VLDB 2026 Research / reviewers in the wild / expert
Changhee Hahn
dblp:147/1524
· DBLP profile ↗
27ranked-venue papers
14as first author
14since 2021 · last 2026
0000-0003-4334-0411ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 7 since 2021Computer networks · 6 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Location-based early detection and prevention of DDoS attacks in mMTC networksabstractThe Random Access (RA) procedure of the current 3GPP cellular network has been adopted for small data packet transmissions by massive Machine Type Communication Devices (MTCDs). However, the initial steps of the RA procedure lack an authentication mechanism, making it susceptible to Distributed Denial of Service (DDoS) attacks, particularly in massive access scenarios. In these cases, attackers can hide among a large number of legitimate stationary devices with limited processing capabilities, such as installed sensors or smart meters. To address this issue, this paper proposes an early DDoS attack detection and prevention method that leverages the Timing Advance (TA) information from stationary MTCDs. The proposed method detects the approximate location of malicious devices sending consecutive preamble codes and blocks them by withholding Resource Blocks (RBs) during the RA procedure. Numerical results from a simulated Physical Random Access Channel (PRACH) for Machine Type Communications (MTC), considering noise and multipath effects, demonstrate the effectiveness of the proposed method in detecting and mitigating DDoS attacks. Under intense attack scenarios, the proposed method effectively identifies network attackers while reducing RA delay and RB consumption for MTCDs by approximately 50% compared to the baseline. This improvement enhances overall network performance and sustainability. Zeinab Rezaeifar, Zahra Alavikia, Changhee Hahn |
Ad Hoc Networks | 3 |
| 2026 | Forgery-Resistant Range Queries via Multi-Client Order-Revealing EncryptionabstractSecure multi-client range-query systems enable multiple parties to search a shared, outsourced database without revealing either the queries or the data. The leading primitives are multi-client order-revealing encryption (m-ORE) and its security-enhanced variant om-ORE, which targets fully malicious clients and server. We show that both schemes remain vulnerable: a colluding malicious clientandserver can launch a practical ciphertext-forgery attack, silently injecting counterfeit records into the encrypted dataset. To close this gap we propose MORES, the first multi-client ORE scheme that preserves range-query functionality while provably resisting arbitrarily malicious participants. In addition to its stronger integrity guarantees, MORES trims query size and comparison cost by roughly one-third relative to both m-ORE and om-ORE, as confirmed by experiments in various bit lengths of plaintext. These gains make MORES an immediate drop-in replacement for encrypted-database systems that demand both efficiency and robustness in adversarial environments. Changhee Hahn |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Decoupled and Privacy-Preserving Key Generation in ABE Under the Minimal Disclosure PrincipleabstractAttribute-Based Encryption (ABE) enables fine-grained access control over outsourced data, but its key generation process typically requires users to disclose their complete attribute sets, introducing significant privacy risks. Existing privacy-preserving approaches—such as those based on zero-knowledge proofs or tightly coupled interactive protocols—suffer from limited scalability, high communication costs, and insufficient support for selective attribute disclosure. To address these limitations, we propose a privacy-enhancing key generation protocol guided by the principle ofMinimal Disclosure, which ensures that users disclose only the minimally necessary subset of attributes required for authorization. Our protocol decouples attribute verification from key issuance: users first obtain cryptographically verifiable attribute tokens, and later issue blinded key requests over selectively chosen attributes. This design enables selective disclosure, supports reusable attribute credentials, and enhances user autonomy. To improve scalability, we introduce a lightweight batch verification mechanism that reduces computation and communication overhead for the attribute authority. We prove that our protocol achieves thebindingandhidingproperties under standard cryptographic assumptions, and we formally verify these guarantees in the symbolic model using the ProVerif tool. In addition, we propose two privacy metrics—AttributeInference Gain (AIG) andPrivacy Gain (PG)—alongside an entropy-based analysis to quantify resistance against attribute inference attacks. Experimental results show that our scheme effectively mitigates inference leakage while offering substantial efficiency gains compared to existing schemes. Youwen Zhu, Xiaodong Yang 0006, Changhee Hahn, Jian Wang 0038, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Dataset ownership verification with invisible backdoors
SeokHee Kim, Changhee Hahn |
Appl. Intell. | 2 |
| 2025 | Towards Secure and Efficient Wildcard Search for Cloud StorageabstractWe delve into the complexities surrounding the delegation of encrypted data to cloud services, which often introduce limitations on search functionalities. To overcome these challenges, the concept of fuzzy searchable encryption has emerged, empowering users to search for data that closely resemble, rather than precisely match, a given query. Notably, wildcard search has emerged as a prominent technique within fuzzy searchable encryption, allowing users to search for words or phrases conforming to specific patterns. However, existing wildcard search schemes require explicit specification of wildcard count and/or positions, thereby potentially introducing security vulnerabilities. Presently, a state-of-the-art security-enhanced wildcard searchable encryption scheme known as SPWSE has alleviated the need for explicit specification of wildcard count and positions in search queries. In this paper, we uncover a novel attack on SPWSE, enabling adversaries not only to discern the underlying keyword but also to determine the count and positions of wildcards utilized in the query. This information leakage stems from cryptographically loose coupling in the trapdoor generation process. To tackle this specific challenge, we propose a novel approach to enhance the security of wildcard searchable encryption. Our proposed scheme integrates additional cryptographic mechanisms to fortify its security posture while concurrently reducing the computational costs associated with data encryption, query generation, and search operations. We evaluate the effectiveness and security of our proposed approach through extensive experimentation, comparing its performance against existing methodologies in the field. Changhee Hahn |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Deep Learning-Based Detection for Multiple Cache Side-Channel AttacksabstractA cache side-channel attack retrieves victim’s sensitive information from a system by exploiting shared cache of CPUs. Since conventional cache side-channel attacks such as FLUSH+RELOAD and PRIME+PROBE are likely to incur numerous cache events, such as cache hits and misses, many previous strategies have focused on monitoring cache events for attack detection. However, as recently proposed attacks such as PRIME+ABORT have exploited the other events as side-channels, it has become challenging to detect them by monitoring only cache events. In this paper, we investigate PRIME+ABORT attack and identifies Intel TSX hardware events are tightly coupled with it as well as cache events. Based on our finding, we propose a novel deep learning-based cache side-channel attack detection method called FRIME. It can concurrently detect not only the conventional attacks such as FLUSH+RELOAD, PRIME+PROBE, but also PRIME+ABORT by leveraging both event types. In order to demonstrate the efficacy of our cache side-channel attack detection scheme in diverse workload conditions in the real world, we implement it using MLP, RNN, and LSTM deep learning models, demonstrating LSTM-based method outperforms the other implementations in terms of detection accuracy. Hodong Kim, Changhee Hahn, Hyunwoo J. Kim, Young-joo Shin, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | VerSA: Verifiable Secure Aggregation for Cross-Device Federated LearningabstractIn privacy-preserving cross-device federated learning, users train a global model on their local data and submit encrypted local models, while an untrusted central server aggregates the encrypted models to obtain an updated global model. Prior work has demonstrated how to verify the correctness of aggregation in such a setting. However, such verification relies on strong assumptions, such as a trusted setup among all users under unreliable network conditions, or it suffers from expensive cryptographic operations, such as bilinear pairing. In this paper, we scrutinize the verification mechanism of prior work and propose a model recovery attack, demonstrating that most local models can be leaked within a reasonable time (e.g.,$98\%$of encrypted local models are recovered within 21 h). Then, we proposeVerSA, a verifiable secure aggregation protocol for cross-device federated learning.VerSAdoes not require any trusted setup for verification between users while minimizing the verification cost by enabling both the central server and users to utilize only a lightweight pseudorandom generator to prove and verify the correctness of model aggregation. We experimentally confirm the efficiency ofVerSAunder diverse datasets, demonstrating thatVerSAis orders of magnitude faster than verification in prior work. Changhee Hahn, Hodong Kim, Minjae Kim 0008, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Certificate Transparency With Enhanced PrivacyabstractDigital certificates play an important role in the authentication of communicating parties for transport layer security. Recently, however, frequent incidents such as the illegal issuance of fake certificates by a compromised certificate authority have raised concerns about the legacy certificate system. Certificate Transparency (CT) mitigates such issues by employing a log server to audit issued certificates publicly, making the certificate issuance and verification processes transparent. Unfortunately, the legacy CT ecosystem suffers from log server compromises and user browsing information leakage. Furthermore, the data structure for the certificate management in the legacy CT system incurs computation overhead linear to the number of registered certificates in the log. In this paper, we propose a secure CT scheme by leveraging a shared value tree (SVT), a novel log structure specifically designed to address the log server compromise and browsing information leakage problems. The verification time of SVT remains constant regardless of the number of registered certificates in the log. We analyze our scheme on the legacy CT system to demonstrate its incremental deployability, guaranteeing a smooth transition toward a more secure web ecosystem. Hyunsoo Kwon, Sangtae Lee, Minjae Kim 0008, Changhee Hahn, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Multi-Key Similar Data Search on Encrypted Storage With Secure Pay-Per-QueryabstractMany commercial cloud service providers (CSPs) adopt pay-per-query pricing models, in which data owners are charged based on the amount of data scanned by each query. In such a data sharing model, not only the privacy preservation for the data and queries but also the trustworthiness of the underlying billing system is of the utmost importance. In this paper, we revisit multi-key searchable encryption (MKSE), an efficient and secure data search algorithm allowing a data owner to grant users the ability to retrieve data of interest over the outsourced, encrypted datasets. We first investigate which factor in existing MKSE schemes renders authorized users over-privileged such that, without risking their credits (e.g., leaking the private keys and/or the passwords for their accounts associated with a project where the shared data resides), they can allow unauthorized users to make valid queries. Unfortunately, this concern may be devastating because the queries made by unauthorized users would incur unexpected financial damage to the owner in practical pay-per-query models. We then propose a novel multi-key data search scheme that is resilient to unauthorized queries. The proposed scheme features a novel user authorization mechanism that carefully limits user privilege such that even an authorized user cannot illegally invite unauthorized users to query unless he entirely leaks his credit. We demonstrate the proposed scheme is comparable to prior work in terms of performance while achieving a higher level of security. Changhee Hahn, Hyundo Yoon, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Delegatable Order-Revealing Encryption for Reliable Cross-Database QueryabstractCloud service providers adopt pay-per-query pricing models to charge data owners based on the amount of data scanned by each query. In such models, the trustworthiness of the underlying billing system is as important as the privacy preservation for the data and queries. In this paper, we revisit delegatable order-revealing encryption (DORE), a range query algorithm allowing authorized users to retrieve data of specific ranges across multiple databases encrypted under different secret keys. We first investigate which factor in the authorization mechanism of DORE can lead to overprivileged users and let them allow any unauthorized user to query over the database of the victim without risking their credits, such as leaking the secret keys. Unfortunately, such unauthorized queries would incur unexpected financial damage to the victim in practical pay-per-query models. We then propose SEDORE, a secure order-revealing encryption scheme with resilience to unauthorized queries across databases. SEDORE features a novel user authorization mechanism limiting user privileges carefully. Consequently, the authorized users cannot illegally invite any unauthorized user to query unless they entirely leak their credits. We demonstrate that the performance of SEDORE is comparable to that of DORE while achieving a higher security level. Changhee Hahn, Junbeom Hur |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Verifiable Outsourced Decryption of Encrypted Data From Heterogeneous Trust NetworksabstractCloud-based Internet of Things (IoT) management services can be utilized to acquire data from devices at any point on Earth. Accordingly, controlling access to data managed by possibly untrusted cloud servers is crucial. Attribute-based encryption (ABE) provides flexible access control and the capability to delegate, facilitating decryption operations with high computationally costs to be outsourced to cloud servers. Earlier studies discussed guarantees to the accuracy of delegated computation through various cryptographic encoding techniques, thus helping data receivers verify the precision of outsourced decryption operations. In this article, we investigate two state-of-the-art schemes addressing verifiable outsourced decryption of encrypted data, and show their vulnerability to our verification bypassing attacks. We then propose a securitywise enhanced encoding scheme that disables such attacks. In addition, a rigorous security analysis is conducted, demonstrating the capabilities of the proposed scheme against bypassing attacks. An experimental analysis finds that the method proposed in this article outperforms the two state-of-the-art works by 82% and 87%, respectively, on the encoding computation cost. Changhee Hahn, Jongkil Kim |
IEEE Internet Things J. | 1 |
| 2022 | Efficient IoT Management With Resilience to Unauthorized Access to Cloud StorageabstractCloud-based Internet of Things (IoT) management services are a promising means of ingesting data from globally dispersed devices. In this setting, it is important to regulate access to data managed by potentially untrusted cloud servers. Attribute-based encryption (ABE) is a highly effective tool for access control. However, applying ABE to IoT environments shows limitations in the following three aspects: First, the demands for storage resources increase in proportion to the complexity of the access control policies. Second, the computation cost of ABE is onerous for resource-limited devices. Lastly, ABE alone is intractable to prevent illegal key-sharing which leads to unauthorized access to data. In this article, we propose an efficient and secure cloud-based IoT data management scheme using ABE. First, we remove the storage-side dependency on the complexity of the access control policies. Second, a substantial part of computationally intensive operations is securely outsourced to the cloud servers. Lastly, unauthorized access to data via illegal key-sharing is strictly forbidden. Our security analysis and experimental results show the security and practicability of the proposed scheme. Changhee Hahn, Jongkil Kim, Hyunsoo Kwon, Junbeom Hur |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractPublic auditing enables efficient integrity checks of data assigned to cloud servers. In this article, we revisit the public auditing for encrypted data, in which a major concern is how to effectively support data dynamics, i.e., data modification, insertion, and deletion. We first determine which factor in existing auditing schemes most limits data dynamics from a cost perspective. We then propose a novel public auditing scheme that provides data dynamics that are orders of magnitude faster than previous methods. Our auditing challenge-response protocol reduces the computation cost of the third-party auditor (TPA) significantly, thus increasing the verification speed for the auditing results. Performance and security analysis demonstrates that the proposed scheme generates minimal computation costs while guaranteeing data integrity and privacy against an untrusted cloud. Changhee Hahn, Hyunsoo Kwon, Daeyeong Kim, Junbeom Hur |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Enabling Fast Public Auditing and Data Dynamics in Cloud ServicesabstractHosting data in the cloud minimizes maintenance requirements, allowing users to easily access their data on cloud servers. However, cloud servers have full control over outsourced data, which raises security concerns about data integrity. The cloud, for example, might have the financial incentive to discard rarely accessed data, freeing up valuable storage space to, say, host other data-centric applications. Therefore, users need to confirm periodically that their data is intact but this has become increasingly onerous due to the ever-growing volume of data being outsourced. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
SERVICES | 1 |
| 2020 | Forward Secure Public Key Encryption with Keyword Search for Cloud-assisted IoTabstractThe Internet of Things (IoT) features a mechanism that extends connectivity to diverse computing devices, such as smart phones, commodity sensors, and appliances. Due to the huge quantity of data generated by the IoT devices, they are likely to be stored and managed by the cloud these days. However, because of the privacy concern about the sensitive data, encryption techniques are typically adopted by the cloud. In order to enable searching over encrypted data for multiple data senders in the cloud, public key encryption with keyword search (PEKS) has been proposed as one variant of searchable encryption (SE). Unfortunately, existing PEKS schemes are vulnerable to adaptive file-injection attack due to the lack of forward privacy. In this paper, we propose a forward secure PEKS scheme based on hierarchical identity-based encryption for cloud-assisted IoT environments. While the existing schemes incur to the data receiver a storage overhead that increases linearly with the number of data senders, our scheme incurs only a constant cost. The experimental analysis with Amazon EC2 and Raspberri Pi shows that our scheme is two to five times more efficient than the previous schemes, which makes our scheme more suitable for multiple data senders in the cloud-assisted IoT environments. Hyeongseob Kim, Changhee Hahn, Junbeom Hur |
CLOUD | 2 |
| 2020 | (In-)Security of Cookies in HTTPS: Cookie Theft by Removing Cookie FlagsabstractHyperText Transfer Protocol (HTTP) cookies are widely used on the web to enhance communication efficiency between a client and a server by storing stateful information. However, cookies may contain private and sensitive information about users. Thus, in order to guarantee the security of cookies, most web browsers and servers support not only Transport Layer Security (TLS) but also other mechanisms such as HTTP Strict Transport Security and cookie flags. However, a recent study has shown that it is possible to circumvent cookie flags in HTTPS by exploiting a vulnerability in HTTP software that allows message truncation. In this paper, we propose a novel cookie hijacking attack called rotten cookie which deactivates cookie flags even if they are protected by TLS by exploiting a weakness in HTTP in terms of integrity checks. According to our investigation, all major browsers ignore uninterpretable sections of the header of HTTP response messages and accept incorrect formats without any rejection. We demonstrate that, when combined with TLS or application vulnerabilities, this form of attack can obtain private cookies by removing cookie flags. Thus, the attacker can impersonate a legitimate user in the eyes of the server when cookies are used as an authentication token. We prove the practicality of our attack by demonstrating that our attack can lead five major web browsers to accept a cookie without any cookie flags. We thus present a mitigation strategy for the transport layer to preserve cookie security against our attack. Hyunsoo Kwon, Hyunjae Nam, Sangtae Lee, Changhee Hahn, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Trustworthy Delegation Toward Securing Mobile Healthcare Cyber-Physical SystemsabstractAttribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE Internet Things J. | 1 |
| 2019 | Secure deduplication with reliable and revocable key management in fog computing
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
Peer-to-Peer Netw. Appl. | 2 |
| 2018 | Toward Trustworthy Delegation: Verifiable Outsourced Decryption with Tamper-Resistance in Public Cloud StorageabstractFor building a secure cloud storage service on top of a public cloud infrastructure, attribute-based encryption (ABE) has been a preferred solution due to its flexible access control. ABE, however, incurs heavy computation cost on users during decryption. Thus, previous studies solved this problem by enabling cloud servers to perform a part of decryption operations on behalf of the users. In order to empower users to verify the correctness of the delegated decryption by the cloud, they employed a cryptographic commitment or message authentication code (MAC) to enable users to check the correctness of partial decryption of the cloud. However, the previous schemes fail to ensure the correctness of computation in the presence of malicious cloud servers. In this paper, we propose a novel and generic commitment scheme for ABE, which is secure against tampering attacks by malicious cloud servers. According to the performance analysis, the proposed scheme is only 0.5 ms slower on average than the previous commitment-based schemes and two to three times faster than the MAC-based scheme. Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
IEEE CLOUD | 1 |
| 2017 | Scalable and Reliable Key Management for Secure Deduplication in Cloud StorageabstractSecure deduplication using convergent encryption eliminates duplicate data and stores only one copy to save storage costs while preserving the security of the outsourced data. However, convergent encryption produces a number of encryption keys, of which size is linear to the number of different data. Although a deduplication scheme has been proposed for efficient convergent key management recently, it has drawbacks in terms of scalability and key management security. In order to solve these problems, we propose a novel secure deduplication scheme with scalable and reliable key management based on paring-based cryptography. The proposed scheme does not require additional secure channels to distribute key components while still guaranteeing secure key management as opposed to the previous schemes. Hyunsoo Kwon, Changhee Hahn, Dongyoung Koo, Junbeom Hur |
CLOUD | 2 |
| 2017 | Secure deduplication for multimedia data with user revocation in cloud storage
Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 2 |
| 2017 | Secure authentication using ciphertext policy attribute-based encryption in mobile multi-hop networks
Hyunsoo Kwon, Daeyeong Kim, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 3 |
| 2016 | POSTER: Towards Privacy-Preserving Biometric Identification in Cloud ComputingabstractWang et al. recently proposed a privacy-preserving biometric identification scheme. However, the security assumption of the scheme does not capture practical aspects of real world attacks. In this paper, we consider a practical attack model which results in the leakage of biometric data in Wang et al.'s scheme. We first show the feasibility of our attack model and demonstrate how an attacker is able to recover the biometric data. Then, we propose a new biometric identification scheme that is secure against the attack model. Changhee Hahn, Junbeom Hur |
CCS | 1 |
| 2016 | Enhanced authentication for outsourced educational contents through provable block possession
Changhee Hahn, Hyunsoo Kwon, Junbeom Hur |
Multim. Tools Appl. | 1 |
| 2016 | Privacy-preserving public auditing for educational multimedia data in cloud computing
Daeyeong Kim, Hyunsoo Kwon, Changhee Hahn, Junbeom Hur |
Multim. Tools Appl. | 3 |
| 2014 | A Privacy Threat in 4th Generation Mobile Telephony and Its Countermeasure
Changhee Hahn, Hyunsoo Kwon, Kyungtae Kang, Junbeom Hur |
WASA | 1 |
| 2014 | Secure Device-to-Device Authentication in Mobile Multi-hop Networks
Hyunsoo Kwon, Changhee Hahn, Kyungtae Kang, Junbeom Hur |
WASA | 2 |