EDBT 2026 Demo / reviewers in the wild / expert
Soumi Chatterjee
dblp:278/6791
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0002-2804-4120ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MIRAGE: Microarchitectural Footprints for Detecting Adversarial Attacks in One-Shot InferenceabstractAdversarial attacks pose severe threats to the integrity of deep neural networks (DNNs), especially in resource-constrained systems where traditional defenses are computationally expensive. While existing defenses in the black-box setting utilize hardware characteristics of adversarial attacks (like Hardware Performance Counter or HPC measurements), these defenses often involve repeating execution of multiple target model inferences to detect the attacks.In this work, we put forth a differing perspective: while detection strategies involving multiple target model inferences appear to be successful in isolation, they have unacceptable and inhibitory requirements. Precisely, we argue that these works require cleaning the micro-architectural state of hardware like the cache and the branch predictor after each inference. This in turn leads to performance degradation of not only the adversarial attack detector, but also of the overall system at large.In this work, we put forth a novel and lightweight detection strategy, MIRAGE, using HPCs that does not require cleaning the micro-architectural state of caches or branch predictors. We train a convolutional neural network (CNN) on these signals to classify inputs as benign or adversarial in a single shot, making our approach practical for online systems, while allowing full use of hardware optimizations for performance uplifts. Experiments on CIFAR-10 and MNIST datasets reveal that our methodology not only detects adversarial samples effectively with greater than 96% accuracy, but also imposes a minimal timing overhead of 60 ms and maintains high throughput. This makes our solution well-suited for embedded and edge-AI scenarios. Soumi Chatterjee, Debadrita Talapatra, Nimish Mishra, Aritra Hazra, Debdeep Mukhopadhyay |
ICCAD | 1 |
| 2025 | PLAnCo: Provable Learnability Analysis of Generic APUF Compositions Using Finite Automata Models
Soumi Chatterjee, Durba Chatterjee, Aritra Hazra, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Breaching the Gap: Modelling SRAM-PUFs via Side-Channel SignaturesabstractCryptographic systems employing SRAM-based Physically Unclonable Functions (SRAM-PUFs) rely on the assumption that modelling the internal PUF state is practically infeasible. This work investigates the modelling prowess of an adversary with access to side-channel information collected from similar, albeit not identical, devices to develop templates for leakages. To the best of our knowledge, this is the first work to show the modelling vulnerability of SRAM-PUFs to side-channel leakages by utilizing the correlation between power, electromagnetic signatures obtained from similar devices with identical patterns in their PUF responses. To evaluate the effectiveness of our attack, we perform extensive experiments on ATmega328P and demonstrate a maximum accuracy of 98.45% in the Hamming Weight ( <?TeX $\mathsf {HW}$?> Math 2 ) prediction of the PUF responses and <?TeX $96.91\%$?> Math 3 for the exact PUF response over 50 target devices. Our attack’s feasibility also extends to newer technology nodes, as validated on the 32-bit ARM Cortex M0+. Additionally, we augment the well-known helper data induced min-entropy loss to factor in the effect of side-channels and show that the residual entropy per byte of SRAM-PUF reduces significantly due to <?TeX $\mathsf {HW}$?> Math 4 leakage. Lastly, we propose an in-situ masking countermeasure using SRAM metastable cells, that effectively randomizes the side-channel signatures and reduces the <?TeX $\mathsf {HW}$?> Math 5 prediction accuracy to <?TeX $< 30\%$?> Math 6 . Kuheli Pratihar, Soumi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
ACM Great Lakes Symposium on VLSI | 2 |
| 2024 | Enhancing SRAM-Based PUF Reliability Through Machine Learning-Aided Calibration TechniquesabstractStatic random access memory (SRAM)-based physically unclonable functions (PUFs) utilize unpredictable start-up values (SUVs) for key generation, making them widely adopted in cryptographic systems. This unpredictability in SUVs is accompanied by device noise that escalates with process-voltage–temperature (PVT) variations, resulting in significant deviations from the golden response collected at ambient conditions, thereby increasing the bit-error-rate (BER) of the PUF responses. To reduce this high-$(\geq 15\%)$BER, either an involved error correcting code (ECC) circuitry with significant overhead is required, or more helper information needs to be generated at varying operating conditions, resulting in increased information leakage. We address this issue by proposing the first reported application of machine learning to recalibrate the responses by predicting the golden responses of the SRAM-based PUF (SRAM-PUF) at different operating conditions with high accuracy. Our recalibration technique is based on a novel collective decision that involves observing the neighborhood cells of the SRAM-PUF, as opposed to the traditional single-cell approach. By leveraging a memory map exhibiting a high correlation in ambient reliability amongst neighboring cells, we indirectly use the physical co-location of SRAM cells to assist neighborhood error prediction. It leads to efficient post-processing for SRAM-PUFs by using helper data generated at ambient conditions only while employing a fixed ECC designed for the same. Subsequently, to justify our claims and validate the efficacy of our proposed methodology, we demonstrate extensive experimentation results over multiple SRAM-PUF instances implemented on the Arduino UNO (an 8-bit microcontroller unit) and its scaled-up version, the Arduino Zero (a 32-bit microcontroller unit) boards, by varying supply voltages from 3.8 to 6.2 V and 7 to 12 V, respectively, and temperature from −25° to 70° C in both cases. Our observations show a vast drop in BER from 17.02% to$\approx 1\%$. Although worst-case conditions with both voltage and temperature variations at play resulted in a BER of 20%, using our proposed approach reduces it to$\approx 1{\text {-}} 2\%$, in turn demonstrating the high efficacy of our scheme. Kuheli Pratihar, Soumi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2020 | Machine Learning Assisted PUF Calibration for Trustworthy Proof of Sensor Data in IoTabstractRemote integrity verification plays a paramount role in resource-constraint devices owing to emerging applications such as Internet-of-Things (IoT), smart homes, e-health, and so on. The concept of Virtual Proof of Reality (VPoR) proposed by Rührmair et al. in 2015 has come up with a Sense-Prove-Validate framework for integrity checking of abundant data generated from billions of connected sensors. It leverages the unreliability factor of Physically Unclonable Functions (PUFs) with respect to ambient parameter variations such as temperature, supply voltages, and so on, and claims to prove the authenticity of the sensor data without using any explicit keys. The state-of-the-art authenticated sensing protocols majorly lack in limited authentications and huge storage overhead. These protocols also assume that the behaviour of the PUF instances varies unpredictably for different levels of ambient factors, which in turn makes them hard to go beyond the theoretical concept. We address these issues in this work 1 and propose a Machine Learning (ML) assisted PUF calibration scheme to predict the Challenge-Response Pair (CRP) behaviour of a PUF instance in a specific environment, given the CRP behaviour in a pivot environment. Here, we present a new class of authenticated sensing protocols where we leverage the beneficence of ML techniques to validate the authenticity and integrity of sensor data over ambient factor variations. The scheme also reduces the storage complexity of the verifier from O ( p * K * l * ( c + r )) to O ( p * l *( c + r )), where p is the number of PUF instances deployed in the framework, l is the number of challenge-response pairs used for authentication, c is the bit lengths of the challenge, r is the response bits of the PUF, and K is the number of levels of ambient factor variations. The scheme alleviates the issue of limited authentication as well, whereby every CRP is used only once for authentication and then deleted from the database. To validate the proposed protocol through actual experiments on FPGA, we propose 5-4 Double Arbiter PUF, which is an extension of Double Arbiter PUFs (DAPUFs) as this design is more suited for FPGA, and implement it on Xilinx Artix-7 FPGAs. We characterise the proposed PUF instance from −20° C to 80° C and use Random Forest --based ML technique to generate a soft model of the PUF instance. This model is further used by the verifier to authenticate the actual PUF circuit. According to the FPGA-based validation, the proposed protocol with DAPUF can be effectively used to authenticate sensor devices across wide variations of temperature values. Urbi Chatterjee, Soumi Chatterjee, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
ACM Trans. Design Autom. Electr. Syst. | 2 |