Kevin Choi

dblp:246/7740 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
12since 2021 · last 2026
0009-0006-6890-7313ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Golden: Lightweight Non-interactive Distributed Key Generation
Benedikt Bünz, Kevin Choi, Chelsea Komlo
CRYPTO (2)2
2025 Evaluating Query Efficiency and Accuracy of Transfer Learning-based Model Extraction Attack in Federated Learning
abstract
Federated Learning (FL) is a collaborative learning framework designed to protect client data, yet it remains highly vulnerable to Intellectual Property (IP) threats. Model extraction (ME) attack poses a significant risk to Machine-Learning-as-a-Service (MLaaS) platforms, enabling attackers to replicate confidential models by querying Black-Box (without internal insight) APIs. Despite FL’s privacy-preserving goals, its distributed nature makes it particularly susceptible to such attacks. This paper examines the vulnerability of the FL-based victim model to two types of model extraction attacks. For various federated clients built under NVFlare platform, we implemented ME attack across two deep-learning architectures and three image datasets. We evaluate the proposed ME attack performance using various metrics, including accuracy, fidelity, and KL divergence. The experiments show that for various FL clients, the accuracy and fidelity of the extraction model are closely related to the size of the attack query set. Additionally, we explore a transfer learning-based approach where pre-trained models serve as the starting point for the extraction process. The results indicate that the accuracy and fidelity of the fine-tuned pre-trained extraction models are notably higher, particularly with smaller query sets, highlighting potential advantages for attackers.
Sayyed Farid Ahamed, Sandip Roy 0001, Soumya Banerjee 0001, Marc Vucovich, Kevin Choi, Abdul Rahman, Alison Hu, Edward Bowen, Sachin Shetty
IWCMC5
2025 RADEP: A Resilient Adaptive Defense Framework Against Model Extraction Attacks
abstract
Machine Learning as a Service (MLaaS) enables users to leverage powerful machine learning models through cloud-based APIs, offering scalability and ease of deployment. However, these services are vulnerable to model extraction attacks, where adversaries repeatedly query the application programming interface (API) to reconstruct a functionally similar model, compromising intellectual property and security. Despite various defense strategies being proposed, many suffer from high computational costs, limited adaptability to evolving attack techniques, and a reduction in performance for legitimate users. In this paper, we introduce a Resilient Adaptive Defense Framework for Model Extraction Attack Protection (RADEP), a multifaceted defense framework designed to counteract model extraction attacks through a multi-layered security approach. RADEP employs progressive adversarial training to enhance model resilience against extraction attempts. Malicious query detection is achieved through a combination of uncertainty quantification and behavioral pattern analysis, effectively identifying adversarial queries. Furthermore, we develop an adaptive response mechanism that dynamically modifies query outputs based on their suspicion scores, reducing the utility of stolen models. Finally, ownership verification is enforced through embedded watermarking and backdoor triggers, enabling reliable identification of unauthorized model use. Experimental evaluations demonstrate that RADEP significantly reduces extraction success rates while maintaining high detection accuracy with minimal impact on legitimate queries. Extensive experiments show that RADEP effectively defends against model extraction attacks and remains resilient even against adaptive adversaries, making it a reliable security framework for MLaaS models.
Amit Chakraborty, Sayyed Farid Ahamed, Sandip Roy 0001, Soumya Banerjee 0001, Kevin Choi, Abdul Rahman, Alison Hu, Edward Bowen, Sachin Shetty
IWCMC5
2025 Improving Novel Anomaly Detection with Domain-Invariant Latent Representations
Padmaksha Roy, Ming Jin 0002, Himanshu Singhal, Tyler Cody, Kevin Choi
ECML/PKDD (1)5
2024 Cornucopia: Distributed Randomness at Scale
Miranda Christ, Kevin Choi, Joseph Bonneau
AFT2
2024 Accountable Secret Leader Election
Miranda Christ, Kevin Choi, Walter McKelvie, Joseph Bonneau, Tal Malkin
AFT2
2024 Data Composition for Continual Learning in Application of Cyberattack Detection
Jiayi Lian, Kevin Choi, Balaji Veeramani, Sathvik Murli, Alison Hu, Laura J. Freeman, Edward Bowen, Xinwei Deng
ASONAM (4)3
2024 EvoluNet: Advancing Dynamic Non-IID Transfer Learning on Graphs
abstract
Non-IID transfer learning on graphs is crucial in many high-stakes domains. The majority of existing works assume stationary distribution for both source and target domains. However, real-world graphs are intrinsically dynamic, presenting challenges in terms of domain evolution and dynamic discrepancy between source and target domains. To bridge the gap, we shift the problem to the dynamic setting and pose the question: given the *label-rich* source graphs and the *label-scarce* target graphs both observed in previous $T$ timestamps, how can we effectively characterize the evolving domain discrepancy and optimize the generalization performance of the target domain at the incoming $T+1$ timestamp? To answer it, we propose a generalization bound for *dynamic non-IID transfer learning on graphs*, which implies the generalization performance is dominated by domain evolution and domain discrepancy between source and target graphs. Inspired by the theoretical results, we introduce a novel generic framework named EvoluNet. It leverages a transformer-based temporal encoding module to model temporal information of the evolving domains and then uses a dynamic domain unification module to efficiently learn domain-invariant representations across the source and target domains. Finally, EvoluNet outperforms the state-of-the-art models by up to 12.1%, demonstrating its effectiveness in transferring knowledge from dynamic source graphs to dynamic target graphs.
Haohui Wang, Yuzhen Mao, Yujun Yan, Yaoqing Yang 0002, Jianhui Sun, Kevin Choi, Balaji Veeramani, Alison Hu, Edward Bowen, Tyler Cody, Dawei Zhou 0003
ICML6
2024 New Complex Sinusoidal Waveform-Based Zero-Knowledge Proof Systems for Efficient Anonymous Authentication
abstract
Zero-knowledge proof systems based on Feige-Fiat–Shamir (FFS) protocol are an interactive protocol between two anonymous authentication parties. However, they require heavy computations because of many iterations for reducing the probability that an attacker can trick a remote server. The algorithm’s time complexity rapidly increases with the total number of the challenge values, which should be unpredictable. Hence, the FFS protocol is not suitable for practical zero-knowledge proof systems. In this study, we propose new zero-knowledge proof systems based on phase mask generation that are complex sinusoidal waveform versions of the FFS algorithm for efficient anonymous authentication in the diverse interactive systems. The proposed anonymous authentication schemes need a single iteration only, allowing for efficient uses of a random challenge mask with large bit-depth. The proposed schemes allow the verifier to verify that the prover knows the secret mask, such as binary pattern, visual image, or hologram, which are the prover’s secrets, without revealing any information about it to anyone else, including the verifier. Various numerical simulations demonstrate the proposed schemes’ feasibility and robustness.
Youhyun Kim, Ongee Jeong, Kevin Choi, Inkyu Moon, Bahram Javidi
IEEE Trans. Syst. Man Cybern. Syst.3
2023 Bicorn: An Optimistically Efficient Distributed Randomness Beacon
Kevin Choi, Arasu Arun, Nirvan Tyagi, Joseph Bonneau
FC (1)1
2023 SoK: Distributed Randomness Beacons
abstract
Motivated and inspired by the emergence of blockchains, many new protocols have recently been proposed for generating publicly verifiable randomness in a distributed yet secure fashion. These protocols work under different setups and assumptions, use various cryptographic tools, and entail unique trade-offs and characteristics. In this paper, we systematize the design of distributed randomness beacons (DRBs) as well as the cryptographic building blocks they rely on. We evaluate protocols on two key security properties, unbiasability and unpredictability, and discuss common attack vectors for predicting or biasing the beacon output and the countermeasures employed by protocols. We also compare protocols by communication and computational efficiency. Finally, we provide insights on the applicability of different protocols in various deployment scenarios and highlight possible directions for further research.
Kevin Choi, Aathira Manoj, Joseph Bonneau
SP1
2022 Zero Day Threat Detection Using Metric Learning Autoencoders
abstract
The proliferation of zero-day threats (ZDTs) to companies’ networks has been immensely costly and requires novel methods to scan traffic for malicious behavior at massive scale. The diverse nature of normal behavior along with the huge landscape of attack types makes deep learning methods an attractive option for their ability to capture highly-nonlinear behavior patterns. In this paper, the authors demonstrate an improvement upon a previously introduced methodology, which used a dual-autoencoder approach to identify ZDTs in network flow telemetry. In addition to the previously-introduced asset-level graph features, which help abstractly represent the role of a host in its network, this new model uses metric learning to train the second autoencoder on labeled attack data. This not only produces stronger performance, but it has the added advantage of improving the interpretability of the model by allowing for multiclass classification in the latent space. This can potentially save human threat hunters time when they investigate predicted ZDTs by showing them which known attack classes were nearby in the latent space. The models presented here are also trained and evaluated with two more datasets, and continue to show promising results even when generalizing to new network topologies.
Dhruv Nandakumar, Robert Schiller, Christopher Redino, Kevin Choi, Abdul Rahman, Edward Bowen, Marc Vucovich, Joe Nehila, Matthew Weeks, Aaron Shaha
ICMLA4
2020 Towards Green Crowdsourced Social Delivery Networks: A Feasibility Study
abstract
With the ever-increasing popularity of fitness trackers, data on the time and location of popular walking, running, and bicycling routes is expansive and growing rapidly. This data is currently used primarily for route discovery and personal fitness tracking, but it may also be leveraged to build ad-hoc transportation flows. We present a novel model that creates delivery networks from these zero-emission transportation flows, and we evaluate the model using data from two popular datasets. Our results indicate that such networks are indeed possible, and can help reduce traffic, emissions, and delivery times. Moreover, we demonstrate how our results can be consistently reproduced in different cities with different subsets of carriers.
Kevin Choi, Luca Bedogni, Marco Levorato
GLOBECOM1