EDBT 2026 Demo / reviewers in the wild / expert
Hyunwoo Choi
dblp:40/309
· DBLP profile ↗
18ranked-venue papers
7as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 4 since 2021Computer networks · 5 · 3 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AVXProbe: Enhancing Website Fingerprinting with Side-Channel-Assisted Kernel-Level Traces
Suryeon Kim, Seung Ho Na, Jaehan Kim, Seungwon Shin 0001, Hyunwoo Choi |
AsiaCCS | 5 |
| 2024 | Implementation and Analysis of Covert Channel Using iBeacon
Ye-Sol Oh, Yeon-Ji Lee, Jiwon Jang, Hyunwoo Choi, Il-Gu Lee |
ICISSP | 4 |
| 2024 | Prefetch for Fun and Profit: A Revisit of Prefetch Attacks on Apple M1
Hyunwoo Choi, Suryeon Kim, Seungwon Shin 0001 |
USENIX Security Symposium | 1 |
| 2023 | AVX Timing Side-Channel Attacks against Address Space Layout RandomizationabstractModern x86 processors support an AVX instruction set to boost performance. However, this extension may cause security issues. We discovered that there are vulnerable properties in implementing masked load/store instructions. Based on this, we present a novel AVX timing side-channel attack that can defeat address space layout randomization. We demonstrate the significance of our attack by showing User and Kernel ASLR breaks on the recent Intel and AMD processors in various environments, including cloud computing systems, an SGX enclave (a fine-grained ASLR break), and major operating systems. We further demonstrate that our attack can be used to infer user behavior, such as Bluetooth events and mouse movements. We highlight that stronger isolation or more fine-grained randomization should be adopted to successfully mitigate our presented attacks. Hyunwoo Choi, Suryeon Kim, Seungwon Shin 0001 |
DAC | 1 |
| 2023 | AVX-TSCHA: Leaking information through AVX extensions in commercial processorsabstractModern x86 processors support an AVX instruction set to boost performance. However, this extension set may also cause security issues. We discovered that there are vulnerable properties in the implementation of the masked load/store instructions. First, these instructions can suppress exceptions caused by invalid or inaccessible memory access. Second, the execution time of these instructions leaks the current state of the page mappings, permissions, and TLB states. Based on this, we present a novel AVX timing side-channel attack that can defeat address space layout randomization. We demonstrate the significance of our side-channel attack by showing User and Kernel ASLR breaks on the recent Intel and AMD processors in various environments, including cloud computing systems (Amazon AWS, Google GCP, and Microsoft Azure), an SGX enclave (a fine-grained ASLR break), and major OSes (Linux, Windows, and macOS). Our attack can identify the Linux kernel's base address in 0.29 ms as well as those of loaded kernel modules in 2.24 ms, with a near-zero error rate. We further demonstrate that our attack can be used to infer user behavior, such as mouse movements and data transmissions over the network. Our evaluation results on multiple mobile, desktop, and server processors (a total of 26 Intel and AMD CPUs) show that 1) the AVX timing side-channel works on the vast majority of Intel processors (from the Sandy Bridge microarchitecture) as well as AMD processors (from the Zen microarchitecture onward) and 2) our KASLR breaks are very fast and reliable. To the best of our knowledge, our attack is the first to demonstrate a KASLR break on both the recent Intel Alder Lake and AMD Zen 3 CPUs. We highlight that more robust isolation or fine-grained randomization should be adopted to mitigate our presented attacks successfully. Suryeon Kim, Seungwon Shin 0001, Hyunwoo Choi |
Comput. Secur. | 3 |
| 2022 | "Feels Like I've Known You Forever": Empathy and Self-Awareness in Human Open-Domain Dialogs
Yoon Kyung Lee, Won-Ik Cho, Seoyeon Bae, Hyunwoo Choi, Jisang Park 0003, Nam Soo Kim, Sowon Hahn |
CogSci | 4 |
| 2019 | Dissecting 802.11ac Performance - Why You Should Turn Off MU-MIMOabstractWhile the recent Wi-Fi standard 802.11ac achieves Gb/s theoretical capacity with Multi-User MIMO (MU-MIMO) technology, several studies reported that throughput of 802.11ac in practice is far from Gb/s link speed. We investigate the downlink throughput of Wi-Fi systems with commercially available 802.11ac products in multiple indoor environments to reveal the throughput of MU-MIMO system that user experiences in practice. From our experiments, Single-User MIMO (SU-MIMO) outperformed MU-MIMO at every experimental environments. We further provide analysis on our experimental results considering channel sounding overhead, user grouping, environmental impact, and transmission mode selection. Hyunwoo Choi, Taesik Gong, Jaehun Kim, Jaemin Shin 0005, Sung-Ju Lee 0001 |
MobiSys | 1 |
| 2019 | Use MU-MIMO at your own risk - Why we don't get Gb/s Wi-Fi
Hyunwoo Choi, Taesik Gong, Jaehun Kim, Jaemin Shin 0005, Sung-Ju Lee 0001 |
Ad Hoc Networks | 1 |
| 2018 | Large-Scale Analysis of Remote Code Injection Attacks in Android AppsabstractIt is pretty well known that insecure code updating procedures for Android allow remote code injection attack. However, other than codes, there are many resources in Android that have to be updated, such as temporary files, images, databases, and configurations (XML and JSON). Security of update procedures for these resources is largely unknown. This paper investigates general conditions for remote code injection attacks on these resources. Using this, we design and implement a static detection tool that automatically identifies apps that meet these conditions. We apply the detection tool to a large dataset comprising 9,054 apps, from three different types of datasets: official market, third-party market, and preinstalled apps. As a result, 97 apps were found to be potentially vulnerable, with 53 confirmed as vulnerable to remote code injection attacks. Hyunwoo Choi, Yongdae Kim |
Secur. Commun. Networks | 1 |
| 2018 | Peeking Over the Cellular Walled Gardens - A Method for Closed Network Diagnosis -abstractA cellular network is a closed system, and each network operator has built a unique “walled garden” for their network by combining different operation policies, network configurations, and implementation optimizations. Unfortunately, some of these combinations can induce performance degradation due to misconfiguration or unnecessary procedures. To detect such degradation, a thorough understanding of even the minor details of the standards and operator-specific implementations is important. However, it is difficult to detect such problems, as the control plane is complicated by numerous procedures. This paper introduces a simple yet powerful method that diagnoses these problems by exploiting the operator-specific implementations of cellular networks. We develop a signaling collection and analysis tool that collects control plane messages from operators and finds problems through comparative analysis. The analysis process consists of three different control plane comparison procedures that can find such problems effectively. These individual procedures use a time threshold, control flow sequence, and signaling failure as the basis for comparison. To this end, we collect approximately 3.1 million control-plane messages from 13 major cellular operators worldwide. As a case study, we analyze the circuit-switched fallback technology that triggers generation crossover between third generation and long-term evolution technologies. Byeongdo Hong, Shinjo Park, Dongkwan Kim 0001, Hyunwook Hong, Hyunwoo Choi, Jean-Pierre Seifert, Sung-Ju Lee 0001, Yongdae Kim |
IEEE Trans. Mob. Comput. | 6 |
| 2017 | When Cellular Networks Met IPv6: Security Problems of Middleboxes in IPv6 Cellular NetworksabstractRecently, cellular operators have started migrating to IPv6 in response to the increasing demand for IP addresses. With the introduction of IPv6, cellular middleboxes, such as firewalls for preventing malicious traffic from the Internet and stateful NAT64 boxes for providing backward compatibility with legacy IPv4 services, have become crucial to maintain stability of cellular networks. This paper presents security problems of the currently deployed IPv6 middleboxes of five major operators. To this end, we first investigate several key features of the current IPv6 deployment that can harm the safety of a cellular network as well as its customers. These features combined with the currently deployed IPv6 middlebox allow an adversary to launch six different attacks. First, firewalls in IPv6 cellular networks fail to block incoming packets properly. Thus, an adversary could fingerprint cellular devices with scanning, and further, she could launch denial-of-service or over-billing attacks. Second, vulnerabilities in the stateful NAT64 box, a middlebox that maps an IPv6 address to an IPv4 address (and vice versa), allow an adversary to launch three different attacks: 1) NAT overflow attack that allows an adversary to overflow the NAT resources, 2) NAT wiping attack that removes active NAT mappings by exploiting the lack of TCP sequence number verification of firewalls, and 3) NAT bricking attack that targets services adopting IP-based blacklisting by preventing the shared external IPv4 address from accessing the service. We confirmed the feasibility of these attacks with an empirical analysis. We also propose effective countermeasures for each attack. Hyunwook Hong, Hyunwoo Choi, Dongkwan Kim 0001, Byeongdo Hong, Yongdae Kim |
EuroS&P | 2 |
| 2016 | Enabling Automatic Protocol Behavior Analysis for Android ApplicationsabstractAndroid application is an important class on today's Internet. While understanding app-specific behavior is important for network operation and management, it is often difficult because it requires an in-depth application-layer protocol analysis due to the common use of HTTP(S) and standard data representations (e.g., JSON). This paper presents Extractocol, the first system to offer an automatic and comprehensive analysis of application protocol behaviors. Extractocol only uses Android application binary as input and accurately reconstructs HTTP transactions (request-response pairs) and identifies their message format and relationships using binary analysis. Our evaluation and in-depth case studies on commercial and open-source apps demonstrate that Extractocol provides high coverage and accurately characterizes network-related application behaviors. Hyunwoo Choi, Hun Namkung, Woohyun Choi, Byungkwon Choi, Hyunwook Hong, Yongdae Kim, Jonghyup Lee, Dongsu Han |
CoNEXT | 2 |
| 2016 | PIkit: A New Kernel-Independent Processor-Interconnect Rootkit
Wonjun Song, Hyunwoo Choi, Junhong Kim, Eunsoo Kim, Yongdae Kim, John Kim 0001 |
USENIX Security Symposium | 2 |
| 2015 | Extractocol: Autoatic Extraction of Application-level Protocol Behaviors for Android ApplicationsabstractNo abstract available. Hyunwoo Choi, Hyunwook Hong, Yongdae Kim, Jonghyup Lee, Dongsu Han |
SIGCOMM | 1 |
| 2014 | Run Away If You Can: - Persistent Jamming Attacks against Channel Hopping Wi-Fi Devices in Dense Networks
Il-Gu Lee, Hyunwoo Choi, Yongdae Kim, Seungwon Shin 0001, Myungchul Kim 0001 |
RAID | 2 |
| 2008 | Novel Detection Algorithm of IDMA System under Channel Estimation ErrorabstractIn this paper, we propose a novel detection algorithm for the elementary signal estimator of an IDMA system considering channel estimation error. To develop the algorithm, we derive new probability density function of decision variable reflecting channel estimation error and modify the conventional algorithm based on it. Through computer simulations, it is shown that the proposed algorithm achieves lower bit error rate than the conventional one. This performance enhancement is provided with negligible increase of its computational complexity. Chulhee Jang, Hyunwoo Choi, Jae Hong Lee |
VTC Fall | 2 |
| 2007 | Capacity of VoIP Services in TDD OFDMA System with Different Delay RequirementsabstractIn this paper, we evaluate the voice service capacity of the TDD OFDMA system based on IEEE 802.16d/e. Voice traffic must be transmitted in real time with very small delay when we use packet transmission networks. Voice over IP (VoIP) services can be provided in this wireless packet network as Unsolicited Granted Service (UGS) or Real Time Polling Service (rtPS) class. As UGS, a fixed amount of bandwidth can be allocated to transmit the voice traffic for the duration of a call. On the other hand, as rtPS, bandwidth is allocated variably as needed to transmit the talk spurts using polling process. In this analysis, we also take into account the delay limit as one of the main Quality of Service (QoS) requirements of the voice services. The capacities of VoIP services for the classes with different delay limits are derived and compared in this paper. Simulation results show that the voice capacity is larger when we treat the VoIP service as rtPS than that as UGS. Hoyoung Choi, Hyunwoo Choi, Daehyoung Hong, Jinwoo Choe, Soonyoung Yoon |
CCNC | 2 |
| 2007 | Cooperative ARQ with Phase Pre-CompensationabstractIn this paper, we propose a novel cooperative ARQ scheme for static channel. The relay nodes, who decode the source's packet correctly, participate in the cooperation to retransmit the packet erroneously received by the destination node. In the cooperative retransmission, we consider simultaneous transmissions, where the phase pre-compensation method is introduced at each relay node to prevent the signals from summing destructively at the destination node. The phase information is obtained by the estimation at each of the relay nodes. The analysis and simulation results are provided to evaluate the proposed scheme in terms of the packet error rate (PER). The proposed cooperative ARQ scheme provides significant performance gain compared to conventional one. Hyunwoo Choi, Jae Hong Lee |
VTC Fall | 1 |