EDBT 2026 Demo / reviewers in the wild / expert
Abdul Serwadda
dblp:42/8733
· DBLP profile ↗
16ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0002-2907-0673ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 5 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Exploiting HDMI and USB Ports for GPU Side-Channel InsightsabstractModern computers rely on USB and HDMI ports for connecting external peripherals and display devices.Despite their built-in security measures, these ports remain susceptible to passive power-based side-channel attacks.This paper presents a new class of attacks that exploit power consumption patterns at these ports to infer GPU activities.We develop a custom device that plugs into these ports and demonstrates that its high-resolution power measurements can drive successful inferences about GPU processes, such as neural network computations and video rendering.The ubiquitous presence of USB and HDMI ports allows for discreet placement of the device, and its non-interference with data channels ensures that no security alerts are triggered.Our findings underscore the need to reevaluate and strengthen the current generation of HDMI and USB port security defenses. CCS Concepts• Security and privacy → Side-channel analysis and countermeasures; Software reverse engineering. Sayed Erfan Arefin, Abdul Serwadda |
CODASPY | 2 |
| 2024 | Secure Audio Classification for Voice Assistants: A Multi-Party Homomorphic ApproachabstractThe widespread adoption of smart speaker technologies like Amazon Echo and Google Home has significantly embedded them into our everyday lives. These devices offer advanced features, including emergency services and smart home capabilities, through environmental sound source detection. However, they also face cybersecurity risks such as backdoor and adversarial attacks, which exploit server-side vulnerabilities. In our experiment, we initially conducted a user survey (n=97) to get an overview of user perspectives on security concerns related to voice assistants. To counteract these threats, our study investigates a secure multi-party homomorphic neural network for audio classification, aiming to safeguard against such threats by processing encrypted audio data. We collected data from 20 homes, extracted time-series features, and encrypted these for input into the Homomorphic Neural Network (HNN), leading to encrypted predictions. The model demonstrated a high accuracy of 93.18% in identifying various audio objects (11 types in this study). This research not only assesses accuracy but also contrasts the multi-party homomorphic method with conventional neural networks across various performance indicators, highlighting the efficiencies, and potential challenges of using encrypted models. Tasnia Ashrafi Heya, Abdul Serwadda |
HSI | 2 |
| 2024 | Exploiting Voice-Controlled Devices to Infer the Layouts of Private SpacesabstractVoice-controlled interactions have recently experienced a surge, fundamentally reshaping how people engage with the digital domain. These interactions are made possible through the integration of voice assistants within devices equipped with microphones and speakers, such as Amazon Echo, Google Nest, etc. Nevertheless, the widespread adoption of these devices in security-sensitive contexts has raised a need to explore their potential security risks. This paper unveils an attack wherein a malicious entity can construct the layout of a user's residence by localizing ambient sound sources, exploiting the user-device communication. To achieve this, we segregated background sound sources like doors, windows, ovens, etc. We then built a classification model to identify these objects with an average accuracy of 91% and a 3D localization mechanism that attained a Relative Distance Error of 15% (85% accuracy). The paper brings to light a security vulnerability that demands mitigation measures to ensure the safe use of voice-controlled devices. Tasnia Ashrafi Heya, Abdul Serwadda |
HSI | 2 |
| 2024 | Unmasking the Giant: A Comprehensive Evaluation of ChatGPT's Proficiency in Coding Algorithms and Data StructuresabstractThe transformative influence of Large Language Models (LLMs) is profoundly reshaping the Artificial Intelligence (AI) technology domain.Notably, ChatGPT distinguishes itself within these models, demonstrating remarkable performance in multi-turn conversations and exhibiting code proficiency across an array of languages.In this paper, we carry out a comprehensive evaluation of ChatGPT's coding capabilities based on what is to date the largest catalog of coding challenges.Our focus is on the python programming language and problems centered on data structures and algorithms, two topics at the very foundations of Computer Science.We evaluate ChatGPT for its ability to generate correct solutions to the problems fed to it, its code quality, and nature of run-time errors thrown by its code.Where ChatGPT code successfully executes, but fails to solve the problem at hand, we look into patterns in the test cases passed in order to gain some insights into how wrong ChatGPT code is in these kinds of situations.To infer whether ChatGPT might have directly memorized some of the data that was used to train it, we methodically design an experiment to investigate this phenomena.Making comparisons with human performance whenever feasible, we investigate all the above questions from the context of both its underlying learning models (GPT-3.5 and GPT-4), on a vast array sub-topics within the main topics, and on problems having varying degrees of difficulty. Sayed Erfan Arefin, Tasnia Ashrafi Heya, Hasan Al-Qudah, Ynes Ineza, Abdul Serwadda |
ICAART (1) | 5 |
| 2021 | Deep Neural Exposure: You Can Run, But Not Hide Your Neural Network Architecture!abstractDeep Neural Networks (DNNs) are at the heart of many of today's most innovative technologies. With companies investing lots of resources to design, build and optimize these networks for their custom products, DNNs are now integral to many companies' tightly guarded Intellectual Property. As is the case for every high-value product, one can expect bad actors to increasingly design techniques aimed to uncover the architectural designs of proprietary DNNs. This paper investigates if the power draw patterns of a GPU on which a DNN runs could be leveraged to glean key details of its design architecture. Based on ten of the most well-known Convolutional Neural Network (CNN) architectures, we study this line of attack under varying assumptions about the kind of data available to the attacker. We show the attack to be highly effective, attaining an accuracy in the 80 percentage range for the best performing attack scenario. Sayed Erfan Arefin, Abdul Serwadda |
IH&MMSec | 2 |
| 2021 | A Wearables-Driven Attack on Examination ProctoringabstractMultiple choice questions are at the heart of many standardized tests and examinations at academic institutions allover the world. In this paper, we argue that recent advancements in sensing and human-computer interaction expose these types of questions to highly effective attacks that today’s proctor’s are simply not equipped to detect. We design one such attack based on a protocol of carefully orchestrated wrist movements combined with haptic and visual feedback mechanisms designed for stealthiness. The attack is done through collaboration between a knowledgeable student (i.e., a mercenary) and a weak student (i.e., the beneficiary) who depends on the mercenary for solutions. Through a combination of experiments and theoretical modeling, we show the attack to be highly effective. The paper makes the case for an outright ban on all tech gadgets inside examination rooms, irrespective of whether their usage appears benign to the plain eye. Tasnia Ashrafi Heya, Abdul Serwadda, Isaac Griswold-Steiner, Richard Matovu |
PST | 2 |
| 2021 | Smartphone speech privacy concerns from side-channel attacks on facial biomechanics
Isaac Griswold-Steiner, Zachary LeFevre, Abdul Serwadda |
Comput. Secur. | 3 |
| 2020 | Defensive Charging: Mitigating Power Side-Channel Attacks on Charging SmartphonesabstractMobile devices are increasingly relied upon in user's daily lives. This dependence supports a growing network of mobile device charging hubs in public spaces such as airports. Unfortunately, the public nature of these hubs make them vulnerable to tampering. By embedding illicit power meters in the charging stations an attacker can launch power side-channel attacks aimed at inferring user activity on smartphones (e.g., web browsing or typing patterns). In this paper, we present three power side-channel attacks that can be launched by an adversary during the phone charging process. Such attacks use machine learning to identify unique patterns hidden in the measured current draw and infer information about a user's activity. To defend against these attacks, we design and rigorously evaluate two defense mechanisms, a hardware-based and software-based solution. The defenses randomly perturb the current drawn during charging thereby masking the unique patterns of the user's activities. Our experiments show that the two defenses force each one of the attacks to perform no better than random guessing. In practice, the user would only need to choose one of the defensive mechanisms to protect themselves against intrusions involving power draw analysis. Richard Matovu, Abdul Serwadda, Argenis V. Bilbao, Isaac Griswold-Steiner |
CODASPY | 2 |
| 2019 | Prying into Private Spaces Using Mobile Device Motion SensorsabstractHuman made structures are designed in a predictable manner, conforming to the expectations of those who use them. These underlying patterns lend themselves to repetition in the way people get between different locations. We investigated the feasibility of an attacker using motion sensor data against their target, with the objective of predicting where they move and what activities they engaged in. In this work, we show that the gyroscope and accelerometer can be used to drive a privacy attack that stealthily maps out a user's private space with high accuracy. In particular, we show that a mobile app with access to this data can leverage it to analyze a user's step execution dynamics, turn operations, and general body movement activities and then methodically combine this information to map out paths and landmarks in protected spaces, such as houses. Using a dataset of 26 users who executed a number of activities and a combination of classification, regression, and distance matching techniques, we show this privacy attack to generate maps whose Normalized Hausdorff Distance from the ground-truth is as low as 0.1159. Zakery Fyke, Isaac Griswold-Steiner, Abdul Serwadda |
PST | 3 |
| 2017 | Handwriting watcher: A mechanism for smartwatch-driven handwriting authenticationabstractDespite decades of research on automated handwriting authentication, there is yet to emerge an automated handwriting authentication application that breaks into the mainstream. In this paper, we argue that the burgeoning wearables market holds the key to a practical handwriting authentication app. With potential applications in online education, standardized testing and mobile banking, we present Handwriting Watcher, a mechanism which leverages a wrist-worn sensor-enabled device to authenticate a user's free handwriting. Through experiments capturing a wide range of writing scenarios, we show Handwriting Watcher attains mean error rates as low as 6.56% across the population. Our work represents a promising step towards a market-ready, generalized handwriting authentication system. Isaac Griswold-Steiner, Richard Matovu, Abdul Serwadda |
IJCB | 3 |
| 2016 | Toward Robotic Robbery on the Touch ScreenabstractDespite the tremendous amount of research fronting the use of touch gestures as a mechanism of continuous authentication on smart phones, very little research has been conducted to evaluate how these systems could behave if attacked by sophisticated adversaries. In this article, we present two Lego-driven robotic attacks on touch-based authentication: a population statistics--driven attack and a user-tailored attack. The population statistics--driven attack is based on patterns gleaned from a large population of users, whereas the user-tailored attack is launched based on samples stolen from the victim. Both attacks are launched by a Lego robot that is trained on how to swipe on the touch screen. Using seven verification algorithms and a large dataset of users, we show that the attacks cause the system’s mean false acceptance rate (FAR) to increase by up to fivefold relative to the mean FAR seen under the standard zero-effort impostor attack. The article demonstrates the threat that robots pose to touch-based authentication and provides compelling evidence as to why the zero-effort attack should cease to be used as the benchmark for touch-based authentication systems. Abdul Serwadda, Vir V. Phoha, Rajesh Kumar 0016, Diksha Shukla |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2015 | When Mice devour the Elephants: A DDoS attack against size-based scheduling schemes in the internet
Abdul Serwadda, Vir V. Phoha |
Comput. Secur. | 1 |
| 2014 | Beware, Your Hands Reveal Your Secrets!abstractResearch on attacks which exploit video-based side-channels to decode text typed on a smartphone has traditionally assumed that the adversary is able to leverage some information from the screen display (say, a reflection of the screen or a low resolution video of the content typed on the screen). This paper introduces a new breed of side-channel attack on the PIN entry process on a smartphone which entirely relies on the spatio-temporal dynamics of the hands during typing to decode the typed text. Implemented on a dataset of 200 videos of the PIN entry process on an HTC One phone, we show, that the attack breaks an average of over 50% of the PINs on the first attempt and an average of over 85% of the PINs in ten attempts. Because the attack can be conducted in such a way not to raise suspicion (i.e., since the adversary does not have to direct the camera at the screen), we believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information. As users conduct more and more of their computing transactions on mobile devices in the open, the paper calls for the community to take a closer look at the risks posed by the now ubiquitous camera-enabled devices. Diksha Shukla, Rajesh Kumar 0016, Abdul Serwadda, Vir V. Phoha |
CCS | 3 |
| 2013 | When kids' toys breach mobile phone securityabstractTouch-based verification --- the use of touch gestures (e.g., swiping, zooming, etc.) to authenticate users of touch screen devices --- has recently been widely evaluated for its potential to serve as a second layer of defense to the PIN lock mechanism. In all performance evaluations of touch-based authentication systems however, researchers have assumed naive (zero-effort) forgeries in which the attacker makes no effort to mimic a given gesture pattern. Abdul Serwadda, Vir V. Phoha |
CCS | 1 |
| 2013 | Examining a Large Keystroke Biometrics Dataset for Statistical-Attack OpeningsabstractResearch on keystroke-based authentication has traditionally assumed human impostors who generate forgeries by physically typing on the keyboard. With bots now well understood to have the capacity to originate precisely timed keystroke sequences, this model of attack is likely to underestimate the threat facing a keystroke-based system in practice. In this work, we investigate how a keystroke-based authentication system would perform if it were subjected to synthetic attacks designed to mimic the typical user. To implement the attacks, we perform a rigorous statistical analysis on keystroke biometrics data collected over a 2-year period from more than 3000 users, and then use the observed statistical traits to design and launch algorithmic attacks against three state-of-the-art password-based keystroke verification systems. Abdul Serwadda, Vir V. Phoha |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2010 | Size-based scheduling: a recipe for DDOS?abstractInternet traffic measurements have shown that the majority of the Internet's flows are short, while a small percentage of the largest flows are responsible for most of the bytes. To exploit this property for performance improvement in routers and Web servers, several studies have proposed size-based schedulings to offer preferential treatment to the shortest flows. In this work, we present analytical and simulation results which confirm that size-based scheduling will ease the task of launching DDOS attacks on the Internet. Abdul Serwadda, Vir V. Phoha, Idris A. Rai |
CCS | 1 |