CREST Site Visit 2026 at Waseda University, Nishi-Waseda
ABOUT

On Wednesday, August 19, 2026, the Research Supervisor and Area Advisors of the JST CREST research area “Creation of System Software for Society 5.0 by Integrating Fundamental Theories and System Platform Technologies” made a site visit to our project, “Security Evaluation and Countermeasures for AI-Driven Cyber-Physical Systems,” at Waseda University’s Nishi-Waseda Campus.
Principal Investigator Tatsuya Mori presented the project’s goals and approach and its highlights, followed by progress reports from each group. The visitors then toured the cluster room housing the GPU servers acquired through CREST, and saw physical-experiment demonstrations and video exhibits of our research in the Mori Lab. The visit closed with an outlook on future work and a discussion with the Research Supervisor and Area Advisors.
Event Overview
Date: Wednesday, August 19, 2026, 14:00–16:00
Venue: Building 63, Nishi-Waseda Campus, Waseda University
Program
- 14:00–14:40 Project overview, progress highlights from each group, and Q&A
- 14:40–15:30 Demonstrations and video exhibits
- Tour of the cluster room (GPU servers acquired through CREST)
- Physical-experiment demo: “Attacks on Occupancy Prediction and Their End-to-End Evaluation” (Go Tsuruoka)
- Physical-experiment demo: “Dynamic Patch Attacks on Visual Odometry” (Zhihe Zhang)
- Video: “End-to-End Evaluation of Adversarial Road Patches” (Hiroto Onoda)
- Video: “V2X-SAFE: An End-to-End Security Evaluation Platform for V2X Cooperation” (Kodai Hirai)
- Video: “DRIFT: Attacks on Drone vSLAM” (Yuga Ebine)
- Video: “Attacks on Traffic Light Detection” (Kyo Suetsugu)
- Video: “A Single-Arm Robot Driven by a VLA Model” (Yuto Yashiro)
- 15:30–16:00 Future outlook and discussion
About the Project
The project aims to achieve “security by design” that prevents the threat of adversarial inputs to AI-driven cyber-physical systems (AI-CPS) before it materializes. It addresses three challenges: (1) evaluating and countering adversarial inputs to individual components (sensors, machine learning modules, and control systems); (2) evaluating and countering adversarial inputs to the end-to-end system in which these components are connected; and (3) building system software that implements the countermeasures. The research is carried out by six groups:
- Security platform for end-to-end systems (Mori Group, Waseda University)
- Security technologies for sensor-integrated systems (Yoshioka Group, Keio University)
- Security theory for physical measurement systems (Sugawara Group, University of Electro-Communications)
- Security theory for machine learning models (Sakuma Group, Institute of Science Tokyo)
- Control security technologies for autonomous vehicles (Sawada Group, Osaka University)
- Security of computer architectures for autonomous vehicles (Akiyama Group, Ritsumeikan University, since April 2026)
Highlights Presented
- Mori Group (Waseda University): We have revealed attacks on each layer of autonomous driving, from perception to maps and control, including artificial fog that exploits LiDAR point-cloud preprocessing (Best Paper Award, ACM AsiaCCS 2025), tampering with HD maps, and art-based adversarial attacks on traffic signs (joint work with Politecnico di Milano). We are building a framework that evaluates these attacks on the whole autonomous driving system, end to end, in both simulation and real vehicles.
- Yoshioka Group (Keio University): The group developed a method that uses machine learning to remove the attack component from the raw waveforms of a LiDAR under a high-frequency pulsed-light jamming attack and to restore its point cloud (NeurIPS 2026). It also built a large-scale full-waveform LiDAR dataset (CVPR 2026) and uncovered attacks on LiDAR SLAM (IROS 2026).
- Sugawara Group (University of Electro-Communications): The group found vulnerabilities in the signal processing specific to thermal cameras that let heat sources plant nonexistent obstacles and persistent afterimages, and proposed countermeasures (NDSS 2026). It also identified why repeating patterns can inject false depth into stereo cameras (ACM CCS 2026, with the Yoshioka Group and the University of Florida), and its demonstration won the Best Demo Award at USENIX VehicleSec 2026.
- Sakuma Group (Institute of Science Tokyo): Against targeted behavior-manipulation attacks that tamper with the state observations of deep reinforcement learning agents to make them act as the attacker wishes, the group proposed a defense based on regularization that smooths the policy (ICLR 2026). Together with the Mori and Sugawara Groups, it also showed the feasibility of attacks that make automated ECG diagnosis detect spoofed arrhythmia (ACM TCPS).
- Sawada Group (Osaka University): The group is validating filtering methods that minimize the impact of attacks on communication and sensors in cooperative adaptive cruise control (CACC). It also formulated the contest between an attacker covertly misguiding an autonomous mobile vehicle and a defender trying to detect it as a zero-sum game, and validated the trade-off between detection accuracy and attack stealthiness in experiments with mobile robots.
- Akiyama Group (Ritsumeikan University): Treating autonomous vehicles as computer systems, the group is examining how far memory attacks such as RowHammer and BadRAM can break the protection offered by IoT device firmware and trusted execution environments (TEEs).