EDBT 2026 Demo / reviewers in the wild / expert
Animesh Chhotaray
dblp:207/6604
· DBLP profile ↗
6ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0006-1051-172XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | One Video to Steal Them All: 3D-Printing IP Theft through Optical Side-ChannelsabstractThe 3D printing industry is rapidly growing and increasingly adopted across various sectors, including manufacturing, healthcare, and defense. However, the operational setup often involves hazardous environments, necessitating remote monitoring through cameras and other sensors, which opens the door to cyber-based attacks. In this paper, we show that an adversary with access to video recordings of the 3D printing process can reverse-engineer the underlying 3D print instructions. Our model tracks the printer nozzle's movements during the printing process and maps the corresponding trajectory into G-code instructions. Further, it identifies the correct parameters, such as feed rate and extrusion rate, leading us to be able to successfully perform IP theft. To validate the success of IP theft, we design an equivalence checker that quantitatively compares two sets of 3D print instructions, evaluating their similarity in producing objects that are alike in shape, external appearance, and internal structure. Our equivalence checker, unlike other simple distance-based metrics such as normalized mean square error, is rotational as well as translational invariant. This is necessary to capture shifts in the base/start position of the reverse-engineered instructions relative to the actual 3D print instructions that can happen due to different camera positions. Our model achieves an average accuracy of 90.87% and generates 30.20% fewer instructions compared to the current state-of-the-art methods that produce instructions that either lead to faulty or incorrect (in terms of difference in shape and internal structure) 3D prints. Additionally, we use our model to reverse-engineer the 3D print instructions from a video recording and print a fully-functional counterfeit object. Twisha Chattopadhyay, Fabricio Ceschin, Marco E. Garza, Dymytriy Zyunkin, Animesh Chhotaray, Aaron P. Stebner, Saman A. Zonouz, Raheem A. Beyah |
CCS | 5 |
| 2025 | A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersabstractMaritime systems, including ships and ports, are critical components of global infrastructure, essential for transporting over 80% of the world's goods and supporting internet connectivity. However, these systems face growing cybersecurity threats, as shown by recent attacks disrupting Maersk, one of the world's largest shipping companies, causing widespread impacts on international trade. The unique challenges of the maritime environment--such as diverse operational conditions, extensive physical access points, fragmented regulatory frameworks, and its deeply interconnected structure--require maritime-specific cybersecurity research. Despite the sector's importance, maritime cybersecurity remains underexplored, leaving significant gaps in understanding its challenges and risks. To address these gaps, we investigate how maritime system operators perceive and navigate cybersecurity challenges within this complex landscape. We conducted a user study comprising surveys and semi-structured interviews with 21 officer-level mariners. Participants reported direct experiences with shipboard cyber-attacks, including GPS spoofing and logistics-disrupting ransomware, demonstrating the real-world impact of these threats. Our findings reveal systemic and human-centric issues, such as training poorly aligned with maritime needs, insufficient detection and response tools, and serious gaps in mariners' cybersecurity understanding. Our contributions include a categorization of threats identified by mariners and recommendations for improving maritime security, including better training, response protocols, and regulation. These insights aim to guide future research and policy to strengthen the resilience of maritime systems. Anna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren, Animesh Chhotaray, Frank Li 0001, Saman A. Zonouz, Raheem A. Beyah |
CCS | 5 |
| 2024 | Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network Data
Ryan Pickren, Animesh Chhotaray, Frank Li 0001, Saman A. Zonouz, Raheem A. Beyah |
CCS | 2 |
| 2022 | Hardening Circuit-Design IP Against Reverse-Engineering AttacksabstractDesign-hiding techniques are a central piece of academic and industrial efforts to protect electronic circuits from being reverse-engineered. However, these techniques have lacked a principled foundation to guide their design and security evaluation, leading to a long line of broken schemes. In this paper, we begin to lay this missing foundation. We establish formal syntax for design-hiding (DH) schemes, a cryptographic primitive that encompasses all known design-stage methods to hide the circuit that is handed to a (potentially adversarial) foundry for fabrication. We give two security notions for this primitive: function recovery (FR) and key recovery (KR). The former is the ostensible goal of design-hiding methods to prevent reverse-engineering the functionality of the circuit, but most prior work has focused on the latter. We then present the first provably (FR,KR)-secure DH scheme, ${OneChaff}_{hd}$. A side-benefit of our security proof is a framework for analyzing a broad class of new DH schemes. We finish by unpacking our main security result, to provide parameter-setting guidance. Animesh Chhotaray, Thomas Shrimpton |
SP | 1 |
| 2021 | Brittle Features of Device Authentication
Washington Garcia, Animesh Chhotaray, Joseph I. Choi, Suman Kalyan Adari, Kevin R. B. Butler, Somesh Jha |
CODASPY | 2 |
| 2017 | Standardizing Bad Cryptographic Practice: A Teardown of the IEEE Standard for Protecting Electronic-design Intellectual PropertyabstractWe provide an analysis of IEEE standard P1735, which describes methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP. We find a surprising number of cryptographic mistakes in the standard. In the most egregious cases, these mistakes enable attack vectors that allow us to recover the entire underlying plaintext IP. Some of these attack vectors are well-known, e.g. padding-oracle attacks. Others are new, and are made possible by the need to support the typical uses of the underlying IP; in particular, the need for commercial system-on-chip (SoC) tools to synthesize multiple pieces of IP into a fully specified chip design and to provide syntax errors. We exploit these mistakes in a variety of ways, leveraging a commercial SoC tool as a black-box oracle. Animesh Chhotaray, Adib Nahiyan, Thomas Shrimpton, Domenic Forte, Mark Tehranipoor |
CCS | 1 |