Publications
Every paper below has a link to read it. Where a free copy can be hosted here it is marked Free PDF, so nothing is stuck behind a paywall.
- 9 Publications
- 33 Citations OpenAlex
- 3 h-index OpenAlex
- 1 Best Paper HOST 2024
- 5 Students Mentored
- 7 Talks Given
Citation figures as of September 2026.
Conference Papers
TinyRadio: Tiny Neural Networks for Fingerprinting Radio Frequency Signals
IEEE National Aerospace and Electronics Conference (NAECON 2025)
Radio-frequency fingerprinting identifies an individual transmitter from imperfections in the signal it emits. TinyRadio carries the tiny-neural-network approach into that setting, building classifiers small enough to run on embedded hardware rather than requiring a workstation to make the identification.
MicroPower: Micro Neural Networks for Side-Channel Attacks
2025 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
A follow-up to TinyPower that pushes compression further, asking how small a neural network can get before side-channel key recovery stops working. The result maps the trade-off between model footprint and attack success, which matters for anyone estimating what an attacker with constrained hardware can actually do.
A Second Look at the Portability of Deep Learning Side-Channel Attacks over EM Traces
27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID '24)
Earlier portability results for EM side-channel attacks were established on easy targets such as 8-bit microcontrollers. This paper re-runs them on harder ones — 32-bit microcontrollers and traces with random delay — under domain shifts from hardware variation, different keys, and inconsistent probe placement. Pre-processing and unsupervised domain adaptation do help, but which method wins depends on the target and probe location, and none dominates: results from easy targets do not generalize. The paper also identifies two evaluation pitfalls that make cross-device attacks look better than they are, and releases a 3-million-trace public dataset.
Abstract
Deep learning side-channel attacks can recover encryption keys on a target by analyzing power consumption or electromagnetic (EM) signals. However, they are less portable when there are domain shifts between training and test data. While existing studies have shown that pre-processing and unsupervised domain adaptation can enhance the portability of deep learning side-channel attacks given domain shifts over EM traces, the findings are limited to easy targets (e.g., 8-bit microcontrollers). In this paper, we investigate the portability of deep learning side-channel attacks over EM traces acquired from more challenging targets, including 32-bit microcontrollers and EM traces with random delay. We study domain shifts introduced by the combination of hardware variations, distinct keys, and inconsistent probe locations between two targets. In addition, we perform comparative analyses of multiple existing (and new) pre-processing and unsupervised domain adaptation methods. We conduct a series of comprehensive experiments and derive three main observations. (1) Pre-processing and unsupervised domain adaptation methods can enhance the portability of deep learning side-channel attacks over more challenging targets. (2) The effectiveness of each method, however, varies depending on the target and probe locations in use. In other words, observations of a method on easy targets do not necessarily generalize to challenging targets. (3) None of the methods can constantly outperform others. Moreover, we highlight two types of pitfalls that could lead to over-optimistic attack results in cross-device evaluations. We also contribute a large-scale public dataset (with 3 million EM traces from 9 probe locations over multiple targets) for benchmarking and reproducibility of side-channel attacks tackling domain shifts over EM traces.
Artifact. Contributes a public dataset of 3 million EM traces across 9 probe locations and multiple targets.
TinyPower: Side-Channel Attacks with Tiny Neural Networks
2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
Deep-learning side-channel attacks are usually assumed to need a well-resourced attacker. TinyPower shows the attack still works after aggressive pruning and quantization, with models compact enough to run on microcontrollers, which lowers the practical bar for mounting one. Awarded Best Student Paper at HOST 2024.
EvilELF: Evasion Attacks on Deep-Learning Malware Detection over ELF Files
2023 International Conference on Machine Learning and Applications (ICMLA)
Malware detectors that learn directly from raw Linux ELF bytes can be steered into the wrong answer. EvilELF constructs evasion attacks that alter ELF files so a deep-learning detector labels malware as benign while the binary still behaves as before, exposing how brittle byte-level detectors are to structure-aware manipulation.
Portability of Deep-Learning Side-Channel Attacks against Software Discrepancies
16th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '23)
Deep-learning side-channel attacks are normally trained and tested against the same software build. This paper asks what survives when the victim's software differs from what the attacker trained on, and measures how much key-recovery performance those software discrepancies cost.
Journal Articles
Evaluating Clinical NLP Services for Chest Radiograph Report Labeling: A Comparative Study on an Independent Pediatric Dataset
Journal of Imaging Informatics in Medicine
Hospitals increasingly buy off-the-shelf clinical NLP to turn free-text radiology reports into structured labels. This study benchmarks general-purpose commercial services against chest-X-ray-specific labelers on an independent pediatric dataset — a population these tools were not built for — so that a purchasing decision can rest on measured performance rather than vendor claims.
Book Chapters
Deep Learning Side-Channel Attacks: Challenges and Opportunities
Advancements in Hardware Design and Trust, CRC Press (ISBN 9781032840420)
A survey chapter mapping where deep-learning side-channel analysis actually stands: what these attacks can now do, where they stay fragile — portability across devices, data requirements, and evaluation methodology — and which open problems matter most for hardware trust.
Preprints & Under Review
Can Modern NLP Systems Reliably Annotate Chest Radiography Exams? A Pre-Purchase Evaluation and Comparative Study of Solutions from AWS, Google, Azure, John Snow Labs, and Open-Source Models on an Independent Pediatric Dataset
Preprint, Research Square
A pre-purchase evaluation putting the major cloud clinical-NLP offerings — AWS, Google, Azure, John Snow Labs — side by side with open-source models on the same independent pediatric chest-radiography dataset, so a hospital can see what it is buying before it commits.
No publications match that search.
