VLDB 2026 Research / reviewers in the wild / expert
Young-joo Shin
dblp:33/2332 · also Youngjoo Shin
· DBLP profile ↗
27ranked-venue papers
8as first author
11since 2021 · last 2026
0000-0003-4831-7392ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 10 since 2021Computer networks · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SysDiver: Lightweight and Fast Static Analysis for Windows Kernel Drivers
Chanhee Park, Young-joo Shin |
AsiaCCS | 3 |
| 2026 | A systematic survey of side-channel attack surfaces in Intel TDX
Young-joo Shin |
Comput. Secur. | 2 |
| 2025 | MimicCall: Bypassing System Call Filters via Kernel Function RedundancyabstractModern operating systems often employ system call filtering to limit untrusted code's access to kernel resources, thereby reducing the kernel attack surface. However, existing filters operate at the system call interface level and often overlook the internal reuse of kernel functions across multiple system calls. This paper identifies and systematically analyzes a class of filter bypasses we term Mimic Calls, wherein alternative, permitted system calls invoke the same vulnerable functions as restricted ones. We present an automated analysis framework that traces syscall-to-function mappings using ftrace, leveraging system calls' test cases to cover diverse system call behaviors, using Syzkaller. Our evaluation of a recent Linux kernel demonstrates that even semantically distinct system calls share extensive kernel logic, and that thousands of patched CVE functions are accessible via multiple call paths. We further analyze filters generated by five representative tools and show that all tools are exposed of vulnerable functions through allowed MimicCalls. Case studies on CVE-2016-4486, CVE-2016-9793, and CVE-2017-7184 validate the practical impact of our findings, demonstrating that real-world exploits can be adapted to bypass filtering. Our results reveal a fundamental limitation in system call level defenses and underscore the need for more semantically informed filtering strategies. Songah Joo, Minchan Park, Hyerean Jang, Young-joo Shin |
ACSAC | 4 |
| 2025 | Vulnerable Intel GPU Context: Prohibit Complete Context Restore by Modifying Kernel Driver
Young-joo Shin |
AsiaCCS | 2 |
| 2025 | Cache Demote for Fast Eviction Set Construction and Page Table Attribute Leakage
Hyerean Jang, Young-joo Shin |
ESORICS (3) | 3 |
| 2025 | T-Time: A Fine-Grained Timing-Based Controlled-Channel Attack Against Intel TDX
Woomin Lee, Seunghee Shin, Junbeom Hur, Young-joo Shin |
ESORICS (3) | 5 |
| 2024 | POSTER: On the Feasibility of Inferring SGX Execution through PMUabstractIntel SGX is a power technology designed to establish a trusted execution environment on processors. Despite its promising features, there are various potential attack surfaces like the Performance Monitoring Unit (PMU) that could be exploited to extract security-sensitive data from SGX enclaves. To address this security threat, Intel has introduced anti side-channel interface (ASCI) that disables the PMU when an SGX enclave is running. However, little attention has been paid to performing the security evaluation of the ASCI feature, leaving the possibility of reviving such an attack. In this paper, we study if Intel's ASCI feature truly hides the internal execution state of SGX enclaves from the PMU to completely eliminate PMU-driven attack surfaces. To achieve this, we design a novel framework that investigates the effect of the running enclave on all possible performance monitoring events. The key idea of our framework is to (i) analyze the linearity between the number of instructions executed within an enclave and the corresponding measured events and (ii) perform single-stepping and zero-stepping attacks with performance monitoring events. Our security evaluation demonstrates that SGX enclave does not leave any footprint on PMUs, except for opt-in (i.e., debug) enclave where a hardware-based protection mechanism is not supported. Woomin Lee, Young-joo Shin |
AsiaCCS | 3 |
| 2024 | SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconabstractApple silicon is the proprietary ARM-based processor that powers the mainstream of Apple devices. The move to this proprietary architecture presents unique challenges in addressing security issues, requiring huge research efforts into the security of Apple silicon-based systems. In this paper, we study the security of KASLR, the randomization-based kernel hardening technique, on the state-of-the-art macOS system equipped with Apple silicon processors. Because KASLR has been subject to many microarchitectural side-channel attacks, the latest operating systems, including macOS, use kernel isolation, which separates the kernel page table from the userspace table. Kernel isolation in macOS provides a barrier to KASLR break attacks. To overcome this, we exploit speculative execution in system calls. By using Spectre-type gadgets in system calls, an unprivileged attacker can cause translations of the attacker's chosen kernel addresses, causing the TLB to change according to the validity of the address. This allows the construction of an attack primitive that breaks KASLR bypassing kernel isolation. Since the TLB is used as a side-channel source, we reverse-engineer the hidden internals of the TLB on various M-series processors using a hardware performance monitoring unit. Based on our attack primitive, we implement SysBumps, the first KASLR break attack on macOS for Apple silicon. Throughout evaluation, we show that SysBumps can effectively break KASLR across different M-series processors and macOS versions. We also discuss possible mitigations against the proposed attack. Hyerean Jang, Young-joo Shin |
CCS | 3 |
| 2024 | Deep Learning-Based Detection for Multiple Cache Side-Channel AttacksabstractA cache side-channel attack retrieves victim’s sensitive information from a system by exploiting shared cache of CPUs. Since conventional cache side-channel attacks such as FLUSH+RELOAD and PRIME+PROBE are likely to incur numerous cache events, such as cache hits and misses, many previous strategies have focused on monitoring cache events for attack detection. However, as recently proposed attacks such as PRIME+ABORT have exploited the other events as side-channels, it has become challenging to detect them by monitoring only cache events. In this paper, we investigate PRIME+ABORT attack and identifies Intel TSX hardware events are tightly coupled with it as well as cache events. Based on our finding, we propose a novel deep learning-based cache side-channel attack detection method called FRIME. It can concurrently detect not only the conventional attacks such as FLUSH+RELOAD, PRIME+PROBE, but also PRIME+ABORT by leveraging both event types. In order to demonstrate the efficacy of our cache side-channel attack detection scheme in diverse workload conditions in the real world, we implement it using MLP, RNN, and LSTM deep learning models, demonstrating LSTM-based method outperforms the other implementations in terms of detection accuracy. Hodong Kim, Changhee Hahn, Hyunwoo J. Kim, Young-joo Shin, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | DevIOus: Device-Driven Side-Channel Attacks on the IOMMUabstractModern computer systems take advantage of Input/Output Memory Management Unit (IOMMU) to protect memory from DMA attacks, or to achieve strong isolation in virtualization. Despite its promising benefits, the IOMMU could be a new source of security threats. Like the MMU, the IOMMU also has Translation Lookaside Buffer (TLB) named IOTLB, an address translation cache that keeps the recent translations. Accordingly, the IOTLB can be a target of a timing side-channel attack, revealing victim’s secret. In this paper, we present DevIOus, a novel device-driven side-channel attack exploiting the IOTLB. DevIOus employs DMA-capable PCIe devices, such as GPU and RDMA-enabled NIC (RNIC), to deliver the attack. Thus, our attack has no influence on CPU caches or TLB in a victim’s machine. Implementing DevIOus is not trivial as microarchitectural internals of the IOTLB of Intel processors are hidden. We overcome this by reverse-engineering the IOTLB and disclose its hidden architectural properties. Based on this, we construct two IOTLB-based timing attack primitives using a GPU and an RNIC. Then, we demonstrate practical attacks that target co-located VMs under hardware-assisted isolation, and remote machines connected over the RDMA network. We also discuss possible mitigations against the proposed side-channel attack. Hyeongjin Park, Seokmin Lee, Seunghee Shin, Junbeom Hur, Young-joo Shin |
SP | 6 |
| 2022 | Avengers, Assemble! Survey of WebAssembly Security SolutionsabstractWebAssembly, abbreviated as Wasm, has emerged as a new paradigm in cloud-native developments owing to its promising properties. Native execution speed and fast startup time make Wasm an alternative for container-based cloud applications. Despite its security-by-design strategy, however, WebAssembly suffers from a variety of vulnerabilities and weaknesses, which hinder its rapid adoption in cloud computing. For instance, the native execution performance attracted cybercriminals to abuse Wasm binaries for the purpose of resource stealing such as cryptojacking. Without proper defense mechanisms, Wasm-based malware would proliferate, causing huge financial loss of cloud users. Moreover, the design principle that allows type-unsafe languages such as C/C++ inherently induces various memory bugs in an Wasm binary. Efficient and robust vulnerability analysis techniques are necessary to protect benign cloud-native Wasm applications from being exploited by attackers. Due to the young age of WebAssembly, however, there are few works in the literature that provide developers guidance to such security techniques. This makes developers to hesitate considering Wasm as their cloud-native platform. In this paper, we surveyed various techniques and methods for Wasm binary security proposed in the literature and systematically classified them according to certain criteria. As a result, we propose future research directions regarding the current lack of WebAssembly binary security research. Hyerean Jang, Young-joo Shin |
CLOUD | 3 |
| 2020 | POSTER: Mitigating Memory Sharing-based Side-channel Attack by Embedding Random Values in Binary for Cloud EnvironmentabstractMemory deduplication is a technique that eliminates duplicate physical pages among virtual machines (VMs). Despite the advantage of efficient memory utilization in cloud computing, it leads to memory sharing-based side-channel attacks. Accordingly, most cloud service providers nowadays disable the memory deduplication on their servers to mitigate threats of the attacks, which comes at the cost of the efficiency loss. In this paper, we propose a novel mitigation technique for cloud computing environments against memory sharing-based side-channel attacks. Our technique converts vulnerable applications to secure ones that resist against the attacks. In particular, we utilize binary instrumentation to embed a secret random value inside an executable binary of the application. The random value will prevent memory sharing of security-sensitive applications with other from different security domains. On the other hand, the application-specific approach allows the systemwide memory deduplication, which preserves the efficient memory usage. We present the design and implementation of proposed mitigation as well as its evaluation results. Young-joo Shin |
AsiaCCS | 2 |
| 2020 | Return of version downgrade attack in the era of TLS 1.3abstractTransport Layer Security (TLS) protocol is often vulnerable to version downgrade attacks, where a man-in-the-middle attacker interferes with the handshake protocol and leads the communicating parties to fall back from a higher version of TLS to lower ones, which are typically provided for backward compatibility. Sangtae Lee, Young-joo Shin, Junbeom Hur |
CoNEXT | 2 |
| 2020 | Inferring Firewall Rules by Cache Side-channel Analysis in Network Function VirtualizationabstractNetwork function virtualization takes advantage of virtualization technology to achieve flexibility in network service provisioning. However, it comes at the cost of security risks caused by cache side-channel attacks on virtual machines. In this study, we investigate the security impact of these attacks on virtualized network functions. In particular, we propose a novel cache-based reconnaissance technique against virtualized Linux-based firewalls. The proposed technique has significant advantages in the perspective of attackers. First, it enhances evasiveness against intrusion detection owing to the ability of source spoofing. Second, it allows inference on a wide variety of filtering rules. During experiment in VyOS, the proposed method could infer the firewall rules with an accuracy of more than 90% by using only a few dozen packets. We also present countermeasures to mitigate cache-based attacks on virtualized network functions. Young-joo Shin, Dongyoung Koo, Junbeom Hur |
INFOCOM | 1 |
| 2020 | Toward Serverless and Efficient Encrypted Deduplication in Mobile Cloud Computing EnvironmentsabstractWith the proliferation of new mobile devices, mobile cloud computing technology has emerged to provide rich computing and storage functions for mobile users. The explosive growth of mobile data has led to an increased demand for solutions that conserve storage resources. Data deduplication is a promising technique that eliminates data redundancy for storage. For mobile cloud storage services, enabling the deduplication of encrypted data is of vital importance to reduce costs and preserve data confidentiality. However, recently proposed solutions for encrypted deduplication lack the desired level of security and efficiency. In this paper, we propose a novel scheme for serverless efficient encrypted deduplication (SEED) in mobile cloud computing environments. Without the aid of additional servers, SEED ensures confidentiality, data integrity, and collusion resistance for outsourced data. The absence of dedicated servers increases the effectiveness of SEED for mobile cloud storage services, in which user mobility is essential. In addition, noninteractive file encryption with the support of lazy encryption greatly reduces latency in the file-upload process. The proposed indexing structure (D-tree) supports the deduplication algorithm and thus makes SEED much more efficient and scalable. Security and performance analyses prove the efficiency and effectiveness of SEED for mobile cloud storage services. Young-joo Shin, Junbeom Hur, Dongyoung Koo, Joobeom Yun |
Secur. Commun. Networks | 1 |
| 2020 | Decentralized Server-Aided Encryption for Secure Deduplication in Cloud StorageabstractCloud storage provides scalable and low cost resources featuring economies of scale based on multi-tenant architecture. As the amount of data outsourced grows explosively, data deduplication, a technique that eliminates data redundancy, becomes essential. However, deduplication leads to problems with data confidentiality, thereby necessitating secure deduplication solutions. Server-aided encryption schemes have been proposed to achieve the strongest confidentiality but with the cost of managing a key server (KS). Previous schemes, however, are based on a centralized KS that uses only a single secret key assuming a single KS in the system. In cloud storage where multi-tenancy and scalability are crucial, such schemes degrade not only the effectiveness of deduplication but also the scalability with increasing users. In this paper, we extend server-aided encryption to a decentralized setting that consists of multiple KSs. The key idea of our proposed scheme is to construct an inter-KS deduplication algorithm, by which a cloud storage service provider can perform deduplication over ciphertexts from different KSs within a tenant or across tenants. This way, our scheme simultaneously offers flexibility of KS management and cross-tenant deduplication over encrypted data. The novelty of the approach is using a decentralized architecture that does not require any centralized entities for the coordination or pre-sharing of secrets among KSs. Therefore, it allows cloud storage services to offer high deduplication efficiency and scalability while preserving strong data confidentiality. We show the result of performance analysis on the proposed scheme by conducting extensive experiments. In addition, our security analysis demonstrate that the proposed scheme satisfies all desired security properties. Young-joo Shin, Dongyoung Koo, Joobeom Yun, Junbeom Hur |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | High Efficiency, Low-noise Meltdown Attack by using a Return Stack BufferabstractMeltdown attack exploits out-of-order execution in modern micro-architectures to extract sensitive data in kernel space of operating systems. Out-of-order execution opens a window of transient execution in which unauthorized access to kernel space is allowed. The original Meltdown attack utilizes an OS signal handler and hardware transactional memory support (e.g., Intel TSX) to create transient executions. Both methods, however, restrict the effectiveness of the attack due to a large amount of system noise from signal handlers and a limited number of processors that support TSX. To overcome this limitation, we propose a new variant of Meltdown attack by using a return stack buffer (RSB). Without the aid of TSX, the proposed attack introduces lower level of noise than the signal handler-based method, which broadens the impact of Meltdown attacks to a wide range of processors. We conclude this paper by presenting several countermeasures against the proposed attack. Young-joo Shin |
AsiaCCS | 2 |
| 2018 | Privacy-Preserving and Updatable Block-Level Data Deduplication in Cloud Storage ServicesabstractTo achieve high storage saving, data deduplication techniques are widely used in many practical cloud storage services, which removes redundant data and keeps only a single copy of them. However, secure data deduplication over encrypted data is challenging since encryption may result in different ciphertexts even when the original messages are the same. Thus, message-locked encryption (MLE) is proposed to solve this issue and demonstrates that it is secure under the unpredictable message set. Since block-level deduplication can achieve more fine-grained storage saving, several block-level deduplication schemes that support updatability are also vividly proposed. However, the previous updatable block-level MLE schemes are vulnerable against brute-force attack when the message set is predictable. Since the size of a block is typically much less than an arbitrary size of a file, the predictability problem is a very important pragmatic concern which should be addressed in the block-level deduplication literature. In this paper, thus, we propose a novel secure block-level deduplication scheme that guarantees efficient data update and brute-force attack resilience even when messages are predictable with the rigorous security proof. Also, our performance evaluation shows that additional time and bandwidth usage can be minimized as the size of a block increases. Hyungjune Shin, Dongyoung Koo, Young-joo Shin, Junbeom Hur |
IEEE CLOUD | 3 |
| 2018 | Unveiling Hardware-based Data Prefetcher, a Hidden Source of Information LeakageabstractData prefetching is a hardware-based optimization mechanism used in most of the modern microprocessors. It fetches data to the cache before it is needed. In this paper, we present a novel microarchitectural attack that exploits the prefetching mechanism. Our attack targets Instruction pointer (IP)-based stride prefetching in Intel processors. Stride prefetcher detects memory access patterns with a regular stride, which are likely to be found in lookup table-based cryptographic implementations. By monitoring the prefetching activities near the lookup table, attackers can extract sensitive information such as secret keys from victim applications. This kind of leakage from prefetching has never been considered in the design of constant time algorithm to prevent side-channel attacks. We show the potential of the proposed attack by applying it against the Elliptic Curve Diffie-Hellman (ECDH) algorithm built upon the latest version of OpenSSL library. To the best of our knowledge, this is the first microarchitectural side-channel attack exploiting the hardware prefetching of modern microprocessors. Young-joo Shin, Hyung Chan Kim, Dokeun Kwon, Ji-Hoon Jeong, Junbeom Hur |
CCS | 1 |
| 2017 | Secure Data Deduplication with Dynamic Ownership Management in Cloud StorageabstractIn cloud services, deduplication technology is commonly used to reduce the space and bandwidth requirements services by eliminating redundant data and storing only single copy. Deduplication is most effective when multiple users outsource the same data to the cloud storage, but raises issues relating to security and ownership. Proof-of-ownership schemes allow any owner of the same data to prove to the cloud storage server that he owns the data in a robust way. However, if encrypted data is outsourced into the cloud storage and the ownership changes dynamically, deduplication would be hampered. Thus, we propose a secure deduplication scheme that supports dynamic ownership management based on randomized convergent encryption in this study. Junbeom Hur, Dongyoung Koo, Young-joo Shin, Kyungtae Kang |
ICDE | 3 |
| 2017 | An Online Data-Oriented Authentication Based on Merkle Tree with Improved ReliabilityabstractIn this paper, we examine the online authentication method based on Merkle (hash) tree focusing on its reliability. Coming from side channels in online authentication, the effectiveness runs into danger in the long run. With consideration of effectiveness, we present a Merkle tree based online authentication resilient against side channels by obfuscating authentication proofs. Security and efficiency are analyzed to demonstrate the practicality of the proposed approach. Dongyoung Koo, Young-joo Shin, Joobeom Yun, Junbeom Hur |
ICWS | 2 |
| 2017 | Secure proof of storage with deduplication for cloud storage systems
Young-joo Shin, Dongyoung Koo, Junbeom Hur, Joobeom Yun |
Multim. Tools Appl. | 1 |
| 2016 | A Hybrid Deduplication for Secure and Efficient Data Outsourcing in Fog ComputingabstractWith prevalence of remote storage services, data privacy issues become more serious owing to loss of control to outsourced data. In the meanwhile, the service providers tend to minimize storage utility costs. To minimize the storage costs while preserving data privacy, secure deduplication techniques have been proposed, which are categorized into client-side or server-side approaches. Client-side approach achieves storage and bandwidth savings at the same time but allows external adversaries to know existence of duplicates in the remote storage. On the contrary, server-side one prevents the adversaries from getting acknowledged but sacrifices network bandwidth savings. In fog computing, however, which is a new computing paradigm extending the cloud computing by outsourcing a centralized workload of the cloud to geographically distributed fog devices located at the edge of the networks, the previous deduplication schemes cannot guarantee efficiency improvement and privacy preservation simultaneously. In this paper, we present a simple but nontrivial solution of these contradictory issues in fog storage. The proposed hybrid secure deduplication protocol combines client-and server-side deduplications by taking untrustworthy fog storage environments into account. The client-side deduplication is applied in inter-network (i.e., cloud-fog network) communications to prevent network congestion at the network core, while the server-side deduplication is adopted in intra-network (i.e., user-fog network) communications to prevent information leakage via side channels for maximal data privacy. Performance and security analyses demonstrate the comparable efficiency of the proposed scheme with security enhancement. Dongyoung Koo, Young-joo Shin, Joobeom Yun, Junbeom Hur |
CloudCom | 2 |
| 2016 | SEED: Enabling Serverless and Efficient Encrypted Deduplication for Cloud StorageabstractData deduplication is a technique that removes redundancy of data on the storage. For cloud storage services, enabling deduplication over encrypted data is of vital importance to achieve both cost savings and keeping data confidentiality simultaneously. Recently proposed solutions are not sufficient because of lacking desired level of security and efficiency. In this paper, we propose SEED, a novel scheme for serverless and efficient encrypted deduplication. Without aid of any additional servers, SEED provides strong confidentiality to the outsourced data. In addition, its non-interactive file encryption with support of lazy encryption greatly reduces latency in file uploading process. Security analysis and performance evaluations show the superior efficiency and effectiveness of SEED for cloud storage services. Young-joo Shin, Dongyoung Koo, Joobeom Yun, Junbeom Hur |
CloudCom | 1 |
| 2016 | Secure Data Deduplication with Dynamic Ownership Management in Cloud StorageabstractIn cloud storage services, deduplication technology is commonly used to reduce the space and bandwidth requirements of services by eliminating redundant data and storing only a single copy of them. Deduplication is most effective when multiple users outsource the same data to the cloud storage, but it raises issues relating to security and ownership. Proof-of-ownership schemes allow any owner of the same data to prove to the cloud storage server that he owns the data in a robust way. However, many users are likely to encrypt their data before outsourcing them to the cloud storage to preserve privacy, but this hampers deduplication because of the randomization property of encryption. Recently, several deduplication schemes have been proposed to solve this problem by allowing each owner to share the same encryption key for the same data. However, most of the schemes suffer from security flaws, since they do not consider the dynamic changes in the ownership of outsourced data that occur frequently in a practical cloud storage service. In this paper, we propose a novel server-side deduplication scheme for encrypted data. It allows the cloud server to control access to outsourced data even when the ownership changes dynamically by exploiting randomized convergent encryption and secure ownership group key distribution. This prevents data leakage not only to revoked users even though they previously owned that data, but also to an honest-but-curious cloud storage server. In addition, the proposed scheme guarantees data integrity against any tag inconsistency attack. Thus, security is enhanced in the proposed scheme. The efficiency analysis results demonstrate that the proposed scheme is almost as efficient as the previous schemes, while the additional computational overhead is negligible. Junbeom Hur, Dongyoung Koo, Young-joo Shin, Kyungtae Kang |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2015 | Differentially private client-side data deduplication protocol for cloud storage servicesabstractAbstract Cloud storage service providers apply data client‐side deduplication across multiple users to achieve cost savings of network bandwidth and disk storage. However, deduplication can be used as a side channel by attackers who try to obtain sensitive information of other users' data. We propose a differentially private client‐side deduplication protocol. A storage gateway allows efficient data deduplication while reducing the risk of information leakage. Its security can be strongly guaranteed according to the definition of differential privacy. We evaluate the effectiveness and efficiency of the proposed protocol through experiments. Copyright © 2014 John Wiley & Sons, Ltd. Young-joo Shin, Kwangjo Kim |
Secur. Commun. Networks | 1 |
| 2012 | Scalable and efficient approach for secure group communication using proxy cryptography
Young-joo Shin, Junbeom Hur |
Wirel. Networks | 1 |