VLDB 2026 Research / reviewers in the wild / expert
Insu Yun
dblp:119/7670
· DBLP profile ↗
25ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0001-8931-2833ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 4 first-author · 15 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RTCON: Context-Adaptive Function-Level Fuzzing for RTOS Kernels
Eun-Kyu Lee, Insu Yun |
NDSS | 3 |
| 2025 | OTABase: Enhancing Over-the-Air Testing to Detect Memory Crashes in Cellular BasebandsabstractBaseband processors (BPs) in cellular devices implement complex radio protocols, and memory corruption vulnerabilities in these implementations can lead to critical security breaches, including remote code execution. Traditional approaches to detecting such vulnerabilities rely on reverse engineering or emulation. However, these methods face significant scalability challenges due to proprietary firmware and architectural complexities. Over-the-air (OTA) testing offers broader applicability but poses challenges in managing UE state, detecting crashes, and ensuring protocol coverage. We present OTABase, an OTA testing framework that enables efficient detection of memory crashes in LTE base-bands by leveraging protocol specifications. OTABase combines three key techniques: a network-side state control mechanism for efficient management of UE states and connections, a specification-guided test case generation targeting memory crashes in NAS and RRC protocols, and a two-phase crash detection oracle utilizing protocol-based liveness checks and manufacturer debug features. Evaluating OTABase on six commercial BPs from three major manufacturers, unearthed seven previously unpatched memory crashes. Among these, three were assigned CVEs, including one out-of-bounds write vulnerability that allows remote code execution. Additionally, we extend OTABase to 5G basebands for PoC, demonstrating its generalizability and practical utility. CheolJun Park, Marc Egli, Beomseok Oh 0001, Tuan Dinh Hoang, Suhwan Jeong, Martin Crettol, Insu Yun, Mathias Payer, Yongdae Kim |
ACSAC | 7 |
| 2025 | Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityabstractFile systems are essential components of modern operating systems, with Windows being one of the most dominant platforms. Recently, a series of attacks have exploited the Windows file system to trigger serious security threats such as privilege escalation. Over the past several years, dozens of such attacks have been reported and even exploited in the wild. However, Microsoft has consistently addressed these issues with targeted patches rather than fundamental redesigns — resembling a precarious game of Jenga where security measures are stacked upon an unstable foundation. In this paper, we present a five-step comprehensive analysis of the Windows file system's design weaknesses. First, we analyze how Windows differs from another operating system, Linux. Second, we investigated how these discrepancies lead to security vulnerabilities in real-world applications and identified 13 high-impact vulnerabilities, including 11 previously unknown ones. Third, we show that current compatibility layers in modern programming languages fail to handle these discrepancies properly. Specifically, we examined compatibility layers in six programming languages and found 27 non-compliant and 9 inconsistencies, rendering these layers unreliable. Fourth, through a user study involving 21 experienced developers, we found that most were unfamiliar with OS-level file system discrepancies and rarely implemented appropriate mitigations. Finally, we analyze existing countermeasures and discuss their limitations. Our findings reveal critical yet largely obscured security risks resulting from design flaws in the Windows file system. Furthermore, we suggest that Microsoft rethink its strategy and address these fundamental weaknesses. Dong-uk Kim, Sanghak Oh, Hyoungshick Kim, Insu Yun |
CCS | 5 |
| 2025 | CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel
Dong-ok Kim, Juhyun Song, Insu Yun |
CCS | 3 |
| 2025 | RGFuzz: Rule-Guided Fuzzer for WebAssembly RuntimesabstractWebAssembly runtimes embed compilers to compile WebAssembly code into machine code for execution. These compilers use various compiler rules to define how to optimize and lower the WebAssembly code. However, existing testing tools struggle to explore these rules effectively due to their complexity. Moreover, they cannot generate test cases diversely due to their limitations, which can result in undetected bugs. This paper presents RGFuzz, a differential fuzzer for WebAssembly runtimes, addressing the existing limitations through two novel techniques. First, RGFuzz uses rule-guided fuzzing; which extracts compiler rules from the WebAssembly runtime, wasmtime, and uses them to guide test case generation, thereby effectively exploring complex rules. Second, RGFuzz uses reverse stack-based generation to generate test cases diversely. These techniques enable RGFuzz to find bugs effectively in WebAssembly runtimes. We implemented RGFuzz and evaluated it on six engines: wasmtime, Wasmer, WasmEdge, V8, SpiderMonkey, and JavaScriptCore. As a result, RGFuzz found 20 new bugs in these engines, including one bug with a CVE ID issued. Our evaluation demonstrates that RGFuzz outperforms existing fuzzers by utilizing the extracted rules and diversely generating test cases. Insu Yun |
SP | 3 |
| 2025 | LLFuzz: An Over-the-Air Dynamic Testing Framework for Cellular Baseband Lower Layers
Tuan Dinh Hoang, Taekkyung Oh, CheolJun Park, Insu Yun, Yongdae Kim |
USENIX Security Symposium | 4 |
| 2025 | Too Much of a Good Thing: (In-)Security of Mandatory Security Software for Financial Services in South Korea
Taisic Yun, Suhwan Jeong, Yonghwa Lee, Seungjoo Kim, Hyoungshick Kim, Insu Yun, Yongdae Kim |
USENIX Security Symposium | 6 |
| 2025 | FirmState: Bringing Cellular Protocol States to Shannon Baseband EmulationabstractCellular baseband processors represent critical security components in modern mobile devices, yet they remain challenging to analyze due to their complexity and restricted access. Recent advances in baseband research introduced FirmWire, the state-of-the-art emulator enabling full-system baseband emulation with extensive features debugging capabilities. However, it lacks protocol state awareness, significantly limiting its coverage and fidenlity. While implementing such support demands substantial engineering effort, accurately modeling protocol states remains essential for comprehensive baseband security analysis. In this paper, we present FirmState, a state-aware methodology that augments baseband emulation, specifically targeting Samsung Shannon baseband. FirmState semi-automatically recovers and applies state information extracted from physical devices during actual network communication, enabling more complete code coverage and authentic behavior reproduction without extensive reverse engineering. Our evaluation demonstrates a significant improvement in code coverage, achieving 7.5% for RRC--2.7× higher than previous work. Additionally, our system newly supports NAS over FirmWire, with code coverage ranging from 4.5% to 9.2%, depending on the protocol state. Using our approach, we discovered and analyzed two 1-day vulnerabilities in Samsung's baseband implementation, demonstrating FirmState's effectiveness for baseband security. We make FirmState open-source to support further research in baseband security. Suhwan Jeong, Beomseok Oh 0001, Insu Yun, Yongdae Kim, CheolJun Park |
WISEC | 4 |
| 2025 | Bridging the Gap between Real-World and Formal Binary Lifting through Filtered-SimulationabstractBinary lifting is a key component in binary analysis tools. In order to guarantee the correctness of binary lifting, researchers have proposed various formally verified lifters. However, such formally verified lifters have too strict requirements on binary, which do not sufficiently reflect real-world lifters. In addition, real-world lifters use heuristic-based assumptions to lift binary code, which makes it difficult to guarantee the correctness of the lifted code using formal methods. In this paper, we propose a new interpretation of the correctness of real-world binary lifting. We formalize the process of binary lifting with heuristic-based assumptions used in real-world lifters by dividing it into a series of transformations, where each transformation represents a lift with new abstraction features. We define the correctness of each transformation as filtered-simulation , which is a variant of bi-simulation, between programs before and after transformation. We present three essential transformations in binary lifting and formalize them: (1) control flow graph reconstruction, (2) abstract stack reconstruction, and (3) function input/output identification. We implement our approach for x86-64 Linux binaries, named fible , and demonstrate that it can correctly lift Coreutils and CGC datasets compiled with GCC. Jihee Park, Insu Yun, Sukyoung Ryu |
Proc. ACM Program. Lang. | 2 |
| 2023 | QueryX: Symbolic Query on Decompiled Code for Finding Bugs in COTS BinariesabstractExtensible static checking tools, such as Sys and CodeQL, have successfully discovered bugs in source code. These tools allow analysts to write application-specific rules, referred to as queries. These queries can leverage the domain knowledge of analysts, thereby making the analysis more accurate and scalable. However, the majority of these tools are inapplicable to binary-only analysis. One exception, joern, translates a binary code into decompiled code and feeds the decompiled code into an ordinary C code analyzer. However, this approach is not sufficiently precise for symbolic analysis, as it overlooks the unique characteristics of decompiled code. While binary analysis platforms, such as angr, support symbolic analysis, analysts must understand their intermediate representations (IRs) although they are mostly working with decompiled code.In this paper, we propose a precise and scalable symbolic analysis called fearless symbolic analysis that uses intuitive queries for binary code and implement this in QueryX. To make the query intuitive, QueryX enables analysts to write queries on top of decompiled code instead of IRs. In particular, QueryX supports callbacks on decompiled code, using which analysts can control symbolic analysis to discover bugs in the code. For precise analysis, we lift decompiled code into our IR named DNR and perform symbolic analysis on DNR while considering the characteristics of the decompiled code. Notably, DNR is only used internally such that it allows analysts to write queries regardless of using DNR. For scalability, QueryX automatically reduces control-flow graphs using callbacks and ordering dependencies between callbacks that are specified in the queries. We applied QueryX to the Windows kernel, the Windows system service, and an automotive binary. As a result, we found 15 unique bugs including 10 CVEs and earned $180,000 from the Microsoft bug bounty program. HyungSeok Han, JeongOh Kyea, Yonghwi Jin, Jinoh Kang, Brian Pak, Insu Yun |
SP | 6 |
| 2023 | BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software
Eunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim 0001, Yongdae Kim, Insu Yun |
USENIX Security Symposium | 6 |
| 2023 | Scalable and Secure Virtualization of HSM With ScaleTrustabstractHardware security modules (HSMs) have been utilized as a trustworthy foundation for cloud services. Unfortunately, existing systems using HSMs fail to meet multi-tenant scalability arising from the emerging trends such as microservices, which utilize frequent cryptographic operations. As an alternative, cloud vendors provide HSMs as a service. However, such cloud-managed HSM usage models raise security concerns due to their untrusted and shared operating environment. We propose ScaleTrust, a scalable and secure system for key management. ScaleTrust allows us to scale the number of virtual HSM partitions, each of which is isolated with respect to each other and is robust against cloud insider attacks, while preserving physical isolation of the root of trust. To enable this, ScaleTrust uses Intel SGX and multiple HSM features, such as restricting key usage by controlling key attributes of in-HSM keys and establishing a secure channel using only HSM commands. Finally, we apply ScaleTrust to four real-world systems: Keyless SSL for TLS private key offloading, JSON Web Token authentication for microservices, key provisioning, and encryption in database systems. Our evaluation shows that ScaleTrust achieves multi-tenancy in a scalable way by providing multiple virtual HSMs with legacy HSM devices that are designed to support a single tenant. ScaleTrust provides security against insider threats while incurring 11.9% and 39.0% of end-to-end throughput and latency overhead for Keyless SSL compared to stand-alone HSMs. Juhyeng Han, Insu Yun, Taesoo Kim, Sooel Son, Dongsu Han |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | Fuzzing@Home: Distributed Fuzzing on Untrusted Heterogeneous ClientsabstractFuzzing is a practical technique to automatically find vulnerabilities in software. It is well-suited to running at scale with distributed computing platforms thanks to its parallelizability. Therefore, individual researchers and companies typically setup fuzzing platforms on multiple servers and run fuzzers in parallel. However, as such resources are private, they suffer from financial and physical limits. In this paper, we propose [email protected]; the first public collaborative fuzzing network, based on heterogeneous machines owned by potentially untrusted users. Using our system, multiple organizations (or individuals) can easily collaborate to fuzz a software of common interest in an efficient way. One can participate and earn economic benefits if the fuzzing network is tied to a bug-bounty program, or simply donate spare computing power as a volunteer. Daehee Jang, Ammar Askar, Insu Yun, Stephen Tong, Yiqin Cai, Taesoo Kim |
RAID | 3 |
| 2022 | DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices
CheolJun Park, Sangwook Bae, Beomseok Oh 0001, Eun-Kyu Lee, Insu Yun, Yongdae Kim |
USENIX Security Symposium | 6 |
| 2021 | HardsHeap: A Universal and Extensible Framework for Evaluating Secure AllocatorsabstractSecure allocators have been extensively studied to mitigate heap vulnerabilities. They employ safe designs and randomized mechanisms to stop or mitigate heap exploitation. Despite extensive research efforts, secure allocators can only be evaluated by with theoretical analysis or pre-defined data sets, which are insufficient to effectively reflect powerful adversaries in the real world. Insu Yun, Woosun Song, Seunggi Min, Taesoo Kim |
CCS | 1 |
| 2021 | BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 Protocols
Eunsoo Kim, Dongkwan Kim 0001, CheolJun Park, Insu Yun, Yongdae Kim |
NDSS | 4 |
| 2021 | Preventing Use-After-Free Attacks with Fast Forward Allocation
Brian Wickman, Hong Hu 0004, Insu Yun, Daehee Jang, Jungwon Lim, Sanidhya Kashyap, Taesoo Kim |
USENIX Security Symposium | 3 |
| 2020 | Fuzzing JavaScript Engines with Aspect-preserving MutationabstractFuzzing is a practical, widely-deployed technique to find bugs in complex, real-world programs like JavaScript engines. We observed, however, that existing fuzzing approaches, either generative or mutational, fall short in fully harvesting high-quality input corpora such as known proof of concept (PoC) exploits or unit tests. Existing fuzzers tend to destruct subtle semantics or conditions encoded in the input corpus in order to generate new test cases because this approach helps in discovering new code paths of the program. Nevertheless, for JavaScript-like complex programs, such a conventional design leads to test cases that tackle only shallow parts of the complex codebase and fails to reach deep bugs effectively due to the huge input space.In this paper, we advocate a new technique, called an aspect-preserving mutation, that stochastically preserves the desirable properties, called aspects, that we prefer to be maintained across mutation. We demonstrate the aspect preservation with two mutation strategies, namely, structure and type preservation, in our fully-fledged JavaScript fuzzer, called Die. Our evaluation shows that Die's aspect-preserving mutation is more effective in discovering new bugs (5.7× more unique crashes) and producing valid test cases (2.4× fewer runtime errors) than the state-of-the-art JavaScript fuzzers. Die newly discovered 48 high-impact bugs in ChakraCore, JavaScriptCore, and V8 (38 fixed with 12 CVEs assigned as of today). The source code of Die is publicly available as an open-source project.1 Wen Xu 0002, Insu Yun, Daehee Jang, Taesoo Kim |
SP | 3 |
| 2020 | Automatic Techniques to Systematically Discover New Heap Exploitation Primitives
Insu Yun, Dhaval Kapil, Taesoo Kim |
USENIX Security Symposium | 1 |
| 2018 | REPT: Reverse Debugging of Failures in Deployed Software
Weidong Cui, Xinyang Ge, Baris Kasikci, Ben Niu 0007, Upamanyu Sharma, Ruoyu Wang 0001, Insu Yun |
OSDI | 7 |
| 2018 | QSYM : A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing
Insu Yun, Sangho Lee 0001, Meng Xu 0001, Yeongjin Jang, Taesoo Kim |
USENIX Security Symposium | 1 |
| 2017 | CAB-Fuzz: Practical Concolic Testing Techniques for COTS Operating Systems
Su Yong Kim, Sangho Lee 0001, Insu Yun, Wen Xu 0002, Byoungyoung Lee, Youngtae Yun, Taesoo Kim |
USENIX ATC | 3 |
| 2016 | HDFI: Hardware-Assisted Data-Flow IsolationabstractMemory corruption vulnerabilities are the root cause of many modern attacks. Existing defense mechanisms are inadequate; in general, the software-based approaches are not efficient and the hardware-based approaches are not flexible. In this paper, we present hardware-assisted data-flow isolation, or, HDFI, a new fine-grained data isolation mechanism that is broadly applicable and very efficient. HDFI enforces isolation at the machine word granularity by virtually extending each memory unit with an additional tag that is defined by dataflow. This capability allows HDFI to enforce a variety of security models such as the Biba Integrity Model and the Bell -- LaPadula Model. We implemented HDFI by extending the RISC-V instruction set architecture (ISA) and instantiating it on the Xilinx Zynq ZC706 evaluation board. We ran several benchmarks including the SPEC CINT 2000 benchmark suite. Evaluation results show that the performance overhead caused by our modification to the hardware is low (<; 2%). We also developed or ported several security mechanisms to leverage HDFI, including stack protection, standard library enhancement, virtual function table protection, code pointer protection, kernel data protection, and information leak prevention. Our results show that HDFI is easy to use, imposes low performance overhead, and allows us to create more elegant and more secure solutions. Chengyu Song, Hyungon Moon, Monjur Alam, Insu Yun, Byoungyoung Lee, Taesoo Kim, Wenke Lee, Yunheung Paek |
IEEE Symposium on Security and Privacy | 4 |
| 2016 | APISan: Sanitizing API Usages through Semantic Cross-Checking
Insu Yun, Changwoo Min, Xujie Si, Yeongjin Jang, Taesoo Kim, Mayur Naik |
USENIX Security Symposium | 1 |
| 2012 | Kargus: a highly-scalable software-based intrusion detection systemabstractAs high-speed networks are becoming commonplace, it is increasingly challenging to prevent the attack attempts at the edge of the Internet. While many high-performance intrusion detection systems (IDSes) employ dedicated network processors or special memory to meet the demanding performance requirements, it often increases the cost and limits functional flexibility. In contrast, existing software-based IDS stacks fail to achieve a high throughput despite modern hardware innovations such as multicore CPUs, manycore GPUs, and 10 Gbps network cards that support multiple hardware queues. Muhammad Asim Jamshed, Jihyung Lee, Insu Yun, Deokjin Kim, Sungryoul Lee, Yung Yi, KyoungSoo Park |
CCS | 4 |