SPIRAL(Center for Security Practice, Intelligence, Research, and Advanced Learning)は、サイバーセキュリティに関する研究・教育・実践を一体的に推進する拠点として、同日に横浜国立大学に設立されたセンターです(センター長:吉岡克成教授)。サイバー攻撃の観測・分析を通じた大学発のサイバーインテリジェンスの提供を掲げ、「サイバーセキュリティ研究実践ラボ」「次世代暗号ラボ」「先進実践教育ラボ」「社会共創ラボ」の4つのラボで構成されています。森は「サイバーセキュリティ研究実践ラボ」に所属し、早稲田大学での本務と兼務しながら、同センターの研究・教育活動に参画します。
We are thrilled to announce that our workshop paper entitled “Physiological Linkage Attacks against Visually Obfuscated Videos Using rPPG” has been accepted for publication in The 3rd Workshop on Cybersecurity in Healthcare (HealthSec 2026), co-located with ACSAC 2026. This work is a collaboration with the National Institute of Advanced Industrial Science and Technology (AIST). Congratulations Iijima-kun, Hasegawa-kun, and Kawaoka-kun!
Remote photoplethysmography (rPPG) enables the contactless estimation of pulse waveforms from ordinary videos. Although visual obfuscation techniques such as eye-region masking and facial pixelation are intended to conceal a person’s identity, they may preserve the subtle temporal variations in skin color from which rPPG signals can be extracted. In this work, we investigate physiological linkage attacks against privacy-processed videos in two settings: cross-modal linkage, where an adversary compares an rPPG signal extracted from an identity-labeled video with a sensor-derived PPG signal in a pseudonymous health record, and cross-video linkage, where the adversary compares an rPPG signal from a privacy-processed video with a reference rPPG signal from an unprocessed video. Using Dynamic Time Warping and a CNN-LSTM targeted verification model on the UBFC-Phys dataset, we show that conventional visual privacy processing does not consistently remove individual-specific physiological information: across all evaluated obfuscation settings, the median F1 scores ranged from 0.83 to 0.87, with maximum F1 scores of 0.994 for eye-region masking and 0.987 for facial pixelation. We further propose a proof-of-concept countermeasure that applies randomized frame-level perturbations to the green channel, disrupting rPPG estimation. These results highlight the need to protect latent physiological information contained in video data.
Ryo Iijima, Koki Hasegawa, Ryo Kawaoka, and Tatsuya Mori, "Physiological Linkage Attacks against Visually Obfuscated Videos Using rPPG." In Proc. of The 3rd Workshop on Cybersecurity in Healthcare (HealthSec 2026), co-located with ACSAC 2026, Los Angeles, CA, USA, Dec 2026.
We are thrilled to announce that our conference paper entitled “Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems” has been accepted for publication in The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027). This work is a fruit of our international collaboration with Politecnico di Milano. The research theme was conceived during the sabbatical stay of Prof. Mori at Politecnico di Milano in 2024. Congratulations to Bruzzese-kun and kudos to the entire team!
Traffic Sign Recognition (TSR) is a safety-critical component widely deployed in modern cars, while stickers and other artistic modifications on traffic signs have become commonplace in urban environments and are rarely perceived as suspicious. This coexistence creates a realistic attack surface. Existing adversarial attacks against TSR are rarely validated on production vehicles, often require expensive or conspicuous equipment, and typically target a narrow range of sign categories. To address this gap, we propose a black-box adversarial pipeline that leverages realistic urban sticker designs to induce misclassification and disappearance in neural-network-based TSR systems. Our method identifies sensitive regions on a target sign, selects stickers from a pre-defined pool, and iteratively optimizes their placement using an ensemble of state-of-the-art surrogate detectors within a high-fidelity rendering engine that simulates diverse driving conditions. We evaluate our approach using two distinct training datasets targeting 11 sign categories, and validate the resulting attacks through extensive real-world experiments on five commercial vehicles equipped with TSR systems. Across these vehicles, the proposed approach induces incorrect detections in 62% of cases on average, significantly outperforming state-of-the-art baselines, which reach only 19%. A human perception survey with over 100 participants further suggests that our perturbations are perceived as plausible urban artifacts, ensuring operational stealth. These findings demonstrate that adversarial examples extend beyond controlled laboratory settings and pose a credible, concrete, low-cost threat to real-world driving safety.
Luigi Bruzzese, Francesco Panebianco, Tatsuya Mori, Michele Carminati, Stefano Zanero, and Stefano Longari, "Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems." In Proc. of The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027), Seoul, Republic of Korea, Mar 2027.