VLDB 2026 Research / reviewers in the wild / expert
Hiroyuki Sato 0002
dblp:68/5837-2
· DBLP profile ↗
40ranked-venue papers
1as first author
24since 2021 · last 2026
0000-0002-2891-3835ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 20 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 6 since 2021Artificial intelligence and machine learning · 9 · 4 since 2021Systems, architecture and hardware · 6 · 5 since 2021Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OracleGuardian: Detecting Price Oracle Manipulation with Gradient-Guided Fuzzing
Yepeng Ding, Ahmed Twabi, Tohru Kondo, Hiroyuki Sato 0002 |
COMPSAC | 5 |
| 2026 | PentestLLM: A Cyber Kill Chain-driven Multi-Agent Large Language Model Framework Enabling Automatic Penetration Testing
Hiroyuki Sato 0002, Zhenzhen Jiang, Lekun Liu, Wenjun Fan |
COMPSAC | 2 |
| 2025 | DynTaskMAS: A Dynamic Task Graph-driven Framework for Asynchronous and Parallel LLM-based Multi-Agent SystemsabstractThe emergence of Large Language Models (LLMs) in Multi-Agent Systems (MAS) has opened new possibilities for artificial intelligence, yet current implementations face significant challenges in resource management, task coordination, and system efficiency. While existing frameworks demonstrate the potential of LLM-based agents in collaborative problem-solving, they often lack sophisticated mechanisms for parallel execution and dynamic task management. This paper introduces DynTaskMAS, a novel framework that orchestrates asynchronous and parallel operations in LLM-based MAS through dynamic task graphs. The framework features four key innovations: (1) a Dynamic Task Graph Generator that intelligently decomposes complex tasks while maintaining logical dependencies, (2) an Asynchronous Parallel Execution Engine that optimizes resource utilization through efficient task scheduling, (3) a Semantic-Aware Context Management System that enables efficient information sharing among agents, and (4) an Adaptive Workflow Manager that dynamically optimizes system performance. Experimental evaluations demonstrate that DynTaskMAS achieves significant improvements over traditional approaches: a 21-33% reduction in execution time across task complexities (with higher gains for more complex tasks), a 35.4% improvement in resource utilization (from 65% to 88%), and near-linear throughput scaling up to 16 concurrent agents (3.47× improvement for 4× agents). Our framework establishes a foundation for building scalable, high-performance LLM-based multi-agent systems capable of handling complex, dynamic tasks efficiently. Yepeng Ding, Hiroyuki Sato 0002 |
ICAPS | 3 |
| 2025 | Spectrum-Adaptive Distribution of 2D Gaussians for Image Representation and CompressionabstractThe prevailing Gaussian Splatting has been adapted for image representation and compression by GaussianImage recently, achieving impressive rendering speeds of 1500–2000 FPS. However, it falls short in rate-distortion performance compared to current state-of-the-art image codecs. We attribute this to its explicit representation and tile-based rasterization process which demands a more efficient utilization of 2D Gaussians for improved performance. In this work, we propose a spectrum-adaptive distribution method to allocate Gaussians in alignment with the complexity of varying image regions. Additionally, we introduce a gradient-based growing strategy for Gaussians to further refine their distribution. Experimental results show that our approach outperforms GaussianImage in image representation quality while maintaining comparable training and rendering speeds. Moreover, by integrating a transform-quantization pipeline for the position attributes of Gaussians, our approach delivers a better rate-distortion curve compared to the INR-based codecs such as COIN and COIN++. Zunian Wan, Jiancheng Zhao, Yepeng Ding, Lingfeng Zhang 0002, Hiroyuki Sato 0002, Takefumi Ogawa |
ICME | 5 |
| 2025 | SegEraser: Augmentation with Linear Segmentation and Contextual Erasing for sEMG Gesture Classification
Lingfeng Zhang 0002, Yepeng Ding, Tao Hu 0012, Jun Li 0077, Hiroyuki Sato 0002 |
PRICAI | 5 |
| 2025 | Dynamic-Segment-Masking Pre-training for Multivariate Time-Series Classification
Lingfeng Zhang 0002, Yepeng Ding, Tao Hu 0012, Jun Li 0077, Hiroyuki Sato 0002 |
PRICAI (5) | 5 |
| 2024 | A Cross-Organizational Identity Proofing System for Seamless Online ID Re-Binding Leveraging Individual Number CardsabstractThis study focuses on the issue of ID management when researchers change their organizational affiliations, aiming at the effective utilization of research data in educational and research organizations. Although research data management systems are being developed at each organization, the continuous use of research data remains an issue for researchers. For example, when a researcher moves from one organization to another, the research data that was previously available to him or her becomes unavailable. In response, there is a need for a system that allows researchers to continue using their research data smoothly even if they move from one organization to another. To solve this problem, the authors propose a cross-organizational identity proofing system that ensures the continuity of IAL2/ AAL2 and completes the ID transfer online. The idea is to use researcher ID numbers, ORCID, and public personal authentication to verify the user's identity when linking the IDs before and after the transfer. To facilitate this, the study performs identity verification using an Individual Number Card (a Japanese governmental system) to enable easy ID linkage between IdPs with high identity confirmation and authentication strength. The implementation has been carried out in the development environment of Orthros, an ID linkage service provided by the National Institute of Informatics (NIl), utilizing the API service of xID Co., which is a solution for linking with the Individual Number Card. This approach is expected to overcome ID management issues associated with researcher transfers and improve the efficiency of research data use. Sayako Shimizu, Hiroyuki Sato 0002, Motonori Nakamura, Hukofumi Suzuki, Yasuo Okabe |
COMPSAC | 2 |
| 2024 | Textual Differential Privacy for Context-Aware Reasoning with Large Language ModelabstractLarge language models (LLMs) have demonstrated proficiency in various language tasks but encounter difficulties in specific domain or scenario. These challenges are mitigated through prompt engineering techniques such as retrieval-augmented generation, which improves performance by integrating contextual information. However, concerns regarding the privacy implications of context-aware reasoning architectures persist, particularly regarding the transmission of sensitive data to LLMs service providers, potentially compromising personal privacy. To mitigate these challenges, this paper introduces Tex-tual Differential Privacy, a novel paradigm aimed at safeguarding user privacy in LLMs-based context-aware reasoning. The proposed Differential Embedding Hash algorithm anonymizes sensitive information while maintaining the reasoning capability of LLMs. Additionally, a quantification scheme for privacy loss is proposed to better understand the trade-off between privacy protection and loss. Through rigorous analysis and experimentation, the effectiveness and robustness of the proposed paradigm in mitigating privacy risks associated with context-aware reasoning tasks are demonstrated. This paradigm addresses privacy concerns in context-aware reasoning architectures, enhancing the trust and utility of LLMs in various applications. Jieyu Zhou, Yepeng Ding, Lingfeng Zhang 0002, Yuheng Guo, Hiroyuki Sato 0002 |
COMPSAC | 6 |
| 2024 | On-Chain Dynamic Policy Evaluation for Decentralized Access Control
Yepeng Ding, Hiroyuki Sato 0002, Tohru Kondo |
ICA3PP (4) | 3 |
| 2024 | Hand Gesture Classification Using Nearest Centroid with Soft-DTW Loss on sEMG SignalsabstractSurface electromyography (sEMG) signals find extensive applications in medicine and bioengineering, particularly in rehabilitation and assistive technologies. Gesture classification using sEMG poses challenges such as noise removal, feature extraction, and personalized classification to accommodate individual variations in human physiology. To address these challenges, we propose an sEMG-based gesture classification method by leveraging the nearest centroid classifier and guiding the generation of centroids generated with Soft-DTW as a loss function. Additionally, we apply denoising techniques to the original sEMG signals, including DC offset removal, bandpass filtering, full-wave rectification, and linear envelope extraction. Additionally, we propose a cubic spline for downsampling. With a 1% downsampling rate, our method achieves 89.1% on average and 90.5% at peak and outperforms the state-of-the-art methods. Lingfeng Zhang 0002, Zunian Wan, Yepeng Ding, Takefumi Ogawa, Hiroyuki Sato 0002 |
ISPA | 6 |
| 2024 | DeRAG: Decentralized Multi-Source RAG System with Optimized Pyth NetworkabstractLarge language models (LLMs) have demonstrated remarkable capabilities in various natural language processing tasks. However, they face significant challenges in accessing up-to-date information and providing verifiable responses, particularly in domain-specific contexts. Retrieval-Augmented Generation (RAG) systems have emerged as a promising solution, but they introduce new vulnerabilities related to data integrity, privacy, and centralization. This paper introduces DeRAG (Decentralized Multi-Source Retrieval-Augmented Generation), a novel approach that leverages blockchain technology and advanced cryptographic techniques to address these challenges. DeRAG incorporates a decentralized multi-source data ecosystem, a RAG-Optimized Pyth Consensus protocol for data validation, and a domain-specific validator network structured as a Directed Acyclic Graph. The system also features an innovative RAG Processing Layer with a decentralized index structure based on Distributed Hash Tables and content-addressable storage. We present a comprehensive performance evaluation framework that assesses the system’s scalability, efficiency, output quality, and economic model effectiveness in a decentralized context. Results demonstrate that DeRAG significantly enhances the security, efficiency, and privacy of RAG systems, paving the way for more robust and reliable RAG applications in information retrieval and generation. Hiroyuki Sato 0002 |
ISPA | 2 |
| 2024 | Data Aggregation Management With Self-Sovereign Identity in Decentralized NetworksabstractData aggregation management is paramount in data-driven distributed systems. Conventional solutions premised on centralized networks grapple with security challenges concerning authenticity, confidentiality, integrity, and privacy. Recently, distributed ledger technology has gained popularity for its decentralized nature to facilitate overcoming these challenges. Nevertheless, insufficient identity management introduces risks like impersonation and unauthorized access. In this paper, we propose Degator, a data aggregation management framework that leverages self-sovereign identity and functions in decentralized networks to address security concerns and mitigate identity-related risks. We formulate fully decentralized aggregation protocols for data persistence and acquisition in Degator. Degator is compatible with existing data persistence methods, and supports cost-effective data acquisition minimizing dependency on distributed ledgers. We also conduct a formal analysis to elucidate the mechanism of Degator to tackle current security challenges in conventional data aggregation management. Furthermore, we showcase the applicability of Degator through its application in the management of decentralized neuroscience data aggregation and demonstrate its scalability via performance evaluation. Yepeng Ding, Hiroyuki Sato 0002, Maro G. Machizawa |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | BlockFusion: Expandable 3D Scene Generation using Latent Tri-plane ExtrapolationabstractWe present BlockFusion, a diffusion-based model that generates 3D scenes as unit blocks and seamlessly incorporates new blocks to extend the scene. BlockFusion is trained using datasets of 3D blocks that are randomly cropped from complete 3D scene meshes. Through per-block fitting, all training blocks are converted into the hybrid neural fields: with a tri-plane containing the geometry features, followed by a Multi-layer Perceptron (MLP) for decoding the signed distance values. A variational auto-encoder is employed to compress the tri-planes into the latent tri-plane space, on which the denoising diffusion process is performed. Diffusion applied to the latent representations allows for high-quality and diverse 3D scene generation. To expand a scene during generation, one needs only to append empty blocks to overlap with the current scene and extrapolate existing latent tri-planes to populate new blocks. The extrapolation is done by conditioning the generation process with the feature samples from the overlapping tri-planes during the denoising iterations. Latent tri-plane extrapolation produces semantically and geometrically meaningful transitions that harmoniously blend with the existing scene. A 2D layout conditioning mechanism is used to control the placement and arrangement of scene elements. Experimental results indicate that BlockFusion is capable of generating diverse, geometrically consistent and unbounded large 3D scenes with unprecedented high-quality shapes in both indoor and outdoor scenarios. Zhennan Wu, Yang Li 0193, Han Yan 0004, Taizhang Shang, Weixuan Sun, Senbo Wang, Ruikai Cui, Weizhe Liu, Hiroyuki Sato 0002, Hongdong Li, Pan Ji |
ACM Trans. Graph. | 9 |
| 2023 | Decentralized Self-sovereign Identity Management System: Empowering Datacenters Through Compact Cancelable Template Generation
Yepeng Ding, Hiroyuki Sato 0002 |
ICA3PP (7) | 4 |
| 2023 | 3D Segmenter: 3D Transformer based Semantic Segmentation via 2D Panoramic Distillation
Zhennan Wu, Yang Li 0193, Yifei Huang 0002, Lin Gu 0003, Tatsuya Harada, Hiroyuki Sato 0002 |
ICLR | 6 |
| 2023 | Operation Management Method of Software Defined Perimeter for Promoting Zero-Trust ModelabstractTelework has been on the rise since the advent of COVID-19, and concerns have arisen about issues such as information leakage due to internal fraud. The zero-trust model is attracting attention as a countermeasure. This model reduces risk by constantly performing authentication and authorization, thus leading to improved security levels and safer operation. However, currently less than 40% of the companies in Japan have introduced zero trust into their security policies, mainly due to the lack of specific guidelines for operational management. We have therefore developed a security policy (service authorization conditions) for the software defined perimeter (SDP) zero-trust model as a universal operational management method to promote zero-trust implementation. Specifically, we simplify the time/place/occasion (TPO) conditions of users as T (inside/outside working hours), P (inside/outside the company, telework), and O (with/without visitors), resulting in 12 patterns, and for each of these TPO conditions, we propose detailed new service authorization conditions for SDP. The results of qualitative evaluation demonstrated the effectiveness of the proposed method. Our findings will contribute to the introduction of the zero-trust model and pave the way for safer and more secure corporate networks. Shigeaki Tanimoto, Sogen Hori, Hiroyuki Sato 0002, Atsushi Kanai |
SERA | 3 |
| 2023 | Model-Driven Security Analysis of Self-Sovereign Identity SystemsabstractBest practices of self-sovereign identity (SSI) are being intensively explored in academia and industry. Reusable solutions obtained from best practices are generalized as architectural patterns for systematic analysis and design reference, which significantly boosts productivity and increases the dependability of future implementations. For security-sensitive projects, architects make architectural decisions with careful consideration of security issues and solutions based on formal analysis and experiment results. In this paper, we propose a model-driven security analysis framework for analyzing architectural patterns of SSI systems with respect to a threat model built on our investigation of real-world security concerns. Our framework mechanizes a modeling language to formalize patterns and threats with security properties in temporal logic and automatically generates programs for verification via model checking. Besides, we present typical vulnerable patterns verified by SecureSSI, a standalone integrated development environment, integrating commonly used pattern and attacker models to practicalize our framework. Yepeng Ding, Hiroyuki Sato 0002 |
TrustCom | 2 |
| 2023 | Inj-Kyber: Enhancing CRYSTALS-Kyber with Information Injection within a Bio-KEM FrameworkabstractSecurity infrastructures heavily rely on public key cryptography. With the emergence of quantum threats, NIST has been standardizing post-quantum cryptographic algorithms like CRYSTALS-Kyber. However, a major challenge in public-key cryptography is establishing a secure connection between verifiable information of specific entities and public keys. Traditionally, this challenge is addressed through Public Key Infrastructures (PKIs). Nevertheless, the current PKIs suffer from security and performance issues due to the requirement of central authorities. In this paper, we propose Inj-Kyber, a novel algorithm enhancing Kyber with information injection. Inj-Kyber achieves robust entity-key binding by injecting verifiable information into public keys while ensuring equivalent security to Kyber. Additionally, we showcase the applicability of Inj-Kyber through Bio-KEM, a KEM framework leveraging Inj-Kyber and biometric authentication to protect public keys via biometric information binding. Yepeng Ding, Yuheng Guo, Kentaro Kotani, Hiroyuki Sato 0002 |
TrustCom | 5 |
| 2023 | 1-D CNN-Based Online Signature Verification with Federated LearningabstractOnline signature verification plays a pivotal role in security infrastructures. However, conventional online signature verification models pose significant risks to data privacy, especially during training processes. To mitigate these concerns, we propose a novel federated learning framework that leverages 1-D Convolutional Neural Networks (CNN) for online signature verification. Furthermore, our experiments demonstrate the effectiveness of our framework regarding 1-D CNN and federated learning. Particularly, the experiment results highlight that our framework 1) minimizes local computational resources; 2) enhances transfer effects with substantial initialization data; 3) presents remarkable scalability. The centralized 1-D CNN model achieves an Equal Error Rate (EER) of 3.33% and an accuracy of 96.25%. Meanwhile, configurations with 2, 5, and 10 agents yield EERs of 5.42%, 5.83%, and 5.63%, along with accuracies of 95.21%, 94.17%, and 94.06%, respectively. Lingfeng Zhang 0002, Yuheng Guo, Yepeng Ding, Hiroyuki Sato 0002 |
TrustCom | 4 |
| 2022 | Two-Tier Trust Structure Model for Dynamic Supply Chain Formulation
Shigeaki Tanimoto, Yudai Watanabe, Hiroyuki Sato 0002, Atsushi Kanai |
AINA (3) | 3 |
| 2022 | Self-Sovereign Identity as a Service: Architecture in PracticeabstractSelf-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, forming a conceptually decentralized architecture. With the support of distributed ledger technology (DLT), it is possible to implement this conceptually decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, and high availability. However, developing such a relatively new identity model has high costs and risks with uncertainty. To facilitate the use of the DLT-based SSI in practice, we formulate Self-Sovereign Identity as a Service (SSIaaS), a concept that enables a system, especially a system cluster, to readily adopt SSI as its identity model for identification, authentication, and authorization. We propose a practical architecture by elaborating the service concept, SSI, and DLT to implement SSIaaS platforms and SSI services. Besides, we present an architecture for constructing and customizing SSI services with a set of architectural patterns and provide corresponding evaluations. Furthermore, we demonstrate the feasibility of our proposed architecture in practice with Selfid, an SSIaaS platform based on our proposed architecture. Yepeng Ding, Hiroyuki Sato 0002 |
COMPSAC | 2 |
| 2022 | Formalism- Driven Development of Decentralized SystemsabstractDecentralized systems have been widely developed and applied to address security and privacy issues in centralized systems, especially since the advancement of distributed ledger technology. However, it is challenging to ensure their correct functioning with respect to their designs and minimize the technical risk before the delivery. Although formal methods have made significant progress over the past decades, a feasible solution based on formal methods from a development process perspective has not been well developed. In this paper, we formulate an iterative and incremental development process, named formalism-driven development (FDD), for developing provably correct decentralized systems under the guidance of formal methods. We also present a framework named Seniz, to practicalize FDD with a new modeling language and scaffolds. Furthermore, we conduct case studies to demonstrate the effectiveness of FDD in practice with the support of Seniz. Yepeng Ding, Hiroyuki Sato 0002 |
ICECCS | 2 |
| 2021 | In-air Signature Authentication Using Smartwatch Motion SensorsabstractHandwriting signature, as an important behavioral biometric trait, has been broadly adopted for authorization and identity verification. Nowadays, the emergence of consumer-level devices and the development of deep neural networks have vastly facilitated this field. In this paper, we present a practical recurrent neural network-based in-air signature authentication system using smartwatch. The signature is represented by the readings of gyroscope and accelerometer compensated by device attitude readings. The system can extract features from in-air signing motions to verify whether a signature is from an imposter or the genuine user. Moreover, an in-air signature dataset, consisting of 3190 signature pairs from 22 participants, is built for validation. Experimental results demonstrate that our proposed approach achieves an equal error rate(EER) of 0.83%. Besides, we investigate the impact of properties of motion sensory data on in-air signature authentication. Lingfeng Zhang 0002, Hiroyuki Sato 0002 |
COMPSAC | 3 |
| 2021 | Sunspot: A Decentralized Framework Enabling Privacy for Authorizable Data Sharing on Transparent Public Blockchains
Yepeng Ding, Hiroyuki Sato 0002 |
ICA3PP (1) | 2 |
| 2020 | Dagbase: A Decentralized Database Platform Using DAG-Based ConsensusabstractAs the infrastructure to provide support for distributed database management systems, the distributed database platform is very important to unify the management of data distributed in intricate environments. However, a traditional distributed database platform with centralized entities faces diverse and serious threats when the central entity is compromised. Consensus mechanisms in distributed ledger technology (DLT) can enhance the capability of defending threats by decentralizing the platform, but the efficiency and cost of consensus mechanisms in classic blockchain techniques are notable issues. In this paper, we propose a novel decentralized database platform, named Dagbase, with the support of an efficient and cost-effective consensus mechanism that uses the directed acyclic graph (DAG) as the structure. Dagbase decentralizes the management and distributes data to prevent threats in untrustworthy environments, which gains benefits from recent DLT. The performance of near-native data reading and high-efficiency data writing is ensured by a layered architecture and DAG-based consensus. Furthermore, we ensure flexibility by decoupling the consensus mechanism from the architecture. Dagbase is also easy-to-use and can be integrated with mainstream database products seamlessly on account of great interoperability. The implementation demonstrates our work and the security and performance analysis are enforced for evaluation. Yepeng Ding, Hiroyuki Sato 0002 |
COMPSAC | 2 |
| 2020 | Formalizing and Verifying Decentralized Systems with Extended Concurrent Separation Logic
Yepeng Ding, Hiroyuki Sato 0002 |
ICA3PP (1) | 2 |
| 2019 | Communication Robot for Elderly Based on Robotic Process AutomationabstractCurrently, a communication robot like an AI speaker has become popular as one of consumer services. As realized high functions seen in cooperation of network and home appliances by them, hurdles for the elderly in operating such advanced IT devices are still high. On the other hand, RPA (Robotic Process Automation) attracts attention for productivity improvement of business processing. However, there are few examples that applied RPA to consumer services. It is caused that there is not common sense about an application method of RPA for consumer services. Therefore, if we could define the application method of RPA for consumer services, we could develop consumer services familiar with the elderly. This paper gives some examples of our developed consumer services for the elderly by communication robots after summarizing requirements for applying RPA to consumer services. Then, we inspect the effectiveness of the consumer services based on RPA. Finally, we make clear a RPA basic model for consumer services. Toru Kobayashi, Kenichi Arai, Tetsuo Imai, Shigeaki Tanimoto, Hiroyuki Sato 0002, Atsushi Kanai |
COMPSAC (2) | 5 |
| 2017 | Collaborative Computation Offloading in Heterogeneous Asynchronous Cloud EnvironmentabstractComputation offloading is a key technique to enhance the performance and interactivity of mobile application through migrating the computation-intensive tasks to the cloud. However, efficient offloading is challenging in practice in that a mobile application often consists of computation tasks that have dependency with execution order constraints as well as parallel tasks that can be executed non-deterministically. In addition, each mobile device executes its application as a separate process, and performs asynchronous communication with cloud environment with heterogeneous computing and storage resource that are shared among mobile devices. In this paper, we propose a collaborative asynchronous computation offloading framework to improve the interactivity and execution efficiency of mobile applications. Initially, each mobile application calculates its local offloading plan. At runtime, it follows the offloading plan for task execution and requests the offloading computation from the cloud system. Upon receiving the request, cloud system performs dynamic adjustment of the offloading request according to the cloud runtime status. We implement our proposed offloading framework. The evaluation on 11 real-world mobile applications demonstrates its effectiveness. Lei Ma 0003, Hiroyuki Sato 0002 |
COMPSAC (1) | 3 |
| 2017 | An empirical study on the effects of code visibility on program testability
Lei Ma 0003, Hiroyuki Sato 0002 |
Softw. Qual. J. | 4 |
| 2016 | Risk assessment quantification of social-media utilization in enterpriseabstractThe purpose of this study is to make social media utilization by enterprises safer, more secure, and more convenient. Enterprises use social media for marketing, but this presents a lot of risks. These risks were comprehensively extracted in our previous study, but it was only a qualitative study, so a quantitative evaluation is needed to make the risks' countermeasures more practical. Thus, in this paper, the risk factors identified in the previous study are analyzed and quantitatively evaluated. Specifically, the values of the risk factors were approximately calculated by using a risk formula used in the field of information security management systems (ISMS). In this way, it was found that the countermeasures in the previous study could reduce their corresponding risk factors by about 60%. The results herein can contribute to helping enterprises to utilize social media more safely, securely, and conveniently in the future. Shigeaki Tanimoto, Motoi Iwashita, Yoshiaki Seki, Hiroyuki Sato 0002, Atsushi Kanai |
ICIS | 4 |
| 2015 | An Approach to Selecting Cloud Services for Data Storage in Heterogneous-Multicloud Environment with High Availability and ConfidentialityabstractCloud services are becoming more popular and as their price has been decreasing, the opportunity to use them has been increasing. However, it has become difficult to select optimal cloud services from many services. This paper proposes an approach to dynamically selecting optimal cloud services to store data in heterogeneous-multi-cloud environments, which we evaluated by using a secret sharing scheme. The results indicated that it is possible to select the best services from the proposed model in heterogeneous multi-cloud environments. Yuuki Kajiura, Shohei Ueno, Atsushi Kanai, Shigeaki Tanimoto, Hiroyuki Sato 0002 |
ISADS | 5 |
| 2015 | GRT: Program-Analysis-Guided Random Testing (T)abstractWe propose Guided Random Testing (GRT), which uses static and dynamic analysis to include information on program types, data, and dependencies in various stages of automated test generation. Static analysis extracts knowledge from the system under test. Test coverage is further improved through state fuzzing and continuous coverage analysis. We evaluated GRT on 32 real-world projects and found that GRT outperforms major peer techniques in terms of code coverage (by 13 %) and mutation score (by 9 %). On the four studied benchmarks of Defects4J, which contain 224 real faults, GRT also shows better fault detection capability than peer techniques, finding 147 faults (66 %). Furthermore, in an in-depth evaluation on the latest versions of ten popular real-world projects, GRT successfully detects over 20 unknown defects that were confirmed by developers. Lei Ma 0003, Cyrille Artho, Hiroyuki Sato 0002, Johannes Gmeiner, Rudolf Ramler |
ASE | 4 |
| 2015 | GRT: An Automated Test Generator Using Orchestrated Program AnalysisabstractWhile being highly automated and easy to use, existing techniques of random testing suffer from low code coverage and defect detection ability for practical software applications. Most tools use a pure black-box approach, which does not use knowledge specific to the software under test. Mining and leveraging the information of the software under test can be promising to guide random testing to overcome such limitations. Guided Random Testing (GRT) implements this idea. GRT performs static analysis on software under test to extract relevant knowledge and further combines the information extracted at run-time to guide the whole test generation procedure. GRT is highly configurable, with each of its six program analysis components implemented as a pluggable module whose parameters can be adjusted. Besides generating test cases, GRT also automatically creates a test coverage report. We show our experience in GRT tool development and demonstrate its practical usage using two concrete application scenarios. Lei Ma 0003, Cyrille Artho, Hiroyuki Sato 0002, Johannes Gmeiner, Rudolf Ramler |
ASE | 4 |
| 2015 | Improvement of multiple CP/CPS based on level of assurance for campus PKI deploymentabstractThe ICT environment has been rapidly developed by ubiquitization, and cloud computing and has become far more convenient to use. On the other hand, the negative side also exists, such as threats of viruses and unlawful access, in which the use of the safe and secure ICT environment is threatened. Public key infrastructure (PKI) construction is desired to achieve the safe and secure use of the ICT environment at universities. However, PKI has not been widely constructed in universities because of its cost. A previous study proposed multiple policies for core PKI operation. However, a dynamic evaluation that considers actual operation is not sufficient. In this paper, first, as a result of reexamining the conventional multiple-policy proposal in detail, an improvement plan is proposed from a viewpoint of the ease of introduction. Next, in addition to the conventional evaluation, dynamic evaluation based on real operation is performed, and effectiveness of the improvement plan is clarified. Shigeaki Tanimoto, Toshihiko Moriya, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 3 |
| 2015 | Risk assessment of social-media utilization in an enterpriseabstractThe purpose of this study contributes to safe improvement in consideration of security in addition to convenience by the social media utilization in the company. The company uses the marketing using social media, but a lot of risks exist. We contribute to safe improvement by performing an example investigation in this study, and doing risk assessment. In this study, in order to extract a risk event, the RBS method was used. And we divided it into next four risk classifications by risk matrix method, "Risk Mitigation", "Risk Avoidance", "Risk Transference", and "Risk Acceptance". As a result, it became clear that it was necessary for the company to take risk measures mainly on "recognition of cost effectiveness", "the countermeasure against blog flaming", and "information leakage measure of employee". It is necessary for the company to take these risks measures from this result with precedence. Based on this, it is believed that the company can utilize social media effectively if the company follows these measures. Shigeaki Tanimoto, Kenichi Ohata, Shoichi Yoneda, Motoi Iwashita, Hiroyuki Sato 0002, Yoshiaki Seki, Atsushi Kanai |
SNPD | 5 |
| 2014 | Efficient testing of software product lines via centralization (short paper)abstractSoftware product line~(SPL) engineering manages families of software products that share common features. However, cost-effective test case generation for an SPL is challenging. Applying existing test case generation techniques to each product variant separately may test common code in a redundant way. Moreover, it is difficult to share the test results among multiple product variants. In this paper, we propose the use of centralization, which combines multiple product variants from the same SPL and generates test cases for the entire system. By taking into account all variants, our technique generally avoids generating redundant test cases for common software components. Our case study on three SPLs shows that compared with testing each variant independently, our technique is more efficient and achieves higher test coverage. Lei Ma 0003, Cyrille Artho, Hiroyuki Sato 0002 |
GPCE | 4 |
| 2014 | Risk assessment quantification in life log serviceabstractA Life Log Service that handles action records, such as an individual search logs and data on shoppers' browsing and buying habits, have attracted attention with the spread of the Internet. Life Log Service is thought to present various risks to private information, such as personal information. For this reason, countermeasures to these risks need to be investigated. We have already qualitatively analyzed the risks of life log services. To extract the specific risks of using a life log service comprehensively, we used a Risk Breakdown Structure (RBS), which is the typical risk-analysis method. Furthermore, after risks were analyzed, concrete countermeasures were proposed. However, these results need to be quantitatively evaluated from a more practical viewpoint. In this paper, the validity is visualized by performing quantitive risk assessment on the proposed countermeasures for risks in the life log obtained in our previous research. Specifically, the risk value based on a risk formula is computed to a risk factor and its proposed countermeasures. Thereby, the effects of the proposed countermeasures on risks of the life log service found in previous research are evaluated quantitatively, and this will contribute to spreading and promoting the life log service. Shigeaki Tanimoto, Ken Takahashi, Taro Yabuki, Kazuhiko Kato, Motoi Iwashita, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 6 |
| 2013 | A Study of Data Management in Hybrid Cloud ConfigurationabstractCloud computing is currently spreading with the further implementation of IT infrastructure. Clouds involve certain negative factors, however, which must be addressed to promote further cloud utilization. As a means of addressing some of these negative factors, a hybrid cloud configuration combining public and private clouds has attracted attention. This configuration stores personal and confidential information in a private cloud and other data in a public cloud. Unfortunately, no detailed classification of where various kinds of data should be stored has yet been fully established. Hence, this paper proposes an enterprise data management method for a hybrid cloud configuration. Specifically, enterprise data was subdivided into 28 categories through a work breakdown structure (WBS) method. Then, the subdivided data was classified in terms of whether it did or did not consist of personal or confidential information. The resulting data portfolio required storing only about 18% of data in a private cloud, with the remaining 82% in a public cloud. In accordance with this basic guideline, a fundamental data management proposal is developed for the hybrid cloud configuration. Shigeaki Tanimoto, Yorihiro Sakurada, Yosiaki Seki, Motoi Iwashita, Shinsuke Matsui, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 6 |
| 2012 | Risk Management to User Perception of Insecurity in Ambient ServiceabstractIn recent years, Ambient service has attracted attention as a ubiquitous, future intelligence infrastructure. The Ambient service provides service suitable for user needs automatically by making a sensor and a computer cooperate, and gathering and analyzing the information about each user. However, with the Ambient service, in order to manage personal information, various risks, such as an information leakage, are assumed. In this research, about a risk of being assumed with the Ambient service, it analyzes from a viewpoint by the side of service provision and service use, and clarifies the proposed measures. Specifically, risk breakdown structure and the risk matrix which are the typical risk management methods of project management were used. These results extracted 40 factors as a risk factor of the Ambient service. As the main feature of countermeasure, for Risk Transference, a countermeasure, such as preparing a third party's inspection on the service provision side, was proposed. Moreover, for Risk Mitigation, a countermeasure, such as a rule for a new specification corresponding to the Ambient service, was proposed. As mentioned above, the risk management of the Ambient service was proposed in this paper. A future subject is evaluating the effectiveness of the proposed countermeasure. Shigeaki Tanimoto, Daisuke Sakurai, Yosiaki Seki, Motoi Iwashita, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 5 |
| 2011 | Building a Security Aware Cloud by Extending Internal Control to CloudabstractFaced with today's innovative blow-up of cloud technologies, we are forced to rebuild services in terms of cloud. In the rebuilding, considering a facet of cloud as social infrastructure, security is a critical problem. Most of insecurity against clouds can be summarized as insecurity of management, which is classified into the multiple stakeholder problem, and the open space security problem. As a solution to these problems, we extend ISMS internal control to cloud by implementing trust base of security on IAM and key management. Because ISMS internal control is a source of trust, its extension to cloud can be an essential solution of security. Moreover, by controlling levels of quality of service and security by contract, we can optimize cost on service and security delegated to a cloud. Hiroyuki Sato 0002, Atsushi Kanai, Shigeaki Tanimoto |
ISADS | 1 |