VLDB 2026 Research / reviewers in the wild / expert
Seira Hidano
dblp:78/5474
· DBLP profile ↗
43ranked-venue papers
7as first author
24since 2021 · last 2026
0009-0006-0571-7168ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 4 first-author · 12 since 2021Artificial intelligence and machine learning · 13 · 3 first-author · 8 since 2021Systems, architecture and hardware · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AISTIP: AI Security Threat Intelligence Platform to Gather Knowledge from Technical Documents
Kento Hasegawa, Seira Hidano |
ICAART (5) | 2 |
| 2026 | Enhancing Certified Robustness in Few-Shot Classification with Contrastive Loss and Defensive Noise in Fine-Tuning
Hiroya Kato, Seira Hidano, Takao Murakami, Hideitsu Hino |
ICISSP (2) | 2 |
| 2025 | Flexible Noise Based Robustness Certification Against Backdoor Attacks in Graph Neural Networks
Hiroya Kato, Ryo Meguro, Seira Hidano, Takuo Suganuma, Masahiro Hiji |
ICISSP (2) | 3 |
| 2025 | Automating the Assessment of Japanese Cyber-Security Technical Assessment Requirements Using Large Language Models
Kento Hasegawa, Yuka Ikegami, Seira Hidano, Kazuhide Fukushima, Kazuo Hashimoto, Nozomu Togawa |
IoTBDS | 3 |
| 2025 | Automated Test Input Generation Based on Web User Interfaces via Large Language Models
Kento Hasegawa, Hibiki Nakanishi, Seira Hidano, Kazuhide Fukushima, Kazuo Hashimoto, Nozomu Togawa |
IoTBDS | 3 |
| 2025 | Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems
Jung-Woo Chang, Ke Sun 0012, Nasimeh Heydaribeni, Seira Hidano, Xinyu Zhang 0003, Farinaz Koushanfar |
NDSS | 4 |
| 2025 | Node-Wise Hardware Trojan Detection Based on Graph LearningabstractIn the fourth industrial revolution, securing the protection of supply chains has become an ever-growing concern. One such cyber threat is a hardware Trojan (HT), a malicious modification to an IC. HTs are often identified during the hardware manufacturing process but should be removed earlier in the design process. Machine learning-based HT detection in gate-level netlists is an efficient approach to identifying HTs at the early stage. However, feature-based modeling has limitations in terms of discovering an appropriate set of HT features. We thus proposeNHTD-GLin this paper, a novel node-wise HT detection method based on graph learning (GL). Given the formal analysis of the HT features obtained from domain knowledge,NHTD-GLbridges the gap between graph representation learning and feature-based HT detection. The experimental results demonstrate thatNHTD-GLachieves 0.998 detection accuracy and 0.921 F1-score and outperforms state-of-the-art node-wise HT detection methods.NHTD-GLextracts HT features without heuristic feature engineering. Kento Hasegawa, Kazuki Yamashita, Seira Hidano, Kazuhide Fukushima, Kazuo Hashimoto, Nozomu Togawa |
IEEE Trans. Computers | 3 |
| 2024 | AutoRed: Automating Red Team Assessment via Strategic Thinking Using Reinforcement LearningabstractAs security risks to network systems have grown, red team assessment has emerged as a powerful methodology for discovering vulnerabilities.Such assessments are difficult to master because technical knowledge and experience are needed.Automating the vulnerability assessment of network systems is expected to help network system administrators conduct these assessments easily.The challenges for automating these assessments include accurately addressing many actions, observing network states, and generalizing agent models.In this paper, we propose a framework, called AutoRed, for the automation of red team assessment via strategic thinking using reinforcement learning (RL).Our framework addresses the following challenges: (1) facilitating action determination by adopting a hierarchical RL model via strategic thinking, (2) establishing a method to observe network systems using graph neural networks (GNNs), and (3) investigating the reusability and generalization ability of the proposed model through experiments.We further evaluate the proposed model in an emulated environment constructed on a virtual machine platform.The experimental results demonstrate that the proposed model trained on three scenarios simultaneously can be applied 10-40 times more efficiently to various scenarios, including unseen scenarios during training, than the state-of-the-art hierarchical model. Kento Hasegawa, Seira Hidano, Kazuhide Fukushima |
CODASPY | 2 |
| 2024 | Gradient-Based Clean Label Backdoor Attack to Graph Neural Networks
Ryo Meguro, Hiroya Kato, Shintaro Narisada, Seira Hidano, Kazuhide Fukushima, Takuo Suganuma, Masahiro Hiji |
ICISSP | 4 |
| 2024 | RAG Certainty: Quantifying the Certainty of Context-Based Responses by LLMsabstractLarge language models (LLMs) have recently been employed for a wide variety of purposes. Retrieval-augmented generation (RAG), in which an LLM generates a response based on context relevant to the prompt, is often used to enable the LLM to adapt to specialized domains. However, sentences generated by a generative LLM may contain incorrect information, known as “hallucinations.” The challenge in identifying hallucinations within the RAG framework involves evaluating the certainty of both context retrieval and LLM outputs. In this paper, we propose a metric called RAG certainty to quantify the certainty of LLM outputs within a RAG framework. The proposed metric is calculated based on certainty scores from both information retrieval and response generation. Experimental results demonstrate that the proposed metric effectively reflects the certainty of information retrieval in a RAG framework. We further validated the proposed metric through a case study that assesses the predicted Common Vulnerability Scoring Sys-tem (CVSS) scores for cybersecurity vulnerabilities and found that errors are mitigated according to the proposed metric. Kento Hasegawa, Seira Hidano, Kazuhide Fukushima |
ICMLA | 2 |
| 2024 | bfOneWORD: Adversarial Text Detection and Prediction Restoration Using One-Word Perturbation
Hoang-Quoc Nguyen-Son, Seira Hidano, Kazuhide Fukushima, Shinsaku Kiyomoto, Isao Echizen |
ICONIP (9) | 2 |
| 2023 | Fully Hidden Dynamic Trigger Backdoor Attacks
Shintaro Narisada, Seira Hidano, Kazuhide Fukushima |
ICAART (3) | 2 |
| 2023 | Automating XSS Vulnerability Testing Using Reinforcement Learning
Kento Hasegawa, Seira Hidano, Kazuhide Fukushima |
ICISSP | 2 |
| 2023 | RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video Compression
Jung-Woo Chang, Mojan Javaheripi, Seira Hidano, Farinaz Koushanfar |
NDSS | 3 |
| 2023 | Membership Inference Attacks against GNN-based Hardware Trojan DetectionabstractGraph neural networks (GNNs) have been actively employed in hardware security and have demonstrated remarkable performance. In particular, GNN models for hardware Trojan (HT) detection significantly outperform existing machine learning-based detection methods. However, GNNs have a potential vulnerability to membership inference attack (MIA), which aims to determine whether a given sample is used in the training dataset. In this paper, we investigate the threat of MIAs for GNN-based HT detection models. First, the MIA scheme for GNN-based HT detection models is established based on the basic MIA settings. The experimental results demonstrate that MIA for GNN-based HT detection can leak information about the HTs included in the training dataset with a 0.945 attack AUC score in the worst-case scenario. Based on this observation, we propose a defense method against MIA utilizing a domain generalization technique. The proposed defense method successfully mitigated the vulnerability of MIA and degraded the attack AUC score to 0.536 for the netlist level while maintaining the original HT detection performance. Kento Hasegawa, Kazuki Yamashita, Seira Hidano, Kazuhide Fukushima, Kazuo Hashimoto, Nozomu Togawa |
TrustCom | 3 |
| 2023 | R-HTDetector: Robust Hardware-Trojan Detection Based on Adversarial TrainingabstractHardware Trojans (HTs) have become a serious problem, and extermination of them is strongly required for enhancing the security and safety of integrated circuits. An effective solution is to identify HTs at the gate level via machine learning techniques. However, machine learning has specific vulnerabilities, such asadversarial examples. In reality, it has been reported that adversarial modified HTs greatly degrade the performance of a machine learning-based HT detection method. Therefore, we propose a robust HT detection method using adversarial training (R-HTDetector). We formally describe the robustness of R-HTDetector in modifying HTs. Our work gives the world-first adversarial training for HT detection with theoretical backgrounds. We show through experiments with Trust-HUB benchmarks that R-HTDetector overcomes adversarial examples while maintaining its original accuracy. Kento Hasegawa, Seira Hidano, Kohei Nozawa, Shinsaku Kiyomoto, Nozomu Togawa |
IEEE Trans. Computers | 2 |
| 2022 | Effective Hardware-Trojan Feature Extraction Against Adversarial Attacks at Gate-Level NetlistsabstractRecently, with the increase in outsourcing of IC design and manufacturing, the possibility of inserting hardware Trojans, which are circuits with malicious functions, has been pointed out. To prevent this threat, a method to identify hardware Trojans using neural networks has been proposed. On the other hand, adversarial attacks have emerged that modify circuit design information to reduce the accuracy of hardware-Trojan classification by neural networks. Since the features designed by existing methods do not take the attacks into account, it is necessary to consider a new method for countermeasures. In this paper, out of 76 features that are strongly related to hardware-Trojan features, we investigate them from the viewpoint of the robustness against the adversarial attacks on circuit design information and newly propose 24 hardware-Trojan features. We compare the classifiers using the proposed 24 features with the classifiers using 11, 36, 51, and 76 existing features, respectively and confirm that the proposed ones are more robust in identifying hardware Trojans in circuits subjected to the adversarial attacks. Kazuki Yamashita, Tomohiro Kato, Kento Hasegawa, Seira Hidano, Kazuhide Fukushima, Nozomu Togawa |
IOLTS | 4 |
| 2021 | Toward Learning Robust Detectors from Imbalanced Datasets Leveraging Weighted Adversarial Training
Kento Hasegawa, Seira Hidano, Shinsaku Kiyomoto, Nozomu Togawa |
CANS | 2 |
| 2021 | Countermeasures Against Backdoor Attacks Towards Malware Detectors
Shintaro Narisada, Yuki Matsumoto, Seira Hidano, Toshihiro Uchibayashi, Takuo Suganuma, Masahiro Hiji, Shinsaku Kiyomoto |
CANS | 3 |
| 2021 | TransMIA: Membership Inference Attacks Using Transfer Shadow TrainingabstractTransfer learning has been widely studied and gained increasing popularity to improve the accuracy of machine learning models by transferring some knowledge acquired in different training. However, no prior work has pointed out that transfer learning can strengthen privacy attacks on machine learning models. In this paper, we propose TransMIA (Transfer learning-based Membership Inference Attacks), which use transfer learning to perform membership inference attacks on the source model when the adversary is able to access the parameters of the transferred model. In particular, we propose a transfer shadow training technique, where an adversary employs the parameters of the transferred model to construct shadow models, to significantly improve the performance of membership inference when a limited amount of shadow training data is available to the adversary. We evaluate our attacks using two real datasets, and show that our attacks outperform the state-of-the-art that does not use our transfer shadow training technique. We also compare four combinations of the learning-based/entropy-based approach and the fine-tuning/freezing approach, all of which employ our transfer shadow training technique. Then we examine the performance of these four approaches based on the distributions of confidence values, and discuss possible countermeasures against our attacks. Seira Hidano, Takao Murakami, Yusuke Kawamoto 0001 |
IJCNN | 1 |
| 2021 | OPA2D: One-Pixel Attack, Detection, and Defense in Deep Neural NetworksabstractAdversarial images have been proposed to deceive deep neural networks (DNNs) by adding perturbations to the pixels. Unlike existing attacks, Su et al. [1] analyzed an attack in an extremely limited constraint where only one pixel was modified. However, their one-pixel attack is easy to recognize by humans. In this paper, we improve the attack to enable the deceit of both DNNs and humans. We conducted a human recognition analysis to prove our attack's effect. We then propose detection and defense methods against the attack by re-attacking the adversarial images. Our experimental results on the six most recent convolutional neural networks show that while our attack achieved approximately the same success rates and confidence scores as in the existing attack, our attack achieves a higher success rate for deceiving humans. Only 49.41 % of participants can recognize our attack even though 81.04 % participants have recognized the existing attack. OPA2D detects 99.33% of the existing attack and 100% of our attack and defends 92.00% of the existing attack and 95.33 % of our attack. Hoang-Quoc Nguyen-Son, Tran Thao Phuong, Seira Hidano, Vanessa Bracamonte, Shinsaku Kiyomoto, Rie Shigetomi Yamaguchi |
IJCNN | 3 |
| 2021 | Data Augmentation for Machine Learning-Based Hardware Trojan Detection at Gate-Level NetlistsabstractDue to the rapid growth in the information and telecommunications industries, an untrusted vendor might compromise the complicated supply chain by inserting hardware Trojans (HTs). Although hardware Trojan detection methods at gate-level netlists employing machine learning have been developed, the training dataset is insufficient. In this paper, we propose a data augmentation method for machine-learning-based hardware Trojan detection. Our proposed method replaces a gate in a hardware Trojan circuit with logically equivalent gates. The experimental results demonstrate that our proposed method successfully enhances the classification performance with all the classifiers in terms of the true positive rates (TPRs). Kento Hasegawa, Seira Hidano, Kohei Nozawa, Shinsaku Kiyomoto, Nozomu Togawa |
IOLTS | 2 |
| 2021 | Machine Translated Text Detection Through Text Similarity with Round-Trip TranslationabstractHoang-Quoc Nguyen-Son, Tran Thao, Seira Hidano, Ishita Gupta, Shinsaku Kiyomoto. Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2021. Hoang-Quoc Nguyen-Son, Tran Thao Phuong, Seira Hidano, Ishita Gupta, Shinsaku Kiyomoto |
NAACL-HLT | 3 |
| 2021 | SEPP: Similarity Estimation of Predicted Probabilities for Defending and Detecting Adversarial Text
Hoang-Quoc Nguyen-Son, Seira Hidano, Kazuhide Fukushima, Shinsaku Kiyomoto |
PACLIC | 2 |
| 2020 | Stronger Targeted Poisoning Attacks Against Malware Detection
Shintaro Narisada, Shoichiro Sasaki, Seira Hidano, Toshihiro Uchibayashi, Takuo Suganuma, Masahiro Hiji, Shinsaku Kiyomoto |
CANS | 3 |
| 2020 | Evaluating the Effect of Justification and Confidence Information on User Perception of a Privacy Policy Summarization Tool
Vanessa Bracamonte, Seira Hidano, Welderufael B. Tesfay, Shinsaku Kiyomoto |
ICISSP | 2 |
| 2020 | Recommender Systems Robust to Data Poisoning using Trim Learning
Seira Hidano, Shinsaku Kiyomoto |
ICISSP | 1 |
| 2020 | Exposing Private User Behaviors of Collaborative Filtering via Model Inversion TechniquesabstractAbstract Privacy risks of collaborative filtering (CF) have been widely studied. The current state-of-theart inference attack on user behaviors (e.g., ratings/purchases on sensitive items) for CF is by Calandrino et al. (S&P, 2011). They showed that if an adversary obtained a moderate amount of user’s public behavior before some timeT, she can infer user’s private behavioraftertimeT. However, the existence of an attack that infers user’s private behaviorbefore Tremains open. In this paper, we propose the first inference attack that reveals past private user behaviors. Our attack departs from previous techniques and is based onmodel inversion(MI). In particular, we propose the first MI attack on factorization-based CF systems by leveraging data poisoning by Li et al. (NIPS, 2016) in a novel way. We inject malicious users into the CF system so that adversarialy chosen “decoy” items are linked with user’s private behaviors. We also show how to weaken the assumption made by Li et al. on the information available to the adversary from the whole rating matrix to only the item profile and how to create malicious ratings effectively. We validate the effectiveness of our inference algorithm using two real-world datasets. Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | Detecting Machine-Translated Paragraphs by Matching Similar Words
Hoang-Quoc Nguyen-Son, Tran Thao Phuong, Seira Hidano, Shinsaku Kiyomoto |
CICLing (1) | 3 |
| 2019 | Evaluating Privacy Policy Summarization: An Experimental Study among Japanese Users
Vanessa Bracamonte, Seira Hidano, Welderufael B. Tesfay, Shinsaku Kiyomoto |
ICISSP | 2 |
| 2019 | Detecting Machine-Translated Text using Back TranslationabstractMachine-translated text plays a crucial role in the communication of people using different languages. However, adversaries can use such text for malicious purposes such as plagiarism and fake review. The existing methods detected a machine-translated text only using the text’s intrinsic content, but they are unsuitable for classifying the machine-translated and human-written texts with the same meanings. We have proposed a method to extract features used to distinguish machine/human text based on the similarity between the intrinsic text and its back-translation. The evaluation of detecting translated sentences with French shows that our method achieves 75.0% of both accuracy and F-score. It outperforms the existing methods whose the best accuracy is 62.8% and the F-score is 62.7%. The proposed method even detects more efficiently the back-translated text with 83.4% of accuracy, which is higher than 66.7% of the best previous accuracy. We also achieve similar results not only with F-score but also with similar experiments related to Japanese. Moreover, we prove that our detector can recognize both machine-translated and machine-back-translated texts without the language information which is used to generate these machine texts. It demonstrates the persistence of our method in various applications in both low- and rich-resource languages. Hoang-Quoc Nguyen-Son, Tran Thao Phuong, Seira Hidano, Shinsaku Kiyomoto |
INLG | 3 |
| 2019 | On Embedding Backdoor in Malware Detectors Using Machine LearningabstractResearching for malware detection using machine learning is becoming active. However, conventional detection techniques do not consider the impact of attacks on machine learning, which has become complicated in recent years. In this research, we focus on data poisoning attack, which is one of the typical attacks on machine learning, and aim to clarify the influence of attacks on malware detection technology. Data poisoning attack is an attack method that intentionally manipulates the predicted result of a learned model by injecting poisoning data into training data, and by applying this, it is possible to embed a backdoor that induces mis-prediction of only specific input data. In this paper, we first propose an attack framework for backdoor embedding that prevents detection of only specific types of malware by data poisoning attack. Next, we will describe a method to generate poisoning data efficiently while avoiding attack detection by solving the optimization problem. Furthermore, we take malware detection technology using logistic regression and show the effectiveness of the our method through evaluation experiments using two datasets. Shoichiro Sasaki, Seira Hidano, Toshihiro Uchibayashi, Takuo Suganuma, Masahiro Hiji, Shinsaku Kiyomoto |
PST | 2 |
| 2018 | Active Attack Against Oblivious RAMabstractWhen a user consumes an encrypted digital content (for example video and music files), the player application accesses the secret key to decrypt the content. If the user is malicious, he can analyse the access pattern of the player application to extract the secret key efficiently. Oblivious RAMs (ORAMs) are effective solution for such threats. However, ORAMs are only effective for `passive' attackers who can observe the RAM access done by the application, but cannot alter data stored on RAM. The attacker with ability to alter data on RAM can be called `active' attackers. In this paper, we evaluate the security of ORAM schemes against active adversaries where they alter data on RAM and try to efficiently extract the secret information. We also propose countermeasures against active adversaries. Yuto Nakano, Seira Hidano, Shinsaku Kiyomoto, Kouichi Sakurai |
AINA | 2 |
| 2018 | An Evaluation Framework for Fastest Oblivious RAM
Seira Hidano, Yuto Nakano, Shinsaku Kiyomoto |
IoTBDS | 1 |
| 2018 | The Possibility of Matrix Decomposition as Anonymization and Evaluation for Time-sequence DataabstractTime-sequence data is high dimensional and con- tains a lot of information, which can be utilized in various fields, such as insurance, finance, and advertising. Personal data including time-sequence data is often converted to anonymized datasets, which need to strike a balance between both privacy and utility. In this paper, we consider low-rank matrix decomposition as one of the anonymization methods and evaluate its efficiency. We convert time-sequence datasets to matrices and evaluate both privacy and utility. The record IDs in time-sequence data are changed at regular intervals to reduce re-identification risk. However, since individuals tend to behave in a similar fashion over periods of time, there remains a risk of record linkage even if record IDs are different. Hence, we evaluate the re- identification and linkage risks as privacy risks of time-sequence data. Our experimental results show that matrix decomposition is a viable anonymization method and it can achieve better utility than existing anonymization methods. Tomoaki Mimoto, Shinsaku Kiyomoto, Seira Hidano, Anirban Basu 0001, Atsuko Miyaji |
PST | 3 |
| 2018 | Linear Depth Integer-Wise Homomorphic Division
Hiroki Okada 0001, Carlos Cid, Seira Hidano, Shinsaku Kiyomoto |
WISTP | 3 |
| 2017 | A Control Mechanism for Live Migration with Data Regulations Preservation
Toshihiro Uchibayashi, Yuichi Hashi, Seira Hidano, Shinsaku Kiyomoto, Bernady O. Apduhan, Toru Abe, Takuo Suganuma, Masahiro Hiji |
ICCSA (1) | 3 |
| 2017 | White-box Implementation of Stream Cipher
Kazuhide Fukushima, Seira Hidano, Shinsaku Kiyomoto |
ICISSP | 2 |
| 2017 | Model Inversion Attacks for Prediction Systems: Without Knowledge of Non-Sensitive AttributesabstractWhile online services based on machine learning (ML) have been attracting considerable attention in both academic and business, privacy issues are becoming a threat that cannot be ignored. Recently, Fredrikson et al. [USENIX 2014] proposed a new paradigm of model inversion attacks, which allows an adversary to expose the sensitive information of users by using an ML system for an unintended purpose. In particular, the attack reveals the sensitive attribute values of the target user by using their non-sensitive attributes and the output of the ML model. Here, for the attack to succeed, the adversary needs to possess the non-sensitive attribute values of the target user prior to the attack. However, in reality, even if this information (i.e., non-sensitive attributes) is not necessarily information the user regards as sensitive, it may be difficult for the adversary to actually acquire it. In this paper, we propose a general model inversion (GMI) framework to capture the above scenario where knowledge of the non-sensitive attributes is not necessarily provided. Here, our framework also captures the scenario of Fredrikson et al. Notably, we generalize the paradigm of Fredrikson et al. by additionally modeling the amount of auxiliary information the adversary possesses at the time of the attack. Our proposed GMI framework enables a new type of model inversion attack for prediction systems, which can be carried out without knowledge of the non-sensitive attributes. At a high level, we use the paradigm of data poisoning in a novel way and inject malicious data into the set of training data to modify the ML model into a target ML model, which we can attack without having to have knowledge of the non-sensitive attributes. Our new attack enables the inference of sensitive attributes in the user input from only the output of the ML model, even when the non-sensitive attributes of the user are not available to the adversary. Finally, we provide a concrete algorithm of our model inversion attack on prediction systems based on linear regression models, and give a detailed description of how the data poisoning algorithm is constructed.We evaluate the performance of our new model inversion attack without the knowledge of non-sensitive attributes through experiments with actual data sets. Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka |
PST | 1 |
| 2016 | Sensor-based Wearable PUFabstractThe Physically Unclonable Function (PUF) is a technique that generates unique device identifiers based on
variations in the manufacturing process. The Internet of Things (IoT) has become widespread, and various
kinds of devices are now available. Device authentication and key management are essential to provide a
secure service to these devices. We can use the unforgeable identifier generated by the PUF as a key for
encryption and authentication. However, the existing PUFs require a dedicated hardware or low-level software,
i.e., driver. Thus, they are impractical to use on smartphones or IoT devices due to the severe limitations
of production cost and power consumption. In this paper, we propose a sensor-based PUF that utilizes the
accelerometer and gyroscope, which are widely available on smartphones and IoT devices. We implement
the proposed PUF on a smartwatch and show that accelerometer-based PUF achieves good usability, extreme
robustness, and a high entropy of 91.66 bits. Kazuhide Fukushima, Seira Hidano, Shinsaku Kiyomoto |
SECRYPT | 2 |
| 2012 | Evaluation of wolf attack for classified target on speaker verification systemsabstractImpersonation attack is one of the major security issues of biometric authentication systems. Wolf attacks use a biometric sample such that the similarities between this sample and a number of templates are resulting in high false matches with these templates. In the conventional evaluation with the wolf attack probability (WAP), wolf attacks took advantage of vulnerabilities on the specific matching algorithms, and thereby high WAPs were achieved. However, in actual biometric authentication systems, their algorithm will be black boxes, and artificial samples will be refused by someones's observation or liveness detection; therefore, wolf attacks do not always have theoretical WAPs. We focus on speaker verification systems, and propose a wolf attack that does not depend on matching algorithms and in which people cannot guess whether wolves are artifacts or not. Additionally, we show that the wolf attack became more efficient by creating a wolf for each gender. Tetsushi Ohki, Seira Hidano, Tatsuya Takehisa |
ICARCV | 2 |
| 2010 | A metric of identification performance of biometrics based on information contentabstractWe propose the minimum distance entropy (MDE) as a metric of biométrie information content. The MDE is the probability that two biométrie samples correspond exactly expressed in information content and can be calculated through the experiment for interpersonal matching using a set of biométrie samples. This metric makes it possible for certain biometrics not only to be compared with other biometrics but also to be partially compared with personal authentication using passwords, PIN, or other methods in regard to the identification performance or the security. In this paper, we discuss the metric in terms of information theory and show how to evaluate it. Then, as an example, we apply it to a fingerprint system and evaluate fingerprint information content through simulations. Seira Hidano, Tetsushi Ohki, Naohisa Komatsu, Kenta Takahashi |
ICARCV | 1 |
| 2008 | On biometric encryption using fingerprint and it's security evaluationabstractBiometric person authentication has been attracting considerable attention in recent years. Conventional biometric person authentication systems, however, simply store each user's template as-is on the system. If registered templates are not properly protected, the risk arises of template leakage to a third party and impersonation using biometric data restored from a template. We propose a technique that encrypts and stores the user template and uses a “fuzzy vault scheme” to generate secret data from the user template and the query biometric data. It incorporates a measure to prevent the secret data and the user template used to obtain the secret data from being recovered from information stored in the system, and it enables the secret data to be generated from the user's biometric data. In this paper, we introduce this technique and evaluate template security with it by simulating a fingerprint authentication system. Seira Hidano, Tetsushi Ohki, Naohisa Komatsu, Masao Kasahara |
ICARCV | 1 |