Hokeun Kim

dblp:24/3377 · DBLP profile ↗
← Back
24ranked-venue papers
4as first author
18since 2021 · last 2026
0000-0003-1450-5248ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 11 · 2 first-author · 10 since 2021Systems, architecture and hardware · 8 · 1 first-author · 4 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Theory of computation · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ACT: Automated CPS Testing for Open-Source Robotic Platforms
abstract
Open-source software for cyber-physical systems (CPS) often lacks robust testing involving robotic platforms, resulting in critical errors that remain undetected. This is especially challenging when multiple modules of CPS software are developed by various open-source contributors. To address this gap, we propose Automated CPS Testing (ACT) that performs automated, continuous testing of open-source software with its robotic platforms, integrated with the open-source infrastructure such as GitHub. We implement an ACT prototype and conduct a case study on an open-source CPS with an educational robotic platform to demonstrate its capabilities.
Aditya A. Krishnan, Hokeun Kim
AST3
2026 Cyber-Physical System Design Space Exploration for Affordable Precision Agriculture
abstract
Precision agriculture promises higher yields and sustainability, but adoption is slowed by the high cost of cyber-physical systems (CPS) and the lack of systematic design methods. We present a cost-aware design space exploration (DSE) framework for multimodal drone–rover platforms to integrate budget, energy, sensing, payload, computation, and communication constraints. Using integer linear programming (ILP) with SAT-based verification, our approach trades off among cost, coverage, and payload while ensuring constraint compliance and a multitude of alternatives. We conduct case studies on smaller and larger-sized farms to show that our method consistently achieves full coverage within budget while maximizing payload efficiency, outperforming state-of-the-art CPS DSE approaches.
Hokeun Kim
DATE2
2026 PREFACE: Proactive Re-executions for Fault-aware Mixed-criticality Environments
abstract
Mixed Criticality Systems (MCSs) enable efficient utilization of hardware resources to execute safety-critical tasks along with non-critical tasks. Soft errors are a critical threat to MCSs, causing detectable as well as undetectable errors. State-of-the-art fault-tolerant MCSs protect the safety-critical tasks against soft errors by reactively re-executing them upon detecting failures. However, assuming that all failures can be detected, existing state-of-the-art failure formulations for fault-tolerant MCSs fail to consider undetected failures. Further, the reactive re-execution strategy cannot improve fault tolerance against undetected failures. To address this problem, we propose PREFACE, Proactive Re-Executions for Fault-Aware mixed-Criticality Environments. PREFACE formulates the failure rates of MCS tasks by differentiating detectable failures from undetectable ones. Based on our novel failure formulation, PREFACE proactively re-executes a task even when no fault is detected to cope with potential undetectable failures, only when it is necessary. Our evaluation demonstrates that PREFACE dramatically improves the scheduling feasibility and reliability compared to state-of-the-art fault-tolerant MCSs.
Hwisoo So, Byeonggil Jun, Chanhee Lee 0002, Hokeun Kim, Aviral Shrivastava
DATE4
2026 Access Controlled Website Interaction for Agentic AI with Delegated Critical Tasks
abstract
Recent studies reveal gaps in delegating critical tasks to agentic AI that accesses websites on the user's behalf, primarily due to limited access control mechanisms on websites designed for agentic AI. In response, we propose a design of website-based interaction for AI agents with fine-grained access control for delegated critical tasks. Our approach encompasses a website design and implementation, as well as modifications to the access grant protocols in an open-source authorization service to tailor it to agentic AI, with delegated critical tasks on the website. The evaluation of our approach demonstrates the capabilities of our access-controlled website used by AI agents.
Hokeun Kim
WWW2
2025 Towards Efficient Privacy-Preserving Federated Learning on Edge with Reconfigurable FPGA
abstract
FPGA-based acceleration has been explored to address performance challenges in architectures incorporating federated learning (FL) and homomorphic encryption (HE). However, model updates, which involve HE, are infrequent in FL applications; thus, static allocation of FPGA resources for HE can lead to inefficiency. In response, this paper presents a work-in-progress FPGA-based FL accelerator that leverages dynamic partial reconfiguration to accelerate HE operations flexibly.
Byeong-Gil Jun, Megan Kuo, Aditya A. Krishnan, Hokeun Kim
FDL4
2025 Garrison: A Defensive Overlay Network for Critical SCADA Infrastructure Networks
Francis Mendoza, Edward Andert, Hokeun Kim
ICBC3
2025 Improving the Efficiency of Coordinating Timed Events in Distributed Systems
Byeong-Gil Jun, Edward A. Lee, Marten Lohstroh, Hokeun Kim
SIGSIM-PADS4
2025 SHIELD: Encrypting Persistent Data of LSM-KVS from Monolithic to Disaggregated Storage
abstract
Log-Structured Merge-tree-based Key-Value Stores (LSM-KVS) are widely used to support modern, high-performance, data-intensive applications. In recent years, with the trend of deploying and optimizing LSM-KVS from monolith to Disaggregated Storage (DS) setups, the confidentiality of LSM-KVS persistent data (e.g., WAL and SST files) is vulnerable to unauthorized access from insiders and external attackers and must be protected using encryption. Existing solutions lack a high-performance design for encryption in LSM-KVS, often focus on in-memory data protection with overheads of 3.4-32.5x, and lack the scalability and flexibility considerations required in DS deployments. This paper proposes two novel designs to address the challenges of providing robust security for persistent components of LSM-KVS while maintaining high performance in both monolith and DS deployments - a simple and effective instance-level design suitable for monolithic LSM-KVS deployments, and SHIELD, a design that embeds encryption into LSM-KVS components for minimal overhead in both monolithic and DS deployment. We achieve our objective through three contributions: (1) A fine-grained integration of encryption into LSM-KVS write path to minimize performance overhead from exposure-limiting practices like using unique encryption keys per file and regularly re-encrypting using new encryption keys during compaction, (2) Mitigating performance degradation caused by recurring encryption of Write-Ahead Log (WAL) writes by using a buffering solution and (3) Extending confidentiality guarantees to DS by designing a metadata-enabled encryption-key-sharing mechanism and a secure local cache for high scalability and flexibility. We implement both designs on RocksDB, evaluating them in monolithic and DS setups while showcasing an overhead of 0-32% for the instance-level design and 0-36% for SHIELD.
Viraj Thakkar, Yingchun Lai, Hokeun Kim, Zhichao Cao 0002
Proc. ACM Manag. Data4
2024 Platform Design for Privacy-Preserving Federated Learning using Homomorphic Encryption : Wild-and-Crazy-Idea Paper
abstract
Federated learning (FL) has been increasingly widely used for distributed and privacy-preserving machine learning (ML) environments, as the raw training data can stay local to clients while leveraging model updates from individual clients. Homomorphic encryption (HE) technologies can provide additional privacy protection for FL by encrypting the model update parameters while allowing model aggregation on a remote server. Although HE-enabled FL seems to be a promising privacy-preserving ML solution, it requires significantly more computational and memory resources, requiring a dedicated hardware and software platform. In this paper, we discuss preliminary but concrete and realizable research ideas for analyzing the requirements for HE-enabled FL and for designing a hardware and software platform. Furthermore, we propose a platform co-design process that considers various design stages and challenges in the platform co-design.
Hokeun Kim, Younghyun Kim 0001, Hoeseok Yang
FDL1
2024 Efficient Coordination for Distributed Discrete-Event Systems
abstract
Timing control while preserving determinism is often a key requirement for ensuring the safety and correctness of distributed cyber-physical systems (CPS). Discrete-event (DE) systems provide a suitable model of computation (MoC) for time-sensitive distributed CPS. The high-level architecture (HLA) is a useful tool for the distributed simulation of DE systems, but its techniques can be adapted for implementing distributed CPS. However, HLA incurs considerable overhead in network messages conveying timing information between the distributed nodes and the centralized run-time infrastructure (RTI). This paper gives a novel approach and implementation that reduces such network messages while preserving DE semantics. An evaluation of our runtime demonstrates that our approach significantly reduces the volume of messages for timing information in HLA.
Byeong-Gil Jun, Edward A. Lee, Marten Lohstroh, Hokeun Kim
MEMOCODE4
2024 Cost-Effective Cyber-Physical System Prototype for Precision Agriculture with a Focus on Crop Growth
abstract
In precision agriculture, integrating advanced technologies is crucial for optimizing plant growth and health monitoring. Cyber-physical system (CPS) platforms tailored to specific agricultural environments have emerged, but the diversity of these environments poses challenges in developing adaptive CPS platforms. This paper explores rapid prototyping methods to address these challenges, focusing on non-destructive techniques for estimating plant growth. We present a CPS prototype that combines sensors, microcontrollers, digital image processing, and predictive modeling to measure leaf area and biomass accumulation in hydroponic environments. Our results show that the prototype effectively monitors and predicts plant growth, highlighting the potential of rapid CPS prototyping in promoting sustainability and improving crop yields at a moderate cost of hardware.
Hokeun Kim
RSP2
2024 Enhanced Wi-Fi Access Point Positioning Using Hexagonal CNN With Mobile Data and Urban Information
abstract
Wi-Fi-based localization has many advantages for personal mobile devices as it works well indoors or in urban environments while consuming much less energy than global positioning system-based localization. The position of Wi-Fi access points (APs) is critical for the accuracy of Wi-Fi-based localization. However, the AP positions are often incorrect or unavailable, making it significantly challenging to use Wi-Fi-based localization for critical position-based services. In this article, we propose novel techniques that significantly enhance the Wi-Fi AP positioning by leveraging daily-collected real-world mobile data collected from six million users over a month. The proposed approach, namely Hexa U-Net, includes novel data processing by incorporating the received signal strength indicator and urban information. We also propose a novel loss function called hex-loss to train the proposed Hexa U-Net. Our evaluation results show that the proposed approach achieves 25 times higher accuracy for the Wi-Fi AP positioning compared to the simple deep neural network-based approach and 2.1 times higher accuracy compared to the state-of-the-art square grid-based convolutional neural network.
Wonseo Choi, Sangmo Sung, Dohyung Han, Haeun Jo, Dongwook Choi, Jae-Il Jung, Hokeun Kim
IEEE Internet Things J.8
2023 Secure Programming Platform for Edge-Based IoT: Wild-and-Crazy-Idea Paper
abstract
The edge computing-based Internet of Things (IoT) offers benefits in terms of efficiency, low latency, security, and privacy. However, programming models and platforms for this edge-based IoT are still an open problem, particularly regarding security and privacy. This paper proposes concrete and realizable ideas for building a secure programming platform called Secure Swarm Programming Platform (SSPP) to ensure platform-level security for the edge-based IoT while utilizing existing system-level security mechanisms. SSPP's easy-to-use software components can enable static and dynamic security analysis of IoT applications, preventing vulnerabilities and detecting intrusions. Software deployed through SSPP can be remotely attested by a verifier on the edge, ensuring it remains untampered with. This paper also plans out future research and evaluation of SSPP's programmability, security, and remote attestation.
Hokeun Kim
FDL1
2023 Risk and Mitigation of Nondeterminism in Distributed Cyber-Physical Systems
Soroush Bateni, Marten Lohstroh, Hou Seng Wong, Hokeun Kim, Shaokai Lin, Christian Menard, Edward A. Lee
MEMOCODE4
2023 Poster Abstract: Securing Edge-Based Real-Time IoT Systems
abstract
The advent of the Internet of Things (IoT) has led to an increased demand for security and real-time guarantees in distributed embedded systems comprising the IoT. Securing edge-based systems with limited resources can be especially problematic due to challenges in adapting traditional network security protocols. In this work, we introduce two methods to provide security guarantees in resource-constrained devices-based ioT systems. As a case study, we propose an integration of Secure Swarm Toolkit (SST), an open-source framework for IoT security, with Lingua Franca (LF), a software platform for concurrent and time-sensitive applications. We report preliminary results on our work-in-progress implementation and experiments, followed by concrete future research plans.
Hokeun Kim
SenSys2
2023 Technology trends and challenges in SDN and service assurance for end-to-end network slicing
abstract
Network slicing is a core technology to enable new services and solutions in 5G and upcoming 6G communications. However, many issues arise when applying network slicing at a commercial scale, as this requires end-to-end management and automation of the network. Network slicing also requires various state-of-the-art technologies based on collaboration across international standards organizations and open-source communities. This paper reviews and summarizes the recent technological trends and challenges related to Software-Defined Networking (SDN) and service assurance for end-to-end network slicing. First, we focus on the essential use cases and technology trends associated with network slicing, followed by a survey of standard organizations and open-source projects related to network slicing and how they have evolved. Then, we overview an end-to-end network slicing architecture considering Open Radio Access Network (O-RAN) standard. For Radio Access Network (RAN) slicing, we zero in on managing RAN and xHaul with an integrated policy. For transport slicing, we discuss SDN architecture and requirements for network slicing with traffic isolation, unified QoS policy, and traffic engineering. We also cover SLA management using protocol-independent active monitoring and passive monitoring. In the later part of the paper, we summarize technical considerations for end-to-end network slicing, including the RAN-integrated xHaul architecture, converged enterprise network for multi-connectivity, 5G edge data center architectures using programmable data plane, and network slicing security. Overall, this paper reviews the various design issues associated with network slicing and the proposals to resolve these issues to facilitate end-to-end network slicing at a commercial scale.
Kibeom Park, Sangmo Sung, Hokeun Kim, Jae-Il Jung
Comput. Networks3
2023 High-performance Deterministic Concurrency Using Lingua Franca
abstract
Actor frameworks and similar reactive programming techniques are widely used for building concurrent systems. They promise to be efficient and scale well to a large number of cores or nodes in a distributed system. However, they also expose programmers to nondeterminism, which often makes implementations hard to understand, debug, and test. The recently proposed reactor model is a promising alternative that enables deterministic concurrency. In this article, we present an efficient, parallel implementation of reactors and demonstrate that the determinacy of reactors does not imply a loss in performance. To show this, we evaluate Lingua Franca (LF), a reactor-oriented coordination language. LF equips mainstream programming languages with a deterministic concurrency model that automatically takes advantage of opportunities to exploit parallelism. Our implementation of the Savina benchmark suite demonstrates that, in terms of execution time, the runtime performance of LF programs even exceeds popular and highly optimized actor frameworks. We compare against Akka and CAF, which LF outperforms by 1.86× and 1.42×, respectively.
Christian Menard, Marten Lohstroh, Soroush Bateni, Matthew Chorlian, Arthur Deng, Peter Donovan, Clément Fournier, Shaokai Lin, Felix Suchert, Tassilo Tanneberger, Hokeun Kim, Jerónimo Castrillón, Edward A. Lee
ACM Trans. Archit. Code Optim.11
2022 Energy-Efficient Bus Encoding Techniques for Next-Generation PAM-4 DRAM Interfaces
abstract
In this paper, we introduce effective bus data en-coding schemes for next-generation interfaces of DRAM with an analysis of their energy and lane efficiency characteristics. The Pulse-Amplitude-Modulation-4 (PAM-4) signaling technique has recently been adopted to memory interfaces due to their increased per-pin data-rate requirements. However, as the power consumption profile of PAM-4 symbols differs from that of NRZ symbols, the conventional Dynamic Bus Inversion (DBI) encoding fails to achieve an expected reduction of termination power. Therefore, this paper proposes data encoding schemes applicable to the PAM-4 memory links and compares their performances in terms of the termination energy with experimental results. We evaluate the proposed approaches by applying data encoding to DRAM memory access traces obtained from executing benchmarks on ARM/x86 ISA-based processors, including caches, simulated on the gem5 architecture simulator. The experimental results show that our advanced encoding algorithms enable us to achieve doubled data rate with minimal power consumption overhead.
Youri Su, Eunji Song, Jaeduk Han, Hokeun Kim
ICCD6
2020 Resilient Authentication and Authorization for the Internet of Things (IoT) Using Edge Computing
abstract
An emerging type of network architecture called edge computing has the potential to improve the availability and resilience of IoT services under anomalous situations such as network failures or denial-of-service (DoS) attacks. However, relatively little has been explored on the problem of ensuring availability even when edge computers that provide key security services (e.g., authentication and authorization) become unavailable themselves. This article proposes a resilient authentication and authorization framework to enhance the availability of IoT services under DoS attacks or failures. The proposed approach leverages a technique called secure migration , which allows an IoT device to migrate to another trusted edge computer when its own local authorization service becomes unavailable. Specifically, we describe the design of a secure migration framework and its supporting mechanisms, including (1) automated migration policy construction and (2) protocols for preparing and executing the secure migration. We formalize secure migration policy construction as an integer linear programming (ILP) problem and show its effectiveness using a case study on smart buildings, where the proposed solution achieves significantly higher availability under simulated attacks on authorization services.
Hokeun Kim, Eunsuk Kang, David Broman, Edward A. Lee
ACM Trans. Internet Things1
2018 A Component Architecture for the Internet of Things
abstract
In this paper, we describe a component-based software architecture for the Internet of Things in which proxies for Things and services that we call “accessors” interact with one another under a concurrent, time-stamped, discrete-event (DE) semantics. These proxies are analogous to web pages, which proxy a cloud-based service such as a bank, but instead of being designed to interface those services with humans, accessors are designed to interface services and Things with other services and Things. A deterministic DE semantics is combined with a widely used pattern for handling network interactions that we call asynchronous atomic callbacks (AACs). AAC enables many concurrent pending requests to be active at once without blocking and without the treacherous concurrency pitfalls of threads. In effect, our architecture combines AAC with actors where the actor model has been endowed with a temporal semantics. We show how this architecture can leverage the previously reported secure swarm toolkit (SST) to achieve stateof- the-art authentication, authorization, and encryption of interactions across networks.
Christopher X. Brooks, Chadlia Jerad, Hokeun Kim, Edward A. Lee, Marten Lohstroh, Victor Nouvelletz, Beth Osyk, Matthew Weber
Proc. IEEE3
2017 A multimodal execution monitor with anomaly classification for robot-assisted feeding
abstract
Activities of daily living (ADLs) are important for quality of life. Robotic assistance offers the opportunity for people with disabilities to perform ADLs on their own. However, when a complex semi-autonomous system provides real-world assistance, occasional anomalies are likely to occur. Robots that can detect, classify and respond appropriately to common anomalies have the potential to provide more effective and safer assistance. We introduce a multimodal execution monitor to detect and classify anomalous executions when robots operate near humans. Our system builds on our past work on multimodal anomaly detection. Our new monitor classifies the type and cause of common anomalies using an artificial neural network. We implemented and evaluated our execution monitor in the context of robot-assisted feeding with a general-purpose mobile manipulator. In our evaluations, our monitor outperformed baseline methods from the literature. It succeeded in detecting 12 common anomalies from 8 able-bodied participants with 83% accuracy and classifying the types and causes of the detected anomalies with 90% and 81% accuracies, respectively. We then performed an in-home evaluation with Henry Evans, a person with severe quadriplegia. With our system, Henry successfully fed himself while the monitor detected, classified the types, and classified the causes of anomalies with 86%, 90%, and 54% accuracy, respectively.
Daehyung Park, Hokeun Kim, Yuuna Hoshi, Zackory Erickson, Ariel Kapusta, Charles C. Kemp
IROS2
2016 Strober: Fast and Accurate Sample-Based Energy Simulation for Arbitrary RTL
abstract
This paper presents a sample-based energy simulation methodology that enables fast and accurate estimations of performance and average power for arbitrary RTL designs. Our approach uses an FPGA to simultaneously simulate the performance of an RTL design and to collect samples containing exact RTL state snapshots. Each snapshot is then replayed in gate-level simulation, resulting in a workload-specific average power estimate with confidence intervals. For arbitrary RTL and workloads, our methodology guarantees a minimum of four-orders-of-magnitude speedup over commercial CAD gate-level simulation tools and gives average energy estimates guaranteed to be within 5% of the true average energy with 99% confidence. We believe our open-source sample-based energy simulation tool Strober can not only rapidly provide ground truth for more abstract power models, but can enable productive design-space exploration early in the RTL design process.
Adam M. Izraelevitz, Christopher Celio, Hokeun Kim, Brian Zimmer, Yunsup Lee, Jonathan Bachrach, Krste Asanovic
ISCA4
2015 System simulation from operational data
abstract
System simulation is a valuable tool to unveil inefficiencies and to test new strategies when implementing and revising systems. Often, simulations are parameterized using offline data and heuristic knowledge. Operational data, i.e., data gained through experimentation and observation, can greatly improve the fidelity between the actual system and the simulation. In a traffic scenario, for example, different road conditions or vehicle types can impact the outcome of the simulation and have to be considered during the modeling stage. This paper proposes using machine learning techniques to generate high fidelity simulation models. A traffic simulation case study exemplifies this approach by generating a model for the SUMO traffic simulator from vehicular telemetry data.
Armin Wasicek, Edward A. Lee, Hokeun Kim, Lev Greenberg, Akihito Iwai, Ilge Akkaya
DAC3
2015 A predictable and command-level priority-based DRAM controller for mixed-criticality systems
abstract
Mixed-criticality systems have tasks with different criticality levels running on the same hardware platform. Today's DRAM controllers cannot adequately satisfy the often conflicting requirements of tightly bounded worst-case latency for critical tasks and high performance for non-critical real-time tasks. We propose a DRAM memory controller that meets these requirements by using bank-aware address mapping and DRAM command-level priority-based scheduling with preemption. Many standard DRAM controllers can be extended with our approach, incurring no performance penalty when critical tasks are not generating DRAM requests. Our approach is evaluated by replaying memory traces obtained from executing benchmarks on an ARM ISA-based processor with caches, which is simulated on the gem5 architecture simulator. We compare our approach against previous TDM-based approaches, showing that our proposed memory controller achieves dramatically higher performance for non-critical tasks, without any significant impact on the worstcase latency of critical tasks.
Hokeun Kim, David Broman, Edward A. Lee, Michael Zimmer 0001, Aviral Shrivastava, Junkwang Oh
RTAS1