VLDB 2026 Research / reviewers in the wild / expert
Takayuki Miura
dblp:182/5304
· DBLP profile ↗
6ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0001-8694-312XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial?
Akira Ito 0002, Takayuki Miura, Yosuke Todo |
CRYPTO (7) | 2 |
| 2025 | Membership Inference Attack Against Bayesian Neural NetworkabstractMembership Inference Attacks (MIAs) have been actively studied to evaluate the privacy risks of training data. However, existing MIAs focus on deterministic deep neural networks (DNNs). In this paper, we extend MIAs against deterministic DNNs to be applicable to Bayesian NNs (BNNs) and evaluate the privacy risks of BNNs. Specifically, we propose four MIAs, each differing in the extent to which detailed information on the posterior predictive distribution is exploited. Additionally, considering the trait of BNNs that produce different outputs for the same input, we also propose four multiple query attacks where attackers query BNNs multiple times using the same data and conduct MIAs with aggregated outputs. We conducted experiments using two tabular datasets for regression tasks and three representative BNNs. Our experiments show that outputting more detailed information on the posterior predictive distribution poses a higher privacy risk. Additionally, we found that the privacy risks may be underestimated if attackers exploiting multiple queries are not assumed. Toshiki Shibahara, Takayuki Miura, Masanobu Kii, Atsunori Ichikawa |
ICC | 2 |
| 2025 | Plausible Token Amplification for Improving Accuracy of Differentially Private In-Context Learning Based on Implicit Bayesian InferenceabstractWe propose Plausible Token Amplification (PTA) to improve the accuracy of Differentially Private In-Context Learning (DP-ICL) using DP synthetic demonstrations. While Tang et al. empirically improved the accuracy of DP-ICL by limiting vocabulary space during DP synthetic demonstration generation, its theoretical basis remains unexplored. By interpreting ICL as implicit Bayesian inference on a concept underlying demonstrations, we not only provide theoretical evidence supporting Tang et al.’s empirical method but also introduce PTA, a refined method for modifying next-token probability distribution. Through the modification, PTA highlights tokens that distinctly represent the ground-truth concept underlying the original demonstrations. As a result, generated DP synthetic demonstrations guide the Large Language Model to successfully infer the ground-truth concept, which improves the accuracy of DP-ICL. Experimental evaluations on both synthetic and real-world text-classification datasets validated the effectiveness of PTA. Yusuke Yamasaki, Kenta Niwa, Daiki Chijiwa, Takumi Fukami, Takayuki Miura |
ICML | 5 |
| 2025 | Lightweight Two-Party Secure Sampling Protocol for Differential PrivacyabstractSecure sampling is a secure multiparty computation protocol that allows a receiver to sample random numbers from a specified non-uniform distribution. It is a fundamental tool for privacy-preserving analysis since adding controlled noise is the most basic and frequently used method to achieve differential privacy. The well-known approaches to constructing a two-party secure sampling protocol are transforming uniform random values into non-uniform ones by computations (e.g., logarithm or binary circuits) or table-lookup. However, they require a large computational or communication cost to achieve a strong differential privacy guarantee. This work addresses this problem with our novel lightweight two-party secure sampling protocol. Our protocol consists of random table-lookup from a small table with the 1-out of-n oblivious transfer and only additions. Furthermore, we provide algorithms for making a table to achieve differential privacy. Our method can reduce the communication cost for (1.0, 2^(-40))-differential privacy from 183GB (naive construction) to 7.4MB. Masanobu Kii, Atsunori Ichikawa, Takayuki Miura |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Efficiently Calculating Stronger Lower Bound for Differentially Private SGD in Black-Box SettingabstractDifferentially private stochastic gradient descent (DP-SGD) is widely used to protect the privacy of training datasets for deep neural networks. Recently, a lower bound of ∊ for DP-SGD has been gaining attention to know whether the upper bound is tight or not. The lower bound is empirically calculated by repeating a game of an attacker and trainer. In the game, the trainer builds a model using one of the neighboring datasets differing by only a target sample. Then the attacker pre-dicts whether the target sample is used in training. In this paper, we focus on a black-box and realistic setting and propose methods for efficiently calculating stronger lower bounds by solving two challenges of lower bound calculation: computational cost and vulnerable neighboring datasets. To reduce the computational cost, we propose a multiple-sample game where an attacker predicts whether multiple target samples are used in training. To make vulnerable neighboring datasets, we propose three methods based on the analysis of vulnerable samples: vulnerability-based selection, label manipulation, and perturbation. We evaluated our methods using three realistic datasets: MNIST, CIFAR-10, and CIFAR-100, and two neural networks: a six-layer convolutional neural network and ResNetl8. Regarding the multiple-sample game, we confirmed that it produced lower bounds similar to those calculated with the prior game while reducing the computational cost by a factor of 1/100. Regarding the neighboring datasets, we compared our datasets with three existing ones and found that we can obtain 1.3 to 57.9 times stronger lower bounds. Toshiki Shibahara, Takayuki Miura, Masanobu Kii, Atsunori Ichikawa |
COMPSAC | 2 |
| 2020 | Differential Privacy and Its Applicability for Official Statistics in Japan - A Comparative Study Using Small Area Data from the Japanese Population Census
Shinsuke Ito, Takayuki Miura, Hiroto Akatsuka, Masayuki Terada |
PSD | 2 |