VLDB 2026 Research / reviewers in the wild / expert
Seoksu Lee
dblp:224/9670
· DBLP profile ↗
8ranked-venue papers
4as first author
6since 2021 · last 2026
0009-0000-6734-0753ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Poster: Automated Generation of a Broad Spectrum of MBA Expressions for Robust Deobfuscation Analysis
Seoksu Lee, Sangjun An, Eunbi Cho, Eun-Sun Cho |
ICST | 1 |
| 2025 | An Enhanced Opaque Predicate Detection Method with Synthesis and Recursive MatchingabstractProgram obfuscation transforms source code into a complex, harder-to-analyze form while preserving functionality, commonly used for intellectual property protection and security. Although it is also exploited by malware developers. Opaque predicate obfuscation increases program size by inserting junk code with conditional expressions that prevent execution. Existing deobfuscation methods rely on symbolic execution and SMT solvers but face limitations based on predicate types. This paper proposes a logic-based deobfuscation technique capable of handling Mixed Boolean Arithmetic obfuscation and dynamic opaque predicates using I/O analysis, program synthesis, and recursive matching. Experimental results show that the proposed method outperforms existing tools against obfuscation by Code Virtualizer, Tigress, and OLLVM. Hyeongchang Jeon, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 2 |
| 2025 | Lightweight Classifier for Obfuscation Methods for IoT DevicesabstractIdentifying obfuscation techniques is essential for effective malware analysis and mitigation. Previous research has primarily focused on x86 architectures, but obfuscation techniques have become increasingly prevalent in IoT malware, particularly on ARM and MIPS architectures.This paper presents a method for identifying obfuscation techniques across different architectures. We first analyze and enhance an existing approach for x86 malware, improving its accuracy and efficiency. We then extend the method to IoT architectures, evaluating how architectural differences influence obfuscation patterns. Experimental results confirm that the proposed method effectively detects obfuscation techniques across multiple platforms, providing a foundation for more robust malware analysis in IoT environments. This research strengthens security measures by enabling more effective deobfuscation strategies against emerging threats. Wanju Kim, Youjeong Noh, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 3 |
| 2024 | Poster: E-Graphs and Equality Saturation for Term-Rewriting in MBA Deobfuscation: An Empirical StudyabstractObfuscation is a powerful software protection technique. It changes a program into a more complicated one while preserving its semantics. Malware distributors also employ this method, to protect their malware from being understood by malware analysts. Thus, it is crucial to deobfuscate malware in a timely manner, to enable a prompt action to malware. Seoksu Lee, Hyeongchang Jeon, Eun-Sun Cho |
CCS | 1 |
| 2024 | Dynamic Opaque Predicate Detection with a Recursive Matching MethodabstractAs program obfuscation techniques have improved, attackers have incorporated obfuscation into their malware and used it to thwart malware analysis. Opaque predicate is one of the widely used obfuscation methods to thwart code analysis, and we found that dynamic opaque predicate in particular cannot be deobfuscated with existing deobfuscators. This work proposes a dynamic opaque predicate detection technique based on recursive propagating of symbolic execution. Hyeongchang Jeon, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 2 |
| 2023 | Assessing Opaque Predicates: Unveiling the Efficacy of Popular Obfuscators with a Rapid DeobfuscatorabstractProgram obfuscation protects a program's intellectual property rights and vulnerabilities by making it unreadable and hardening program analysis. However, obfuscation typically adds size and complexity to programs, resulting in performance overhead. Fortunately. opaque predicates, which are the conditional expressions always evaluated to be true or always false, reduce the overhead by ensuring that the inserted dummy code is never executed. Furthermore, when combined with other forms of obfuscation such as MBA obfuscation, opaque predicates have been found to efficiently defeat existing SMT-based analysis methods. However, new program analysis techniques have recently emerging that can simplify more obfuscation, which suggests that opaque predicate-based obfuscation may no longer be robust enough. In this paper, we introduce a novel opaque predicate classification, taking into account robustness against various deobfuscation techniques. According to this proposed classification, we assess real-world obfuscation results produced by popular obfuscation tools. Hyeonachang Jeon, Seoyeon Kang, Seoksu Lee, Eun-Sun Cho |
APSEC | 3 |
| 2019 | Toward Machine Learning Based Analyses on Compressed FirmwareabstractAs Internet of Things (IoT) applications are getting attention these days, the importance of firmware security is also growing. However, it is not straightforward to analyze the bugs or vulnerabilities that reside in firmware. One of the major challenges is to detect information about hardware architectures of compressed firmware. Traditional analysis tools make use of static signatures embedded in the compressed binary code of firmware. However, signature extraction needs the careful elaboration of experts, and it is not always even possible. In this paper, we introduce our experience in analyzing the hardware information of compressed firmware. Since it is not possible to use the semantic information of compressed binary code, we adopt machine learning technologies for this purpose. Despite various difficulties, we have positive experimental results. Seoksu Lee, Joon-Young Paik, Rize Jin, Eun-Sun Cho |
COMPSAC (2) | 1 |
| 2018 | Toward Firmware-Type Analysis Using Machine Learning TechniquesabstractDue to the development of the Internet, a considerable amount of firmware that operates on various types of hardware has been developed. The process of analyzing firmware according to these developments has also been important. Among the various tools for analyzing firmware, the tool for analyzing firmware types is important as the first step of the process of analyzing firmware. This paper introduces a signature-based firmware analysis approach of the type mainly used at present and proposes a new idea for analyzing firmware types based on machine learning. Seoksu Lee, Eun-Sun Cho |
COMPSAC (1) | 1 |