EDBT 2026 Demo / reviewers in the wild / expert
Tsunato Nakai
dblp:149/5103
· DBLP profile ↗
7ranked-venue papers
5as first author
4since 2021 · last 2026
0009-0008-0544-3173ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 4 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Can Large Language Models Unlock Logic Locking?abstractIn the realm of integrated circuit (IC) manufacturing, the industry faces security threats such as the theft of intellectual property and reverse engineering. In response to these threats, logic locking has gained significant attention as a viable countermeasure. Logic locking is a technique that obfuscates the operation of an IC by integrating specific gates or components into the circuit design, allowing the IC to function only under certain conditions. Traditional logic locking methods have been vulnerable to SAT attacks; however, recent research has shown that multi-key logic locking serves as an effective countermeasure against these attacks. Currently, there is a growing body of research in the field of security that explores sophisticated attacks utilizing large language models (LLMs), with numerous studies documented. Nevertheless, to the best of the authors’ knowledge, there have been no reports on attack methodologies that utilize LLMs to target logic locking specifically. This study presents, for the first time, an attack using LLMs against circuits employing logic locking, particularly those enhanced with multi-key logic locking that is resistant to SAT attacks. Through the proposed attack methodology utilizing LLMs, we successfully executed an attack against the state-of-the-art multi-key logic locking scheme known as K-Gate Lock. Takuya Higashi, Tsunato Nakai |
ASP-DAC | 2 |
| 2026 | LumiLock: LUT-based Multi-Key Logic LockingabstractLogic locking, which ensures that a logic circuit operates correctly only when the correct key is input, has gained attention as a countermeasure against the infringement of hardware intellectual property and reverse engineering threats. However, many existing methods have been compromised by SAT attacks. Recent research has reported that multi-key logic locking methods are effective as a fundamental countermeasure against SAT attacks. However, these methods face major issues, such as limitations in their application scope and increased overhead when applied. We propose LumiLock, a novel LUTbased multi-key logic locking method, to fundamentally address these issues. LumiLock strategically hybridizes LUT-based and multi-key techniques, employing a unique mechanism with static and dynamic input-dependent keys. This approach fundamentally disrupts SAT solvers’ ability to identify consistent distinguishing input patterns, thereby preventing key extraction. Evaluation against 10 types of SAT attacks on ISCAS’85, ISCAS’89, and ITC’99 benchmarks demonstrates LumiLock’s robustness. It consistently resists all tested attacks across both combinational and sequential circuits, where conventional multi-key methods are inapplicable. Furthermore, LumiLock achieves this strong security with optimized overhead, including a smaller key size compared to other state-of-the-art multi-key schemes. Tsunato Nakai, Takuya Higashi |
ASP-DAC | 1 |
| 2024 | Co-designing Trusted Execution Environment and Model Encryption for Secure High-Performance DNN Inference on FPGAsabstractAI processing units (APUs) may need to perform isolated execution for the confidentiality of model information and the integrity of execution tasks. Isolated execution of APUs significantly reduces the processing performance, which results in about three times the execution time overhead due to trusted execution environment (TEE) and cryptographic processing for isolated execution according to previous work. In this paper, we propose a high-performance, practical, and general-purpose isolated execution method of APUs by jointly co-designing APU data transfer and model encryption. In the evaluation results, our method can improve the execution time overhead by a factor of 2 or less compared with the previous work. Tsunato Nakai, Ryo Yamamoto |
ISCAS | 1 |
| 2024 | SEDMA: Self-Distillation with Model Aggregation for Membership PrivacyabstractMembership inference attacks (MIAs) are important measures to evaluate potential risks of privacy leakage from machine learning (ML) models. State-of-the-art MIA defenses have achieved favorable privacy-utility trade-offs using knowledge distillation on split training datasets. However, such defenses increase computational costs as a large number of the ML models must be trained on the split datasets. In this study, we proposed a new MIA defense, called SEDMA, based on self-distillation using model aggregation to mitigate the MIAs, inspired by the model parameter averaging as used in federated learning. The key idea of SEDMA is to split the training dataset into several parts and aggregate multiple ML models trained on each split for self-distillation. The intuitive explanation of SEDMA is that model aggregation prevents model over-fitting by smoothing information related to the training data among the multiple ML models and preserving the model utility, such as in federated learning. Through our experiments on major benchmark datasets (Purchase100, Texas100, and CIFAR100), we show that SEDMA outperforms state-of-the-art MIA defenses in terms of membership privacy (MIA accuracy), model accuracy, and computational costs. Specifically, SEDMA incurs at most approximately 3 - 5% model accuracy drop, while achieving the lowest MIA accuracy in state-of-the-art empirical MIA defenses. For computational costs, SEDMA takes significantly less processing time than a defense with the state-of-the-art privacy-utility trade-offs in previous defenses. SEDMA achieves both favorable privacy-utility trade-offs and low computational costs. Tsunato Nakai, Kota Yoshida, Takeshi Fujino |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | Whitelisting Cyber Attack Detection according to Estimated Operational States for CPSabstractThese days, cyber attacks against cyber-physical systems (CPS) such as power plants are constantly growing, and therefore the countermeasures are essential. Whitelisting cyber attack detection, that detects anomalous activity as deviation from normal network communication, is especially attracting attention as one of the countermeasures because the traffic patterns are predictable in CPS. However, attackers can execute illegal operations within the normal network communication defined as the whitelisting detection rules because such operations tend to cause unstable control depending on operational states. In this work, we propose a new whitelisting cyber attack detection method that estimates the operational state of CPS and monitors the CPS network with the whitelisting detection rules according to the estimated state. The proposed method can define the more limited normal network communication to generate the whitelisting detection rules in each operational state. We experimented and evaluated the method on a plant simulator, and confirmed the effectiveness of the method: state estimation with support vector machine and attack detection with divided whitelisting detection rules. Tsunato Nakai, Sachihiro Ichikawa, Nobuhiro Kobayashi, Kosuke Hata, Kenji Sawada |
INDIN | 1 |
| 2015 | Tamper-resistant authentication system with side-channel attack resistant AES and PUF using MDR-ROMabstractAs a threat of security devices, side-channel attacks (SCAs) and invasive attacks have been identified in the last decade. The SCA reveals a secret key on a cryptographic circuit by measuring power consumption or electromagnetic radiation during the cryptographic operations. We have proposed the MDR-ROM scheme as the low-power and small-area counter-measure against SCAs. Meanwhile, secret data in a nonvolatile memory is analyzed by invasive attacks, and the cryptographic device is counterfeited and cloned by an adversary. We proposed to combine the MDR-ROM scheme with the Physical Unclonable Function (PUF) technique, which is expected as the counter-measure against the counterfeit, and the prototype chip was fabricated with a 180nm CMOS technology. In addition, the keyless entry demonstration system was produced in order to present the effectiveness of SCA resistance and PUF technique. Our experiments confirmed that this demonstration system achieved sufficient tamper resistance. Mitsuru Shiozaki, Takaya Kubota, Tsunato Nakai, Akihiro Takeuchi, Takashi Nishimura, Takeshi Fujino |
ISCAS | 3 |
| 2014 | Side-channel attack resistant AES cryptographic circuits with ROM reducing address-dependent EM leaksabstractSide-channel attacks reveal the secret key of a cryptographic circuit by measuring power consumption or electromagnetic radiation during cryptographic operations. Side-channel information leaks that are exploited by power analysis (PA) and electromagnetic analysis (EMA) attacks are thought to be caused by consumption current. However, our research group recently found novel geometric leaks that only EMA attacks can target successfully. This paper studies the causes of memory-dependent EM geometric leaks. We find that the current flow from bit-lines to the ground through the activated ROM cell causes the geometric leaks. We propose a new ROM structure to reduce geometric leak, and use the new ROM to design an AES cryptographic circuit that is resistant to side-channel attacks. Our experiments confirm that the new ROM greatly reduces geometric leak and reveals no key data during PA or EMA attacks. Tsunato Nakai, Megumi Shibatani, Mitsuru Shiozaki, Takaya Kubota, Takeshi Fujino |
ISCAS | 1 |