Takaaki Tateishi

dblp:29/636 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
2since 2021 · last 2023
0000-0001-7456-2442ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 4 first-authorArtificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Databases, data mining, and information retrieval
1 paper
Data mining · 50% Data integration and cleaning · 50%
Software engineering, system software, and programming languages
5 papers
Program analysis · 58% Program verification · 21% Program synthesis and code generation · 16%
Network and information security
3 papers
Authentication and access control · 58% Web and mobile security · 42%

Topics — the 9 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Data mining
feature engineering
0.612022
Semantic Feature Discovery with Code Mining and Semantic Type Detection · AAAI 2022
Data integration and cleaning › table understanding › table annotation
semantic type detection
0.612022
Semantic Feature Discovery with Code Mining and Semantic Type Detection · AAAI 2022
Program analysis › data flow analysis › value analysis
string analysis
0.432013
Path- and index-sensitive string analysis based on monadic second-order logic · ACM Trans. Softw. Eng. Methodol. 2013
Path- and index-sensitive string analysis based on monadic second-order logic · ISSTA 2011
Modular string-sensitive permission analysis with demand-driven precision · ICSE 2009
Program analysis
static analysis
0.322013
Path- and index-sensitive string analysis based on monadic second-order logic · ACM Trans. Softw. Eng. Methodol. 2013
Modular string-sensitive permission analysis with demand-driven precision · ICSE 2009
Program synthesis and code generation
code mining
0.212022
Semantic Feature Discovery with Code Mining and Semantic Type Detection · AAAI 2022
Authentication and access control › access control
permission analysis
0.112009
Modular string-sensitive permission analysis with demand-driven precision · ICSE 2009
Programming languages and type systems
type inference
0.112006
Automated Verification Tool for DHTML · ASE 2006
Program verification
web application verification
0.112006
Automated Verification Tool for DHTML · ASE 2006
Web and mobile security
web application security
0.012013
Path- and index-sensitive string analysis based on monadic second-order logic · ACM Trans. Softw. Eng. Methodol. 2013

Methods — techniques the papers use, named apart from their topics

semantic type detection · 1.1code mining · 1.1theorem proving · 0.5monadic second-order logic · 0.5MONA · 0.3static analysis · 0.2program slicing · 0.2type inference · 0.1
YearPublicationVenuePosition
2023 Datetime Feature Recommendation Using Textual Information
abstract
Analysis to gain new knowledge from huge amounts of data is called data science, and its widespread use is now socially important. Feature engineering, the process of extracting features from data, is one of the main tasks in data science, and since this task relies on the experience of experts, research is being conducted to automate it. In this paper, we propose a novel approach to automate feature identification from textual information in data column names. Specifically, we use techniques of natural language processing and source code analysis, for data descriptions and source codes in Python notebooks to create a knowledge database with a particular focus on datetime features. We develop a recommendation system of datetime features for newly given text information based on that knowledge database. In experiments, we confirmed the classification accuracy of the knowledge database, applied the database to actual forecasting tasks such as home price forecasting, and achieved 5.76% on average for accuracy gain.
Satoshi Masuda, Takaaki Tateishi, Toshihiro Takahashi
KES2
2022 Semantic Feature Discovery with Code Mining and Semantic Type Detection
abstract
In recent years, the automation of machine learning and data science (AutoML) has attracted significant attention. One under-explored dimension of AutoML is being able to automatically utilize domain knowledge (such as semantic concepts and relationships) located in historical code or literature from the problem's domain. In this paper, we demonstrate Semantic Feature Discovery, which enables users to interactively explore features semantically discovered from existing data science code and external knowledge. It does so by detecting semantic concepts for a given dataset, and then using these concepts to determine relevant feature engineering operations from historical code and knowledge.
Kavitha Srinivas, Takaaki Tateishi, Daniel Karl I. Weidele, Udayan Khurana, Horst Samulowitz, Toshihiro Takahashi, Dakuo Wang, Lisa Amini
AAAI2
2013 Path- and index-sensitive string analysis based on monadic second-order logic
abstract
We propose a novel technique for statically verifying the strings generated by a program. The verification is conducted by encoding the program in Monadic Second-order Logic (M2L). We use M2L to describe constraints among program variables and to abstract built-in string operations. Once we encode a program in M2L, a theorem prover for M2L, such as MONA, can automatically check if a string generated by the program satisfies a given specification, and if not, exhibit a counterexample. With this approach, we can naturally encode relationships among strings, accounting also for cases in which a program manipulates strings using indices. In addition, our string analysis is path sensitive in that it accounts for the effects of string and Boolean comparisons, as well as regular-expression matches. We have implemented our string analysis algorithm, and used it to augment an industrial security analysis for Web applications by automatically detecting and verifying sanitizers —methods that eliminate malicious patterns from untrusted strings, making these strings safe to use in security-sensitive operations. On the 8 benchmarks we analyzed, our string analyzer discovered 128 previously unknown sanitizers, compared to 71 sanitizers detected by a previously presented string analysis.
Takaaki Tateishi, Marco Pistoia, Omer Tripp
ACM Trans. Softw. Eng. Methodol.1
2011 Static discovery and remediation of code-embedded resource dependencies
abstract
Many enterprises perform data-center transformation, consolidation, and migration in order to improve the efficiency of their IT infrastructures. These transformation projects begin with the discovery of the existing infrastructure, in particular the dependencies between applications. These dependencies are needed in planning, in order to determine how components influence one another, and in relinking, so that the component names and addresses can be updated. Typically, dependency discovery is done by network monitoring and middleware configuration analysis. These existing approaches will often fail to detect dependencies expressed in the application code. In this paper, we present the first method and tool for automatically identifying code-embedded external dependencies in Java Enterprise Edition applications. In addition, our tool can automatically alter the application code to update the dependencies, or externalize them to configuration files. We analyzed over 1000 Java EE applications from three enterprise environments. The results demonstrate the prevalence of code-embedded dependencies that would otherwise have to be identified manually, often causing failures during user-acceptance testing.
Nikolai Joukov, Vasily Tarasov, Joel Ossher, Birgit Pfitzmann, Sergej Chicherin, Marco Pistoia, Takaaki Tateishi
Integrated Network Management7
2011 Path- and index-sensitive string analysis based on monadic second-order logic
abstract
We propose a novel technique for statically verifying the strings generated by a program. The verification is conducted by encoding the program in Monadic Second-Order Logic (M2L). We use M2L to describe constraints among program variables and to abstract built-in string operations. Once we encode a program in M2L, a theorem prover for M2L, such as MONA, can automatically check if a string generated by the program satisfies a given specification, and if not, exhibit a counterexample. With this approach, we can naturally encode relationships among strings, accounting also for cases in which a program manipulates strings using indices. In addition, our string analysis is path sensitive in that it accounts for the effects of string and Boolean comparisons, as well as regular-expression matches.
Takaaki Tateishi, Marco Pistoia, Omer Tripp
ISSTA1
2009 Modular string-sensitive permission analysis with demand-driven precision
abstract
In modern software systems, programs are obtained by dynamically assembling components. This has made it necessary to subject component providers to access-control restrictions. What permissions should be granted to each component? Too few permissions may cause run-time authorization failures, too many constitute a security hole. We have designed and implemented a composite algorithm for precise static permission analysis for Java and the CLR. Unlike previous work, the analysis is modular and fully integrated with a novel slicing-based string analysis that is used to statically compute the string values defining a permission and disambiguate permission propagation paths. The results of our research prototype on production-level Java code support the effectiveness, practicality, and precision of our techniques, and show outstanding improvement over previous work.
Emmanuel Geay, Marco Pistoia, Takaaki Tateishi, Barbara G. Ryder, Julian Dolby
ICSE3
2007 Reducing Unnecessary Conservativeness in Access Rights Analysis with String Analysis
abstract
The JavaTM2 runtime system has a security mechanism which guarantees the code under execution has appropriate access permissions to a certain system resource. Use of this security mechanism requires access control policies to specify what operations are permitted on each such resource at each program point. Previous work proposed a program analysis algorithm to statically infer a semi-optimal policy set from given program text. However the proposed method cannot calculate the optimal policy when the target resource is determined by string values at run-time, since it does not keep track of all potential string values generated through built-in or user-defined methods. This results in generating excessive access policies where actually unnecessary resource accesses are permitted. To overcome such limitations, we apply static string analysis to program variables relevant to access control policies. This paper shows that unnecessary permissions can be reduced with string analysis by applying it to analyzing open-source libraries.
Mika Koganeyama, Naoshi Tabuchi, Takaaki Tateishi
APSEC3
2007 Secure Behavior of Web Browsers to Prevent Information Leakages
abstract
Recently Web browsers are widely used as client-side application platforms beyond the traditional use of Web browsers. One of main reasons for such evolution of the browsers is the client-side JavaScript language that can execute programs embedded in a document. However, Web applications with client-side JavaScript programs have problems of leaking private information (such as cookie information) due to interactions between the browser and scripts embedded in the document. We propose a new calculus representing browser behavior that prevents information from leakage by means of language-based information flow. The proposed calculus can deal with script rewriting and higher-order functions. In addition, our calculus has a noninterference property depending on a security policy statically given by the user.
Takaaki Tateishi, Naoshi Tabuchi
APSEC1
2007 Verifying the Consistency of Security Policies by Abstracting into Security Types
abstract
The service-oriented architecture (SOA) makes application development easier, because applications can be built from existing services with a bottom-up methodology. However, it is difficult to determine if a desired new service can be built from existing services. Not only the functional consistency of the existing services, but also the consistency of their non-functional (such as security) aspects must be verified. Message protection is an aspect of security. Every service needs an appropriate security policy defining the protection of messages exchanged between the parties to the service. Because of the intricacy of the Web services security policy language, it is difficult to verify the consistency of the security policies. We are developing a method to verify the consistency of security policies by abstracting them. Each security policy is abstracted, and then attached as a security type to the corresponding service in the application model. The security type denotes a security level for message protection. The security developer defines the possible abstraction methods. In this paper, we define the constraint of abstraction methods based on the semantics of the policy language. And also we state verifying the consistency of security types by using information flow analysis.
Kouichi Ono, Yuichi Nakamura 0003, Fumiko Satoh, Takaaki Tateishi
ICWS4
2006 Automated Verification Tool for DHTML
abstract
Automated verification for client-side programs of DHTML applications has become necessary. This is because DHTML applications are increasingly complicated in order to enhance the functionality and usability of dynamic Web content. We are therefore motivated to create a tool for automatically verifying a JavaScript program of a DHTML application against a specification describing the page flows. The verification is based on a type inference technique focusing on DOM updates
Takaaki Tateishi, Hisashi Miyashita, Kouichi Ono, Shin Saito
ASE1