Takahiro Matsuda 0002

dblp:m/TakahiroMatsuda2 · DBLP profile ↗
← Back
53ranked-venue papers
11as first author
17since 2021 · last 2026
0000-0002-2882-3901ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 51 · 11 first-author · 17 since 2021Theory of computation · 12 · 5 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 (Re-)Formalization and Construction of Reusable and Robust Threshold Fuzzy Extractors
Keisuke Hara, Keitaro Hashimoto, Takahiro Matsuda 0002, Wataru Nakamura, Kenta Takahashi
ACNS (2)3
2026 A Unifying Umbrella for Circular-Secure Cryptographic Primitives
Fuyuki Kitagawa, Takahiro Matsuda 0002
CRYPTO (1)2
2026 Revisiting Security Definitions of Sender-Anamorphic Encryption
Yuichi Tanishita, Takahiro Matsuda 0002, Kanta Matsuura
PKC (4)2
2025 Abuse-Resistant Evaluation of AI-as-a-Service via Function-Hiding Homomorphic Signatures
Nuttapong Attrapadung, Goichiro Hanaoaka, Ryo Hiromasa, Yoshihiro Koseki, Takahiro Matsuda 0002, Yutaro Nishida, Yusuke Sakai 0001, Jacob C. N. Schuldt, Satoshi Yasuda
ESORICS (1)5
2025 Chosen Ciphertext Security via BARGs
Takahiro Matsuda 0002
PKC (4)1
2024 On the Implications from Updatable Encryption to Public-Key Cryptographic Primitives
Yuichi Tanishita, Ryuya Hayashi, Ryu Ishii, Takahiro Matsuda 0002, Kanta Matsuura
ACISP (1)4
2024 Privacy-Preserving Verifiable CNNs
abstract
Convolutional neural networks (CNNs) have emerged as one of the most successful deep learning approaches to image recognition and classification. A recent line of research, which includes zkCNN (ACM CCS ’21), vCNN (Cryptology ePrint Archive), and ZEN (Cryptology ePrint Archive), aims at protecting the privacy of CNN models by developing publicly verifiable proofs of correct classification which do not leak any information about the underlying CNN models themselves. A shared feature of these schemes is that they require the entity constructing the proof to have access to both the model and the input in the clear. In other words, a client holding a potentially sensitive input is required to reveal this input to the entity holding the CNN model, thereby sacrificing his privacy, to be able to obtain a verifiable proof of correct classification. This is in contrast to the security guarantees provided by secure classification considered in privacy-preserving machine learning, which does not require the client to reveal his input to obtain a (non-verifiable) classification. In this paper, we propose a privacy-preserving verifiable CNN scheme that overcomes this limitation of the previous schemes by allowing the client to obtain a classification proof without having to reveal his input. The obtained proof allows the client to selectively reveal properties of the obtained classification and his input, which will be verifiable to any third-party verifier. Our scheme is based on the recent notion of collaborative zk-SNARKs by Ozdemir and Boneh (USENIX ’22). Specifically, we construct a new collaborative zk-SNARK based on Bulletproofs achieving an efficient maliciously secure proof generation protocol. Based on this, we then present an optimized approach to CNN evaluation. Finally, we demonstrate the feasibility of our approach by measuring the performance of our scheme on a CNN for classifying the MNIST dataset.
Nuttapong Attrapadung, Goichiro Hanaoka, Ryo Hiromasa, Yoshihiro Koseki, Takahiro Matsuda 0002, Yutaro Nishida, Yusuke Sakai 0001, Jacob C. N. Schuldt, Satoshi Yasuda
ACNS (2)5
2024 Updatable Encryption Secure Against Randomness Compromise
Yuichi Tanishita, Ryuya Hayashi, Ryu Ishii, Takahiro Matsuda 0002, Kanta Matsuura
CANS (2)4
2023 Signature for Objects: Formalizing How to Authenticate Physical Data and More
Ryuya Hayashi, Taiki Asano, Junichiro Hayata, Takahiro Matsuda 0002, Shota Yamada 0001, Shuichi Katsumata, Yusuke Sakai 0001, Tadanori Teruya, Jacob C. N. Schuldt, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Tsutomu Matsumoto
FC (1)4
2023 Two-Dimensional Dynamic Fusion for Continuous Authentication
abstract
Continuous authentication has been widely studied to provide high security and usability for mobile devices by continuously monitoring and authenticating users. Recent studies adopt multibiometric fusion for continuous authentication to provide high accuracy even when some of captured biometric data are of a low quality. However, existing continuous fusion approaches are resource-heavy as they rely on all classifiers being activated all the time and may not be suitable for mobile devices.In this paper, we propose a new approach to multibiometric continuous authentication: two-dimensional dynamic fusion. Our key insight is that multibiometric continuous authentication calculates two-dimensional matching scores over classifiers and over time. Based on this, we dynamically select a set of classifiers based on the context in which authentication is taking place, and fuse matching scores by multi-classifier fusion and multi-sample fusion. Through experimental evaluation, we show that our approach provides a better balance between resource usage and accuracy than the existing fusion methods. In particular, we show that our approach provides higher accuracy than the existing methods with the same number of score calculations by adopting multi-sample fusion.
Nuttapong Attrapadung, Goichiro Hanaoka, Haochen M. Kotoi-Xie, Takahiro Matsuda 0002, Takumi Moriyama, Takao Murakami, Hidenori Nakamura, Jacob C. N. Schuldt, Masaaki Tokuyama
IJCB4
2023 Maliciously circuit-private multi-key FHE and MPC based on LWE
abstract
Abstract In this paper, we construct multi-key homomorphic and fully homomorphic encryption (resp. MKHE and MKFHE) schemes with malicious circuit privacy. Our schemes are based on learning with errors (LWE) besides appropriate circular security assumptions. In contrast, the previous maliciously circuit-private MKFHE scheme by Chongchitmate and Ostrovsky (PKC, 2017) is based on the non-standard decisional small polynomial ratio (DSPR) assumption with a super-polynomial modulus, besides ring learning with errors and circular security assumptions. We note that it was shown by Albrecht et al. (CRYPTO, 2016) that there exists a sub-exponential time attack against this type of DSPR assumption. The main building block of our maliciously circuit-private MKFHE scheme is a (plain) MKFHE scheme by Brakerski et al. (TCC, 2017), and the security of our schemes is proven under the hardness of LWE with sub-exponential modulus-to-noise ratio and circular security assumptions related to the Brakerski et al. scheme. Furthermore, based on our MKFHE schemes, we construct four-round multi-party computation (MPC) protocols with circuit privacy against a semi-honest server and malicious clients in the plain model. The protocols are obtained by combining our schemes with a maliciously sender-private oblivious transfer protocol and a circuit garbling scheme, all of which can be instantiated only assuming LWE.
Nuttapong Attrapadung, Goichiro Hanaoka, Ryo Hiromasa, Takahiro Matsuda 0002, Jacob C. N. Schuldt
Des. Codes Cryptogr.4
2023 NIZK from SNARGs
Fuyuki Kitagawa, Takahiro Matsuda 0002, Takashi Yamakawa
J. Cryptol.2
2022 Generic transformation from broadcast encryption to round-optimal deniable ring authentication
Keisuke Hara, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
Des. Codes Cryptogr.2
2022 CCA Security and Trapdoor Functions via Key-Dependent-Message Security
Fuyuki Kitagawa, Takahiro Matsuda 0002, Keisuke Tanaka
J. Cryptol.2
2022 Adam in Private: Secure and Fast Training of Deep Neural Networks with Adaptive Moment Estimation
abstract
Machine Learning (ML) algorithms, especially deep neural networks (DNN), have proven themselves to be extremely useful tools for data analysis, and are increasingly being deployed in systems operating on sensitive data, such as recommendation systems, banking fraud detection, and healthcare systems. This underscores the need for privacy-preserving ML (PPML) systems, and has inspired a line of research into how such systems can be constructed efficiently. However, most prior works on PPML achieve efficiency by requiring advanced ML algorithms to be simplified or substituted with approximated variants that are “MPC-friendly” before multi-party computation (MPC) techniques are applied to obtain a PPML systems. A drawback of this approach is that it requires careful fine-tuning of the combined ML and MPC algorithms, and might lead to less efficient algorithms or inferior quality ML (such as lower prediction accuracy). This is an issue for secure training of DNNs in particular, as this involves several arithmetic algorithms that are thought to be “MPCunfriendly”, namely, integer division, exponentiation, inversion, and square root extraction. In this work, we take a structurally different approach and propose a framework that allows efficient and secure evaluation of full-fledged state-of-the-art ML algorithms via secure multi-party computation. Specifically, we propose secure and efficient protocols for the above seemingly MPC-unfriendly computations (but which are essential to DNN). Our protocols are three-party protocols in the honest-majority setting, and we propose both passively secure and actively secure with abort variants. A notable feature of our protocols is that they simultaneously provide high accuracy and efficiency. This framework enables us to efficiently and securely compute modern ML algorithms such as Adam (Adaptive moment estimation) and the softmax function “as is”, without resorting to approximations. As a result, we obtain secure DNN training that outperforms state-of-the-art threeparty systems; our full training is up to 6.7 times faster than just the online phase of FALCON (Wagh et al. at PETS’21) and up to 4.2 times faster than Dalskov et al. (USENIX’21) on the standard benchmark network for secure training of DNNs. The potential advantage of our approach is even greater when considering more complex realistic networks. To demonstrate this, we perform measurements on real-world DNNs, AlexNet and VGG16, which are large networks containing millions of parameters. The performance of our framework for these networks is up to a factor of 26 ∼ 33 faster for AlexNet and 48 ∼ 51 faster for VGG16 to achieve an accuracy of 60% and 70%, respectively, when compared to FALCON. Even compared to CRYPTGPU (Tan et al. IEEE S&P’21), which is optimized for and runs on powerful GPUs, our framework achieves a factor of 2.1 and 4.1 faster performance, respectively, on these networks.
Nuttapong Attrapadung, Koki Hamada, Dai Ikarashi, Ryo Kikuchi, Takahiro Matsuda 0002, Ibuki Mishina, Hiraku Morita, Jacob C. N. Schuldt
Proc. Priv. Enhancing Technol.5
2021 Oblivious Linear Group Actions and Applications
abstract
In this paper we propose efficient two-party protocols for obliviously applying a (possibly random) linear group action to a data set. Our protocols capture various applications such as oblivious shuffles, circular shifts, matrix multiplications, to name just a few. A notable feature enjoyed by our protocols, is that they admit a round-optimal (more precisely, one-round) online computation phase, once an input-independent off-line computation phase has been completed. Our oblivious shuffle is the first to achieve a round-optimal online phase. The most efficient instantiations of our protocols are obtained in the so-called client-aided client-server setting, where the offline phase is run by a semi-honest input party (client) who will then distribute the generated correlated randomness to the computing parties (servers). When comparing the total running time to the previous best two-party oblivious shuffle protocol by Chase et al. (Asiacrypt 2020), our shuffle protocol in this client-aided setting is up to 105 times and 152 times faster, in the LAN and WAN setting, respectively. We additionally show how the Chase et al. protocol (which is a standard two-party protocol) can be modified to leverage the advantages of the client-aided setting, but show that, even doing so, our scheme is still two times faster in the online phase and 1.34 times faster in total on average.
Nuttapong Attrapadung, Goichiro Hanaoka, Takahiro Matsuda 0002, Hiraku Morita, Kazuma Ohara, Jacob C. N. Schuldt, Tadanori Teruya, Kazunari Tozawa
CCS3
2021 Revisiting Fuzzy Signatures: Towards a More Risk-Free Cryptographic Authentication System based on Biometrics
abstract
Biometric authentication is one of the promising alternatives to standard password-based authentication offering better usability and security. In this work, we revisit the biometric authentication based on fuzzy signatures introduced by Takahashi et al. (ACNS'15, IJIS'19). These are special types of digital signatures where the secret signing key can be a ''fuzzy'' data such as user's biometrics. Compared to other cryptographically secure biometric authentications as those relying on fuzzy extractors, the fuzzy signature-based scheme provides a more attractive security guarantee. However, despite their potential values, fuzzy signatures have not attracted much attention owing to their theory-oriented presentations in all prior works. For instance, the discussion on the practical feasibility of the assumptions (such as the entropy of user biometrics), which the security of fuzzy signatures hinges on, is completely missing.
Shuichi Katsumata, Takahiro Matsuda 0002, Wataru Nakamura, Kazuma Ohara, Kenta Takahashi
CCS2
2020 Circular Security Is Complete for KDM Security
Fuyuki Kitagawa, Takahiro Matsuda 0002
ASIACRYPT (1)2
2020 NIZK from SNARG
Fuyuki Kitagawa, Takahiro Matsuda 0002, Takashi Yamakawa
TCC (1)2
2020 Lattice-based revocable (hierarchical) IBE with decryption key exposure resistance
Shuichi Katsumata, Takahiro Matsuda 0002, Atsushi Takayasu
Theor. Comput. Sci.2
2019 Field Extension in Secret-Shared Form and Its Applications to Efficient Secure Computation
Ryo Kikuchi, Nuttapong Attrapadung, Koki Hamada, Dai Ikarashi, Ai Ishida, Takahiro Matsuda 0002, Yusuke Sakai 0001, Jacob C. N. Schuldt
ACISP6
2019 Simple and Efficient KDM-CCA Secure Public Key Encryption
Fuyuki Kitagawa, Takahiro Matsuda 0002, Keisuke Tanaka
ASIACRYPT (3)2
2019 CCA Security and Trapdoor Functions via Key-Dependent-Message Security
Fuyuki Kitagawa, Takahiro Matsuda 0002, Keisuke Tanaka
CRYPTO (3)2
2019 CPA-to-CCA Transformation for KDM Security
Fuyuki Kitagawa, Takahiro Matsuda 0002
TCC (2)2
2019 Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions
abstract
This paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes.
Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazuma Ohara, Kazumasa Omote, Yusuke Sakai 0001
Secur. Commun. Networks4
2019 Simulation-based receiver selective opening CCA secure PKE from standard computational assumptions
Keisuke Hara, Fuyuki Kitagawa, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
Theor. Comput. Sci.3
2018 Efficient Bit-Decomposition and Modulus-Conversion Protocols with an Honest Majority
Ryo Kikuchi, Dai Ikarashi, Takahiro Matsuda 0002, Koki Hamada, Koji Chida
ACISP3
2018 Constrained PRFs for \mathrmNC^1 in Traditional Groups
Nuttapong Attrapadung, Takahiro Matsuda 0002, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa
CRYPTO (2)2
2018 Memory Lower Bounds of Reductions Revisited
Yuyu Wang 0001, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
EUROCRYPT (1)2
2018 A New Key Encapsulation Combiner
abstract
Key encapsulation mechanism (KEM) combiners, recently formalized by Giacon, Heuer, and Poettering (PKC'18), enable hedging against insecure KEMs or weak parameter choices by combining ingredient KEMs into a single KEM that remains secure assuming just one of the underlying ingredient KEMs is secure. This seems particularly relevant when considering quantum-resistant KEMs which are often based on arguably less well-understood hardness assumptions and parameter choices. We propose a new simple KEM combiner based on a one-time secure message authentication code (MAC) and two-time correlated input secure hash. Instantiating the correlated input secure hash with a t-wise independent hash for an appropriate value of t, yields a KEM combiner based on a strictly weaker additional primitive than the standard model construction of Giacon et al. and furthermore removes the need to do n full passes over the encapsulation, where n is the number of ingredient KEMs, which Giacon et al. highlight as a disadvantage of their scheme.
Takahiro Matsuda 0002, Jacob C. N. Schuldt
ISITA1
2018 Embedding Lemmas for Functional Encryption
abstract
Functional encryption is an extension of the ordinary public key encryption where decryption results vary depending on the functions (or key attributes) associated to secret keys. In this paper, we show an embedding lemma for functional encryption, which provides a sufficient criterion for implication from one FE to FE with another function class. The lemma is an extension of the embedding lemma for attribute-based encryption that was introduced in the previous work by Boneh and Hamburg (Asiacrypt 2008). As an application of our lemma, we show that FE for cubic forms can be constructed from FE for inner product or FE for quadratic forms.
Ryo Kato, Naohisa Nishida, Ryo Hirano, Tatsumi Oba, Yuji Unagami, Shota Yamada 0001, Tadanori Teruya, Nuttapong Attrapadung, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA9
2018 Chosen ciphertext secure keyed-homomorphic public-key cryptosystems
Keita Emura, Goichiro Hanaoka, Koji Nuida, Go Ohtake, Takahiro Matsuda 0002, Shota Yamada 0001
Des. Codes Cryptogr.5
2016 Fuzzy Signatures: Relaxing Requirements and a New Construction
Takahiro Matsuda 0002, Kenta Takahashi, Takao Murakami, Goichiro Hanaoka
ACNS1
2016 How to Obtain Fully Structure-Preserving (Automorphic) Signatures from Structure-Preserving Ones
Yuyu Wang 0001, Zongyang Zhang, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
ASIACRYPT (2)3
2016 Tag-KEM/DEM framework for public-key encryption with non-interactive opening
Yusuke Sakai 0001, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA2
2016 Private similarity searchable encryption for Euclidean distance
Yuji Unagami, Natsume Matsuzaki, Shota Yamada 0001, Nuttapong Attrapadung, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA5
2016 Efficient key encapsulation mechanisms with tight security reductions to standard assumptions in the two security models
abstract
Abstract In this paper, we propose two new practical constructions of chosen ciphertext attack secure (CCA secure) key encapsulation mechanisms (KEM, which is the main building block for public key encryption in hybrid encryption), with remarkable security features: Our KEMs can be proved not only to satisfy CCA security (or constrained CCA security introduced by Hofheinz and Kiltz at CRYPTO'07) in the standard model with a tight security reduction to a basic indistinguishability‐type assumption but also to be CCA secure in the random oracle model with a tight security reduction to a basic computational‐type assumption. Our first construction is based on the Diffie–Hellman‐type assumptions, and compared with the KEM by Shoup at EUROCRYPT'00 that has security reductions in two security models (but its security proof in the random model is a loose reduction), our proposed KEM has a smaller ciphertext size with the same computational costs, and more importantly, ours has a tight security reduction also in the random oracle model. Our second construction is based on assumptions related to integer factoring, and compared with the KEM by Hofheinz and Kiltz at CRYPTO'99 that also has tight security reductions in two security models to factoring‐related assumptions, our proposed KEM has similar efficiency (both ciphertext size and computational costs) and bases the security on incomparable assumptions. Copyright © 2016 John Wiley & Sons, Ltd.
Yoshikazu Hanatani, Goichiro Hanaoka, Takahiro Matsuda 0002, Takashi Yamakawa
Secur. Commun. Networks3
2015 A Signature Scheme with a Fuzzy Private Key
Kenta Takahashi, Takahiro Matsuda 0002, Takao Murakami, Goichiro Hanaoka, Masakatsu Nishigaki
ACNS2
2015 An Asymptotically Optimal Method for Converting Bit Encryption to Multi-Bit Encryption
Takahiro Matsuda 0002, Goichiro Hanaoka
ASIACRYPT (1)1
2015 Completeness of Single-Bit Projection-KDM Security for Public Key Encryption
Fuyuki Kitagawa, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
CT-RSA2
2015 Re-Encryption Verifiability: How to Detect Malicious Activities of a Proxy in Proxy Re-Encryption
Satsuya Ohata, Yutaka Kawai, Takahiro Matsuda 0002, Goichiro Hanaoka, Kanta Matsuura
CT-RSA3
2015 Constructing and Understanding Chosen Ciphertext Security via Puncturable Key Encapsulation Mechanisms
Takahiro Matsuda 0002, Goichiro Hanaoka
TCC (1)1
2014 Chosen Ciphertext Security via Point Obfuscation
Takahiro Matsuda 0002, Goichiro Hanaoka
TCC1
2014 On the Impossibility of Basing Public-Coin One-Way Permutations on Trapdoor Permutations
Takahiro Matsuda 0002
TCC1
2013 Reducing Public Key Sizes in Bounded CCA-Secure KEMs with Optimal Ciphertext Length
Takashi Yamakawa, Shota Yamada 0001, Takahiro Matsuda 0002, Goichiro Hanaoka, Noboru Kunihiro
ISC3
2012 On the Impossibility of Constructing Efficient Key Encapsulation and Programmable Hash Functions in Prime Order Groups
Goichiro Hanaoka, Takahiro Matsuda 0002, Jacob C. N. Schuldt
CRYPTO2
2012 Generic Construction of Chosen Ciphertext Secure Proxy Re-Encryption
Goichiro Hanaoka, Yutaka Kawai, Noboru Kunihiro, Takahiro Matsuda 0002, Jian Weng 0001, Rui Zhang 0002, Yunlei Zhao
CT-RSA4
2012 Group Signatures with Message-Dependent Opening
Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazumasa Omote
Pairing5
2011 Efficient Generic Constructions of Signcryption with Insider Security in the Multi-user Setting
Daiki Chiba 0002, Takahiro Matsuda 0002, Jacob C. N. Schuldt, Kanta Matsuura
ACNS2
2011 On Black-Box Separations among Injective One-Way Functions
Takahiro Matsuda 0002, Kanta Matsuura
TCC1
2010 Efficient Generic Constructions of Timed-Release Encryption with Pre-open Capability
Takahiro Matsuda 0002, Yasumasa Nakai, Kanta Matsuura
Pairing1
2009 An Efficient Encapsulation Scheme from Near Collision Resistant Pseudorandom Generators and Its Application to IBE-to-PKE Transformations
Takahiro Matsuda 0002, Goichiro Hanaoka, Kanta Matsuura, Hideki Imai
CT-RSA1
2007 A CDH-Based Strongly Unforgeable Signature Without Collision Resistant Hash Function
Takahiro Matsuda 0002, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Hideki Imai
ProvSec1