EDBT 2026 Demo / reviewers in the wild / expert
Edlira Dushku
dblp:217/2945
· DBLP profile ↗
12ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0002-4974-9739ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 6 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Modeling of physical unclonable functions (PUF): A systematic literature reviewabstractHardware fingerprinting technologies are an integral part for security of interconnected devices, for which the Physical Unclonable Function (PUF) has attracted attention in industry and academia for over 20 years. PUFs exploit uncontrollable manufacturing variations to provide hardware-intrinsic fingerprints, which are hardware analogues to biometrics in humans. These fingerprints can be used as secrets that are highly sensitive to physical tampering. However, many questions remain on the applicability of PUFs given the prominent existence of modeling techniques that allow to predict or manipulate these secret fingerprints. In this survey, we analyze the trends and state-of-the-art in PUF modeling from 254 papers obtained from a systematic search and screening process. Our results provide an extensive list of PUF designs and protocols, which we classify based on three main perspectives: application, operational, and defensive. Similarly, we list and classify modeling techniques based on the defined PUF models and learning algorithms. Most of the surveyed papers consider modeling techniques purely as a vulnerability. However, we also include the perspective of modeling as an enabler for lightweight sharing of PUF secrets. Finally, we provide an exhaustive knowledge base and identify gaps and promising directions for future work in the field. Mieszko Ferens, Edlira Dushku, Sokol Kosta |
Comput. Secur. | 2 |
| 2025 | SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle NetworksabstractIn recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK. Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens |
EuroS&P | 4 |
| 2025 | PU-QKD: Enhancing Authentication of Quantum Key Distribution via Physical Unclonable FunctionabstractThe rapid advances in quantum computing pressure the existing essential cryptographic algorithms. In this context, Quantum Key Distribution (QKD) has been proposed as a quantum safe solution for key distribution. However, current QKD systems require an authenticated classical channel which relies on pre-shared symmetric keys that are manually distributed and do not guarantee the identity of the hardware that hosts them. This paper proposes a novel scheme, the Physically Unclonable Quantum Key Distribution (PU-QKD) system, to intrinsically authenticate the communicating endpoints in QKD. The PU-QKD scheme leverages classical Physical Unclonable Functions (PUFs) to encode the data transmission in discrete variable QKD protocols (e.g., BB84). Our scheme maintains the information-theoretic security of QKD protocols by integrating the PUF as an additional layer. Authentication is bound to hardware, providing a robust fingerprint, while lower post-processing overhead increases key rates. Additionally, the proposed scheme is resilient against state-of-the-art PUF vulnerabilities, such as modeling attacks. Mieszko Ferens, Edlira Dushku, Simon Rommel, Idelfonso Tafur Monroy, Sokol Kosta |
GLOBECOM | 2 |
| 2025 | PRIVÉ: Towards Privacy-Preserving Swarm AttestationabstractIn modern large-scale systems comprising multiple heterogeneous devices, the introduction of swarm attestation schemes aims to alleviate the scalability and efficiency issues of traditional single-Prover and single-Verifier attestation. In this paper, we propose PRIVÉ, a privacy-preserving, scalable, and accountable swarm attestation scheme that addresses the limitations of existing solutions. Specifically, we eliminate the assumption of a trusted Verifier, which is not always applicable in real-world scenarios, as the need for the devices to share identifiable information with the Verifier may lead to the expansion of the attack landscape. To this end, we have designed an enhanced variant of the Direct Anonymous Attestation (DAA) protocol, offering traceability and linkability whenever needed. This enables PRIVÉ to achieve anonymous, privacy-preserving attestation while also providing the capability to trace a failed attestation back to the compromised device. To the best of our knowledge, this paper presents the first Universally Composable (UC) security model for swarm attestation accompanied by mathematical UC security proofs, as well as experimental benchmarking results that highlight the efficiency and scalability of the proposed scheme. Nada El Kassem, Wouter Hellemans, Ioannis Siachos, Edlira Dushku, Stefanos Vasileiadis, Dimitrios S. Karas, Liqun Chen 0002, Constantinos Patsakis, Thanassis Giannetsos |
SECRYPT | 4 |
| 2025 | ITERATOR: Interruptible Remote Attestation Through Cuckoo FiltersabstractRemote attestation (RA) is emerging as a promising security mechanism that establishes trust in IoT devices by detecting the malware presence. Typically, RA consists of computing a hash over the device’s memory and is executed as anatomicprocedure to guarantee the reliability of the attestation evidence. However, in real-world situations, such as those involving real-time systems, energy-harvesting devices, or mission-critical operations, the IoT device may not be able to complete the attestation procedure due to various factors like task scheduling, limited battery life, or higher priority tasks. In such scenarios where flexibility, adaptability, and security are paramount, enablinginterruptibilityof RA is crucial. This paper presents a novel approach called ITERATOR which leverages hash-based storage to enable interruptible RA without any additional hardware requirements. Our proposal transforms the device attestation procedure from the traditional approach of memory hash computation to a lookup operation in a hash-based storage, namely, Cuckoo filter. The ITERATOR protocol divides the device’s memory into blocks associated with a Cuckoo filter bucket. This approach allows the device to perform RA in multiple rounds, ensuring secure interruptible attestation. We perform software simulations of ITERATOR, demonstrating its high effectiveness in detecting the malware presence. Due to its interruptible design, ITERATOR cannot guarantee 100% detection in a single attestation round; however, repeated rounds make long-term evasion by malware highly unlikely. In particular, the experiments showed that the probability of evading the detection ranges between 37% and less than 1%, depending on the protocol configuration. Moreover, we validate ITERATOR’s efficiency through two hardware proof-of-concept implementations that rely on ESP32 and FPGA platforms. The FPGA implementation shows the high efficiency of the protocol, with 34.3ns to attest a single memory block. Nicoló Sponziello, Arish Sateesan, Md Masoom Rabbani, Nele Mentens, Nicola Dragoni, Edlira Dushku |
IEEE Internet Things J. | 6 |
| 2025 | When Random Is Bad: Selective CRPs for Protecting PUFs Against Modeling AttacksabstractResource-constrains are a significant challenge when designing secure IoT devices. To address this problem, the physical unclonable function (PUF) has been proposed as a lightweight security primitive capable of hardware fingerprinting. PUFs can provide device identification capabilities by exploiting random manufacturing variations, which can be used for authentication with a verifier that identifies a device through challenge-response interactions with its PUF. However, extensive research has shown that PUFs are inherently vulnerable to machine learning (ML) modeling attacks. Such attacks use challenge-response samples to train ML algorithms to learn the underlying parameters that define the physical PUF. In this article, we present a defensive technique to be used by the verifier called selective challenge-response pairs (CRPs). We propose generating challenges selectively, instead of randomly, to negatively affect the parameters of ML models trained by attackers. Specifically, we provide three methods: 1) binary-coded with padding (BP); 2) random shifted pattern (RSP); and 3) binary shifted pattern (BSP). We characterize them based on Hamming distance patterns, and evaluate their applicability based on their effect on the uniqueness, uniformity, and reliability of the underlying PUF implementation. Furthermore, we analyze and compare their resilience to ML modeling with the traditional random challenges on the well-studied XOR PUF, feed-forward PUF, and lightweight secure PUF, showing improved resilience of up to 2 times the number of CRPs. Finally, we suggest using our method on the interpose PUF to counter reliability-based attacks which can overcome selective CRPs and show that up to 4 times the number of CRPs can be exchanged securely. Mieszko Ferens, Edlira Dushku, Sokol Kosta |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2024 | Securing PUFs via a Predictive Adversarial Machine Learning System by Modeling of AttackersabstractThe widespread adoption of Internet-of-Things (IoT) devices is elevating the security expectations of many application domains. Meanwhile, numerosity, hardware and software heterogeneity, and low cost of IoT devices makes meeting such expectations challenging. A key security function that IoT devices must possess is identity and the capability to authenticate themselves. However, traditional authentication mechanisms rely on hash-based cryptography, requiring complex hardware and computational resources. To mitigate this problem, the Physical Unclonable Function (PUF) has been proposed as a lightweight source of device-specific entropy that can be used for identifying IoT devices. However, a major challenge to this approach is protecting PUFs against Machine Learning (ML)-based modeling attacks, where an attacker can clone an authentic PUF after collecting enough training data from the communication protocol, e.g., as a passive eavesdropper. In this paper, we propose a Predictive Adversarial System (PAS) that aims to prevent ML modeling attacks by predicting the capabilities of an attacker in a PUF system. We analyze the best approaches to implement our system and evaluate their performance in terms of the modeling capacity that a passive attacker exhibits. Our experiments show that the proposed approach can increase the training data required for a successful modeling attack over one million samples, without increasing the security overhead of resource-constrained PUF-enabled IoT devices. Mieszko Ferens, Edlira Dushku, Shreyas Srinivasa, Sokol Kosta |
ACSAC | 2 |
| 2024 | On the Feasibility of Deep Reinforcement Learning for Modeling Delay-Based PUFsabstractModeling of Physical Unclonable Functions (PUFs) through Machine Learning (ML) algorithms has been widely applied to break their security. Currently, many different algorithms are capable of modeling a wide range of delay-based PUFs, preventing these primitives from being effectively applied to security applications such as authentication. To tackle this, other studies have developed PUF designs that prevent ML modeling attacks. However, these studies typically focus on defending against well-known Supervised Learning techniques, including Logistic Regression or Multi-Layer Perceptron. On the other hand, since ML is rapidly evolving, new techniques can be potentially applied to model the latest proposed PUFs. For this reason, in this paper, we study the applicability of a subfield of ML, namely Deep Reinforcement Learning (DRL), for PUF modeling and comparing it to the state-of-the-art. We find that DRL, specifically the Deep Q-Network (DQN) algorithm, can be as effective as state-of-the-art modeling attacks on XOR Arbiter PUF, making it a new threat to delay-based PUFs. Additionally, when considering PUFs with challenge obfuscation, such as the Interpose PUF, DQN outperforms the state-of-the-art, raising concerns about the long-term security of obfuscation techniques. Mieszko Ferens, Edlira Dushku, Sokol Kosta |
WiMob | 2 |
| 2023 | ZEKRA: Zero-Knowledge Control-Flow AttestationabstractTo detect runtime attacks against programs running on a remote computing platform, Control-Flow Attestation (CFA) lets a (trusted) verifier determine the legality of the program’s execution path, as recorded and reported by the remote platform (prover). However, besides complicating scalability due to verifier complexity, this assumption regarding the verifier’s trustworthiness renders existing CFA schemes prone to privacy breaches and implementation disclosure attacks under “honest-but-curious” adversaries. Thus, to suppress sensitive details from the verifier, we propose to have the prover outsource the verification of the attested execution path to an intermediate worker of which the verifier only learns the result. However, since a worker might be dishonest about the outcome of the verification, we propose a purely cryptographical solution of transforming the verification of the attested execution path into a verifiable computational task that can be reliably outsourced to a worker without relying on any trusted execution environment. Specifically, we propose to express a program-agnostic execution path verification task inside an arithmetic circuit whose correct execution can be verified by untrusted verifiers in zero knowledge. Heini Bergsson Debes, Edlira Dushku, Thanassis Giannetsos, Ali Marandi |
AsiaCCS | 2 |
| 2023 | PROVE: Provable remote attestation for public verifiabilityabstractThe expanding attack surface of Internet of Things (IoT) systems calls for innovative security approaches to verify the reliability of IoT devices. To this end, Remote Attestation (RA) serves as a key mechanism that remotely detects the presence of malware in IoT devices. Typically, RA allows a centralized trusted Verifier to retrieve reliable evidence about the software integrity of an untrusted Prover. Existing RA schemes generally rely on the assumption that the Verifier and the Prover know each other and have pre-shared cryptographic keys during the bootstrap phase. However, these assumptions are not realistic to employ over commonly used event-driven IoT networks, in which the interacting parties do not know each other and do not communicate directly. This paper proposes PROVE, a novel protocol that allows many Verifiers to attest one or more Provers without pre-shared key material and without using public-key cryptography which is often not suitable for resource-constraint IoT devices. In particular, PROVE considers a realistic IoT system where devices adopt the publish/subscribe communication paradigm. In PROVE, the subscribers act as untrusted Verifiers and attest not only the firmware integrity of the publishers that act as untrusted Provers but also the authenticity of the received data originated from these publishers. We simulate PROVE on the Contiki emulator and demonstrate the scalability of the solution. We also validate PROVE through two hardware proof-of-concept implementations: PROVE and PROVE+, which rely on different cryptographic cores. The results show that a complete execution of the protocol takes 4605 ns and 324 ns for PROVE and PROVE+, respectively. Edlira Dushku, Md Masoom Rabbani, Jo Vliegen, An Braeken, Nele Mentens |
J. Inf. Secur. Appl. | 1 |
| 2021 | RESERVE: Remote Attestation of Intermittent IoT devicesabstractInternet of Things (IoT) devices have enveloped our surroundings and have been increasingly deployed in many domains. Even though the IoT has generated unprecedented opportunities, the poorly secured design of IoT devices makes them an easy target for cyber attacks. Aimed at securing IoT devices, Remote Attestation (RA) is a security technique that identifies threat presence in IoT systems. Typically, RA is an atomic procedure that requires uninterrupted connectivity to execute. However, in energy harvesting context where intermittent IoT devices go into sleep mode immediately after regular operations, the atomic property is difficult to achieve. In this paper, we propose RESERVE, a novel lightweight RA protocol designed specifically for Intermittent IoT devices. RESERVE aims to improve the security of intermittent systems by detecting malware presence during online mode and guaranteeing with some probability software legitimacy during offline mode. In particular, RESERVE ensures trustworthiness by organizing the device's software into modules, and after regular operation each device attests as many modules as fit in its energy budget. Md Masoom Rabbani, Edlira Dushku, Jo Vliegen, An Braeken, Nicola Dragoni, Nele Mentens |
SenSys | 2 |
| 2020 | SARA: Secure Asynchronous Remote Attestation for IoT SystemsabstractRemote attestation has emerged as a valuable security mechanism which aims to verify remotely whether or not a potentially untrusted device has been compromised. The protocols of Remote attestation are particularly important for securing Internet of Things (IoT) systems which, due to the large number of interconnected devices and limited security protections, are susceptible to a wide variety of cyber attacks. To guarantee the integrity of a software running on a single device, remote attestation is usually executed as an uninterrupted procedure: at the attestation time, a device stops the normal operation and executes the attestation of the entire device without interruption. The remote attestation protocols that aim to attest a large number of devices also follow the assumption on uninterrupted execution: when a device attests its network neighbours, each device verified in the neighborhood suspends its normal operation until the attestation protocol is completed. To avoid unnecessary suspension of the normal operation of the devices, this paper proposes a novel Secure Asynchronous Remote Attestation (SARA) protocol that releases the constraint of synchronous interaction among devices. In particular, SARA is an attestation protocol that exploits asynchronous communication capabilities among IoT devices in order to attest a distributed IoT service executed by them. SARA verifies both that each IoT device is not compromised (device trustworthiness), and that the exchanged communication data have not maliciously influence the communicating devices (legitimate operations). By tracing the execution order of each service invocation of an asynchronous distributed service, SARA allows each service to collect accurately historical data of its interactions, and transmits asynchronously such historical data to other interacting services. We have implemented and validated SARA through a realistic simulation on the Contiki emulator that demonstrates the functionality and efficiency of our protocol. The results confirm the suitability of SARA for low-end devices. Edlira Dushku, Md Masoom Rabbani, Mauro Conti, Luigi V. Mancini, Silvio Ranise |
IEEE Trans. Inf. Forensics Secur. | 1 |