EDBT 2026 Demo / reviewers in the wild / expert
Ankit Gangwal
dblp:185/7073
· DBLP profile ↗
19ranked-venue papers
11as first author
12since 2021 · last 2026
0000-0002-8065-3700ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 first-author · 8 since 2021Computer networks · 4 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LORETTA: A Low Resource Framework to Poison Continuous Time Dynamic GraphsabstractTemporal Graph Neural Networks (TGNNs) are increasingly used in high-stakes domains, such as financial forecasting, recommendation systems, and fraud detection. However, their susceptibility to poisoning attacks poses a critical security risk. We introduce LoReTTA (Low Resource Two-phase Temporal Attack), a novel adversarial framework on Continuous-Time Dynamic Graphs, which degrades TGNN performance by an average of 29.47% across 4 widely benchmark datasets and 4 State-of-the-Art (SotA) models. LoReTTA operates through a two-stage approach: (1) sparsify the graph by removing high-impact edges using any of the 16 tested temporal importance metrics, (2) strategically replace removed edges with adversarial negatives via LoReTTA’s novel degree-preserving negative sampling algorithm. Our plug-and-play design eliminates the need for expensive surrogate models while adhering to realistic unnoticeability constraints. LoReTTA degrades performance by upto 42.0% on MOOC, 31.5% on Wikipedia, 28.8% on UCI, and 15.6% on Enron. LoReTTA outperforms 11 attack baselines, remains undetectable to 4 leading anomaly detection systems, and is robust to 4 SotA adversarial defense training methods, establishing its effectiveness, unnoticeability, and robustness. Himanshu Pal, Venkata Sai Pranav Bachina, Ankit Gangwal, Charu Sharma |
AAAI | 3 |
| 2025 | POSTER: Disappearing Ink: How Partial Model Extraction Erases Watermarks
Venkata Sai Pranav Bachina, Ankit Gangwal |
AsiaCCS | 2 |
| 2025 | POSTER: Investigating Transferability of Adversarial Examples in Model MergingabstractModel Merging (MM) has emerged as a promising approach to combine multiple fine-tuned models into a single model that maintains performance across tasks.However, its impact on (transferable) adversarial examples remains unexplored.Specifically, we investigate the affect of MM on the transferability of adversarial examples -a black-box, adversarial attack where adversarial examples generated for surrogate model successfully mislead target model.Preliminary experiments on image classification models suggest, similar to recent findings of MM on backdoor attacks, where MM tends to sanitize the backdoor present in individual fine-tuned models, MM may not boost adversarial transferability.Our results suggest MM having minimal affect, and under certain conditions, inhibiting affect on vulnerability to transferable adversarial examples.Consequently, our preliminary findings suggest MM potentially giving a "free lunch" of adversarial robustness and provides important insights for designing more secure systems that employ MM. Ankit Gangwal, Aaryan Ajay Sharma |
AsiaCCS | 1 |
| 2025 | KeTS: Kernel-Based Trust Segmentation Against Model Poisoning Attacks
Ankit Gangwal, Mauro Conti, Tommaso Pauselli |
ESORICS (1) | 1 |
| 2025 | CSUM-G: Group Software Updates for CubeSat ClustersabstractCubeSats have become a popular platform for low-cost space missions, supporting application ranging from Earth observation to space exploration. Despite their growing adoption, CubeSats face significant challenges in supporting in-orbit software updates with strong authentication and integrity guarantees due to severe constraints on computation, power, and communication bandwidth. Existing approaches either impose unsustainable overhead (e.g., public key cryptography) or focus solely on ground station-to-CubeSat delivery. In our prior work, we introduced CSUM, an efficient hash chain based protocol for broadcast authentication from ground stations. However, it does not address the dissemination of update within a CubeSat cluster, which limits scalability and increase transmission redundancy.In this paper, we propose an enhancement to the CSUM protocol by replacing its custom hash concatenation mechanism with a standardized HMAC construction to achieve stronger resistance against cryptographic attacks, with minimal trade-off in efficiency. Building on this enhancement, we introduce CSUM-G, an extension of CSUM that enables authenticated software update propagation across a CubeSat cluster using inter-satellite links and shared secret cluster keys. In our implementation, CSUM-G achieves 100% update success with only 0.13-0.20 average retries per update, and propagates updates in as little as 0.04 seconds for 6 CubeSats and 3.68 seconds for 600 nodes. Ankit Gangwal, Aashish Paliwal |
LCN | 1 |
| 2025 | SharHSC: A Sharding-Based Hybrid State Channel to Realize Blockchain Scalability and SecurityabstractAddressing blockchain's insufficient throughput and scalability is imperative for practical viability. Off-chain approaches, such as state channels (including Hash Time Lock Contract (HTLC), virtual channels), demonstrate enhanced throughput by enabling parallel transaction processing. While virtual channels introduce execution complexity, HTLC suffers from high update delays. Moreover, existing methods face network attacks. We present Sharding-based Hybrid State Channel (SharHSC) to address these issues. First, we introduce a novel off-chain sharding architecture, which partitions proxy nodes into multiple shards. Thus, when the off-chain node count increases, adding shards enhances system throughput. Second, each shard establishes a supervisory committee to record latest channel statuses to ensure accurate fund distribution upon channel closure. Third, we combine the strengths of HTLC and virtual channels. In particular, SharHSC constructs a single virtual channel across all the nodes involved in the payment by treating the nodes between payer and payee as an intermediate entity, which utilizes HTLC for fund routing. This realizes both low latency and streamlined complexity. Finally, our work is substantiated by security analysis and experiments. As the node number varies, compared with HTLC and virtual channels, the latency is reduced by 49.32% and 31.82%, and the throughput is increased by 8.93 and 1.89 times. Yizhong Liu, Dongyu Li, Chengqi Wu, Qianhong Wu, Ankit Gangwal, Prayag Tiwari, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | CSUM: A Novel Mechanism for Updating CubeSat while Preserving Authenticity and IntegrityabstractThe recent rise of CubeSat has revolutionized global space explorations, as it offers cost-effective solutions for low-orbit space applications (including climate monitoring, weather measurements, communications, and earth observation). A salient feature of CubeSat is that applications currently on-boarded can either be updated or entirely replaced by new applications via software updates, which allows reusing in-orbit hardware, reduces space debris, and saves cost as well as time. Securing software updates employing traditional methods (e.g., encryption) remains impractical mainly due to the low-resource capabilities of CubeSat. Therefore, the security of software updates for CubeSats remains a critical issue.In this paper, we propose CubeSat Update Mechanism (CSUM), a lightweight scheme to provide integrity, authentication, and data freshness guarantees for software update broadcasts to CubeSats using a hash chain. We empirically evaluate our proof of concept implementation to demonstrate the feasibility and effectiveness of our approach. CSUM can validate 50,000 consecutive updates successfully in less than a second. We also perform a comparative analysis of different cryptographic primitives. Our empirical evaluations show that the hash-based approach is at least 61× faster than the conventional mechanisms, even in resource-constrained environments. Ankit Gangwal, Aashish Paliwal |
LCN | 1 |
| 2023 | AutoSpill: Credential Leakage from Mobile Password ManagersabstractPassword managers (PMs) are becoming increasingly popular on mobile devices, especially on small-screen devices, mainly due to the convenience of automatically filling credentials into login forms. Modern mobile OSes advocate for system-wide autofill frameworks to support autofilling on browsers as well as other apps. Mobile OSes also empower apps to directly render web content within WebView controls without redirecting users to the main browser. \par We present a novel technique, called AutoSpill, to leak users' saved credentials during an autofill operation on a webpage loaded into an app's WebView. AutoSpill conveniently dodges the secure autofill process. The majority of popular Android PMs considered in our experiments were found vulnerable to AutoSpill; even when the app hosting the WebView is not actively participating in the leak. Android intermediates in the autofill process because of its app sandboxing. Hence, the responsibility for any credential leakage is often stranded between PMs and the Android system. We investigate the root causes of AutoSpill and propose countermeasures to fundamentally fix AutoSpill for both the parties. We responsibly disclosed our findings to the affected PMs and Android security team. Ankit Gangwal, Abhijeet Srivastava |
CODASPY | 1 |
| 2023 | A survey of Layer-two blockchain protocols
Ankit Gangwal, Haripriya Ravali Gangavalli, Apoorva Thirupathi |
J. Netw. Comput. Appl. | 1 |
| 2022 | Analyzing Price Deviations in DeFi Oracles
Ankit Gangwal, Rahul Valluri, Mauro Conti |
CANS | 1 |
| 2022 | BLEWhisperer: Exploiting BLE Advertisements for Data Exfiltration
Ankit Gangwal, Riccardo Spolaor, Abhijeet Srivastava |
ESORICS (1) | 1 |
| 2021 | Improving Password Guessing via Representation LearningabstractLearning useful representations from unstructured data is one of the core challenges, as well as a driving force, of modern data-driven approaches. Deep learning has demonstrated the broad advantages of learning and harnessing such representations.In this paper, we introduce a deep generative model representation learning approach for password guessing. We show that an abstract password representation naturally offers compelling and versatile properties that open new directions in the extensively studied, and yet presently active, password guessing field. These properties can establish novel password generation techniques that are neither feasible nor practical with the existing probabilistic and non-probabilistic approaches. Based on these properties, we introduce: (1) A general framework for conditional password guessing that can generate passwords with arbitrary biases; and (2) an Expectation Maximization-inspired framework that can dynamically adapt the estimated password distribution to match the distribution of the attacked password set. Dario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi, Mauro Conti |
SP | 2 |
| 2020 | Detecting Covert Cryptomining Using HPC
Ankit Gangwal, Samuele Giuliano Piazzetta, Gianluca Lain, Mauro Conti |
CANS | 1 |
| 2020 | Cryptomining Cannot Change Its Spots: Detecting Covert Cryptomining Using Magnetic Side-ChannelabstractWith new cryptocurrencies being frequently introduced to the market, the demand for cryptomining - a fundamental operation associated with most of the cryptocurrencies - has initiated a new stream of earning financial gains. The cost associated with the lucrative cryptomining has driven general masses to unethically mine cryptocurrencies using “plundered” resources in the public organizations (e.g., universities) as well as in the corporate sector that follows Bring Your Own Device (BYOD) culture. Such exploitation of the resources causes financial detriment to the affected organizations, which often discover the abuse when the damage has already been done. In this paper, we present a novel approach that leverages magnetic side-channel to detect covert cryptomining. Our proposed approach works even when the examiner does not have login-access or root-privileges on the suspect device. It merely requires the physical proximity of the examiner and a magnetic sensor, which is often available on smartphones. The fundamental idea of our approach is to profile the magnetic field emission of a processor for the set of available mining algorithms. We built a complete implementation of our system using advanced machine learning techniques. In our experiments, we included all the cryptocurrencies supported by the top-10 mining pools, which collectively comprise the largest share (84% during Q3 2018) of the cryptomining market. Moreover, we tested our methodology primarily on two different laptops. By using the data recorded from the magnetometer of an ordinary smartphone, our classifier achieved an average precision of over 88% and an average F1 score of 87%. Apart from our primary goal - which is to identify covert cryptomining - we also performed four additional experiments to further evaluate our approach. We found that due to its underlying design, our system is future-ready and can readily adapt even to zero-day cryptocurrencies. Ankit Gangwal, Mauro Conti |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | On the Exploitation of Online SMS Receiving Services to Forge ID VerificationabstractCommunication service providers (e.g., Whatsapp) enable users to connect with people around the world. These services have been widely adopted and used by millions of users, and such services have emerged as a replacement of the transitional calling and messaging. Unfortunately, these communication services have also been used to commit illegal activities and serious crimes. Therefore, service providers ask for user's phone/mobile number to verify the user's identity and to prevent misuses. Mohammad Hajian Berenjestanaki, Mauro Conti, Ankit Gangwal |
ARES | 3 |
| 2019 | Blockchain Trilemma Solver Algorand has Dilemma over Undecidable MessagesabstractA variety of solutions, e.g., Proof-of-Work (PoW), Proof-of-Stake (PoS), Proof-of-Burn (PoB), and Proof-of-Elapsed-Time (PoET), have been proposed to make consensus mechanism used by the blockchain technology more democratic, efficient, and scalable. However, these solutions have a number of limitations, e.g., PoW approach requires a huge amount of computational power, scales poorly, and wastes a lot of electrical energy. Recently, an innovative protocol called Algorand has been proposed to overcome these limitations. Algorand not only guarantees an overwhelming probability of linearity of the blockchain, but it also aims to solve the "blockchain trilemma" of decentralization, scalability, and security. Mauro Conti, Ankit Gangwal, Michele Todero |
ARES | 2 |
| 2018 | On the economic significance of ransomware campaigns: A Bitcoin transactions perspective
Mauro Conti, Ankit Gangwal, Sushmita Ruj |
Comput. Secur. | 2 |
| 2017 | A comprehensive and effective mechanism for DDoS detection in SDNabstractDDoS attack is one of the major concerns for network and cloud service providers, due to its substantial impact on revenue/cost and especially on their reputation. Also, network administrators are looking for solutions to manage voluminous data traffic. SDN is an emerging networking paradigm that provides a flexible network management. Hence, SDN is being widely adopted for wired, wireless, and mobile networks. Apart from a single point of failure (the controller), an attacker can target SDN at various levels by DDoS attacks. Existing solutions either focus on a particular attack type or require cumbersome alterations in SDN infrastructure. In this paper, we propose a comprehensive, yet effective and lightweight approach to detect various fundamentally different DDoS attacks in SDN. Our approach relies on sequential analysis. We employ a non-parametric change point detection technique called Cumulative Sum (CuSum). Our framework also includes an adaptive threshold scheme that adapts with the changing traffic pattern. Additionally, our framework can be tuned to suffice critical security requirements such as high detection rate and low false alarm rate. We evaluated the effectiveness of our solution using CAIDA Internet traces as well as DARPA intrusion detection evaluation dataset. Our results confirm the effectiveness of our mechanism. In particular, average false alarm rate in our experiments was under 11.64%. On average, our method is able to detect DDoS attacks within 4.15 seconds. Mauro Conti, Ankit Gangwal, Manoj Singh Gaur |
WiMob | 2 |
| 2016 | ELBA: Efficient Layer Based Routing Algorithm in SDNabstractAdaptive streaming dynamically adapts video quality level according to the perceived device status and network conditions. It requires several representations of the same content, each encoded at different quality rates. As a representative example, H.264/SVC eliminates the requirement of redundant representations, improving the efficiency of caching and storage infrastructure. SVC video consists of a "Base Layer" and one or more of "Enhancement Layers". These layers have inter-dependencies and different QoS requirements. On another side, SDN allows forwarding tables to be adjusted dynamically, enabling us to route every individual flow differently. In this paper, we propose ELBA, an algorithm for scalable video streaming over SDN. ELBA utilizes the dynamic re-routing capability of SDN, to stream different layers of SVC coded video over possibly different suitable paths. In the proposed video streaming system, we use a novel mechanism to exchange information between the control plane and streaming servers. We have compared the performance of our approach with traditional Internet routing technique. Our evaluation results show that our proposal is not only feasible but in particular, it significantly outperforms the traditional Internet routing approach in terms of QoE. Ankit Gangwal, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti |
ICCCN | 1 |