Futa Waseda

dblp:309/7483 · also Futa Kai Waseda · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0004-5902-1567ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
4 papers
Trustworthy machine learning · 92% Efficient and distributed learning · 4% Vision and language · 4%
Network and information security
1 paper
Security and privacy of machine learning · 50% Digital forensics and information hiding · 50%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.722025
Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models · ACM Multimedia 2025
Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training
0.912025
Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarially robust generalization
robustness-accuracy trade-off
0.912025
Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off · ICLR 2025
Digital forensics and information hiding
fingerprinting
0.912025
MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025
Security and privacy of machine learning › model intellectual property protection
model ownership verification
0.912025
MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025
Machine learning › Trustworthy machine learning
calibration
0.712023
Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023
Machine learning › Trustworthy machine learning › calibration
post-hoc calibration
0.712023
Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023
Machine learning › Trustworthy machine learning
robustness
0.712023
Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023
Machine learning › Trustworthy machine learning
uncertainty estimation
0.712023
Beyond In-Domain Scenarios: Robust Density-Aware Calibration · ICML 2023
Machine learning › Efficient and distributed learning
model merging
0.312025
MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models · ACL (1) 2025
Computer vision › Vision and language
vision-language model
0.312025
Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models · ACM Multimedia 2025

Methods — techniques the papers use, named apart from their topics

pseudo-merged model optimization · 1.7fingerprint embedding · 1.7stop-gradient · 0.9multimodal learning · 0.9language-guided training · 0.9invariance regularization · 0.9batchnorm · 0.9k-nearest neighbors · 0.7density estimation · 0.7
YearPublicationVenuePosition
2026 Multimodal Adversarial Defense for Vision-Language Models by Leveraging One-To-Many Relationships
abstract
Pre-trained vision-language (VL) models are highly vulnerable to adversarial attacks. However, existing defense methods primarily focus on image classification, overlooking two key aspects of VL tasks: multimodal attacks, where both image and text can be perturbed, and the one-to-many relationship of images and texts, where a single image can correspond to multiple textual descriptions and vice versa (1:N and N:1). This work is the first to explore defense strategies against multimodal attacks in VL tasks, whereas prior VL defense methods focus on vision robustness. We propose multimodal adversarial training (MAT), which incorporates adversarial perturbations in both image and text modalities during training, significantly outperforming existing unimodal defenses. Furthermore, we discover that MAT is limited by deterministic one-to-one (1:1) image-text pairs in VL training data. To address this, we conduct a comprehensive study on leveraging one-to-many relationships to enhance robustness, investigating diverse augmentation techniques. Our analysis shows that, for a more effective defense, augmented image-text pairs should be well-aligned, diverse, yet avoid distribution shift—conditions overlooked by prior research. This work pioneers defense strategies against multimodal attacks, providing insights for building robust VLMs from both optimization and data perspectives. Our code is publicly available at https://github.com/CyberAgentAILab/multimodal-adversarialtraining.
Futa Waseda, Antonio Tejero-de-Pablos, Isao Echizen
WACV1
2025 MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models
abstract
Protecting the intellectual property of Large Language Models (LLMs) has become increasingly critical due to the high cost of training.Model merging, which integrates multiple expert models into a single multi-task model, introduces a novel risk of unauthorized use of LLMs due to its efficient merging process.While fingerprinting techniques have been proposed for verifying model ownership, their resistance to model merging remains unexplored.To address this gap, we propose a novel fingerprinting method, MERGEPRINT, which embeds robust fingerprints capable of surviving model merging.MERGEPRINT enables blackbox ownership verification, where owners only need to check if a model produces target outputs for specific fingerprint inputs, without accessing model weights or intermediate outputs.By optimizing against a pseudo-merged model that simulates merged behavior, MERGEPRINT ensures fingerprints that remain detectable after merging.Additionally, to minimize performance degradation, we pre-optimize the fingerprint inputs.MERGEPRINT pioneers a practical solution for black-box ownership verification, protecting LLMs from misappropriation via merging, while also excelling in resistance to broader model theft threats.
Shojiro Yamabe, Futa Waseda, Tsubasa Takahashi 0001, Koki Wataoka
ACL (1)2
2025 Rethinking Invariance Regularization in Adversarial Training to Improve Robustness-Accuracy Trade-off
abstract
Adversarial training often suffers from a robustness-accuracy trade-off, where achieving high robustness comes at the cost of accuracy. One approach to mitigate this trade-off is leveraging invariance regularization, which encourages model invariance under adversarial perturbations; however, it still leads to accuracy loss. In this work, we closely analyze the challenges of using invariance regularization in adversarial training and understand how to address them. Our analysis identifies two key issues: (1) a "gradient conflict" between invariance and classification objectives, leading to suboptimal convergence, and (2) the mixture distribution problem arising from diverged distributions between clean and adversarial inputs. To address these issues, we propose Asymmetric Representation-regularized Adversarial Training (ARAT), which incorporates asymmetric invariance loss with stop-gradient operation and a predictor to avoid gradient conflict, and a split-BatchNorm (BN) structure to resolve the mixture distribution problem. Our detailed analysis demonstrates that each component effectively addresses the identified issues, offering novel insights into adversarial defense. ARAT shows superiority over existing methods across various settings. Finally, we discuss the implications of our findings to knowledge distillation-based defenses, providing a new perspective on their relative successes.
Futa Waseda, Ching-Chun Chang, Isao Echizen
ICLR1
2025 Quality Text, Robust Vision: The Role of Language in Enhancing Visual Robustness of Vision-Language Models
Futa Waseda, Saku Sugawara, Isao Echizen
ACM Multimedia1
2024 Defending Against Physical Adversarial Patch attacks On Infrared Human Detection
abstract
Infrared detection is an emerging technique for safety-critical tasks owing to its remarkable anti-interference capability. However, recent studies have revealed that it is vulnerable to physically-realizable adversarial patches, posing risks in its real-world applications. To address this problem, we are the first to investigate defense strategies against adversarial patch attacks on infrared detection, especially human detection. We propose a straightforward defense strategy, patch-based occlusion-aware detection (POD), which efficiently augments training samples with random patches and subsequently detects them. POD not only robustly detects people but also identifies adversarial patch locations. Surprisingly, while being extremely computationally efficient, POD easily generalizes to state-of-the-art adversarial patch attacks that are unseen during training. Furthermore, POD improves detection precision even in a clean (i.e., no-attack) situation due to the data augmentation effect. Our evaluation demonstrates that POD is robust to adversarial patches of various shapes and sizes. The effectiveness of our baseline approach is shown to be a viable defense mechanism for real-world infrared human detection systems, paving the way for exploring future research directions.
Lukas Strack, Futa Waseda, Huy H. Nguyen, Yinqiang Zheng, Isao Echizen
ICIP2
2023 Beyond In-Domain Scenarios: Robust Density-Aware Calibration
abstract
Calibrating deep learning models to yield uncertainty-aware predictions is crucial as deep neural networks get increasingly deployed in safety-critical applications. While existing post-hoc calibration methods achieve impressive results on in-domain test datasets, they are limited by their inability to yield reliable uncertainty estimates in domain-shift and out-of-domain (OOD) scenarios. We aim to bridge this gap by proposing DAC, an accuracy-preserving as well as Density-Aware Calibration method based on k-nearest-neighbors (KNN). In contrast to existing post-hoc methods, we utilize hidden layers of classifiers as a source for uncertainty-related information and study their importance. We show that DAC is a generic method that can readily be combined with state-of-the-art post-hoc methods. DAC boosts the robustness of calibration performance in domain-shift and OOD, while maintaining excellent in-domain predictive uncertainty estimates. We demonstrate that DAC leads to consistently better calibration across a large number of model architectures, datasets, and metrics. Additionally, we show that DAC improves calibration substantially on recent large-scale neural networks pre-trained on vast amounts of data.
Christian Tomani, Futa Waseda, Yuesong Shen, Daniel Cremers
ICML2
2023 Closer Look at the Transferability of Adversarial Examples: How They Fool Different Models Differently
abstract
Deep neural networks are vulnerable to adversarial examples (AEs), which have adversarial transferability: AEs generated for the source model can mislead another (target) model’s predictions. However, the transferability has not been understood in terms of to which class target model’s predictions were misled (i.e., class-aware transferability). In this paper, we differentiate the cases in which a target model predicts the same wrong class as the source model ("same mistake") or a different wrong class ("different mistake") to analyze and provide an explanation of the mechanism. We find that (1) AEs tend to cause same mistakes, which correlates with "non-targeted transferability"; how-ever, (2) different mistakes occur even between similar models, regardless of the perturbation size. Furthermore, we present evidence that the difference between same mistakes and different mistakes can be explained by non-robust features, predictive but human-uninterpretable patterns: different mistakes occur when non-robust features in AEs are used differently by models. Non-robust features can thus provide consistent explanations for the class-aware transferability of AEs.
Futa Waseda, Sosuke Nishikawa, Trung-Nghia Le, Huy H. Nguyen, Isao Echizen
WACV1