VLDB 2026 Research / reviewers in the wild / expert
Daeseon Choi
dblp:57/6425
· DBLP profile ↗
17ranked-venue papers
0as first author
11since 2021 · last 2027
0000-0002-1438-0265ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | TRACER: Temporal retrieval-augmented contextual evaluator for robustness in ML trainingabstractSecurity vulnerabilities that arise during the training phase of machine learning models often emerge progressively and stealthily, making it difficult to fully analyze their causes and evolution through single-point performance evaluation alone. Existing security analysis frameworks primarily focus on one-off attack execution and quantitative metric reporting, which limits their ability to systematically interpret cumulative state changes and vulnerability manifestation patterns throughout the training process. To address this limitation, this study proposes an autonomous vulnerability analysis agent driven by a Large Language Model. The proposed framework employs an iterative analysis loop that integrates execution logs, step-wise analytical memory, and externally retrieved knowledge to track state transitions and anomalous signs during training, and to interpret the underlying mechanisms and causal relationships of vulnerability emergence. Experimental results across diverse training-phase attack scenarios show that the proposed agent is not restricted to a specific attack type, but can identify the distinct performance degradation mechanisms induced by different threat models and consistently infer their causal relationships based on execution logs and retrieved knowledge. In addition, quantitative reliability evaluations indicate that the generated reports are generally consistent with actual observations and support evidence-grounded, coherent analysis. Ultimately, the proposed framework provides an explainable and automated analytical foundation for security vulnerability analysis in the training phase of AI systems. Junseok Shin, Jinhyeok Jang, Daeseon Choi |
Expert Syst. Appl. | 5 |
| 2026 | ASTRA: Adversarial Stealthy Trigger Reasoning Attacks for Black-Box LLMs
Seong-Gyu Park, Daeseon Choi |
PAKDD (4) | 3 |
| 2026 | TRACE: Confounder-free Adversarial Fine-tuning for Robust Object DetectionabstractAdversarial patch attacks critically endanger object detection systems by causing severe mispredictions with small, easily realizable perturbations in both digital and physical environments. Existing defenses such as certified methods or patch detection suffer from high latency, while conventional adversarial training often overfits to specific patches and lacks generalization, particularly in multi-object scenarios. To overcome high latency and poor generalization, we introduce TRACE (Tuning Robustness by Adversarial-patch Confounder Elimination), an adversarial fine-tuning framework that leverages Instrumental Variable Regression in the feature space. TRACE treats patch-related variations—including location, rotation, and brightness—as confounders, thereby eliminating spurious correlations and guiding the model toward causal features that sustain robust detection. Evaluations on YOLOv5 and YOLOv8 show that TRACE consistently outperforms conventional defense methods in both efficiency and robustness under adaptive and unseen patch attacks. Moreover, physical testbed experiments confirm its effectiveness beyond digital settings, highlighting TRACE as a practical solution for achieving generalized robustness in object detection. Wonho Lee, Jisu Lee, Hyunsik Na, Daeseon Choi |
WACV | 5 |
| 2025 | Head Feature-Based Adversarial Attack for Proactive Defense Against Face SwappingabstractFace swapping, a deepfake technique that composites the face of a source individual onto the image of a target individual, has emerged as a significant security threat that needs to be addressed. Our study aims to proactively prevent images from being exploited in face swapping applications by injecting imperceptible perturbation into the images. To achieve this, a novel perturbation injection method that effectively maximizes the impact of the perturbation is proposed by specifically injecting perturbations into the Head Features. The proposed adversarial attack method is evaluated against existing adversarial attack methods to verify its effectiveness. Additionally, experiments were conducted to evaluate the practical applicability of the proposed method by examining its performance over different inference times and target transferability. The results demonstrated that the proposed method is sufficiently practical in terms of performance for real-world applications. Seungdeok Roh, Daeseon Choi |
AVSS | 4 |
| 2025 | Infrared Thermal-Guided Adversarial Patch Defense for Robust Visible Person DetectorsabstractAdversarial patch attacks on visible person detectors pose significant risks to recognition and safety. To counter this, we propose a defense method that integrates thermal imaging with RGB images to exploit differences in thermal characteristics between adversarial patches and humans. Our approach segments thermal images using selective search to generate mask sets and apply them to RGB images for attack detection and mitigation. To evaluate the proposed method, we created a physical attack dataset by conducting a hiding attack using printed adversarial patches against a person detector. This dataset enabled a quantitative assessment of our method. Experimental results demonstrate that our approach effectively defends against adversarial patches while maintaining performance on clean images, validating its robustness in practical scenarios. Hayeon Jeong, Daeseon Choi |
AVSS | 3 |
| 2025 | Adversarial Image Detection for Vision Transformers via Attention MapabstractMost deep neural networks are vulnerable to adversarial attacks, making it crucial to develop effective defenses against them. Adversarial examples are created by applying slight perturbations either to the entire image or specific regions, depending on attack methods. By contrast, benign examples typically lead models to focus attention on contiguous regions of the image during classification. Therefore, adversarial examples can be detected effectively by leveraging attention values. First, we conduct simple experiment to investigate how the model’s attention responds to adversarial perturbations. Second, we derive features by calculating the changes in attention values across ViT layers for adversarial and benign examples. These attention-derived features are then fed into the detection model, ResNet-50, to learn the differences in the activation locations between both examples. Third, we demonstrate the effectiveness of our approach by thorough experiments on various attack methods, datasets, and target models. The experiments prove the effectiveness of our approach, achieving superior performance compared to baseline methods on the ImageNet dataset across ViT-B and ViT-L. Our findings underscore the potential of utilizing attention-derived features as powerful indicators for enhancing the resilience of ViT models against adversarial perturbations. Seonggyu Park, Hyunsik Na, Daeseon Choi |
AVSS | 3 |
| 2025 | Countering Jailbreak Attacks with Two-Axis Pre-detection and Conditional Warning Wrappers
Hyunsik Na, Hajun Kim, Dooshik Yoon, Daeseon Choi |
ESORICS (1) | 4 |
| 2024 | Session Replication Attack Through QR Code Sniffing in Passkey CTAP Registration
Seungmin Kim, Gwonsang Ryu, Daeseon Choi |
SEC | 4 |
| 2023 | A hybrid adversarial training for deep learning model and denoising network resistant to adversarial examplesabstractAbstract Deep neural networks (DNNs) are vulnerable to adversarial attacks that generate adversarial examples by adding small perturbations to the clean images. To combat adversarial attacks, the two main defense methods used are denoising and adversarial training. However, both methods result in the DNN having lower classification accuracy for clean images than conventionally trained DNN models. To overcome this problem, we propose a hybrid adversarial training (HAT) method that trains the denoising network and DNN model simultaneously. The proposed HAT method uses both clean images and adversarial examples denoised by the denoising network and non-denoised clean images and adversarial examples to train the DNN model. The results of experiments conducted on the MNIST, CIFAR-10, CIFAR-100, and GTSRB datasets show that the HAT method results in a higher classification accuracy than both conventional training with a denoising network and previous adversarial training methods. They also indicate that training with the HAT method results in average improvements in robustness of 0.84%, 27.33%, 28.99%, and 17.61% against adversarial attacks compared with several state-of-the-art adversarial training methods on the MNIST, CIFAR-10, CIFAR-100, and GTSRB datasets, respectively. Thus, the proposed HAT method results in improved robustness for DNNs against a wider range of adversarial attacks. Gwonsang Ryu, Daeseon Choi |
Appl. Intell. | 2 |
| 2021 | Adversarial attacks by attaching noise markers on the face against deep face recognitionabstractDeep neural networks (DNNs) have become increasingly effective in difficult machine learning tasks, such as image classification, speech recognition, and natural language processing. Face recognition (FR) using DNNs shows high performance and is widely used in various domains such as payment systems and immigration inspection. However, DNNs are vulnerable to adversarial examples generated by adding a small amount of noise to an original sample, resulting in misclassification by the DNNs. In this study, we attempt to deceive state-of-the-art FR by attaching noise markers on a face in the real world. To deceive an FR model in the real world, we address challenges in the attack process, including selection of locations of noise markers, the differences between colors of digital noise markers and those of noise markers after printing, the differences between the colors of noise markers that are attached to the face and those of noise markers after a picture is taken, and the differences between the locations of digital noise markers and those of noise markers that are attached to the face. In experiments, we generate noise markers considering these challenges and show that state-of-the-art FR can be deceived by attaching a maximum of 10 noise markers to a face. This can cause a security risk for FR models using DNNs. Gwonsang Ryu, Hosung Park, Daeseon Choi |
J. Inf. Secur. Appl. | 3 |
| 2021 | Classification score approach for detecting adversarial example in deep neural networkabstractAbstract Deep neural networks (DNNs) provide superior performance on machine learning tasks such as image recognition, speech recognition, pattern analysis, and intrusion detection. However, an adversarial example, created by adding a little noise to an original sample, can cause misclassification by a DNN. This is a serious threat to the DNN because the added noise is not detected by the human eye. For example, if an attacker modifies a right-turn sign so that it misleads to the left, autonomous vehicles with the DNN will incorrectly classify the modified sign as pointing to the left, but a person will correctly classify the modified sign as pointing to the right. Studies are under way to defend against such adversarial examples. The existing method of defense against adversarial examples requires an additional process such as changing the classifier or modifying input data. In this paper, we propose a new method for detecting adversarial examples that does not invoke any additional process. The proposed scheme can detect adversarial examples by using a pattern feature of the classification scores of adversarial examples. We used MNIST and CIFAR10 as experimental datasets and Tensorflow as a machine learning library. The experimental results show that the proposed method can detect adversarial examples with success rates: 99.05% and 99.9% for the untargeted and targeted cases in MNIST, respectively, and 94.7% and 95.8% for the untargeted and targeted cases in CIFAR10, respectively. Hyun Kwon, Yongchul Kim, Hyunsoo Yoon, Daeseon Choi |
Multim. Tools Appl. | 4 |
| 2020 | Selective Audio Adversarial Example in Evasion Attack on Speech Recognition SystemabstractDeep neural networks (DNNs) are widely used for image recognition, speech recognition, and other pattern analysis tasks. Despite the success of DNNs, these systems can be exploited by what is termed adversarial examples. An adversarial example, in which a small distortion is added to the input data, can be designed to be misclassified by the DNN while remaining undetected by humans or other systems. Such adversarial examples have been studied mainly in the image domain. Recently, however, studies on adversarial examples have been expanding into the voice domain. For example, when an adversarial example is applied to enemy wiretapping devices (victim classifiers) in a military environment, the enemy device will misinterpret the intended message. In such scenarios, it is necessary that friendly wiretapping devices (protected classifiers) should not be deceived. Therefore, the selective adversarial example concept can be useful in mixed situations, defined as situations in which there is both a classifier to be protected and a classifier to be attacked. In this paper, we propose a selective audio adversarial example with minimum distortion that will be misclassified as the target phrase by a victim classifier but correctly classified as the original phrase by a protected classifier. To generate such examples, a transformation is carried out to minimize the probability of incorrect classification by the protected classifier and that of correct classification by the victim classifier. We conducted experiments targeting the state-of-the-art DeepSpeech voice recognition model using Mozilla Common Voice datasets and the Tensorflow library. They showed that the proposed method can generate a selective audio adversarial example with a 91.67% attack success rate and 85.67% protected classifier accuracy. Hyun Kwon, Yongchul Kim, Hyunsoo Yoon, Daeseon Choi |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | UAV-Undertaker: Securely Verifiable Remote Erasure Scheme with a Countdown-Concept for UAV via Randomized Data SynchronizationabstractUnmanned aerial vehicles (UAVs) play an increasingly core role in modern warfare, with powerful but tiny embedded computing systems actively applied in the military field. Confidential data, such as military secrets, may be stored inside military devices such as UAVs, and the capture or loss of such data could cause significant damage to national security. Therefore, the development of securely verifiable remote erasure techniques for military devices is considered a core technology. In this study, we devised a verifiable remote erasure scheme with a countdown-concept using randomized data synchronization to satisfy securely verifiable remote erasure technology. The scheme allows the GCS (Ground Control Station) to remotely erase data stored in the UAV, even on loss of communication, and returns proof of erasure to GCS after erasure. Our approach classifies the accumulated data stored in the UAV as a new data type and applies the characteristics of that data type to generate the proof of erasure. We select a small-volume data sample (rather than all of the data) and perform prior learning only on that sample; in this way, we can obtain the probative power of the evidence of erasure with a relatively small amount of traffic. When we want to erase data of 100 Mbytes of remote device, 100 Mbytes of data transfer is required for related work, whereas our system has data transfer according to the ratio of amount of randomly selected data. By doing this, communication stability can be acquired even in unstable communication situations where the maximum traffic can change or not be predicted. Furthermore, when the UAV sends the proof of erasure to the GCS, the UAV does its best to perform the erasure operation given its situation. Taek-Young Youn, Daeseon Choi, Ki-Woong Park |
Wirel. Commun. Mob. Comput. | 3 |
| 2018 | POSTER: Zero-Day Evasion Attack Analysis on Race between Attack and DefenseabstractDeep neural networks (DNNs) exhibit excellent performance in machine learning tasks such as image recognition, pattern recognition, speech recognition, and intrusion detection. However, the usage of adversarial examples, which are intentionally corrupted by noise, can lead to misclassification. As adversarial examples are serious threats to DNNs, both adversarial attacks and methods of defending against adversarial examples have been continuously studied. Zero-day adversarial examples are created with new test data and are unknown to the classifier; hence, they represent a more significant threat to DNNs. To the best of our knowledge, there are no analytical studies in the literature of zero-day adversarial examples with a focus on attack and defense methods through experiments using several scenarios. Therefore, in this study, zero-day adversarial examples are practically analyzed with an emphasis on attack and defense methods through experiments using various scenarios composed of a fixed target model and an adaptive target model. The Carlini method was used for a state-of-the-art attack, while an adversarial training method was used as a typical defense method. We used the MNIST dataset and analyzed success rates of zero-day adversarial examples, average distortions, and recognition of original samples through several scenarios of fixed and adaptive target models. Experimental results demonstrate that changing the parameters of the target model in real time leads to resistance to adversarial examples in both the fixed and adaptive target models. Hyun Kwon, Hyunsoo Yoon, Daeseon Choi |
AsiaCCS | 3 |
| 2018 | POSTER: Address Authentication Based on Location HistoryabstractThis paper proposes an address authentication method based on the user's location history. For address authentication, existing studies discover the user's regular locations called location of interest (LOI) from the location history by using clustering algorithms. They authenticate an address if the address is contained in one of the LOIs. However, unnecessary LOIs which are unrelated to the address may lead to false authentications of illegitimate addresses, i.e. other users' addresses or feigned addresses. The proposed method tries to reduce the authentication error rate by eliminating unnecessary LOIs with the distinguishing properties of address. In other words, only few LOIs that satisfy the properties (long duration, high density, and consistency) are kept and utilized for address authentication. Experimental results show that the proposed method decreases the authentication error rate compared with previous approaches using time-based clustering and density-based clustering. Hosung Park, Daeyong Kwon, Seungsoo Nam, Daeseon Choi |
AsiaCCS | 4 |
| 2018 | Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier
Hyun Kwon, Yongchul Kim, Ki-Woong Park, Hyunsoo Yoon, Daeseon Choi |
Comput. Secur. | 5 |
| 2017 | Simplified small exponent test for batch verification
Jung Yeon Hwang, Boyeon Song, Daeseon Choi, Seung-Hun Jin, Hyun Sook Cho, Mun-Kyu Lee |
Theor. Comput. Sci. | 3 |