EDBT 2026 Demo / reviewers in the wild / expert
Smriti Bhatt
dblp:193/1480
· DBLP profile ↗
10ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0001-5376-4491ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FairVLM: Enhancing Fairness and Prompt Sensitivity in Vision Language Models for Medical Image SegmentationabstractVision-language models (VLMs) have demonstrated substantial promise in medical image segmentation by utilizing radiology reports as prompts to segment regions of interest. However, VLM deployment in clinical settings is challenged by two intertwined issues: i) demographic bias, where performance varies across demographic groups, and ii) prompt sensitivity, where semantically similar prompts yield inconsistent outputs. These challenges are interconnected; demographic underrepresentation can worsen a model’s sensitivity to prompts, and prompt instability can more heavily affect certain demographic groups. In this study, we present FairVLM, a unified framework that addresses both demographic disparity and prompt sensitivity in VLMs. FairVLM integrates three key components: (1) Semantic-Retaining Counterfactual Prompting (SRCP), which generates clinically consistent and diverse prompt variations via large language models; (2) Demographic-Aware Feature Normalization (DAFN), a lightweight module that mitigates latent representation bias across demographic groups; and (3) a Fairness-Calibrated Loss (FCL) that explicitly penalizes performance disparities while encouraging prompt consistency. Extensive evaluations on the Harvard-FairSeg dataset show that FairVLM significantly improves equity-scaled segmentation. It also reduces demographic disparity (DI) by over 65% and relative performance gap (RPG) by over 60%, while maintaining or boosting overall accuracy. FairVLM is robust to prompt changes, with less than 0.5% performance drop across varied prompts, and also generalizes well on unseen datasets. These findings present FairVLM as a new state-of-the-art, robust, and adaptable framework for a fair, prompt-invariant vision-language model. Code and data are available at https://github.com/Rahman-Motiur/FairVLM. Md Motiur Rahman 0001, Saeka Rahman, Smriti Bhatt, Miad Faezipour |
WACV | 3 |
| 2025 | Text-Assisted Vision Model for Medical Image SegmentationabstractPrecise medical image segmentation is important for automating diagnosis and treatment planning in healthcare. While images present the most significant information for segmenting organs using deep learning models, text reports also provide complementary details that can be leveraged to improve segmentation precision. Performance improvement depends on the proper utilization of text reports and the corresponding images. Most attention modules focus on single-modality computation of spatial, channel, or pixel-level attention. They are ineffective in cross-modal alignment, raising issues in multi-modal scenarios. This study addresses these gaps by presenting a text-assisted vision (TAV) model for medical image segmentation with a novel attention computation module named tri-guided attention module (TGAM). TGAM computes visual-visual, language-language, and language-visual attention, enabling the model to understand the important features and correlation between images and medical notes. This module helps the model identify the relevant features within images, text annotations, and text annotations to visual interactions. We incorporate an attention gate (AG) that modulates the influence of TGAM, ensuring it does not overflow the encoded features with irrelevant or redundant information, while maintaining their uniqueness. We evaluated the performance of TAV on two popular datasets containing images and corresponding text annotations. We find TAV to be a new state-of-the-art model, as it improves the performance by 2-7% compared to other models. Extensive experiments were performed to demonstrate the effectiveness of each component of the proposed model. Md Motiur Rahman 0001, Saeka Rahman, Smriti Bhatt, Miad Faezipour |
IEEE J. Biomed. Health Informatics | 3 |
| 2024 | MIST: Medical Image Segmentation Transformer with Convolutional Attention Mixing (CAM) DecoderabstractOne of the common and promising deep learning approaches used for medical image segmentation is transformers, as they can capture long-range dependencies among the pixels by utilizing self-attention. Despite being successful in medical image segmentation, transformers face limitations in capturing local contexts of pixels in multimodal dimensions. We propose a Medical Image Segmentation Transformer (MIST) incorporating a novel Convolutional Attention Mixing (CAM) decoder to address this issue. MIST has two parts- a pre-trained multi-axis vision transformer (MaxViT) is used as an encoder, and the encoded feature representation is passed through the CAM decoder for segmenting the images. In the CAM decoder, an attention-mixer combining multi-head self-attention, spatial attention, and squeeze and excitation attention modules is introduced to capture long-range dependencies in all spatial dimensions. Moreover, to enhance spatial information gain, deep and shallow convolutions are used for feature extraction and receptive field expansion, respectively. The integration of low-level and high-level features from different network stages is enabled by skip connection, allowing MIST to suppress unnecessary information. The experiments show that our MIST transformer with CAM decoder outperforms the state-of-the-art models specifically designed for medical image segmentation on the ACDC and Synapse datasets. Our results also demonstrate that adding the CAM decoder with a hierarchical transformer improves the segmentation performance significantly. Our model with data and code is publicly available on GitHub1. Md Motiur Rahman 0001, Shiva Shokouhmand, Smriti Bhatt, Miad Faezipour |
WACV | 3 |
| 2024 | ZTA-IoT: A Novel Architecture for Zero-Trust in IoT Systems and an Ensuing Usage Control ModelabstractRecently, several researchers motivated the need to integrate Zero Trust (ZT) principles when designing and implementing authentication and authorization systems for IoT. An integrated Zero Trust IoT system comprises the network infrastructure (physical and virtual) and operational policies in place for IoT as a product of a ZT architecture plan. This article proposes a novel Zero Trust architecture for IoT systems called ZTA-IoT. Additionally, based on different types of interactions between various layers and components in this architecture, we present ZTA-IoT-ACF, an access control framework that recognizes different interactions that need to be controlled in IoT systems. Within this framework, the article then refines its focus to object-level interactions, i.e., interactions where the target resource is a device (equivalently a thing) or an information file generated or stored by a device. Building on the recently proposed Zero Trust score-based authorization framework (ZT-SAF), we develop the object-level Zero Trust score-based authorization framework for IoT systems, denoted as ZTA-IoT-OL-SAF, to govern access requests in this context. With this machinery in place, we finally develop a novel usage control model for users-to-objects and devices-to-objects interactions, denoted as UCON \(_{IoT}\) . We give formal definitions, illustrative use cases, and a proof-of-concept implementation of UCON \(_{IoT}\) . This article is a first step toward establishing a rigorous formally defined score-based access control framework for Zero Trust IoT systems. Safwa Ameer, Lopamudra Praharaj, Ravi S. Sandhu, Smriti Bhatt, Maanak Gupta |
ACM Trans. Priv. Secur. | 4 |
| 2022 | BlueSky: Towards Convergence of Zero Trust Principles and Score-Based Authorization for IoT Enabled Smart SystemsabstractZero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. It assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. We have billions of devices in IoT ecosystems connected to enable smart environments, and these devices are scattered around different locations, sometimes multiple cities or even multiple countries. Moreover, the deployment of resource-constrained devices motivates the integration of IoT and cloud services. This adoption of a plethora of technologies expands the attack surface and positions the IoT ecosystem as a target for many potential security threats. This complexity has outstripped legacy perimeter-based security methods as there is no single, easily identified perimeter for different use cases in IoT. Hence, we believe that the need arises to incorporate ZT guiding principles in workflows, systems design, and operations that can be used to improve the security posture of IoT applications. This paper motivates the need to implement ZT principles when developing access control models for smart IoT systems. It first provides a structured mapping between the ZT basic tenets and the PEI framework when designing and implementing a ZT authorization system. It proposes the ZT authorization requirements framework (ZT-ARF), which provides a structured approach to authorization policy models in ZT systems. Moreover, it analyzes the requirements of access control models in IoT within the proposed ZT-ARF and presents the vision and need for a ZT score-based authorization framework (ZT-SAF) that is capable of maintaining the access control requirements for ZT IoT connected systems. Safwa Ameer, Maanak Gupta, Smriti Bhatt, Ravi S. Sandhu |
SACMAT | 3 |
| 2022 | Vulnerability Assessment for Applications Security Through Penetration Simulation and TestingabstractCybersecurity threats and attacks are a critical concern for computing systems as general and specifically in web applications. There are many types and categories of cyberattacks on web applications. Many of these attacks are made possible due to existing vulnerabilities in the networking environments and platforms that host these web applications. So, the vulnerability assessment and attacks simulations on these networking platforms are of extreme importance to protect and secure the top web applications that play a prime role in our daily life. One of the widely used mechanisms to identify vulnerabilities and defend against different attacks on systems and networks is Penetration Testing. It allows us to simulate real-world attacks on a network or a single device to determine the susceptibility and impact of cybersecurity attacks. Pen testing aims to secure a system or network by performing a full-blown attack against it. Several techniques have been used for that, from port scanning, service, and operating system detection to network enumeration, creating specially crafted packets, and modifying software to exploit vulnerabilities. However, while it is used widely as a defensive technique, some attackers also employ it for malicious intentions utilizing available open-source penetration testing tools. Penetration testing on internal networks such as networks that connect IoT/sensors/web cameras, can be utilized to find vulnerabilities and fix them to secure the networks. In this research, we present a detailed discussion on penetration testing and its seven phases of action and provide a step-by-step procedure with instructions using various open-source tools to conduct penetration testing and vulnerability assessments of a network. We finally demonstrate the process and results of simulated attacks on our network within the testing environment. This research provides a comprehensive introduction to penetration testing and testbed through real-world attack simulation. The IT administrator or security enthusiast can utilize them to secure networks, devices, clients, servers, and applications while enhancing the overall organization’s security. Petar Lachkov, Lo'ai Ali Tawalbeh, Smriti Bhatt |
J. Web Eng. | 3 |
| 2020 | A Game Theoretic Analysis for Cooperative Smart FarmingabstractThe application of Internet of Things (IoT) and Machine Learning (ML) to the agricultural industry has enabled the development and creation of smart farms and precision agriculture. The growth in the number of smart farms and potential cooperation between these farms has given rise to the Cooperative Smart Farming (CSF) where different connected farms collaborate with each other and share data for their mutual benefit. This data sharing through CSF has various advantages where individual data from separate farms can be aggregated by ML models and be used to produce actionable outputs which then can be utilized by all the farms in CSFs. This enables farms to gain better insights for enhancing desired outputs, such as crop yield, managing water resources and irrigation schedules, as well as better seed applications. However, complications may arise in CSF when some of the farms do not transfer high-quality data and rather rely on other farms to feed ML models. Another possibility is the presence of rogue farms in CSFs that want to snoop on other farms without actually contributing any data. In this paper, we analyze the behavior of farms participating in CSFs using game theory approach, where each farm is motivated to maximize its profit. We first present the problem of defective farms in CSFs due to lack of better data, and then propose a ML framework that segregates farms and automatically assign them to an appropriate CSF cluster based on the quality of data they provide. Our proposed model rewards the farms supplying better data and penalize the ones that do not provide required data or are malicious in nature, thus, ensuring the model integrity and better performance all over while solving the defective farms problem. Deepti Gupta, Paras Bhatt, Smriti Bhatt |
IEEE BigData | 3 |
| 2020 | Poster: IoT SENTINEL - An ABAC Approach Against Cyber-Warfare In OrganizationsabstractRecently, Internet of Things (IoT) devices and applications are becoming increasingly popular among users in various IoT domains, such as Wearable IoT, Smart Cities, Smart Home, and Smart Industry. With a range of IoT devices, cyber attack surface has hugely expanded from traditional user workstations to small autonomous devices connected to the Internet. In today's connected world, every user owns multiple connected smart devices which seamlessly connect to their organization's network. Therefore, secure and fine-grained access control policies need to be implemented at the organizational level to defend against such attacks. In this paper, we propose an Attribute-Based Access Control (ABAC) approach to defend against cyber attacks in the context of an organization environment which are launched through compromised IoT devices owned by various legitimate users. For example, a wearable IoT device of an employee of an organization which can connect to the organization's network and compromise the whole network and lack of secure access control mechanism will enable IoT Warfare in the future. Therefore, secure and fine-grained ABAC access control mechanisms and policies need to be employed for access control and authorization requirements of IoT devices. Paras Bhatt, Smriti Bhatt, Myung S. Ko 0001 |
SACMAT | 2 |
| 2020 | ABAC-CC: Attribute-Based Access Control and Communication Control for Internet of ThingsabstractInternet of Things (IoT) is revolutionizing the capabilities of the Internet with billions of connected devices in the cyberspace. These devices are commonly referred to as smart things enabling smart environments, such as Smart Home, Smart Health, Smart Transportation, and overall Smart Communities, together with key enabling technologies like Cloud Computing, Artificial Intelligence (AI) and Machine Learning (ML). Security and privacy are major concerns for today's diverse autonomous IoT ecosystem. Autonomous things and a large amount of data associated with things have fueled significant research in IoT access control and privacy in both academia and industry. To enable futuristic IoT with sustainable growth, dynamic access and communication control framework that adequately addresses security and privacy issues in IoT is inevitable. In this paper, we analyze the access and communication control requirements in Cloud-Enabled IoT (CE-IoT) and propose an attribute-based framework for access control and communication control, known as ABAC-CC, to secure accesses and communications (data flow) between various entities in the IoT architecture. We also introduce a novel Attribute-Based Communication Control (ABCC) model, which focuses on securing communications and data flow in IoT and enables users to define privacy policies using attributes of various entities. Furthermore, we analyze the applicability of ABAC-CC in specific IoT application domains, and finally, we present future research directions in the context of Cloud and Edge computing enabled IoT platforms. Smriti Bhatt, Ravi S. Sandhu |
SACMAT | 1 |
| 2017 | Access Control Model for AWS Internet of Things
Smriti Bhatt, Farhan Patwa, Ravi S. Sandhu |
NSS | 1 |