VLDB 2026 Research / reviewers in the wild / expert
Atsunori Ichikawa
dblp:243/4463
· DBLP profile ↗
7ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0001-8013-7071ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 4 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Membership Inference Attack Against Bayesian Neural NetworkabstractMembership Inference Attacks (MIAs) have been actively studied to evaluate the privacy risks of training data. However, existing MIAs focus on deterministic deep neural networks (DNNs). In this paper, we extend MIAs against deterministic DNNs to be applicable to Bayesian NNs (BNNs) and evaluate the privacy risks of BNNs. Specifically, we propose four MIAs, each differing in the extent to which detailed information on the posterior predictive distribution is exploited. Additionally, considering the trait of BNNs that produce different outputs for the same input, we also propose four multiple query attacks where attackers query BNNs multiple times using the same data and conduct MIAs with aggregated outputs. We conducted experiments using two tabular datasets for regression tasks and three representative BNNs. Our experiments show that outputting more detailed information on the posterior predictive distribution poses a higher privacy risk. Additionally, we found that the privacy risks may be underestimated if attackers exploiting multiple queries are not assumed. Toshiki Shibahara, Takayuki Miura, Masanobu Kii, Atsunori Ichikawa |
ICC | 4 |
| 2025 | Lightweight Two-Party Secure Sampling Protocol for Differential PrivacyabstractSecure sampling is a secure multiparty computation protocol that allows a receiver to sample random numbers from a specified non-uniform distribution. It is a fundamental tool for privacy-preserving analysis since adding controlled noise is the most basic and frequently used method to achieve differential privacy. The well-known approaches to constructing a two-party secure sampling protocol are transforming uniform random values into non-uniform ones by computations (e.g., logarithm or binary circuits) or table-lookup. However, they require a large computational or communication cost to achieve a strong differential privacy guarantee. This work addresses this problem with our novel lightweight two-party secure sampling protocol. Our protocol consists of random table-lookup from a small table with the 1-out of-n oblivious transfer and only additions. Furthermore, we provide algorithms for making a table to achieve differential privacy. Our method can reduce the communication cost for (1.0, 2^(-40))-differential privacy from 183GB (naive construction) to 7.4MB. Masanobu Kii, Atsunori Ichikawa, Takayuki Miura |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Efficiently Calculating Stronger Lower Bound for Differentially Private SGD in Black-Box SettingabstractDifferentially private stochastic gradient descent (DP-SGD) is widely used to protect the privacy of training datasets for deep neural networks. Recently, a lower bound of ∊ for DP-SGD has been gaining attention to know whether the upper bound is tight or not. The lower bound is empirically calculated by repeating a game of an attacker and trainer. In the game, the trainer builds a model using one of the neighboring datasets differing by only a target sample. Then the attacker pre-dicts whether the target sample is used in training. In this paper, we focus on a black-box and realistic setting and propose methods for efficiently calculating stronger lower bounds by solving two challenges of lower bound calculation: computational cost and vulnerable neighboring datasets. To reduce the computational cost, we propose a multiple-sample game where an attacker predicts whether multiple target samples are used in training. To make vulnerable neighboring datasets, we propose three methods based on the analysis of vulnerable samples: vulnerability-based selection, label manipulation, and perturbation. We evaluated our methods using three realistic datasets: MNIST, CIFAR-10, and CIFAR-100, and two neural networks: a six-layer convolutional neural network and ResNetl8. Regarding the multiple-sample game, we confirmed that it produced lower bounds similar to those calculated with the prior game while reducing the computational cost by a factor of 1/100. Regarding the neighboring datasets, we compared our datasets with three existing ones and found that we can obtain 1.3 to 57.9 times stronger lower bounds. Toshiki Shibahara, Takayuki Miura, Masanobu Kii, Atsunori Ichikawa |
COMPSAC | 4 |
| 2023 | Communication-Efficient Inner Product Private Join and Compute with CardinalityabstractPrivate join and compute (PJC) is a paradigm where two parties owing their private database securely join their databases and compute a function over the combined database. Inner product PJC, introduced by Lepoint et al. (Asiacrypt’21), is a class of PJC that has a wide range of applications such as secure analysis of advertising campaigns. In this computation, two parties, each of which has a set of identifier-value pairs, compute the inner product of the values after the (inner) join of their databases with respect to the identifiers. They proposed inner product PJC protocols that are specialized for the unbalanced setting where the input sizes of both parties are significantly different and not suitable for the balanced setting where the sizes of two inputs are relatively close. Koji Chida, Koki Hamada, Atsunori Ichikawa, Masanobu Kii, Junichi Tomida |
AsiaCCS | 3 |
| 2023 | 3-Party Secure Computation for RAMs: Optimal and Concretely Efficient
Atsunori Ichikawa, Ilan Komargodski, Koki Hamada, Ryo Kikuchi, Dai Ikarashi |
TCC (1) | 1 |
| 2023 | Efficient Noise Generation Protocols for Differentially Private Multiparty ComputationabstractTo bound information leakage in outputs of protocols, it is important to construct secure multiparty computation protocols which output differentially private values perturbed by the addition of noise. However, previous noise generation protocols have round and communication complexity growing with differential privacy budgets, or require parties to locally generate non-uniform noise, which makes it difficult to guarantee differential privacy against active adversaries. We propose three kinds of protocols for generating noise drawn from certain distributions providing differential privacy. The two of them generate noise from finite-range variants of the discrete Laplace distribution. For$(\epsilon,\delta )$-differential privacy, they only need constant numbers of rounds independent of$\epsilon,\delta$while the previous protocol needs the number of rounds depending on$\delta$. The two protocols are incomparable as they make a trade-off between round and communication complexity. Our third protocol non-interactively generate shares of noise from the binomial distribution by predistributing keys for a pseudorandom function. It achieves communication complexity independent of$\epsilon$or$\delta$for the computational analogue of$(\epsilon,\delta )$-differential privacy while the previous protocols require communication complexity depending on$\epsilon$. We also prove that our protocols can be extended so that they provide differential privacy in the active setting. Reo Eriguchi, Atsunori Ichikawa, Noboru Kunihiro, Koji Nuida |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Efficient Secure Multi-Party Protocols for Decision Tree Classification
Atsunori Ichikawa, Wakaha Ogata, Koki Hamada, Ryo Kikuchi |
ACISP | 1 |