EDBT 2026 Demo / reviewers in the wild / expert
Samit Shahnawaz Miftah
dblp:377/4799
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0009-7533-376XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 4 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Microelectronics Systems Education - CHASE: A Cloud-Native Platform for Hardware Security
Rahul Magesh, Amisha Srivastava, Sharath Pendyala, Samit Shahnawaz Miftah, Aydin Aysu, Kanad Basu |
ACM Great Lakes Symposium on VLSI | 4 |
| 2026 | PoSyn: Secure Power Side-Channel Aware SynthesisabstractPower side-channel (PSC) attacks exploit power consumption patterns to extract sensitive information, posing risks to cryptographic operations crucial for secure systems. Traditional countermeasures, such as masking, face challenges like complex synthesis integration, high area overhead, and vulnerability to optimization removal during logic synthesis. To address these issues, we introduce proposed side-channel aware synthesis (PoSyn), a novel logic synthesis framework designed to enhance cryptographic hardware’s resistance against PSC attacks. Our approach focuses on the optimal bipartite mapping of vulnerable register transfer level (RTL) components to standard cells from the technology library to minimize PSC leakage. By employing a cost function that integrates key characteristics from the RTL design and the standard cell library, we strategically modify the mapping criteria during the conversion of RTL designs into standard cell netlists without altering the design functionality. Furthermore, PoSyn is theoretically shown to minimize mutual information leakage, further reinforcing its security against PSC vulnerabilities. PoSyn is evaluated on a variety of cryptographic hardware, including AES, RSA, PRESENT, and postquantum cryptography algorithms like Saber and CRYSTALS-Kyber across 65-, 45-, and 15-nm nodes. Our experimental results demonstrate a significant reduction of success rates for differential power analysis (DPA) and correlation power analysis (CPA) attacks, as low as 3% and 6%, respectively. Furthermore, test vector leakage assessment (TVLA) confirms that the synthesized netlists exhibit negligible leakage. Moreover, compared to traditional countermeasures such as masking and shuffling, PoSyn achieves notably lowers the success rates, achieving a reduction by up to 72%, while simultaneously enhancing area efficiency by as much as$3.79\times $. These results highlight the effectiveness of PoSyn in securing cryptographic hardware with minimal impact on area and performance. Amisha Srivastava, Samit Shahnawaz Miftah, Debjit Pal, Kanad Basu |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2025 | InterConFuzz: A Fuzzing-based Comprehensive NoC Verification FrameworkabstractSecurity verification of Network-on-Chip (NoC) systems is essential due to their intricate and high-concurrency structures. Traditional methods often fail to cover all scenarios or scale effectively, leading to prolonged verification and overlooked vulnerabilities. Our proposed solution, InterConFuzz, a hybrid hardware fuzzing technique, uses symbolic execution for extensive coverage. Developed on Universal Verification Methodology (UVM), InterConFuzz discovered five security flaws in the NoC architecture of the OpenTitan SoC-surpassing existing techniques by three-while reducing memory and computational needs by 24.4% and 29.5%, respectively. Furthermore, InterConFuzz furnished comparable functional coverage compared to existing NoC fuzzing approaches, proving its efficiency and robustness. Samit Shahnawaz Miftah, Kanad Basu |
DAC | 1 |
| 2025 | SymbFuzz: Symbolic Execution Guided Hardware Fuzzing
Samit Shahnawaz Miftah, Amisha Srivastava, Shiyi Wei, Kanad Basu |
MICRO | 1 |
| 2025 | OpenAssert: Towards Secure Assertion Generation using Large Language ModelsabstractAssertions are critical components used in hardware verification, ensuring robust functionality, fortifying design security, and providing essential verification features. Traditional hardware assertion methods are not automated, complicate security audits, and require effort, causing prolonged development cycles. Recent studies have highlighted the potential of commercial Large Language Models (LLMs) to generate security-focused assertions by leveraging textual data from design specifications. However, reliance on proprietary models like GPT-4 severely jeopardizes IP privacy and data confidentiality, undermining transparency and accountability in data handling practices. In this paper, we address secure hardware assertion generation by proposing a practical approach to significantly enhance the feasibility of open-source LLMs. Our proposed method, OpenAssert, involves fine-tuning existing models to be utilized locally at the user’s end without compromising confidentiality. Additionally, we employ Retrieval Augmentation Generation to refine these models, mitigating hallucinations and security-related errors. OpenAssert demonstrates improvements, achieving up to a 44% increase in rouge-1 score, a 49% improvement in cosine similarity, and a 43.4% reduction in word error rate for security-critical designs compared to open-source models. Anand Menon, Samit Shahnawaz Miftah, Amisha Srivastava, Shamik Kundu, Shovik Kundu, Arnab Raha, Suvadeep Banerjee, Deepak Mathaikutty, Kanad Basu |
VTS | 2 |
| 2024 | Assert-O: Context-based Assertion Optimization using LLMsabstractModern computing relies on System-on-Chips (SoCs), integrating IP cores for complex functions. However, this integration introduces vulnerabilities, necessitating rigorous hardware security validation. The effectiveness of this validation depends on the security properties embedded in the SoC. Recent studies explore large language models (LLMs) for generating security properties, but these may not be directly optimized for validation. Manual intervention remains necessary to reduce their number. Security validation methods that rely on human expertise are not scalable as they are time-intensive and prone to human error. In order to address these issues, we introduce Assert-O, an automated framework designed to derive security properties from SoC documentation and optimize the generated properties. It also ranks the properties based on the security vulnerabilities they are associated with, thereby streamlining the validation process. Our method leverages hardware documentation to initially create security properties, which are subsequently consolidated and prioritized based on their level of criticality. This approach serves to expedite the validation procedure. Assert-O is trained on documentation of six IPs from OpenTitan. To evaluate our proposed method, Assert-O was assessed on five other modules from OpenTitan. Assert-O was able to generate 183 properties, which was further optimized to reduce them to 138 properties. Subsequently, these properties were ranked based on their impact on the security of the overall system. Samit Shahnawaz Miftah, Amisha Srivastava, Kanad Basu |
ACM Great Lakes Symposium on VLSI | 1 |
| 2024 | System-on-Chip Information Flow Validation Under Asynchronous ResetsabstractModern System-on-Chip (SoC) designs comprise hundreds of individual IP blocks, each with its custom implementation of reset signals in most cases. The asynchronous nature of these resets while crossing different reset domains makes the SoC prone to various vulnerabilities if not implemented and validated thoroughly. A key aspect in validating system functionality is to ensure the functionality under reset is verified. Traditional simulation-based validation techniques often become a bottleneck in complex SoC designs due to the large control path of these designs. We propose SoCCAR, a SoC validation framework that addresses this problem. SoCCAR leverages control flow graphs (CFG) of the design to extract the control flow associated with property violations caused by reset domain crossings due to asynchronous resets. SoCCAR efficiently tracks the chain of events leading to the payload without suffering from state space explosion, a common challenge in complex designs. We test the efficacy of SoCCAR in detecting such vulnerabilities by developing multiple SoC benchmarks, each embedded with custom vulnerability originating from reset implementations across different domains. These vulnerabilities reflect practical design complexity and correspond to security violations encountered in practice as a result of multiple asynchronous resets. SoCCAR successfully detected all violations with minimal computation overhead and runtime, making it a viable approach for detecting such violations in complex SoC designs. Samit Shahnawaz Miftah, Kshitij Raj, Sandip Ray, Kanad Basu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |