VLDB 2026 Research / reviewers in the wild / expert
Sunpill Kim
dblp:289/5983
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0002-7767-4084ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Reversibility of Locality-Sensitive Hashing-Based Biometric Template ProtectionsabstractWith the extensive deployment of biometric authentication systems, the need for biometric template protection (BTP) has been widely recognized. Designing a secure yet efficient BTP is still a long-lasting challenge, and locality-sensitive hashing (LSH) is a promising building block for designing BTPs. In this study, we propose a novel pre-image attack applicable to lots of existing LSH-based BTPs, showing that many of them are in factreversible. Our attack leverages structural properties shared by several LSH-based BTPs. Through investigation, we formalize a certain class of LSHs vulnerable to our attack, calledPMA-LSH, which contains several known LSH-based BTPs, even not-yet-cryptanalyzed ones. Furthermore, the recovered pre-image from our attack is much closer to the original template compared to previous attacks, facilitating recovery of the original biometrics via reconstruction attacks. With existing reconstruction methods, we successfully recovered biometrics from templates protected by several LSH-based BTPs. The recovered biometrics sufficiently resemble the original ones, so they can be further exploited to impersonate other recognition systems, including commercial APIs. To facilitate further study, our source code is publicly available athttps://github.com/Cryptology-Algorithm-Lab/Analysis_LSH. Seunghun Paik, Chanwoo Hwang, Sunpill Kim, Jae Hong Seo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | IDFace: Face Template Protection for Efficient and Secure IdentificationabstractAs face recognition systems (FRS) become more widely used, user privacy becomes more important. A key privacy issue in FRS is protecting the user's face template, as the characteristics of the user's face image can be recovered from the template. Although recent advances in cryptographic tools such as homomorphic encryption (HE) have provided opportunities for securing the FRS, HE cannot be used directly with FRS in an efficient plug-and-play manner. In particular, although HE is functionally complete for arbitrary programs, it is basically designed for algebraic operations on encrypted data of predetermined shape, such as a polynomial ring. Thus, a non-tailored combination of HE and the system can yield very inefficient performance, and many previous HE-based face template protection methods are hundreds of times slower than plain systems without protection. In this study, we propose IDFace, a new HE-based secure and efficient face identification method with template protection. IDFace is designed on the basis of two novel techniques for efficient searching on a (homomorphically encrypted) biometric database with an angular metric. The first technique is a template representation transformation that sharply reduces the unit cost for the matching test. The second is a space-efficient encoding that reduces wasted space from the encryption algorithm, thus saving the number of operations on encrypted templates. Through experiments, we show that IDFace can identify a face template from among a database of 1M encrypted templates in 126ms, showing only 2X overhead compared to the identification over plaintexts. Sunpill Kim, Seunghun Paik, Chanwoo Hwang, Dongsoo Kim 0004, Jun-Bum Shin, Jae Hong Seo |
ICCV | 1 |
| 2025 | Non-Adaptive Adversarial Face GenerationabstractAdversarial attacks on face recognition systems (FRSs) pose serious security and privacy threats, especially when these systems are used for identity verification. In this paper, we propose a novel method for generating adversarial faces—synthetic facial images that are visually distinct yet recognized as a target identity by the FRS. Unlike iterative optimization-based approaches (e.g., gradient descent or other iterative solvers), our method leverages the structural characteristics of the FRS feature space. We figure out that individuals sharing the same attribute (e.g., gender or race) form an attributed subsphere. By utilizing such subspheres, our method achieves both non-adaptiveness and a remarkably small number of queries. This eliminates the need for relying on transferability and open-source surrogate models, which have been a typical strategy when repeated adaptive queries to commercial FRSs are impossible. Despite requiring only a single non-adaptive query consisting of 100 face images, our method achieves a high success rate of over 93% against AWS’s CompareFaces API at its default threshold. Furthermore, unlike many existing attacks that perturb a given image, our method can deliberately produce adversarial faces that impersonate the target identity while exhibiting high-level attributes chosen by the adversary. Sunpill Kim, Seunghun Paik, Chanwoo Hwang, Jae Hong Seo |
NeurIPS | 1 |
| 2025 | Deep face template protection in the wild
Sunpill Kim, Hoyong Shin, Jae Hong Seo |
Pattern Recognit. | 1 |
| 2024 | Towards Certifiably Robust Face Recognition
Seunghun Paik, Dongsoo Kim 0004, Chanwoo Hwang, Sunpill Kim, Jae Hong Seo |
ECCV (85) | 4 |
| 2024 | Scores Tell Everything about Bob: Non-adaptive Face Reconstruction on Face Recognition SystemsabstractFace recognition systems (FRSs) typically store databases of discriminative real-valued template vectors, which are extracted from each enrolled user’s facial image(s). Such template databases must be carefully protected for user privacy—indeed, the dangers of template leakages have been widely reported in the literature. In contrast, the similarity scores between queried images and enrolled users is often unprotected and can be readily queried through typical FRS APIs. Such scores provide a potential avenue of adversarial attack on FRSs, but recently proposed score-based attacks remain largely impractical because they essentially rely on trial-and-error strategies that use an enormous number of adaptive queries (>50K) for face reconstruction.We present the first practical score-based face reconstruction and impersonation attack against three commercial FRS APIs: AWS CompareFaces, FACE++, and KAIROS, as well as five commonly used pre-trained open-source FRSs. Our attack is carried out in the black-box FRS model, where the adversary has no knowledge of the FRS (underlying models, parameters, template databases, etc.), except for the ability to make a limited number of similarity score queries. Notably, the attack is straightforward to implement, requires no trial-and-error guessing, and uses a small number of nonadaptive score queries. We motivate the attack by analyzing the topological meaning of similarity scores and then present our novel method using orthogonal face sets: a precomputed approximate basis set of human-like face images that enables us to get meaningful similarity scores from a small number of non-adaptive queries. Our approach successfully reconstructs human-like impersonation images with >20% (resp. >96%) success rates across three test datasets when directly attacking the AWS CompareFaces API (resp. open-source CosFace FRS) using only 100 queries—up to two orders of magnitude fewer queries than previous approaches. We provide evidence that personally identifiable biometric features are captured in our reconstructions by evaluating our approach in transfer-like attack settings and through other image similarity metrics. Sunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal, Khin Mi Mi Aung, Jae Hong Seo |
SP | 1 |
| 2023 | Security Analysis on Locality-Sensitive Hashing-based Biometric Template Protection Schemes
Seunghun Paik, Sunpill Kim, Jae Hong Seo |
BMVC | 2 |
| 2021 | IronMask: Modular Architecture for Protecting Deep Face TemplateabstractConvolutional neural networks have made remarkable progress in the face recognition field. The more the technology of face recognition advances, the greater discriminative features into a face template. However, this increases the threat to user privacy in case the template is exposed.In this paper, we present a modular architecture for face template protection, called IronMask, that can be combined with any face recognition system using angular distance metric. We circumvent the need for binarization, which is the main cause of performance degradation in most existing face template protections, by proposing a new real-valued error-correcting-code that is compatible with real-valued templates and can therefore, minimize performance degradation. We evaluate the efficacy of IronMask by extensive experiments on two face recognitions, ArcFace and Cos-Face with three datasets, CMU-Multi-PIE, FEI, and Color-FERET. According to our experimental results, IronMask achieves a true accept rate (TAR) of 99.79% at a false accept rate (FAR) of 0.0005% when combined with ArcFace, and 95.78% TAR at 0% FAR with CosFace, while providing at least 115-bit security against known attacks. Sunpill Kim, Yunseong Jeong, Jungkon Kim, Hyung Tae Lee, Jae Hong Seo |
CVPR | 1 |