EDBT 2026 Demo / reviewers in the wild / expert
Sachin Lodha
dblp:14/6843 · also Sachin Premsukh Lodha
· DBLP profile ↗
36ranked-venue papers
1as first author
16since 2021 · last 2026
0000-0001-5771-4977ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 10 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Theory of computation · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: FuzzyExtract - A Lightweight Approach for Cryptographic Bill of Materials Extraction from Java Binaries
Manish Shukla 0001, Sachin Lodha |
AsiaCCS | 2 |
| 2026 | Meta Transaction Fee Mechanisms for Equitable Arbitrage
Aditya Ahuja, M. A. Rajan, Sachin Lodha |
ICBC | 3 |
| 2025 | Poster: Impulse in the Clickstream: Behavioral Insights from Browsing HistoryabstractPhishing attacks often exploit user impulsivity, leading to reflexive clicks on malicious links without proper evaluation. While prior research has explored phishing awareness, there remains a gap in understanding impulsive clicking behavior. In this study, we present a novel approach to characterize clicking impulsivity using browser history data. Our session-level analysis reveals that user's impulsive clicking behavior is situational and context dependent. Our findings offer actionable insights for adaptive security interventions based on real-time user behavior. Shubham Malaviya, Anuj Bagad, Manish Shukla 0001, Sachin Lodha |
CCS | 4 |
| 2025 | Post Quantum Cryptographic Schemes and Libraries Selection
Shubhro Roy, Mangesh S. Gharote, Pankaj Sahu, Sutapa Mondal, M. A. Rajan, Sachin Lodha |
DEXA (2) | 6 |
| 2025 | CrossCoin: An International CBDC System with Optimal InvestmentsabstractWe consider the design of an international CBDC system, where users can transact within or across jurisdictions under central bank issued CBDC units. We present CrossCoin, a pair of an economic design and a blockchain protocol that incentivizes CBDC currency service providers and allocates them CBDC transactions for validation. The CrossCoin economy determines the ideal valuation of transaction validation for service providers under the Cournot regime. The CrossCoin blockchain protocol, an amendment to Streamlet, ensures that the system remains functional even when a minority of the set of enrolled jurisdictional authorities decide to opt out of the economy under exogenous incentives. Aditya Ahuja, Sachin Lodha |
ICBC | 2 |
| 2025 | TenderWallet: A Private Access and Compliant Collateralized CBDC SystemabstractWe present TenderWallet, a CBDC system that offers a balance of inclusive privacy-preserving access and complete regulatory compliance. Our proposed system provides a CBDC functionality that is responsive to user behaviour, and in case of non-compliance by the user while availing the CBDC service, compensates the indirect monetary loss induced to the nation state, through collateralization. The TenderWallet system is also hybrid, such that it dynamically works as one variant of two well established offline CBDC models, thereby reducing the computational overhead of the service. We detail the behaviour of the TenderWallet system, analyze its deployment characteristics, and argue that it is superior to other potential hybrid CBDC designs. We conclude by showing that TenderWallet is near optimal, while considering compensation to the state and low-compute privacy and transparency of users as the main requirements of a CBDC system. Aditya Ahuja, Siddhasagar Pani, Srujana Kanchanapalli, R. Vigneswaran, M. A. Rajan, Sachin Lodha |
ICBC | 6 |
| 2024 | Poster: Context-Based Effective Password Detection in PlaintextabstractFrom an enterprise perspective, storage of passwords in plaintext on a computer hard disk is a serious concern. Such password storage practice helps a malicious agent to do privilege escalation, install a backdoor, disable critical monitoring tools, and allow them to laterally move within organization's network. Considering the exploitability of the plaintext password stored on a storage device, it is imperative for an organization to identify such files and safeguard them without causing disruption to a user's work routine. In this work, we present a context-based password discovery solution for plaintext that performs multi-step context discovery for reducing false positives and negatives. Moreover, we protect all the identified files using an on-the-fly user authentication layer, which helps in preventing automated or command-line-based access to sensitive content in case of a cyberattack. Manish Shukla 0001, Shubham Malaviya, Sachin Lodha |
CCS | 3 |
| 2024 | Poster: Unmasking Label Errors: A need for Robust Cybersecurity BenchmarksabstractCyber Threat Intelligence (CTI) utilizes information from various sources, necessitating high-quality labeled datasets for effective application of machine learning. Our study addresses the often-overlooked issue of labeling errors in cybersecurity benchmarks, resulting in the creation of D-LADDER++, a curated version of the recently published LADDER dataset. We evaluated the performance of both an open-source model (Microsoft Phi-3) and a closed-source model (Google Gemini) on D-LADDER++. We assessed their zero-shot and few-shot capabilities and fine-tuned the Phi-3 model for enhanced adaptability. Our assessment of the impact of test errors on model performance emphasizes the critical need for robust benchmarks in cybersecurity to ensure accurate model evaluation and selection. Shubham Malaviya, Manish Shukla 0001, Saurabh Anand, Sachin Lodha |
CCS | 4 |
| 2024 | TrapShield: Enhancing Security and Privacy in Serverless Workflows using Honeypots by Robust Adversary PenalizationabstractThe marked shift of application developers to serverless computing has led to an increase in the number of cyberattacks and privacy concerns, thus prompting the need for secure serverless workflows. We propose TrapShield, a honeypots-based, secure and privacy preserving framework to protect serverless computing applications from insider and outsider attacks. It utilizes honeypots to deceive the attackers and penalize them by redirecting to a random set of dummy functions forming a cycle. Evaluations on Google Cloud Platform and Amazon Web Services for three popular serverless applications show TrapShield’s effectiveness in reducing costs for thwarting attacks while maintaining high runtime performance (approximately 1.3 seconds for an airline booking application). Surabhi Garg, Maithri Suresh, Meena Singh Dilip Thakur, M. A. Rajan, Pankaj Sahu, Mangesh S. Gharote, Manju Ramesh, Sachin Lodha |
IC2E | 8 |
| 2024 | LIMBOCOIN: On the Denial-of-Service of Token based Retail CBDCsabstractSeveral nations across the world are contemplating optimal design choices for Central Bank Digital Currencies (CBDCs). We present LimboCoin, an analytical framework for an arbitrary token based CBDC protocol. LimboCoin, under practical state-of-the-art assumptions on secure system design and protocol incentivization, considers an adversarial behaviour to achieve denial-of-service on the CBDC’s associated system and token economy. LimboCoin outlines the quality of the CBDC system and economy resultant from the interaction of honest and adversarial users in the CBDC’s jurisdiction. Through LimboCoin, we show that in the worst case, the number of compromised CBDC wallets in operation can exceed the number of legitimate wallets in operation, within the CBDC’s jurisdiction. We also show that in the worst case, the value associated with victim token transactions that are denied service exceeds 90 percent of the value associated with token transactions that are in legitimate service. Aditya Ahuja, Siddhasagar Pani, Srujana Kanchanapalli, R. Vigneswaran, M. A. Rajan, Sachin Lodha |
ICBC | 6 |
| 2024 | CompFreeze : Combining Compacters and Layer Freezing for Enhanced Pre-Trained Language ModelabstractLeveraging vast datasets from various security tools and sources for training AI models in cybersecurity offers significant potential to learn better representations of real-world behavior. However, data drift and labeled data scarcity are major challenges leading to frequent and costly model updates and the risk of overfitting. To address these issues, we introduce CompFreeze, a parameter-efficient fine-tuning technique combining compacters and layer freezing strategies. We evaluate the effectiveness of CompFreeze on three pre-trained models in the cybersecurity domain across various downstream tasks. We demonstrate that with significantly less trainable parameters, CompFreeze performs on par with full model fine-tuning while taking less training time. We have performed comprehensive experimental analysis involving investigating the impact of different learning rates and varying the number of compacter modules integrated into models, offering an in-depth analysis of the trade-off between accuracy and inference time. Saurabh Anand, Shubham Malaviya, Manish Shukla 0001, Sachin Lodha |
PST | 4 |
| 2024 | Privacy Preservation in Service Operations by Minimizing Sensitive Data ExposureabstractIn IT service operations such as service help desk, the primary task is to resolve customer queries satisfactorily within the stipulated service level agreements (SLA). These customer queries, referred to as tickets often contain sensitive and non-sensitive information. The disclosure of sensitive information even to an authorized agents is a privacy concern and could increase the risk of insider threat. In this work, we propose a framework to restrict the data exposure to authorized agents in such IT service operations. To facilitate privacy-enabled service operations, we assess the risk associated with the disclosure of attributes using its vulnerability and provide a masking strategy to reduce the data exposure. However, fully masking the key attributes within the ticket could hinder the resolution time and potentially lead to SLA violations. To overcome this, we propose an optimization model for partial masking which takes into consideration the attribute vulnerability and privacy requirement of an application, to minimize the overall data exposure. We provide an illustration on how this masking schemes can be implemented. Rishabh Kumar, Sutapa Mondal, Mangesh S. Gharote, Praveen Gauravaram, Sachin Lodha |
PST | 6 |
| 2022 | Secure Scheduling of Scientific Workflows in Cloud
Shubhro Roy, Arun Ramamurthy, Anand Pawar, Mangesh S. Gharote, Sachin Lodha |
CLOSER | 5 |
| 2021 | Multi-objective Optimization for Virtual Machine Allocation in Computational Scientific Workflow under UncertaintyabstractProviding resources and services from various cloud providers is now an increasingly promising paradigm. Workflow applications are becoming increasingly computation-intensive or data-intensive, with resource allocation being maintained in terms of pay per usage. In this paper, a multi-objective optimization study for scientific workflow in a cloud environment is proposed. The aim is to minimize execution time and purchasing cost simultaneously while satisfying the demand requirements of customers. The uncertainties present in the model are identified and handled using a well-known technique called Chance Constrained Programming (CCP) for real-world implementation. The model is solved using the Non-dominated Sorting Genetic Algorithm – II (NSGA-II). This comprehensive study shows that the solutions obtained on considering uncertainties vary from the deterministic case. Based on the probability of constraint satisfaction, the objective functions improve but at the cost of reliability of the solution. Copyright © 2021 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved Arun Ramamurthy, Priyanka Devi Pantula, Mangesh S. Gharote, Kishalay Mitra, Sachin Lodha |
CLOSER | 5 |
| 2021 | Robust Collaborative Fraudulent Transaction Detection using Federated LearningabstractFraudulent transaction detection is a difficult problem for an individual bank, since the number of fraudulent transactions within a single bank’s records is significantly less compared to the day-to-day regular transactions it processes. Hence, due to this extreme data imbalance, training a classifier is difficult. Also, the model will not be able to learn from different types of fraudulent transactions, which a single bank’s database lacks. Collaboration between banks is the only way to achieve a generalized model, but banks will not share their data with each other due to competition and regulatory restrictions. Federated Learning can be leveraged here to solve this problem. However, in a cross-silo setting like this, the data held by different banks will be different in terms of distribution and hence follows a non-IID scenario across the participants’ datasets. Moreover, we are considering that a minority of the banks could be malicious and will try to disrupt this federated learning process. Hence the problem is to perform federated learning in a non-IID setting with active adversaries involved, which is a new research area under fraud detection. We perform non-IID partitioning of the transaction dataset to simulate 10 banks or silos. Then, for benchmark, we perform federated averaging with a subset of the banks set as malicious. Furthermore, we propose a novel algorithm - Epsilon Cluster Selection, a filter-based aggregation technique to recognize and prevent malicious nodes from contributing to the global model being trained. We apply this algorithm to the same setting with malicious banks and compare the results. Delton Myalil, M. A. Rajan, Manoj Apte, Sachin Lodha |
ICMLA | 4 |
| 2021 | Visuals Triumph in a Curious Case of Privacy Policy
Shree Nivas, C. J. Gokul, Vijayanand Banahatti, Sachin Lodha |
INTERACT (4) | 4 |
| 2020 | rProfiler - Assessing Insider Influence on Enterprise AssetsabstractInsider threat is a well-recognized problem in the cyber-security domain. There is good amount of research on detecting and predicting an insider attack. However, none of them addresses the influence of an insider over other individuals, and the spread of impact due to direct and indirect access to enterprise assets by having such influence. In this work, we propose a graph-based influence profiling solution called rProfiler that analyzes the data from multiple sources to determine the influence spread and calculate the probability of loss of data from an affected device using pertinent graph features. We also highlight multiple enterprise scenarios that may benefit from this work. Manish Shukla 0001, Sachin Lodha |
CCS | 2 |
| 2020 | Secure and Privacy Preserving Method for Biometric Template Protection using Fully Homomorphic EncryptionabstractThe rapid proliferation of biometrics has led to growing concerns about the security and privacy of the biometric data (template). A biometric uniquely identifies an individual and unlike passwords, it cannot be revoked or replaced since it is unique and fixed for every individual. To address this problem, many biometric template protection methods using fully homomorphic encryption have been proposed. But, most of them (i) are computationally expensive and practically infeasible (ii) do not support operations over real valued biometric feature vectors without quantization (iii) do not support packing of real valued feature vectors into a ciphertext (iv) require multishot enrollment of users for improved matching performance. To address these limitations, we propose a secure and privacy preserving method for biometric template protection using fully homomorphic encryption. The proposed method is computationally efficient and practically feasible, supports operations over real valued feature vectors without quantization and supports packing of real valued feature vectors into a single ciphertext. In addition, the proposed method enrolls the users using one-shot enrollment. To evaluate the proposed method, we use three face datasets namely LFW, FEI and Georgia tech face dataset. The encrypted face template (for 128 dimensional feature vector) requires 32.8 KB of memory space and it takes 2.83 milliseconds to match a pair of encrypted templates. The proposed method improves the matching performance by ~ 3% when compared to state-of-the-art, while providing high template security. Arun Kumar Jindal, Imtiyazuddin Shaik, Vasudha, Srinivasa Rao Chalamala, M. A. Rajan, Sachin Lodha |
TrustCom | 6 |
| 2019 | pFilter: Retrofitting Legacy Applications for Data PrivacyabstractEnterprise needs to process customer data for providing tailored services to them, however, the data often includes sensitive and personally identifiable information. This leads to a difficult situation wherein the enterprise has to balance the necessity to process the sensitive data with the requirement to safeguard its privacy. The problem is more prominent in legacy applications with almost no privacy controls in place. A well-studied technique to retrofit legacy application is to mask sensitive content before it is rendered on the screen using path based methods. In this work we show the gap in the existing state of art and describe a dynamic system which utilizes a context to perform locality based searching and masking of sensitive content. Manish Shukla 0001, Kumar Vidhani, Gangadhara Reddy Sirigireddy, Vijayanand Banahatti, Sachin Lodha |
CCS | 5 |
| 2019 | Force vs. Nudge: Comparing Users' Pattern Choices on SysPal and TinPal
Harshal Tupsamudre, Sukanya Vaddepalli, Vijayanand Banahatti, Sachin Lodha |
CCS | 4 |
| 2019 | Multi-objective stable matching and distributional constraints
Mangesh S. Gharote, Nitin Phuke, Rahul Patil, Sachin Lodha |
Soft Comput. | 4 |
| 2017 | Pass-O: A Proposal to Improve the Security of Pattern Unlock SchemeabstractThe graphical pattern unlock scheme which requires users to connect a minimum of 4 nodes on 3X3 grid is one of the most popular authentication mechanism on mobile devices. However prior research suggests that users' pattern choices are highly biased and hence vulnerable to guessing attacks. Moreover, 3X3 pattern choices are devoid of features such as longer stroke lengths, direction changes and intersections that are considered to be important in preventing shoulder-surfing attacks. We attribute these insecure practices to the geometry of the grid and its complicated drawing rules which prevent users from realising the full potential of graphical passwords. In this paper, we propose and explore an alternate circular layout referred to as Pass-O which unlike grid layout allows connection between any two nodes, thus simplifying the pattern drawing rules. Consequently, Pass-O produces a theoretical search space of 9,85,824, almost 2.5 times greater than 3X3 grid layout. We compare the security of 3X3 and Pass-O patterns theoretically as well as empirically. Theoretically, Pass-O patterns are uniform and have greater visual complexity due to large number of intersections. To perform empirical analysis, we conduct a large-scale web-based user study and collect more than 1,23,000 patterns from 21,053 users. After examining user-chosen 3X3 and Pass-O patterns across different metrics such as pattern length, stroke length, start point, end point, repetitions, number of direction changes and intersections, we find that Pass-O patterns are much more secure than 3X3 patterns. Harshal Tupsamudre, Vijayanand Banahatti, Sachin Lodha, Ketan Vyas |
AsiaCCS | 3 |
| 2017 | Privacy Aware Temporal Profiling of Emails in Distributed SetupabstractThe enterprise email promises to be a rich source for knowledge discovery. This is made possible due to the direct nature of communication, support for diverse media types, active participation of entities and presence of chronological ordering of messages. Also, the enterprise emails are more trustworthy than external emails due to their formal nature. This data source has not been fully tapped. In fact, the existing work on profiling of emails focuses primarily on expertise identification and retrieval. Even in these studies, the researchers have made some restrictive assumptions. For instance, in many of the formulations, the underlying system assumes a centralized data repository, and the communication network is complete. They do not account for individual biases in an email while mining and aggregating results. Furthermore, email holds fair amount of personal and organizational sensitive information. None of the existing work on email profiling suggests anything on alleviating the individual and organizational privacy concerns. Sutapa Mondal, Manish Shukla 0001, Sachin Lodha |
CIKM | 3 |
| 2016 | POSTER: Locally Virtualized Environment for Mitigating Ransomware ThreatabstractRansomware is one of the rising malwares in the crimeware family. It encrypts the user files and demands extortion money. From the perspective of an enterprise it is very crucial to detect and stop a ransomware attack. A well studied technique is to monitor file system behavior for suspicious activity. In this work we will show the gap in the existing state of art and describe a dynamic system which learns new behavior while under attack. Manish Shukla 0001, Sutapa Mondal, Sachin Lodha |
CCS | 3 |
| 2016 | POSTER: Improved Markov Strength Meters for PasswordsabstractMarkov-based strength meters provide more accurate estimate of password strength as opposed to rule-based strength meters. However, we observed that these meters assign very high scores to slightly altered weak passwords. It is important to score modified variants of weak passwords more conservatively as the existing password cracking tools generate such guesses much more quickly. In this paper, we propose a simple greedy algorithm to detect small alterations and improve the scoring mechanism of Markov strength meters. Harshal Tupsamudre, Vijayanand Banahatti, Sachin Lodha |
CCS | 3 |
| 2016 | Unsupervised Word Clustering Using Deep FeaturesabstractDigitization is crucial especially in the Indian context. OCR engines fail on Indian scripts mainly because character segmentation is non-trivial. Even word based recognition approaches suffer from the issues such as time degradations, word segmentation errors, font style/size variations. In this paper, we propose a deep learning architecture based approach for unsupervised word clustering. An edge responsive untrained Convolutional Neural Network (CNN) is used as a feature extractor. Graph connected component analysis is applied on the similarity graph computed from the word features. Our approach inherently detects similar shape patterns at word level and hence, it is language agnostic. We validated our approach against multiple state of art word matching techniques. Experimental results show that our approach significantly outperforms all of them on variety of data sets. In addition, the approach is observed to be robust to word segmentation errors, font style/size variations. Mandar Kulkarni, Shirish S. Karande, Sachin Lodha |
DAS | 3 |
| 2016 | On Employing a Highly Mismatched Crowd for Speech Transcription
Purushotam G. Radadia, Kanika Kalra, Shirish S. Karande, Sachin Lodha |
INTERSPEECH | 5 |
| 2015 | POSTER: WinOver Enterprise Dark DataabstractAny persistent untagged, untapped and unclassified data can be termed as dark data. It has two common traits: first, it is not possible to determine its worth, and second, in most of the scenarios it is inadequately protected. Previous work and existing solutions are restricted to cater single node system. Moreover, they perform specialized processing of selected content, for example, logs. Further, there is total negligence of stakeholders and minimal focus on the data getting generated within the enterprise. From the perspective of an enterprise it is important to understand the distribution, nature and worth of dark data, as it helps in choosing right security controls, insurance or steps needed to pre-process a system before discarding it. In this paper we demonstrate a distributed system, called File WinOver, for File Lifecycle Management (FLM). The solution operates in a distributed environment where it identifies the dormant and active files on a system, filters them as per requirement and computes their fingerprint. Moreover, the content fingerprinting is utilized to detect closed user groups. After which, it classifies the content based on configured policies, and maps them with the stakeholders. This mapping is further used for valuating the risk exposure of the file. Thus, our system helps in identifying dark data and assigns quantitative risk value. Manish Shukla 0001, Sumesh Manjunath Ramesh, Rohit Saxena, Sutapa Mondal, Sachin Lodha |
CCS | 5 |
| 2015 | Multi-view image inpainting with sparse representationsabstractThis paper proposes a patch based image inpainting algorithm for multi-view images. In our framework we fill the holes which are created by removing objects from an image pair. We assume that a user provides two masks to remove objects from an image pair. Our algorithm consists of two stages. In the first stage we align the images and construct an exemplar dictionary with the patches sampled from the reference as well as the warped image. In the second stage, the reference image is iteratively filled by choosing patches along the boundary of the hole. We use l1-minimization framework to estimate the unknown pixels. This proposed method is observed to outperform existing techniques that are built upon exemplar based sparse reconstruction. Sandhya Thaskani, Shirish S. Karande, Sachin Lodha |
ICIP | 3 |
| 2013 | On the real-time masking of the sound of credit cards using hot patchingabstractPhone based card payments utilize inband DTMF signaling to convey data. Since the DTMF signals are audible to a human ear, a call operator is in position to carry out a privacy attack. We investigate real-time techniques that can obfuscate the 'digit' values without deteriorating the voice quality. Furthermore, we consider a setting where the privacy solution is being provided by a third party which does not have the benefit of open interfaces to the communication application. Our experiments reveal the efficacy of binary interception to 'inject' the signal filtering. Meanwhile, we observe that several DTMF suppression techniques that have been proposed in literature can leave a residue that is sufficient for de-anonymizing the digit value. In light of these observations, we argue in favor of more modest privacy guarantees, which can be achieved by suppressing only the higher frequency. We show that margin crossings and peak variances can be used for fast pre-filtering of audio to detect the presence of a tone, thus reducing the computational needs. Manish Shukla 0001, Purushotam G. Radadia, Shirish S. Karande, Sachin Lodha |
CCS | 4 |
| 2012 | Data Privacy Using MASKETEERTM
Sachin Lodha, Nikhil Patwardhan, Ashim Roy, Sharada Sundaram, Dilys Thomas |
ICTAC | 1 |
| 2006 | The Graham-Knowlton Problem Revisited
Navin Goyal, Sachin Lodha, S. Muthukrishnan 0001 |
Theory Comput. Syst. | 2 |
| 2004 | On Minimum Circular Arrangement
Murali K. Ganapathy, Sachin Lodha |
STACS | 2 |
| 2002 | Efficient proper 2-coloring of almost disjoint hypergraphs
József Beck, Sachin Lodha |
SODA | 2 |
| 2001 | Algorithms for Efficient Filtering in Content-Based Multicast
Stefan Langerman, Sachin Lodha, Rahul Shah 0001 |
ESA | 2 |
| 1998 | Fast Digital Identity Revocation (Extended Abstract)
William Aiello, Sachin Lodha, Rafail Ostrovsky |
CRYPTO | 2 |