Raja Hasnain Anwar
Microsoft Building 36
16255 NE 36th Way,
Redmond, WA 98052
Hi, I am a ML Scientist II in OfficeAI @ Microsoft and a PhD student @ University of Massachusetts Amherst. I work on security policy analysis of large-scale systems with Dr. Muhammad Taqi Raza in Khwarizmi Lab.
I find vulnerabilities in the authentication, authorization, and access-control protocols securing large-scale payment systems, often distributed across independent parties or built on legacy designs. I showed that digital wallets’ decentralized trust model lets an attacker add a victim’s bank card to their own wallet and bypass payment authorization, validated against major US banks and wallet apps (USENIX Security 2024; covered by Investopedia and TechRadar). I later found a legacy flaw in the EMV contactless protocol that lets a Visa card with an altered expiry date complete purchases after being reported stolen (USENIX Security 2026; covered by WIRED, The Hacker News, and others).
This protocol-security methodology extends naturally to other distributed and legacy systems. In aviation, I found that in-flight Wi-Fi paywalls share the same broken device-authentication logic as digital wallets, letting attackers bypass the paywall for free Internet access (ACM WiSec 2025). In 5G, I showed that radio-resource scheduling, which enforces the same kind of authorization logic I broke in payments, leaks which application a user is running in real time (IEEE MASS 2024). In quantum networking, I formally verified the classical control plane coordinating quantum key distribution against ETSI and ITU-T specifications and found three protocol-level vulnerabilities, along with countermeasures verified in Tamarin (IEEE QCE 2026). And in machine learning, I extended this side-channel lens to show that aggregate GPU execution profiles leak a deployed model’s architecture with complete accuracy (ACM TAISAP).
Alongside security research, I study the capabilities of computer-use agents. I co-developed PPT-Eval, a benchmark of 120 PowerPoint creation and editing tasks with rubric-based evaluation that measures partial progress and penalizes unnecessary changes.
Before joining UMass, I completed my Bachelor’s in Computer Science (BSCS) from National University of Sciences and Technology (NUST), Pakistan in 2020. At NUST, I worked as a Research Assistant in the TUKL-NUST R&D Center, focusing on document detection, localization, and OCR for information extraction.
news
| May 15, 2026 | Paper on EMV security, ‘Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments’ has been accepted at USENIX Security 2026. |
|---|---|
| Apr 30, 2026 | Paper on my internship work at Microsoft, ‘PPT-Eval: A Benchmark for Computer-Use Agents on PowerPoint Tasks,’ has been accepted at ICML 2026. |
| Apr 27, 2026 | Paper InferNet: Exploiting Aggregate GPU Profiles as Side-Channel for DNN Architecture Inference has been accepted for publication in ACM Transactions on AI Security and Privacy. |
| Feb 02, 2026 | Started working at Microsoft as a Data Scientist II on the Office AI team; working on building WXP apps for M365 Copilot. |
| Jan 23, 2026 | Defended my PhD thesis proposal on security of emerging digital payment technologies. |