Prithwish Basu Roy

dblp:314/8313 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0003-2025-6102ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 SCREAM: Secure Channels for Real-time Evaluation of Additive Manufacturing
abstract
Additive Manufacturing (AM), also known as 3D printing, offers several advantages, including on-site production, enhanced throughput, and efficient use of raw materials. However, the rise in its usage has also led to an increase in potential threats that aim to disrupt the printing process. These attacks can subtly alter the design (CAD or STL) files or machine instructions (g-code), which can cause significant economic and reputational harm to the victim company. Current detection techniques, based on acoustic, magnetic, and accelerationbased side-channel analysis, have proven to be ineffective. Although power side-channel analysis is more effective than other means, it is expensive and not scalable. This paper proposes a novel detection method, SCREAM, that assumes the user has access to a trusted STL source and an untrusted g-code. SCREAM leverages the pulse trains sent to the motors to reconstruct the executing g-code. To ensure the safe and accurate execution of g-code, a three-level comparison is performed between recovered and untrusted g-code, as well as trusted STL ensuring successful detection of any anomalies present in the executing g-code. Our testing has shown that this method can detect a range of existing attacks on AM, including malicious firmware manipulation, FLAW3D, and Needle in a Haystack.
Prithwish Basu Roy, Jason Blocklove, Mudit Bhargava, Hammond A. Pearce, Prashanth Krishnamurthy, Ozgur Sinanoglu, Nikhil Gupta 0002, Farshad Khorrami, Ramesh Karri
AsiaCCS1
2026 POSTER: Hector - An Agentic LLM Framework for Logic Locking
Prithwish Basu Roy, Akashdeep Saha, Lilas Alrahis, Johann Knechtel, Ozgur Sinanoglu, Ramesh Karri
AsiaCCS1
2026 RTL-Forge: CNF-Anchored, LLM-Assisted Verilog Generation
Prithwish Basu Roy, Akashdeep Saha, Manaar Alam, Johann Knechtel, Michail Maniatakos, Ozgur Sinanoglu, Ramesh Karri
VTS1
2025 Educational Framework for Power Side-Channel Attacks on Neural Networks in Embedded Systems
abstract
We present an educational framework for security analysis of neural networks using the ChipWhisperer (CW) embedded system. More specifically, our contribution is to build a simple framework capable of performing power side-channel attacks from traces directly captured by CW’s microcontroller. CW eliminates the need for expensive and complex equipment like oscilloscopes, which helps to simplify the educational mission. Our work provides a modern educational tool, enabling students to learn about the real-world resilience of neural networks end-to-end, from training to deployment to security analysis, thereby contributing to the development of more secure systems in the future. In addition, we incorporate learning of software coding on embedded systems assisted by large language models.
Rupesh Raj Karn, Prithwish Basu Roy, Johann Knechtel, Ozgur Sinanoglu
ISCAS2
2025 GLLaMoR: Graph-based Logic Locking by Large Language Models for Enhanced Robustness
abstract
Logic locking protects integrated circuits (ICs) from design piracy. The idea is to insert key-controlled components, a.k.a. key-gates, to lock the IC’s functionality, where the correct key is the designer’s secret. The robustness of logic locking can be enhanced by carefully identifying best locations to insert key-gates, e.g., by analyzing the IC’s topology and lock parts with high impact on functional behaviour. Traditionally, the challenge of identifying critical locations relies on computationally-intensive graph traversal and design methods like fault analysis. The rise of large language models (LLMs), which have recently demonstrated proficiency also on complex graph data, presents an interesting opportunity to revisit this challenge. Here, we present GLLaMoR, a first-of-its-kind framework using LLMs on graph-based IC representations to identify critical locking locations. Through LLM performance evaluation and end-to-end case studies, we demonstrate that GLLaMoR paves the way for more effective and scalable logic locking.
Akashdeep Saha, Prithwish Basu Roy, Johann Knechtel, Ramesh Karri, Ozgur Sinanoglu, Lilas Alrahis
VTS2
2024 Offramps: An FPGA-Based Intermediary for Analysis and Modification of Additive Manufacturing Control Systems
abstract
Cybersecurity threats in Additive Manufacturing (AM) are an increasing concern as AM adoption continues to grow. AM is now being used for parts in the aerospace, transportation, and medical domains. Threat vectors which allow for part compromise are particularly concerning, as any failure in these domains would have life-threatening consequences. A major challenge to investigation of AM part-compromises comes from the difficulty in evaluating and benchmarking both identified threat vectors as well as methods for detecting adversarial actions. In this work, we introduce a generalized platform for systematic analysis of attacks against and defenses for 3D printers. Our “OFFRAMPS” platform is based on the open-source 3D printer control board “RAMPS.“ Offramps allows analysis, recording, and modification of all control signals and I/O for a 3D printer. We show the efficacy of Offramps by presenting a series of case studies based on several Trojans, including ones identified in the literature, and show that Offramps can both emulate and detect these attacks, i.e., it can both change and detect arbitrary changes to the g-code print commands.
Jason Blocklove, Md Raz, Prithwish Basu Roy, Hammond A. Pearce, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri
DSN3
2022 Avatar: Reinforcing Fault Attack Countermeasures in EDA with Fault Transformations
abstract
Cryptography hardware are highly vulnerable to a class of side-channel attacks known as Differential Fault Analysis (DFA). These attacks exploit fault induced errors to compromise secret keys from ciphers within a few seconds. A bias in the error probabilities strengthens the attack considerably. It abets in bypassing countermeasures and is also the basis of powerful attack variants like the Differential Fault Intensity Analysis (DFIA) and Statistical Ineffective Fault Analysis (SIFA). In this paper, we make two significant contributions. First, we identify the correlation between fault induced errors and gatelevel parameters like the threshold voltage, gate size, and${V_{\text{DD}}}$. We show how these parameters can influence the bias in the error probabilities. Then, we propose an algorithm, called Avatar, that carefully tunes gate-level parameters to strengthen the redundancy countermeasures against DFA, DFIA, and SIFA attacks with no additional logic needed. The central idea of Avatar is to reconfigure gates in the redundant circuits so that each circuit has a unique behavior to faults, making fault detection much more efficient. In AES for instance, fault attack resistance improves by 40% for DFA and DFIA, and 99% in the case of SIFA. Avatar incurs negligible area overheads and can be quickly adopted in any cipher design. It can be incorporated in commercial EDA flows and provides users with tunable knobs to trade-off performance and power consumption, for fault attack security.
Prithwish Basu Roy, Patanjali SLPSK, Chester Rebeiro
ASP-DAC1