EDBT 2026 Demo / reviewers in the wild / expert
Seung Ho Na
dblp:248/7166
· DBLP profile ↗
10ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0003-0908-1233ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 6 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MOEVIL: Poisoning Experts to Compromise the Safety of Mixture-of-Experts LLMsabstractMixture-of-Experts (MoE) has emerged as a prominent architecture for scaling large language models (LLMs). In particular, leveraging readily available fine-tuned LLMs as experts provides an efficient and flexible approach to developing MoE LLMs. However, integrating highly capable but untrustworthy LLMs into an MoE system poses a significant safety risk, potentially compromising the overall safety of the MoE LLM system. To date, no study has explored how adversaries compromise an MoE LLM service by introducing a poisoned expert LLM. In this paper, we introduce MOEVIL, a novel expert poisoning attack designed to compromise the safety of MoE LLMs. We address the dissipation of harmful effects from a target expert within MoE systems by conducting harmful preference learning. Next, we strategically manipulate this expert's latent vector to deceive the gating networks. This manipulation indirectly steers routing decisions toward the poisoned expert when generating responses to harmful queries. MOEVIL demonstrates strong attack performance across diverse MoE configurations based on both Llama and Qwen LLMs, even when poisoning only a single expert. MOEVIL increases the harmfulness score from 0.58 to 79.42 in a Llama-based MoE LLM, outperforming existing harmful poisoning attacks. Furthermore, our results demonstrate that even safety alignment, when combined with an efficient MoE training strategy, fails to fully mitigate these risks. Our findings demonstrate the significant threat posed by harmful experts in MoE systems, underscoring the need for robust safety measures in MoE-based LLM development. Our implementation is available at https://github.com/jaehanwork/MoEvil. Jaehan Kim, Seung Ho Na, Minkyoo Song, Seungwon Shin 0001, Sooel Son |
ACSAC | 2 |
| 2025 | AVXProbe: Enhancing Website Fingerprinting with Side-Channel-Assisted Kernel-Level Traces
Suryeon Kim, Seung Ho Na, Jaehan Kim, Seungwon Shin 0001, Hyunwoo Choi |
AsiaCCS | 2 |
| 2025 | When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs
Hanna Kim, Minkyoo Song, Seung Ho Na, Seungwon Shin 0001, Kimin Lee |
USENIX Security Symposium | 3 |
| 2023 | Evolving Bots: The New Generation of Comment Bots and their Underlying Scam Campaigns in YouTubeabstractThis paper presents a pioneering investigation into a novel form of scam advertising method on YouTube, termed "social scam bots'' (SSBs). These bots have evolved to emulate benign user behavior by posting comments and engaging with other users, oftentimes appearing prominently among the top rated comments. We analyzed the YouTube video comments and proposed a method to identify SSBs and extract the underlying scam domains. Our study revealed 1,134 SSBs promoting 72 scam campaigns responsible for infecting 31.73% of crawled videos. Further investigation revealed that SSBs exhibit advances that surpass traditional bots. Notably, they targeted specific audience by aligning scam campaigns with related video content, effectively leveraging the YouTube recommendation algorithm. We monitored these SSBs over a period of six months, enabling us to evaluate the effectiveness of YouTube's mitigation efforts. We also uncovered various strategies they use to evade mitigation attempts, including a novel strategy called "self-engagement," aimed at boosting their comment ranking. By shedding light on the phenomenon of SSBs and their evolving tactics, our study aims to raise awareness and contribute to the prevention of these malicious actors, ultimately fostering a safer online platform. Seung Ho Na, Sumin Cho, Seungwon Shin 0001 |
IMC | 1 |
| 2023 | Witnessing Erosion of Membership Inference Defenses: Understanding Effects of Data Drift in Membership PrivacyabstractData drift is the phenomenon when the input data distribution in testing time is different from the training time. This strengthens the generalization gap in a model, which is known to severely deteriorate the model’s performance. Meanwhile, previous studies state that membership inference attacks (MIA) take advantage of the generalization gap of a machine learning model. By transitive logic, we can deduce that data drift would affect these privacy attacks. In this work, we consider data drift when applied to the privacy threat of MIA. As the first work to explore the detrimental extent of data drift on membership privacy, we conduct a literature review on current MIA defense works under selected dimensions associated with data drift. Our study reveals that not only has data drift never been tested in MIA defense, but there is also no infrastructure to juxtapose data drift with MIA defense. We overcome this by proposing a design for simulating authentic and synthetic data drift and evaluate the benchmark MIA defense methods on various settings. The evaluation shows that data drift strongly enhances the attack success rate of MIA, regardless of defense. In this, we propose MIAdapt, a proof of concept of a MIA defense that allows update in data drift. From this evaluation, we provide security insight into possible solutions in negating the effects of data drift. We hope our work brings attention to the threat of data drift and instigates the development of MIA defense that are adaptable to data drift. Seung Ho Na, Kwanwoo Kim, Seungwon Shin 0001 |
RAID | 1 |
| 2022 | Closing the Loophole: Rethinking Reconstruction Attacks in Federated Learning from a Privacy StandpointabstractFederated Learning was deemed as a private distributed learning framework due to the separation of data from the central server. However, recent works have shown that privacy attacks can extract various forms of private information from legacy federated learning. Previous literature describe differential privacy to be effective against membership inference attacks and attribute inference attacks, but our experiments show them to be vulnerable against reconstruction attacks. To understand this outcome, we execute a systematic study of privacy attacks from the standpoint of privacy. The privacy characteristics that reconstruction attacks infringe are different from other privacy attacks, and we suggest that privacy breach occurred at different levels. From our study, reconstruction attack defense methods entail heavy computation or communication costs. To this end, we propose Fragmented Federated Learning (FFL), a lightweight solution against reconstruction attacks. This framework utilizes a simple yet novel gradient obscuring algorithm based on a newly proposed concept called the global gradient and determines which layers are safe for submission to the server. We show empirically in diverse settings that our framework improves practical data privacy of clients in federated learning with an acceptable performance trade-off without increasing communication cost. We aim to provide a new perspective to privacy in federated learning and hope this privacy differentiation can improve future privacy-preserving methods. Seung Ho Na, Hyeong Gwon Hong, Junmo Kim 0002, Seungwon Shin 0001 |
ACSAC | 1 |
| 2022 | Meta-Path-based Fake News Detection Leveraging Multi-level Social Context InformationabstractFake news, false or misleading information presented as news, has a significant impact on many aspects of society, such as in politics or healthcare domains. Due to the deceiving nature of fake news, applying Natural Language Processing (NLP) techniques to the news content alone is insufficient. Therefore, more information is required to improve fake news detection, such as the multi-level social context (news publishers and engaged users in social media) information and the temporal information of user engagement. The proper usage of this information, however, introduces three chronic difficulties: 1) multi-level social context information is hard to be used without information loss, 2) temporal information of user engagement is hard to be used along with multi-level social context information, and 3) news representation with multi-level social context and temporal information is hard to be learned in an end-to-end manner. To overcome all three difficulties, we propose a novel fake news detection framework, Hetero-SCAN. We use Meta-Path, a composite relation connecting two node types, to extract meaningful multi-level social context information without loss. We then propose Meta-Path instance encoding and aggregation methods to capture the temporal information of user engagement and learn news representation end-to-end. According to our experiment, Hetero-SCAN yields significant performance improvement over state-of-the-art fake news detection methods. Kwanwoo Kim, Seung Ho Na, Seungwon Shin 0001 |
CIKM | 3 |
| 2022 | Reconfigurable regular expression matching architecture for real-time pattern update and payload inspection
Jaehyun Nam, Seung Ho Na, Seungwon Shin 0001, Taejune Park |
J. Netw. Comput. Appl. | 2 |
| 2021 | Reinhardt: Real-time Reconfigurable Hardware Architecture for Regular Expression Matching in DPIabstractRegular expression (regex) matching is an integral part of deep packet inspection (DPI) but a major bottleneck due to its low performance. For regex matching (REM) acceleration, FPGA-based studies have emerged and exploited parallelism by matching multiple regex patterns concurrently. However, even though guaranteeing high-performance, existing FPGA-based regex solutions do not still support dynamic updates in run time. Hence, it was inappropriate as a DPI function due to frequently altered malicious signatures. In this work, we introduce Reinhardt, a real-time reconfigurable hardware architecture for REM. Reinhardt represents regex patterns as a combination of reconfigurable cells in hardware and updates regex patterns in real-time while providing high performance. We implement the prototype using NetFPGA-SUME, and our evaluation demonstrates that Reinhardt updates hundreds of patterns within a second and achieves up to 10 Gbps throughput (max. hardware bandwidth). Our case studies show that Reinhardt can operate as NIDS/NIPS and as the REM accelerator for them. Taejune Park, Jaehyun Nam, Seung Ho Na, Jaewoong Chung, Seungwon Shin 0001 |
ACSAC | 3 |
| 2018 | Knowledge Seeking on The Shadow BrokersabstractThe Shadow Brokers (TSB) are an infamous group of hackers responsible for major cybercrime incidents. There are currently few studies on TSB, and to prevent their attacks in the future, we believe it is necessary to study them beforehand. This study constructs a relation graph of all the entities concerning TSB using identifiers in the Web. We introduce a systematic approach to finding relations among entities using a case study based on identifiers and clearness of relations. Our investigation covers data from both the Surface Web and Dark Web, with our Dark Web data consisting of over 40 million Dark Web webpages. We have uncovered many hacking forums, hacking groups, and individuals having a relation with TSB using our method. The relation graph of TSB will become a stepping stone in developing a knowledge base of TSB. Seung Ho Na, Kwanwoo Kim, Seungwon Shin 0001 |
CCS | 1 |