Systems and Network Security Researcher
Previously Postdoctoral Research Fellow, UBC (2023–2026). PhD, IIT Madras (2015–2022).
Open to work (Available immediately) E-mail: gargimiitm [at] gmail [dot] com
New technologies rarely replace legacy infrastructure. Instead, they are layered on top, invalidating the security and privacy assumptions of the original threat model. I take an interdisciplinary systems approach to identify the assumptions that no longer hold during such integrations, demonstrate them with proof-of-concept attacks, and recommend effective mitigations accordingly.
I first demonstrated this in encrypted web traffic. HTTP/2 multiplexing was believed to hinder traffic analysis; I designed the first attack that defeats it to reveal website users' browsing activities (DSN 2020). When Netflix layered interactive movies onto its encrypted streaming service, I inferred viewers' choices from the encrypted traffic. For its most popular title, "Black Mirror: Bandersnatch", the worst-case accuracy was 96% (covered by WIRED).
I then extended encrypted traffic analysis to cloud-connected industrial control systems, a recent shift in ICS network architecture. I conceived ICS-Sniper (NDSS 2027) and led a five-member team that developed it. In this attack, an on-path adversary outside the plant disrupts the physical process by selectively dropping the encrypted packets that carry critical control data, as demonstrated on a popular water-treatment testbed.
AI is the most recent layer. Safety-critical systems such as medical devices now embed AI/ML models that implicitly trust inputs from legacy sensors and wireless links. With students I mentored, I developed LLM-based tools that identify the resulting attack paths at design time, and presented them to the FDA, Medtronic, and GE. I am currently developing agentic AI tools that detect vulnerabilities and attacks in multi-vendor networks and improve their own detection rules over time.
I am looking for roles in security research (threat detection / network security and privacy / AI security).
Last updated October 2026