Juhwan Noh

dblp:167/0564 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0001-6730-1893ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Revisiting GPS Spoofing in Phasor Measurement: Real-World Exploitation and Practical Detection in Power Grids
abstract
Phasor Measurement Units (PMUs) are critical devices in modern power grids, providing precise voltage and current phasor measurements (synchrophasors) for real-time monitoring, fault detection, and stability assessment. While previous research suggested that arbitrary time manipulation through GPS spoofing could disrupt grid operations, our study reveals that successful attacks require specific conditions, contrary to earlier assumptions. Through careful analysis of the synchrophasor data specification (IEEE Standard C37.118.x), we demonstrate that arbitrary time manipulation does not directly lead to phase manipulation. Instead, arbitrary manipulations can cause GPS holdover (loss of lock), alert operators with erroneous timing, and ultimately invalidate the received synchrophasors. An experiment with a commercial PMU confirms our specification analysis. We identify the time spoofing conditions to avoid GPS holdover and discover that nanosecond-scale signal alignment (approximately 375 ns error) and gradual time manipulation (around 50 ns/s error) are required. Experiments on a commercial Wide Area Monitoring System (WAMS) testbed demonstrate that GPS spoofing meeting the identified criteria results in a 500-microsecond time error (10.8-degree phase error) after 12 hours without triggering alarms. Given that a 60-degree phase variation is considered a fault, triggering protection mechanisms, this GPS spoofing technique could potentially induce false faults within 70 hours. To counter this threat, we propose a practical method to distinguish GPS spoofing-induced false faults from actual faults caused by events like lightning strikes or ground shorts. Analysis of 10 real-world incidents from the past six months demonstrates that genuine faults consistently exhibit instantaneous phase variations within three electrical cycles, providing a basis for differentiation.
Chung-Hyo Kim, Juhwan Noh, Esmaeil Ghahremani, Yongdae Kim
ACM Trans. Priv. Secur.2
2023 Un-Rocking Drones: Foundations of Acoustic Injection Attacks and Recovery Thereof
Jinseob Jeong, Dongkwan Kim 0001, Joon-Ha Jang, Juhwan Noh, Changhun Song, Yongdae Kim
NDSS4
2023 Lightbox: Sensor Attack Detection for Photoelectric Sensors via Spectrum Fingerprinting
abstract
Photoelectric sensors are utilized in a range of safety-critical applications, such as medical devices and autonomous vehicles. However, the public exposure of the input channel of a photoelectric sensor makes it vulnerable to malicious inputs. Several studies have suggested possible attacks on photoelectric sensors by injecting malicious signals. While a few defense techniques have been proposed against such attacks, they could be either bypassed or used for limited purposes. In this study, we propose Lightbox, a novel defense system to detect sensor attacks on photoelectric sensors based on signal fingerprinting. Lightbox uses the spectrum of the received light as a feature to distinguish the attacker’s malicious signals from the authentic signal, which is a signal from the sensor’s light source. We evaluated Lightbox against (1) a saturation attacker, (2) a simple spoofing attacker, and (3) a sophisticated attacker who is aware of Lightbox and can combine multiple light sources to mimic the authentic light source. Lightbox achieved the overall accuracy over 99% for the saturation attacker and simple spoofing attacker, and robustness against a sophisticated attacker. We also evaluated Lightbox considering various environments such as transmission medium, background noise, and input waveform. Finally, we demonstrate the practicality of Lightbox with experiments using a single-board computer after further reducing the training time.
Dohyun Kim 0004, ManGi Cho, Hocheol Shin, Juhwan Noh, Yongdae Kim
ACM Trans. Priv. Secur.5
2022 Path-Aware and Structure-Preserving Generation of Synthetically Accessible Molecules
abstract
Computational chemistry aims to autonomously design specific molecules with target functionality. Generative frameworks provide useful tools to learn continuous representations of molecules in a latent space. While modelers could optimize chemical properties, many generated molecules are not synthesizable. To design synthetically accessible molecules that preserve main structural motifs of target molecules, we propose a reaction-embedded and structure-conditioned variational autoencoder. As the latent space jointly encodes molecular structures and their reaction routes, our new sampling method that measures the path-informed structural similarity allows us to effectively generate structurally analogous synthesizable molecules. When targeting out-of-domain as well as in-domain seed structures, our model generates structurally and property-wisely similar molecules equipped with well-defined reaction paths. By focusing on the important region in chemical space, we also demonstrate that our model can design new molecules with even higher activity than the seed molecules.
Juhwan Noh, Dae-Woong Jeong, Kiyoung Kim, Sehui Han, Moontae Lee, Honglak Lee, Yousung Jung
ICML1
2020 The System That Cried Wolf: Sensor Security Analysis of Wide-area Smoke Detectors for Critical Infrastructure
abstract
Fire alarm and signaling systems are a networked system of fire detectors, fire control units, automated fire extinguishers, and fire notification appliances. Malfunction of these safety-critical cyber-physical systems may lead to chaotic evacuations, property damage, and even loss of human life. Therefore, reliability is one of the most crucial factors for fire detectors. Indeed, even a single report of a fire cannot be ignored, considering the importance of early fire detection and suppression. In this article, we show that wide-area smoke detectors, which are globally installed in critical infrastructures such as airports, sports facilities, and auditoriums, have significant vulnerabilities in terms of reliability; one can remotely and stealthily induce false fire alarms and suppress real fire alarms with a minimal attacker capability using simple equipment. The practicality and generalizability of these vulnerabilities has been assessed based on the demonstration of two types of sensor attacks on two commercial off-the-shelf optical beam smoke detectors from different manufacturers. Further, the practical considerations of building stealthy attack equipment has been analyzed, and an extensive survey of almost all optical beam smoke detectors on the market has been conducted. In addition, we show that the current standards of the fire alarm network connecting the detector and a control unit exacerbate the problem, making it impossible or very difficult to mitigate the threats we found. Finally, we discuss hardware- and software-based possible countermeasures for both wide-area smoke detectors and the fire alarm network; the effectiveness of one of the countermeasures is experimentally evaluated.
Hocheol Shin, Juhwan Noh, Dohyun Kim 0004, Yongdae Kim
ACM Trans. Priv. Secur.2
2019 Tractor Beam: Safe-hijacking of Consumer Drones with Adaptive GPS Spoofing
abstract
The consumer drone market is booming. Consumer drones are predominantly used for aerial photography; however, their use has been expanding because of their autopilot technology. Unfortunately, terrorists have also begun to use consumer drones for kamikaze bombing and reconnaissance. To protect against such threats, several companies have started “anti-drone” services that primarily focus on disrupting or incapacitating drone operations. However, the approaches employed are inadequate, because they make any drone that has intruded stop and remain over the protected area. We specify this issue by introducing the concept of safe-hijacking , which enables a hijacker to expel the intruding drone from the protected area remotely. As a safe-hijacking strategy, we investigated whether consumer drones in the autopilot mode can be hijacked via adaptive GPS spoofing. Specifically, as consumer drones activate GPS fail-safe and change their flight mode whenever a GPS error occurs, we performed black- and white-box analyses of GPS fail-safe flight mode and the following behavior after GPS signal recovery of existing consumer drones. Based on our analyses results, we developed a taxonomy of consumer drones according to these fail-safe mechanisms and designed safe-hijacking strategies for each drone type. Subsequently, we applied these strategies to four popular drones: DJI Phantom 3 Standard, DJI Phantom 4, Parrot Bebop 2, and 3DR Solo. The results of field experiments and software simulations verified the efficacy of our safe-hijacking strategies against these drones and demonstrated that the strategies can force them to move in any direction with high accuracy.
Juhwan Noh, Yujin Kwon, Yunmok Son, Hocheol Shin, Dohyun Kim 0004, Jaeyeong Choi, Yongdae Kim
ACM Trans. Priv. Secur.1
2018 GyrosFinger: Fingerprinting Drones for Location Tracking Based on the Outputs of MEMS Gyroscopes
abstract
Drones are widely used for various purposes such as delivery, aerial photography, and surveillance. Considering the increasing drone-related services, tracking the locations of drones can cause security threats such as escaping from drone surveillance, disturbing drone-related services, and capturing drones. For wirelessly monitoring the status of drones, telemetry is used, and this status information contains various data such as latitude and longitude, calibrated sensor outputs, and sensor offsets. Because most of the telemetry implementation supports neither authentication nor encryption, an attacker can obtain the status information of the drones by using an appropriate wireless communication device such as software-defined radio. While the attacker knows the locations of the drones from the status information, this information is not sufficient for tracking drones because the status information does not include any identity information that can bind the identity of the drone with its location. <?tight?>In this article, we propose a fingerprinting method for drones in motion for the binding of the identity of the drone with its location. Our fingerprinting method is based on the sensor outputs included in the status information, i.e., the offsets of micro-electro mechanical systems (MEMS) gyroscope, an essential sensor for maintaining the attitude of drones. We found that the offsets of MEMS gyroscopes are different from each other because of manufacturing mismatches, and the offsets of five drones obtained through their telemetry are distinguishable and constant during their flights. To evaluate the performance of our fingerprinting method on a larger scale, we collected the offsets from 70 stand-alone MEMS gyroscopes to generate fingerprints. Our experimental results show that, when using the offsets of three and two axes calculated from 128 samples of the raw outputs per axis as fingerprints, the F-scores of the proposed method reach 98.78% and 94.47%, respectively. The offsets collected after a month are also fingerprinted with F-scores of 96.58% and 78.45% under the same condition, respectively. The proposed fingerprinting method is effective, robust, and persistent. Additionally, unless the MEMS gyroscope is not replaced, our fingerprinting method can be used for drone tracking even when the target drones are flying.
Yunmok Son, Juhwan Noh, Jaeyeong Choi, Yongdae Kim
ACM Trans. Priv. Secur.2
2016 Dissecting Customized Protocols: Automatic Analysis for Customized Protocols based on IEEE 802.15.4
abstract
IEEE 802.15.4 is widely used as lower layers for not only wellknown wireless communication standards such as ZigBee, 6LoWPAN, and WirelessHART, but also customized protocols developed by manufacturers, particularly for various Internet of Things (IoT) devices. Customized protocols are not usually publicly disclosed nor standardized. Moreover, unlike textual protocols (e.g., HTTP, SMTP, POP3.), customized protocols for IoT devices provide no clues such as strings or keywords that are useful for analysis. Instead, they use bits or bytes to represent header and body information in order to save power and bandwidth. On the other hand, they often do not employ encryption, fragmentation, or authentication to save cost and effort in implementations. In other words, their security relies only on the confidentiality of the protocol itself.
Kibum Choi, Yunmok Son, Juhwan Noh, Hocheol Shin, Jaeyeong Choi, Yongdae Kim
WISEC3
2015 Rocking Drones with Intentional Sound Noise on Gyroscopic Sensors
Yunmok Son, Hocheol Shin, Dongkwan Kim 0001, Young-Seok Park, Juhwan Noh, Kibum Choi, Jungwoo Choi, Yongdae Kim
USENIX Security Symposium5