Lavanya Elluri

dblp:229/4060 · DBLP profile ↗
← Back
9ranked-venue papers in the field
3as first author
7since 2021 · last 2025
0000-0002-8881-3369ORCID · verified

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 8 (2 first)Knowledge Engineering, Semantic Web & Information Systems · 1 (1 first)
YearPublicationVenuePosition
2025 Modeling Romanized Hindi and Bengali: Dataset Creation and Multilingual LLM Integration
Kanchon Gharami, Quazi Sarwar Muhtaseem, Deepti Gupta, Lavanya Elluri, Shafika Showkat Moni
IEEE Big Data4
2025 Recent Advancements in Machine Learning for Cybercrime Prediction
abstract
Cybercrime is a growing threat to organizations and individuals worldwide, with criminals using sophisticated techniques to breach security systems and steal sensitive data. This paper aims to comprehensively survey the latest advancements in cybercrime prediction, highlighting the relevant research. For this purpose, we reviewed more than 150 research articles and discussed 50 most recent and appropriate ones. We start the review with some standard methods cybercriminals use and then focus on the latest machine and deep learning techniques, which detect anomalous behavior and identify potential threats. We also discuss transfer learning, which allows models trained on one dataset to be adapted for use on another dataset. We then focus on active and reinforcement learning as part of early-stage algorithmic research in cybercrime prediction. Finally, we discuss critical innovations, research gaps, and future research opportunities in Cybercrime prediction. This paper presents a holistic view of cutting-edge developments and publicly available datasets.
Lavanya Elluri, Varun Mandalapu, Piyush Vyas, Nirmalya Roy
J. Comput. Inf. Syst.1
2024 Blockchain-Enhanced Framework for Secure Third-Party Vendor Risk Management and Vigilant Security Controls
abstract
In an era of heightened digital interconnectedness, businesses increasingly rely on third-party vendors to enhance their operational capabilities. However, this growing dependency introduces significant security risks, making it crucial to develop a robust framework to mitigate potential vulnerabilities. This paper proposes a comprehensive secure framework for managing third-party vendor risk, integrating blockchain technology to ensure transparency, traceability, and immutability in vendor assessments and interactions. By leveraging blockchain, the framework enhances the integrity of vendor security audits, ensuring that vendor assessments remain up-to-date and tamperproof. This proposed framework leverages smart contracts to reduce human error while ensuring real-time monitoring of compliance and security controls. By evaluating critical security controls—such as data encryption, access control mechanisms, multi-factor authentication, and zero-trust architecture—this approach strengthens an organization’s defense against emerging cyber threats. Additionally, continuous monitoring enabled by blockchain ensures the immutability and transparency of vendor compliance processes. In this paper, a case study on iHealth’s transition to AWS Cloud demonstrates the practical implementation of the framework, showing a significant reduction in vulnerabilities and marked improvement in incident response times. Through the adoption of this blockchain-enabled approach, organizations can mitigate vendor risks, streamline compliance, and enhance their overall security posture. Our findings highlight the importance of employing blockchain to enforce security controls and maintain compliance with healthcare regulations such as HIPAA. In this paper, we present a comprehensive set of security controls and demonstrate how blockchain technology enhances their effectiveness, ensuring greater transparency, accountability, and automation in vendor assessments. By reducing human error, enabling real-time monitoring, and validating compliance, blockchain strengthens the overall security and resilience of the third-party vendor ecosystem.
Deepti Gupta, Lavanya Elluri, Avi Jain, Shafika Showkat Moni, Ömer Aslan
IEEE Big Data2
2024 Automated Knowledge Framework for IoT Cybersecurity Compliance
abstract
Rapid expansion in the manufacture and use of Internet of Things (IoT) devices has introduced significant challenges in ensuring compliance with cybersecurity standards. To protect user data and privacy, all organizations providing IoT devices must adhere to complex guidelines such as the National Institute of Standards and Technology Inter agency Report (NIST IR) 8259, which defines essential cybersecurity guidelines for IoT manufacturers. However, interpreting and applying these rules from these guidelines and the privacy policies remains a significant challenge for companies. Thus, this project presents a novel approach to extract knowledge from NIST 8259 for creating semantically rich ontology mappings. Our ontology captures key compliance rules, which are stored in a knowledge graph (KG) that allows organizations to crosscheck and update privacy policy documents with ease. The KG also enables real-time querying using SPARQL and offers a transparent view of regulatory adherence for IoT manufacturers and users. By automating the process of verifying cybersecurity compliance, the framework ensures that companies remain aligned with NIST standards, eliminating manual checks and reducing the risk of non-compliance. We also demonstrate that compared to the baseline Large Language Models (LLMs), our proposed framework has more compliance accuracy, and is more efficient and scalable.
Ikechukwu Oranekwu, Lavanya Elluri, Gunjan Batra
IEEE Big Data2
2024 Towards Building Generalizable Models for Malware Detection
abstract
As malware evolves and adapts, traditional detection systems struggle to identify novel and unseen threats. This challenge highlights the critical need for building generalizable models that can effectively detect unknown malware types. In this paper, we propose meta-learning as a tool to explore the adaptability of malware detection systems. Our approach focuses on understanding how much model updating is required to extend detection capabilities to previously unseen malware samples. By leveraging meta-learning, we aim to identify the most useful data for building generalizable models, optimizing the trade-off between data efficiency and detection accuracy. Through this investigation, we seek to provide insights into creating more robust and adaptable malware detection systems capable of addressing the constantly evolving threat landscape. Our results suggest that, among three popular representations of malware data, the combination of static and dynamic analysis reports is the most helpful in building generalizable models.
Jihoon Shin, Emilia Rivas, Daniel Lucio, Aritran Piplai, Lavanya Elluri
IEEE Big Data5
2023 Privacy-Preserving Data Sharing in Agriculture: Enforcing Policy Rules for Secure and Confidential Data Synthesis
abstract
Big Data empowers the farming community with the information needed to optimize resource usage, increase productivity, and enhance the sustainability of agricultural practices. The use of Big Data in farming requires the collection and analysis of data from various sources such as sensors, satellites, and farmer surveys. While Big Data can provide the farming community with valuable insights and improve efficiency, there is significant concern regarding the security of this data as well as the privacy of the participants. Privacy regulations, such as the European Union’s General Data Protection Regulation (GDPR), the EU Code of Conduct on agricultural data sharing by contractual agreement, and the proposed EU AI law, have been created to address the issue of data privacy and provide specific guidelines on when and how data can be shared between organizations. To make confidential agricultural data widely available for Big Data analysis without violating the privacy of the data subjects, we consider privacy-preserving methods of data sharing in agriculture. Synthetic data that retains the statistical properties of the original data but does not include actual individuals’ information provides a suitable alternative to sharing sensitive datasets. Deep learning-based synthetic data generation has been proposed for privacy-preserving data sharing. However, there is a lack of compliance with documented data privacy policies in such privacy-preserving efforts. In this study, we propose a novel framework for enforcing privacy policy rules in privacy-preserving data generation algorithms. We explore several available agricultural codes of conduct, extract knowledge related to the privacy constraints in data, and use the extracted knowledge to define privacy bounds in a privacy-preserving generative model. We use our framework to generate synthetic agricultural data and present experimental results that demonstrate the utility of the synthetic dataset in downstream tasks. We also show that our framework can evade potential threats, such as re-identification and linkage issues, and secure data based on applicable regulatory policy rules.
Anantaa Kotal, Lavanya Elluri, Deepti Gupta, Varun Mandalapu, Anupam Joshi
IEEE Big Data2
2021 Trusted Compliance Enforcement Framework for Sharing Health Big Data
abstract
COVID pandemic management via contact tracing and vaccine distribution has resulted in a large volume and high velocity of Health-related data being collected and exchanged among various healthcare providers, regulatory and government agencies, and people. This unprecedented sharing of sensitive health-related Big Data has raised technical challenges of ensuring robust data exchange while adhering to security and privacy regulations. We have developed a semantically rich and trusted Compliance Enforcement Framework for sharing large velocity Health datasets. This framework, built using Semantic Web technologies, defines a Trust Score for each participant in the data exchange process and includes ontologies combined with policy reasoners that ensure data access complies with health regulations, like Health Insurance Portability and Accountability Act (HIPAA). We have validated our framework by applying it to the Centers for Disease Control and Prevention (CDC) Contact Tracing Use case by exchanging over 1 million synthetic contact tracing records. This paper presents our framework in detail, along with the validation results against Contact Tracing data exchange. This framework can be used by all entities who need to exchange high velocity-sensitive data while ensuring real-time compliance with data regulations.
Dae-young Kim, Lavanya Elluri, Karuna P. Joshi
IEEE BigData2
2020 Measuring Semantic Similarity across EU GDPR Regulation and Cloud Privacy Policies
abstract
Data protection authorities formulate policies and rules which the service providers have to comply with to ensure security and privacy when they perform Big Data analytics using users Personally Identifiable Information (PII). The knowledge contained in the data regulations and organizational privacy policies are typically maintained as short unstructured text in HTML or PDF formats. Hence it is an open challenge to determine the specific regulation rules that are being addressed by a provider's privacy policies. We have developed a semantically rich framework, using techniques from Semantic Web and Natural Language Processing, to extract and compare the context of a short text in real-time. This framework allows automated incremental text comparison and identifying context from short text policy documents by determining the semantic similarity score and extracting semantically similar key terms. Additionally, we also created a knowledge graph to store the semantically similar comparison results while evaluating our framework across EU GDPR and privacy policies of 20 organizations complying with this regulation associated with various categories apply to Big Data stored in the cloud. Our approach can be utilized by Big Data practitioners to update their referential documents regularly based on the authority documents.
Lavanya Elluri, Karuna P. Joshi, Anantaa Kotal
IEEE BigData1
2018 An Integrated Knowledge Graph to Automate GDPR and PCI DSS Compliance
abstract
Big data analytics related to consumer behavior, market analysis, opinions, and recommendation often deal with end user's derived and inferred data, along with the observed data. To ensure consumer data protection, rules defined by the European Union's General Data Protection Regulation (EU GDPR) must be adhered to by every organization using Personally Identifiable Information (PII) data for Big Data analysis. Similarly, Payment Card Industry Data Security Standard (PCI DSS) has policy guidelines specifically for organizations handling consumer's payment card data. Both data regulation policies are currently available only in textual format and require significant manual effort to ensure their compliance. We have developed an integrated, semantically rich Knowledge Graph (or Ontology) to represent the rules mandated by both PCI DSS and EU GDPR. In the Ontology, we have also identified the obligations defined in these regulations and related them with corresponding Cloud Security Alliance (CSA) controls. We have validated this Knowledge Graph against the data policies of major vendors that deal with Big Data. This Knowledge Graph that is available in the public domain can be used by Big Data practitioners to automate data protection compliance in their organization.
Lavanya Elluri, Ankur Nagar, Karuna P. Joshi
IEEE BigData1