Sanket Shukla

dblp:257/9771 · DBLP profile ↗
← Back
13ranked-venue papers
8as first author
11since 2021 · last 2024
0000-0002-1861-249XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 11 · 6 first-author · 11 since 2021Artificial intelligence and machine learning · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Resource- and Workload-aware Malware Detection through Distributed Computing in IoT Networks
abstract
Networked IoT systems have emerged in recent years to facilitate seamless connectivity, portability, and smarter functionality. Despite lending a plethora of benefits, IoT devices are exploited by adversaries for various illicit purposes. IoT systems are a popular target due to the lack of security traits in the design, and minimal available computational and storage resources on the devices. Among multiple threats, malicious applications a.k.a malware are seen as a pivotal security threat on IoT devices and networks. Many malware detection techniques have been proposed recently. However, the existing techniques focus either on general-purpose systems or assume the availability of abundant resources at their disposal for malware detection. However, for IoT devices, the ongoing workloads such as sensing, and on-device computations further minimize the available resources for malware detection. We propose a novel resource- and workload-aware malware detection integrated with distributed computing for IoT networked systems to address these challenges. The device analyzes the available resources for malware detection using a lightweight regression model. Depending on the available resources, ongoing workload executions, and communication cost the malware detection task is either performed on-device or offloaded to neighboring IoT nodes with sufficient resources. To ensure data integrity and user privacy, instead of offloading the whole malware detection, the classifier is partitioned and distributed over multiple nodes and further integrated at the parent node for malware detection. Experimental analysis shows that the proposed technique can achieve a speed-up of $9.8 \times$ compared to on-device inference while maintaining a malware detection accuracy of 96.7%.
Sreenitha Kasarapu, Sanket Shukla, Sai Manoj Pudukotai Dinakarrao
ASPDAC2
2024 Energy Harvesting-assisted Ultra-Low-Power Processing-in-Memory Accelerator for ML Applications
abstract
The proliferation of Internet of Things (IoT) and edge computing devices has become an essential aspect of our daily routines. Particularly, the rise of wearable technology like smartwatches, health trackers, and smart glasses has contributed significantly to their popularity. These gadgets are equipped with diverse sensors that enable researchers and manufacturers to collect user data. Subsequently, this data undergoes processing through on-device Machine Learning (ML) algorithms, enhancing user interactions. However, implementing ML algorithms on these compact IoTs and edge devices consumes substantial power and energy. It’s crucial to recognize that these devices operate within strict energy and power constraints. Thus, optimizing battery usage is paramount for prolonging a device’s lifespan. Therefore, we propose a Processing-In-Memory (PIM) architecture utilizing Look-up-Table (LUT) based processing for improved performance and energy efficiency. To further enhance energy efficiency in this work we introduce a framework that efficiently utilizes kinetic energy harvesting to intermittently support ML computations/tasks, thereby alleviating the load on the device’s built-in battery. By offloading ML computations to the PIM architecture, the framework reduces the reliance on the device’s internal battery power, optimizing the use of harvested kinetic energy and extending battery life. Furthermore, PIM architecture facilitates seamless integration of harvested kinetic energy, ensuring efficient ML computations with minimal energy consumption. This integrated approach presents a compelling solution for energy management in IoT and edge-based applications, as evidenced by experiments and analysis showing significant reductions in overall energy usage. We evaluated the proposed Energy Harvesting-assisted PIM architecture on various CNN architectures, such as LeNet, AlexNet, ResNet -18, -34, -50.
Sanket Shukla, Sathwika Bavikadi, Sai Manoj Pudukotai Dinakarrao
ACM Great Lakes Symposium on VLSI1
2024 Energy Harvesting-Supported Efficient Low-Power ML Processing with Adaptive Checkpointing and Intermittent Computing
abstract
The rise of ultra-low-power embedded processors has led to increased use of energy harvesting devices (EHDs), providing portability and extended lifespans, but also presenting challenges due to sporadic ambient energy and limited storage. This paper introduces "Micro-Controller Unit - Early Exit Neural Network" MCU-EENet, a framework utilizing kinetic energy harvesting to support machine learning tasks intermittently with early exits. The intermittent nature of ambient energy can lead to potential program interruptions, necessitating efficient state retention techniques within MCU-EENet. We propose "SmartCheck," a memory-optimized runtime checkpointing technique integrated with MCU-EENet to manage and utilize harvested energy efficiently. Through extensive experimentation, our framework demonstrates significant energy savings and performance enhancements, making it a promising solution for energy-constrained environments. Experimental results show a ~ 30% to 50% reduction in energy footprint and a 1.2X to 2.4X speed improvement over existing checkpointing methods.
Sanket Shukla, Sai Manoj Pudukotai Dinakarrao
ISLPED1
2023 Federated Learning with Heterogeneous Models for On-device Malware Detection in IoT Networks
abstract
IoT devices have been widely deployed in many applications to facilitate smart technology, increased portability, and seamless connectivity. Despite being widely adopted, security in IoT devices is often considered an afterthought due to resource and cost constraints. Among multiple security threats, malware attacks are observed to be a pivotal threat to IoT devices. Considering the spread of IoT devices and the threats they experience over time, deploying a static malware detector trained offline seems ineffective. On the other hand, on-device learning is an expensive or infeasible option due to the limited available resources on IoT devices. To overcome these challenges, this work employs ‘Federated Learning’ (FL) which enables timely updates to the malware detection models for increased security while mitigating the high communication or data storage overhead of centralized cloud approaches. Federated learning allows training machine learning models with decentralized data while preserving its privacy by design. However, one of the challenges with the FL is that the on-device models are required to be homogeneous, which may not be true in the case of networked IoT systems. As a panacea, we introduce a methodology to unify the models in the cloud with minimal overheads and an impact on on-device malware detection. We evaluate the proposed technique against homogeneous models in networked IoT systems encompassing Raspberry Pi devices. The experimental results and system efficiency analysis indicate that end-to-end training time is just 1.12× higher than traditional FL, testing latency is 1.63× faster, and malware detection performance is improved by 7% to 13% for resource-constrained IoT devices.
Sanket Shukla, Setareh Rafatirad, Houman Homayoun, Sai Manoj Pudukotai Dinakarrao
DATE1
2023 Resource- and Workload-Aware Model Parallelism-Inspired Novel Malware Detection for IoT Devices
abstract
The wide adoption of Internet of Things (IoT) devices has led to better connectivity along with seamless communication and smart computation capabilities across the network. Despite being deployed widely across the globe, IoT devices are prominently exploited for security vulnerabilities due to the lack of inherent security measures. Among multiple threats, malicious applications also known as malware is a pivotal security threat for IoT devices. Lack of security traits and limited resources are the primary hindrances for the adoption of existing malware detection techniques in IoT devices. Furthermore, the existing techniques assume the availability of all the device resources for malware detection. However, for IoT devices deployed for critical real-world applications, the available on-device resources for a given task, including malware detection are minimal compared to the overall available resources. To address this primary challenge, this work introduces a novel resource- and workload-aware model-parallelism-inspired malware detection for IoT devices. The device first analyzes the available resources for malware detection using a lightweight regression model. Depending on the available resources, ongoing workload executions, and communication costs, the malware detection task is either performed on-device or offloaded to neighboring IoT nodes with sufficient resources. To ensure data integrity and user privacy, instead of offloading the whole malware detection, the classifier is partitioned and distributed over multiple nodes and further integrated at the parent node for malware detection. Experimental analysis shows that the proposed technique can achieve a speed-up of$9.8\times $compared to on-device inference while maintaining a malware detection accuracy of 96.7%.
Sreenitha Kasarapu, Sanket Shukla, Sai Manoj Pudukotai Dinakarrao
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2022 CAD-FSL: Code-Aware Data Generation based Few-Shot Learning for Efficient Malware Detection
abstract
One of the pivotal security threats for embedded computing systems is malicious softwarea.k.a malware. With efficiency and efficacy, Machine Learning (ML) has been widely adopted for malware detection in recent times. Despite being efficient, the existing techniques require updating the ML model frequently with newer benign and malware samples for training and modeling an efficient malware detector. Furthermore, such constraints limit the detection of emerging malware samples due to the lack of sufficient malware samples required for efficient training. To address such concerns, we introduce a code-aware data generation-based few-shot learning technique. CAD-FSL generates multiple mutated samples of the limitedly seen malware for efficient malware detection. Loss minimization ensures that the generated samples closely mimic the limitedly seen malware, restore malware functionality and mitigate the impractical samples. Such developed synthetic malware is incorporated into the training set to formulate the model that can efficiently detect the emerging malware despite having limited (few-shot) exposure. The experimental results demonstrate that with the proposed "Code-Aware Data Generation" technique, we detect malware with 90% accuracy, which is approximately 9% higher while training classifiers with only limitedly available training data.
Sreenitha Kasarapu, Sanket Shukla, Rakibul Hassan, Avesta Sasan, Houman Homayoun, Sai Manoj Pudukotai Dinakarrao
ACM Great Lakes Symposium on VLSI2
2022 RAFeL - Robust and Data-Aware Federated Learning-inspired Malware Detection in Internet-of-Things (IoT) Networks
abstract
Federated Learning (FL) is a decentralized machine learning in which the training data is distributed on the Internet-of-Things (IoT) devices and learns a shared global model by aggregating local updates. However, the training data can be poisoned and manipulated by malicious adversaries, contaminating locally computed updates. To prevent this, detecting malicious IoT devices is very important. Since the local updates are large because of the high volume of data, minimizing the communication overhead is also necessary. This paper proposes a "RAFeL" framework, comprising of two techniques to tackle the above issues, (1) a robust defense technique and (2) a "Performance-aware bit-wise encoding" technique. "Robust and Active Protection with Intelligent Defense (RAPID)" is a defense system that detects malicious IoT devices and restricts the participation of the contaminated local updates computed by these malicious devices. To minimize communication cost, "Performance-aware bit-wise encoding" selects the appropriate encoding scheme for individual split bits based on their significance and effect on FL performance. The results illustrate that the proposed framework shows a 1.2-1.8x higher compression rate than lossy and lossless encoding techniques and has an average accuracy drop of 3% to 10% even with a fraction of malicious devices.
Sanket Shukla, Gaurav Kolhe, Houman Homayoun, Setareh Rafatirad, Sai Manoj Pudukotai Dinakarrao
ACM Great Lakes Symposium on VLSI1
2022 Iron-Dome: Securing IoT Networked Systems at Runtime by Network and Device Characteristics to Confine Malware Epidemics
abstract
The rapid growth of IoT networks presents an enlarged "attack space" for the adversary and poses significant security risks on a large scale. A single device in a network that is compromised under the influence of a malware attack, has the potential to spread malware across the network. This leads to a plethora of attacks, including DoS and ceasing the network functionality. Given the scale of IoT networks and the connectivity among the devices, mere detection and quarantining of malware in IoT networks does not limit the propagation of malware in IoT networks. This work proposes an integrated defense, termed as "IRON-DOME", comprising of (1) an on-device application analyzer: Image-based Malware detector that utilizes grayscale images of executables, (2) Device dynamic behavior analysis: Reliable extraction and dynamic analysis of malware Hardware Performance Counter (HPC) values; and (3) Device communication trait analyzer: Uses network packet data analysis to confine and propagate malware in the IoT network. The proposed solution yields: (1) a runtime malware detection accuracy of 93% within 19 ns, (2) is resource and power efficient; it consumes 30% fewer resources and 40% less power than state-of-the art defense techniques.
Sanket Shukla, Abhijitt Dhavlle, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Setareh Rafatirad
ICCD1
2021 On-device Malware Detection using Performance-Aware and Robust Collaborative Learning
abstract
The proliferation of the Internet-of-Things (IoT) devices has facilitated smart connectivity and enhanced computational capabilities. Lack of proper security protocols in such devices makes them vulnerable to cyber threats, especially malware attacks. Given the diversity and sophistication in malware samples, detecting them using traditional vendor database-based signature matching techniques is inefficient. This paper presents a collaborative machine learning (ML)-based malware detection framework. We introduce a) performance-aware precision-scaled federated learning (FL) to minimize the communication overheads with minimal device-level computations; and (2) a Robust and Active Protection with Intelligent Defense strategy against malicious activity (RAPID) at the device and network-level due to malware and other cyber-attacks. Deploying FL facilitates detecting malware attacks through collaborative learning and prevents data sharing, thus ensuring data security and privacy. RAPID denies the illegitimate user and aids in developing an effective collaborative malware detection model. A comprehensive analysis, results, and performance of the proposed technique are presented along with the communication overheads. An average accuracy of 94% is obtained with the proposed technique with 15% communication overhead, indicating 19% better performance than state-of-the-art techniques. Furthermore, the minimum accuracy drop of a model trained using RAPID is only 3% when 10% of devices are adversarial and 16% even when 40% of devices are adversarial.
Sanket Shukla, Sai Manoj Pudukotai Dinakarrao, Gaurav Kolhe, Setareh Rafatirad
DAC1
2021 HMD-Hardener: Adversarially Robust and Efficient Hardware-Assisted Runtime Malware Detection
abstract
To overcome the performance overheads incurred by the traditional software-based malware detection techniques, machine learning (ML) based Hardware-assisted Malware Detection (HMD) has emerged as a panacea to detect malicious applications and provide security. HMD primarily relies on the generated low-level microarchitectural events captured through Hardware Performance Counters (HPCs). This work proposes an adversarial attack on the HMD systems to tamper the security by introducing perturbations in performance counter traces with an adversarial sample generator application. To craft the attack, we first deploy an adversarial sample predictor to predict the adversarial HPC pattern for a given application to be misclassified by the deployed ML classifier in the HMD. Further, as the attacker has no direct access to manipulate the HPCs generated during runtime, based on the adversarial sample predictor's output, devise an adversarial sample generator wrapped around the victim application to produce HPC patterns similar to the adversarial predictor's estimated trace. With the proposed attack, malware detection accuracy is reduced to 18.1% from 82%. To render the HMD robust to such attacks, we further propose adversarially training the HMD to demonstrate that hardening can render HMD resilient against attacks; the detection accuracy post hardening raises to 81.2%.
Abhijitt Dhavlle, Sanket Shukla, Setareh Rafatirad, Houman Homayoun, Sai Manoj Pudukotai Dinakarrao
DATE2
2021 Adversarial Attack Mitigation Approaches Using RRAM-Neuromorphic Architectures
abstract
The rising trend and advancements in machine learning has resulted into its numerous applications in the field of computer vision, pattern recognition to providing security to hardware devices. Eventhough the proven achievements showcased by advancement in machine learning, one can exploit the vulnerabilities in those techniques by feeding adversaries. Adversarial samples are generated by well crafting and adding perturbations to the normal input samples. There exists majority of the software based adversarial attacks and defenses. In this paper, we demonstrate the effects of adversarial attacks on a reconfigurable RRAM-neuromorphic architecture with different learning algorithms and device characteristics. We also propose an integrated solution for mitigating the effects of the adversarial attack using the reconfigurable RRAM architecture.
Siddharth Barve, Sanket Shukla, Sai Manoj Pudukotai Dinakarrao, Rashmi Jha
ACM Great Lakes Symposium on VLSI2
2019 RNN-Based Classifier to Detect Stealthy Malware using Localized Features and Complex Symbolic Sequence
abstract
Malware detection and classification has enticed a lot of researchers in the past decades. Several mechanisms based on machine learning (ML), computer vision and deep learning have been deployed to this task and have achieved considerable results. However, advanced malware (stealthy malware) generated using various obfuscation techniques like code relocation, code transposition, polymorphism and mutation thwart the detection. In this paper, we propose a two-pronged technique which can efficiently detect both traditional and stealthy malware. Firstly, we extract the microarchitectural traces procured while executing the application, which are fed to the traditional ML classifiers to identify malware spawned as separate thread. In parallel, for an efficient stealthy malware detection, we instigate an automated localized feature extraction technique that will be used as an input to recurrent neural networks (RNNs) for classification. We have tested the proposed mechanism rigorously on stealthy malware created using code relocation obfuscation technique. With the proposed two-pronged approach, an accuracy of 94%, precision of 93%, recall score of 96% and F-1 score of 94% is achieved. Furthermore, the proposed technique attains up to 11% higher on average detection accuracy and precision, along with 24% higher on average recall and F-1 score as compared to the CNN-based sequence classification and hidden Markov model (HMM) based approaches in detecting stealthy malware.
Sanket Shukla, Gaurav Kolhe, Sai Manoj Pudukotai Dinakarrao, Setareh Rafatirad
ICMLA1
2019 Stealthy Malware Detection using RNN-Based Automated Localized Feature Extraction and Classifier
abstract
Malware analysis, detection and classification has allured a lot of researchers in the past few years. Numerous methods based on machine learning (ML), computer vision and deep learning have been applied to this task and have accomplished some pragmatic results. One of the basic assumption of these works is that malware is spawned as a separate thread and the distinguishing features can be extracted in a "clean" manner irrespective of the malware obfuscation deployed. However, this assumption does not hold true for the advanced malware obfuscation techniques such as code relocation, mutation and polymorphism. Stealthy malware is a malware created by embedding the malware in a benign application through advanced obfuscation strategies to thwart the detection. To perform efficient malware detection for traditional and stealthy malware alike, we propose a two-pronged approach. Firstly, we extract the microarchitectural traces obtained while executing the application, which are fed to the traditional ML classifiers to detect malware spawned as separate thread. In parallel, for an efficient stealthy malware detection, we introduce an automated localized feature extraction technique that will be further processed using the recurrent neural networks (RNNs) for classification. To perform this, we translate the application binaries into images and further convert it into sequences and extract local features for stealthy malware detection. With the proposed two-pronged approach, an accuracy of 94% and nearly 90% is achieved in detecting normal and stealthy malware created through code relocation obfuscation technique. Furthermore, the proposed approach achieves up to 11% higher detection accuracy compared to the CNN-based sequence classification and hidden Markov model (HMM) based approaches in detecting stealthy malware.
Sanket Shukla, Gaurav Kolhe, Sai Manoj Pudukotai Dinakarrao, Setareh Rafatirad
ICTAI1