EDBT 2026 Demo / reviewers in the wild / expert
Rijoy Mukherjee
dblp:175/0573
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0002-8432-3418ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Security Vulnerabilities in AI Hardware: Threats and CountermeasuresabstractThe advancement of artificial intelligence (AI) has led to its application to a broad spectrum of complex problems associated with everyday life. AI is extensively deployed in many daily applications through dedicated hardware accelerators, in several safety-critical security-sensitive systems, e.g. self-driving cars, smart home devices, health monitoring apps, bio-metric access control, public surveillance systems, etc. However, several recent studies have demonstrated that these hardware-centric AI applications are susceptible to diverse attacks, with great potential to cause harm. To mitigate such threats, many works have focused on developing effective countermeasures for different attack scenarios, to design robust AI-based system. This paper surveys different potent and imaginative attacks on AI hardware, and countermeasures to mitigate them. We analyse various threat models, and provide a detailed discussion of the challenges of attacks and the efficacy of various countermeasures. We also point to future directions of research. Rijoy Mukherjee, Sneha Swaroopa, Rajat Subhra Chakraborty |
ATS | 1 |
| 2024 | HLS-IRT: Hardware Trojan Insertion through Modification of Intermediate Representation During High-Level SynthesisabstractModern integrated circuit (IC) design incorporates the usage of proprietary computer-aided design (CAD) software and integration of third-party hardware intellectual property (IP) cores. Subsequently, the fabrication process for the design takes place in untrustworthy offshore foundries that raises concerns regarding security and reliability. Hardware Trojans (HTs) are difficult to detect malicious modifications to IC that constitute a major threat, which if undetected prior to deployment, can lead to catastrophic functional failures or the unauthorized leakage of confidential information. Apart from the risks posed by rogue human agents, recent studies have shown that high-level synthesis (HLS) CAD software can serve as a potent attack vector for inserting HTs. In this article, we introduce a novel automated attack vector, which we term “HLS-IRT”, by inserting HT in the register transfer logic (RTL) description of circuits generated during an HLS based IC design flow, by directly modifying the compiler-generated intermediate representation (IR) corresponding to the design. We demonstrate the attack using a design and implementation flow based on the open-source Bambu HLS software and Xilinx FPGA, on several hardware accelerators spanning different application domains. Our results show that the resulting HTs are surreptitious and effective, while incurring minimal design overhead. We also propose a novel detection scheme for HLS-IRT, since existing techniques are found to be inadequate to detect the proposed HTs. Rijoy Mukherjee, Archisman Ghosh 0001, Rajat Subhra Chakraborty |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2023 | Attacks on Recent DNN IP Protection Techniques and Their MitigationabstractWith the rapid increase in the development of deep learning methodologies, deep neural networks (DNNs) are now being commonly deployed in smart systems (e.g., autonomous vehicles) and high-end security applications (e.g., face recognition, biometric authentication, etc.). The training of such DNN models often requires exclusive valuable training datasets, enormous computational resources, and expert fine-tuning skills. Hence, a trained DNN model can be regarded as valuable proprietary intellectual property (IP). Piracy of such DNN IPs has emerged as a major concern, with increasing trends of illegal copying and redistribution. A number of mitigation approaches targeting DNN IP protection have been proposed in recent years. In this work, we target two recently proposed DNN IP protection schemes: 1) chaotic map theory-based encryption of the weight parameters and 2) traditional block cipher-based encryption of the weights. We demonstrate attacks on two recent DNN IP protection techniques, with one technique each belonging to the above-mentioned schemes, under a pragmatic attack model. We also propose a novel DNN IP protection technique based on selective encryption of the weight parameters, termed limited encryption of weights for IP protection (LEWIP) to mitigate the exposed weaknesses, while having low implementation and performance overheads. Finally, we demonstrate the effectiveness of the LEWIP technique against state-of-the-art DNN implementations. Rijoy Mukherjee, Rajat Subhra Chakraborty |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | APUF-BNN: An Automated Framework for Efficient Combinational Logic Based Implementation of Arbiter PUF through Binarized Neural NetworkabstractAnalysis of Physically Unclocnable Functions (PUFs) from a Boolean function perspective, and the efficient hardware implementation of such Boolean representations, can potentially lead to interesting insights about their behavior and robustness. Such a circuit implementation can also be a convenient substitute for the machine learning model of a PUF instance in PUF-based security protocols. In this paper, we present APUF-BN, a novel computer-aided design (CAD) framework to efficiently generate a combinational circuit representation of an Arbiter PUF (APUF) instance, which accurately mimics its input-output behavior. This representation is derived from an optimized fully-connected Binarized Neural Network (BNN) model of the APUF. Our fully-automated CAD framework takes challenge-response pairs (CRPs) of an APUF instance as input, and generates Verilog description corresponding to the optimized combinational circuit representation as output. The optimized Boolean logic representation achieves more than 24% reduction in area overhead compared to the unoptimized BNN representation, while achieving close to 98% modeling accuracy. We also validate the derived combinational circuit representation on Xilinx Artix-7 FPGA platform. Pranesh Santikellur, Rijoy Mukherjee, Rajat Subhra Chakraborty |
ACM Great Lakes Symposium on VLSI | 2 |