EDBT 2026 Demo / reviewers in the wild / expert
Rupesh Raj Karn
dblp:166/3074
· DBLP profile ↗
22ranked-venue papers
22as first author
19since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 19 · 19 first-author · 16 since 2021Software engineering, systems software and programming languages · 4 · 4 first-author · 4 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Benchmarking Continual Learning on Netlists with Circuit-Targeted Graph Neural NetworksabstractThe rapid evolution of integrated circuits demands that machine learning (ML) for electronic design automation (EDA) adapts to new circuit semantics without catastrophic forgetting (CF) of prior knowledge-a challenge unaddressed by commonly established, static training paradigms. Continual learning (CL) offers a promising approach, but its application to evolving netlists remains unexplored. Here, we present the first benchmarking study of CL on netlists with circuit-targeted graph neural networks (GNNs). We evaluate six CL methods, including parameter regularization, replay-based, and hybrid approaches, all for a fixed GNN architecture for fair comparison. Our benchmarking covers two foundational GNN applications commonly found in EDA: gate-level node classification and netlistlevel link prediction. We find that replay-based CL techniques are particularly suitable for hindering CF in such circuit-targeted GNN applications. This work paves the way for future adaptive EDA tools for emerging design landscapes. All benchmarking materials are released at [1]. Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
ASP-DAC | 1 |
| 2026 | Black-Box Robustness Probing of Graph Neural Networks for VLSI Circuit NetlistsabstractGraph Neural Network (GNN) models are becoming increasingly popular due to their native ability to represent complex integrated circuits as graph data. However, many deployed models remain black boxes with unexamined potential vulnerabilities, including a lack of robustness against perturbations in data distributions. We present a framework for black-box probing for GNN robustness via input-output queries only, utilizing key metrics such as Jacobian, Lipschitz constants, Hessian, prediction margins, robustness radius, and noise stability, relating them all to model performance. We assess various GNN models and seminal architectures, including GraphSAINT, GraphSAGE, GIN, and GAT, all operating on the well-known ISCAS’85 and EPFL benchmarks. We consider gate classification and hardware Trojan detection, the latter being a task that requires excellent robustness by nature. Across node-, subgraph-, and graph-level operation, we find that even highly accurate GNNs can exhibit notable local fragility under perturbations. Overall, our work calls for more stringent consideration of robustness for GNN integration, especially when utilizing third-party service providers, and our framework provides well-defined means for an independent evaluation of this challenge. Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
DATE | 1 |
| 2026 | Interpretable Graph Neural Networks for Fault Detection in Circuit NetlistsabstractThis work presents a framework for accurate and interpretable fault detection in digital circuit netlists using multiple state-of-the-art Graph Neural Network (GNN) architectures. Targeting three representative fault types—stuck-at, bridging, and glitch—we formulate the detection task as a multi-label node classification problem. Using a robust parsing pipeline, we construct graph datasets from the ISCAS85 and EPFL benchmarks, embedding both structural attributes and novel relational features. Results demonstrate that most GNNs achieve over 90% accuracy, with the proposed relational features consistently boosting performance. Furthermore, we leverage these relational features for model interpretability, successfully highlighting features most relevant to circuit faults. Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
DATE | 1 |
| 2026 | Securing Hyper-Dimensional Computing: A Locking Mechanism with FPGA Implementation
Rupesh Raj Karn, Paul R. Genssler, Hussam Amrouch, Ozgur Sinanoglu |
ICISSP (2) | 1 |
| 2026 | LLM-Driven Python-to-Rust Translation for Efficient and Safe Code for Neural Networks: llm4py2rs
Rupesh Raj Karn, Johann Knechtel, Siddharth Garg, Ramesh Karri, Ozgur Sinanoglu |
ICISSP (2) | 1 |
| 2026 | Structural Security Entropy: A Novel Prior for Robust GNN-Based Security Assessment of Netlists
Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
IOLTS | 1 |
| 2026 | Interpretable GNNs for Fault Detection in Circuits
Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
IOLTS | 1 |
| 2026 | Educational Perspectives on LLM Architectures: Analyzing Code Generation for Circuits and Systems
Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
ISCAS | 1 |
| 2026 | Dynamic GNNs for Continual Learning on Circuits
Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
ISCAS | 1 |
| 2025 | LLM-Driven Code Generation for Neural Networks on FPGAs: Bridging Python and HLSabstractLarge language models (LLMs) have transformed code generation across various fields. Here, we study the specific opportunities and challenges that LLMs present in generating hardware designs for neural networks (NNs) on fieldprogrammable gate arrays (FPGAs). We illustrate how LLMs can be utilized to achieve code optimizations essential for this task, such as parallelism, memory management, and latency reduction. Additionally, we compare the proposed specialized approach for NN code generation with others for more generalized hardware. Through a series of case studies and performance evaluations, we also contrast our results with prior state of the art. Rupesh Raj Karn, Johann Knechtel, Ramesh Karri, Ozgur Sinanoglu |
ICCD | 1 |
| 2025 | Logic Locking for Random Forests: Securing HDL Design and FPGA Accelerator Implementation
Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
ICISSP (2) | 1 |
| 2025 | Educational Framework for Power Side-Channel Attacks on Neural Networks in Embedded SystemsabstractWe present an educational framework for security analysis of neural networks using the ChipWhisperer (CW) embedded system. More specifically, our contribution is to build a simple framework capable of performing power side-channel attacks from traces directly captured by CW’s microcontroller. CW eliminates the need for expensive and complex equipment like oscilloscopes, which helps to simplify the educational mission. Our work provides a modern educational tool, enabling students to learn about the real-world resilience of neural networks end-to-end, from training to deployment to security analysis, thereby contributing to the development of more secure systems in the future. In addition, we incorporate learning of software coding on embedded systems assisted by large language models. Rupesh Raj Karn, Prithwish Basu Roy, Johann Knechtel, Ozgur Sinanoglu |
ISCAS | 1 |
| 2025 | Trojan Attacks on Graph Convolution Neural Networks for Circuit AnalysisabstractGraph convolutional neural networks (GCNNs) have become a powerful tool for circuit analysis in VLSI design. This work systematically studies Trojan attacks on neural networks, first demonstrating their impact on a simple CNN trained on MNIST to illustrate trigger insertion and misclassification. We then extend this approach to GCNNs for node classification in circuit netlists (ISCAS’85, EPFL), introducing node features and graph connectivity triggers to force misclassification to a target class. Experiments show that while Trojanized models maintain high accuracy on clean data, they reliably misclassify triggered samples, highlighting the need for robust architectures in circuit analysis. The attacks exhibit high success rates and clean-data fidelity across diverse trigger types and gate classes, revealing structural vulnerabilities in GCNN-based EDA pipelines. Rupesh Raj Karn, Ozgur Sinanoglu |
VLSI-SoC | 1 |
| 2024 | Order-Preserving Cryptography for the Confidential Inference in Random Forests: FPGA Design and ImplementationabstractPrior work has addressed the problem of confidential inference in decision trees. Both traditional order-preserving cryptography (OPE) and order-preserving NTRU cryptography have been used to ensure data and model privacy in decision trees. Furthermore, FPGA architectures and implementations have been proposed for implementing such confidential inference algorithms on resource-limited, edge-based platforms such as low-cost FPGA boards. In this paper, we address the challenging problem of scalability of order-preserving confidential inference to random forests, which are ensembles of decision trees that are meant to improve their classification accuracy and reduce their overfitting. The paper develops a methodology and an FPGA implementation strategy for scaling up OPE to random forests. In particular, a framework is used to study the multifaceted tradeoffs that exist between the number of trees in the random forest, the strength of the encryption, the accuracy of the inferences, and the resources of the edge platform. Extensive experiments are conducted using the MNIST dataset and the Intel DE10 Standard FPGA board. Rupesh Raj Karn, Kashif Nawaz, Ibrahim M. Elfadel |
DAC | 1 |
| 2024 | Obfuscation of FSMs for Secure Outsourcing of Neural Network Inference onto FPGAsabstractFinite-state machine (FSM)-based networks are an alternative to implement neural networks (NNs) on hardware-constrained devices, such as field-programmable gate arrays (FPGAs), because this approach helps to synthesize complex multi-input functions needed for NN inference. Such FSM network, implemented according to the NN learning outcome, constitutes intellectual property (IP). Thus, it is necessary to prevent IP theft and its illegal use. This paper presents an obfuscation approach for locking of such FSM networks at the behavioral level of abstraction. The proposed technique is built on the encryption of both the state and the transition encoding, each with its unique key, known only to the IP provider. A steganography approach is used on top, to ensure that the message containing the secret key for unlocking does not capture the attacker’s attention as target for inspection. The FSM-based NN works as intended only if the proper key is entered at runtime; otherwise, it will perform erroneous classification. We use Xilinx’s Artix-7 FPGA board to demonstrate this locking approach. We also provide a scalability study on the hardware implementation. Rupesh Raj Karn, Johann Knechtel, Ozgur Sinanoglu |
ISCAS | 1 |
| 2023 | Post-Quantum, Order-Preserving Encryption for the Confidential Inference in Decision Trees: FPGA Design and ImplementationabstractOne main objective of this paper is to show how to adapt the well-known, lattice-based NTRU post-quantum encryption to the confidential inference in decision trees. Another objective is to describe a resource-efficient FPGA implementation of the adapted NTRU. The typical use case of such encryption is that of two parties where one party has proprietary ownership of the decision tree model while the other party has proprietary ownership of the data. Confidential inference in decision trees can be insured using order-preserving cryptography, which has much weaker requirements and is therefore easier to implement than fully homomorphic cryptography. Post-quantum NTRU is not order-preserving, but interestingly, it can be modified to obey the order-preserving property. We call the resulting cipher OP-NTRU. Lossless compression can be applied to the ciphertext produced by OP-NTRU to facilitate its hardware acceleration. OP-NTRU has been implemented on an FPGA with the HDL code automatically compiled from the machine learning framework. Confidential inference experiments report more than 96% compression without degrading inference accuracy in FPGA for the MNIST dataset. Rupesh Raj Karn, Kashif Nawaz, Ibrahim M. Elfadel |
VLSI-SoC | 1 |
| 2022 | Hyper-parameter Tuning for Progressive Learning and its Application to Network Cyber SecurityabstractThe long-term deployment of data-driven AI technology using artificial neural networks (ANNs) should be scalable and maintainable when new data becomes available. To insure smooth adaptation, the learning must be cumulative so that the network consumes new data without compromising its inference performance based on past data. Such incremental accumulation of learning experience is known as progressive learning. In this paper, we address the open problem of tuning the hyperparameters of neural networks during progressive learning. A hyper-parameter optimization framework is proposed that selects the best hyper-parameter values on a task-by-task basis. The neural network model adapts to each progressive learning task by adjusting the hyper-parameters under which the neural architecture is incrementally grown. Several hyper-parameter search strategies are explored and compared in support of progressive learning. In contrast to the predominant practice of using imaging datasets in machine learning, we have used cybersecurity datasets to illustrate the advantages of the proposed hyper-parameter tuning algorithms. Rupesh Raj Karn, Matthew M. Ziegler, Jinwook Jung, Ibrahim M. Elfadel |
ISCAS | 1 |
| 2022 | Confidential Inference in Decision Trees: FPGA Design and ImplementationabstractIn confidential computing, algorithms operate on encrypted inputs to produce encrypted outputs. Specifically, in confidential inference, Alice has the parameters of the machine-learning model but does not want to reveal them to Bob who has the data. Bob wants to use Alice’s model for inference but does not want to reveal his data. Alice and Bob agree to use homomorphic encryption for running the inference engine in full confidence without revealing either model or data. They find that full homomorphic encryption is very time consuming and very challenging to accelerate on hardware. In this particular case, homomorphic encryption can be made computationally efficient and can even be readily accelerated on hardware. In this paper, we reveal how Alice and Bob run the inference engine in full confidence and show an FPGA implementation of the specialized homomorphic computing algorithm they used. We further evaluate the resources needed to implement the encrypted decision tree and compare them with those of a plain decision tree. Confidential inference tests are run on the encrypted FPGA design using the MNIST dataset. Rupesh Raj Karn, Ibrahim M. Elfadel |
VLSI-SoC | 1 |
| 2021 | Cryptomining Detection in Container Clouds Using System Calls and Explainable Machine LearningabstractThe use of containers in cloud computing has been steadily increasing. With the emergence of Kubernetes, the management of applications inside containers (or pods) is simplified. Kubernetes allows automated actions like self-healing, scaling, rolling back, and updates for the application management. At the same time, security threats have also evolved with attacks on pods to perform malicious actions. Out of several recent malware types, cryptomining has emerged as one of the most serious threats with its hijacking of server resources for cryptocurrency mining. During application deployment and execution in the pod, a cryptomining process, started by a hidden malware executable can be run in the background, and a method to detect malicious cryptomining software running inside Kubernetes pods is needed. One feasible strategy is to use machine learning (ML) to identify and classify pods based on whether or not they contain a running process of cryptomining. In addition to such detection, the system administrator will need an explanation as to the reason(s) of the ML's classification outcome. The explanation will justify and support disruptive administrative decisions such as pod removal or its restart with a new image. In this article, we describe the design and implementation of an ML-based detection system of anomalous pods in a Kubernetes cluster by monitoring Linux-kernel system calls (syscalls). Several types of cryptominers images are used as containers within an anomalous pod, and several ML models are built to detect such pods in the presence of numerous healthy cloud workloads. Explainability is provided using SHAP, LIME, and a novel auto-encoding-based scheme for LSTM models. Seven evaluation metrics are used to compare and contrast the explainable models of the proposed ML cryptomining detection engine. Rupesh Raj Karn, Prabhakar Kudva, Hai Huang 0002, Sahil Suneja, Ibrahim M. Elfadel |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2020 | Dynamically Generated Compact Neural Networks for Task Progressive LearningabstractTask progressive learning is often required where the training data become available in batches over the time. Such learning has the characteristic of using an existing model trained over a set of tasks to learn a new task while maintaining the accuracy of older tasks. Artificial Neural Networks (ANNs) have a higher capacity for progressive learning than other traditional machine learning models due to the availability of a large number of ANN parameters. A progressive model that uses a fully connected ANN suffers from long training time, overfitting, and excessive resource usage. It is therefore necessary to generate the ANN incrementally as new tasks arrive and new training is needed. In this paper, an incremental algorithm is presented to dynamically generate a compact neural network by pruning and expanding the synaptic weights based on the learning requirements of the new tasks. The algorithm is implemented, analyzed, and validated using the cloud network security datasets, UNSW and AWID, as well as the image dataset, MNIST. Rupesh Raj Karn, Prabhakar Kudva, Ibrahim M. Elfadel |
ISCAS | 1 |
| 2019 | Dynamic Autoselection and Autotuning of Machine Learning Models for Cloud Network AnalyticsabstractCloud network monitoring data is dynamic and distributed. Signals to monitor the cloud can appear, disappear or change their importance and clarity over time. Machine learning (ML) models tuned to a given data set can therefore quickly become inadequate. A model might be highly accurate at one point in time but may lose its accuracy at a later time due to changes in input data and their features. Distributed learning with dynamic model selection is therefore often required. Under such selection, poorly performing models (although aggressively tuned for the prior data) are retired or put on standby while new or standby models are brought in. The well-known method of Ensemble ML (EML) may potentially be applied to improve the overall accuracy of a family of ML models. Unfortunately, EML has several disadvantages, including the need for continuous training, excessive computational resources, requirement for large training datasets, high risks of overfitting, and a time-consuming model-building process. In this paper, we propose a novel cloud methodology for automatic ML model selection and tuning that automates model building and selection and is competitive with existing methods. We use unsupervised learning to better explore the data space before the generation of targeted supervised learning models in an automated fashion. In particular, we create a Cloud DevOps architecture for autotuning and selection based on container orchestration and messaging between containers, and take advantage of a new autoscaling method to dynamically create and evaluate instantiations of ML algorithms. The proposed methodology and tool are demonstrated on cloud network security datasets. Rupesh Raj Karn, Prabhakar Kudva, Ibrahim M. Elfadel |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2015 | Multicore power proxies using least-angle regressionabstractThe use of performance counters (PCs) to develop per-core power proxies for multicore processors is now well established. These proxies are typically obtained using traditional linear regression techniques. These techniques have the disadvantage of requiring the full PC set regardless of the workload run by the multicore processor. Typically a computationally expensive principal component analysis is conducted to find the PCs most correlated with each workload. In this paper, we use the more recent algorithm of least-angle regression to efficiently develop power proxies that include only PCs most relevant to the workload. Such PCs can be considered workload signatures and used to categorize the workload and to trigger specific power management action. Our new power proxies are trained and tested on workloads from the PARSEC and SPEC CPU 2006 benchmarks with an average error of less than 3%. Rupesh Raj Karn, Ibrahim M. Elfadel |
ISCAS | 1 |