EDBT 2026 Demo / reviewers in the wild / expert
Vireshwar Kumar
dblp:41/9886
· DBLP profile ↗
18ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-2214-1571ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 7 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ImageNet-LC: A Benchmark for Object-Centric Robustness Under Localized Corruptions
Sanchit Gupta, Subrat Kumar Swain, Mayank Taneja, Muskan Singh, Nishtha Gupta, Nikunj Aggarwal, Vireshwar Kumar |
ICPR (7) | 7 |
| 2025 | DeepShieldFed: Securing Face Templates via Deep Cancelable Transforms and Federated LearningabstractThe adoption of facial recognition technology for identity verification has seen significant growth in recent years. While state-of-the-art (SOTA) facial recognition systems demonstrate high accuracy, the biometric features extracted and stored in system databases are inherently privacy-sensitive. If compromised, this data poses a serious threat to user privacy. To address this challenge, we propose a novel federated learning-based cancelable template protection framework that combines secure, user-specific transformations with collaborative training. In our approach, each user’s face features are first converted into a cancelable template, revocable representation, and then used to train a shared model through federated learning, which enables multiple clients to jointly update a global model without sharing their raw or transformed biometric data. We evaluate our method across key security properties, including unlinkability, revocability, and resilience to inversion attacks, in compliance with the ISO/IEC 30136 standard for biometric performance and protection. Experiments conducted on the large-scale CelebA and LFW dataset using modern facial recognition architectures demonstrate that our approach achieves competitive recognition performance while significantly enhancing security, while preserving recognition performance. Amber Hayat, Md. Atiqur Rahman Ahad, Vireshwar Kumar, Ashok Kumar Bhateja |
IJCB | 3 |
| 2025 | SigTem: A non-invertible technique for online signature template protection
Amber Hayat, Syed Sadaf Ali, Vireshwar Kumar, Ashok Kumar Bhateja |
Expert Syst. Appl. | 3 |
| 2024 | SpotOn: Adversarially Robust Keyword Spotting on Resource-Constrained IoT PlatformsabstractIoT devices (e.g., voice assistants) that execute real-time speech commands are proliferating fast in our daily lives. In such a device, detecting the correct keyword spoken as a command triggers the supported function, and hence keyword spotting (KWS) using a machine learning (ML) model is the pivotal task in their functioning. However, KWS is vulnerable to adversarial machine learning (AML)-based attacks through which an adversary can craft an adversarial audio sample that sounds like a benign keyword to a human, but is detected as a different keyword by the KWS pipeline. In this paper, we propose SpotOn, a novel KWS pipeline that both recovers from AML attacks, as well as detects whether an attacker is using the device to generate AML noise. Using the Google speech command dataset, we demonstrate that SpotOn provides reasonable accuracy in correctly detecting keywords in the absence or presence of AML attacks. Through careful optimizations, we enable SpotOn to process streaming speech input on resource-constrained IoT devices. Overall, the design of SpotOn provides critical insights into making voice-controlled IoT devices suitable for safety-critical systems. Mehreen Jabbeen, Vireshwar Kumar, Rijurekha Sen |
AsiaCCS | 2 |
| 2023 | SPAT: Semantic-Preserving Adversarial Transformation for Perceptually Similar Adversarial ExamplesabstractAlthough machine learning models achieve high classification accuracy against benign examples, they are vulnerable to adversarial machine learning (AML) attacks which generate adversarial examples by adding well-crafted perturbations to the benign examples. The perturbations can be increased to enhance the attack success rate, however, if the perturbations are added without considering the semantic or perceptual similarity between the benign and adversarial examples, the attack can be easily perceived/detected. As such, there exists a trade-off between the attack success rate and the perceptual similarity. In this paper, we propose a novel Semantic-Preserving Adversarial Transformation (SPAT) framework which facilitates an advantageous trade-off between the two metrics. SPAT modifies the optimisation objective of an AML attack to include the goal of increasing the attack success rate as well as the goal of maintaining the perceptual similarity between benign and adversarial examples. Our experiments on a variety of datasets including CIFAR-10, GTSRB, and MNIST demonstrate that SPAT-transformed AML attacks achieve better perceptual similarity while maintaining the attack success rates as the conventional AML attacks. Subrat Kumar Swain, Vireshwar Kumar, Dong Seong Kim 0001, Guangdong Bai |
ECAI | 2 |
| 2023 | ZBCAN: A Zero-Byte CAN Defense System
Khaled Serag, Rohit Bhatia, Akram Faqih, Muslum Ozgur Ozmen, Vireshwar Kumar, Z. Berkay Celik, Dongyan Xu |
USENIX Security Symposium | 5 |
| 2021 | Practical Attestation for Edge Devices Running Compute Heavy Machine Learning ApplicationsabstractMachine Learning (EdgeML) algorithms on edge devices facilitate safety-critical applications like building security management and smart city interventions. However, their wired/wireless connections with the Internet make such platforms vulnerable to attacks compromising the embedded software. We find that in the prior works, the issue of regular runtime integrity assessment of the deployed software with negligible EdgeML performance degradation is still unresolved. In this paper, we present PracAttest, a practical runtime attestation framework for embedded devices running compute-heavy EdgeML applications. Unlike the conventional remote attestation schemes that check the entire software in each attestation event, PracAttest segments the software and randomizes the integrity check of these segments over short random attestation intervals. The segmentation coupled with the randomization leads to a novel performance-vs-security trade-off that can be tuned per the EdgeML application’s performance requirements. Additionally, we implement three realistic EdgeML benchmarks for pollution measurement, traffic intersection control, and face identification, using state-of-the-art neural network and computer vision algorithms. We specify and verify security properties for these benchmarks and evaluate the efficacy of PracAttest in attesting the verified software. PracAttest provides 50x-80x speedup over the state-of-the-art baseline in terms of mean attestation time, with negligible impact on application performance. We believe that the novel performance-vs-security trade-off facilitated by PracAttest will expedite the adoption of runtime attestation on edge platforms. Ismi Abidi, Vireshwar Kumar, Rijurekha Sen |
ACSAC | 2 |
| 2021 | Evading Voltage-Based Intrusion Detection on Automotive CAN
Rohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik, Mathias Payer, Dongyan Xu |
NDSS | 2 |
| 2021 | PASAN: Detecting Peripheral Access Concurrency Bugs within Bare-Metal Embedded Applications
Taegyu Kim, Vireshwar Kumar, Junghwan Rhee, Jizhou Chen, Kyungtae Kim, Dongyan Xu, Jing (Dave) Tian |
USENIX Security Symposium | 2 |
| 2021 | Exposing New Vulnerabilities of Error Handling Mechanism in CAN
Khaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik, Dongyan Xu |
USENIX Security Symposium | 3 |
| 2021 | Cumulative Message Authentication Codes for Resource-Constrained IoT NetworksabstractIn resource-constrained Internet-of-Things networks, the use of conventional message authentication codes (MACs) to provide message authentication and integrity is not possible due to the large size of the MAC output. A straightforward yet naive solution to this problem is to employ a truncated MAC which undesirably sacrifices cryptographic strength in exchange for reduced communication overhead. In this article, we address this problem by proposing a novel approach for message authentication called cumulative MAC (CuMAC), which consists of two distinctive procedures: 1) aggregation and 2) accumulation. In aggregation, a sender generates compact authentication tags from segments of multiple MACs by using a systematic encoding procedure. In accumulation, a receiver accumulates the cryptographic strength of the underlying MAC by collecting and verifying the authentication tags. Embodied with these two procedures, CuMAC enables the receiver to achieve an advantageous tradeoff between the cryptographic strength and the latency in the processing of the authentication tags. Furthermore, for some latency-sensitive messages where this tradeoff may be unacceptable, we propose a variant of CuMAC that we refer to as CuMAC with speculation (CuMAC/S). In addition to the aggregation and accumulation procedures, CuMAC/S enables the sender and receiver to employ a speculation procedure for predicting future message values and precomputing the corresponding MAC segments. For the messages which can be reliably speculated, CuMAC/S significantly reduces the MAC verification latency without compromising the cryptographic strength. We have carried out a comprehensive evaluation of CuMAC and CuMAC/S through simulation and a prototype implementation on a real car. He Li 0007, Vireshwar Kumar, Jung-Min Park 0001, Yaling Yang |
IEEE Internet Things J. | 2 |
| 2020 | BlueShield: Detecting Spoofing Attacks in Bluetooth Low Energy Networks
Jianliang Wu 0002, Yuhong Nan, Vireshwar Kumar, Mathias Payer, Dongyan Xu |
RAID | 3 |
| 2018 | Direct Anonymous Attestation with Efficient Verifier-Local Revocation for Subscription SystemabstractFor a computing platform that is compliant with the Trusted Platform Module (TPM) standard, direct anonymous attestation (DAA) is an appropriate cryptographic protocol for realizing an anonymous subscription system. This approach takes advantage of a cryptographic key that is securely embedded in the platform's hardware, and enables privacy-preserving authentication of the platform. In all of the existing DAA schemes, the platform suffers from significant computational and communication costs that increase proportionally to the size of the revocation list. This drawback renders the existing schemes to be impractical when the size of the revocation list grows beyond a relatively modest size. In this paper, we propose a novel scheme called Lightweight Anonymous Subscription with Efficient Revocation (LASER) that addresses this very problem. In LASER, the computational and communication costs of the platform's signature are multiple orders of magnitude lower than the prior art. LASER achieves this significant performance improvement by shifting most of the computational and communication costs from the DAA's online procedure (i.e., signature generation) to its offline procedure (i.e., acquisition of keys/credentials). We have conducted a thorough analysis of LASER's performance related features. We have implemented LASER on a laptop with an on-board TPM. To the best of our knowledge, this is the first implementation of a DAA scheme on an actual TPM cryptoprocessor that is compliant with the most recent TPM specification, viz., TPM 2.0. Vireshwar Kumar, He Li 0007, Noah Luther, Pranav Asokan, Jung-Min Park 0001, Kaigui Bian, Martin B. H. Weiss, Taieb Znati |
AsiaCCS | 1 |
| 2017 | Transmitter authentication using hierarchical modulation in dynamic spectrum sharing
Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian |
J. Netw. Comput. Appl. | 1 |
| 2016 | PHY-Layer Authentication Using Duobinary Signaling for Spectrum EnforcementabstractSpectrum security and enforcement is one of the major challenges that need to be addressed before spectrum sharing technologies can be adopted widely. The problem of rogue transmitters is a major threat to the viability of spectrum sharing. One approach for deterring rogue transmissions is to enable receivers to authenticate or uniquely identify transmitters. Although cryptographic mechanisms at the higher layers have been widely used to authenticate transmitters, the ability to authenticate transmitters at the physical (PHY) layer has a number of key advantages over higher layer approaches. In existing schemes, the authentication signal is added to the message signal in such a way that the authentication signal appears as noise to the message signal and vice versa. Hence, existing schemes are constrained by a fundamental tradeoff between the message signal's signal-to-noise ratio (SNR) and the authentication signal's SNR. In this paper, we extend the precoded duobinary signaling (P-DS) technique to devise a new PHY-layer authentication scheme called P-DS for authentication (P-DSA). P-DSA exploits the redundancy introduced by P-DS to embed the authentication signal into the message signal. P-DSA is not constrained by the aforementioned tradeoff between the message and authentication signals. Our results show that P-DSA improves the detection performance compared with the prior art without sacrificing message throughput or increasing transmission power. Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Group Signatures with Probabilistic Revocation: A Computationally-Scalable Approach for Providing Privacy-Preserving AuthenticationabstractGroup signatures (GSs) is an elegant approach for providing privacy-preserving authentication. Unfortunately, modern GS schemes have limited practical value for use in large networks due to the high computational complexity of their revocation check procedures. We propose a novel GS scheme called the Group Signatures with Probabilistic Revocation (GSPR), which significantly improves scalability with regard to revocation. GSPR employs the novel notion of probabilistic revocation, which enables the verifier to check the revocation status of the private key of a given signature very efficiently. However, GSPR's revocation check procedure produces probabilistic results, which may include false positive results but no false negative results. GSPR includes a procedure that can be used to iteratively decrease the probability of false positives. GSPR makes an advantageous tradeoff between computational complexity and communication overhead, resulting in a GS scheme that offers a number of practical advantages over the prior art. We provide a proof of security for GSPR in the random oracle model using the decisional linear assumption and the bilinear strong Diffie-Hellman assumption. Vireshwar Kumar, He Li 0007, Jung-Min Park 0001, Kaigui Bian, Yaling Yang |
CCS | 1 |
| 2014 | Blind Transmitter Authentication for Spectrum Security and EnforcementabstractRecent advances in spectrum access technologies, such as cognitive radios, have made spectrum sharing a viable option for addressing the spectrum shortage problem. However, these advances have also contributed to the increased possibility of "hacked" or "rogue" radios causing harm to the spectrum sharing ecosystem by causing significant interference to other wireless devices. One approach for countering such threats is to employ a scheme that can be used by a regulatory entity (e.g., FCC) to uniquely identify a transmitter by authenticating its waveform. This enables the regulatory entity to collect solid evidence of rogue transmissions that can be used later during an adjudication process. We coin the term Blind Transmitter Authentication (BTA) to refer to this approach. Unlike in the existing techniques for PHY-layer authentication, in BTA, the entity that is authenticating the waveform is not the intended receiver. Hence, it has to extract and decode the authentication signal "blindly" with little or no knowledge of the transmission parameters. In this paper, we propose a novel BTA scheme called Frequency offset Embedding for Authenticating Transmitters (FEAT). FEAT embeds the authentication information into the transmitted waveform by inserting an intentional frequency offset. Our results indicate that FEAT is a practically viable approach and is very robust to harsh channel conditions. Our evaluation of FEAT is based on theoretical bounds, simulations, and indoor experiments using an actual implementation. Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian |
CCS | 1 |
| 2014 | Security and Enforcement in Spectrum SharingabstractWhen different stakeholders share a common resource, such as the case in spectrum sharing, security and enforcement become critical considerations that affect the welfare of all stakeholders. Recent advances in radio spectrum access technologies, such as cognitive radios, have made spectrum sharing a viable option for significantly improving spectrum utilization efficiency. However, those technologies have also contributed to exacerbating the difficult problems of security and enforcement. In this paper, we review some of the critical security and privacy threats that impact spectrum sharing. We propose a taxonomy for classifying the various threats, and describe representative examples for each threat category. We also discuss threat countermeasures and enforcement techniques, which are discussed in the context of two different approaches: ex ante (preventive) and ex post (punitive) enforcement. Jung-Min Park 0001, Jeffrey H. Reed, A. A. Louis Beex, T. Charles Clancy, Vireshwar Kumar, Behnam Bahrak |
Proc. IEEE | 5 |