Yeonjoon Lee

dblp:153/5787 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-5010-8277ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 3 first-author · 4 since 2021Computer networks · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 PROMPRINT: Prompt Fingerprinting via First-Token Response for LLM App Cloning Detection
abstract
As Large Language Model applications (LLM apps) become widespread, system prompts that determine app behavior are increasingly regarded as intellectual property, raising concerns about leakage.Recent studies show that this threat is no longer theoretical, revealing the prevalence of cloned apps replicating system prompts from others on real-world platforms.These clones pose risks of copyright infringement and malicious misuse, highlighting the need for early and reliable detection.In this paper, we propose PROMPRINT, a novel fingerprinting approach for detecting cloned LLM apps without exposing their system prompts.Motivated by the observation that different system prompts yield distinct first output token distributions for the same query, PROMPRINT optimizes queries that induce the LLM to generate a specific first output token associated with the given system prompt, resulting in distinctive query-first-token pairs.Experiments on four instruction-tuned LLMs show that generated pairs effectively identify the corresponding system prompts, achieving over 74% probability of generating the target token while remaining below 2.2% on average under other prompts.Furthermore, we demonstrate that our fingerprinting remains robust to partial system prompt modifications and effective under the injection of adversarial instructions.
Peizhuo Lv, Yeonjoon Lee
ACL (1)3
2025 Enhanced DGA botnet domain detection and family classification via n-gram analysis and Hellinger distance
Sungju Yun, Nahyun Kim, Yeonjoon Lee
Comput. Networks4
2024 Ensuring Integrity in Online Content Usage and Download Counting with Smart Contracts
Shubham Joshi, Dillon Davidson, Yeonjoon Lee, Homook Cho, Junggab Son
SecureComm (3)3
2024 DARKFLEECE: Probing the Dark Side of Android Subscription Apps
Chang Yue, Chen Zhong 0008, Kai Chen 0012, Zhiyu Zhang 0017, Yeonjoon Lee
USENIX Security Symposium5
2024 Station: Gesture-Based Authentication for Voice Interfaces
abstract
The popularity of smart home devices has led to an increase in security incidents happening in smart homes. A key measure to avoid such incidents is to authenticate users before they can interact with smart devices. However, current methods often require additional hardware. This paper proposes, a gesture-based authentication system, an effective gesture-based authentication method built on top of the voice interfaces already available in these smart home devices, without adding new hardware. uses a gesture processing pipeline that identifies Doppler-existing frames and detects the Direction of Arrival of Reflection to authenticate users in low SNR environments and at longer distances. Furthermore, regarding the nature of gesture-based authentication, this system also supports detecting user liveness, preventing replay and synthesis attacks from remote attackers. The evaluation of shows high accuracy with a False Accept Rate (FAR) of 0.08% and False Reject Rate (FRR) of 3.10% for users within 1.5m of the device.
Sungbin Park, Xueqiang Wang, Kai Chen 0012, Yeonjoon Lee
IEEE Internet Things J.4
2024 Exclusively in-store: Acoustic location authentication for stationary business devices
Sungbin Park, Chang-Bae Seo, Xueqiang Wang, Yeonjoon Lee, Seung-Hyun Seo
J. Netw. Comput. Appl.4
2023 Aliasing Backdoor Attacks on Pre-trained Models
Cheng'an Wei, Yeonjoon Lee, Kai Chen 0012, Guozhu Meng, Peizhuo Lv
USENIX Security Symposium2
2021 Understanding Illicit UI in iOS Apps Through Hidden UI Analysis
abstract
In Chameleon apps, benign UIs are displayed during Apple App vetting while their hidden potentially-harmful illicit UIs (PHI-UI) are revealed once they reached App Store. In this article, we report the first systematic study on iOS Chameleon apps, which sheds light on a largely overlooked threat that the illicit activities are launched solely based on UI. Our research employed Chameleon-Hunter, a new static analysis approach that determines the suspiciousness of a PHI-UI leveraging the semantic features generated from iOS app UI and metadata. The approach is based on the observation that PHI-UI not only is structurally hidden but also has notable semantic inconsistency with the benign UI. Our evaluation shows that Chameleon-Hunter is highly effective, achieving 92.6 percent precision and 94.7 percent recall. From 28K Apple App Store apps, we found 142 new Chameleon apps, which were confirmed and promptly removed by Apple. Our work reveals that Chameleon apps can easily bypass the App store vetting and conduct a set of suspicious activities including collecting users' private information, swindling money with fake monetary services, and leading the user to a pirated app store.
Yeonjoon Lee, Xueqiang Wang, Xiaojing Liao, XiaoFeng Wang 0001
IEEE Trans. Dependable Secur. Comput.1
2019 Understanding iOS-based Crowdturfing Through Hidden UI Analysis
Yeonjoon Lee, Xueqiang Wang, Kwangwuk Lee, Xiaojing Liao, XiaoFeng Wang 0001, Tongxin Li 0002, Xianghang Mi
USENIX Security Symposium1
2017 Mass Discovery of Android Traffic Imprints through Instantiated Partial Execution
abstract
Monitoring network behaviors of mobile applications, controlling their resource access and detecting potentially harmful apps are becoming increasingly important for the security protection within today's organizational, ISP and carriers. For this purpose, apps need to be identified from their communication, based upon their individual traffic signatures (called imprints in our research). Creating imprints for a large number of apps is nontrivial, due to the challenges in comprehensively analyzing their network activities at a large scale, for millions of apps on today's rapidly-growing app marketplaces. Prior research relies on automatic exploration of an app's user interfaces (UIs) to trigger its network activities, which is less likely to scale given the cost of the operation (at least 5 minutes per app) and its effectiveness (limited coverage of an app's behaviors).
Yi Chen 0024, Wei You 0001, Yeonjoon Lee, Kai Chen 0012, XiaoFeng Wang 0001
CCS3
2017 Ghost Installer in the Shadow: Security Analysis of App Installation on Android
abstract
Android allows developers to build apps with app installation functionality themselves with minimal restriction and support like any other functionalities. Given the critical importance of app installation, the security implications of the approach can be significant. This paper reports the first systematic study on this issue, focusing on the security guarantees of different steps of the App Installation Transaction (AIT). We demonstrate the serious consequences of leaving AIT development to individual developers: most installers (e.g., Amazon AppStore, DTIgnite, Baidu) are riddled with various security-critical loopholes, which can be exploited by attackers to silently install any apps, acquiring dangerous-level permissions or even unauthorized access to system resources. Surprisingly, vulnerabilities were found in all steps of AIT. The attacks we present, dubbed Ghost Installer Attack (GIA), are found to pose a realistic threat to Android ecosystem. Further, we developed both a user-app-level and a system-level defense that are innovative and practical.
Yeonjoon Lee, Tongxin Li 0002, Nan Zhang 0018, Soteris Demetriou, Mingming Zha 0001, XiaoFeng Wang 0001, Kai Chen 0012, Xiao-yong Zhou, Xinhui Han, Michael Grace
DSN1
2017 HanGuard: SDN-driven protection of smart home WiFi devices from malicious mobile apps
abstract
A new development of smart-home systems is to use mobile apps to control IoT devices across a Home Area Network (HAN). As verified in our study, those systems tend to rely on the Wi-Fi router to authenticate other devices. This treatment exposes them to the attack from malicious apps, particularly those running on authorized phones, which the router does not have information to control. Mitigating this threat cannot solely rely on IoT manufacturers, which may need to change the hardware on the devices to support encryption, increasing the cost of the device, or software developers who we need to trust to implement security correctly. In this work, we present a new technique to control the communication between the IoT devices and their apps in a unified, backward-compatible way. Our approach, called HanGuard, does not require any changes to the IoT devices themselves, the IoT apps or the OS of the participating phones. HanGuard uses an SDN-like approach to offer fine-grained protection: each phone runs a non-system userspace Monitor app to identify the party that attempts to access the protected IoT device and inform the router through a control plane of its access decision; the router enforces the decision on the data plane after verifying whether the phone should be allowed to talk to the device. We implemented our design over both Android and iOS (> 95% of mobile OS market share) and a popular router. Our study shows that HanGuard is both efficient and effective in practice.
Soteris Demetriou, Nan Zhang 0018, Yeonjoon Lee, XiaoFeng Wang 0001, Carl A. Gunter, Xiao-yong Zhou, Michael Grace
WISEC3
2016 Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOS
abstract
It is reported recently that legitimate libraries are repackaged for propagating malware. An in-depth analysis of such potentially-harmful libraries (PhaLibs), however, has never been done before, due to the challenges in identifying those libraries whose code can be unavailable online (e.g., removed from the public repositories, spreading underground, etc.). Particularly, for an iOS app, the library it integrates cannot be trivially recovered from its binary code and cannot be analyzed by any publicly available anti-virus (AV) systems. In this paper, we report the first systematic study on PhaLibs across Android and iOS, based upon a key observation that many iOS libraries have Android versions that can potentially be used to understand their behaviors and the relations between the libraries on both sides. To this end, we utilize a methodology that first clusters similar packages from a large number of popular Android apps to identify libraries, and strategically analyze them using AV systems to find PhaLibs. Those libraries are then used to search for their iOS counterparts within Apple apps based upon the invariant features shared cross platforms. On each discovered iOS PhaLib, our approach further identifies its suspicious behaviors that also appear on its Android version and uses the AV system on the Android side to confirm that it is indeed potentially harmful. Running our methodology on 1.3 million Android apps and 140,000 popular iOS apps downloaded from 8 markets, we discovered 117 PhaLibs with 1008 variations on Android and 23 PhaLibs with 706 variations on iOS. Altogether, the Android PhaLibs is found to infect 6.84% of Google Play apps and the iOS libraries are embedded within thousands of iOS apps, 2.94% among those from the official Apple App Store. Looking into the behaviors of the PhaLibs, not only do we discover the recently reported suspicious iOS libraries such as mobiSage, but also their Android counterparts and 6 other back-door libraries never known before. Those libraries are found to contain risky behaviors such as reading from their host apps' keychain, stealthily recording audio and video and even attempting to make phone calls. Our research shows that most Android-side harmful behaviors have been preserved on their corresponding iOS libraries, and further identifies new evidence about libraries repackaging for harmful code propagations on both sides.
Kai Chen 0012, Xueqiang Wang, Yi Chen 0024, Peng Wang 0088, Yeonjoon Lee, XiaoFeng Wang 0001, Bin Ma 0019, Aohui Wang
IEEE Symposium on Security and Privacy5
2015 What's in Your Dongle and Bank Account? Mandatory and Discretionary Protection of Android External Resources
Soteris Demetriou, Xiao-yong Zhou, Muhammad Naveed 0001, Yeonjoon Lee, Kan Yuan, XiaoFeng Wang 0001, Carl A. Gunter
NDSS4
2015 Finding Unknown Malice in 10 Seconds: Mass Vetting for New Threats at the Google-Play Scale
Kai Chen 0012, Peng Wang 0088, Yeonjoon Lee, XiaoFeng Wang 0001, Nan Zhang 0018, Heqing Huang 0001, Peng Liu 0005
USENIX Security Symposium3
2014 Mayhem in the Push Clouds: Understanding and Mitigating Security Hazards in Mobile Push-Messaging Services
abstract
Push messaging is among the most important mobile-cloud services, offering critical supports to a wide spectrum of mobile apps. This service needs to coordinate complicated interactions between developer servers and their apps in a large scale, making it error prone. With its importance, little has been done, however, to understand the security risks of the service. In this paper, we report the first security analysis on those push-messaging services, which reveals the pervasiveness of subtle yet significant security flaws in them, affecting billions of mobile users. Through even the most reputable services like Google Cloud Messaging (GCM) and Amazon Device Messaging (ADM), the adversary running carefully-crafted exploits can steal sensitive messages from a target device, stealthily install or uninstall any apps on it, remotely lock out its legitimate user or even completely wipe out her data. This is made possible by the vulnerabilities in those services' protection of device-to-cloud interactions and the communication between their clients and subscriber apps on the same devices. Our study further brings to light questionable practices in those services, including weak cloud-side access control and extensive use of PendingIntent, as well as the impacts of the problems, which cause popular apps or system services like Android Device Manager, Facebook, Google+, Skype, PayPal etc. to leak out sensitive user data or unwittingly act on the adversary's command. To mitigate this threat, we developed a technique that helps the app developers establish end-to-end protection of the communication with their apps, over the vulnerable messaging services they use.
Tongxin Li 0002, Xiao-yong Zhou, Luyi Xing, Yeonjoon Lee, Muhammad Naveed 0001, XiaoFeng Wang 0001, Xinhui Han
CCS4
2014 The Peril of Fragmentation: Security Hazards in Android Device Driver Customizations
abstract
Android phone manufacturers are under the perpetual pressure to move quickly on their new models, continuously customizing Android to fit their hardware. However, the security implications of this practice are less known, particularly when it comes to the changes made to Android's Linux device drivers, e.g., those for camera, GPS, NFC etc. In this paper, we report the first study aimed at a better understanding of the security risks in this customization process. Our study is based on ADDICTED, a new tool we built for automatically detecting some types of flaws in customized driver protection. Specifically, on a customized phone, ADDICTED performs dynamic analysis to correlate the operations on a security-sensitive device to its related Linux files, and then determines whether those files are under-protected on the Linux layer by comparing them with their counterparts on an official Android OS. In this way, we can detect a set of likely security flaws on the phone. Using the tool, we analyzed three popular phones from Samsung, identified their likely flaws and built end-to-end attacks that allow an unprivileged app to take pictures and screenshots, and even log the keys the user enters through touch screen. Some of those flaws are found to exist on over a hundred phone models and affect millions of users. We reported the flaws and helped the manufacturers fix those problems. We further studied the security settings of device files on 2423 factory images from major phone manufacturers, discovered over 1,000 vulnerable images and also gained insights about how they are distributed across different Android versions, carriers and countries.
Xiao-yong Zhou, Yeonjoon Lee, Nan Zhang 0018, Muhammad Naveed 0001, XiaoFeng Wang 0001
IEEE Symposium on Security and Privacy2