Sangwon Hyun

dblp:65/3536 · DBLP profile ↗
← Back
18ranked-venue papers
9as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Computer networks · 3 · 3 first-authorSecurity and privacy · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 DDPT: Diffusion-Driven Prompt Tuning for Large Language Model Code Generation
abstract
Large Language Models (LLMs) have demonstrated remarkable capabilities in code generation. However, the quality of the generated code is heavily dependent on the structure and composition of the prompts used. Crafting high-quality prompts is a challenging task that requires significant knowledge and skills of prompt engineering. To advance the automation support for the prompt engineering for LLM-based code generation, we propose a novel solution Diffusion-Driven Prompt Tuning (DDPT) that learns how to generate optimal prompt embedding from Gaussian Noise to automate the prompt engineering for code generation. We evaluate the feasibility of diffusion-based optimization and abstract the optimal prompt embedding as a directional vector toward the optimal embedding. We use the code generation loss given by the LLMs to help the diffusion model capture the distribution of optimal prompt embedding during training. The trained diffusion model can build a path from the noise distribution to the optimal distribution at the sampling phrase, the evaluation result demonstrates that DDPT helps improve the prompt optimization for code generation.
Sangwon Hyun, M. Ali Babar
CAIN2
2025 Collaboration failure analysis in cyber-physical system-of-systems using context fuzzy clustering
abstract
Abstract A cyber-physical system-of-systems (CPSoS) facilitates the achievement of high-level goals, such as efficient traffic management on roads, by designing and developing the collaboration of constituent CPSs. A platooning that groups autonomous vehicles in proximity is an example of collaboration. The intricate collaboration innately causes serious collaboration failures such as collisions. However, limited knowledge and complex dynamics of CPSoS cause several challenges in effectively analyzing the collaboration failures. Existing studies have applied pattern mining techniques to investigate various failures but have limitations when applied to collaboration failures: (1) absence of data model for continuous and discrete logs in CPSoS; (2) information loss problem by not considering the integrated relationship of the data; (3) dependence only on failed logs; (4) limited capability of fixed-size time windows. We propose a fuzzy clustering-based pattern mining approach that consists of a novel data model for CPSoS logs and comprehensive metrics for classifying and mining optimal collaboration failure patterns. In experiments on vehicle platooning, our approach exhibited the highest accuracy on pattern mining and clustering results. Further, we identified five collaboration failure scenarios in the empirical analysis of drone swarming results. The findings of this study can facilitate the effective analysis of CPSoS collaboration failures.
Sangwon Hyun, Eunkyoung Jee, Doo-Hwan Bae
Empir. Softw. Eng.1
2024 METAL: Metamorphic Testing Framework for Analyzing Large-Language Model Qualities
abstract
Large-Language Models (LLMs) have shifted the paradigm of natural language data processing. However, their black-boxed and probabilistic characteristics can lead to potential risks in the quality of outputs in diverse LLM applications. Recent studies have tested Quality Attributes (QAs), such as robustness or fairness, of LLMs by generating adversarial input texts. However, existing studies have limited their coverage of QAs and tasks in LLMs and are difficult to extend. Additionally, these studies have only used one evaluation metric, Attack Success Rate (ASR), to assess the effectiveness of their approaches. We propose a MEtamorphic Testing for Analyzing LLMs (METAL) framework to address these issues by applying Metamorphic Testing (MT) techniques. This approach facilitates the systematic testing of LLM qualities by defining Metamorphic Relations (MRs), which serve as modularized evaluation metrics. The METAL framework can automatically generate hundreds of MRs from templates that cover various QAs and tasks. In addition, we introduced novel metrics to assess the effectiveness of MRs accurately by integrating the ASR method into the semantic qualities of text. Through the experiments conducted with three prominent LLMs, we have confirmed that the METAL framework effectively evaluates essential QAs on primary LLM tasks and reveals the quality risks in LLMs. Moreover, the newly proposed metrics can guide the optimal MRs for testing each task and suggest the most effective method for generating MRs.
Sangwon Hyun, Mingyu Guo 0001, Muhammad Ali Babar 0001
ICST1
2023 Timed pattern-based analysis of collaboration failures in system-of-systems
Sangwon Hyun, Jiyoung Song, Eunkyoung Jee, Doo-Hwan Bae
J. Syst. Softw.1
2022 Automatic Generation of Metamorphic Relations for a Cyber-Physical System-of-Systems Using Genetic Algorithm
abstract
A Cyber-Physical System-of-Systems (CPSoS) has innate uncertainties from operation in the physical environment and interaction among the constituent systems. These uncertainties make a CPSoS more susceptible to the oracle problem, a challenge in determining the correct behavior when testing the system. Metamorphic testing (MT) suggests a solution to addressing this challenge by utilizing metamorphic relations (MRs), relations among multiple inputs and corresponding outputs of the system. However, when applying MT on a CPSoS, generating MRs is difficult due to the continuous operation of a CPSoS in uncertain environment. In this study, we propose a method to automatically generate MRs from field operational test (FOT) data logs of a CPSoS. We define an MR template to capture the CPSoS behaviors. We then apply genetic algorithm to adapt the MR generated by the engineers, and thus improve the testing effectiveness. Our method is validated in a case study of an autonomous robot vehicle. Our results show that the automatically generated MRs capture the behaviors of a CPSoS more realistically than the manually generated MRs. With our method, engineers can obtain CPSoS MRs with minimal manual effort.
Esther Cho, Sangwon Hyun, Hansu Kim, Doo-Hwan Bae
APSEC3
2022 Continuous verification of system of systems with collaborative MAPE-K pattern and probability model slicing
Jiyoung Song, Jeehoon Kang, Sangwon Hyun, Eunkyoung Jee, Doo-Hwan Bae
Inf. Softw. Technol.3
2022 A Bayesian approach to modeling phytoplankton population dynamics from size distribution time series
abstract
The rates of cell growth, division, and carbon loss of microbial populations are key parameters for understanding how organisms interact with their environment and how they contribute to the carbon cycle. However, the invasive nature of current analytical methods has hindered efforts to reliably quantify these parameters. In recent years, size-structured matrix population models (MPMs) have gained popularity for estimating division rates of microbial populations by mechanistically describing changes in microbial cell size distributions over time. Motivated by the mechanistic structure of these models, we employ a Bayesian approach to extend size-structured MPMs to capture additional biological processes describing the dynamics of a marine phytoplankton population over the day-night cycle. Our Bayesian framework is able to take prior scientific knowledge into account and generate biologically interpretable results. Using data from an exponentially growing laboratory culture of the cyanobacterium Prochlorococcus, we isolate respiratory and exudative carbon losses as critical parameters for the modeling of their population dynamics. The results suggest that this modeling framework can provide deeper insights into microbial population dynamics provided by size distribution time-series data.
Jann Paul Mattern, Kristof Glauninger, Gregory L. Britten, John R. Casey, Sangwon Hyun, E. Virginia Armbrust, Zaïd Harchaoui, Francois Ribalet
PLoS Comput. Biol.5
2022 Mutexion: Mutually Exclusive Compression System for Mitigating Compression Side-Channel Attacks
abstract
To enhance the performance of web services, web servers often compress data to be delivered. Unfortunately, the data compression technique has also introduced a side effect called compression side-channel attacks (CSCA) . CSCA allows eavesdroppers to unveil secret strings included in the encrypted traffic by observing the length of data. A promising defense technique called Debreach was recently proposed to mitigate CSCA by excluding all secret data in a web page during the compression process. Although Debreach has proven to be safe against CSCA and outperforms other approaches, the exclusion of all secret data from compression eventually resulted in a decreased compression efficiency. In this paper, we present a highly efficient CSCA mitigation system called “Mutexion” ( Mut ually ex clusive compress ion ) which allows us to fully take advantage of compression over an entire web page, including secret data. The key idea behind Mutexion is to fully take advantage of all the matching subsequences within a web page except only for those between secret data and user-controlled data (potentially controlled by an attacker) during the compression process. This approach of Mutexion effectively prevents side-channel leaks of secret data under CSCA misusing user-controlled data in a web page while minimizing the degradation in compression efficiency. It is required for our compressor to trace both secret data and user-controlled data in its compression process of web pages. To meet this requirement, we provide techniques to enable automated annotation of secret and user-controlled data in web pages. We implemented Mutexion as a fully working system to test live web pages and evaluated its performance with respect to security and compression efficiency. Our evaluation results demonstrated that Mutexion effectively prevents CSCA and also achieves almost the same compression ratio as the original zlib, which is vulnerable to CSCA, with a slight increase (0.032 milliseconds (7.9%) on average) in execution time.
Taegeun Moon, Hyoungshick Kim, Sangwon Hyun
ACM Trans. Web3
2020 Pattern-based Analysis of Interaction Failures in Systems-of-Systems: a Case Study on Platooning
abstract
Interactions between software components play a major role in the achievement of goals in complex systems, such as platooning System-of-Systems (SoS). A platooning SoS groups vehicles in order to increase their fuel efficiency and alleviates traffic congestion by enabling driving in close proximity using operation protocols. In a platooning SoS, the execution of typical operations, such as Leave or Merge, consists of 20 micro-operations on average. Owing to this overabundance of sub-operations, interaction failures in a specific operation sequence can occur in an SoS execution. Further, analyzing the root cause of such failures is highly time-consuming, due to the density of the constituent interactions. Existing techniques suffer from two limitations: (1) The majority of the root cause analysis techniques are not capable of isolating faulty interaction sequences, because they do not directly utilize interaction data; (2) The majority of the fault diagnosis techniques assume the preexamined fault knowledge base, which needs too high cost due to limited knowledge in an SoS. To effectively analyze interaction failures in an SoS, we propose a pattern-based faulty interaction analysis technique. To this end, an interaction model is first defined for an SoS, followed by the proposal of a suspicious interaction pattern mining algorithm. During the case study using a platooning simulator, the technique automatically abstracts interaction data from logs and extracts faulty interaction patterns, thereby enabling the identification of seven new unreported interaction failure scenarios. The conclusions of this study can enrich the general fault knowledge base for platooning SoS.
Sangwon Hyun, Jiyoung Song, Seungchyul Shin, Young Min Baek, Doo-Hwan Bae
APSEC1
2019 Statistical Verification Framework for Platooning System of Systems with Uncertainty
abstract
Platooning system is a well-known technology for alleviating traffic congestion and increasing fuel efficiency by grouping vehicles. It has the major characteristics of Systems of Systems (SoS), such as uncertainty. Several internal and external factors of uncertainty exist in the platooning system, such as car accidents, network disconnections, and simultaneous requests from other platoons. These factors make it difficult to guarantee that the system operates correctly in unpredictable scenarios and environments. The existing techniques used to verify the platooning system have two limitations: 1) the lack of consideration of uncertainty in scenarios and environments; 2) the application of exhaustive verification techniques which are vulnerable to the state-explosion problem. Thus, we suggest a statistical verification framework for a platooning SoS to address the above two limitations. The proposed framework automatically generates platooning configurations and scenarios with internal and external uncertain factors considered, and bypasses the state-explosion problem using a statistical verification technique. In this study, experimental results showed that the proposed approach generates 50% more valid scenarios than pure random strategy. In addition, we found two types of undiscovered failures and their causes in the VENTOS platooning system. These results indicate that our approaches enable the deep analysis of the platooning management system.
Sangwon Hyun, Jiyoung Song, Seungchyul Shin, Doo-Hwan Bae
APSEC1
2019 Kerberoid: A Practical Android App Decompilation System with Multiple Decompilers
abstract
Decompilation is frequently used to analyze binary programs. In Android, however, decompilers all perform differently with varying apps due to their own characteristics. Obviously, there is no universal solution in all conditions. Based on this observation, we present a practical Android app decompilation system (called Kerberoid) that automatically stitches the results from multiple decompilers together to maximize the coverage and the accuracy of decompiled codes. We evaluate the performance of Kerberoid with 151 Android apps in which their corresponding source codes are publicly available. Kerberoid fully recovered all functions for 17% of the apps tested and gained a similarity score over 50% for 40% of the apps tested, increased by 7% and 9%, respectively, compared with the best existing decompiler.
Heejun Jang, Beomjin Jin, Sangwon Hyun, Hyoungshick Kim
CCS3
2018 Nonmechanistic forecasts of seasonal influenza with iterative one-week-ahead distributions
abstract
Accurate and reliable forecasts of seasonal epidemics of infectious disease can assist in the design of countermeasures and increase public awareness and preparedness. This article describes two main contributions we made recently toward this goal: a novel approach to probabilistic modeling of surveillance time series based on "delta densities", and an optimization scheme for combining output from multiple forecasting methods into an adaptively weighted ensemble. Delta densities describe the probability distribution of the change between one observation and the next, conditioned on available data; chaining together nonparametric estimates of these distributions yields a model for an entire trajectory. Corresponding distributional forecasts cover more observed events than alternatives that treat the whole season as a unit, and improve upon multiple evaluation metrics when extracting key targets of interest to public health officials. Adaptively weighted ensembles integrate the results of multiple forecasting methods, such as delta density, using weights that can change from situation to situation. We treat selection of optimal weightings across forecasting methods as a separate estimation task, and describe an estimation procedure based on optimizing cross-validation performance. We consider some details of the data generation process, including data revisions and holiday effects, both in the construction of these forecasting methods and when performing retrospective evaluation. The delta density method and an adaptively weighted ensemble of other forecasting methods each improve significantly on the next best ensemble component when applied separately, and achieve even better cross-validated performance when used in conjunction. We submitted real-time forecasts based on these contributions as part of CDC's 2015/2016 FluSight Collaborative Comparison. Among the fourteen submissions that season, this system was ranked by CDC as the most accurate.
Logan C. Brooks, David C. Farrow, Sangwon Hyun, Ryan J. Tibshirani, Ronald Rosenfeld
PLoS Comput. Biol.3
2018 Design and Analysis of Push Notification-Based Malware on Android
abstract
Establishing secret command and control (C&C) channels from attackers is important in malware design. This paper presents design and analysis of malware architecture exploiting push notification services as C&C channels. The key feature of the push notification-based malware design is remote triggering , which allows attackers to trigger and execute their malware by push notifications. The use of push notification services as covert channels makes it difficult to distinguish this type of malware from other normal applications also using the same services. We implemented a backdoor prototype on Android devices as a proof-of-concept of the push notification-based malware and evaluated its stealthiness and feasibility. Our malware implementation effectively evaded the existing malware analysis tools such as 55 antimalware scanners from VirusTotal and SandDroid. In addition, our backdoor implementation successfully cracked about 98% of all the tested unlock secrets (either PINs or unlock patterns) in 5 seconds with only a fraction (less than 0.01%) of the total power consumption of the device. Finally, we proposed several defense strategies to mitigate push notification-based malware by carefully analyzing its attack process. Our defense strategies include filtering subscription requests for push notifications from suspicious applications, providing centralized management and access control of registration tokens of applications, detecting malicious push messages by analyzing message contents and characteristic patterns demonstrated by malicious push messages, and detecting malware by analyzing the behaviors of applications after receiving push messages.
Sangwon Hyun, Junsung Cho, Geumhwan Cho, Hyoungshick Kim
Secur. Commun. Networks1
2018 Secure and DoS-Resilient Fragment Authentication in CCN-Based Vehicular Networks
abstract
Content‐Centric Networking (CCN) is considered as a promising alternative to traditional IP‐based networking for vehicle‐to‐everything communication environments. In general, CCN packets must be fragmented and reassembled based on the Maximum Transmission Unit (MTU) size of the content delivery path. It is thus challenging to securely protect fragmented packets against attackers who intentionally inject malicious fragments to disrupt normal services on CCN‐based vehicular networks. This paper presents a new secure content fragmentation method that is resistant to Denial‐of‐Service (DoS) attacks in CCN‐based vehicular networks. Our approach guarantees the authenticity of each fragment through the immediate fragment verification at interim nodes on the routing path. Our experiment results demonstrate that the proposed approach provides much stronger security than the existing approach named FIGOA, without imposing a significant overhead in the process. The proposed method achieves a high immediate verification probability of 98.2% on average, which is 52% higher than that of FIGOA, while requiring only 14% more fragments than FIGOA.
Sangwon Hyun, Hyoungshick Kim
Wirel. Commun. Mob. Comput.1
2017 FEC-Seluge: Efficient, reliable, and secure large data dissemination using erasure codes
Sangwon Hyun, Kun Sun 0001, Peng Ning
Comput. Commun.1
2017 A human judgment approach to epidemiological forecasting
abstract
Infectious diseases impose considerable burden on society, despite significant advances in technology and medicine over the past century. Advanced warning can be helpful in mitigating and preparing for an impending or ongoing epidemic. Historically, such a capability has lagged for many reasons, including in particular the uncertainty in the current state of the system and in the understanding of the processes that drive epidemic trajectories. Presently we have access to data, models, and computational resources that enable the development of epidemiological forecasting systems. Indeed, several recent challenges hosted by the U.S. government have fostered an open and collaborative environment for the development of these technologies. The primary focus of these challenges has been to develop statistical and computational methods for epidemiological forecasting, but here we consider a serious alternative based on collective human judgment. We created the web-based "Epicast" forecasting system which collects and aggregates epidemic predictions made in real-time by human participants, and with these forecasts we ask two questions: how accurate is human judgment, and how do these forecasts compare to their more computational, data-driven alternatives? To address the former, we assess by a variety of metrics how accurately humans are able to predict influenza and chikungunya trajectories. As for the latter, we show that real-time, combined human predictions of the 2014-2015 and 2015-2016 U.S. flu seasons are often more accurate than the same predictions made by several statistical systems, especially for short-term targets. We conclude that there is valuable predictive power in collective human judgment, and we discuss the benefits and drawbacks of this approach.
David C. Farrow, Logan C. Brooks, Sangwon Hyun, Ryan J. Tibshirani, Donald S. Burke, Ronald Rosenfeld
PLoS Comput. Biol.3
2015 Flexible Modeling of Epidemics with an Empirical Bayes Framework
abstract
Seasonal influenza epidemics cause consistent, considerable, widespread loss annually in terms of economic burden, morbidity, and mortality. With access to accurate and reliable forecasts of a current or upcoming influenza epidemic's behavior, policy makers can design and implement more effective countermeasures. This past year, the Centers for Disease Control and Prevention hosted the "Predict the Influenza Season Challenge", with the task of predicting key epidemiological measures for the 2013-2014 U.S. influenza season with the help of digital surveillance data. We developed a framework for in-season forecasts of epidemics using a semiparametric Empirical Bayes framework, and applied it to predict the weekly percentage of outpatient doctors visits for influenza-like illness, and the season onset, duration, peak time, and peak height, with and without using Google Flu Trends data. Previous work on epidemic modeling has focused on developing mechanistic models of disease behavior and applying time series tools to explain historical data. However, tailoring these models to certain types of surveillance data can be challenging, and overly complex models with many parameters can compromise forecasting ability. Our approach instead produces possibilities for the epidemic curve of the season of interest using modified versions of data from previous seasons, allowing for reasonable variations in the timing, pace, and intensity of the seasonal epidemics, as well as noise in observations. Since the framework does not make strict domain-specific assumptions, it can easily be applied to some other diseases with seasonal epidemics. This method produces a complete posterior distribution over epidemic curves, rather than, for example, solely point predictions of forecasting targets. We report prospective influenza-like-illness forecasts made for the 2013-2014 U.S. influenza season, and compare the framework's cross-validated prediction error on historical data to that of a variety of simpler baseline predictors.
Logan C. Brooks, David C. Farrow, Sangwon Hyun, Ryan J. Tibshirani, Ronald Rosenfeld
PLoS Comput. Biol.3
2008 Seluge: Secure and DoS-Resistant Code Dissemination in Wireless Sensor Networks
abstract
Wireless sensor networks are considered ideal candidates for a wide range of applications, such as industry monitoring, data acquisition in hazardous environments, and military operations. It is desirable and sometimes necessary to reprogram sensor nodes through wireless links after deployment, due to, for example, the need of removing bugs and adding new functionalities. The process of propagating a new code image to the nodes in a wireless sensor network is referred to as code dissemination. This paper presents the design, implementation, and evaluation of an efficient, secure, robust, and DoS-resistant code dissemination system named Seluge for wireless sensor networks. Seluge is a secure extension to Deluge, an open source, state-of-the-art code dissemination system for wireless sensor networks. It provides security protections for code dissemination, including the integrity protection of code images and immunity from, to the best of our knowledge, all DoS attacks that exploit code dissemination protocols. Seluge is superior to all previous attempts for secure code dissemination, and is the only solution that seamlessly integrates the security mechanisms and the Deluge efficient propagation strategies. Besides the theoretical analysis that demonstrates the security and performance of Seluge, this paper also reports the experimental evaluation of Seluge in a network of MicaZ motes, which shows the efficiency of Seluge in practice.
Sangwon Hyun, Peng Ning, An Liu 0001, Wenliang Du 0001
IPSN1