EDBT 2026 Demo / reviewers in the wild / expert
Jaejong Baek
dblp:186/6013
· DBLP profile ↗
8ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-8588-3524ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Deception by Design: A Configurable Platform for Flexible Cyber Deception Strategy Testing and Evaluation
Sukwha Kyung, Souradip Nath, Jaejong Baek, Gail-Joon Ahn |
ACNS (3) | 3 |
| 2026 | Towards Agentic AI for Access Control in Cyber-infrastructures: Exploring the Security and Human Factors: [BlueSky Paper]abstractAccess Control (AC) remains one of the fundamental paradigms of computer security due to its potential to mitigate serious threats by restricting access to sensitive resources within emerging technologies. However, despite decades of research, the life-cycle, i.e., specification, evaluation, and enforcement, of AC policies in modern cyber-infrastructures remains incomplete, inaccurate, and unverified, which largely decreases their effectiveness and efficiency to counteract emerging threats and vulnerabilities. Carlos E. Rubio-Medrano, Souradip Nath, Ananta Soneji, Jennifer Mondragon, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 5 |
| 2025 | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing InfrastructuresabstractResearch Computing Infrastructures (RCIs) inte-grate high-performance computing, advanced data storage solutions, and sophisticated network protocols, connecting people, data, and computing resources to facilitate scientific collaboration in today's data-driven world. Access control is essential in such highly collaborative environments to prevent resource misutilization, safeguard data integrity, and allocate resources effectively, thereby enabling secure and trusted in-teractions among different users. However, unlocking the full potential of RCIs for collaborative research through effective access control requires more than technological exploration-it demands a deep, human-centered understanding of the stakeholders who operate and utilize these systems. In this paper, we present the first qualitative study that explores the human dimensions of RCI interactions, drawing insights from 24 key stakeholders, including researchers and system administrators, across 12 research institutions to ex-amine the collaborative practices, challenges, and needs with a focus on access control. Our findings reveal operational complexities and project-specific, trust-based resource-sharing dynamics, highlighting tensions between security and usability. Based on these insights, we provide stakeholder-driven rec-ommendations and requirements for adaptive, user-centered access control for RCIs, laying the groundwork for advancing human-centered security practices in RCIs. Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doupé, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
SP | 3 |
| 2023 | Targeted Privacy Attacks by Fingerprinting Mobile Apps in LTE Radio LayerabstractWe investigate the feasibility of targeted privacy attacks using only information available in physical channels of LTE mobile networks and propose three privacy attacks to demonstrate this feasibility: mobile-app fingerprinting attack, history attack, and correlation attack. These attacks can reveal the geolocation of targeted mobile devices, the victim's app usage patterns, and even the relationship between two users within the same LTE network cell. An attacker also may launch these attacks stealthily by capturing radio signals transmitted over the air, using only a passive sniffer as equipment. To ensure the impact of these attacks on mobile users' privacy, we perform evaluations in both laboratory and real-world settings, demonstrating their practicality and dependability. Furthermore, we argue that these attacks can target not only 4G/LTE but also the evolving 5G standards. Jaejong Baek, Pradeepkumar Duraisamy, Sukwha Kyung, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
DSN | 1 |
| 2023 | SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented RealityabstractMobile Augmented Reality (MAR) is a portable, powerful, and suitable technology that integrates digital content, e.g., 3D virtual objects, into the physical world, which not only has been implemented for multiple intents such as shopping, entertainment, gaming, etc., but it is also expected to grow at a tremendous rate in the upcoming years. Unfortunately, the applications that implement MAR, hereby referred to as MAR-Apps, bear security issues, which have been imaged in worldwide incidents such as robberies, which has led authorities to ban MAR-Apps at specific locations. Existing problems with MAR-Apps can be classified into three categories: first, Space Invasion, which implies the intrusive modification through MAR of sensitive spaces, e.g., hospitals, memorials, etc. Second, Space Affectation, which involves the degradation of users' experience via interaction with undesirable MAR or malicious entities. Finally, MAR-Apps mishandling sensitive data leads to Privacy Leaks. Luis Claramunt, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 3 |
| 2021 | Poster: Preventing Spatial and Privacy Attacks in Mobile Augmented Reality TechnologiesabstractThe growing popularity of applications featuring Mobile Augmented Reality (MAR) raises serious concerns regarding the use of such a game-changing technology inside sensitive physical spaces, e.g., memorials, hospitals, museums, etc., such that the safety and privacy of users is preserved. To address such concerns, we present our ongoing work for mediating the way MAR Content, e.g., digital objects rendered on top of a video stream, is generated, distributed, and consumed by applications. We introduce a theoretical model, a supporting framework, as well as SpaceMediator, a proof-of-concept application implementing our approach. Luis Claramunt, Larissa Pokam Epse, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 4 |
| 2021 | Poster: DyPolDroid: User-Centered Counter-Policies Against Android Permission-Abuse AttacksabstractAndroid applications are extremely popular, as they are used for banking, social media, e-commerce, etc. However, several malicious applications have recently carried out data leaks and spurious credit card charges by abusing the Android Permissions granted initially to them by unaware users in good faith. To alleviate this pressing concern, we present DyPolDroid, a dynamic, semi-automated security framework that builds upon Android Enterprise, a device-management framework for organizations, allowing for users to design and enforce custom Counter-Policies, effectively protecting against such malicious applications without requiring advanced security and/or technical expertise. Matthew Hill, Carlos E. Rubio-Medrano, Luis Claramunt, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 4 |
| 2018 | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi CallingabstractWi-Fi Calling, which is used to make and receive calls over the Wi-Fi network, has been widely adopted and deployed to extend the coverage and increase the capacity in weak signal areas by moving traffic from LTE to Wi-Fi networks. However, the security of Wi-Fi Calling mechanism has not been fully analyzed, and Wi-Fi Calling may inherently have greater security risks than conventional LTE calling. To provide secure connections with confidentiality and integrity, Wi-Fi Calling leverages the IETF protocols IKEv2 and IPSec. Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ACSAC | 1 |