VLDB 2026 Research / reviewers in the wild / expert
Hoki Kim
dblp:75/6518
· DBLP profile ↗
15ranked-venue papers
8as first author
14since 2021 · last 2026
0000-0001-5361-459XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 6 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial Retain-Free Unlearning for Bearing Prognostics and Health ManagementabstractPrognostics and health management (PHM) systems increasingly rely on machine learning for reliable bearing fault diagnosis. However, data deletion in PHM remains an open problem. Since retraining a model from scratch is often infeasible, this raises a new challenge. Moreover, in most cases, only the pretrained model and the user-requested data are available. Existing approaches under this constraint often fail to achieve proper unlearning and substantially degrade model performance, thereby disrupting the original embedding space and collapsing the structural integrity of the pretrained model. To address this, we propose adversarial retain-free unlearning (ARU). Our framework integrates adversarial samples generated from the pretrained model with a semantic-driven loss to preserve representational stability. Experiments on public and private bearing datasets demonstrate that ARU achieves unlearning efficacy and structural consistency comparable to Retrain while maintaining diagnostic accuracy. We believe that our proposed framework provides a practical and reliable solution for retain-free unlearning in real-world industrial PHM systems. Chaewon Yoon, Hoki Kim |
IEEE Trans. Ind. Informatics | 3 |
| 2025 | Unlearning-Aware MinimizationabstractMachine unlearning aims to remove the influence of specific training samples (i.e., forget data) from a trained model while preserving its performance on the remaining samples (i.e., retain data). Existing approximate unlearning approaches, such as fine-tuning or negative gradient, often suffer from either insufficient forgetting or significant degradation on retain data.
In this paper, we introduce Unlearning-Aware Minimization (UAM), a novel min–max optimization framework for machine unlearning. UAM perturbs model parameters to maximize the forget loss and then leverages the corresponding gradients to minimize the retain loss. We derive an efficient optimization method for this min-max problem, which enables effective removal of forget data and uncovers better optima that conventional methods fail to reach.
Extensive experiments demonstrate that UAM outperforms existing methods across diverse benchmarks, including image classification datasets (CIFAR-10, CIFAR-100, TinyImageNet) and multiple-choice question-answering benchmarks for large language models (WMDP-Bio, WMDP-Cyber). Hoki Kim, Keonwoo Kim 0004, Sungwon Chae |
NeurIPS | 1 |
| 2025 | Towards undetectable adversarial attack on time series classification
Hoki Kim, Yunyoung Lee, Jaewook Lee 0001 |
Inf. Sci. | 1 |
| 2024 | Fair Sampling in Diffusion Models through Switching MechanismabstractDiffusion models have shown their effectiveness in generation tasks by well-approximating the underlying probability distribution. However, diffusion models are known to suffer from an amplified inherent bias from the training data in terms of fairness. While the sampling process of diffusion models can be controlled by conditional guidance, previous works have attempted to find empirical guidance to achieve quantitative fairness. To address this limitation, we propose a fairness-aware sampling method called \textit{attribute switching} mechanism for diffusion models. Without additional training, the proposed sampling can obfuscate sensitive attributes in generated data without relying on classifiers. We mathematically prove and experimentally demonstrate the effectiveness of the proposed method on two key aspects: (i) the generation of fair data and (ii) the preservation of the utility of the generated data. Jinseong Park 0001, Hoki Kim, Jaewook Lee 0001, Saerom Park |
AAAI | 3 |
| 2024 | Are Self-Attentions Effective for Time Series Forecasting?abstractTime series forecasting is crucial for applications across multiple domains and various scenarios. Although Transformers have dramatically advanced the landscape of forecasting, their effectiveness remains debated. Recent findings have indicated that simpler linear models might outperform complex Transformer-based approaches, highlighting the potential for more streamlined architectures. In this paper, we shift the focus from evaluating the overall Transformer architecture to specifically examining the effectiveness of self-attention for time series forecasting. To this end, we introduce a new architecture, Cross-Attention-only Time Series transformer (CATS), that rethinks the traditional transformer framework by eliminating self-attention and leveraging cross-attention mechanisms instead.
By establishing future horizon-dependent parameters as queries and enhanced parameter sharing, our model not only improves long-term forecasting accuracy but also reduces the number of parameters and memory usage. Extensive experiment across various datasets demonstrates that our model achieves superior performance with the lowest mean squared error and uses fewer parameters compared to existing models.
The implementation of our model is available at: https://github.com/dongbeank/CATS. Dongbin Kim, Jinseong Park 0001, Jaewook Lee 0001, Hoki Kim |
NeurIPS | 4 |
| 2024 | Evaluating practical adversarial robustness of fault diagnosis systems via spectrogram-aware ensemble method
Hoki Kim, Jaewook Lee 0001, Youngdoo Son |
Eng. Appl. Artif. Intell. | 1 |
| 2023 | Differentially Private Sharpness-Aware TrainingabstractTraining deep learning models with differential privacy (DP) results in a degradation of performance. The training dynamics of models with DP show a significant difference from standard training, whereas understanding the geometric properties of private learning remains largely unexplored. In this paper, we investigate sharpness, a key factor in achieving better generalization, in private learning. We show that flat minima can help reduce the negative effects of per-example gradient clipping and the addition of Gaussian noise. We then verify the effectiveness of Sharpness-Aware Minimization (SAM) for seeking flat minima in private learning. However, we also discover that SAM is detrimental to the privacy budget and computational time due to its two-step optimization. Thus, we propose a new sharpness-aware training method that mitigates the privacy-optimization trade-off. Our experimental results demonstrate that the proposed method improves the performance of deep learning models with DP from both scratch and fine-tuning. Code is available at https://github.com/jinseongP/DPSAT. Jinseong Park 0001, Hoki Kim, Jaewook Lee 0001 |
ICML | 2 |
| 2023 | Fantastic Robustness Measures: The Secrets of Robust GeneralizationabstractAdversarial training has become the de-facto standard method for improving the robustness of models against adversarial examples. However, robust overfitting remains a significant challenge, leading to a large gap between the robustness on the training and test datasets. To understand and improve robust generalization, various measures have been developed, including margin, smoothness, and flatness-based measures. In this study, we present a large-scale analysis of robust generalization to empirically verify whether the relationship between these measures and robust generalization remains valid in diverse settings. We demonstrate when and how these measures effectively capture the robust generalization gap by comparing over 1,300 models trained on CIFAR-10 under the $L_\infty$ norm and further validate our findings through an evaluation of more than 100 models from RobustBench across CIFAR-10, CIFAR-100, and ImageNet. We hope this work can help the community better understand adversarial robustness and motivate the development of more robust defense methods against adversarial attacks. Hoki Kim, Jinseong Park 0001, Jaewook Lee 0001 |
NeurIPS | 1 |
| 2023 | Bridged adversarial training
Hoki Kim, Sungyoon Lee, Jaewook Lee 0001 |
Neural Networks | 1 |
| 2023 | GradDiv: Adversarial Robustness of Randomized Neural Networks via Gradient Diversity RegularizationabstractDeep learning is vulnerable to adversarial examples. Many defenses based on randomized neural networks have been proposed to solve the problem, but fail to achieve robustness against attacks using proxy gradients such as the Expectation over Transformation (EOT) attack. We investigate the effect of the adversarial attacks using proxy gradients on randomized neural networks and demonstrate that it highly relies on the directional distribution of the loss gradients of the randomized neural network. We show in particular that proxy gradients are less effective when the gradients are more scattered. To this end, we propose Gradient Diversity (GradDiv) regularizations that minimize the concentration of the gradients to build a robust randomized neural network. Our experiments on MNIST, CIFAR10, and STL10 show that our proposed GradDiv regularizations improve the adversarial robustness of randomized neural networks against a variety of state-of-the-art attack methods. Moreover, our method efficiently reduces the transferability among sample models of randomized neural networks. Sungyoon Lee, Hoki Kim, Jaewook Lee 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2023 | Generating Transferable Adversarial Examples for Speech Classification
Hoki Kim, Jinseong Park 0001, Jaewook Lee 0001 |
Pattern Recognit. | 1 |
| 2022 | Variational cycle-consistent imputation adversarial networks for general missing patterns
Sungyoon Lee, Junyoung Byun, Hoki Kim, Jaewook Lee 0001 |
Pattern Recognit. | 4 |
| 2021 | Understanding Catastrophic Overfitting in Single-step Adversarial TrainingabstractAlthough fast adversarial training has demonstrated both robustness and efficiency, the problem of "catastrophic overfitting" has been observed. This is a phenomenon in which, during single-step adversarial training, the robust accuracy against projected gradient descent (PGD) suddenly decreases to 0% after a few epochs, whereas the robust accuracy against fast gradient sign method (FGSM) increases to 100%. In this paper, we demonstrate that catastrophic overfitting is very closely related to the characteristic of single-step adversarial training which uses only adversarial examples with the maximum perturbation, and not all adversarial examples in the adversarial direction, which leads to decision boundary distortion and a highly curved loss surface. Based on this observation, we propose a simple method that not only prevents catastrophic overfitting, but also overrides the belief that it is difficult to prevent multi-step adversarial attacks with single-step adversarial training. Hoki Kim, Jaewook Lee 0001 |
AAAI | 1 |
| 2021 | Compact class-conditional domain invariant learning for multi-class domain adaptation
Hoki Kim, Jaewook Lee 0001 |
Pattern Recognit. | 2 |
| 2001 | A practical built-in current sensor for I_DDQ testingabstractThis paper describes a new built-in current sensor (BICS) design, comprised of a MAGFET current sensor, stochastic sensor, self-calibration tool, counter, and scan chain. By indirectly measuring the current, the sensor avoids the unacceptable drawbacks of past BICS designs. Test chips fabricated in 180 nm and 250 nm technology demonstrate that the sensor can be used for IDDQ testing of large, high-performance, deep submicron circuits. This sensor should extend practical IDDQ testing to the 35 nm technology generation. Hoki Kim, D. M. H. Walker, David Colby |
ITC | 1 |