A paper got accepted!

We are thrilled to announce that our workshop paper entitled “Physiological Linkage Attacks against Visually Obfuscated Videos Using rPPG” has been accepted for publication in The 3rd Workshop on Cybersecurity in Healthcare (HealthSec 2026), co-located with ACSAC 2026. This work is a collaboration with the National Institute of Advanced Industrial Science and Technology (AIST). Congratulations Iijima-kun, Hasegawa-kun, and Kawaoka-kun!

Remote photoplethysmography (rPPG) enables the contactless estimation of pulse waveforms from ordinary videos. Although visual obfuscation techniques such as eye-region masking and facial pixelation are intended to conceal a person’s identity, they may preserve the subtle temporal variations in skin color from which rPPG signals can be extracted. In this work, we investigate physiological linkage attacks against privacy-processed videos in two settings: cross-modal linkage, where an adversary compares an rPPG signal extracted from an identity-labeled video with a sensor-derived PPG signal in a pseudonymous health record, and cross-video linkage, where the adversary compares an rPPG signal from a privacy-processed video with a reference rPPG signal from an unprocessed video. Using Dynamic Time Warping and a CNN-LSTM targeted verification model on the UBFC-Phys dataset, we show that conventional visual privacy processing does not consistently remove individual-specific physiological information: across all evaluated obfuscation settings, the median F1 scores ranged from 0.83 to 0.87, with maximum F1 scores of 0.994 for eye-region masking and 0.987 for facial pixelation. We further propose a proof-of-concept countermeasure that applies randomized frame-level perturbations to the green channel, disrupting rPPG estimation. These results highlight the need to protect latent physiological information contained in video data.

Ryo Iijima, Koki Hasegawa, Ryo Kawaoka, and Tatsuya Mori, "Physiological Linkage Attacks against Visually Obfuscated Videos Using rPPG." In Proc. of The 3rd Workshop on Cybersecurity in Healthcare (HealthSec 2026), co-located with ACSAC 2026, Los Angeles, CA, USA, Dec 2026.

A paper got accepted!

We are thrilled to announce that our conference paper entitled “Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems” has been accepted for publication in The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027). This work is a fruit of our international collaboration with Politecnico di Milano. The research theme was conceived during the sabbatical stay of Prof. Mori at Politecnico di Milano in 2024. Congratulations to Bruzzese-kun and kudos to the entire team!

Traffic Sign Recognition (TSR) is a safety-critical component widely deployed in modern cars, while stickers and other artistic modifications on traffic signs have become commonplace in urban environments and are rarely perceived as suspicious. This coexistence creates a realistic attack surface. Existing adversarial attacks against TSR are rarely validated on production vehicles, often require expensive or conspicuous equipment, and typically target a narrow range of sign categories. To address this gap, we propose a black-box adversarial pipeline that leverages realistic urban sticker designs to induce misclassification and disappearance in neural-network-based TSR systems. Our method identifies sensitive regions on a target sign, selects stickers from a pre-defined pool, and iteratively optimizes their placement using an ensemble of state-of-the-art surrogate detectors within a high-fidelity rendering engine that simulates diverse driving conditions. We evaluate our approach using two distinct training datasets targeting 11 sign categories, and validate the resulting attacks through extensive real-world experiments on five commercial vehicles equipped with TSR systems. Across these vehicles, the proposed approach induces incorrect detections in 62% of cases on average, significantly outperforming state-of-the-art baselines, which reach only 19%. A human perception survey with over 100 participants further suggests that our perturbations are perceived as plausible urban artifacts, ensuring operational stealth. These findings demonstrate that adversarial examples extend beyond controlled laboratory settings and pose a credible, concrete, low-cost threat to real-world driving safety.

Luigi Bruzzese, Francesco Panebianco, Tatsuya Mori, Michele Carminati, Stefano Zanero, and Stefano Longari, "Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems." In Proc. of The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027), Seoul, Republic of Korea, Mar 2027.

A paper got accepted!

We are thrilled to announce that our conference paper entitled “Privacy in Motion: Role Perspectives on Connected Vehicle Data Collection” has been accepted for publication in The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027). Congratulations to Moore-kun and kudos to the entire team!

Connected vehicles have become data-intensive platforms that collect vast amounts of personal information not only from drivers but also from passengers and even nearby pedestrians, yet privacy protections and public understanding have not kept pace. In this work, we bridge the gap between what manufacturers disclose and how people perceive these practices through two complementary studies. In Study 1, we analyze the U.S. privacy policies of 17 major vehicle manufacturers, revealing extensive data collection, fragmented disclosures, and limited user control over third-party sharing. In Study 2, we survey 437 participants from the U.S., Germany, and China to examine comfort, expectations, and willingness to share data across the roles of driver, passenger, and pedestrian. We find that biometric and commercial data are perceived as particularly sensitive, that comfort with data collection varies significantly by role, and that a majority of users are willing to opt out of data collection. The results highlight a substantial disconnect between industry practices and public understanding, calling for clearer, role-aware, and culturally sensitive transparency mechanisms.

Lachlan Moore, Yinan Zhao, Rei Yamagishi, Allan Wirth, and Tatsuya Mori, "Privacy in Motion: Role Perspectives on Connected Vehicle Data Collection." In Proc. of The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027), Seoul, Republic of Korea, Mar 2027.