Hodong Kim

dblp:260/1195 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-3906-7240ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2026 Abortection: Robust TSX-Based Detection of Cache Side-Channel Attacks on Modern Intel CPUs with Non-Inclusive LLCs
abstract
Cache side-channel attacks such as Flush+Reload and Prime+Probe continue to threaten isolation across mutually untrusted processes. Although many attack detection mechanisms have been proposed, recent Intel processors introduce non-inclusive last-level caches and directory-based coherence. These architectural changes give rise to new attack behaviors that have not been examined by previous detection methods, which predominantly focus on inclusive cache hierarchies. As a result, real-time techniques that can account for both flush-based and directory-based eviction patterns without relying on assumptions specific to individual attack types remain largely underexplored.
Hyungjung Joo, Hodong Kim, Junbeom Hur
AsiaCCS2
2024 Deep Learning-Based Detection for Multiple Cache Side-Channel Attacks
abstract
A cache side-channel attack retrieves victim’s sensitive information from a system by exploiting shared cache of CPUs. Since conventional cache side-channel attacks such as FLUSH+RELOAD and PRIME+PROBE are likely to incur numerous cache events, such as cache hits and misses, many previous strategies have focused on monitoring cache events for attack detection. However, as recently proposed attacks such as PRIME+ABORT have exploited the other events as side-channels, it has become challenging to detect them by monitoring only cache events. In this paper, we investigate PRIME+ABORT attack and identifies Intel TSX hardware events are tightly coupled with it as well as cache events. Based on our finding, we propose a novel deep learning-based cache side-channel attack detection method called FRIME. It can concurrently detect not only the conventional attacks such as FLUSH+RELOAD, PRIME+PROBE, but also PRIME+ABORT by leveraging both event types. In order to demonstrate the efficacy of our cache side-channel attack detection scheme in diverse workload conditions in the real world, we implement it using MLP, RNN, and LSTM deep learning models, demonstrating LSTM-based method outperforms the other implementations in terms of detection accuracy.
Hodong Kim, Changhee Hahn, Hyunwoo J. Kim, Young-joo Shin, Junbeom Hur
IEEE Trans. Inf. Forensics Secur.1
2023 VerSA: Verifiable Secure Aggregation for Cross-Device Federated Learning
abstract
In privacy-preserving cross-device federated learning, users train a global model on their local data and submit encrypted local models, while an untrusted central server aggregates the encrypted models to obtain an updated global model. Prior work has demonstrated how to verify the correctness of aggregation in such a setting. However, such verification relies on strong assumptions, such as a trusted setup among all users under unreliable network conditions, or it suffers from expensive cryptographic operations, such as bilinear pairing. In this paper, we scrutinize the verification mechanism of prior work and propose a model recovery attack, demonstrating that most local models can be leaked within a reasonable time (e.g.,$98\%$of encrypted local models are recovered within 21 h). Then, we proposeVerSA, a verifiable secure aggregation protocol for cross-device federated learning.VerSAdoes not require any trusted setup for verification between users while minimizing the verification cost by enabling both the central server and users to utilize only a lightweight pseudorandom generator to prove and verify the correctness of model aggregation. We experimentally confirm the efficiency ofVerSAunder diverse datasets, demonstrating thatVerSAis orders of magnitude faster than verification in prior work.
Changhee Hahn, Hodong Kim, Minjae Kim 0008, Junbeom Hur
IEEE Trans. Dependable Secur. Comput.2
2022 Exploiting Metaobjects to Reinforce Data Leakage Attacks
abstract
Reflective features in modern programming languages allow programs to introspect and modify their own structures and behavior during runtime. As these self-referential capabilities are frequently adopted in practice, security of the reflective systems becomes crucial. In this paper, we explore an adversary against reflective systems with access to a data leakage channel, which has previously been considered impractical to pose a realistic threat. In particular, we show that a crucial component of reflection, referred to as metaobjects, can be exploited to reinforce these data leakage channels. We introduce a novel attack strategy that exploits certain metaobjects as in-memory gadgets to leak data in a selective and target-oriented manner, consequentially eliminating the unnecessary sampling procedures inevitable in naive data leakage attacks. Such approach significantly optimizes the data space subject to extraction, elevating the practicality of the underlying data leakage channel. As an instantiation of our strategy, we propose and demonstrate SMDL, a framework that exploits reflection to reinforce Meltdown-type attacks to steal valuable data from the victim’s memory. To demonstrate the efficacy of our attack, we implement SMDL against two different target applications, cryptographic library and deep learning service, and show that the secret key and neural network can be extracted with high accuracy and efficiency. Finally, we suggest metaobject obfuscation techniques to mitigate such exploitation.
Hoyong Jeong, Hodong Kim, Junbeom Hur
RAID2