EDBT 2026 Demo / reviewers in the wild / expert
Ajaya Neupane
dblp:154/7852
· DBLP profile ↗
18ranked-venue papers
7as first author
4since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 6 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorArtificial intelligence and machine learning · 1Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Users Really Do Respond To SmishingabstractText phish messages, referred to as Smishing (SMS + phishing) is a type of social engineering attack where fake text messages are created, and used to lure users into responding to those messages. These messages aim to obtain user credentials, install malware on the phones, or launch smishing attacks. They ask users to reply to their message, click on a URL that redirects them to a phishing website, or call the provided number. Drawing inspiration by the works of Tu et al. on Robocalls and Tischer et al. on USB drives, this paper investigates why smishing works. Accordingly, we designed smishing experiments and sent phishing SMSes to 265 users to measure the efficacy of smishing attacks. We sent eight fake text messages to participants and recorded their CLICK, REPLY, and CALL responses along with their feedback in a post-test survey. Our results reveal that 16.92% of our participants had potentially fallen for our smishing attack. To test repeat phishing, we subjected a set of randomly selected participants to a second round of smishing attacks with a different message than the one they received in the first round. As a result, we observed that 12.82% potentially fell for the attack again. Using logistic regression, we observed that a combination of user REPLY and CLICK actions increased the odds that a user would respond to our smishing message when compared to CLICK. Additionally, we found a similar statistically significant increase when comparing Facebook and Walmart entity scenario to our IRS baseline. Based on our results, we pinpoint essentially message attributes and demographic features that contribute to a statistically significant change in the response rates to smishing attacks. Muhammad Lutfor Rahman, Daniel Timko, Hamid Wali, Ajaya Neupane |
CODASPY | 4 |
| 2023 | Machine learning based fileless malware traffic classification using image visualizationabstractAbstract In today’s interconnected world, network traffic is replete with adversarial attacks. As technology evolves, these attacks are also becoming increasingly sophisticated, making them even harder to detect. Fortunately, artificial intelligence (AI) and, specifically machine learning (ML), have shown great success in fast and accurate detection, classification, and even analysis of such threats. Accordingly, there is a growing body of literature addressing how subfields of AI/ML (e.g., natural language processing (NLP)) are getting leveraged to accurately detect evasive malicious patterns in network traffic. In this paper, we delve into the current advancements in ML-based network traffic classification using image visualization. Through a rigorous experimental methodology, we first explore the process of network traffic to image conversion. Subsequently, we investigate how machine learning techniques can effectively leverage image visualization to accurately classify evasive malicious traces within network traffic. Through the utilization of production-level tools and utilities in realistic experiments, our proposed solution achieves an impressive accuracy rate of 99.48% in detecting fileless malware, which is widely regarded as one of the most elusive classes of malicious software. Fikirte Ayalke Demmese, Ajaya Neupane, Sajad Khorsandroo, May Wang, Kaushik Roy 0003 |
Cybersecur. | 2 |
| 2022 | BigEye: Detection and Summarization of Key Global Events From Distributed Crowdsensed DataabstractSocial media postings using smartphones (referred to as crowd-sensed data) can often facilitate real-time detection of key physical events in applications like disaster recovery or in smart cities. These postings also often contain visual content (e.g., images) that can be used to obtain zoomed-in views of such events. These crowd-sensed data are likely to be of large volume and distributed across a plurality of producers (e.g., cloudlets). Blindly transferring this large volume of raw data from the producers to a consumer will induce information overload and consume very high bandwidth. The problem is exacerbated in scenarios with limited bandwidth (e.g., after a disaster). In this article, we designBigEye, a novel framework that only transfers very limited data from the distributed producers to a central summarizer, and yet supports: 1) highly accurate detection and 2) concise visual summarization of key events of global interest. In realizingBigEye, we address several challenges including: 1) identifying events that have the highest global interest via the transfer of appropriate limited metadata from the producers to the summarizer; 2) reconciling metadata that could be inconsistent across the producers; and 3) the timely retrieval of visual summaries of the key events given bandwidth constraints. We show thatBigEyeachieves the same accuracy in detecting key events, as a system, where all data are available centrally while transferring only 1% of the raw data volume. Compared to the baseline approaches,BigEye’s parallelized transfer of visual content reduces the average delay by 67%. Abdulrahman Fahim, Ajaya Neupane, Evangelos E. Papalexakis, Lance M. Kaplan, Srikanth V. Krishnamurthy, Tarek F. Abdelzaher |
IEEE Internet Things J. | 2 |
| 2021 | Side Channel Attacks on GPUsabstractGraphics Processing Units (GPUs) are commonly integrated with computing devices to enhance the performance and capabilities of graphical workloads. In addition, they are increasingly being integrated in data centers and clouds such that they can be used to accelerate data intensive workloads. Under a number of scenarios the GPU can be shared between multiple applications at a fine granularity allowing a spy application to monitor side channels and attempt to infer the behavior of the victim. For example, OpenGL and WebGL send workloads to the GPU at the granularity of a frame, allowing an attacker to interleave the use of the GPU to measure the side-effects of the victim computation through performance counters or other resource tracking APIs. We demonstrate the vulnerability by implementing three end-to-end attacks. We show that an OpenGL or CUDA based spy can fingerprint websites accurately (attack I), track user activities within the website, and even infer the keystroke timings for a password text box (attack II) with high accuracy. The third attack demonstrates how a CUDA spy application can derive the internal parameters of a neural network model being used by another CUDA application on the cloud. To counter these attacks, the paper suggests mitigations based on limiting the rate of the calls, or limiting the granularity of the returned information. Hoda Naghibi Jouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Edge-Assisted Detection and Summarization of Key Global Events from Distributed Crowd-Sensed DataabstractThis paper introduces a novel service for distributed detection and summarization of crowd-sensed events. The work is motivated by the proliferation of microblogging media, such as Twitter, that can be used to detect and describe events in the physical world, such as protests, disasters, or civil unrest. Since crowd-sensed data is likely to be distributed, we consider an architecture, where the data first accumulates across a plurality of edge servers (e.g. cloudlets or repositories) and is then summarized, rather than being shipped directly to its ultimate destination (e.g., in a remote cloud). The architecture allows graceful handling of overload and bandwidth limitations (e.g., in scenarios where capacity is impaired, as the case might be after a disaster). When bandwidth is scarce, our service, BigEye, only transfers very limited metadata from the distributed edge repositories to the central summarizer and yet supports highly accurate detection and concise summarization of key events of global interest. These summaries can then be sent to consumers (e.g., rescue personnel). Our emulations show that BigEye achieves the same precision and recall values in detecting key events as a system where all data is available centrally, while consuming only 1% of the bandwidth needed to transmit all raw data. Abdelrahman Fahim, Ajaya Neupane, Evangelos E. Papalexakis, Lance M. Kaplan, Srikanth V. Krishnamurthy, Tarek F. Abdelzaher |
IC2E | 2 |
| 2019 | CATCHA: When Cats Track Your Movements Online
Prakash Shrestha, Nitesh Saxena, Ajaya Neupane, Kiavash Satvat |
ISPEC | 3 |
| 2019 | Stealthy Adversarial Perturbations Against Real-Time Video Classification Systems
Shasha Li 0001, Ajaya Neupane, Sujoy Paul, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Ananthram Swami |
NDSS | 2 |
| 2019 | The Crux of Voice (In)Security: A Brain Study of Speaker Legitimacy Detection
Ajaya Neupane, Nitesh Saxena, Leanne M. Hirshfield, Sarah Bratt |
NDSS | 1 |
| 2019 | Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics Libraries
Daimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh, Srikanth V. Krishnamurthy, Edward Colbert, Paul L. Yu |
NDSS | 2 |
| 2019 | Brain Hemorrhage: When Brainwaves Leak Sensitive Medical Conditions and Personal InformationabstractBrain Computer Interfaces (BCI) are rapidly gaining popularity in consumer market. It is therefore important to analyze the security and privacy threats these devices may introduce to their users. In this paper, we explore how malicious access to brainwave signals may surreptitiously reveal users' privacy-sensitive medical conditions and personal information, while they are browsing the web (or interacting with an app). At a conceptual level, we investigate the potential of brainwave signals, captured during a user's normal interactions with visual stimuli (e.g., images and audio-visuals) through a website or computer, in exposing whether the user is suffering from a given medical disorder (e.g., drug abuse or autism) and to which demographics group the user belongs (e.g., young vs. elderly or male vs. female). At an empirical level, as two representative case studies into such conceptual attacks, we present a concrete brainwave privacy attack, (Brain) Hemorrhage11In the context of our work, the term “Hemorrhage” is an attack against brainwave privacy. Brain Hemorrhage is a type of alcoholic cocktail, and hence the terminology is also intended to capture one of the case studies of our work on Alcohol Use Disorder., focusing on the leakage of Alcohol Usage Disorder (AUD) and users' age group. Hemorrhage is designed using machine learning techniques to identify the users suffering from AUD and age group by analyzing the seemingly innocuous brainwave signals leaked online in response to users' viewing of simple images or watching of videos. Based on the publicly available EEG datasets on AUD and aging, our study shows that Hemorrhage can predict the presence or absence of alcohol usage disorder with the precision of 96% and the presence or absence of aging condition with 94% accuracy. We also analyze, visualize and interpret the differences in the brainwave signals corresponding to AUD and aging, which serves to justify why our attack succeeds. While the use of neuroimaging devices to diagnose medical disorders in clinical settings is a common practice in the medical field, our study constitutes one of the first steps towards exploring the malicious use of brainwave devices in compromising people's health information privacy in an online setting (otherwise protected under the HIPAA law) as well as their age privacy. Given any website can have unfettered, permission-less access to the signals captured by the current BCI devices, we believe that our work raises a serious online health privacy and age privacy issues as these devices get widely deployed. Ajaya Neupane, Kiavash Satvat, Mahshid Hosseini, Nitesh Saxena |
PST | 1 |
| 2018 | Do Social Disorders Facilitate Social Engineering?: A Case Study of Autism and Phishing AttacksabstractSocial engineering is a well-established and well-studied threat especially against healthy computer users. Little studied, however, is the level of vulnerability to social engineering attacks against people with medical conditions. Social disorders in particular may make people more susceptible to such attacks. In this paper, as an initial line of investigation into this understudied research line, we launch a study of phishing, a prominent social engineering attack, against people suffering from autism spectrum disorder, a unique developmental disorder characterized by hampered social skills and communication. Ajaya Neupane, Kiavash Satvat, Nitesh Saxena, Despina Stavrinos, Haley Johnson Bishop |
ACSAC | 1 |
| 2018 | IAC: On the Feasibility of Utilizing Neural Signals for Access ControlabstractAccess control is the core security mechanism of an operating system (OS). Ideally, the access control system should enforce context integrity, i.e., an application can only access security and privacy sensitive resources expected by users. Unfortunately, existing access control systems, including the permission systems in modern OS like iOS and Android, all fail to enforce context integrity thus allow apps to abuse their permissions. A naive approach to enforce context integrity is to prompt users every time a sensitive resource is accessed, but this will quickly lead to habituation. The state-of-art solutions include (1) user-driven access control, which binds a predefined context to protected GUI elements and (2) predicting users' authorization decision based on their previous behaviors and privacy preferences. However, previous studies have shown that the first approach is vulnerable to attacks (e.g., clickjacking) and the second approach i challenging to implement as it is difficult to infer the context. In this work, we explore the feasibility of a novel approach to enforce the context integrity---by inferring what task users want to do under the given context from their neural signals; then automatically authorizes access to a predefined set of sensitive resources that are necessary for that task. We conducted a comprehensive user study including 41 participants where we collected their neural signals when they were performing tasks that required access to sensitive resources. After preprocessing and features extraction, we trained machine learning classifier to infer what kind of tasks a user wants to perform. The experiment results show that the classifier was able to infer the high-level intents like take a photo with a weighted average precision of 88%. Muhammad Lutfor Rahman, Ajaya Neupane, Chengyu Song |
ACSAC | 2 |
| 2018 | Rendered Insecure: GPU Side Channel Attacks are PracticalabstractGraphics Processing Units (GPUs) are commonly integrated with computing devices to enhance the performance and capabilities of graphical workloads. In addition, they are increasingly being integrated in data centers and clouds such that they can be used to accelerate data intensive workloads. Under a number of scenarios the GPU can be shared between multiple applications at a fine granularity allowing a spy application to monitor side channels and attempt to infer the behavior of the victim. For example, OpenGL and WebGL send workloads to the GPU at the granularity of a frame, allowing an attacker to interleave the use of the GPU to measure the side-effects of the victim computation through performance counters or other resource tracking APIs. We demonstrate the vulnerability using two applications. First, we show that an OpenGL based spy can fingerprint websites accurately, track user activities within the website, and even infer the keystroke timings for a password text box with high accuracy. The second application demonstrates how a CUDA spy application can derive the internal parameters of a neural network model being used by another CUDA application, illustrating these threats on the cloud. To counter these attacks, the paper suggests mitigations based on limiting the rate of the calls, or limiting the granularity of the returned information. Hoda Naghibi Jouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh |
CCS | 2 |
| 2018 | Learning Tensor-Based Representations from Brain-Computer Interface Data for Cybersecurity
Muhammad Lutfor Rahman, Sharmistha Bardhan, Ajaya Neupane, Evangelos E. Papalexakis, Chengyu Song |
ECML/PKDD (3) | 3 |
| 2017 | Neural Underpinnings of Website Legitimacy and Familiarity Detection: An fNIRS StudyabstractIn this paper, we study the neural underpinnings relevant to user-centered web security through the lens of functional near-infrared spectroscopy (fNIRS). Specifically, we design and conduct an fNIRS study to pursue a thorough investigation of users' processing of legitimate vs. illegitimate and familiar vs. unfamiliar websites. We pinpoint the neural activity in these tasks as well as the brain areas that control such activity. We show that, at the neurological level, users process the legitimate websites differently from the illegitimate websites when subject to phishing attacks. Similarly, we show that users exhibit marked differences in the way their brains process the previously familiar websites from unfamiliar websites. These findings have several defensive and offensive implications. In particular, we discuss how these differences may be used by the system designers in the future to differentiate between legitimate and illegitimate websites automatically based on neural signals. Similarly, we discuss the potential for future malicious attackers, with access to neural signals, in compromising the privacy of users by detecting whether a website is previously familiar or unfamiliar to the user. Ajaya Neupane, Nitesh Saxena, Leanne M. Hirshfield |
WWW | 1 |
| 2016 | Neural Markers of Cybersecurity: An fMRI Study of Phishing and Malware WarningsabstractThe security of computer systems often relies upon decisions and actions of end users. In this paper, we set out to investigate users' susceptibility to cybercriminal attacks by concentrating at the most fundamental component governing user behavior-the human brain. We introduce a novel neuroscience-based study methodology to inform the design of user-centered security systems as it relates to cybercrime. In particular, we report on an functional magnetic resonance imaging study measuring users' security performance and underlying neural activity with respect to two critical security tasks: (1) distinguishing between a legitimate and a phishing website and (2) heeding security (malware) warnings. We identify the neural markers that might be controlling users' performance in these tasks, and establish relationships between brain activity and behavioral performance as well as between users' personality traits and security behavior. Our results provide a largely positive perspective on users' capability and performance vis-à-vis these crucial security tasks. First, we show that users exhibit significant brain activity in key regions associated with decision-making, attention, and problem-solving (phishing and malware warnings) as well as language comprehension and reading (malware warnings), which means that users are actively engaged in these security tasks. Second, we demonstrate that certain individual traits, such as impulsivity measured via an established questionnaire, are associated with a significant negative effect on brain activation in these tasks. Third, we discover a high degree of correlation in brain activity (in decision-making regions) across phishing detection and malware warnings tasks, which implies that users' behavior in one task may potentially be predicted by their behavior in the other. Fourth, we discover high functional connectivity among the core regions of the brain, while users performed the phishing detection task. Finally, we discuss the broader impacts and implications of our work on the field of user-centered security, including the domain of security education, targeted security training, and security screening. Ajaya Neupane, Nitesh Saxena, Jose Omar Maximo, Rajesh K. Kana |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | A Multi-Modal Neuro-Physiological Study of Phishing Detection and Malware WarningsabstractDetecting phishing attacks (identifying fake vs. real websites) and heeding security warnings represent classical user-centered security tasks subjected to a series of prior investigations. However, our understanding of user behavior underlying these tasks is still not fully mature, motivating further work concentrating at the neuro-physiological level governing the human processing of such tasks. Ajaya Neupane, Muhammad Lutfor Rahman, Nitesh Saxena, Leanne M. Hirshfield |
CCS | 1 |
| 2014 | Neural Signatures of User-Centered Security: An fMRI Study of Phishing, and Malware Warnings
Ajaya Neupane, Nitesh Saxena, Keya Kuruvilla, Michael Georgescu, Rajesh K. Kana |
NDSS | 1 |