EDBT 2026 Demo / reviewers in the wild / expert
Anand Agrawal
dblp:178/3655
· DBLP profile ↗
9ranked-venue papers
7as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 6 first-author · 5 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TinyAP: An Intelligent Access Point to Combat Wi-Fi Attacks Using TinyMLabstractIn the recent past, there has been a significant surge in MAC layer Wi-Fi attacks, leaving wireless local area networks (WLANs) vulnerable to different types of network intrusions. The current routers cum access point (AP) lack the necessary intelligence to prevent or combat these attacks, thereby making it imperative to rely on various network intrusion detection systems. To address this issue, we have developed an intelligent AP that can identify different MAC layer attacks and generate alerts as required. This has been achieved using lightweight machine learning (ML) models on a microcontroller, leveraging the TensorFlow-lite-micro (TFLite Micro) libraries. A framework called TinyAP has been developed, which uses the efficient neural architecture search (NAS) and the lightweight to classify Wi-FI attack at the AP level. The system consists of a Raspberry Pi 3 B+, functioning as an AP and an Arduino Nano 33 BLE Sense acting as a plugin. The Nano module executes pretrained Tiny ML (TinyML) models, where the models are prepared (i.e., searched, trained and converted) on a Desktop PC (DESKTOP-47M82UC). We employed NAS for multilevel perceptrons (MLPNAS) to generate the five best neural architecture models to deploy on the system. To test the efficacy of this innovative approach, an online data set containing 13 different Wi-Fi-labeled attacks has been used. TinyAP has achieved an average accuracy of 96.45% for all the Wi-Fi attacks and a maximum accuracy of 100% in the 2 Class (2C) classification for some of the Wi-Fi attacks like key reinstallation attack and Kr00k. Additionally, TinyAP has also shown a maximum accuracy of 95.19% in multiclass classification. The average accuracy of TinyAP shows a marginal reduction of 0.76% in 2C classification and 0.04% in multiclass classification when compared with multilayer perceptron (MLP) models. The promising result of the TinyAP is that it provides a much-needed layer of protection for networks and offers a proactive security solution at the AP level. Anand Agrawal, Rajib Ranjan Maiti |
IEEE Internet Things J. | 1 |
| 2024 | POSTER: iTieProbe: Is IoT Device Provisioning secure against MAC Layer authentication-token based replay attacks?abstractIoT device provisioning is the process of setting up headless IoT devices with their companion mobile apps. IoT vendors and manufacturers have the flexibility of different provisioning methods, one of them being the Access Point (AP) pairing mode over Wi-Fi, and hence, they can derive existing Wi-Fi threats and add new ones. AP pairing mode provisioning shares critical information about the Wi-Fi router or sends an authentication token associated with the user's cloud account, which may lead to vulnerabilities. In this paper, we have designed and developed a vulnerability testing tool called "iTieProbe". iTieProbe captures the Wi-Fi traffic to check the provisioning of commercial IoT devices and has the capability to extract critical security parameters. Further, iTieprobe selectively crafts the captured Wi-Fi packets and replays them to test three different vulnerabilities (V1- V3): i) In V1- iTieprobe replays the Wi-Fi packets outside the lifetime of the authentication token without any manipulation, ii) In V2 - iTieprobe replays within the lifetime of the authentication token without any manipulation in the Wi-Fi packets, iii) In V3- iTieprobe meticulously crafts the selected UDP packets and then replays it within the lifetime of the authentication token. The effect of these vulnerabilities ranges from a simple denial of service by a legitimate user not being able to provision the IoT device to a more severe one, where an adversary can set up the IoT devices. We have evaluated the efficacy of iTieprobe against two commercial IoT devices, IoT Haat Smart Plug and Wipro Smart Plug, that are using Tuya-based implementations for their provisioning. We believe this work will help the vendors to improve their provisioning methods. Anand Agrawal, Rajib Ranjan Maiti |
AsiaCCS | 1 |
| 2024 | Guarding the Wi-Fi 4-Way Handshake against Channel-based MiTM: A Case Study on KRACK AttackabstractIn the rapidly evolving digital age, the security of wireless networks is paramount. In this paper, we present a comprehensive analysis and defense mechanism against Key Reinstallation Attacks (KRACKs) targeting the Wi-Fi Protected Access II (WPA2) protocol suite. WPA2 is vulnerable to KRACK, where an attacker replays a specific set of packets in the 4-way handshake used in WPA2 to install a Pairwise Transient Key (PTK) in both the client and Access Point (AP). We have proposed a scheme to add a channel feature in the packets that are exchanged in the 4-way handshake to guard against channel-based Man-in-The-Middle (MiTM), which is an essential pre-condition for KRACK. In particular, we propose to integrate message 1 (\emphmsg-1 ) and message 3 (\emphmsg-3 ) of handshake with the channel number that has been advertised in the beacon frames. In addition to the predefined parameters in the msg-1 and msg-3, the AP sends an authenticated channel number to the client. On receiving, the client first validates the authenticated channel number and then processes the other parameters in these two messages. This paper details the implementation and evaluation of our solution, demonstrating its effectiveness in thwarting KRACK without compromising network performance or user convenience. Anand Agrawal, Rajib Ranjan Maiti |
CODASPY | 1 |
| 2024 | iTieProbe: How Vulnerable Your IoT Provisioning via Wi-Fi AP Mode or EZ Mode?abstractIoT provisioning is a critical phase in IoT communication, where a number of security parameters are exchanged that are used both in this phase and later. Due to the headless nature of IoT devices, the exchange of these parameters faces challenges of balancing security and convenience. Some proprietary (e.g., “SmartConfig” by Texas Instruments) and open de-facto standards (e.g., AP mode and EZ mode by Tuya Inc.) are proposed to address these challenges, leaving scopes for certain vendor-specific settings. The analysis of vulnerability and threats thereby is a challenging task due to the lack of a common model of IoT provisioning in commercial IoT devices over Wi-Fi AP mode and EZ mode. In this paper, we propose a model using a sequence diagram for such provisioning and fuse seven research questions (RQs) to discover vendor-agnostic vulnerabilities. We develop a system, called iTieProbe to resolve the RQs. We discover six non-trivial potential vulnerabilities, identified as$\mathcal {V}1$to$\mathcal {V}6$. We evaluate the efficacy of testing these six vulnerabilities using iTieProbe by applying it to nine commercial IoT devices that include seven types, like a smart plug, IoT doorbell, spy bulb, smart speaker, spy clock, smart camera, and air quality monitor. We show that using iTieProbe, among others, an attacker can find$\mathcal {V}1$- leads to access neighbor’s Wi-Fi AP - in five devices,$\mathcal {V}3$and$\mathcal {V}4$in three devices, and$\mathcal {V}5$and$\mathcal {V}6$- both lead to successful provisioning using either an expired authentication token or a valid token belonging to an attacker - in three devices. We have reported all these vulnerabilities to respective vendors via email and received acknowledgment from some of them with three registered vulnerability (CVE-2024-7408, CVE-2024-46040, CVE-2024-46041). The average runtime of iTieProbe to test a vulnerability of any individual IoT provisioning is about 48.95 seconds, which is much less than the provisioning itself (typically in the range of a few minutes). We believe that our revelation can help the vendors or the developers of these IoT devices to fix the security vulnerabilities in their implementations of the provisioning. Anand Agrawal, Rajib Ranjan Maiti |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | CheckShake: Passively Detecting Anomaly in Wi-Fi Security Handshake Using Gradient Boosting Based Ensemble LearningabstractRecently, a number of attacks have been demonstrated (like key reinstallation attack, called KRACK) on WPA2 protocol suite in Wi-Fi WLAN, for which a patching is often challenging. In this article, we design and implement a system, called CheckShake, to passively detect anomalies in the handshake of Wi-Fi security protocols, in particular WPA2, between a client and an AP using COTS radios. Our proposed system works without decrypting any traffic and sniffing on multiple channels in parallel. It uses a state machine model for grouping Wi-Fi handshake packets and then perform deep packet inspection to identify the symptoms of the anomaly in specific stages of a handshake session. Our implementation of CheckShake does not require any modification to the firmware of the client or the AP or the COTS devices, it only requires to be physically placed within the range of the AP and its clients. We use both the publicly available dataset and our own data set for performance analysis of CheckShake. Using gradient boosting-based supervised machine learning (ML) models, we show that an accuracy around 98.50% with no false positive can be achieved using CheckShake in open sourced data that has non-zero probability of missing packets per group of packets. Anand Agrawal, Urbi Chatterjee, Rajib Ranjan Maiti |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | kTRACKER: Passively Tracking KRACK using ML ModelabstractRecently, a number of attacks have been demonstrated (like key reinstallation attack, called KRACK) on WPA2 protocol suite in Wi-Fi WLAN. In this paper, we design and implement a system, called kTRACKER, to passively detect anomalies in the handshake of Wi-Fi security protocols, in particular WPA2, between a client and an access point using COTS radios. A state machine model is implemented to detect KRACK attack by passively monitoring multiple wireless channels. In particular, we perform deep packet inspection and develop a grouping algorithm to group Wi-Fi handshake packets to identify the symptoms of the KRACK in specific stages of a handshake session. Our implementation of kTRACKER does not require any modification to the firmware of the supplicant i.e., client or the authenticator i.e., access point or the COTS devices, our system just needs to be in the accessible range from clients and access points. We use a publicly available dataset for performance analysis of kTRACKER. We employ gradient boosting-based supervised machine learning models, and show that an accuracy around 93.39% and a false positive rate of 5.08% can be achieved using kTRACKER. Anand Agrawal, Urbi Chatterjee, Rajib Ranjan Maiti |
CODASPY | 1 |
| 2020 | Process skew: fingerprinting the process for anomaly detection in industrial control systemsabstractIn an Industrial Control System (ICS), its complex network of sensors, actuators and controllers have raised security concerns. In this paper, we proposed a technique called Process Skew that uses the small deviations in the ICS process (herein called as a process fingerprint) for anomaly detection. The process fingerprint appears as noise in sensor measurements due to the process fluctuations. Such a fingerprint is unique to a process due to the intrinsic operational constraints of the physical process. We validated the proposed scheme using the data from a real-world water treatment testbed. Our results show that we can effectively identify a process based on its fingerprint, and detect process anomaly with a very low false-positive rate. Chuadhry Mujeeb Ahmed, Jay Prakash, Rizwan Qadeer, Anand Agrawal, Jianying Zhou 0001 |
WISEC | 4 |
| 2018 | Poster: Physics-Based Attack Detection for an Insider Threat Model in a Cyber-Physical SystemabstractTo ensure the proper functioning of critical systems, it is important to design secure Cyber Physical Systems (CPS). Since CPS are connected systems, most studies consider external adversaries as a threat model, which might not be able to cater for an insider threat with the physical access to the system. In this article, we proposed an attack detection mechanism for an insider who has physical access to a CPS. The proposed method exploits the dynamics of the system and detects an attack based on the laws of Physics. Based on the mass flow equations, we analyze the rate of change in the plant's process and create a feature vector based on the process dynamics. The model has been trained by passing rate of change in system's state as input to Support Vector Machine (SVM), to detect the abnormal behavior in the system. Based on the proposed framework, experiments are performed on a real water treatment testbed, to validate our model and to measure the efficiency of the plant in normal and under attack scenarios. The detection result shows that proposed scheme can detect attacks with accuracy as high as $96%$. Anand Agrawal, Chuadhry Mujeeb Ahmed, Ee-Chien Chang |
AsiaCCS | 1 |
| 2006 | Semantic mediacasting and collaborative feed sharing
Narendra Kumar Shukla, Anand Agrawal |
Dublin Core Conference | 2 |