EDBT 2026 Demo / reviewers in the wild / expert
Jubayer Mahmod
dblp:240/6970 · also Md Jubayer al Mahmod
· DBLP profile ↗
8ranked-venue papers
7as first author
6since 2021 · last 2025
0000-0001-6535-182XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 first-author · 3 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Retain the Date: Detecting Recycled Chips in the Supply Chain Through SRAM's Data Retention BehaviorabstractThe life cycle of an Integrated Circuit (IC) involves a global network of stakeholders—designers, manufacturers, suppliers, and system integrators—introducing inherent opacity into the supply chain. This complexity is exacerbated by IC shortages, lingering effects of the global pandemic, and rising geopolitical tensions, all of which increase the risk of counterfeit infiltration. Among these, the most prevalent threat is the recycled chip: a used IC that is repackaged and sold as new. These recycled devices, while functionally equivalent, suffer from degraded reliability, which poses a serious challenge to system integrity and long-term dependability. We present Retain The Date (RTD), a hardware-overhead-free method for detecting recycled ICs that exploits Static Random Access Memory's (SRAM) data retention voltage to identify previously-used devices. RTD exploits an observation that SRAM—the most ubiquitous form of computer memory—retains data at just a fraction of its nominal voltage; and as SRAM cells age, statistical properties over whole-SRAM data retention voltage change in a way that differentiates it from the statistical properties of new devices. We design a variable-resolution time-analog of data retention voltage to measure aging-induced statistical asymmetry that forgoes specialized or expensive measurement equipment. RTD detects previously-used commercial ICs with 97% accuracy, preventing recycled counterfeits from affecting the availability of critical systems. Jubayer Mahmod, Matthew Hicks |
ACSAC | 1 |
| 2025 | PhasePrint: Exposing Cloud FPGA Fingerprints by Inducing Timing Faults at RuntimeabstractCloud FPGAs, with their scalable and flexible nature, are rapidly gaining traction as go-to hardware acceleration platforms for compute-intensive workloads. However, their increasing adoption introduces unique security challenges. The hardware-level access that FPGAs provide leads to many vulnerabilities, including the leakage of sensitive information through data remanence and the creation of analog-domain covert channels among users. A foundational requirement in these scenarios is the ability to target an individual FPGA; knowing this, cloud vendors prevent FPGA localization by restricting access to low-level information of the underlying hardware. Beyond aiding adversaries, FPGA localization enables defenders to strategically rotate FPGA usage, preventing prolonged exposure that can lead to confidential data leakage due to long-term data remanence. Jubayer Mahmod, Matthew Hicks |
ASPLOS (2) | 1 |
| 2024 | SRAM Imprinting for System Protection and DifferentiationabstractThe foundation of trusted computation depends on the ability to verify the authenticity of the underlying hardware. This need is further compounded by the presence of counterfeit components in the market, highlighting the necessity for pre-deployment and run-time chip identification techniques. Current solutions involve burning authentication information in physical fuses or creating a unique mask for each integrated circuit, which are either costly or susceptible to forgery. While many solutions have been proposed to prevent chip counterfeiting at design time, no accurate, reference-free, and cost-effective solutions exist for chip buyers to authenticate their purchases in the pre-deployment phase and enable software-level verification at runtime. The lack of industry-standard authentication methods forces chip buyers to either adopt expensive solutions, such as X-Ray imaging, or simply rely on blind faith. Jubayer Mahmod, Matthew Hicks |
AsiaCCS | 1 |
| 2024 | UnTrustZone: Systematic Accelerated Aging to Expose On-chip SecretsabstractAs technology scaling brings society closer to the vision of smart dust, system designers must address the threat of physical attacks. To address the threat of physical access to computing devices, defenders move secrets on the chip, keeping them out of reach of non-nation-state-level attackers. Modern systems allow hardware-backed security enclaves called Trusted Execution Environments (TEEs); TEEs add hardware-level protections on top of keeping secrets on chips that extend protection against privileged software and flaws within the untrusted parts of the software. While the best TEEs protect against concurrent and temporally recent attacks (e.g., the cold boot attack), we uncover a new threat to all forms of on-chip crypto: long-term data remanence.We show that the most ubiquitous form of on-chip memory, Static Random-Access Memory (SRAM), changes at the analog-domain-level in a data-dependent way as software uses it. Under normal conditions, these changes occur gradually over a device’s lifetime, but we show how an attacker can systematically accelerate this data imprinting on SRAM’s analog domain to effectively burn-in on-chip secrets. We then reveal the imprinted secrets through measurements of SRAM’s power-on state. We use this capability to demonstrate three attacks: one that reveals an AES key protected by TrustZone, proprietary firmware protected by TrustZone, and secrets stored in cache memory. Overall, we show that it is possible to imprint and exfiltrate secrets from a range of SRAM-based memories across 13 devices, from 8 manufacturers, produced across three decades—with up to 98% accuracy. To address this threat, we provide guidance to chip vendors and programmers on the defensive trade space. Jubayer Mahmod, Matthew Hicks |
SP | 1 |
| 2022 | SRAM has no chill: exploiting power domain separation to steal on-chip secretsabstractThe abundance of embedded systems and smart devices increases the risk of physical memory disclosure attacks. One such classic non-invasive attack exploits dynamic RAM's temperature-dependent ability to retain information across power cycles---known as a cold boot attack. When exposed to low temperatures, DRAM cells preserve their state for a short time without power, mimicking non-volatile memories in that time frame. Attackers exploit this physical phenomenon to gain access to a system's secrets, leading to data theft from encrypted storage. To prevent cold boot attacks, programmers hide secrets on-chip in Static Random-Access Memory (SRAM); by construction, on-chip SRAM is isolated from external probing and has little intrinsic capacitance, making it robust against cold boot attacks. Jubayer Mahmod, Matthew Hicks |
ASPLOS | 1 |
| 2022 | Invisible bits: hiding secret messages in SRAM's analog domainabstractElectronic devices are increasingly the subject of inspection by authorities. While encryption hides secret messages, it does not hide the transmission of those secret messages---in fact, it calls attention to them. Thus, an adversary, seeing encrypted data, turns to coercion to extract the credentials required to reveal the secret message. Steganographic techniques hide secret messages in plain sight, providing the user with plausible deniability, removing the threat of coercion. Jubayer Mahmod, Matthew Hicks |
ASPLOS | 1 |
| 2019 | Special Session: Delay Fault Testing - Present and FutureabstractThis article presents a brief survey of digital delay fault testing, which lists 100+ references on fault models, simulators, ATPG, DFT, and tools. Continuing studies are needed in this maturing field for new technologies, signal integrity, process variations, faster than critical path operation, asynchronous circuits, counterfeit ICs, and hardware Trojans. This information is compiled to provide direction to students, practicing engineers, and researchers alike. Jubayer Mahmod, Spencer K. Millican, Ujjwal Guin, Vishwani D. Agrawal |
VTS | 1 |
| 2019 | Low-Cost and Secure Firmware Obfuscation Method for Protecting Electronic Systems From CloningabstractThe continuous growth of the cloning of electronic devices poses a severe threat to our critical infrastructure that uses the Internet, as cloned devices can transmit secret information and cause security concerns. Cloned devices can also be unreliable as they may be manufactured with inferior quality materials, and they may have many defects as they may not be tested properly. It is thus extremely important to protect these electronic devices from cloning. An efficient way to prevent a device being cloned is to prevent the firmware from being copied because, without the proper firmware, the device will not function like the original. In this paper, we present a novel firmware obfuscation method without encrypting the entire memory. The firmware is obfuscated by swapping a subset of instructions. The instructions to be swapped are specifically chosen so that an attacker cannot discover their location. During operation, the hardware reconstructs the original program using a physically unclonable function-generated identifier and a small memory that stores the swapped instructions. An adversary cannot make a program work completely without knowing which instructions have been swapped, as the program will execute in the wrong sequence and produce the incorrect result. Our proposed solution requires only a small overhead to reconstruct the firmware, making it practical for devices with strict resource constraints. This solution also allows remote updates of new obfuscated firmware without any modification and is practical for the rising trend of ubiquitous computing. Benjamin Cyr, Jubayer Mahmod, Ujjwal Guin |
IEEE Internet Things J. | 2 |