EDBT 2026 Demo / reviewers in the wild / expert
Taegyu Kim
dblp:157/5259
· DBLP profile ↗
16ranked-venue papers
6as first author
9since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 5 first-author · 6 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Fuzzing Acceleration for Memory Safety Bug Discovery with SlicerabstractMemory safety bugs are major threats to software because they occupy 65%-70% of severe security bugs. Consequently, researchers have introduced directed fuzzers and directed coverage-guided fuzzers, which can target memory safety bugs. However, they waste much time testing uninteresting code that may not contain memory safety bugs. In this paper, we propose Slicer, a program slicing technique, to accelerate directed fuzzing targeting memory safety bugs. The key idea is to remove as many code snippets irrelevant to memory safety bugs from target programs as possible to minimize uninteresting code execution. For that, Slicer first identifies and keeps the code snippets, such as memory access code, memory management code (e.g., malloc), and relevant control flow statements, that potentially violate memory safety. Next, Slicer identifies and keeps extra code snippets, such as program initialization code, that are required to run programs. Finally, Slicer removes the other code snippets. This approach is beneficial to directed fuzzers when they target memory safety bugs because Slicer can improve performance orthogonal to the points that directed fuzzers improve. We evaluate Slicer with 24 programs and found ten new bugs with seven CVEs. Furthermore, Slicer accelerates program execution speed 1.61× faster. Moreover, Slicer shows 1.52× improved testing coverage for code relevant to memory safety bugs when integrated with directed coverage-guided and coverage-guided fuzzers, ParmeSan and Darwin. Finally, integrating Slicer with three directed fuzzers, AFLGo, WindRanger, and SelectFuzz shows 1.64× faster memory safety bug discovery than those fuzzers without Slicer. Giyeol Kim, Dohyun Ryu, Seungjin Bae, Changyul Lee, Taegyu Kim |
ACSAC | 5 |
| 2025 | NeuroScope: Reverse Engineering Deep Neural Network on Edge Devices using Dynamic Analysis
Muqi Zou, Arslan Khan, Taegyu Kim, Dongyan Xu, Jing (Dave) Tian, Antonio Bianchi |
USENIX Security Symposium | 4 |
| 2024 | Differential Fuzzing for Data Distribution Service Programs with Dynamic ConfigurationabstractData Distribution Service (DDS) is a distributed network protocol widely used in cyber-physical systems. DDS provides flexible configurations defined in the formal design specification for safety and security. However, DDS programs suffer from both semantic bugs violating design specifications and software implementation bugs. To discover bugs, network protocol fuzzers have focused on testing client-server models by mutating input packets. However, they are unsuitable for fuzzing DDS programs due to a lack of consideration of the DDS-specific features, such as the DDS-specific input spaces (e.g., dynamic network topology formation and QoS and DDS security configurations) and impacts of DDS-specific semantic bugs (e.g., incorrect topology construction). Dohyun Ryu, Giyeol Kim, Seungjin Bae, Junghwan Rhee, Taegyu Kim |
ASE | 7 |
| 2024 | LTA: Control-Driven UAV Testing and Bug Localization with Flight Record DecompositionabstractAs UAVs have been widely used in various domains, such as the military and industry, their safety and security have become crucial. One of their root causes is software bugs, which fall into two bug categories: traditional software bugs, such as memory safety bugs, and UAV-specific logical model-misimplementation (LMM) bugs leading to physical misbehavior, such as crashes. To discover and localize bugs, many proactive and reactive techniques have been proposed. However, LMM bug mitigation techniques are still immature, unlike well-established techniques for traditional software bugs, because existing approaches are unable to track the causal relationship between the LMM bug root cause in software and its resulting physical misbehavior. Specifically, existing proactive approaches require extensive, time-consuming dynamic testing to capture the physical impacts of LMM bug exploitation amidst a vast input space. Conversely, previous reactive approaches are inaccurate because existing work cannot accurately identify the causal relationship between misbehavior and bug-triggering inputs mixed with benign but suspicious inputs. Changyul Lee, Deokjin Kim, Giyeol Kim, Taegyu Kim |
SenSys | 5 |
| 2022 | ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUsabstractController Area Network (CAN) is the de-facto standard in-vehicle network system. Despite its wide adoption by automobile manufacturers, the lack of security design makes it vulnerable to attacks. For instance, broadcasting packets without authentication allows the impersonation of electronic control units (ECUs). Prior mitigations, such as message authentication or intrusion detection systems, fail to address the compatibility requirement with legacy ECUs, stealthy and sporadic malicious messaging, or guaranteed attack detection. We propose a novel authentication system called ShadowAuth that overcomes the aforementioned challenges by offering backwardcompatible packet authentication to ECUs without requiring ECU firmware source code. Specifically, our authentication scheme provides transparent CAN packet authentication without modifying existing CAN packet definitions (e.g., J1939) via automatic ECU firmware instrumentation technique to locate CAN packet transmission code, and instrument authentication code based on the CAN packet behavioral transmission patterns. ShadowAuth enables vehicles to detect state-of-the-art CAN attacks, such as busoff and packet injection, responsively within 60ms without false positives. ShadowAuth provides a sound and deployable solution for real-world ECUs. Sungwoo Kim 0005, Gisu Yeo, Taegyu Kim, Junghwan Rhee, Yuseok Jeon, Antonio Bianchi, Dongyan Xu, Jing (Dave) Tian |
AsiaCCS | 3 |
| 2022 | Reverse engineering and retrofitting robotic aerial vehicle control firmware using dispatchabstractUnmanned Aerial Vehicles as a service (UAVaaS) has increased the field deployment of Robotic Aerial Vehicles (RAVs) for different services such as transportation and terrain exploration. These RAVs are controlled by firmware, which is often closed-source, developed by vendors, and flashed into the ROM. While these binary blobs enable off-the-shelf management of RAVs, end users (individuals or organizations) have no idea if the control firmware is designed and implemented correctly, and can only rely on firmware updates from vendors when any vulnerability is discovered. This paper proposes DisPatch, the first reverse engineering and patching framework for understanding and improving controller design and implementation within RAV firmware. DisPatch first decompiles binary instructions and recovers controller functions and core controller variables by combining control theory with program analysis using symbolic execution and data flow analysis. End users can then write a patch in a domain-specific language (DSL), which will be translated and injected into the binary firmware by DisPatch automatically. We have applied DisPatch to two instances of commodity firmware from3DR IRIS+ and MantisQ RAVs and demonstrated 100% and 80.7% accuracy respectively in the controller decompilation. We have also shown the ability to prevent severe controller performance degradation by patching two real-world bugs with in the firmware and without breaking other functionality. Finally, we show that DisPatch introduces less than 0.53% of space overhead and 1.48% of runtime overhead without violating the soft real-time deadlines. DisPatch provides the first step towards an RAV binary firmware reverse engineering and patching system to customize controller design and implementation. Taegyu Kim, Aolin Ding, Sriharsha Etigowni, Jizhou Chen, Luis Garcia 0001, Saman A. Zonouz, Dongyan Xu, Jing (Dave) Tian |
MobiSys | 1 |
| 2022 | FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksabstractUniversal Serial Bus (USB) is the de facto protocol supported by peripherals and mobile devices, such as USB thumb drives and smart phones. For many devices, USB Type-C ports are the primary interface for charging, file transfer, audio, video, etc. Accordingly, attackers have exploited different vulnerabilities within USB stacks, compromising host machines via BadUSB attacks or jailbreaking iPhones from USB connections. While there exist fuzzing frameworks dedicated to USB vulnerability discovery, all of them focus on USB host stacks and ignore USB gadget stacks, which enable all the features within modern peripherals and smart devices. In this paper, we propose FuzzUSB, the first fuzzing framework for the USB gadget stack within commodity OS kernels, leveraging static analysis, symbolic execution, and stateful fuzzing. FuzzUSB combines static analysis and symbolic execution to extract internal state machines from USB gadget drivers, and uses them to achieve state-guided fuzzing through multi-channel inputs. We have implemented FuzzUSB upon the syzkaller kernel fuzzer and applied it to the most recent mainline Linux, Android, and FreeBSD kernels. As a result, we have found 34 previously unknown bugs within the Linux and Android kernels, and opened 8 CVEs. Furthermore, compared to the baseline, FuzzUSB has also demonstrated different improvements, including $ 3\times$ higher code coverage, $ 50\times$ improved bug-finding efficiency for Linux USB gadget stacks, $ 2\times$ higher code coverage for FreeBSD USB gadget stacks, and reproducing known bugs that could not be detected by the baseline fuzzers. We believe FuzzUSB provides developers a powerful tool to thwart USB-related vulnerabilities within modern devices and complete the current USB fuzzing scope. Kyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee, Kevin R. B. Butler, Antonio Bianchi, Jing (Dave) Tian |
SP | 2 |
| 2022 | DnD: A Cross-Architecture Deep Neural Network Decompiler
Taegyu Kim, Jing (Dave) Tian, Antonio Bianchi, Dongyan Xu |
USENIX Security Symposium | 2 |
| 2021 | PASAN: Detecting Peripheral Access Concurrency Bugs within Bare-Metal Embedded Applications
Taegyu Kim, Vireshwar Kumar, Junghwan Rhee, Jizhou Chen, Kyungtae Kim, Dongyan Xu, Jing (Dave) Tian |
USENIX Security Symposium | 1 |
| 2020 | From Control Model to Program: Investigating Robotic Aerial Vehicle Accidents with MAYDAY
Taegyu Kim, Altay Ozen, Fei Fan 0002, Zhan Tu, Xiangyu Zhang 0001, Jing (Dave) Tian, Dongyan Xu |
USENIX Security Symposium | 1 |
| 2019 | RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided Testing
Taegyu Kim, Junghwan Rhee, Fei Fan 0002, Zhan Tu, Gregory Walkup, Xiangyu Zhang 0001, Dongyan Xu |
USENIX Security Symposium | 1 |
| 2018 | Cross-Layer Retrofitting of UAVs Against Cyber-Physical AttacksabstractAs a rapidly growing cyber-physical platform, unmanned aerial vehicles are facing more security threats as their capabilities and applications continue to expand. Adversaries with detailed knowledge about the vehicle could orchestrate sophisticated attacks that are not easily detected or handled by the vehicle's control system. In this work, we purpose a generic security framework, termed BlueBox, capable of detecting and handling a variety of cyber-physical attacks. To demonstrate an application of BlueBox in practice, we retrofitted an off-the-shelf quadcopter. A series of attacks were then launched by embedding malicious code in the control software and by altering the vehicle's hardware with the specific targeting of sensors, controller, motors, vehicle dynamics, and operating system. Experimental results verified that BlueBox was capable of both detecting a variety of cyber-physical attacks, while also providing the means in which to recover from such attacks. Fei Fan 0002, Zhan Tu, Ruikun Yu, Taegyu Kim, Xiangyu Zhang 0001, Dongyan Xu |
ICRA | 4 |
| 2018 | Securing Real-Time Microcontroller Systems through Customized Memory View Switching
Taegyu Kim, Hongjun Choi, Zhongshu Gu, Byoungyoung Lee, Xiangyu Zhang 0001, Dongyan Xu |
NDSS | 2 |
| 2018 | Learning from the Ones that Got Away: Detecting New Forms of Phishing AttacksabstractPhishing attacks continue to pose a major threat for computer system defenders, often forming the first step in a multi-stage attack. There have been great strides made in phishing detection; however, some phishing emails appear to pass through filters by making simple structural and semantic changes to the messages. We tackle this problem through the use of a machine learning classifier operating on a large corpus of phishing and legitimate emails. We design SAFe-PC (Semi-Automated Feature generation for Phish Classification), a system to extract features, elevating some to higher level features, that are meant to defeat common phishing email detection strategies. To evaluate SAFe-PC , we collect a large corpus of phishing emails from the central IT organization at a tier-1 university. The execution of SAFe-PC on the dataset exposes hitherto unknown insights on phishing campaigns directed at university users. SAFe-PC detects more than 70 percent of the emails that had eluded our production deployment of Sophos, a state-of-the-art email filtering tool. It also outperforms SpamAssassin, a commonly used email filtering tool. We also developed an online version of SAFe-PC, that can be incrementally retrained with new samples. Its detection performance improves with time as new samples are collected, while the time to retrain the classifier stays constant. Christopher N. Gutierrez, Taegyu Kim, Raffaele Della Corte, Jeffrey Avery, Dan Goldwasser, Marcello Cinque, Saurabh Bagchi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | RevARM: A Platform-Agnostic ARM Binary Rewriter for Security ApplicationsabstractARM is the leading processor architecture in the emerging mobile and embedded market. Unfortunately, there has been a myriad of security issues on both mobile and embedded systems. While many countermeasures of such security issues have been proposed in recent years, a majority of applications still cannot be patched or protected due to run-time and space overhead constraints and the unavailability of source code. More importantly, the rapidly evolving mobile and embedded market makes any platform-specific solution ineffective. In this paper, we propose RevARM, a binary rewriting technique capable of instrumenting ARM-based binaries without limitation on the target platform. Unlike many previous binary instrumentation tools that are designed to instrument binaries based on x86, RevARM must resolve a number of new, ARM-specific binary rewriting challenges. Moreover, RevARM is able to handle stripped binaries, requires no symbolic/semantic information, and supports Mach-O binaries, overcoming the limitations of existing approaches. Finally, we demonstrate the capabilities of RevARM in solving real-world security challenges. Our evaluation results across a variety of platforms, including popular mobile and embedded systems, show that RevARM is highly effective in instrumenting ARM binaries with an average of 3.2% run-time and 1.3% space overhead. Taegyu Kim, Hongjun Choi, Yonghwi Kwon 0001, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
ACSAC | 1 |
| 2015 | Malfinder: Accelerated Malware Classification System through Filtering on Manycore SystemabstractControl flow matching methods have been utilized to detect malware variants. However, as the number of malware variants has soared, it has become harder and harder to detect all malware variants while maintaining high accuracy. Even though many researchers have proposed control flow matching methods, there is still a trade-off between accuracy and performance. To solve this trade-off, we designed Malfinder, a method based on approximate matching, which is accurate but slow. To overcome its low performance, we resolve its performance bottleneck and non-parallelism on three fronts: I-Filter for identical string matching, table division to exclude unnecessary comparisons with some malware and dynamic resource allocation for efficient parallelism. Our performance evaluation shows that the total performance improvement is 280.9 times. Taegyu Kim, Woomin Hwang, Chulmin Kim, Dong-Jae Shin, Ki-Woong Park, Kyu Ho Park 0002 |
ICISSP | 1 |