Hari Venugopalan

dblp:257/7230 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-7607-7256ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 GlucOS: Security, correctness, and simplicity for automated insulin delivery
abstract
We present GlucOS, a novel system for trustworthy automated insulin delivery. Fundamentally, this paper is about a system we designed, implemented, and deployed on real humans and the lessons learned from our experiences. GlucOS introduces a novel architecture that allows users to personalize diabetes management using any predictive model (including ML) for insulin dosing while simultaneously protecting them against malicious models. We also introduce a novel holistic security mechanism that adapts to unprecedented changes to human physiology. We use formal methods to prove correctness of critical components and incorporate humans as part of our defensive strategy. Our evaluation includes both a real-world deployment with seven individuals and results from simulation to show that our techniques generalize. We highlight that our results are not from a lab study, with people using GlucOS to manage Type 1 Diabetes in their daily lives. Our results show that GlucOS maintains safety and improves glucose control even under attack conditions. This work demonstrates the potential for secure, personalized, automated healthcare systems. Our entire source code is available at this link.
Hari Venugopalan, Shreyas Madhav Ambattur Vijayanand, Caleb Stanford, Stephanie Crossen, Samuel T. King
MobiSys1
2025 FP-Rowhammer: DRAM-Based Device Fingerprinting
Hari Venugopalan, Kaustav Goswami 0002, Zain ul Abi Din, Jason Lowe-Power, Samuel T. King, Zubair Shafiq
AsiaCCS1
2025 FP-Inconsistent: Measurement and Analysis of Fingerprint Inconsistencies in Evasive Bot Traffic
abstract
Browser fingerprinting is used for bot detection. In response, bots have started altering their fingerprints to evade detection. We conduct the first large-scale evaluation to study whether and how altering fingerprints helps bots evade detection. To systematically investigate such evasive bots, we deploy a honey site that includes two anti-bot services (DataDome and BotD) and solicit bot traffic from 20 different bot services that purport to sell ''realistic and undetectable traffic.'' Across half a million requests recorded on our honey site, we find an average evasion rate of 52.93% against DataDome and 44.56% evasion rate against BotD. Our analysis of fingerprint attributes of evasive bots shows that they indeed alter their fingerprints. Moreover, we find that the attributes of these altered fingerprints are often inconsistent with each other. We propose FP-Inconsistent, a data-driven approach to detect such inconsistencies across space (two attributes in a given browser fingerprint) and time (a single attribute at two different points in time). Our evaluation shows that our approach can reduce the evasion rate of evasive bots by 44.95%-48.11% while maintaining a true negative rate of 96.84% on traffic from real users.
Hari Venugopalan, Shaoor Munir, S. Shuaib Ahmed, Tangbaihe Wang, Samuel T. King, Zubair Shafiq
IMC1
2021 Doing good by fighting fraud: Ethical anti-fraud systems for mobile payments
abstract
App builders commonly use security challenges, a form of step-up authentication, to add security to their apps. However, the ethical implications of this type of architecture has not been studied previously.In this paper, we present a large-scale measurement study of running an existing anti-fraud security challenge, Boxer, in real apps running on mobile devices. We find that although Boxer does work well overall, it is unable to scan effectively on devices that run its machine learning models at less than one frame per second (FPS), blocking users who use inexpensive devices.With the insights from our study, we design Daredevil, a new anti-fraud system for scanning payment cards that works well across the broad range of performance characteristics and hardware configurations found on modern mobile devices. Daredevil reduces the number of devices that run at less than one FPS by an order of magnitude compared to Boxer, providing a more equitable system for fighting fraud.In total, we collect data from 5,085,444 real devices spread across 496 real apps running production software and interacting with real users.
Zain ul Abi Din, Hari Venugopalan, Adam Wushensky, Steven Liu, Samuel T. King
SP2
2020 Boxer: Preventing fraud by scanning credit cards
Zain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li, Weisu Yin, Haohui Mai, Yong Jae Lee, Steven Liu, Samuel T. King
USENIX Security Symposium2
2019 MultiLock: biometric-based graded authentication for mobile devices
abstract
While traditionally smartphones have relied on methods such as a passcode or pattern-based authentication, biometric authentication techniques are gaining popularity. However current biometric methods are heavily dependent on various environmental factors. For example, face authentication methods depend on lighting conditions, camera shake and picture framing, while fingerprint scanning relies on finger placement. All of these variables can result in these systems becoming time-consuming for the user to use. To remedy these problems, we propose MultiLock, a passive, graded authentication system, which uses face authentication as a case study to propose a system that gives users access to their devices without requiring them to manually interact with the lock screen. Multi-Lock allows a user to categorize applications into various security bins based on their sensitivity. By doing so MultiLock can grant users access to different sensitivity applications, based on varying degrees of sureness that the device is being used by its rightful owner. Thus, allowing the device to be used even in adverse lighting conditions without hampering user experience. In our tests, MultiLock was able to grant access to users for 88% of the interactions on average, while passively running in the background. While we use face authentication as an example to demonstrate and propose MultiLock, our system can be used with any confidence based biometric system.
Shravan Aras, Chris Gniady, Hari Venugopalan
MobiQuitous3