Jaewon Hur

dblp:263/9985 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0003-7963-0952ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 DLBox: New Model Training Framework for Protecting Training Data
Jaewon Hur, Juheon Yi, Cheolwoo Myung, Youngki Lee 0001, Byoungyoung Lee
NDSS1
2025 Secure Data Analytics in Apache Spark with Fine-grained Policy Enforcement and Isolated Execution
Byeongwook Kim, Jaewon Hur, Adil Ahmad, Byoungyoung Lee
NDSS2
2022 SpecDoctor: Differential Fuzz Testing to Find Transient Execution Vulnerabilities
abstract
Transient execution vulnerabilities have critical security impacts to software systems since those break the fundamental security assumptions guaranteed by the CPU. Detecting these critical vulnerabilities in the RTL development stage is particularly important, as it offers a chance to fix the vulnerability early before reaching the chip manufacturing stage.
Jaewon Hur, Suhwan Song, Byoungyoung Lee
CCS1
2022 R2Z2: Detecting Rendering Regressions in Web Browsers through Differential Fuzz Testing
abstract
A rendering regression is a bug introduced by a web browser where a web page no longer functions as users expect. Such rendering bugs critically harm the usability of web browsers as well as web applications. The unique aspect of rendering bugs is that they affect the presented visual appearance of web pages, but those web pages have no pre-defined correct appearance. Therefore, it is challenging to automatically detect errors in their appearance. In practice, web browser vendors rely on non-trivial and time-prohibitive manual analysis to detect and handle rendering regressions.
Suhwan Song, Jaewon Hur, Philip Rogers, Byoungyoung Lee
ICSE2
2022 FuzzOrigin: Detecting UXSS vulnerabilities in Browsers through Origin Fuzzing
Jaewon Hur, Suhwan Song, Gwangmu Lee, Byoungyoung Lee
USENIX Security Symposium3
2021 DifuzzRTL: Differential Fuzz Testing to Find CPU Bugs
abstract
Security bugs in CPUs have critical security impacts to all the computation related hardware and software components as it is the core of the computation. In spite of the fact that architecture and security communities have explored a vast number of static or dynamic analysis techniques to automatically identify such bugs, the problem remains unsolved and challenging largely due to the complex nature of CPU RTL designs.This paper proposes DIFUZZRTL, an RTL fuzzer to automatically discover unknown bugs in CPU RTLs. DIFUZZRTL develops a register-coverage guided fuzzing technique, which efficiently yet correctly identifies a state transition in the finite state machine of RTL designs. DIFUZZRTL also develops several new techniques in consideration of unique RTL design characteristics, including cycle-sensitive register coverage guiding, asynchronous interrupt events handling, a unified CPU input format with Tilelink protocols, and drop-in-replacement designs to support various CPU RTLs. We implemented DIFUZZRTL, and performed the evaluation with three real-world open source CPU RTLs: OpenRISC Mor1kx Cappuccino, RISC-V Rocket Core, and RISC-V Boom Core. During the evaluation, DIFUZZRTL identified 16 new bugs from these CPU RTLs, all of which were confirmed by the respective development communities and vendors. Six of those are assigned with CVE numbers, and to the best of our knowledge, we reported the first and the only CVE of RISC-V cores, demonstrating its strong practical impacts to the security community.
Jaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek, Jangwoo Kim, Byoungyoung Lee
SP1
2021 Push yoUr Password: Secure and Fast WiFi Connection for IoT Devices
abstract
Internet of things (IoT) is an indispensable paradigm in today's industrial change. IoT interconnects appliances around us through the Internet, and user's private information is deeply placed inside the network. Nonetheless, security vulnerabilities in IoT have not been addressed appropriately so far due to various reasons. Even in the initial WiFi connection procedures of IoT devices, WiFi credentials can be leaked, making the WiFi access point (AP) a hacking path. We propose a secure connection scheme, termed PUP, that aims to securely and quickly connect an IoT device to the AP in proximity while improving the user experience. PUP shows perfect security performance, enabling connection time within 11 s.
Junyoung Choi 0001, Jaewon Hur, Saewoong Bahk
WCNC2
2019 EV-CAST: Interference and Energy-Aware Video Multicast Exploiting Collaborative Relays
abstract
Video multicast over wireless local area network (WLAN) has been gaining attraction for applications sharing a venue-specific common video with multiple users. However, wireless multicast is limited by a receiver that has the weakest communication link to the source. Collaborative relaying could overcome this challenge by enabling selected receiver nodes to relay the packets from the source to other receivers. We propose EV-CAST, an interference and energy-aware video multicast system using collaborative relays, which entails (i) online topology management based on interference-aware link characterization, (ii) joint selection of relay nodes and transmission parameters, and (iii) polling-based relay protocol. Our proposed algorithm, the core of EV-CAST, judiciously selects the relay nodes and transmission parameters in consideration of interference, battery status, and spatial reuse. Our prototype-based experiment results demonstrate that EV-CAST enhances video multicast delivery under various network scenarios. EV-CAST enables 2x more nodes to achieve a target video packet loss ratio with 0.59x shorter airtime than the state-of-the-art video multicast scheme.
Yeonchul Shin, Jaewon Hur, Gyujin Lee, Jonghoe Koo, Junyoung Choi 0001, Sung-Ju Lee 0001, Sunghyun Choi 0001
MASS2