EDBT 2026 Demo / reviewers in the wild / expert
Khaza Anuarul Hoque
dblp:88/10918
· DBLP profile ↗
38ranked-venue papers
2as first author
27since 2021 · last 2026
0000-0002-1625-6479ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 2 first-author · 9 since 2021Systems, architecture and hardware · 12 · 1 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 7 since 2021Human-computer interaction and ubiquitous computing · 7 · 7 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Theory of computation · 4 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RIFT: A Scalable Methodology for LLM Accelerator Fault Assessment using Reinforcement LearningabstractThe massive scale of modern AI accelerators presents critical challenges to traditional fault assessment methodologies, which face prohibitive computational costs and provide poor coverage of critical failure modes. This paper introduces RIFT (Reinforcement Learning-guided Intelligent Fault Targeting), a scalable framework that automates the discovery of minimal, high-impact fault scenarios for efficient design-time fault assessment. RIFT transforms the complex search for worst-case faults into a sequential decision-making problem, combining hybrid sensitivity analysis for search space pruning with reinforcement learning to intelligently generate minimal, high-impact test suites. Evaluated on billion-parameter Large Language Model (LLM) workloads using NVIDIA A100 GPUs, RIFT achieves a 2.2× fault assessment speedup over evolutionary methods and reduces the required test vector volume by over 99% compared to random fault injection, all while achieving superior fault coverage. The proposed framework also provides actionable data to enable intelligent hardware protection strategies, demonstrating that RIFT-guided selective error correction code provides a 12.8× improvement in cost-effectiveness (coverage per unit area) compared to uniform triple modular redundancy protection. RIFT automatically generates UVM-compliant verification artifacts, ensuring its findings are directly actionable and integrable into commercial RTL verification workflows. Khurram Khalil, Muhammad Mahad Khaliq, Khaza Anuarul Hoque |
DATE | 3 |
| 2026 | CHOP: Breaking Anonymity in XR through a Novel and Cost-effective Chain of Privacy Attacks and Differential Privacy-Based DefensesabstractThe convergence of artificial intelligence (AI) and extended reality (XR) technologies (AIXR) promises innovative applications across many domains. However, the sensitive nature of data (e.g., eye-tracking) used in these systems also raises significant privacy concerns, as adversaries can exploit this data and these models to infer personal information. Prior research has primarily examined membership inference attacks (MIA) to leak privacy at the model-level and re-identification attacks (RDA) at the dataset-level, separately as individual attacks. While these attacks are relevant to the XR domain, launching these attacks as individual attacks is not practical and incurs more attack cost. To address this gap, we present the first comprehensive study of chain of privacy (CHOP) attacks against AIXR applications. We demonstrate how adversaries can launch such attacks with a high success rate, in a cost-effective way, by sequentially combining MIA and Attribute inference attacks (AIA) to re-identify XR users without access to raw XR data, training distributions, or model parameters. We evaluate our proposed method in realistic AIXR settings by adopting deep learning (DL)-based cybersickness detection as a representative AIXR application. Specifically, we train two state-of-the-art DL models on two open-source datasets: Simulation 2021 and VRWalking, and a new XR cybersickness dataset constructed from 34 participants via a user study. Our findings reveal that the proposed CHOP attacks pose severe risks to DL-based cybersickness detection, achieving re-identification rates of up to 94% and 97% on the open-source and the developed cross-linked datasets, respectively, underscoring the feasibility and severity of cross-dataset privacy violations. Furthermore, cost analysis reveals that the proposed CHOP attack is ≈ 2× more cost-effective than traditional individual attacks for re-identifying XR users. Finally, we propose two ε-differential privacy (DP)-enabled privacy-preserving mechanisms: Differentially Private Stochastic Gradient Descent (DPSGD) and Private Aggregation of Teacher Ensembles (PATE) to mitigate CHOP attacks. Our results show that the proposed defense reduces the re-identification rate by up to 88% and 79% while maintaining high model utility, with classification accuracies of up to 94% and 92% for the same datasets using Transformer models. Ripan Kumar Kundu, Brendan David-John, Khaza Anuarul Hoque |
VR | 3 |
| 2025 | EdgeGuard: Robust and Fault-Aware Design for Resilient Edge Computing AI Accelerators
Sabrina Ahmed, Khaza Anuarul Hoque, Benjamin Carrión Schäfer |
ACM Great Lakes Symposium on VLSI | 2 |
| 2025 | TOGGLE: Temporal Logic-Guided Large Language Model Compression for EdgeabstractLarge Language Models (LLMs) deliver exceptional performance across natural language tasks but demand substantial computational resources, limiting their deployment on resource-constrained edge devices. Existing compression techniques, such as quantization and pruning, often degrade critical linguistic properties and lack formal guarantees for preserving model behavior. We propose TOGGLE (Temporal Logic-Guided Large Language Model Compression), a novel framework that leverages Signal Temporal Logic (STL) to formally specify and enforce linguistic properties during compression. TOGGLE employs an STL robustness-guided Bayesian optimization to systematically explore layer-wise quantization and pruning configurations, generating compressed models that formally satisfy specified linguistic constraints without re-training or fine-tuning. Evaluating TOGGLE on four LLM architectures (GPT-2, DeepSeek-V2 7B, LLaMA 3 8B, and Mistral 7B), we achieve up to 3.3× reduction in computational costs (FLOPs) and up to a 68.8% reduction in model size while satisfying all linguistic properties. TOGGLE represents the first integration of formal methods into LLM compression, enabling efficient, verifiable deployment of LLMs on edge hardware. Khurram Khalil, Khaza Anuarul Hoque |
ICCAD | 2 |
| 2025 | EPSILON: Adaptive Fault Mitigation in Approximate Deep Neural Network using Statistical SignaturesabstractThe increasing adoption of approximate computing in deep neural network accelerators (AxDNNs) promises significant energy efficiency gains. However, permanent faults in AxDNNs can severely degrade their performance compared to their accurate counterparts (AccDNNs). Traditional fault detection and mitigation approaches, while effective for AccDNNs, introduce substantial overhead and latency, making them impractical for energy-constrained real-time deployment. To address this, we introduce EPSILON, a lightweight framework that leverages pre-computed statistical signatures and layer-wise importance metrics for efficient fault detection and mitigation in AxDNNs. Our framework introduces a novel non-parametric pattern-matching algorithm that enables constant-time fault detection without interrupting normal execution while dynamically adapting to different network architectures and fault patterns. EPSILON maintains model accuracy by intelligently adjusting mitigation strategies based on a statistical analysis of weight distribution and layer criticality while preserving the energy benefits of approximate computing. Extensive evaluations across various approximate multipliers, AxDNN architectures, popular datasets (MNIST, CIFAR-10, CIFAR-100, ImageNet-1k), and fault scenarios demonstrate that EPSILON maintains 80.05% accuracy while offering 22% improvement in inference time and 28% improvement in energy efficiency, establishing EPSILON as a practical solution for deploying reliable AxDNNs in safety-critical edge applications. Khurram Khalil, Khaza Anuarul Hoque |
IJCNN | 2 |
| 2025 | ApproXAI: Energy-Efficient Hardware Acceleration of Explainable AI using Approximate ComputingabstractExplainable artificial intelligence (XAI) enhances AI system transparency by framing interpretability as an optimization problem. However, this approach often necessitates numerous iterations of computationally intensive operations, limiting its applicability in real-time scenarios. While recent research has focused on XAI hardware acceleration on FPGAs and TPU, these methods do not fully address energy efficiency in real-time settings. To address this limitation, we propose XAIedge, a novel framework that leverages approximate computing techniques into XAI algorithms, including integrated gradients, model distillation, and Shapley analysis. XAIedge translates these algorithms into approximate matrix computations and exploits the synergy between convolution, Fourier transform, and approximate computing paradigms. This approach enables efficient hardware acceleration on TPU-based edge devices, facilitating faster real-time outcome interpretations. Our comprehensive evaluation demonstrates that XAIedge achieves a 2× improvement in energy efficiency compared to existing accurate XAI hardware acceleration techniques while maintaining comparable accuracy. These results highlight the potential of XAIedge to significantly advance the deployment of explainable AI in energy-constrained real-time applications. Ayesha Siddique, Khurram Khalil, Khaza Anuarul Hoque |
IJCNN | 3 |
| 2025 | PrivateXR: Defending Privacy Attacks in Extended Reality Through Explainable AI-Guided Differential PrivacyabstractThe convergence of artificial intelligence (AI) and extended reality (XR) technologies (AI XR) promises innovative applications across many domains. However, the sensitive nature of data (e.g., eyetracking) used in these systems raises significant privacy concerns, as adversaries can exploit these data and models to infer and leak personal information through membership inference attacks (MIA) and re-identification (RDA) with a high success rate. Researchers have proposed various techniques to mitigate such privacy attacks, including differential privacy (DP). However, AI XR datasets often contain numerous features, and applying DP uniformly can introduce unnecessary noise to less relevant features, degrade model accuracy, and increase inference time, limiting real-time XR deployment. Motivated by this, we propose a novel framework combining explainable AI (XAI) and DP-enabled privacy-preserving mechanisms to defend against privacy attacks. Specifically, we leverage post-hoc explanations to identify the most influential features in AI XR models and selectively apply DP to those features during inference. We evaluate our XAI-guided DP approach on three state-of-the-art AI XR models and three datasets: cybersickness, emotion, and activity classification. Our results show that the proposed method reduces MIA and RDA success rates by up to 43 % and 39 %, respectively, for cybersickness tasks while preserving model utility with up to 97 % accuracy using Transformer models. Furthermore, it improves inference time by up to$\approx 2 \times$compared to traditional DP approaches. To demonstrate practicality, we deploy the XAI-guided DP AI XR models on an HTC VIVE Pro headset and develop a user interface (UI), namely PrivateXR, allowing users to adjust privacy levels (e.g., low, medium, high) while receiving real-time task predictions, protecting user privacy during XR gameplay. Finally, we validate our approach through a user study, which confirms that participants found the PrivateXR UI effective, with satisfactory utility and user experience. Ripan Kumar Kundu, Istiak Ahmed, Khaza Anuarul Hoque |
ISMAR | 3 |
| 2025 | Hyperproperty-Constrained Secure Reinforcement LearningabstractHyperproperties for Time Window Temporal Logic (HyperTWTL) is a domain-specific formal specification language known for its effectiveness in compactly representing security, opacity, and concurrency properties for robotics applications. This paper focuses on HyperTWTL-constrained secure reinforcement learning (SecRL). Although temporal logic-constrained safe reinforcement learning (SRL) is an evolving research problem with several existing literature, there is a significant research gap in exploring security-aware reinforcement learning (RL) using hyperproperties. Given the dynamics of an agent as a Markov Decision Process (MDP) and opacity/security constraints formalized as HyperTWTL, we propose an approach for learning security-aware optimal policies using dynamic Boltzmann softmax RL while satisfying the HyperTWTL constraints. The effectiveness and scalability of our proposed approach are demonstrated using a pick-up and delivery robotic mission case study. We also compare our results with two other baseline RL algorithms, showing that our proposed method outperforms them. Ernest Bonnah, Luan Viet Nguyen, Khaza Anuarul Hoque |
MEMOCODE | 3 |
| 2025 | Enhancing Immersive Virtual Reality Experiences with Multiple Tasks Prediction Using Pre-Trained Large Foundation ModelsabstractImmersive virtual reality (VR) environments pose significant cognitive and physical challenges as users engage in multitasking scenarios involving attention management and working memory, often leading to increased cognitive load, sensory conflicts, and cybersickness, diminishing users’ performance and immersion. While traditional machine learning (ML) and deep learning (DL) methods have been employed to predict individual factors such as cybersickness or attention, they often fail to capture the interconnected and dynamic nature of these cognitive and physiological demands. Moreover, these methods typically require large volumes of labeled data, extended training times, and struggle to generalize across diverse VR contexts. To address these limitations, we propose an innovative method for predicting multiple tasks, i.e., cybersickness, cognitive load, working memory, and attention by leveraging the knowledge of pre-trained large foundation models, namely TimeGPT and Chronos. We apply two learning mechanisms, zero-shot and few-shot learning, for adapting these foundation models for multiple task predictions. We validate our approach on the open-source VRWalking dataset, utilizing multimodal data fusion and participant-specific grouping (based on age and gender), and compare it against traditional DL-based methods trained from scratch. Results show that our few-shot-based fine-tuned TimeGPT and Chronos models significantly outperform traditional DL models in multiple tasks. Specifically, the fine-tuned TimeGPT model achieves significantly lower RMSE values for predicting cybersickness, cognitive physical load, cognitive mental load, working memory, attention success rate, and reaction time, respectively, outperforming the traditional transformer. Furthermore, the fine-tuned TimeGPT model achieves a 4.52 × reduction in training time compared to a conventional Transformer model for the same prediction tasks. Moreover, we deploy the fine-tuned TimeGPT model on the HTC VIVE Pro VR headset, enabling real-time prediction of multiple task severity levels from streaming VR simulation data during gameplay. Ripan Kumar Kundu, Istiak Ahmed, Khaza Anuarul Hoque |
VRST | 3 |
| 2025 | Securing Virtual Reality Experiences: Unveiling and Tackling Cybersickness Attacks With Explainable AIabstractThe synergy between virtual reality (VR) and artificial intelligence (AI), specifically deep learning (DL)-based cybersickness detection models, has ushered in unprecedented advancements in immersive experiences by automatically detecting cybersickness severity and adaptively various mitigation techniques, offering a smooth and comfortable VR experience. While this DL-enabled cybersickness detection method provides promising solutions for enhancing user experiences, it also introduces new risks since these models are vulnerable to adversarial attacks; a small perturbation of the input data that is visually undetectable to human observers can fool the cybersickness detection model and trigger unexpected mitigation, thus disrupting user immersive experiences (UIX) and even posing safety risks. In this paper, we present a new type of VR attack, specifically a cybersickness attack, which successfully prevents the triggering of cybersickness mitigation by deceiving DL-based cybersickness detection models and significantly hinders the UIX. Next, we propose a novel explainable artificial intelligence (XAI)-guided cybersickness attack detection framework to detect such attacks in VR, ensuring UIX and a comfortable VR experience. We evaluate the proposed attack and detection framework using two state-of-the-art open-source VR cybersickness datasets: the Simulation 2021 dataset and the Gameplay dataset. Finally, to verify the effectiveness of our proposed method, we implement the attack and the XAI-based detection using a custom-built testbed with a VR roller coaster simulation, utilizing an HTC Vive Pro Eye headset, and conduct a user study. Our study shows that such an attack can dramatically hinder the UIX. However, our proposed XAI-guided cybersickness attack detection can successfully detect cybersickness attacks and trigger the proper mitigation, effectively reducing VR cybersickness. Ripan Kumar Kundu, Matthew Denton, Genova Mongalo, Prasad Calyam, Khaza Anuarul Hoque |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Explainable AI-Guided Neural Architecture Search for Adversarial Robustness in Approximate DNNsabstractDeep neural networks are lucrative targets of adversarial attacks and approximate deep neural networks (AxDNNs) are no exception. Searching manually for adversarially robust AxDNN architectures incurs outrageous time and human effort. In this paper, we propose XAI-NAS, an explainable neural architecture search (NAS) method that leverages explainable artificial intelligence (XAI) to efficiently co-optimize the adversarial robustness and hardware efficiency of AxDNN architectures on systolic-array hardware accelerators. During the NAS process, AxDNN architectures are evolved layer-wise with heterogeneous approximate multipliers to deliver the best trade-offs between adversarial robustness, energy consumption, latency, and memory footprint. The most suitable approximate multipliers are automatically selected from an open-source Evoapprox8b library. Our extensive evaluations provide a set of Pareto optimal hardware efficient and adversarially robust solutions. For example, a Pareto-optimal DNN AxDNN for the MNIST and CIFAR-10 datasets exhibits up to 1.5× higher adversarial robustness, 2.1× less energy consumption, 4.39× reduced latency, and 2.37× low memory footprint when compared to the state-of-the-art NAS approaches. Ayesha Siddique, Khaza Anuarul Hoque |
IEEE Trans. Sustain. Comput. | 2 |
| 2024 | Efficient SMT-Based Model Checking for HyperTWTL
Ernest Bonnah, Luan Viet Nguyen, Khaza Anuarul Hoque |
ICFEM | 3 |
| 2024 | Preserving Personal Space: Differentially Private Cybersickness Detection in Immersive Virtual Reality EnvironmentsabstractCybersickness is a common problem that users often encounter during virtual reality (VR) experiences. Several automated methods exist based on machine learning (ML)/deep learning (DL) to detect cybersickness. However, the sensitive nature of data used by these ML/DL models (e.g., eye-tracking, head-tracking, etc.) introduces significant privacy risks since adversaries could exploit this data to infer and leak sensitive personal information, track individuals, or manipulate user experiences. Our research seeks to address this gap, underscoring the necessity for a private approach to cybersickness detection to protect user privacy and ensure a better VR experience. Thus, this paper proposes a privacy-preserving mechanism for DL-enabled cybersickness detection modeled. Specifically, we employ differential privacy (DP) to develop four private DL cybersickness detection models: long short-term memory (LSTM), grated recurrent unit (GRU), convolutional neural network (CNN), and multilayer perceptron (MLP) using Simulations 2021 and Gameplay, two open-source datasets. Our proposed models show high cybersickness detection accuracy for the proposed private cybersickness models. For instance, the private LSTM model shows the cybersickness detection accuracy of up to 92% and 91% for the Simulations 2021 and Gameplay datasets, respectively. Our experimental results also exhibit the privacy-preserving nature of private cybersickness detection. For instance, the private LSTM model reduces the membership inference attack’s success rate by up to 32% and 45% for the Simulations 2021 and Gameplay datasets compared to the baseline/non-private LSTM model for the same datasets. Ripan Kumar Kundu, Khaza Anuarul Hoque |
ISMAR | 2 |
| 2024 | Mazed and Confused: A Dataset of Cybersickness, Working Memory, Mental Load, Physical Load, and Attention During a Real Walking Task in VRabstractVirtual Reality (VR) is quickly establishing itself in various industries, including training, education, medicine, and entertainment, in which users are frequently required to carry out multiple complex cognitive and physical activities. However, the relationship between cognitive activities, physical activities, and familiar feelings of cybersickness is not well understood and thus can be unpredictable for developers. Researchers have previously provided labeled datasets for predicting cybersickness while users are stationary, but there have been few labeled datasets on cybersickness while users are physically walking. Moreover, it is unclear how walking while cybersick will affect cognitive load, even though room-scale interaction is typical in many VR games. Thus, from 39 participants, we collected head orientation, head position, eye tracking, images, physiological readings from external sensors, and the self-reported cybersickness severity, physical load, and mental load in VR. Throughout the data collection, participants navigated mazes via real walking and performed tasks challenging their attention and working memory. To demonstrate the dataset’s utility, we conducted a case study of training classifiers in which we achieved 95% accuracy for cybersickness severity classification. The noteworthy performance of the straightforward classifiers makes this dataset ideal for future researchers to develop cybersickness detection and reduction models. To better understand the features that helped with classification, we performed SHAP(SHapley Additive exPlanations) analysis, highlighting the importance of eye tracking and physiological measures for cybersickness prediction while walking. This open dataset can allow future researchers to study the connection between cybersickness and cognitive loads and develop prediction models. This dataset will empower future VR developers to design efficient and effective Virtual Environments by improving cognitive load management and minimizing cybersickness. Jyotirmay Nag Setu, Joshua M. Le, Ripan Kumar Kundu, Barry Giesbrecht, Tobias Höllerer, Khaza Anuarul Hoque, Kevin Desai, John Quarles |
ISMAR | 6 |
| 2024 | Formal Verification for Blockchain-based Insurance Claims ProcessingabstractInsurance claims processing involves multi-domain entities and multi-source data, along with a number of human-agent interactions. Use of Blockchain technology-based platform can significantly improve scalability and response time for processing of claims which are otherwise manually-intensive and time-consuming. However, the chaincodes involved within the processes that issue claims, approve or deny them as required, need to be formally verified to ensure secure and reliable processing of transactions in Blockchain. In this paper, we use a formal modeling approach to verify various processes and their underlying chaincodes relating to different stages in insurance claims processing viz., issuance, approval, denial, and flagging for fraud investigation by using linear temporal logic (LTL). We simulate the formalism on the chaincodes and analyze the breach of chaincodes via model checking. Roshan Neupane, Ernest Bonnah, Bishnu Bhusal, Kiran Neupane, Khaza Anuarul Hoque, Prasad Calyam |
NOMS | 5 |
| 2024 | Moving Target Defense Through Approximation for Low-Power Neuromorphic Edge IntelligenceabstractNeuromorphic intelligence is driven by spiking neural networks (SNNs) to achieve high algorithmic performance. However, similar to artificial neural networks (ANNs), SNNs are vulnerable to adversarial attacks. Such attacks often succeed in misclassification by repeatedly probing a fixed target model. Recent works claim that repeated attacks can be defended in ANNs by employing a moving target defense (MTD). Nonetheless, the state-of-the-art defense mechanisms in SNNs do not consider the notion of moving targets and are limited to shallow network architectures. To this end, we propose a novel MTD strategy for neuromorphic edge intelligence (MTSpike) that incorporates approximate knowledge distillation based on the distinct inherent structural parameters, i.e., firing threshold and time steps in SNNs, under a pre-train and finetune paradigm. Indeed, it is a 2-in-1 approach that enhances robustness against repeated attacks and reduces energy consumption for deeper SNNs. We evaluate our proposed MTSpike with four benchmark image classification datasets, i.e., ImageNet, CIFAR10, DVS128 Gesture, and CIFAR10-DVS datasets against white-box, black-box, and grey-box FGSM, PGD, sparse and efficiency attacks on deep residual SNNs. Our results demonstrate that MTSpike outperforms the state-of-the-art defense techniques by enabling SNNs to operate with a negligible drop in classification accuracy (as low as 1%–2%) under adversarial attacks. Also, MTSpike achieves 1.3× higher energy efficiency under efficiency attack. Apart from defense, MTSpike provides an additional advantage of energy efficiency by reducing the spike rate by 3× in deeper SNNs. Ayesha Siddique, Khaza Anuarul Hoque |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2023 | Security-Aware Approximate Spiking Neural Networks
Syed Tihaam Ahmad, Ayesha Siddique, Khaza Anuarul Hoque |
DATE | 3 |
| 2023 | Improving Reliability of Spiking Neural Networks through Fault Aware Threshold Voltage OptimizationabstractSpiking neural networks have made breakthroughs in computer vision by lending themselves to neuromorphic hardware. However, the neuromorphic hardware lacks parallelism and hence, limits the throughput and hardware acceleration of SNNs on edge devices. To address this problem, many systolic-array SNN accelerators (systolicSNNs) have been proposed recently, but their reliability is still a major concern. In this paper, we first extensively analyze the impact of permanent faults on the SystolicSNNs. Then, we present a novel fault mitigation method, i.e., fault-aware threshold voltage optimization in retraining (FalVolt). FalVolt optimizes the threshold voltage for each layer in retraining to achieve the classification accuracy close to the baseline in the presence of faults. To demonstrate the effectiveness of our proposed mitigation, we classify both static (i.e., MNIST) and neuromorphic datasets (i.e., N-MNIST and DVS Gesture) on a 256x256 systolicSNN with stuck-at faults. We empirically show that the classification accuracy of a systolicSNN drops significantly even at extremely low fault rates (as low as 0.012%). Our proposed FalVolt mitigation method improves the performance of systolicSNNs by enabling them to operate at fault rates of up to 60%, with a negligible drop in classification accuracy (as low as 0.1%). Our results show that FalVolt is 2x faster compared to other state-of-the-art techniques common in artificial neural networks (ANNs), such as fault-aware pruning and retraining without threshold voltage optimization. Ayesha Siddique, Khaza Anuarul Hoque |
DATE | 2 |
| 2023 | VR-LENS: Super Learning-based Cybersickness Detection and Explainable AI-Guided Deployment in Virtual RealityabstractVirtual reality (VR) systems are known for their susceptibility to cybersickness, which can seriously hinder users’ experience. Therefore, a plethora of recent research has proposed several automated methods based on machine learning (ML) and deep learning (DL) to detect cybersickness. However, these detection methods are perceived as computationally intensive and black-box methods. Thus, those techniques are neither trustworthy nor practical for deploying on standalone VR head-mounted displays (HMDs). This work presents an explainable artificial intelligence (XAI)-based framework VR-LENS for developing cybersickness detection ML models, explaining them, reducing their size, and deploying them in a Qualcomm Snapdragon 750G processor-based Samsung A52 device. Specifically, we first develop a novel super learning-based ensemble ML model for cybersickness detection. Next, we employ a post-hoc explanation method, such as SHapley Additive exPlanations (SHAP), Morris Sensitivity Analysis (MSA), Local Interpretable Model-Agnostic Explanations (LIME), and Partial Dependence Plot (PDP) to explain the expected results and identify the most dominant features. The super learner cybersickness model is then retrained using the identified dominant features. Our proposed method identified eye tracking, player position, and galvanic skin/heart rate response as the most dominant features for the integrated sensor, gameplay, and bio-physiological datasets. We also show that the proposed XAI-guided feature reduction significantly reduces the model training and inference time by 1.91X and 2.15X while maintaining baseline accuracy. For instance, using the integrated sensor dataset, our reduced super learner model outperforms the state-of-the-art works by classifying cybersickness into 4 classes (none, low, medium, and high) with an accuracy of and regressing (FMS 1–10) with a Root Mean Square Error (RMSE) of 0.03. Our proposed method can help researchers analyze, detect, and mitigate cybersickness in real time and deploy the super learner-based cybersickness detection model in standalone VR headsets. Ripan Kumar Kundu, Osama Yahia Elsaid, Prasad Calyam, Khaza Anuarul Hoque |
IUI | 4 |
| 2023 | QTWTL: Quality Aware Time Window Temporal Logic for Performance Monitoring
Ernest Bonnah, Khaza Anuarul Hoque |
MEMOCODE | 2 |
| 2023 | Model Checking Time Window Temporal Logic for Hyperproperties
Ernest Bonnah, Luan Viet Nguyen, Khaza Anuarul Hoque |
MEMOCODE | 3 |
| 2023 | LiteVR: Interpretable and Lightweight Cybersickness Detection using Explainable AIabstractCybersickness is a common ailment associated with virtual reality (VR) user experiences. Several automated methods exist based on machine learning (ML) and deep learning (DL) to detect cyber-sickness. However, most of these cybersickness detection methods are perceived as computationally intensive and black-box methods. Thus, those techniques are neither trustworthy nor practical for deploying on standalone energy-constrained VR head-mounted devices (HMDs). In this work, we present an explainable artificial intelligence (XAI)-based framework Lite VR for cybersickness detection, explaining the model's outcome, reducing the feature dimensions, and overall computational costs. First, we develop three cybersick-ness DL models based on long-term short-term memory (LSTM), gated recurrent unit (GRU), and multilayer perceptron (MLP). Then, we employed a post-hoc explanation, such as SHapley Additive Explanations (SHAP), to explain the results and extract the most dominant features of cybersickness. Finally, we retrain the DL models with the reduced number of features. Our results show that eye-tracking features are the most dominant for cybersickness detection. Furthermore, based on the XAI-based feature ranking and dimensionality reduction, we significantly reduce the model's size by up to 4.3×, training time by up to 5.6×, and its inference time by up to 3.8×, with higher cybersickness detection accuracy and low regression error (i.e., on Fast Motion Scale (FMS)). Our proposed lite LSTM model obtained an accuracy of 94% in classifying cyber-sickness and regressing (i.e., FMS 1–10) with a Root Mean Square Error (RMSE) of 0.30, which outperforms the state-of-the-art. Our proposed Lite VR framework can help researchers and practitioners analyze, detect, and deploy their DL-based cybersickness detection models in standalone VR HMDs. Ripan Kumar Kundu, Rifatul Islam, John Quarles, Khaza Anuarul Hoque |
VR | 4 |
| 2023 | Detection of Security and Privacy Attacks Disrupting User Immersive Experience in Virtual Reality Learning EnvironmentsabstractVirtual Reality Learning Environments (VRLEs) are a new form of immersive environments which are integrated with wearable devices for delivering distance learning content in a collaborative manner in e.g.,special education,surgical training. Gaining unauthorized access to these connected devices can cause security, privacy attacks (SP) that adversely impacts the user immersive experience (UIX). In this article, we identify potential SP attack surfaces that impact the application usability and immersion experience, and propose a novel anomaly detection method to detect attacks before the UIX can be disrupted. Specifically, we apply: (i) machine learning techniques such as amulti-label KNN classificationalgorithm to detect anomaly events of network-based attacks that include potential threat scenarios ofDoS (packet tampering, packet drop, packet duplication), and (ii) statistical analysis techniques that use a combination of boolean and threshold functions (Z-scores) to detect an anomaly related to application-based attacks (Unauthorized access). We demonstrate the effectiveness of our proposed anomaly detection method using a VRLE application case study viz., vSocial, specifically designed for teaching youth with learning impediments about social cues and interactions. Based on our detection results, we validate the impact of network and application based SP attacks on the VRLE UIX. Samaikya Valluripally, Benjamin Frailey, Brady Kruse, Boonakij Palipatana, Roland Oruche, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam |
IEEE Trans. Serv. Comput. | 7 |
| 2023 | Exposing Reliability Degradation and Mitigation in Approximate DNNs Under Permanent FaultsabstractApproximate computing is known for enhancing deep neural network accelerators’ energy efficiency by introducing inexactness with a tolerable accuracy loss. However, small accuracy variations may increase the sensitivity of these accelerators toward undesired subtle disturbances, such as permanent faults. The impact of permanent faults in accurate deep neural network (AccDNN) accelerators has been thoroughly investigated in the literature. Conversely, the impact of permanent faults and their mitigation in approximate DNN (AxDNN) accelerators is vastly underexplored. Toward this, we first present an extensive fault resilience analysis of approximate multilayer perceptrons (MLPs) and convolutional neural networks (CNNs) using the state-of-the-art Evoapprox8b multipliers in graphic processing unit (GPU) and tensor processing unit (TPU) accelerators. Then, we propose a novel fault mitigation method, i.e., fault-aware retuning of weights (Fal-reTune). Fal-reTune retunes the weights using a weight mapping function in the presence of faults for improved classification accuracy. To evaluate the fault resilience and the effectiveness of our proposed mitigation method, we used the most widely used MNIST, Fashion-MNIST, and CIFAR10 datasets. Our results demonstrate that the permanent faults exacerbate the accuracy loss in AxDNNs compared with the AccDNN accelerators. For instance, a permanent fault in AxDNNs can lead to 56% accuracy loss, whereas the same faulty bit can lead to only 4% accuracy loss in AccDNN accelerators. We empirically show that our proposed Fal-reTune mitigation method improves the performance of AxDNNs up to 98%, even with fault rates up to 50%. Furthermore, we observe that the fault resilience in AxDNNs is orthogonal to their energy efficiency. Ayesha Siddique, Khaza Anuarul Hoque |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2022 | Is Approximation Universally Defensive Against Adversarial Attacks in Deep Neural Networks?abstractApproximate computing is known for its effectiveness in improvising the energy efficiency of deep neural network (DNN) accelerators at the cost of slight accuracy loss. Very recently, the inexact nature of approximate components, such as approximate multipliers have also been reported successful in defending adversarial attacks on DNNs models. Since the approximation errors traverse through the DNN layers as masked or unmasked, this raises a key research question—can approximate computing always offer a defense against adversarial attacks in DNNs, i.e., are they universally defensive? Towards this, we present an extensive adversarial robustness analysis of different approximate DNN accelerators (AxDNNs) using the state-of-the-art approximate multipliers. In particular, we evaluate the impact of ten adversarial attacks on different AxDNNs using the MNIST and CIFAR-10 datasets. Our results demonstrate that adversarial attacks on AxDNNs can cause 53% accuracy loss whereas the same attack may lead to almost no accuracy loss (as low as 0.06%) in the accurate DNN. Thus, approximate computing cannot be referred to as a universal defense strategy against adversarial attacks. Ayesha Siddique, Khaza Anuarul Hoque |
DATE | 2 |
| 2022 | TruVR: Trustworthy Cybersickness Detection using Explainable Machine LearningabstractCybersickness can be characterized by nausea, vertigo, headache, eye strain, and other discomforts when using virtual reality (VR) systems. The previously reported machine learning (ML) and deep learning (DL) algorithms for detecting (classification) and predicting (regression) VR cybersickness use black-box models; thus, they lack explainability. Moreover, VR sensors generate a massive amount of data, resulting in complex and large models. Therefore, having inherent explainability in cybersickness detection models can significantly improve the model’s trustworthiness and provide insight into why and how the ML/DL model amved at a specific decision. To address this issue, we present three explainable machine learning (xML) models to detect and predict cybersickness: 1) explainable boosting machine (EBM), 2) decision tree (DT), and 3) logistic regression (LR). We evaluate xML-based models with publicly available physiological and gameplay datasets for cybersickness. The results show that the EBM can detect cybersickness with an accuracy of 99.75% and 94.10% for the physiological and gameplay datasets, respectively. On the other hand, while predicting the cybersickness, EBM resulted in a Root Mean Square Error (RMSE) of 0.071 for the physiological dataset and 0.27 for the gameplay dataset. Furthermore, the EBM-based global explanation reveals exposure length, rotation, and acceleration as key features causing cybersickness in the gameplay dataset. In contrast, galvanic skin responses and heart rate are most significant in the physiological dataset. Our results also suggest that EBM-based local explanation can identify cybersickness-causing factors for individual samples. We believe the proposed xML-based cybersickness detection method can help future researchers understand, analyze, and design simpler cybersickness detection and reduction models. Ripan Kumar Kundu, Rifatul Islam, Prasad Calyam, Khaza Anuarul Hoque |
ISMAR | 4 |
| 2022 | Modeling and Defense of Social Virtual Reality Attacks Inducing CybersicknessabstractSocial Virtual Reality Learning Environments (VRLE) offer a new medium for flexible and immersive learning environments with geo-distributed users. Ensuring user safety in VRLE application domains such as education, flight simulations, military training is of utmost importance. Specifically, there is a need to study the impact of “immersion attacks” (e.g., chaperone attack, occlusion) and other types of attacks/faults (e.g., unauthorized access, network congestion) that may cause user safety issues (i.e., inducing ofcybersickness). In this article, we present a novel framework to quantify the security, privacy issues triggered via immersion attacks and other types of attacks/faults. By using a real-world social VRLE viz., vSocial and creating a novel attack-fault tree model, we show that such attacks can induce undesirable levels of cybersickness. Next, we convert these attack-fault trees into stochastic timed automata (STA) representations to perform statistical model checking for a given attacker profile. Using this model checking approach, we determine the most vulnerable threat scenarios that can trigger high occurrence cases of cybersickness for VRLE users. Lastly, we show the effectiveness of our attack-fault tree modeling by incorporating suitable design principles such ashardening,diversity,redundancyandprinciple of least privilegeto ensure user safety in a VRLE session. Samaikya Valluripally, Aniket Gulhane, Khaza Anuarul Hoque, Prasad Calyam |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Attack Trees for Security and Privacy in Social Virtual Reality Learning EnvironmentsabstractSocial Virtual Reality Learning Environment (VRLE) is a novel edge computing platform for collaboration amongst distributed users. Given that VRLEs are used for critical applications (e.g., special education, public safety training), it is important to ensure security and privacy issues. In this paper, we present a novel framework to obtain quantitative assessments of threats and vulnerabilities for VRLEs. Based on the use cases from an actual social VRLE viz., vSocial, we first model the security and privacy using the attack trees. Subsequently, these attack trees are converted into stochastic timed automata representations that allow for rigorous statistical model checking. Such an analysis helps us adopt pertinent design principles such as hardening, diversity and principle of least privilege to enhance the resilience of social VRLEs. Through experiments in a vSocial case study, we demonstrate the effectiveness of our attack tree modeling with a reduction of 26% in probability of loss of integrity (security) and 80% in privacy leakage (privacy) in before and after scenarios pertaining to the adoption of the design principles. Samaikya Valluripally, Aniket Gulhane, Reshmi Mitra, Khaza Anuarul Hoque, Prasad Calyam |
CCNC | 4 |
| 2020 | Crafting Adversarial Examples for Deep Learning Based PrognosticsabstractIn manufacturing, unexpected failures are considered a primary operational risk, as they can hinder productivity and can incur huge losses. State-of-the-art Prognostics and Health Management (PHM) systems incorporate Deep Learning (DL) algorithms and Internet of Things (IoT) devices to ascertain the health status of equipment, and thus reduce the downtime, maintenance cost and increase the productivity. Unfortunately, IoT sensors and DL algorithms, both are vulnerable to cyber attacks, and hence pose a significant threat to PHM systems. In this paper, we adopt the adversarial example crafting techniques from the computer vision domain and apply them to the PHM domain. Specifically, we craft adversarial examples using the Fast Gradient Sign Method (FGSM) and Basic Iterative Method (BIM) and apply them on the Long Short-Term Memory (LSTM), Gated Recurrent Unit (GRU), and Convolutional Neural Network (CNN) based PHM models. We evaluate the impact of adversarial attacks using NASA's turbofan engine dataset. The obtained results show that all the evaluated PHM models are vulnerable to adversarial attacks and can cause a serious defect in the remaining useful life estimation. The obtained results also show that the crafted adversarial examples are highly transferable and may cause significant damages to PHM systems. Gautam Raj Mode, Khaza Anuarul Hoque |
ICMLA | 2 |
| 2020 | High-level Modeling of Manufacturing Faults in Deep Neural Network AcceleratorsabstractThe advent of data-driven real-time applications requires the implementation of Deep Neural Networks (DNNs) on Machine Learning accelerators. Google's Tensor Processing Unit (TPU) is one such neural network accelerator that uses systolic array-based matrix multiplication hardware for computation in its crux. Manufacturing faults at any state element of the matrix multiplication unit can cause unexpected errors in these inference networks. In this paper, we propose a formal model of permanent faults and their propagation in a TPU using the Discrete-Time Markov Chain (DTMC) formalism. The proposed model is analyzed using the probabilistic model checking technique to reason about the likelihood of faulty outputs. The obtained quantitative results show that the classification accuracy is sensitive to the type of permanent faults as well as their location, bit position and the number of layers in the neural network. The conclusions from our theoretical model have been validated using experiments on a digit recognition-based DNN. Shamik Kundu, Ahmet Soyyigit, Khaza Anuarul Hoque, Kanad Basu |
IOLTS | 3 |
| 2020 | Impact of False Data Injection Attacks on Deep Learning Enabled Predictive AnalyticsabstractIndustry 4.0 is the latest industrial revolution primarily merging automation with advanced manufacturing to reduce direct human effort and resources. Predictive maintenance (PdM) is an industry 4.0 solution, which facilitates predicting faults in a component or a system powered by state-of-the- art machine learning (ML) algorithms (especially deep learning algorithms) and the Internet-of-Things (IoT) sensors. However, IoT sensors and deep learning (DL) algorithms, both are known for their vulnerabilities to cyber-attacks. In the context of PdM systems, such attacks can have catastrophic consequences as they are hard to detect due to the nature of the attack. To date, the majority of the published literature focuses on the accuracy of DL enabled PdM systems and often ignores the effect of such attacks. In this paper, we demonstrate the effect of IoT sensor attacks (in the form of false data injection attack) on a PdM system. At first, we use three state-of-the-art DL algorithms, specifically, Long Short-Term Memory (LSTM), Gated Recurrent Unit (GRU), and Convolutional Neural Network (CNN) for predicting the Remaining Useful Life (RUL) of a turbofan engine using NASA's C-MAPSS dataset. The obtained results show that the GRU-based PdM model outperforms some of the recent literature on RUL prediction using the C-MAPSS dataset. Afterward, we model and apply two different types of false data injection attacks (FDIA), specifically, continuous and interim FDIAs on turbofan engine sensor data and evaluate their impact on CNN, LSTM, and GRU-based PdM systems. The obtained results demonstrate that FDI attacks on even a few IoT sensors can strongly defect the RUL prediction in all cases. However, the GRU-based PdM model performs better in terms of accuracy and resiliency to FDIA. Lastly, we perform a study on the GRU-based PdM model using four different GRU networks with different sequence lengths. Our experiments reveal an interesting relationship between the accuracy, resiliency and sequence length for the GRU-based PdM models. Gautam Raj Mode, Prasad Calyam, Khaza Anuarul Hoque |
NOMS | 3 |
| 2019 | Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment ApplicationsabstractSocial Virtual Reality based Learning Environments (VRLEs) such as vSocial render instructional content in a three-dimensional immersive computer experience for training youth with learning impediments. There are limited prior works that explored attack vulnerability in VR technology, and hence there is a need for systematic frameworks to quantify risks corresponding to security, privacy, and safety (SPS) threats. The SPS threats can adversely impact the educational user experience and hinder delivery of VRLE content. In this paper, we propose a novel risk assessment framework that utilizes attack trees to calculate a risk score for varied VRLE threats with rate and duration of threats as inputs. We compare the impact of a well-constructed attack tree with an adhoc attack tree to study the trade-offs between overheads in managing attack trees, and the cost of risk mitigation when vulnerabilities are identified. We use a vSocial VRLE testbed in a case study to showcase the effectiveness of our framework and demonstrate how a suitable attack tree formalism can result in a more safer, privacy-preserving and secure VRLE system. Aniket Gulhane, Akhil Vyas, Reshmi Mitra, Roland Oruche, Gabriela Hoefer, Samaikya Valluripally, Prasad Calyam, Khaza Anuarul Hoque |
CCNC | 8 |
| 2018 | Towards Probabilistic Formal Analysis of SATS-Simultaneously Moving Aircraft (SATS-SMA)
Muhammad Usama Sardar, Nida Afaq, Osman Hasan, Khaza Anuarul Hoque |
J. Autom. Reason. | 4 |
| 2018 | Cyber-Physical Specification MismatchesabstractEmbedded systems use increasingly complex software and are evolving into cyber-physical systems (CPS) with sophisticated interaction and coupling between physical and computational processes. Many CPS operate in safety-critical environments and have stringent certification, reliability, and correctness requirements. These systems undergo changes throughout their lifetimes, where either the software or physical hardware is updated in subsequent design iterations. One source of failure in safety-critical CPS is when there are unstated assumptions in either the physical or cyber parts of the system, and new components do not match those assumptions. In this work, we present an automated method toward identifying unstated assumptions in CPS. Dynamic specifications in the form of candidate invariants of both the software and physical components are identified using dynamic analysis (executing and/or simulating the system implementation or model thereof). A prototype tool called Hynger (for HYbrid iNvariant GEneratoR) was developed that instruments Simulink/Stateflow (SLSF) model diagrams to generate traces in the input format compatible with the Daikon invariant inference tool, which has been extensively applied to software systems. Hynger, in conjunction with Daikon, is able to detect candidate invariants of several CPS case studies. We use the running example of a DC-to-DC power converter and demonstrate that Hynger can detect a specification mismatch where a tolerance assumed by the software is violated due to a plant change. Another case study of an automotive control system is also introduced to illustrate the power of Hynger and Daikon in automatically identifying cyber-physical specification mismatches. Luan Viet Nguyen, Khaza Anuarul Hoque, Stanley Bak, Steven Drager 0001, Taylor T. Johnson |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2018 | Maintenance of Smart Buildings using Fault TreesabstractTimely maintenance is an important means of increasing system dependability and life span. Fault Maintenance trees (FMTs) are an innovative framework incorporating both maintenance strategies and degradation models and serve as a good planning platform for balancing total costs (operational and maintenance) with dependability of a system. In this work, we apply the FMT formalism to a Smart Building application and propose a framework that efficiently encodes the FMT into Continuous Time Markov Chains. This allows us to obtain system dependability metrics such as system reliability and mean time to failure, as well as costs of maintenance and failures over time, for different maintenance policies. We illustrate the pertinence of our approach by evaluating various dependability metrics and maintenance strategies of a Heating, Ventilation, and Air-Conditioning system. 1 Nathalie Cauchi, Khaza Anuarul Hoque, Mariëlle Stoelinga, Alessandro Abate |
ACM Trans. Sens. Networks | 2 |
| 2017 | Formal specification and dependability analysis of optical communication networksabstractNetwork dependability reflects the ability to deliver continuous services even after failures, such as man-made or natural disturbances, e.g., storms, hurricanes, and floods, etc. In the last decade, optical networks have been increasingly deployed to provide multicast traffic in metropolitan areas. In this paper, we provide a formal specification of double-rings with dual attachments (DRDA) topologies of optical networks using Continuous-Time Markov Chains. Our formal modeling includes the concept of pre-configured protection cycles (p-cycles), which provide effective fault tolerance against link-failures in optical networks. Our approach is generic enough to handle networks of any size that are prone to any combinations of link failures. We formally specify several dependability properties using Continuous Stochastic Logic (CSL). We then provide a quantitative evaluation of these properties using the PRISM model checker. We observe that such formal analysis can provide critical information at early design stages to network operators for designing highly-dependable optical networks in metropolitan areas (e.g., availability on the order of 99.99% or 99.999%). Umair Siddique, Khaza Anuarul Hoque, Taylor T. Johnson |
DATE | 2 |
| 2015 | Towards an accurate reliability, availability and maintainability analysis approach for satellite systems based on probabilistic model checking
Khaza Anuarul Hoque, Otmane Aït Mohamed, Yvon Savaria |
DATE | 1 |
| 2014 | Probabilistic model checking based DAL analysis to optimize a combined TMR-blind-scrubbing mitigation technique for FPGA-based aerospace applicationsabstractSRAM-based FPGAs are increasingly popular in the aerospace industry for their field programmability and low cost. However, they suffer from cosmic radiation induced Single Event Upsets (SEUs), commonly known as soft errors. In safety-critical applications, the dependability of the design is a prime concern since failures may have catastrophic consequences. An early analysis of dependability of such safety-critical applications will enable designers to develop a design that meets the high availability and reliability requirements of the DO-254 standard. This paper introduces a novel methodology based on probabilistic model checking, to analyze the dependability properties of safety-critical systems and to suggest required mitigation techniques, such as Triple Modular Redundancy (TMR) or TMR with less frequent scrubs for early design decisions. Starting from a high-level description of a system, a Markov model is constructed from the Control Data Flow Graph (CDFG) expressing the functionality and from failure/mitigation parameters for the targeted FPGAs. Such an exhaustive model captures all the failures and repairs possible in the system within the radiation environment. We present a case study on a benchmark circuit to illustrate the applicability of the proposed approach to demonstrate that a wide range of useful dependability properties can be analyzed using our proposed methodology. Khaza Anuarul Hoque, Otmane Aït Mohamed, Yvon Savaria, Claude Thibeault |
MEMOCODE | 1 |