EDBT 2026 Demo / reviewers in the wild / expert
Mark Yampolskiy
dblp:74/1161
· DBLP profile ↗
11ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0003-4626-2754ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 5 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Stop Stealing My Data: Sanitizing Stego Channels in 3D Printing Design FilesabstractThe increased adoption of additive manufacturing (AM) and the acceptance of AM outsourcing created an ecosystem in which the sending and receiving of digital designs by different actors became normal. It has recently been shown that the STL design files---most commonly used in AM---contain steganographic channels. Such channels can allow additional data to be embedded within the STL files without changing the printed model. These factors create a threat of misusing the design files as a covert communication channel to either exfiltrate stolen sensitive digital data from organizations or infiltrate malicious software into a secure environment. This paper addresses this security threat by designing and evaluating a sanitizer that erases hidden content where steganographic channels might exist. The proposed sanitizer takes into account a set of specific constraints imposed by the application domain, such as not affecting the ability to manufacture part of the required quality using the sanitized design. Aleksandr Dolgavin, Mark Yampolskiy, Moti Yung |
CODASPY | 2 |
| 2022 | AMSec'22: ACM CCS Workshop on Additive Manufacturing (3D Printing) SecurityabstractWhile Security is universally needed, it is rarely plug-and-play. The new domain of Additive Manufacturing (a.k.a. 3D Printing) Security requires novel solutions to its unique security concerns. This workshop brings together researchers and practitioners working in this highly inter-disciplinary research field and closely related areas. Mark Yampolskiy, Moti Yung |
CCS | 1 |
| 2022 | Crypto-Steganographic Validity for Additive Manufacturing (3D Printing) Design Files
Mark Yampolskiy, Lynne Graves, Jacob Gatlin, Jeffrey Todd McDonald, Moti Yung |
ISC | 1 |
| 2021 | Encryption is Futile: Reconstructing 3D-Printed Models Using the Power Side-ChannelabstractOutsourced Additive Manufacturing (AM) exposes sensitive design data to external malicious actors. Even with end-to-end encryption between the design owner and 3D-printer, side-channel attacks can be used to bypass cyber-security measures and obtain the underlying design. In this paper, we develop a method based on the power side-channel that enables accurate design reconstruction in the face of full encryption measures without any prior knowledge of the design. Our evaluation on a Fused Deposition Modeling (FDM) 3D Printer has shown 99 % accuracy in reconstruction, a significant improvement on the state of the art. This approach demonstrates the futility of pure cyber-security measures applied to Additive Manufacturing. Jacob Gatlin, Sofia Belikovetsky, Yuval Elovici, Anthony Skjellum, Joshua Lubell, Paul Witherell, Mark Yampolskiy |
RAID | 7 |
| 2021 | What Did You Add to My Additive Manufacturing Data?: Steganographic Attacks on 3D Printing FilesabstractAdditive Manufacturing (AM) adoption is increasing in home and industrial settings, but information security for this technology is still immature. Thus far, three security threat categories have been identified: technical data theft, sabotage, and illegal part manufacturing. In this paper, we expand to a new threat category: misuse of digital design files as a subliminal communication channel. We identify and explore attacks by which arbitrary information can be embedded steganographically in the most common digital design file format, the STL, without distorting the printed object. Because the technique will not change the manufactured object’s geometry, it is likely to remain unnoticed and can be exploited for data transfer. Further, even with knowledge of our methods, defenders cannot distinguish between actual data transfer and random manipulation of the files. This is the first info-hiding attack on this system, conducted despite the fact that random changes may spoil the physical artifact and result in detection. Mark Yampolskiy, Lynne Graves, Jacob Gatlin, Anthony Skjellum, Moti Yung |
RAID | 1 |
| 2019 | Digital Audio Signature for 3D Printing IntegrityabstractAdditive manufacturing (AM, or 3D printing) is a novel manufacturing technology that has been adopted in industrial and consumer settings. However, the reliance of this technology on computerization has raised various security concerns. In this paper, we address issues associated with sabotage via tampering during the 3D printing process by presenting an approach that can verify the integrity of a 3D printed object. Our approach operates on acoustic side-channel emanations generated by the 3D printer's stepper motors, which results in a non-intrusive and real-time validation process that is difficult to compromise. The proposed approach constitutes two algorithms. The first algorithm is used to generate a master audio fingerprint for the verifiable unaltered printing process. The second algorithm is applied when the same 3D object is printed again, and this algorithm validates the monitored 3D printing process by assessing the similarity of its audio signature with the master audio fingerprint. To evaluate the quality of the proposed thresholds, we identify the detectability thresholds for the following minimal tampering primitives: insertion, deletion, replacement, and modification of a single tool path command. By detecting the deviation at the time of occurrence, we can stop the printing process for compromised objects, thus saving time and preventing material waste. We discuss various factors that impact the method, such as background noise, audio device changes, and different audio recorder positions. Sofia Belikovetsky, Yosef A. Solewicz, Mark Yampolskiy, Jinghui Toh, Yuval Elovici |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Identifying 3D printer residual data via open-source documentation
Daniel Bradford Miller, William Glisson, Mark Yampolskiy, Kim-Kwang Raymond Choo |
Comput. Secur. | 3 |
| 2017 | How to Ensure Bad Quality in Metal Additive Manufacturing: In-Situ Infrared Thermography from the Security PerspectiveabstractAdditive Manufacturing, a.k.a. 3D Printing, is increasingly used to manufacture functional parts, including components of safety critical systems. Therefore, assuring part quality has become of paramount importance. In-situ infrared (IR) imaging systems are a promising solution to increase final build quality and minimize time-consuming and costly post processing and characterization. However, it also raises novel security concerns. We argue that, if compromised, the same in-situ quality control can be abused to sabotage manufactured parts. As a basis for our discussion, we first detail how IR thermography is used in open-loop and, experimentally, in closed-loop quality control for powder bed fusion (PBF) systems. We then identify malicious manipulations that an adversary can perform. We discuss the consequences of the manipulations on the manufactured part's quality. For selected attacks, we also provide experimental proof of the identified manipulations and their consequences. Andrew Slaughter, Mark Yampolskiy, Manyalibo Matthews, Wayne E. King, Gabe Guss, Yuval Elovici |
ARES | 2 |
| 2013 | Reliability Analysis of Wireless Real-Time Control NetworksabstractProbability of successful delivery under deadline constraints is one of the most important performance measures in a wireless real-time multihop control and sensor network. In this paper we approach the problem of determining the probability of successful packet delivery by calculating the per-link outage probability for different fading channel models. We provide easily computable results for the end-to-end reliability for two different physical layer designs. Furthermore, we show that incorporating physical layer information into routing and scheduling decisions can result in significant performance improvements when strict deadlines are imposed on the system. Mark Yampolskiy, Yuan Xue 0001, Xenofon Koutsoukos, Janos Sztipanovits |
ICCCN | 2 |
| 2007 | Management of Multidomain End-to-End Links; A Federated Approach for the Pan-European Research Network Géant 2abstractModern large-scale research projects require a tight international cooperation and have exceeding network bandwidth demands. Dedicated optical multi gigabit End-to-End (E2E) Links offer a possible way to meet these requirements. These links generally are realized with layer 1 and 2 technologies and cross multiple networks operated by different organisational domains. The federated organisation of the operation and the usage of heterogeneous hardware applying a variety of information access and management techniques require a new approach for the management of these multidomain E2E Links. This paper gives an overview about the organisational and technical challenges of E2E Link operations and shows the elaborated solution as well as intermediate results of the ongoing work within the pan-European research network Geant2. Mark Yampolskiy, Matthias K. Hamm |
Integrated Network Management | 1 |
| 2005 | Code security analysis with assertionsabstractDesigning and implementing cryptographic protocols is known to be difficult. A lot of research has been devoted to develop formal techniques to analyze abstract designs of cryptographic protocols. Less attention has been paid to the verification of implementation-relevant aspects of cryptographic protocols. This is an important challenge since it is non-trivial to securely implement secure designs, because a specification by its nature is more abstract than the corresponding implementation, and the additional information may introduce attacks not present on the design level. We propose an approach to determine security goals provided by a protocol implementation based on control flow graphs and automated theorem provers for first-order logic. More specifically, here we explain how to make use of assertions in the source code for a practical and efficient security analysis. Jan Jürjens, Mark Yampolskiy |
ASE | 2 |