VLDB 2026 Research / reviewers in the wild / expert
Sungjae Hwang
dblp:86/2055
· DBLP profile ↗
15ranked-venue papers
10as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 4 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Security and privacy · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unveiling the Underground Phishing Ecosystem: A 12-Year Longitudinal Study of Deep and Dark Web Forums
Doowon Kim, Sungjae Hwang |
WWW | 4 |
| 2024 | An Empirical Study of JVMs' Behaviors on Erroneous JNI InteroperationsabstractJava Native Interface (JNI) allows Java applications to access native libraries, but it is challenging to develop correct JNI programs. By leveraging native code, the JNI enables Java developers to implement efficient applications and reuse code written in other programming languages such as C and C++. The core Java libraries use the JNI to provide system features like graphical user interfaces, and mainstream Java Virtual Machines (JVMs) support the JNI. However, implementing correct JNI programs is not trivial due to the complex interoperation semantics between different programming languages. While JVMs do not validate JNI interoperations by default because of the performance overhead, they provide two methods. First, JVMs report the interoperation failures defined in the JNI specification at runtime. Second, they support a debug option, which validates JNI interoperations, degrading the runtime performance. To the best of our knowledge, literature has not thoroughly studied the quality of JVMs’ methods, even though erroneous JNI interoperations may result in incorrect behaviors. In this paper, we empirically study the behaviors of JVMs on erroneous JNI interoperations. For a systematic study, we proposeJUSTGen, a semi-automatic tool that generates JNI test programs incurring erroneous interoperations from the JNI specification.JUSTGenreceives the JNI specification written in our domain-specific language (DSL) and automatically discovers cases that may lead to runtime errors on interoperations using an SMT solver. It then generates test programs that trigger the behaviors on the erroneous cases. Using the generated tests, we empirically evaluate JVM's failure handling mechanisms and the debug option capabilities on erroneous JNI interoperations. Our experiment results show that there exist erroneous cases in which JVMs do not handle failures or handle them differently from the specification. We also found that the JNI debug option does not validate thousands of erroneous cases, which can cause critical runtime errors such as memory corruption and violation of the Java type system. We reported 18 erroneous cases of which JVMs do not handle failures correctly to their respective vendors. Among them, 16 cases have been resolved. Sungjae Hwang, Sukyoung Ryu |
IEEE Trans. Software Eng. | 1 |
| 2023 | RT-Blockchain: Achieving Time-Predictable TransactionsabstractAlthough blockchain technology is being increasingly utilized across various fields, the challenge of providing timing guarantees for transactions remains unmet, which is an obstacle in implementing blockchain solutions for time-sensitive applications such as high-frequency trading and real-time payments. In this paper, we propose the first solution to achieve a timing guarantee on blockchain. To this end, we raise and address two issues for timely transactions on a blockchain: (a) architectural support, and (b) real-time scheduling principles specialized for blockchain. For (a), we modify an existing blockchain network, offering an interface to preferentially select the transactions with the earliest deadlines. We then extend the blockchain network to provide the flexibility of the number of generated blocks at a single block time. Under such architectural supports, we achieve (b) with three steps. First, to resolve a discrepancy between a periodic request of a transaction-generating node and the corresponding arrival on a block-generating node, we translate the former into the latter, which eases the modeling of the transaction load imposed on the blockchain network. Second, we derive a schedulability condition of the modeled transaction load, which guarantees no missed deadline for all transactions under a work-conserving deadline-based scheduling policy. Last, we develop a lazy scheduling policy and its condition, which reduces the number of generated blocks without compromising the degree of timing guarantees for the work-conserving policy. By implementing RT-blockchain on top of an existing open-source blockchain project, we demonstrate the effectiveness of the proposed scheduling principles with architectural supports in not only ensuring timely transactions but also reducing the number of generating blocks. Seunghoon Lee 0002, Sukmin Kang, Seungyeon Cho, Hyunwoo Koo, Sungjae Hwang, Jinkyu Lee 0001 |
RTSS | 5 |
| 2023 | EtherDiffer: Differential Testing on RPC Services of Ethereum NodesabstractBlockchain is a distributed ledger that records transactions among users on top of a peer-to-peer network. Among all, Ethereum is the most popular general-purpose platform and its support of smart contracts led to a new form of applications called decentralized applications (DApps). A typical DApp has an off-chain frontend and on-chain backend architecture, and the frontend often needs interactions with the backend network, e.g., to acquire chain data or make transactions. Therefore, Ethereum nodes implement the official RPC specification and expose a uniform set of RPC methods to the frontend. However, the specification is not sufficient in two points: (1) lack of clarification for non-deterministic event handling, and (2) lack of specification for invalid arguments. To effectively disclose any deviations caused by the insufficiency, this paper introduces EtherDiffer that automatically performs differential testing on four major node implementations in terms of their RPC services. EtherDiffer first generates a non-deterministic chain by multi-concurrent transactions and propagation delay. Then, it applies our key techniques called property-based generation and type-preserving mutation to generate both semantically-valid and semantically-invalid-yet-executable test cases. EtherDiffer executes the test cases on target nodes and reports any deviations in error handling or return values. The evaluation showed the effectiveness of our test case generation techniques with the success ratios of 98.8% and 95.4%, respectively. Also, EtherDiffer detected 48 different classes of deviations including 11 implementation bugs such as crash and denial-of-service bugs. We reported 44 of the detected classes to the specification and node developers and received acknowledgements as well as bug patches. Lastly, it significantly outperformed the official node testing tool in every technical aspect. We believe that our research findings can contribute to more stable DApp ecosystem by reducing the inconsistencies among nodes. Shinhae Kim, Sungjae Hwang |
ESEC/SIGSOFT FSE | 2 |
| 2021 | JUSTGen: Effective Test Generation for Unspecified JNI Behaviors on JVMsabstractJava Native Interface (JNI) provides a way for Java applications to access native libraries, but it is difficult to develop correct JNI programs. By leveraging native code, the JNI enables Java developers to implement efficient applications and to reuse code written in other programming languages such as C and C++. Besides, the core Java libraries already use the JNI to provide system features like a graphical user interface. As a result, many mainstream Java Virtual Machines (JVMs) support the JNI. However, due to the complex interoperation semantics between different programming languages, implementing correct JNI programs is not trivial. Moreover, because of the performance overhead, JVMs do not validate erroneous JNI interoperations by default, but they validate them only when the debug feature, the -Xcheck:jni option, is enabled. Therefore, the correctness of JNI programs highly relies on the checks by the -Xcheck:jni option of JVMs. Questions remain, however, on the quality of the checks provided by the feature. Are there any properties that the -Xcheck:jni option fails to validate? If so, what potential issues can arise due to the lack of such validation? To the best of our knowledge, no research has explored these questions in-depth. In this paper, we empirically study the validation quality and impacts of the -Xcheck:jni option on mainstream JVMs using unspecified corner cases in the JNI specification. Such unspecified cases may lead to unexpected run-time behaviors because their semantics is not defined in the specification. For a systematic study, we propose JUSTGEN, a semi-automated approach to identify unspecified cases from a specification and generate test programs. JUSTGEN receives the JNI specification written in our domain specific language (DSL), and automatically discovers unspecified cases using an SMT solver. It then generates test programs that trigger the behaviors of unspecified cases. Using the generated tests, we empirically study the validation ability of the -Xcheck:jni option. Our experimental result shows that the JNI debug feature does not validate thousands of unspecified cases on JVMs, and they can cause critical run-time errors such as violation of the Java type system and memory corruption. We reported 792 unspecified cases that are not validated by JVMs to their corresponding JVM vendors. Among them, 563 cases have been fixed and the remaining cases will be fixed in near future. Based on our empirical study, we believe that the JNI specification should specify the semantics of the missing cases clearly and the debug feature should be supported completely. Sungjae Hwang, Sukyoung Ryu |
ICSE | 1 |
| 2020 | Gap between theory and practice: an empirical study of security patches in solidityabstractEthereum, one of the most popular blockchain platforms, provides financial transactions like payments and auctions through smart contracts. Due to the immense interest in smart contracts in academia, the research community of smart contract security has made a significant improvement recently. Researchers have reported various security vulnerabilities in smart contracts, and developed static analysis tools and verification frameworks to detect them. However, it is unclear whether such great efforts from academia has indeed enhanced the security of smart contracts in reality. Sungjae Hwang, Sukyoung Ryu |
ICSE | 1 |
| 2020 | All about activity injection: Threats, semantics, detection, and defenseabstractSummary Android supports seamless user experience by maintaining activities from different applications (apps) in the same activity stack. Although such close inter‐app communication is essential in the Android framework, the powerful inter‐app communication contains vulnerabilities that can inject malicious activities into a victim app's activity stack to hijack user interaction flows. In this article, we demonstrate activity injection attacks with a simple malware, and formally specify the activity activation mechanism using operational semantics. Based on the operational semantics, we develop a static analysis tool, which analyzes Android apps to detect activity injection attacks. Our tool is fast enough to analyze real‐world Android apps in 6 seconds on average, and our experiments found that 1761 apps out of 129,756 real‐world Android apps inject their activities into other apps' tasks. Moreover, we propose a defense mechanism, dubbed signature‐based activity access control (SAAC), which completely prohibits activity injection attacks. The defense mechanism is general enough to keep the current Android multitasking features intact, and it is simple enough to be independent of the complex activity activation semantics, which does not increase activity activation time noticeably. With the extension of the formal semantics for SAAC, we prove that SAAC correctly mitigates activity injection attacks without any false alarms. Sungjae Hwang, Sukyoung Ryu |
Softw. Pract. Exp. | 1 |
| 2017 | All about activity injection: threats, semantics, and detectionabstractAndroid supports seamless user experience by maintaining activities from different apps in the same activity stack. While such close inter-app communication is essential in the Android framework, the powerful inter-app communication contains vulnerabilities that can inject malicious activities into a victim app's activity stack to hijack user interaction flows. In this paper, we demonstrate activity injection attacks with a simple malware, and formally specify the activity activation mechanism using operational semantics. Based on the operational semantics, we develop a static analysis tool, which analyzes Android apps to detect activity injection attacks. Our tool is fast enough to analyze real-world Android apps in 6 seconds on average, and our experiments found that 1,761 apps out of 129,756 real-world Android apps inject their activities into other apps' tasks. Sungjae Hwang, Sukyoung Ryu |
ASE | 2 |
| 2015 | Bittersweet ADB: Attacks and DefensesabstractAndroid devices and applications become prevalent and ask for unanticipated capabilities thanks to the increased interests in smartphones and web applications. As a way to use the capabilities not directly available to ordinary users, applications have used Android Debug Bridge (ADB), a command line tool to communicate with Android devices for debugging purposes. While ADB provides powerful features that require permissions to use critical system resources, it opens a gate to adversaries. Sungjae Hwang, Yongdae Kim, Sukyoung Ryu |
AsiaCCS | 1 |
| 2013 | MagPen: magnetically driven pen interactions on and around conventional smartphonesabstractThis paper introduces MagPen, a magnetically driven pen interface that works both on and around mobile devices. The proposed device is accompanied by a new vocabulary of gestures and techniques that increase the expressiveness of the standard capacitive stylus. These techniques are: 1) detecting the orientation that the stylus is pointing to, 2) selecting colors using locations beyond screen boundaries, 3) recognizing different spinning gestures associated with different actions, 4) inferring the pressure being applied to the pen, and 5) identifying various pens associated with different operational modes. These techniques are achieved using commonly available smartphones that sense and analyze the magnetic field produced by a permanent magnet embedded in a standard capacitive stylus. This paper explores how magnets can be used to expand the design space of current pen interaction, and proposes a new technology to achieve such results. Sungjae Hwang, Andrea Bianchi, Myungwook Ahn, Kwangyun Wohn |
Mobile HCI | 1 |
| 2013 | VibPress: estimating pressure input using vibration absorption on mobile devicesabstractThis paper introduces VibPress, a software technique that enables pressure input interaction on mobile devices by measuring the level of vibration absorption with the built-in accelerometer when the device is in contact with a damping surface (e.g., user's hands). This is achieved using a real-time estimation algorithm running on the device. Through a user evaluation, we provide evidence that this system is faster than previous software-based approaches, and accurate as hardware-augmented approaches (up to 99.7% accuracy). With this work, we also provide an insight about the maximum number of pressure levels that users can reliably distinguish, reporting usability metrics (time, errors and cognitive load) for different pressure levels and types of gripping gestures (press and squeeze). Sungjae Hwang, Andrea Bianchi, Kwangyun Wohn |
Mobile HCI | 1 |
| 2013 | MagGetz: customizable passive tangible controllers on and around conventional mobile devicesabstractThis paper proposes user-customizable passive control widgets, called MagGetz, which enable tangible interaction on and around mobile devices without requiring power or wireless connections. This is achieved by tracking and ana-lyzing the magnetic field generated by controllers attached on and around the device through a single magnetometer, which is commonly integrated in smartphones today. The proposed method provides users with a broader interaction area, customizable input layouts, richer physical clues, and higher input expressiveness without the need for hardware modifications. We have presented a software toolkit and several applications using MagGetz. Sungjae Hwang, Myungwook Ahn, Kwangyun Wohn |
UIST | 1 |
| 2011 | Aroundplot: Focus+context interface for off-screen objects in 3D environments
Hyungeun Jo, Sungjae Hwang, Jung-hee Ryu |
Comput. Graph. | 2 |
| 2010 | My Green Pet: a current-based interactive plant for childrenabstractThe difficulty that children have in perceiving plants as living entities has been verified by several studies. As an initial attempt to address this issue, we propose My Green Pet, an interactive plant for children. Through this, children enjoy human-like interactions with the plant and also perceive that this particular plant is living. This is achieved by personifying a regular plant by giving it human feelings and emotions, such as pain, joy, laughter, etc. The interactive plant is implemented over a current-based framework, which enables it to recognize multiple gestures and give audio and visual feedback to the user. The effectiveness of the interactive plant on the conception of plants on children was studied with a simple user test. We observed the children interacting with My Green Pet and noticed interactions resembling those between people. We also noticed the children being increasingly curious about the plant, resulting in spending more time with My Green Pet. A straight-forward questionnaire done by children revealed that the children's perception of life in plants greatly differed after showing My Green Pet. Sungjae Hwang, Kibeom Lee, Woonseung Yeo |
IDC | 1 |
| 2010 | EXMAR: EXpanded view of mobile augmented realityabstractThere have been many studies to minimize the psychological and physical load increase caused by mobile augmented reality systems. In this paper, we propose a new technique called “EXMAR”, which enables the user to explore his/her surroundings with an expanded field of view, resulting in a decrease of physical movement. Through this novel interaction technique, the user can explore off-screen point of interests with environmental contextual information by simple dragging gestures. To evaluate this initial approach, we conducted a proof of concept usability test under a set of scenarios such as “Exploring objects behind the user”, “Avoiding the invasion of personal space” and “Walk and type with front-view.” Through this initial examination, we found that users can explore off-screen point of interests and grasp the spatial relations without the increase of mental effort. We believe that this preliminary study gives a meaningful indication that employing the interactive field of view can be a useful method to decrease the physical load without any additional mental efforts in a mixed and augmented reality environment. Sungjae Hwang, Hyungeun Jo, Jung-hee Ryu |
ISMAR | 1 |