Guest talk by Prof. Zhiqiang Lin (Ohio State University)

On June 24, 2026, we were honored to host Prof. Zhiqiang Lin (Distinguished Professor of Engineering, and Director of the Institute for Cybersecurity and Digital Trust, The Ohio State University) at our laboratory on the Nishi-Waseda campus. Prof. Lin gave a research talk followed by an open discussion with our students and invited researchers.

Title: Validated Exploits, Not LLM Claims: Runtime-Grounded Security Agents for AI-Generated Code

Abstract: AI coding agents are rapidly changing how software is produced, but they also create a new assurance problem: generated code can be deployed faster than humans can review it. This talk examines how large language models can be used not merely to flag suspicious code, but to construct evidence-backed security findings for full-stack web applications. Prof. Lin presented BuckAI, an LLM-agent pipeline for web vulnerability discovery that combines code reasoning, static analysis, automated deployment, exploit generation, and runtime validation. The central design principle is that LLMs should propose hypotheses, while validators and runtime oracles determine whether those hypotheses correspond to real, exploitable behavior. The talk covered the challenges of building such a system — the lack of runnable benchmarks, the difficulty of deploying diverse web applications, and the unreliability of LLMs as final security judges — and concluded with lessons for building trustworthy security agents and open research directions in agentic AI for software security.

We thank Prof. Lin for the stimulating talk and the lively discussions with our group, and we look forward to future collaborations.

A paper got accepted!

We are thrilled to announce that our conference paper entitled “Detecting Phishing on Shared-Domain Hosting Services Using LLM-Based Contextual Mismatch Reasoning” has been accepted for publication in The 21st International Conference on Availability, Reliability and Security (ARES 2026). Congratulations to Inuzuka-kun and kudos to the entire team!

In this work, we propose an LLM-based phishing detection workflow tailored to shared-domain hosting services (SHSs) such as free website builders, where benign and malicious pages coexist under the same provider-managed domain and conventional URL- and domain-based features break down. Our three-stage pipeline — Brand Analyzer, Content Analyzer, and Judge — reasons about the contextual mismatch between the brand a page claims to represent and the sensitive actions it prompts. Evaluated across ten SHSs with both commercial (GPT-4.1-mini) and open-source (Qwen3-8B) models, our system achieves high recall, outperforms state-of-the-art baselines including FreePhish and PhishLLM, and provides natural-language rationales that explain each verdict.

Sho Inuzuka, Takaaki Toda, Daiki Chiba, and Tatsuya Mori, "Detecting Phishing on Shared-Domain Hosting Services Using LLM-Based Contextual Mismatch Reasoning." In Proc. of The 21st International Conference on Availability, Reliability and Security (ARES 2026), Linköping, Sweden, Aug 2026.

A paper got accepted!

We are thrilled to announce that our journal paper entitled “Comprehensive Evaluation and Defense against Adversarial Fog Attacks on LiDAR-Based Autonomous Driving” has been accepted for publication in the Journal of Information Processing (JIP). Congratulations to Tanaka-kun and kudos to the entire team!

This paper is an extended journal version of our ACM AsiaCCS 2025 paper. In this work, we present a comprehensive evaluation of Adversarial Fog Attacks (AFA), which exploit vulnerabilities of point cloud preprocessing filters in LiDAR-based autonomous driving. We systematically analyze how environmental and attack parameters affect the attack effectiveness, physically validate the attack across multiple LiDAR models, and investigate post-detection avoidance behaviors together with practical defense strategies. The paper will appear in Vol. 34 (September 2026).

Yuuna Tanaka, Kazuki Nomoto, Ryunosuke Kobayashi, Go Tsuruoka, and Tatsuya Mori, "Comprehensive Evaluation and Defense against Adversarial Fog Attacks on LiDAR-Based Autonomous Driving." Journal of Information Processing, Vol. 34, Sep 2026.

情報通信功績賞を受賞

本研究室の主宰者である森が、令和8年度「電波の日・情報通信月間」における表彰において、情報通信月間推進協議会会長表彰(情報通信功績賞)を受賞いたしました。

「高度人材の育成、AIセキュリティ政策の推進に尽力し、我が国の安全・安心なサイバー空間の実現に多大な貢献をした」ことを評価いただいたものです。表彰対象は個人ですが、日頃から一緒に研究・教育に取り組んでくれている学生の皆さん、共同研究者の皆様、そして関係コミュニティの皆様のご支援あっての受賞と考えています。ここに感謝いたします。