Publications
* equal contributions
2026
-
How Developers Respond to Insecure AI Code Suggestions under Poisoning Attacks: An Empirical Study of Interface-Level Countermeasures.
Sanghak Oh, Eun Jung, Sangjun Chae, and Hyoungshick Kim.
IEEE TSE IEEE Transactions on Software Engineering
PDF -
KARMA: Lightweight Anomaly Detection for Industrial Control Systems via Knowledge Distillation.
Bedeuro Kim, Sanghak Oh, and Hyoungshick Kim.
IEEE TDSC IEEE Transactions on Dependable and Secure Computing
PDF -
CCA-Droid: Context-Aware Cryptographic API Misuse Detection in Android Apps.
Minwook Lee, Eunsoo Kim, Sanghak Oh, Joonsang Baek, Willy Susilo, and Hyoungshick Kim.
ASIACCS ‘26 The 21st ACM ASIA Conference on Computer and Communications Security
PDF -
PP-Vul: Privacy-Preserving Vulnerability Detection Using Homomorphic Encryption.
Seungho Kim, Seonhye Park, Jihun Kim, Eunsoo Kim, Sanghak Oh, Hyunmin Choi, and Hyoungshick Kim.
ASIACCS ‘26 The 21st ACM ASIA Conference on Computer and Communications Security
PDF
2025
-
When Does Wasm Malware Detection Fail? A Systematic Analysis of Their Robustness to Evasion.
Taeyoung Kim, Sanghak Oh, Kiho Lee, Weihang Wang, Yonghwi Kwon, Sanghyun Hong, and Hyoungshick Kim.
ASE ‘25 The 40th IEEE/ACM International Conference on Automated Software Engineering
PDF -
Windows plays Jenga: Uncovering Design Weaknesses in Windows File System Security.
Dong-uk Kim*, Junyoung Park*, Sanghak Oh, Hyoungshick Kim, and Insu Yun.
CCS ‘25 The 32nd ACM Conference on Computer and Communications Security
PDF -
Insecure Coding Habits Die Hard. Can PEFT Really Turn LLMs into Secure Coders?
Sangjun Chae, Jangseop Choi, Taeyang Kim, Eun Jung, Sanghak Oh, and Hyoungshick Kim.
CCS ‘25 (Poster) The 32nd ACM Conference on Computer and Communications Security
PDF -
Understanding and Improving User Adoption and Security Awareness in Password Checkup Services.
Sanghak Oh, Heewon Baek, Jun Ho Huh, Taeyoung Kim, Woojin Jeon, Ian Oakley, and Hyoungshick Kim.
CHI ‘25 The 43rd ACM SIGCHI Conference on Human Factors in Computing Systems
PDF
2024
- Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers’ Coding Practices with Insecure Suggestions from Poisoned AI Models.
Sanghak Oh*, Kiho Lee*, Seonhye Park, Doowon Kim, and Hyoungshick Kim.
S&P ‘24 The 45th IEEE Symposium on Security and Privacy
PDF News
2023
-
AppSniffer: Towards Robust Mobile App Fingerprinting Against VPN.
Sanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino, and Hyoungshick Kim.
TheWebConf ‘23 The 32nd ACM Web Conference (formerly WWW)
PDF -
A Comparative Study of Time Series Anomaly Detection Models for Industrial Control Systems.
Bedeuro Kim, Mohsen Ali Alawami, Eunsoo Kim, Sanghak Oh, Jeongyong Park, and Hyoungshick Kim.
Sensors
PDF
2022
- Adversarial Perturbation Attacks on the State-of-the-Art Cryptojacking Detection System in IoT Networks.
Kiho Lee, Sanghak Oh, and Hyoungshick Kim.
CCS ‘22 (Poster) The 29th ACM Conference on Computer and Communications Security
PDF
2017
-
Wrong Siren! A Location Spoofing Attack on Indoor Positioning Systems: The Starbucks Case Study.
Junsung Cho, Jaegwan Yu, Sanghak Oh, Jungwoo Ryoo, Jaeseung Song, and Hyoungshick Kim.
IEEE ComMag IEEE Communications Magazine
PDF -
A Flexible Architecture for Orchestrating Network Security Functions to Support High-Level Security Policies.
Sanghak Oh, Eunsoo Kim, Jaehoon Jeong, Hoon Ko, and Hyoungshick Kim.
IMCOM ‘17 The 11th ACM International Conference on Ubiquitous Information Management and Communication
PDF
2016
- Empirical Analysis of SSL/TLS Weaknesses in Real Websites: Who Cares?
Sanghak Oh, Eunsoo Kim, and Hyoungshick Kim.
WISA ‘16 The 17th World Conference on Information Security Applications
PDF