Shoichi Saito

dblp:86/3995 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
7since 2021 · last 2026
0000-0003-3103-9656ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 VDDPI: Verifiable Decentralized Data Processing Infrastructure for Data Usage Control and Confidential Data Processing
Shota Tokuda, Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
IEEE Trans. Dependable Secur. Comput.4
2025 Investigating the Inconsistency of Errors Between CAs in the Wild for Trustworthiness Evaluation in Cross-Domain Authentication
abstract
Motivated by challenges in cyber-physical systems (CPS), this paper investigates the inconsistency of errors between certification authorities (CAs) to evaluate trustworthiness in cross-domain authentication. CPS integrates physical space and cyberspace through interconnected devices. Cross-domain authentication is essential for CPS, enabling dynamic communication between devices from different domains. Public key infrastructure (PKI) facilitates this authentication as multiple CAs bind public keys to device identities. However, recent research on evaluating the trustworthiness of PKI focuses on a single CA and overlooks the relationships between CAs. We analyze the inconsistency of errors between CAs based on public key certificates collected from the wild via Censys. Our findings reveal that CAs with inconsistencies often lack essential access information for CAs, risking incomplete certificate verification and communication with fraudulent devices. This research highlights the importance of considering CA relationships in trustworthiness evaluations for secure cross-domain authentication in heterogeneous CPS environments.
Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
KES3
2025 Plaintext in the Wild: Investigating Secure Connection Label Accuracy for Android Apps
abstract
Smartphones have become deeply integrated into daily life, prompting widespread concern over how mobile apps handle user data. The Google Play Store requires Android developers to disclose whether their apps encrypt user data during transmission via a "secure connection" label in the Data Safety section. However, these labels are self-declared, and their consistency with actual app behavior remains unclear. In this study, we empirically evaluate the consistency of secure connection labels with real-world data transmission practices by dynamically analyzing network traffic from over 12,000 top-ranked Android apps. We identify 65 apps transmitting sensitive data without encryption, and they collectively account for over 5.842 billion installs, indicating that a substantial number of users may be affected. A majority of them (i.e., 46 apps) falsely claim to encrypt data while transmitting sensitive information in plaintext, and the others correctly disclose the lack of encryption and transmit sensitive data in plaintext. We contacted developers of the inconsistent apps, resulting in several label updates. Our findings reveal a disconnect between declared and actual security practices and offer concrete recommendations to improve the integrity of privacy disclosures on app marketplaces.
Yusei Sakuraba, Hiroki Inayoshi, Shoichi Saito, Akito Monden
SCAM3
2024 Decentralized Data Usage Control with Confidential Data Processing on Trusted Execution Environment and Distributed Ledger Technology
Shota Tokuda, Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
NSS4
2022 Plug and Analyze: Usable Dynamic Taint Tracker for Android Apps
abstract
Taint analyses, especially static taint analyses, are utilized to uncover hidden and suspicious behaviors in Android apps. However, current static taint analyzers use imprecise Android models, producing unreliable results and increasing the result verification cost. On the other hand, current dynamic taint trackers accurately detect execution paths. However, they depend on specific Android versions and modified devices, reducing their usability. Also, the users may not be able to analyze prepared datasets comprehensively. The results of the current analyses would be biased and less trustworthy. This paper presents a new dynamic taint analyzer called T-Recs that tracks information flows by recording the app execution at the app's bytecode level on an Android device and reconstructing the execution on a server independently of specific Android versions and devices. The users can instantly start analyzing apps with T-Recs after plugging an unmodified device into their computer. We implemented and evaluated T-Recs with 158 apps of DroidBench 3.0 in comparison with current taint analyzers: FlowDroid (w/ and w/o IC3), Amandroid, DroidSafe, and TaintDroid (w/ and w/o IntelliDroid), and only T-Recs achieved 100% accuracy. The result of privacy leak detection in 96 popular Google Play apps shows that T-Recs detected 43 true positives, the highest among compared tools. Also, T-Recs analyzed 39,480 apps from Google Play and Anzhi, showing that T-Recs can be applied to apps that vary in supported SDK versions. Further, the result of ID leak detection in 158 popular apps from Google Play in 2021 shows that T-Recs can detect leaks in recently-developed apps. T-Recs is one of the promising tools for future app analysis.
Hiroki Inayoshi, Shohei Kakei, Shoichi Saito
SCAM3
2022 Granting Access Privileges Using OpenID Connect in Permissioned Distributed Ledgers
Shohei Kakei, Yoshiaki Shiraishi, Shoichi Saito
SecureComm3
2021 VTDroid: Value-based Tracking for Overcoming Anti-Taint-Analysis Techniques in Android Apps
abstract
Bytecode-level taint tracking discovers suspicious apps on the Android platform; however, malicious apps can bypass it by transferring information via system layers in the Android. A context tainting countermeasure has been devised, but since it employs a list of flow-causing API methods, it will miss flows when unlisted methods are exploited and can also produce false positives. This paper presents a new taint-tracking technique operating value logging and matching based on the flows’ characteristics to detect such flows without relying on lists of API methods. We implemented it into our taint-tracking system called VTDroid and confirmed its effectiveness with our test suite. We also evaluated it with popular apps collected from Google Play. The results show that the precision of VTDroid is 37 points higher than the context tainting.
Hiroki Inayoshi, Shohei Kakei, Eiji Takimoto, Koichi Mouri, Shoichi Saito
ARES5
2014 VSE: Virtual Switch Extension for Adaptive CPU Core Assignment in Softirq
abstract
An Edge-Overlay model constructing virtual networks using both virtual switches and IP tunnels is promising in cloud datacenter networks. But software-implemented virtual switches can cause performance problems because the packet processing load is concentrated on a particular CPU core. Although multi queue functions like Receive Side Scaling (RSS) can distribute the load onto multiple CPU cores, there are still problems to be solved such as IRQ core collision of heavy traffic flows as well as competitive resource use between physical and virtual for packet processing. In this paper, we propose a software packet processing unit named VSE (Virtual Switch Extension) to address these problems by adaptively determining softirq cores based on both CPU load and VM-running information. Furthermore, the behavior of VSE can be managed by Open Flow controllers. Our performance evaluation results showed that throughput of our approach was higher than an existing RSSbased model as packet processing load increased. In addition, we show that our method prevented performance of high-loaded flows from being degraded by priority-based CPU core selection.
Shin Muramatsu, Ryota Kawashima, Shoichi Saito, Hiroshi Matsuo
CloudCom3
2013 Forecasting Students' Future Academic Records Using Past Attendance Recording Data and Grade Data
abstract
In this study, the authors forecast students’ future academic records using past attendance recording data and grade data. We use a Bayesian network as forecasting method. During construction of the Bayesian network forecasting model, unnecessary variables become noise and so lower the forecasting accuracy. Therefore, to improve the forecasting accuracy, we used information gain to reduce the number of variables in the model. As a result, accuracy improved.
Hirotaka Itoh, Yuma Itoh, Kenji Funahashi, Daisuke Yamamoto, Shoichi Saito, Ichi Takumi, Hiroshi Matsuo
KES5
2013 Orthros: A High-Reliability Operating System with Transmigration of Processes
abstract
We propose a method to solve problems that accompany recovering from operating system (OS) failures. First, to reduce recovery time, we make two OSes run simultaneously and configure them as an active-backup structure in one computer. This structure can provide a fast recovery from failures by a failover. Recovery time when using the proposed method is about 0.4 seconds at a minimum and up to about 10 seconds even if 2 GB memory is restored. Next, for smooth continuation of services after recovery, the proposed method preserves processes, their network connections, and file caches, and does not have runtime overhead to obtain a process execution status from the running active OS before a crash. In addition, the resources consumed to build the active-backup structure are only one CPU core and a small amount of memory. The hardware required to implement the proposed method is a multi-core processor and one disk for each OS, consequently, introduction of the proposed method incurs low cost. In the evaluation, we confirmed that the downtime was up to about 1.5 seconds when the active OS of the proposed system crashed while running a text editor, an NFS server, and a database server.
Kenji Yoshida, Shoichi Saito, Koichi Mouri, Hiroshi Matsuo
PRDC2
2010 Monitoring Library Function-based Intrusion Prevention System with Continuing Execution Mechanism
abstract
Anomaly-based Intrusion Prevention Systems have been studied to prevent zero-day attacks. However these existing systems can't prevent mimicry attacks because of the inadequacy of monitoring accuracy. Moreover, they provide no continuity for monitored applications when they have been compromised. In this paper, we propose a novel Intrusion Prevention System named Belem that detects anomaly states by checking the ordering of library functions and has a Continuing Execution Mechanism to provide application continuity. We implemented Belem on Linux and evaluated it.
Yudai Kato, Yuji Makimoto, Hironori Shirai, Hiromi Shimizu, Yusuke Furuya, Shoichi Saito, Hiroshi Matsuo
EUC6
2009 Bifrost : A Novel Anonymous Communication System with DHT
abstract
An immense amount of information is processed on the Internet due to its spread, increasing the severity of such problems as the disclosure of personal information; privacy protection is required. Research to protect anonymity has become crucial. Anonymous communication systems must consider a sudden breakaway of nodes. However existing systems isn't considering this enough. This paper proposes separating a node management layer from an anonymous communication layer. A novel anonymous communication system is realized by a node management layer that uses Chord, which is a distributed hash table, and the anonymous communication layer uses multiplex encryptions.
Masaki Kondo, Shoichi Saito, Kiyohisa Ishiguro, Hiroyuki Tanaka, Hiroshi Matsuo
PDCAT2
2002 Estimation of EM radiation source in ELF band
abstract
Our goal is to locate anomalous electromagnetic (EM) source caused by seismic activity for earthquake prediction. For the purpose, we have been measured EM wave of 223 Hz at 35 sites in Japan. This paper analyses relation between EM power attenuation and distance from its source. The relation is necessary to estimate the source location.
Ichi Takumi, Shoichi Saito, Akio Shimura, Masayasu Hata, Hiroshi Yasukawa
IGARSS2