Institution profile

Institute of Electrical and Electronics Engineers

Academic institutionnorthamerica · us
Official website
Research library100linked papers
Opportunities0open roles
Selected work

Representative Papers

Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication

Apr 20, 2025

CI/CD systems in enterprises commonly rely on static keys or short-lived credentials for authentication, lacking robust runtime identity assurance—leading to excessive privileges, insufficient isolation, and heightened risk during supply chain attacks. This paper introduces the first zero-trust identity framework specifically designed for CI/CD workloads. It systematically adopts the SPIFFE standard to decouple identity from infrastructure, integrating OpenID Connect–based federated authentication, dynamic SVID issuance, workload attestation, and policy-driven access control. The framework enables automated, job-level identity provisioning, mutual TLS-based authentication, and fine-grained authorization. Evaluated across multi-cloud and hybrid environments, it significantly mitigates risks of credential leakage and lateral movement, delivering a portable, auditable zero-trust identity foundation. By shifting CI/CD security from implicit trust to runtime-verifiable, context-aware interactions, the approach advances the operational paradigm toward verifiable, least-privilege execution.

2 citationsRead paper

Self-Supervision via Controlled Transformation and Unpaired Self-Conditioning for Low-Light Image Enhancement

Mar 01, 2025IEEE Transactions on Instrumentation and Measurement

This paper addresses the challenging problem of unsupervised low-light image enhancement in the absence of paired real-world low-light/normal-light training data. We propose an end-to-end unsupervised framework featuring two key innovations: (1) a controllable transform-based self-supervision mechanism, leveraging invertible brightness/contrast transformations to enforce photometric consistency and enhance stability; and (2) an unpaired self-conditioning strategy integrating low-gradient magnitude suppression, detail-preserving noise modeling, and contrastive learning to achieve pixel-wise adaptive intensity control—effectively mitigating artifacts and over-enhancement. The method operates entirely without paired supervision. Extensive experiments demonstrate state-of-the-art performance across multiple benchmarks, with significant PSNR and SSIM improvements and more natural visual quality. Ablation studies confirm the efficacy of each component.

2 citationsRead paper

ADVANCING DIGITAL ACCESSIBILITY IN DIGITAL PHARMACY, HEALTHCARE, AND WEARABLE DEVICES: INCLUSIVE SOLUTIONS FOR ENHANCED PATIENT ENGAGEMENT

Apr 22, 2025International Journal of Healthcare Information Systems and Informatics

Digital health services face significant accessibility barriers for users with auditory, visual, cognitive, and motor impairments. Method: This study proposes a cross-modal accessibility design paradigm integrating WCAG/ADA compliance frameworks with AI-powered voice interaction, haptic feedback, and adaptive UIs—applied across digital pharmacies, telemedicine platforms, and wearable health devices. It innovatively combines multimodal AI (speech recognition, natural language understanding), a dynamic accessibility adaptation engine, and web-based automated accessibility auditing tools to enable real-time, personalized interface adaptation. Contribution/Results: Empirical evaluation demonstrates a 68% increase in task completion rates and a 52% reduction in error rates among users with disabilities. The work yields 12 reusable, scenario-specific accessibility implementation guidelines and has directly informed the adoption of three industry standards. Collectively, it establishes a policy–technology–service co-design framework to advance inclusive digital health ecosystems.

1 citationsRead paper

Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD

Apr 20, 2025

To address static permission bloat, coarse-grained auditing, and inadequate support for zero-trust principles in CI/CD pipelines, this paper proposes a dynamic credential proxy architecture grounded in runtime-verifiable identities (SPIFFE/SVID). The architecture decouples identity from access permissions and enables instantaneous, short-lived (second-scale) cross-trust-domain credential issuance via OAuth 2.0 Token Exchange. It integrates a gRPC-based proxy with unified RBAC/ABAC policy enforcement, enabling fine-grained, policy-driven authorization. This work introduces the first pipeline-centric dynamic credential proxy design paradigm, bridging a critical engineering gap in applying zero-trust identity models to continuous delivery. Evaluation in production demonstrates sub-500 ms policy enforcement latency, substantial reduction in long-lived credential exposure risk, and significant improvements in audit real-time performance and traceability.

1 citationsRead paper

New Scenarios and Trends in Nontraditional Laboratories From 2000 to 2020

Jan 24, 2025IEEE Transactions on Learning Technologies

This study investigates the evolutionary mechanisms and pedagogical transformations of non-traditional experimental platforms in STEM education from 2000 to 2020. Employing a mixed-methods approach integrating bibliometric analysis and topic modeling, it systematically maps the development trajectory across 3,726 publications from 20 countries, contextualized with ICT historical milestones and national educational technology policy documents. The study introduces, for the first time, a scenario-based classification framework that rigorously delineates conceptual boundaries and synergistic relationships among virtual, remote, DIY, and hybrid laboratory platforms, identifying five dominant instructional scenarios. Beyond offering a comprehensive, longitudinal synthesis of two decades of innovation, the research yields a transferable platform selection guideline and an integrative implementation roadmap. These contributions advance theoretical understanding of platform evolution and provide actionable, adaptable frameworks for diversifying and enhancing STEM laboratory instruction.

1 citationsRead paper
Recent publications

Latest Papers

Inferential Capability Does Not Determine Legal Scope

Aug 11, 2026

This study addresses the regulatory ambiguity arising from conflicting legal definitions of “inference” under the EU Artificial Intelligence Act and the General Data Protection Regulation (GDPR), particularly in agent-based systems. It proposes a two-tiered legal framework that distinguishes between the constitutive and protective functions of inference, introducing key concepts such as the “inference threshold,” “inference scope,” and “inference chain.” The work demonstrates for the first time that inferential capability does not inherently trigger GDPR applicability and develops a “combinatorial effect test” to identify automated decision-making units under Article 22 of the GDPR. Furthermore, it designs a documentation obligation allocation mechanism grounded in the inference chain. Employing legal hermeneutics and institutional mapping, the study offers interpretive rules for EU digital legislation, clarifies liability attribution for inferential acts in intelligent agents, and enhances regulatory coherence and operational clarity.

0 citationsRead paper

A Hybrid Edge-Cloud Architecture for Low-Latency Entitlement Verification in Resource-Constrained Devices

Jun 09, 2026

This study addresses the high latency incurred by resource-constrained devices on over-the-top (OTT) platforms due to their reliance on cloud-based authorization, which degrades user experience. To mitigate this, the authors propose an edge-cloud collaborative authorization architecture that introduces a secure local caching layer within device middleware, integrating an adaptive eviction and proactive refresh mechanism (AEC-PR) to decouple user interactions from backend network dependencies. For the first time on such constrained devices, the design combines Ed25519 deterministic signatures, Trusted Execution Environment (TEE) isolation, and ARM Cortex-A hardware support to enable low-latency, side-channel-resistant local cryptographic verification. Experimental results demonstrate a reduction in authorization latency from 422.8 ms to 18.4 ms—a 95.6% improvement—significantly enhancing both performance and security.

0 citationsRead paper

Self-Healing Agentic Orchestrators for Reliable Tool-Augmented Large Language Model Systems

May 31, 2026

This work addresses the reliability degradation and silent failures commonly observed in tool-augmented large language models, which often stem from orchestration-layer issues such as tool timeouts, incorrect parameters, or stale context. The authors formulate reliability as a bounded runtime control problem and introduce the first self-healing orchestration framework that integrates fault classification, budget-constrained action selection, and verification-guided recovery. By leveraging runtime observability to detect failure signals, classify fault types, and execute targeted recovery strategies within resource budgets, the system achieves a 98.8% single-attempt recovery success rate on a 100-task benchmark—outperforming naive retry and full replanning by 8.7 and 5.8 percentage points, respectively. Notably, the approach entirely eliminates semantic silent failures, substantially enhancing both system reliability and diagnosability.

0 citationsRead paper