Anirban Chakraborty 0003

dblp:73/2286-3 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
11since 2021 · last 2025
0000-0001-7411-7509ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 8 since 2021Systems, architecture and hardware · 5 · 4 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2025 IND-CPAbf C: A New Security Notion for Conditional Decryption in Fully Homomorphic Encryption
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Nimish Mishra, Ayantika Chatterjee, Debdeep Mukhopadhyay
PQCrypto (2)2
2025 Systematic Evaluation of Randomized Cache Designs against Cache Occupancy
Anirban Chakraborty 0003, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya, Debdeep Mukhopadhyay
USENIX Security Symposium1
2024 On the Security of Privacy-Preserving Machine Learning Against Model Stealing Attacks
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Ayantika Chatterjee, Debdeep Mukhopadhyay
CANS (2)2
2024 Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault Attacks
abstract
Existing countermeasures to DVFS based fault attacks are overly restrictive because (1) they prevent benign, non-SGX processes from utilizing DVFS, and (2) rely upon a less practical threat model than that of Intel SGX. Consequently, this work proposes a new countermeasure principle to defend against DVFS based fault attacks on modern Intel systems. First, we establish that the fundamental cause of DVFS fault attacks is the ability to independently control the frequency and voltage of a processor. Using this observation, we construct a partition of frequency-voltage tuples into unsafe-safe states based on whether a tuple causes timing violations according to switching circuit theoretic principles. Our countermeasure completely prevents DVFS faults on three Intel generation CPUs: Sky Lake, Kaby Lake R, and Comet Lake. Further, it can also be deployed both as microcode or as model-specific registers at the hardware level, unlike previous countermeasures. Our countermeasure incurs a slowdown of only 0.28% on overall system performance when benchmarked against SPEC2017.
Nimish Mishra, Rahul Arvind Mool, Anirban Chakraborty 0003, Debdeep Mukhopadhyay
DAC3
2024 "Ask and Thou Shall Receive": Reaction-Based Full Key Recovery Attacks on FHE
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Ayantika Chatterjee, Debdeep Mukhopadhyay
ESORICS (4)2
2024 FHEDA: Efficient Circuit Synthesis with Reduced Bootstrapping for Torus FHE
abstract
Fully Homomorphic Encryption (FHE) schemes are widely used cryptographic primitives for performing arbitrary computations on encrypted data. However, FHE incorporates a computationally intensive mechanism called bootstrapping, that resets the noise in the ciphertext to a lower level allowing the computation on circuits of arbitrary depth. This process can take significant time, ranging from several minutes to hours. To address the above issue, in this work, we propose an Electronic Design Automation (EDA) framework$\mathsf{FHEDA}$that generates efficient Boolean representations of circuits compatible with the Torus-FHE (ASIACRYPT 2020) scheme. To the best of our knowledge, this is the first work in the EDA domain of FHE. We integrate logic synthesis and gate optimization techniques into our$\mathsf{FHEDA}$framework for reducing the total number of bootstrapping operations in a Boolean circuit, which leads to a significant (up to 50%) reduction in homomorphic computation time. Our$\mathsf{FHEDA}$is built upon the observation that in Torus-FHE two consecutive Boolean gate evaluations over fresh encryptions require only one bootstrapping instead of two, based on appropriate parameter choices. By integrating this observation with logic replacement techniques into$\mathsf{FHEDA}$, we could reduce the total number of bootstrapping operations along with the circuit depth. This eventually reduces the homomorphic evaluation time of Boolean circuits. In order to verify the efficacy of our approach, we assess the performance of the proposed EDA flow on a diverse set of representative benchmarks including privacy-preserving machine learning and different symmetric key block ciphers.
Smita Das, Anirban Chakraborty 0003, Rajat Sadhukhan, Ayantika Chatterjee, Debdeep Mukhopadhyay
EuroS&P3
2024 Faults in Our Bus: Novel Bus Fault Attack to Break ARM TrustZone
Nimish Mishra, Anirban Chakraborty 0003, Debdeep Mukhopadhyay
NDSS2
2024 Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel Processors
Anirban Chakraborty 0003, Nimish Mishra, Debdeep Mukhopadhyay
USENIX Security Symposium1
2023 Are Randomized Caches Truly Random? Formal Analysis of Randomized-Partitioned Caches
abstract
Cache based side-channel attacks exploit the fact that an adversary can setup the shared cache memory (the last level cache in modern systems) into a known state and detect any microarchitectural state changes made by the victim on the cache. Different mitigation techniques have been proposed in the literature that aims to mitigate these attacks by randomizing the address to cache location mappings. The security guarantees in these schemes are based on the degree of difficulty for an attacker to reliably determine the cache lines accessed by the victim within practical time settings. However, prior attacks have shown that newer and more improved algorithms can be envisaged that discover conflicting sets in the secured randomized caches. In this work, we first categorize different types of cache designs into four broad classes based on the extent of non-determinism and randomness of allocating an address in those caches. We then develop a mathematical framework to formally analyse the security implications of the randomized and partitioned cache designs in terms of collision probability, self-collision probability and size of the eviction set required to perform a successful eviction-based attack. We further empirically demonstrate set associative eviction on recently proposed randomization schemes called Mirage and Scattercache. Next, we propose two algorithms to generate efficient eviction set on these schemes and analytically evaluate the efficacy of our algorithms against the one proposed in the literature. Finally, we argue that mere randomization using a cryptographic primitive as used in popular schemes like Scattercache, CEASER-S, Mirage etc. does not provide the required randomness. Although the randomized-partitioned caches provide some resilience against eviction-set generation techniques, they are still vulnerable to eviction-based attacks.
Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay
HPCA1
2022 Time's a Thief of Memory - Breaking Multi-tenant Isolation in TrustZones Through Timing Based Bidirectional Covert Channels
Nimish Mishra, Anirban Chakraborty 0003, Urbi Chatterjee, Debdeep Mukhopadhyay
CARDIS2
2022 Timed speculative attacks exploiting store-to-load forwarding bypassing cache-based countermeasures
abstract
In this paper, we propose a novel class of speculative attacks, called Timed Speculative Attacks (TSA), that does not depend on the state changes in the cache memory. Instead, it makes use of the timing differences that occur due to store-to-load forwarding. We propose two attack strategies - Fill-and-Forward utilizing correctly speculated loads, and Fill-and-Misdirect using mis-speculated load instructions. While Fill-and-Forward exploits the shared store buffers in a multi-threaded CPU core, the Fill-and-Misdirect approach exploits the influence of rolled back mis-speculated loads on subsequent instructions. As case studies, we demonstrate a covert channel using Fill-and-Forward and key recovery attacks on OpenSSL AES and Romulus-N Authenticated Encryption with Associated Data scheme using Fill-and-Misdirect approach. Finally, we show that TSA is able to subvert popular cache-based countermeasures for transient attacks.
Anirban Chakraborty 0003, Nikhilesh Singh, Sarani Bhattacharya, Chester Rebeiro, Debdeep Mukhopadhyay
DAC1
2020 ExplFrame: Exploiting Page Frame Cache for Fault Analysis of Block Ciphers
abstract
Page Frame Cache (PFC) is a purely software cache, present in modern Linux based operating systems (OS), which stores the page frames that were recently released by the processes running on a particular CPU. In this paper, we show that the page frame cache can be maliciously exploited by an adversary to steer the pages of a victim process to some pre-decided attacker-chosen locations in the memory. We practically demonstrate an end-to-end attack, ExplFrame, where an attacker having only user-level privilege is able to force a victim process's memory pages to vulnerable locations in DRAM and deterministically conduct Rowhammer to induce faults. As a case study, we induce single bit faults in the T-tables on OpenSSL (v1.1.1) AES using our proposed attack ExplFrame. We also propose an improvised fault analysis technique which can exploit any Rowhammer-induced bit-flips in the AES T-tables.
Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay
DATE1
2019 Deep Learning Based Diagnostics for Rowhammer Protection of DRAM Chips
abstract
Modern day DRAM chips have been shown to have a reliability issue which can lead to erratic bit flips, a phenomenon which is called Rowhammer. Although current DRAM modules come with in-built countermeasures, recent attacks have shown they are still vulnerable. The Rowhammer vulnerability has been used in conjunction with other side-channels to lead to devastating attacks. In this work, we take a novel approach by training a deep learning model based on several successful and unsuccessful attempts to conduct Rowhammer. The objective of the model is to analyze the access patterns of the DRAM by reverse engineering the physical address to pinpoint exact DRAM location and in turn use them for early prediction of a potential Rowhammer flip. We showed that our approach could detect a probable Rowhammer attempt with considerably high accuracy and even before the completion of the attack. In a more general context, this work shows that suitable combinations of deep learning and reverse engineering of physical address space can help to enhance both the reliability and security of systems.
Anirban Chakraborty 0003, Manaar Alam, Debdeep Mukhopadhyay
ATS1