EDBT 2026 Demo / reviewers in the wild / expert
Radha Poovendran
dblp:29/5044
· DBLP profile ↗
123ranked-venue papers
6as first author
36since 2021 · last 2026
0000-0003-0269-8097ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 38 · 1 first-author · 2 since 2021Security and privacy · 27 · 1 first-author · 15 since 2021Artificial intelligence and machine learning · 19 · 15 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 2 first-author · 3 since 2021Systems, architecture and hardware · 9 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 2 since 2021Theory of computation · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BadScientist: Can a Research Agent Write Convincing but Unsound Papers that Fool LLM Reviewers?abstractFengqing Jiang, Yichen Feng, Yuetai Li, Luyao Niu, Basel Alomair, Radha Poovendran. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Fengqing Jiang, Yichen Feng, Yuetai Li, Luyao Niu, Basel Alomair, Radha Poovendran |
ACL (1) | 6 |
| 2026 | Temporal Sampling for Forgotten Reasoning in LLMsabstractYuetai Li, Zhangchen Xu, Fengqing Jiang, Bhaskar Ramasubramanian, Luyao Niu, Bill Yuchen Lin, Xiang Yue, Radha Poovendran. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Yuetai Li, Zhangchen Xu, Fengqing Jiang, Bhaskar Ramasubramanian, Luyao Niu, Bill Y. Lin, Xiang Yue, Radha Poovendran |
ACL (1) | 8 |
| 2026 | Electric Vehicles Security and Privacy: Challenges, Solutions, and Future NeedsabstractElectric Vehicles (EVs) share common technologies with classic fossil-fueled cars, but they also employ novel technologies and components (e.g., Charging System and Battery Management System) that create an unexplored attack surface for malicious users. Although several contributions in the literature explored cybersecurity aspects of particular components of the EV ecosystem (e.g., charging infrastructure), there is still no contribution to the holistic cybersecurity of EVs and their related technologies from a Cyber-Physical System (CPS) perspective. In this article, we provide the first in-depth study of the Security and Privacy (S&P) threats associated with the EV ecosystem. We analyze the threats associated with both the EV and the different charging solutions. Focusing on the CPS paradigm, we provide a detailed analysis of all the processes that an attacker might exploit to affect the S&P of both drivers and the infrastructure. To address the highlighted threats, we present possible solutions that might be implemented. We also provide an overview of possible future directions to guarantee the S&P of the EV ecosystem. Based on our analysis, we stress the need for EV-specific cybersecurity solutions to help both vehicle owners and infrastructure deployers securing the EV ecosystem. Alessandro Brighente, Mauro Conti, Denis Donadel, Radha Poovendran, Federico Turrin, Jianjing Zhou |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2025 | ChatBug: A Common Vulnerability of Aligned LLMs Induced by Chat TemplatesabstractLarge language models (LLMs) are expected to follow instructions from users and engage in conversations. Techniques to enhance LLMs' instruction-following capabilities typically fine-tune them using data structured according to a predefined chat template. Although chat templates are shown to be effective in optimizing LLM performance, their impact on safety alignment of LLMs has been less understood, which is crucial for deploying LLMs safely at scale. In this paper, we investigate how chat templates affect safety alignment of LLMs. We identify a common vulnerability, named ChatBug, that is introduced by chat templates. Our key insight to identify ChatBug is that the chat templates provide a rigid format that need to be followed by LLMs, but not by users. Hence, a malicious user may not necessarily follow the chat template when prompting LLMs. Instead, malicious users could leverage their knowledge of the chat template and accordingly craft their prompts to bypass safety alignments of LLMs. We study two attacks to exploit the ChatBug vulnerability. Additionally, we demonstrate that the success of multiple existing attacks can be attributed to the ChatBug vulnerability. We show that a malicious user can exploit the ChatBug vulnerability of eight state-of-the-art (SOTA) LLMs and effectively elicit unintended responses from these models. Moreover, we show that ChatBug can be exploited by existing jailbreak attacks to enhance their attack success rates. We investigate potential countermeasures to ChatBug. Our results show that while adversarial training effectively mitigates the ChatBug vulnerability, the victim model incurs significant performance degradation. These results highlight the trade-off between safety alignment and helpfulness. Developing new methods for instruction tuning to balance this trade-off is an open and critical direction for future research. Fengqing Jiang, Zhangchen Xu, Luyao Niu, Bill Y. Lin, Radha Poovendran |
AAAI | 5 |
| 2025 | CANTXSec: A Deterministic Intrusion Detection and Prevention System for CAN Bus Monitoring ECU Activations
Denis Donadel, Kavya Balasubramanian, Alessandro Brighente, Bhaskar Ramasubramanian, Mauro Conti, Radha Poovendran |
ACNS (2) | 6 |
| 2025 | Magpie: Alignment Data Synthesis from Scratch by Prompting Aligned LLMs with NothingabstractHigh-quality instruction data is critical for aligning large language models (LLMs). Although some models, such as Llama-3-Instruct, have open weights, their alignment data remain private, which hinders the democratization of AI. High human labor costs and a limited, predefined scope for prompting prevent existing open-source data creation methods from scaling effectively, potentially limiting the diversity and quality of public alignment datasets. Is it possible to synthesize high-quality instruction data at scale by extracting it directly from an aligned LLM? We present a self-synthesis method for generating large-scale alignment data named Magpie. Our key observation is that aligned LLMs like Llama-3-Instruct can generate a user query when we input only the pre-query templates up to the position reserved for user messages, thanks to their auto-regressive nature. We use this method to prompt Llama-3-Instruct and generate 4 million instructions along with their corresponding responses. We further introduce extensions of Magpie for filtering, generating multi-turn, preference optimization, domain-specific and multilingual datasets. We perform a comprehensive analysis of the Magpie-generated data. To compare Magpie-generated data with other public instruction datasets (e.g., ShareGPT, WildChat, Evol-Instruct, UltraChat, OpenHermes, Tulu-V2-Mix, GenQA), we fine-tune Llama-3-8B-Base with each dataset and evaluate the performance of the fine-tuned models. Our results indicate that using Magpie for supervised fine-tuning (SFT) solely can surpass the performance of previous public datasets utilized for both SFT and preference optimization, such as direct preference optimization with UltraFeedback. We also show that in some tasks, models supervised fine-tuned with Magpie perform comparably to the official Llama-3-8B-Instruct, despite the latter being enhanced with 10 million data points through SFT and subsequent preference optimization. This advantage is evident on alignment benchmarks such as AlpacaEval, ArenaHard, and WildBench. Zhangchen Xu, Fengqing Jiang, Luyao Niu, Yuntian Deng, Radha Poovendran, Yejin Choi 0001, Bill Y. Lin |
ICLR | 5 |
| 2025 | ZebraLogic: On the Scaling Limits of LLMs for Logical ReasoningabstractWe investigate the logical reasoning capabilities of Large Language Models (LLMs) and their scalability across complex deductive tasks. Using ZebraLogic, a newly developed benchmark dataset of logic grid puzzles derived from constraint satisfaction problems (CSPs), we systematically evaluate LLM performance. ZebraLogic spans a broad range of search space complexities and incorporates diverse logical constraints, providing a controlled environment to assess reasoning abilities. Our results reveal a significant decline in accuracy as problem complexity increases—a phenomenon we term the “curse of complexity.” Notably, this limitation persists even with scaling model size and inference-time computation, suggesting fundamental constraints in current LLM reasoning capabilities. Additionally, we explore strategies such as Best-of-N sampling, backtracking mechanisms, and self-verification prompts to enhance logical reasoning performance. Our findings provide critical insights into the scaling behavior of LLMs, highlight their limitations, and outline potential directions for advancing their reasoning capabilities. Bill Y. Lin, Ronan Le Bras 0001, Kyle Richardson 0001, Ashish Sabharwal, Radha Poovendran, Peter Clark, Yejin Choi 0001 |
ICML | 5 |
| 2025 | Stronger Models are Not Always Stronger Teachers for Instruction TuningabstractZhangchen Xu, Fengqing Jiang, Luyao Niu, Bill Yuchen Lin, Radha Poovendran. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2025. Zhangchen Xu, Fengqing Jiang, Luyao Niu, Bill Y. Lin, Radha Poovendran |
NAACL (Long Papers) | 5 |
| 2025 | Identity-Based Authentication for On-Demand Charging of Electric VehiclesabstractDynamic wireless power transfer provides a means for charging Electric Vehicles (EVs) while driving, avoiding stopping to charge and hence fostering their widespread adoption. Researchers have devoted much effort over the last decade to providing a reliable infrastructure for potential users to improve their comfort and time management. Due to the severe security and performance system requirements, the different schemes proposed in the last years lack a unified protocol involving the modern architecture model with merged authentication and billing processes. Furthermore, they require the continuous interaction of the trusted entity during the process, increasing the delay in communication and reducing security due to a large number of message exchanges. This article proposes a secure, computationally lightweight, unified protocol for fast authentication and billing that provides on-demand dynamic charging to deal with all the computational and security comprehensively with additional usability for the customers. The protocol employs an ID-based public encryption scheme to manage mutual authentication and pseudonyms to preserve the user's identity across multiple charging processes. Compared to state-of-the-art authentication protocols, our proposal provides on-demand service and public critical infrastructure security without impacting performances with around 7 ms, close to the most straightforward scheme available. Surudhi Asokraj, Tommaso Bianchi, Alessandro Brighente, Mauro Conti, Radha Poovendran |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | CANLP: Intrusion Detection for Controller Area Networks Using Natural Language Processing and Embedded Machine LearningabstractThe Controller Area Network (CAN) protocol is the most widely used standard in the automotive industry for in-vehicle networks. However, the CAN protocol lacks essential security features such as encryption and message authentication. Absence of such security features has been shown to make the vehicle network vulnerable to exploits by an adversary. Although multiple types of intrusion detection systems (IDS) have been developed for CAN, it can be difficult to deploy them in real-time with low latency. Further, many of these IDSs are unable to isolate specific CAN frames on which an attack has been mounted, which makes it challenging to design defense mechanisms. In this paper, we develop CANLP, a Natural Language Processing (NLP)-based intrusion detection system to determine whether each transmitted message originated from a legitimate ECU or an adversary. CANLP uses Term Frequency-Inverse Document Frequency (TF-IDF), a NLP technique to discern complex features associated with CAN data and trains machine learning models to identify three types of attacks- fuzzing, spoofing, and masquerade. When an attack is detected, CANLP identifies the malicious CAN frame, which is important for developing resilient systems. Extensive experiments on 4 publicly available vehicle network datasets (which represent data collected from over three vehicle makes and four models) show that CANLP performs attack classification with high F1-scores of 0.9974. We also show that CANLP can be deployed for attack detection on resource-constrained hardware through implementation using RaspberryPi and experiments on a testbed with latency as low as$\lt \text{0.05}~ms$, making it suitable for real-world automotive applications such as fleet monitoring within the same vehicle class. Kavya Balasubramanian, Adithya Gowda Baragur, Denis Donadel, Dinuka Sahabandu, Alessandro Brighente, Bhaskar Ramasubramanian, Mauro Conti, Radha Poovendran |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2024 | ArtPrompt: ASCII Art-based Jailbreak Attacks against Aligned LLMsabstractFengqing Jiang, Zhangchen Xu, Luyao Niu, Zhen Xiang, Bhaskar Ramasubramanian, Bo Li, Radha Poovendran. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Fengqing Jiang, Zhangchen Xu, Luyao Niu, Zhen Xiang, Bhaskar Ramasubramanian, Bo Li 0026, Radha Poovendran |
ACL (1) | 7 |
| 2024 | SafeDecoding: Defending against Jailbreak Attacks via Safety-Aware DecodingabstractZhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia, Bill Yuchen Lin, Radha Poovendran. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Zhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia 0001, Bill Y. Lin, Radha Poovendran |
ACL (1) | 6 |
| 2024 | POSTER: Identifying and Mitigating Vulnerabilities in LLM-Integrated ApplicationsabstractCompared with the traditional usage of large language models (LLMs) where users directly send queries to an LLM, LLM-integrated applications serve as middleware to refine users' queries with domain-specific knowledge to better inform LLMs and enhance the responses. However, LLM-integrated applications also introduce new attack surfaces. This work considers a setup where the user and LLM interact via an application in the middle. We focus on the interactions that begin with user's queries and end with LLM-integrated application returning responses to the queries, powered by LLMs at the service backend. We identify potential high-risk vulnerabilities in this setting that can originate from the malicious application developer or from an outsider threat initiator that can control the database access, manipulate and poison high-risk data for the user. Successful exploits of the identified vulnerabilities result in the users receiving responses tailored to the intent of a threat initiator. We assess such threats against LLM-integrated applications empowered by GPT-3.5 and GPT-4. Our experiments show that the threats can effectively bypass the restrictions and moderation policies of OpenAI, resulting in users exposing to the risk of bias, toxic content, privacy, and disinformation. We develop a lightweight, threat-agnostic defense to mitigate insider and outsider threats. Our evaluations demonstrate the efficacy of our defense. Fengqing Jiang, Zhangchen Xu, Luyao Niu, Boxin Wang, Jinyuan Jia 0001, Bo Li 0026, Radha Poovendran |
AsiaCCS | 7 |
| 2024 | POSTER: Double-Dip: Thwarting Label-Only Membership Inference Attacks with Transfer Learning and RandomizationabstractTransfer learning (TL) has been demonstrated to improve DNN model performance when faced with a scarcity of training samples. However, the suitability of TL as a solution to reduce vulnerability of overfitted DNNs to privacy attacks is unexplored. A class of privacy attacks called membership inference attacks (MIAs) aim to determine whether a given sample belongs to the training dataset (member) or not (nonmember). We introduce Double-Dip to investigate the use of TL (Stage-1) combined with randomization (Stage-2) to thwart MIAs on overfitted DNNs without degrading classification accuracy. Our study examines roles of shared feature space and parameter values between source and target models, number of frozen layers, and complexity of pretrained models. Our preliminary evaluations of Double-Dip demonstrate that Stage-1 reduces adversary success while also significantly increasing classification accuracy of nonmembers against an adversary attempting to carry out SOTA label-only MIAs. After Stage-2, success of an adversary carrying out a label-only MIA is further reduced to near 50%, bringing it closer to a random guess and showing the effectiveness of Double-Dip. Stage-2 of Double-Dip also achieves lower ASR and higher classification accuracy than regularization and differential privacy-based methods. Arezoo Rajabi, Reeya Pimple, Aiswarya Janardhanan, Surudhi Asokraj, Bhaskar Ramasubramanian, Radha Poovendran |
AsiaCCS | 6 |
| 2024 | POSTER: Game of Trojans: Adaptive Adversaries Against Output-based Trojaned-Model DetectorsabstractDeep Neural Network (DNN) models are vulnerable to Trojan attacks, wherein a Trojaned DNN will mispredict trigger-embedded inputs as malicious targets, while outputs for clean inputs remain unaffected. Output-based Trojaned model detectors, which analyze outputs of DNNs to perturbed inputs have emerged as a promising approach for identifying Trojaned DNN models. At present, these SOTA detectors assume that the adversary is (i) static and (ii) does not have prior knowledge about deployed detection mechanisms. Dinuka Sahabandu, Arezoo Rajabi, Luyao Niu, Bhaskar Ramasubramanian, Bo Li 0026, Radha Poovendran |
AsiaCCS | 7 |
| 2024 | Poster: Brave: Byzantine-Resilient and Privacy-Preserving Peer-to-Peer Federated LearningabstractFederated learning (FL) enables multiple participants to train a global machine learning model without sharing their private training data. Peer-to-peer (P2P) FL advances existing centralized FL paradigms by eliminating the server that aggregates local models from participants and then updates the global model. However, P2P FL is vulnerable to (i) honest-but-curious participants whose objective is to infer private training data of other participants, and (ii) Byzantine participants who can transmit arbitrarily manipulated local models to corrupt the learning process. P2P FL schemes that simultaneously guarantee Byzantine resilience and preserve privacy have been less studied. In this paper, we develop Brave, a protocol that ensures Byzantine Resilience And priVacy-prEserving property for P2P FL in the presence of both types of adversaries. We show that Brave preserves privacy by establishing that any honest-but-curious adversary cannot infer other participants' private data by observing their models. We further prove that Brave is Byzantine-resilient, which guarantees that all benign participants converge to an identical model that deviates from a global model trained without Byzantine adversaries by a bounded distance. We evaluate Brave against three state-of-the-art adversaries on a P2P FL for image classification tasks on benchmark datasets CIFAR10 and MNIST. Our results show that global models learned with Brave in the presence of adversaries achieve comparable classification accuracy to global models trained in the absence of any adversary. Zhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia 0001, Radha Poovendran |
AsiaCCS | 5 |
| 2024 | CleanGen: Mitigating Backdoor Attacks for Generation Tasks in Large Language ModelsabstractYuetai Li, Zhangchen Xu, Fengqing Jiang, Luyao Niu, Dinuka Sahabandu, Bhaskar Ramasubramanian, Radha Poovendran. Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing. 2024. Yuetai Li, Zhangchen Xu, Fengqing Jiang, Luyao Niu, Dinuka Sahabandu, Bhaskar Ramasubramanian, Radha Poovendran |
EMNLP | 7 |
| 2024 | BadChain: Backdoor Chain-of-Thought Prompting for Large Language ModelsabstractLarge language models (LLMs) are shown to benefit from chain-of-thought (COT) prompting, particularly when tackling tasks that require systematic reasoning processes. On the other hand, COT prompting also poses new vulnerabilities in the form of backdoor attacks, wherein the model will output unintended malicious content under specific backdoor-triggered conditions during inference. Traditional methods for launching backdoor attacks involve either contaminating the training dataset with backdoored instances or directly manipulating the model parameters during deployment. However, these approaches are not practical for commercial LLMs that typically operate via API access. In this paper, we propose BadChain, the first backdoor attack against LLMs employing COT prompting, which does not require access to the training dataset or model parameters and imposes low computational overhead. BadChain leverages the inherent reasoning capabilities of LLMs by inserting a backdoor reasoning step into the sequence of reasoning steps of the model output, thereby altering the final response when a backdoor trigger is embedded in the query prompt. In particular, a subset of demonstrations will be manipulated to incorporate a backdoor reasoning step in COT prompting. Consequently, given any query prompt containing the backdoor trigger, the LLM will be misled to output unintended content. Empirically, we show the effectiveness of BadChain for two COT strategies across four LLMs (Llama2, GPT-3.5, PaLM2, and GPT-4) and six complex benchmark tasks encompassing arithmetic, commonsense, and symbolic reasoning. We show that the baseline backdoor attacks designed for simpler tasks such as semantic classification will fail on these complicated tasks. In addition, our findings reveal that LLMs endowed with stronger reasoning capabilities exhibit higher susceptibility to BadChain, exemplified by a high average attack success rate of 97.0\% across the six benchmark tasks on GPT-4. We also demonstrate the interpretability of BadChain by showing that the relationship between the trigger and the backdoor reasoning step can be well-explained based on the output of the backdoored model. Finally, we propose two defenses based on shuffling and demonstrate their overall ineffectiveness against BadChain. Therefore, BadChain remains a severe threat to LLMs, underscoring the urgency for the development of robust and effective future defenses. Zhen Xiang, Fengqing Jiang, Zidi Xiong, Bhaskar Ramasubramanian, Radha Poovendran, Bo Li 0026 |
ICLR | 5 |
| 2024 | Fault Tolerant Neural Control Barrier Functions for Robotic Systems under Sensor Faults and AttacksabstractSafety is a fundamental requirement of many robotic systems. Control barrier function (CBF)-based approaches have been proposed to guarantee the safety of robotic systems. However, the effectiveness of these approaches highly relies on the choice of CBFs. Inspired by the universal approximation power of neural networks, there is a growing trend toward representing CBFs using neural networks, leading to the notion of neural CBFs (NCBFs). Current NCBFs, however, are trained and deployed in benign environments, making them ineffective for scenarios where robotic systems experience sensor faults and attacks. In this paper, we study safety-critical control synthesis for robotic systems under sensor faults and attacks. Our main contribution is the development and synthesis of a new class of CBFs that we term fault tolerant neural control barrier function (FT-NCBF). We derive the necessary and sufficient conditions for FT-NCBFs to guarantee safety, and develop a data-driven method to learn FT-NCBFs by minimizing a loss function constructed using the derived conditions. Using the learned FT-NCBF, we synthesize a control input and formally prove the safety guarantee provided by our approach. We demonstrate our proposed approach using two case studies: obstacle avoidance problem for an autonomous mobile robot and spacecraft rendezvous problem, with code available via https://github.com/HongchaoZhang-HZ/FTNCBF. Luyao Niu, Andrew Clark 0001, Radha Poovendran |
ICRA | 4 |
| 2024 | Rapid Autonomy Transfer in Reinforcement Learning with a Single Pre- Trained CriticabstractReinforcement learning (RL) is a well-studied framework to solve complex decision-making problems in unknown environments. The actor-critic model in RL facilitates autonomy transfer by allowing agents to iteratively update their policies using ongoing dynamic evaluations of value functions via a critic. In this paper, we examine the impact of using different pretrained critics on the performance of actor-critic algorithms. First, in any single given environment, we show that a pretrained critic can be effective in reducing the duration of an initial training phase, thereby accelerating convergence by a factor of up to 2×. In this setting, we identify the critical range of the number of episodes for which a critic will need to be trained in order for it to be an effective pretrained critic. Second, we show that a critic trained in one environment enables transfer of autonomy by aiding learning of behaviors in a different, yet related environment. We carry out extensive experiments on a bipedal locomotion task in the MuJoCo physics engine to verify our hypotheses. Our results in this paper mark the first step towards demonstrating the role and impact of pretrained critics to achieve rapid autonomy transfer for complex reinforcement learning tasks while minimizing costs associated with retraining in new environments. M. Faraz Karim, Yunjie Deng 0001, Luyao Niu, Bhaskar Ramasubramanian, Michail S. Alexiou, Dinuka Sahabandu, Radha Poovendran, J. Sukarno Mertoguno |
ICTAI | 7 |
| 2024 | EDC: Effective and Efficient Dialog Comprehension For Dialog State TrackingabstractQifan Lu, Bhaskar Ramasubramanian, Radha Poovendran. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024. Qifan Lu, Bhaskar Ramasubramanian, Radha Poovendran |
NAACL-HLT | 3 |
| 2024 | ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated Learning
Zhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia 0001, Bo Li 0026, Radha Poovendran |
USENIX Security Symposium | 6 |
| 2023 | POSTER: A Common Framework for Resilient and Safe Cyber-Physical System DesignabstractCyber-physical systems (CPS), which are often required to satisfy critical properties such as safety, have been shown to be vulnerable to exploits originating from cyber and/or physical sides. Recently, novel resilient architectures, which equip CPS with capabilities of recovering to normal operations, have been developed to guarantee the safety of CPS under cyber attacks. These resilient architectures utilize distinct mechanisms involving different parameters and are seemingly unrelated. Currently, the analysis and design methods of one novel resilient architecture for CPS are not readily applicable to one another. Consequently, evaluating the appropriateness and effectiveness of a set of candidate resilient architectures to a given CPS is currently impractical. In this poster, we report our progress on the development of a common framework for analyzing the safety and assessing recovery performance of two or more resilient architectures intended for CPS under attacks. We formulate a hybrid model as a common representation of resilient architectures. Our insight is that the resilient architectures have a shared set of discrete states, including vulnerable, under attack, unsafe, and recovery modes, which can be mapped to the discrete states of the unifying hybrid model. The hybrid model enables a unified safety analysis. We parameterize the required behaviors for the cyber and physical components in order to guarantee safety. The parameters then inform the development of metrics to measure the resilience of CPS. For CPS consisting of multiple heterogeneous components, we show that the effect of interconnections on the spatial and temporal parameters can be quantified efficiently, allowing a compositional approach to the safety verification of large-scale CPS. Luyao Niu, Andrew Clark 0001, J. Sukarno Mertoguno, Radha Poovendran |
AsiaCCS | 5 |
| 2023 | LDL: A Defense for Label-Based Membership Inference AttacksabstractThe data used to train deep neural network (DNN) models in applications such as healthcare and finance typically contain sensitive information. A DNN model may suffer from overfitting– it will perform very well on samples seen during training, and poorly on samples not seen during training. Overfitted models have been shown to be susceptible to query-based attacks such as membership inference attacks (MIAs). MIAs aim to determine whether a sample belongs to the dataset used to train a classifier (members) or not (nonmembers). Recently, a new class of label-based MIAs (LAB MIAs) was proposed, where an adversary was only required to have knowledge of predicted labels of samples. LAB MIAs used the insight that member samples were typically located farther away from a classification decision boundary than nonmembers, and were shown to be highly effective across multiple datasets. Developing a defense against an adversary carrying out a LAB MIA on DNN models that cannot be retrained remains an open problem. Arezoo Rajabi, Dinuka Sahabandu, Luyao Niu, Bhaskar Ramasubramanian, Radha Poovendran |
AsiaCCS | 5 |
| 2023 | MDTD: A Multi-Domain Trojan Detector for Deep Neural NetworksabstractMachine learning models that use deep neural networks (DNNs) are vulnerable to backdoor attacks. An adversary carrying out a backdoor attack embeds a predefined perturbation called a trigger into a small subset of input samples and trains the DNN such that the presence of the trigger in the input results in an adversary-desired output class. Such adversarial retraining however needs to ensure that outputs for inputs without the trigger remain unaffected and provide high classification accuracy on clean samples. Existing defenses against backdoor attacks are computationally expensive, and their success has been demonstrated primarily on image-based inputs. The increasing popularity of deploying pretrained DNNs to reduce costs of re/training large models makes defense mechanisms that aim to detect 'suspicious' input samples preferable. Arezoo Rajabi, Surudhi Asokraj, Fengqing Jiang, Luyao Niu, Bhaskar Ramasubramanian, James A. Ritcey, Radha Poovendran |
CCS | 7 |
| 2023 | Learning Dissemination Strategies for External Sources in Opinion Dynamic Models with Cognitive BiasesabstractThe opinions of members of a population are influenced by opinions of their peers, their own predispositions, and information from external sources via one or more information channels (e.g., news, social media). Due to individual cognitive biases, the perceptual impact of and importance assigned by agents to information on each channel can be different. In this paper, we propose a model of opinion evolution that uses prospect theory to represent perception of information from the external source along each channel. Our prospect-theoretic model reflects traits observed in humans such as loss aversion, assigning inflated (deflated) values to low (high) probability events, and evaluating outcomes relative to an individually known reference point. We consider the problem of determining information dissemination strategies for the external source to adopt in order to drive opinions of individuals towards a desired value. However, computing a strategy faces a challenge that agents' initial predispositions and functions characterizing their perceptions of information disseminated might be unknown. We overcome this challenge by using Gaussian process learning to estimate these unknown parameters. When the external source sends information over multiple channels, the problem of jointly selecting optimal dissemination strategies is in general, combinatorial. We prove that this problem is submodular, and design near-optimal dissemination algorithms. We evaluate our model on three different widely used large graphs that represent real-world social interactions. Our results indicate that the external source can effectively drive opinions towards a desired value when using prospect-theory based dissemination strategies. Luyao Niu, Bhaskar Ramasubramanian, Andrew Clark 0001, Radha Poovendran |
IJCAI | 5 |
| 2023 | FedGame: A Game-Theoretic Defense against Backdoor Attacks in Federated LearningabstractFederated learning (FL) provides a distributed training paradigm where multiple clients can jointly train a global model without sharing their local data. However, recent studies have shown that FL offers an additional surface for backdoor attacks. For instance, an attacker can compromise a subset of clients and thus corrupt the global model to misclassify an input with a backdoor trigger as the adversarial target. Existing defenses for FL against backdoor attacks usually detect and exclude the corrupted information from the compromised clients based on a static attacker model. However, such defenses are inadequate against dynamic attackers who strategically adapt their attack strategies. To bridge this gap, we model the strategic interactions between the defender and dynamic attackers as a minimax game. Based on the analysis of the game, we design an interactive defense mechanism FedGame. We prove that under mild assumptions, the global model trained with FedGame under backdoor attacks is close to that trained without attacks. Empirically, we compare FedGame with multiple state-of-the-art baselines on several benchmark datasets under various attacks. We show that FedGame can effectively defend against strategic attackers and achieves significantly higher robustness than baselines. Our code is available at: https://github.com/AI-secure/FedGame. Jinyuan Jia 0001, Zhuowen Yuan, Dinuka Sahabandu, Luyao Niu, Arezoo Rajabi, Bhaskar Ramasubramanian, Bo Li 0026, Radha Poovendran |
NeurIPS | 8 |
| 2023 | QEVSEC: Quick Electric Vehicle SEcure Charging via Dynamic Wireless Power TransferabstractDynamic Wireless Power Transfer (DWPT) can be used for on-demand recharging of Electric Vehicles (EV) while driving. However, DWPT raises numerous security and privacy concerns. Recently, researchers demonstrated that DWPT systems are vulnerable to adversarial attacks. In an EV charging scenario, an attacker can prevent the authorized customer from charging, obtain a free charge by billing a victim user and track a target vehicle. State-of-the-art authentication schemes relying on centralized solutions are either vulnerable to various attacks or have high computational complexity, making them unsuitable for a dynamic scenario. In this paper, we propose Quick Electric Vehicle SEcure Charging (QEVSEC), a novel, secure, and efficient authentication protocol for the dynamic charging of EVs. Our idea for QEVSEC originates from multiple vulnerabilities we found in the state-of-the-art protocol that allows tracking of user activity and is susceptible to replay attacks. Based on these observations, the proposed protocol solves these issues and achieves lower computational complexity by using only primitive cryptographic operations in a very short message exchange. QEVSEC provides scalability and a reduced cost in each iteration, thus lowering the impact on the power needed from the grid. Tommaso Bianchi, Surudhi Asokraj, Alessandro Brighente, Mauro Conti, Radha Poovendran |
VTC2023-Spring | 5 |
| 2023 | BARON: Base-Station Authentication Through Core Network for Mobility Management in 5G NetworksabstractFifth-generation (5G) cellular communication networks are being deployed on applications beyond mobile devices, including vehicular networks and industry automation. Despite their increasing popularity, 5G networks, as defined by the Third Generation Partnership Project (3GPP), have been shown to be vulnerable against fake base station (FBS) attacks. An adversary carrying out an FBS attack emulates a legitimate base station by setting up a rogue base station. This enables the adversary to control the connection of any user equipment that (inadvertently) connects with the rogue base station. Such an adversary can gather sensitive information belonging to the user. While there is a large body of work focused on the development of tools to detect FBSs, the user equipment will continue to remain vulnerable to an FBS attack. In this paper, we propose BARON, a defense methodology to enable user equipment to determine whether a target base station that it is connecting to is legitimate or rogue. BARON accomplishes this by ensuring that the user receives an authentication token from the target base station which can be computed only by a legitimate and trusted entity. As a consequence, receiving such an authentication token from a base station ensures legitimacy of the base station. We evaluate BARON through extensive experiments on the handover process between base stations in 5G networks. Our experimental results show that BARON introduces an overhead of less than 1% during handover completion, which is 10000× lower than the overhead reported by a state-of-the-art method. BARON is also effective in thwarting an FBS attack and quickly recovering connection to a legitimate base station. Alessandro Lotto, Vaibhav Singh 0002, Bhaskar Ramasubramanian, Alessandro Brighente, Mauro Conti, Radha Poovendran |
WISEC | 6 |
| 2023 | A Timing-Based Framework for Designing Resilient Cyber-Physical Systems under Safety ConstraintabstractCyber-physical systems (CPS) are required to satisfy safety constraints in various application domains such as robotics, industrial manufacturing systems, and power systems. Faults and cyber attacks have been shown to cause safety violations, which can damage the system and endanger human lives. Resilient architectures have been proposed to ensure safety of CPS under such faults and attacks via methodologies including redundancy and restarting from safe operating conditions. The existing resilient architectures for CPS utilize different mechanisms to guarantee safety, and currently, there is no common framework to compare them. Moreover, the analysis and design undertaken for CPS employing one architecture is not readily extendable to another. In this article, we propose a timing-based framework for CPS employing various resilient architectures and develop a common methodology for safety analysis and computation of control policies and design parameters. Using the insight that the cyber subsystem operates in one out of a finite number of statuses, we first develop a hybrid system model that captures CPS adopting any of these architectures. Based on the hybrid system, we formulate the problem of joint computation of control policies and associated timing parameters for CPS to satisfy a given safety constraint and derive sufficient conditions for the solution. Utilizing the derived conditions, we provide an algorithm to compute control policies and timing parameters relevant to the employed architecture. We also note that our solution can be applied to a wide class of CPS with polynomial dynamics and also allows incorporation of new architectures. We verify our proposed framework by performing a case study on adaptive cruise control of vehicles. Luyao Niu, Andrew Clark 0001, J. Sukarno Mertoguno, Radha Poovendran |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2023 | A Natural Language Processing Approach for Instruction Set Architecture IdentificationabstractBinary analysis of software is a critical step in cyber forensics applications such as program vulnerability assessment and malware detection. This involves interpreting instructions executed by software and often necessitates converting the software’s binary file data to assembly language. The conversion process requires information about the binary file’s target instruction set architecture (ISA). However, ISA information might not be included in binary files due to compilation errors, partial downloads, or adversarial corruption of file metadata. Machine learning (ML) is a promising methodology that can be used to identify the target ISA using binary data in the object code section of binary files. In this paper we propose a binary code feature extraction model to improve the accuracy and scalability of ML-based ISA identification methods. Our feature extraction model can be used in the absence of domain knowledge about the ISAs. Specifically, we adapt models from natural language processing (NLP) to i) identify successive byte patterns commonly observed in binary codes, ii) estimate the significance of each byte pattern to a binary file, and iii) estimate the relevance of each byte pattern in distinguishing between ISAs. We introduce character-level features of encoded binaries to identify fine-grained bit patterns inherent to each ISA. We evaluate our approach using two different datasets: binaries from 12 ISAs and 23 ISAs. Empirical evaluations show that using our byte-level features in ML-based ISA identification results in ~ 98% accuracy compared to the ~ 91% accuracy of state-of-the-art features based on byte-histograms and byte pattern signatures. We observe that character-level features allow reducing the size of the feature set by up to 16x while maintaining accuracy of ISA identification above 97%. Dinuka Sahabandu, J. Sukarno Mertoguno, Radha Poovendran |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Guest Editorial: Cyber-Physical Threats and Solutions for Autonomous Transportation SystemsabstractThe rapid evolution of technology has radically changed our everyday lives from multiple points of view. Systems and devices are nowadays more interconnected and capable of taking autonomous decisions without or with limited human intervention. Among the others, transportation systems are populated by smart and interconnected vehicles that need to communicate with each other and with critical infrastructures to orchestrate traffic and mobility. Such vehicles are equipped with multiple modules, which are sensing or communication devices that help the vehicle in assessing its well-being besides providing the basic information to be shared for the orchestration in the overall network. Transportation systems are hence operated through multiple technologies that need to cooperate to provide efficient delivery of goods and human mobility, as well as to provide security in the overall network. The latter task is complicated by the fact that vehicles autonomously drive and cooperate in the network without human intervention. In fact, thanks to the self-regulating capacity of the modules deployed both inside each vehicle and in the network infrastructure, vehicles do not need to be actively and fully driven by humans as in the past but require minimum intervention to mitigate extreme cases. The level of human intervention depends on the specific architecture and solution but is generally very limited. The overall transportation network can be therefore represented by a cyber--physical system, where a large number of sensors, actuators, and multiple technologies are connected and exchange information. Alessandro Brighente, Mauro Conti, Radha Poovendran, Jianying Zhou 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | EVExchange: A Relay Attack on Electric Vehicle Charging SystemabstractAbstract To support the increasing spread of Electric Vehicles (EVs), Charging Stations (CSs) are being installed worldwide. The new generation of CSs employs the Vehicle-To-Grid (V2G) paradigm by implementing novel standards such as the ISO 15118. This standard enables high-level communication between the vehicle and the charging column, helps manage the charge smartly, and simplifies the payment phase. This novel charging paradigm, which connects the Smart Grid to external networks (e.g., EVs and CSs), has not been thoroughly examined yet. Therefore, it may lead to dangerous vulnerability surfaces and new research challenges. In this paper, we present EVExchange , the first attack to steal energy during a charging session in a V2G communication: i.e., charging the attacker’s car while letting the victim pay for it. Furthermore, if reverse charging flow is enabled, the attacker can even sell the energy available on the victim’s car! Thus, getting the economic profit of this selling, and leaving the victim with a completely discharged battery. We developed a virtual and a physical testbed in which we validate the attack and prove its effectiveness in stealing the energy. To prevent the attack, we propose a lightweight modification of the ISO 15118 protocol to include a distance bounding algorithm. Finally, we validated the countermeasure on our testbeds. Our results show that the proposed countermeasure can identify all the relay attack attempts while being transparent to the user. Mauro Conti, Denis Donadel, Radha Poovendran, Federico Turrin |
ESORICS (1) | 3 |
| 2022 | Side-channel attacks on mobile and IoT devices for Cyber-Physical systems
Mauro Conti, Eleonora Losiouk, Radha Poovendran, Riccardo Spolaor |
Comput. Networks | 3 |
| 2022 | Covert Channel-Based Transmitter Authentication in Controller Area NetworksabstractIn recent years, the security of automotive Cyber-Physical Systems (CPSs) is facing urgent threats due to the widespread use of legacy in-vehicle communication systems. As a representative legacy bus system, the Controller Area Network (CAN) hosts Electronic Control Units (ECUs) that are crucial for the vehicles functioning. In this scenario, malicious actors can exploit the CAN vulnerabilities, such as the lack of built-in authentication and encryption schemes, to launch CAN bus attacks (e.g., suspension, injection, and masquerade attacks) with life-threatening consequences (e.g., disabling brakes). In this article, we present TACAN (Transmitter Authentication in CAN), which provides secure authentication of ECUs on the legacy CAN bus by exploiting thecovert channels, without introducing CAN protocol modifications or traffic overheads (no extra bits or CAN messages are used). TACAN turns upside-down the originally malicious concept of covert channels and exploits it to build an effective defensive technique that facilitates transmitter authentication via a centralized, trusted Monitor Node. TACAN consists of three different covert channels for ECU authentication: 1) the Inter-Arrival Time (IAT)-based, leveraging the IATs of CAN messages; 2) the Least Significant Bit (LSB)-based, concealing authentication messages into the LSBs of normal CAN data; and 3) a hybrid covert channel, exploiting the combination of the first two. In order to validate TACAN, we implement the covert channels on the University of Washington (UW) EcoCAR (Chevrolet Camaro 2016) testbed. We further evaluate the bit error, throughput, and detection performance of TACAN through extensive experiments using the EcoCAR testbed and a publicly available dataset collected from Toyota Camry 2010. We demonstrate the feasibility of TACAN and the effectiveness of detecting CAN bus attacks, highlighting no traffic overheads and attesting the regular functionality of ECUs. Xuhang Ying, Giuseppe Bernieri, Mauro Conti, Linda Bushnell, Radha Poovendran |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Truck platoon security: State-of-the-art and road ahead
Amrita Ghosal, Sang Uk Sagong, Subir Halder, Kalana Sahabandu, Mauro Conti, Radha Poovendran, Linda Bushnell |
Comput. Networks | 6 |
| 2019 | Shape of the Cloak: Formal Analysis of Clock Skew-Based Intrusion Detection System in Controller Area NetworksabstractThis paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based intrusion detection systems (IDSs) that detect masquerade attacks in the controller area network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used network time protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS. Xuhang Ying, Sang Uk Sagong, Andrew Clark 0001, Linda Bushnell, Radha Poovendran |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2017 | No Free Charge Theorem: A Covert Channel via USB Charging Cable on Mobile Devices
Riccardo Spolaor, Laila Abudahi, Veelasha Moonsamy, Mauro Conti, Radha Poovendran |
ACNS | 5 |
| 2017 | On the Limitation of Convolutional Neural Networks in Recognizing Negative ImagesabstractConvolutional Neural Networks (CNNs) have achieved state-of-the-art performance on a variety of computer vision tasks, particularly visual classification problems, where new algorithms reported to achieve or even surpass the human performance. In this paper, we examine whether CNNs are capable of learning the semantics of training data. To this end, we evaluate CNNs on negative images, since they share the same structure and semantics as regular images and humans can classify them correctly. Our experimental results indicate that when training on regular images and testing on negative images, the model accuracy is significantly lower than when it is tested on regular images. This leads us to the conjecture that current training methods do not effectively train models to generalize the concepts. We then introduce the notion of semantic adversarial examples - transformed inputs that semantically represent the same objects, but the model does not classify them correctly - and present negative images as one class of such inputs. Hossein Hosseini, Baicen Xiao, Mayoore S. Jaiswal, Radha Poovendran |
ICMLA | 4 |
| 2017 | Google's Cloud Vision API is Not Robust to NoiseabstractGoogle has recently introduced the Cloud Vision API for image analysis. According to the demonstration website, the API "quickly classifies images into thousands of categories, detects individual objects and faces within images, and finds and reads printed words contained within images." It can be also used to "detect different types of inappropriate content from adult to violent content." In this paper, we evaluate the robustness of Google Cloud Vision API to input perturbation. In particular, we show that by adding sufficient noise to the image, the API generates completely different outputs for the noisy image, while a human observer would perceive its original content. We show that the attack is consistently successful, by performing extensive experiments on different image types, including natural images, images containing faces and images with texts. For instance, using images from ImageNet dataset, we found that adding an average of 14.25% impulse noise is enough to deceive the API. Our findings indicate the vulnerability of the API in adversarial environments. For example, an adversary can bypass an image filtering system by adding noise to inappropriate images. We then show that when a noise filter is applied on input images, the API generates mostly the same outputs for restored images as for original images. This observation suggests that cloud vision API can readily benefit from noise filtering, without the need for updating image analysis algorithms. Hossein Hosseini, Baicen Xiao, Radha Poovendran |
ICMLA | 3 |
| 2017 | Detecting LTE-U duty cycling misbehavior for fair sharing with Wi-Fi in shared bandsabstractCoexistence of Wi-Fi and LTE Unlicensed (LTE-U) in shared or unlicensed bands has drawn growing attention from both academia and industry. An important consideration is fairness between Wi-Fi and duty cycled LTE-U, which is often defined in terms of channel access time, as adopted by the LTE-U Forum. Despite many studies on duty cycle adaptation design for fair sharing, one crucial fact has often been neglected: LTE-U systems unilaterally control LTE-U duty cycles; hence, as selfinterested users, they have incentives to misbehave, e.g., transmitting with a larger duty cycle that exceeds a given limit, so as to gain a greater share in channel access time and throughput. In this paper, we propose a scheme that allows the spectrum manager managing the shared bands to estimate the duty cycle of a target LTE-U cell based on PHY layer observations from a nearby Wi-Fi AP, without interrupting normal Wi-Fi operations. We further propose a thresholding scheme to detect duty cycling misbehavior (i.e., determining if the duty cycle exceeds the assigned limit), and analyze its performance in terms of detection and false alarm probabilities. The proposed schemes are implemented in ns3 and evaluated with extensive simulations. Our results show that the proposed scheme provides an estimate within ± 1% of the true duty cycle, and detects misbehavior with a duty cycle 2.8% higher than the limit with a detection probability of at least 95%, while keeping the false alarm probability less than or equal to 1%. Xuhang Ying, Radha Poovendran, Sumit Roy 0001 |
PIMRC | 2 |
| 2017 | LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined NetworkingabstractSoftware defined networking (SDN) is a new networking paradigm that in recent years has revolutionized network architectures. At its core, SDN separates the data plane, which provides data forwarding functionalities, and the control plane, which implements the network control logic. The separation of these two components provides a virtually centralized point of control in the network, and at the same time abstracts the complexity of the underlying physical infrastructure. Unfortunately, while promising, the SDN approach also introduces new attacks and vulnerabilities. Indeed, previous research shows that, under certain traffic conditions, the required communication between the control and data plane can result in a bottleneck. An attacker can exploit this limitation to mount a new, network-wide, type of denial of service attack, known as the control plane saturation attack. This paper presents LineSwitch, an efficient and effective data plane solution to tackle the control plane saturation attack. LineSwitch employs probabilistic proxying and blacklisting of network traffic to prevent the attack from reaching the control plane, and thus preserve network functionality. We implemented LineSwitch as an extension of the reference SDN implementation, OpenFlow, and run a thorough set of experiments under different traffic and attack scenarios. We compared LineSwitch to the state of the art, and we show that it provides at the same time, the same level of protection against the control plane saturation attack, and a reduced time overhead by up to 30%. Moreno Ambrosin, Mauro Conti, Fabio De Gaspari, Radha Poovendran |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | Secure Error-Tolerant Graph Matching Protocols
Kalikinkar Mandal, Basel Alomair, Radha Poovendran |
CANS | 3 |
| 2016 | Learning Temporal Dependence from Time-Series Data with Latent VariablesabstractWe consider the setting where a collection of time series, modeled as random processes, evolve in a causal manner, and one is interested in learning the graph governing the relationships of these processes. A special case of wide interest and applicability is the setting where the noise is Gaussian and relationships are Markov and linear. We study this setting with two additional features: firstly, each random process has a hidden (latent) state, which we use to model the internal memory possessed by the variables (similar to hidden Markov models). Secondly, each variable can depend on its latent memory state through a random lag (rather than a fixed lag), thus modeling memory recall with differing lags at distinct times. Under this setting, we develop an estimator and prove that under a genericity assumption, the parameters of the model can be learned consistently. We also propose a practical adaption of this estimator, which demonstrates significant performance gains in both synthetic and real-world datasets. Hossein Hosseini, Sreeram Kannan, Baosen Zhang, Radha Poovendran |
DSAA | 4 |
| 2016 | Pricing Mechanism for Quality-Based Radio Mapping via CrowdsourcingabstractWhite Space (WS) Networking crucially relies on the active monitoring of spatio-temporal spectrum usage (to identify WS opportunities). To achieve this, one way is to gather spectrum data via wide-area sensor deployment and construct better Radio Environment Maps (REMs) with spatial models such as Kriging and Gaussian Process (GP). An economically viable alternative is via incentivized crowdsourcing, i.e., outsourcing sensing tasks to mobile users who have sensorized high-end client devices like tablets or smartphones, and providing proper incentives to compensate for users' sensing costs. In crowdsourced REM, features that impact REM performance and economic cost include user locations and the heterogeneity of user devices, which impact data quality and sensing costs. In this work, we emphasize the use of a hardware noise term in the GP model to account for data quality, and adopt mutual information to quantify sampling performance; we further design a pricing mechanism that allows the platform to maximize its expected utility at each stage and send optimal price offers to users sequentially, with joint consideration of sampling value, data quality and cost. We conduct simulations to evaluate the performance. Simulation results show that our mechanism outperforms two baseline mechanisms, and benefits from more users and less hardware noise (i.e., better data quality). Xuhang Ying, Sumit Roy 0001, Radha Poovendran |
GLOBECOM | 3 |
| 2015 | LineSwitch: Efficiently Managing Switch Flow in Software-Defined Networking while Effectively Tackling DoS AttacksabstractSoftware Defined Networking (SDN) is a new networking architecture that aims to provide better decoupling between network control (control plane) and data forwarding functionalities (data plane). This separation introduces several benefits, such as a directly programmable and (virtually) centralized network control. However, researchers showed that the required communication channel between the control and data plane of SDN creates a potential bottleneck in the system, introducing new vulnerabilities.Indeed, this behavior could be exploited to mount powerful attacks, such as the control plane saturation attack, that can severely hinder the performance of the whole network. Moreno Ambrosin, Mauro Conti, Fabio De Gaspari, Radha Poovendran |
AsiaCCS | 4 |
| 2015 | Scalable and distributed submodular maximization with matroid constraintsabstractSubmodular maximization enables efficient approximation of machine learning, networking, and language processing problems. Typically, these problems have been shown to have matroid constraints, which generalize matching and partition conditions. Developing scalable, distributed submodular optimization algorithms that guarantee the same performance as centralized techniques has been an active area of research. In this paper, we address the problem of developing scalable distributed algorithms for submodular maximization with a matroid constraint. Our key step is to construct an auxiliary function from the submodular objective function, and develop distributed exchange-based algorithms for optimizing the auxiliary function. We first introduce a distributed algorithm for maximizing a submodular function with a matroid constraint. We then develop an algorithm for maximizing time-varying submodular functions under partition matroid constraints, which arises in sensor placement and data caching. We prove that both algorithms provide (1-1/e) optimality bounds, and hence achieve the same guarantees as the best centralized algorithms. Andrew Clark 0001, Basel Alomair, Linda Bushnell, Radha Poovendran |
WiOpt | 4 |
| 2014 | Distributed online submodular maximization in resource-constrained networksabstractMaximization of submodular set functions arises in wireless applications such as scheduling, caching, and leader selection. For a centralized entity with oracle access to the submodular function, submodular maximization can be approximated up to a constant factor using polynomial-time algorithms; such an entity, however, may be unavailable in decentralized wireless networks. In this paper, we consider maximization of a time-varying submodular function by distributed, resource-constrained nodes. We present algorithms for unconstrained distributed submodular maximization, as well as monotone submodular maximization subject to cardinality constraints. For the unconstrained submodular maximization problem, our algorithm achieves an expected optimality gap of 1/3. For cardinality-constrained submodular maximization, our algorithm achieves an expected optimality gap of 1/2, while reducing the storage and communication overhead, as well as the computation requirements of the nodes, compared to existing techniques. We evaluate our approach through an experimental study using sensor scheduling data, and find that our approach is within ten percent of the best achievable utility in the unconstrained case and within five percent in the constrained case. Andrew Clark 0001, Basel Alomair, Linda Bushnell, Radha Poovendran |
WiOpt | 4 |
| 2014 | E-MACs: Toward More Secure and More Efficient Constructions of Secure ChannelsabstractIn cryptography, secure channels enable the confidential and authenticated message exchange between authorized users. A generic approach of constructing such channels is by combining an encryption primitive with an authentication primitive (MAC). In this work, we introduce the design of a new cryptographic primitive to be used in the construction of secure channels. Instead of using general purpose MACs, we propose the deployment of special purpose MACs, named ε-MACs. The main motivation behind this work is the observation that, since the message must be both encrypted and authenticated, there might be some redundancy in the computations performed by the two primitives. Therefore, removing such redundancy can improve the efficiency of the overall composition. Moreover, computations performed by the encryption algorithm can be further utilized to improve the security of the authentication algorithm. In particular, we will show how ε-MACs can be designed to reduce the amount of computation required by standard MACs based on universal hash functions, and show how ε-MACs can be secured against key-recovery attacks. Basel Alomair, Radha Poovendran |
IEEE Trans. Computers | 2 |
| 2014 | Efficient Authentication for Mobile and Pervasive ComputingabstractWith today's technology, many applications rely on the existence of small devices that can exchange information and form communication networks. In a significant portion of such applications, the confidentiality and integrity of the communicated messages are of particular interest. In this work, we propose two novel techniques for authenticating short encrypted messages that are directed to meet the requirements of mobile and pervasive applications. By taking advantage of the fact that the message to be authenticated must also be encrypted, we propose provably secure authentication codes that are more efficient than any message authentication code in the literature. The key idea behind the proposed techniques is to utilize the security that the encryption algorithm can provide to design more efficient authentication mechanisms, as opposed to using standalone authentication primitives. Basel Alomair, Radha Poovendran |
IEEE Trans. Mob. Comput. | 2 |
| 2014 | Guest Editors' Introduction: Special Issue on Trust, Security, and Privacy in Parallel and Distributed SystemsabstractThe articles in this special section focus on trust, network security, and privacy deployed in parallel and distributed systems. Zhenfu Cao, Keqiu Li, Patrick D. McDaniel, Radha Poovendran, Guojun Wang 0001, Yang Xiang 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2013 | Optimized relay-route assignment for anonymity in wireless networksabstractAnonymous wireless networks use covert relays to prevent unauthorized entities from determining communicating parties through traffic timing analysis. In a multipath anonymous network, the choice of which relay nodes should be covert, as well as the route selection by the network nodes, affect both the anonymity and network performance. Although assigning relays as covert and selecting routes composed of covert relays can provide higher anonymity, the selection of these two parameters will increase the packet dropping rate of the network. In this paper, we introduce an analytical framework for joint relay assignment and route selection in multi-path anonymous wireless networks. The main contributions of this work are two-fold. First, we show that joint relay assignment and route selection can be formulated as a convex optimization problem which guarantees global optimum solution. Second, as special cases of our formulation, we derive solutions for the problem of route selection to maximize anonymity when the relay configuration is given, as well as the problem of relay configuration for a given route selection. Chouchang Yang, Basel Alomair, Radha Poovendran |
ISIT | 3 |
| 2013 | A convex optimization approach for clone detection in wireless sensor networks
Tamara Bonaci, Phillip Lee, Linda Bushnell, Radha Poovendran |
Pervasive Mob. Comput. | 4 |
| 2013 | Aviation Cyber-Physical Systems: Foundations for Future Aircraft and Air TransportabstractA century of revolutionary growth in aviation has made global travel a reality of daily life. Aircraft and air transport overcame a number of formidable challenges and hostilities in the physical world. Success in this arduous pursuit was not without leveraging advances of the “cyber” layer, i.e., digital computing, data storage and networking, and software, in hardware, infrastructures, humans, and processes, within the airframe, in space, and on the ground. The physical world, however, is evolving continuously in the 21st century, contributing traffic growth and diversity, fossil fuel and ozone layer depletion, demographics and economy dynamics, as some major factors in aviation performance equations. In the next 100 years, apart from breakthrough physical advances, such as aircraft structural and electrical designs, we envision aviation's progress will depend on conquering cyberspace challenges and adversities, while safely and securely transitioning cyber benefits to the physical world. A tight integration of cyberspace with the physical world streamlines this vision. This paper proposes a novel cyber-physical system (CPS) framework to understand the cyber layer and cyber-physical interactions in aviation, study their impacts, and identify valuable research directions. This paper presents CPS challenges and solutions for aircraft, aviation users, airports, and air traffic management. Krishna Sampigethaya, Radha Poovendran |
Proc. IEEE | 2 |
| 2013 | Toward a Statistical Framework for Source Anonymity in Sensor NetworksabstractIn certain applications, the locations of events reported by a sensor network need to remain anonymous. That is, unauthorized observers must be unable to detect the origin of such events by analyzing the network traffic. Known as the source anonymity problem, this problem has emerged as an important topic in the security of wireless sensor networks, with variety of techniques based on different adversarial assumptions being proposed. In this work, we present a new framework for modeling, analyzing, and evaluating anonymity in sensor networks. The novelty of the proposed framework is twofold: first, it introduces the notion of "interval indistinguishability” and provides a quantitative measure to model anonymity in wireless sensor networks; second, it maps source anonymity to the statistical problem of binary hypothesis testing with nuisance parameters. We then analyze existing solutions for designing anonymous sensor networks using the proposed model. We show how mapping source anonymity to binary hypothesis testing with nuisance parameters leads to converting the problem of exposing private source information into searching for an appropriate data transformation that removes or minimize the effect of the nuisance information. By doing so, we transform the problem from analyzing real-valued sample points to binary codes, which opens the door for coding theory to be incorporated into the study of anonymous sensor networks. Finally, we discuss how existing solutions can be modified to improve their anonymity. Basel Alomair, Andrew Clark 0001, Jorge Cuéllar, Radha Poovendran |
IEEE Trans. Mob. Comput. | 4 |
| 2012 | FakeBook: Detecting Fake Profiles in On-Line Social NetworksabstractOn-line Social Networks (OSNs) are increasingly influencing the way people communicate with each other and share personal, professional and political information. Like the cyberspace in Internet, the OSNs are attracting the interest of the malicious entities that are trying to exploit the vulnerabilities and weaknesses of the OSNs. Increasing reports of the security and privacy threats in the OSNs is attracting security researchers trying to detect and mitigate threats to individual users. With many OSNs having tens or hundreds of million users collectively generating billions of personal data content that can be exploited, detecting and preventing attacks on individual user privacy is a major challenge. Most of the current research has focused on protecting the privacy of an existing online profile in a given OSN. Instead, we note that there is a risk of not having a profile in the last fancy social network! The risk is due to the fact that an adversary may create a fake profile to impersonate a real person on the OSN. The fake profile could be exploited to build online relationship with the friends of victim of identity theft, with the final target of stealing personal information of the victim, via interacting online with the friends of the victim. In this paper, we report on the investigation we did on a possible approach to mitigate this problem. In doing so, we also note that we are the first ones to analyze social network graphs from a dynamic point of view within the context of privacy threats. Mauro Conti, Radha Poovendran, Marco Secchiero |
ASONAM | 2 |
| 2012 | Optimized flow allocation for anonymous communication in multipath wireless networksabstractIn anonymous networks, a subset of nodes is chosen to act as covert relays to hide timing information from unauthorized observers. While such covert relays increase anonymity, they cause performance degradation by delaying or dropping packets. In this paper, we propose flow allocation methods that maximize anonymity for multipath wireless networks with predetermined covert relay nodes, while taking into account packet-loss as a constraint. Using a rate-distortion framework, we show how to assign probabilities which split the flows from source to destination among all possible routes and show that selecting routes according to the assigned probabilities achieves maximum anonymity given the packet-loss constraint. Chouchang Yang, Basel Alomair, Radha Poovendran |
ISIT | 3 |
| 2012 | Leader selection for minimizing convergence error in leader-follower systems: A supermodular optimization approach
Andrew Clark 0001, Linda Bushnell, Radha Poovendran |
WiOpt | 3 |
| 2012 | Message from the workshop chairsabstractAs the organizing committee, it is our pleasure to present the proceedings of the 3rd IEEE International Workshop on Data Security and PrivAcy in wireless Networks (D-SPAN), held on June 25, 2012, in San Francisco, California, USA. The goal of this one-day workshop, organized in conjunction with the 13th IEEE WoWMoM 2012, is to exchange cutting-edge ideas for securing the next-generation wireless networks, systems and applications. The scope of D-SPAN includes a wide variety of topics, including security and privacy of data collection, transmission, storage, publishing, and sharing in wireless networks broadly defined such as cellular and mobile ad hoc networks (MANET), vehicular ad hoc networks (VANET), cognitive and sensor networks to applying data analytics techniques to address security and privacy challenges in these networks. D-SPAN provides a forum for academic and industry researchers to present research ideas that build bridges across three communities: wireless networks and databases, and security. Sajal K. Das 0001, Krishna Sampigethaya, Guevara Noubir, Radha Poovendran |
WOWMOM | 4 |
| 2012 | Special Issue on Cyber-Physical Systems [Scanning the Issue]abstractThis Special Issue presents papers that cover key features of Cyber - Physical Systems (CPS), including new research and technology advances, open problems, and technical challenges with the papers organized into three categories: theoretical foundations, small-scale applications, and large-scale applications. Radha Poovendran, Krishna Sampigethaya, Sandeep K. S. Gupta, Insup Lee 0001, K. Venkatesh Prasad, David Corman, James L. Paunicka |
Proc. IEEE | 1 |
| 2012 | Scalable RFID Systems: A Privacy-Preserving Protocol with Constant-Time IdentificationabstractIn RFID literature, most “privacy-preserving” protocols require the reader to search all tags in the system in order to identify a single tag. In another class of protocols, the search complexity is reduced to be logarithmic in the number of tags, but it comes with two major drawbacks: it requires a large communication overhead over the fragile wireless channel, and the compromise of a tag in the system reveals secret information about other, uncompromised, tags in the same system. In this work, we take a different approach to address time complexity of private identification in large-scale RFID systems. We utilize the special architecture of RFID systems to propose a symmetric-key privacy-preserving authentication protocol for RFID systems with constant-time identification. Instead of increasing communication overhead, the existence of a large storage device in RFID systems, the database, is utilized for improving the time efficiency of tag identification. Basel Alomair, Andrew Clark 0001, Jorge Cuéllar, Radha Poovendran |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2011 | GeM-REM: Generative Model-Driven Resource Efficient ECG Monitoring in Body Sensor NetworksabstractWith recent advances in smart phones and wearable sensors, Body Sensor Networks (BSNs) have been proposed for use in continuous, remote electrocardiogram (ECG) monitoring. In such systems, sampling the ECG at clinically recommended rates (250 Hz) and wireless transmission of the collected data incurs high energy consumption at the energy-constrained body sensor. The large volume of collected data also makes data storage at the sensor infeasible. Thus, there is a need for reducing the energy consumption and data size at the sensor, while maintaining the ECG quality required for diagnosis. In this paper, we propose GeM-REM, a resource-efficient ECG monitoring method for BSNs. GeM-REM uses a generative ECG model at the base station and its lightweight version at the sensor. The sensor transmits data only when the sensed ECG deviates from model-based values, thus saving transmission energy. Further, the model parameters are continually updated based on the sensed ECG. The proposed approach enables storage of ECG data in terms of model parameters rather than data samples, which reduces the required storage space. Implementation on a sensor platform and evaluation using real ECG data from MIT-BIH dataset shows transmission energy and data storage reduction ratios of 42.1:1 and 37.3:1 respectively, which are better than state of the art ECG data compression schemes. Sidharth Nabar, Ayan Banerjee 0001, Sandeep K. S. Gupta, Radha Poovendran |
BSN | 4 |
| 2011 | Distributed clone detection in wireless sensor networks: An optimization approachabstractIn this paper, we study distributed algorithms for detecting cloned nodes in wireless sensor networks. We consider the impact of leaving undetected cloned nodes in the network, as well as the communication cost and the storage cost incurred by each algorithm. We develop an optimization framework for choosing clone detection parameters based on these costs and analyze existing detection schemes using the developed framework. Simulations are provided to validate the methodology. Tamara Bonaci, Phillip Lee, Linda Bushnell, Radha Poovendran |
WOWMOM | 4 |
| 2011 | Securing low-cost RFID systems: An unconditionally secure approachabstractIn this paper, we explore a new direction towards solving the identity authentication problem in RFID systems. We break the RFID authentication process into two main problems: message authentication and random number generation. For parties equipped with a good source of randomness and a secure cry ptographic primitive to authenticate messages, the literature of cryptography is rich with well-studied solutions for secure identity authentication. However, the two operations, random number generation and message authentication, can be expensive for low-cost RFID tags. In this paper, we lay down the foundations of a new direction towards solving these problems in RFID systems. We propose an unconditionally secure direction for authenticating RFID systems. We use the fact that RFID readers are computationally powerful devices to design a protocol that allows RFID readers to deliver random numbers to RFID tags in an unconditionally secure manner. Then, by taking advantage of the information-theoretic security of the transmitted messages, we develop a novel unconditionally secure message authentication code that is computed with a single multiplication operation. The goal of this work is to bring more research to the design of such unconditionally secure protocols, as opposed to the computationally secure protocols that have been proposed extensively, for the purpose of suiting the stringent computational capabilities of low-cost devices. Basel Alomair, Loukas Lazos, Radha Poovendran |
J. Comput. Secur. | 3 |
| 2011 | Future E-Enabled Aircraft Communications and Security: The Next 20 Years and BeyondabstractAircraft data communications and networking are key enablers for civilian air transportation systems to meet projected aviation demands of the next 20 years and beyond. In this paper, we show how the envisioned e-enabled aircraft plays a central role in streamlining system modernization efforts. We show why performance targets such as safety, security, capacity, efficiency, environmental benefit, travel comfort, and convenience will heavily depend on communications, networking and cyber-physical security capabilities of the e-enabled aircraft. The paper provides a comprehensive overview of the state-of-the-art research and standardization efforts. We highlight unique challenges, recent advances, and open problems in enhancing operations as well as certification of the future e-enabled aircraft. Krishna Sampigethaya, Radha Poovendran, Sudhakar Shetty, Terry Davis, Chuck Royalty |
Proc. IEEE | 2 |
| 2011 | Jamming-aware traffic allocation for multiple-path routing using portfolio selectionabstractMultiple-path source routing protocols allow a data source node to distribute the total traffic among available paths. In this paper, we consider the problem of jamming-aware source routing in which the source node performs traffic allocation based on empirical jamming statistics at individual network nodes. We formulate this traffic allocation as a lossy network flow optimization problem using portfolio selection theory from financial statistics. We show that in multisource networks, this centralized optimization problem can be solved using a distributed algorithm based on decomposition in network utility maximization (NUM). We demonstrate the network's ability to estimate the impact of jamming and incorporate these estimates into the traffic allocation problem. Finally, we simulate the achievable throughput using our proposed traffic allocation method in several scenarios. Patrick Tague, Sidharth Nabar, James A. Ritcey, Radha Poovendran |
IEEE/ACM Trans. Netw. | 4 |
| 2010 | Minimizing Energy Consumption in Body Sensor Networks via Convex OptimizationabstractBody Sensor Networks (BSNs) consist of miniature sensors deployed on or implanted into the human body for health monitoring. Conserving the energy of these sensors, while guaranteeing a required level of performance, is a key challenge in BSNs. In terms of communication protocols, this translates to minimizing energy consumption while limiting the latency in data transfer. In this paper, we focus on polling-based communication protocols for BSNs, and address the problem of optimizing the polling schedule to achieve minimal energy consumption and latency. We show that this problem can be posed as a geometric program, which belongs to the class of convex optimization problems, solvable in polynomial time. We also introduce a dynamic priority vector for each sensor, based on the observation that relative priorities of sensors in a BSN change over time. This vector is used to develop a decision-tree based approach for resolving scheduling conflicts among devices. The proposed framework is applicable to a broad class of periodic polling-based communication protocols. We design one such protocol in detail and show that it achieves an improvement of approximately 45% over the widely accepted standard IEEE 802.15.4 MAC protocol. Sidharth Nabar, Jeffrey S. Walling, Radha Poovendran |
BSN | 3 |
| 2010 | Scalable RFID systems: a privacy-preserving protocol with constant-time identificationabstractIn RFID literature, most “privacy-preserving” protocols require the reader to search all tags in the system in order to identify a single tag. In another class of protocols, the search complexity is reduced to be logarithmic in the number of tags, but it comes with two major drawbacks: it requires a large communication overhead over the fragile wireless channel, and the compromise of a tag in the system reveals secret information about other, uncompromised, tags in the same system. In this work, we take a different approach to address time-complexity of private identification in large-scale RFID systems. We utilize the special architecture of RFID systems to propose the first symmetric-key privacy-preserving authentication protocol for RFID systems with constant-time identification. Instead of increasing communication overhead, the existence of a large storage device in RFID systems, the database, is utilized for improving the time efficiency of tag identification. Basel Alomair, Andrew Clark 0001, Jorge Cuéllar, Radha Poovendran |
DSN | 4 |
| 2010 | Statistical Framework for Source Anonymity in Sensor NetworksabstractIn this work, we investigate the security of anonymous wireless sensor networks. To lay down the foundations of a formal framework, we develop a new model for analyzing and evaluating anonymity in sensor networks. The novelty of the proposed model is twofold: first, it introduces the notion of ``interval indistinguishability" that is stronger than existing notions; second, it provides a quantitative measure to evaluate anonymity in sensor networks. The significance of the proposed model is that it captures a source of information leakage that cannot be captured using existing models. By analyzing current anonymous designs under the proposed model, we expose the source of information leakage that is undetectable by existing models and quantify the anonymity of current designs. Finally, we show how the proposed model can lead to a general and intuitive direction for improving the anonymity of current designs. Basel Alomair, Andrew Clark 0001, Jorge Cuéllar, Radha Poovendran |
GLOBECOM | 4 |
| 2010 | Efficient Authentication for Mobile and Pervasive Computing
Basel Alomair, Radha Poovendran |
ICICS | 2 |
| 2010 | Spatial-Temporal Access Control for E-health ServicesabstractThe transformation of healthcare from human-based to online services can expose e-health to the security threats as other online applications. The identities of legitimate e-health users need to be verified cautiously before the access privileges are granted. Since each treatment service of a patient occurs within a time interval and specific location, we propose to make use of time as well as the location as additional parameters in verifying that legitimate users are involved in services. In particular, we develop and implement a prototype of the Spatial-Temporal Access Control to authenticate and authorize users of e-health services, termed STAC-eHS. STAC-eHS is beneficial for e-health services since it allows system users to define the spatial and/or temporal constraints for e-health authentication and authorization decisions, thus, improving e-health system security and protection of patient's privacy. We also perform experiments to evaluate STAC-eHS. The results show that STAC-eHS increases the accuracy of the detection of illegitimate users in an e-health system by about 3-12%, as compared to traditional RBAC, with a small delay of less than two seconds. Apaporn Boonyarattaphan, Sam Chung, Radha Poovendran |
NAS | 4 |
| 2010 | A Metric for Quantifying Key Exposure Vulnerability in Wireless Sensor NetworksabstractWireless sensor networks are often used in applications where message confidentiality, integrity, and authentication are required. Cryptography is a common mechanism for meeting these security requirements. The use of cryptography requires that nodes share secret keys, which are typically assigned to each node according to key distribution schemes. Given a key distribution, there is currently no design metric for evaluating vulnerability to key exposure. In this work, we introduce a metric for analyzing and comparing the resilience of key distributions by introducing the concept of a Link Key Security Metric (LKSM). We define the properties needed in an LKSM and provide a metric that satisfies them. Andrew Clark 0001, Radha Poovendran |
WCNC | 2 |
| 2010 | Privacy versus scalability in radio frequency identification systems
Basel Alomair, Radha Poovendran |
Comput. Commun. | 2 |
| 2010 | Cyber-Physical Systems: Close Encounters Between Two Parallel Worlds [Point of View]abstractTechnology, science, and engineering continue to redefine physical world capabilities. Take mobility of humans, for example. In the 20th century, transportation systems moved us to unimaginable distances, speeds on earth and made us set foot on the Moon. Star Trek popularized teleportation, a fictitious technology that instantly allows us to "go where no person has gone before." Before end of the century, Internet and wireless networking helped to create the parallel "cyber world," virtually "teleporting" us great distances to interact with remote objects, people, and places. In the new millennium, our restless society's need for such ground-breaking capabilities in time and space has never been greater. Cyber-physical system (CPS) is a promising new class of systems that deeply embed cyber capabilities in the physical world, either on humans, infrastructure or platforms, to transform interactions with the physical world. Advances in the cyber world such as communications, networking, sensing, computing, storage, and control, as well as in the physical world such as materials, hardware, and renewable "green" fuels, are all rapidly converging to realize this class of highly collaborative computational systems that are reliant on sensors and actuators to monitor and effect change.Tomorrow's CPS is expected to enrich cyber-physical interactions by intimately coupling assets and dynamics of the physical and engineered systems with the computing and communications of cyber systems, at grand scales and depths from nanosystems to geographically dispersed systems-of-systems. It must be able to adapt rapidly to anomalies in the environment and embrace the evolution of technologies while still providing critical assertions of performance and other constraints. Radha Poovendran |
Proc. IEEE | 1 |
| 2010 | Group Event Detection With a Varying Number of Group Members for Video SurveillanceabstractThis paper presents a novel approach for automatic recognition of group activities for video surveillance applications. We propose to use a group representative to handle the recognition with a varying number of group members, and use an asynchronous hidden Markov model (AHMM) to model the relationship between people. Furthermore, we propose a group activity detection algorithm which can handle both symmetric and asymmetric group activities, and demonstrate that this approach enables the detection of hierarchical interactions between people. Experimental results show the effectiveness of our approach. Weiyao Lin, Ming-Ting Sun, Radha Poovendran, Zhengyou Zhang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2010 | Optimal Jamming Attack Strategies and Network Defense Policies in Wireless Sensor NetworksabstractWe consider a scenario where a sophisticated jammer jams an area in which a single-channel random-access-based wireless sensor network operates. The jammer controls the probability of jamming and the transmission range in order to cause maximal damage to the network in terms of corrupted communication links. The jammer action ceases when it is detected by the network (namely by a monitoring node), and a notification message is transferred out of the jammed region. The jammer is detected by employing an optimal detection test based on the percentage of incurred collisions. On the other hand, the network defends itself by computing the channel access probability to minimize the jamming detection plus notification time. The necessary knowledge of the jammer in order to optimize its benefit consists of knowledge about the network channel access probability and the number of neighbors of the monitor node. Accordingly, the network needs to know the jamming probability of the jammer. We study the idealized case of perfect knowledge by both the jammer and the network about the strategy of each other and the case where the jammer and the network lack this knowledge. The latter is captured by formulating and solving optimization problems where the attacker and the network respond optimally to the worst-case or the average-case strategies of the other party. We also take into account potential energy constraints of the jammer and the network. We extend the problem to the case of multiple observers and adaptable jamming transmission range and propose a meaningful heuristic algorithm for an efficient jamming strategy. Our results provide valuable insights about the structure of the jamming problem and associated defense mechanisms and demonstrate the impact of knowledge as well as adoption of sophisticated strategies on achieving desirable performance. Iordanis Koutsopoulos, Radha Poovendran |
IEEE Trans. Mob. Comput. | 3 |
| 2009 | Group Event Detection for Video SurveillanceabstractThis paper presents a novel approach for automatic recognition of group activities for video surveillance applications. We propose to use a group representative to handle the recognition with flexible or varying number of group members, and use an asynchronous hidden Markov model (AHMM) to model the relationship between two people. Furthermore, we propose a group activity detection algorithm which can handle symmetric and asymmetric group activities, and demonstrate that this approach enables the detection of hierarchical interactions between people. Experimental results show the effectiveness of our approach. Weiyao Lin, Ming-Ting Sun, Radha Poovendran, Zhengyou Zhang |
ISCAS | 3 |
| 2009 | A coding-theoretic approach for efficient message verification over insecure channelsabstractWe address the problem of allowing authorized users, who have yet to establish a secret key, to securely and efficiently exchange key establishment messages over an insecure channel in the presence of jamming and message insertion attacks. This problem was first introduced by Strasser, Pöpper, Čapkun, and Čagalj in their recent work, leaving joint consideration of security and efficiency as an open problem. In this paper, we present three approaches based on coding theory which reduce the overall time required to verify the packets and reconstruct the original message in the presence of jamming and malicious insertion. We first present the Hashcluster scheme which reduces the total overhead included in the short packets. We next present the Merkleleaf scheme which uses erasure coding to reduce the average number of packet receptions required to reconstruct the message. We then present the Witnesscode scheme which uses one-way accumulators to individually verify packets and reduce redundancy. We demonstrate through analysis and simulation that our candidate protocols can significantly decrease the amount of time required for key establishment in comparison to existing approaches without degrading the guaranteed level of security. David Slater, Patrick Tague, Radha Poovendran, Brian J. Matt |
WISEC | 3 |
| 2009 | Evaluating the Vulnerability of Network Traffic Using Joint Security and Routing AnalysisabstractJoint analysis of security and routing protocols in wireless networks reveals vulnerabilities of secure network traffic that remain undetected when security and routing protocols are analyzed independently. We formulate a class of continuous metrics to evaluate the vulnerability of network traffic as a function of security and routing protocols used in wireless networks. We develop two complementary vulnerability definitions using set theoretic and circuit theoretic interpretations of the security of network traffic, allowing a network analyst or an adversary to determine weaknesses in the secure network. We formalize node capture attacks using the vulnerability metric as a nonlinear integer programming minimization problem and propose the GNAVE algorithm, a Greedy Node capture Approximation using Vulnerability Evaluation. We discuss the availability of security parameters to the adversary and show that unknown parameters can be estimated using probabilistic analysis. We demonstrate vulnerability evaluation using the proposed metrics and node capture attacks using the GNAVE algorithm through detailed examples and simulation. Patrick Tague, David Slater, Jason Rogers, Radha Poovendran |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2009 | Mitigation of Control Channel Jamming under Node Capture AttacksabstractAvailability of service in many wireless networks depends on the ability for network users to establish and maintain communication channels using control messages from base stations and other users. An adversary with knowledge of the underlying communication protocol can mount an efficient denial of service attack by jamming the communication channels used to exchange control messages. The use of spread spectrum techniques can deter an external adversary from such control channel jamming attacks. However, malicious colluding insiders or an adversary who captures or compromises system users is not deterred by spread spectrum, as they know the required spreading sequences. For the case of internal adversaries, we propose a framework for control channel access schemes using the random assignment of cryptographic keys to hide the location of control channels. We propose and evaluate metrics to quantify the probabilistic availability of service under control channel jamming by malicious or compromised users and show that the availability of service degrades gracefully as the number of colluding insiders or compromised users increases. We propose an algorithm called GUIDE for the identification of compromised users in the system based on the set of control channels that are jammed. We evaluate the estimation error using the GUIDE algorithm in terms of the false alarm and miss rates in the identification problem. We discuss various design trade-offs between robustness to control channel jamming and resource expenditure. Patrick Tague, Radha Poovendran |
IEEE Trans. Mob. Comput. | 3 |
| 2009 | Analytic evaluation of target detection in heterogeneous wireless sensor networksabstractIn this article, we address the problem of target detection in Wireless Sensor Networks (WSNs). We formulate the target detection problem as a line-set intersection problem and use integral geometry to analytically characterize the probability of target detection for both stochastic and deterministic deployments. Compared to previous work, we analyze WSNs where sensors have heterogeneous sensing capabilities. For the stochastic case, we evaluate the probability that the target is detected by at least k sensors and compute the free path until the target is first detected. For the deterministic case, we show an analogy between the target detection problem and the problem of minimizing the average symbol error probability in 2D digital modulation schemes. Motivated by this analogy, we propose a heuristic sensor placement algorithm, called DATE, that makes use of well-known signal constellations for determining good WSN constellations. We also propose a heuristic called CDATE for connected WSN constellations, that yields high target detection probability. Loukas Lazos, Radha Poovendran, James A. Ritcey |
ACM Trans. Sens. Networks | 2 |
| 2009 | Detection of mobile targets on the plane and in space using heterogeneous sensor networks
Loukas Lazos, Radha Poovendran, James A. Ritcey |
Wirel. Networks | 2 |
| 2008 | Vulnerability of Network Traffic under Node Capture Attacks Using Circuit Theoretic AnalysisabstractWe investigate the impact of node capture attacks on the confidentiality and integrity of network traffic. We map the compromise of network traffic to the flow of current through an electric circuit and propose a metric for quantifying the vulnerability of the traffic using the circuit mapping. We compute the vulnerability metric as a function of the routing and the cryptographic protocols used to secure the network traffic. We formulate the minimum cost node capture attack problem as a nonlinear integer programming problem. Due to the NP-hardness of the minimization problem, we provide a greedy heuristic that approximates the minimum cost attack. We provide examples of node capture attacks using our vulnerability metric and show that the adversary can expend significantly less resources to compromise target traffic by exploiting information leakage from the routing and cryptographic protocols. Patrick Tague, David Slater, Jason Rogers, Radha Poovendran |
INFOCOM | 4 |
| 2008 | Human activity recognition for video surveillanceabstractThis paper presents a novel approach for automatic recognition of human activities from video sequences. We first group features with high correlations into Category Feature Vectors (CFVs). Each activity is then described by a combination of GMMs (Gaussian Mixture Models) with each GMM representing the distribution of a CFV. We show that this approach offers flexibility to add new events and to deal with the problem of lacking training data for building models for unusual events. For improving the recognition accuracy, a Confident-Frame-based Recognizing algorithm (CFR) is proposed to recognize the human activity, where the video frames which have high confidence for recognition an activity (Confident-Frames) are used as a specialized model for classifying the rest of the video frames. Experimental results show the effectiveness of the proposed approach. Weiyao Lin, Ming-Ting Sun, Radha Poovendran, Zhengyou Zhang |
ISCAS | 3 |
| 2008 | Throughput optimization for multipath unicast routing under probabilistic jammingabstractWe present a framework for throughput optimization for multipath unicast routing in wireless networks in the presence of probabilistic jamming. The framework introduces a statistical characterization into the maximum network flow problem to compensate for the reduction in network flow due to the loss of jammed packets. We map the problem of throughput optimization under probabilistic jamming to that of optimal investment portfolio selection, treating the network throughput as the return on financial investments and using a common portfolio selection framework from financial statistics. Based on the portfolio selection framework, we present approaches to maximize expected throughput and to minimize throughput variance. We include both a detailed example and a simulation study to illustrate the application of the throughput optimization framework. Patrick Tague, Sidharth Nabar, James A. Ritcey, David Slater, Radha Poovendran |
PIMRC | 5 |
| 2008 | Secure Operation, Control, and Maintenance of Future E-Enabled AirplanesabstractCommercial aviation is at the threshold of the era of the e-enabled airplane, brought about by the convergence of rapidly expanding worldwide data communication infrastructures, network-centric information processing, and commoditized lightweight computational hardware. With advanced avionics, processing, and wireless communication capabilities, the e-enabled airplane can revolutionize the current air transportation system. However, the use of unregulated information technology and wireless technologies introduces vulnerabilities that can be exploited to provide unauthorized access to the onboard aviation information systems and impede their operation. The emerging security threats are not covered by current aviation guidance, and regulations, hence, remain to be addressed. This paper presents a comprehensive survey of security of the e-enabled airplane with applications such as electronic distribution of loadable software and data, as well as future directions such as wireless health monitoring, networked control, and airborne ad hoc networks. Krishna Sampigethaya, Radha Poovendran, Linda Bushnell |
Proc. IEEE | 2 |
| 2008 | Activity Recognition Using a Combination of Category Components and Local Models for Video SurveillanceabstractThis paper presents a novel approach for automatic recognition of human activities for video surveillance applications. We propose to represent an activity by a combination of category components and demonstrate that this approach offers flexibility to add new activities to the system and an ability to deal with the problem of building models for activities lacking training data. For improving the recognition accuracy, a confident-frame-based recognition algorithm is also proposed, where the video frames with high confidence for recognizing an activity are used as a specialized local model to help classify the remainder of the video frames. Experimental results show the effectiveness of the proposed approach. Weiyao Lin, Ming-Ting Sun, Radha Poovendran, Zhengyou Zhang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2007 | Optimal Jamming Attacks and Network Defense Policies in Wireless Sensor NetworksabstractWe consider a scenario where a sophisticated jammer jams an area in a single-channel wireless sensor network. The jammer controls the probability of jamming and transmission range to cause maximal damage to the network in terms of corrupted communication links. The jammer action ceases when it is detected by a monitoring node in the network, and a notification message is transferred out of the jamming region. The jammer is detected at a monitor node by employing an optimal detection test based on the percentage of incurred collisions. On the other hand, the network computes channel access probability in an effort to minimize the jamming detection plus notification time. In order for the jammer to optimize its benefit, it needs to know the network channel access probability and number of neighbors of the monitor node. Accordingly, the network needs to know the jamming probability of the jammer. We study the idealized case of perfect knowledge by both the jammer and the network about the strategy of one another, and the case where the jammer or the network lack this knowledge. The latter is captured by formulating and solving optimization problems, the solutions of which constitute best responses of the attacker or the network to the worst-case strategy of each other. We also take into account potential energy constraints of the jammer and the network. We extend the problem to the case of multiple observers and adaptable jamming transmission range and propose a intuitive heuristic jamming strategy for that case. Iordanis Koutsopoulos, Radha Poovendran |
INFOCOM | 3 |
| 2007 | Probabilistic detection of mobile targets in heterogeneous sensor networksabstractTarget detection and field surveillance are among the most prominent applications of Sensor Networks (SN). The quality of detection achieved by a SN can be quantified by evaluating the probability of detecting a mobile target crossing a Field of Interest (FoI). In this paper, we analytically evaluate the detection probability of mobile targets when N sensors are stochastically deployed to monitor a Fol. We map the target detection problem to a line-set intersection problem and derive analytical formulas using tools from Integral Geometry and Geometric Probability. We show that the detection probability depends on the length of the perimeters of the sensing areas of the sensors and not their shape. Hence, compared to prior work, our formulation allows us to consider a heterogeneous sensing model, where each sensor can have an arbitrary sensing area. We also evaluate the mean free path until a target is first detected. Loukas Lazos, Radha Poovendran, James A. Ritcey |
IPSN | 2 |
| 2007 | Probabilistic Mitigation of Control Channel Jamming via Random Key DistributionabstractThe use of distinct, dedicated communication channels to transmit data and control traffic introduces a single point of failure for a denial of service attack, in that an adversary may be able to jam control channel traffic and prevent relevant data traffic. Hence, it is of interest to design control channel access schemes which are resilient to jamming. We map the problem of providing resilient control channel access under jamming to that of secure communication channel establishment. We propose the use of random key distribution to hide the location of control channels in time and/or frequency. We evaluate performance metrics of resilience to control channel jamming, identification of compromised users, and delay due to jamming as a function of the number of compromised users. Patrick Tague, Radha Poovendran |
PIMRC | 3 |
| 2007 | Electronic Distribution of Airplane Software and the Impact of Information Security on Airplane Safety
Richard Robinson, Scott Lintelman, Krishna Sampigethaya, Radha Poovendran, David von Oheimb, Jens-Uwe Bußer, Jorge Cuéllar |
SAFECOMP | 5 |
| 2007 | Modeling adaptive node capture attacks in multi-hop wireless networks
Patrick Tague, Radha Poovendran |
Ad Hoc Networks | 2 |
| 2007 | AMOEBA: Robust Location Privacy Scheme for VANETabstractCommunication messages in vehicular ad hoc networks (VANET) can be used to locate and track vehicles. While tracking can be beneficial for vehicle navigation, it can also lead to threats on location privacy of vehicle user. In this paper, we address the problem of mitigating unauthorized tracking of vehicles based on their broadcast communications, to enhance the user location privacy in VANET. Compared to other mobile networks, VANET exhibits unique characteristics in terms of vehicular mobility constraints, application requirements such as a safety message broadcast period, and vehicular network connectivity. Based on the observed characteristics, we propose a scheme called AMOEBA, that provides location privacy by utilizing thegroup navigation of vehicles. By simulating vehicular mobility in freeways and streets, the performance of the proposed scheme is evaluated under VANET application constraints and two passive adversary models. We make use of vehicular groups for anonymous access to location based service applications in VANET, for user privacy protection. The robustness of the user privacy provided is considered under various attacks. Krishna Sampigethaya, Leping Huang, Radha Poovendran |
IEEE J. Sel. Areas Commun. | 4 |
| 2007 | Energy and bandwidth-efficient key distribution in wireless ad hoc networks: a cross-layer approach
Javier Salido, Loukas Lazos, Radha Poovendran |
IEEE/ACM Trans. Netw. | 3 |
| 2007 | A canonical seed assignment model for key predistribution in wireless sensor networksabstractA promising solution for trust establishment in wireless sensor networks is the assignment of cryptographic seeds (keys, secrets, etc.) to sensor nodes prior to network deployment, known as key predistribution . In this article, we propose a canonical seed assignment model for key predistribution characterizing seed assignment in terms of the probability distribution describing the number of nodes receiving each seed and the algorithm for seed assignment. In addition, we present a sampling framework for seed assignment algorithms in the canonical model. We propose a probabilistic k -connectivity model for randomly deployed secure networks using spatial statistics and geometric random graph theory. We analyze key predistribution schemes in the canonical model in terms of network connectivity and resilience to node capture. The analytical results can be used to determine the average or worst-case connectivity or resilience to node capture for a key predistribution scheme. Furthermore, we demonstrate the design of new key predistribution schemes and the inclusion of existing schemes in the canonical model. Finally, we present a general approach to analyze the addition of nodes to an existing secure network and derive results for a well-known scheme. Patrick Tague, Radha Poovendran |
ACM Trans. Sens. Networks | 2 |
| 2007 | Power proximity based key management for secure multicast in ad hoc networks
Loukas Lazos, Radha Poovendran |
Wirel. Networks | 2 |
| 2007 | A graph theoretic framework for preventing the wormhole attack in wireless ad hoc networks
Radha Poovendran, Loukas Lazos |
Wirel. Networks | 1 |
| 2006 | Coverage in heterogeneous sensor networksabstractIn this paper we study the problem of coverage in heterogeneous planar sensor networks. Coverage as a performance metric, quantifies the quality of monitoring provided by the sensor network. We formulate the problem of coverage as a set intersection problem arising in Integral Geometry, and derive analytical expressions for stochastic coverage. Our formulation allows us to consider a heterogeneous sensing model, where sensors need not have an identical sensing capability. In addition, our approach is applicable to scenarios where the sensing area of each sensor has arbitrary shape and sensors are deployed according to any distribution. We present analytical expressions only for convex sensing areas, however, our results can be generalized to non-convex areas. The validity of our expressions is verified by extensive simulations. Loukas Lazos, Radha Poovendran |
WiOpt | 2 |
| 2006 | A general probabilistic model for improving key assignment in wireless networksabstractWe study the problem of establishing secure communication channels in resource-constrained wireless networks using key predistribution. Pairwise communication channels between nodes are secured using link keys which are established as a function of cryptographic seeds predistributed to each node. We propose a general model for seed assignment which regulates the number of nodes sharing each seed. In addition, we provide a general model for wireless network connectivity where communication is restricted by both radio range and an independent pairwise relationship. We provide probabilistic analysis for network connectivity and resilience to node capture in terms of our seed assignment and network connectivity models. Finally, we provide a numerical example demonstrating how the proposed approach reduces key wastage while maintaining resilience to node capture of prior results. Patrick Tague, Radha Poovendran |
WiOpt | 2 |
| 2006 | A framework and taxonomy for comparison of electronic voting schemes
Krishna Sampigethaya, Radha Poovendran |
Comput. Secur. | 2 |
| 2006 | HiRLoc: high-resolution robust localization for wireless sensor networksabstractIn this paper, we address the problem of robustly estimating the position of randomly deployed nodes of a wireless sensor network (WSN), in the presence of security threats. We propose a range-independent localization algorithm called high-resolution range-independent localization (HiRLoc), that allows sensors to passively determine their location with high resolution, without increasing the number of reference points, or the complexity of the hardware of each reference point. In HiRLoc, sensors determine their location based on the intersection of the areas covered by the beacons transmitted by multiple reference points. By combining the communication range constraints imposed by the physical medium with computationally efficient cryptographic primitives that secure the beacon transmissions, we show that HiRLoc is robust against known attacks on WSN, such as the wormhole attack, the Sybil attack, and compromise of network entities. Finally, our performance evaluation shows that HiRLoc leads to a significant improvement in localization accuracy compared with state-of-the-art range-independent localization schemes, while requiring fewer reference points. Loukas Lazos, Radha Poovendran |
IEEE J. Sel. Areas Commun. | 2 |
| 2006 | A Survey on Mix Networks and Their Secure ApplicationsabstractAnonymity is a subdiscipline of information hiding, required in a number of applications, such as in electronic voting. For network communications, anonymity can be provided by a mix network (mixnet). A mixnet is a multistage system that uses cryptography and permutations to provide anonymity. The basic idea of a mixnet has evolved into a number of different classes. In addition to presenting the existing mixnet classifications, this paper classifies mixnets based on the verification mechanisms employed for robustness. The construction of mixnets is presented under a common framework to provide insight into both the design and weaknesses of existing solutions. Basic forms of attack on mixnets and the corresponding robustness solutions are reviewed. Comparison with other solutions for anonymity and suggestions for interesting future research in mix networks are also provided Krishna Sampigethaya, Radha Poovendran |
Proc. IEEE | 2 |
| 2006 | Disenrollment with perfect forward secrecy in threshold schemesabstractIn this correspondence, we propose a new model for threshold schemes with disenrollment capability (TSDC), to address the scenarios in which the ability of a coalition to construct future shared secrets is prohibited. Compared to existing TSDC models, our model provides forward secrecy by adding a constraint that the broadcast from the dealer is required to activate the reconstruction of any secret. We also present a TSDC model in which the dealer has the enhanced capability of disenrolling any subset of participants, to prevent the otherwise unnecessary rekey of the entire group when a large number of participants are compromised. We establish the lower bounds on the entropy of broadcast messages in both proposed models, as guidelines on constructing broadcast efficient schemes, and present bound achieving schemes. Radha Poovendran |
IEEE Trans. Inf. Theory | 2 |
| 2006 | Stochastic coverage in heterogeneous sensor networksabstractWe study the problem of coverage in planar heterogeneous sensor networks. Coverage is a performance metric that quantifies how well a field of interest is monitored by the sensor deployment. To derive analytical expressions of coverage for heterogeneous sensor networks, we formulate the coverage problem as a set intersection problem, a problem studied in integral geometry. Compared to previous analytical results, our formulation allows us to consider a network model where sensors are deployed according to an arbitrary stochastic distribution; sensing areas of sensors need not follow the unit disk model but can have any arbitrary shape; sensors need not have an identical sensing capability. Furthermore, our formulation does not assume deployment of sensors over an infinite plane and, hence, our derivations do not suffer from the border effect problem arising in a bounded field of interest. We compare our theoretical results with the spatial Poisson approximation that is widely used in modeling coverage. By computing the Kullback-Leibler and total variation distance between the probability density functions derived via our theoretical results, the Poisson approximation, and the simulation, we show that our formulas provide a more accurate representation of the coverage in sensor networks. Finally, we provide examples of calculating network parameters such as the network size and sensing range in order to achieve a desired degree of coverage. Loukas Lazos, Radha Poovendran |
ACM Trans. Sens. Networks | 2 |
| 2005 | A key management scheme in distributed sensor networks using attack probabilitiesabstractClustering approaches have been found useful in providing scalable data aggregation, security and coding for large scale distributed sensor networks (DSNs). Clustering (also known as subgrouping) has also been effective in containing and compartmentalizing node compromise in large scale networks. We consider the problem of designing a clustered DSN when the probability of node compromise in different deployment regions is known a priori. We make use of the a priori probability to design a variant of random key predistribution method that improves the resilience and hence the fraction of compromised communications compared to seminal works. We further relate the key ring size of the subgroup node to the probability of node compromise, and design an effective scalable security mechanism that increases the resilience to the attacks for the sensor subgroups. Simulation results show that by using our scheme, the performance can be substantially improved in the sensor network (including the resilience and the fraction of compromised communications) that only sacrifices a small extent in the probability of a shared key exists between two nodes, compared to those of the prior results. Siu-Ping Chan, Radha Poovendran, Ming-Ting Sun |
GLOBECOM | 2 |
| 2005 | Rope: robust position estimation in wireless sensor networksabstractWe address the problem of secure location determination, known as secure localization, and the problem of verifying the location claim of a node, known as location verification, in wireless sensor networks (WSN). We propose a robust positioning system we call ROPE that allows sensors to determine their location without any centralized computation. In addition, ROPE provides a location verification mechanism that verifies the location claims of the sensors before data collection. We show that ROPE bounds the ability of an attacker to spoof sensors' locations, with relatively low density deployment of reference points. We confirm the robustness of ROPE against attacks analytically and via simulations. Loukas Lazos, Radha Poovendran, Srdjan Capkun |
IPSN | 2 |
| 2005 | Scalable power-efficient broadcast over densely deployed wireless ad hoc networksabstractWireless ad hoc or sensor networks usually operate over strictly or partially battery energy limited environments. To prolong the network operating time, energy-efficiency should be carefully considered at every layer of the network protocols and algorithms. Moreover, cross-layer effects and interactions have to be carefully analyzed and utilized. We consider the problem of constructing scalable power-efficient broadcast routing trees over densely deployed wireless ad hoc or sensor networks. The keys to resolving scalability issues are: (1) using a distributed implementation; (2) using a hierarchical approach; (3) using a (partially) shared routing tree structure. We achieve these by using, as a basic building block, the idea of a center-oriented broadcast (COBRA) scheme we presented earlier (Kang, I. and Poovendran, R., IEEE Wireless Commun. and Networking Conf., 2004). Intae Kang, Radha Poovendran |
WCNC | 2 |
| 2005 | Preventing wormhole attacks on wireless ad hoc networks: a graph theoretic approachabstractWe study the problem of characterizing the wormhole attack, an attack that can be mounted on a wide range of wireless network protocols without compromising any cryptographic quantity or network node. A wormhole, in essence, creates a communication link between an origin and a destination point that could not exist with the use of the regular communication channel. Hence, a wormhole modifies the connectivity matrix of the network, and can be described by a graph abstraction of the ad hoc network. Making use of geometric random graphs induced by the communication range constraint of the nodes, we present the necessary and sufficient conditions for detecting and defending against wormholes. Using our theory, we also present a defense mechanism based on local broadcast keys. We believe our work is the first one to present analytical calculation of the probabilities of detection. We also present simulation results to illustrate our theory. Loukas Lazos, Radha Poovendran, Catherine Meadows 0001, Paul F. Syverson, LiWu Chang |
WCNC | 2 |
| 2005 | Iterated Local Optimization for Minimum Energy BroadcastabstractIn our prior work, we presented a highly effective local search based heuristic algorithm called the largest expanding sweep search (LESS) to solve the minimum energy broadcast (MEB) problem over wireless ad hoc or sensor networks. In this paper, the performance is further strengthened by using iterated local optimization (ILO) techniques at the cost of additional computational complexity. To the best of our knowledge, this implementation constitutes currently the best performing algorithm among the known heuristics for MEB. We support this claim through extensive simulation study, comparing with globally optimal solutions obtained by an integer programming (IP) solver. For small network size up to 20 nodes, which is imposed by practical limitation of the IP solver, the ILO based algorithm produces globally optimal solutions with very high frequency (70%), and average performance is within 1.12% of the optimal solution. Intae Kang, Radha Poovendran |
WiOpt | 2 |
| 2005 | Minimizing center key storage in hybrid one-way function based group key management with communication constraints
Radha Poovendran, David A. McGrew |
Inf. Process. Lett. | 2 |
| 2005 | Maximizing Network Lifetime of Broadcasting Over Wireless Stationary Ad Hoc Networks
Intae Kang, Radha Poovendran |
Mob. Networks Appl. | 2 |
| 2005 | SeRLoc: Robust localization for wireless sensor networksabstractMany distributed monitoring applications of Wireless Sensor Networks (WSNs) require the location information of a sensor node. In this article, we address the problem of enabling nodes of Wireless Sensor Networks to determine their location in an untrusted environment, known as the secure localization problem. We propose a novel range-independent localization algorithm called SeRLoc that is well suited to a resource constrained environment such as a WSN. SeRLoc is a distributed algorithm based on a two-tier network architecture that allows sensors to passively determine their location without interacting with other sensors. We show that SeRLoc is robust against known attacks on a WSNs such as the wormhole attack , the Sybil attack , and compromise of network entities and analytically compute the probability of success for each attack. We also compare the performance of SeRLoc with state-of-the-art range-independent localization schemes and show that SeRLoc has better performance. Loukas Lazos, Radha Poovendran |
ACM Trans. Sens. Networks | 2 |
| 2004 | Broadcast with heterogeneous node capability [wireless ad hoc or sensor networks]abstractIn this paper, we investigate the power-efficient broadcast routing problem over heterogeneous wireless ad hoc or sensor networks where network nodes have a heterogeneous capability. The network links between pairs of nodes can no longer be modeled as symmetric or bidirectional. We show that, while most previous power-efficient algorithms work in this setting with minor modifications, they are not designed to exploit such asymmetric constraints. We present a suitable algorithm which takes into account the constraints and yet is the most power-efficient among all known algorithms. Intae Kang, Radha Poovendran |
GLOBECOM | 2 |
| 2004 | Cross-layer design for energy-efficient secure multicast communications in ad hoc networksabstractThis paper considers the problem of secure multicast in an energy-constrained wireless environment. We present an analytical formulation of the energy expenditure associated with the communication overhead of key management and highlight its dependence on the network topology and the key distribution method. We show that the optimal solution of this formulation does not scale with multicast group size and propose a suboptimal, cross-layer, low-complexity algorithm for energy efficient key distribution. We present simulation studies that show the energy savings achieved by our scheme and compare its performance when different routing algorithms are employed. Loukas Lazos, Radha Poovendran |
ICC | 2 |
| 2004 | COBRA: center-oriented broadcast routing algorithms for wireless ad hoc networksabstractWe provide the initial framework for the study of center-oriented broadcast routing problems using omnidirectional antennas. From the intuition that the best place to take advantage of the wireless broadcast advantage is at the center of a network deploy region, we concretize this idea into a currently best performing power-efficient broadcast routing algorithm for wireless ad hoc networks. We support this statement with extensive simulation studies. Intae Kang, Radha Poovendran |
WCNC | 2 |
| 2003 | A comparison of power-efficient broadcast routing algorithmsabstractFollowing the seminal work of Wieselthier et al. on power-efficient broadcast routing, a novel technique called embedded wireless multicast advantage (EWMA) was proposed to further reduce the total transmit power of a broadcast routing tree. In our previous work, we showed that when the network lifetime is defined as the time for the first node failure due to battery depletion, the total transmit power is not the only measure of power-efficiency. We proved that either maximum transmit power or link longevity plays a crucial role in extending the network lifetime. In this paper, we compare the performance of four known power-efficient algorithms (and their variants) not only in terms of the total transmit power but also in terms of other performance measures such as static network lifetime, total receive and interference power, and maximum and average hop count which have direct impacts on physical, link, and MAC layers and on end-to-end network delay. Intae Kang, Radha Poovendran |
GLOBECOM | 2 |
| 2003 | Energy-aware secure multicast communication in ad-hoc networks using geographic location informationabstractThe problem of securing multicast communications in an energy-constrained ad-hoc network requires the efficient management of cryptographic quantities. We show that existing efficient key distribution techniques for wired networks that rely on logical hierarchies are extremely energy inefficient. We also show that the consideration of the physical location of the members is critical for developing energy-efficient key distribution schemes. By exploiting the spatial correlation between the members of the multicast group, we construct an energy-aware key distribution scheme. We present simulation results to illustrate the improvements achieved by our proposed algorithm. Loukas Lazos, Radha Poovendran |
ICASSP (4) | 2 |
| 2003 | Maximizing static network lifetime of wireless broadcast ad hoc networksabstractWe investigate the problem of energy-efficient broadcast routing over wireless static ad hoc network where host mobility is not involves. We define the lifetime of a network as the duration of time until the first node failure due to battery depletion. We provide a globally optimal solution to the problem maximizing a static network lifetime through a graph theoretic approach. We also provide extensive comparative simulation studies. Intae Kang, Radha Poovendran |
ICC | 2 |
| 2003 | Key management and distribution for secure multimedia multicastabstractThe problem of controlling access to multimedia multicasts requires the distribution and maintenance of keying information. Typically, the problem of key management is considered separately from the problem of distributing the rekeying messages. Multimedia sources provide two approaches to distributing the rekeying messages associated with securing group communication. The first, and more conventional approach employs the use of a media-independent channel to convey rekeying messages. We propose, however, a second approach that involves the use of a media-dependent channel, and is achieved for multimedia by using data embedding techniques. Compared to a media-independent channel, the use of data embedding to convey rekeying messages provides enhanced security by masking the presence of rekeying operations. This covert communication makes it difficult for an adversary to gather information regarding the group membership and its dynamics. In addition to proposing a new mode of conveyance for the rekeying messages, we introduce a new message format that is suitable for multicast key management schemes. This new message format uses one-way functions to securely distribute new key material to subgroups of users. An advantage of this approach over the traditional message format is that no additional messages must be sent to flag the users which portion of the message is intended for them, thereby reducing communication overhead. We then show how to map the message to a tree structure in order to achieve desirable scalability in communication and computational overhead. Next, as an example of the interplay between the key management scheme and the mode of conveyance, we study the feasibility of embedding rekeying messages using a data embedding method that has been recently proposed for fractional-pel video coding standards such as H.263 and MPEG-2. Finally, since multimedia services will involve multiple layers or objects, we extend the tree-based key management schemes to include new operations needed to handle multilayer multimedia applications where group members may subscribe or cancel membership to some layers while maintaining membership to other layers. Wade Trappe, Jie Song 0004, Radha Poovendran, K. J. Ray Liu |
IEEE Trans. Multim. | 3 |
| 2001 | Key distribution for secure multimedia multicasts via data embeddingabstractThe problem of controlling access to multimedia multicasts requires the distribution and maintenance of keying information. The conventional approach to distributing keys is to use a channel independent of the multimedia content. We propose a second approach that involves the use of a data-dependent channel, and can be achieved for multimedia by using data embedding techniques. Using data embedding to convey rekeying messages can provide an additional layer of security when compared with the traditional approach. We then introduce multicast key distribution, and employ a recent tree-based key distribution scheme to exhibit the factors involved in transmitting keys using data embedding. Wade Trappe, Jie Song 0004, Radha Poovendran, K. J. Ray Liu |
ICASSP | 3 |
| 2001 | An information-theoretic approach for design and analysis of rooted-tree-based multicast key management schemesabstractPrevious literature presents several seemingly different approaches to rooted-tree-based multicast key distribution schemes that try to minimize the user key storage while providing efficient member deletion. In this paper, we show that the user key storage on rooted trees can be systematically studied using basic concepts from information theory. We show that the rooted-tree-based multicast key distribution problem can be posed as an optimization problem that is abstractly identical to the optimal codeword length selection problem in information theory. In particular, we show that the entropy of member deletion statistics quantifies the optimal value of the average number of keys to be assigned to a member. We relate the sustainable key length to statistics of member deletion event and the hardware bit generation rate. We then demonstrate the difference between the key distribution on rooted trees and the optimal codeword length selection problem with an example of a key distribution scheme that attains optimality but fails to prevent user collusion. Radha Poovendran, John S. Baras |
IEEE Trans. Inf. Theory | 1 |
| 2000 | A Decision-Process Analysis of Implicit CoschedulingabstractThis paper presents a theoretical framework based on Bayesian decision theory for analyzing recently reported results on implicit coscheduling of parallel applications on clusters of workstations. Using probabilistic modeling, We show that the approach presented can be applied for processes with arbitrary communication mixes. We also note that our approach can be used for deciding the additional spin times in the case of spin-yield. Finally, we present arguments for the use of a different notion of fairness than assumed by prior work. Radha Poovendran, Peter J. Keleher, John S. Baras |
IPDPS | 1 |
| 1999 | An Information Theoretic Analysis of Rooted-Tree Based Secure Multicast Key Distribution Schemes
Radha Poovendran, John S. Baras |
CRYPTO | 1 |