Sandeep Gupta 0002

dblp:62/3849-2 · DBLP profile ↗
← Back
10ranked-venue papers
8as first author
8since 2021 · last 2026
0000-0001-9220-7700ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Techniques and metrics for evasion attack mitigation
abstract
Evasion attacks pose a substantial risk to the application of Machine Learning (ML) in Cybersecurity, potentially leading to safety hazards or security breaches in large-scale deployments. Adversaries can employ evasion attacks as an initial tactic to deceive malware or network scanners using ML, thereby orchestrating traditional cyber attacks to disrupt systems availability or compromise integrity. Adversarial data designed to fool AI systems for cybersecurity can be engineered by strategically selecting, modifying, or creating test instances. This paper presents novel defender-centric techniques and metrics for mitigating evasion attacks by leveraging adversarial knowledge, exploring potential exploitation methods, and enhancing alarm detection capabilities. We first introduce two new evasion resistance metrics: adversarial failure rate ( afr ) and adversarial failure curves ( afc ). These metrics generalize previous approaches, as they can be applied to threshold classifiers, facilitating analyses for adversarial attacks comparable to those performed with Receiver Operating Characteristics (ROC) curve. Subsequently, we propose two novel evasion resistance techniques (trainset size pinning and model matrix), extending research in keyed intrusion detection and randomization. We explore the application of proposed techniques and metrics to an intrusion detection system as a pilot study using two public datasets, ‘BETH 2021’ and ‘Kyoto 2015’, which are well-established cybersecurity datasets for uncertainty and robustness benchmarking. The experimental results demonstrate that the combination of the proposed randomization techniques consistently produces remarkable improvement over other known randomization techniques.
Francesco Bergadano, Sandeep Gupta 0002, Bruno Crispo
Comput. Secur.2
2025 Evaluating a Bimodal User Verification Robustness Against Synthetic Data Attacks
abstract
Smartphones balance security and convenience by offering both knowledge-based (PINs, patterns) and biometric (facial, fingerprint) verification methods. However, studies have reported that PINs and patterns can be readily circumvented, while synthetically manipulated face data can easily deceive smartphone facial verification mechanisms. In this paper, we design a bimodal user verification mechanism that combines behavioral (pickup gesture) and biological (face) biometrics for user verification on smartphones. This work establishes a baseline for single-user verification scenarios on smartphones using a one-class verification model. The evaluation is performed in two stages: first, performance is assessed in both unimodal and bimodal settings using publicly available datasets; second, the robustness of the employed biological and behavioral traits is examined against four diverse attacks. Our findings emphasize the necessity of investigating diverse attack vectors, particularly fully synthetic data, to design robust user verification mechanisms.
Sandeep Gupta 0002, Rajesh Kumar 0016, Kiran B. Raja, Bruno Crispo, Carsten Maple
SECRYPT1
2025 An investigation of visual foundation models robustness
Sandeep Gupta 0002, Roberto Passerone
Mach. Learn.1
2023 Device Behavioral Profiling for Autonomous Protection Using Deep Neural Networks
abstract
Demand for autonomous protection in computing devices can not go unnoticed with an enormous increase in cyber attacks. Consequently, cybersecurity measures to continuously monitor and analyze device critical activity, identify suspicious behavior, and proactively mitigate security risks are highly desirable. In this article, a concept of behavioral profiling is described to distinguish between benign and malicious software by observing a system's internal resource usage on Windows devices. We rely on the Windows built-in event tracing mechanism to log processes' critical interactions for a given amount of time that are converted into structured data using a graph data structure. After that, we extract features from the generated graphs to analyze a process behavior using a deep neural network. Finally, we evaluate our prototype on a collected dataset that contains one thousand benign and malicious samples each and achieve an accuracy of ≈ 90%.
Sandeep Gupta 0002, Bruno Crispo
ISCC1
2023 A survey of human-computer interaction (HCI) & natural habits-based behavioural biometric modalities for user recognition schemes
Sandeep Gupta 0002, Carsten Maple, Bruno Crispo, Kiran B. Raja, Artsiom Yautsiukhin, Fabio Martinelli
Pattern Recognit.1
2022 Step & turn - A novel bimodal behavioral biometric-based user verification scheme for physical access control
Sandeep Gupta 0002, Mouna Kacimi, Bruno Crispo
Comput. Secur.1
2022 RiderAuth: A cancelable touch-signature based rider authentication scheme for driverless taxis
Sandeep Gupta 0002, Kiran B. Raja, Fabio Martinelli, Bruno Crispo
J. Inf. Secur. Appl.1
2022 IDeAuth: A novel behavioral biometric-based implicit deauthentication scheme for smartphones
Sandeep Gupta 0002, Rajesh Kumar 0016, Mouna Kacimi, Bruno Crispo
Pattern Recognit. Lett.1
2019 DriverAuth: A risk-based multi-modal biometric-based driver authentication scheme for ride-sharing platforms
Sandeep Gupta 0002, Attaullah Buriro, Bruno Crispo
Comput. Secur.1
2018 DIALERAUTH: A Motion-assisted Touch-based Smartphone User Authentication Scheme
abstract
This paper introduces DIALERAUTH - a mechanism which leverages the way a smartphone user taps/enters any text-independent 10-digit number (replicating the dialing process) and the hand's micro-movements she makes while doing so. DIALERAUTH authenticates the user on the basis of timing differences in the entered 10-digit strokes. DIALERAUTH provides enhanced security by leveraging the transparent and unobservable layer based on another modality - user's hand micro-movements. Furthermore, DIALERAUTH increases the usability and acceptability by utilizing the users' familiarity with the dialing process and the flexibility of choosing any combination of 10-digit number. We implemented DIALERAUTH for both data collection and proof-of-concept real-time analysis. We collected, in total 10500 legitimate samples involving 97 users, through an extensive unsupervised field experiment, to evaluate the effectiveness of DIALERAUTH. Analysis using one-class Multilayer Perceptron (MLP) shows a True Acceptance Rate (TAR) of 85.77% in identifying the genuine users. Security analysis involving 240 adversarial attempts proved DIALERAUTH as significantly resilient against random and mimic attacks. A usability study based on System Usability Scale (SUS) reflects a positive feedback on user acceptance (SUS score = 73.29).
Attaullah Buriro, Bruno Crispo, Sandeep Gupta 0002, Filippo Del Frari
CODASPY3