activity
20212026
most citedMaking Secure Software Insecure without Changing Its Code: The Possibilities and Impacts of Attacks on the DevOps Pipeline

2 citations · 2 across the 6 of their papers we have counts for

collaborators
Showing cs.CRShow all

8 papers · 1 filter

cs.CR2026

Semi-Automated Threat Modeling of Cloud-Based Systems Through Extracting Software Architecture from Configuration and Network Flow

Nicholas Pecka, Lotfi Ben Othmane, Bharat Bhargava +1

Traditional threat modeling occurs during design, but cloud deployments introduce unanticipated threats, especially multi-stage attacks chaining vulnerabilities across trust bounda…

cs.CR2026

Extending Adaptive Cruise Control with Machine Learning Intrusion Detection Systems

Lotfi Ben Othmane, Yasaswini Konapalli, Naga Prudhvi Mareedu

An Adaptive Cruise Control (ACC) system automatically adjusts the host vehicle's speed to maintain a safe following distance from a lead vehicle. In typical implementations, a feed…

cs.CR2025

Reverse Engineering and Control-Aware Security Analysis of the ArduPilot UAV Framework

Yasaswini Konapalli, Lotfi Ben Othmane, Cihan Tunc +2

Unmanned Aerial Vehicle (UAV) technologies are gaining high interest for many domains, which makes UAV security of utmost importance. ArduPilot is among the most widely used open-s…

cs.CR2025

Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis

Nicholas Pecka, Lotfi Ben Othmane, Renee Bryce

Threat modeling plays a critical role in the identification and mitigation of security risks; however, manual approaches are often labor intensive and prone to error. This paper in…

cs.CR2025

Comparison of Fully Homomorphic Encryption and Garbled Circuit Techniques in Privacy-Preserving Machine Learning Inference

Kalyan Cheerla, Lotfi Ben Othmane, Kirill Morozov

Machine Learning (ML) is making its way into fields such as healthcare, finance, and Natural Language Processing (NLP), and concerns over data privacy and model confidentiality con…

cs.CR20222 cited

Making Secure Software Insecure without Changing Its Code: The Possibilities and Impacts of Attacks on the DevOps Pipeline

Nicholas Pecka, Lotfi ben Othmane, Altaz Valani

Companies are misled into thinking they solve their security issues by using a DevSecOps system. This paper aims to answer the question: Could a DevOps pipeline be misused to trans…