Rakesh Podder profile photo

Rakesh Podder

Ph.D. Candidate in Computer Science · Colorado State University

Developing AI-planning frameworks for security and resiliency of cyber-physical systems.

Advised by: Prof. Indrajit Ray

NIST Foreign Research Scientist: 2024–2026

Awards: 2× IEEE Best Paper (TPS-ISA 2024, QRS 2024)

About

I am a Ph.D. candidate in Computer Science at Colorado State University, advised by Prof. Indrajit Ray. My research develops AI-planning-based frameworks for the security and resiliency analysis of cyber-physical systems, centered on three connected contributions: attack-connectivity graph analysis (SPEAR and i-EXAM), unified Resiliency and Safety Graph frameworks for modeling cascading IT-OT failures, and SERA, a re-programmable simulation testbed for explainable resiliency analysis. Alongside this work, I develop CAPE, a context-aware vulnerability prioritization engine, as an independent research line. From 2024 to 2026, I served as a Foreign Research Scientist at the National Institute of Standards and Technology (NIST), collaborating with Irena Bojanova on the Bugs Framework to formalize the classification of security bugs, CVEs, and CWEs. My research has been supported by the Office of Naval Research, the National Science Foundation, and the Department of Energy, and recognized with Best Paper awards at IEEE TPS-ISA 2024 and IEEE QRS 2024. Alongside research, I teach and mentor at CSU as a graduate teaching assistant and research mentor, designing hands-on security labs and lecturing independently when called on.

Research Interests

Cyber-Physical System Security & Resiliency AI Planning for Security Attack Graphs & Vulnerability Analysis Firmware & Hardware Security (HRoT) Formal Methods & Verification Explainable AI & Adversarial ML Software Supply Chain Security Cybersecurity Education

Education

2022 – present

Ph.D. Candidate, Computer Science

Colorado State University, Fort Collins, CO, USA

CGPA: 4.00 / 4.00

2022 – 2025

Master of Science (Thesis), Computer Science

Colorado State University, Fort Collins, CO, USA

CGPA: 4.00 / 4.00

Thesis: Preventing Malicious Modifications to Firmware Using Hardware Root of Trust (HRoT)

2018 – 2020

Master of Engineering (Thesis), Electrical Engineering

Jadavpur University, Kolkata, West Bengal, India

CGPA: 9.11 / 10 Gold Medalist

Thesis: Data Security of IoT Enabled Autonomous Robots from the Perspective of its Various Controlled Actions

2013 – 2017

Bachelor of Technology, Electrical Engineering

Indian Institute of Technology, Patna, Bihar, India

CGPA: 7.5 / 10

Dissertation: Low Cost Signal Generator

Professional Appointments

Jan 2026 – present

Graduate Research Assistant

Colorado State University, Department of Computer Science · Colorado, USA

Feb 2026 – Jun 2026

Graduate Mentor

Office for Undergraduate Research and Artistry, Colorado State University · Colorado, USA

May 2024 – May 2026

Foreign Research Scientist

National Institute of Standards and Technology (NIST) · Gaithersburg, USA

Aug 2025 – Dec 2025

Graduate Teaching Assistant

Colorado State University, Department of Computer Science · Colorado, USA

May 2022 – Aug 2025

Graduate Research Assistant

Colorado State University, Department of Computer Science · Colorado, USA

Jun 2021 – Apr 2022

Systems Engineer

Infosys Ltd. · Bhubaneswar, India

Nov 2020 – May 2021

Programmer Analyst

Cognizant Technology Solutions India Pvt. Ltd. · Kolkata, India

May 2016 – Jul 2016

Summer Intern

Chandrapura Thermal Power Station, DVC · Bokaro, India

Research

My research centers on AI-planning-based frameworks for cyber-physical system security and resiliency.

i-EXAM web application landing page

SPEAR & i-EXAM

Attack-connectivity graph modeling and hardening analysis. AI-planning and LLM-powered tool for system administrators to build network security profiles and run what-if hardening analyses.

AI Planning Attack Graphs Network Security
Live demo → i-EXAM
Resiliency Graph framework

Resiliency & Safety Graphs

Unified frameworks modeling how cyber attacks propagate into system failures across IT and OT domains in cyber-physical systems.

CPS Security Attack Propagation Failure Analysis
SERA simulation environment

SERA

An AI-driven, re-programmable simulation environment for explainable resiliency analysis, supporting offensive/defensive security research and teaching modules for cybersecurity education.

Simulation XAI CPS Education
CAPE prioritization engine pipeline

CAPE

Context-Aware CVE Prioritization Engine. Scores CVEs against a project's SBOM using reachability and patch-presence evidence, re-ranks with 4-dimension AHP-weighted priority.

Vulnerability Management SBOM Prioritization
OSCAR cross-level risk pipeline

OSCAR

Cross-level risk propagation framework linking code-level metrics to ecosystem-level dependency exposure, surfacing false-positive CVE alerts and structurally critical micro-dependencies.

Supply Chain Security Risk Analysis Dependencies
Firmware security with Cerberus

Firmware Security

Secure firmware remote update (S-RFUP), protection-in-transit protocol (PIT), and CDDL mapping schema (CoDICE) built on Microsoft Project Cerberus and Google Open-DICE.

Firmware Hardware Root of Trust Open Source

Publications

* = equal contribution

Peer-Reviewed Conference

1.

R. Podder, F. G. Arellano and I. Ray, "Hidden Amplifiers: Cross-Level Risk in Software Supply Chains," in Proceedings of the 42nd International Conference on Software Maintenance and Evolution (ICSME), 2026. Accepted

2.

R. Podder and I. Ray, "SERA – An AI Driven Re-Programmable Simulation Environment for Explainable Resiliency Analysis in Cyber-Physical Systems," in Proceedings of the 6th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (SaT-CPS '26), Frankfurt am Main, Germany, June 23–25, 2026. 10.1145/3806008.3811708

3.

R. Podder, W. Ganim, S. Sreedharan, I. Ray, and I. Ray, "i-EXAM: Instructable and Explainable Attack Connectivity Graph Modeler," in Proceedings of the International Conference on Automated Planning and Scheduling (ICAPS '26), 2026. (Demo Paper)

4.

R. Podder, J. Simental, E. Azizli, B. Mantha and I. Ray, "CoDICE: Roll the DICE for Firmware Attestation," in Proceedings of 2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA), Pittsburgh, PA, USA, 2025, pp. 183-196. 10.1109/TPS-ISA67132.2025.00028

5.

T. Rhaimi, H. Aghayarzadeh, R. Podder and I. Ray, "Formal Specification and Verification of Protection in Transit (PIT) Protocol Using UPPAAL," in Proceedings of 2025 22nd Annual International Conference on Privacy, Security, and Trust (PST), Fredericton, NB, Canada, 2025, pp. 1-6. 10.1109/PST65910.2025.11268865

6.

R. Podder T. Caglar, S. K. Bashir, S. Sreedharan, I. Ray, and I. Ray, "SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs," in Proceedings of the 30th ACM Symposium on Access Control Models and Technologies (SACMAT '25). Association for Computing Machinery, New York, NY, USA, 62–73. 10.1145/3734436.3734451

7.

R. Talukdar, R. Podder, and I. Ray, "VKG2AG : Generating Automated Knowledge-Enriched Attack Graph (AG) from Vulnerability Knowledge Graph (VKG)," in Proceedings of the 22nd International Conference on Security and Cryptography (SECRYPT 2025). SciTePress, pp. 420-428. 10.5220/0013526700003979

8.

R. Podder, T. Rios, I. Ray, P. Raman, and S. Righi, "S-RFUP: Secure Remote Firmware Update Protocol," in Proceedings of the International Conference on Information Systems Security (ICISS 2024). Lecture Notes in Computer Science, Cham, Springer Nature Switzerland, vol 15416, pp. 42-62. 10.1007/978-3-031-80020-7_3

9.

S. K. Bashir*, R. Podder*, S. Sreedharan, I. Ray and I. Ray, "Resiliency Graphs: Modelling the Interplay between Cyber Attacks and System Failures through AI Planning," in Proceedings of the 2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA), Washington, DC, USA, 2024, pp. 292-302. (*Equal contribution) 10.1109/TPS-ISA62245.2024.00041 Best Paper Award

10.

R. Podder and S. Ghosh, "Impact of White-Box Adversarial Attacks on Convolutional Neural Networks," in Proceedings of the 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), Windhoek, Namibia, 2024, pp. 1-9. 10.1109/ETNCC63262.2024.10767521

11.

R. Podder, J. Sovereign, I. Ray, M. B. Santharam and S. Righi, "The PIT-Cerberus Framework: Preventing Device Tampering During Transit," in Proceedings of the 2024 IEEE 24th International Conference on Software Quality, Reliability and Security (QRS), Cambridge, United Kingdom, 2024, pp. 584-595. 10.1109/QRS62785.2024.00064 Best Paper Award

12.

I. Ray, S. Sreedharan, R. Podder, S. K. Bashir and I. Ray, "Explainable AI for Prioritizing and Deploying Defenses for Cyber-Physical System Resiliency," in Proceedings of the 2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA), Atlanta, GA, USA, 2023, pp. 184-192. 10.1109/TPS-ISA58951.2023.00032

13.

R. Podder and R. K. Barai, "Hybrid Encryption Algorithm for the Data Security of ESP32 based IoT-enabled Robots," in Proceedings of the 2021 Innovations in Energy Management and Renewable Resources(52042), Kolkata, India, 2021, pp. 1-5. 10.1109/IEMRE52042.2021.9386824

Peer-Reviewed Journal

1.

R. Podder, M. Abdelgawad, I. Ray, I. Ray, M. Santharam, and S. Righi, "Correctness and security analysis of the protection in transit (PIT) protocol," Journal of Systems and Software, 230, p.112501, 2025. 10.1016/j.jss.2025.112501

2.

R. Muslim, R. Delfianti, C. Harsito, S. Palaloi, N. A. Aryono, A. Y. Indrarahmana, S. R. Joshua, and R. Podder, "Optimizing the Integration of Wind and Solar Power for Hybrid Electrical Energy in High-Rise Building Energy Systems," Engineered Science, 35, p.1555, 2025. 10.30919/es1555

3.

E. Rovianto, R. Delfianti, F. Minelli, C. Harsito, R. Podder and S. R. Joshua, "Crossflow Thermoelectric Kitchen Hood System for Enhancing Sustainable Energy in Buildings," Civil Engineering Journal, 12(6), 2402–2414. 10.28991/CEJ-2026-012-06-014

Conference Abstracts

1.

I. Ray, R. Podder, S. Sreedharan, I. Ray, and S. K. Bashir, "iEXAM: AI-Driven Cyber Security with Explainability," in 2026 CAE Cybersecurity Community Symposium, Pittsburgh, Pennsylvania, 2026, pp. 73. Abstract Link

2.

I. Ray, S. K. Bashir, R. Podder, S. Sreedharan, and I. Ray, "From Cyber Attacks to System Recovery: A Resiliency-Centered View of Cyber-Physical Systems Security," in 2026 CAE Cybersecurity Community Symposium, Pittsburgh, Pennsylvania, 2026, pp. 74. Abstract Link

Under Review

1.

F. G. Arellano and R. Podder, "From Fix Commits to Vulnerable Functions: Automated Patch Mining for Function-Level CVE Resolution," in Proceedings of the 2026 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED), 2026, Co-located with ACM CCS 2026. Under Review

2.

R. Podder, V. Koscinski and I. Ray, "CAPE — Context-Aware Prioritization Engine for Vulnerability Scoring and Management," in Proceedings of the 49th International Conference on Software Engineering (ICSE), 2027. Under Review

3.

S. K. Bashir, P. D. Hopkins, R. Podder, S. Shreedharan, I. Ray and I. Ray, "AWARE-RG: Abstraction Aware Explanation of Resiliency Graphs for Cyber Physical Systems," in Proceedings of the 48th IEEE Symposium on Security and Privacy, 2027. Under Review

4.

R. Podder, P. D. Hopkins, S. K. Bashir, S. Shreedharan, I. Ray and I. Ray, "Safety Graph: When Safety Responses Become Attack Surfaces in Cyber-Physical Systems," in Proceedings of the Network and Distributed System Security (NDSS) Symposium, 2026. Under Review

5.

S. K. Bashir, R. Podder, S. Sreedharan, I. Ray, and I. Ray, "AFROT: A Framework for Modeling and Analyzing Cascading Failures in CPS Triggered by Cyber Attacks," IEEE Transactions on Dependable and Secure Computing, 2026. Under Review

6.

E. Rovianto, S. D. Prasetyo, C. Harsito, S. R. Joshua, R. Podder, A. Y. Indrarahman, and A. N. S. Permata, "Artificial Intelligence–Based Energy Management in Hybrid Biomass–Storage–EV Microgrids: A Systematic Review and Meta-Analysis," Green Technologies and Sustainability, 2026. Under Review

Patents

1.

R. Podder, S. K. Bashir, S. Sreedharan, I. Ray, and I. Ray, "Instructable AI Agent For Explainable Cybersecurity Planning and Analysis," U.S. Provisional Patent Application Serial No. 63/839,787, filed on July 7, 2025. Approved

2.

R. Podder, S. K. Bashir, S. Sreedharan, I. Ray, and I. Ray, "System and Methods for Building an Instructable AI Agent for Explainable Cybersecurity Planning and Analysis," U.S. Full Patent Application, filed on July 7, 2026. Submitted

Awards & Funding

Awards & Honors

2026

Computer Science Graduate Fellowship Award

College of Natural Sciences, CSU | $6,250

2026

Certificate of Academic Excellence Award

Colorado State University

2025

Student Travel Grants Award

IEEE CIC/TPS/CogMI 2025 | $700

2025

Robert B. France Fellowship in Computer Science

Department of Computer Science, CSU | $2,400

2025

GSC Conference Travel Grant

Graduate Student Council, CSU | $500

2025

Excellence in Teaching Award

Colorado State University

2024

Best Paper Award – IEEE TPS-ISA 2024

"Resiliency Graphs: Modelling the Interplay between Cyber Attacks and System Failures through AI Planning"

2024

Best Paper Award – IEEE QRS 2024

"The PIT-Cerberus Framework: Preventing Device Tampering During Transit" | $450

2024

GSC Conference Travel Grant

Graduate Student Council, CSU | $500

2024

GSC Conference Travel Grant

Graduate Student Council, CSU | $250

2023

Certificate of Academic Excellence Award

Colorado State University

2018

AICTE Post Graduate Scholarship

All India Council for Technical Education | ₹12,500/month for 2 years

2014

Top Class Undergraduate Scholarship

MHRD, Indian Government | ₹75,000/year for 4 years

2013

Dr. B R Ambedkar Award

West Bengal State Government | ₹100,000

Research Funding

U.S. Office of Naval Research (ONR) | "Explainable AI for Prioritizing and Deploying Defenses for Cyber-Physical System Resiliency" | PhD Researcher | N000142612041

NSF IUCRC CCA | "Improving Cyber Security Robustness, Resiliency and Management From Devices to Enterprises" | PhD Researcher | CNS 1822118, CNS 2226232

U.S. Department of Energy | "Cyber Risk Research" | PhD Researcher | DE-NE0008986

NIST | PhD Researcher | 60NANB23D152

State of Colorado | PhD Researcher | SB 18-086

NSF | PhD Researcher | DMS 2123761

American Megatrends International LLC | "Hardware Root of Trust (HRoT) for Firmware Security" | PhD Researcher

Teaching & Mentoring

Teaching Experience

Colorado State University

Graduate Teaching Assistant (Aug 2025 – Dec 2025)

  • CS457 (Computer Networks and the Internet): recitation sessions, independent lectures (4 occasions), exam design
  • CS557 (Advanced Networking): designed penetration-testing and binary reverse-engineering labs
  • CS556 (Computer Security): student research and project support
  • Excellence in Teaching Award 2025 for active-learning and Bloom's Taxonomy alignment

CSU Cybersecurity Summer Camp

Instructor/Camp Designer (2023–2025)

  • Designed and delivered week-long cybersecurity day camps for 35–50+ high school students annually
  • Lectures, hands-on activities, and classroom exercises spanning three consecutive years

Office for Undergraduate Research and Artistry (OURA)

Graduate Mentor (Feb 2026 – Jun 2026)

  • Guided undergraduate mentees through research projects, academic advising, and critical-thinking development

Pedagogical Training: Completed CSU Institute for Learning and Teaching certifications in Best Practices in Teaching, Critical Thinking, Inclusive Pedagogy, and Accessible Electronic Content.

Mentoring Experience

Wadia Ganim
Engineer | Illinois ARCS | Singapore
(1 Research Paper)

Sachin Kurup
CSU Intern | BTech Computer Science
Amrita Vishwa Vidyapeetham

Matthew Leman
Undergraduate | Computer Science
Colorado State University

Saswat Subhankar
Undergraduate Intern | Computer Science
Colorado State University

Enock Apedjinou
OURA Mentee | Computer Science
Colorado State University

Jason Simental
Undergraduate Researcher | Computer Science
Colorado State University (1 Research Paper)

Tyler Rios
Graduate Student | Computer Science
Denver University (1 Research Paper)

Jack Sovereign
Software Engineer | Ductus
(1 Research Paper)

Service

Reviewer Services

Ad Hoc Journal Reviewer

  • IEEE Transactions on Big Data (2026) – 1 paper
  • Journal of Electronic Testing Theory and Applications (2025) – 1 paper
  • Journal of Nonlinear, Complex and Data Science (2024) – 1 paper

Ad Hoc Conference Reviewer

  • ICSE 2027 Dublin (Apr 25-May 1, 2027) – 4 papers
  • ICECER'26 Istanbul (Dec 3-5, 2026) – 1 paper
  • ICECCME'26 Bali (Oct 15-17, 2026) – 1 paper
  • ESORICS'26 Rome (Sep 14-16, 2026) – 4 papers
  • ACM SACMAT'26 Waterloo (Jul 8-10, 2026) – 3 papers
  • ICECET'26 Rome (Jul 6-9, 2026) – 2 papers
  • CODASPY'26 Frankfurt (Jun 23-25, 2026) – 1 paper
  • ACDSA'26 Philippines (Feb 5-7, 2026) – 2 papers
  • ASCENT Workshop at ICDCN'26 Japan (Jan 6-9, 2026) – 2 papers
  • TPS-ISA 2025 Pittsburgh (Nov 11-14, 2025) – 1 paper
  • ICECER'25 Madagascar (Dec 6-8, 2025) – 2 papers
  • ETNCC'25 Windhoek (Aug 5-7, 2025) – 1 paper
  • ACDSA'25 Turkey (Aug 7-9, 2025) – 2 papers
  • ICECCME'25 Tanzania (Oct 16-19, 2025) – 1 paper
  • ESORICS'25 Toulouse (Sep 22-26, 2025) – 3 papers
  • ESORICS'24 Poland (Sep 16-20, 2024) – 1 paper
  • CODASPY'24 Porto (Jun 19-21, 2024) – 1 paper
  • ESORICS'23 Netherlands (Sep 25-29, 2023) – 1 paper
  • ICISS'22 Beijing (Aug 26-28, 2022) – 1 paper
  • DBSec'22 Rutgers (Jul 18-20, 2022) – 1 paper

Professional Engagement

Talks & Presentations

Invited Talks

July 2026

CAE Community of Practice Cyber Research
"i-EXAM. A running case study"

March 2026

Universitas Sam Ratulangi, Manado, Indonesia
"From Classical Systems to Intelligent Secure and Data-Centric Computing"

October 2025

Northern Colorado ISSA, Lory Centre CSU, Fort Collins, CO
"AI-Powered Cyber Security & Cyber Resiliency"

July 2024

TMI Summer Talks, Fort Collins, CO
"The PIT-Cerberus Framework: Preventing Device Tampering During Transit"

October 2023

NSF IUCRC Center for CCAA, CSU, Fort Collins, CO
"Remote Firmware Updates: Preventing Firmware Tampering"

April 2023

NSF IUCRC Center for CCAA, George Mason University, Fairfax, VA
"Protection in Transit – What do we solve?"

October 2022

NSF IUCRC Center for CCAA, UNCC, Charlotte
"Protection in Transit: Enabling Tripartite Trust using a Mesh of Trusted Agents"

Conference & Poster Presentations

17 conference and poster presentations at international venues including ICAPS, IEEE TPS-ISA, IEEE QRS, ETNCC, NSF IUCRC centers, and CSU Graduate Showcases.

  • 6 conference presentations: i-EXAM, CoDICE, Resiliency Graphs, Adversarial Attacks, PIT-Cerberus, Hybrid Encryption
  • 11 poster presentations: Firmware security, Resiliency analysis, and related topics at NSF IUCRC meetings, Graduate Showcases, and workshops

Skills

Languages

Native: Bengali | Other: English, Hindi

Programming & Development

C/C++ PDDL Python JavaScript SQL Java Git Verilog HDL LaTeX

Libraries & ML Algorithms

TensorFlow PyTorch NumPy Pandas Matplotlib Scikit-Learn Seaborn ART cleverhans LLM CtmNN Decision Trees Transformers

Databases & Operating Systems

PostgreSQL MySQL MongoDB Kali Linux Mac OS Windows Hypervisors QEMU VirtualBox VMware Docker

Tools & Technologies

Splunk ELK CAN STRIDE GNS3 TLA+ Wazuh Caldera OPNsense pfSense CPN Wireshark Google Colab Heroku Azure Jupyter Notebook UPPAAL Syft x86 ARM MITRE ATT&CK Suricata Procmon Grype OpenVAS Tenable Active Directory LLVM NIST 800-61 ISO 27035 REMnux Burp Suite

Open Source Projects

HexStrike AI Project Cerberus OpenBMC-libpldm VAL Forbid Iterator Fast Downward Open-DICE

Contact

Email (personal): rakeshpodder3@gmail.com

Email (CSU): rakesh.podder@colostate.edu

Phone: +1 (970) 732-8524

Location: Fort Collins, Colorado, USA