EDBT 2026 Demo / reviewers in the wild / expert
Hyunwoo Lee 0001
dblp:55/8846-1
· DBLP profile ↗
15ranked-venue papers
5as first author
14since 2021 · last 2026
0000-0001-7490-9936ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 6 since 2021Computer networks · 4 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VWAttacker: A Systematic Security Testing Framework for Voice over WiFi User EquipmentsabstractWe present VWAttacker, the first systematic testing framework for analyzing the security of Voice over WiFi (VoWiFi) User Equipment (UE) implementations. VWAttacker includes a complete VoWiFi network testbed that communicates with Commercial-Off-The-Shelf (COTS) UEs based on a simple interface to test the behavior of diverse VoWiFi UE implementations; uses property-guided adversarial testing to uncover security issues in different UEs systematically. To reduce manual effort in extracting and testing properties, we introduce an LLM-based, semi-automatic, and scalable approach for property extraction and testcase (TC) generation. These TCs are systematically mutated by two domain-specific transformations. Furthermore, we introduce two deterministic oracles to detect property violations automatically. Coupled with these techniques, VWAttacker extracts 63 properties from 11 specifications, evaluates 1,116 testcases, and detects 13 issues in 21 UEs. The issues range from enforcing a DH shared secret to 0 to supporting weak algorithms. These issues result in attacks that expose the victim UE's identity or establish weak channels, thus severely hampering the security of cellular networks. We responsibly disclose the findings to all the related vendors. At the time of writing, one of the vulnerabilities has been acknowledged by MediaTek with high severity. Imtiaz Karim, Hyunwoo Lee 0001, Hassan Asghar 0002, Kazi Samin Mubasshir, Seulgi Han, Mashroor Hasan Bhuiyan, Elisa Bertino |
INFOCOM | 2 |
| 2025 | IoTDSCreator: A Framework to Create Labeled Datasets for IoT Intrusion Detection SystemsabstractIntrusion detection systems (IDSes) are critical building blocks for securing Internet-of-Things (IoT) devices and networks. Advances in AI techniques are contributing to enhancing the efficiency of IDSes, but their performance typically depends on high-quality training datasets. The scarcity of such datasets is a major concern for the effective use of machine learning for IDSes in IoT networks. To address such a need, we present IoTDSCreator - a tool for the automatic generation of labeled datasets able to support various devices, connectivity technologies, and attacks. IoTDSCreator provides a user with DC-API, an API by which the user can describe a target network and an attack scenario against it. Based on the description, the framework configures the network, leveraging virtualization techniques on user-provided physical machines, performs single or multi-step attacks, and finally returns labeled datasets. Thereby, IoTDSCreator dramatically reduces the manual effort for generating labeled and diverse datasets. We release the source code of IoTDSCreator and 16 generated datasets with 193 features based on 26 types of IoT devices, 2 types of communication links, and 15 types of IoT applications. Hyunwoo Lee 0001, Charalampos Katsis, Alireza Lotfi, Taejun Choi, Soeun Kim, Ashish Kundu, Elisa Bertino |
CODASPY | 1 |
| 2025 | Poster: Automated Security Property Extraction from Protocol Specifications
Hassan Asghar 0002, Myeong-Ha Hwang, Jeonghyun Joo, Heewoon Kang, YooJin Kwon, Kazi Samin Mubasshir, Imtiaz Karim, Elisa Bertino, Hyunwoo Lee 0001 |
ICNP | 9 |
| 2025 | ExpressPQDelivery: Toward Efficient and Immediately Deployable Post-Quantum Key Delivery for Web-of-ThingsabstractPost-quantum cryptography (PQC) aims to develop quantum-safe algorithms against attacks by a quantum computer. As quantum-safe algorithms require much larger keys in their operation compared to the current RSA/ECC practice, the networking latency significantly increases when executing the protocols with sending such large keys. This problem gets more challenging in the era of Web-of-Things (WoT) with low-memory devices. To tackle the problem, we propose ExpressPQDelivery, which is, to the best of our knowledge, the first immediately deployable protocol to efficiently transport large keys. It leverages the DNS infrastructure, as DNS is close to clients, guaranteeing express key delivery with a short round-trip time (RTT). We split a large PQ key along with a server's signature and feed them into several DNS records. To show the feasibility of ExpressPQDelivery, we instantiate it with TLS 1.3 and demonstrate that it reduces 27% of network latency between a server and a client on average compared to the standard TLS 1.3. We deploy ExpressPQDelivery on a low-capability board with 256 KB RAM, showing a significant high gain (34%). Jane Kim, Jung-Hun Kang, Hyunwoo Lee 0001, Seung-Hyun Seo |
WWW | 3 |
| 2024 | Sharing cyber threat intelligence: Does it really help?
Beomjin Jin, Eunsoo Kim, Hyunwoo Lee 0001, Elisa Bertino, Doowon Kim, Hyoungshick Kim |
NDSS | 3 |
| 2024 | ARIoTEDef: Adversarially Robust IoT Early Defense System Based on Self-Evolution against Multi-step AttacksabstractInternet of Things (IoT) cyber threats, exemplified by jackware and crypto mining, underscore the vulnerability of IoT devices. Due to the multi-step nature of many attacks, early detection is vital for a swift response and preventing malware propagation. However, accurately detecting early-stage attacks is challenging, as attackers employ stealthy, zero-day, or adversarial machine learning to evade detection. To enhance security, we propose ARIoTEDef, an Adversarially Robust IoT Early Defense system, which identifies early-stage infections and evolves autonomously. It models multi-stage attacks based on a cyber kill chain and maintains stage-specific detectors. When anomalies in the later action stage emerge, the system retroactively analyzes event logs using an attention-based sequence-to-sequence model to identify early infections. Then, the infection detector is updated with information about the identified infections. We have evaluated ARIoTEDef against multi-stage attacks, such as the Mirai botnet. Results show that the infection detector’s average F1 score increases from 0.31 to 0.87 after one evolution round. We have also conducted an extensive analysis of ARIoTEDef against adversarial evasion attacks. Our results show that ARIoTEDef is robust and benefits from multiple rounds of evolution. Mengdie Huang, Hyunwoo Lee 0001, Ashish Kundu, Xiaofeng Chen 0001, Anand Mudgerikar, Ninghui Li 0001, Elisa Bertino |
ACM Trans. Internet Things | 2 |
| 2023 | Towards Efficient Privacy-Preserving Deep Packet Inspection
Hyunwoo Lee 0001, Elisa Bertino, Ninghui Li 0001 |
ESORICS (2) | 2 |
| 2023 | ZTLS: A DNS-based Approach to Zero Round Trip Delay in TLS handshakeabstractEstablishing secure connections fast to end-users is crucial to online services. However, when a client sets up a TLS session with a server, the TLS handshake needs one round trip time (RTT) to negotiate a session key. Additionally, establishing a TLS session also requires a DNS lookup (e.g., the A record lookup to fetch the IP address of the server) and a TCP handshake. In this paper, we propose ZTLS to eliminate the 1-RTT latency for the TLS handshake by leveraging the DNS. In ZTLS, a server distributes TLS handshake-related data (i.e., Diffie-Hellman elements), dubbed Z-data, as DNS records. A ZTLS client can fetch Z-data by DNS lookups and derive a session key. With the session key, the client can send encrypted data along with its ClientHello, achieving 0-RTT. ZTLS supports incremental deployability on the current TLS-based infrastructure. Our prototype-based experiments show that ZTLS is 1-RTT faster than TLS in terms of the first response time. Sangwon Lim, Hyeonmin Lee, Hyunwoo Lee 0001, Ted Taekyoung Kwon |
WWW | 4 |
| 2023 | AppSniffer: Towards Robust Mobile App Fingerprinting Against VPNabstractApplication fingerprinting is a useful data analysis technique for network administrators, marketing agencies, and security analysts. For example, an administrator can adopt application fingerprinting techniques to determine whether a user’s network access is allowed. Several mobile application fingerprinting techniques (e.g., FlowPrint, AppScanner, and ET-BERT) were recently introduced to identify applications using the characteristics of network traffic. However, we find that the performance of the existing mobile application fingerprinting systems significantly degrades when a virtual private network (VPN) is used. To address such a shortcoming, we propose a framework dubbed AppSniffer that uses a two-stage classification process for mobile app fingerprinting. In the first stage, we distinguish VPN traffic from normal traffic; in the second stage, we use the optimal model for each traffic type. Specifically, we propose a stacked ensemble model using Light Gradient Boosting Machine (LightGBM) and a FastAI library-based neural network model to identify applications’ traffic when a VPN is used. To show the feasibility of AppSniffer, we evaluate the detection accuracy of AppSniffer for 150 popularly used Android apps. Our experimental results show that AppSniffer effectively identifies mobile applications over VPNs with F1-scores between 84.66% and 95.49% across four different VPN protocols. In contrast, the best state-of-the-art method (i.e., AppScanner) demonstrates significantly lower F1-scores between 25.63% and 47.56% in the same settings. Overall, when normal traffic and VPN traffic are mixed, AppSniffer achieves an F1-score of 90.63%, which is significantly better than AppScanner that shows an F1-score of 70.36%. Sanghak Oh, Minwook Lee, Hyunwoo Lee 0001, Elisa Bertino, Hyoungshick Kim |
WWW | 3 |
| 2023 | How to decentralize the internet: A focus on data consolidation and user privacyabstractOver the years, the Internet has become a field in which a small number of large Internet companies dominate most of the Internet services. As users get used to using their services, the users’ generated content and the data about their online behaviors are concentrated in such companies. This phenomenon, called “data consolidation”, has become a serious problem, which makes the Internet society seek to decentralize the current Internet. The decentralized Internet aims to (i) prevent the concentration of user data in a few giant companies like Google and Facebook, and (ii) give users full ownership and control of their data. Various technical solutions that address the data consolidation problem have been proposed; however, those solutions focus on somewhat different scopes of the problem often from their limited viewpoints. The main contributions in this paper are the following. First, we survey the solutions relevant to Internet decentralization based on the following criteria: data consolidation, data ownership, and the privacy of user data. Second, we suggest a holistic reference framework from a functional viewpoint, while the prior proposals in the literature handle a limited set of requirements. Last, we seek to identify remaining research issues, considering additional requirements that have not been addressed in the existing solutions. Ted Taekyoung Kwon, Jung Hwan Song, Heeyoung Jung, Selin Chun, Hyunwoo Lee 0001, Minhyeok Kang, Minkyung Park, Eunsang Cho 0001 |
Comput. Networks | 5 |
| 2022 | VWAnalyzer: A Systematic Security Analysis Framework for the Voice over WiFi ProtocolabstractIn this paper, we evaluate the security of the Voice over WiFi (VoWiFi) protocol by proposing the VWAnalyzer framework. We model five critical procedures of the VoWiFi protocol and deploy a model-based testing approach to uncover potential design flaws. Since the standards of the VoWiFi protocol contain underspecifications that can lead to vulnerable scenarios, VWAnalyzer explicitly deals with them. Unlike prior approaches that do not consider the underspecifications, VWAnalyzer adopts a systematic approach that constructs diverse and viable scenarios based on the underspecifications and substantially reduces the number of possible scenarios. Then the scenarios are verified against security properties. VWAnalyzer automatically generates 960 viable scenarios to be analyzed among 10,368 scenarios (91% decrease) from the initial models. We demonstrate the effectiveness of VWAnalyzer by verifying 38 properties and uncovering 3 new attacks. Notable among our findings is the denial-of-cellular-connectivity attack, due to insecure handover that disconnects the user through both VoWiFi and VoLTE. To ensure that the exposed attacks pose real threats and are indeed realizable in practice, we have validated the attacks in a real-world testbed. We also report several implementations issues that were uncovered during the testbed evaluation. Hyunwoo Lee 0001, Imtiaz Karim, Ninghui Li 0001, Elisa Bertino |
AsiaCCS | 1 |
| 2022 | An Infection-Identifying and Self-Evolving System for IoT Early Defense from Multi-Step Attacks
Hyunwoo Lee 0001, Anand Mudgerikar, Ashish Kundu, Ninghui Li 0001, Elisa Bertino |
ESORICS (2) | 1 |
| 2021 | Analyzing Spatial Differences in the TLS Security of Delegated Web ServicesabstractTo provide secure content delivery, Transport Layer Security (TLS) has become a de facto standard over a couple of decades. However, TLS has a long history of security weaknesses and drawbacks. Thus, the security of TLS has been enhanced by addressing security problems through continuous version upgrades. Meanwhile, to provide fast content delivery globally, websites (or origin web servers) need to deploy and administer many machines in globally distributed environments. They often delegate the management of machines to web hosting services or content delivery networks (CDNs), where the security configurations of distributed servers may vary spatially depending on the managing entities or locations. Based on these spatial differences in TLS security, we find that the security level of TLS connections (and their web services) can be lowered. After collecting the information of (web) domains that exhibit different TLS versions and cryptographic options depending on clients' locations, we show that it is possible to redirect TLS handshake messages to weak TLS servers, which both the origin server and the client may not be aware of. We investigate 7M domains with these spatial differences of security levels in the wild and conduct the analyses to better understand the root causes of this phenomenon. We also measure redirection delays at various locations in the world to see whether there are noticeable delays in redirections. Hyunwoo Lee 0001, Jongheon Jeong, Doowon Kim, Ted Taekyoung Kwon |
AsiaCCS | 2 |
| 2021 | TLS 1.3 in Practice: How TLS 1.3 Contributes to the InternetabstractTransport Layer Security (TLS) has become the norm for secure communication over the Internet. In August 2018, TLS 1.3, the latest version of TLS, was approved, providing improved security and performance of the previous TLS version. In this paper, we take a closer look at TLS 1.3 deployments in practice regarding adoption rate, security, performance, and implementation by applying temporal, spatial, and platform-based approaches on 687M connections. Hyunwoo Lee 0001, Doowon Kim, Yonghwi Kwon 0001 |
WWW | 1 |
| 2019 | maTLS: How to Make TLS middlebox-aware?
Hyunwoo Lee 0001, Zach Smith, Junghwan Lim, Gyeongjae Choi, Selin Chun, Taejoong Chung, Ted Taekyoung Kwon |
NDSS | 1 |