Ashley Kurian

I help AI keep its secrets.

Ashley Kurian
01 — About

I'm a PhD student in Electrical & Computer Engineering at North Carolina State University, advised by Dr. Aydin Aysu in the HECTOR (Hardware and Embedded Cyber-threat Research) lab.

My work sits at the intersection between machine learning and physical security. On the attack side, I have demonstrated commercial AI accelerators leak their trained parameters through electromagnetic side channels. On the defense side, I build countermeasures with minimal overhead that mitigate the vulnerability.

02 — Research Contributions
ATTACKTCHES 2025

Side-channel model stealing on Google's Edge TPU

First of its kind — recovered model architecture and hyper-parameters (layer count, activation functions, kernel sizes) across multiple neural networks from Google edge TPU, a commercial DNN accelerator using electromagnetic side channels, in collaboration with Google.

DEFENSENeurIPS 2025

Extraction-aware training defense

First defense against cryptanalytic neural network parameter extraction attacks, with a theoretical framework that quantifies an attack's success probability against a given neural network.

DEFENSENeurIPS 2026 · under review

Retrofittable side-channel defense for off-the-shelf TPUs

First retrofit defense for commercial Edge TPUs that trains multiple functionally-equivalent parameter versions per layer and shuffles them randomly at inference, suppressing EM leakage below the TVLA detection threshold with under 1% accuracy loss.

TOOLINGopen source

A Python framework for side-channel analysis

End-to-end trace acquisition and post-processing such as alignment, TVLA computation, and averaging integrated into a single reusable pipeline.

03 — Experience
Student Researcher, Google
Aug – Nov 2025
Mountain View, CA
  • Performed security analysis of neural-network models deployed on latest-generation Tensor SoCs, focused on parameter and architecture confidentiality.
  • Characterized threat vectors targeting on-device ML inference, informing hardware- and model-level defenses.
R&D Intern, Caspia Technologies
May – Aug 2024
Gainesville, FL
  • Developed a pre-silicon side-channel vulnerability assessment tool at the RTL level (Icarus Verilog, Python, Tcl, PyQt).
  • Tested and verified the CODAx static linting tool — which flags RTL patterns leading to post-silicon security flaws — and automated its evaluation across multiple benchmarks.
Graduate Research Assistant, NC State University
Aug 2022 – present
HECTOR Lab · Raleigh, NC
  • Side-channel analysis of machine-learning accelerators and the design of training-time defenses (see Research).
Research Assistant, NIT Karnataka
Aug 2020 – Jul 2022
Surathkal, India
  • Studied Posit arithmetic as an alternative to the IEEE-754 standard, evaluating resource and timing costs of a RISC-V accelerator implementation synthesized for an Artix-7 FPGA.
  • Built RoCC sub-interfaces linking the Posit accelerator to the floating-point unit and investigated hardware type-casting implementations.
04 — Publications
No TPU Left Behind: Retrofitting Side-Channel Protection into Edge TPUs
A. Kurian, A. Dubey, M. Ayyagari, A. Aysu
NeurIPS · 2026 · under review View
Survey of Challenges in Implementation-Security Metrics for Side-Channel and Fault-Injection Attacks
A. A. Malik, S. Sanjaya, H. Mihir, A. Kurian, A. Jayasena, P. Mishra, A. Aysu
IEEE Design & Test 2026 · survey View
Train to Defend: First Defense Against Cryptanalytic Neural Network Parameter Extraction Attacks
A. Kurian, A. Aysu
NeurIPS 2025 View
TPUXtract: An Exhaustive Hyperparameter Extraction Framework
A. Kurian, A. Dubey, F. Yaman, A. Aysu
IACR TCHES 2025 View
Posit arithmetic acceleration on a RISC-V core
M.Tech. research · RISC-V accelerator synthesized for Artix-7 FPGA
Springer · book chapter · 2022 View
05 — In the Press
06 — Education
Ph.D., Electrical & Computer Engineering
North Carolina State University · Raleigh, NC
Aug 2022 – presentGPA 3.833 / 4
M.Tech. (Research), VLSI Design
National Institute of Technology, Karnataka · India
Aug 2020 – Jul 2022GPA 9.67 / 10
B.Tech., Electronics & Communication Engineering
APJ Abdul Kalam Technological University · Kerala, India
Aug 2015 – Jul 2019GPA 9.16 / 10
07 — Skills & Tools

Domains

Hardware security Side-channel attacks Fault attacks SCA defenses Machine & deep learning Computer architecture RTOS Multi-core systems

Languages

C C++ Python Verilog

Tools & Instruments

Keysight Inspector TensorFlow MATLAB Linux Oscilloscope icWaves Transceiver
08 — Course Projects
Cryptographic Engineering & HW Security

Crypto hardware & DPA

Built Ring-Binary-LWE encryption hardware, and extracted an AES key via Differential Power Analysis.

Python · Verilog
Architecture of Parallel Computers

Coherence & parallel GEMM

Simulator comparing MSI vs. Dragon coherence protocols; implemented GEMM scheduling in the OpenMP parallel model.

C++ · OpenMP
Microprocessor Architecture

Scheduling & cache simulators

Designed a dynamic instruction-scheduling and branch-predictor simulator, plus an L1 / L1+L2 cache simulator.

C++
Operating Systems Design

Xinu kernel internals

Added a fork system call and lottery & MLFQ scheduling to the Xinu kernel; implemented spinlocks, priority-inheritance, virtual memory, and interrupt handling.

C · Xinu · x86
Compiler Optimization & Scheduling

LLVM optimization passes

Implemented dead-code and common-subexpression elimination and load-store optimization; applied function-inlining heuristics and measured benchmark speedups.

C · LLVM · Flex & Bison