EDBT 2026 Demo / reviewers in the wild / expert
Futa Waseda
dblp:309/7483 · also Futa Kai Waseda
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0004-5902-1567ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
4 papers |
Trustworthy machine learning · 92% Efficient and distributed learning · 4% Vision and language · 4% | |
| Network and information security
1 paper |
Security and privacy of machine learning · 50% Digital forensics and information hiding · 50% |
Topics — the 11 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.7 | 2 | 2025 | Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models · ACM Multimedia 2025 Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
0.9 | 1 | 2025 | Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarially robust generalization
robustness-accuracy trade-off |
0.9 | 1 | 2025 | Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025 |
Digital forensics and information hiding
fingerprinting |
0.9 | 1 | 2025 | MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025 |
Security and privacy of machine learning › model intellectual property protection
model ownership verification |
0.9 | 1 | 2025 | MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025 |
Machine learning › Trustworthy machine learning
calibration |
0.7 | 1 | 2023 | Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023 |
Machine learning › Trustworthy machine learning › calibration
post-hoc calibration |
0.7 | 1 | 2023 | Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023 |
Machine learning › Trustworthy machine learning
robustness |
0.7 | 1 | 2023 | Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023 |
Machine learning › Trustworthy machine learning
uncertainty estimation |
0.7 | 1 | 2023 | Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023 |
Machine learning › Efficient and distributed learning
model merging |
0.3 | 1 | 2025 | MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025 |
Computer vision › Vision and language
vision-language model |
0.3 | 1 | 2025 | Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models · ACM Multimedia 2025 |
Methods — techniques the papers use, named apart from their topics
pseudo-merged model optimization · 1.7fingerprint embedding · 1.7stop-gradient · 0.9multimodal learning · 0.9language-guided training · 0.9invariance regularization · 0.9batchnorm · 0.9k-nearest neighbors · 0.7density estimation · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multimodal Adversarial Defense for Vision-Language Models by Leveraging One-To-Many RelationshipsabstractPre-trained vision-language (VL) models are highly vulnerable to adversarial attacks. However, existing defense methods primarily focus on image classification, overlooking two key aspects of VL tasks: multimodal attacks, where both image and text can be perturbed, and the one-to-many relationship of images and texts, where a single image can correspond to multiple textual descriptions and vice versa (1:N and N:1). This work is the first to explore defense strategies against multimodal attacks in VL tasks, whereas prior VL defense methods focus on vision robustness. We propose multimodal adversarial training (MAT), which incorporates adversarial perturbations in both image and text modalities during training, significantly outperforming existing unimodal defenses. Furthermore, we discover that MAT is limited by deterministic one-to-one (1:1) image-text pairs in VL training data. To address this, we conduct a comprehensive study on leveraging one-to-many relationships to enhance robustness, investigating diverse augmentation techniques. Our analysis shows that, for a more effective defense, augmented image-text pairs should be well-aligned, diverse, yet avoid distribution shift—conditions overlooked by prior research. This work pioneers defense strategies against multimodal attacks, providing insights for building robust VLMs from both optimization and data perspectives. Our code is publicly available at https://github.com/CyberAgentAILab/multimodal-adversarialtraining. Futa Waseda, Antonio Tejero-de-Pablos, Isao Echizen |
WACV | 1 |
| 2025 | MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language ModelsabstractProtecting the intellectual property of Large Language Models (LLMs) has become increasingly critical due to the high cost of training.Model merging, which integrates multiple expert models into a single multi-task model, introduces a novel risk of unauthorized use of LLMs due to its efficient merging process.While fingerprinting techniques have been proposed for verifying model ownership, their resistance to model merging remains unexplored.To address this gap, we propose a novel fingerprinting method, MERGEPRINT, which embeds robust fingerprints capable of surviving model merging.MERGEPRINT enables blackbox ownership verification, where owners only need to check if a model produces target outputs for specific fingerprint inputs, without accessing model weights or intermediate outputs.By optimizing against a pseudo-merged model that simulates merged behavior, MERGEPRINT ensures fingerprints that remain detectable after merging.Additionally, to minimize performance degradation, we pre-optimize the fingerprint inputs.MERGEPRINT pioneers a practical solution for black-box ownership verification, protecting LLMs from misappropriation via merging, while also excelling in resistance to broader model theft threats. Shojiro Yamabe, Futa Waseda, Tsubasa Takahashi 0001, Koki Wataoka |
ACL (1) | 2 |
| 2025 | Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-offabstractAdversarial training often suffers from a robustness-accuracy trade-off, where achieving high robustness comes at the cost of accuracy.
One approach to mitigate this trade-off is leveraging invariance regularization, which encourages model invariance under adversarial perturbations; however, it still leads to accuracy loss.
In this work, we closely analyze the challenges of using invariance regularization in adversarial training and understand how to address them.
Our analysis identifies two key issues: (1) a "gradient conflict" between invariance and classification objectives, leading to suboptimal convergence, and (2) the mixture distribution problem arising from diverged distributions between clean and adversarial inputs.
To address these issues, we propose Asymmetric Representation-regularized Adversarial Training (ARAT), which incorporates asymmetric invariance loss with stop-gradient operation and a predictor to avoid gradient conflict, and a split-BatchNorm (BN) structure to resolve the mixture distribution problem.
Our detailed analysis demonstrates that each component effectively addresses the identified issues, offering novel insights into adversarial defense.
ARAT shows superiority over existing methods across various settings. Finally, we discuss the implications of our findings to knowledge distillation-based defenses, providing a new perspective on their relative successes. Futa Waseda, Ching-Chun Chang, Isao Echizen |
ICLR | 1 |
| 2025 | Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models
Futa Waseda, Saku Sugawara, Isao Echizen |
ACM Multimedia | 1 |
| 2024 | Defending Against Physical Adversarial Patch attacks On Infrared Human DetectionabstractInfrared detection is an emerging technique for safety-critical tasks owing to its remarkable anti-interference capability. However, recent studies have revealed that it is vulnerable to physically-realizable adversarial patches, posing risks in its real-world applications. To address this problem, we are the first to investigate defense strategies against adversarial patch attacks on infrared detection, especially human detection. We propose a straightforward defense strategy, patch-based occlusion-aware detection (POD), which efficiently augments training samples with random patches and subsequently detects them. POD not only robustly detects people but also identifies adversarial patch locations. Surprisingly, while being extremely computationally efficient, POD easily generalizes to state-of-the-art adversarial patch attacks that are unseen during training. Furthermore, POD improves detection precision even in a clean (i.e., no-attack) situation due to the data augmentation effect. Our evaluation demonstrates that POD is robust to adversarial patches of various shapes and sizes. The effectiveness of our baseline approach is shown to be a viable defense mechanism for real-world infrared human detection systems, paving the way for exploring future research directions. Lukas Strack, Futa Waseda, Huy H. Nguyen, Yinqiang Zheng, Isao Echizen |
ICIP | 2 |
| 2023 | Beyond In-Domain Scenarios: Robust Density-Aware CalibrationabstractCalibrating deep learning models to yield uncertainty-aware predictions is crucial as deep neural networks get increasingly deployed in safety-critical applications. While existing post-hoc calibration methods achieve impressive results on in-domain test datasets, they are limited by their inability to yield reliable uncertainty estimates in domain-shift and out-of-domain (OOD) scenarios. We aim to bridge this gap by proposing DAC, an accuracy-preserving as well as Density-Aware Calibration method based on k-nearest-neighbors (KNN). In contrast to existing post-hoc methods, we utilize hidden layers of classifiers as a source for uncertainty-related information and study their importance. We show that DAC is a generic method that can readily be combined with state-of-the-art post-hoc methods. DAC boosts the robustness of calibration performance in domain-shift and OOD, while maintaining excellent in-domain predictive uncertainty estimates. We demonstrate that DAC leads to consistently better calibration across a large number of model architectures, datasets, and metrics. Additionally, we show that DAC improves calibration substantially on recent large-scale neural networks pre-trained on vast amounts of data. Christian Tomani, Futa Waseda, Yuesong Shen, Daniel Cremers |
ICML | 2 |
| 2023 | Closer Look at the Transferability of Adversarial Examples: How They Fool Different Models DifferentlyabstractDeep neural networks are vulnerable to adversarial examples (AEs), which have adversarial transferability: AEs generated for the source model can mislead another (target) model’s predictions. However, the transferability has not been understood in terms of to which class target model’s predictions were misled (i.e., class-aware transferability). In this paper, we differentiate the cases in which a target model predicts the same wrong class as the source model ("same mistake") or a different wrong class ("different mistake") to analyze and provide an explanation of the mechanism. We find that (1) AEs tend to cause same mistakes, which correlates with "non-targeted transferability"; how-ever, (2) different mistakes occur even between similar models, regardless of the perturbation size. Furthermore, we present evidence that the difference between same mistakes and different mistakes can be explained by non-robust features, predictive but human-uninterpretable patterns: different mistakes occur when non-robust features in AEs are used differently by models. Non-robust features can thus provide consistent explanations for the class-aware transferability of AEs. Futa Waseda, Sosuke Nishikawa, Trung-Nghia Le, Huy H. Nguyen, Isao Echizen |
WACV | 1 |