Manohar Vanga

dblp:157/0686 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
2since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Security and privacy of machine learning · 100%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 65% Distributed systems · 25% Embedded and real-time systems · 10%
Software engineering, system software, and programming languages
1 paper
Operating systems · 50% Concurrent programming · 50%
Artificial intelligence
1 paper
Efficient and distributed learning · 100%

Topics — the 13 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning
federated learning security
1.012026
Model Hijacking Attack in Federated Learning · IEEE Trans. Inf. Forensics Secur. 2026
Security and privacy of machine learning › poisoning attack
model hijacking attack
1.012026
Model Hijacking Attack in Federated Learning · IEEE Trans. Inf. Forensics Secur. 2026
Security and privacy of machine learning
poisoning attack
1.012026
Model Hijacking Attack in Federated Learning · IEEE Trans. Inf. Forensics Secur. 2026
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management
0.512021
SmartHarvest: harvesting idle CPUs safely and efficiently in the cloud · EuroSys 2021
Distributed systems › resource sharing
idle resource harvesting
0.512021
SmartHarvest: harvesting idle CPUs safely and efficiently in the cloud · EuroSys 2021
Cloud and datacenter computing
virtualization
0.312018
Tableau: a high-throughput and predictable VM scheduler for high-density workloads · EuroSys 2018
Cloud and datacenter computing › virtualization › virtual machine management
virtual machine scheduling
0.312018
Tableau: a high-throughput and predictable VM scheduler for high-density workloads · EuroSys 2018
Machine learning › Efficient and distributed learning
federated learning
0.312026
Model Hijacking Attack in Federated Learning · IEEE Trans. Inf. Forensics Secur. 2026
Operating systems › real-time systems
real-time operating systems
0.212014
Fast on Average, Predictable in the Worst Case: Exploring Real-Time Futexes in LITMUSRT · RTSS 2014
Concurrent programming
synchronization
0.212014
Fast on Average, Predictable in the Worst Case: Exploring Real-Time Futexes in LITMUSRT · RTSS 2014
Embedded and real-time systems
real-time scheduling
0.222018
Tableau: a high-throughput and predictable VM scheduler for high-density workloads · EuroSys 2018
Fast on Average, Predictable in the Worst Case: Exploring Real-Time Futexes in LITMUSRT · RTSS 2014
Cloud and datacenter computing › virtualization
virtual machine management
0.112021
SmartHarvest: harvesting idle CPUs safely and efficiently in the cloud · EuroSys 2021
Embedded and real-time systems › real-time scheduling
worst-case analysis
0.112014
Fast on Average, Predictable in the Worst Case: Exploring Real-Time Futexes in LITMUSRT · RTSS 2014

Methods — techniques the papers use, named apart from their topics

pixel-level perturbation · 2.0feature-space alignment · 1.0feature space alignment · 1.0batch scheduling · 0.5CPU core harvesting · 0.5priority inheritance protocol · 0.4multiprocessor priority ceiling protocol · 0.4futex · 0.4flexible multiprocessor locking protocol · 0.4table-driven dispatch · 0.3real-time scheduling · 0.3
YearPublicationVenuePosition
2026 Model Hijacking Attack in Federated Learning
abstract
Machine learning (ML), driven by prominent paradigms such as centralized and federated learning, has made significant progress in various critical applications. However, its remarkable success has been accompanied by various attacks. Recently, the model hijacking attack has shown that ML models can be hijacked to execute tasks different from their original tasks, which increases both accountability and parasitic computational risks. Nevertheless, thus far, this attack has only focused on centralized learning. In this work, we broaden the scope of this attack to the federated learning domain, where multiple clients collaboratively train a global model without sharing their data. Specifically, we present the first-of-its-kind hijacking attack against the global model in federated learning, namely HijackFL. The adversary aims to force the global model to perform a different task (called hijacking task) from its original task without the server or benign client noticing. To accomplish this, unlike existing methods that use data poisoning to modify the target model’s parameters, HijackFL searches for pixel-level perturbations based on their local model (without modifications) to align hijacking samples with the original ones in the feature space. When performing the hijacking task, the adversary applies these perturbations to the hijacking samples, compelling the global model to identify them as original ones and predict them accordingly. Extensive experiments demonstrate HijackFL significantly outperforms baselines, e.g., 92.75% vs. 10%. We further investigate the factors that affect its performance and discuss possible defenses to mitigate its impact.
Zheng Li 0023, Ruichuan Chen, Paarijaat Aditya, Istemi Ekin Akkus, Manohar Vanga, Min Zhang 0043, Hao Li 0092, Yang Zhang 0016
IEEE Trans. Inf. Forensics Secur.6
2021 SmartHarvest: harvesting idle CPUs safely and efficiently in the cloud
abstract
We can increase the efficiency of public cloud datacenters by harvesting allocated but temporarily idling CPU cores from customer virtual machines (VMs) to run batch or analytics workloads. Even small efficiency gains translate into substantial savings, since provisioning and operating a datacenter costs hundreds of millions of dollars per year. The main challenge is to harvest idle cores with little or no impact on customer VMs, which could be running latency-sensitive services and are essentially black-boxes to the cloud provider.
Kapil Arya, Marios Kogias, Manohar Vanga, Aditya Bhandari, Neeraja J. Yadwadkar, Siddhartha Sen 0001, Sameh Elnikety, Christoforos E. Kozyrakis, Ricardo Bianchini
EuroSys4
2018 Tableau: a high-throughput and predictable VM scheduler for high-density workloads
abstract
In the increasingly competitive public-cloud marketplace, improving the efficiency of data centers is a major concern. One way to improve efficiency is to consolidate as many VMs onto as few physical cores as possible, provided that performance expectations are not violated. However, as a prerequisite for increased VM densities, the hypervisor's VM scheduler must allocate processor time efficiently and in a timely fashion. As we show in this paper, contemporary VM schedulers leave substantial room for improvements in both regards when facing challenging high-VM-density workloads that frequently trigger the VM scheduler. As root causes, we identify (i) high runtime overheads and (ii) unpredictable scheduling heuristics. To better support high VM densities, we propose Tableau, a VM scheduler that guarantees a minimum processor share and a maximum bound on scheduling delay for every VM in the system. Tableau combines a low-overhead, core-local, table-driven dispatcher with a fast on-demand table-generation procedure (triggered on VM creation/teardown) that employs scheduling techniques typically used in hard real-time systems. In an evaluation of Tableau and three current Xen schedulers on a 16-core Intel Xeon machine, Tableau is shown to improve tail latency (e.g., a 17X reduction in maximum ping latency compared to Credit) and throughput (e.g., 1.6X peak web server throughput compared to RTDS when serving 1 KiB files with a 100 ms SLA).
Manohar Vanga, Arpan Gujarati, Björn B. Brandenburg
EuroSys1
2017 TimerShield: Protecting High-Priority Tasks from Low-Priority Timer Interference (Outstanding Paper)
abstract
Timer interference arises when a high-priority realtime task is delayed by a timer interrupt that is intended for a lower-priority task. We demonstrate that high-resolution timers, as exposed for instance by Linux's hrtimer API, can cause substantial timer interference, which manifests as significantly increased response times and lowered throughput. To eliminate this source of unpredictability, we propose TimerShield, a priority-aware highresolution timer subsystem that selectively delays the servicing of lower-priority timer interrupts while a high-priority task is executing. We present the design and implementation of a fully functional TimerShield prototype in Linux PREEMPT RT and compare it against Linux's stock hrtimer subsystem on two different platforms (x86 and ARM). Our results show that TimerShield adds only little overhead, while completely eliminating the timing unpredictability and throughput degradation caused by unnecessary interrupts.
Pratyush Patel, Manohar Vanga, Björn B. Brandenburg
RTAS2
2014 Scaling global scheduling with message passing
abstract
Global real-time schedulers have earned the reputation of scaling poorly due to the high runtime overheads involved in global state management. In this paper, two mature implementations, one using fine-grained locking (SCHED DEADLINE) and one using coarse-grained locking (LITMUSRT's G-EDF plugin), are evaluated and it is shown that, regardless of locking granularity, indeed neither scales well w.r.t. worst-case overheads due to excessive lock contention. To demonstrate that this is not an inherent limitation of global scheduling, the design of G-EDF-MP is presented, a global scheduler that uses message passing to avoid lock contention and cache-line sharing. It is shown to offer up to a 23- to 36-fold reduction in worst-case scheduling overhead on a 64-core platform, which translates into much improved schedulability (in some cases, more than 120 additional tasks can be supported).
Felipe Cerqueira, Manohar Vanga, Björn B. Brandenburg
RTAS2
2014 Fast on Average, Predictable in the Worst Case: Exploring Real-Time Futexes in LITMUSRT
abstract
This paper explores the problem of how to improve the average-case performance of real-time locking protocols, preferably without significantly deteriorating worst-case performance. Motivated by the futex implementation in Linux, where uncontended lock operations under the Priority Inheritance Protocol (PIP) do not incur mode-switching overheads, we extend this concept to more sophisticated protocols, namely the PCP, the MPCP and the FMLP+. We identify the challenges involved in implementing futexes for these protocols and present the design and evaluation of their implementations in LITMUSRT, a real-time extension of the Linux kernel. Our evaluation shows substantial improvements in the uncontended case (e.g., A futex implementation of the PCP lowers lock acquisition and release overheads by up to 75% and 92%, respectively), at the expense of some increases in worst-case overhead on par with Linux's existing futex implementation.
Roy Spliet, Manohar Vanga, Björn B. Brandenburg, Sven Dziadek
RTSS2