Research
The rapid progress of AI and quantum technologies, together with the arrival of next-generation network technologies such as IoT and CPS, is expected to create new value and services and enable a richer society. At the same time, the misuse or diversion of such emerging technologies can give rise to a wide range of new threats. In applications such as autonomous control, automated driving, medical equipment, and social infrastructure, attacks that cause malfunctions or stoppages can seriously affect human life and social systems. While conventional information security has focused mainly on cyberspace accessed over the network, these new systems and applications require security to be built in comprehensively, from the devices and hardware in direct contact with the real world through to AI.
Our laboratory pursues the entire chain, from the security design and implementation of next-generation information and communication systems to the analysis and evaluation of their security, and works to create new security technologies, aiming to build a social system in which anyone can use future services and technologies safely and securely. Our current main research topics are (1) security computing centered on next-generation cryptography, (2) the theory and implementation of secure information systems robust against various physical attacks, which are performed by physically accessing the system, and (3) security for AI and security by AI. More details on each topic are offered below. In the future, we aim to establish a systematic security design and evaluation technology with a wide scope, covering every layer from devices and hardware to AI, together with their usage environments and applications.
Security Computing Based on Next-Generation Cryptography

Security functions such as cryptography require lengthy and complex computation. Their performance depends largely on how that computation is implemented; thus, software and hardware must be designed appropriately for the application and required performance. Furthermore, for next-generation systems such as physical AI, IoT, and CPS, tamper resistance and tampering detection are important design considerations beyond conventional performance indicators such as speed, power consumption, and energy.
Our laboratory has been studying implementation theory in a range of number systems used in security functions, e.g., Galois fields, and has developed a variety of hardware, including the most efficient Advanced Encryption Standard (AES) hardware in the world and high-performance RSA hardware resistant to attacks. More recently, we have been studying software and hardware implementation techniques for next-generation cryptography, including post-quantum cryptography. We also study cryptographic techniques suited to AI and IoT systems constrained by computational resources or operating conditions, as well as formal and empirical methods for detecting hardware into which malicious functions have been embedded, or that has been tampered with or repurposed.
Examples of research topics:
- Post-quantum cryptographic software and hardware
- Tamper-resistant cryptographic software and hardware
- Detection methods for malicious, tampered, and repurposed hardware
- Formal design and verification methods for hardware on Galois fields
- Cryptographic techniques for AI and IoT systems
Theory and Implementation of Secure Information Systems

In the next-generation society, where devices around us are all connected to the network, even those with limited computational resources, such as sensors and small terminals in contact with the real world, can be targeted by attackers and must therefore be properly equipped with security functions. Because attackers can also physically access them, they must be prepared for physical attacks, including side-channel attacks, which infer secret information from physical quantities such as power consumption and electromagnetic emanations, and fault attacks, which deliberately induce malfunction. Regarding applications such as IC and SIM cards, we must also assume that the owners themselves can become attackers. In recent years, machine learning has dramatically improved the efficiency of these attacks, making threat assessment increasingly difficult.
Under these constraints and attack scenarios, our laboratory is studying the design, implementation, and security analysis of information systems equipped with security functions and countermeasure technologies. For example, the design and security evaluation platform for cryptographic embedded systems we developed is currently used by universities, research institutes, and companies worldwide. Our successful countermeasure against side-channel attacks using electromagnetic emanations from smart devices received the best paper award at the field's most important international conference, attracting worldwide attention. We also study secure computation systems that process data while keeping it encrypted.
Examples of research topics:
- Side-channel attacks and countermeasures
- Fault attacks and countermeasures
- Machine-learning-assisted physical attacks and countermeasures
- Design and evaluation platform for secure information systems
- Secure computation systems
Security for AI / Security by AI
Artificial intelligence is now widely deployed across a broad range of information systems and services. At the same time, AI systems introduce new security and privacy risks. Training data may contain personal or sensitive information, and its unintended disclosure can have serious consequences. Moreover, as AI is increasingly used in safety-critical domains such as autonomous driving, healthcare, and social infrastructure, attacks that manipulate the behavior of AI systems could pose significant risks to individuals and society. Our laboratory studies security and privacy threats specific to AI and develops techniques for the secure design, evaluation, and protection of AI systems. Our goal is to enable the safe and trustworthy use of AI.
One of our research areas is model extraction attacks, in which an adversary attempts to recover information about or replicate the functionality of a target model through queries to the model and observations of its outputs. Because training high-performance AI models often requires substantial computational resources, data, and development costs, protecting trained models from unauthorized extraction is an important security challenge. We study model extraction from a cryptanalytic perspective, analyzing what information can be recovered, under what conditions, and with what computational complexity. By clarifying the capabilities and fundamental limitations of such attacks, we aim to establish rigorous methods for evaluating AI security and designing effective countermeasures. Our research in this area has received international recognition, including publications at leading international cryptography conferences.
Examples of research topics:
- Model extraction attacks and defenses from a cryptanalytic perspective
- Privacy-preserving techniques for integrating trained models without sharing data
- Backdoor attacks against large language models and their defenses
- Machine unlearning methods for removing the influence of specific training data from trained models
- Security and privacy in federated learning