EDBT 2026 Demo / reviewers in the wild / expert
Eun-Sun Cho
dblp:83/142
· DBLP profile ↗
34ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-9406-3314ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 21 · 3 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 17 · 3 first-author · 5 since 2021Security and privacy · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Poster: Transformer-Based Detection of Code Obfuscation Techniques Using Opcode Sequences
Inwoo Jo, Wanju Kim, Eun-Sun Cho |
ICST | 3 |
| 2026 | Poster: Automated Generation of a Broad Spectrum of MBA Expressions for Robust Deobfuscation Analysis
Seoksu Lee, Sangjun An, Eunbi Cho, Eun-Sun Cho |
ICST | 4 |
| 2025 | An Enhanced Opaque Predicate Detection Method with Synthesis and Recursive MatchingabstractProgram obfuscation transforms source code into a complex, harder-to-analyze form while preserving functionality, commonly used for intellectual property protection and security. Although it is also exploited by malware developers. Opaque predicate obfuscation increases program size by inserting junk code with conditional expressions that prevent execution. Existing deobfuscation methods rely on symbolic execution and SMT solvers but face limitations based on predicate types. This paper proposes a logic-based deobfuscation technique capable of handling Mixed Boolean Arithmetic obfuscation and dynamic opaque predicates using I/O analysis, program synthesis, and recursive matching. Experimental results show that the proposed method outperforms existing tools against obfuscation by Code Virtualizer, Tigress, and OLLVM. Hyeongchang Jeon, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 3 |
| 2025 | Lightweight Classifier for Obfuscation Methods for IoT DevicesabstractIdentifying obfuscation techniques is essential for effective malware analysis and mitigation. Previous research has primarily focused on x86 architectures, but obfuscation techniques have become increasingly prevalent in IoT malware, particularly on ARM and MIPS architectures.This paper presents a method for identifying obfuscation techniques across different architectures. We first analyze and enhance an existing approach for x86 malware, improving its accuracy and efficiency. We then extend the method to IoT architectures, evaluating how architectural differences influence obfuscation patterns. Experimental results confirm that the proposed method effectively detects obfuscation techniques across multiple platforms, providing a foundation for more robust malware analysis in IoT environments. This research strengthens security measures by enabling more effective deobfuscation strategies against emerging threats. Wanju Kim, Youjeong Noh, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 4 |
| 2024 | Poster: E-Graphs and Equality Saturation for Term-Rewriting in MBA Deobfuscation: An Empirical StudyabstractObfuscation is a powerful software protection technique. It changes a program into a more complicated one while preserving its semantics. Malware distributors also employ this method, to protect their malware from being understood by malware analysts. Thus, it is crucial to deobfuscate malware in a timely manner, to enable a prompt action to malware. Seoksu Lee, Hyeongchang Jeon, Eun-Sun Cho |
CCS | 3 |
| 2024 | Dynamic Opaque Predicate Detection with a Recursive Matching MethodabstractAs program obfuscation techniques have improved, attackers have incorporated obfuscation into their malware and used it to thwart malware analysis. Opaque predicate is one of the widely used obfuscation methods to thwart code analysis, and we found that dynamic opaque predicate in particular cannot be deobfuscated with existing deobfuscators. This work proposes a dynamic opaque predicate detection technique based on recursive propagating of symbolic execution. Hyeongchang Jeon, Seoksu Lee, Eun-Sun Cho |
COMPSAC | 3 |
| 2024 | WeBMO: WebAssembly Memory Bitwise Operation ObfuscationabstractThe development of web browsers has made it possible for people to share information with each other. However, as the use of browsers increases and their uses become more diverse, vulnerabilities are increasingly being discovered and exploited to cause various types of damage, such as stealing personal information from an unspecified number of people or maliciously placing malicious code in the browser to infect computers. In particular, most attacks are related to memory vulnerabilities, and web browsers also use the memory of JavaScript and WebAssembly through the V8 engine, and WebAssembly is a recently introduced low-level byte code language, so there are various problems. Typically, WebAssembly uses linear memory to improve browser speed. However, problems such as stack-based buffer overflows, heap metadata corruption, and data overwriting have arisen. As a recently emerged language, not much research has been done on it. Accordingly, this paper proposes memory protection through WeBMO, which uses the Bitwise Memory Operation (BMO) obfuscation technique to address WebAssembly's memory problem by manipulating and merging memory bit by bit using bitwise operations. Obfuscation is a technique that makes code written in a programming language difficult to read. By applying this obfuscation to WebAssembly memory, we propose a WeBMO design that mitigates vulnerabilities and protects memory from attackers. Jeongpil Park, Eun-Sun Cho |
COMPSAC | 2 |
| 2023 | Assessing Opaque Predicates: Unveiling the Efficacy of Popular Obfuscators with a Rapid DeobfuscatorabstractProgram obfuscation protects a program's intellectual property rights and vulnerabilities by making it unreadable and hardening program analysis. However, obfuscation typically adds size and complexity to programs, resulting in performance overhead. Fortunately. opaque predicates, which are the conditional expressions always evaluated to be true or always false, reduce the overhead by ensuring that the inserted dummy code is never executed. Furthermore, when combined with other forms of obfuscation such as MBA obfuscation, opaque predicates have been found to efficiently defeat existing SMT-based analysis methods. However, new program analysis techniques have recently emerging that can simplify more obfuscation, which suggests that opaque predicate-based obfuscation may no longer be robust enough. In this paper, we introduce a novel opaque predicate classification, taking into account robustness against various deobfuscation techniques. According to this proposed classification, we assess real-world obfuscation results produced by popular obfuscation tools. Hyeonachang Jeon, Seoyeon Kang, Seoksu Lee, Eun-Sun Cho |
APSEC | 4 |
| 2022 | Stone: A Privacy Policy Enforcement System for Smart ContractsabstractSmart contracts running on blockchain potentially disclose all data to the participants of the chain. Therefore, because privacy is important in many areas, smart contracts may not be considered a good option. To overcome this limitation, this paper introduces Stone, a privacy preservation system for smart contracts. With Stone, an arbitrary Solidity smart contract can be combined with a separate privacy policy in JSON, which prevents the storage data in the contract from being publicised. Because this approach is convenient for policy developers as well as smart contract programmers, we envision that this approach will be practically acceptable for real-world applications. Jihyeon Kim, Dae-hyeon Jeong, Eun-Sun Cho |
SANER | 4 |
| 2022 | Malware classification using a byte-granularity feature based on structural entropyabstractAbstract Rapidly evolving malware has become a major cybersecurity threat. Several feature‐engineering techniques have been proposed to defend against malware attacks. An entropy is a typical indicator used in identifying malware. Structural entropy is a sequence of entropy values where an entropy of a segment is calculated by the equation of the entropy itself. However, entropy‐based features are likely to be abstract and miss important information. This article proposes a feature engineering technique that involves the concept of structural entropy. This technique allows every segment to be represented as 256 entropy values for every byte value, but not as an entropy value. Our research, fine‐granularity structural entropy (FiG_SE), incorporates global patterns across all segments, local patterns across adjacent segments, and internal patterns within the segments. To extract higher‐level characteristics from our entropy feature, we use a convolutional neural network (CNN) architecture because it is effective for extracting local and global patterns, and especially for shift‐invariant patterns. Our malware classification based on CNN with the proposed feature outperforms the previous classification methods that use byte streams, entropy streams, and structural‐entropy‐based streams as inputs. Moreover, our research combined with CNN is highly resilient to obfuscation techniques and is also well suited to malware detection. Joon-Young Paik, Rize Jin, Eun-Sun Cho |
Comput. Intell. | 3 |
| 2022 | Byte Frequency Based Indicators for Crypto-Ransomware Detection from Empirical Analysis
GeunYong Kim, Joon-Young Paik, Yeong-Cheol Kim, Eun-Sun Cho |
J. Comput. Sci. Technol. | 4 |
| 2021 | OBFUS: An Obfuscation Tool for Software Copyright and Vulnerability ProtectionabstractIn this paper, we propose OBFUS, a web-based tool that can easily apply obfuscation techniques to high-level and low-level programming languages. OBFUS's high-level obfuscator parses and obfuscates the source code, overlaying the obfuscation to produce more complex results. OBFUS's low-level obfuscator decompiles binary programs into LLVM IR. This LLVM IR pro-gram is obfuscated and the LLVM IR program is recompiled to become an obfuscated binary program. Seoyeon Kang, Sujeong Lee, Yumin Kim, Seong-Kyun Mok, Eun-Sun Cho |
CODASPY | 5 |
| 2021 | Lightweight extension of an execution environment for safer function calls in Solidity/Ethereum Virtual Machine smart contractsabstractSolidity, a programming language used to write smart contracts, has been improved since its initial release, but a number of vulnerabilities remain. As smart contracts are usually related to cryptocurrency, these vulnerabilities should be avoided to prevent the risk of financial loss. In this paper, we classify common vulnerabilities of function calls of Solidity programs into three groups and suggest a method to avoid them. The proposed method makes use of Ethereum Virtual Machine as well as Solidity extension. Experimental results with real-world smart contracts show that our method will detect and avoid these vulnerabilities. Sooyeon Lee, Eun-Sun Cho |
SANER | 2 |
| 2019 | Efficient SVM Based Packer Identification with Binary Diffing MeasuresabstractPacker identification is an essential process followed by further investigation on malware. For efficient packer identification, we introduce an SVM based automatized method, which uses kernel lifting with binary diffing measures for RBF kernels. According to the experimental results, we found that LCS, n-gram and other binary diffing measure serve kernels with better performance in packer identification than previous works, which has used traditional kernels or no kernel-lifting at all. In addition, Edit distance-based RBF kernels in previous works (e.g., [6]) do not show satisfying results compared to other binary diffing measure-based kernels. Yeong-Cheol Kim, Joon-Young Paik, Seokwoo Choi, Eun-Sun Cho |
COMPSAC (1) | 4 |
| 2019 | A Modified Smart Contract Execution Enviroment for Safe Function CallsabstractWhen a Solidity smart contract has a problem in calling a function of another contract, the "fallback function" of the contract is supposed to be executed automatically. However, in many cases, a fallback function is arbitrarily created and called, with their behaviors unknown to developers, so that its execution is vulnerable to exploits by attackers. To reduce these risks, this paper proposes a method that provides developers with new keywords by modifying existing Solidity compiler and Ethereum Virtual Machine (EVM). Developers mark their intention using the newly introduced keywords, and the modified existing Solidity compiler and EVM uses flags and conditional statements to prevent calls of fallback functions to reduce the risk of calls to fallback functions. Sooyeon Lee, Eun-Sun Cho |
COMPSAC (1) | 2 |
| 2019 | Toward Machine Learning Based Analyses on Compressed FirmwareabstractAs Internet of Things (IoT) applications are getting attention these days, the importance of firmware security is also growing. However, it is not straightforward to analyze the bugs or vulnerabilities that reside in firmware. One of the major challenges is to detect information about hardware architectures of compressed firmware. Traditional analysis tools make use of static signatures embedded in the compressed binary code of firmware. However, signature extraction needs the careful elaboration of experts, and it is not always even possible. In this paper, we introduce our experience in analyzing the hardware information of compressed firmware. Since it is not possible to use the semantic information of compressed binary code, we adopt machine learning technologies for this purpose. Despite various difficulties, we have positive experimental results. Seoksu Lee, Joon-Young Paik, Rize Jin, Eun-Sun Cho |
COMPSAC (2) | 4 |
| 2019 | Outlier Detection for Ship Trajectory PredictionabstractThe ACM International Conference on Distributed and Eventbased Systems (ACM DEBS) Grand Challenge is aiming to build faster and more accurate distributed and event based systems. In 2018, the goal of the Grand Challenge was to make predictions for vessels' destinations and arrival times. In our previous work [3], as a participant of the Grand Challenge, we adopted a grid-based Bayesian inference model to yield a decent result. However, we found that a number of serious outliers in the real-world data may adversely affect predictions. This paper introduces our attempts to enhance the performance of the previous model for predicting the destination and arrival time of a vessel issued by ACM DEBS GC 2018, by proposing an outlier detection method based on clustering and refning training data. Hyungkun Jung, Kang-Woo Lee, Eun-Sun Cho |
MobiSys | 3 |
| 2018 | A Storage-level Detection Mechanism against Crypto-RansomwareabstractRansomware represents a significant threat to both individuals and organizations. Moreover, the emergence of ransomware that exploits kernel vulnerabilities poses a serious detection challenge. In this paper, we propose a novel ransomware detection mechanism at a storage device, especially a flash-based storage device. To this end, we design a new buffer management policy that allows our detector to identify ransomware behaviors. Our mechanism detects a realistic ransomware sample with little negative impacts on the hit ratios of the buffers internally located in a storage device. Joon-Young Paik, Joong-Hyun Choi, Rize Jin, Eun-Sun Cho |
CCS | 5 |
| 2018 | Toward Firmware-Type Analysis Using Machine Learning TechniquesabstractDue to the development of the Internet, a considerable amount of firmware that operates on various types of hardware has been developed. The process of analyzing firmware according to these developments has also been important. Among the various tools for analyzing firmware, the tool for analyzing firmware types is important as the first step of the process of analyzing firmware. This paper introduces a signature-based firmware analysis approach of the type mainly used at present and proposes a new idea for analyzing firmware types based on machine learning. Seoksu Lee, Eun-Sun Cho |
COMPSAC (1) | 2 |
| 2018 | Building a CFG to Include ExceptionsabstractA control flow graph (CFG) is essential for binary program analysis. However, exceptions, which are part of a program, have not been previously considered when building a CFG. Recent work has suggested how to make a CFG with exceptions through symbolic execution. This method extracts the instruction that generates the exception, then creates the input that causes the exception through symbolic execution, and links the handling function. However, this method involves too much overhead because it requires consideration of the candidate instruction and each program path. Therefore, we propose an improved method of reducing overhead through abstract interpretation. Our proposed method can reduce the overhead of symbolic execution by identifying the range of the operand value of the instruction and further reducing candidate instructions. Seong-Kyun Mok, Eun-Sun Cho |
COMPSAC (1) | 2 |
| 2018 | Message from the SEPT Symposium Program ChairsabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Dianxiang Xu, Eun-Sun Cho |
COMPSAC (1) | 2 |
| 2017 | Automated Crash Filtering Using Interprocedural Static Analysis for Binary CodesabstractThis paper introduces a static binary analysis tool called CrashFilter, which classifies the crashes arisen during the test, according to the risk levels. It has advantages in accuracy and provides wider coverage of analysis, due to newly introduced analyses-Memory Location Analysis and Inter-Procedure Analysis. Hyeon-Gu Jeon, Seong-Kyun Mok, Eun-Sun Cho |
COMPSAC (1) | 3 |
| 2017 | Dynamic Allocation Mechanism to Reduce Read Latency in Collaboration With a Device Queue in Multichannel Solid-State DevicesabstractIn this paper, we focus on read operations in flash memory, which have received less attention than write operations. To reduce read latency, we propose a read-aware dynamic allocation mechanism for multichannel solid-state devices. The proposed mechanism enables read operations to be executed immediately by reserving the resources of channels, packages, and dies dedicated to read operations. This is done in collaboration with an internal device queue, in which write operations are freely routed to their proper addresses while maintaining the merits of a dynamic allocation mechanism. Our read-aware mechanism reduces read latency by avoiding read operation conflicts when trying to access resources already occupied by preissued write operations. The experimental results show that, with our proposed mechanism, read latency decreases by up to 32.5% with an increase of write latency of up to 6.8% in real traces while providing high compatibility with existing dynamic allocation schemes. Joon-Young Paik, Tae-Sun Chung, Eun-Sun Cho |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2015 | Automated Crash Filtering for ARM Binary ProgramsabstractThis paper aims to help to differentiate security related crashes from benign vulnerabilities, using static taint-analysis. To achieve this goal, we propose a tool named Crash Filter, which determines if a crash can be made to be exploitable or not, by analyzing ARM binary codes. We envision that the proposed analysis would help to timely fix security-critical bugs. Ki-Jin Eom, Joon-Young Paik, Seong-Kyun Mok, Hyeon-Gu Jeon, Eun-Sun Cho, Jaecheol Ryu |
COMPSAC | 5 |
| 2014 | An Efficient Static Taint-Analysis Detecting Exploitable-Points on ARM BinariesabstractThis paper aims to differentiate benign vulnerabilities from those used by cyber-attacks, based on STA (Static TaintAnalysis.) To achieve this goal, the proposed STA determines if a crash is from severe vulnerabilities, after analyzing related exploitable-points in ARM binaries. We envision that the proposed analysis would reduce the complexity of analysis, by making use of CPA (Constant Propagation Analysis) and runtime information of crash points. Ki-Jin Eom, Choong-Hyun Choi, Joon-Young Paik, Eun-Sun Cho |
SRDS | 4 |
| 2012 | An Intermediate Language for Semantic Exceptions in Context-Aware SystemsabstractSemantic exceptions mean undesirable contexts with respect to application semantics in context aware systems. Description of such semantic exceptions is based on regular expressions, which entails high complexity to detect exceptions. In this paper we devise an intermediate language for semantic exceptions of context aware applications. By bridging the gap between high level programming languages and event stream processing engines, this language is expected to mitigate the complexity and to provide opportunities to optimize exception detection process. Eun-Sun Cho, Abdelsalam Helal |
COMPSAC | 1 |
| 2011 | Profiling-Based Log Block Replacement Scheme in FTL for Update-Intensive ExecutionsabstractFTL (Flash Translation Layer) hides details of flash memory, providing file systems with an abstract view of the flash memory. For NAND flash memory, some previous researches have achieved dramatic performance enhancement by adopting log-based FTL, which records time-consuming write operations in log blocks, rather than executes them immediately. Log block replacement scheme plays an essential role in this method, due to the limitation of pre-reserved log block space, this method entails selecting some victims from the existing blocks and re-use them for newly issued operations. However, simple replacement algorithms are vulnerable to select such log blocks that will be used soon, which causes performance degradation. In this paper we propose a smarter log block replacement scheme to alleviate this problem by keeping busy log blocks from being selected, based on profiling and analyzing log block status. We show that our scheme reduces unnecessary time-consuming write operations and achieves performance improvement especially for the applications having intensive locality. Joon-Young Paik, Tae-Sun Chung, Eun-Sun Cho |
EUC | 3 |
| 2011 | Future robotic computer: a new type of computing device with robotic functionsabstractWith the advance of IT technologies, a new type of computing device will be introduced in our daily life in the near future. In this paper, we outline our on-going development of the robotic computer that naturally interacts with users, understands current situation about users and environments, and proactively provides users with services. We describe the system architecture and the implementation of a proof-of-concept prototype of the robotic computer proposed. Young-Ho Suh, Joo-Haeng Lee, Joonmyun Cho, Moohun Lee, Jeongnam Yeom, Eun-Sun Cho |
HRI | 7 |
| 2005 | Preventing Illegal Usage of Mobile Phone SoftwareabstractTraditional white and black box testing methods are effective in revealing many kinds of defects, but the more elusive bugs slip past them. Model-based testing incorporates additional application concepts in the selection of tests, which may provide more refined bug detection, but does not go far enough. Test selection patterns identify defect-oriented contexts in a program. They also identify suggested tests for risks associated with a specified context. A context and its risks is a kind of conceptual trap designed to corner a bug. The suggested tests will find the bug if it has been caught in the trap. Yun-Sam Kim, Eun-Sun Cho |
COMPSAC (2) | 2 |
| 2001 | SKETHIC: Secure Kernel Extension against Trojan Horses with Information-Carrying Codes
Eun-Sun Cho, Sunho Hong, Hongjin Yeh, Cheol Won Lee, Hyundong Park, Chun-Sik Park |
ACISP | 1 |
| 2000 | Interface/implementation Separation Mechanism for Integrating Object-oriented Management Systems and General-purpose Programming LanguagesabstractWhen a database is shared in different database applications, it is helpful for data-independence and program readability to screen off the implementation details of a schema class from the programs other than the method implementation code. This makes some systems allow their users to define the schema class in two parts—the interface and the implementation. In this paper, we propose a preprocessing-based approach with the object model for OODBPLs (object oriented database programming languages) with interface/implementation separation. Eun-Sun Cho |
Comput. J. | 1 |
| 2000 | LOD*: A C++ extension for OODBMSs with orthogonal persistence to class hierarchies
Eun-Sun Cho |
Inf. Softw. Technol. | 1 |
| 1997 | A New Data Abstraction Layer Required For OODBMS abstractA 'class' in the object-oriented paradigm represents both interface and implementation of the class. However, interface and implementation of a class are needed for different purposes, since class interface is shared among most users, while class implementation is used only by the implementers of the class. The authors introduce a new level of data abstraction, called the 'class-implementation level', which is based on separate management of interface and implementation of a class. They also describe a new model for OODBMS which provides users with the abstract view of the class implementation. Eun-Sun Cho, Sang-Yong Han, Hyoung-Joo Kim 0001 |
IDEAS | 1 |
| 1996 | A Semantics of the Separation of Interface and Implementation in C++abstractC++ uses 'class' as the basis of 'subtype polymorphism' and 'inheritance', but it has been pointed out that the overloading of 'class' limits the expressiveness and makes its type system inflexible. This means that C++ and some other object oriented languages had to separate a class into two modules-an interface and an implementation. But, there seems to be no leading C++ model for separating the interface lattice from the implementation lattice. Moreover none of the proposed models describe the result of the separation in a formal way. As a result it is hard to understand what the type space would be like after the separation. The paper presents a formal model for the separation of interface and implementation in C++, and which explains the properties of the resulting type space after the separation. Eun-Sun Cho, Sang-Yong Han, Hyoung-Joo Kim 0001 |
COMPSAC | 1 |