VLDB 2026 Research / reviewers in the wild / expert
Yoo-Seung Won
dblp:177/5752
· DBLP profile ↗
7ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0002-5205-7530ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Ablation Analysis for Multi-Device Deep Learning-Based Physical Side-Channel AnalysisabstractThe use of deep learning-based side-channel analysis is an effective way of performing profiling attacks on power and electromagnetic leakages, even against targets protected with countermeasures. While many research papers have reported successful results, they typically focus on profiling and attacking a single device, assuming that leakages are similar between devices of the same type. However, this assumption is not always realistic due to variations in hardware and measurement setups, creating what is known as the portability problem. Profiling multiple devices has been proposed as a solution, but obtaining access to these devices may pose a challenge for attackers. This paper proposes a new approach to overcome the portability problem by introducing a neural network layer assessment methodology based on the ablation paradigm. This methodology evaluates the sensitivity and resilience of each layer, providing valuable knowledge to create a Multiple Device Model from Single Device (MDMSD). Specifically, it involves ablating a specific neural network section and performing recovery training. As a result, the profiling model, trained initially on a single device, can be generalized to leakage traces measured from various devices. By addressing the portability problem through a single device, practical side-channel attacks could be more accessible and effective for attackers. Lichao Wu, Yoo-Seung Won, Dirmanto Jap, Guilherme Perin, Shivam Bhasin, Stjepan Picek |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Fault injection attacks on SoftMax function in deep neural networksabstractSoftmax is commonly used activation function in neural networks to normalize the output to probability distribution over predicted classes. Being often deployed in the output layer, it can potentially be targeted by fault injection attacks to create misclassification. In this extended abstract, we perform a preliminary fault analysis of Softmax against single bit faults. Dirmanto Jap, Yoo-Seung Won, Shivam Bhasin |
CF | 2 |
| 2021 | Are Cold Boot Attacks Still Feasible: A Case Study on Raspberry Pi With Stacked MemoryabstractCold boot attacks are semi-invasive attacks which have threatened computer systems over a decade now to leak sensitive user information passwords, keys and PIN. With internet of things (IoT) finding mass deployment, their security must be well investigated. In this work, we take a look at popular IoT device Raspberry Pi (model B+), which is already deployed in millions. Raspberry Pi features a stacked memory on top of its processor, making it impossible to physically separate the RAM from the processor. We investigate the decay model of a cold boot attack on Raspberry Pi. The results show a decay rate as low as 0.00027% which is orders of magnitude lower than previous works allowing close to perfect data recovery. We further report successful recovery of secret disk encryption key when using dm-crypt on Raspberry Pi followed by discussion on mitigation strategies. Yoo-Seung Won, Shivam Bhasin |
FDTC | 1 |
| 2021 | DeepFreeze: Cold Boot Attacks and High Fidelity Model Recovery on Commercial EdgeML DeviceabstractEdgeML accelerators like Intel Neural Compute Stick 2 (NCS) can enable efficient edge-based inference with complex pre-trained models. The models are loaded in the host (like Raspberry Pi) and then transferred to NCS for inference. In this paper, we demonstrate practical and low-cost cold boot based model recovery attacks on NCS to recover the model architecture and weights, loaded from the Raspberry Pi. The architecture is recovered with 100% success and weights with an error rate of 0.04%. The recovered model reports maximum accuracy loss of 0.5% as compared to original model and allows high fidelity transfer of adversarial examples. We further extend our study to other cold boot attack setups reported in the literature with higher error rates leading to accuracy loss as high as 70%. We then propose a methodology based on knowledge distillation to correct the erroneous weights in recovered model, even without access to original training data. The proposed attack remains unaffected by the model encryption features of the OpenVINO and NCS framework. Yoo-Seung Won, Dirmanto Jap, Arindam Basu, Shivam Bhasin |
ICCAD | 1 |
| 2021 | A Systematic Side-Channel Evaluation of Black Box AES in Secure MCU: Architecture Recovery and Retrieval of PUF Based Secret KeyabstractModern microcontrollers (MCUs) come packed with features to support rising demand of security and privacy in different applications. Features like hardware support for cryptography, trusted execution environment, memory protection, etc are widely available. In this paper, we take a deeper look into ARM Cortex M33 microcontroller designed to support critical applications like point of sale, smart home, smart factory, etc. In particular, we demonstrate architecture recovery of black box AES engine using side-channel analysis. The architecture is then exploited through side-channels to recover device intrinsic keys based on physical unclonable functions. Finally, feasibility of cross-device attacks are investigated with deep learning based side-channel attacks. Our results give a better insight into embedded AES engine available off-the shelf and allow user to design secure applications knowing such vulnerabilities at design time. Yoo-Seung Won, Shivam Bhasin |
ISCAS | 1 |
| 2021 | Back to the Basics: Seamless Integration of Side-Channel Pre-Processing in Deep Neural NetworksabstractDeep learning approaches have become popular for Side-Channel Analysis (SCA) in the recent years. Especially Convolutional Neural Networks (CNN) due to their natural ability to overcome jitter-based as well as masking countermeasures. Most of the recent works have been focusing on optimising the performance on given dataset, for example finding optimal architecture and using ensemble, and bypass the need for trace pre-processing. However, trace pre-processing is a long studied topic and several proven techniques exist in the literature. There is no straightforward manner to integrate those techniques into deep learning based SCA. In this paper, we propose a generic framework which allows seamless integration of multiple, user defined pre-processing techniques into the neural network architecture. The framework is based on Multi-scale Convolutional Neural Networks ( MCNN) that were originally proposed for time series analysis. MCNN are composed of multiple branches that can apply independent transformation to input data in each branch to extract the relevant features and allowing a better generalization of the model. In terms of SCA, these transformations can be used for integration of pre-processing techniques, such as phase-only correlation, principal component analysis, alignment methods, etc. We present successful results on generic network which generalizes to different publicly available datasets. Our findings show that it is possible to design a network that can be used in a more general way to analyze side-channel leakage traces and perform well across datasets. Yoo-Seung Won, Xiaolu Hou, Dirmanto Jap, Jakub Breier, Shivam Bhasin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | On the Security of Balanced Encoding Countermeasures
Yoo-Seung Won, Philip Hodgers, Máire O'Neill, Dong-Guk Han |
CARDIS | 1 |