VLDB 2026 Research / reviewers in the wild / expert
Hiroki Inayoshi
dblp:274/5971
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0003-3355-8804ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Plaintext in the Wild: Investigating Secure Connection Label Accuracy for Android AppsabstractSmartphones have become deeply integrated into daily life, prompting widespread concern over how mobile apps handle user data. The Google Play Store requires Android developers to disclose whether their apps encrypt user data during transmission via a "secure connection" label in the Data Safety section. However, these labels are self-declared, and their consistency with actual app behavior remains unclear. In this study, we empirically evaluate the consistency of secure connection labels with real-world data transmission practices by dynamically analyzing network traffic from over 12,000 top-ranked Android apps. We identify 65 apps transmitting sensitive data without encryption, and they collectively account for over 5.842 billion installs, indicating that a substantial number of users may be affected. A majority of them (i.e., 46 apps) falsely claim to encrypt data while transmitting sensitive information in plaintext, and the others correctly disclose the lack of encryption and transmit sensitive data in plaintext. We contacted developers of the inconsistent apps, resulting in several label updates. Our findings reveal a disconnect between declared and actual security practices and offer concrete recommendations to improve the integrity of privacy disclosures on app marketplaces. Yusei Sakuraba, Hiroki Inayoshi, Shoichi Saito, Akito Monden |
SCAM | 2 |
| 2024 | Porting a Python Application to the Web Using Django: A Case Study of an Archaeological Image Processing SystemabstractIn recent years, desktop applications are often ported to the Web. This is because Web applications running in a cloud environment have many advantages, for example, they can be used by a wide variety of clients over the Internet and can dynamically allocate computing resources according to demand. Such porting is also very important in terms of effectively utilizing existing software assets in a modern environment. However, porting to the Web involves numerous considerations that are not easy for those without the knowledge and skills to perform. In this paper we describe in detail our experience of porting a desktop Python application, which uses the image processing library OpenCV and the GUI library PySimpleGUI, into a web application, which uses the web framework Django, the CSS framework Bootstrap, the database management system MySQL and phpMyAdmin. We also employed Docker and Docker Compose for flexible development and deployment. Through our experience, we have identified six key aspects to consider when porting a desktop application to the web. This paper will elaborate on these aspects and how to deal with them. This paper also reports which parts of source code could be reused, which parts had to be newly developed, and the size and time required to conduct reuse, modification, and additional development. Hikaru Tomita, Mariko Sasakura, Kinari Nishiura, Hiroki Inayoshi, Akito Monden |
SERA | 4 |
| 2022 | Plug and Analyze: Usable Dynamic Taint Tracker for Android AppsabstractTaint analyses, especially static taint analyses, are utilized to uncover hidden and suspicious behaviors in Android apps. However, current static taint analyzers use imprecise Android models, producing unreliable results and increasing the result verification cost. On the other hand, current dynamic taint trackers accurately detect execution paths. However, they depend on specific Android versions and modified devices, reducing their usability. Also, the users may not be able to analyze prepared datasets comprehensively. The results of the current analyses would be biased and less trustworthy. This paper presents a new dynamic taint analyzer called T-Recs that tracks information flows by recording the app execution at the app's bytecode level on an Android device and reconstructing the execution on a server independently of specific Android versions and devices. The users can instantly start analyzing apps with T-Recs after plugging an unmodified device into their computer. We implemented and evaluated T-Recs with 158 apps of DroidBench 3.0 in comparison with current taint analyzers: FlowDroid (w/ and w/o IC3), Amandroid, DroidSafe, and TaintDroid (w/ and w/o IntelliDroid), and only T-Recs achieved 100% accuracy. The result of privacy leak detection in 96 popular Google Play apps shows that T-Recs detected 43 true positives, the highest among compared tools. Also, T-Recs analyzed 39,480 apps from Google Play and Anzhi, showing that T-Recs can be applied to apps that vary in supported SDK versions. Further, the result of ID leak detection in 158 popular apps from Google Play in 2021 shows that T-Recs can detect leaks in recently-developed apps. T-Recs is one of the promising tools for future app analysis. Hiroki Inayoshi, Shohei Kakei, Shoichi Saito |
SCAM | 1 |
| 2021 | VTDroid: Value-based Tracking for Overcoming Anti-Taint-Analysis Techniques in Android AppsabstractBytecode-level taint tracking discovers suspicious apps on the Android platform; however, malicious apps can bypass it by transferring information via system layers in the Android. A context tainting countermeasure has been devised, but since it employs a list of flow-causing API methods, it will miss flows when unlisted methods are exploited and can also produce false positives. This paper presents a new taint-tracking technique operating value logging and matching based on the flows’ characteristics to detect such flows without relying on lists of API methods. We implemented it into our taint-tracking system called VTDroid and confirmed its effectiveness with our test suite. We also evaluated it with popular apps collected from Google Play. The results show that the precision of VTDroid is 37 points higher than the context tainting. Hiroki Inayoshi, Shohei Kakei, Eiji Takimoto, Koichi Mouri, Shoichi Saito |
ARES | 1 |