Tushar M. Jois

dblp:285/5429 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-2740-8407ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 8 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Hands-On Platform for Medical Device Security Education
abstract
Modern medical devices integrate hardware and software, thereby expanding the attack surface and creating patient safety risks. Regulators set cybersecurity expectations, and international standards guide implementation. However, outcome-based, method-agnostic policies give manufacturers wide latitude, producing variability, ambiguity, and fragmented, non-reproducible practices in training and education. We address this gap with a reproducible, open-source reference platform that operationalizes security-by-design in alignment with current regulatory expectations and standards. We also report an initial pilot course using the platform as a foundation for consistent medical-device cybersecurity curricula.
Kaixin Du, Dibyajyoti Nath, Ramit Saraswat, Zhicheng Sun 0006, Michael Rushanan, Tushar M. Jois
SIGCSE (2)6
2025 Amigo: Secure Group Mesh Messaging in Realistic Protest Settings
abstract
During large-scale protests, a repressive government will often disable the Internet to thwart communication between protesters. Smartphone mesh networks, which route messages over short-range, possibly ephemeral, radio connections between nearby phones, allow protesters to communicate without relying on centralized Internet infrastructure. Unfortunately, prior work on providing secure communication in Internet shutdown settings fails to adequately consider protester needs. Previous attempts fail to support efficient private group communication (a crucial requirement for protests), and evaluate their solutions in network environments which fail to accurately capture link churn, physical spectrum contention, and the mobility models found in realistic protest settings. In this paper, we introduce Amigo, a novel mesh messaging system which supports group communication through a decentralized approach to continuous key agreement, and forwards messages using a novel routing protocol. Amigo is uniquely designed to handle the challenges of ad-hoc routing scenarios, where dynamic network topologies and node mobility make achieving key agreement nontrivial. Our extensive simulations reveal the poor scalability of prior approaches, the benefits of Amigo's protest-specific optimizations, and the challenges that still must be solved to scale secure mesh networks to protests with thousands of participants.
David Inyangson, Sarah Radway, Tushar M. Jois, Nelly Fazio, James W. Mickens
CCS3
2025 Engaging Students from Under-Represented Groups to Pursue Graduate School in Computer Science and Engineering
Ravindra Mangar, Cesar Arguello, David Inyangson, Tina Pavlovich, Karen Gareis, Tushar M. Jois
SIGCSE (1)6
2025 SoK: Security in the Inaudible World
abstract
Ultrasound and near-ultrasound acoustic frequencies offer non-intrusive and low-overhead mediums for data transmission protocols. These protocols and the technologies built upon them are becoming more prevalent, yet their security remains largely unexplored. We present the first systematization of ultrasound and near-ultrasound enabled applications, developing a unified threat model to address their security. Our analysis reveals misguided assumptions, missing protections, and the need for standardization. Through our taxonomy, we highlight key insights, future research directions, and propose a framework for securing these protocols.
David Inyangson, Aditya Gaur, Atheer Almogbil, Tushar M. Jois, Aviel D. Rubin
WISEC4
2024 Pulsar: Secure Steganography for Diffusion Models
abstract
Widespread efforts to subvert access to strong cryptography has renewed interest in steganography, the practice of embedding sensitive messages in mundane cover messages. Recent efforts at provably secure steganography have focused on text-based generative models and cannot support other types of models, such as diffusion models, which are used for high-quality image synthesis. In this work, we study securely embedding steganographic messages into the output of image diffusion models. We identify that the use of variance noise during image generation provides a suitable steganographic channel. We develop our construction, Pulsar, by building optimizations to make this channel practical for communication. Our implementation of Pulsar is capable of embedding ≈320--613 bytes (on average) into a single image without altering the distribution of the generated image, all in < 3 seconds of online time on a laptop. In addition, we discuss how the results of Pulsar can inform future research into diffusion models. Pulsar shows that diffusion models are a promising medium for steganography and censorship resistance.
Tushar M. Jois, Gabrielle Beck, Gabriel Kaptchuk
CCS1
2024 Root the (Ballot) Box: Designing Security Engineering Courses with E-Voting
abstract
Security courses often focus on individual attacks and defenses, and lack practical experience with secure system design. Consequently, such courses rarely address the societal implications of security breaches. We propose an inductive teaching approach to address these challenges in teaching security engineering. To this end, we design a course that focuses on electronic voting (e-voting) as a practical application of security engineering. Our course integrates relevant technical content through experiential learning, adversarial thinking skills through a group project, and societal factors with a student debate. Our approach has seen success in engaging students in both distance-learning and in-person teaching while preparing them for real-world security challenges.
Tushar M. Jois, Atheer Almogbil, Logan Kostick
SIGCSE (2)1
2024 Smart Use of Smart Devices in Your Home: A Smart Home Security and Privacy Workshop for the General Public
abstract
With 'smart' technology becoming more prevalent in homes, computing is increasingly embedded into everyday life. The benefits are well-advertised, but the risks associated with these technologies are not as clearly articulated. We aim to address this gap by educating community members on some of these risks, and providing actionable advice to mitigate risks. To this end, we describe our efforts to design and implement a hands-on workshop for the public on smart-home security and privacy.
Tushar M. Jois, Tina Pavlovich, Brigid M. McCarron, David Kotz, Timothy J. Pierson
SIGCSE (1)1
2024 SocIoTy: Practical Cryptography in Smart Home Contexts
abstract
Smartphones form an important source of trust in modern computing. But, while their mobility is convenient, smartphones can be stolen or seized, allowing an adversary to impersonate the user in their digital life: accessing the user's services and decrypting their sensitive files. With this in mind, we build SocIoTy, which leverages a user's existing IoT devices to add a context-sensitive layer of security for non-expert users. Instead of assuming the existence of dedicated hardware, SocIoTy re-uses the devices of a user's smart home to provide cryptographic services, which we term at-home cryptography. We show that at-home cryptography can be built from simple cryptographic primitives, and that our SocIoTy solution is able to provide useful functionalities, like two-factor authentication (2FA) and secure file storage, while protecting against powerful adversaries in this setting. We implement and evaluate SocIoTy in real-world use cases and provide microbenchmarks for individual cryptographic operations on realistic models of IoT devices. We also provide full benchmarks of an end-to-end deployment on a simulated smart home, using a smartphone and 9 IoT devices to generate and display 2FA one-time passwords in less than 200 milliseconds. SocIoTy is able to provide strong, practical cryptography while binding its execution to the smart home itself, all without requiring additional hardware.
Tushar M. Jois, Gabrielle Beck, Sofia Belikovetsky, Joseph Carrigan, Alishah Chator, Logan Kostick, Maximilian Zinkus, Gabriel Kaptchuk, Aviel D. Rubin
Proc. Priv. Enhancing Technol.1
2023 Towards Application-Driven IoT Education
abstract
The increased popularity of Internet of Things (IoT) systems and platforms in various engineering and science fields has made training practitioners in IoT a necessity. At the same time, the active evolution of research on IoT has made available a wealth of educational resources like evaluation and development kits, web development frameworks, single-board microcontrollers and minicomputers, and hands-on books and courseware. The diversity of applications served by IoT from one side and the abundant educational resources from the other side raise questions on how best to train practitioners in IoT. In this paper, we introduce a new approach in designing and teaching a course on IoT: application-driven IoT education. The aim of this course design is to teach IoT through understanding a target application in depth. Rather than introducing IoT conceptually over several weeks before linking the theoretical concepts to an application, in an application-driven course the audience instead first learns a real-world application; then, students utilize the different components of an IoT platform (sensors, actuators, connectivity technologies, web interface, and cloud computing) to realize the application. To better demonstrate the concept, we use the application-driven approach to design a “smart home security and privacy” IoT course. This work is based on a combined experience of three years of teaching and researching IoT at both the American University of Kuwait and Johns Hopkins University.
Mounib Khanafer, Tushar M. Jois
EDUCON2
2023 Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning
Jonathan Prokos, Neil Fendley, Matthew Green 0001, Roei Schuster, Eran Tromer, Tushar M. Jois, Yinzhi Cao
USENIX Security Symposium6
2022 SoK: Cryptographic Confidentiality of Data on Mobile Devices
abstract
Mobile devices have become an indispensable component of modern life. Their high storage capacity gives these devices the capability to store vast amounts of sensitive personal data, which makes them a high-value target: these devices are routinely stolen by criminals for data theft, and are increasingly viewed by law enforcement agencies as a valuable source of forensic data. Over the past several years, providers have deployed a number of advanced cryptographic features intended to protect data on mobile devices, even in the strong setting where an attacker has physical access to a device. Many of these techniques draw from the research literature, but have been adapted to this entirely new problem setting.
Maximilian Zinkus, Tushar M. Jois, Matthew Green 0001
Proc. Priv. Enhancing Technol.2
2021 Meteor: Cryptographically Secure Steganography for Realistic Distributions
abstract
Despite a long history of research and wide-spread applications to censorship resistant systems, practical steganographic systems capable of embedding messages into realistic communication distributions, like text, do not exist. We identify two primary impediments to deploying universal steganography: (1) prior work leaves the difficult problem of finding samplers for non-trivial distributions unaddressed, and (2) prior constructions have impractical minimum entropy requirements. We investigate using generative models as steganographic samplers, as they represent the best known technique for approximating human communication. Additionally, we study methods to overcome the entropy requirement, including evaluating existing techniques and designing a new steganographic protocol, called Meteor. The resulting protocols are provably indistinguishable from honest model output and represent an important step towards practical steganographic communication for mundane communication channels. We implement Meteor and evaluate it on multiple computation environments with multiple generative models.
Gabriel Kaptchuk, Tushar M. Jois, Matthew Green 0001, Aviel D. Rubin
CCS2
2021 DOVE: A Data-Oblivious Virtual Environment
Hyun Bin Lee, Tushar M. Jois, Christopher W. Fletcher, Carl A. Gunter
NDSS2