VLDB 2026 Research / reviewers in the wild / expert
Akira Yamada 0001
dblp:22/3273-1
· DBLP profile ↗
16ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-7213-5834ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accurate, Generalizable, and Practical Behavioral Models to Identify Impending User Exposure to Malicious WebsitesabstractTo keep users safe online, current protections frequently employ blocklists of known malware and phishing websites. However, such defenses suffer from an inherent gap between malicious content creation and its detection, leaving a window where users are left vulnerable. To address this limitation, earlier research has shown that one could use individual user web browsing behavior to identify imminent exposure to malicious content. While existing methods frequently rely on temporal proximity (e.g., aggregating browsing patterns over the recent past), they do not leverage temporal ordering in user browsing, which results in suboptimal performance and is, in practice, inadequate given the low base rates of malware incidence. We introduce network and browser-level features (e.g., page rank, tab browsing time) and a temporal model that captures user behavior through a time-series representation. This not only improves classification performance by a significant margin (between 93% and 145% F1-score improvements) over previous models, but also maintains strong robustness across completely disparate sets of users. More importantly, our method shows strong resilience to concept drift, as performance holds steady over multiple years of testing. We discuss how this method is capable of anticipating future exposure. We also assess the relative importance of each feature to the performance, as well as their impact on false positive rates—whose minimization is critical to foster adoption. Finally, we discuss use cases for such behavior-based models. Jin-Dong Dong, Kyle Crichton, Akira Yamada 0001, Yukiko Sawaya, Lorrie Faith Cranor, Nicolas Christin |
ACM Trans. Web | 3 |
| 2024 | A Study on Time-Resilient Features for Detecting TLS Encrypted Malware Traffic
Kaisei Fujiwara, Akira Yamada 0001, Seiichi Ozawa |
ICONIP (11) | 2 |
| 2023 | Designing a Location Trace Anonymization ContestabstractFor a better understanding of anonymization methods for location traces, we have designed and held a location trace anonymization contest that deals with a long trace (400 events per user) and fine-grained locations (1024 regions). In our contest, each team anonymizes her original traces, and then the other teams perform privacy attacks against the anonymized traces. In other words, both defense and attack compete together, which is close to what happens in real life. Prior to our contest, we show that re-identification alone is insufficient as a privacy risk and that trace inference should be added as an additional risk. Specifically, we show an example of anonymization that is perfectly secure against re-identification and is not secure against trace inference. Based on this, our contest evaluates both the re-identification risk and trace inference risk and analyzes their relationship. Through our contest, we show several findings in a situation where both defense and attack compete together. In particular, we show that an anonymization method secure against trace inference is also secure against re-identification under the presence of appropriate pseudonymization. We also report defense and attack algorithms that won first place, and analyze the utility of anonymized traces submitted by teams in various applications such as POI recommendation and geo-data analysis. Takao Murakami, Hiromi Arai, Koki Hamada, Takuma Hatano, Makoto Iguchi, Hiroaki Kikuchi, Atsushi Kuromasa, Hiroshi Nakagawa, Yuichi Nakamura 0004, Kenshiro Nishiyama, Ryo Nojima, Hidenobu Oguri, Chiemi Watanabe, Akira Yamada 0001, Takayasu Yamaguchi, Yuji Yamaoka |
Proc. Priv. Enhancing Technol. | 14 |
| 2021 | SeBeST: Security Behavior Stage Model and Its Application to OS Update
Ayane Sano, Yukiko Sawaya, Akira Yamada 0001, Ayumu Kubota |
AINA (2) | 3 |
| 2021 | Designing Personalized OS Update Message based on Security Behavior Stage ModelabstractAs one of the scales which assess the end-user’s security behavior, the security behavior stage model (SeBeST) [1] is a practical approach to characterize similar groups of users (precontemplation, contemplation, preparation, action and maintenance stages) and provide customized remedies to improve their security behavior. For example, in OS update message customization, a group that does not update OS continuously may require a message indicating the ease of OS update; on the other hand, updating users need a message indicating the importance of OS update. In this paper, we propose a personalized OS update message interface based on SeBeST. We conduct two online surveys to evaluate effective appearance and message as the personalized user interface (UI). First, we assess the interface’s appearance individually for the three behavior stages (preparation, action, and maintenance) and then combine the customized messages and the selected impressions for these stages. We confirmed that appropriate appearances are different for each stage. For example, a highlighted red button is efficient for users in the preparation stage. On the other hand, the red background is suitable for users of the action and maintenance stages. We discovered that the combination of the message indicating the disadvantage of the OS update and the UI which is the highlighted red button is suitable for the preparation and action stages. In addition, we confirmed the best combination for users of the maintenance stage is a message indicating the ease of OS update and the UI which is mouse over pop-up representation. Therefore, it is necessary for each user to show the appropriate message and UI. Ayane Sano, Yukiko Sawaya, Akira Yamada 0001, Ayumu Kubota, Takamasa Isohara |
PST | 3 |
| 2020 | Human Factors in Homograph Attack Recognition
Tran Thao Phuong, Yukiko Sawaya, Hoang-Quoc Nguyen-Son, Akira Yamada 0001, Ayumu Kubota, Tran Van Sang, Rie Shigetomi Yamaguchi |
ACNS (2) | 4 |
| 2019 | Hunting Brand Domain Forgery: A Scalable Classification for Homograph Attack
Tran Thao Phuong, Yukiko Sawaya, Hoang-Quoc Nguyen-Son, Akira Yamada 0001, Kazumasa Omote, Ayumu Kubota |
SEC | 4 |
| 2018 | Predicting Impending Exposure to Malicious Content from User BehaviorabstractMany computer-security defenses are reactive---they operate only when security incidents take place, or immediately thereafter. Recent efforts have attempted to predict security incidents before they occur, to enable defenders to proactively protect their devices and networks. These efforts have primarily focused on long-term predictions. We propose a system that enables proactive defenses at the level of a single browsing session. By observing user behavior, it can predict whether they will be exposed to malicious content on the web seconds before the moment of exposure, thus opening a window of opportunity for proactive defenses. We evaluate our system using three months' worth of HTTP traffic generated by 20,645 users of a large cellular provider in 2017 and show that it can be helpful, even when only very low false positive rates are acceptable, and despite the difficulty of making "on-the-fly'' predictions. We also engage directly with the users through surveys asking them demographic and security-related questions, to evaluate the utility of self-reported data for predicting exposure to malicious content. We find that self-reported data can help forecast exposure risk over long periods of time. However, even on the long-term, self-reported data is not as crucial as behavioral measurements to accurately predict exposure. Mahmood Sharif, Junpei Urakawa, Nicolas Christin, Ayumu Kubota, Akira Yamada 0001 |
CCS | 5 |
| 2017 | Self-Confidence Trumps Knowledge: A Cross-Cultural Study of Security BehaviorabstractComputer security tools usually provide universal solutions without taking user characteristics (origin, income level, ...) into account. In this paper, we test the validity of using such universal security defenses, with a particular focus on culture. We apply the previously proposed Security Behavior Intentions Scale (SeBIS) to 3,500 participants from seven countries. We first translate the scale into seven languages while preserving its reliability and structure validity. We then build a regression model to study which factors affect participants' security behavior. We find that participants from different countries exhibit different behavior. For instance, participants from Asian countries, and especially Japan, tend to exhibit less secure behavior. Surprisingly to us, we also find that actual knowledge influences user behavior much less than user self-confidence in their computer security knowledge. Stated differently, what people think they know affects their security behavior more than what they do know. Yukiko Sawaya, Mahmood Sharif, Nicolas Christin, Ayumu Kubota, Akihiro Nakarai, Akira Yamada 0001 |
CHI | 6 |
| 2017 | AI Web-Contents Analyzer for Monitoring Underground Marketplace
Yuki Kawaguchi, Akira Yamada 0001, Seiichi Ozawa |
ICONIP (5) | 2 |
| 2016 | On the implementation of path-based dynamic pricing in edge-directed routingabstractFuture Internet proposals have employed edge-directed routing to realize the benefits of path choice by the sources (e.g., end users). However, economic issues hamper the adoption by ISPs: 1) ISPs' costs increase when sources choose paths that are not economically optimal for ISPs, and 2) ISPs have to overprovision their links aggressively since traffic engineering is shifted to the users and congestion is more likely to occur. We implement a path-based dynamic pricing scheme that addresses these challenges. ISPs can dynamically adjust the prices of paths in order to compensate for potential losses incurred by users' choices and to incentivize users to switch paths in case of congestion. We describe our implementation in the context of future Internet architectures and demonstrate a mutually beneficial situation for ISPs and users. Junpei Urakawa, Cristina Basescu, Kohei Sugiyama, Christos Pappas, Akira Yamada 0001, Ayumu Kubota, Adrian Perrig |
APCC | 5 |
| 2013 | Passive OS Fingerprinting by DNS Traffic AnalysisabstractIn this paper, we propose a new passive OS fingerprinting method which only requires DNS traffic analysis. The method utilizes characteristics on DNS queries specific to each OS, e.g. unique domain names, query patterns, time interval etc. The method can estimate the number of devices with each OS from the number of queries by utilizing the characteristics of the time interval patterns. The method considers the likelihood of irregular events that some queries are sent at less than regular time intervals, and some other queries are sent at more than regular time intervals. We analyze DNS traffic sent by each OS and extract the characteristics for OS fingerprinting. Then, we examine our estimation method by using DNS traffic in our intra-network. According to our examination, some results of our estimation method are close to the results of DHCP fingerprinting. Takashi Matsunaka, Akira Yamada 0001, Ayumu Kubota |
AINA | 2 |
| 2012 | LAP: Lightweight Anonymity and PrivacyabstractPopular anonymous communication systems often require sending packets through a sequence of relays on dilated paths for strong anonymity protection. As a result, increased end-to-end latency renders such systems inadequate for the majority of Internet users who seek an intermediate level of anonymity protection while using latency-sensitive applications, such as Web applications. This paper serves to bridge the gap between communication systems that provide strong anonymity protection but with intolerable latency and non-anonymous communication systems by considering a new design space for the setting. More specifically, we explore how to achieve near-optimal latency while achieving an intermediate level of anonymity with a weaker yet practical adversary model (i.e., protecting an end-host's identity and location from servers) such that users can choose between the level of anonymity and usability. We propose Lightweight Anonymity and Privacy (LAP), an efficient network-based solution featuring lightweight path establishment and stateless communication, by concealing an end-host's topological location to enhance anonymity against remote tracking. To show practicality, we demonstrate that LAP can work on top of the current Internet and proposed future Internet architectures. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Akira Yamada 0001, Samuel C. Nelson, Marco Gruteser, Wei Meng 0001 |
IEEE Symposium on Security and Privacy | 4 |
| 2009 | Anomaly Detection for DNS Servers Using Frequent Host SelectionabstractDNS is one of the internet's fundamental building blocks, used by various applications such as web and mail transfer. Therefore, monitoring DNS traffic has potential to detect host anomalies such as spammers and infected hosts in a network. However, previous works assume a small number of hosts or target on domain name anomalies, so that they cannot be applied to a large-scale networks due to performance issues. A large number of hosts and long-term tracing consume computational resources and make real-time analysis difficult. In this paper, we propose anomaly detection for DNS servers using frequent host selection, which selects only potential hosts and does not depend on the number of hosts. We evaluate the proposed system using DNS traffic for 6 months of tracing, and show that the system can feasibly handle hosts in the dataset and detect anomalies, such as mail servers suffering from spam and DNS servers are configured incorrectly. Akira Yamada 0001, Yutaka Miyake, Masahiro Terabe, Kazuo Hashimoto, Nei Kato |
AINA | 1 |
| 2009 | Visual similarity-based phishing detection without victim site informationabstractPhishing attacks, which steal users' account information by fake Websites, have become a serious problem on theInternet. There are two major approaches in phishing detection: the blacklist- and the heuristics-based approach. Heuristics-based approaches employ common characteristics of phishing sites such as distinctive keywords used in Web pages or URLs in order to detect new phishing sites that are not yet listed in blacklists. However, these kinds of heuristics can be easily circumvented by phishers once their mechanism is revealed. In order to overcome this weakness, visual similarity-based detection techniques have been proposed. Because phishing sites have to mimic victim sites, visual similarity between phishing sites and their victim sites is supposed to be an inherent and not easily concealable characteristic. However, these techniques require images of real victim sites for detection. In this paper, we propose a phishing detection mechanism based on visual similarity among phishing sites that mimic the same victim site. Surprisingly, just by analyzing visual similarity among Web pages without a priori knowledge, our method automatically extracts 224 distinct Web page layouts mimicked by 2,262 phishing sites and achieves a detection rate of over 80% while keeping the false-positive rate to 17.5%. We also find that the false-positive rate can be reduced. Masanoei Hara, Akira Yamada 0001, Yutaka Miyake |
CICS | 2 |
| 2006 | L2VPN over Chord: Hosting Millions of Small Zeroconf Networks over DHT NodesabstractAlthough there are variety of VPN products and software available today, it is still difficult for normal users to setup their own VPN server and configure their firewall and NAT so that they can allow remote access to their home network. In this paper, we propose a DHT-based L2VPN hosting infrastructure that allows millions of consumer users to easily create their own L2VPN server processes outside their home network, which can then bridge their home network and remote VPN clients. Because each L2VPN server acts like a virtual Ethernet switch, a user can use auto-configuration technologies like Zeroconf, which relies on layer-2 broadcast capability, among his or her networks and hosts bridged by the L2VPN server. This extends applicability of Zeroconf-like technologies from local are to wide area and greatly broaden their usefulness. A user can dynamically form a L2VPN with widely distributed hosts and use it as a secure plug & play networking platform for Zeroconf-enabled applications. We show that the proposed infrastructure can be easily implemented using an existing DHT technology while achieving great scalability and minimizing the operational cost of the infrastructure nodes. Ayumu Kubota, Akira Yamada 0001, Yutaka Miyake |
GLOBECOM | 2 |