VLDB 2026 Research / reviewers in the wild / expert
Dohyun Ryu
dblp:285/1437
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Fuzzing Acceleration for Memory Safety Bug Discovery with SlicerabstractMemory safety bugs are major threats to software because they occupy 65%-70% of severe security bugs. Consequently, researchers have introduced directed fuzzers and directed coverage-guided fuzzers, which can target memory safety bugs. However, they waste much time testing uninteresting code that may not contain memory safety bugs. In this paper, we propose Slicer, a program slicing technique, to accelerate directed fuzzing targeting memory safety bugs. The key idea is to remove as many code snippets irrelevant to memory safety bugs from target programs as possible to minimize uninteresting code execution. For that, Slicer first identifies and keeps the code snippets, such as memory access code, memory management code (e.g., malloc), and relevant control flow statements, that potentially violate memory safety. Next, Slicer identifies and keeps extra code snippets, such as program initialization code, that are required to run programs. Finally, Slicer removes the other code snippets. This approach is beneficial to directed fuzzers when they target memory safety bugs because Slicer can improve performance orthogonal to the points that directed fuzzers improve. We evaluate Slicer with 24 programs and found ten new bugs with seven CVEs. Furthermore, Slicer accelerates program execution speed 1.61× faster. Moreover, Slicer shows 1.52× improved testing coverage for code relevant to memory safety bugs when integrated with directed coverage-guided and coverage-guided fuzzers, ParmeSan and Darwin. Finally, integrating Slicer with three directed fuzzers, AFLGo, WindRanger, and SelectFuzz shows 1.64× faster memory safety bug discovery than those fuzzers without Slicer. Giyeol Kim, Dohyun Ryu, Seungjin Bae, Changyul Lee, Taegyu Kim |
ACSAC | 2 |
| 2024 | Differential Fuzzing for Data Distribution Service Programs with Dynamic ConfigurationabstractData Distribution Service (DDS) is a distributed network protocol widely used in cyber-physical systems. DDS provides flexible configurations defined in the formal design specification for safety and security. However, DDS programs suffer from both semantic bugs violating design specifications and software implementation bugs. To discover bugs, network protocol fuzzers have focused on testing client-server models by mutating input packets. However, they are unsuitable for fuzzing DDS programs due to a lack of consideration of the DDS-specific features, such as the DDS-specific input spaces (e.g., dynamic network topology formation and QoS and DDS security configurations) and impacts of DDS-specific semantic bugs (e.g., incorrect topology construction). Dohyun Ryu, Giyeol Kim, Seungjin Bae, Junghwan Rhee, Taegyu Kim |
ASE | 1 |
| 2024 | $\gamma$γ-Knife: Extracting Neural Network Architecture Through Software-Based Power Side-ChannelabstractSeveral side-channel attacks exploiting timing, cache, or power side channels have recently been proposed to obtain private information of a neural network. However, the hardware-based attacks require physical access to the system, using high-precision equipment to measure physical system behaviors such as power consumption or electromagnetic emanations, to exploit them as side channels. Whereas, the previous software-based side-channel attacks on neural networks can extract their model information only when the target architecture is known. In this paper, we propose the$\gamma$-Knife attack, a software-based power side-channel attack on a neural network, which can extract its architecture without any physical access or high-precision measuring equipment. Our work demonstrates that side-channels can be formed that leak architecture of neural networks by utilizing statistical metrics without high-resolution power data. The$\gamma$-Knife attack can reduce the search space of candidate architectures by obtaining private information such as filter size, depth of convolutional layer, and activation functions in the target architecture, as accurately as hardware-based power side-channel attacks even when the target neural network is totally unknown. We demonstrated the efficacy of the$\gamma$-Knife attack by implementing the attack on the well-known neural networks VGGNet, ResNet, GoogleNet, and MobileNet, using the Pytorch library on Intel CPUs and AMD CPUs. The$\gamma$-Knife attack could identify the target neural network architecture with an accuracy of approximately 90%, and efficiently extract its private information, by significantly reducing the search space of the target architecture. Dohyun Ryu, Yerim Kim, Junbeom Hur |
IEEE Trans. Dependable Secur. Comput. | 1 |