Takayuki Sasaki

dblp:34/3589 · DBLP profile ↗
← Back
14ranked-venue papers
8as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author · 3 since 2021Computer networks · 2 · 2 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 The End of Anarchy? Understanding the Life of HTTP Exploits Used in IoT Malware Infections
Ryu Kuki, Takayuki Sasaki, Arwa Abdulkarim Al Alsadi, Carlos Gañán, Katsunari Yoshioka
AsiaCCS2
2026 CIC-YNU-IoTMal: A comprehensive multilayer dataset for static and dynamic analysis of IoT malware behavior
abstract
Malware continues to pose a critical security threat to the Internet of Things (IoT) ecosystem, driven by the diversity and dynamics of network environments. These conditions introduce significant vulnerabilities, rendering IoT devices prime targets for sophisticated malware attacks. Honeypots have been employed to emulate IoT devices and generate comprehensive malware datasets, enabling the development of adaptive defense systems. However, existing approaches often rely solely on static or dynamic analysis, which fails to keep pace with the evolving nature of malware. Moreover, rigorous detection requires high-fidelity datasets that reflect real-world threats, yet publicly available, multi-architecture IoT malware datasets with recent signatures remain scarce. To address this gap, we present CIC-YNU-IoTMal, a well-researched dataset integrating static and dynamic malware behaviors. Leveraging IoTPOT data and simulated IoT devices, we captured raw network packets, system calls, and system activity logs. Specifically, 10,000 malware binaries were executed on simulated IoT devices within Docker containers and sandbox environments tailored to each architecture. The pipeline processes ARM, MIPS, MIPSEL, and x86 architectures, collecting network traffic (PCAP), system traces (STRACE), and system statistics (SAR). These files were converted to CSV, analyzed, and used to train machine learning algorithms for malware classification. CIC-YNU-IoTMal comprises 2.4M PCAP, 1.8M SAR, and 105M STRACE samples across architectures, representing families such as Mirai, Bashlite (Gafgyt), DarkNexus, Rudedevil, Agent, Generic, and Tsunami. Experimental validation demonstrates that dynamic malware behaviors can be effectively tracked and detected. CIC-YNU-IoTMal2026 is publicly available, advancing research toward a more secure IoT environment.
Sajjad Dadkhah, Ogobuchi Daniel Okey, Sebin Abraham Maret, Yen-Wu Lo, Amir Firouzi, Ryu Kuki, Takayuki Sasaki, Katsunari Yoshioka, Tao Ban, Seiichi Ozawa, Ali A. Ghorbani 0001
Inf. Syst.7
2025 Bits and Pieces: Piecing Together Factors of IoT Vulnerability Exploitation
Arwa Abdulkarim Al Alsadi, Mathew Vermeer, Takayuki Sasaki, Katsunari Yoshioka, Michel van Eeten, Carlos Gañán
AsiaCCS3
2025 Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service
Takayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Simon Edward Parkin, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
USENIX Security Symposium1
2025 Revisiting Disparity from Dual-Pixel Images: Physics-Informed Lightweight Depth Estimation
abstract
In this study, we propose a high-performance disparity (depth) estimation method using dual-pixel (DP) images with few parameters. Conventional end-to-end deep-learning methods have many parameters but do not fully ex-ploit disparity constraints, which limits their performance. Therefore, we propose a lightweight disparity estimation method based on a completion-based network that explicitly constrains disparity and learns the physical and systemic disparity properties of DP. By modeling the DP-specific dis-parity error parametrically and using it for sampling during training, the network acquires the unique properties of DP and enhances robustness. This learning also allows us to use a common RGB-D dataset for training without a DP dataset, which is labor-intensive to acquire. Further-more, we propose a non-learning-based refinement frame-work that efficiently handles inherent disparity expansion errors by appropriately refining the confidence map of the network output. As a result, the proposed method achieved state-of-the-art results while reducing the overall system size to 1/5 of that of the conventional method, even without using the DP dataset for training, thereby demonstrating its effectiveness. The code and dataset are available on our project site.
Teppei Kurita, Yuhi Kondo, Legong Sun, Takayuki Sasaki, Sho Nitta, Yasuhiro Hashimoto, Yoshinori Muramatsu, Yusuke Moriuchi
WACV4
2024 Sparse Regularization Based on Reverse Ordered Weighted L1-Norm and Its Application to Edge-Preserving Smoothing
abstract
Sparse regularization is being applied to solve indeterminate inverse problems. However, current regularization is unable to manage sparsity and small perturbations at the same time, and does not perform well enough for some applications. In this study, we propose reversed ordered weighted L1-norm regularization (ROWL) that can tolerate small perturbations while well-handling sparsity. Since ROWL can make proximity mapping easy to compute, it is possible to construct an algorithm to find a suboptimal solution to the inverse problem using the proximity splitting method. Using ROWL for image edge-preserving smoothing, allows us to control both edge sharpness and gradation smoothness.
Takayuki Sasaki, Yukihiro Bandoh, Masaki Kitahara
ICASSP1
2024 Who Left the Door Open? Investigating the Causes of Exposed IoT Devices in an Academic Network
abstract
Many studies have discovered internet-facing systems exposing services that are vulnerable to attack. These are often assumed to be misconfigured systems that are not meant to expose these services to the network, especially not in an enterprise network. In this study, we clarify the causes of the presence of IoT devices exposing Telnet and FTP in a university enterprise network. This also helps us to understand who is responsible. We scanned the network and found 185 IoT devices consisting of 30 device models exposing Telnet and 49 models exposing FTP. We sent out a security notification and a survey to device owners. The survey demonstrated that 2 out of 21 and 8 out of 41 owners intentionally enabled Telnet and FTP, respectively, on all their devices. After receiving the notification, 38 out of 47 owners said they were willing to take measures on at least one of their IoT devices. All except one of the devices of these willing owners were successfully remediated. When we investigated the manuals of the devices, we were able to confirm that there was no disclosure whatsoever of the exposed service in 15 out of 30 manuals for models with Telnet and 10 out of 49 manuals for models with FTP. We also confirmed, by combining a survey of the manufacturers with the device manuals, that 22 out of 30 and 29 out of 49 devices enabled Telnet and FTP by default, respectively. From the above results, we conclude that the presence of misconfigured devices was less driven by human errors of the owners and more by the choices of the manufacturers. The majority of owners were motivated to remediate the security risks once made aware of them.
Takayuki Sasaki, Takaya Noma, Yudai Morii, Toshiya Shimura, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
SP1
2023 Complexity Reduction of Graph Signal Denoising Based on Fast Graph Fourier Transform
abstract
Denoising is one of the most fundamental and important problems in signal processing, and graph signal denoising methods have been actively studied. Several graph signal denoising methods based on mathematical programming require solving linear equations involving Laplacian matrix, which creates problem with computational accuracy and running time. This study proposes a fast and accurate solution of linear equations for denoising based on the fast graph Fourier transform method. Moreover, the proposed method can perform denoising not only on graphs for which the fast graph Fourier transform can be performed, but also on a wide class of graphs with more relaxed conditions, without loss of accuracy. Experiments demonstrate the efficiency of the proposed method and confirm that denoising can be performed up to 167.3 times faster without loss of accuracy.
Takayuki Sasaki, Yukihiro Bandoh, Masaki Kitahara
ICIP1
2022 An Internet-Wide View of Connected Cars: Discovery of Exposed Automotive Devices
abstract
As the number of connected cars increases, cyber-attacks targeting them become significant risks. Especially, On-Board Equipment (OBE) that is directly accessible from the Internet can be an immediate target. However, it is not known what kind of and how many connected automotive devices can be remotely accessed from the Internet and, if compromised, become an entry point for further attacks on in-vehicle networks. In this study, we investigate the prevalence of such exposed vehicular devices. We propose a discovery method that utilizes an Internet-wide scan engine and a regular web search engine to find Internet-facing OBE. Using the proposed method, we discovered 2,532 devices of 12 different OBE products across 27 countries. We also investigated the potential cyber-attack risks against the discovered devices. 11 out of the 12 products have security concerns for remote compromises, such as running Telnet or outdated server programs. Moreover, we found that nine products have the capability to connect to the in-vehicle network. We could confirm from the information displayed in their user interface that at least two of them indeed connected to the in-vehicle network. Additionally, we noticed three products expose privacy-sensitive information such as GPS location. We believe this result provides a lower bound of the security risk of Internet-facing vehicular devices.
Takahiro Ueda, Takayuki Sasaki, Katsunari Yoshioka, Tsutomu Matsumoto
ARES2
2022 Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management Devices
abstract
Geographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device.
Takayuki Sasaki, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
SP1
2016 SDNsec: Forwarding Accountability for the SDN Data Plane
abstract
SDN promises to make networks more flexible, programmable, and easier to manage. Inherent security problems in SDN today, however, pose a threat to the promised benefits. First, the network operator lacks tools to proactively ensure that policies will be followed or to reactively inspect the behavior of the network. Second, the distributed nature of state updates at the data plane leads to inconsistent network behavior during reconfigurations. Third, the large flow space makes the data plane susceptible to state exhaustion attacks. This paper presents SDNsec, an SDN security extension that provides forwarding accountability for the SDN data plane. Forwarding rules are encoded in the packet, ensuring consistent network behavior during reconfigurations and limiting state exhaustion attacks due to table lookups. Symmetric-key cryptography is used to protect the integrity of the forwarding rules and enforce them at each switch. A complementary path validation mechanism allows the controller to reactively examine the actual path taken by the packets. Furthermore, we present mechanisms for secure link-failure recovery.
Takayuki Sasaki, Christos Pappas, Taeho Lee 0003, Torsten Hoefler, Adrian Perrig
ICCCN1
2016 Optical distortion correction for eyeglasses-type wearable device using multi-mirror array
abstract
We developed an optical distortion correction technique for an eyeglasses-type wearable device using a multi-mirror array (MMA). This wearable device is small and light weight, but optics using MMA can cause optical distortions, such as geometric distortion and chromatic aberration of magnification, that depend on the user's pupil distance and degrade the visibility of displayed virtual images. We model distortion in a captured virtual image by using the proposed virtual image evaluation system, and calculate an inversely corrected image based on the distortion. As a result, the proposed technique provides users with clear visibility regardless of pupil distance.
Takayuki Sasaki, Masahiro Baba
ICIP1
2013 Load distribution of an OpenFlow controller for role-based network access control
Takayuki Sasaki, Yoichi Hatano, Kentaro Sonoda, Yoichiro Morita, Hideyuki Shimonishi, Toshihiko Okamura
APNOMS1
2003 A Practical Approach for Bus Architecture Optimization at Transaction Level
Osamu Ogawa, Sylvain Bayon de Noyer, Pascal Chauvet, Katsuya Shinohara, Yoshiharu Watanabe, Hiroshi Niizuma, Takayuki Sasaki, Yuji Takai
DATE7