Daisuke Mashima

dblp:90/7355 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0003-1946-1790ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorArtificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 CPSIoTSec'25: The 7th Joint Workshop on CPS & IoT Security and Privacy
abstract
The 7th Joint Workshop on CPS & IoT Security and Privacy is set to take place in Taipei, Taiwan, on October 17, 2025, in conjunction with the ACM Conference on Computer and Communications Security (CCS'25). This workshop marks the amalgamation of two workshops held in 2019: one focused on the security and privacy of cyber-physical systems, while the other one centered on the security and privacy of IoT. The primary objective of this workshop is to create a collaborative forum that brings together academia, industry experts, and governmental entities, encouraging them to contribute cutting-edge research, share demonstrations or hands-on experiences, and engage in discussions. This year, our call for contributions encompassed a broad spectrum, including full research papers, work-in-progress submissions, and one-page abstracts. The workshop program includes nine full/short papers on the security and privacy of CPS/IoT, alongside one demo paper that presents a virtual cybersecurity testbed. Furthermore, the workshop will feature one distinguished keynote presentation by Prof. Daniel Xiapu Luo, a world-renowned expert in CPS security. The talk will offer deep insights on automotive cybersecurity. The complete CPSIoTSec'25 workshop proceedings are available at https://doi.org/10.1145/3733801
Kassem Fawaz, Daisuke Mashima
CCS2
2024 On Practicality of Using ARM TrustZone Trusted Execution Environment for Securing Programmable Logic Controllers
abstract
Programmable logic controllers (PLCs) are crucial devices for implementing automated control in various industrial control systems (ICS), such as smart power grids, water treatment systems, manufacturing, and transportation systems. Owing to their importance, PLCs are often the target of cyber attackers that are aiming at disrupting the operation of ICS, including the nation's critical infrastructure, by compromising the integrity of control logic execution. While a wide range of cybersecurity solutions for ICS have been proposed, they cannot counter strong adversaries with a foothold on the PLC devices, which could manipulate memory, I/O interface, or PLC logic itself. These days, many ICS devices in the market, including PLCs, run on ARM-based processors, and there is a promising security technology called ARM TrustZone, to offer a Trusted Execution Environment (TEE) on embedded devices. Envisioning that such a hardware-assisted security feature becomes available for ICS devices in the near future, this paper investigates the application of the ARM TrustZone TEE technology for enhancing the security of PLC. Our aim is to evaluate the feasibility and practicality of the TEE-based PLCs through the proof-of-concept design and implementation using open-source software such as OP-TEE and OpenPLC. Our evaluation assesses the performance and resource consumption in real-world ICS configurations, and based on the results, we discuss bottlenecks in the OP-TEE secure OS towards a large-scale ICS and desired changes for its application on ICS devices. Our implementation is made available to public for further study and research.
Daisuke Mashima, Wen Shei Ong, Ertem Esiner, Zbigniew T. Kalbarczyk, Ee-Chien Chang
AsiaCCS2
2023 Machine Learning Assisted Bad Data Detection for High-Throughput Substation Communication
abstract
Electrical substations are becoming more prone to cyber-attacks due to increasing digitalization. Prevailing defence measures based on cyber rules are often inadequate to detect attacks that use legitimate-looking measurements. In this work, we design and implement a bad data detection solution for electrical substations called ResiGate, that effectively combines a physics-based approach and a machine-learning-based approach to provide substantial speed-up in high-throughput substation communication scenarios, while still maintaining high detection accuracy and confidence. While many existing physics-based schemes are designed for deployment in control centers (due to their high computational requirement), ResiGate is designed as a security appliance that can be deployed on low-cost industrial computers at the edge of the smart grid so that it can detect local substation-level attacks in a timely manner. A key challenge for this is to continuously run the computationally demanding physics-based analysis to monitor the measurement data frequently transmitted in a typical substation. To provide high throughput without sacrificing accuracy, ResiGate uses machine learning to effectively filter out most of the non-suspicious (normal) data and thereby reducing the overall computational load, allowing efficient performance even with a high volume of network traffic. We implement ResiGate on a low-cost industrial computer and our experiments confirm that ResiGate can detect attacks with zero error while sustaining a high throughput.
Suman Sourav, Partha P. Biswas, Vyshnavi Mohanraj, Binbin Chen 0001, Daisuke Mashima
ICC5
2023 Message Authentication and Provenance Verification for Industrial Control Systems
abstract
Successful attacks against industrial control systems (ICSs) often exploit insufficient checking mechanisms. While firewalls, intrusion detection systems, and similar appliances introduce essential checks, their efficacy depends on the attackers’ ability to bypass such middleboxes. We propose a provenance solution to enable the verification of an end-to-end message delivery path and the actions performed on a message. Fast and flexible provenance verification (F2-Pro) provides cryptographically verifiable evidence that a message has originated from a legitimate source and gone through the necessary checks before reaching its destination. F2-Prorelies on lightweight cryptographic primitives and flexibly supports various communication settings and protocols encountered in ICS thanks to its transparent, bump-in-the-wire design. We provide formal definitions and cryptographically prove F2-Pro’s security. For human interaction with ICS via a field service device, F2-Profeatures a multi-factor authentication mechanism that starts the provenance chain from a human user issuing commands. We compatibility tested F2-Proon a smart power grid testbed and reported a sub-millisecond latency overhead per communication hop using a modest ARM Cortex-A15 processor.
Ertem Esiner, Utku Tefek, Daisuke Mashima, Binbin Chen 0001, Zbigniew T. Kalbarczyk, David M. Nicol
ACM Trans. Cyber Phys. Syst.3
2022 CPSS '22: 8th ACM Cyber-Physical System Security Workshop
abstract
Cyber-Physical Systems (CPS) consist of large-scale interconnected systems of heterogeneous components interacting with their physical environments. There exist a multitude of CPS devices and applications deployed to serve critical functions in our lives thus making security an important non-functional attribute of such systems. CPSS'22 workshop will provide a platform for professionals from academia, government, and industry to discuss novel ways to address the ever-present security and privacy challenges in CPS.
Alvaro A. Cárdenas, Daisuke Mashima
AsiaCCS2
2022 Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems
abstract
Attacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and communication overhead, C(M)MA eliminates all cryptographic operations for the source after the message is given, and all expensive cryptographic operations for the destinations after the message is received. C(M)MA considers the urgency profile (or likelihood) of a set of future messages for even faster verification of the most time-critical (or likely) messages. We demonstrate the feasibility of C(M)MA in an ICS setting based on a substation automation system in smart grids.
Utku Tefek, Ertem Esiner, Daisuke Mashima, Binbin Chen 0001, Yih-Chun Hu
INFOCOM3
2019 Who's Scanning Our Smart Grid? Empirical Study on Honeypot Data
abstract
In order to implement and fine-tune cyber defense mechanisms, it is crucial to know who are the potential enemies and what tactics they are using. In the general cyber security area, honeypot, a decoy system intended to attract cyber attackers, is considered as an effective measure to collect such threat intelligence. However, publication analysing such data is scarce, especially in industrial control systems and smart grid domain. In this paper, we discuss our findings based on the empirical study with 6-month network traces collected in low-interaction smart grid honeypot systems deployed in geographically different regions on Amazon cloud platform. In particular, we discuss actual attack patterns observed as well as insights from the data-driven study on access/attack patterns, correlations among different locations, and dynamics in access sources, some of which are considered effective when configuring security mechanisms such as firewall and intrusion detection systems.
Daisuke Mashima, Binbin Chen 0001
GLOBECOM1
2017 PowerLSTM: Power Demand Forecasting Using Long Short-Term Memory Neural Network
Chang Xu 0003, Daisuke Mashima, Vrizlynn L. L. Thing, Yongdong Wu
ADMA3
2014 Towards Secure Demand-Response Systems on the Cloud
abstract
Demand response (DR) systems are gaining fast adoption and utilities are increasingly relying on them for peak load shaving, demand side management, and maintaining power quality. DR systems are cyber-physical systems (CPS) where the communication component is cyber, whereas the control components have physical effects. As DR systems experience wider adoption and manipulate much larger loads, achieving scalability has become an important concern. On the other hand, demand response events are often sporadic, and maintaining systems and infrastructure that could easily scale up or down is often desirable for utility companies in terms of operational cost, which makes us envision that DR systems would eventually move to the cloud. However, moving to cloud is not an elixir as it brings some concerns of its own. In this paper, we focus on Open ADR 2.0-based systems and discuss security properties and challenges that must be considered when migrating DR systems to the cloud.
Apurva Mohan, Daisuke Mashima
DCOSS2
2012 Evaluating Electricity Theft Detectors in Smart Grid Networks
Daisuke Mashima, Alvaro A. Cárdenas
RAID1
2012 Visualizing Dynamic Data with Maps
abstract
Maps offer a familiar way to present geographic data (continents, countries), and additional information (topography, geology), can be displayed with the help of contours and heat-map overlays. In this paper, we consider visualizing large-scale dynamic relational data by taking advantage of the geographic map metaphor. We describe a map-based visualization system which uses animation to convey dynamics in large data sets, and which aims to preserve the viewer's mental map while also offering readable views at all times. Our system is fully functional and has been used to visualize user traffic on the Internet radio station last.fm, as well as TV-viewing patterns from an IPTV service. All map images in this paper are available in high-resolution at [1] as are several movies illustrating the dynamic visualization.
Daisuke Mashima, Stephen G. Kobourov, Yifan Hu 0001
IEEE Trans. Vis. Comput. Graph.1
2011 Visualizing dynamic data with maps
abstract
Maps offer a familiar way to present geographic data (continents, countries), and additional information (topography, geology), can be displayed with the help of contours and heat-map overlays. In this paper we consider visualizing large-scale dynamic relational data by taking advantage of the geographic map metaphor. We describe a system that visualizes user traffic on the Internet radio station last.fm and address challenges in mental map preservation, as well as issues in animated map-based visualization.
Daisuke Mashima, Stephen G. Kobourov, Yifan Hu 0001
PacificVis1
2009 User-Centric Handling of Identity Agent Compromise
Daisuke Mashima, Mustaque Ahamad, Swagath Kannan
ESORICS1