Hajime Shimada

dblp:10/5714 · DBLP profile ↗
← Back
23ranked-venue papers
1as first author
10since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 1 first-author · 7 since 2021Security and privacy · 6 · 1 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Lightweight and Stateless PUF-based Authentication Key Exchange Protocol for IoT Devices
Koki Mizoguchi, Rizka Reza Pahlevi, Hajime Shimada, Hirokazu Hasegawa, Hiroki Takakura
COMPSAC3
2026 A Masked-Frozen Approach to Reliable and Secure PUF-Based Authentication
Rizka Reza Pahlevi, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC4
2026 Transferability of the GCG Attack Across LLMs: Correlation with Attention Similarity and Transfer Rate Prediction
Kazuki Takaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC4
2026 Hierarchical Wakeup Logic of the Issue Queue for High Scalability
Hideki Ando, Hajime Shimada
ISCA2
2025 Privacy-Aware Traffic Log Anonymization Method for Realizing Both Malicious Activity Detection and Privacy
abstract
The number of cyber-attacks is still increasing, and a Network-based Intrusion Detection System (NIDS) plays an important role in countermeasures for the cyber-attacks. However, due to increases in both cyber-attacks and traffic amount, burden of supervisors who check NIDS logs also increases. To alleviate this burden, we propose a method for detecting malicious activity under anonymized traffic logs that can be reviewed by low-privilege staffs. By performing preliminary screening with these anonymized traffic logs, we can reduce the burdens of supervisors. To realize this concept, we propose a privacy-aware traffic log anonymization method. We defined privacy-sensitive features within the traffic logs and explored the importance of Gain metric analysis on LightGBM. Then, we applied simple anonymization to features that have not so large value in metrics and applied complex anonymization such as fine-grained quantization to preserve Gain of the key features. We evaluated the performance of malicious activity detection and found that it achieves over 96% performance in widely accepted metrics. Additionally, we assessed the anonymization performance and confirmed that the number of unique sessions was reduced to less than 1/10 after anonymization. Furthermore, we confirmed that the uniqueness metric after anonymization is usable as a feature in the classifier. It improves widely accepted classification performance metrics by 0.59 to 1.27 percentage points.
Takeshi Ogawa, Hajime Shimada, Hirokazu Hasegawa, Yukiko Yamaguchi
COMPSAC2
2025 An Enhanced Event-Based Dynamic Authentication Protocol Leveraging Arbiter PUF for IoT Devices
abstract
We propose a secure and lightweight authentication protocol tailored for resource-constrained Internet of Things (IoT) environments. Widely adopted approaches that store authentication data on IoT devices are inadequate, particularly in the presence of physical attacks. Building upon the Event-Based Dynamic protocol, we integrate an Enhanced Arbiter Physical Unclonable Function (PUF) to eliminate the need for static key storage and strengthen resistance against physical attacks. The proposed design introduces new Registration and Authentication phases that dynamically generate session keys using hardware-rooted entropy. Formal verification using the Tamarin Prover confirms the protocol’s correctness, mutual authentication, replay resistance, and confidentiality. Informal verification demonstrates robustness against node capture, impersonation, and guessing attacks. Simulation results show that the protocol achieves a throughput of 170–180 authentications per second, with communication overhead of 326–329 bytes and RAM usage of 212–215 bytes per client. These results confirm the protocol’s practicality and scalability for real-world IoT deployment.
Rizka Reza Pahlevi, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC4
2024 Localizing the Tag Comparisons in the Wakeup Logic to Reduce Energy Consumption of the Issue Queue
abstract
There is a high demand to reduce the energy consumption of microprocessors. Among resources in a processor, the issue queue is one of the largest energy consumers, with much of the energy being consumed by the wakeup logic. The wakeup logic comprises the content-addressable memory, where tag comparisons are performed for all entries. Such global tag comparisons consume an appreciable amount of energy. This paper proposes a scheme called segmenting wakeup logic (SegWU), where the wakeup logic is segmented logically. An instruction is dispatched to an available entry in the segment selected based on the partial bits of the source tag values. At the wakeup time, a broadcast destination tag is compared only in the segment that corresponds to the partial bits of the destination tag value. Tag comparisons are not performed in the other segments. This localization of tag comparisons reduces the energy consumption. Our evaluation results for SPEC2017 benchmark programs show that SegWU reduces the number of tag comparisons by 90.3%. This lowers the IQ energy consumption, and the net reduction excluding the secondary effect (activity lowering of the front-end) and overhead is 3.0% in the base core energy consumption with no performance degradation. The overall energy reduction including the secondary effect is 6.9%.
Kenichiro Mori, Sota Kosugi, Hiroto Yoshida, Hajime Shimada, Hideki Ando
MICRO4
2022 Malware Detection using Attributed CFG Generated by Pre-trained Language Model with Graph Isomorphism Network
abstract
Traditional malware detection methods cannot keep up with the massive amount of newly created malware quickly and effectively. Machine learning is a promising method for the detection and classification of large-scale newly created malware according to the features of samples. The current research trend is to use machine learning technology, such as the Gradient Boosting Decision Tree (GBDT) and deep neural network technology, to learn newly created malware rapidly and accurately. We propose Control-Flow Graph (CFG)- and Graph Isomorphism Network (GIN)-based malware classification, where we first extract the CFG from portable executable (PE) files and use the large-scale pre-training language model MiniLM to generate the node features of CFG. The extracted CFG is compressed to a feature vector with GIN and classified with Multi-Layer Perceptron. To evaluate our approach, we made a CFG-based malware detection dataset from PE files of the Dike Dataset, which we call the Malware Geometric Dataset (MGD), and collected the results. The evaluation results show that our proposal demonstrated 0.9977 in the Area Under Curve metric and achieved a 97.44 % detection rate when the False Positive Rate was 0.1 %.
Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC4
2022 Cyber Attack Stage Tracing System based on Attack Scenario Comparison
Masahito Kumazaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura
ICISSP4
2021 Potential Security Risks of Internationalized Domain Name Processing for Hyperlink
abstract
Domain names and URLs are essential technologies in the current Internet. Thus, a failure in URL processing not only gives an inconvenience to users but also causes serious security vulnerability. If URLs are still organized with only ASCII characters, there may be no problem on URL processing. However, current URLs are further extended and complicated. One of the complexity is coming from Internationalized Domain Name (IDN) related extensions. Thus, there are no simple ways to process URLs due to their characteristics and historical extensions. In this paper, firstly, we introduce possible threats due to wrong IDN processing. Then, we present potential threats due to URL extraction operations in applications with classifying attack surfaces. We examined the above problems with various programming languages and web browsers and confirmed many issues in different environments. Furthermore, we confirmed and demonstrated that the failure pattern are not identical because the issues that come from IDN processing varies. Finally, we conclude the experimental result and propose ways to a comprehensive solution.
Taiga Shirakura, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC4
2020 Quantifying the Significance of Cybersecurity Text through Semantic Similarity and Named Entity Recognition
Otgonpurev Mendsaikhan, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
ICISSP4
2019 Identification of Cybersecurity Specific Content Using the Doc2Vec Language Model
abstract
It has become more challenging for the security analysts to identify cyber threat related content on the Internet because of the vast amount of publicly available digital texts. In this research, we proposed building an autonomous system for extracting cyber threat information from publicly available information sources. We tested a neural embedding method called doc2vec as a natural language filter for the proposed system. With cybersecurity-specific training data and custom preprocessing, we were able to train a doc2vec model and evaluate its performance. According to our evaluation, the natural language filter was able to identify cybersecurity specific natural language text with 83% accuracy.
Otgonpurev Mendsaikhan, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC (1)4
2019 Rogue Wireless AP Detection using Delay Fluctuation in Backbone Network
abstract
Nowadays, wireless LAN service has been taken for granted for everyone. On the other hand, there is an increasing cyber threat in wireless LAN. For example, there is an attack called Evil-Twin Attack which places rogue access point which has the same SSID as legitimate one to make clients unknowingly connect to it. Once attacked, all of the traffic moving across the network will be eavesdropped by attackers. In this paper, we propose a method to detect rogue AP by comparing delay fluctuation of backbone network. We define delay of backbone network as the difference between ICMP travel from client to first gateway and to the Internet Server. By comparing 100 samples of backbone delay evaluation results among 5 different wireless networks, which have different backbone networks, we obtained a perspective to discriminate networks by histogram of the backbone delay.
Ziwei Zhang 0011, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
COMPSAC (1)4
2018 Malware Detection based on HTTPS Characteristic via Machine Learning
Paul Calderon, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
ICISSP4
2016 Evaluation on Malware Classification by Session Sequence of Common Protocols
Shohei Hiruta, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura, Takeshi Yagi, Mitsuaki Akiyama
CANS3
2015 Reliability-configurable mixed-grained reconfigurable array compatible with high-level synthesis
abstract
This paper presents a mixed-grained reconfigurable VLSI array architecture that can cover mission-critical applications to consumer products through C-to-array application mapping. A proof-of-concept VLSI chip was fabricated in a 65nm process. Measurement results show that applications on the chip can be working in a harsh radiation environment.
Masanori Hashimoto, Dawood Alnajiar, Hiroaki Konoura, Yukio Mitsuyama, Hajime Shimada, Kazutoshi Kobayashi, Hiroyuki Kanbara, Hiroyuki Ochi, Takashi Imagawa, Kazutoshi Wakabayashi, Takao Onoye, Hidetoshi Onodera
ASP-DAC5
2015 Malware Classification Method Based on Sequence of Traffic Flow
abstract
Network-based malware classification plays an important role in improving system security than system-based malware classification. The vast majority of malware needs a network activity in order to accomplish its purpose (e.g., downloading malware, connecting to a C&C server, etc.). Many malware classification approaches based on network behavior have thus been proposed. Nevertheless, they merely rely on either a request URL or payload for signature matching. To classify the network activity of malware, the patterns of network behavior must be understood and the changes in behavior observed. Therefore, the sequence of flows and their correlation caused by the malware should be analysed. In this paper, we present a novel malware classification method based on clustering of flow features and sequence alignment algorithms for computing sequence similarity, which represents network behavior of malware. We focus on analysing the sequence similarity between the sequence patterns of malware traffic flow generated by executing malware on the dynamic analysing system. We also performed an evaluation by using malware traffic collected from a real environment. On the basis of our experimental results, we identified the most appropriate method for classifying malware by similarity of network activity.
Hyoyoung Lim, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura
ICISSP3
2014 A Countermeasure Recommendation System against Targeted Attacks with Preserving Continuity of Internal Networks
abstract
Recently, the sophistication of targeted cyber attacks makes conventional countermeasures useless to defend our network. Proper network design, i.e., Moderate segmentation and adequate access control, is one of the most effective countermeasures to prevent stealth activities of the attacks inside the network. By paying attention to the violation of the control, we can be aware of the existence of the attacks. In case that suspicious activities are found, we should adopt more strict design for further analysis and mitigation of damage. However, an organization must assume that its network administrators have full knowledge of its business and enough information of its network structure for selecting the most suitable design. This paper discusses a recommendation system to enhance the ability of a semi-automatic network design system previously proposed by us. Our new system evaluates on the viewpoint of two criteria, the effectiveness against malicious activities and the impact on business. The former takes the infection probability and hazardousness of communication into account and the latter considers the impact of the countermeasure which affects the organization's activities. By reviewing the candidate of the countermeasures with these criteria, the most suitable one to the organization can be selected.
Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura
COMPSAC3
2014 Development of a Secure Traffic Analysis System to Trace Malicious Activities on Internal Networks
abstract
In contrast to conventional cyber attacks such as mass infection malware, targeted attacks take a long time to complete their mission. By using a dedicated malware for evading detection at the initial attack, an attacker quietly succeeds in setting up a front-line base in the target organization. Communication between the attacker and the base adopts popular protocols to hide its existence. Because conventional countermeasures deployed on the boundary between the Internet and the internal network will not work adequately, monitoring on the internal network becomes indispensable. In this paper, we propose an integrated sandbox system that deploys a secure and transparent proxy to analyze internal malicious network traffic. The adoption of software defined networking technology makes it possible to redirect any internal traffic from/to a suspicious host to the system for an examination of its insidiousness. When our system finds malicious activity, the traffic is blocked. If the malicious traffic is regarded as mandatory, e.g., For controlled delivery, the system works as a transparent proxy to bypass it. For benign traffic, the system works as a transparent proxy, as well. If binary programs are found in traffic, they are automatically extracted and submitted to a malware analysis module of the sandbox. In this way, we can safely identify the intention of the attackers without making them aware of our surveillance.
Soshi Hirono, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura
COMPSAC3
2014 Unknown Attack Detection by Multistage One-Class SVM Focusing on Communication Interval
Shohei Araki, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura
ICONIP (3)3
2011 A Fine-Grained Runtime Power/Performance Optimization Method for Processors with Adaptive Pipeline Depth
Jun Yao 0001, Shinobu Miwa, Hajime Shimada, Shinji Tomita
J. Comput. Sci. Technol.3
2010 A Minimal Roll-Back Based Recovery Scheme for Fault Toleration in Pipeline Processors
abstract
In this paper, we proposed a light-weighted recovery scheme for fault tolerable pipeline processors after error has been detected by redundant executions. A minimal rolling back procedure is designed to schedule the re-execution based recovery in a one-cycle delay. This scheme makes full use of in-fly pipeline working status to aid the recovery, which relieves the recovery from a large checkpoint buffer.
Jun Yao 0001, Ryoji Watanabe, Takashi Nakada, Hajime Shimada, Yasuhiko Nakashima, Kazutoshi Kobayashi
PRDC4
2003 Pipeline stage unification: a low-energy consumption technique for future mobile processors
abstract
Recent mobile processors are required to exhibit both low-energy consumption and high performance. To satisfy these requirements, dynamic voltage scaling (DVS) is currently employed. However, its effectiveness will be limited in the future because of shrinking the variable supply voltage range. As an alternative, we previously proposed pipeline stage unification (PSU), which unifies multiple pipeline stages without reducing the supply voltage at a power-saving mode. This paper compares effectiveness of PSU to DVS in current and future process generations. Our evaluation results show PSU will reduce energy consumption by 27-34% more than DVS after about 10 years.
Hajime Shimada, Hideki Ando, Toshio Shimada
ISLPED1