VLDB 2026 Research / reviewers in the wild / expert
Haehyun Cho
dblp:164/2543
· DBLP profile ↗
19ranked-venue papers
5as first author
12since 2021 · last 2025
0000-0002-5344-5252ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 1 first-author · 10 since 2021Systems, architecture and hardware · 3 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Intent-aware Fuzzing for Android Hardened ApplicationabstractThe widespread adoption of app hardening techniques in Android applications makes it more challenging for current analysis techniques to analyze hardened apps, leading to limited analysis coverage. This limitation is mainly due to the difficulties in obtaining detailed information about Intents, which is essential for component communication and the execution of specific events in Android applications. Seongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi, Hyungsub Kim, Yuseok Jeon |
CCS | 3 |
| 2025 | Do All Autoregressive Transformers Remember Facts the Same Way? A Cross-Architecture Analysis of Recall MechanismsabstractUnderstanding how Transformer-based language models store and retrieve factual associations is critical for improving interpretability and enabling targeted model editing.Prior work, primarily on GPT-style models, has identified MLP modules in early layers as key contributors to factual recall.However, it remains unclear whether these findings generalize across different autoregressive architectures.To address this, we conduct a comprehensive evaluation of factual recall across several models-including GPT, LLaMA, Qwen, and DeepSeek-analyzing where and how factual information is encoded and accessed.Consequently, we find that Qwen-based models behave differently from previous patterns: attention modules in the earliest layers contribute more to factual recall than MLP modules.Our findings suggest that even within the autoregressive Transformer family, architectural variations can lead to fundamentally different mechanisms of factual recall. 1 Minyeong Choe, Haehyun Cho, Changho Seo, Hyunil Kim |
EMNLP | 2 |
| 2025 | Enhancing in-process isolation for robust defense against information disclosure attacks
Hongjoo Jin, Sumin Yang, Haehyun Cho |
Comput. Secur. | 3 |
| 2024 | DryJIN: Detecting Information Leaks in Android Applications
Minseong Choi, Yubin Im, Steven Y. Ko, Yonghwi Kwon 0001, Yuseok Jeon, Haehyun Cho |
SEC | 6 |
| 2024 | Satellite: Effective and Efficient Stack Memory Protection Scheme for Unsafe Programming Languages
Hongjoo Jin, Sumin Yang, Moon Chan Park, Haehyun Cho |
SEC | 4 |
| 2023 | Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at ScaleabstractDespite recent advancements in malicious website detection and phishing mitigation, the security ecosystem has paid little attention to Fraudulent e-Commerce Websites (FCWs), such as fraudulent shopping websites, fake charities, and cryptocurrency scam websites. Even worse, there are no active large-scale mitigation systems or publicly available datasets for FCWs.In this paper, we first propose an efficient and automated approach to gather FCWs through crowdsourcing. We identify eight different types of non-phishing FCWs and derive key defining characteristics. Then, we find that anti-phishing mitigation systems, such as Google Safe Browsing, have a detection rate of just 0.46% on our dataset. We create a classifier, BEYOND PHISH, to identify FCWs using manually defined features based on our analysis. Validating BEYOND PHISH on never-before-seen (untrained and untested data) through a user study indicates that our system has a high detection rate and a low false positive rate of 98.34% and 1.34%, respectively. Lastly, we collaborated with a major Internet security company, Palo Alto Networks, as well as a major financial services provider, to evaluate our classifier on manually labeled real-world data. The model achieves a false positive rate of 2.46% and a 94.88% detection rate, showing potential for real-world defense against FCWs. Marzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu, Jorij Abraham, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
SP | 2 |
| 2022 | ViK: practical mitigation of temporal memory safety violations through object ID inspectionabstractTemporal memory safety violations, such as use-after-free (UAF) vulnerabilities, are a critical security issue for software written in memory-unsafe languages such as C and C++. Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ASPLOS | 1 |
| 2022 | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking BehaviorabstractPhishing is a ubiquitous and increasingly sophisticated online threat. To evade mitigations, phishers try to "cloak" malicious content from defenders to delay their appearance on blacklists, while still presenting the phishing payload to victims. This cat-and-mouse game is variable and fast-moving, with many distinct cloaking methods---we construct a dataset identifying 2,933 real-world phishing kits that implement cloaking mechanisms. These kits use information from the host, browser, and HTTP request to classify traffic as either anti-phishing entity or potential victim and change their behavior accordingly. Sukwha Kyung, Hans Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doupé |
CCS | 6 |
| 2022 | Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability
Kyle Zeng, Yueqi Chen 0001, Haehyun Cho, Xinyu Xing 0001, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao |
USENIX Security Symposium | 3 |
| 2021 | Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing EcosystemabstractPhishing attacks are causing substantial damage albeit extensive effort in academia and industry. Recently, a large volume of phishing attacks transit toward adopting HTTPS, leveraging TLS certificates issued from Certificate Authorities (CAs), to make the attacks more effective. In this paper, we present a comprehensive study on the security practices of CAs in the HTTPS phishing ecosystem. We focus on the CAs, critical actors under-studied in previous literature, to better understand the importance of the security practices of CAs and thwart the proliferating HTTPS phishing. In particular, we first present the current landscape and effectiveness of HTTPS phishing attacks comparing to traditional HTTP ones. Then, we conduct an empirical experiment on the CAs' security practices in terms of the issuance and revocation of the certificates. Our findings highlight serious conflicts between the expected security practices of CAs and reality, raising significant security concerns. We further validate our findings using a longitudinal dataset of abusive certificates used for real phishing attacks in the wild. We confirm that the security concerns of CAs prevail in the wild and these concerns can be one of the main contributors to the recent surge of HTTPS phishing attacks. Doowon Kim, Haehyun Cho, Yonghwi Kwon 0001, Adam Doupé, Sooel Son, Gail-Joon Ahn, Tudor Dumitras |
AsiaCCS | 2 |
| 2021 | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases
Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili |
NDSS | 2 |
| 2021 | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingabstractPhishing is a critical threat to Internet users. Although an extensive ecosystem serves to protect users, phishing websites are growing in sophistication, and they can slip past the ecosystem’s detection systems—and subsequently cause real-world damage—with the help of evasion techniques. Sophisticated client-side evasion techniques, known as cloaking, leverage JavaScript to enable complex interactions between potential victims and the phishing website, and can thus be particularly effective in slowing or entirely preventing automated mitigations. Yet, neither the prevalence nor the impact of client-side cloaking has been studied.In this paper, we present CrawlPhish, a framework for automatically detecting and categorizing client-side cloaking used by known phishing websites. We deploy CrawlPhish over 14 months between 2018 and 2019 to collect and thoroughly analyze a dataset of 112,005 phishing websites in the wild. By adapting state-of-the-art static and dynamic code analysis, we find that 35,067 of these websites have 1,128 distinct implementations of client-side cloaking techniques. Moreover, we find that attackers’ use of cloaking grew from 23.32% initially to 33.70% by the end of our data collection period. Detection of cloaking by our framework exhibited low false-positive and false-negative rates of 1.45% and 1.75%, respectively. We analyze the semantics of the techniques we detected and propose a taxonomy of eight types of evasion across three high-level categories: User Interaction, Fingerprinting, and Bot Behavior.Using 150 artificial phishing websites, we empirically show that each category of evasion technique is effective in avoiding browser-based phishing detection (a key ecosystem defense). Additionally, through a user study, we verify that the techniques generally do not discourage victim visits. Therefore, we propose ways in which our methodology can be used to not only improve the ecosystem’s ability to mitigate phishing websites with client-side cloaking, but also continuously identify emerging cloaking techniques as they are launched by attackers. Adam Oest, Haehyun Cho, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
SP | 3 |
| 2020 | SmokeBomb: effective mitigation against cache side-channel attacks on the ARM architectureabstractCache side-channel attacks abuse microarchitectural designs meant to optimize memory access to infer information about victim processes, threatening data privacy and security. Recently, the ARM architecture has come into the spotlight of cache side-channel attacks with its unprecedented growth in the market. Haehyun Cho, Jinbum Park, Donguk Kim 0003, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
MobiSys | 1 |
| 2018 | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi CallingabstractWi-Fi Calling, which is used to make and receive calls over the Wi-Fi network, has been widely adopted and deployed to extend the coverage and increase the capacity in weak signal areas by moving traffic from LTE to Wi-Fi networks. However, the security of Wi-Fi Calling mechanism has not been fully analyzed, and Wi-Fi Calling may inherently have greater security risks than conventional LTE calling. To provide secure connections with confidentiality and integrity, Wi-Fi Calling leverages the IETF protocols IKEv2 and IPSec. Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ACSAC | 3 |
| 2018 | Prime+Count: Novel Cross-world Covert Channels on ARM TrustZoneabstractThe security of ARM TrustZone relies on the idea of splitting system-on-chip hardware and software into two worlds, namely normal world and secure world. In this paper, we report cross-world covert channels, which exploit the world-shared cache in the TrustZone architecture. We design a Prime+Count technique that only cares about how many cache sets or lines have been occupied. The coarser-grained approach significantly reduces the noise introduced by the pseudo-random replacement policy and world switching. Using our Prime+Count technique, we build covert channels in single-core and cross-core scenarios in the TrustZone architecture. Our results demonstrate that Prime+Count is an effective technique for enabling cross-world covert channels on ARM TrustZone. Haehyun Cho, Donguk Kim 0003, Jinbum Park, Choong-Hoon Lee, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
ACSAC | 1 |
| 2018 | SeCore: Continuous Extrospection with High Visibility on Multi-core ARM PlatformsabstractWe present SeCore, which is a novel continuous extrospection system on multi-core ARM platform. SeCore leverages ARM TrustZone technology to keep one core in the secure world and assure the integrity of the static kernel data and code in the normal world. By breaking the original time-sharing paradigm of such systems, SeCore enables continuous coprocessor-like monitoring with high visibility into the rich execution environment on mobile and IoT platforms. By ensuring that secure tools execute on certain physical CPU cores, the system's attack surface is also significantly reduced. Bernard Ngabonziza, Haehyun Cho, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 3 |
| 2016 | TripleMon: A multi-layer security framework for mediating inter-process communication on AndroidabstractAs smartphones have become an indispensable part of daily life, mobile users are increasingly relying on them to process personal information with feature-rich applications. This situation requires robust security mechanisms for protecting sensitive applications and data on mobile devices. Android, as one the most popular smartphone operating systems, provides two core security mechanisms, application sandboxing and a permission system. However, recent studies show that these mechanisms are vulnerable to be passed by a variety of attacks. In this paper, we argue for the need of designing and implementing more comprehensive security mechanisms for Android. We realize that mediating Inter-Process Communication (IPC) channels used by Android applications can mitigate prominent attacks effectively and efficiently. Based on this observation, we propose a practical multi-layer security framework called TripleMon to support policy-based mediation on Android IPC. We also discuss and evaluate a proof-of-concept prototype of TripleMon along with the experimental results derived from real malware samples and synthetic attacks. Yiming Jing, Gail-Joon Ahn, Hongxin Hu, Haehyun Cho, Ziming Zhao 0001 |
J. Comput. Secur. | 4 |
| 2016 | Mobile application tamper detection scheme using dynamic code injection against repackaging attacks
Haehyun Cho, Jiwoong Bang, Myeongju Ji, Jeong Hyun Yi |
J. Supercomput. | 1 |
| 2016 | Anti-debugging scheme for protecting mobile apps on android platform
Haehyun Cho, Jongsu Lim, Hyunki Kim, Jeong Hyun Yi |
J. Supercomput. | 1 |