Sanghak Oh

dblp:195/6446 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-5047-5683ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 6 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 PP-Vul: Privacy-Preserving Vulnerability Detection Using Homomorphic Encryption
Seungho Kim, Seonhye Park, Eunsoo Kim, Sanghak Oh, Hyunmin Choi, Hyoungshick Kim
AsiaCCS5
2026 CCA-Droid: Context-Aware Cryptographic API Misuse Detection in Android Apps
abstract
We present CCA-Droid, a static analysis tool designed to detect cryptographic misuse related to chosen-ciphertext attacks (CCA) and chosen-plaintext attacks (CPA). CCA-Droid utilizes three key techniques: domain-specific slicing optimization to reduce analysis noise, crypto-state-aware call graph construction to capture indirect data flows via member variables, and conditional constant propagation for improved path sensitivity. Our evaluation demonstrates that CCA-Droid achieves 100% accuracy on CryptoAPI-Bench, surpassing CryptoGuard (72.3%), and maintains 94.8% accuracy on mutated code. Evaluations on the Ghera benchmark further confirm CCA-Droid's effectiveness, achieving 100% recall and 81.8% accuracy. On 16,284 real-world Android apps, CCA-Droid analyzed 96.4%, significantly outperforming existing tools such as CryptoGuard (80.4%) and QARK (40.0%). It identified cryptographic vulnerabilities in 12,678 apps (77.9%), with IV reuse, hardcoded keys, and missing authenticated encryption being the most prevalent issues.
Minwook Lee, Eunsoo Kim, Sanghak Oh, Joonsang Baek, Willy Susilo, Hyoungshick Kim
AsiaCCS3
2025 Poster: Insecure Coding Habits Die Hard. Can PEFT Really Turn LLMs into Secure Coders?
abstract
Large language models (LLMs) have advanced automated code generation but often produce code with critical security flaws, including buffer overflows, memory leaks, and unsafe file handling.While prior work emphasizes post-hoc vulnerability detection, we introduce a framework for secure-by-construction code generation via parameter-efficient fine-tuning (PEFT).We construct a secure training dataset by automatically fixing 7 high-impact vulnerability types in 37,540 C code samples from CodeNet, achieving 95.36% CWE reduction.We then apply prompt and prefix tuning to four open-source models (CodeGen-16B/6B-multi and StarCoder2-7B/3B), updating fewer than 1% of the parameters.On the LLMSe-cEval benchmark, our approach increases secure code generations from 20 to 36 for StarCoder2-3B and from 10 to 27 for CodeGen-6B.These results demonstrate that PEFT can substantially improve code security without full model retraining.
Sangjun Chae, Jangseop Choi, Taeyang Kim, Eun Jung, Sanghak Oh, Hyoungshick Kim
CCS5
2025 Windows plays Jenga: Uncovering Design Weaknesses in Windows File System Security
abstract
File systems are essential components of modern operating systems, with Windows being one of the most dominant platforms. Recently, a series of attacks have exploited the Windows file system to trigger serious security threats such as privilege escalation. Over the past several years, dozens of such attacks have been reported and even exploited in the wild. However, Microsoft has consistently addressed these issues with targeted patches rather than fundamental redesigns — resembling a precarious game of Jenga where security measures are stacked upon an unstable foundation. In this paper, we present a five-step comprehensive analysis of the Windows file system's design weaknesses. First, we analyze how Windows differs from another operating system, Linux. Second, we investigated how these discrepancies lead to security vulnerabilities in real-world applications and identified 13 high-impact vulnerabilities, including 11 previously unknown ones. Third, we show that current compatibility layers in modern programming languages fail to handle these discrepancies properly. Specifically, we examined compatibility layers in six programming languages and found 27 non-compliant and 9 inconsistencies, rendering these layers unreliable. Fourth, through a user study involving 21 experienced developers, we found that most were unfamiliar with OS-level file system discrepancies and rarely implemented appropriate mitigations. Finally, we analyze existing countermeasures and discuss their limitations. Our findings reveal critical yet largely obscured security risks resulting from design flaws in the Windows file system. Furthermore, we suggest that Microsoft rethink its strategy and address these fundamental weaknesses.
Dong-uk Kim, Sanghak Oh, Hyoungshick Kim, Insu Yun
CCS3
2025 Understanding and Improving User Adoption and Security Awareness in Password Checkup Services
Sanghak Oh, Heewon Baek, Jun-Ho Huh, Woojin Jeon, Ian Oakley, Hyoungshick Kim
CHI1
2025 When Does Wasm Malware Detection Fail? A Systematic Analysis of Their Robustness to Evasion
abstract
WebAssembly (Wasm) provides a language-agnostic compilation target that delivers near-native performance for web applications, yet it also attracts adversaries who exploit Wasm to effectively steal someone else’s computer resources such as cryptojackers. While several detection tools have been proposed, their robustness against perturbations remains largely unknown.In this paper, we introduce Swamped (Systematic WebAssembly Module Perturbation Evaluation of Detectors), a framework that incorporates 22 semantics-preserving perturbation methods. Swamped generates a total of 48,840 perturbed variants from 43 cryptojacker samples and 31 additional Wasm malware binaries from real-world. We assess detection performance of six detectors: three Wasm-specific ones and three deep neural network (DNN) detectors. We find that DNN-based detectors are vulnerable to perturbations that shift the instruction distribution; profiling-based methods are disrupted by changes in instruction frequency; and semantic-aware approaches are highly sensitive to function-level dependency modifications. DNN-based detectors, which lack Wasm-specific modeling, are particularly susceptible to changes in the spatial layout of Wasm binaries. These findings highlight fundamental limitations in current Wasm malware detection approaches, relying on overly specific detection heuristics and inadequately trained or designed models. We offer suggestions to improve the robustness against perturbations.
Sanghak Oh, Kiho Lee, Weihang Wang 0001, Yonghwi Kwon 0001, Sanghyun Hong 0001, Hyoungshick Kim
ASE2
2024 Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI Models
abstract
AI-powered coding assistant tools (e.g., ChatGPT, Copilot, and IntelliCode) have revolutionized the software engineering ecosystem. However, prior work has demonstrated that these tools are vulnerable to poisoning attacks. In a poisoning attack, an attacker intentionally injects maliciously crafted insecure code snippets into training datasets to manipulate these tools. The poisoned tools can suggest insecure code to developers, resulting in vulnerabilities in their products that attackers can exploit. However, it is still little understood whether such poisoning attacks against the tools would be practical in real-world settings and how developers address the poisoning attacks during software development. To understand the real-world impact of poisoning attacks on developers who rely on AI-powered coding assistants, we conducted two user studies: an online survey and an in-lab study. The online survey involved 238 participants, including software developers and computer science students. The survey results revealed widespread adoption of these tools among participants, primarily to enhance coding speed, eliminate repetition, and gain boilerplate code. However, the survey also found that developers may misplace trust in these tools because they overlooked the risk of poisoning attacks. The in-lab study was conducted with 30 professional developers. The developers were asked to complete three programming tasks with a representative type of AI-powered coding assistant tool (e.g., ChatGPT or IntelliCode), running on Visual Studio Code. The in-lab study results showed that developers using a poisoned ChatGPT-like tool were more prone to including insecure code than those using an IntelliCode-like tool or no tool. This demonstrates the strong influence of these tools on the security of generated code. Our study results highlight the need for education and improved coding practices to address new security issues introduced by AI-powered coding assistant tools.
Sanghak Oh, Kiho Lee, Seonhye Park, Doowon Kim, Hyoungshick Kim
SP1
2023 AppSniffer: Towards Robust Mobile App Fingerprinting Against VPN
abstract
Application fingerprinting is a useful data analysis technique for network administrators, marketing agencies, and security analysts. For example, an administrator can adopt application fingerprinting techniques to determine whether a user’s network access is allowed. Several mobile application fingerprinting techniques (e.g., FlowPrint, AppScanner, and ET-BERT) were recently introduced to identify applications using the characteristics of network traffic. However, we find that the performance of the existing mobile application fingerprinting systems significantly degrades when a virtual private network (VPN) is used. To address such a shortcoming, we propose a framework dubbed AppSniffer that uses a two-stage classification process for mobile app fingerprinting. In the first stage, we distinguish VPN traffic from normal traffic; in the second stage, we use the optimal model for each traffic type. Specifically, we propose a stacked ensemble model using Light Gradient Boosting Machine (LightGBM) and a FastAI library-based neural network model to identify applications’ traffic when a VPN is used. To show the feasibility of AppSniffer, we evaluate the detection accuracy of AppSniffer for 150 popularly used Android apps. Our experimental results show that AppSniffer effectively identifies mobile applications over VPNs with F1-scores between 84.66% and 95.49% across four different VPN protocols. In contrast, the best state-of-the-art method (i.e., AppScanner) demonstrates significantly lower F1-scores between 25.63% and 47.56% in the same settings. Overall, when normal traffic and VPN traffic are mixed, AppSniffer achieves an F1-score of 90.63%, which is significantly better than AppScanner that shows an F1-score of 70.36%.
Sanghak Oh, Minwook Lee, Hyunwoo Lee 0001, Elisa Bertino, Hyoungshick Kim
WWW1
2022 Poster: Adversarial Perturbation Attacks on the State-of-the-Art Cryptojacking Detection System in IoT Networks
abstract
The popularity of cryptocurrency raised a new cyber security threat dubbed cryptojacking representing malicious activities for abusing victims' computing resources without their consent to mine cryptocurrency. Recently, Tekiner et al. [1] proposed an effective cryptojacking detection technique using a machine learning model with the statistical properties of the network traffic for cryptojacking in the Internet of Things (IoT) devices. In this paper, however, we demonstrate that this state-of-the-art method can effectively be evaded by maliciously manipulating the network packets for cryptojacking. Our evaluation results show that packet manipulations (packet splitting, dummy packet/payload insertion, and a proxy network) can effectively evade the model's detection -- the packet splitting technique significantly decreased the F1-score of the detection model from 0.93 to 0.30. Finally, the best combination of those packet manipulations can decrease the F1-score of the detection model to 0.21.
Kiho Lee, Sanghak Oh, Hyoungshick Kim
CCS2