EDBT 2026 Demo / reviewers in the wild / expert
Yujun Kim
dblp:285/9420
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0003-4091-4395ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ISFL-AE: Insider-Specific Feature Learning Autoencoder for Lightweight Insider Threat DetectionabstractMalicious insiders who possess system access and security expertise are notoriously difficult to detect and can inflict severe financial damage. While recent advances in deep learning have demonstrated impressive accuracy in detecting insider threats, these models often assume the presence of well-defined or previously known anomalies. In practical organizational environments, however, threats may manifest as novel, subtle, or context-dependent behaviors that are not captured by existing patterns. Detecting such anomalies necessitates the extraction and analysis of rich behavioral features from large-scale insider activity data—an approach that, while effective, often leads to increased model complexity and computational burden. This, in turn, impedes real-time responsiveness and operational viability, potentially resulting in delayed threat mitigation and financial losses. Therefore, there is a pressing need for lightweight yet robust insider threat detection frameworks that can ensure timely and efficient deployment without compromising detection performance. To address this challenge, this paper proposes the Insider-Specific Feature Learning Autoencoder (ISFL-AE), a model designed to achieve high detection accuracy and fast processing speed. Unlike traditional reconstruction-based anomaly detection models—which use a single set of model parameters to reconstruct normal behavior for all insiders regardless of their role, authority level, or other attributes—ISFL-AE tailors its feature learning to insider-specific characteristics. ISFL-AE operates with the same number of parameters as a conventional autoencoder (AE), maintaining comparable processing speed while significantly improving detection performance. We evaluated ISFL-AE using the CERT r4.2 and r6.2 datasets. The results show that, while processing data at the same speed as a standard AE, ISFL-AE delivered markedly higher detection accuracy. Furthermore, it outperformed other machine learning models in detection accuracy and processing speed. Furthermore, our empirical results demonstrate that integrating insider-specific feature learning into autoencoder-based deep learning architectures significantly enhances anomaly detection performance, all while preserving real-time processing efficiency. Yujun Kim, Young-Gab Kim |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Incremental Gradient Descent with Small Epoch Counts is Surprisingly Slow on Ill-Conditioned ProblemsabstractRecent theoretical results demonstrate that the convergence rates of permutation-based SGD (e.g., random reshuffling SGD) are faster than uniform-sampling SGD; however, these studies focus mainly on the large epoch regime, where the number of epochs $K$ exceeds the condition number $\kappa$. In contrast, little is known when $K$ is smaller than $\kappa$, and it is still a challenging open question whether permutation-based SGD can converge faster in this small epoch regime (Safran and Shamir, 2021). As a step toward understanding this gap, we study the naive deterministic variant, Incremental Gradient Descent (IGD), on smooth and strongly convex functions. Our lower bounds reveal that for the small epoch regime, IGD can exhibit surprisingly slow convergence even when all component functions are strongly convex. Furthermore, when some component functions are allowed to be nonconvex, we prove that the optimality gap of IGD can be significantly worse throughout the small epoch regime. Our analyses reveal that the convergence properties of permutation-based SGD in the small epoch regime may vary drastically depending on the assumptions on component functions. Lastly, we supplement the paper with tight upper and lower bounds for IGD in the large epoch regime. Yujun Kim, Jaeyoung Cha, Chulhee Yun |
ICML | 1 |
| 2025 | The Cost of Robustness: Tighter Bounds on Parameter Complexity for Robust Memorization in ReLU NetsabstractWe study the parameter complexity of robust memorization for ReLU networks: the number of parameters required to interpolate any dataset with $\epsilon$-separation between differently labeled points, while ensuring predictions remain consistent within a $\mu$-ball around each training example. We establish upper and lower bounds on the parameter count as a function of the robustness ratio $\rho = \mu / \epsilon$. Unlike prior work, we provide a fine-grained analysis across the entire range $\rho \in (0,1)$ and obtain tighter upper and lower bounds that improve upon existing results. Our findings reveal that the parameter complexity of robust memorization matches that of non-robust memorization when $\rho$ is small, but grows with increasing $\rho$. As a special case, when the input dimension is comparable to or exceeds the dataset size, our bounds become tight (up to logarithmic factors) across the entire range of $\rho$. Yujun Kim, Chaewon Moon, Chulhee Yun |
NeurIPS | 1 |
| 2025 | MPE: Multi-frame prediction error-based video anomaly detection framework for robust anomaly inference
Yujun Kim, Young-Gab Kim |
Pattern Recognit. | 1 |
| 2024 | A Method for Quantitative Object De-Identification Analysis of Anonymized VideoabstractThe rise in video content has amplified the risk of information leakage, prompting the development of various anonymization techniques. These techniques include traditional methods such as pixelation, blurring, and masking, as well as more advanced approaches like video encryption, which involves encrypting parameters during video encoding, and techniques that subtly alter facial features to prevent identification. However, assessing the effectiveness of these anonymization techniques remains challenging. Common metrics such as the structural similarity index (SSIM) and peak signal-to-noise ratio (PSNR), often used for object anonymization in videos, primarily assess image quality and lack accuracy for security evaluation. Furthermore, subjective human evaluations fail to provide the consistent, quantitative data necessary for cross-study comparisons. Given that a single identifiable frame in a video can compromise overall security, this study introduces a quantitative method for evaluating the de-identification rate in regions of interest (ROI) within videos. The proposed approach calculates an object de-identification rate (ODR) by combining SSIM and edge detection ratio (EDR) using a harmonic mean and a power mean. Our proposed method enhances the precision and reliability for security of anonymized video. Deok-Han Kim, Yujun Kim, Young-Gab Kim |
TrustCom | 2 |
| 2024 | Transfer Learning-Based Robust Insider Threat DetectionabstractA malicious insider’s threats who has access to the organization’s systems and is familiar with security policies are difficult to detect and can cause significant financial damage. A reconstruction-based anomaly detection method leveraging deep learning is one method for detecting insider threats. The method is employed to solve a data imbalance problem caused by the scarcity of abnormal data in real environments. The method trains a deep learning model to reconstruct normal data received from all users. After training, the model reconstructs normal data more accurately than abnormal data, and the reconstruction-based anomaly detection method can detect anomalies based on the reconstruction difference between normal and abnormal data. However, existing reconstruction-based anomaly detection methods train on all users’ normal data using the same network parameters. Consequently, if a behavior is normal for one user but abnormal for another, the reconstruction model learns this behavior as normal because the reconstruction model trains only on normal behaviors. Since normal behaviors differ for each user depending on their position, role, and other factors within the organization, it is necessary to develop methods for detecting abnormal behaviors specific to each user. To address this problem, we propose a transfer learning-based insider threat detection method. The proposed method consists of 1) a pre-trained encoder that outputs latent representations of normal data for all users and 2) user-specific decoders assigned to each user, which are trained on the corresponding user’s normal data to reconstruct their normal data. We evaluate the proposed method’s detection rate (DR) and area under the curve (AUC) on the CERT dataset and compare it with a deep learning model trained on normal data from all users. The experimental results show that the proposed method achieves higher DR and AUC than the deep learning model. These results indicate that the proposed method enhances insider threat detection performance by enabling the detection of user-specific abnormal behaviors. Yujun Kim, Deok-Han Kim, Young-Gab Kim |
TrustCom | 1 |