EDBT 2026 Demo / reviewers in the wild / expert
Tiffany Hyun-Jin Kim
dblp:47/9491
· DBLP profile ↗
27ranked-venue papers
7as first author
3since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 2 since 2021Computer networks · 6 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-authorDatabases, data management, data science and information retrieval · 4 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats
Kai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li, Tiffany Hyun-Jin Kim, Hsu-Chun Hsiao |
USENIX Security Symposium | 5 |
| 2024 | Detecting IP Prefix Mismatches on SDN Data PlaneabstractSoftware-defined networking (SDN) enables centralized network management by separating the control and data plane. However, the actual packet behavior on data-plane may deviate from the control-plane rules sometimes. Many probe-based tools have been developed to verify the data plane’s correctness and detect forwarding errors by sending test packets. However, they all assume simple fault models, such as incorrect action fields in the forwarding rules. To address this gap, this paper identifies a new class of error affecting the IP match field called IP prefix mismatch, which previous tools failed to identify thoroughly. We categorize IP prefix mismatches into prefix shrinkage and prefix expansion. We then present novel test packet generation algorithms to construct test packets designed to exhibit different behaviors depending on the presence of these errors. Using these algorithms, we develop a system that guarantees the discovery of at least one prefix mismatch in every detection round, even in the worst-case scenario.Several experiments were conducted to compare our system to a conventional probe-based method that sends a single test packet per rule. The results demonstrate that our system achieves perfect fault coverage within a minimal number of detection rounds. Even when faced with a network containing 50% erroneous rules, it successfully identifies all prefix mismatches within an average of only two detection rounds. In contrast, the conventional method fails to uncover all errors, even after spending on additional detection rounds. Shu-Po Tung, Yu-Min Lin, Keng-Lun Chang, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim |
ICCCN | 5 |
| 2023 | Capturing Antique Browsers in Modern Devices: A Security Analysis of Captive Portal Mini-Browsers
Ping-Lun Wang, Kai-Hsiang Chou, Shou-Ching Hsiao, Ann Tene Low, Tiffany Hyun-Jin Kim, Hsu-Chun Hsiao |
ACNS (1) | 5 |
| 2020 | On the Privacy Risks of Compromised Trigger-Action Platforms
Yu-Hsi Chiang, Hsu-Chun Hsiao, Chia-Mu Yu, Tiffany Hyun-Jin Kim |
ESORICS (2) | 4 |
| 2020 | Bidirectional BlockchainabstractEnsuring the authenticity and integrity of data transferred over the Internet is still a daunting task. Although various mechanisms have been proposed to strengthen the key management infrastructure, they still rely on trusted third parties (TTPs) or require additional entities to monitor the system. This paper introduces Bidirectional Blockchain - a collection of protocols that ensure the authenticity of data sent from a collection of one or more servers to distributed clients (e.g., Internet of Things (IoT) devices) without relying on TTPs. Bidirectional Blockchain is based on the benefits of multi-party computation and blockchain to ensure the secrecy of keys used to sign the distributed data and the correctness and integrity of the received data, respectively. We implemented Bidirectional Blockchain on a Raspberry Pi, and our evaluation results confirm that Bidirectional Blockchain is lightweight and hence can be used to secure a variety of data transactions, including software updates, even on resource-constrained devices. Joshua Lampkins, Tiffany Hyun-Jin Kim |
ICCCN | 2 |
| 2019 | An Investigation of Cyber Autonomy on Government WebsitesabstractFrom a national security viewpoint, a higher degree of cyber autonomy is crucial to reduce the reliance on external, oftentimes untrustworthy entities, in order to achieve better resilience against adversaries. To probe into the concept of government cyber autonomy, this study examines the external dependency of public-facing government websites across the world's major industrialized, Group of Seven (G7) countries. Over a two-year period, we measured HTTPS adoption rates, the autonomy status of CAs, and the autonomy status of CPs on G7 government websites. We find that approximately 85% of web resources loaded by G7 government sites originate from the United States. By reviewing policy documents and surveying technicians who maintain government websites, we identify four significant forces that can influence the degree of a government's autonomy, including government mandates on HTTPS adoption, website development outsourcing, the citizens' fear of large-scale surveillance, and user confusion. Because a government websites are considered critical information infrastructures, we expect this study to raise awareness of their complex dependency, thereby reducing the risk of blindly trusting external entities when using critical government services. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Yu-Ming Ku, Chun-Ming Chang, Hung-Fang Chen, Chun-Wen Wang, Wei Jeng |
WWW | 2 |
| 2018 | BRICS: Blockchain-based Resilient Information Control SystemabstractThis paper introduces a system for providing integrity, authenticity, and privacy of data transactions for resource-limited Internet of Things (IoT) smart devices using blockchain (BC) and Multi-Party Computation (MPC). In particular, we introduce two mechanisms: one provides privacy and integrity protections on the data being collected by the smart devices, such as medical records or diagnostic data, and the other provides authenticity and integrity of data going into the smart devices, such as software updates. Our experimental results indicate that our proposed mechanisms incur small overhead in terms of storage, communication, and computation, indicating their feasibility to IoT devices with limited storage, computational, and communicational capabilities. Tiffany Hyun-Jin Kim, Joshua Lampkins |
IEEE BigData | 1 |
| 2018 | SDNProbe: Lightweight Fault Localization in the Error-Prone EnvironmentabstractProbe-based fault localization identifies potential faulty nodes, which are manually inspected for confirmation. This work explores efficient and accurate fault localization, which is crucial for reducing the manual effort without affecting network functionality. Prior work suffers from either high bandwidth overhead or false detection (i.e., incorrectly attributing good nodes or missing faulty nodes), especially in the presence of multiple or inconsistent faults. We propose SDNProbe, a lightweight SDN application that sends a provably minimized number of probe packets to pinpoint malfunctioning switches. We extend SDNProbe to randomize tested paths and packet headers to further improve the detection accuracy. Using realistic topologies and flow rules, our evaluation results confirm that SDNProbe can rapidly localize faulty switches while reducing the number of required test packets by 30%, compared to prior approaches. Even with 50% of switches being faulty, the extended SDNProbe can detect all faulty switches in 33 seconds, whereas prior approaches have false negative rates of 15-40%. Yu-Ming Ke, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim |
ICDCS | 3 |
| 2018 | Design, Analysis, and Implementation of ARPKI: An Attack-Resilient Public-Key InfrastructureabstractThe current Transport Layer Security (TLS) Public-Key Infrastructure (PKI) is based on a weakest-link security model that depends on over a thousand trust roots. The recent history of malicious and compromised Certification Authorities has fueled the desire for alternatives. Creating a new, secure infrastructure is, however, a surprisingly challenging task due to the large number of parties involved and the many ways that they can interact. A principled approach to its design is therefore mandatory, as humans cannot feasibly consider all the cases that can occur due to the multitude of interleavings of actions by legitimate parties and attackers, such as private key compromises (e.g., domain, Certification Authority, log server, other trusted entities), key revocations, key updates, etc. We present ARPKI, a PKI architecture that ensures that certificate-related operations, such as certificate issuance, update, revocation, and validation, are transparent and accountable. ARPKI efficiently supports these operations, and gracefully handles catastrophic events such as domain key loss or compromise. Moreover ARPKI is the first PKI architecture that is co-designed with a formal model, and we verify its core security property using the TAMARIN prover. We prove that ARPKI offers extremely strong security guarantees, where compromising even n - 1 trusted signing and verifying entities is insufficient to launch a man-in-the-middle attack. Moreover, ARPKI's use deters misbehavior as all operations are publicly visible. Finally, we present a proof-of-concept implementation that provides all the features required for deployment. Our experiments indicate that ARPKI efficiently handles the certification process with low overhead. It does not incur additional latency to TLS, since no additional round trips are required. David A. Basin, Cas Cremers, Tiffany Hyun-Jin Kim, Adrian Perrig, Ralf Sasse, Pawel Szalachowski |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Security Implications of Redirection Trail in Popular Websites WorldwideabstractURL redirection is a popular technique that automatically navigates users to an intended destination webpage with- out user awareness. However, such a seemingly advantageous feature may offer inadequate protection from security vulnerabilities unless every redirection is performed over HTTPS. Even worse, as long as the final redirection to a website is performed over HTTPS, the browser's URL bar indicates that the website is secure regardless of the security of prior redirections, which may provide users with a false sense of security. This paper reports a well-rounded investigation to analyze the wellness of URL redirection security. As an initial large-scale investigation, we screened the integrity and consistency of URL redirections for the Alexa top one million (1M) websites, and further examined 10,000 (10K) websites with their login features. Our results suggest that 1) the majority (83.3% in the 1M dataset and 78.6% in the 10K dataset) of redirection trails among web- sites that support only HTTPS are vulnerable to attacks, and 2) current incoherent practices (e.g., naked domains and www subdomains being redirected to different destinations with varying security levels) undermine the security guarantees provided by HTTPS and HSTS. Li Chang, Hsu-Chun Hsiao, Wei Jeng, Tiffany Hyun-Jin Kim, Wei-Hsi Lin |
WWW | 4 |
| 2017 | Authentication Challenges in a Global EnvironmentabstractIn this article, we address the problem of scaling authentication for naming, routing, and end-entity (EE) certification to a global environment in which authentication policies and users’ sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and EE certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose the Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities’ authentication information globally discoverable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures. Stephanos Matsumoto, Raphael M. Reischuk, Pawel Szalachowski, Tiffany Hyun-Jin Kim, Adrian Perrig |
ACM Trans. Priv. Secur. | 4 |
| 2015 | A Practical System for Guaranteed Access in the Presence of DDoS Attacks and Flash CrowdsabstractWith the growing incidents of flash crowds and sophisticated DDoS attacks mimicking benign traffic, it becomes challenging to protect Internet-based services solely by differentiating attack traffic from legitimate traffic. While fair-sharing schemes are commonly suggested as a defense when differentiation is difficult, they alone may suffer from highly variable or even unbounded waiting times. We propose RainCheck Filter (RCF), a lightweight primitive that guarantees bounded waiting time for clients despite server flooding without keeping per-client state on the server. RCF achieves strong waiting time guarantees by prioritizing clients based on how long the clients have waited - as if the server maintained a queue in which the clients lined up waiting for service. To avoid keeping state for every incoming client request, the server sends to the client a raincheck, a timestamped cryptographic token that not only informs the client to retry later but also serves as a proof of the client's priority level within the virtual queue. We prove that every client complying with RCF can access the server in bounded time, even under a flash crowd incident or a DDoS attack. Our large-scale simulations confirm that RCF provides a small and predictable maximum waiting time while existing schemes cannot. To demonstrate its deployability, we implement RCF as a Python module such that web developers can protect a critical server resource by adding only three lines of code. Yi-Hsuan Kung, Taeho Lee 0003, Po-Ning Tseng, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Soo Bum Lee, Yue-Hsun Lin, Adrian Perrig |
ICNP | 5 |
| 2015 | Secure broadcast in distributed networks with strong adversariesabstractAbstract This paper proposes a framework that enables secureone‐to‐manycommunication for networks with limited capabilities in the face of a strong adversary that can capture an arbitrary set of nodes. Our approach consists of two main components: (a) group key establishment protocol and (b) special key management. Especially, we try to address the following question:How strong of security properties can we achieve for broadcast communication in hardware‐limited networks with a strong adversary?We propose approaches and their variants that neither require special hardware nor use costly cryptographic operations. With thorough security and efficiency analyses, we discuss how our solutions can be applied to a variety of hardware‐limited distributed systems. We also describe the implementation and evaluation results of the most promising variants. Copyright © 2015 John Wiley & Sons, Ltd. Pawel Szalachowski, Tiffany Hyun-Jin Kim |
Secur. Commun. Networks | 2 |
| 2014 | ARPKI: Attack Resilient Public-Key InfrastructureabstractWe present ARPKI, a public-key infrastructure that ensures that certificate-related operations, such as certificate issuance, update, revocation, and validation, are transparent and accountable. ARPKI is the first such infrastructure that systematically takes into account requirements identified by previous research. Moreover, ARPKI is co-designed with a formal model, and we verify its core security property using the Tamarin prover. We present a proof-of-concept implementation providing all features required for deployment. ARPKI efficiently handles the certification process with low overhead and without incurring additional latency to TLS. David A. Basin, Cas Cremers, Tiffany Hyun-Jin Kim, Adrian Perrig, Ralf Sasse, Pawel Szalachowski |
CCS | 3 |
| 2014 | YourPassword: applying feedback loops to improve security behavior of managing multiple passwordsabstractVarious mechanisms exist to secure users' passwords, yet users continue to struggle with the complexity of multiple password management. We explore the effectiveness of a feedback loop to improve users' password management. We introduce YourPassword, a web-based application that uses feedback to inform users about the security of their password behavior. YourPassword has two main components: a password behavior checker that converts password strengths into numerical scores and a dashboard interface that visualizes users' overall password behavior and provides visual feedback in real time. YourPassword not only provides a total score on all passwords, but also visualizes when passwords are too similar to each other. To test the efficacy of YourPassword, we conducted a between-subjects experiment and think-aloud test with 48 participants. Participants either had access to YourPassword, an existing commercial password checker, or no password tool (control condition). YourPassword helped participants improve their password behavior as compared with the commercial tool or no tool. Tiffany Hyun-Jin Kim, H. Colleen Stuart, Hsu-Chun Hsiao, Yue-Hsun Lin, Leon Zhang, Laura A. Dabbish, Sara B. Kiesler |
AsiaCCS | 1 |
| 2014 | Mechanized Network Origin and Path Authenticity ProofsabstractA secure routing infrastructure is vital for secure and reliable Internet services. Source authentication and path validation are two fundamental primitives for building a more secure and reliable Internet. Although several protocols have been proposed to implement these primitives, they have not been formally analyzed for their security guarantees. In this paper, we apply proof techniques for verifying cryptographic protocols (e.g., key exchange protocols) to analyzing network protocols. We encode LS2, a program logic for reasoning about programs that execute in an adversarial environment, in Coq. We also encode protocol-specific data structures, predicates, and axioms. To analyze a source-routing protocol that uses chained MACs to provide origin and path validation, we construct Coq proofs to show that the protocol satisfies its desired properties. To the best of our knowledge, we are the first to formalize origin and path authenticity properties, and mechanize proofs that chained MACs can provide the desired authenticity properties. Fuyuan Zhang, Limin Jia 0001, Cristina Basescu, Tiffany Hyun-Jin Kim, Yih-Chun Hu, Adrian Perrig |
CCS | 4 |
| 2014 | Lightweight source authentication and path validationabstractIn-network source authentication and path validation are fundamental primitives to construct higher-level security mechanisms such as DDoS mitigation, path compliance, packet attribution, or protection against flow redirection. Unfortunately, currently proposed solutions either fall short of addressing important security concerns or require a substantial amount of router overhead. In this paper, we propose lightweight, scalable, and secure protocols for shared key setup, source authentication, and path validation. Our prototype implementation demonstrates the efficiency and scalability of the protocols, especially for software-based implementations. Tiffany Hyun-Jin Kim, Cristina Basescu, Limin Jia 0001, Soo Bum Lee, Yih-Chun Hu, Adrian Perrig |
SIGCOMM | 1 |
| 2014 | The Effect of Social Influence on Security Sensitivity
Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, Jason I. Hong |
SOUPS | 2 |
| 2013 | STRIDE: sanctuary trail - refuge from internet DDoS entrapmentabstractWe propose STRIDE, a new DDoS-resilient Internet architecture that isolates attack traffic through viable bandwidth allocation, preventing a botnet from crowding out legitimate flows. This new architecture presents several novel concepts including tree-based bandwidth allocation and long-term static paths with guaranteed bandwidth. In concert, these mechanisms provide domain-based bandwidth guarantees within a trust domain - administrative domains grouped within a legal jurisdiction with enforceable accountability; each administrative domain in the trust domain can then internally split such guarantees among its endhosts to provide (1) connection establishment with high probability, and (2) precise bandwidth guarantees for established flows, regardless of the size or distribution of the botnet outside the source and the destination domains. Moreover, STRIDE maintains no per-flow state on backbone routers and requires no key establishment across administrative domains. We demonstrate that STRIDE achieves these DDoS defense properties through formal analysis and simulation. We also show that STRIDE mitigates emerging DDoS threats such as Denial-of-Capability (DoC) [6] and N2 attacks [22] based on these properties that none of the existing DDoS defense mechanisms can achieve. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Sangjae Yoo, Xin Zhang 0003, Soo Bum Lee, Virgil D. Gligor, Adrian Perrig |
AsiaCCS | 2 |
| 2013 | SafeSlinger: easy-to-use and secure public-key exchangeabstractUsers regularly experience a crisis of confidence on the Internet. Is that email or instant message truly originating from the claimed individual? Such doubts are commonly resolved through a leap of faith, expressing the desperation and helplessness of users. To establish a secure basis for online communication, we propose SafeSlinger, a system leveraging the proliferation of smartphones to enable people to securely and privately exchange their public keys. Through the exchanged authentic public keys, SafeSlinger establishes a secure channel offering secrecy and authenticity, which we use to support secure messaging and file exchange. SafeSlinger also provides an API for importing applications' public keys into a user's contact information. By slinging entire contact entries to others, we propose secure introductions, as the contact entry includes the SafeSlinger public keys as well as other public keys that were imported. We present the design and implementation of SafeSlinger for Android and iOS, which is available from the respective app stores. An overview video of SafeSlinger is available at: http://www.youtube.com/watch?v=IFXL8fUqNKY Michael W. Farb, Yue-Hsun Lin, Tiffany Hyun-Jin Kim, Jonathan M. McCune, Adrian Perrig |
MobiCom | 3 |
| 2013 | Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructureabstractRecent trends in public-key infrastructure research explore the tradeoff between decreased trust in Certificate Authorities (CAs), resilience against attacks, communication overhead (bandwidth and latency) for setting up an SSL/TLS connection, and availability with respect to verifiability of public key information. In this paper, we propose AKI as a new public-key validation infrastructure, to reduce the level of trust in CAs. AKI integrates an architecture for key revocation of all entities (e.g., CAs, domains) with an architecture for accountability of all infrastructure parties through checks-and-balances. AKI efficiently handles common certification operations, and gracefully handles catastrophic events such as domain key loss or compromise. We propose AKI to make progress towards a public-key validation infrastructure with key revocation that reduces trust in any single entity. Tiffany Hyun-Jin Kim, Lin-Shung Huang, Adrian Perrig, Collin Jackson, Virgil D. Gligor |
WWW | 1 |
| 2012 | OTO: online trust oracle for user-centric trust establishmentabstractMalware continues to thrive on the Internet. Besides automated mechanisms for detecting malware, we provide users with trust evidence information to enable them to make informed trust decisions. To scope the problem, we study the challenge of assisting users with judging the trustworthiness of software downloaded from the Internet. Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han 0001, Emmanuel Owusu, Jason I. Hong, Adrian Perrig, Debin Gao |
CCS | 1 |
| 2012 | ShortMAC: Efficient Data-Plane Fault Localization
Xin Zhang 0003, Zongwei Zhou, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Patrick Tague |
NDSS | 4 |
| 2012 | LAP: Lightweight Anonymity and PrivacyabstractPopular anonymous communication systems often require sending packets through a sequence of relays on dilated paths for strong anonymity protection. As a result, increased end-to-end latency renders such systems inadequate for the majority of Internet users who seek an intermediate level of anonymity protection while using latency-sensitive applications, such as Web applications. This paper serves to bridge the gap between communication systems that provide strong anonymity protection but with intolerable latency and non-anonymous communication systems by considering a new design space for the setting. More specifically, we explore how to achieve near-optimal latency while achieving an intermediate level of anonymity with a weaker yet practical adversary model (i.e., protecting an end-host's identity and location from servers) such that users can choose between the level of anonymity and usability. We propose Lightweight Anonymity and Privacy (LAP), an efficient network-based solution featuring lightweight path establishment and stateless communication, by concealing an end-host's topological location to enhance anonymity against remote tracking. To show practicality, we demonstrate that LAP can work on top of the current Internet and proposed future Internet architectures. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Akira Yamada 0001, Samuel C. Nelson, Marco Gruteser, Wei Meng 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | Cyber-Physical Security of a Smart Grid InfrastructureabstractIt is often appealing to assume that existing solutions can be directly applied to emerging engineering domains. Unfortunately, careful investigation of the unique challenges presented by new domains exposes its idiosyncrasies, thus often requiring new approaches and solutions. In this paper, we argue that the “smart” grid, replacing its incredibly successful and reliable predecessor, poses a series of new security challenges, among others, that require novel approaches to the field of cyber security. We will call this new field cyber-physical security. The tight coupling between information and communication technologies and physical systems introduces new security concerns, requiring a rethinking of the commonly used objectives and methods. Existing security approaches are either inapplicable, not viable, insufficiently scalable, incompatible, or simply inadequate to address the challenges posed by highly complex environments such as the smart grid. A concerted effort by the entire industry, the research community, and the policy makers is required to achieve the vision of a secure smart grid infrastructure. Yilin Mo, Tiffany Hyun-Jin Kim, Kenneth Brancik, Dona Dickinson, Heejo Lee, Adrian Perrig, Bruno Sinopoli |
Proc. IEEE | 2 |
| 2011 | A Picture is Worth a Thousand Words: Improving Usability and Robustness of Online Recommendation SystemsabstractRecent statistics show that the number of online shoppers are increasing where the majority of them use online recommendation systems for product/service reviews. Although online reviews are becoming increasingly important, consumers face two major challenges of usability and robustness when they make purchase decisions based on the available reviews. More specifically, usability issues arise when consumers need to be able to extract relevant information given a high volume of data with uncertainty due to high variance. For robustness, judging the degree of truthfulness of the available recommendations can be a daunting task for consumers. In this paper, we propose a post-purchase tracking system as an enhancement to current online recommendation systems by embracing a peer review process and ask each consumer to score the reviews that previous consumers have posted. Furthermore, we propose to visualize the peer review processes such that people find the recommendation systems more efficient and useful to learn information. Our preliminary user study results indicate that our post-purchase tracking system is a promising approach that can help online consumers determine what information to trust with high confidence. Tiffany Hyun-Jin Kim, Virgil D. Gligor, Adrian Perrig |
ICCCN | 1 |
| 2010 | Challenges in Access Right Assignment for Secure Home Networks
Tiffany Hyun-Jin Kim, Lujo Bauer, James Newsome, Adrian Perrig, Jesse Walker |
HotSec | 1 |