EDBT 2026 Demo / reviewers in the wild / expert
Hyun Kwon
dblp:215/8223
· DBLP profile ↗
24ranked-venue papers
19as first author
19since 2021 · last 2026
0000-0003-1169-9892ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 8 first-author · 6 since 2021Artificial intelligence and machine learning · 8 · 7 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Selective black-box adversarial examples: Protecting a specific model while inducing misperceptions in others
Hyun Kwon, Jang-Woon Baek |
Neurocomputing | 1 |
| 2026 | GaussGuard: Leave-one-out detection and mitigation of view-conditional poisoning attacks on 3D Gaussian Splatting
Hyun Kwon, Jang-Woon Baek |
Neurocomputing | 1 |
| 2026 | Inducing divergent misclassifications: dual-targeted adversarial attacks on video recognition models
Hyun Kwon |
Mach. Vis. Appl. | 1 |
| 2026 | Selective access control for medical image classification via friend-safe semantic-aware reversible adversarial examples
Hyun Kwon |
Mach. Vis. Appl. | 1 |
| 2026 | Time-constrained adversarial attacks for video recognition models: temporally sparse but effective perturbations
Joo Bon Maeng, Hyun Kwon |
Mach. Vis. Appl. | 2 |
| 2025 | Comrade-Secure Adversarial Noise for 3D Point Cloud Classification Model
Taehwa Lee, Hyun Kwon |
IET Image Process. | 3 |
| 2024 | AudioGuard: Speech Recognition System Robust against Optimized Audio Adversarial Examples
Hyun Kwon |
Multim. Tools Appl. | 1 |
| 2023 | Detecting textual adversarial examples through text modification on text classification systems
Hyun Kwon |
Appl. Intell. | 1 |
| 2023 | Multi-targeted audio adversarial example for use against speech recognition systems
Kyoungmin Ko, Sunghwan Kim 0003, Hyun Kwon |
Comput. Secur. | 3 |
| 2023 | Erratum to 'Ensemble transfer attack targeting text classification systems' [Computers & Security 117 (2022) 1-8/ 102695]
Hyun Kwon |
Comput. Secur. | 1 |
| 2023 | Audio adversarial detection through classification score on speech recognition systems
Hyun Kwon, Seung-Hun Nam |
Comput. Secur. | 1 |
| 2023 | Adversarial image perturbations with distortions weighted by color on deep neural networks
Hyun Kwon |
Multim. Tools Appl. | 1 |
| 2022 | Ensemble transfer attack targeting text classification systems
Hyun Kwon |
Comput. Secur. | 1 |
| 2022 | Friend-guard adversarial noise designed for electroencephalogram-based brain-computer interface spellers
Hyun Kwon |
Neurocomputing | 1 |
| 2022 | BlindNet backdoor: Attack on deep neural network using blind watermark
Hyun Kwon, Yongchul Kim |
Multim. Tools Appl. | 1 |
| 2022 | Compliance-Driven Cybersecurity Planning Based on Formalized Attack Patterns for Instrumentation and Control Systems of Nuclear Power PlantsabstractThe instrumentation and control (I&C) system of a nuclear power plant (NPP) employs a cybersecurity program regulated by the government. Through regulation, the government requires the implementation of security controls in order for a system to be developed and operated. Accordingly, the licensee of an NPP works to comply with this requirement, beginning in the development phase. The compliance-driven approach is efficient when the government supervises NPPs, but it is inefficient when a licensee constructs them. The security controls described in regulatory guidance do not consider system characteristics. In other words, the development organization spends a considerable amount of time excluding unnecessary control items and preparing the evidence to justify their exclusion. In addition, security systems can vary according to the developer’s level of security knowledge, leading to differences in levels of security between systems. This paper proposes a method for a developer to select the appropriate security controls when preparing the security requirements during the early development phase; it is designed to ensure the system’s security and reduce the cost of excluding unnecessary security controls. We have formalized the representation of attack patterns and security control patterns and identified the relationships between these patterns. We conducted a case study applying RG 5.71 in the Plant Protection System (PPS) to confirm the validity of the proposed method. Minsoo Lee, Hyun Kwon, Hyunsoo Yoon |
Secur. Commun. Networks | 2 |
| 2021 | Vision Control Unit in Fully Self Driving Vehicles using Xilinx MPSoC and Opensource StackabstractFully self-driving (FSD) vehicles are becoming increasing popular over the last few years and companies are investing significantly into its research and development. In the recent years, FSD technology innovators like Tesla, Google etc. have been working on proprietary autonomous driving stacks and have been able to successfully bring the vehicle to the roads. On the other end, organizations like Autoware Foundation and Baidu are fueling the growth of self-driving mobility using open source stacks. These organizations firmly believe in enabling autonomous driving technology for everyone and support developing software stacks through the open source community that is SoC vendor agnostic. In this proposed solution we describe a vision control unit for a fully self-driving vehicle developed on Xilinx MPSoC platform using open source software components. Ravikumar V. Chakaravarthy, Hyun Kwon |
ASP-DAC | 2 |
| 2021 | Classification score approach for detecting adversarial example in deep neural networkabstractAbstract Deep neural networks (DNNs) provide superior performance on machine learning tasks such as image recognition, speech recognition, pattern analysis, and intrusion detection. However, an adversarial example, created by adding a little noise to an original sample, can cause misclassification by a DNN. This is a serious threat to the DNN because the added noise is not detected by the human eye. For example, if an attacker modifies a right-turn sign so that it misleads to the left, autonomous vehicles with the DNN will incorrectly classify the modified sign as pointing to the left, but a person will correctly classify the modified sign as pointing to the right. Studies are under way to defend against such adversarial examples. The existing method of defense against adversarial examples requires an additional process such as changing the classifier or modifying input data. In this paper, we propose a new method for detecting adversarial examples that does not invoke any additional process. The proposed scheme can detect adversarial examples by using a pattern feature of the classification scores of adversarial examples. We used MNIST and CIFAR10 as experimental datasets and Tensorflow as a machine learning library. The experimental results show that the proposed method can detect adversarial examples with success rates: 99.05% and 99.9% for the untargeted and targeted cases in MNIST, respectively, and 94.7% and 95.8% for the untargeted and targeted cases in CIFAR10, respectively. Hyun Kwon, Yongchul Kim, Hyunsoo Yoon, Daeseon Choi |
Multim. Tools Appl. | 1 |
| 2021 | MedicalGuard: U-Net Model Robust against Adversarially Perturbed ImagesabstractDeep neural networks perform well for image recognition, speech recognition, and pattern analysis. This type of neural network has also been used in the medical field, where it has displayed good performance in predicting or classifying patient diagnoses. An example is the U-Net model, which has demonstrated good performance in data segmentation, an important technology in the field of medical imaging. However, deep neural networks are vulnerable to adversarial examples. Adversarial examples are samples created by adding a small amount of noise to an original data sample in such a way that to human perception they appear to be normal data but they will be incorrectly classified by the classification model. Adversarial examples pose a significant threat in the medical field, as they can cause models to misidentify or misclassify patient diagnoses. In this paper, I propose an advanced adversarial training method to defend against such adversarial examples. An advantage of the proposed method is that it creates a wide variety of adversarial examples for use in training, which are generated by the fast gradient sign method (FGSM) for a range of epsilon values. A U-Net model trained on these diverse adversarial examples will be more robust to unknown adversarial examples. Experiments were conducted using the ISBI 2012 dataset, with TensorFlow as the machine learning library. According to the experimental results, the proposed method builds a model that demonstrates segmentation robustness against adversarial examples by reducing the pixel error between the original labels and the adversarial examples to an average of 1.45. Hyun Kwon |
Secur. Commun. Networks | 1 |
| 2020 | Acoustic-decoy: Detection of adversarial examples through audio modification on speech recognition systemabstractDeep neural networks (DNNs) display good performance in the domains of recognition and prediction, such as on tasks of image recognition, speech recognition, video recognition, and pattern analysis. However, adversarial examples, created by inserting a small amount of noise into the original samples, can be a serious threat because they can cause misclassification by the DNN. Adversarial examples have been studied primarily in the context of images, but their effect in the audio context is now drawing considerable interest as well. For example, by adding a small distortion to an original audio sample, imperceptible to humans, an audio adversarial example can be created that humans hear as error-free but that causes misunderstanding by a machine. Therefore, it is necessary to create a method of defense for resisting audio adversarial examples. In this paper, we propose an acoustic-decoy method for detecting audio adversarial examples. Its key feature is that it adds well-formalized distortions using audio modification that are sufficient to change the classification result of an adversarial example but do not affect the classification result of an original sample. Experimental results show that the proposed scheme can detect adversarial examples by reducing the similarity rate for an adversarial example to 6.21%, 1.27%, and 0.66% using low-pass filtering (with 12 dB roll-off), 8-bit reduction, and audio silence removal techniques, respectively. It can detect an audio adversarial example with a success rate of 97% by performing a comparison with the initial audio sample. Hyun Kwon, Hyunsoo Yoon, Ki-Woong Park |
Neurocomputing | 1 |
| 2020 | Selective Audio Adversarial Example in Evasion Attack on Speech Recognition SystemabstractDeep neural networks (DNNs) are widely used for image recognition, speech recognition, and other pattern analysis tasks. Despite the success of DNNs, these systems can be exploited by what is termed adversarial examples. An adversarial example, in which a small distortion is added to the input data, can be designed to be misclassified by the DNN while remaining undetected by humans or other systems. Such adversarial examples have been studied mainly in the image domain. Recently, however, studies on adversarial examples have been expanding into the voice domain. For example, when an adversarial example is applied to enemy wiretapping devices (victim classifiers) in a military environment, the enemy device will misinterpret the intended message. In such scenarios, it is necessary that friendly wiretapping devices (protected classifiers) should not be deceived. Therefore, the selective adversarial example concept can be useful in mixed situations, defined as situations in which there is both a classifier to be protected and a classifier to be attacked. In this paper, we propose a selective audio adversarial example with minimum distortion that will be misclassified as the target phrase by a victim classifier but correctly classified as the original phrase by a protected classifier. To generate such examples, a transformation is carried out to minimize the probability of incorrect classification by the protected classifier and that of correct classification by the victim classifier. We conducted experiments targeting the state-of-the-art DeepSpeech voice recognition model using Mozilla Common Voice datasets and the Tensorflow library. They showed that the proposed method can generate a selective audio adversarial example with a 91.67% attack success rate and 85.67% protected classifier accuracy. Hyun Kwon, Yongchul Kim, Hyunsoo Yoon, Daeseon Choi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | POSTER: Detecting Audio Adversarial Example through Audio ModificationabstractDeep neural networks (DNNs) perform well in the fields of image recognition, speech recognition, pattern analysis, and intrusion detection. However, DNNs are vulnerable to adversarial examples that add a small amount of noise to the original samples. These adversarial examples have mainly been studied in the field of images, but their effect on the audio field is currently of great interest. For example, adding small distortion that is difficult to identify by humans to the original sample can create audio adversarial examples that allow humans to hear without errors, but only to misunderstand the machine. Therefore, a defense method against audio adversarial examples is needed because it is a threat in this audio field. In this paper, we propose a method to detect audio adversarial examples. The key point of this method is to add a new low level distortion using audio modification, so that the classification result of the adversarial example changes sensitively. On the other hand, the original sample has little change in the classification result for low level distortion. Using this feature, we propose a method to detect audio adversarial examples. To verify the proposed method, we used the Mozilla Common Voice dataset and the DeepSpeech model as the target model. Based on the experimental results, it was found that the accuracy of the adversarial example decreased to 6.21% at approximately 12 dB. It can detect the audio adversarial example compared to the initial audio sample. Hyun Kwon, Hyunsoo Yoon, Ki-Woong Park |
CCS | 1 |
| 2018 | POSTER: Zero-Day Evasion Attack Analysis on Race between Attack and DefenseabstractDeep neural networks (DNNs) exhibit excellent performance in machine learning tasks such as image recognition, pattern recognition, speech recognition, and intrusion detection. However, the usage of adversarial examples, which are intentionally corrupted by noise, can lead to misclassification. As adversarial examples are serious threats to DNNs, both adversarial attacks and methods of defending against adversarial examples have been continuously studied. Zero-day adversarial examples are created with new test data and are unknown to the classifier; hence, they represent a more significant threat to DNNs. To the best of our knowledge, there are no analytical studies in the literature of zero-day adversarial examples with a focus on attack and defense methods through experiments using several scenarios. Therefore, in this study, zero-day adversarial examples are practically analyzed with an emphasis on attack and defense methods through experiments using various scenarios composed of a fixed target model and an adaptive target model. The Carlini method was used for a state-of-the-art attack, while an adversarial training method was used as a typical defense method. We used the MNIST dataset and analyzed success rates of zero-day adversarial examples, average distortions, and recognition of original samples through several scenarios of fixed and adaptive target models. Experimental results demonstrate that changing the parameters of the target model in real time leads to resistance to adversarial examples in both the fixed and adaptive target models. Hyun Kwon, Hyunsoo Yoon, Daeseon Choi |
AsiaCCS | 1 |
| 2018 | Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier
Hyun Kwon, Yongchul Kim, Ki-Woong Park, Hyunsoo Yoon, Daeseon Choi |
Comput. Secur. | 1 |