Sunoo Park

dblp:123/8680 · DBLP profile ↗
← Back
16ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-1884-9585ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 6 since 2021Theory of computation · 6Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Real-World Law-Enforcement Hack: The Case of Encrochat
Martin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas Stebila
CRYPTO (10)2
2026 "Security vs. Interoperability" Arguments: An Analytical Framework
abstract
Concerns about big tech's monopoly power have featured prominently in recent media and policy discourse, as regulators across the European Union (EU), the United States (US) and beyond have ramped up efforts to promote healthier market competition. One favored approach is to require certain kinds of interoperation between platforms, to mitigate the current concentration of power in the biggest companies. Unsurprisingly, interoperability initiatives have generally been met with resistance by big tech companies. Perhaps more surprisingly, a significant part of that pushback has been in the name of security -- that is, arguing against interoperation on the basis that it will undermine security. We conduct a systematic examination of "security vs. interoperability" (SvI) discourse in the context of EU antitrust and competition proceedings. Our resulting contributions are threefold. First, we propose a taxonomy of SvI concerns in three categories: engineering, vetting, and hybrid. Second, we present an analytical framework for assessing real-world SvI concerns, and illustrate its utility by analyzing several case studies spanning our three taxonomy categories. Third, we undertake a comparative analysis that highlights key considerations around the interplay of economic incentives, market power, and security across our diverse case study contexts, identifying common patterns in each taxonomy category. Our contributions provide valuable analytical tools for experts and non-experts alike to critically assess SvI discourse in today's fast-paced regulatory landscape.
Daji Landis, Elettra Bietti, Sunoo Park
EuroS&P3
2026 LendLocked: Privacy & Transparency for Digital Library Lending
abstract
Digital library lending is a critical resource for access to information. Currently prevalent models of digital lending, however, involve opaque licensing schemes that entail serious drawbacks to reader privacy and freedom of expression. In popular modern library apps, publishers and hidden intermediaries control a wealth of information about readers and reading habits, at a scale and level of detail that would be essentially impossible in physical library lending. To understand digital lending needs in practice, our work begins with a series of interviews with library professionals (N=11). We present thematic findings on their concerns with existing systems, including privacy, surveillance, preservation, and lack of library control over resources. Many of the concerns raised are inherently unproblematic in the context of physical library lending---leading us to our central technical question: Can digital lending achieve privacy and transparency at least as strong as physical library lending? Based on our qualitative findings, we provide the first rigorous modeling of security, privacy, and transparency requirements in digital library lending. As existing systems fall short of the strong guarantees we model, we propose a new system design, LendLocked, based on cryptography and trusted hardware, and prove it achieves these guarantees in the random oracle model. We micro-benchmark our design's key cryptographic functionalities, showing tolerable efficiency at the scale of the largest libraries.
Boya Wang, Sunoo Park
Proc. Priv. Enhancing Technol.3
2025 The Pitfalls of "Security by Obscurity" and What They Mean for Transparent AI
abstract
Calls for transparency in AI systems are growing in number and urgency from diverse stakeholders ranging from regulators to researchers to users (with a comparative absence of companies developing AI). Notions of transparency for AI abound, each addressing distinct interests and concerns. In computer security, transparency is likewise regarded as a key concept. The security community has for decades pushed back against so-called security by obscurity - the idea that hiding how a system works protects it from attack - against significant pressure from industry and other stakeholders, e.g., (Bellovin and Bush 2002). And over those decades, in a community process that is imperfect and ongoing, security researchers and practitioners have gradually built up some norms and practices around how to balance transparency interests with possible negative side effects. This paper asks: What insights can the AI community take from the security community's experience with transparency? We identify three key themes in the security community's perspective on the \emph{benefits of transparency} and their approach to balancing transparency against countervailing interests. For each, we investigate parallels and insights relevant to transparency in AI. We then provide a case study discussion on how transparency has shaped the research subfield of anonymization. Finally, shifting our focus from similarities to differences, we highlight key transparency issues where modern AI systems present challenges different from other kinds of security-critical systems, raising interesting open questions for the security and AI communities alike.
Olivia Mundahl, Sunoo Park
AAAI3
2024 Scan, Shuffle, Rescan: Two-Prover Election Audits With Untrusted Scanners
Douglas W. Jones, Sunoo Park, Ronald L. Rivest, Adam Sealfon
FC (2)2
2023 The Superlinearity Problem in Post-quantum Blockchains
Sunoo Park, Nicholas Spooner
FC (1)1
2021 KeyForge: Non-Attributable Email from Forward-Forgeable Signatures
Michael A. Specter, Sunoo Park, Matthew Green 0001
USENIX Security Symposium2
2020 Fully Deniable Interactive Encryption
Ran Canetti, Sunoo Park, Oxana Poburinnaya
CRYPTO (1)2
2020 Data structures meet cryptography: 3SUM with preprocessing
abstract
This paper shows several connections between data structure problems and cryptography against preprocessing attacks. Our results span data structure upper bounds, cryptographic applications, and data structure lower bounds, as summarized next.
Alexander Golovnev, Siyao Guo 0001, Thibaut Horel, Sunoo Park, Vinod Vaikuntanathan
STOC4
2019 It Wasn't Me! - Repudiability and Claimability of Ring Signatures
Sunoo Park, Adam Sealfon
CRYPTO (3)1
2019 How to Subvert Backdoored Encryption: Security Against Adversaries that Decrypt All Ciphertexts
abstract
In this work, we examine the feasibility of secure and undetectable point-to-point communication when an adversary (e.g., a government) can read all encrypted communications of surveillance targets. We consider a model where the only permitted method of communication is via a government-mandated encryption scheme, instantiated with government-mandated keys. Parties cannot simply encrypt ciphertexts of some other encryption scheme, because citizens caught trying to communicate outside the government's knowledge (e.g., by encrypting strings which do not appear to be natural language plaintexts) will be arrested. The one guarantee we suppose is that the government mandates an encryption scheme which is semantically secure against outsiders: a perhaps reasonable supposition when a government might consider it advantageous to secure its people's communication against foreign entities. But then, what good is semantic security against an adversary that holds all the keys and has the power to decrypt? We show that even in the pessimistic scenario described, citizens can communicate securely and undetectably. In our terminology, this translates to a positive statement: all semantically secure encryption schemes support subliminal communication. Informally, this means that there is a two-party protocol between Alice and Bob where the parties exchange ciphertexts of what appears to be a normal conversation even to someone who knows the secret keys and thus can read the corresponding plaintexts. And yet, at the end of the protocol, Alice will have transmitted her secret message to Bob. Our security definition requires that the adversary not be able to tell whether Alice and Bob are just having a normal conversation using the mandated encryption scheme, or they are using the mandated encryption scheme for subliminal communication. Our topics may be thought to fall broadly within the realm of steganography. However, we deal with the non-standard setting of an adversarially chosen distribution of cover objects (i.e., a stronger-than-usual adversary), and we take advantage of the fact that our cover objects are ciphertexts of a semantically secure encryption scheme to bypass impossibility results which we show for broader classes of steganographic schemes. We give several constructions of subliminal communication schemes under the assumption that key exchange protocols with pseudorandom messages exist (such as Diffie-Hellman, which in fact has truly random messages).
Thibaut Horel, Sunoo Park, Silas Richelson, Vinod Vaikuntanathan
ITCS2
2018 Static-Memory-Hard Functions, and Modeling the Cost of Space vs. Time
Thaddeus Dryja, Quanquan C. Liu, Sunoo Park
TCC (1)3
2018 Practical Accountability of Secret Processes
Jonathan Frankle, Sunoo Park, Daniel Shaar, Shafi Goldwasser, Daniel J. Weitzner
USENIX Security Symposium2
2016 How to Incentivize Data-Driven Collaboration Among Competing Parties
abstract
The availability of vast amounts of data is changing how we can make medical discoveries, predict global market trends, save energy, and develop new educational strategies. In certain settings such as Genome Wide Association Studies or deep learning, the sheer size of data (patient files or labeled examples) seems critical to making discoveries. When data is held distributed by many parties, as often is the case, they must share itly to reap its full benefits.
Pablo Azar 0002, Shafi Goldwasser, Sunoo Park
ITCS3
2015 Adaptively Secure Coin-Flipping, Revisited
Shafi Goldwasser, Yael Tauman Kalai, Sunoo Park
ICALP (2)3
2014 Cryptographically blinded games: leveraging players' limitations for equilibria and profit
abstract
In this work we apply methods from cryptography to enable mutually distrusting players to implement broad classes of mediated equilibria of strategic games without trusted mediation. Our implementation uses a pre-play 'cheap talk' phase, consisting of non- binding communication between players prior to play in the original game. In the cheap talk phase, the players run a secure multi-party computation protocol to sample from an equilibrium of a "cryptographically blinded" version of the game, in which actions are encrypted.
Pavel Hubácek, Sunoo Park
EC2