About | Open To | Tech Stack | Research Interests | AI/ML | Projects | Experience | Publications | Open Source | Hackathons | Achievements | Certifications | Philosophy | Analytics | Connect
First-year B.Tech CSE (Cybersecurity) student at DBS Global University, currently doing security research at IIT Bhilai under Dr. Dhiman Saha. My work sits across hardware forensics, cryptographic attacks, and penetration testing of secure hardware. I have a paper accepted at IJCACI 2026 and a 9.09 SGPA.
I am not waiting for a later year to do real work.
Right now that means pulling apart a secure element to see if its guarantees actually hold, running a Rowhammer attack in a simulated environment to understand memory-level exploitation from the inside, and attacking a government-backed hardware token whose design changes because of what I find.
- Security research collaborations
- Open source contributions
- Security engineering roles
- Graduate research opportunities
- Hardware security projects
- Reverse engineering work
- AI security research
Programming Languages
Hardware Security & Embedded Systems
Reverse Engineering & Firmware Analysis
Digital Forensics
Network Security
Cryptography & Hardware Attacks
Web Development
Operating Systems & Developer Tools
Active Research
| Area | Focus |
|---|---|
| Hardware Security | Secure element forensics on the TROPIC01 devkit |
| Cryptographic Attacks | Rowhammer implementation in a simulated environment |
| Power Analysis | Side-channel analysis with ChipWhisperer Husky and PhyWhisperer USB |
| Firmware Reverse Engineering | Ghidra-based decompilation and behavioural analysis |
| Digital Forensics | USB and SPI protocol reconstruction, conformance testing |
| Secure Hardware Verification | Empirical key-destruction testing (Mac-and-Destroy), full conformance suites |
| AI for Security | Computational-intelligence-driven ransomware detection literature |
Exploring Next
| Area | Direction |
|---|---|
| Fault Injection | Extending the power analysis phase into fault injection on secure hardware |
| Secure Hardware Verification | Generalising the TROPIC01 conformance methodology to other secure elements |
| Domain | Experience | Application | Current Work |
|---|---|---|---|
| Computational Intelligence for Security | Literature synthesis across 4 years of ML/DL ransomware research (IJCACI 2026) | ML/DL-based ransomware detection, attack-vector analysis, forensic recovery | Extending the review methodology toward hardware-level threat detection |
This is research and review work, not production ML engineering.
Forensic and security analysis of the TROPIC01 secure element development board, run end to end at the de.ci.phe.red Lab, IIT Bhilai.
Full case study
Overview Passive USB reconnaissance, active SPI protocol analysis, behavioural conformance testing, empirical key-destruction verification, and firmware decompilation, all on one devkit.
Problem Secure elements are trusted because their internals are supposed to be opaque. That trust is worth testing directly instead of taking the datasheet's word for it.
Methodology USB traffic captured and reconstructed. SPI protocol characterised against the TROPIC01 conformance spec, with a full test suite built from scratch to run it repeatably. Firmware pulled apart in Ghidra. Mac-and-Destroy key-destruction behaviour verified empirically across 11 sequential PIN attempts.
Findings 62 confirmed findings logged against the conformance suite.
Security Perspective Tests whether the chip's documented security guarantees survive direct interrogation, not just whether they read well on paper.
Technologies Ghidra, custom SPI conformance suite, USB forensics tooling, ChipWhisperer Husky, PhyWhisperer USB.
Status Power analysis phase in progress.
Repository Confidential. IIT Bhilai lab-restricted research.
Attack, analysis, and penetration testing on TruToken, a secure hardware token built by C-DAC Noida and IIT Bhilai.
Full case study
Overview Structured hardware penetration testing against a token that is still being designed. Findings go straight back into the design process.
Problem A secure token in active development needs adversarial testing before it ships, not after.
Approach Attack and analysis methodology applied against TruToken's hardware security assumptions.
Impact Vulnerability findings feed directly into TruToken's ongoing development.
Technologies Hardware penetration testing methodology, secure token analysis.
Repository Confidential. Government-institutional research (C-DAC Noida, IIT Bhilai).
Implementing a Rowhammer attack in a simulated environment as part of broader hardware attack research.
Full case study
Overview Rowhammer turns a physical memory quirk into a security bypass. Understanding it means building it, not just reading the paper on it.
Status In progress, simulated environment.
Technologies Cryptographic and hardware attack research tooling.
Repository Confidential. IIT Bhilai lab-restricted research.
Full case study
Overview A platform letting homebound women take on MSME contracts directly through WhatsApp.
Problem Skilled women who cannot leave home for work have no easy channel into a gig economy that runs on WhatsApp anyway.
Solution A trust-scoring system to vet contract reliability, UPI payouts for instant settlement, and Hindi voice input so literacy is not a barrier to entry.
Impact Reached the CII Yi Yuva National Grand Finale 2026 and drew investor interest at the event.
Technologies WhatsApp Business API, React, Node.js, REST APIs.
Repository Not publicly released.
Full case study
Overview A traffic optimisation system built for Smart India Hackathon 2025.
Role Led a 6-member team. Built the frontend and ran the Linux-based SUMO simulations myself.
Result National Finalist at IIIT Dharwad. Handled the full jury Q&A.
Technologies SUMO traffic simulation, Linux, frontend development.
Repository Not publicly released.
Research Intern · de.ci.phe.red Lab, IIT Bhilai Jun 2026 – Aug 2026 · Supervisor: Dr. Dhiman Saha
Cryptographic attacks, hardware security, digital forensics. Selected via a two-round interview. One of very few undergraduates placed here.
Scope of Work TROPIC01 forensic analysis, TruToken security analysis, Rowhammer attack research, and an in-progress power analysis phase.
Key Contributions 62 confirmed findings on the TROPIC01 devkit. Full conformance test suite built and run. Empirical Mac-and-Destroy verification across 11 sequential PIN attempts.
Technologies Ghidra, ChipWhisperer Husky, PhyWhisperer USB, custom SPI tooling.
Intern · VLED Lab, IIT Ropar Jun 2026 · Supervisor: Prof. Sudarshan Iyengar
India-centric open source problems.
Scope of Work Learning phase on a live public repository focused on India-centric software problems.
Towards Intelligent Ransomware Defence: A Computational-Intelligence-Driven Thematic Review of Detection, Forensics, and Recovery
Parneet Kaur, Prof. Merry KP · IJCACI 2026 (US) · Accepted · 2025–2026
Summary A systematic review of ML/DL ransomware detection, attack vectors, and forensic recovery across 4 years of literature, in Springer LLNCS format. Techniques validated independently in FlareVM and REMnux.
Research Areas Ransomware detection, computational intelligence, digital forensics.
Technologies FlareVM, REMnux.
OWASP Nettacker · GSoC 2026 applicant · 2025–2026
1 merged PR, 2 pending. Researched CVE-2025-32756 (Fortinet FortiVoice RCE) to extend scanner detection coverage. Kept contributing after the GSoC rejection.
GirlScript Summer of Code (GSSoC) Contributor.
Saheli · CII Yi Yuva · National Grand Finale 2026
WhatsApp-first labour marketplace for women. Trust-scoring, UPI payouts, Hindi voice input. Drew investor interest at the finale. Full write-up under Featured Projects.
GreenLight · Smart India Hackathon 2025 · National Finalist, IIIT Dharwad
Intelligent traffic optimisation. Led a 6-member team, built the frontend, ran the Linux SUMO simulations, and handled the jury Q&A. Full write-up under Featured Projects.
| Achievement | Detail |
|---|---|
| CII Yi Yuva National Grand Finale 2026 | Saheli, investor interest at the finale |
| Smart India Hackathon 2025, National Finalist | GreenLight, IIIT Dharwad |
| Google Gemini Student Ambassador 2026 | Shortlisted |
| Queen's Commonwealth Essay Competition | Silver Award |
| Vidyarthi Vigyan Manthan | District Rank 1 |
Verify before you assume. A secure element's guarantees mean nothing until someone tests them directly. Conformance suites and empirical key-destruction testing exist because datasheets are not proof.
Build before you claim expertise. First-year does not mean early enough to wait. It means early enough to start.
Understand systems from first principles. Decompiling firmware and reconstructing a protocol from raw SPI traffic teaches more than reading documentation about either.
Open source is a discipline, not a resume line. Getting rejected from GSoC did not stop the Nettacker contributions. The work was never about the label.
Research means being willing to be wrong in public. A published review has to survive scrutiny from people who know the literature better than I do. That is the point of publishing it.
current_focus:
learning:
- Power analysis with ChipWhisperer Husky
- Fault injection fundamentals
building:
- TROPIC01 conformance test suite
- Personal portfolio site
researching:
- Secure element verification methodology
- Ransomware detection with computational intelligence
exploring:
- Fault injection attacks on secure hardware
open_to:
- Research collaborations
- Security engineering roles
- Graduate researchSecure systems are proven, not assumed.