EDBT 2026 Demo / reviewers in the wild / expert
Sashank Narain
dblp:148/4618
· DBLP profile ↗
23ranked-venue papers
5as first author
17since 2021 · last 2026
0000-0001-5377-3750ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 13 · 1 first-author · 13 since 2021Security and privacy · 9 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cryptographic Vulnerability Detection in Code: A Hybrid Syntactic and Semantic Analysis Framework
Krishna Vellamchety, Maryam Abbasalizadeh, Areej Alnahdi, Pranathi Rayavaram, Vaishali Mohan Pajai, Sashank Narain |
ICISSP (1) | 6 |
| 2025 | Current Research, Challenges, and Future Directions in Stalkerware Detection Techniques for Mobile Ecosystems
Mounika Bonam, Pranathi Rayavaram, Maryam Abbasalizadeh, Claire Seungeun Lee, April Pattavina, Sashank Narain |
ICISSP (1) | 6 |
| 2025 | Enhancing Cybersecurity Education using Scoring Engines: A Practical Approach to Hands-On Learning and FeedbackabstractIn today's digital landscape, the demand for skilled cybersecurity professionals is higher than ever. However, many educational programs primarily focus on theoretical concepts, leaving students with insufficient practical skills. To address this gap, students need actionable feedback on their hands-on labs and assignments. We present an open-source scoring engine that provides iterative, step-by-step feedback, enabling students to solve complex cybersecurity problems progressively. Integrated into existing courses, this engine can enhance labs with detailed, structured feedback, bridging the gap between theoretical knowledge and practical application. A preliminary study with 11 students showed that all participants could complete complex tasks using the feedback provided by the engine, with limited instruction from the authors. Additionally, about 90% of the students reported high satisfaction with the structured feedback. This approach has the potential to transform cybersecurity education, making it more interactive, practical, and aligned with real-world requirements. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Sashank Narain, Xinwen Fu |
SIGCSE (1) | 4 |
| 2025 | Practical Cybersecurity Education: A Course Model Using Experiential Learning TheoryabstractThe increasing sophistication of cybersecurity threats necessitates an educational approach that blends theoretical knowledge with practical experience. Many courses focus primarily on theoretical concepts, leaving students with limited hands-on experience with real-world challenges. This paper introduces a cybersecurity course model that integrates Experiential Learning Theory to provide a comprehensive hands-on learning environment. The course covers important cybersecurity topics, including SSH, VPNs, TLS, MFA, OpenID Connect, OAuth2, web server security, high availability, replication, distributed file systems, and orchestration with Docker and Kubernetes. These topics are explored through a mix of lectures, peer presentations, and weekly hands-on team practices. Over three years, the course has been offered at our large public university with 72 students enrolled, consistently receiving high course ratings between 4.8 and 5.0. This paper discusses the course design, methodology, and outcomes, offering insights for educators to replicate and adapt the model for their own institutions. Sashank Narain, Pranathi Rayavaram, Christopher Morales, Matthew Harper, Maryam Abbasalizadeh, Krishna Vellamchety, Xinwen Fu |
SIGCSE (1) | 1 |
| 2025 | CryptoEL: A Novel Experiential Learning Tool for Enhancing K-12 Cryptography Education
Pranathi Rayavaram, Ukaegbu Onyinyechukwu, Maryam Abbasalizadeh, Krishna Vellamchety, Sashank Narain |
SIGCSE (1) | 5 |
| 2024 | Evaluating the Efficacy of Productivity Tools in Engineering EducationabstractProductivity methodologies and tools are crucial in technology-focused organizations, fostering efficiency and collaboration. Industry practices, such as Scrum and Objectives and Key Results (OKRs), along with tools like Jira and Git, empower individuals and teams. Communication platforms like Zoom, Microsoft Teams, Slack, and Confluence bridge geographical gaps. Despite their significance, a noticeable gap exists in integrating these practices into academic institutions, hindering students' transitions to the professional realm. This research focuses on effectively integrating industry best practices—Scrum, OKRs, Jira, Git, Zoom, Microsoft Teams, Slack, and Confluence—into academic settings to improve students' individual and team performance in the classroom and to elevate their overall readiness for industry. The study presents practical guidelines derived from interviews with industry professionals, establishing parallels between industry and academia. These guidelines encompass supplemental learning, pairing students with experienced individuals, and recommending cost-effective tools like Discord for collaboration. Scrum principles, implemented through Taiga (a free alternative to Jira) and GitHub, along with OKRs, are endorsed for project and task tracking, providing a comprehensive framework for enhanced productivity in academic contexts. An assessment of these guidelines in an intensive cybersecurity course at a large public university reveals positive outcomes. Pairing students and leveraging Discord for communication prove effective. Methodologies like Scrum and OKRs receive positive responses, with Git emerging as a favorite for collaborative work. The role of Taiga in task accountability is acknowledged. Overall, the implementation of our guidelines demonstrates a positive impact on student and team performance, emphasizing the potential for the effective integration of industry-endorsed practices in academic settings. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Manoj Yeddanapudi, Sashank Narain, Xinwen Fu |
EDUCON | 5 |
| 2024 | Let's Go for a Drive: Exploring AI's Societal Impact in K-8 Education with an Interactive Self-Driving Car ToolabstractThis innovative practice full paper discusses the development of an interactive tool designed to educate middle school students on the ethical considerations and societal impacts of artificial intelligence (AI). As AI technologies become more embedded in our daily lives, the younger generation must grasp the implications of algorithmic bias and its societal effects. Our tool aims to deepen this understanding by focusing on self-driving cars-a relevant and significant example of AI technology. The interactive tool incorporates three advanced image recognition models trained on diverse datasets, including traffic cones, animals, and pedestrians. Through the tool's interface, students can choose one of these models to apply in a self-driving car simulation and select different obstacles for the car to encounter, such as traffic cones, animals, and pedestrians. This hands-on simulation highlights the importance of comprehensive AI model training, showcasing how well-trained models help avoid collisions and the risks associated with encountering untrained obstacles. It engages students by demonstrating how developers' AI training decisions can significantly influence end-user experiences. Moreover, the tool emphasizes the need for diverse and representative data in building fair and robust AI systems. To assess the effectiveness of this educational tool, we conducted a two-day AI exhibit attended by 26 middle-school students from grades six to eight. The effectiveness was evaluated through posttrial questionnaires to measure the students' understanding of several key concepts: the development of resilient AI models, the societal impacts of AI, and the ethical considerations of road safety in the context of AI. The results showed that 84.6 % of the participants understood how poor training decisions could impact AI outcomes, and about 96 % recognized the necessity for diverse data. Pranathi Rayavaram, Sashank Narain, Fred G. Martin |
FIE | 2 |
| 2024 | Perception, Trust, Attitudes, and Models: Introducing Children to AI and Machine Learning with Five Software ExhibitsabstractArtificial intelligence (AI) and machine learning (ML) have a deepening impact in our world. For empowered citizenship and career readiness, elementary and middle school students need to understand these technologies. This poster reports on five original interactive AI and ML software exhibits tested by 125 elementary and middle school students aged 7 to 14 years. Four themes emerged: Students recognized that AI and ML systems can process data from cameras (perception); they saw that these systems responded to their training input (trust); they appreciated the practical import of AI/ML systems (affective and cognitive attitudes); and students were introduced to models and modes (specialization). Fred G. Martin, Saniya Vahedian Movahed, James Dimino, Andrew Farrell, Elyas Irankhah, Srija Ghosh, Garima Jain, Vaishali Mahipal, Pranathi Rayavaram, Ismaila Temitayo Sanusi, Erika Salas, Kelilah L. Wolkowicz, Sashank Narain |
SIGCSE (2) | 13 |
| 2024 | Visual CryptoED: A Role-Playing and Visualization Tool for K-12 Cryptography EducationabstractRole-playing and visual interfaces are vital in computer science education, notably cybersecurity, where a concrete understanding of defensive and offensive strategies matters. In this work, we implemented a cryptography education tool combining real-world scenarios, role-playing and visual interfaces to simplify cryptography education for K-12 students. This tool covers symmetric and asymmetric cryptography and secure hashing algorithms, which are fundamental to principles like confidentiality, integrity protection, and authentication. Our tool's core idea is to simulate a cryptographic transaction between a user and a bank while an attacker tries to compromise the communication. Within this role-playing and visual environment, students step into the roles of both the user and the bank, using an intuitive visual interface to perform essential cryptographic operations and grasp the underlying concepts. We evaluated our educational tool on 58 students (41 middle and 17 high school students), measuring comprehension via a survey. Our analysis revealed that middle and high school students could readily understand the key operations related to symmetric cryptography, asymmetric cryptography, and hashing using our role-playing tool. Nearly all participants expressed satisfaction with the tool and were willing to recommend it to others. Pranathi Rayavaram, Sahithi Charitha Dindukuri, Krishna Vellamchety, Justin Marwad, Maryam Abbasalizadeh, Claire Seungeun Lee, Sashank Narain |
SIGCSE (1) | 7 |
| 2023 | Integrating Data Structures and Algorithms in K-12 Education using Block-based ProgrammingabstractThis paper describes the design and evaluation of DSAScratch, an extension to Scratch, a widely used block-based programming language. The DSAScratch framework implements advanced data structures such as arrays, sets, dictionaries, and searching and sorting algorithms. By presenting these concepts in an intuitive block-based interface, these blocks abstract away technical details and simplify data structures and algorithms concepts for K-12 students to grasp and apply to programming problems more readily. A preliminary evaluation of the tools' usability and learning outcomes is presented in this paper. Given the information we have gathered about DSAScratch, we show that the extension is beneficial for students to develop a deeper understanding of programming and an intuitive understanding of these concepts in high school. We present the methodology and preliminary results of a user study conducted with ten high school students. During the user study, 70% of the participants understood the key ideas behind DSAScratch implemented data structures and algorithms through a mixture of lectures and hands-on activities. We show that DSAScratch was also an important part of the workshop for 90% of the students who participated, as it enhanced their understanding of algorithms and data structures. Furthermore, they indicated that they would recommend DSAScratch to their peers. Ashwin Jagadeesha, Pranathi Rayavaram, Justin Marwad, Sashank Narain, Claire Seungeun Lee |
EDUCON | 4 |
| 2023 | Designing a Visual Cryptography Curriculum for K-12 EducationabstractWe have designed and developed a simple, visual, and narrative K-12 cybersecurity curriculum leveraging the Scratch programming platform to demonstrate and teach fundamental cybersecurity concepts such as confidentiality, integrity protection, and authentication. The visual curriculum simulates a real-world scenario of a user and a bank performing a bank transaction and an adversary attempting to attack the transaction. We have designed six visual scenarios, the curriculum first introduces students to three visual scenarios demonstrating attacks that exist when systems do not integrate concepts such as confidentiality, integrity protection, and authentication. Then, it introduces them to three visual scenarios that build on the attacks to demonstrate and teach how these fundamental concepts can be used to defend against them. We conducted an evaluation of our curriculum through a study with 18 middle and high school students. To evaluate the student's comprehension of these concepts we distributed a technical survey, where overall average of students answering these questions related to the demonstrated concepts is 9.28 out of 10. Furthermore, the survey results revealed that 66.7% found the system extremely easy and the remaining 27.8% found it easy to use and understand. Pranathi Rayavaram, Sreekriti Sista, Ashwin Jagadeesha, Justin Marwad, Nathan Percival, Sashank Narain, Claire Seungeun Lee |
EDUCON | 6 |
| 2023 | Designing a Visual Cryptography Curriculum for K-12 EducationabstractWe have designed and developed a simple, visual, and narrative K-12 cybersecurity curriculum leveraging the Scratch programming platform to demonstrate and teach fundamental cybersecurity concepts such as confidentiality, integrity protection, and authentication. The visual curriculum simulates a real-world scenario of a user and a bank performing a banking transaction and an adversary attempting to attack the transaction. The curriculum first introduces students to three visual scenarios demonstrating attacks that exist when systems do not integrate the fundamental concepts of confidentiality, integrity protection, and authentication. Then, it introduces them to three visual scenarios that build on the attacks to demonstrate and teach how the fundamental concepts can be used to defend against them. Pranathi Rayavaram, Ashwin Jagadeesha, Sashank Narain, Claire Seungeun Lee |
SIGCSE (2) | 3 |
| 2022 | CryptoScratch: Developing and evaluating a block-based programming tool for teaching K-12 cryptography education using ScratchabstractThe world continues to experience a shortage of skilled cybersecurity personnel. The widely accepted solution for reducing this gap is raising awareness about cybersecurity. In response, many schools are integrating cybersecurity into the K-12 curriculum. Also, educational initiatives from the National Initiative for Cybersecurity Education, GenCyber, and the CryptoClub project enable universities to provide enrichment to middle- and high-school students regarding the importance of cybersecurity. Unfortunately, there is currently an absence of visual and straightforward tools that limits the feasibility of hands-on practice during these initiatives. This paper presents the design, implementation, and evaluation of a new framework called CryptoScratch, which extends the Scratch programming environment with modern cryptographic algorithms (e.g., AES, RSA, SHA-256) implemented as visual blocks. Using the simple interface of CryptoScratch, K-12 students can study how to use cryptographic algorithms for services like confidentiality, authentication, and integrity protection; and then use these blocks to build complex modern cryptographic schemes (e.g., Pretty Good Privacy, Digital Signatures). In addition, we present the design and implementation of a Task Block that provides students instruction on various cryptography problems and verifies that they have successfully completed the problem. The task block also generates feedback, nudging learners to implement more secure solutions for cryptographic problems. An initial usability study was performed with 16 middle-school students where students were taught basic cryptographic concepts and then asked to complete tasks using those concepts. Once students had knowledge of a variety of basic cryptographic algorithms, they were asked to use those algorithms to implement complex cryptographic schemes such as Pretty Good Privacy and Digital Signatures. Using the successful implementation of the cryptographic and task blocks in Scratch, the initial testing indicated that $\approx 60\%$ of the students could quickly grasp and implement complex cryptography concepts using CryptoScratch, while $\approx 90\%$ showed comfort with cryptography concepts and use-cases. Based on the positive results from the initial testing, a larger study of students is being developed to investigate the effectiveness across the socioeconomic spectrum. Nathan Percival, Pranathi Rayavaram, Sashank Narain, Claire Seungeun Lee |
EDUCON | 3 |
| 2022 | AlgoScratch - Simplifying Data Structures and Algorithms Education using Block-based ProgrammingabstractWe have implemented a novel framework called AlgoScratch as an extension to the popular Scratch programming language. AlgoScratch is designed to simplify Data Structures and Algorithms education in the K-12 curriculum through visual and intuitive Scratch blocks. The framework implements widely used data structures such as Arrays, Stacks, Queues, Sets, and Maps; and algorithms such as Binary Search and Quick Sort. This poster discusses the implementation of the AlgoScratch blocks and their ability to simplify complex computer science concepts through visual programming that employs a simple drag and drop-based interface. Ashwin Jagadeesha, Pranathi Rayavaram, Mounika Bonam, Sashank Narain, Claire Seungeun Lee |
ITiCSE (2) | 4 |
| 2022 | CryptoScratch: Teaching Cryptography with Block-based CodingabstractWe have implemented a novel framework called CryptoScratch for teaching cryptography using the widely available Scratch platform. CryptoScratch enables K-12 students to learn how to use cryptographic algorithms such as AES, RSA, and SHA2 and combine these algorithms to build complex modern cryptographic schemes such as Digital Signatures and Pretty Good Privacy. CryptoScratch implements the algorithms as intuitive visual blocks abstracting away the mathematical and technical details of the algorithms. This poster discusses the implementation of CryptoScratch and how using these blocks can help students develop and understand the importance of cryptography in their digital lives. Nathan Percival, Pranathi Rayavaram, Sashank Narain, Claire Seungeun Lee |
SIGCSE (2) | 3 |
| 2022 | Clang __usercall: towards native support for user defined calling conventionsabstractIn reverse engineering interfacing with C/C++ functions is of great interest because it provides much more flexibility for product development and security purpose. However, it has been a great challenge when interfacing functions with user defined calling conventions due to the lack of sufficient and user-friendly tooling. In this work, we design and implement Clang __usercall, which aims to provide programmers with an elegant and familiar syntax to specify user defined calling conventions on functions in C/C++ source code. Our key novelties lie in mimicing the most popular syntax and adapting Clang for interfacing purpose. Our preliminary user study shows that our solution outperforms the existing ones in multiple key aspects including user experience and required lines of code. Clang __usercall is already added to the Compiler Explorer website as well. Jared Q. Widberg, Sashank Narain, Yimin Chen 0004 |
ESEC/SIGSOFT FSE | 2 |
| 2021 | Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsabstractBluetooth Low Energy advertisements are increasingly used for proximity privacy-preserving protocols. We investigate information leakage from BLE advertisements. Our analysis, among other things, reveals that the design of today’s Bluetooth chips enables the linking of BLE advertisements to Bluetooth Classic (BTC) frames, and to a globally unique identifier (BDADDR). We demonstrate that the inference of the BDADDR from BLE advertisements is robust achieving over 90% reliability across apps, mobile devices, density of devices, and tens of meters away from the victims. We discuss the implications of current chipsets vulnerability on privacy-preserving protocols. The attack, for instance, reveals the BDADDR of devices of infected users of contact-tracing apps. We also discuss how the vulnerability can lead to de-anonymization of victims. Furthermore, current mobile devices do not allow selective disabling of BTC independently of BLE which renders simple countermeasures impractical. We developed several mitigations for the Android OS and the Bluetooth stack and demonstrate their efficacy. Norbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara Noubir |
SP | 3 |
| 2019 | Security of GPS/INS Based On-road Location Tracking SystemsabstractLocation information is critical to a wide variety of navigation and tracking applications. GPS, today's de-facto outdoor localization system has been shown to be vulnerable to signal spoofing attacks. Inertial Navigation Systems (INS) are emerging as a popular complementary system, especially in road transportation systems as they enable improved navigation and tracking as well as offer resilience to wireless signals spoofing and jamming attacks. In this paper, we evaluate the security guarantees of INS-aided GPS tracking and navigation for road transportation systems. We consider an adversary required to travel from a source location to a destination and monitored by an INS-aided GPS system. The goal of the adversary is to travel to alternate locations without being detected. We develop and evaluate algorithms that achieve this goal, providing the adversary significant latitude. Our algorithms build a graph model for a given road network and enable us to derive potential destinations an attacker can reach without raising alarms even with the INS-aided GPS tracking and navigation system. The algorithms render the gyroscope and accelerometer sensors useless as they generate road trajectories indistinguishable from plausible paths (both in terms of turn angles and roads curvature). We also design, build and demonstrate that the magnetometer can be actively spoofed using a combination of carefully controlled coils. To experimentally demonstrate and evaluate the feasibility of the attack in real-world, we implement a first real-time integrated GPS/INS spoofer that accounts for traffic fluidity, congestion, lights, and dynamically generates corresponding spoofing signals. Furthermore, we evaluate our attack on ten different cities using driving traces and publicly available city plans. Our evaluations show that it is possible for an attacker to reach destinations that are as far as 30 km away from the actual destination without being detected. We also show that it is possible for the adversary to reach almost 60-80% of possible points within the target region in some cities. Such results are only a lower-bound, as an adversary can adjust our parameters to spend more resources (e.g., time) on the target source/destination than we did for our performance evaluations of thousands of paths. We propose countermeasures that limit an attacker's ability, without the need for any hardware modifications. Our system can be used as the foundation for countering such attacks, both detecting and recommending paths that are difficult to spoof. Sashank Narain, Aanjhan Ranganathan, Guevara Noubir |
IEEE Symposium on Security and Privacy | 1 |
| 2019 | A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link
Milan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich, David Kreitschmann, Guevara Noubir, Matthias Hollick |
USENIX Security Symposium | 2 |
| 2019 | Mitigating Location Privacy Attacks on Mobile Devices using Dynamic App SandboxingabstractAbstract We present the design, implementation and evaluation of a system, called MATRIX, developed to protect the privacy of mobile device users from location inference and sensor side-channel attacks. MATRIX gives users control and visibility over location and sensor (e.g., Accelerometers and Gyroscopes) accesses by mobile apps. It implements aPrivoScopeservice that audits all location and sensor accesses by apps on the device and generates real-time notifications and graphs for visualizing these accesses; and aSynthetic Locationservice to enable users to provide obfuscated or synthetic location trajectories or sensor traces to apps they find useful, but do not trust with their private information. The services are designed to be extensible and easy for users, hiding all of the underlying complexity from them. MATRIX also implements aLocation Providercomponent that generates realistic privacy-preserving synthetic identities and trajectories for users by incorporating traffic information using historical data from Google Maps Directions API, and accelerations using statistical information from user driving experiments. These mobility patterns are generated by modeling/solving user schedule using a randomized linear program and modeling/solving for user driving behavior using a quadratic program. We extensively evaluated MATRIX using user studies, popular location-driven apps and machine learning techniques, and demonstrate that it is portable to most Android devices globally, is reliable, has low-overhead, and generates synthetic trajectories that are difficult to differentiate from real mobility trajectories by an adversary. Sashank Narain, Guevara Noubir |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | An autonomic and permissionless Android covert channelabstractDemand for mobile devices continues to experience worldwide growth. Within the U.S., there is a significant shift away from broadband usage towards Smartphones as the primary Internet entry point for consumers. Although technological advancements have helped fuel demand for greater features and functionality to enhance the user experience, they have also drawn attention from malicious actors seeking to access and exfiltrate increasingly available sensitive and content rich personalized information. Kenneth Block, Sashank Narain, Guevara Noubir |
WISEC | 2 |
| 2016 | Inferring User Routes and Locations Using Zero-Permission Mobile SensorsabstractLeakage of user location and traffic patterns is a serious security threat with significant implications on privacy as reported by recent surveys and identified by the US Congress Location Privacy Protection Act of 2014. While mobile phones can restrict the explicit access to location information to applications authorized by the user, they are ill-equipped to protect against side-channel attacks. In this paper, we show that a zero-permissions Android app can infer vehicular users' location and traveled routes, with high accuracy and without the users' knowledge, using gyroscope, accelerometer, and magnetometer information. We modeled this problem as a maximum likelihood route identification on a graph. The graph is generated from the OpenStreetMap publicly available database of roads. Our route identification algorithms output both a ranked list of potential routes as well a ranked list of route-clusters. Through extensive simulations over 11 cities, we show that for most cities with probability higher than 50% it is possible to output a short list of 10 routes containing the traveled route. In real driving experiments (over 980 Km) in the cities of Boston (resp. Waltham), Massachusetts, we report a probability of 30% (resp. 60%) of inferring a list of 10 routes containing the true route. Sashank Narain, Triet Vo Huu, Kenneth Block, Guevara Noubir |
IEEE Symposium on Security and Privacy | 1 |
| 2014 | Single-stroke language-agnostic keylogging using stereo-microphones and domain specific machine learningabstractMobile phones are equipped with an increasingly large number of precise and sophisticated sensors. This raises the risk of direct and indirect privacy breaches. In this paper, we investigate the feasibility of keystroke inference when user taps on a soft keyboard are captured by the stereoscopic microphones on an Android smartphone. We developed algorithms for sensor-signals processing and domain specific machine learning to infer key taps using a combination of stereo-microphones and gyroscopes. We implemented and evaluated the performance of our system on two popular mobile phones and a tablet: Samsung S2, Samsung Tab 8 and HTC One. Based on our experiments, and to the best of our knowledge, our system (1) is the first to exceed 90% accuracy requiring a single attempt, (2) operates on the standard Android QWERTY and number keyboards, and (3) is language agnostic. We show that stereo-microphones are a much more effective side channel as compared to the gyroscope, however, their data can be combined to boost the accuracy of prediction. While previous studies focused on larger key sizes and repetitive attempts, we show that by focusing on the specifics of the keyboard and creating machine learning models and algorithms based on keyboard areas combined with adequate filtering, we can achieve an accuracy of 90% - 94% for much smaller key sizes in a single attempt. We also demonstrate how such attacks can be instrumentalized by a malicious application to log the keystrokes of other sensitive applications. Finally, we describe some techniques to mitigate these attacks. Sashank Narain, Amirali Sanatinia, Guevara Noubir |
WISEC | 1 |