Yoon-Ho Choi

dblp:04/2081 · DBLP profile ↗
← Back
21ranked-venue papers
9as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 3 since 2021Systems, architecture and hardware · 4 · 3 since 2021Computer networks · 4 · 4 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 A user-centric privacy transformation framework for federated learning in industrial internet of things
Assem Utaliyeva, Yoon-Ho Choi
J. Inf. Secur. Appl.2
2026 Container-Specific Service Mesh-Based System for Mitigating Lateral Movement Attacks
abstract
The dynamic nature of containers within a Kubernetes cluster substantially expands the potential attack surface. In particular, lateral movement attacks enable adversaries to compromise additional subsystems after gaining initial access. To defend against lateral movement attacks, most anomaly detection methods rely on offline learning using system call data accumulated over a period of time. However, such offline learning methods struggle to capture the unique system call patterns of individual containers and lack adaptability to changes caused by frequent container updates. To address these limitations, we propose a new service mesh-based system for online learning of container-specific system call patterns observed under cloud-native microservice environments. The proposed service mesh-based system consists of three key functional processes as follows: (i) a zero-copy-based system call collection process, which leverages eBPF for efficient monitoring; (ii) an anomaly detection and container isolation process, which employs lightweight machine learning models, and leverages a proxy container for swift traffic control; and (iii) a container-specific online learning process, which continuously updates anomaly detection models by learning observed system call sequences. From the experimental results, we show that the proposed zero-copy-based system call collection process significantly improves system call collection speeds by as much as 4.5 times and shows lower CPU usage by as much as half compared to other state-of-the-art methods. Furthermore, the container-specific online learning process consistently outperforms offline learning approaches across various system call datasets and maintains stable detection performance by continuously adapting to behavioral changes caused by container updates over time.
Geon-Woo Yoon, Jin-Myeong Shin, Jae-Seok Kim, Seunghyuk Kim, Jaeyoung Jeong, Yoon-Ho Choi
IEEE Trans. Cloud Comput.6
2026 DeFiTrace: Event-Enriched Detection of Price Oracle Manipulation Across DeFi Transactions
abstract
The rapid growth of Decentralized Finance (DeFi) has been accompanied by increasingly sophisticated security threats. Price Oracle Manipulation Attacks (POMA), a critical vulnerability, have evolved beyond simple economic exploits to include complex, multi-transaction attacks that exploit smart contract logic, causing hundreds of millions in losses. State-of-the-art detection methods, however, often focus on single-transaction, economic manipulations and typically fail to identify these emerging attack vectors, particularly when smart contract source code is unavailable. This article introduces a novel, EVM-compatible detection pipeline that addresses this gap. By combining transaction event logs and execution traces, we engineer a rich set of semantic and structural features that capture the underlying behavior of on-chain operations. We train a regularized autoencoder exclusively on the features of benign transactions to learn a deep representation of normal activity, flagging significant deviations as malicious. Our evaluation demonstrates the effectiveness of this approach, achieving 100% recall on a comprehensive dataset of single-transaction attacks and 98.25% event-level recall on a new, manually collected dataset of real-world multi-transaction exploits, with an overall precision of 97.15%. We present a robust, learning-based model capable of identifying both known and unseen POMA variants without relying on source code. Furthermore, we contribute a new dataset of multi-transaction attacks to foster further research, providing a more generalizable and resilient approach to securing the DeFi ecosystem.
Millati Pratiwi, Yoon-Ho Choi
ACM Trans. Priv. Secur.2
2024 Zero-SAD: Zero-Shot Learning Using Synthetic Abnormal Data for Abnormal Behavior Detection on Private Cloud
abstract
While many studies have been conducted to detect abnormal behavior in cloud environments by analyzing system call sequences, these studies often cannot be applied to real-world cloud environments since they do not consider actual user behavior and rely on publicly available datasets. In actual cloud environments, the frequency of duplicate system calls is significantly higher than that observed in these datasets. This discrepancy necessitates a considerably larger scale of analysis to fully understand the sequential relationships among system calls. In this paper, we propose a practical abnormal behavior detection system for private cloud environments. The proposed system comprises of a deduplicated embedding process that efficiently represents duplicate system calls occurring within the cloud into a single embedding vector and a zero-shot abnormal behavior detection process that rapidly analyzes the large volume of system call sequences generated by numerous users through a zero-shot learning model. To demonstrate the practicality of our proposed system, we use both publicly available datasets and datasets directly collected from real cloud environments by implementing attacks from the MITRE ATT&CK framework as a proof of concept (PoC). Experimental results show that our system achieved an accuracy an accuracy of 92.13%, and it can detect attacks 5.48 times faster than existing research.
Jae-Seok Kim, Joonho Seo, SeonJin Hwang, Jin-Myeong Shin, Yoon-Ho Choi
SoCC5
2023 PIHA: Detection method using perceptual image hashing against query-based adversarial attacks
Seok-Hwan Choi 0001, Jin-Myeong Shin, Yoon-Ho Choi
Future Gener. Comput. Syst.3
2023 WINE: Warning miner for improving bug finders
Yoon-Ho Choi, Jaechang Nam
Inf. Softw. Technol.1
2023 Semantics-Preserving Reinforcement Learning Attack Against Graph Neural Networks for Malware Detection
abstract
As an increasing number of deep-learning-based malware scanners have been proposed, the existing evasion techniques, including code obfuscation and polymorphic malware, are found to be less effective. In this work, we propose a reinforcement learning based semantics-preserving (i.e. functionality-preserving) attack against black-box GNNs (Graph Neural Networks) for malware detection. The key factor of adversarial malware generation via semanticNopsinsertion is to select the appropriate semanticNopsand their corresponding basic blocks. The proposed attack uses reinforcement learning to automatically make these “how to select” decisions. To evaluate the attack, we have trained two kinds of GNNs with three types (e.g., Backdoor, Trojan, and Virus) of Windows malware samples and various benign Windows programs. The evaluation results have shown that the proposed attack can achieve a significantly higher evasion rate than four baseline attacks, namely the binary diversification attack, the semantics-preserving random instruction insertion attack, the semantics-preserving accumulative instruction insertion attack, and the semantics-preserving gradient-based instruction insertion attack.
Lan Zhang 0008, Peng Liu 0005, Yoon-Ho Choi, Ping Chen 0003
IEEE Trans. Dependable Secur. Comput.3
2022 On the Naturalness of Bytecode Instructions
abstract
Bytecode is used in software analysis and other approaches due to its advantages such as high availability and simple specification. Therefore, to leverage these advantages in training language models with bytecode, it is important to clearly recognize the characteristics of the naturalness of bytecode. However, the naturalness of bytecode has not been actively explored.
Yoon-Ho Choi, Jaechang Nam
ASE1
2020 Using deep learning to solve computer security challenges: a survey
abstract
Abstract Although using machine learning techniques to solve computer security challenges is not a new idea, the rapidly emerging Deep Learning technology has recently triggered a substantial amount of interests in the computer security community. This paper seeks to provide a dedicated review of the very recent research works on using Deep Learning techniques to solve computer security challenges. In particular, the review covers eight computer security problems being solved by applications of Deep Learning: security-oriented program analysis, defending return-oriented programming (ROP) attacks, achieving control-flow integrity (CFI), defending network attacks, malware classification, system-event-based anomaly detection, memory forensics, and fuzzing for software security.
Yoon-Ho Choi, Peng Liu 0005, Zitong Shang, Lan Zhang 0008, Junwei Zhou 0002, Qingtian Zou
Cybersecur.1
2019 Unsupervised multi-stage attack detection framework without details on single-stage attacks
Jin-Myeong Shin, Seok-Hwan Choi 0001, Peng Liu 0005, Yoon-Ho Choi
Future Gener. Comput. Syst.4
2019 Dynamic Nonparametric Random Forest Using Covariance
abstract
As the representative ensemble machine learning method, the Random Forest (RF) algorithm has widely been used in diverse applications on behalf of the fast learning speed and the high classification accuracy. Research on RF can be classified into two categories: (1) improving the classification accuracy and (2) decreasing the number of trees in a forest. However, most of papers related to the performance improvement of RF have focused on improving the classification accuracy. Only some papers have focused on reducing the number of trees in a forest. In this paper, we propose a new Covariance-Based Dynamic RF algorithm, called C-DRF. Compared to the previous works, while ensuring the good-enough classification accuracy, the proposed C-DRF algorithm reduces the number of trees. Specifically, by computing the covariance between the number of trees in a forest and F -measure at each iteration, the proposed algorithm determines whether to increase the number of trees composing a forest. To evaluate the performance of the proposed C-DRF algorithm, we compared the learning time, the test time, and the memory usage with the original RF algorithm under the different areas of datasets. Under the same or higher classification accuracy, it is shown that the proposed C-DRF algorithm improves the performance of the original RF algorithm by as much as 58.68% at learning time, 47.91% at test time, and 68.06% in memory usage on average. As a practical application area, we also show that the proposed C-DRF algorithm is more efficient than the state-of-the-art RF algorithms in Network Intrusion Detection (NID) area.
Seok-Hwan Choi 0001, Jin-Myeong Shin, Yoon-Ho Choi
Secur. Commun. Networks3
2017 A similarity query system for road traffic data based on a NoSQL document store
Titus Irma Damaiyanti, Ardi Imawan, Fitri Indra Indikawati, Yoon-Ho Choi, Joonho Kwon
J. Syst. Softw.4
2016 A game theoretic model for dynamic configuration of large-scale intrusion detection signatures
Xaiver Jerald Punithan, Jong-Deok Kim, Dongseok Kim, Yoon-Ho Choi
Multim. Tools Appl.4
2013 BLAST: B-LAyered bad-character SHIFT tables for high-speed pattern matching
abstract
In this study, the authors propose a new multi‐pattern matching algorithm, called BLAST (B‐LAyered bad‐character Shift Tables with a single‐byte search unit), which considers space‐time tradeoff in the context of shift values during the search. Here, the term ‘bad character’ is a character that causes a mismatch. While checking multiple bytes in scanning the text at a time, the BLAST algorithm overcomes the reduction of the average shift value in a typical search, which is caused by the dependency on the multi‐byte search unit (MBSU) and the large frequency of the last character of the given patterns. From the theoretical analysis, the authors validate the correctness of the BLAST algorithm. Also, from the experimental results across different setups, the authors show that the BLAST algorithm provides the faster search time than the other algorithms. For example, the authors obtain an enhancement by as much as 212.41% on average for various numbers of attack patterns and attack traffic conditions compared with that of the modified Wu‐Manber algorithm. In addition, it is shown that the BLAST algorithm drastically reduces the amount of memory required for constructing the shift table based on a MBSU from 64 KB to 1 KB.
Yoon-Ho Choi, Seung-Woo Seo
IET Inf. Secur.1
2012 Comparing Statistical and Data Mining Approaches to Classify 4-year Risk for Progression of Coronary Artery Calcification in Men
Hye Jin Kam, Ha-Young Kim, Sanghyun Yoo, Kyoung-Gu Woo, Yoon-Ho Choi, Jidong Sung, Sung Won Cho
AMIA6
2012 Prediction of Carotid Artery Stenosis using Ensemble-based Classification
Sanghyun Yoo, Ha-Young Kim, Hye Jin Kam, Kyoung-Gu Woo, Yoon-Ho Choi, Hee Young Shin, Mira Kang
AMIA6
2011 A fast pattern matching algorithm with multi-byte search unit for high-speed network security
Yoon-Ho Choi, Moon-Young Jung, Seung-Woo Seo
Comput. Commun.1
2010 Creation of the importance scanning worm using information collected by Botnets
Yoon-Ho Choi, Peng Liu 0005, Seung-Woo Seo
Comput. Commun.1
2010 Worm virulence estimation for the containment of local worm outbreak
Yoon-Ho Choi, Lunquan Li, Peng Liu 0005, George Kesidis
Comput. Secur.1
2008 L+1-MWM: A Fast Pattern Matching Algorithm for High-Speed Packet Filtering
abstract
A signature-based network intrusion detection system (NIDS) identifies intrusions by comparing the data traffic with known signature patterns. In this process, matching of packet strings against signature patterns dominates the overall system performance. The MWM algorithm has been known as the fastest pattern matching algorithm when the patterns in a rule set rarely appear in packets. However, the matching time does not decrease if the length of the shortest pattern in a signature group is too short. In this paper, by extending the length of the shortest pattern, we minimize the pattern matching time of the algorithm which uses multi-byte unit. For example, when the length of the shortest pattern is less than 5, the proposed algorithm shows 38.87% enhancement in average.
Yoon-Ho Choi, Moon-Young Jung, Seung-Woo Seo
INFOCOM1
2006 A WDM Optical Packet Switch based on Wavelength Converter Blocks with Heterogeneous Conversion Capability
abstract
The wavelength-division-multiplexing (WDM) optical packet switches (OPSes) using wavelength converters (WCs) have been focused to improve the optical network performance significantly. Among them, a shared-per-node (SPN) switch architecture has been considered as a way to utilize WCs efficiently. In this paper, we propose a new switch control algorithm for the architecture, which reduces the total number of wavelength conversion degree (WCD) of a wavelength converter block (WCB). The algorithm also reduces the number of WCs with higher WCD while minimizing the packet loss by wavelength contention at outbound links. Based on this algorithm, we then design a flexible WDM OPS architecture. The proposed algorithm, different from the previous works, focuses on using the heterogeneous wavelength converter blocks (HeWCBs), where a HeWCB consists of WCs with different WCD. The proposed HeWCBs are motivated by the observation that the conventional WDM OPS architecture seldom uses long-range convertible WCs. The architecture shows the same packet loss probability as that of the homogeneous WCBs (HoWCBs) consisting of WCs with the same WCD. Through analysis and simulation, it is shown that the WDM OPS architecture using a combination of WCs of WCD less than or equal to d achieves the same performance as using HoWCBs with WCs of WCD d.
Yoon-Ho Choi, Seung-Woo Seo
GLOBECOM1