VLDB 2026 Research / reviewers in the wild / expert
Naoto Yanai
dblp:95/8821
· DBLP profile ↗
26ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0002-0817-6188ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 7 since 2021Theory of computation · 4 · 2 first-authorComputer networks · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SolShift: Design of Automated Solidity Code Translation Method to Prevent Reentrancy Attacks
Tsuyoshi Kanemaru, Naoto Yanai, Hideharu Kojima |
ICBC | 2 |
| 2026 | MUTUALISM: Low-Footprint and High-Throughput Software Implementation of HQC for Resource-Constrained DevicesabstractHamming Quasi-Cyclic (HQC) is a code-based key-encapsulation mechanism selected by NIST for post-quantum cryptography standardization, but it is challenging to deploy on resource-constrained devices due to its memory and computational costs. In this paper, we propose a novel software implementation of HQC, named MUTUALISM, which is deployable on resource-constrained devices. MUTUALISM builds on an efficient multiply-then-reduce method for sparse-dense polynomial multiplication that minimizes costly modular reduction operations. We further propose two variants of the multiplication algorithm that optimize memory footprint and computation throughput, respectively. We then present MUTUALISM as a unified and optimized implementation derived from fine-grained profiling of HQC. This implementation systematically integrates the aforementioned multiplication algorithms with additional optimizations throughout the HQC implementation pipeline, thereby reducing the memory footprint and improving end-to-end throughput. Our experiments on ARM Cortex-M4 show that MUTUALISM achieves a speedup of more than 57 times compared with PQClean while reducing the memory footprint by 80%. To the best of our knowledge, MUTUALISM is the first software-only HQC implementation deployable on resource-constrained devices with 64 KB of RAM across all security levels. This enables post-quantum key establishment on BLE-class IoT microcontrollers with only tens of kilobytes of SRAM, thereby bridging the gap between PQC standards and real-world wireless embedded deployments. Cong Liu 0029, Akira Maruko, Yasushi Takahashi, Naoto Yanai |
WISEC | 4 |
| 2025 | Aggregated Zero-Knowledge Proofs Toward Distributed Proof-of-Deep-LearningabstractThe recent machine learning requires huge machine resources and is often hard for users with limited resources. Although there are DPT, these are unsuitable for a situation where a trained model should be unrevealed from other users. In this paper, we first propose a new learning method, aggregated zero-knowledge deep learning (AZKDL), whereby even a user with a limited resource contributes to the learning process without revealing its model. Our main idea is to utilize aggregated zero-knowledge proofs where individual zero-knowledge proofs are aggregated into a single proof. Loosely speaking, users generate proofs for their training of parts of models and then aggregate both the models and the proofs to verify the entire models without revealing them. We also prove that AZKDL can detect malicious training. When we conduct experiments to evaluate AZKDL, we identify that even a client with the largest model parameters can finish the computation within a second. Furthermore, we propose the distributed proof-of-deep-learning (DPoDL) that rewards users who contribute to the learning process by applying AZKDL to a mining process of blockchains. DPoDL can detect malicious users by AZKDL. Yasushi Takahashi, Naohisa Nishida, Yuji Unagami, Naoto Yanai |
ICC | 4 |
| 2025 | MADONNA: Browser-based malicious domain detection using Optimized Neural Network by leveraging AI and feature analysisabstractDetecting malicious domains is a critical aspect of cybersecurity, with recent advancements leveraging Artificial Intelligence (AI) to enhance accuracy and speed. However, existing browser-based solutions often struggle to achieve both high accuracy and efficient throughput. In this paper, we present MADONNA, a novel browser-based malicious domain detector that exceeds the current state-of-the-art in both accuracy and throughput. MADONNA utilizes feature selection through correlation analysis and model optimization techniques, including pruning and quantization, to significantly enhance detection speed without compromising accuracy. Our approach employs a Shallow Neural Network (SNN) architecture, outperforming Large Language Models (LLMs) and state-of-the-art methods by improving accuracy by 6% (reaching 0.94) and F1-score by 4% (reaching 0.92). We further integrated MADONNA into a Google Chrome extension, demonstrating its practical application with a real-time domain detection accuracy of 94% and an average inference time of 0.87 s. These results highlight MADONNA’s effectiveness in balancing speed and accuracy, providing a scalable, real-world solution for malicious domain detection. Janaka Senanayake, Sampath Rajapaksha, Naoto Yanai, Harsha K. Kalutarage, Chika Komiya |
Comput. Secur. | 3 |
| 2025 | Empirical Study of Impact of Solidity Compiler Updates on Vulnerabilities in Ethereum Smart ContractsabstractVulnerabilities in Ethereum smart contracts often cause significant financial damage. Whereas the Solidity compiler has been updated to mitigate vulnerabilities, the effectiveness of these updates remains undisclosed to the best of our knowledge. In this paper, we aim to shed light on the impact of compiler versions on reducing vulnerabilities in Ethereum smart contracts. To achieve this, we collected 497,344 contracts with Solidity source codes from the Ethereum blockchain and analyzed their vulnerabilities. For three vulnerabilities of high severity, i.e., Locked Money , Using tx.origin , and Unchecked Call , we illustrate their appearance rate changes, showing decreases attributed to major updates of the Solidity compiler. Subsequently, we found the following four key insights. Firstly, updates to version 0.6 and version 0.8 led to decreased appearance rates for Locked Money . Secondly, regardless of compiler updates, the appearance rate for Using tx.origin was significantly low. Thirdly, the appearance rate for Unchecked Call significantly decreased from version 0.5 to version 0.8. Lastly, as an incidental discovery from our empirical study, we identified implications for code clones, which merit attention from subsequent researchers and developers. Chihiro Kado, Naoto Yanai, Jason Paul Cruz, Kyosuke Yamashita, Shingo Okamura |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2023 | IoT-REX: A Secure Remote-Control System for IoT Devices from Centralized Multi-designated Verifier Signatures
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata |
ISPEC | 2 |
| 2023 | MADONNA: Browser-Based MAlicious Domain Detection Through Optimized Neural Network with Feature Analysis
Janaka Senanayake, Sampath Rajapaksha, Naoto Yanai, Chika Komiya, Harsha K. Kalutarage |
SEC | 3 |
| 2023 | Do Backdoors Assist Membership Inference Attacks?
Yumeki Goto, Nami Ashizawa, Toshiki Shibahara, Naoto Yanai |
SecureComm (2) | 4 |
| 2023 | Privacy-Preserving Taxi-Demand Prediction Using Federated LearningabstractTaxi-demand prediction is an important application of machine learning that enables taxi-providing facilities to optimize their operations and city planners to improve transportation infrastructure and services. However, the use of sensitive data in these systems raises concerns about privacy and security. In this paper, we propose the use of federated learning for taxi-demand prediction that allows multiple parties to train a machine learning model on their own data while keeping the data private and secure. This can enable organizations to build models on data they otherwise would not be able to access. Evaluation with real-world data collected from 16 taxi service providers in Japan over a period of six months showed that the proposed system can predict the demand level accurately within 1% error compared to a single model trained with integrated data. Yumeki Goto, Tomoya Matsumoto, Hamada Rizk, Naoto Yanai, Hirozumi Yamaguchi |
SMARTCOMP | 4 |
| 2022 | APKC '22: 9th ACM ASIA Public-Key Cryptography WorkshopabstractPublic key cryptography plays an essential role in ensuring many security properties required in data processing of various kinds. The theme of this workshop is novel public-key cryptosystems for solving a wide range of real-life application problems. This workshop solicits original contributions on both applied and theoretical aspects of public-key cryptography. Jason Paul Cruz, Naoto Yanai |
AsiaCCS | 2 |
| 2022 | Eth2Vec: Learning contract-wide code representations for vulnerability detection on Ethereum smart contractsabstractEthereum smart contracts are computer programs that are deployed and executed on the Ethereum blockchain to enforce agreements among untrusting parties. Being the most prominent platform that supports smart contracts, Ethereum has been targeted by many attacks and plagued by security incidents. Consequently, many smart contract vulnerabilities have been discovered in the past decade. To detect and prevent such vulnerabilities, different security analysis tools, including static and dynamic analysis tools, have been created, but their performance decreases drastically when codes to be analyzed are constantly being rewritten. In this paper, we propose Eth2Vec, a machine-learning-based static analysis tool that detects smart contract vulnerabilities. Eth2Vec maintains its robustness against code rewrites; i.e., it can detect vulnerabilities even in rewritten codes. Other machine-learning-based static analysis tools require features, which analysts create manually, as inputs. In contrast, Eth2Vec uses a neural network for language processing to automatically learn the features of vulnerable contracts. In doing so, Eth2Vec can detect vulnerabilities in smart contracts by comparing the similarities between the codes of a target contract and those of the learned contracts. We performed experiments with existing open databases, such as Etherscan, and Eth2Vec was able to outperform a recent model based on support vector machine in terms of well-known metrics, i.e., precision, recall, and F1-score. Nami Ashizawa, Naoto Yanai, Jason Paul Cruz, Shingo Okamura |
Blockchain Res. Appl. | 2 |
| 2021 | Anonymous Broadcast Authentication for Securely Remote-Controlling IoT Devices
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata |
AINA (2) | 2 |
| 2021 | SQUAB: A Virtualized Infrastructure for Experiments on BGP and its Extensions
Naoki Umeda, Naoto Yanai, Tatsuya Takemura, Masayuki Okada, Jason Paul Cruz, Shingo Okamura |
AINA (1) | 2 |
| 2021 | Self-Organizing Map assisted Deep Autoencoding Gaussian Mixture Model for Intrusion DetectionabstractIn the information age, a secure and stable network environment is essential and hence intrusion detection is critical for any networks. In this paper, we propose a self-organizing map assisted deep autoencoding Gaussian mixture model (SOM-DAGMM) supplemented with well-preserved input space topology for more accurate network intrusion detection. The deep autoencoding Gaussian mixture model comprises a compression network and an estimation network which is able to perform unsupervised joint training. However, the code generated by the autoencoder is inept at preserving the topology of the input space, which is rooted in the bottleneck of the adopted deep structure. A self-organizing map has been introduced to construct SOM-DAGMM for addressing this issue. The superiority of the proposed SOM-DAGMM is empirically demonstrated with extensive experiments conducted upon two datasets. Experimental results show that SOM-DAGMM outperforms state-of-the-art DAGMM on all tests, and achieves up to 15.58% improvement in F1 score and with better stability. Yang Chen 0007, Nami Ashizawa, Seanglidet Yean, Chai Kiat Yeo, Naoto Yanai |
CCNC | 5 |
| 2021 | APVAS+: A Practical Extension of BGPsec with Low Memory RequirementabstractBGPsec is a protocol that utilizes digital signatures to guarantee the validity of routing information on the Internet. However, it is impractical because its use of digital signatures requires significant memory that is beyond the memory capacity of current routers. The latest extension of BGPsec based on an aggregate signature scheme, which aggregates individual signatures into a single short signature, has been proposed in the recent years, but its memory requirement is still impractical. In this paper, we present APVAS+, a protocol that reduces the memory consumption of routers compared to state-of-the-art protocols. The memory requirement of APVAS+ is almost within the memory capacity of real-world routers. While the latest BGPsec protocol can only aggregate signatures generated on a single linear network topology, APVAS+ can aggregate signatures generated on any network topology by using a novel aggregate signature scheme. We also show a prototype implementation of APVAS+ by extending a router software called BIRD. Using this prototype, we conducted experiments on a full route information, i.e., about 800,000 routes. We consider that APVAS+ can be optimized to further reduce its memory requirement, and our promising results show that the memory consumption of routers running APVAS+ is lower than that of routers running other protocols by more than half when guaranteeing the validity of routing information. Tatsuya Takemura, Naoto Yanai, Naoki Umeda, Masayuki Okada, Shingo Okamura, Jason Paul Cruz |
ICC | 2 |
| 2021 | Multi-scale Self-Organizing Map assisted Deep Autoencoding Gaussian Mixture Model for unsupervised intrusion detection
Yang Chen 0007, Nami Ashizawa, Chai Kiat Yeo, Naoto Yanai, Seanglidet Yean |
Knowl. Based Syst. | 4 |
| 2019 | Implementation and Evaluation of ISDSR in Emulation EnvironmentsabstractSecure wireless routing protocols which use an authentication mechanism, such as digital signatures, prevent attacks whereby an attacker injects fake data in the route information in the process of establishing a route. In this paper, we focus on a multi-hop secure routing protocol called ISDSR, which is a secure variant of DSR with ID-based sequential aggregate signatures. ISDSR guarantees the correctness of route information that contains a collection of nodes that constitute a travel path of a received packet. Analytic results on the performance of this protocol were provided in previous work; but the performance in a practical situation has not been investigated so far. In this work, we present the results of our experiments using two types of emulation environments where the network are formed with nine to 100 nodes. The results show that ISDSR is superior to the RSA-based secure routing protocol with respect to packet loss rate. Shinnosuke Shimizu, Hideharu Kojima, Naoto Yanai, Tatsuhiro Tsuchiya |
WCNC | 3 |
| 2017 | Identity-Based Key-Insulated Aggregate Signatures, Revisited
Nobuaki Kitajima, Naoto Yanai, Takashi Nishide |
Inscrypt | 2 |
| 2016 | Tightly-Secure Identity-Based Structured Aggregate Signature Scheme under the Computational Diffie-Hellman AssumptionabstractAn aggregate signature scheme is a primitive whereby each signer signs an individual document and combines them to compress data size. We propose an aggregate signature scheme which is an extension in two standpoints of structured signatures and ID-based signatures, i.e., we construct an identity-based structured aggregate signature scheme. The proposed scheme is expected to be used with consumer-generated media services. We prove the security of the proposed scheme with tight reduction under the computational Diffie-Hellman (CDH) assumption in the random oracle model. Tight reduction means that the cost of a reduction algorithm is independent of an adversary's capability, i.e., security is not downgraded by the adversary's capability. To the best of our knowledge, no structured signature scheme with tight reduction has been proposed to date because it contains complicated structures that make the reduction inefficient. Note that the security of our scheme captures the switching attack (CCS 2007, Boldyreva et al.) and the re-ordering attack (ISPEC 2007, Shao), which break several famous schemes. Tomoya Iwasaki, Naoto Yanai, Masaki Inamura, Keiichi Iwamura |
AINA | 2 |
| 2016 | Towards a formal foundation of protection against data-oriented attacks
Ryo Fukuyama, Naoto Yanai, Shingo Okamura, Toru Fujiwara |
ISITA | 2 |
| 2016 | Web security model with cache
Hayato Shimamoto, Naoto Yanai, Shingo Okamura, Toru Fujiwara |
ISITA | 2 |
| 2016 | ISDSR: Secure DSR with ID-based Sequential Aggregate SignatureabstractWireless sensor networks are often more vulnerable than wired ones. Especially, an adversary can attack the
networks by utilizing false route information. A countermeasure against the attack is a secure routing protocol
with digital signatures to guarantee the validity of route information. However, existing secure routing protocols
are inefficient because the memory size and the computational overhead are heavy. To overcome these
problems, we focus on ID-based sequential aggregate signatures (IBSAS) (Boldyreva et al., 2007). IBSAS
allow users to aggregate individual signatures into a single signature. Moreover, certificates of public keys are
unnecessary for IBSAS. Therefore, IBSAS can drastically decrease the memory size and the computational
overhead. Besides, one of the main concerns for practical use is to construct a protocol specification with
IBSAS. Moreover, since IBSAS are sometimes weak against compromising secret keys, another concern is to
construct its countermeasure. For these purposes, we propose a secure dynamic source routing with ID-based
sequential aggregate signatures, called ISDSR for short and discuss the key management to revoke/update
compromised keys. We also show that the performance of ISDSR is the best in comparison with the existing
protocols. Kenta Muranaka, Naoto Yanai, Shingo Okamura, Toru Fujiwara |
SECRYPT | 2 |
| 2015 | Gateway Threshold Password-based Authenticated Key Exchange Secure against Undetectable On-line Dictionary AttackabstractPassword-based Authenticated Key Exchange (PAKE) allows a server to authenticate a user and to establish a session key shared between the server and the user just by having memorable passwords. In PAKE, conventionally the server is assumed to have the authentication functionality and also provide on-line services simultaneously. However, in the real-life applications, this may not be the case, and the authentication server may be separate from on-line service providers. In such a case, there is a problem that a malicious service provider with no authentication functionality may be able to guess the passwords by interacting with other participants repeatedly. Abdalla et al. put forward a notion of the server password protection security to deal with this problem. However, their proposed schemes turned out to be vulnerable to Undetectable On-line Dictionary Attack (UDonDA). To cope with this situation, we propose the Gateway Threshold PAKE provably secure against this password guessing attack by also taking the corruption of authentication servers into consideration. Yukou Kobayashi, Naoto Yanai, Kazuki Yoneyama, Takashi Nishide, Goichiro Hanaoka, Kwangjo Kim, Eiji Okamoto |
SECRYPT | 2 |
| 2014 | A CDH-based ordered multisignature scheme in the standard model with better efficiency
Naoto Yanai, Masahiro Mambo, Eiji Okamoto |
ISITA | 1 |
| 2013 | An Ordered Multisignature Scheme Under the CDH Assumption Without Random Oracles
Naoto Yanai, Masahiro Mambo, Eiji Okamoto |
ISC | 1 |
| 2010 | A structured aggregate signature schemeabstractIn multisignature scheme, verifiying the signing order is sometimes very important. A multisignature scheme in which generated signatures reflect the structure of signers, e.g. signing order, is called structured multisignature scheme and many such schemes have been proposed so far. Structured multisignature schemes are dedicated to represent not only serial/parallel signer structures but also mixture of serial and parallel signer structures. In most structured schemes, the signature size depends on the number of signers. There are some structured schemes which can generate fixed-size signatures, but these schemes do not have order-flexibility, i.e. public keys arranged for one signer structure cannot be used for other signer structure. On the other hand, a sequential multisignature scheme is one type of structured multisignature schemes, which is dedicated to represent the serial signer structure. Some sequential multisig-nature scheme like sequential aggregate signature schemes can generate fixed-size signatures and have order-flexibility but no structured aggregate signature scheme has been proposed so far. In this paper, we construct a structured aggregate scheme which provides order-flexiblity, the fixed-size signature and applicability to mixed signer structures by extending the sequential aggregate signature scheme by Boldyreva et al. Naoto Yanai, Eikoh Chida, Masahiro Mambo |
ISITA | 1 |