VLDB 2026 Research / reviewers in the wild / expert
Jongkil Kim
dblp:140/2998
· DBLP profile ↗
20ranked-venue papers
9as first author
9since 2021 · last 2026
0000-0001-5755-108XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 8 first-author · 4 since 2021Computer networks · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 5G-AKA-HPQC: Hybrid Postquantum Cryptography Protocol for Quantum-Resilient 5G Primary Authentication With Forward Secrecyabstract5G serves as a catalyst for transformative digital innovation by enabling convergence with various services in our daily lives. The success of this paradigm shift undeniably hinges on robust security measures, with primary authentication— securing access to the 5G network—being paramount. Two protocols, 5G Authentication and Key Agreement (5G-AKA) and the Extensible Authentication Protocol for Authentication and Key Agreement Prime (EAP-AKA’), have been standardized for this purpose, with the former designed for 3rd Generation Partnership Project (3GPP) devices and the latter for non-3GPP devices. However, recent studies have exposed vulnerabilities in the 5G-AKA protocol, rendering it susceptible to security breaches, including linkability attacks. Furthermore, the advent of quantum computing poses significant quantum threats, underscoring the urgent need for the adoption of quantum-resistant cryptographic mechanisms. Although post-quantum cryptography (PQC) is being standardized, the lack of real-world deployment limits its proven robustness. In contrast, conventional cryptographic schemes have demonstrated reliability over decades of practical application. To address this gap, the Internet Engineering Task Force (IETF) has initiated the standardization of hybrid PQC algorithms (HPQC), combining classical and quantum-resistant techniques. Consequently, ensuring forward secrecy and resilience to quantum threats in the 5G-AKA protocol is critical. To address these security challenges, we propose the 5G-AKA-HPQC protocol. Our protocol is designed to maintain compatibility with existing standards while enhancing security by combining keys negotiated via the Elliptic Curve Integrated Encryption Scheme (ECIES) with those derived from a PQC-Key Encapsulation Mechanism (KEM). To rigorously and comprehensively validate the security of 5G-AKA-HPQC, we employ formal verification tools such as SVO Logic and ProVerif. The results confirm the protocol’s security and correctness. Furthermore, performance evaluations highlight the computational and communication overheads inherent to 5G-AKA-HPQC. With only average of 56.5 millisecond(+112.32%) on a total authentication time, proposed protocol provides its advantages. Also, on a environment of multiple UE registration, compared to single UE registration, the difference of increased rate of average authentication time is only 0.01%. The negligible difference 0.01% indicates that the addition of PQC does not lead to increased overhead in multi-UE registration environments, demonstrating its scalability and practical feasibility. In conclusion, our research provides significant insights into the design of secure, quantum-safe authentication protocols and lays the groundwork for the future standardization of secure authentication and key agreement protocols for mobile telecommunications. Yongho Ko, I Wayan Adi Juliawan Pawana, Hoseok Kwon, SeongHan Shin, Jongkil Kim, Joonsang Baek, Ilsun You |
IEEE Internet Things J. | 5 |
| 2024 | IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and WatermarkingabstractTraining Deep Neural Networks (DNNs) can be expensive when data is difficult to obtain or labeling them requires significant domain expertise. Hence, it is crucial that the Intellectual Property (IP) of DNNs trained on valuable data be protected against IP infringement. DNN fingerprinting and watermarking are two lines of work in DNN IP protection. Recently proposed DNN fingerprinting techniques are able to detect IP infringement while preserving model performance by relying on the key assumption that the decision boundaries of independently trained models are intrinsically different from one another. In contrast, DNN watermarking embeds a watermark in a model and verifies IP infringement if an identical or similar watermark is extracted from a suspect model. The techniques deployed in fingerprinting and watermarking vary significantly because their underlying mechanisms are different. From an adversary's perspective, a successful IP removal attack should defeat both fingerprinting and watermarking. However, to the best of our knowledge, there is no work on such attacks in the literature yet. In this paper, we fill this gap by presenting an IP removal attack that can defeat both fingerprinting and watermarking. We consider the challenging data-free scenario whereby all data is inverted from the victim model. Under this setting, a stolen model only depends on the victim model. Experimental results demonstrate the success of our attack in defeating state-of-the-art DNN fingerprinting and watermarking techniques. This work reveals a novel attack surface that exploits generative model inversion attacks to bypass DNN IP defenses. This threat must be addressed by future defenses for reliable IP protection. Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Jongkil Kim, Seyit Ahmet Çamtepe |
AAAI | 5 |
| 2023 | PCSF: Privacy-Preserving Content-Based Spam FilterabstractThe purpose of privacy-preserving spam filtering is to inspect email while preserving the privacy of its detection rules and the email content. Although many solutions have emerged, they suffer from the following: 1) Theprivacyprovided is insufficient as the email content or detection rules may be exposed to third parties; 2) Due to improper use of encryption, exhaustive word search attacks are possible, potentially breaking theconfidentialityof encrypted emails; 3) When spam filtering is outsourced, email is given to the outsource, whereuser privacy may be compromisedif privacy protection measures are not properly put in place; 4) Confirmation of whether the encrypted email is spam is only determinedafterthe receiver receives the email, which can lead to a situation in which spam is loaded to the memory of the receiver’s terminal for spam filtering. This can be harmful, for example, when an attacker inserts a web browser vulnerability into the body of an email to lure users to a phishing site simply by reading the email; 5)Computationally expensive operationsare unavoidable to provide required features of privacy-preserving spam filtering. We present Privacy-preserving Content-based Spam Filter (PCSF), which is a spam filter system that does not suffer from the aforementioned issues. Additionally, our system providespre-validationbefore the receiver reads the email. We provide an implementation of our system based on the Naive Bayes spam filter and prove its security. Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim, Yang-Wai Chow |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Verifiable Outsourced Decryption of Encrypted Data From Heterogeneous Trust NetworksabstractCloud-based Internet of Things (IoT) management services can be utilized to acquire data from devices at any point on Earth. Accordingly, controlling access to data managed by possibly untrusted cloud servers is crucial. Attribute-based encryption (ABE) provides flexible access control and the capability to delegate, facilitating decryption operations with high computationally costs to be outsourced to cloud servers. Earlier studies discussed guarantees to the accuracy of delegated computation through various cryptographic encoding techniques, thus helping data receivers verify the precision of outsourced decryption operations. In this article, we investigate two state-of-the-art schemes addressing verifiable outsourced decryption of encrypted data, and show their vulnerability to our verification bypassing attacks. We then propose a securitywise enhanced encoding scheme that disables such attacks. In addition, a rigorous security analysis is conducted, demonstrating the capabilities of the proposed scheme against bypassing attacks. An experimental analysis finds that the method proposed in this article outperforms the two state-of-the-art works by 82% and 87%, respectively, on the encoding computation cost. Changhee Hahn, Jongkil Kim |
IEEE Internet Things J. | 2 |
| 2022 | Efficient IoT Management With Resilience to Unauthorized Access to Cloud StorageabstractCloud-based Internet of Things (IoT) management services are a promising means of ingesting data from globally dispersed devices. In this setting, it is important to regulate access to data managed by potentially untrusted cloud servers. Attribute-based encryption (ABE) is a highly effective tool for access control. However, applying ABE to IoT environments shows limitations in the following three aspects: First, the demands for storage resources increase in proportion to the complexity of the access control policies. Second, the computation cost of ABE is onerous for resource-limited devices. Lastly, ABE alone is intractable to prevent illegal key-sharing which leads to unauthorized access to data. In this article, we propose an efficient and secure cloud-based IoT data management scheme using ABE. First, we remove the storage-side dependency on the complexity of the access control policies. Second, a substantial part of computationally intensive operations is securely outsourced to the cloud servers. Lastly, unauthorized access to data via illegal key-sharing is strictly forbidden. Our security analysis and experimental results show the security and practicability of the proposed scheme. Changhee Hahn, Jongkil Kim, Hyunsoo Kwon, Junbeom Hur |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | Harnessing Policy Authenticity for Hidden Ciphertext Policy Attribute-Based EncryptionabstractThe field of cryptography has endeavored to solve numerous security problems. However, a common premise of many of those problems is that the encryptor always generates the ciphertext correctly. Around 10 years ago, this premise was not a problem. However, due to the rapid development and the use of the cloud, which has introduced various access policies and functionalities to provide higher security, it is not correct to assume that this premise is always applied. A “Fake Policy Attack”, which we introduce in this article, is an attack that incorrectly sets the access policy of the ciphertext against the system rules so that users who do not meet the rules can decrypt the ciphertext. In other words, it is an attack that ignores the rules of the system and eventually breaks the security and leaks information. This attack can be more critical for the application environments that require strong security not to leak any related information about ciphertext. In this article, we demonstrate the possible threat of the Fake Policy Attack by providing two relevant examples. Then, we propose a scheme called Policy Authenticable ABE (PA-ABE) to resolve this issue. We provide a formal security analysis of the proposed scheme and performance evaluation results based on our implementation. Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | P2DPI: Practical and Privacy-Preserving Deep Packet InspectionabstractThe amount of encrypted Internet traffic almost doubles every year thanks to the wide adoption of end-to-end traffic encryption solutions such as IPSec, TLS and SSH. Despite all the benefits of user privacy the end-to-end encryption provides, the encrypted internet traffic blinds intrusion detection system (IDS) and makes detecting malicious traffic hugely difficult. The resulting conflict between the user's privacy and security has demanded solutions for deep packet inspection (DPI) over encrypted traffic. The approach of those solutions proposed to date is still restricted in that they require intensive computations during connection setup or detection. For example, BlindBox, introduced by Sherry et al. (SIGCOMM 2015) enables inspection over the TLS-encrypted traffic without compromising users' privacy, but its usage is limited due to a significant delay on establishing an inspected channel. PrivDPI, proposed more recently by Ning et al. (ACM CCS 2019), improves the overall efficiency of BlindBox and makes the inspection scenario more viable. Despite the improvement, we show in this paper that the user privacy of Ning et al.'s PrivDPI can be compromised entirely by the rule generator without involving any other parties, including the middlebox. Having observed the difficulties of realizing efficiency and security in the previous work, we propose a new DPI system for encrypted traffic, named "Practical and Privacy-Preserving Deep Packet Inspection (P2DPI)''. P2DPI enjoys the same level of security and privacy that BlindBox provides. At the same time, P2DPI offers fast setup and encryption and outperforms PrivDPI. Our results are supported by formal security analysis. We implemented our P2DPI and comparable PrivDPI and performed extensive experimentation for performance analysis and comparison. Jongkil Kim, Seyit Ahmet Çamtepe, Joonsang Baek, Willy Susilo, Josef Pieprzyk, Surya Nepal |
AsiaCCS | 1 |
| 2021 | SyLPEnIoT: Symmetric Lightweight Predicate Encryption for Data Privacy Applications in IoT Environments
Tran Viet Xuan Phuong, Willy Susilo, Guomin Yang, Jongkil Kim, Yang-Wai Chow, Dongxi Liu |
ESORICS (2) | 4 |
| 2021 | Utilizing QR codes to verify the visual fidelity of image datasets for machine learning
Yang-Wai Chow, Willy Susilo, Jianfeng Wang 0001, Richard Buckland, Joonsang Baek, Jongkil Kim, Nan Li 0007 |
J. Netw. Comput. Appl. | 6 |
| 2020 | Efficient Anonymous Multi-group Broadcast Encryption
Intae Kim, Seong Oun Hwang, Willy Susilo, Joonsang Baek, Jongkil Kim |
ACNS (1) | 5 |
| 2020 | Inspecting TLS Anytime Anywhere: A New Approach to TLS InterceptionabstractTransport Layer Security (TLS) is one of the most widely-used security protocols for the modern internet. However, TLS does not differentiate regular users from threat actors who want to evade detection through the privacy provided by TLS. For this reason, organizations have been increasingly interested in middlebox technology whereby encrypted TLS traffic can be filtered and inspected. Joonsang Baek, Jongkil Kim, Willy Susilo |
AsiaCCS | 2 |
| 2019 | Ciphertext-Delegatable CP-ABE for a Dynamic Credential: A Modular Approach
Jongkil Kim, Willy Susilo, Joonsang Baek, Surya Nepal, Dongxi Liu |
ACISP | 1 |
| 2019 | A New Encoding Framework for Predicate Encryption with Non-linear Structures in Prime Order Groups
Jongkil Kim, Willy Susilo, Fuchun Guo, Joonsang Baek, Nan Li 0007 |
ACNS | 1 |
| 2019 | Identity-Based Broadcast Encryption with Outsourced Partial Decryption for Hybrid Security Models in Edge ComputingabstractEach layer of nodes and communication networks in edge computing, from cloud to the end device (i.e, often considered as resource-constrained IoT devices), exhibits a different level of trust for each stakeholder - e.g., edge nodes may not be fully trusted by IoT devices and the cloud. Moreover, asymmetric nature of resources between layers makes it hard to establish a balance between security and performance - e.g., lightweight cryptography may degrade security level against untrusted nodes while heavyweight ones may not be feasible for the light-weight end devices. An advanced encryption scheme such as the Identity-Based Broadcast Encryption (IBBE) is a popular technique to reduce storage and communication overhead. However, IBBE requires heavy computation to the end devices and still does not fully satisfy the security requirements that exist in the layers of edge computing. This paper presents a new IBBE with outsourced partial decryption for hybrid security models that each layer in edge computing requires. It balances the computational overhead based on asymmetric nature that nodes in each layer have. Particularly, with new schemes, the ciphertext can be transformed from its initial format. The cloud encrypts their data for multiple end devices and store them in the edge nodes, but those interim nodes can blindly transform the ciphertext from the cloud into a form which (i) is decryptable by only an authorized end device, and (ii) imposes smaller decryption and data transmission burden to end devices, regardless of the number of recipients. Our security analysis shows that new schemes are selectively and adaptively secure. We implement our solution and show that new schemes reduce the communication overhead from an edge node to end devices and the computation overhead on the end devices, compared to the original IBBE schemes. Jongkil Kim, Seyit Ahmet Çamtepe, Willy Susilo, Surya Nepal, Joonsang Baek |
AsiaCCS | 1 |
| 2019 | Puncturable Proxy Re-Encryption Supporting to Group Messaging Service
Tran Viet Xuan Phuong, Willy Susilo, Jongkil Kim, Guomin Yang, Dongxi Liu |
ESORICS (1) | 3 |
| 2018 | Functional encryption for computational hiding in prime order groups via pair encodings
Jongkil Kim, Willy Susilo, Fuchun Guo, Man Ho Au |
Des. Codes Cryptogr. | 1 |
| 2017 | An Efficient KP-ABE with Short Ciphertexts in Prime OrderGroups under Standard AssumptionabstractWe introduce an efficient Key-Policy Attribute-Based Encryption (KP-ABE) scheme in prime order groups. Our scheme is semi-adaptively secure under the decisional linear assumption and supports a large universe of attributes and multi-use of attributes. Those properties are critical for real applications of KP-ABE schemes since they enable an efficient and flexible access control. Prior to our work, existing KP-ABE schemes with short ciphertexts were in composite order groups or utilized either Dual Pairing Vector Spaces (DPVS) or Dual System Groups (DSG) in prime order groups. However, those techniques brought an efficiency loss. In this work, we utilize a nested dual system encryption which is a variant of Waters' dual system encryption (Crypto' 09) to achieve semi-adaptively secure KP-ABE. As a result, we obtain a new scheme having better efficiency compared to existing schemes while it keeps a semi-adaptive security under the standard assumption. We implement our scheme and compare its efficiency with the previous best work. Jongkil Kim, Willy Susilo, Fuchun Guo, Man Ho Au, Surya Nepal |
AsiaCCS | 1 |
| 2016 | A Cryptographically Enforced Access Control with a Flexible User Revocation on Untrusted Cloud StorageabstractCloud storage services have become ubiquitous. A large number of individuals and organizations are using them to store and share data, taking the benefits of mobility and affordability offered by these services. However, secure management of data in cloud storage services, more specifically supporting multi-party sharing in the context of a collaboration, is a challenging problem. The problem is further exacerbated if the data owner does not have any trust on the cloud storage providers and the data need regular updates from collaborating parties. A number of cryptographically enforced secure cloud storage solutions have been proposed to address this problem. One of the key issues with these solutions is the revocation of access to data for invalid users without moving the data (in the era of big data) and relying on the cloud service providers. In this paper, we introduce a cloud storage system that offers cryptographically enforced security. In contrast to other cryptographically protected cloud storage systems, our system supports a fine-grained access control mechanism and allows flexible revocations of invalid users without moving the data and relying on the cloud service providers. Our system employs an attribute-based encryption technique to support a complex access structure that allows a user to define human readable access policies to the data in the cloud storage. In addition, our system supports a flexible revocation scheme that can revoke invalid users directly by updating the revoked users’ list or indirectly by updating an epoch counter. The system administrator can choose one of these options flexibly depending on the needs. Our system also allows authorized users to update the encrypted data, and any users accessing such updated data in future can verify whether the data are modified by authorized users. Jongkil Kim, Surya Nepal |
Data Sci. Eng. | 1 |
| 2015 | Adaptively Secure Identity-Based Broadcast Encryption With a Constant-Sized CiphertextabstractIn this paper, we present an adaptively secure identity-based broadcast encryption system featuring constant sized ciphertext in the standard model. The size of the public key and the private keys of our system are both linear in the maximum number of receivers. In addition, our system is fully collusion-resistant and has stateless receivers. Compared with the state-of-the-art, our scheme is well optimized for the broadcast encryption. The computational complexity of decryption of our scheme depends only on the number of receivers, not the maximum number of receivers of the system. Technically, we employ dual system encryption technique and our proposal offers adaptive security under the general subgroup decisional assumption. Our scheme demonstrates that the adaptive security of the schemes utilizing a composite order group can be proven under the general subgroup decisional assumption, while many existing systems working in a composite order group are secure under multiple subgroup decision assumptions. We note that this finding is of an independent interest, which may be useful in other scenarios. Jongkil Kim, Willy Susilo, Man Ho Au, Jennifer Seberry |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Efficient Semi-static Secure Broadcast Encryption Scheme
Jongkil Kim, Willy Susilo, Man Ho Au, Jennifer Seberry |
Pairing | 1 |