VLDB 2026 Research / reviewers in the wild / expert
Hirokazu Hasegawa
dblp:29/3962
· DBLP profile ↗
17ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0001-6841-5358ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 1 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 1 first-author · 8 since 2021Security and privacy · 6 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lightweight and Stateless PUF-based Authentication Key Exchange Protocol for IoT Devices
Koki Mizoguchi, Rizka Reza Pahlevi, Hajime Shimada, Hirokazu Hasegawa, Hiroki Takakura |
COMPSAC | 4 |
| 2026 | A Masked-Frozen Approach to Reliable and Secure PUF-Based Authentication
Rizka Reza Pahlevi, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC | 2 |
| 2026 | Transferability of the GCG Attack Across LLMs: Correlation with Attention Similarity and Transfer Rate Prediction
Kazuki Takaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC | 2 |
| 2026 | Cybersecurity Exercise Generation System Using LLMs with Real Attack Datasets
Hirokazu Hasegawa, Hiroki Takakura |
ICISSP (1) | 1 |
| 2025 | Privacy-Aware Traffic Log Anonymization Method for Realizing Both Malicious Activity Detection and PrivacyabstractThe number of cyber-attacks is still increasing, and a Network-based Intrusion Detection System (NIDS) plays an important role in countermeasures for the cyber-attacks. However, due to increases in both cyber-attacks and traffic amount, burden of supervisors who check NIDS logs also increases. To alleviate this burden, we propose a method for detecting malicious activity under anonymized traffic logs that can be reviewed by low-privilege staffs. By performing preliminary screening with these anonymized traffic logs, we can reduce the burdens of supervisors. To realize this concept, we propose a privacy-aware traffic log anonymization method. We defined privacy-sensitive features within the traffic logs and explored the importance of Gain metric analysis on LightGBM. Then, we applied simple anonymization to features that have not so large value in metrics and applied complex anonymization such as fine-grained quantization to preserve Gain of the key features. We evaluated the performance of malicious activity detection and found that it achieves over 96% performance in widely accepted metrics. Additionally, we assessed the anonymization performance and confirmed that the number of unique sessions was reduced to less than 1/10 after anonymization. Furthermore, we confirmed that the uniqueness metric after anonymization is usable as a feature in the classifier. It improves widely accepted classification performance metrics by 0.59 to 1.27 percentage points. Takeshi Ogawa, Hajime Shimada, Hirokazu Hasegawa, Yukiko Yamaguchi |
COMPSAC | 3 |
| 2025 | An Enhanced Event-Based Dynamic Authentication Protocol Leveraging Arbiter PUF for IoT DevicesabstractWe propose a secure and lightweight authentication protocol tailored for resource-constrained Internet of Things (IoT) environments. Widely adopted approaches that store authentication data on IoT devices are inadequate, particularly in the presence of physical attacks. Building upon the Event-Based Dynamic protocol, we integrate an Enhanced Arbiter Physical Unclonable Function (PUF) to eliminate the need for static key storage and strengthen resistance against physical attacks. The proposed design introduces new Registration and Authentication phases that dynamically generate session keys using hardware-rooted entropy. Formal verification using the Tamarin Prover confirms the protocol’s correctness, mutual authentication, replay resistance, and confidentiality. Informal verification demonstrates robustness against node capture, impersonation, and guessing attacks. Simulation results show that the protocol achieves a throughput of 170–180 authentications per second, with communication overhead of 326–329 bytes and RAM usage of 212–215 bytes per client. These results confirm the protocol’s practicality and scalability for real-world IoT deployment. Rizka Reza Pahlevi, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC | 2 |
| 2023 | Security Operation Support by Estimating Cyber Attacks Without Traffic DecryptionabstractThe use of encrypted communications has become common and now majority on Internet traffic. Taking advantage of this trend, attackers also use encrypted communications for cyber attacks. In addition, the shift to cloud environments is in progress, and the effectiveness of measures of traffic analysis with decryption and re-encryption is becoming less and less. Installing software to monitor decrypted traffic on endpoints is also very costly. Therefore, many organizations require a method to narrow down the number of encrypted traffic candidates in a monitoring operation to a number that analysts can investigate to see if it is an attack without decryption. In this paper, we propose a method to estimate cyber attacks without traffic decryption to support the monitoring operation of encrypted traffic. The proposed method consists of a following two-step process where session information of encrypted traffic is used for the estimation: 1. A method to narrow down to encrypted traffic that behaves similarly to attacks from a large number of encrypted traffic. 2. A method to determine whether the narrowed-down encrypted traffic requires further investigation by analysts. By extracting and analyzing 17 million encrypted traffic from a 40 Gbps network, narrowed down to 194 encrypted traffic that can be analyzed in detail in the human operation. Additionally, 49 of those encrypted traffic were determined to be threats and 72 of those were determined to be scans by the detailed analysis. Shohei Hiruta, Itaru Hosomi, Hirokazu Hasegawa, Hiroki Takakura |
COMPSAC | 3 |
| 2022 | Malware Detection using Attributed CFG Generated by Pre-trained Language Model with Graph Isomorphism NetworkabstractTraditional malware detection methods cannot keep up with the massive amount of newly created malware quickly and effectively. Machine learning is a promising method for the detection and classification of large-scale newly created malware according to the features of samples. The current research trend is to use machine learning technology, such as the Gradient Boosting Decision Tree (GBDT) and deep neural network technology, to learn newly created malware rapidly and accurately. We propose Control-Flow Graph (CFG)- and Graph Isomorphism Network (GIN)-based malware classification, where we first extract the CFG from portable executable (PE) files and use the large-scale pre-training language model MiniLM to generate the node features of CFG. The extracted CFG is compressed to a feature vector with GIN and classified with Multi-Layer Perceptron. To evaluate our approach, we made a CFG-based malware detection dataset from PE files of the Dike Dataset, which we call the Malware Geometric Dataset (MGD), and collected the results. The evaluation results show that our proposal demonstrated 0.9977 in the Area Under Curve metric and achieved a 97.44 % detection rate when the False Positive Rate was 0.1 %. Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC | 2 |
| 2022 | Cyber Attack Stage Tracing System based on Attack Scenario Comparison
Masahito Kumazaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
ICISSP | 2 |
| 2021 | Potential Security Risks of Internationalized Domain Name Processing for HyperlinkabstractDomain names and URLs are essential technologies in the current Internet. Thus, a failure in URL processing not only gives an inconvenience to users but also causes serious security vulnerability. If URLs are still organized with only ASCII characters, there may be no problem on URL processing. However, current URLs are further extended and complicated. One of the complexity is coming from Internationalized Domain Name (IDN) related extensions. Thus, there are no simple ways to process URLs due to their characteristics and historical extensions. In this paper, firstly, we introduce possible threats due to wrong IDN processing. Then, we present potential threats due to URL extraction operations in applications with classifying attack surfaces. We examined the above problems with various programming languages and web browsers and confirmed many issues in different environments. Furthermore, we confirmed and demonstrated that the failure pattern are not identical because the issues that come from IDN processing varies. Finally, we conclude the experimental result and propose ways to a comprehensive solution. Taiga Shirakura, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC | 2 |
| 2021 | A Dynamic Access Control System based on Situations of UsersabstractRecently, cyber attacks have been sophisticated and cause serious damages. As one of the solutions for mitigating the damages, the network separation and fine granularity of access controls are effective against attacks. However, the COVID-19 changes human work style, and telecommuting comes to be generally. It may give many chances to attackers for invading the organization's internal network by infecting user's vulnerable home terminals, which are out of control by the organization. To ensure the security of organizations, we propose a dynamic access control system based on the situations of users. The system evaluates communications based on the user's risk and the importance of resources in destination terminals. When a user connects to the organization network from the outside, the system dynamically changes the access controls according to the evaluation results. The such situation requires stricter access controls than usual ones. For example, the communication by the high-risk user and the communication to servers storing important resources are restricted. By applying such dynamic access controls, the system enables us to ensure our network security with maintaining the convenience of users telecommuting. Hirokazu Hasegawa, Hiroki Takakura |
ICISSP | 1 |
| 2020 | Quantifying the Significance of Cybersecurity Text through Semantic Similarity and Named Entity Recognition
Otgonpurev Mendsaikhan, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
ICISSP | 2 |
| 2019 | Identification of Cybersecurity Specific Content Using the Doc2Vec Language ModelabstractIt has become more challenging for the security analysts to identify cyber threat related content on the Internet because of the vast amount of publicly available digital texts. In this research, we proposed building an autonomous system for extracting cyber threat information from publicly available information sources. We tested a neural embedding method called doc2vec as a natural language filter for the proposed system. With cybersecurity-specific training data and custom preprocessing, we were able to train a doc2vec model and evaluate its performance. According to our evaluation, the natural language filter was able to identify cybersecurity specific natural language text with 83% accuracy. Otgonpurev Mendsaikhan, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC (1) | 2 |
| 2019 | Rogue Wireless AP Detection using Delay Fluctuation in Backbone NetworkabstractNowadays, wireless LAN service has been taken for granted for everyone. On the other hand, there is an increasing cyber threat in wireless LAN. For example, there is an attack called Evil-Twin Attack which places rogue access point which has the same SSID as legitimate one to make clients unknowingly connect to it. Once attacked, all of the traffic moving across the network will be eavesdropped by attackers. In this paper, we propose a method to detect rogue AP by comparing delay fluctuation of backbone network. We define delay of backbone network as the difference between ICMP travel from client to first gateway and to the Internet Server. By comparing 100 samples of backbone delay evaluation results among 5 different wireless networks, which have different backbone networks, we obtained a perspective to discriminate networks by histogram of the backbone delay. Ziwei Zhang 0011, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
COMPSAC (1) | 2 |
| 2019 | Construction of Secure Internal Networks with Communication Classifying System
Yuya Sato, Hirokazu Hasegawa, Hiroki Takakura |
ICISSP | 2 |
| 2018 | Malware Detection based on HTTPS Characteristic via Machine Learning
Paul Calderon, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada |
ICISSP | 2 |
| 2014 | A Countermeasure Recommendation System against Targeted Attacks with Preserving Continuity of Internal NetworksabstractRecently, the sophistication of targeted cyber attacks makes conventional countermeasures useless to defend our network. Proper network design, i.e., Moderate segmentation and adequate access control, is one of the most effective countermeasures to prevent stealth activities of the attacks inside the network. By paying attention to the violation of the control, we can be aware of the existence of the attacks. In case that suspicious activities are found, we should adopt more strict design for further analysis and mitigation of damage. However, an organization must assume that its network administrators have full knowledge of its business and enough information of its network structure for selecting the most suitable design. This paper discusses a recommendation system to enhance the ability of a semi-automatic network design system previously proposed by us. Our new system evaluates on the viewpoint of two criteria, the effectiveness against malicious activities and the impact on business. The former takes the infection probability and hazardousness of communication into account and the latter considers the impact of the countermeasure which affects the organization's activities. By reviewing the candidate of the countermeasures with these criteria, the most suitable one to the organization can be selected. Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
COMPSAC | 1 |