EDBT 2026 Demo / reviewers in the wild / expert
Manish Shukla 0001
dblp:133/7191-1
· DBLP profile ↗
12ranked-venue papers
8as first author
6since 2021 · last 2026
0000-0003-4867-3530ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 8 first-author · 6 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: FuzzyExtract - A Lightweight Approach for Cryptographic Bill of Materials Extraction from Java Binaries
Manish Shukla 0001, Sachin Lodha |
AsiaCCS | 1 |
| 2026 | POSTER: Advancing Enterprise Cyber Defense with Digital Twin-Modelling, Simulation and PredictionabstractEnterprise networks face rapidly evolving threats that exceed the capabilities of reactive or historically trained defenses. This paper presents a digital-twin based framework for proactive cybersecurity strategy evaluation. The digital twin models enterprise infrastructure, user behaviors, defensive controls, and both observed and speculative threats through an executable, actor-based representation. By capturing deterministic operations and stochastic attacker decisions, it supports systematic in-silico experimentation across diverse attack paths. The approach enables evidence-driven assessment of mitigation strategies prior to deployment, addressing the limitations of retrospective methods and improving enterprise cyber resilience. Manish Shukla 0001, Shivam Shinde, Geetika Agarwal, Reshma Korabu, Souvik Barat |
AsiaCCS | 1 |
| 2025 | Poster: Impulse in the Clickstream: Behavioral Insights from Browsing HistoryabstractPhishing attacks often exploit user impulsivity, leading to reflexive clicks on malicious links without proper evaluation. While prior research has explored phishing awareness, there remains a gap in understanding impulsive clicking behavior. In this study, we present a novel approach to characterize clicking impulsivity using browser history data. Our session-level analysis reveals that user's impulsive clicking behavior is situational and context dependent. Our findings offer actionable insights for adaptive security interventions based on real-time user behavior. Shubham Malaviya, Anuj Bagad, Manish Shukla 0001, Sachin Lodha |
CCS | 3 |
| 2024 | Poster: Context-Based Effective Password Detection in PlaintextabstractFrom an enterprise perspective, storage of passwords in plaintext on a computer hard disk is a serious concern. Such password storage practice helps a malicious agent to do privilege escalation, install a backdoor, disable critical monitoring tools, and allow them to laterally move within organization's network. Considering the exploitability of the plaintext password stored on a storage device, it is imperative for an organization to identify such files and safeguard them without causing disruption to a user's work routine. In this work, we present a context-based password discovery solution for plaintext that performs multi-step context discovery for reducing false positives and negatives. Moreover, we protect all the identified files using an on-the-fly user authentication layer, which helps in preventing automated or command-line-based access to sensitive content in case of a cyberattack. Manish Shukla 0001, Shubham Malaviya, Sachin Lodha |
CCS | 1 |
| 2024 | Poster: Unmasking Label Errors: A need for Robust Cybersecurity BenchmarksabstractCyber Threat Intelligence (CTI) utilizes information from various sources, necessitating high-quality labeled datasets for effective application of machine learning. Our study addresses the often-overlooked issue of labeling errors in cybersecurity benchmarks, resulting in the creation of D-LADDER++, a curated version of the recently published LADDER dataset. We evaluated the performance of both an open-source model (Microsoft Phi-3) and a closed-source model (Google Gemini) on D-LADDER++. We assessed their zero-shot and few-shot capabilities and fine-tuned the Phi-3 model for enhanced adaptability. Our assessment of the impact of test errors on model performance emphasizes the critical need for robust benchmarks in cybersecurity to ensure accurate model evaluation and selection. Shubham Malaviya, Manish Shukla 0001, Saurabh Anand, Sachin Lodha |
CCS | 2 |
| 2024 | CompFreeze : Combining Compacters and Layer Freezing for Enhanced Pre-Trained Language ModelabstractLeveraging vast datasets from various security tools and sources for training AI models in cybersecurity offers significant potential to learn better representations of real-world behavior. However, data drift and labeled data scarcity are major challenges leading to frequent and costly model updates and the risk of overfitting. To address these issues, we introduce CompFreeze, a parameter-efficient fine-tuning technique combining compacters and layer freezing strategies. We evaluate the effectiveness of CompFreeze on three pre-trained models in the cybersecurity domain across various downstream tasks. We demonstrate that with significantly less trainable parameters, CompFreeze performs on par with full model fine-tuning while taking less training time. We have performed comprehensive experimental analysis involving investigating the impact of different learning rates and varying the number of compacter modules integrated into models, offering an in-depth analysis of the trade-off between accuracy and inference time. Saurabh Anand, Shubham Malaviya, Manish Shukla 0001, Sachin Lodha |
PST | 3 |
| 2020 | rProfiler - Assessing Insider Influence on Enterprise AssetsabstractInsider threat is a well-recognized problem in the cyber-security domain. There is good amount of research on detecting and predicting an insider attack. However, none of them addresses the influence of an insider over other individuals, and the spread of impact due to direct and indirect access to enterprise assets by having such influence. In this work, we propose a graph-based influence profiling solution called rProfiler that analyzes the data from multiple sources to determine the influence spread and calculate the probability of loss of data from an affected device using pertinent graph features. We also highlight multiple enterprise scenarios that may benefit from this work. Manish Shukla 0001, Sachin Lodha |
CCS | 1 |
| 2019 | pFilter: Retrofitting Legacy Applications for Data PrivacyabstractEnterprise needs to process customer data for providing tailored services to them, however, the data often includes sensitive and personally identifiable information. This leads to a difficult situation wherein the enterprise has to balance the necessity to process the sensitive data with the requirement to safeguard its privacy. The problem is more prominent in legacy applications with almost no privacy controls in place. A well-studied technique to retrofit legacy application is to mask sensitive content before it is rendered on the screen using path based methods. In this work we show the gap in the existing state of art and describe a dynamic system which utilizes a context to perform locality based searching and masking of sensitive content. Manish Shukla 0001, Kumar Vidhani, Gangadhara Reddy Sirigireddy, Vijayanand Banahatti, Sachin Lodha |
CCS | 1 |
| 2017 | Privacy Aware Temporal Profiling of Emails in Distributed SetupabstractThe enterprise email promises to be a rich source for knowledge discovery. This is made possible due to the direct nature of communication, support for diverse media types, active participation of entities and presence of chronological ordering of messages. Also, the enterprise emails are more trustworthy than external emails due to their formal nature. This data source has not been fully tapped. In fact, the existing work on profiling of emails focuses primarily on expertise identification and retrieval. Even in these studies, the researchers have made some restrictive assumptions. For instance, in many of the formulations, the underlying system assumes a centralized data repository, and the communication network is complete. They do not account for individual biases in an email while mining and aggregating results. Furthermore, email holds fair amount of personal and organizational sensitive information. None of the existing work on email profiling suggests anything on alleviating the individual and organizational privacy concerns. Sutapa Mondal, Manish Shukla 0001, Sachin Lodha |
CIKM | 2 |
| 2016 | POSTER: Locally Virtualized Environment for Mitigating Ransomware ThreatabstractRansomware is one of the rising malwares in the crimeware family. It encrypts the user files and demands extortion money. From the perspective of an enterprise it is very crucial to detect and stop a ransomware attack. A well studied technique is to monitor file system behavior for suspicious activity. In this work we will show the gap in the existing state of art and describe a dynamic system which learns new behavior while under attack. Manish Shukla 0001, Sutapa Mondal, Sachin Lodha |
CCS | 1 |
| 2015 | POSTER: WinOver Enterprise Dark DataabstractAny persistent untagged, untapped and unclassified data can be termed as dark data. It has two common traits: first, it is not possible to determine its worth, and second, in most of the scenarios it is inadequately protected. Previous work and existing solutions are restricted to cater single node system. Moreover, they perform specialized processing of selected content, for example, logs. Further, there is total negligence of stakeholders and minimal focus on the data getting generated within the enterprise. From the perspective of an enterprise it is important to understand the distribution, nature and worth of dark data, as it helps in choosing right security controls, insurance or steps needed to pre-process a system before discarding it. In this paper we demonstrate a distributed system, called File WinOver, for File Lifecycle Management (FLM). The solution operates in a distributed environment where it identifies the dormant and active files on a system, filters them as per requirement and computes their fingerprint. Moreover, the content fingerprinting is utilized to detect closed user groups. After which, it classifies the content based on configured policies, and maps them with the stakeholders. This mapping is further used for valuating the risk exposure of the file. Thus, our system helps in identifying dark data and assigns quantitative risk value. Manish Shukla 0001, Sumesh Manjunath Ramesh, Rohit Saxena, Sutapa Mondal, Sachin Lodha |
CCS | 1 |
| 2013 | On the real-time masking of the sound of credit cards using hot patchingabstractPhone based card payments utilize inband DTMF signaling to convey data. Since the DTMF signals are audible to a human ear, a call operator is in position to carry out a privacy attack. We investigate real-time techniques that can obfuscate the 'digit' values without deteriorating the voice quality. Furthermore, we consider a setting where the privacy solution is being provided by a third party which does not have the benefit of open interfaces to the communication application. Our experiments reveal the efficacy of binary interception to 'inject' the signal filtering. Meanwhile, we observe that several DTMF suppression techniques that have been proposed in literature can leave a residue that is sufficient for de-anonymizing the digit value. In light of these observations, we argue in favor of more modest privacy guarantees, which can be achieved by suppressing only the higher frequency. We show that margin crossings and peak variances can be used for fast pre-filtering of audio to detect the presence of a tone, thus reducing the computational needs. Manish Shukla 0001, Purushotam G. Radadia, Shirish S. Karande, Sachin Lodha |
CCS | 1 |