VLDB 2026 Research / reviewers in the wild / expert
Yonggon Kim
dblp:05/10702
· DBLP profile ↗
4ranked-venue papers
2as first author
2since 2021 · last 2021
0000-0002-6384-5313ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Mind control attack: Undermining deep learning with GPU memory exploitationabstractModern deep learning frameworks rely heavily on GPUs to accelerate the computation. However, the security implication of GPU device memory exploitation on deep learning frameworks has been largely neglected. In this paper, we argue that GPU device memory manipulation is a novel attack vector against deep learning systems. We present a novel attack method leveraging the attack vector, which makes deep learning predictions no longer different from random guessing by degrading the accuracy of the predictions. To the best of our knowledge, we are the first to show a practical attack that directly exploits deep learning frameworks through GPU memory manipulation. We confirmed that our attack works on three popular deep learning frameworks, TensorFlow, CNTK, and Caffe, running on CUDA. Finally, we propose potential defense mechanisms against our attack, and discuss concerns of GPU memory safety. Sang-Ok Park, Ohmin Kwon 0001, Yonggon Kim, Sang Kil Cha, Hyunsoo Yoon |
Comput. Secur. | 3 |
| 2021 | ZeroKernel: Secure Context-Isolated Execution on Commodity GPUsabstractIn the last decade, the dedicated graphics processing unit (GPU) has emerged as an architecture for high-performance computing workloads. Recently, researchers have also focused on the isolation property of a dedicated GPU and suggested GPU-based secure computing environments with several promising applications. However, despite the security analysis conducted by the prior studies, it has been unclear whether a dedicated GPU can be leveraged as a secure processor in the presence of a kernel-privileged attacker. In this paper, we first demonstrate the security of dedicated GPUs through comprehensive studies on context information for GPU execution. The paper shows that a kernel-privileged attacker can manipulate the GPU contexts to redirect memory accesses or execute arbitrary GPU codes on the running GPU kernel. Based on the security analysis, this paper proposes a new on-chip execution model for the dedicated GPU and a novel defense mechanism supporting the security of the on-chip execution. With comprehensive evaluation, the paper assures that the proposed solutions effectively isolate sensitive data in on-chip storages and defend against known attack vectors from a privileged attacker, supporting that the commodity GPUs can be leveraged as a secure processor. Ohmin Kwon 0001, Yonggon Kim, Jaehyuk Huh 0001, Hyunsoo Yoon |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | On-demand bootstrapping mechanism for isolated cryptographic operations on commodity accelerators
Yonggon Kim, Ohmin Kwon 0001, Jin Soo Jang, Seongwook Jin, Hyeongboo Baek, Brent ByungHoon Kang, Hyunsoo Yoon |
Comput. Secur. | 1 |
| 2011 | An Alternative Memory Access Scheduling in Manycore AcceleratorsabstractMemory controllers in graphics processing units (GPU) often employ out-of-order scheduling to maximize row access locality. However, this requires complex logic to enable out-of-order scheduling compared with in-order scheduling. To provide a low-cost and low-complexity memory scheduling, we propose an alternative memory scheduling where the memory scheduling is performed not at the destination (i.e., memory controller) but is done at the source (i.e., the cores). We propose two complementary techniques in source-based memory scheduling - network congestion-aware source throttling and super packets, where multiple request packets are grouped together to create a single super packet. By combing these techniques, the performance across a wide range of application is within 95% of the complex FR-FCFS on average and at significantly lower cost and complexity. Yonggon Kim, Hyunseok Lee, John Kim 0001 |
PACT | 1 |