숙명여자대학교 소프트웨어학부 · 2026년 9월 개설Division of Software · est. September 2026
우리는 AI의 머릿속 구조를
뚫고, 지킵니다.
We break and defend the structure inside an AI.
얼굴·음성 인식과 생성형 AI가 무엇을 흘리고, 어떻게 지킬 수 있는지. 공격과 방어를 함께 다루는 새 연구실입니다. 석사·박사 과정 학생을 모집합니다. What face and speaker recognizers and generative models leak, and how to defend them. A new lab working on both attack and defense. Master's and Ph.D. students are welcome.
우리 연구가 발표된 곳 · 올려 보면 무엇을 했는지 보입니다Where our work appears · hover to see what each paper did
- IEEE S&PScores Tell Everything about Bob인식기가 돌려준 점수만으로, 경사하강법 없이 얼굴을 복원합니다.Reconstructs a face from the recognizer's scores alone, no gradients.
- ACM CCSCasting the Net!얼굴 하나로 수많은 사람을 동시에 사칭하는 MasterFace 공격을 다시 봅니다.Revisits MasterFace: one face that impersonates many people at once.
- NeurIPSNon-Adaptive Adversarial Face Generation질문을 미리 다 정해 두고, 노이즈 없는 자연스러운 사칭 이미지를 만듭니다.All queries fixed up front; produces natural, perturbation-free impersonation images.
- ICCVIDFace암호화된 얼굴 템플릿을 복호화 없이 수백만 명 규모로 검색합니다.Searches millions of encrypted face templates without ever decrypting them.
- ECCVTowards Certifiably Robust Face Recognition"이 반지름 안의 어떤 공격도 판단을 못 바꾼다"를 인식 모델에 대해 증명합니다.Proves that no attack within a radius can flip a recognizer's decision.
- CVPRIronMask얼굴 템플릿을 되돌릴 수 없게 감싸는 모듈형 보호 구조입니다.A modular architecture that wraps face templates so they cannot be inverted.
- BMVCSecurity Analysis on LSH-based Template Protection해시 기반 보호 기법이 실제로는 되돌려질 수 있음을 보였습니다. Oral.Shows that hash-based protections can in fact be reversed. Oral.
- IEEE TDSCOn the Reversibility of LSH-based Protections어떤 변환이 정말 되돌릴 수 없는지에 대한 통합된 분석입니다.A unified account of which transformations are truly irreversible.
- Pattern RecognitionDeep Face Template Protection in the Wild실제 배포 조건에서 동작하는 얼굴 템플릿 보호입니다.Face template protection that holds up under real deployment conditions.
연구 주제Research
하나의 질문에서 다섯 갈래로. One question, five threads.
현대의 인식 모델은 입력을 고차원 공간의 점으로 바꿉니다. 그 점들이 어떻게 놓여 있는지가 공격자가 무엇을 얻을 수 있고 방어자가 무엇을 숨길 수 있는지를 결정합니다. 우리는 이 구조를 연구의 중심에 둡니다. Modern recognizers turn inputs into points in a high-dimensional space. How those points are arranged governs what an attacker can extract and what a defender can hide. We put that structure at the center.
공격Attack
인식 시스템이 돌려주는 점수만으로 얼굴을 복원하거나 다른 사람을 사칭할 수 있을까요? 경사하강법 없이, 질문을 미리 다 정해 두는 공격으로 상용 API까지 뚫었습니다. Can the scores a recognizer returns be enough to reconstruct a face or impersonate someone? Without gradient descent, with every query fixed up front, our attacks break commercial APIs.
02보호Protect
비밀번호는 바꿀 수 있지만 얼굴은 바꿀 수 없습니다. 오차가 있는 생체 정보를 비밀키 없이 안전하게 저장하고 검색하는 방법을 오류정정부호와 동형암호로 만듭니다. You can change a password, not your face. We build ways to store and search noisy biometrics without a secret key, using error-correcting codes and homomorphic encryption.
03보증Certify
"지금 알려진 공격은 막는다"가 아니라 "이 범위 안의 어떤 공격도 못 뚫는다"를 수학적으로 증명합니다. 분류가 아닌 인식 문제에 맞게 증명 도구를 다시 짭니다. Not "we resist known attacks" but "no perturbation within this radius can flip the decision", proven. We rebuild certification tools for recognition rather than classification.
04탐지Detect
딥페이크 탐지기와 vision-language 모델도 인식기와 같은 구조 위에 있습니다. 픽셀을 건드리지 않고 프롬프트만으로 탐지기를 속이는 방법과, 그것을 막는 방법을 함께 봅니다. Deepfake detectors and vision-language models share the recognizer's structure. We study prompt-only evasion that never touches a pixel, and how to close that gap.
05프라이버시Privacy
AI는 모든 것을 벡터로 바꿔 비교합니다. 그 비교를 원본을 드러내지 않고 하는 방법, 즉 암호화된 채로 유사도를 계산하는 기술을 만듭니다. 검색, 매칭, 집합 교집합까지. AI turns everything into vectors and compares them. We build ways to do that comparison without revealing the originals: similarity computed on encrypted data, for search, matching, and set intersection.
06여섯 번째 갈래는
당신이 만듭니다.The sixth thread
is yours to start.
석사·박사 과정 학생을 모집합니다.Master's and Ph.D. students welcome.
왜 여기서Why here
작은 연구실이 잘하는 것.What a small lab does well.
수학과 코드, 두 언어Two languages: math and code
문제를 수학으로 정의하고 실험으로 확인합니다. 선형대수·확률·정수론이 도구이고, 어느 한쪽만으로는 보안 연구가 완성되지 않습니다.Problems are defined in math and confirmed by experiment. Linear algebra, probability, and number theory are the tools; neither side alone completes security research.
교수와 직접Directly with the PI
신생 연구실이라 모든 학생이 교수와 매주 직접 만납니다. 연구 주제를 정하는 단계부터 학회 발표까지 직접 지도합니다.A new lab means every student meets the PI directly, every week. Guidance is hands-on from choosing a topic to presenting at a conference.
최고 학회에서 검증된 방법Methods proven at top venues
IEEE S&P, ACM CCS, NeurIPS, ICCV, ECCV, CVPR. 보안과 AI 양쪽의 최상위 학회에 발표해 온 연구 흐름을 그대로 잇습니다.IEEE S&P, ACM CCS, NeurIPS, ICCV, ECCV, CVPR. You join a line of work that publishes at the top of both security and AI.
국경 없는 협업Collaboration across borders
국내외 대학·연구기관과 공동 연구를 이어갑니다. 해외 파견과 국제 공동연구의 기회가 열려 있습니다.Ongoing joint work with universities and research institutes at home and abroad. Research visits and international collaboration are real options.
소식News
최근 소식Recent news
연구실의 문은 열려 있습니다.The door is open.
석사·박사 과정 학생을 모집합니다. 보안을 몰라도 괜찮습니다. 궁금한 것이 많은 사람이면 충분합니다. Master's and Ph.D. students are welcome. No security background required. Curiosity is the prerequisite.