VLDB 2026 Research / reviewers in the wild / expert
Hiroshi Esaki
dblp:41/6012
· DBLP profile ↗
47ranked-venue papers
1as first author
18since 2021 · last 2026
0000-0001-5657-9216ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 6 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Security and privacy · 2Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Spatial ID-Driven Edge-Cloud Architecture for Real-Time Urban Digital TwinsabstractThe integration of static geospatial datasets and real-time IoT streams is essential for responsive and scalable urban Digital Twins (DTs). However, current infrastructures remain fragmented across domains, formats, and reference systems, limiting interoperability and city-scale deployment. This paper presents the first city-scale implementation of a Spatial ID–driven edge–cloud architecture that unifies heterogeneous static and dynamic urban data under a hierarchical four-dimensional identifier. Unlike prior DT systems that rely on ad hoc tiling or local schemas, our design operationalizes Spatial ID as a universal indexing layer across batch and streaming pipelines, enabling multi-resolution queries, real-time synchronization, and cross-domain interoperability. A prototype deployment in Tokyo’s Chiyoda and Bunkyo wards demonstrates the approach, integrating 3D city models with live IoT streams. Evaluation shows millisecond-to-second query performance over 148 million records, sub-100 ms vector tile delivery, and real-time IoT stream processing at 30 fps. These results establish Spatial ID not only as a conceptual framework but as a practical, deployable foundation for interoperable, low-latency, and scalable DT infrastructures aligned with the vision of Society 5.0. Sami Brahim Djelloul, Alex Orsholits, Manabu Tsukada, Hiroshi Esaki |
CCNC | 5 |
| 2025 | Towards Efficient Roadside LiDAR Deployment: A Fast Surrogate Metric Based on Entropy-Guided VisibilityabstractThe deployment of roadside LiDAR sensors plays a crucial role in the development of Cooperative Intelligent Transport Systems (C-ITS). However, the high cost of LiDAR sensors necessitates efficient placement strategies to maximize detection performance. Traditional roadside LiDAR deployment methods rely on expert insight, making them time-consuming. Automating this process, however, demands extensive computation, as it requires not only visibility evaluation but also assessing detection performance across different LiDAR placements. To address this challenge, we propose a fast surrogate metric, the Entropy-Guided Visibility Score (EGVS), based on information gain to evaluate object detection performance in roadside LiDAR configurations. EGVS leverages Traffic Probabilistic Occupancy Grids (TPOG) to prioritize critical areas and employs entropy-based calculations to quantify the information captured by LiDAR beams. This eliminates the need for direct detection performance evaluation, which typically requires extensive labeling and computational resources. By integrating EGVS into the optimization process, we significantly accelerate the search for optimal LiDAR configurations. Experimental results using the AWSIM simulator demonstrate that EGVS strongly correlates with Average Precision (AP) scores and effectively predicts object detection performance. This approach offers a computationally efficient solution for roadside LiDAR deployment, facilitating scalable smart infrastructure development. Yuze Jiang, Ehsan Javanmardi, Manabu Tsukada, Hiroshi Esaki |
IV | 4 |
| 2025 | A multipath redundancy communication framework for enhancing 5G mobile communication qualityabstractAs networks increasingly become the backbone of modern society, the demands placed on them by various applications have become more complex. In particular, the demand for high-capacity, low-latency services such as real-time streaming is increasing every year. Although 5G has been deployed to meet these needs, its effectiveness can vary significantly by location and time, and sometimes falls short of requirements. Traditionally, much of the research to improve communication stability has focused on TCP-based systems, which do not translate well to real-time UDP streaming applications. To address the above challenges, we propose a multipath redundant communication framework designed to improve the quality of real-time media streaming. This framework has been tested using multipath redundant communication over two mobile networks with a moving vehicle in an urban environment. Using a real-time streaming application based on WebRTC, our framework demonstrates a significant reduction in packet loss and an increase in bitrate, outperforming existing multipath redundant communication systems without interfering with the application’s congestion control mechanisms. • Proposal of a Framework: The paper proposes a multipath redundant communication framework to improve the streaming quality via multipath redundant communications in 5G networks, particularly focusing on UDP media streaming applications. • Implementation and Verification: The framework has been implemented and verified using multipath communication over two mobile networks, with a vehicle moving in a real experiment, leveraging a real-time streaming application based on WebRTC. • Significant Improvements Demonstrated in a real experiment: Results from the implementation show significant reductions in packet loss and increases in bitrate, which notably outperforms existing multipath redundant communication systems without disrupting the applications’ congestion control mechanisms. • Challenges Addressed: The paper discusses the specific challenges related to the traditional approaches of multipath redundancy, especially in maintaining communication quality across varied network fields and discusses the advantages of the proposed method. • Future Research Directions: The paper concludes by discussing potential future research directions, including the necessity to further evaluate the framework in varied environments to verify its general applicability and latency performance. Koki Ito, Jin Nakazato, Romain Fontugne, Manabu Tsukada, Hiroshi Esaki |
Comput. Commun. | 5 |
| 2024 | Optimizing mmWave Beamforming for High-Speed Connected Autonomous Vehicles: An Adaptive ApproachabstractThe commercialization of 5G has been initiated for a while. Furthermore, millimeter wave (mmWave) has been introduced to small cells with small coverage due to its strong linearity and non-winding characteristics. On the other hand, in connected autonomous vehicles (CAV s), where various traffic systems can cooperatively perform recognition, decision-making, and execution, communication is assumed to be always connected. Therefore, to use low latency mm Wave for high-speed moving CAV, existing beamforming cannot follow them at high speed. This paper proposes an improved beam tracking algorithm for high-speed CAVs, which can be evaluated in a more general environment using a traffic simulator. We proposed an adaptive algorithm for a general road environment by increasing the number of beam searches and search dimensions. Ryo Iwaki, Jin Nakazato, Muhammad Asad 0002, Ehsan Javanmardi, Kazuki Maruta, Manabu Tsukada, Hideya Ochiai, Hiroshi Esaki |
CCNC | 8 |
| 2024 | Zero-Knowledge Proof of Distinct Identity: a Standard-compatible Sybil-resistant Pseudonym Extension for C-ITSabstractPseudonyms are widely used in Cooperative Intelligent Transport Systems (C-ITS) to protect the location privacy of vehicles. However, the unlinkability nature of pseudonyms also enables Sybil attacks, where a malicious vehicle can pretend to be multiple vehicles at the same time. In this paper, we propose a novel protocol called zero-knowledge Proof of Distinct Identity (zk-PoDI,) which allows a vehicle to prove that it is not the owner of another pseudonym in the local area, without revealing its actual identity. Zk-PoDI is based on the Diophantine equation and zk-SNARK, and does not rely on any specific pseudonym design or infrastructure assistance. We show that zk-PoDI satisfies all the requirements for a practical Sybil-resistance pseudonym system, and it has low latency, adjustable difficulty, moderate computation overhead, and negligible communication cost. We also discuss the future work of implementing and evaluating zk-PoDI in a realistic city-scale simulation environment. Ye Tao 0007, Hongyi Wu, Ehsan Javanmardi, Manabu Tsukada, Hiroshi Esaki |
IV | 5 |
| 2024 | Neuron Personalization of Collaborative Federated Learning via Device-to-Device CommunicationsabstractWireless Ad Hoc Federated Learning (WAFL) has been proposed to allow fully distributed collaborative learning in a device-to-device communication without depending on any centralized mechanisms. The main focus of previous studies has been to generalize models of users over label distribution skew cases in not independent and identically distributed (Non- IID) scenarios. However, a generalized WAFL model does not always provide correct answers to each individual over label preference skew, which needs personalization. We proposed a personalization method of WAFL for label preference skew in a previous work, which divide a local model into public and private parameters by layer. In this paper, we propose more fine- grained parameter decoupling approach, Neuron Personalization. We have carried out evaluations using modified CIFAR10 dataset and Pascal VOC dataset. The results indicate that the Neuron Personalization have a good effects to keeping the balance between generalization and personalization for label preference skew. Ryusei Higuchi, Hiroshi Esaki, Hideya Ochiai |
WiMob | 2 |
| 2023 | zk-PoT: Zero-Knowledge Proof of Traffic for Privacy Enabled Cooperative PerceptionabstractCooperative perception is an essential and widely discussed application of connected automated vehicles. However, the authenticity of perception data is not ensured, because the vehicles cannot independently verify the event they did not see. Many methods, including trust-based (i.e., statistical) approaches and plausibility-based methods, have been proposed to determine data authenticity. However, these methods cannot verify data without a priori knowledge. In this study, a novel approach of constructing a self-proving data from the number plate of target vehicles was proposed. By regarding the pseudonym and number plate as a shared secret and letting multiple vehicles prove they know it independently, the data authenticity problem can be transformed to a cryptography problem that can be solved without trust or plausibility evaluations. Our work can be adapted to the existing works including ETSI/ISO ITS standards while maintaining backward compatibility. Analyses of common attacks and attacks specific to the proposed method reveal that most attacks can be prevented, whereas preventing some other attacks, such as collusion attacks, can be mitigated. Experiments based on realistic data set show that the rate of successful verification can achieve 70% to 80% at rush hours. Ye Tao 0007, Yuze Jiang, Pengfei Lin 0005, Manabu Tsukada, Hiroshi Esaki |
CCNC | 5 |
| 2023 | Iterative Resolution with IPv6 Packets FailingabstractThe exhaustion of IPv4 addresses has driven the rapid adoption of IPv6 networks, which has created challenges in the domain name resolution process, particularly for IPv6-only iterative resolvers. This paper presents an experimental analysis to quantify the extent of this problem, revealing a significantly lower success rate of name resolution using IPv6-only resolvers (64.1%) compared to IPv4-only resolvers (98.8%). By analysing the success rates and percentages of A and AAAA records for the top 1,000,000 domains in the Tranco list, we identify the limitations of IPv6-only iterative resolvers and highlight the urgent need for comprehensive solutions to improve DNS resolution in IPv6-only networks. Our findings emphasise the importance of full IPv6 adoption for improved compatibility in IPv6-only environments, and serve as a basis for addressing the challenges faced by IPv6-only networks. Momoka Yamamoto, Jin Nakazato, Manabu Tsukada, Hiroshi Esaki |
ICCCN | 4 |
| 2023 | Detection of Global Anomalies on Distributed IoT Edges with Device-to-Device CommunicationabstractAnomaly detection is an important function in IoT applications for finding outliers caused by abnormal events. Anomaly detection sometimes comes with high-frequency data sampling which should be carried out at Edge devices rather than Cloud. In this paper, we consider the case that multiple IoT devices are installed in a single remote site and that they collaboratively detect anomalies from the observations with device-to-device communications. For this, we propose a fully distributed collaborative scheme for training distributed anomaly detectors. We introduce the concept of Global Anomaly which sample is not only rare to the local device but rare to all the devices in the target domain. We also propose a distributed threshold-finding algorithm for Global Anomaly detection. With our standard benchmark-based evaluation, we have confirmed that our scheme trained anomaly detectors perfectly across the devices. We have also confirmed that the devices collaboratively found thresholds for Global Anomaly detection with low false positive rates while achieving high true positive rates with few exceptions. Hideya Ochiai, Riku Nishihata, Eisuke Tomiyama, Yuwei Sun, Hiroshi Esaki |
MobiHoc | 5 |
| 2023 | Poster: Evaluation of IPv6-only-Capable Iterative ResolversabstractThis paper introduces an "IPv6-only-Capable resolver" to address the issue of many zones remaining unresolvable due to a lack of IPv6 connectivity in authoritative name servers. The proposed method utilizes NAT64 to transmit packets to IPv4-only authoritative name servers and increases resolution success rates with competitive response times compared to a traditional IPv6-only resolver. Momoka Yamamoto, Jin Nakazato, Romain Fontugne, Manabu Tsukada, Hiroshi Esaki |
SIGCOMM | 5 |
| 2023 | AutowareV2X: Reliable V2X Communication and Collective Perception for Autonomous DrivingabstractFor cooperative intelligent transport systems (C-ITS), vehicle-to-everything (V2X) communication is utilized to allow autonomous vehicles to share critical information with each other. We propose AutowareV2X, an implementation of a V2X communication module that is integrated into the autonomous driving (AD) software, Autoware. AutowareV2X provides external connectivity to the entire AD stack, enabling the end-to-end (E2E) experimentation and evaluation of connected autonomous vehicles (CAV). The Collective Perception Service was also implemented, allowing the transmission of Collective Perception Messages (CPMs). A dual-channel mechanism that enables wireless link redundancy on the critical object information shared by CPMs is also proposed. Performance evaluation in field experiments has indicated that the CPM-based perception information can be transmitted in around 30 ms, and shared object data can be used by the AD software to conduct collision avoidance maneuvers. The dual-channel delivery of CPMs transmits perception information through two different wireless technologies. The receiver-side CAV can then dynamically select the best CPM from CPMs received from both links, depending on the freshness of their information. Yu Asabe, Ehsan Javanmardi, Jin Nakazato, Manabu Tsukada, Hiroshi Esaki |
VTC2023-Spring | 5 |
| 2023 | Attacker Localization with Machine Learning in RS-485 Industrial Control NetworksabstractCyber-attacks on industrial control systems (ICSs) may cause huge damage to our society and our lives. RS-485 is a backbone network for many ICSs deployed worldwide as a standard. Attack detection in the RS-485 network has been studied in the past. However, the operator still needs to identify and eliminate the attacker in the network after detected, which may require a huge downtime of the system. We propose an attacker localization framework for RS-485 networks. This framework uses (1) a current transformer for monitoring the analog signals of the communication line and (2) machine learning for detecting and localizing the attacker. We have carried out a performance evaluation on a 200-meter scale testbed and found that regression-based localization model performed the best with an averaging aggregator. It could estimate the location of the attacker with about 100% accuracy if we could obtain 6 or 10 attacker points in the training dataset. It could also estimate the location with 93%-96% accuracy with only 4 attacker training points, which would be still practically useful for finding the attacker in RS-485 network. Hideya Ochiai, Md Delwar Hossain, Youki Kadobayashi, Hiroshi Esaki |
WFCS | 4 |
| 2022 | Suspicious ARP Activity Detection and Clustering Based on Autoencoder Neural NetworksabstractThe rapidly increasing number of smart devices on the Internet necessitates an efficient inspection system for safeguarding our networks from suspicious activities such as Address Resolution Protocol (ARP) probes. In this research, we analyze sequence data of ARP traffic on LAN based on the numerical count and degree of its packets. A dynamic threshold is employed to detect underlying suspicious activities, which are further converted into feature vectors to train an unsupervised autoencoder neural network. Then, we leverage K-means clustering to separate the extracted latent features of suspicious activities from the autoencoder into various patterns. Yuwei Sun, Hideya Ochiai, Hiroshi Esaki |
CCNC | 3 |
| 2022 | Misbehavior Detection Using Collective Perception under Privacy ConsiderationsabstractIn cooperative ITS, security and privacy protection are essential. Cooperative Awareness Message (CAM) is a basic V2V message standard, and misbehavior detection is critical for protection against attacking CAMs from the inside system, in addition to node authentication by Public Key Infrastructure (PKI). On the contrary, pseudonym IDs, which have been introduced to protect privacy from tracking, make it challenging to perform misbehavior detection. In this study, we improve the performance of misbehavior detection using observation data of other vehicles. This is referred to as collective perception message (CPM), which is becoming the new standard in European countries. We have experimented using realistic traffic scenarios and succeeded in reducing the rate of rejecting valid CAMs (false positive) by approximately 15 percentage points while maintaining the rate of correctly detecting attacks (true positive). Manabu Tsukada, Shimpei Arii, Hideya Ochiai, Hiroshi Esaki |
CCNC | 4 |
| 2022 | Unsupervised Anomaly Detection in RS-485 Traffic using Autoencoders with Unobtrusive MeasurementabstractRemotely connected devices have been adopted in several industrial control systems (ICS) recently due to the advancement in the Industrial Internet of Things (IIoT). This led to new security vulnerabilities because of the expansion of the attack surface. Moreover, cybersecurity incidents in critical infrastructures are increasing. In the ICS, RS-485 cables are widely used in its network for serial communication between each component. However, almost 30 years ago, most of the industrial network protocols implemented over RS-485 such as Modbus were designed without security features. Therefore, anomaly detection is required in industrial control networks to secure communication in the systems. The goal of this paper is to study unsupervised anomaly detection in RS-485 traffic using autoencoders. Five threat scenarios in the physical layer of the industrial control network are proposed. The novelty of our method is that RS-485 traffic is collected indirectly by an analog-to-digital converter. In the experiments, multilayer perceptron (MLP), 1D convolutional, Long Short-Term Memory (LSTM) autoencoders are trained to detect anomalies. The results show that three autoencoders effectively detect anomalous traffic with F1-scores of 0.963, 0.949, and 0.928 respectively. Due to the indirect traffic collection, our method can be practically applied in the industrial control network. Pawissakan Chirupphapa, Md Delwar Hossain, Hiroshi Esaki, Hideya Ochiai |
IPCCC | 3 |
| 2021 | Multi-Type Anomaly Detection Based on Raw Network TrafficabstractIn this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively. Yuwei Sun, Hideya Ochiai, Hiroshi Esaki |
CCNC | 3 |
| 2021 | Towards Extracting Semantics of Network Config BlocksabstractConfiguring network devices is a main task of network operators. However, understanding and consistently updating network configuration files (config) is not an easy task especially in a large-scale and complicated networks. In this paper, we propose a semantic approach to provide better understanding of such config files, different from syntax based approaches. The key idea of the work is to extract semantics of blocks of the config files by document embedding techniques in NLP. This extraction enables us to understand context of config blocks with semantic similarity metrics instead of syntax similarity ones. Furthermore, this approach can be naturally extended to additional technical documents such as vendor’s manual documents to add more specific information on the semantics of configs. We first discuss the quality of the obtained semantics for several embedding techniques, by using clustering evaluations. We next demonstrate the effectiveness of our approach with two case studies with real network configs: (1) similar config block detection and (2) automatic labeling of config block with vendor’s documents. Kazuki Otomo, Satoru Kobayashi, Kensuke Fukuda, Osamu Akashi, Kimihiro Mizutani, Hiroshi Esaki |
COMPSAC | 6 |
| 2021 | Latent Semantics Approach for Network Log Analysis: Modeling and its application
Kazuki Otomo, Satoru Kobayashi, Kensuke Fukuda, Hiroshi Esaki |
IM | 4 |
| 2020 | Scan-Based Self Anomaly Detection: Client-Side Mitigation of Channel-Based Man-in-the-Middle Attacks Against Wi-FiabstractIn recent years, Wi-Fi has been used as a means of near-field high-speed communication across personal computers, smartphones and IoT devices such as hospital healthcare devices. Meanwhile, there have been many attempts to exploit equipment leveraging Wi-Fi. Among those exploits and attacks, an attack called channel-based man-in-the-middle (MITM) attack is a serious threat, since it can be used to exploit WPA2, which is a standard encryption and authentication scheme currently and widely in use. In this paper, we propose a scan-based self anomaly detection (SSAD), which is a client-side solution to detect and mitigate channel-based man-in-the-middle attacks using access point (AP) scans. SSAD enables wireless devices to verify the authenticity of wireless access points without the support of the access points, but running anomaly detection by themselves. This characteristic of SSAD, independent from access points, is especially favorable to mobile clients such as smartphones and IoT devices since they usually connect to multiple wireless access points. We implemented SSAD into an open source Wi-Fi client software and evaluated the effectiveness. With our experiments in some operational fields, we achieved 99% detection rate if an attacker was in the same room of a legitimate AP, and over 91% detection rate if an attacker and a legitimate AP were in different rooms. Sheng Gong, Hideya Ochiai, Hiroshi Esaki |
COMPSAC | 3 |
| 2020 | Blockchain-Based Federated Learning Against End-Point Adversarial Data CorruptionabstractWith the approach of 5G Society, more and more devices have been connected to the Internet, where information is stored, analyzed, and shared. Federated learning allows participants to train a machine learning model through sharing the parameters of it based on local training, instead of raw private data at local. In this research, we propose the implementation of the blockchain in federated learning for local parameters evaluation and global parameter aggregation, thus alleviating the influence of end-point adversarial training data. Besides, all updates of local parameters are encrypted and stored in a block of the blockchain after the consensus by the committee. We evaluate the performance of the scheme when adopting various types of corruption to the adversary's dataset, including noise with various degrees and circle occlusion with various diameters. At last, it shows robust and resilient performance compared with the traditional federated learning, achieving a validation accuracy rate of 0.957 when adding noise with a degree of 1.0, and one of 0.944 when adopting circle occlusion with a diameter of 28 pixels for the classification. Yuwei Sun, Hiroshi Esaki, Hideya Ochiai |
ICMLA | 2 |
| 2020 | Intrusion Detection with Segmented Federated Learning for Large-Scale Multiple LANsabstractTraditional approaches to cybersecurity issues usually protect users from attacks after the occurrence of specific types of attacks. Besides, patterns of recent cyberattacks tend to be changeable, which add up to unpredictability of them. On the other hand, machine learning, as a new method used to detect intrusion, is attracting more and more attention. Moreover, through the sharing of local training data, the centralized learning approach has proven to improve a model's performance. In this research, a segmented federated learning is proposed, different from a collaborative learning based on single global model in a traditional federated learning model, it keeps multiple global models which allow each segment of participants to conduct collaborative learning separately and rearranges the segmentation of participants dynamically as well. Furthermore, these multiple global models interact with each other for updating parameters, thus being adaptable to various participants' LANs. A dataset covering two months' traffic data from 20 participants' LANs in the LAN-Security Monitoring Project is used. We adopt three types of knowledge-based methods for labeling network events and train a CNN model based on the dataset. At last, we achieve validation accuracies of 0.923, 0.813 and 0.877 individually with these labeling methods. Yuwei Sun, Hideya Ochiai, Hiroshi Esaki |
IJCNN | 3 |
| 2020 | XGBoosted Misuse Detection in LAN-Internal Traffic DatasetabstractThere is an apparently increasing trend of cyber attacks towards LANs in recent years. It is getting more important to monitor the behaviors in LAN and detect intrusions rapidly and accurately. However, there are few studies for the behavior of LAN-internal communications. These works are faced with problems including (1) the lack of popular datasets especially captured from real-world LAN-internal communications, and (2) the lack of well-designed feature extraction for LAN communications. In this paper we propose (1) LAN traffic dataset with protocol based features and labels, and (2) XGBoost based misuse intrusion detection for LAN. After deploying 45 monitoring devices in distributed LANs in 10 countries, we detect malicious hosts from total 52,463 hosts appearing during Nov.1st, 2019 to May.5th, 2020 by extracting their behavioral features on each protocol. Evaluation results demonstrate that our misuse detection performs 97.5% in overall precision and 97.5% in overall recall. Besides, we also discovered that ARP, MDNS and NBNS are the top 3 protocols that influence the intrusion detection most in LAN. Pawissakan Chirupphapa, Hiroshi Esaki, Hideya Ochiai |
ISI | 3 |
| 2020 | Co-sound: An Interactive Medium with WebAR and Spatial Synchronization
Kazuma Inokuchi, Manabu Tsukada, Hiroshi Esaki |
ICEC | 3 |
| 2020 | Spider: Parallelizing Longest Prefix Matching with Optimization for SIMD InstructionsabstractLongest prefix matching (LPM) is a fundamental process in IP routing used not only in traditional hardware routers but also in modern software middleboxes such as the applications of Network Function Virtualization. However, the performance of recent LPM methods in software routers is insufficient for high-speed packet processing such as two or more 100 Gbps throughput. To improve the performance of LPM, we propose Spider, a new LPM method that achieves a fully parallelized LPM procedure using single instruction, multiple data (SIMD) instructions in a CPU. The evaluation shows that the proposed method has 1.8-1.9 times faster LPM performance compared with the state-of-the-art methods in this study area. We describe the Spider's lookup procedure fully parallelized by SIMD instructions and the design of the routing table efficiently processed by the procedure. We also report the following three evaluations: (1) The effect of parallelization by SIMD instructions on the performance of Spider; (2) the scalability of Spider with the number of CPU cores; and (3) the performance comparison with the previous methods in terms of randomly generated and real-trace traffic patterns. Yukito Ueno, Yohei Kuga, Hiroshi Esaki |
NetSoft | 4 |
| 2020 | Mitigating Privacy Leak by Injecting Unique Noise into the Traffic of Smart SpeakersabstractIn recent years, in the Internet, it is common to encrypt communication lines for the assumption that the contents of communication are eavesdropped, but even if the communication lines are secure, there are many cases in which the possibility of the contents of communication being leaked to a third party by a side-channel attack is not taken into account. Although it is important that the contents of all communication are not known by the third party, the information related to privacy may be leaked unintentionally by only encrypting traffics. In this study, we made smart speakers, an IoT device that has started to penetrate into our daily lives, to perform eight kinds of activities, and used their traffic data to estimate their activities with CNN, and we were able to estimate the activities with 98% accuracy. As a counter measure, we propose a method to reduce the accuracy of estimation by adding dummy packets to their communication traffic as noise. While adding random noise only reduced the accuracy of our machine learning model to 0.5 with 800 [packets/100msec] of noise, by adding well-designed noise, we were able to reduce the accuracy to 0.28 with 200 [packets/100msec] of noise of the same model. In this study, we made smart speakers, an IoT device that has started to penetrate into our daily lives, to perform eight kinds of activities, and used their traffic data to estimate their activities with CNN, and we were able to estimate the activities with 98% accuracy. As a counter measure, we propose a method to reduce the accuracy of estimation by adding dummy packets to their communication traffic as noise. While adding random noise only reduced the accuracy of our machine learning model to 0.5 with 800 [packets/100msec] of noise, by adding well-designed noise, we were able to reduce the accuracy to 0.28 with 200 [packets/100msec] of noise of the same model. While adding random noise only reduced the accuracy of our machine learning model to 0.5 with 800 [packets/100msec] of noise, by adding well-designed noise, we were able to reduce the accuracy to 0.28 with 200 [packets/100msec] of noise of the same model. Rikuta Furuta, Hideya Ochiai, Hiroshi Esaki |
SMARTCOMP | 3 |
| 2020 | AutoC2X: Open-source software to realize V2X cooperative perception among autonomous vehiclesabstractThe realization of vehicle-to-everything (V2X) communication enhances the capabilities of autonomous vehicles in terms of safety efficiency and comfort. In particular, sensor data sharing, known as cooperative perception, is a crucial technique to accommodate vulnerable road users in a cooperative intelligent transport system (ITS). In this regard, open-source software plays a significant role in prototyping, validation, and deployment. Specifically, in the developer community, Autoware is a popular open-source software for self-driving vehicles, and OpenC2X is an open-source experimental and prototyping platform for cooperative ITS. This paper reports on a system named AutoC2X to enable cooperative perception by using OpenC2X for Autoware-based autonomous vehicles. The developed system is evaluated by conducting field experiments involving real hardware. The results demonstrate that AutoC2X can deliver the cooperative perception message within 100 ms in the worst case. Manabu Tsukada, Takaharu Oi, Akihide Ito, Mai Hirata, Hiroshi Esaki |
VTC Fall | 5 |
| 2018 | Mining Causality of Network Events in Log DataabstractNetwork log messages (e.g., syslog) are expected to be valuable and useful information to detect unexpected or anomalous behavior in large scale networks. However, because of the huge amount of system log data collected in daily operation, it is not easy to extract pinpoint system failures or to identify their causes. In this paper, we propose a method for extracting the pinpoint failures and identifying their causes from network syslog data. The methodology proposed in this paper relies on causal inference that reconstructs causality of network events from a set of time series of events. Causal inference can filter out accidentally correlated events, thus it outputs more plausible causal events than traditional cross-correlation-based approaches can. We apply our method to 15 months' worth of network syslog data obtained from a nationwide academic network in Japan. The proposed method significantly reduces the number of pseudo correlated events compared with the traditional methods. Also, through three case studies and comparison with trouble ticket data, we demonstrate the effectiveness of the proposed method for practical network operation. Satoru Kobayashi, Kazuki Otomo, Kensuke Fukuda, Hiroshi Esaki |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2017 | Software defined media: Virtualization of audio-visual servicesabstractInternet-native audio-visual services are witnessing rapid development. Among these services, object-based audiovisual services are gaining importance. In 2014, we established the Software Defined Media (sDM) consortium to target new research areas and markets involving object-based digital media and Internet-by-design audio-visual environments. In this paper, we introduce the SDM architecture that virtualizes networked audio-visual services along with the development of smart buildings and smart cities using Internet of Things (IoT) devices and smart building facilities. Moreover, we design the SDM architecture as a layered architecture to promote the development of innovative applications on the basis of rapid advancements in software-defined networking (SDN). Then, we implement a prototype system based on the architecture, present the system at an exhibition, and provide it as an SDM API to application developers at hackathons. Various types of applications are developed using the API at these events. An evaluation of SDM API access shows that the prototype SDM platform effectively provides 3D audio reproducibility and interactiveness for SDM applications. Manabu Tsukada, Keiko Ogawa, Masahiro Ikeda, Takuro Sone, Kenta Niwa, Shoichiro Saito, Takashi Kasuya, Hideki Sunahara, Hiroshi Esaki |
ICC | 9 |
| 2017 | Mining causes of network events in log data with causal inferenceabstractNetwork log message (e.g., syslog) is valuable information to detect unexpected or anomalous behavior in a large scale network. However, pinpointing failures and their causes is not an easy problem because of a huge amount of system log data in daily operation. In this study, we propose a method extracting failures and their causes from network syslog data. The main idea of the method relies on causal inference that reconstructs causality of network events from a set of the time series of events. Causal inference allows us to reduce the number of correlated events by chance, thus it outputs more plausible causal events than a traditional cross-correlation based approach. We apply our method to 15 months network syslog data obtained in a nation-wide academic network in Japan. Our method significantly reduces the number of pseudo correlated events compared with the traditional method. Also, through two case studies and comparison with trouble ticket data, we demonstrate the effectiveness of our method for network operation. Satoru Kobayashi, Kensuke Fukuda, Hiroshi Esaki |
IM | 3 |
| 2017 | Overlaying and slicing for IoT era based on internet's end-to-end disciplineabstractThis paper discuss and analyze the IPv6 deployment in Japan, from the view point of large scale multiple-stack layer 3 network development and deployment, focusing on the future network development. Since IPv6 network does not have compatibility with IPv4 network, it is considered the dual-stack operation is mandatory. However, when we analyze the IPv6 deployment in Japan, we realized that the integration of multiple single-stack networks using a tunneling with “locator” function works well, both in wired and wireless infrastructures. Also, the paper discuss the Internet is going to third wave with IoT and entering from CPS to Cyber-Twin and Cyber-First. To come up with this situation, the paper proposes the system design and implementation should be based on “Internet-by-Design”, which preserve the key features the Internet. Finally, the practical examples of system design and implementation based on the “Internet-by-Design”. These are smart building/campus to integrate different IoT systems and the “locator” and “identifier” separation via “tunneling” in IP layer for large scale multiple-stack layer 3 network development. Hiroshi Esaki |
LANMAN | 1 |
| 2015 | A common data plane for multiple overlay networks
Kouji Okada, Yuji Sekiya, Hiroshi Esaki |
Comput. Networks | 4 |
| 2014 | ovstack: A protocol stack of common data plane for overlay networksabstractVarious overlay networks have been proposed and developed to increase flexibility on networks to address issues of the IP network. However, the existing overlay networks have two problems: 1) the topology of existing overlays is essentially full-mesh tunneling topology, 2) dependence of control plane and data plane. The full-mesh tunneling topology cannot enable the overlay routing for performance improvement of networks. The dependence of them causes complication of operations due to the isolation of overlay networks, and increases development costs. To improve the problems, we propose a new abstraction layer provides a common architecture for data planes of overlay networks that can deploy overlay routing. Based on the architecture, we design and implement a protocol stack, called ovstack. In this paper, we describe the architecture, design and implementation, then evaluate the performance of overlays including ovstack. The ovstack can contribute to construct more flexible overlay networks on the current networks easily. Kouji Okada, Yuji Sekiya, Hiroshi Esaki |
NOMS | 4 |
| 2013 | An Analysis of Players and Bots Behaviors in MMORPGabstract"Bot", automatic robot software, has been one of most serious problems in Massively Multiplayer Online Role Playing Game (MMORPG). Bots earn much more money in a virtual world than human players, and finally collapse balance and fairness of the MMORPG. At present, many techniques have been applied to detect and exterminate bots. However, they have a common problem that the technique effective in a certain MMORPG is not equally effective in other MMORPGs, thus no general method to detect bots has been established. Toward establishing such general technique, we analyze behavioral patterns of human players and bots in server-side game log data with two commonly available features characterizing users (human players and bots): location-based information (i.e., speed of players) and action frequency information (i.e., action count per fixed time slot). The main findings of our analysis are as follows: (1) The variation of the speed of bots is smaller than that of humans (i.e, the movement of bots is more efficient). However, the discriminative power of this location-based feature is not so significant in MMORPG, while it showed good performance in First Person Shooting (FPS) game. (2) Action count and battle count indicate more discriminative power than the speed feature. In particular, the action count is more robust than battle count against the size of the time slot. Yutaro Mishima, Kensuke Fukuda, Hiroshi Esaki |
AINA | 3 |
| 2013 | Implementation and Operation of User Defined Network on IaaS Clouds using Layer 3 Overlay
Yuji Sekiya, Hiroshi Esaki |
CLOSER | 3 |
| 2013 | Mining anomalous electricity consumption using Ensemble Empirical Mode DecompositionabstractSensor deployments in large buildings allow the administrators to supervise the building infrastructure and identify abnormalities. Nevertheless, the numerous data streams reported by the increasing number of sensors overwhelm the building administrators. We propose a methodology that assists them to identify abnormal devices usages. The proposed method takes advantage of Ensemble Empirical Mode Decomposition (E-EMD) to uncover the patterns of power-draw signals, thereby enabling us to estimate the intrinsic inter-device correlations. By monitoring the devices correlations over time we compute the usual usage of the devices and report the devices that deviate from their normal usage. Our evaluation with 10 weeks of real data shows the efficiency of the proposed method to uncover the devices intrinsic relationships and detect peculiar events that require the administrators attention. Romain Fontugne, Nicolas Tremblay, Pierre Borgnat, Patrick Flandrin, Hiroshi Esaki |
ICASSP | 5 |
| 2013 | Nine years of observing traffic anomalies: Trending analysis in backbone networks
Youngjoon Won, Romain Fontugne, Kenjiro Cho, Hiroshi Esaki, Kensuke Fukuda |
IM | 4 |
| 2013 | Strip, bind, and search: a method for identifying abnormal energy consumption in buildingsabstractA typical large building contains thousands of sensors, monitoring the HVAC system, lighting, and other operational sub-systems. With the increased push for operational efficiency, operators are relying more on historical data processing to uncover opportunities for energy-savings. However, they are overwhelmed with the deluge of data and seek more efficient ways to identify potential problems. In this paper, we present a new approach called the Strip, Bind and Search (SBS); a method for uncovering abnormal equipment behavior and in-concert usage patterns. SBS uncovers relationships between devices and constructs a model for their usage pattern relative to other devices. It then flags deviations from the model. We run SBS on a set of building sensor traces; each containing hundred sensors reporting data flows over 18 weeks from two separate buildings with fundamentally different infrastructures. We demonstrate that, in many cases, SBS uncovers misbehavior corresponding to inefficient device usage that leads to energy waste. The average waste uncovered is as high as 2500~kWh per device. Romain Fontugne, Jorge Ortiz 0001, Nicolas Tremblay, Pierre Borgnat, Patrick Flandrin, Kensuke Fukuda, David E. Culler, Hiroshi Esaki |
IPSN | 8 |
| 2013 | Synoptic Graphlet: Bridging the Gap Between Supervised and Unsupervised Profiling of Host-Level Network TrafficabstractEnd-host profiling by analyzing network traffic comes out as a major stake in traffic engineering. Graphlet constitutes an efficient and common framework for interpreting host behaviors, which essentially consists of a visual representation as a graph. However, graphlet analyses face the issues of choosing between supervised and unsupervised approaches. The former can analyze a priori defined behaviors but is blind to undefined classes, while the latter can discover new behaviors at the cost of difficult a posteriori interpretation. This paper aims at bridging the gap between the two. First, to handle unknown classes, unsupervised clustering is originally revisited by extracting a set of graphlet-inspired attributes for each host. Second, to recover interpretability for each resulting cluster, a synoptic graphlet, defined as a visual graphlet obtained by mapping from a cluster, is newly developed. Comparisons against supervised graphlet-based, port-based, and payload-based classifiers with two datasets demonstrate the effectiveness of the unsupervised clustering of graphlets and the relevance of the a posteriori interpretation through synoptic graphlets. This development is further complemented by studying evolutionary tree of synoptic graphlets, which quantifies the growth of graphlets when increasing the number of inspected packets per host. Yosuke Himura, Kensuke Fukuda, Kenjiro Cho, Pierre Borgnat, Patrice Abry, Hiroshi Esaki |
IEEE/ACM Trans. Netw. | 6 |
| 2011 | Hop-by-hop reliable, parallel message propagation for intermittently-connected mesh networksabstractWireless mesh networks suffer from intermittent connectivity, and thus hop-by-hop reliability and parallel message propagation, which DTN researches have explored, can be applied to allow scalable message propagation over such challenged network environments. We implemented those communication schemes onto UTMesh - 50-node scale wireless mesh network testbed, and studied the delivery patterns. On the evaluation result with UTMesh, we have confirmed (1) that hop-by-hop reliability scheme achieves scalable message propagation (e.g., 23 hops), and (2) that message propagation speed increases as the redundancy-level increases. We have also observed that the smallest hop count path does not always achieve the fastest message delivery. This was probably because longer distant links were unstable and message paths over short distant links provided faster propagation. Hideya Ochiai, Masaya Nakayama, Hiroshi Esaki |
WOWMOM | 3 |
| 2009 | An Automatic and Dynamic Parameter Tuning of a Statistics-Based Anomaly Detection AlgorithmabstractThe detection of anomalies in network traffic is a crucial issue affecting the security of Internet users. A statistical network anomaly detection algorithm is a promising way of detecting such anomalies, however, it has to be given appropriate parameters for accurate detection and identification. In general, it is very difficult to obtain appropriate parameter settings a priori, because network traffic is not stable in time or space. Thus, although many anomaly detection methods have been proposed, there has been little discussion about their parameter tunings. In this paper, we investigate an automatic and dynamic parameter tuning of a statistical network traffic anomaly detection method. In particular, we clarify whether one can consistently use the best parameter fixed for a certain instance; this choice clearly depends on the macroscopic and dynamic behavior of Internet traffic anomalies. We ascertain the appropriate learning period for setting a parameter of an anomaly detection algorithm based on a sketch and multi-scale gamma-function model by using real network traces measured in a trans-Pacific link over a period of six months. The main results of our study are as follows: (1) Without learning, the best parameter varies day by day. (2) With a longer learning period, the best parameter setting is affected by significant data during the learning period. (3) The appropriate period of the learning is about 3 days. (4) The performance degradation from introducing dynamic parameter tuning is 17% in the best case. Yosuke Himura, Kensuke Fukuda, Kenjiro Cho, Hiroshi Esaki |
ICC | 4 |
| 2009 | Inferring POP-Level ISP Topology through End-to-End Delay Measurement
Kaoru Yoshida, Yutaka Kikuchi, Masateru Yamamoto, Yoriko Fujii, Kenichi Nagami, Ikuo Nakagawa, Hiroshi Esaki |
PAM | 7 |
| 2008 | Observing slow crustal movement in residential user trafficabstractIt is often argued that rapidly increasing video content along with the penetration of high-speed access is leading to explosive growth in the Internet traffic. Contrary to this popular claim, technically solid reports show only modest traffic growth worldwide. This paper sheds light on the causes of the apparently slow growth trends by analyzing commercial residential traffic in Japan where the fiber access rate is much higher than other countries. We first report that Japanese residential traffic also has modest growth rates using aggregated measurements from six ISPs. Then, we investigate residential per-customer traffic in one ISP by comparing traffic in 2005 and 2008, before and after the advent of YouTube and other similar services. Although at first glance a small segment of peer-to-peer users still dictate the overall volume, they are slightly decreasing in population and volume share. Meanwhile, the rest of the users are steadily moving towards rich media content with increased diversity. Surely, a huge amount of online data and abundant headroom in access capacity can conceivably lead to a massive traffic growth at some point in the future. The observed trends, however, suggest that video content is unlikely to disastrously overflow the Internet, at least not anytime soon. Kenjiro Cho, Kensuke Fukuda, Hiroshi Esaki, Akira Kato |
CoNEXT | 3 |
| 2008 | On seamless connectivity over multi-radio and multi-channel wireless mesh networksabstractIn IEEE802.11 wireless mesh networks (WMN), we had suffered from performance degradation caused by contention and interference. To avoid the issue with a reasonable cost, we have been working on the configuration where nodes are equipped with multiple commodity IEEE802.11 interfaces and antennas. Although the WMNs of the configuration were segmented by multi-channelized links, traditional applications needed it to be a single-tier and easy-to-use network. In this paper, we present a scheme introducing a virtual link layer that allows mobile nodes to move around without changing its identifier and losing its connectivity to such kind of WMNs. We have implemented a prototype system of our scheme using the click modular router framework [2]. We have confirmed that existing applications, such as DHCP and mDNS, run on the multi-radio and multichannel WMN without any modification. Sho Fujita, Tadashi Yasumoto, Hiroshi Esaki |
CoNEXT | 3 |
| 2006 | Collecting Adaptive Data for Isolated Wireless Sensors with Patrol Nodes in Live E!abstractRecently, Technology of sensor networks develops rapidly. In addition, people have started utilizing many kinds of sensors. Sensors independently collect environmental information all over the world. Unfortunately those sensed data are not shared and open to the public. Therefore, we have constructed super-large-scale sensor network system to share sensed data collected from sensors all over the world. We call such a project Live E!. In a part of Live E!, To sense a public area in whole, we assume public objects(mailbox, bus stop, dumpster) uniformly allocate in a district evenly is equipped with a sensor and a wireless device. The public objects often dose not have connectivity to a network. Those are Isolated Wireless Sensor Nodes (ISNs). .. Then, we need to consider the way of collecting from the ISNs. Accordingly, we utilize a Patrol Node (PN) that moves around ISNs, and collects sensed data from ISNs. The ISN stores the sensed data until the time PN comes back. However, because the communication time to the PN depends on the speed of the PN, ISNs can not necessarily transmit all the maintained sensed data to the PN. Therefore, we suggest that the ISN should send adaptive data according to the speed of PN. We propose a technique for transmitting adaptive data depending on the movement of the PN. In addition, we have implemented a prototype of our proposal and verified the effectiveness of our proposed system. Finally, we show that our system improves the performance of the sensor network. Hiroki Ishizuka, Kenji Sasaki, Satoshi Matsuura, Makoto Kamiya, Hideki Sunahara, Hiroshi Esaki |
MDM | 6 |
| 2006 | The impact and implications of the growth in residential user-to-user trafficabstractIt has been reported worldwide that peer-to-peer traffic is taking up a significant portion of backbone networks. In particular, it is prominent in Japan because of the high penetration rate of fiber-based broadband access. In this paper, we first report aggregated traffic measurements collected over 21 months from seven ISPs covering 42% of the Japanese backbone traffic. The backbone is dominated by symmetric residential traffic which increased 37%in 2005. We further investigate residential per-customer trafficc in one of the ISPs by comparing DSL and fiber users, heavy-hitters and normal users, and geographic traffic matrices. The results reveal that a small segment of users dictate the overall behavior; 4% of heavy-hitters account for 75% of the inbound volume, and the fiber users account for 86%of the inbound volume. About 63%of the total residential volume is user-to-user traffic. The dominant applications exhibit poor locality and communicate with a wide range and number of peers. The distribution of heavy-hitters is heavy-tailed without a clear boundary between heavy-hitters and normal users, which suggests that users start playing with peer-to-peer applications, become heavy-hitters, and eventually shift from DSL to fiber. We provide conclusive empirical evidence from a large and diverse set of commercial backbone data that the emergence of new attractive applications has drastically affected traffic usage and capacity engineering requirements. Kenjiro Cho, Kensuke Fukuda, Hiroshi Esaki, Akira Kato |
SIGCOMM | 3 |
| 1999 | Flow aggregated, traffic driven label mapping in label-switching networksabstractLabel-switching technology enables high performance and flexible layer-3 packet forwarding based on the fixed-length label information that is mapped to the layer-3 packet stream. A label-switching router (LSR) forwards layer-3 packets based on their layer-3 address information or their label information that is mapped to the layer-3 address information. Two label-mapping policies have been proposed. One is traffic driven mapping, where the label is mapped for a layer-3 packet stream of each host-pair according to the actual packet arrival. The other is topology driven mapping, where the label is mapped in advance for a layer-3 packet stream toward the same destination network, regardless of actual packet arrival to the LSR. This paper evaluates the required number of labels under each of these two label-mapping policies using real backbone traffic traces. The evaluation shows that both label-mapping policies require a large number of labels. In order to reduce the required number of labels, we propose a label-mapping policy that is a combination of the two label-mapping policies above. This is traffic-driven label mapping for the packet stream toward the same destination network. The evaluation shows that the proposed label-mapping policy requires only about one-tenth as many labels as the traffic-driven label mapping for the host-pair packet stream and the topology-driven label mapping for the destination-network packet stream. Kenichi Nagami, Hiroshi Esaki, Yasuhiro Katsube, Osamu Nakamura |
IEEE J. Sel. Areas Commun. | 2 |
| 1997 | Internetworking based on cell switch router-architecture and protocol overviewabstractThis paper describes an internetworking architecture and related protocol overview based on routers that have asynchronous transfer mode (ATM) cell switching capability in addition to conventional Internet protocol (IP) packet forwarding. The proposed architecture can provide high-throughput and low-latency switched paths for individual application flows or a group of application flows while retaining current router-based internetworking architecture. The proposed router is able to establish the switched path based on the characteristics of flows, e.g., arrival of a data packet with specific upper layer protocols or arrival of more than a certain amount of data packets in a predetermined period, as well as by the reception of an IP-layer resource reservation request, such as resource reservation protocol (RSVP). One important feature that is provided by the proposed router is interoperability with the emerging ATM network platform specified by the ATM Forum and the telecommunications sector of the International Telecommunications Union (ITU-T). The proposed routers can be interconnected with each other over the point-to-point synchronous optical network link as well as over the ATM network platform, which provides permanent virtual channel, virtual path, or switched virtual channel (SVC) services. That enables network carriers to provide Internet/intranet services as well as others, such as telephony, ATM/time division multiplexing leased line, or native ATM SVC services. Yasuhiro Katsube, Kenichi Nagami, Shigeo Matsuzawa, Hiroshi Esaki |
Proc. IEEE | 4 |