profile

Hanna Kim

Ph.D. student, KAIST (EE), advised by Prof. Seungwon Shin

LLM SecurityAI for CybersecurityInterpretability & Failure Analysis

About

Hello, I’m Hanna. I’m a fourth-year Ph.D. student at KAIST, where I also earned my Bachelor’s and Master’s degrees in Electrical Engineering.

I study how large language models reshape information for operational use in cybersecurity, and how those changes shape both attack and defense. On the offensive side, I examine how advances in LLM capabilities make existing information more useful for cyberattacks. On the defensive side, I ask how reliably models recover and reason over that information, and investigate the systematic failure modes and underlying mechanisms that limit their reliability.

Selected Publications

Submitted
ScriptIOC-Bench: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs
H. Kim, J. Cui, M. Song, H. Heo, S. Shin, K. Lee, X. Liao · Under review at USENIX Security 2027
Security'25
When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs
H. Kim, M. Song, S.H. Na, S. Shin, K. Lee · USENIX Security 2025
Security'25
Refusal Is Not an Option: Unlearning Safety Alignment of Large Language Models
M. Song, H. Kim, J. Kim, S. Shin, S. Son · USENIX Security 2025
Other publications (7)
Submitted
ARGORA: Orchestrated Argumentation for Causally Grounded LLM Reasoning and Decision Making
Y. Jin, H. Kim, K. Kim, C. Lee, S. Shin · Under review at NeurIPS 2026
NDSS'25
Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
J. Cui, H. Kim, E. Jang, D. Yim, K. Kim, Y. Lee, J.W. Chung, S. Shin, X. Liao · NDSS 2025
NAACL'25
Claim-guided textual backdoor attack for practical applications
M. Song, H. Kim, J. Kim, Y. Jin, S. Shin · NAACL 2025 Findings
NDSS'24
DRAINCLoG: Detecting Rogue Accounts with Illegally-obtained NFTs using Classifiers Learned on Graphs
H. Kim, J. Cui, E. Jang, C. Lee, Y. Lee, J.W. Chung, S. Shin · NDSS 2024
Submitted
AutoNF: Automatic Generation of Network Functions for SmartNICs Using Multi-Agent LLM Framework
M. You, H. Kim, J. Nam, I. Kim, M. Seo, T. Kim, S. Shin · Under review at ASPLOS 2026
arXiv'23
A Deep Dive into NFT Whales: A Longitudinal Study of the NFT Trading Ecosystem
N.H. Park, H. Kim, C. Lee, C. Yoon, S. Lee, Y. Jin, S. Shin · arXiv preprint, 2023
IEICE'22
A Large-Scale Bitcoin Abuse Measurement and Clustering Analysis Utilizing Public Reports
J. Choi, J. Kim, M. Song, H. Kim, N. Park, M. Seo, Y. Jin, S. Shin · IEICE Transactions on Information and Systems, 2022

Experience

Carnegie Mellon University (CMU)
Visiting Scholar, Advisor: Prof. Lujo Bauer
Sep 2026 – Mar 2027 · United States
  • I’ll be in Pittsburgh through March 2027 — if you’re around, I’d love to meet.
University of Illinois Urbana-Champaign (UIUC)
Visiting Scholar, Advisor: Prof. Xiaojing Liao
Nov 2025 – May 2026 · United States
  • Studied how reliably LLMs extract actionable threat intelligence from real-world malicious scripts, and developed a failure taxonomy, finding a distinct error profile for each model
  • Built ScriptIOC-Bench to measure this, and showed that deterministic string tools and GRPO fine-tuning make extraction more reliable
S2W (site)
Research Intern, Jul 2022 – Feb 2023 · South Korea
  • NFT scam analysis; built GNN-based malicious account detection
  • Graph-based security event detection with contrastive learning

Invited Talks & Media Coverage

Honors & Awards

Global Advanced Cybersecurity HRD Program Grant (>$25,000) — Korea Institute of Information Security & Cryptology, 2026
Global Advanced Cybersecurity HRD Program Grant (>$25,000) — Korea Institute of Information Security & Cryptology, 2025
7th Financial Security Institute Research Paper Competition — Korea Financial Security Institute (K-FSI), 2023
The 2023 Korea Cyber Security Paper Award — Korea National Intelligence Service, 2023
5th Financial Security Institute Research Paper Competition — Korea Financial Security Institute, 2021