Raja Hasnain Anwar

PXL_20240102_144222706.RAW-01.COVER~2.jpg

Microsoft Building 36

16255 NE 36th Way,

Redmond, WA 98052

Hi, I am a ML Scientist II in OfficeAI @ Microsoft and a PhD student @ University of Massachusetts Amherst. I work on security policy analysis of large-scale systems with Dr. Muhammad Taqi Raza in Khwarizmi Lab.

I find vulnerabilities in the authentication, authorization, and access-control protocols securing large-scale payment systems, often distributed across independent parties or built on legacy designs. I showed that digital wallets’ decentralized trust model lets an attacker add a victim’s bank card to their own wallet and bypass payment authorization, validated against major US banks and wallet apps (USENIX Security 2024; covered by Investopedia and TechRadar). I later found a legacy flaw in the EMV contactless protocol that lets a Visa card with an altered expiry date complete purchases after being reported stolen (USENIX Security 2026; covered by WIRED, The Hacker News, and others).

This protocol-security methodology extends naturally to other distributed and legacy systems. In aviation, I found that in-flight Wi-Fi paywalls share the same broken device-authentication logic as digital wallets, letting attackers bypass the paywall for free Internet access (ACM WiSec 2025). In 5G, I showed that radio-resource scheduling, which enforces the same kind of authorization logic I broke in payments, leaks which application a user is running in real time (IEEE MASS 2024). In quantum networking, I formally verified the classical control plane coordinating quantum key distribution against ETSI and ITU-T specifications and found three protocol-level vulnerabilities, along with countermeasures verified in Tamarin (IEEE QCE 2026). And in machine learning, I extended this side-channel lens to show that aggregate GPU execution profiles leak a deployed model’s architecture with complete accuracy (ACM TAISAP).

Alongside security research, I study the capabilities of computer-use agents. I co-developed PPT-Eval, a benchmark of 120 PowerPoint creation and editing tasks with rubric-based evaluation that measures partial progress and penalizes unnecessary changes.

Before joining UMass, I completed my Bachelor’s in Computer Science (BSCS) from National University of Sciences and Technology (NUST), Pakistan in 2020. At NUST, I worked as a Research Assistant in the TUKL-NUST R&D Center, focusing on document detection, localization, and OCR for information extraction.

news

May 15, 2026 Paper on EMV security, ‘Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments’ has been accepted at USENIX Security 2026.
Apr 30, 2026 Paper on my internship work at Microsoft, ‘PPT-Eval: A Benchmark for Computer-Use Agents on PowerPoint Tasks,’ has been accepted at ICML 2026.
Apr 27, 2026 Paper InferNet: Exploiting Aggregate GPU Profiles as Side-Channel for DNN Architecture Inference has been accepted for publication in ACM Transactions on AI Security and Privacy.
Feb 02, 2026 Started working at Microsoft as a Data Scientist II on the Office AI team; working on building WXP apps for M365 Copilot.
Jan 23, 2026 Defended my PhD thesis proposal on security of emerging digital payment technologies.

selected publications

  1. zombie_setup.png
    Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
    Raja Hasnain Anwar , Gerard DeCunha , and Muhammad Taqi Raza
    2026
  2. QCE
    Beyond the Quantum Promise: A Security Analysis of Classical Control in Quantum Key Distribution
    Ali Hamza Malik , Raja Hasnain Anwar , and Muhammad Taqi Raza
    In IEEE International Conference on Quantum Computing and Engineering (QCE) , 2026
  3. pptarena.png
    PPTArena: A Benchmark for Computer-Use Agents on PowerPoint Tasks
    Apurva Gandhi , Vishwas Suryanarayanan , Raja Hasnain Anwar , and 6 more authors
    2026
  4. infernet.png
    InferNet: Exploiting Aggregate GPU Profiles as Side-Channel for DNN Architecture Inference
    Raja Hasnain Anwar , Jonah O’Brien Weiss , Tiago Alves , and 2 more authors
    ACM Transactions on AI Security and Privacy, 2026
  5. verificagent.png
    VerificAgent: Domain-Specific Memory Verification for Scalable Oversight of Aligned Computer-Use Agents
    Thong Q. Nguyen , Shubhang Desai , Raja Hasnain Anwar , and 3 more authors
    2025
  6. airline_overview.png
    Cloud Nine Connectivity: Security Analysis of In-Flight Wi-Fi Paywall Systems
    Abdullah Al Ishtiaq , Raja Hasnain Anwar , Yasra Chandio , and 3 more authors
    In 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks , 2025
    * First two authors contributed equally.
  7. payment_arch.png
    In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping
    Raja Hasnain Anwar , Syed Rafiul Hussain , and Muhammad Taqi Raza
    In USENIX Security Symposium , 2024
  8. 5g_scheduler.png
    Characterizing Encrypted Application Traffic through Cellular Radio Interface Protocol
    Md Ruman Islam , Raja Hasnain Anwar , Spyridon Mastorakis , and 1 more author
    In IEEE International Conference on Mobile Ad-Hoc and Smart Systems (MASS) , 2024