VLDB 2026 Research / reviewers in the wild / expert
Boojoong Kang
dblp:00/10949 · also BooJoong Kang
· DBLP profile ↗
14ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0001-5984-9867ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pack Defender: Proactive Defense Against Packet Attacks in NoCs Using an XGBoost-RNN ModelabstractThe Network-on-Chip (NoC) serves as the critical communication backbone in modern Multi-Processor Systems-on-Chip (MPSoCs), particularly for Deep Learning (DL) hardware where it underpins the reliable execution of machine learning models by facilitating efficient data and weight exchange. However, the NoC is vulnerable to stealthy packet-based attacks initiated by malicious Intellectual Property (IP) cores. Such attacks can severely degrade NoC latency and throughput, which are critical for efficient DL inference, and even compromise the correctness of model execution. Current detection methods are inherently reactive; they identify anomalies by monitoring global system features only after an attack has manifested, lacking the foresight to anticipate impending threats. To address this, we propose Pack Defender, a proactive NoC security framework based on temporal behavior modeling that forecasts future system states and reuses its partial prediction generative model for detection, eliminating the need for a separate module. Experimental results show strong predictive power, with average/top-three similarities of 83%/92% for Source-Level Packet Dropping (SLPD) and 90%/94% for In - Network Packet Diversion (INPD). The low Mean Absolute Error (0.05 for SLPD, 0.03 for INPD) further confirms its accuracy. The detection model (XGBoost) achieves 100% accuracy, with recall rates of 96% and 99% for SLPD and INPD respectively, significantly outperforming state-of-the-art methods lacking proactive prediction. Shengkai Hu, Basel Halak, Boojoong Kang |
ASP-DAC | 4 |
| 2026 | C-STAR: Cost-Aware Adaptive Learning under Concept Drift for Android Malware Detection
Nahee Kwon, Kyoungmin Roh, Young-Sup Hwang, Seong-je Cho, Boojoong Kang |
SECRYPT (1) | 5 |
| 2025 | Uncovering Evaluation Bias in Node Attachment Strategies for the Lightning NetworkabstractThe Lightning Network (LN) is a peer-to-peer network composed of nodes and channels, operating as an offchain payment protocol on top of the Bitcoin blockchain. A newly joining node needs to determine which existing node(s) to establish channel(s) with. This decision is guided by an attachment strategy, which is an algorithm that strategically recommends which Lightning Network node(s) to connect to based on predefined metrics and optimization goals. Current research on Lightning Network attachment strategies focuses primarily on evaluating and enhancing performance, such as payment success rate and transaction fees, as well as influence on network centralisation. However, the evaluation methods commonly used in the literature display two shortcomings: (i) they often rely on a single network topology snapshot, and/or (ii) their simulations are not based on realistic models (e.g., neglecting the network's evolution over time). In this paper, we demonstrate that these two shortcomings can generate biased results, potentially leading to non-generalisable and skewed evaluations of attachment strategies. In our evaluation, six state-of-the-art attachment strategies are evaluated using diverse real-world snapshots of the Lightning Network and a realistic network evolution model based on an estimated churn rate. The experimental results show significant differences from those reported in the literature, confirming that their evaluation methods are subject to bias. For instance, k-median, previously noted for strong fee revenue, sees its routing share drop from 3 % to 0.2 % in a different snapshot; k-center shifts from best to worst in long-term fee reduction under churn; random strategy unexpectedly outperforms in reducing fees and promoting decentralization; and computationally intensive strategies like k-median become impractical on larger topologies, emphasizing the need for diverse, realistic evaluation settings. Asma Almosa, Leonardo Aniello, Boojoong Kang |
SRDS | 3 |
| 2025 | Forensic investigation of vehicle-related data in Android phones connected to In-Vehicle Infotainment systems
Seongbin Cho, Hojun Seong, Haein Kang, Seong-je Cho, Boojoong Kang |
Comput. Networks | 5 |
| 2025 | Business email compromise: A systematic review of understanding, detection, and challengesabstractBusiness Email Compromise (BEC) is a widespread fraud targeting businesses and individuals to obtain financial benefits and gain access to highly sensitive data. BEC fraud significantly impacts almost all organizations worldwide, resulting in substantial losses. Despite its prevalence, there is a shortage of research on understanding and protecting against this fraud. Consequently, this paper aims to survey existing BEC detection techniques. It first provides an overview of the methods and strategies used by attackers in BEC schemes. It also reviews existing BEC detection and prevention techniques, including both technical and non-technical solutions. The strengths of each technique are objectively discussed, and their limitations are critically analyzed. Finally, this study offers a thorough set of current challenges in BEC detection and outlines future research directions, providing valuable guidance for improving security measures against BEC fraud. Amirah Almutairi, Boojoong Kang, Nawfal F. Al Hashimy |
Comput. Secur. | 2 |
| 2023 | The Effectiveness of Transformer-Based Models for BEC Attack Detection
Amirah Almutairi, Boojoong Kang, Nawfal F. Fadhel |
NSS | 2 |
| 2019 | Intrusion Resilience for PV Inverters in a Distribution Grid Use-Case Featuring Dynamic Voltage Control
Boojoong Kang, David Umsonst, Mario Faschang, Christian Seitl, Ivo Friedberg, Friederich Kupzog, Henrik Sandberg, Kieran McLaughlin |
CRITIS | 1 |
| 2019 | A Multimodal Deep Learning Method for Android Malware Detection Using Various FeaturesabstractWith the widespread use of smartphones, the number of malware has been increasing exponentially. Among smart devices, android devices are the most targeted devices by malware because of their high popularity. This paper proposes a novel framework for android malware detection. Our framework uses various kinds of features to reflect the properties of android applications from various aspects, and the features are refined using our existence-based or similarity-based feature extraction method for effective feature representation on malware detection. Besides, a multimodal deep learning method is proposed to be used as a malware detection model. This paper is the first study of the multimodal deep learning to be used in the android malware detection. With our detection model, it was possible to maximize the benefits of encompassing multiple feature types. To evaluate the performance, we carried out various experiments with a total of 41 260 samples. We compared the accuracy of our model with that of other deep neural network models. Furthermore, we evaluated our framework in various aspects including the efficiency in model updates, the usefulness of diverse features, and our feature representation method. In addition, we compared the performance of our framework with those of other existing methods including deep learning-based methods. TaeGuen Kim 0002, Boojoong Kang, Mina Rho, Sakir Sezer, Eul-Gyu Im |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Binary executable file similarity calculation using function matching
TaeGuen Kim 0002, Yeo Reum Lee, Boojoong Kang, Eul-Gyu Im |
J. Supercomput. | 3 |
| 2018 | Peer Based Tracking using Multi-Tuple Indexing for Network Traffic Analysis and Malware DetectionabstractTraditional firewalls, Intrusion Detection Systems(IDS) and network analytics tools extensively use the `flow' connection concept, consisting of five `tuples' of source and destination IP, ports and protocol type, for classification and management of network activities. By analysing flows, information can be obtained from TCP/IP fields and packet content to give an understanding of what is being transferred within a single connection. As networks have evolved to incorporate more connections and greater bandwidth, particularly from “always on” IoT devices and video and data streaming, so too have malicious network threats, whose communication methods have increased in sophistication. As a result, the concept of the 5 tuple flow in isolation is unable to detect such threats and malicious behaviours. This is due to factors such as the length of time and data required to understand the network traffic behaviour, which cannot be accomplished by observing a single connection. To alleviate this issue, this paper proposes the use of additional, two tuple and single tuple flow types to associate multiple 5 tuple communications, with generated metadata used to profile individual connnection behaviour. This proposed approach enables advanced linking of different connections and behaviours, developing a clearer picture as to what network activities have been taking place over a prolonged period of time. To demonstrate the capability of this approach, an expert system rule set has been developed to detect the presence of a multi-peered ZeuS botnet, which communicates by making multiple connections with multiple hosts, thus undetectable to standard IDS systems observing 5 tuple flow types in isolation. Finally, as the solution is rule based, this implementation operates in realtime and does not require post-processing and analytics of other research solutions. This paper aims to demonstrate possible applications for next generation firewalls and methods to acquire additional information from network traffic. Matthew Hagan, Boojoong Kang, Kieran McLaughlin, Sakir Sezer |
PST | 2 |
| 2017 | Deep Android Malware DetectionabstractIn this paper, we propose a novel android malware detection system that uses a deep convolutional neural network (CNN). Malware classification is performed based on static analysis of the raw opcode sequence from a disassembled program. Features indicative of malware are automatically learned by the network from the raw opcode sequence thus removing the need for hand-engineered malware features. The training pipeline of our proposed system is much simpler than existing n-gram based malware detection methods, as the network is trained end-to-end to jointly learn appropriate features and to perform classification, thus removing the need to explicitly enumerate millions of n-grams during training. The network design also allows the use of long n-gram like features, not computationally feasible with existing methods. Once trained, the network can be efficiently executed on a GPU, allowing a very large number of files to be scanned quickly. Niall McLaughlin, Jesús Martínez del Rincón, Boojoong Kang, Suleiman Y. Yerima, Paul Miller 0003, Sakir Sezer, Yeganeh Safaei, Erik Trickel, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 3 |
| 2016 | Credible, resilient, and scalable detection of software plagiarism using authority histograms
Dong-Kyu Chae, Jiwoon Ha, Sang-Wook Kim, Boojoong Kang, Eul-Gyu Im, Sunju Park |
Knowl. Based Syst. | 4 |
| 2015 | Investigating cyber-physical attacks against IEC 61850 photovoltaic inverter installationsabstractCyber-attacks against Smart Grids have been found in the real world. Malware such as Havex and BlackEnergy have been found targeting industrial control systems (ICS) and researchers have shown that cyber-attacks can exploit vulnerabilities in widely used Smart Grid communication standards. This paper addresses a deep investigation of attacks against the manufacturing message specification of IEC 61850, which is expected to become one of the most widely used communication services in Smart Grids. We investigate how an attacker can build a custom tool to execute man-in-the-middle attacks, manipulate data, and affect the physical system. Attack capabilities are demonstrated based on NESCOR scenarios to make it possible to thoroughly test these scenarios in a real system. The goal is to help understand the potential for such attacks, and to aid the development and testing of cyber security solutions. An attack use-case is presented that focuses on the standard for power utility automation, IEC 61850 in the context of inverter-based distributed energy resource devices; especially photovoltaics (PV) generators. Boojoong Kang, Peter Maynard 0001, Kieran McLaughlin, Sakir Sezer, Filip Andren, Christian Seitl, Friederich Kupzog, Thomas I. Strasser |
ETFA | 1 |
| 2013 | Software plagiarism detection: a graph-based approachabstractAs plagiarism of software increases rapidly, there are growing needs for software plagiarism detection systems. In this paper, we propose a software plagiarism detection system using an API-labeled control flow graph (A-CFG) that abstracts the functionalities of a program. The A-CFG can reflect both the sequence and the frequency of APIs, while previous work rarely considers both of them together. To perform a scalable comparison of a pair of A-CFGs, we use random walk with restart (RWR) that computes an importance score for each node in a graph. By the RWR, we can generate a single score vector for an A-CFG and can also compare A-CFGs by comparing their score vectors. Extensive evaluations on a set of Windows applications demonstrate the effectiveness and the scalability of our proposed system compared with existing methods. Dong-Kyu Chae, Jiwoon Ha, Sang-Wook Kim, Boojoong Kang, Eul-Gyu Im |
CIKM | 4 |