Research/Publications


Publications (recent first)

2025


[S&P’25] PEARTS: Provable Execution in Real-Time Embedded Systems


[S&P’25] SoK: Integrity, Attestation, and Auditing of Program Execution


2024


[ACSAC’24] TRACES: TEE-based Runtime Auditing for Commodity Embedded Systems


[ACSAC’24] SpecCFA: Enhancing Control Flow Attestation and Auditing via Application-Aware Sub-Path Speculation


[ACM EMSoft’24 and IEEE TCAD] Untrusted Code Compartmentalization for Bare Metal Embedded Devices


[IEEE ComMag’24] Towards Remotely Verifiable Software Integrity in Resource-Constrained IoT Devices


2023


[USENIX SEC’23] ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow Attestation


[RTAS’23] ISC-FLAT: On the Conflict Between Control Flow Attestation and Real-Time Operations


[ICCAD’23] DiCA: A Hardware-Software Co-Design for Differential Check-Pointing in Intermittently Powered Devices


[ICCAD’23] PARseL: Towards a Verified Root-of-Trust over seL4


[ESORICS’23] Oblivious Extractors and Improved Security in Biometric-based Authentication Systems


2022


[ICCAD’22] CASU: Compromise Avoidance via Secure Updates for Low-end Embedded Systems


[S&P’22] Privacy-from-Birth: Protecting Sensed Data from Malicious Sensors with VERSA


[DAC’22] ASAP: Reconciling Asynchronous Real-Time Operations and Proofs of Execution in Simple Embedded Systems


[USENIX SEC’22] GAROTA: Generalized Active Root-Of-Trust Architecture (for Tiny Embedded Devices)


2021


[CCS’21] On the TOCTOU Problem in Remote Attestation


[DAC’21] DIALED: Data Integrity Attestation for Low-end Embedded Devices


[WiSec’21] Delegated Attestation: Scalable Remote Attestation of Commodity CPS by Blending Proofs of Execution with Software Attestation


[IPSN’21] On the Root of Trust Identification Problem


[DATE’21] Tiny-CFA: Minimalistic Control-Flow Attestation Using Verified Proofs of Execution


2020


[USENIX Sec’20] APEX: A Verified Architecture for Proofs of Execution on Remote Devices Under Full Software Compromise


2019


[USENIX Sec’19] VRASED: A Verified Hardware/Software Co-Design for Remote Attestation


[ICCAD’19] PURE: Using Verified Remote Attestation to Obtain Proofs of Update, Reset and Erasure in Low-End Embedded Systems


[ICDCS’19] Towards Systematic Design of Collective Remote Attestation Protocols


[FGCS’19] SNUSE: A Secure Computation Approach for Large-Scale User Re-Enrollment in Biometric Authentication Systems


2018


[ACNS’18] KRB-CCN: Lightweight Authentication & Access Control for Private Content-Centric Networks


[CSCML’18] Secure Non-Interactive User Re-Enrollment in Biometrics-based Identification and Authentication Systems


[IEEE ComMag’18] Combining Spatial and Social Awareness in D2D Opportunistic Routing


2017


[LCN’17] Namespace Tunnels in Content-Centric Networks


[MSWIM’17] GRM: Group Regularity Mobility Model


[ComNet’17] GROUPS-NET: Group Meetings Aware Routing in Multi-Hop D2D Networks


[ISCC’17] ST-Drop: A Novel Buffer Management Strategy for D2D Opportunistic Networks


2016


[SenSys’16] AoT: Authentication and Access Control for the Entire IoT Device Life-Cycle


[IEEE WCM’16] Leveraging D2D Multi-Hop Communication Through Social Group Meetings Awareness


[ICC’16] Group Mobility: Detection, Tracking and Characterization


2015


[SBRC (workshops)’15] Fault Tolerance in Strongly Minimum Energy Topology with MLD: A Distributed, Energy Efficient yet Simple Protocol


[SBRC (workshops)’15] Designing a Low Cost Home WSN for Remote Energy Monitoring and Eletronic Devices Control