EDBT 2026 Demo / reviewers in the wild / expert
Agnideven Palanisamy Sundar
dblp:275/8669
· DBLP profile ↗
13ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-7187-195XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 4 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Data-Free Backdoor Attack on Malware Image Classification ModelsabstractMachine learning-based image malware classifiers are increasingly vital for safeguarding enterprises and infrastructure. However, these models are vulnerable to backdoor attacks, where adversaries inject subtle triggers causing intentional misclassifications. Existing backdoor techniques typically require access to the original training data, a significant limitation in regulated domains where malware datasets are proprietary and confidential. In this work, we propose a novel data-free backdoor attack methodology that circumvents this constraint by utilizing surrogate datasets constructed from publicly available malware repositories. Our approach incorporates a logit-based dictionary filtering mechanism to select surrogate samples closely resembling the original training distribution, subsequently embedding stealthy visual triggers—such as checkerboard patterns and noise patches—into these samples. By fine-tuning a blackbox convolutional neural network (CNN) malware classifier with this poisoned surrogate data and employing a logit similarity-based loss function, we successfully implant robust backdoors. Experimental results demonstrate an attack success rate (ASR) of up to 99%, where we utilize the DIKE dataset to construct the surrogate dataset and target an existing CNN-based malware classifier architecture [2], with minimal degradation in clean sample classification accuracy. Our findings highlight a critical vulnerability in contemporary malware detection systems, emphasizing the necessity for enhanced defense mechanisms against data-free adversarial threats. The code and dataset are available at our GitHub repository1. Garvit Agarwal, Yousef Mohammed Y. Alomayri, Agnideven Palanisamy Sundar, Feng Li 0001 |
ICCCN | 3 |
| 2025 | Vigilante Defender: A Vaccination-based Defense Against Backdoor Attacks on 3D Point Clouds Using Particle Swarm OptimizationabstractBackdoor attacks on 3D Point Clouds (PCs) pose a serious threat by embedding hidden triggers into a subset of the training data. These triggers cause targeted misclassifications at inference time while leaving the model’s behavior unaffected in the absence of triggers, making them stealthy and difficult to detect. In distributed learning settings, where a central trainer aggregates data from multiple sources and offers only black-box access to the model, a single malicious contributor can compromise the model’s integrity if defenses are not in place. We propose a novel client-side defense that empowers individual contributors to act as vigilante defenders. By injecting benign ‘vaccination’ triggers—identified via Particle Swarm Optimization—into their local training data, defenders can proactively neutralize potential backdoors without prior knowledge of their location or structure. Experiments on standard benchmarks with PointNet and DGCNN show our method significantly reduces attack success while preserving classification accuracy, outperforming existing defenses. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Yucheng Xie, Ryan Hosler |
ICCCN | 1 |
| 2025 | Vaccination Against Backdoor Attacks on Federated Learning Systems
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao, Ryan Hosler |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2024 | Subjective Logic-based Decentralized Federated Learning for Non-IID DataabstractExisting Federated Learning (FL) methods are highly influenced by the training data distribution. In the single global model FL systems, users with highly non-IID data do not improve the global model, and neither does the global model work well on their local data distribution. Even with the clustering-based FL approaches, not all participants get clustered adequately enough for the models to fulfill their local demands. In this work, we design a modified subjective logic-based FL system utilizing the distribution-based similarity among users. Each participant has complete control over their own aggregated model, with handpicked contributions from other participants. The existing clustered model only satisfies a subset of clients, while our individual aggregated models satisfy all the clients. We design a decentralized FL approach, which functions without a trusted central server; the communication and computation overhead is distributed among the clients. We also develop a layer-wise secret-sharing scheme to amplify privacy. We experimentally show that our approach improves the performance of each participant’s aggregated model on their local distribution over the existing single global model and clustering-based approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ARES | 1 |
| 2024 | Graph Representation Learning on Novel Feature Based Graphs for Network Intrusion DetectionabstractNetwork Intrusions are an ever present threat in the modern age of instant transmission of data over the cyberspace. Ideally, an effective cybersecurity mechanism will detect an attack before it affects a given network. Hence, organizations utilize Network Intrusion Detection Systems (NIDS) to monitor incoming network traffic for all potential misuses. For this research, we present a novel method for aggregating network traffic into a graph for representation learning capable of outperforming existing NIDS in literature. We apply and validate our methods on numerous publically available network flow datasets for demonstrable and concrete performance evaluation. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 2 |
| 2024 | Toward Multimodal Vertical Federated Learning: A Traffic Analysis Case StudyabstractFederated Learning (FL) is an emerging subclass of Artificial Intelligence that decentralizes the learning process. Unlike the well-studied Horizontal Federated Learning (HFL), which requires the feature space of all participants to be the same, the newly emerging Vertical Federated Learning (VFL) allows participants to hold different features, provided the sample space is the same. This unique aspect enables VFL to incorporate features from different data modalities, a capability that has not yet been sufficiently explored. Currently, VFL researchers adapt datasets originally used for HFL by splitting the data vertically, whether it is text, tabular, or image data. In this paper, we extend the application of VFL to multimodal datasets, specifically in the field of Intelligent Transportation. We build models by combining local models from participants holding CCTV image datasets and Traffic flow tabular datasets. Due to the absence of suitable existing datasets, we introduce a new dataset, the INDOT traffic dataset, which also supports sequential training across time and distance. Our experiments demonstrate the efficiency of VFL in the multimodal traffic analysis scenario and aim to expand the scope of VFL research. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ICCCN | 1 |
| 2024 | Generating-Based Attacks to Online Social NetworksabstractOnline social network (OSN) privacy leakage problem addresses more and more users’ concerns. Studying the problem from attackers’ view could tell us how to prevent further data leakage. Currently, attackers mainly focus on mapping identities between their background knowledge and the published data to collect useful information. However, it becomes difficult to find the global optimal mapping strategy because of the complexity of the OSN data. This article proposes a novel generating-based attack on OSN data, no longer restricted to mapping-based information collection. Generally, the proposed scheme learns OSN properties from the attackers’ background knowledge and employs the knowledge to fill the unknown area in the published data. The proposed scheme employs a generative adversarial network to ensure the similarity between the generated graph and the published data. The conditional information is also added in the generation process such that the generated graph is restricted to the conditions under attackers’ background knowledge. Experimental results show that the proposed scheme successfully infer private information with real-world OSN datasets. Tianchong Gao, Yucheng Bian, Feng Li 0001, Agnideven Palanisamy Sundar |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2023 | Unsupervised Deep Learning for an Image Based Network Intrusion Detection SystemabstractThe most cost-effective method of cybersecurity is prevention. Therefore, organizations and individuals utilize Network Intrusion Detection Systems (NIDS) to inspect network flow for potential intrusions. However, Deep Learning based NIDS still struggle with high false alarm rates and detecting novel and unseen attacks. Therefore, in this paper, we propose a novel NIDS framework based on generating images from feature vectors and applying Unsupervised Deep Learning. For evaluation, we apply this method on four publicly available datasets and have demonstrated an accuracy improvement of up to 8.25 % when compared to Deep Learning models applied to the original feature vectors. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 2 |
| 2023 | TrustNetFL: Enhancing Federated Learning with Trusted Client Aggregation for Improved SecurityabstractFederated Learning (FL) has emerged as a promising approach for training machine learning models across individual devices while preserving data privacy. However, FL faces many challenges, specifically a vulnerability to adversarial attacks due to its strict adherence to ensuring individual client model and data privacy. To mitigate these issues, dynamic clipping techniques have been proposed which dynamically adjust the gradient clipping threshold during model aggregation. However, current iterations depend on specific and often intensive calculations to determine a clipping threshold which can lead to an over fitting to a specific dataset or attacker model. In this paper, we focus on improving the limitations of existing FL and dynamic clipping approaches by introducing a novel method that incorporates a group of trusted users during the aggregation of client models for a global update. By identifying and utilizing a network of trusted users, our defense method TrustNetFL enhances the robustness of model aggregation against malicious updates. This method not only maintains the model's performance but also improves its resistance to adversarial influences. We demonstrate the effectiveness of our defense through extensive experiments thus showcasing its superiority and simplicity in achieving enhanced model security in FL settings. Agnideven Palanisamy Sundar, Feng Li 0001 |
MobiHoc | 3 |
| 2022 | Distributed Swift and Stealthy Backdoor Attack on Federated LearningabstractFederated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
NAS | 1 |
| 2021 | Learning Discriminative Features for Adversarial RobustnessabstractDeep Learning models have shown incredible image classification capabilities that extend beyond humans. However, they remain susceptible to image perturbations that a human could not perceive. A slightly modified input, known as an Adversarial Example, will result in drastically different model behavior. The use of Adversarial Machine Learning to generate Adversarial Examples remains a security threat in the field of Deep Learning. Hence, defending against such attacks is a studied field of Deep Learning Security. In this paper, we present the Adversarial Robustness of discriminative loss functions. Such loss functions specialize in either inter-class or intra-class compactness. Therefore, generating an Adversarial Example should be more difficult since the decision barrier between different classes will be more significant. We conducted White-Box and Black-Box attacks on Deep Learning models trained with different discriminative loss functions to test this. Moreover, each discriminative loss function will be optimized with and without Adversarial Robustness in mind. From our experimentation, we found White-Box attacks to be effective against all models, even those trained for Adversarial Robustness, with varying degrees of effectiveness. However, state-of-the-art Deep Learning models, such as Arcface, will show significant Adversarial Robustness against Black-Box attacks while paired with adversarial defense methods. Moreover, by exploring Black-Box attacks, we demonstrate the transferability of Adversarial Examples while using surrogate models optimized with different discriminative loss functions. Ryan Hosler, Tyler Phillips 0001, Xiaoyuan Yu, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001 |
MSN | 4 |
| 2020 | Deep Dynamic Clustering of Spam Reviewers using Behavior-Anomaly-based Graph EmbeddingabstractOnline reviews have become an increasingly important factor in the purchase decision of a customer. However, many spammers write deceptive reviews to alter the credibility of a product/service. Often than not, these spammers exhibit group behavior, which can be exploited to differentiate them from authentic reviewers. Such behaviors are found in spammers working together as well as with crowdsourced review manipulators. The existing graph-based spammer detection approaches do not capture the dynamic and nonlinear relationship between the users. This paper aims to address this issue by introducing a method to use a deep structure embedding approach that preserves highly nonlinear structural information along with the dynamic aspects of user reviews to identify and cluster the spam users. It is worth mentioning that, in the experiment with real datasets, our method captures about 92% of all spam reviewers using an unsupervised learning approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
GLOBECOM | 1 |
| 2020 | Multi-Armed-Bandit-based Shilling Attack on Collaborative Filtering Recommender SystemsabstractCollaborative Filtering (CF) is a popular recommendation system that makes recommendations based on similar users’ preferences. Though it is widely used, CF is prone to Shilling/Profile Injection attacks, where fake profiles are injected into the CF system to alter its outcome. Most of the existing shilling attacks do not work on online systems and cannot be efficiently implemented in real-world applications. In this paper, we introduce an efficient Multi-Armed-Bandit-based reinforcement learning method to practically execute online shilling attacks. Our method works by reducing the uncertainty associated with the item selection process and finds the most optimal items to enhance attack reach. Such practical online attacks open new avenues for research in building more robust recommender systems. We treat the recommender system as a black box, making our method effective irrespective of the type of CF used. Finally, we also experimentally test our approach against popular state-of-the-art shilling attacks. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Qin Hu 0001, Tianchong Gao |
MASS | 1 |