VLDB 2026 Research / reviewers in the wild / expert
Takeshi Sugawara 0001
dblp:68/2734
· DBLP profile ↗
39ranked-venue papers
7as first author
23since 2021 · last 2026
0000-0001-9356-534XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 5 first-author · 21 since 2021Systems, architecture and hardware · 4 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tight Multi-user Security of CCM and Enhancement by Tag-Based Key Derivation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ACNS (1) | 3 |
| 2026 | Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CRYPTO (6) | 8 |
| 2026 | The Heat is On: Understanding and Mitigating Vulnerabilities of Thermal Image Perception in Autonomous Systems
S. Hrushikesh Bhupathiraju, Shaoyuan Xie, Michael Clifford, Qi Alfred Chen, Takeshi Sugawara 0001, Sara Rampazzi |
NDSS | 5 |
| 2026 | AESpoly: Symmetric-Key Cryptographic Designs Using Instruction-Level Parallelism Between AES and Polynomial Hash
Yukihito Hiraga, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
SP | 4 |
| 2026 | To Go or Not to Go: Shedding Light on Traffic Light Signal Manipulation and Defense StrategiesabstractConnected autonomous vehicles must accurately detect, and adhere, to traffic light signals to ensure safe and efficient traffic flow. Misinterpretation of traffic lights can result in potential safety issues for drivers and pedestrians. Recent work demonstrated attacks that projected structured light patterns onto vehicle cameras, causing traffic signs and traffic light color misinterpretation. In this work, we characterize a novel vulnerability of traffic light physical structures that can be exploited by attackers to deceive recognition systems. When visible and invisible laser light is projected onto traffic lights, it is scattered by its internal reflectors. To a vehicle’s camera, the reflected light appears the same as a genuine light source, resulting in dangerous red and green traffic light status misclassifications. We evaluate our attack against three state-of-the-art traffic light recognition models and show successful misclassification up to 25 m from the target traffic light. Furthermore, the attack succeeds both in daytime and nighttime conditions both in static and moving vehicle scenarios up to 10 km/h speed. To mitigate this threat, we propose a detection system based on light texture patterns that achieve 100% TPR and 1.8% FPR in our real-world scenarios. S. Hrushikesh Bhupathiraju, Takami Sato, Michael Clifford, Takeshi Sugawara 0001, Qi Alfred Chen, Sara Rampazzi |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2026 | Adversarial Beats: Feasibility Study of Spoofed Arrhythmia in Automated Electrocardiogram DiagnosisabstractThis study aims to assess the feasibility of applying adversarial examples to attack cardiac diagnosis systems powered by machine learning algorithms. To achieve this, we introduce “ adversarial beats ,” which are adversarial perturbations that are tailored specifically against classification systems designed to diagnose electrocardiograms (ECGs). We first formulated an algorithm to generate adversarial examples for multiple neural network models for ECG classification and studied their attack success rates. Next, to evaluate their feasibility in a physical environment, we mounted a hardware attack by designing a malicious signal generator that injects adversarial beats into ECG sensor readings using commercial off-the-shelf hardware. To the best of our knowledge, our research is the first to evaluate the proficiency of adversarial examples for ECGs in a physical setup. Our real-world experiments demonstrate that, against an automated ECG diagnosis apparatus, our attack method can fake the presence of potential signs of cardiomyopathy with approximately 42.1% chance of success and the attacker can repeat the attack until a fraudulent insurance claim or other health care fraud is established. Based on the comprehensive feasibility study of attacks using adversarial beats, we conclude that the attacks have a sufficient chance to succeed such that an attacker may be incentivized to fake the presence of cardiomyopathy, potentially leading to unnecessary medication prescriptions and fraudulent medical insurance claims. Taiga Ono, Takeshi Sugawara 0001, Jun Sakuma, Tatsuya Mori 0003 |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2025 | Beyond-Birthday-Bound Security with HCTR2: Cascaded Construction and Tweak-Based Key Derivation
Yu Long Chen, Yukihito Hiraga, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ASIACRYPT (1) | 6 |
| 2025 | Poster: Recapture Detection Using Disparity Map Obtained from Dual-Pixel Image SensorsabstractRecapturing computer monitors with a camera is a common threat to cryptographic techniques designed to verify the origin of images and prevent AI-generated deepfakes. Although depth information can help distinguish a real-world scene from a flat computer monitor, incorporating additional depth sensors is often cost-prohibitive. To address this challenge, we explore the use of dual-pixel (DP) image sensors commonly found in still and smartphone cameras for fast autofocus, as a means to extract depth information for distinguishing real scenes from recaptured ones, without requiring additional hardware. Our signal processing pipeline is composed of (i) a stereo matching algorithm to obtain a disparity map using a pair of images generated from a DP image sensor and (ii) plane fitting to evaluate the flatness of the scene. Our proof-of-concept evaluation on a real-world DP image dataset demonstrates that the proposed method detects recaptured images at 100% accuracy. Similarly, it successfully distinguishes real-world scenes from recaptured deepfake images with >98% accuracy. Tetsu Ishizue, Sara Rampazzi, Takeshi Sugawara 0001 |
CCS | 3 |
| 2025 | The Exact Multi-User Security of Key-Alternating Feistel Ciphers with a Single Permutation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CRYPTO (5) | 3 |
| 2025 | The Multi-user Security of GCM-SST and Further Enhancements
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ISC | 3 |
| 2025 | Sound of Interference: Electromagnetic Eavesdropping Attack on Digital Microphones Using Pulse Density Modulation
Arifu Onishi, S. Hrushikesh Bhupathiraju, Rishikesh Bhatt, Sara Rampazzi, Takeshi Sugawara 0001 |
USENIX Security Symposium | 5 |
| 2024 | KIVR: Committing Authenticated Encryption Using Redundancy and Application to GCM, CCM, and More
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ACNS (1) | 3 |
| 2024 | The Exact Multi-user Security of 2-Key Triple DES
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CT-RSA | 3 |
| 2024 | The Exact Multi-user Security of (Tweakable) Key Alternating Ciphers with a Single Permutation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
EUROCRYPT (1) | 3 |
| 2024 | Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign Perception
Takami Sato, S. Hrushikesh Bhupathiraju, Michael Clifford, Takeshi Sugawara 0001, Qi Alfred Chen, Sara Rampazzi |
NDSS | 4 |
| 2024 | AquaSonic: Acoustic Manipulation of Underwater Data Center Operations and Resource ManagementabstractUnderwater data centers (UDCs) hold promise as next-generation data storage due to their energy efficiency and environmental sustainability benefits. While the natural cooling properties of water save power, the isolated aquatic environment and long-range sound propagation characteristics in water create unique vulnerabilities which differ from those of on-land data centers. Our research discovers the unique vulnerabilities of fault-tolerant storage devices, resource allocation software, and distributed file systems to acoustic injection attacks in UDCs. With a realistic testbed approximating UDC server operations, we empirically characterize the capabilities of acoustic injection underwater and find that an attacker can reduce fault-tolerant RAID 5 storage system throughput by 17% up to 100%. Our closed-water analyses reveal that an attacker can (i) cause unresponsiveness and automatic node removal in a distributed filesystem with only 2.4 minutes of sustained acoustic injection, (ii) induce a distributed database’s latency to increase by up to 92.7% to reduce system reliability, and (iii) induce load-balance managers to redirect up to 74% of resources to a target server to cause overload or force resource colocation. Furthermore, we perform open-water experiments in a lake and find that an attacker can cause controlled throughput degradation at the maximum allowable distance of 6.35 m using a commercial speaker. We also investigate and discuss the effectiveness of standard defenses against acoustic injection attacks. Finally, we formulate a novel machine learning-based detection system that reaches 0% False Positive Rate and 98.2% True Positive Rate trained on our dataset of profiled hard disk drives under 30-second FIO benchmark execution. With this work, we aim to help manufacturers proactively protect UDCs against acoustic injection attacks and ensure the security of subsea computing infrastructures. Jennifer Sheldon, Weidong Zhu 0002, Adnan Abdullah, S. Hrushikesh Bhupathiraju, Takeshi Sugawara 0001, Kevin R. B. Butler, Md Jahidul Islam, Sara Rampazzi |
SP | 5 |
| 2023 | Permutation-Based Deterministic Authenticated Encryption with Minimum Memory Size
Yukihito Hiraga, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ISC | 4 |
| 2023 | You Can't See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks
S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara 0001, Z. Morley Mao, Sara Rampazzi |
USENIX Security Symposium | 4 |
| 2023 | EMI-LiDAR: Uncovering Vulnerabilities of LiDAR Sensors in Autonomous Driving Setting using Electromagnetic InterferenceabstractAutonomous Vehicles (AVs) using LiDAR-based object detection systems are rapidly improving and becoming an increasingly viable method of transportation. While effective at perceiving the surrounding environment, these detection systems are shown to be vulnerable to attacks using lasers which can cause obstacle misclassifications or removal. These laser attacks, however, are challenging to perform, requiring precise aiming and accuracy. Our research exposes a new threat in the form of Intentional Electro-Magnetic-Interference (IEMI), which affects the time-of-flight (TOF) circuits that make up modern LiDARs. We show that these vulnerabilities can be exploited to force the AV Perception system to misdetect, misclassify objects, and perceive non-existent obstacles. We evaluate the vulnerability in three AV perception modules (PointPillars, PointRCNN, and Apollo) and show how the classification rate drops below 50%. We also analyze the impact of the IEMI injection on two fusion models (AVOD and Frustum-ConvNet) and in real-world scenarios. Finally, we discuss potential countermeasures and propose two strategies to detect signal injection. S. Hrushikesh Bhupathiraju, Jennifer Sheldon, Luke A. Bauer, Vincent Bindschaedler, Takeshi Sugawara 0001, Sara Rampazzi |
WISEC | 5 |
| 2022 | The Multi-User Security of Triple Encryption, Revisited: Exact Security, Strengthening, and Application to TDESabstractWe study the security of triple encryption in the multi-user setting with its application to Triple DES (TDES) in mind. Although depreciation of TDES is a global trend, the migration will take the next decade, considering the billions of TDES hardware the industry has invested so far. The multi-user security captures the reality of practical systems with multiple users, substantially impacts security, and is already considered in practical protocols such as TLS 1.3. The best multi-user lower bound of TDES is 43-(3/2) \cdot łog_2 u bits with u users, which is tractable with a standard PC and is unacceptably low. We devise a new proof to improve the multi-user security and show its tightness by giving a concrete attack. The new bound with the TDES parameters is 79-(1/2) \cdot łog_2 u bits. We also propose TEFX that strengthens triple encryption with the FX construction while preserving the compatibility with legacy hardware. TDES with TEFX achieves the multi-user security of 114-(1/2) \cdot łog_2 q bits with q TEFX calls: it achieves 84.5 bits with 2^40 users and 2^21 TEFX calls for each user, which is comparable to that of AES (128-40=88 bits). Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001, Kan Yasuda |
CCS | 3 |
| 2022 | Poster: Inaudible Acoustic Noise from Silicon Capacitors for Voice-Command InjectionabstractMulti-layer ceramic capacitors (MLCCs), commonly used in electronics products, can generate acoustic noise driven by electrical deviation. Such acoustic noise has been exploited to attack systems' security. In particular, CapSpeaker silently delivers voice commands to voice-controllable systems using inaudible acoustic noise and intermodulation distortion (IMD). Silicon capacitor is an emerging technology that achieves a larger capacitance with a smaller footprint fabricated with semiconductor manufacturing processes using different structures and materials. Do silicon capacitors still generate acoustic noise despite the differences? We positively answer the question by experimentally showing that an off-the-shelf silicon capacitor generates audible acoustic noise through IMD; CapSpeaker is still feasible with the new capacitor Kohei Doi, Takeshi Sugawara 0001 |
CCS | 2 |
| 2022 | Secret Can Be Public: Low-Memory AEAD Mode for High-Order Masking
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CRYPTO (3) | 3 |
| 2021 | Double-Block-Length Hash Function for Minimum Memory Size
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
ASIACRYPT (3) | 3 |
| 2020 | Lightweight Authenticated Encryption Mode Suitable for Threshold Implementation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
EUROCRYPT (2) | 3 |
| 2020 | Light Commands: Laser-Based Audio Injection Attacks on Voice-Controllable Systems
Takeshi Sugawara 0001, Benjamin Cyr, Sara Rampazzi, Daniel Genkin, Kevin Fu |
USENIX Security Symposium | 1 |
| 2019 | Side-Channel Leakage of Alarm Signal for a Bulk-Current-Based Laser Sensor
Yang Li 0001, Ryota Hatano, Sho Tada, Kohei Matsuda, Noriyuki Miura, Takeshi Sugawara 0001, Kazuo Sakiyama |
Inscrypt | 6 |
| 2018 | Sensor CON-Fusion: Defeating Kalman Filter in Signal Injection AttackabstractIn recent years, information systems have become increasingly able to interact with the real world by using relatively cheap connected embedded devices. In such systems, sensors are crucial components because systems can observe the real world only through sensors. Recently, there have been emerging threats to sensors, which involve the injection of false information in the physical/analog domain. To counter such attacks, sensor fusion is considered a promising approach because the robustness of a measurement can be improved by combining data from redundant sensors. However, sensor fusion algorithms were not originally designed to consider security, and thus their effectiveness is unclear. For this reason, in this paper, we evaluate in detail the security of sensor fusion. Notably, we consider a sensor fusion scenario that involves measuring inclination, with a combination of an accelerometer, gyroscope, and magnetometer using Kalman filter. Based on a theoretical analysis of the algorithm, two concrete attacks that defeat the sensor fusion are proposed. The feasibility of the proposed attacks is verified by performing experiments in emulated and real environments. We also propose a countermeasure that thwarts the new attacks. Furthermore, we logically prove that the proposed countermeasure detects all possible attacks. Shoei Nashimoto, Daisuke Suzuki, Takeshi Sugawara 0001, Kazuo Sakiyama |
AsiaCCS | 3 |
| 2018 | Recovering Memory Access Sequence with Differential Flush+Reload Attack
Zhiwei Yuan, Yang Li 0001, Kazuo Sakiyama, Takeshi Sugawara 0001, Jian Wang 0038 |
ISPEC | 4 |
| 2017 | Exploiting Bitflip Detector for Non-invasive Probing and its Application to Ineffective Fault AnalysisabstractMatsuda et al. proposed a countermeasure against laser fault injection that uses distributed on-chip sensors. The sensor raises an alarm by detecting an electrical phenomenon caused in conjunction with a bitflip. A cryptographic module can stop releasing a faulty ciphertext by using the alarm. In this paper, security and limitation of the countermeasure by Matsuda et al. is rigorously evaluated. We show that an attacker can get side-channel information by observing how the sensors react to laser fault injection. That enables the attacker to probe intermediate values in a chip non-invasively. On the one hand, under a chosen-plaintext setting, the laser-based probing enables to run the conventional probing attack on AES by Schmidt and Kim. On the other hand, under a ciphertext-only setting, the laser-based probing raises a new challenge: the attacker is given correct ciphertexts and corresponding single-bit probing results. We propose a new ineffective fault analysis against AES based on linear cryptanalysis that can be used in the above setting. Takeshi Sugawara 0001, Natsu Shoji, Kazuo Sakiyama, Kohei Matsuda, Noriyuki Miura, Makoto Nagata |
FDTC | 1 |
| 2016 | Output Masking of Tweakable Even-Mansour Can Be Eliminated for Message Authentication Code
Shoichi Hirose, Yusuke Naito 0001, Takeshi Sugawara 0001 |
SAC | 3 |
| 2014 | Reversing Stealthy Dopant-Level Circuits
Takeshi Sugawara 0001, Daisuke Suzuki, Ryoichi Fujii, Shigeaki Tawa, Ryohei Hori, Mitsuru Shiozaki, Takeshi Fujino |
CHES | 1 |
| 2013 | On Measurable Side-Channel Leaks Inside ASIC Design Primitives
Takeshi Sugawara 0001, Daisuke Suzuki, Minoru Saeki, Mitsuru Shiozaki, Takeshi Fujino |
CHES | 1 |
| 2012 | Circuit Simulation for Fault Sensitivity Analysis and Its Application to Cryptographic LSIabstractCircuit simulation method for Fault Sensitivity Analysis (FSA) is proposed. The simulation can be used both for (i) security evaluation before fabrication and (ii) investigation of leak mechanism. The proposed method extracts fault sensitivity data from post place-and-route logic simulation results, thus it can easily be integrated with conventional LSI design flow. As a proof of concept, the proposed method is applied to netlist of an AES implementation on 130-nm SASEBO LSI. In the experiment, key recovery attack is successfully recreated using simulated data of a standard implementation (AES_Comp). In addition, to bridge a gap between the simulation and real measurement, we model the effect of induced timing jitter (measurement noise) on the resulting correlation. Takeshi Sugawara 0001, Daisuke Suzuki, Toshihiro Katashita |
FDTC | 1 |
| 2012 | Fair and Consistent Hardware Evaluation of Fourteen Round Two SHA-3 CandidatesabstractThe first contribution of our paper is that we propose a platform, a design strategy, and evaluation criteria for a fair and consistent hardware evaluation of the second-round SHA-3 candidates. Using a SASEBO-GII field-programmable gate array (FPGA) board as a common platform, combined with well defined hardware and software interfaces, we compare all 256-bit version candidates with respect to area, throughput, latency, power, and energy consumption. Our approach defines a standard testing harness for SHA-3 candidates, including the interface specification for the SHA-3 module on our testing platform. The second contribution is that we provide both FPGA and 90-nm CMOS application-specific integrated circuit (ASIC) synthesis results and thereby are able to compare the results. Our third contribution is that we release the source code of all the candidates and by using a common, fixed, publicly available platform, our claimed results become reproducible and open for a public verification. Miroslav Knezevic, Kazuyuki Kobayashi, Jun Ikegami, Shin'ichiro Matsuo, Akashi Satoh, Ünal Koçabas, Junfeng Fan, Toshihiro Katashita, Takeshi Sugawara 0001, Kazuo Sakiyama, Ingrid Verbauwhede, Kazuo Ohta, Naofumi Homma, Takafumi Aoki |
IEEE Trans. Very Large Scale Integr. Syst. | 9 |
| 2009 | High-Performance Hardware Architectures for Galois Counter ModeabstractVarious high-performance hardware architectures for Galois counter mode (GCM) in conjunction with various advanced encryption standard (AES) circuits and multiplier-adders are proposed. A total of 17 GCM-AES circuits were synthesized by using a 130-nm CMOS standard cell library, and the trade-offs between speed and hardware resources were evaluated. Our flexible architectures achieved a wide variety of performances from compact (2.56 Gbps with 34.5 Kgates) to high speed (62.6 Gbps with 979.3 Kgates). All of our architectures support key sizes of 128, 192, and 256 bits, while only one previous approach does. Even with variable-length key support, our architecture also achieved the highest hardware efficiency (defined as throughput per gate) among the designs using the same generation of process technology. Akashi Satoh, Takeshi Sugawara 0001, Takafumi Aoki |
IEEE Trans. Computers | 2 |
| 2008 | High-Performance Concurrent Error Detection Scheme for AES Hardware
Akashi Satoh, Takeshi Sugawara 0001, Naofumi Homma, Takafumi Aoki |
CHES | 2 |
| 2008 | High-performance ASIC implementations of the 128-bit block cipher CLEFIAabstractIn the present paper, we introduce high-performance hardware architectures for the 128-bit block cipher CLEFIA and evaluate their ASIC performances in comparison with the ISO/IEC 18033-3 standard block ciphers (AES, Camellia, SEED, CAST-128, MISTY1, and TDEA). We designed five types of hardware architectures for CLEFIA, combining two loop structures and three F-functions. These designs were synthesized with a 90-nm CMOS standard cell library, and size and speed performances were evaluated. The highest hardware efficiency (defined as throughput/gates) obtained was 400.96 Kbps/gates, which is 1.5 times higher than previously achieved efficiencies. Takeshi Sugawara 0001, Naofumi Homma, Takafumi Aoki, Akashi Satoh |
ISCAS | 1 |
| 2007 | A High-Performance ASIC Implementation of the 64-bit Block Cipher CAST-128abstractThe authors propose a compact hardware architecture for the 64-bit block cipher CAST-128, which is one of the ISO/IEC 18033-3 standard algorithms. Part of the complexity of CAST-128 is its use of various S-boxes in various sequences, and three types of f-function are switched depending on the round numbers. Therefore a large amount of hardware resources are required for a straight-forward implementation. In order to create compact CAST-128 hardware, the authors minimized the number of S-box components, and merged the three f-functions into one arithmetic component. The CAST-128 hardware based on the proposed architecture was synthesized using 0.13μm and 0.18-μm CMOS standard cell libraries and small, practical circuits of 26.4-39.5 Kgates and 189.9-614.7 Mbps were obtained. Takeshi Sugawara 0001, Naofumi Homma, Takafumi Aoki, Akashi Satoh |
ISCAS | 1 |
| 2007 | High-Speed Pipelined Hardware Architecture for Galois Counter Mode
Akashi Satoh, Takeshi Sugawara 0001, Takafumi Aoki |
ISC | 2 |