CERIAS Weekly Security Seminar - Purdue University

CERIAS

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

  1. 3d ago ·  Video

    Krassimir Tzvetanov, Trading Privacy for Convenience: Leading through example in a Hyper-Connected Era

    In contemporary digital environments, individuals increasingly exchange personal privacy for the convenience afforded by online services, often without full awareness of the breadth or implications of this trade-off. This study examines this phenomenon through a comparative analysis of the data practices of major communication, social networking, and dating applications, including Meta, Instagram, WhatsApp, TikTok, LinkedIn, Google,WeChat, Signal, Telegram, Snapchat, and others. By systematically reviewing privacy policies and related disclosures, the research evaluates how these platforms collect, process, and utilize a wide range of user data, encompassing identifiers such as IP address, location information, demographic attributes,behavioral telemetry, device metadata, and access to sensitive content. The analysis reveals substantial heterogeneity in data collection practices - both in terms of scope and transparency - across different categories of applications and geopolitical ecosystems. Notably,privacy-oriented services such as Signal demonstrate markedly reduced data gathering compared to mainstream or commercially driven platforms. An illustrative comparison between high-privacy and low-privacy application models highlights the extent to which features that enhance user convenience,including personalization algorithms and streamlined authentication, are frequently enabled by extensive behavioral tracking. The findings underscore the imperative for security professionals to advocate for stronger privacy standards, promote informed consent, and encourage data-minimizing design principles. Ultimately, the study argues that safeguarding privacy is not solely a technical undertaking but also a cultural and ethical responsibility requiring leadership within the securitycommunity. About the speaker: Dr. Tzvetanov has served as a Graduate Researcher at Purdue University for the past six years, focusing on Homeland Security, Cyber Threat Intelligence (CTI), and Influence Operations. Concurrently, he has served as Instructor of Record for graduate-level courses in Cybersecurity and Homeland Security.For the past three years, Dr. Tzvetanov has also served as CISO and Director of Security Engineering at Hydrolix. Prior to this role, he held positions including CTI Lead, Principal Security Engineer and Architect,and Red Team Operator at major technology companies such as Cisco, Yahoo!, and Google. Throughout his career, he has authored training materials, whitepapers, and academic publications covering distributed denial-of-service (DDoS)attack mitigation and investigation, cyber threat intelligence, privacy, and influence operations. He has also contributed to numerous law enforcement investigations, including providing expert witness testimony in federal court.Dr. Tzvetanov is an active contributor to the global cybersecurity research and incident response communities. He has served on program committees for ShmooCon, FIRST, NANOG, BayThreat, and the Underground Economy. He is an active participant in several Special Interest Groups within the Forum of Incident Response and Security Teams (FIRST), has contributed to the Honeynet Project, and was a principal organizer of the Bay Threat security conference. He also led the Radio Communications Department at DEF CON.Dr. Tzvetanov holds a Ph.D. and an M.S. in Technology, both with a concentration in Homeland Security; an M.S. in Digital Forensics and Investigations; and a B.S. in Electrical Engineering with a concentration in Radio Communications.

  2. Sep 23 ·  Video

    Jingjie Li, Advancing Online Safety Governance for Digital Platforms and Communities

    Internet users increasingly interact through emerging digital platforms and communities, which create complex online safety, security and privacy challenges that aredifficult to navigate. This talk will present insights from our research to understand the rising online safety landscape and improve online safety governance. I will first present our work characterizing online community responses to globalized scam-driven human trafficking, which received a Best Paper Award at ACM CHI 2026. Scam-driven cross-border human trafficking has become a long-standing societal crisis in Asia. Through our analysis of community responses on RedNote, a major Chinese social media platform, we identify several key challenges, including cultural values that can both enable trafficking and hinder survivors' recovery. Although online communities develop and share protective strategies, these efforts are complicated by uncertainty about the reliability of available support and difficulties in cross-border coordination. I will discuss the implications of these findings for prevention, platform governance, and international cooperation against scam-driven trafficking. Building on this work, I will then highlight opportunities for more proactive approaches to governing digital platforms and online communities, drawing on insights from our parallel research efforts. Finally, I will reflect on methodological lessons from our research and motivate discussion about future opportunities for studying and improving online safety, security and privacy in emerging digital environments. About the speaker: Jingjie Li is a Lecturer (Assistant Professor) in the School of Informatics, University of Edinburgh. His work spans privacy, security, and online safety,with the goal of seamlessly integrating these principles into emerging human-centered technologies such as smart homes, augmented and virtual reality, and AI-enabled systems. He published impactful work at premier conferences in security and privacy (IEEE S&P, USENIX Security, and ACM CCS), human-computer interaction (ACM CHI and ACM CSCW), and computer systems (IEEE/ACM ISCA, IEEE TMC and IEEE TVLSI). His interdisciplinary work received multiple best paper awards and has informed industry development and policymaking with key stakeholders across countries. Before joining the University of Edinburgh, Jingjie obtained a Ph.D. degree from the University of Wisconsin-Madison in 2023. For more information, please visit his homepage: www.jingjieli.me

  3. Sep 16 ·  Video

    Mahimna Kelkar, Rethinking Cryptography and Blockchain Attacker Models

    In the past few years, blockchains have emerged as a new class of decentralized systems with wide-ranging applications. But the promise of blockchains has been marred by hype, speculation, and a plethora of high-profile attacks.The purpose of this talk is to demonstrate, through examples from my research, why blockchain security is challenging. Blockchains operate in a radically new, highly adversarial environment where subtle protocol flaws can be immediately monetized by anonymous actors. This fundamentally intertwines an assortment of fields---cryptography, distributed systems, and mechanism design, among many others. Blockchain security should no longer be thought of from a single lens.In this talk, I will show powerful new attacks, motivated by blockchains, that erode security through the very same tools typically used to build secure protocols. These attacks provide valuable insights on existing, well-studied security and cryptographic models. In turn, this shows why understanding blockchain security has broader utility and how it can serve as a guiding principle when designing secure systems.The first part of my talk challenges assumptions in cryptographic models of knowledge by showing powerful bribery attacks in bribery-resistant voting---fixing these attacks requires a stronger notion of knowledge. The second part will discuss new techniques for collusion using blockchains, and how it impacts incentives and models in accountable cryptography. About the speaker: Mahimna Kelkar is an assistant professor of computer science at Purdue University. His research designs and builds secure systems using techniques from applied cryptography, blockchain technology, and game theory. Before joining Purdue, he received his PhD in computer science from Cornell University and spent a year as a postdoctoral fellow at Columbia University. More details can be found on his websitehttps://mahimnakelkar.github.io/

  4. Sep 9 ·  Video

    Romila Pradhan, Reasoning About Interventions in Data and Machine Learning Systems

    Modern machine learning systems are only as reliable as the data and pipelines that support them, yet improving their behavior often requires navigating enormous spaces of possible data and system configurations. These systems are complex enough that improving them by changing everything at once is both inefficient and unreliable. This talk explores a simple principle for building smarter data and machine learning systems: identify which intervention is most likely to change the outcome, and act there.  I will first introduce DataSift that applies this principle to model behavior, identifying the most influential data to expand the training data when the goal is to improve fairness without sacrificing predictive performance. By combining data valuation, influence functions, and multi-armed bandits, DataSift identifies small, high-impact subsets of candidate data rather than indiscriminately adding data to the training set. Next, I will present PipeLens that applies the same principle to data science pipelines, identifying the components and parameters whose intervention is most likely to repair a malfunctioning pipeline. By learning from successful and failed pipeline executions, PipeLens identifies causally relevant root causes and efficiently searches for interventions that restore pipeline utility. Despite addressing different problems, both systems replace brute-force search with targeted intervention using principled reasoning about influence and causality to determine what to change, why it matters, and how to change it efficiently. About the speaker: Romila Pradhan is an Assistant Professor in the School of Applied & Creative Computing at Purdue University and leads the Responsible DataScience Lab, where she and her students build trustworthy and responsible data-driven decision-making systems. Her research is in the broader areas of databases and data management and is driven by the need to design algorithms and develop solutions that enable system explainability, fairness, and robustness.  Her research is supported by NSF, Google, and Underwriters Laboratories. She is a recipient of a Google Research Scholar award and an NSF CAREER award. Romila earned her Ph.D. in Computer Science from Purdue University and graduated with M.S. and B.S. in Mathematics and Computing from the Indian Institute of Technology (IIT) Kharagpur, India.

  5. Sep 2 ·  Video

    Armin Moin, TianoShield: Improving the Security Posture of the TianoCore Ecosystem

    In this talk, I will provide an overview of our NSF-sponsored award, TianoShield, focused on enhancing the security posture and the software maintenance process of the open-source core of the UEFI Firmware, called EDK II, and maintained by the TianoCore community. The talk will highlight our ongoing collaborations with our industrial partners, including Intel Corporation, Arm, AMI, Insyde Software, GitHub, Phoenix Technologies, Binarly, etc. First, we will discuss our methods and techniques for rapid triaging of existing bug reports that have remained open for a long time due to a lack of resources in the community. Second, we will introduce our security analysis tools and their enhancements for static and dynamic analysis of the UEFI firmware, thus discovering many new vulnerabilities. Finally, we will present our suggestions and improvements for software maintenance, specifically bug handling, and DevOps/DevSecOps practices in TianoCore. A key pillar of TianoShield is leveraging the state of the art in Artificial Intelligence (AI), including Large Language Models (LLMs) for software security and software maintenance. As part of the dissemination practices in TianoShield, we have organized/will organize a full-day workshop, called FirmVuln26, at VulnCon26 in Scottsdale, AZ, in April 2026, and another full-day workshop, called FTA 2026, at ISSTA 2026 in Oakland, CA, in October 2026. The TianoShield project started in October 2025 and is expected to run until September 2027. About the speaker: Dr. Armin Moin is a Tenure-Track Assistant Professor and Director of the Purdue Quantum-Classical AI and Software Engineering (QCASE) Lab at the School of Applied and Creative Computing (ACC) in the Polytechnic Institute at Purdue University in West Lafayette and Indianapolis, Indiana, USA. He previously (2023-2026) held a Tenure-Track Assistant Professor position in the Computer Science (CS) department of the University of Colorado Colorado Springs (UCCS). Before starting his faculty position, he worked as a Postdoctoral Scholar-Employee in the CS Department of the University of California, Santa Barbara (UCSB) in the U.S. and as a Postdoctoral Scholar in the CS Department of the University of Antwerp and FlandersMake in Belgium. Dr. Moin obtained his Ph.D. in CS from the Technical University of Munich (TUM), Germany, one of the world's top universities, in 2022. He also has a Master's in CS and an Executive MBA in Innovation and Business Creation. His research focuses on the intersection of Artificial Intelligence (AI) and Software Engineering (SE), particularly AI4SE and SE4AI, with an emphasis on hybrid quantum-classical computing and software security. Grants from various sources, including the U.S. National Science Foundation (NSF) and the Colorado Office of Economic Development and International Trade (OEDIT), have funded his lab. Besides conducting research and teaching at Purdue University, Dr. Moin reviews top academic conferences and journals. He is passionate about encouraging and empowering students to start their ventures based on what they learn at the university. Please refer to his academic homepage at https://web.ics.purdue.edu/~moin/index.html or his professional profile at https://polytechnic.purdue.edu/profile/moin for more information.

  6. Aug 26 ·  Video

    Matt Scheurer, Lies, Telephony, and Hacking History

    You may find yourself attending a CERIAS Security Seminar, and you may ask yourself "Well, how did we get here?" Once upon a time, not long ago, there was no cybersecurity industry or careers. This talk transports attendees on a retrospective journey through time to highlight the advancements which paved the way here. We further explore historic attack vectors to understand how they relate to the cyberattacks of today. Topics include when Social Engineering first intertwined with technology following previous milestones in telecommunications. Our expedition highlights the technological origins of Phone Phreaking, Computer Hacking, Social Engineering, and how these activities relate to modern attacks. The speaker pulls out numerous hardware relics from the past to show attendees and demo them throughout this presentation. Come learn about what the underground phone phreak and early computer hacker scenes were like, and get ready for some "Show & Telecom"! About the speaker: Matt Scheurer is the show host of the ThreatReel Podcast, and Vice President of Computer Security and Incident Response in a large enterprise environment. He has many years of hands-on technical experience. Matt is an official "Hacking is NOT a Crime" Advocate, serves on the Advisory Board for the Warren County (Ohio) Career Center "Information Technology and Cybersecurity" program, and also volunteers as a technical mentor for the Women's Security Alliance (WomSA). He has presented numerous Information Security topics at countless technology meetup groups, and prominent Information Security conferences, including keynotes at the Cybersecurity Collaboration Forum Cincinnati Leadership Exchange, the Information Security Summit in Cleveland, Queen City Con (0x1, 0x2, and 0x3) in Cincinnati, and SecureWV in Charleston. He is awarded with delivering lifetime conference Keynote Addresses at Queen City Con. Matt is also a 2019 comSpark "Rising Tech Stars Award" winner, named a "Top 12 Hacking Influencer" by Bishop Fox in 2023, and awarded a "Black Badge" for continuous community engagement at Queen City Con in 2024.

  7. Apr 29 ·  Video

    Pragathi Jha, Modeling Cyber Adversaries: A Critical Survey of Methods and Assumptions

    Cybersecurity practitioners face a persistent methodological problem: how should we reason about intelligent adversaries who observe our defenses, adapt their tactics, and choose targets based on our vulnerabilities? The field has responded with a fragmented toolkit. Quantitative risk assessment borrowed from safety engineering treats threat, vulnerability, and consequence as independent terms. Threat modeling frameworks such as STRIDE and attack trees emphasize structure but rarely quantify uncertainty. Game-theoretic models assume rationality and common knowledge that real attackers do not exhibit. Qualitative heat maps compress uncertainty into colored cells that cannot support budget optimization.This talk surveys these approaches critically, examining what each method commits you to and what it quietly sets aside. A common thread emerges: the alternatives can be understood as approximations to a Bayesian decision-theoretic ideal, each relaxing one or more assumptions for tractability. Modeling an adversary requires addressing four dimensions of uncertainty (what they want, what they know, what they can do, and how they decide) and the standard critiques of probabilistic cyber risk analysis (information asymmetry, correlated inputs, adaptation, the absence of objective base rates) turn out to be errors of naive practice rather than indictments of the methodology itself. Threat intelligence feeds, indicator matches, and shifts in attacker tradecraft fit naturally as Bayesian updates rather than as awkward inputs to frequentist frameworks. The survey closes not with a prescription but with a diagnostic question for practitioners and researchers alike: are the assumptions embedded in your chosen method appropriate for the decision you are trying to support? About the speaker: Pragathi Jha is a doctoral researcher in Industrial Engineering at Purdue University, where her work focuses on optimization, stochastic modeling, and game-theoretic approaches to decision-making under uncertainty. Her research lies at the intersection of operations research, applied probability, and strategic interaction, with an emphasis on developing rigorous mathematical frameworks for complex, adversarial systems.Her academic interests include multi-stage stochastic optimization, game theory, and the modeling of strategic behavior in dynamic environments. In the context of cybersecurity, she is particularly interested in adversarial decision-making, risk-aware resource allocation, and the design of resilient systems that account for uncertainty and strategic threats. Her work aims to bridge theoretical advances in optimization and game theory with practical applications in security, infrastructure protection, and data-driven decision support.Pragathi brings a strong foundation in quantitative methods and is committed to advancing research that is both mathematically rigorous and operationally impactful. Through her work, she seeks to contribute to the development of robust, scalable frameworks for analyzing and mitigating risks in complex, high-stakes environments.

  8. Apr 22 ·  Video

    Smriti Bhatt, Evolving Security Landscape in the Agentic AI-Enabled IoT Era

    The rapid evolution of connected devices and technologies has transformed the Internet of Things (IoT) into increasingly intelligent and autonomous systems. This talk focuses on the progression from traditional IoT to the Artificial Intelligence of Things (AIoT), and further toward Agent-Based IoT (AB-IoT), also referred to as Agentic AI-enabled IoT. As intelligent agents become embedded within IoT ecosystems, they introduce new capabilities for autonomy and decision-making, but also significantly reshape the security landscape. In this talk, I first outline the technological evolution from IoT to AIoT and Agentic AI-enabled IoT systems. I then discuss how the adoption of agentic intelligence in IoT environments introduces emerging security risks and threats with particular emphasis on challenges related to authentication, access control, and trust management in highly distributed and autonomous environments. I also present potential approaches to address these challenges, including zero-trust security frameworks and context-aware machine learning–based access control mechanisms. Finally, this talk highlights current research challenges and open problems in securing Agentic AI-enabled IoT systems, outlining future directions for building resilient, trustworthy, and secure next-generation Agentic AI-enabled IoT infrastructures. About the speaker: Dr. Smriti Bhatt is an Assistant Professor of Cybersecurity in the School of Applied and Creative Computing at Purdue University. She has received her Ph.D. and M.S. in Computer Science from the University of Texas at San Antonio and did her doctoral research at the Institute for Cyber Security (ICS) and NSF CREST Center for Security and Privacy Enhanced Cloud Computing (C-SPECC). Dr. Bhatt's research focuses on security and privacy in the Internet of Things (IoT) and Cyber-Physical Systems (CPS) leveraging Cloud and Edge Computing. Her research interests also include the application of AI and Machine Learning to secure IoT and CPS infrastructures in various application domains, such as Smart Health, Smart Home, and Wearable IoT. Some of her current research work includes access control models, secure data communication, and anomaly detection for different domains in Cloud-Enabled IoT. She has several conference and journal publications, and also continually serves as an expert reviewer for various journals and technical program committees for several conferences and workshops.

Ratings & Reviews

4.1
out of 5
7 Ratings

About

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.