EDBT 2026 Demo / reviewers in the wild / expert
Brooks Olney
dblp:228/3540
· DBLP profile ↗
4ranked-venue papers
3as first author
3since 2021 · last 2022
0000-0001-9178-0783ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Protecting Deep Neural Network Intellectual Property with Architecture-Agnostic Input ObfuscationabstractDeep Convolutional Neural Networks (DCNNs) have revolutionized and improved many aspects of modern life. However, these models are increasingly more complex, and training them to perform at desirable levels is difficult undertaking; hence, the trained parameters represent a valuable intellectual property (IP) asset which a motivated attacker may wish to steal. To better protect the IP, we propose a method of lightweight input obfuscation that is undone prior to inference, where input data is obfuscated in order to use the model to specification. Without using the correct key and unlocking sequence, the accuracy of the classifier is reduced to a random guess, thus protecting the input/output interface and mitigating model extraction attacks which rely on such access. We evaluate the system using a VGG-16 network trained on CIFAR-10, and demonstrate that with an incorrect deobfuscation key or sequence, the classification accuracy drops to a random guess, with an inference timing overhead of 4.4% on an Nvidia-based evaluation platform. The system avoids the costs associated with retraining and has no impact on model accuracy for authorized users. Brooks Olney, Robert Karam |
ACM Great Lakes Symposium on VLSI | 1 |
| 2022 | Trojan Resilience in Implantable and Wearable Medical Devices with Virtual BiosensingabstractImplantable and wearable medical devices (IWMDs) provide a wide range of benefits, including monitoring various physiological conditions and providing patients real-time treatment and emergency support. The latest generation of IWMDs incorporates greater communication and computation capabilities, enabling personalized healthcare. Security and reliability of these devices is therefore paramount. In this paper, we discuss potential vulnerabilities and attacks on IWMDs, including attacks which may interfere with the availability and correctness of integrated sensors. We propose effective countermeasures that can improve devices’ resilience towards these attacks. We utilize a set of statistical and machine learning (ML) models as virtual biosensors, which serve to both detect and correct anomalous biosensor measurement errors in real-time. Experiments with a blood glucose dataset demonstrate that the virtual biosensors can not only detect anomalous measurements, but also fix measurement errors or even DoS-style attacks, which impact the availability of the sensor. Shakil Mahmud, Farhath Zareen, Brooks Olney, Mateus Augusto Fernandes Amador, Robert Karam |
ICCD | 3 |
| 2022 | Diverse, Neural Trojan Resilient Ecosystem of Neural Network IPabstractAdversarial machine learning is a prominent research area aimed towards exposing and mitigating security vulnerabilities in AI/ML algorithms and their implementations. Data poisoning and neural Trojans enable an attacker to drastically change the behavior and performance of a Convolutional Neural Network (CNN) merely by altering some of the input data during training. Such attacks can be catastrophic in the field, e.g. for self-driving vehicles. In this paper, we propose deploying a CNN as an ecosystem of variants , rather than a singular model. The ecosystem is derived from the original trained model, and though every derived model is structurally different, they are all functionally equivalent to the original and each other. We propose two complementary techniques: stochastic parameter mutation , where the weights θ of the original are shifted by a small, random amount, and a delta-update procedure which functions by XOR’ing all of the parameters with an update file containing the Δ θ values. This technique is effective against transferability of a neural Trojan to the greater ecosystem by amplifying the Trojan’s malicious impact to easily detectable levels; thus, deploying a model as an ecosystem can render the ecosystem more resilient against a neural Trojan attack. Brooks Olney, Robert Karam |
ACM J. Emerg. Technol. Comput. Syst. | 1 |
| 2020 | Tunable FPGA Bitstream Obfuscation with Boolean Satisfiability Attack CountermeasureabstractField Programmable Gate Arrays (FPGAs) are seeing a surge in usage in many emerging application domains, where the in-field reconfigurability is an attractive characteristic for diverse applications with dynamic design requirements, such as cloud computing, automotive, IoT, and aerospace. The security of the FPGA configuration file, or bitstream , is critical, especially for devices with long in-field lifetimes, where attackers may attempt to extract valuable Intellectual Property (IP) from within. In this article, we propose a tunable obfuscation approach that protects IP from typical bitstream attacks while enabling designers to trade off security with acceptable overhead. We also consider two potential attacks on this protection mechanism: Boolean SAT Attacks on the obfuscation and removal attacks on the protection circuitry. The obfuscation and SAT countermeasure are integrated in a custom CAD framework within a commercial FPGA toolflow and together provide mathematically strong protection against common bitstream attacks. Further, we quantify the difficulty of a removal attack on the protection circuitry through pattern matching and direct bitstream manipulation. The average area, power, and delay overhead for obfuscation with 95% mismatch probability are 18%, 16%, and 8%, respectively, for small combinational circuits, and 1%, 2%, and 5% for larger arithmetic modules. Brooks Olney, Robert Karam |
ACM Trans. Design Autom. Electr. Syst. | 1 |