VLDB 2026 Research / reviewers in the wild / expert
Yung Ryn Choe
dblp:82/5827
· DBLP profile ↗
18ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-6114-054XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Systems, architecture and hardware · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorComputer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Measuring Attack Observability in Cloud Telemetry Logs: A Cross-Platform Analysis
Mary Grace Dhooghe, Minkyung Park, Junghwan Rhee, Yung Ryn Choe |
DSN | 4 |
| 2025 | Few-Shot Learning-Based Cyber Incident Detection with Augmented Context IntelligenceabstractIn recent years, the adoption of cloud services has been expanding at an unprecedented rate. As more and more organizations migrate or deploy their businesses to the cloud, a multitude of related cybersecurity incidents such as data breaches are on the rise. Many inherent attributes of cloud environments, for example, data sharing, remote access, dynamicity and scalability, pose significant challenges for the protection of cloud security. Even worse, cyber threats are becoming increasingly sophisticated and covert. Attack methods, such as Advanced Persistent Threats (APTs), are continually developed to bypass traditional security measures. Among the emerging technologies for robust threat detection, system provenance analysis is being considered as a promising mechanism, thus attracting widespread attention in the field of incident response. This paper proposes a new few-shot learning-based attack detection with improved data context intelligence. We collect operating system behavior data of cloud systems during realistic attacks and leverage an innovative semiotics extraction method to describe system events. Inspired by the advances in semantic analysis, which is a fruitful area focused on understanding natural languages in computational linguistics, we further convert the anomaly detection problem into a similarity comparison problem. Comprehensive experiments show that the proposed approach is able to generalize over unseen attacks and make accurate predictions, even if the incident detection models are trained with very limited samples. Fei Zuo, Junghwan Rhee, Yung Ryn Choe, Chenglong Fu 0002, Xianshan Qu |
COMPSAC | 3 |
| 2024 | BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
Fei Zuo, Cody Tompkins, Qiang Zeng 0001, Lannan Luo, Yung Ryn Choe, Junghwan Rhee |
SecureComm (3) | 5 |
| 2024 | Automatic Configurator to Prevent Attacks for Azure Cloud SystemabstractCloud systems are integral for delivering scalable and virtualized resources globally. It also provides security updates and monitoring to keep user data safe. However, the growing complexity of these systems poses significant challenges, particularly in the realm of logging and security. It is difficult to know for users which detail is critical for further security analysis of the resources. Also, external packages used in the cloud system require updates by users to mitigate the vulnerability, but the large number of packages to manage makes them outdated versions. This paper shares the weakness of cloud logging systems we observed, which can be exploited by attackers. We propose a tool that configures alerts automatically when commands that have missing details in logs are executed and updates vulnerable versions of packages. Our tool leverages a list that includes the commands with missing details in logs and packages that need to be updated because of the known vulnerabilities. To make the list, we conduct complete enumerating for 1,279 commands in five major resources of Azure to find logs with missing details and search related communities to find vulnerable packages that require the manual update. We evaluate the proposed tool with eight attack scenarios based on real-world cases and the result shows that our tool prevents them successfully. Chijung Jung, Yung Ryn Choe, Junghwan Rhee, Yonghwi Kwon 0001 |
SERA | 2 |
| 2023 | Recurrent Neural Network and Convolutional Neural Network for Detection of Denial of Service Attack in MicroservicesabstractContainerized Cloud computing system is a lightweight virtualization platform to build and deploy applications easily. Especially it can help to mitigate many of the challenges associated with microservices architecture. However, with the help of high scalability of lightweight container servers, microservices build complex internal hierarchy providing unknown attack surfaces where attackers can exploit. In this work, we show a microservice specific Denial of Service attack that exploits complexity of internal traffics between microservices. To detect malicious activities apparently looking normal and legal, we applied both Recurrent Neural Network model trained from the dataset of sequential TCP sessions, and Convolutional Neural Network model trained from the dataset of connection trees among microservices. As a result, we obtained high detection rates, which are 98.4% for the Recurrent Neural Network and 97.0% for the Convolutional Neural Network respectively and low false detection rates. Yung Ryn Choe, Raiat Subhra Ghosh |
ICMLA | 2 |
| 2023 | Raw Packet Data Ingestion with Transformers for Malicious Activity ClassificationsabstractTraffic diversity, novel attacks, and sheer volume of network traffic creates a significant challenge in detecting and identifying malicious actions against a network. Due to these factors, human auditing of network events is unfeasible, requiring advanced approaches, such as machine learning techniques. Furthermore, the increasing novelty of network attacks render traditional filtering mechanisms unable to handle such threats. In this paper, we propose a novel, natural language processing approach to detecting malicious, network-based attacks, using ByT5. Our approach classifies network packet data as malicious or benign. ByT5 is a token-free sequence to sequence model, enabling the model to take in raw packet streams and classify the packets without feature extraction or preprocessing via an encoding schema. The results of our approach in classifying traffic as benign or malicious indicates promising results. Namely, when applied to the ISOT dataset, our approach achieves a maximal recall of 0.834 and a maximal F1 score of 0.693. Nitin Sharan, Thomas Quig, Eric Goodman, Yung Ryn Choe, Dalton A. Brucker-Hahn |
ICMLA | 4 |
| 2023 | ProvSec: Cybersecurity System Provenance Analysis Benchmark DatasetabstractSystem provenance forensic analysis has been studied by a large body of research work. This area needs fine granularity data such as system calls along with event fields to track the dependencies of events. While prior work on security datasets has been proposed, we found a useful dataset of realistic attacks and details that can be used for provenance tracking is lacking. We created a new dataset of eleven vulnerable cases for system forensic analysis. It includes the full details of system calls including syscall parameters. Realistic attack scenarios with real software vulnerabilities and exploits are used. Also, we created two sets of benign and adversary scenarios which are manually labeled for supervised machine-learning analysis. We demonstrate the details of the dataset events and dependency analysis. Madhukar Shrestha, Jeehyun Oh, Junghwan Rhee, Yung Ryn Choe, Fei Zuo, Myung-Ah Park, Gang Qian |
SERA | 5 |
| 2019 | Toward the Analysis of Embedded Firmware through Automated Re-hosting
Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurélien Francillon, Yung Ryn Choe, Christopher Krügel, Giovanni Vigna |
RAID | 9 |
| 2018 | Using Loops For Malware Classification Resilient to Feature-unaware PerturbationsabstractIn the past few years, both the industry and the academic communities have developed several approaches to detect malicious Android apps. State-of-the-art research approaches achieve very high accuracy when performing malware detection on existing datasets. These approaches perform their malware classification tasks in an "offline" scenario, where malware authors cannot learn from and adapt their malicious apps to these systems. In real-world deployments, however, adversaries get feedback about whether their app was detected, and can react accordingly by transforming their code until they are able to influence the classification. Aravind Machiry, Nilo Redini, Eric Gustafson, Yanick Fratantonio, Yung Ryn Choe, Christopher Krügel, Giovanni Vigna |
ACSAC | 5 |
| 2017 | Intrusion Detection with Unsupervised Heterogeneous Ensembles Using Cluster-Based NormalizationabstractOutlier detection has been shown to be a promising machine learning technique for a diverse array of felds and problem areas. However, traditional, supervised outlier detection is not well suited for problems such as network intrusion detection, where proper labelled data is scarce. This has created a focus on extending these approaches to be unsupervised, removing the need for explicit labels, but at a cost of poorer performance compared to their supervised counterparts. Recent work has explored ways of making up for this, such as creating ensembles of diverse models, or even diverse learning algorithms, to jointly classify data. While using unsupervised, heterogeneous ensembles of learning algorithms has been proposed as a viable next step for research, the implications of how these ensembles are built and used has not been explored. Scott Ruoti, Scott Heidbrink, Mark O'Neill, Eric Gustafson, Yung Ryn Choe |
ICWS | 5 |
| 2017 | BOOMERANG: Exploiting the Semantic Gap in Trusted Execution Environments
Aravind Machiry, Eric Gustafson, Chad Spensky, Christopher Salls, Nick Stephens, Ruoyu Wang 0001, Antonio Bianchi, Yung Ryn Choe, Christopher Krügel, Giovanni Vigna |
NDSS | 8 |
| 2011 | Experimental Evaluation of the Impact of Packet Capturing Tools for Web ServicesabstractNetwork measurement is a discipline that provides the techniques to collect data that are fundamental to many branches of computer science. While many capturing tools and comparisons have made available in the literature and elsewhere, the impact of these packet capturing tools on existing processes have not been thoroughly studied. While not a concern for collection methods in which dedicated servers are used, many usage scenarios of packet capturing now requires the packet capturing tool to run concurrently with operational processes. In this paper we perform experimental evaluations of the performance impact that packet capturing process have on webbased services; in particular, we observe the impact on web servers. We find that packet capturing processes indeed impact the performance of web servers, but on a multi- core system the impact varies depending on whether the packet capturing and web hosting processes are co-located or not. In addition, the architecture and behavior of the web server and process scheduling is coupled with the behavior of the packet capturing process, which in turn also affect the web server's performance. Chao-Chih Chen, Yung Ryn Choe, Chen-Nee Chuah, Prasant Mohapatra |
GLOBECOM | 2 |
| 2009 | Peer-to-peer video on demand: Challenges and solutionsabstractThe challenges and solutions required for peer-to-peer video-on-demand (P2P VoD) provided by a fixed provider such as a cable company are fundamentally different from those seen in traditional P2P networks or client-server VoD solutions. Unlike traditional P2P networks, the end nodes (set top boxes with DVR capabilities) are largely under control of the system provider. Consequently, issues like churn and free-loading are less substantial. Unlike client-server solutions, there is always a readily-available resource of peer nodes able to contribute even if they are not using the VoD service! This paper explores requirements for efficient preloading of VoD movie data onto numerous customer set-top boxes. This research is currently exploring mathematical programming algorithms that minimize uplink traffic, given a popularity model for various pieces of content and information about storage and bandwidth capacity constraints at the customer nodes. Given the complex non-linear nature of P2P interactions, these mathematical programs require non-linear optimization approaches or heuristic solutions. However, even heuristic solutions would likely provide substantial advantages over simple dynamic allocation. Vijay S. Pai, Yung Ryn Choe, Jagadeesh M. Dyaberi, Derek L. Schuff, Karthik N. Kannan |
ICME | 2 |
| 2008 | Conservative vs. Optimistic Parallelization of Stateful Network Intrusion DetectionabstractThis paper presents and experimentally analyzes the performance of three parallelization strategies for the popular open-source Snort network intrusion detection system (NIDS). The parallelizations include 2 conservative variants and 1 optimistic scheme. The conservative strategy parallelizes inspection at the level of TCP/IP flows, as any potential inter-packet dependences are confined to a single flow. The flows are partitioned among threads, and each flow is processed in-order at one thread. A second variation reassigns flows between threads to improve load balance but still requires that only one thread process a given flow at a time. The flow-concurrent scheme provides good performance for 3 of the 5 network packet traces studied, reaching as high as 4.1 speedup and 3.1 Gbps inspection rate on a commodity 8-core server. Dynamic reassignment does not improve performance scalability because it introduces locking overheads that offset any potential benefits of load balancing. Neither conservative version can achieve good performance, however, without enough concurrent networkflows. For this case, this paper presents an optimistic parallelization that exploits the observation that not all packets from a flow are actually connected by dependences. This system allows a single flow to be simultaneously processed by multiple threads, stalling if an actual dependence is found. The optimistic version has additional overheads that reduce speedup by 25% for traces with flow concurrency, but its benefits allow one additional trace to see substantial speedup (2.4 on five cores). Derek L. Schuff, Yung Ryn Choe, Vijay S. Pai |
ISPASS | 2 |
| 2007 | A Model and Prototype of a Resource-Efficient Storage Server for High-Bitrate Video-on-DemandabstractThis paper presents a mathematical model and a prototype of a resource-efficient storage server for high-bitrate video-on-demand (VoD) applications. Rapid exponential growth of disk capacity enables the storage of high-bitrate VoD streams; however, a server system must be carefully designed to allow those streams to be retrieved from disk and delivered to the network efficiently. Additionally, a cost-effective server should be implemented using only commodity components, such as standard PCs, SATA disks and controllers, and Gigabit Ethernet links. This paper presents a model: detailed enough to account for the rate-based nature of streaming video, the buffering time allowed by the application, and average-case disk hardware characteristics while remaining simple enough to use for algorithm and system design. This paper then describes a prototype storage server designed to serve large video files at the specified bitrates and finds its performance to agree closely with the model (with an average discrepancy of 11% for high-bitrate streams). The system uses up to 8 SATA-300 disks and can simultaneously serve 290 distinct DVD-quality (6 Mbps) streams or 74 distinct HDTV-quality (25 Mbps) streams from disk, achieving an aggregate network throughput of 1.85 Gbps. Yung Ryn Choe, Chase Douglas, Vijay S. Pai |
IPDPS | 1 |
| 2007 | Achieving Reliable Parallel Performance in a VoD Storage Server Using Randomization and ReplicationabstractThis paper investigates randomization and replication as strategies to achieve reliable performance in disk arrays targeted for video-on-demand (VoD) workloads. A disk array can provide high aggregate throughput, but only if the server can effectively balance the load on the disks. Such load balance is complicated by two key factors: workload hotspots caused by differences in popularity among media streams, and "fail-stutter" faults that arise when the performance of one or more devices drops below expectations due to manufacturing variations, hardware problems, or geometry-related variations. This paper focuses on the random duplicate assignment (RDA) data allocation policy which places each data block on two disks chosen at random, independent of other blocks in the same media stream or other streams. This strategy is compared to traditional single-disk file allocation, disk striping (RAID-0), disk mirroring (RAID-1), and randomization without duplication. The various allocation schemes are implemented and tested using a prototype VoD server with 2 dual-core Opteron processors, 8 SATA disks, and 4 gigabit Ethernet interfaces running the Linux 2.6 kernel. The results indicate that combining randomization and replication allows RDA to effectively tolerate both workload hotspots and fail-stutter faults better than previous schemes. Yung Ryn Choe, Vijay S. Pai |
IPDPS | 1 |
| 2007 | Improving VoD server efficiency with bittorrentabstractThis paper presents and evaluates Toast, a scalable Video-on-Demand (VoD)streaming system that combines the popular BitTorrent peer-to-peer (P2P)file-transfer technology with a simple dedicated streaming server to decrease server load and increase client transfer speed. Toast includes a modified version of BitTorrent that supports streaming data delivery and that communicates with a VoD server when the desired data cannot be delivered in real-time by other peers. Yung Ryn Choe, Derek L. Schuff, Jagadeesh M. Dyaberi, Vijay S. Pai |
ACM Multimedia | 1 |
| 2007 | Conservative vs. optimistic parallelization of stateful network intrusion detectionabstractThis paper presents two approaches to parallelizing the Snort network intrusion detection system (NIDS). One scheme parallelizes NIDS processing conservatively across independent network flows, while the other optimistically achieves intra-flow parallelism by exploiting the observation that certain intra-flow dependences are uncommon and may be ignored under certain circumstances. Both schemes achieve average speedup over 2 on four cores, with an average throughput over 1 Gbps on 5 traces tested. Derek L. Schuff, Yung Ryn Choe, Vijay S. Pai |
PPoPP | 2 |