Maria Mushtaq

dblp:219/6953 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0003-0046-2582ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Microarchitectural Analysis of Speculative Execution Patterns in RISC-V using Machine Learning and ISA-Level Masking Wrappers
Maria Mushtaq, Lirida A. B. Naviner, Jawad Haj-Yahya, Florent Bruguier
IOLTS2
2026 DRsam: Detection of Fault-Based Microarchitectural Side-Channel Attacks in RISC-V Using Statistical Preprocessing and Association Rule Mining
abstract
RISC-V processors are becoming ubiquitous in critical applications, but their susceptibility to microarchitectural side-channel attacks is a serious concern. Detection of microarchitectural attacks in RISC-V is an emerging research topic that is relatively underexplored, compared to x86 and ARM. The first line of work to detect flush+fault-based microarchitectural attacks in RISC-V leverages Machine Learning (ML) models, yet it leaves several practical aspects that need further investigation. To address overlooked issues, we leveraged gem5 and propose a new detection method combining statistical preprocessing and association rule mining having reconfiguration capabilities to generalize the detection method for any microarchitectural attack. The performance comparison with state-of-the-art reveals that the proposed detection method achieves up to 5.15% increase in accuracy, 7% rise in precision, and 3.91% improvement in recall under the cryptographic, computational, and memory-intensive workloads alongside its flexibility to detect new variant of flush+fault attack. Moreover, as the attack detection relies on association rules, their human-interpretable nature provides deep insight to understand microarchitectural behavior during the execution of attack and benign applications.
Maria Mushtaq, Jaan Raik, Tara Ghasempouri
IOLTS2
2026 Traphalt: Indirect Core Halt via Trap Handling to Halt a RISC-V Core from User Mode through Kernel-Mediated Fault Handling
Maria Mushtaq, Lirida A. B. Naviner, Jawad Haj-Yahya, Florent Bruguier
SECRYPT (2)2
2026 Comic character recognition using graph embedding in graph representations
Nadeem Iqbal 0003, Malik Muhammad Saad Missen, Maruf Pasha, Mickaël Coustaty, Muhammad Muzzamil Luqman, Faiza Belbachir, Maria Mushtaq
Int. J. Document Anal. Recognit.7
2025 Evict+Spec+Time on RISC-V: Gem5-Based Implementation and Microarchitectural Analysis
abstract
Microarchitectural side-channel attacks are a growing concern and have been widely studied on x86 and ARM architectures, but RISC-V’s susceptibility to similar attacks remains understudied. We present the first implementation and evaluation of the Evict+Spec+Time attack on RISC-V, previously demonstrated only on x86 [2]. This advanced variant of Evict+Time integrates three critical phases: eviction, speculation, and timing. First, the attack forcibly evicts target cache lines using RISC-V’s cbo.flush instruction via the Zicbom extension [6]. Next, it exploits out-of-order execution to manipulate microarchitectural resources such as the reorder buffer, limiting the processor’s ability to mask cache-miss latency. Finally, it infers secret-dependent memory access patterns through precise timing measurements. We validate RISC-V’s vulnerability by recovering secret keys from AES T-table implementations. Using the gem5 simulator [4], we provide the first detailed analysis of microarchitectural behavior during the attack, including cache contention, pipeline stalls, and latency variations. These insights establish foundational guidance for developing RISC-V-specific countermeasures against such attacks.
Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille
DSD2
2025 Side-Channel Attack Detection Using gem5 and Machine Learning: A Case Study on Fault-Based Attacks in RISC-V
abstract
Microarchitectural side-channel attacks pose a significant threat to modern computing architectures. This paper presents a machine learning-based methodology for detecting these attacks using the gem5 simulator, focusing on the recently discovered Flush+Fault attack [6] on RISC-V. Our approach follows a three-phase process. The first phase is data collection, where we simulate attack and non-attack scenarios in gem5 and extract microarchitectural features indicative of side-channel activity. The second phase is the training phase, where we utilize machine learning (ML) techniques to build a classification model capable of distinguishing between normal execution and attack patterns. The last phase is the testing phase, where we evaluate the trained model using various performance metrics to validate its accuracy and precision. To the best of our knowledge, this is the first detection framework for Flush+Fault attacks [6] on RISC-V, showcasing its effectiveness in mitigating emerging threats. Our results indicate that gem5 metrics combined with machine learning models can reliably detect Flush+Fault attacks, achieving 0.99 accuracy with random forest (RF), 0.96 with support vector machine (SVM), and 0.95 with naïve bayes (NB). Moreover, this methodology is adaptable to different side-channel attacks and architectures, making it a promising approach for strengthening microarchitectural security.
Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille
IOLTS2
2025 Assessing Security RISC: Analyzing Flush+Fault Attack on RISC-V Using gem5 Simulator
abstract
International audience
Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille
SECRYPT2
2024 Decoding Attack Behaviors by Analyzing Patterns in Instruction-Based Attacks using gem5
abstract
The diversity of Instruction Set Architectures (ISAs), each with its unique constraints and optimization strategies, presents significant opportunities and challenges in processor design. Modern processor vendors exploit these ISAs to enhance security, reliability, and performance. Recent security vulnerabilities, notably Spectre and Meltdown, have highlighted the critical need for robust hardware security measures. In this paper, we employ gem5, a state-of-the-art cycle-accurate simulation tool, to simulate the Spectre attack. We developed and modified scripts for both x86 and ARM architectures to ensure compatibility with gem5 version 23.1. Our simulation setup involved running attack scenarios under various configurations to gather comprehensive data on cache misses, cache hits, mispredicted branches, and level 2 cache hits and misses. In the simulation, we analyzed the trace files generated by gem5, utilizing a range of debug flags such as Exec for disassembly (dasm) insights. By detailed analysis of cache and branch prediction using detailed debug data revealed by gem5 traces, we identify some specific attack patterns that are useful for automating the detection of the attacks. Our future work aims to expand this analysis to include additional attack vectors and find more attack patterns, thereby strengthening our attack pattern recognition capabilities.
Maria Mushtaq, Lirida A. B. Naviner, Florent Bruguier, Jawad Haj-Yahya, Pascal Benoit
RSP2
2023 Optimal Functional Splitting, Placement and Routing for Isolation-Aware Network Slicing in NG-RAN
abstract
In the rapidly evolving landscape of 5G and its successor technologies, the Next Generation Radio Access Network (NG-RAN) stands out as a transformative pillar. Functional splitting, a core concept in NG-RAN, splits the traditional base station into distinct functional entities, notably the Distributed Unit (DU), Centralized Unit (CU) and Radio Unit (RU). With flexible functional splitting, Infrastructure Providers (InPs) can dynamically allocate RAN resources to cater to each network slice's distinct throughput and latency demand. However, the problem of optimally selecting functional splits, placement of RAN functions in DU/CU with constrained computational capacities and determining routing paths present an NP-hard challenge. The coexistence of multiple slices on shared infrastructure may necessitate slice isolation for security, performance, and operational reasons, adding another layer of complexity. To address this multifaceted problem, we formulate an Integer Linear Programming (ILP) model that seeks to maximize the InP profit considering computation, virtual machine instantiation and routing costs. Using Gurobi optimizer, we show that optimal slice admission solutions directly impact InP profit and that enhanced computational capacities can increase the number of slices admitted.
Maria Mushtaq, Morteza Golkarifard, Nashid Shahriar, Raouf Boutaba, Aladdin Saleh
CNSM1
2022 CAN-BERT do it? Controller Area Network Intrusion Detection System based on BERT Language Model
abstract
Due to the rising number of sophisticated customer functionalities, electronic control units (ECUs) are increasingly integrated into modern automotive systems. However, the high connectivity between the in-vehicle and the external networks paves the way for hackers who could exploit in-vehicle network protocols' vulnerabilities. Among these protocols, the Controller Area Network (CAN), known as the most widely used in-vehicle networking technology, lacks encryption and authentication mechanisms, making the communications delivered by distributed ECUs insecure. Inspired by the outstanding performance of bidirectional encoder representations from transformers (BERT) for improving many natural language processing tasks, we propose in this paper “CAN-BERT”, a deep learning based network intrusion detection system, to detect cyber attacks on CAN bus protocol. We show that the BERT model can learn the sequence of arbitration identifiers (IDs) in the CAN bus for anomaly detection using the “masked language model” unsupervised training objective. The experimental results on the “Car Hacking: Attack & Defense Challenge 2020” dataset show that “CAN-BERT” outperforms state-of-the-art approaches. In addition to being able to identify in-vehicle intrusions in real-time within 0.8 ms to 3 ms w.r.t CAN ID sequence length, it can also detect a wide variety of cyberattacks with an F1-score of between 0.81 and 0.99.
Natasha Alkhatib, Maria Mushtaq, Hadi Ghauch, Jean-Luc Danger
AICCSA2
2022 Unsupervised Network Intrusion Detection System for AVTP in Automotive Ethernet Networks
abstract
Network Intrusion Detection Systems (NIDSs) are widely regarded as efficient tools for securing in-vehicle networks against diverse cyberattacks. However, since cyberattacks are always evolving, signature-based intrusion detection systems are no longer adopted. An alternative solution can be the deployment of deep learning based intrusion detection system which play an important role in detecting unknown attack patterns in network traffic. Hence, in this paper, we compare the performance of different unsupervised deep and machine learning based anomaly detection algorithms, for real-time detection of anomalies on the Audio Video Transport Protocol (AVTP), an application layer protocol implemented in the recent Automotive Ethernet based in-vehicle network. The numerical results, conducted on the recently published “Automotive Ethernet Intrusion Dataset show that deep learning models significantly outperfom other state-of-the art traditional anomaly detection models in machine learning under different experimental settings.
Natasha Alkhatib, Maria Mushtaq, Hadi Ghauch, Jean-Luc Danger
IV2
2021 Transit-Guard: An OS-based Defense Mechanism Against Transient Execution Attacks
abstract
Transient attacks manipulate speculative execution to alter the control flow path in an application program and modify microarchitectural state. These state changes are not captured by the existing Instruction Set Architectures (ISAs). In this paper, we propose a novel OS-level detection-based mitigation mechanism, called Transit-Guard, that uses machine learning and real-time behavioral data of concurrent processes to detect and subsequently mitigate these attacks at run-time.
Maria Mushtaq, David Novo, Florent Bruguier, Pascal Benoit, Muhammad Khurram Bhatti
ETS1
2021 OctoMap: Supporting Service Function Chaining via Supervised Learning and Online Contextual Bandit
abstract
Network Function Virtualization (NFV) replaces physical middleboxes with elastic Virtual Network Functions (VNFs). Those VNFs need to be instantiated, and their resources dynamically scaled to meet application and traffic fluctuation requirements. Despite recent extensive research, deciding how to map virtual resources optimally to the underlying infrastructure remains practically a challenge. Existing approaches mostly assign fixed resources to each VNF instance, and transfer virtual flows using a single physical path, without prior knowledge of traffic patterns and available bandwidth. Such resource binding strategies lead to suboptimal physical link utilization. We advance the state of the art in this regard by presenting OctoMap, a system designed to support with learning theory any chain embedding algorithm. OctoMap utilizes a Convolution Neural Network for traffic prediction and provisioning, and a contextual multi-armed bandit algorithm to solve the online VNF chain embedding problem. We show the performance benefits of OctoMap with a trace-driven simulation campaign using publicly available datasets. In particular, we show how OctoMap reduces the costs of provisioning network services under node and link constraints, comparing different predictors and different multi-armed bandit policies.
Aziza Alzadjali, Maria Mushtaq, Flavio Esposito, Claudio Fiandrino, Jitender S. Deogun
NetSoft2
2021 Implementing Rowhammer Memory Corruption in the gem5 Simulator
abstract
Modern computer memories have shown to have reliability issues. The main memory is the target of a security threat called Rowhammer, which causes bit flips in adjacent victim cells of aggressor rows. Numerous countermeasures have been proposed, some of the most efficient ones relying on memory controller modifications, which make them non-integrable in existing systems. These solutions have to be effective against attacks on current and future architectures and technology nodes. In order to prove the efficiency of such mitigation techniques, we have to use simulation platforms. Unfortunately, existing architecture simulators do not provide any implementation of unintended memory modifications like bit-flips. Integrating memory corruption into architecture simulators would allow the construction of attacks and mitigations for current and future computers, using feedback from the simulator. In this paper, we propose an implementation of the Rowhammer effect in the gem5 architecture simulator, demonstrate its capabilities and state its limitations.
Loïc France, Florent Bruguier, Maria Mushtaq, David Novo, Pascal Benoit
RSP3
2021 Necklace: An Architecture for Distributed and Robust Service Function Chains With Guarantees
abstract
The service function chaining paradigm links ordered service functions via network virtualization, in support of applications with severe network constraints. To provide wide-area (federated) virtual network services, a distributed architecture should orchestrate cooperating or competing processes to generate and maintain virtual paths hosting service function chains while, guaranteeing performance and fast asynchronous consensus even in the presence of failures. To this end, we propose a prototype of an architecture for robust service function chain instantiation with convergence and performance guarantees. To instantiate a service chain, our system uses a fully distributed asynchronous consensus mechanism that has bounds on convergence time and leads to a (1 - 1/e)-approximation ratio with respect to the Pareto optimal chain instantiation, even in the presence of (non-byzantine) failures. Moreover, we show that a better optimal chain approximation cannot exist. To establish the practicality of our approach, we evaluate the system performance, policy tradeoffs, and overhead via simulations and through a prototype implementation. We then describe our extensible management object model and compare our asynchronous consensus's overhead against Raft, a recent decentralized consensus protocol, showing superior performance. We furthermore discuss a new management object model for distributed service function chain instantiation.
Flavio Esposito, Maria Mushtaq, Michele Berno, Gianluca Davoli, Davide Borsatti, Walter Cerroni, Michele Rossi
IEEE Trans. Netw. Serv. Manag.2
2020 Winter is here! A decade of cache-based side-channel attacks, detection & mitigation for RSA
Maria Mushtaq, Muhammad Asim Mukhtar, Vianney Lapotre, Muhammad Khurram Bhatti, Guy Gogniat
Inf. Syst.1
2020 FLUSH + PREFETCH: A countermeasure against access-driven cache-based side-channel attacks
abstract
Cache-based side-channel attacks (SCAs) are becoming a security threat to the emerging computing platforms. To mitigate these attacks, numerous countermeasures have been proposed. However, these countermeasures require either radical hardware modification or they are incompatible with the performance features like super-page and data de-duplication. This paper presents a countermeasure, called Flush+Prefetch, which obfuscates the memory access behavior of a secure application using independent threads that randomly access the memory belonging to secure application. Unlike existing state-of-the-art countermeasures, Flush+Prefetch works with commodity hardware and it is compatible with existing performance features. As a proof-of-concept, we have studied the effectiveness of Flush+Prefetch by defending the secret key of RSA cryptosystem against a high-resolution cache side-channel attack called Flush+Reload. We have evaluated the confidentiality of RSA decryption process on an Intel Xeon E5-2643 processor by generating 100,000 requests to a web-server sequentially while considering the effect on performance as well. Our experimental results show that the confidentiality of memory accesses by RSA is preserved under Flush+Prefetch countermeasure. Our results show that the performance, in terms of average execution time , is improved by 10.2% for best design case as compared to the system under attack.
Muhammad Asim Mukhtar, Maria Mushtaq, Muhammad Khurram Bhatti, Vianney Lapotre, Guy Gogniat
J. Syst. Archit.2