Seyoung Lee 0003

dblp:118/2458-3 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0002-8277-8486ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Lifecycle-aware security evaluation of programmable DeFi hooks: A framework for Uniswap V4
abstract
The programmable hook architecture introduced in Uniswap V4 enables external logic to be executed at predefined lifecycle events within automated market maker (AMM) protocols, enhancing the customizability. However, this design introduces a novel attack surface that conventional static analysis tools are ill-equipped to handle, particularly due to hooks’ context-dependent behavior and lack of publicly available source code. This paper proposes HookScope, a lifecycle-aware dynamic analysis framework for evaluating the structural security of programmable hooks. HookScope defines five runtime threat types (T1-T5) specific to the Uniswap V4 hook model and employs simulation-based testing to detect their manifestation during live contract execution. Risk scores are computed using a CVSS-inspired model that incorporates threat severity, execution context, and system-level impact. Comparative evaluation demonstrates that HookScope identifies threats overlooked by widely-used baseline tools such as Mythril, highlighting the necessity of lifecycle-aware dynamic analysis for programmable DeFi infrastructure. The proposed framework contributes a reproducible, quantifiable approach to threat detection in decentralized protocols and provides a foundation for future research on secure extensibility in AMM-based systems.
Hoon Oh, Seyoung Lee 0003
Comput. Networks2
2025 Poster: Inferring On-Screen Keyboard Input via Gamepad-based Mouse Movement Traces
abstract
On-screen keyboards operated via directional input devices-such as remote controls, D-pads, or game controllers-are widely used in smart TVs, kiosks, and accessibility-focused systems.Although these systems appear secure due to limited interaction bandwidth and the absence of direct screen access, we demonstrate that the sequence of directional movements and confirmation clicks can be exploited to infer sensitive input such as passwords.We propose a novel side-channel attack that reconstructs cursor trajectories from direction-click logs, simulates all possible starting positions, and ranks candidate passwords based on geometric and semantic scoring.Our evaluation over 1000 randomly generated passwords shows that the correct password appears in the top-5 candidates in 100% of cases and ranks first in 85.8% of them.We also investigate practical mitigation techniques-such as temporal jitter and randomized directional noise-and demonstrate that these defenses reduce the attack success rate to 18.2%.This study highlights a previously underexplored threat surface in GUI-based systems using directional input and calls for renewed attention to input privacy in constrained environments. CCS Concepts• Security and privacy → Side-channel analysis and countermeasures.
Gyujeong Jin, Seyoung Lee 0003
CCS2
2025 Poster: Longitudinal Analysis of Romance Scam Infrastructure Evolution: Evidence of Strategic Legitimization
abstract
Romance scams represent a cybercrime category causing more than 650 million in reported losses annually, with limited systematic longitudinal analysis. We present a 12-year infrastructure evolution study analyzing 11,674 romance scammer profiles from ScamDigger (2012-2024). Using IP geolocation and ASN classification, we identify a marked inflection in 2019. Contrary to expected technological advancement, we observe strategic migration toward legitimate infrastructure: Traditional ISP usage increased substantially while proxy usage declined from an average of 90.6% (pre-2019) to 53.1% (post-2019), corresponding to a 37.5 percentage-point decrease. Analysis reveals systematic geographic specialization with operational bases in West African Traditional ISPs (Nigeria: 94.2%, Ghana: 94.6%) and deceptive infrastructure in Western cloud services (US: 53.1%, Germany: 59.9%). ASN diversity contracted 31.3%, indicating ecosystem consolidation. These findings suggest ongoing industrialization through legitimacy exploitation, motivating adjustments to detection methodologies.
Nayeon Ryu, Heeyeong Suh, Seyoung Lee 0003
CCS3
2024 In-Vehicle Network Intrusion Detection System Using CAN Frame-Aware Features
abstract
With the advancement of connected and automated vehicles (CAVs), drivers now have access to convenient features such as lane-keeping, cruise control, and more. The electronic control units (ECUs) equipped within vehicles communicate with each other through the controller area network (CAN). However, since the CAN does not possess any security mechanisms, it becomes a target for adversaries to attack. In light of this, a significant amount of research regarding intrusion detection systems (IDSs) has focused on detecting such maliciously injected CAN packets. Nevertheless, most existing machine learning-based IDSs neither calculate the exact time intervals of the CAN packets nor utilize the counter information. Precise timing intervals are a crucial feature for detecting spoofing, fuzzing, and replay attacks, and counter information is also a significant feature that can detect fuzzing and replay attacks. Therefore, in this paper, we propose a methodology for extracting two detection features that are aware of CAN frame characteristics: the interframe space (IFS) between two consecutive CAN packets, and the counter information of a CAN data payload (i.e., data field). Using these features, we introduce decision tree-based IDS. We evaluate the proposed features with popular decision tree-based models such as random forest and extreme gradient boosting (XGBoost). The results show that our proposed IDS can detect maliciously injected CAN packets with an F1 score of 99.54% in binary classification and 97.99% in multi-class classification, which are higher scores than what existing machine/deep learning-based IDSs achieve. Additionally, we measure the detection time of our proposed IDS in both online and offline testing environments.
Yeonseon Jeong, Hyunghoon Kim, Seyoung Lee 0003, Wonsuk Choi 0001, Dong Hoon Lee 0001, Hyo Jin Jo
IEEE Trans. Intell. Transp. Syst.3
2023 RIDAS: Real-time identification of attack sources on controller area networks
Jiwoo Shin, Hyunghoon Kim, Seyoung Lee 0003, Wonsuk Choi 0001, Dong Hoon Lee 0001, Hyo Jin Jo
USENIX Security Symposium3
2023 ErrIDS: An Enhanced Cumulative Timing Error-Based Automotive Intrusion Detection System
abstract
Contemporary vehicles have undergone numerous transformations to become fully computerized machines. This computerizing process is intended to provide safety and convenience for drivers; however, there have been many studies demonstrating how to remotely maneuver a vehicle by compromising its in-vehicle electronic control units (ECU). As a countermeasure, automotive intrusion detection systems (IDSs) have also been extensively explored as potential remedies. The clock-based IDS was one of the most promising methods for an automotive IDS, but researchers have recently determined it to be insufficient, as adversaries can emulate the clock skew. In this paper, we propose a novel automotive IDS that leverages the residuals—which have traditionally been considered an error that should be removed from analysis—of average and actual timestamp intervals of two consecutive controller area network (CAN) messages. Thus, we present a rationale as to why large residuals occur in a real in-vehicle CAN network. Our method analyzes transmission periodicity so closely that any minuscule change can be detected in the event of an intrusion. We show that our method detects a vehicle intrusion with a low false-alarm rate, and that it can detect a new sophisticated attack which emulates the clock skew of an original transmission. To the best of our knowledge, this is the first approach analyzing transmission time to detect the frequency masquerading attack with clock skew emulation. Finally, our method enables the sharing of parameters determined in a vehicle with other like models, which is meaningful for manufacturers in terms of scalability.
Seyoung Lee 0003, Wonsuk Choi 0001, Hyo Jin Jo, Dong Hoon Lee 0001
IEEE Trans. Intell. Transp. Syst.1
2022 Cybersecurity and Capacity Requirement for Data Storage of Autonomous Driving System
abstract
Autonomous vehicles (AVs) require large dataset to perceive surrounding accurately, and continuous connectivity to update software frequently. The more connection and data the vehicle has the more cybersecurity incidents could occur. To address the challenges of AVs development, new regulations and standards have been introduced from Event Data Recorder (EDR) and Data Storage System for Automated Driving (DSSAD) to automotive cybersecurity, and these new regulations and requirements demand AVs to equip large data storage to analyze accidents of AVs. New data storage for AVs could bring new cybersecurity risks. The main purpose of this paper is to derive data storage requirements for automated driving system (ADS) and to conduct systematic cybersecurity risk analysis for data storage. In this paper, the regulations and standards for AVs are reviewed and new requirements for data storage of automated driving system are derived based on that. Plus, cybersecurity risk of the future data storage is analyzed with threat analysis and risk analysis (TARA) method. Finally, cybersecurity validation and verification methods have been researched for data storage of AVs.
Insup Kim, Ganggyu Lee, Seyoung Lee 0003
VTC Fall3