Sunwoo Lee 0004

dblp:56/7811-4 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-5216-0266ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 EchoType: Identity recognition from typing-induced ultrasonic reflections
Yena So, Youngjoo Park, Chaehyeon Kim, Jihee Lee, Sunwoo Lee 0004
Comput. Secur.6
2026 Charging Into Your Privacy: Indirect Privacy Leakage Attack Using a Laptop Charger
abstract
Can an everyday peripheral device, such as a laptop charger, function as an indirect side channel through which private user activities are exposed? In this paper, we propose PrivateCharger, a novel side-channel attack that affirms this possibility. By analyzing subtle variations in the magnetic field signals emitted by a laptop charger, PrivateCharger infers user activity without requiring any physical access to the laptop itself. Unlike prior work that targets internal components via power consumption or electromagnetic emissions, our approach shifts the attack vector to an external and previously overlooked component—the charger. This redirection enables stealthy inference from a distance, even outside the user's line of sight. Importantly, PrivateCharger operates using only commercially available devices, with no hardware modifications to the laptop or charger, significantly lowering the barrier to execution and enhancing real-world applicability. We evaluate our method across laptops with diverse hardware architectures and charger power ratings, achieving high recognition accuracy—especially at battery levels between 50% and 80%, where it reaches an average of 84.6% on two MacBook Pro models. Furthermore, we demonstrate the attack's robustness in complex real-world conditions, including multi-charger environments and concurrent application scenarios. These findings reveal that seemingly innocuous peripheral devices can serve as covert conduits for privacy leakage, expanding the threat landscape of passive sidechannel attacks in everyday computing environments.
Nahyun Kim, Hanseul Jung, Jeongmin Bak, Sunwoo Lee 0004
IEEE Trans. Dependable Secur. Comput.5
2025 Eyes on your Typing: Snooping Finger Motions on Virtual Keyboards
abstract
The rapid growth of augmented reality (AR) and virtual reality (VR) technologies has introduced immersive digital experiences for consumers across numerous fields, including banking, education, and professional spheres. In these environments, head-mounted displays (HMDs) enable users to interact with virtual objects through head and hand tracking. In particular, virtual keyboards are emerging as a primary input method, allowing users to type directly with their hands-eliminating the need for additional devices and adding convenience for portable HMD use. However, this direct hand-based typing introduces new security concerns, namely subtle head movements that occur during direct hand-based typing can unintentionally reveal private information. In this paper, we propose SNOOPFINGER, a novel side-channel attack that leverages head movement data, which is accessible without additional user permissions, to estimate typed inputs on a virtual keyboard. Unlike previous methods, SNOOPFINGER uniquely employs a cross-modality approach, relying solely on head movement data to infer hand-typed inputs without the use of controllers. Additionally, our approach is designed to identify a victim's typed inputs without requiring prior access to extensive head movement data from the victim or other users. In an experiment involving 24 participants, SNOOPFING ER achieved high inference accuracy rates, with an average Top-1 accuracy of 55.2% for word inference and 68.8% for sentence reconstruction. Finally, we discuss potential mitigation strategies to counteract such attacks. Our findings reveal critical privacy risks associated with direct hand-based typing in AR/VR environments, demonstrating how zero-permission sensor data can be exploited to obtain private information.
Sunwoo Lee 0004
SP1
2023 The vibration knows who you are! A further analysis on usable authentication for smartwatch users
abstract
These days, smartwatches are becoming more common and can even operate in stand-alone mode. This increases the need for smartwatches to authenticate users independently without paired smartphones. Currently, password or pattern-based methods can authenticate the smartwatch users in stand-alone mode, but these methods are known to be vulnerable to simple attacks such as shoulder-surfing and password dictionary attacks. In addition, biometric-based methods, which are expected to release on smartwatches in the near future, require inconvenient user interaction or special sensors for measurement. In light of this, we propose a smartwatch user authentication method that does not require any additional sensors or user interaction. Based on the fact that the human body structure affects the way vibrations are absorbed, reflected, and propagated, we designed a smartwatch user authentication method based on a challenge-response structure using vibrations. In our method, a challenge is a set of fresh random vibrations, which are provided by default in current smartwatches, and a response to the challenge is measured by built-in gyroscope and accelerometer sensors. Our earlier study demonstrated that commercial smartwatch users can be authenticated with a low equal error rate (EER) of 1.37 %. In this paper, we extended the analysis of our method on various vibration types by using a prototype setup. As a result, we discovered an outperformed vibration type for user authentication. We conducted further analysis for users with heavier body weights as these individuals are more vulnerable to a not-in-wear attack. Finally, we conducted more advanced impersonation attacks on test participants with one or more similar physical indicators to demonstrate that our method is also secure against a wider range of more complex attacks.
Sunwoo Lee 0004, Wonsuk Choi 0001, Dong Hoon Lee 0001
Comput. Secur.1
2023 From Attack to Identification: MEMS Sensor Fingerprinting Using Acoustic Signals
abstract
A device pretending to be behaving normally can carry out malicious acts that result in the leakage of sensitive information, invasion of privacy, damage property, or even loss of life. The first step to detect these malicious acts is to identify whether a device is authorized or not. There are existing methods for identifying devices based on cryptographic schemes or physical unclonable function (PUF), but each of these methods has disadvantages in that key management costs are incurred or additional chips or circuits are required. In this article, we propose a device identification method that overcomes these shortcomings. Based on the fact that MEMS sensors are built-in to most devices due to their various applications and the property that MEMS sensors are sensitive to acoustic signals with resonant frequencies, the proposed method uses MEMS sensor readings to acoustic signals. Many attack methods have been studied using this property to disable the normal function of the sensor or eavesdrop on speech around a device. On the other hand, our method is the first to fingerprint MEMS sensors using raw sensor readings to acoustic signals from a security point of view rather than from this conventional attack point of view. Furthermore, our method is based on a challenge-response structure to be secure from replay attacks; here, a challenge is a random acoustic signal, and a response is the unique MEMS sensor reading to the challenge. In our evaluation, we use commercial MEMS sensors and a low-cost speaker that costs less than$\$ $1. The results show that under various conditions that may affect MEMS sensor readings, the macro F1-scores when identifying authorized devices is 1.0, and the macro accuracy of detecting attacks using devices other than authorized ones is 0.994. As a result, our method can identify devices well at a low cost.
Sunwoo Lee 0004, Dong Hoon Lee 0001
IEEE Internet Things J.1
2021 Usable User Authentication on a Smartwatch using Vibration
abstract
Smartwatches have come into wide use in recent years, and a number of smartwatch applications that improve convenience and user health are being developed and introduced constantly. Moreover, the latest smartwatches are now designed to operate without their paired smartphones, and as such, it is necessary for smartwatches to independently authenticate users. In these current devices, personal identification numbers (PIN) or patterns are entered to authenticate users, but these methods require inconvenient interaction for the user and are not highly secure. Particularly relevant to smartwatch technology, even user authentication based on biometric information needs either special sensors capable of measuring biometric information or user interaction. In this paper, we propose a usable method for user authentication on smartwatches without additional devices. Based on the fact that vibration is absorbed, reflected, and propagated differently according to the physical structure of each human body, our method is designed as a challenge-response scheme, in which the challenge is a random sequence of multiple vibration types that are already built into current smartwatches. The responses to vibrations are measured by the default gyroscope and accelerometer sensors in smartwatches. Moreover, our method is the first working model for commercial smartwatch models with low specifications when vibrating and measuring responses. We evaluated our method using a commercial smartwatch, and the results show that our method is able to authenticate a user with an equal error rate (EER) of 1.37%.
Sunwoo Lee 0004, Wonsuk Choi 0001, Dong Hoon Lee 0001
CCS1