Jae Hong Seo

dblp:38/6152 · DBLP profile ↗
← Back
37ranked-venue papers
10as first author
17since 2021 · last 2026
0000-0003-0547-5702ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 7 first-author · 9 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Theory of computation · 5 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Scalable Private Set Intersection over Distributed Encrypted Data
abstract
Finding intersections across sensitive data is a core operation in many real-world data-driven applications, such as healthcare, anti-money laundering, financial fraud, or watchlist applications. These applications often require large-scale collaboration across thousands or more independent sources, such as hospitals, financial institutions, or identity bureaus, where all records must remain encrypted during storage and computation, and are typically outsourced to dedicated/cloud servers. Such a highly distributed, large-scale, and encrypted setting makes it very challenging to apply existing solutions, e.g., (multi-party) private set intersection (PSI) or private membership test (PMT).
Seunghun Paik, Nirajan Koirala, Jack Nero, Hyunjung Son, Yunki Kim, Jae Hong Seo, Taeho Jung
AsiaCCS6
2026 Select-Then-Compute: Encrypted Label Selection and Analytics over Distributed Datasets using FHE
Nirajan Koirala, Seunghun Paik, Sam Martin, Helena Berens, Tasha Januszewicz, Jonathan Takeshita, Jae Hong Seo, Taeho Jung
NDSS7
2026 Toward Generating Unlearnable Examples for Open-Set Face Recognition
Seunghun Paik, Chanwoo Hwang, Jae Hong Seo
IEEE Signal Process. Lett.3
2026 On the Reversibility of Locality-Sensitive Hashing-Based Biometric Template Protections
abstract
With the extensive deployment of biometric authentication systems, the need for biometric template protection (BTP) has been widely recognized. Designing a secure yet efficient BTP is still a long-lasting challenge, and locality-sensitive hashing (LSH) is a promising building block for designing BTPs. In this study, we propose a novel pre-image attack applicable to lots of existing LSH-based BTPs, showing that many of them are in factreversible. Our attack leverages structural properties shared by several LSH-based BTPs. Through investigation, we formalize a certain class of LSHs vulnerable to our attack, calledPMA-LSH, which contains several known LSH-based BTPs, even not-yet-cryptanalyzed ones. Furthermore, the recovered pre-image from our attack is much closer to the original template compared to previous attacks, facilitating recovery of the original biometrics via reconstruction attacks. With existing reconstruction methods, we successfully recovered biometrics from templates protected by several LSH-based BTPs. The recovered biometrics sufficiently resemble the original ones, so they can be further exploited to impersonate other recognition systems, including commercial APIs. To facilitate further study, our source code is publicly available athttps://github.com/Cryptology-Algorithm-Lab/Analysis_LSH.
Seunghun Paik, Chanwoo Hwang, Sunpill Kim, Jae Hong Seo
IEEE Trans. Dependable Secur. Comput.4
2025 UTRA: Universal Token Reusability Attack and Token Unforgeable Delegatable Order-Revealing Encryption
Jaehwan Park, Hyeonbum Lee, Junbeom Hur, Jae Hong Seo, Doowon Kim
ESORICS (2)4
2025 IDFace: Face Template Protection for Efficient and Secure Identification
abstract
As face recognition systems (FRS) become more widely used, user privacy becomes more important. A key privacy issue in FRS is protecting the user's face template, as the characteristics of the user's face image can be recovered from the template. Although recent advances in cryptographic tools such as homomorphic encryption (HE) have provided opportunities for securing the FRS, HE cannot be used directly with FRS in an efficient plug-and-play manner. In particular, although HE is functionally complete for arbitrary programs, it is basically designed for algebraic operations on encrypted data of predetermined shape, such as a polynomial ring. Thus, a non-tailored combination of HE and the system can yield very inefficient performance, and many previous HE-based face template protection methods are hundreds of times slower than plain systems without protection. In this study, we propose IDFace, a new HE-based secure and efficient face identification method with template protection. IDFace is designed on the basis of two novel techniques for efficient searching on a (homomorphically encrypted) biometric database with an angular metric. The first technique is a template representation transformation that sharply reduces the unit cost for the matching test. The second is a space-efficient encoding that reduces wasted space from the encryption algorithm, thus saving the number of operations on encrypted templates. Through experiments, we show that IDFace can identify a face template from among a database of 1M encrypted templates in 126ms, showing only 2X overhead compared to the identification over plaintexts.
Sunpill Kim, Seunghun Paik, Chanwoo Hwang, Dongsoo Kim 0004, Jun-Bum Shin, Jae Hong Seo
ICCV6
2025 Non-Adaptive Adversarial Face Generation
abstract
Adversarial attacks on face recognition systems (FRSs) pose serious security and privacy threats, especially when these systems are used for identity verification. In this paper, we propose a novel method for generating adversarial faces—synthetic facial images that are visually distinct yet recognized as a target identity by the FRS. Unlike iterative optimization-based approaches (e.g., gradient descent or other iterative solvers), our method leverages the structural characteristics of the FRS feature space. We figure out that individuals sharing the same attribute (e.g., gender or race) form an attributed subsphere. By utilizing such subspheres, our method achieves both non-adaptiveness and a remarkably small number of queries. This eliminates the need for relying on transferability and open-source surrogate models, which have been a typical strategy when repeated adaptive queries to commercial FRSs are impossible. Despite requiring only a single non-adaptive query consisting of 100 face images, our method achieves a high success rate of over 93% against AWS’s CompareFaces API at its default threshold. Furthermore, unlike many existing attacks that perturb a given image, our method can deliberately produce adversarial faces that impersonate the target identity while exhibiting high-level attributes chosen by the adversary.
Sunpill Kim, Seunghun Paik, Chanwoo Hwang, Jae Hong Seo
NeurIPS5
2025 Deep face template protection in the wild
Sunpill Kim, Hoyong Shin, Jae Hong Seo
Pattern Recognit.3
2024 Towards Certifiably Robust Face Recognition
Seunghun Paik, Dongsoo Kim 0004, Chanwoo Hwang, Sunpill Kim, Jae Hong Seo
ECCV (85)5
2024 PrivHChain: Monitoring the Supply Chain of Controlled Substances with Privacy-Preserving Hierarchical Blockchain
abstract
With rapidly increasing drug abuse across the world, it is imperative to monitor their supply chain with sufficient transparency. Blockchain is a common solution for achieving transparency in supply chain monitoring, but it does not have sufficient throughput for large-scale supply chains. It is challenging to achieve throughput and privacy simultaneously because complex dependencies among the supply chain events and the need for aggregation both make the application of ZKP challenging. We present PrivHChain, a privacy-preserving hierarchical blockchain that preserves transaction privacy even against blockchain peers while allowing them to verify record consistencies. This is enabled by novel modeling of supply chain events which makes it possible to use novel efficient zero-knowledge protocol schemes to verify the complex dependencies. Novel aggregation techniques are proposed to enable the proof aggregation, and the proofs are used to design monitoring protocols. PrivHChain is implemented and validated with extensive experiments and simulations. The results indicate that (i) the extra overhead of encryption and ZKP schemes is acceptable or negligible, and (ii) the throughput is improved by up to 5 times in simulations even with all the encryption/ZKP schemes.
Hyeonbum Lee, Kyuhwan Lee, Wenyi Tang, Shankha Shubhra Mukherjee, Jae Hong Seo, Taeho Jung
ICBC5
2024 Scores Tell Everything about Bob: Non-adaptive Face Reconstruction on Face Recognition Systems
abstract
Face recognition systems (FRSs) typically store databases of discriminative real-valued template vectors, which are extracted from each enrolled user’s facial image(s). Such template databases must be carefully protected for user privacy—indeed, the dangers of template leakages have been widely reported in the literature. In contrast, the similarity scores between queried images and enrolled users is often unprotected and can be readily queried through typical FRS APIs. Such scores provide a potential avenue of adversarial attack on FRSs, but recently proposed score-based attacks remain largely impractical because they essentially rely on trial-and-error strategies that use an enormous number of adaptive queries (>50K) for face reconstruction.We present the first practical score-based face reconstruction and impersonation attack against three commercial FRS APIs: AWS CompareFaces, FACE++, and KAIROS, as well as five commonly used pre-trained open-source FRSs. Our attack is carried out in the black-box FRS model, where the adversary has no knowledge of the FRS (underlying models, parameters, template databases, etc.), except for the ability to make a limited number of similarity score queries. Notably, the attack is straightforward to implement, requires no trial-and-error guessing, and uses a small number of nonadaptive score queries. We motivate the attack by analyzing the topological meaning of similarity scores and then present our novel method using orthogonal face sets: a precomputed approximate basis set of human-like face images that enables us to get meaningful similarity scores from a small number of non-adaptive queries. Our approach successfully reconstructs human-like impersonation images with >20% (resp. >96%) success rates across three test datasets when directly attacking the AWS CompareFaces API (resp. open-source CosFace FRS) using only 100 queries—up to two orders of magnitude fewer queries than previous approaches. We provide evidence that personally identifiable biometric features are captured in our reconstructions by evaluating our approach in transfer-like attack settings and through other image similarity metrics.
Sunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal, Khin Mi Mi Aung, Jae Hong Seo
SP6
2023 Security Analysis on Locality-Sensitive Hashing-based Biometric Template Protection Schemes
Seunghun Paik, Sunpill Kim, Jae Hong Seo
BMVC3
2023 On the security of functional encryption in the generic group model
Hyung Tae Lee, Jae Hong Seo
Des. Codes Cryptogr.2
2023 Leopard: Sublinear Verifier Inner Product Argument Under Discrete Logarithm Assumption
abstract
An inner product (IP) argument is a proof system that convinces the verifier of an IP relation between committed integer vectors. IP arguments are crucial building blocks for range proof and zero knowledge arguments, which can be applied to verifiable computation, confidential transactions, decentralized identification, and so on. This paper proposes a novel efficient IP argument with a trustless setup. For integer vectors of size N, the proposed IP argument provides a proof size of O(log2 N), a verification cost of O(√N), and a size of public parameter size of O(√N). The construction uses bilinear pairings and its security relies solely on the discrete logarithm (DL) assumption, a well-established standard cryptographic assumption. Consequently, we obtain the first DL-based IP argument with a trustless setup that achieves a sublinear verifier and logarithmic proof size, which we call Leopard. Furthermore, We empirically evaluate the performance of Leopard. The experimental results demonstrate that Leopard is highly efficient and scalable compared to previous works.
Sungwook Kim 0001, Gwangwoon Lee, Hyeonbum Lee, Jae Hong Seo
IEEE Trans. Inf. Forensics Secur.4
2022 Efficient Zero-Knowledge Arguments in Discrete Logarithm Setting: Sublogarithmic Proof or Sublinear Verifier
Sungwook Kim 0001, Hyeonbum Lee, Jae Hong Seo
ASIACRYPT (2)3
2021 IronMask: Modular Architecture for Protecting Deep Face Template
abstract
Convolutional neural networks have made remarkable progress in the face recognition field. The more the technology of face recognition advances, the greater discriminative features into a face template. However, this increases the threat to user privacy in case the template is exposed.In this paper, we present a modular architecture for face template protection, called IronMask, that can be combined with any face recognition system using angular distance metric. We circumvent the need for binarization, which is the main cause of performance degradation in most existing face template protections, by proposing a new real-valued error-correcting-code that is compatible with real-valued templates and can therefore, minimize performance degradation. We evaluate the efficacy of IronMask by extensive experiments on two face recognitions, ArcFace and Cos-Face with three datasets, CMU-Multi-PIE, FEI, and Color-FERET. According to our experimental results, IronMask achieves a true accept rate (TAR) of 99.79% at a false accept rate (FAR) of 0.0005% when combined with ArcFace, and 95.78% TAR at 0% FAR with CosFace, while providing at least 115-bit security against known attacks.
Sunpill Kim, Yunseong Jeong, Jungkon Kim, Hyung Tae Lee, Jae Hong Seo
CVPR6
2021 Efficient revocable identity-based encryption with short public parameters
abstract
Revocation functionality is vital to real-world cryptographic systems for managing their reliability. In the context of identity-based encryption (IBE), Boldyreva, Goyal, and Kumar (ACM CCS 2008) first showed an efficient revocation method for IBE, and such an IBE scheme with the scalable revocation method is called revocable IBE (RIBE). Seo and Emura (PKC 2013) introduced a new security notion, called decryption key exposure resistance (DKER), which is a desirable security notion for RIBE. However, all existing RIBE schemes that achieve adaptive security with DKER require long public parameters or composite-order bilinear groups. In this paper, we first show an RIBE scheme that (1) satisfies adaptive security; (2) achieves DKER; (3) realizes constant-size public parameters; and (4) is constructed over prime-order bilinear groups. Our core technique relies on Seo and Emura's one (PKC 2013), which transform the Waters IBE (EUROCRYPT 2005) to the corresponding RIBE scheme. Specifically, we construct an IBE scheme that satisfies constant-size public parameters over prime-order groups and some requirements for the Seo-Emura technique, and then transform the IBE scheme to an RIBE scheme. We also discuss how to extend the proposed RIBE scheme to a chosen-ciphertext secure one and server-aided one (ESORICS 2015).
Keita Emura, Jae Hong Seo, Yohei Watanabe 0001
Theor. Comput. Sci.2
2020 Public key encryption with equality test in the standard model
Hyung Tae Lee, San Ling, Jae Hong Seo, Huaxiong Wang, Taek-Young Youn
Inf. Sci.3
2020 Efficient digital signatures from RSA without random oracles
Jae Hong Seo
Inf. Sci.1
2019 Public key encryption with equality test from generic assumptions in the random oracle model
abstract
Public key encryption with equality test (PKEET) is a variant of classical public key encryption (PKE) with the special functionality of an equality test, and can be used in many applications such as in keyword search on encrypted data and for efficient management by partitioning encrypted data in the cloud. Since the original proposal of Yang et al. (CT-RSA, 2010), several subsequent proposals to improve the efficiency or functionality of PKEET have been reported. We present a PKEET construction from generic assumptions in the random oracle model . In particular, whereas previous results require number-theoretic assumptions or strictly stronger generic assumptions such as the existence of secure hierarchical identity-based encryption, our proposal requires only the existence of cryptographic hash functions and secure PKE schemes satisfying a special property , called randomness extractability . Informally, randomness extractability means that one can recover the randomness used in a ciphertext when given a secret key corresponding to a public key for the ciphertext . We investigate the fact that PKE schemes satisfying this property can be designed by the Fujisaki-Okamoto (FO) transformation, which is the widely utilized method to obtain secure PKE schemes from basic cryptographic primitives in the random oracle model . As a result, in combination with the FO transformation, we obtain a PKEET construction in the random oracle model if there exist a one-way PKE scheme, a one-time secure symmetric key encryption scheme , collision-resistant and one-way hash functions , and a pseudorandom function. In this sense, we remark that our PKEET construction is derived from fundamental generic assumptions only.
Hyung Tae Lee, San Ling, Jae Hong Seo, Huaxiong Wang
Inf. Sci.3
2019 A new approach to practical function-private inner product encryption
Sungwook Kim 0001, Jae Hong Seo
Theor. Comput. Sci.3
2018 A new scale-invariant homomorphic encryption scheme
Sungwook Kim 0001, Jae Hong Seo
Inf. Sci.3
2017 New Revocable IBE in Prime-Order Groups: Adaptively Secure, Decryption Key Exposure Resistant, and with Short Public Parameters
Yohei Watanabe 0001, Keita Emura, Jae Hong Seo
CT-RSA3
2017 Short Signatures from Diffie-Hellman: Realizing Almost Compact Public Key
Jae Hong Seo
J. Cryptol.1
2016 CCA2 Attack and Modification of Huang et al.'s Public Key Encryption with Authorized Equality Test
abstract
In this article, we identify a flaw in Huang et al.'s public key encryption with authorized equality test (The Computer Journal, 2015). More precisely, we point out that the proof of the indistinguishability under adaptive chosen ciphertext attack (IND-CCA2) security for their scheme has a serious flaw. We illustrate this flaw by presenting a polynomial time CCA2 attack on their scheme. We also provide a solution to correct this flaw by modifying their scheme slightly. Our solution is quite efficient because it provides security against CCA2 attack by exploiting only the hash computation of a two times longer input without any increase in the sizes of ciphertexts and warrants.
Hyung Tae Lee, San Ling, Jae Hong Seo, Huaxiong Wang
Comput. J.3
2016 Semi-generic construction of public key encryption and identity-based encryption with equality test
abstract
Public key encryption with equality test (PKEET), which was first introduced by Yang et al. (CT-RSA, 2010), has various applications including facilitating keyword search on encrypted data and partitioning encrypted data on the cloud. It can be also applied to manage personal health records on the internet. For these reasons, there have been improvements on earlier PKEET schemes in terms of performance and functionality. We present a semi-generic method for PKEET constructions, assuming only the existence of IND-CCA2 secure traditional public key encryption (PKE) schemes, the hardness of Computational Diffie-Hellman (CDH) problems, and random oracles. Our approach has several advantages; it enables us to understand requirements for the equality test functionality more clearly. Furthermore, our approach is quite general, in that if we change the underlying PKE scheme with the identity-based encryption (IBE) scheme (and we assume the hardness of Bilinear Diffie-Hellman problems instead of CDH), then we obtain the first IBE scheme with equality test (IBEET) satisfying analogous security arguments to those of PKEET. Although an IBEET construction was recently proposed, but we note that it satisfies only weak security requirements.
Hyung Tae Lee, San Ling, Jae Hong Seo, Huaxiong Wang
Inf. Sci.3
2016 Revocable hierarchical identity-based encryption via history-free approach
Jae Hong Seo, Keita Emura
Theor. Comput. Sci.1
2015 Accumulable Optimistic Fair Exchange from Verifiably Encrypted Homomorphic Signatures
Jae Hong Seo, Keita Emura, Keita Xagawa, Kazuki Yoneyama
ACNS1
2015 Revocable Hierarchical Identity-Based Encryption: History-Free Update, Security Against Insiders, and Short Ciphertexts
Jae Hong Seo, Keita Emura
CT-RSA1
2014 A New Additive Homomorphic Encryption based on the co-ACD Problem
abstract
We propose an efficient additive homomorphic encryption scheme. In our scheme, an encryption of a message is simply its noisy modular reduction by several different moduli. The security of our scheme relies on the hardness of a new problem, the co-Approximate Common Divisor problem. We analyze its hardness by applying all known attacks and devising dedicated attacks. These analyses are not complete, but give sufficiently plausible evidence for the hardness of this new problem.
Jung Hee Cheon, Hyung Tae Lee, Jae Hong Seo
CCS3
2014 Security Analysis of Multilinear Maps over the Integers
Hyung Tae Lee, Jae Hong Seo
CRYPTO (1)2
2014 Revocable hierarchical identity-based encryption
Jae Hong Seo, Keita Emura
Theor. Comput. Sci.1
2014 Revocable Identity-Based Cryptosystem Revisited: Security Models and Constructions
abstract
Boneh and Franklin gave a naive revocation method in identity-based encryption (IBE) which imposes a huge overhead into the key generation center. Later, Boldyreva, Goyal, and Kumar proposed an elegant way of achieving an IBE with efficient revocation, called revocable IBE (RIBE). In this paper, we revisit RIBE from the viewpoint of both security models and constructions. First, we introduce a realistic threat, which we call decryption key exposure, and show that all prior RIBE constructions, except the Boneh-Franklin one, are vulnerable to decryption key exposure. Next, we propose the first scalable RIBE scheme with decryption key exposure resistance by combining the (adaptively secure) Waters IBE scheme and the (selectively secure) Boneh-Boyen IBE scheme, and show that our RIBE scheme is more efficient than all previous adaptively secure scalable RIBE schemes. In addition, we extend our interest into identity-based signatures; we introduce a new security definition of revocable identity-based signature (RIBS) with signing key exposure resistance, and propose the first scalable RIBS scheme based on the Paterson-Schuldt IBS. Finally, we provide implementation results of our schemes to adduce the feasibility of our schemes.
Jae Hong Seo, Keita Emura
IEEE Trans. Inf. Forensics Secur.1
2013 Efficient Delegation of Key Generation and Revocation Functionalities in Identity-Based Encryption
Jae Hong Seo, Keita Emura
CT-RSA1
2013 Practical Signatures from Standard Assumptions
Florian Böhl, Dennis Hofheinz, Tibor Jager, Jessica Koch, Jae Hong Seo, Christoph Striecks
EUROCRYPT5
2012 On the (Im)possibility of Projecting Property in Prime-Order Setting
Jae Hong Seo
ASIACRYPT1
2012 Beyond the Limitation of Prime-Order Bilinear Groups, and Round Optimal Blind Signatures
Jae Hong Seo, Jung Hee Cheon
TCC1