EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Nasim Imtiaz Khan
dblp:182/2241
· DBLP profile ↗
20ranked-venue papers
11as first author
3since 2021 · last 2022
0000-0002-4531-5191ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 19 · 10 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Analysis of Power-Oriented Fault Injection Attacks on Spiking Neural NetworksabstractSpiking Neural Networks (SNN) are quickly gaining traction as a viable alternative to Deep Neural Networks (DNN). In comparison to DNNs, SNNs are more computationally powerful and provide superior en-ergy efficiency. SNNs, while exciting at first appearance, contain security-sensitive assets (e.g., neuron threshold voltage) and vulnerabilities (e.g., sensitivity of classification accuracy to neuron threshold voltage change) that adversaries can exploit. We investigate global fault injection attacks by employing external power supplies and laser-induced local power glitches to corrupt crucial training parameters such as spike amplitude and neuron's membrane threshold potential on SNNs developed using common analog neurons. We also evaluate the impact of power-based attacks on individual SNN layers for 0% (i.e., no attack) to 100% (i.e., whole layer under attack). We investigate the impact of the attacks on digit classification tasks and find that in the worst-case scenario, classification accuracy is reduced by 85.65%. We also propose defenses e.g., a robust current driver design that is immune to power-oriented attacks, improved circuit sizing of neuron components to reduce/recover the adversarial accuracy degradation at the cost of negligible area and 25% power overhead. We also present a dummy neuron-based voltage fault injection detection system with ~ 1% power and area overhead. Karthikeyan Nagarajan, Junde Li, Sina Sayyah Ensan, Mohammad Nasim Imtiaz Khan, Sachhidh Kannan, Swaroop Ghosh |
DATE | 4 |
| 2021 | SCARE: Side Channel Attack on In-Memory Computing for Reverse EngineeringabstractIn-memory computing (IMC) architectures provide a much needed solution to energy-efficiency barriers posed by Von-Neumann computing. The functions implemented in such in-memory architectures are often proprietary and constitute confidential intellectual property (IP). Our studies indicate that IMC architectures implemented using resistive RAM (RRAM) are susceptible to side channel attack (SCA). Unlike the conventional SCAs that are aimed to leak private keys from cryptographic implementations, SCA on IMC for reverse engineering (SCARE) can reveal the sensitive IP implemented within the memory through power/timing side channels. Therefore, the adversary does not need to perform invasive reverse engineering (RE) to unlock the functionality. We demonstrate SCARE by taking recent IMC architectures, such as dynamic computing in memory (DCIM) and memristor-aided logic (MAGIC) as test cases. Simulation results indicate that AND, OR, and NOR gates (which are the building blocks of complex functions) yield distinct power and timing signatures based on the number of inputs, making them vulnerable to SCA. We show that adversary can use templates (using foundry-calibrated simulations or fabricating known functions in test chips) and analysis to identify the structure of the implemented function by testing a limited number of patterns. We also propose countermeasures, such as redundant inputs and expansion of literals. Redundant inputs can mask the IP with 25% area and 20% power overhead. However, functions can be found at higher RE effort. Expansion of literals incurs 36% power overhead. However, it imposes a brute force search increasing the adversarial RE effort by$3.04\times $. Sina Sayyah Ensan, Karthikeyan Nagarajan, Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2021 | SecNVM: Power Side-Channel Elimination Using On-Chip Capacitors for Highly Secure Emerging NVMabstractEmerging nonvolatile memories (NVMs), such as resistive RAM (RRAM) and spin-transfer-torque RAM (STTRAM), present exciting opportunities for data storage applications and offer improved access speeds, retention times, power consumption, and scalability. However, these technologies leak the Hamming weight of data through power side-channel during read and write operations. We propose a technique leveraging on-chip capacitor and voltage regulator (VR) that powers the NVM read/write operations. The side-channel leakage is eliminated due to the isolation of memory array from the external power supply during read/write operations. The residual charge on capacitor bank is discarded safely to prevent information leakage during capacitor recharging. The VR ensures a steady voltage during the entire read/write operations even though the capacitor discharges. The design presents a performance (instructions per cycle) degradation of 0.53%-1.2% under parsec and splash-2 benchmarks and incurs an area overhead of ~ 3.54×10-5% and an energy overhead of ~ 3.05 ×10-5% for a 4-Mb RRAM memory array. For a 64-bit word, the design improves security by 2.7 × 1019× to 264×. SecNVM should be used in small security-critical memory macros to limit the overhead. SecNVM is generic and could protect any security module such as encryption engines, against power side-channel attacks. Karthikeyan Nagarajan, Farid Uddin Ahmed, Mohammad Nasim Imtiaz Khan, Asmit De, Masud H. Chowdhury, Swaroop Ghosh |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2020 | Power Side Channel Attack Analysis and DetectionabstractSide Channel Attack (SCA) is a serious threat to the hardware implementation of cryptographic protocols. Various side channels such as, power, timing, electromagnetic emission and acoustic noise have been explored to extract the secret keys. Machine Learning (ML)-based detection of SCA have been proposed in past which incur high design overheads and, require digitization that reduce their accuracy under process variations. We propose a real-time power SCA detection technique using on-chip sensors based on a thorough analysis. The dependency of phase/frequency of Ring Oscillator (RO) on supply voltage is exploited to detect the insertion of a SCA resistance in the power rail. The proposed approach is validated using simulation with a detailed model of Power Delivery Network (PDN) and power grid. The technique can detect a minimum resistance of 1 Ω within 2 μs of attack initiation and incurs a tiny fraction of area/power (0.044%/0.1065%, respectively) compared to ML-based techniques. Navyata Gattu, Mohammad Nasim Imtiaz Khan, Asmit De, Swaroop Ghosh |
ICCAD | 2 |
| 2020 | Assuring Security and Reliability of Emerging Non-Volatile MemoriesabstractAt the end of Silicon roadmap, keeping the leakage power in tolerable limit has become one of the biggest challenges. Several promising Non-Volatile Memories (NVMs) offering high-density, high speed, and competitive reliability/endurance while eliminating leakage issues are being investigated. On one hand, the above-desired properties make emerging NVM suitable candidates to assist or replace conventional memories in memory hierarchy as well as to infuse compute capability to eliminate Von-Neumann bottleneck. On the other hand, their unique features such as high and asymmetric read/write current and persistence bring new threats to data security while compute-capability imposes new fundamentally different security challenges. Some of these memories are already deployed in full systems and as discrete chips. Therefore, it is utmost important to investigate the security issues of NVMs spanning the application space. This work makes pioneering contributions to this challenge through a holistic approach- from devices to circuits and systems using a combination of design and test methodologies to develop secure and resilient NVMs. The proposed attacks and countermeasures are validated on test boards using commercial NVM chips. Finally, this research has been tied to education by converting the test boards to design a modular and reproducible self-learning cybersecurity kit which has been piloted to train graduate and undergraduate students and K-12 teachers. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
ITC | 1 |
| 2020 | Test Methodologies and Test-Time Compression for Emerging Non-Volatile MemoryabstractEmerging nonvolatile memories (NVMs) are considered as suitable candidates to replace conventional memories such as static RAM (SRAM) and dynamic RAM (DRAM) due to high density, high performance, and low (static) power operation. However, NVMs bring new fault issues and call for new tests. For example, NVMs exhibit wide read and write latency distribution, incur high write current (leads to high supply noise), are susceptible to external magnetic/thermal field, show high and stochastic retention time, and are prone to endurance and reliability failures. The conventional tests either cannot capture the faults specific to emerging NVMs or they incur significant test time if implemented on emerging NVMs. In this article, we summarize fault models specific to NVMs and explain the related test issues and challenges. We also propose new tests along with necessary design-for-test techniques to characterize the failures. We further summarize NVM tests proposed in prior works and analyze their test time requirements. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
IEEE Trans. Reliab. | 1 |
| 2020 | HarTBleed: Using Hardware Trojans for Data Leakage ExploitsabstractData and information leakage is an important security concern in current systems. Several data leakage prevention (DLP) techniques have been proposed in the literature to prevent external as well as internal data leakage. Most of these solutions try to trace data flow and perform privilege checks to ensure the security of the data at the software and system level. Architecture level leakage vulnerabilities such as Spectre and Meltdown can be mitigated by performance-expensive software patches or by modifying the architecture itself. However, these solutions assume that the underlying hardware platform is secure and free from tampering. In this article, we present HarTBleed, a class of system attacks involving hardware compromised with a Trojan embedded in the CPU. We show that attacks crafted specifically to make use of the Trojan can be used to obtain sensitive information from the address space of a process. We propose the use of a capacitor-based Trojan trigger that exploits the virtual addressing of L1 cache to activate a Trojan payload that resets a target translation lookaside buffer (TLB) entry to maliciously map to sensitive data in memory. Extensive circuit simulation indicates that the proposed Trojan trigger is not activated during test or normal operation even under a wide range of process/temperature conditions. Therefore, it remains undetected. A successful HarTBleed-based exploit is demonstrated using an attack code by modeling the Trojan effects in the GEM5 simulator. Asmit De, Mohammad Nasim Imtiaz Khan, Karthikeyan Nagarajan, Swaroop Ghosh |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2020 | Cache-Out: Leaking Cache Memory Using Hardware TrojanabstractData leakage is an important security concern in current systems. Existing data leakage prevention techniques assume that the underlying hardware platform is secure and free from tampering. In this work, we present Cache-Out, a class of system attacks involving hardware compromised with a Trojan embedded in the CPU. We assume that a memory Trojan trigger is present in L1 d-cache and gets activated if one particular address of L1 d-cache is hammered with a particular data pattern for a certain number of times. Once the Trojan is triggered, accessing another address delivers payloads, such as, read disturb, write disturb, retention failure, and information leakage. We mainly exploit the advanced circuit features employed in the peripherals of nanometer cache memories, such as wordline underdrive (WLUD) (prevents read disturb) and negative bitline (NBL) (assists write) for static RAM (SRAM) to deliver the payloads. Simulation indicates that WLUD and NBL manipulation can inject read and write failures, respectively. We also show that WLUD activation during write operation can inject write failure. Furthermore, NBL along with column multiplexing can also be leveraged to steal data. We validated Cache-Out using GEM5 architectural simulator. We propose L1 address obfuscation, read/write verification, scrambling error correcting code (ECC) bits, and trusted ECC as countermeasures. Results indicate that read/write verification incurs 7.56 μm2of area and 0.1 μW/91.3 μW of static/dynamic power in 22-nm technology for a 64-bit word size. Mohammad Nasim Imtiaz Khan, Asmit De, Swaroop Ghosh |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2019 | Hardware Trojans in Emerging Non-Volatile MemoriesabstractEmerging Non-Volatile Memories (NVMs) possess unique characteristics that make them a top target for deploying Hardware Trojan. In this paper, we investigate such knobs that can be targeted by the Trojans to cause read/write failure. For example, NVM read operation depends on clamp voltage which the adversary can manipulate. Adversary can also use ground bounce generated in NVM write operation to hamper another parallel read/write operation. We have designed a Trojan that can be activated and deactivated by writing a specific data pattern to a particular address. Once activated, the Trojan can couple two predetermined addresses and data written to one address (victim's address space) will get copied to another address (adversary's address space). This will leak sensitive information e.g., encryption keys. Adversary can also create read/write failure to predetermined locations (fault injection). Simulation results indicate that the Trojan can be activated by writing a specific data pattern to a specific address for 1956 times. Once activated, the attack duration can be as low as 52.4μs and as high as 1.1ms (with reset-enable trigger). We also show that the proposed Trojan can scale down the clamp voltage by 400mV from optimum value which is sufficient to inject specific data-polarity read error. We also propose techniques to inject noise in the ground/power rail to cause read/write failure. Mohammad Nasim Imtiaz Khan, Karthikeyan Nagarajan, Swaroop Ghosh |
DATE | 1 |
| 2019 | Meeting the Conflicting Goals of Low-Power and Resiliency Using Emerging Memories : (Invited Paper)abstractEmerging non-volatile memory (NVM) technologies are being aggressively explored to replace and/or assist conventional CMOS technology. Although NVMs can cut down leakage power, achieve low footprint and allow compute capability along with storage, they suffer from new sources of variability. We review the noise sources associated with NVMs and describe resilience enhancement techniques for both memory and computing. We also present security applications where noise and variability is desirable. Karthikeyan Nagarajan, Mohammad Nasim Imtiaz Khan, Sina Sayyah Ensan, Abdullah Ash-Saki, Swaroop Ghosh |
IOLTS | 2 |
| 2019 | SHINE: A Novel SHA-3 Implementation Using ReRAM-based In-Memory ComputingabstractIn memory-computing (IMC) architectures provide a much needed solution to energy-efficiency barriers posed by Von-Neumann computing due to movement of data between the processor and the memory. Emerging non-volatile memories (NVM) such as Resistive RAM (ReRAM) implemented in a crossbar array are promising substrates to realize IMC due to excellent High Resistance State (HRS) to Low Resistance State (LRS) ratios and high-densities. Hardware security primitives such as SHA-3 require heavy data traffic between processing elements and memory. Therefore, they can be benefited substantially by in-memory acceleration. We propose SHINE, a high performance and area efficient hardware implementation of the Keccak function that forms the core of SHA-3 by exploiting ReRAM-based IMC. SHINE implements various functions in a Sum of Product (SOP) form in the crossbar array architecture. Simulation results show that it cuts down energy by ~90.5% and increases throughput by 1.5X to 2.8X as compared to conventional CMOS based implementations such as [1] and [2]. Karthikeyan Nagarajan, Sina Sayyah Ensan, Mohammad Nasim Imtiaz Khan, Swaroop Ghosh, Anupam Chattopadhyay |
ISLPED | 3 |
| 2018 | Novel application of spintronics in computing, sensing, storage and cybersecurityabstractWith conventional Von Neumann computing struggling to match the energy-efficiency of biological systems, there is pressing need to explore alternative computing models. CMOS switches, although universal, fails to offer additional features to meet this end goal Recent experimental studies have revealed that spintronics possess many promising features that can not only enable non Von Neumann compute models but also high-density storage, sensing of environmental parameters and protection from cybersecurity threats. This paper provides an in-depth study of spintronics and its relation to these novel aspects from device, circuit and system standpoint. Seyedhamidreza Motaman, Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
DATE | 2 |
| 2018 | Analysis of Row Hammer Attack on STTRAMabstractIn this paper, we model and investigate the impact of Row Hammering (RH) on Spin-Transfer Torque RAM (STTRAM) by exploiting its write operation. STTRAM suffers from high write current and long write latency which can result in ground bounce. The magnitude of the bounce depends on the old data and the new data that is being written. The bounce can propagate to the nearest word-line drivers and partially turn ON the access transistors making weak current flow through the memory bitcells and reducing their thermal energy barrier. Therefore, continuous write at a particular location can force the massive number of unselected bits to suffer from degraded thermal barrier due to weak RH current. Reduced thermal barrier may lead to retention failures and make the bits sensitive to stray magnetic field/thermal noise. Those bits can also suffer from read disturb if they are read. These issues could be even worse for Short Retention NVM (SRNVM) which is suitable for Last Level Cache (LLC) and has a base retention of only few seconds. The ground bounce can also propagate to bitline/ source-line drivers and the selected cells will experience lower headroom voltage. This will lead to read failure (due to degraded sense margin) and write failure (due to increased write latency). Simulation result indicates that RH attack can flip the bits in just 30.84secs for STTRAM with base retention of 1 min. In presence of elevated temperature, the retention time can be further reduced to 2.46secs and 0.19secs for T=50C and T=75C respectively. RH attack can increase read disturb by 2.09X for bitcell with 1min base retention at T=25C. Simulation result also indicates that RH attack can cause read/write failure if the bitcell being read/written experience 306mV (for data 0)/110mV (for writing 0 –> 1) of bounce. To the best of our knowledge, this is the first RH attack study for STTRAM-based cache. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
ICCD | 1 |
| 2018 | Information Leakage Attacks on Emerging Non-Volatile Memory and CountermeasuresabstractEmerging Non-Volatile Memories (NVMs) suffer from high and asymmetric read/write current and long write latency which can result in supply noise, such as supply voltage droop and ground bounce. The magnitude of supply noise depends on the old data and the new data that is being written (for a write operation) or on the stored data (for a read operation). Therefore, victim's write operation creates a supply noise which propagates to adversary's memory space. The adversary can detect victim's write initiation and can leverage faster read latency (compared to write) to further sense the Hamming Weight (HW) of the victim's write data by detecting read failures in his memory space. These attacks are specifically possible if exhaustive testing of the memory for all patterns, all possible location combinations, all possible parallel read/write conditions are not performed under bit-to-bit process variations and specified (-10°C to 90°C) and unspecified temperature ranges (i.e., less than -10°C and greater than 90°C). Simulation result indicates that adversary can sense HW of victim's (near-by) write data = 66.77%, and further narrow the range based on read/write failure characteristics. Side Channel Attacks can utilize this information to strengthen the attacks. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
ISLPED | 1 |
| 2018 | Test of Supply Noise for Emerging Non-Volatile MemoryabstractEmerging Non-Volatile Memories (NVMs) suffer from high read/write current which can result in supply noise such as voltage droop and ground bounce. The magnitude of supply noise depends on the old data and the new data that is being written (for a write operation) or the stored data (for a read operation). In prior work, it has been shown that the noise generated by one access can affect another parallel access. Therefore, parallel read/write operation should be tested considering the supply noise. However, testing for read/write failure with supply noise considerations can take significant test time. In this work, we show that test time can be reduced by 410.82X for RRAM-based NVM Last Level Cache (LLC) by using Design for Test (DFT) circuits such as wordline overdrive and ending write operation early. We also show that the proposed test can save 79.875J of energy compared to the baseline test method. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
ITC | 1 |
| 2018 | Test challenges and solutions for emerging non-volatile memoriesabstractAt the end of Silicon roadmap, keeping the leakage power in tolerable limit has become one of the biggest challenges. Several promising non-volatile memories (NVMs) are being investigated by the scientific community to address the issue. Some of the NVMs such as Spin-Transfer Torque RAM, Magnetic RAM, Resistive RAM, Phase Change Memory and Ferroelectric RAM have already entered the mainstream computing. However, the unique characteristics of these NVMs bring new fault models such as statistical and stochastic retention failures, magnetic and thermal tolerance failures, voltage droop and ground bounce induced read and write failures and long latency failures. In this work, we summarize new test failure mechanisms in NVMs and associated test challenges. We also propose new test methodologies, test patterns and Design-for-Test (DFT) techniques to characterize new failure models and compress test time. Mohammad Nasim Imtiaz Khan, Swaroop Ghosh |
VTS | 1 |
| 2018 | Novel Magnetic Burn-In for Retention and Magnetic Tolerance Testing of STTRAM
Mohammad Nasim Imtiaz Khan, Anirudh Iyengar, Swaroop Ghosh |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2017 | Novel magnetic burn-in for retention testing of STTRAMabstractSpin-Transfer Torque RAM (STTRAM) is an emerging Non-Volatile Memory (NVM) technology that has drawn significant attention due to complete elimination of bitcell leakage. However, it brings new challenges in characterizing the retention time of the array during test. Significant shift of retention time under static (process variation (PV)) and dynamic (voltage, temperature fluctuation) variability furthers this issue. In this paper, we propose a novel magnetic burn-in (MBI) test which can be implemented with minimal changes in the existing test flow to enable STTRAM retention testing at short test time. The magnetic burn-in is also combined with thermal burn-in (MBI−BI) for further compression of retention and test time. Simulation results indicate MBI with 220Oe (at 25C) can improve the test time by 3.71×1013X while MBI−BI with 220Oe at 125C can improve the test time by 1.97×1014X. Mohammad Nasim Imtiaz Khan, Anirudh Iyengar, Swaroop Ghosh |
DATE | 1 |
| 2017 | Side-Channel Attack on STTRAM Based Cache for Cryptographic ApplicationabstractIn this paper, we propose a Side Channel Attack (SCA) model on Spin-Torque Transfer RAM (STTRAM) where an adversary can monitor the supply current of the memory array consumed during read/write operations and recover the secret key of Advanced Encryption Standard (AES) execution. Simulation results indicate that by monitoring write current, 50% of keys could be extracted using 2000 traces. Further improvement of attacks on write operation is also proposed. The read current is found to be more susceptible to leak the key. It reveals first byte in only 40 traces and leaks the entire key in as low as 400 traces. The results are then compared with Static RAM (SRAM) based cache. The attack model has been experimentally validated on read operation of commercial MRAM chip (STTRAM variant). Experimental results indicate that the attack can reveal correct key in 15 traces compared to 40 in simulation due to less algorithmic noise. To the best of our knowledge, this is the first comprehensive SCA study for STTRAM based cache for cryptographic application. Mohammad Nasim Imtiaz Khan, Shivam Bhasin, Alex Yuan, Anupam Chattopadhyay, Swaroop Ghosh |
ICCD | 1 |
| 2016 | Security and privacy threats to on-chip non-volatile memories and countermeasuresabstractNon-volatile memories (NVMs) such as Spin-Transfer Torque RAM (STTRAM) have drawn significant attention due to complete elimination of bitcell leakage. In addition to the plethora of benefits such as density, non-volatility, low-power and high speed, majority of Non-Volatile Memories (NVMs) are also compatible with CMOS technology enabling easy integration. Although promising, NVM brings new security challenges that were absent in their conventional volatile memory counterparts such as Static RAM (SRAM) and embedded Dynamic RAM (eDRAM). The root cause is persistent data that may allow the adversary to retrieve sensitive information like password or cryptographic keys. This is primarily due to the fundamental dependency of these memory technologies on environmental parameters such as magnetic fields and temperature which can be exploited by the adversary to tamper with the stored data. This paper investigates the data security and privacy challenges in NVMs by exploring the security specific properties and novel security primitives realized using spintronic building blocks. A thorough analysis is done on the vulnerabilities, data security and privacy issues, threats and possible countermeasures to enable safe computing environment using spintronics. Swaroop Ghosh, Mohammad Nasim Imtiaz Khan, Asmit De, Jae-Won Jang |
ICCAD | 2 |