Minjae Kim 0008

dblp:16/418-8 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2023
0000-0001-5392-9110ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2023 VerSA: Verifiable Secure Aggregation for Cross-Device Federated Learning
abstract
In privacy-preserving cross-device federated learning, users train a global model on their local data and submit encrypted local models, while an untrusted central server aggregates the encrypted models to obtain an updated global model. Prior work has demonstrated how to verify the correctness of aggregation in such a setting. However, such verification relies on strong assumptions, such as a trusted setup among all users under unreliable network conditions, or it suffers from expensive cryptographic operations, such as bilinear pairing. In this paper, we scrutinize the verification mechanism of prior work and propose a model recovery attack, demonstrating that most local models can be leaked within a reasonable time (e.g.,$98\%$of encrypted local models are recovered within 21 h). Then, we proposeVerSA, a verifiable secure aggregation protocol for cross-device federated learning.VerSAdoes not require any trusted setup for verification between users while minimizing the verification cost by enabling both the central server and users to utilize only a lightweight pseudorandom generator to prove and verify the correctness of model aggregation. We experimentally confirm the efficiency ofVerSAunder diverse datasets, demonstrating thatVerSAis orders of magnitude faster than verification in prior work.
Changhee Hahn, Hodong Kim, Minjae Kim 0008, Junbeom Hur
IEEE Trans. Dependable Secur. Comput.3
2023 Certificate Transparency With Enhanced Privacy
abstract
Digital certificates play an important role in the authentication of communicating parties for transport layer security. Recently, however, frequent incidents such as the illegal issuance of fake certificates by a compromised certificate authority have raised concerns about the legacy certificate system. Certificate Transparency (CT) mitigates such issues by employing a log server to audit issued certificates publicly, making the certificate issuance and verification processes transparent. Unfortunately, the legacy CT ecosystem suffers from log server compromises and user browsing information leakage. Furthermore, the data structure for the certificate management in the legacy CT system incurs computation overhead linear to the number of registered certificates in the log. In this paper, we propose a secure CT scheme by leveraging a shared value tree (SVT), a novel log structure specifically designed to address the log server compromise and browsing information leakage problems. The verification time of SVT remains constant regardless of the number of registered certificates in the log. We analyze our scheme on the legacy CT system to demonstrate its incremental deployability, guaranteeing a smooth transition toward a more secure web ecosystem.
Hyunsoo Kwon, Sangtae Lee, Minjae Kim 0008, Changhee Hahn, Junbeom Hur
IEEE Trans. Dependable Secur. Comput.3