EDBT 2026 Demo / reviewers in the wild / expert
Arnab Kumar Biswas
dblp:167/0671
· DBLP profile ↗
13ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-3057-2478ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 6 first-author · 3 since 2021Computer networks · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HBQS: Lightweight Post-Quantum Secure Authentication for Satellite Networks Leveraging Hardware TRNG and PUFsabstractSatellite communication networks play a critical role in providing connectivity to remote regions and areas with limited infrastructure. However, their inherently open nature and physical exposure make them particularly susceptible to security threats, including replay, impersonation, and man-in- the-middle attacks. The emergence of quantum computing further undermines the robustness of conventional cryptographic schemes that rely on number-theoretic assumptions. To mitigate these challenges, this article proposesHBQS, a lightweight post-quantum authentication framework designed for satellite platforms with limited resources.HBQSintegrates Physically Unclonable Functions (PUFs) with hash-based cryptography, leveraging SPHINCS+ digital signatures and SHA-3 hashing to provide secure mutual authentication and session key establishment. The protocolHBQSwas implemented and evaluated on embedded hardware platforms, including Raspberry Pi 4.0, PYNQ-Z2 FPGA, and a Dell ground control station. The experimental results demonstrate thatHBQSachieves mutual authentication in 0.88 ms, offering an approximately 67% reduction in execution time compared to representative baselines from the prior literature. Entropy analysis confirms that the proposed protocol maintains a high entropy across critical components, withHBQSachieving a signature entropy of 164.63 bits and PUF response entropy of 172.58 bits, indicating strong resistance to statistical and modeling attacks. A formal security analysis conducted within the Random Oracle Model demonstrates semantic security against both classical and quantum adversaries. The protocolHBQSshows a significant improvement over existing methods, achieving approximately 67% reduction in computational execution time, approximately 11.5% faster user-side handshake time, approximately 0.6% improvement on the satellite side and full security coverage across all evaluated security features with only a 21.4% increase in static memory usage as the trade-off. These findings positionHBQSas an efficient, secure, and scalable authentication solution for next-generation satellite communication systems operating in the post-quantum era. Muhammad Arslan Akram, Arnab Kumar Biswas, Máire O'Neill, Ayesha Khalid, Adnan Noor Mian |
IEEE Internet Things J. | 2 |
| 2026 | Adaptive Intrusion Detection Systems: Leveraging Meta-Learning for Improved CybersecurityabstractIn the evolving landscape of cybersecurity, the integration of machine learning (ML) into Intrusion Detection Systems (IDS) has become critical for detecting both known and unknown attacks. This paper proposes a novel multi-stage hybrid IDS framework combining unsupervised anomaly detection, supervised classification, and low-shot adaptation for enhanced resilience to concept drift. The architecture comprises three interconnected stages: Stage 1 (unsupervised anomaly gating) and Stage 2 (supervised taxonomy learning) operate in parallel on a shared harmonized feature space; Stage 3 (Hybrid Low-Shot Adapter (H-LSA)) performs low-shot adaptation when the Stage 1 trigger fires, using transferred Stage 2 weights and a prototype-based cosine-kNN jury. Within the meta-learning family, we instantiate a metric-based low-shot adaptation approach eschewing second-order Model-Agnostic Meta-Learning (MAML) in favor of a partial-freeze, first-order protocol with a prototype-based cosine-kNN jury to enable rapid, low-resource adaptation. Extensive experiments were conducted on the CICIDS2017 (Source), CSECIC-IDS2018 (Target), and the modern BCCC-cPacket-Cloud-DDoS-2024 (Target) datasets (hereafter referred to as BCCC-2024). The results demonstrate that while static Stage 2 models suffer catastrophic failure under concept drift (dropping to 45.36% and 38.32% accuracy on CICIDS2018 and harmonized BCCC-2024, respectively), the proposed framework successfully adapts to new environments, achieving 90.64% accuracy on CICIDS2018 (Macro-F1: 0.8981) and 89.70% on BCCC-2024 (Macro-F1: 0.8801) with a low-resource support set of only 500 labeled samples per class. Furthermore, the system exhibits high computational efficiency, achieving a Stage 3 adapted inference latency between 0.0786 ms and 0.1667 ms per flow across diverse traffic profiles, proving its suitability for real-time, scalable deployment in modern cloud and edge network infrastructures. Ashiqur Rahaman Ridoy, Arnab Kumar Biswas |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Privacy-Preserving Lightweight LoRaWAN Authentication Protocol for IoT ApplicationsabstractSecurity and privacy are two primary concerns in critical applications within Internet of Things (IoT) environments. The Long Range Wide Area Network (LoRaWAN) protocol facilitates long-range communication for battery-powered end devices in IoT and has gained widespread adoption among both individuals and industries. To foster trust and facilitate its use, ensuring security and privacy for data collected by end devices is essential. User authentication and key establishment protocols play a pivotal role in this regard. While existing authentication schemes in the literature are unsuitable for LoRaWAN networks, this article proposes an energy-efficient LoRaWAN authentication protocol for privacy preservation in IoT applications. Through formal verification using the Random Oracle Model (ROM) and AVISPA tool, we demonstrate our protocol’s resilience against common attacks including replay, man-in-the-middle, and impersonation threats. Performance evaluations reveal significant advantages over existing schemes: 48% faster computation (0.1953 ms vs. 0.3647 ms baseline), 24% lower communication overhead (2398 bits vs. 3168 bits), and 44% energy savings (1.27 mJ vs. 2.27 mJ) over state-of-the-art protocols. These improvements, combined with enhanced security features, such as resistance to sensor capture and stolen device attacks, make our protocol particularly suitable for practical IoT deployments in smart agriculture and industrial monitoring systems where both security and energy efficiency are paramount. The balance of strong security guarantees and low operational overhead represents a significant advance in LoRaWAN authentication mechanisms. Muhammad Arslan Akram, Adnan Noor Mian, Arnab Kumar Biswas, Saru Kumari, Chien-Ming Chen 0001 |
IEEE Internet Things J. | 3 |
| 2024 | On the Design of a Searchable Encryption Protocol for Keyword Search using Proactive Secret SharingabstractSearchable encryption allows users to perform search operations on encrypted data before decrypting it first. Secret sharing is one of the most important cryptographic primitives used to design an information theoretic scheme. Nowadays cryptosys-tem designers are providing a facility to adjust the security parameters in real time to circumvent AI-enabled cyber security threats. For long term security of data which is used by various applications, proactive secret sharing allows the shares of the original secret to be dynamically adjusted during a specific interval of time. In proactive secret sharing, the updation of shares at regular intervals of time is done by the servers (participants) and not by the dealer. In this paper, we propose a novel proactive secret sharing scheme where the shares stored at servers are updated using preshared pairwise keys between servers at regular intervals of time. The direct search of words over sentences using the conjunctive search function without the generation of any index is possible using the underlying querying method. Praveen K, Gabriel Anand K. S, Indranil Ghosh Ray, Avishek Adhikari, Sabyasachi Datta, Arnab Kumar Biswas |
e-Science | 6 |
| 2022 | Protecting Network-on-Chip Intellectual Property Using Timing Channel FingerprintingabstractThe theft of Intellectual property (IP) is a serious security threat for all businesses that are involved in the creation of IP. In this article, we consider such attacks against IP for Network-on-Chip (NoC) that are commonly used as a popular on-chip scalable communication medium for Multiprocessor System-on-Chip. As a protection mechanism, we propose a timing channel fingerprinting method and show its effectiveness by implementing five different solutions using this method. We also provide a formal proof of security of the proposed method. We show that the proposed technique provides better security and requires much lower hardware overhead (64%–74% less) compared to an existing NoC IP security solution without affecting the normal packet latency or degrading the NoC performance. Arnab Kumar Biswas, Biplab Sikdar 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2022 | Using Pattern of On-Off Routers and Links and Router Delays to Protect Network-on-Chip Intellectual PropertyabstractIntellectual Property (IP) reuse is a well known practice in chip design processes. Nowadays, network-on-chips (NoCs) are increasingly used as IP and sold by various vendors to be integrated in a multiprocessor system-on-chip (MPSoC). However, IP reuse exposes the design to IP theft, and an attacker can launch IP stealing attacks against NoC IPs. With the growing adoption of MPSoC, such attacks can result in huge financial losses. In this article, we propose four NoC IP protection techniques using fingerprint embedding: ON-OFF router-based fingerprinting (ORF), ON-OFF link-based fingerprinting (OLF), Router delay-based fingerprinting (RTDF), and Row delay-based fingerprinting (RWDF). ORF and OLF techniques use patterns of ON-OFF routers and links, respectively, while RTDF and RWDF techniques use router delays to embed fingerprints. We show that all of our proposed techniques require much less hardware overhead compared to an existing NoC IP security solution (square spiral routing) and also provide better security from removal and masking attacks. In particular, our proposed techniques require between 40.75% and 48.43% less router area compared to the existing solution. We also show that our solutions do not affect the normal packet latency and hence do not degrade the NoC performance. Arnab Kumar Biswas |
ACM Trans. Comput. Syst. | 1 |
| 2021 | Cryptographic Software IP Protection without Compromising Performance or Timing Side-channel LeakageabstractProgram obfuscation is a widely used cryptographic software intellectual property (IP) protection technique against reverse engineering attacks in embedded systems. However, very few works have studied the impact of combining various obfuscation techniques on the obscurity (difficulty of reverse engineering) and performance (execution time) of obfuscated programs. In this article, we propose a Genetic Algorithm (GA)-based framework that not only optimizes obscurity and performance of obfuscated cryptographic programs, but it also ensures very low timing side-channel leakage. Our proposed T iming S ide C hannel S ensitive P rogram O bfuscation O ptimization F ramework (TSC-SPOOF) determines the combination of obfuscation transformation functions that produce optimized obfuscated programs with preferred optimization parameters. In particular, TSC-SPOOF employs normalized compression distance (NCD) and channel capacity to measure obscurity and timing side-channel leakage, respectively. We also use RISC-V rocket core running on a Xilinx Zynq FPGA device as part of our framework to obtain realistic results. The experimental results clearly show that our proposed solution leads to cryptographic programs with lower execution time, higher obscurity, and lower timing side-channel leakage than unguided obfuscation. Arnab Kumar Biswas |
ACM Trans. Archit. Code Optim. | 1 |
| 2020 | Network-on-Chip Intellectual Property Protection Using Circular Path-based FingerprintingabstractIntellectual property (IP) reuse is a well-known technique in chip design industry. But this technique also exposes a security vulnerability called IP stealing attack. Network-on-Chip (NoC) is an on-chip scalable communication medium and is used as an IP and sold by various vendors to be integrated in a Multiprocessor System-on-Chip (MPSoC). An attacker can launch IP stealing attack against NoC IP. In this article, we propose a NoC IP protection technique called circular path--based fingerprinting (CPF) using fingerprint embedding. We also provide a theoretical model using polyomino theory to get the number of distinct fingerprints in a NoC. We show that our proposed technique requires much less hardware overhead compared to an existing NoC IP security solution and also provides better security against removal and masking attacks. In particular, our proposed CPF technique requires 27.41% less router area compared to the existing solution. We also show that our CPF solution does not affect the normal packet latency and hence does not degrade the NoC performance. Arnab Kumar Biswas |
ACM J. Emerg. Technol. Comput. Syst. | 1 |
| 2020 | LAMBDA: Lightweight Assessment of Malware for emBeddeD ArchitecturesabstractSecurity is a critical aspect in many of the latest embedded and IoT systems. Malware is one of the severe threats of security for such devices. There have been enormous efforts in malware detection and analysis; however, occurrences of newer varieties of malicious codes prove that it is an extremely difficult problem given the nature of these surreptitious codes. In this article, instead of addressing a general solution, we aim at malware detection for platforms that have more than one core for performance enhancement. We investigate the utility of multiple cores from the point of view of security, where one of the cores operate as a watchdog. We define a notion of a new metric called LAMBDA (Lightweight Assessment of Malware for emBeddeD Architectures), denoted by λ, indicating a conceptual boundary between the programs which are allowed to run on a given platform, with the codes that are suspected as malwares. The metric λ is computed using carefully chosen monitors or features, which are tuples of high-level programs representing OS resources, along with low-level hardware performance counters. In comparison to heavy-weight machine learning techniques, we use an online hypothesis testing, in the form of t -test, to classify a given program-under-test. For applications where security is of prime concern, we propose an additional step based on multivariate analysis to classify the unknown programs that are closer to the threshold with a high degree of confidence. We present experimental results focusing on an ARM-based platform which validate that the proposed approach provides a lightweight, accurate assessment of malware codes for embedded platforms. In addition to it, we also present a security analysis to show the difficulty of a mimicry attack attempting to bypass LAMBDA. Sai Praveen Kadiyala, Manaar Alam, Yash Shrivastava, Sikhar Patranabis, Muhamed Fauzi Bin Abbas, Arnab Kumar Biswas, Debdeep Mukhopadhyay, Thambipillai Srikanthan |
ACM Trans. Embed. Comput. Syst. | 6 |
| 2020 | KLEESpectre: Detecting Information Leakage through Speculative Cache Attacks via Symbolic ExecutionabstractSpectre-style attacks disclosed in early 2018 expose data leakage scenarios via cache side channels. Specifically, speculatively executed paths due to branch mis-prediction may bring secret data into the cache, which are then exposed via cache side channels even after the speculative execution is squashed. Symbolic execution is a well-known test generation method to cover program paths at the level of the application software. In this article, we extend symbolic execution with modeling of cache and speculative execution. Our tool KLEE SPECTRE , built on top of the KLEE symbolic execution engine, can thus provide a testing engine to check for data leakage through the cache side channel as shown via Spectre attacks. Our symbolic cache model can verify whether the sensitive data leakage due to speculative execution can be observed by an attacker at a given program point. Our experiments show that KLEE SPECTRE can effectively detect data leakage along speculatively executed paths and our cache model can make the leakage detection more precise. Sudipta Chattopadhyay 0001, Arnab Kumar Biswas, Tulika Mitra, Abhik Roychoudhury |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2018 | CIDPro: Custom Instructions for Dynamic Program DiversificationabstractTiming side-channel attacks pose a major threat to embedded systems due to their ease of accessibility. We propose CIDPro, a framework that relies on dynamic program diversification to mitigate timing side-channel leakage. The proposed framework integrates the widely used LLVM compiler infrastructure and the increasingly popular RISC-V FPGA soft-processor. The compiler automatically generates custom instructions in the security critical segments of the program, and the instructions execute on the RISC-V custom co-processor to produce diversified timing characteristics on each execution instance. CIDPro has been implemented on the Zynq7000 XC7Z020 FPGA device to study the performance overhead and security tradeoffs. Experimental results show that our solution can achieve 80% and 86% timing side-channel capacity reduction for two benchmarks with an acceptable performance overhead compared to existing solutions. In addition, the proposed method incurs only a negligible hardware area overhead of 1% slices of the entire RISC-V system. Thinh Hung Pham, Alexander Fell, Arnab Kumar Biswas, Siew-Kei Lam, Nandeesha Veeranna |
FPL | 3 |
| 2018 | Efficient Timing Channel Protection for Hybrid (Packet/Circuit-Switched) Network-on-ChipabstractContinuous development of Network-on-Chip (NoC) enables different types of applications to run efficiently in a Multiprocessor System-on-Chip (MP-SoC). Guaranteed service (GS) can be provided by circuit switching NoC and Best effort service (BES) can be provided by packet switching NoC. A hybrid NoC containing both packet and circuit switching, can provide both types of services to these different applications. But these different applications can be of different security levels and one application can interfere another application's timing characteristics during network transmission. Using this interference, a malicious application can extract secret information from higher security level flows (timing side channel) or two applications can communicate covertly violating the system's security policy (covert timing channel). We propose different mechanisms to protect hybrid routers from timing channel attacks. For design space exploration, we propose three timing channel secure hybrid routers viz. Separate Hybrid (SH), Combined with Separate interface Hybrid (CSH), and Combined Hybrid (CH) routers. Simulation results show that all three routers are secure from timing channel when compared to a conventional hybrid router. Synthesis results show that the area increments compared to a conventional hybrid router are only 7.63, 11.8, and 19.69 percent for SH, CSH, and CH routers respectively. Thus simulation and synthesis results prove the effectiveness of our proposed mechanisms with acceptable area overheads. Arnab Kumar Biswas |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2016 | Source Authentication Techniques for Network-on-Chip Router Configuration PacketsabstractIt is known that maliciously configured Network-on-Chip routers can enable an attacker to launch different attacks inside a Multiprocessor System-on-Chip. A source authentication mechanism for router configuration packets can prevent such vulnerability. This ensures that a router is configured by the configuration packets sent only by a trusted configuration source. Conventional method like Secure Hash Algorithm-3 (SHA-3) can provide required source authentication in a router but with a router area overhead of 1355.25% compared to a normal router area. We propose eight source authentication mechanisms that can achieve similar level of security as SHA-3 for a router configuration perspective without causing significant area and power increase. Moreover, the processing time of our proposed techniques is 1/100th of SHA-3 implementation. Most of our proposed techniques use different timing channel watermarking methods to transfer source authentication data to the receiver router. We also propose the Individual packet-based stream authentication technique and combinations of this technique with timing channel watermarking techniques. It is shown that, among all of our proposed techniques, maximum router area increment required is 28.32% compared to a normal router. Arnab Kumar Biswas |
ACM J. Emerg. Technol. Comput. Syst. | 1 |