Donghyun Kwon

Donghyun Kwon권동현

Associate Professor · Director, Computer Security Lab

School of Computer Science and Engineering
Pusan National University, Busan, South Korea

Office
Room 718, IT Building (Bldg. 102)
Email

Research

I work on system security. My research builds defenses that make low-level software memory-safe and properly isolated, usually by co-designing compilers and runtimes with the hardware features already present in commodity processors — ARM TrustZone and TrustZone-M, memory tagging, memory domains and protection keys, and custom RISC-V ISA extensions.

Recent work targets resource-constrained embedded and IoT devices, WebAssembly runtimes, and robotics middleware, where conventional protections are too expensive to apply directly.

Memory safety · Control-flow integrity · In-process isolation · Trusted execution environments · Embedded and IoT security · WebAssembly · RISC-V · Kernel protection

Openings

I am looking for motivated graduate and undergraduate students who want to work on system security. If you enjoy operating systems, compilers, or computer architecture and want to break and then fix real systems, please get in touch by email. Details are on the lab page.

Publications

* corresponding author  ·  ** joint first authors

2026
  1. Mind the Gap: In-Process Isolation for Safe Rust in WebAssembly Suhyeon Song, Chaewon Shin, and Donghyun Kwon* ESORICS — European Symposium on Research in Computer Security, 2026
  2. XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-M Yunju Gu, Jaeyeol Park, and Donghyun Kwon* USENIX Security Symposium, 2026 PDFCode
  3. TzPy: Python Runtime for Edge Code Deployment on TrustZone Suhyeon Song, Jaeyeol Park, Chaewon Shin, and Donghyun Kwon* ACM Transactions on Embedded Computing Systems (TECS), 2026 PDF
  4. SERA: Secure Micro XRCE-DDS Establishment with Remote Attestation for micro-ROS Jeonghwan Kang, Seungmin Kang, Euijun Kim, Jaeseon Park, Kyounghwan Kim, and Donghyun Kwon* IEEE Access, 2026 PDF
  5. WARD: Efficient Memory Protection for WebAssembly on Tiny Embedded Systems Chaewon Shin, Gowon Han, Suhyeon Song, Jinsun Park, Yoon-ho Choi, and Donghyun Kwon* IEEE Access, 2026 PDF
  6. Beyond Address Spaces: In-process Memory Isolation for RISC-V Seonghwan Park, Hayoung Kang, and Donghyun Kwon* Computers & Security, 2026 PDF
2025
  1. SMORE: Practical Redzone-Based Stack Memory Error Detection Mechanism for Embedded Systems Jaeyeol Park, Yunju Gu, and Donghyun Kwon* ACSAC — Annual Computer Security Applications Conference, 2025 PDFCode
  2. ELK: Effective Lock-and-Key Technique for Temporal Memory Safety on Embedded Devices in ARMv8-M Jeonghwan Kang, Kyounghwan Kim, and Donghyun Kwon* ACSAC — Annual Computer Security Applications Conference, 2025 PDFCode
  3. Watch Your Callback: Offline Anomaly Detection using Machine Learning in ROS 2 Jeonghwan Kang, Kyounghwan Kim, and Donghyun Kwon* IEEE Access, 2025 PDF
  4. WasDom: An Efficient Write Protection for Wasm JITed Code With ARM Domain Suhyeon Song, Chaewon Shin, and Donghyun Kwon* IEEE Access, 2025 PDF
  5. ROSec: Intra-Process Isolation for ROS Composition with Memory Protection Keys Jiwon Seo, Kayondo Martin, Jeonghwan Kang, Donghyun Kwon*, and Yunheung Paek* IEEE Transactions on Automation Science and Engineering (T-ASE), 2025 PDF
2024
  1. Look Before You Access: Efficient Heap Memory Safety for Embedded Systems on ARMv8-M Jeonghwan Kang, Jaeyeol Park, Jiwon Seo, and Donghyun Kwon* DAC — Design Automation Conference, 2024 PDF
  2. MECAT: Memory-Safe Smart Contracts in ARM TrustZone Seonghwan Park, Hayoung Kang, Sanghun Han, Jonghee M. Youn*, and Donghyun Kwon* IEEE Access, 2024 PDF
  3. Non-volatile flip-flop with soft error tolerant capability using DICE and C-element Shogo Takahashi, Donghyun Kwon, and Kazuteru Namba* IEICE Nonlinear Theory and Its Applications (NOLTA), 2024 PDF
Earlier publications · 2013 — 2023 · 27 papers
2023
  1. SFITAG: Efficient Software Fault Isolation with Memory Tagging for ARM Kernel Extensions Jiwon Seo, Junseung You, Yungi Cho, Yeongpil Cho, Donghyun Kwon*, and Yunheung Paek* ACM ASIACCS — ACM ASIA Conference on Computer and Communications Security, 2023 PDF
  2. ZOMETAG: Zone-based Memory Tagging for Fast, Deterministic Detection of Spatial Memory Violations on ARM Jiwon Seo, Junseung You, Donghyun Kwon, Yeongpil Cho*, and Yunheung Paek* IEEE Transactions on Information Forensics and Security (TIFS), 2023 PDF
  3. Enhancing a Lock-and-key Scheme with MTE to Mitigate Use-After-Frees Inyoung Bang, Martin Kayondo, Junseung Yu, Donghyun Kwon, Yeongpil Cho*, and Yunheung Paek* IEEE Access, 2023 PDF
  4. metaSafer: A Technique to Detect Heap Metadata Corruption in WebAssembly Suhyeon Song, Seonghwan Park, and Donghyun Kwon* IEEE Access, 2023 PDF
  5. DEMIX: Domain-Enforced Memory Isolation for Embedded System Haeyoung Kim, Harashta Tatimma Larasati, Jonguk Park, Howon Kim, and Donghyun Kwon* Sensors, 2023 PDF
2022
  1. Efficient CFI Enforcement for Embedded Systems Using ARM TrustZone-M Gisu Yeo, Yeryeong Kim, Suhyeon Song, and Donghyun Kwon* IEEE Access, 2022 PDF
  2. Exploring Effective Uses of the Tagged Memory for Reducing Bounds Checking Overheads Jiwon Seo, Inyoung Bang, Yungi Cho, Jangseop Shin, Dongil Hwang, Donghyun Kwon, Yeongpil Cho, and Yunheung Paek The Journal of Supercomputing, 2022 PDF
  3. Bratter: An Instruction Set Extension for Forward Control-Flow Integrity in RISC-V Seonghwan Park, Dongwook Kang, Jeonghwan Kang, and Donghyun Kwon* Sensors, 2022 PDF
2021
  1. CoMeT: Configurable Tagged Memory Extension Jinjae Lee, Derry Pratama, Minjae Kim, Howon Kim, and Donghyun Kwon* Sensors, 2021 PDF
  2. A Hardware Platform for Ensuring OS Kernel Integrity on RISC-V Donghyun Kwon, Dongil Hwang, and Yunheung Paek Electronics, 2021 PDF
2020
  1. RIMI: Instruction-level Memory Isolation for Embedded Systems on RISC-V Haeyoung Kim, Jinjae Lee, Derry Pratama, Asep Muhamad Awaludin, Howon Kim, and Donghyun Kwon* ICCAD — International Conference on Computer-Aided Design, 2020 PDF
  2. PrOS: Light-weight Privatized Secure OSes in ARM TrustZone Donghyun Kwon, Jiwon Seo, Yeongpil Cho, Byoungyoung Lee, and Yunheung Paek IEEE Transactions on Mobile Computing (TMC), 2020 PDF
2019
  1. uXOM: Efficient eXecute-Only Memory on ARM Cortex-M Donghyun Kwon, Jangseop Shin, Giyeol Kim, Byoungyoung Lee, Yeongpil Cho, and Yunheung Paek USENIX Security Symposium, 2019 PDF
  2. CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-After-Free in Legacy C/C++ Jangseop Shin, Donghyun Kwon, Jiwon Seo, Yeongpil Cho, and Yunheung Paek NDSS — Network and Distributed System Security Symposium, 2019 PDF
  3. RiskiM: Toward Complete Kernel Protection with Hardware Support Dongil Hwang, Myunghoon Yang, Seongil Jeon, Younghan Lee, Donghyun Kwon*, and Yunheung Paek DATE — Design, Automation and Test in Europe, 2019 PDF
  4. Safe and Efficient Implementation of a Security System on ARM using Intra-Level Privilege Separation Donghyun Kwon, Hayoon Yi, Yeongpil Cho, and Yunheung Paek ACM Transactions on Privacy and Security (TOPS), 2019 PDF
2018
  1. Hypernel: A Hardware-Assisted Framework for Kernel Protection without Nested Paging Donghyun Kwon**, Kuenwhee Oh**, Junmo Park, Seungyong Yang, Yeongpil Cho, Brent Byunghoon Kang, and Yunheung Paek DAC — Design Automation Conference, 2018 PDF
  2. VM-CFI: Control-Flow Integrity for Virtual Machine Kernel Using Intel PT Donghyun Kwon, Jiwon Seo, Sehyun Baek, Giyeol Kim, Sunwoo Ahn, and Yunheung Paek ICCSA — International Conference on Computational Science and Its Applications, 2018
2017
  1. Instruction-Level Data Isolation for the Kernel on ARM Yeongpil Cho, Donghyun Kwon, and Yunheung Paek DAC — Design Automation Conference, 2017 PDF
  2. Dynamic Virtual Address Range Adjustment for Intra-Level Privilege Separation on ARM Yeongpil Cho, Donghyun Kwon, Hayoon Yi, and Yunheung Paek NDSS — Network and Distributed System Security Symposium, 2017 PDF
  3. Optimization Techniques to Enable Execution Offloading for 3D Video Games Donghyun Kwon, Seungjun Yang, Yunheung Paek, and Kwangman Ko Multimedia Tools and Applications (MTAP), 2017 PDF
2016
  1. Hardware-Assisted On-Demand Hypervisor Activation for Efficient Security Critical Code Execution on Mobile Devices Yeongpil Cho, Jun-Bum Shin, Donghyun Kwon, MyungJoo Ham, Yuna Kim, and Yunheung Paek USENIX ATC — USENIX Annual Technical Conference, 2016 PDF
  2. Precise Execution Offloading for Applications with Dynamic Behavior in Mobile Cloud Computing Yongin Kwon, Hayoon Yi, Donghyun Kwon, Seungjun Yang, Yeongpil Cho, and Yunheung Paek Pervasive and Mobile Computing (PMC), 2016 PDF
2015
  1. Mantis: Efficient Predictions of Execution Time, Energy Usage, Memory Usage and Network Usage on Smart Mobile Devices Yongin Kwon, Sangmin Lee, Hayoon Yi, Donghyun Kwon, Seungjun Yang, Byung-gon Chun, Ling Huang, Petros Maniatis, Mayur Naik, and Yunheung Paek IEEE Transactions on Mobile Computing (TMC), 2015 PDF
2014
  1. Techniques to Minimize State Transfer Costs for Dynamic Execution Offloading in Mobile Cloud Computing Seungjun Yang, Donghyun Kwon, Hayoon Yi, Yeongpil Cho, Yongin Kwon, and Yunheung Paek IEEE Transactions on Mobile Computing (TMC), 2014 PDF
2013
  1. Mantis: Automatic Performance Prediction for Smartphone Applications Yongin Kwon, Sangmin Lee, Hayoon Yi, Donghyun Kwon, Seungjun Yang, Byung-Gon Chun, Ling Huang, Petros Maniatis, Mayur Naik, and Yunheung Paek USENIX ATC — USENIX Annual Technical Conference, 2013 PDF
  2. Fast Dynamic Execution Offloading for Efficient Mobile Cloud Computing Seungjun Yang, Yongin Kwon, Yeongpil Cho, Hayoon Yi, Donghyun Kwon, Jonghee Youn, and Yunheung Paek PerCom — IEEE International Conference on Pervasive Computing and Communications, 2013 PDF

Teaching

Graduate

Undergraduate