Hyungsub Kim

dblp:155/0040 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 6 first-author · 8 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Intent-aware Fuzzing for Android Hardened Application
abstract
The widespread adoption of app hardening techniques in Android applications makes it more challenging for current analysis techniques to analyze hardened apps, leading to limited analysis coverage. This limitation is mainly due to the difficulties in obtaining detailed information about Intents, which is essential for component communication and the execution of specific events in Android applications.
Seongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi, Hyungsub Kim, Yuseok Jeon
CCS5
2025 Automated Discovery of Semantic Attacks in Multi-Robot Navigation Systems
Doguhan Yeke, Kartik Anand Pant, Muslum Ozgur Ozmen, Hyungsub Kim, James Goppert, Inseok Hwang 0002, Antonio Bianchi, Z. Berkay Celik
USENIX Security Symposium4
2025 Multiagent Distributed DQN and Transfer Learning for Energy-Efficient Power Management in Solar Energy-Harvested Small-Cell Networks
abstract
The integration of solar energy harvesting into small-cell networks is a promising solution for achieving energy-efficient and sustainable wireless communications. However, the inherent variability and intermittency of solar energy, coupled with precise intercell interference management, significantly hinder efficient network operation. To resolve these challenges, we propose a multiagent distributed deep Q-network framework, where the distributed base stations learn the optimal transmit power control policies. To further enhance adaptability under varying solar conditions, we present a daily model transfer with a fine-tuning approach, enabling efficient deployment without extensive training overhead. Simulation results demonstrate that the proposed methods remarkably improve energy efficiency while maintaining robust adaptability under dynamic solar conditions, revealing their potential for sustainable small-cell network deployments.
Hyebin Cho, Hyungsub Kim, Jeehyeon Na, Seung-Chan Lim, Howon Lee 0001
IEEE Internet Things J.2
2024 Hybrid LoRa Network Architecture: Automatic Switching between LoRaWAN and LoRa Mesh Network in Environments with Dynamic Obstacle Variations
abstract
The LoRaWAN network is widely employed in agricultural Internet of Things (IoT) applications requiring long-range wireless communication and low-energy consumption. However, challenges arise in dynamic environments like woodlands, where obstacles such as tree foliage disrupt the Fresnel zone and absorb signals. A previous study proposes a solution utilizing a LoRa Mesh Network (LoRa Meshnet) capable of establishing connections under tree canopies. Still, LoRa Meshnet is less battery-efficient than LoRaWAN. Thus, relying solely on LoRa Meshnet is inefficient in situations where LoRaWAN communication is affected by dynamic obstacles like seasonally varying foliage. To address this, we introduce a hybrid LoRa network architecture that utilizes LoRaWAN as the primary network and LoRa Meshnet as the backup, automatically switching between them. This approach ensures energy efficiency in sparse foliage situations by using LoRaWAN while guaranteeing stable data transmission in dense foliage scenarios with the use of LoRa Meshnet. Additionally, the system offers easy network deployment and cost-effectiveness.
Hyungsub Kim, Hayoung Kim, Somi Baek, Ryan Melenchuk, Jaden Soroka
ICCCN1
2024 A Systematic Study of Physical Sensor Attack Hardness
abstract
Physical sensor attacks against robotic vehicles (RV) have become a serious concern due to their prevalence and potential physical threat. However, RV software developers often do not deploy appropriate countermeasures. This hesitance stems from their belief that attackers face substantial challenges when conducting sensor attacks, e.g., nullifying sensor redundancy in hardware and circumventing sensor filters in software. Yet, we discover that attackers can overcome the challenges by fulfilling specific prerequisites and finely tuning attack parameters. The misconceptions that the developers have arisen from a lack of study regarding the level of difficulty attackers face in successfully achieving their attack goals, which we call "attack hardness".In this paper, we examine the hardness of 12 well-known sensor attacks. We first identify the prerequisites required to conduct the attacks successfully. We then quantify the hardness of each attack as how frequent the prerequisites enabling a specific attack are in the real world. To automate this analysis, we introduce RVPROBER, an attack prerequisite analysis framework. RVPROBER discovered that the 12 sensor attacks require, on average, 4.4 prerequisites, highlighting that previous literature has often missed important details required to perform these attacks. By satisfying the identified prerequisites and tuning attack parameters, we increased the number of successful attacks from 6 to 11. Moreover, our analysis showed that an average of 57.08% of actual RV users are vulnerable to sensor attacks. Finally, starting from the identified prerequisites, we analyzed the reasons behind the success of each attack and found previously-unknown root causes, such as design flaws in the RV software’s fail-safe logic.
Hyungsub Kim, Rwitam Bandyopadhyay, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi, Yongdae Kim, Dongyan Xu
SP1
2023 PatchVerif: Discovering Faulty Patches in Robotic Vehicles
Hyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi, Dongyan Xu
USENIX Security Symposium1
2023 Discovering Adversarial Driving Maneuvers against Autonomous Vehicles
Ruoyu Song 0001, Muslum Ozgur Ozmen, Hyungsub Kim, Raymond Muller, Z. Berkay Celik, Antonio Bianchi
USENIX Security Symposium3
2022 PGPatch: Policy-Guided Logic Bug Patching for Robotic Vehicles
abstract
Automated program repair (APR) methods aim to identify patches for a given bug and apply them with minimal human intervention. To date, existing APR approaches focus on repairing software bugs, such as memory safety bugs. However, our analysis of popular robotic vehicle (RV) control software shows that most of their bugs are not memory bugs but rather logic bugs. These bugs, while not causing software crashes, can cause an RV to reach an undesired physical state (e.g., hitting the ground). To fix these logic bugs, we introduce PGPatch, a policy-guided program repair framework for RV control programs, which identifies the correct patch for a given logic bug and applies it without human intervention. PGPatch takes, as input, existing or new logic formulas used to discover logic bugs. It then leverages the formulas using a dedicated dynamic analysis to classify the previously known logic bugs into a patch type. It next uses a customized algorithm, based on the identified patch type and violated formula, to produce a source code patch as output. Lastly, it creates repeatable tests to verify the patch’s completeness, ensuring that the patch is correct and does not degrade the RV’s performance. We evaluate PGPatch on selected bug cases from three popular RV control software and find that it correctly fixes 258 out of 297 logic bugs (86.9%). We additionally recruit 18 experienced RV developers and users and conduct a user study that demonstrates how using PGPatch makes fixing bugs in RV software significantly quicker and less error-prone.
Hyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi, Dongyan Xu
SP1
2021 PGFUZZ: Policy-Guided Fuzzing for Robotic Vehicles
Hyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik, Dongyan Xu
NDSS1
2021 M2MON: Building an MMIO-based Security Reference Monitor for Unmanned Vehicles
Arslan Khan, Hyungsub Kim, Byoungyoung Lee, Dongyan Xu, Antonio Bianchi, Jing (Dave) Tian
USENIX Security Symposium2
2016 Inferring browser activity and status through remote monitoring of storage usage
Hyungsub Kim, Sangho Lee 0001, Jong Kim 0001
ACSAC1
2015 Identifying Cross-origin Resource Status Using Application Cache
Sangho Lee 0001, Hyungsub Kim, Jong Kim 0001
NDSS2
2014 Exploring and mitigating privacy threats of HTML5 geolocation API
abstract
The HTML5 Geolocation API realizes location-based services via theWeb by granting web sites the geographical location information of user devices. However, the Geolocation API can violate a user's location privacy due to its coarse-grained permission and location models. The API provides either exact location or nothing to web sites even when they only require approximate location. In this paper, we first conduct case studies on numerous web browsers and web sites to explore how they implement and utilize the Geolocation API. We detect 14 vulnerable web browsers and 603 overprivileged web sites that can violate a user's location privacy. To mitigate the privacy threats of the Geolocation API, we propose a novel scheme that (1) supports fine-grained permission and location models, and (2) recommends appropriate privacy settings to each user by inspecting the location sensitivity of each web page. Our scheme can accurately estimate each web page's necessary geolocation degree (estimation accuracy: ~93.5%). We further provide suggestions to improve the Geolocation API.
Hyungsub Kim, Sangho Lee 0001, Jong Kim 0001
ACSAC1