek Chakraborty 0001, Sarani Bhattacharya, Tanu Hari Dixit, Chester Rebeiro, Debdeep Mukhopadhyay |
IET Inf. Secur. | 2 |
| 2015 | Who Watches the Watchmen?: Utilizing Performance Monitors for Compromising Keys of RSA on Intel Platforms
Sarani Bhattacharya, Debdeep Mukhopadhyay |
CHES | 1 |