日本語

Contact

Lab visits, graduate study, research collaboration — feel free to get in touch.

Email

kyoshioka47@keio.jp

Kentaro (Ken) Yoshioka

Address

〒223-8522

Yagami Campus Bldg. 23, 3-14-1 Hiyoshi, Kohoku-ku, Yokohama, Kanagawa 223-8522, Japan

Students: 23-214, 14-305, 24-318 / PI: 23-216A

Projects

Projects

21 ongoing and published projects. Every card links straight to the paper, code, and project page.

2026

10
Accepted★

Ghost-FWL

The first large-scale annotated mobile full-waveform LiDAR dataset for ghost artifact detection and removal, with 24,412 frames and 7.5 billion peak-level annotations — 100× more than prior work. Ghost points arise from multi-path reflections off glass and reflective surfaces, degrading 3D mapping and object detection in autonomous driving. Includes FWL-MAE pretraining and transformer-based detection baselines across Ghost, Object, Glass, and Noise categories.

Accepted

PULSAR-Net

PULSAR-Net, the first effective defense against LiDAR jamming attacks that blind sensors by flooding them with high-frequency laser pulses. By leveraging intermediate full-waveform data (normally discarded after peak detection) and simultaneous multi-laser sensing patterns, a 3D U-Net with axial spatial-temporal attention segments attack pulses from legitimate reflections directly in the waveform domain. Trained exclusively on synthetic data, PULSAR-Net achieves 92% and 73% point-cloud reconstruction rates for vehicles erased by attacks in real-world static and driving scenarios respectively.

Preprint

DetAS

An agentic detection framework that treats object detection as a dynamic decision process rather than a fixed pipeline. A multimodal large language model acts as the central agent, composing a detection workflow per scene by choosing from a toolbox of restoration modules and specialized detectors. Two components drive it: Self-Adaptive Image Restoration, which decides whether and how to enhance an image before detection, and Multi-Expertise Detection, which reconciles the predictions of several domain-specialized detectors through instance-level reasoning. DetAS-X extends this with Self-Evolving Experience Harvesting, accumulating node-level decision experience from a small annotated set so the system reasons from past decisions at inference time. Across six challenging benchmarks DetAS-X outperforms existing MLLM-based detectors by 28.36% F1 on average, reaching a 37.01% gain on DarkFace.

Accepted★

FLARE & ChromaGuard

Vision-Language-Action models have become a powerful paradigm for general-purpose robot manipulation, but moving them into the real world exposes a vulnerability to minor environmental perturbations. FLARE is an optimized physical spotlight attack that exploits this through targeted illumination, dropping baseline task success rates to zero without any access to model internals. Adversarial training is the standard countermeasure — but it hides a pitfall. Naive data augmentation conditions VLA models to treat color as noise, collapsing their perception into a purely shape-biased processor. A diagnostic grayscale evaluation exposes the damage: the defended model keeps high success rates on grayscale inputs while its success on benign, color-dependent tasks falls to at most 47.5%, below the undefended baseline. ChromaGuard is a chroma-preserving adversarial training method that closes the gap. On a physical 6-DoF robotic platform it reaches 97.5% success on benign color-dependent tasks and 92.5% under attack.

Published

BitROM

A weight reload-free Compute-in-Read-Only-Memory (CiROM) architecture for billion-parameter LLM inference using 1.58-bit (ternary) weights. Integrates bidirectional ROM arrays, tri-mode local accumulators, and eDRAM KV-cache management, reducing external DRAM access by 43.6% during decoding. Achieves 20.8 TOPS/W and 10× area efficiency improvement over prior digital CiROM designs.

Accepted

D-SLAMSpoof

D-SLAMSpoof overcomes the fundamental limitation of prior LiDAR spoofing attacks — ineffectiveness in feature-rich environments such as urban areas and indoor spaces. By designing spatially structured injection shapes and temporally coordinated dynamic patterns guided by scan matching principles, the attack successfully manipulates SLAM-based localization regardless of environmental complexity. The paper also proposes ISD-SLAM, a practical defense that detects and mitigates spoofing-induced drift using only onboard inertial dead-reckoning signals, requiring no additional hardware.

Accepted

D4C

Addresses data-free quantization of CLIP vision-language models by tackling the core challenge of insufficient semantic diversity in synthesized calibration samples. D4C combines prompt-guided semantic alignment, structural contrastive generation for compositional diversity, and perturbation-aware enhancement — enabling effective W4A4 CLIP compression without original training data.

Published

LiDAR Beacon

A LiDAR fiducial marker achieving 309m recognition distance — approximately 19× longer than prior work — by encoding IDs into temporal reflection patterns using a single laser return on a PDLC film. Integrated into an autonomous localization system enabling GPS-free, sub-meter accurate positioning of construction machinery in GPS-denied environments such as tunnels and open terrain.

Published

MCRA

A multicolumn residue accumulation analog compute-in-memory architecture using a time-domain M-input ΣΔ ADC to achieve high-precision analog computation. Residues from multiple columns are accumulated sequentially to boost ADC effective resolution without proportional area cost, enabling energy-efficient on-chip inference for edge AI.

Accepted

MirrorDrift

MirrorDrift demonstrates that mirror reflections are a stealthy, injection-free alternative to signal-injection-based LiDAR attacks. Using a planar mirror equipped with an actuation mechanism, ghost points are created by reflecting existing laser pulses, systematically biasing scan matching correspondences without emitting any signal. The attack optimizes mirror placement, alignment, and actuation to maximize localization error — achieving a 6.1× increase in mean pose error over random placement, inducing up to 6.03 m of localization error, and degrading three SLAM systems to 2.29–3.31 m average trajectory error.

2025

7
Published★

AHCPTQ

Enables the first functional 4-bit post-training quantization of the Segment Anything Model (SAM) via two hardware co-designed innovations: Hybrid Log-Uniform Quantization (HLUQ) for heavy-tailed post-GELU activations, and Channel-Aware Grouping (CAG) cutting on-chip register overhead by 99.7%. FPGA deployment achieves 7.89× speedup and 8.64× energy efficiency over float at W4A4 with 36.6% mAP.

Published

ASiM

A simulation framework for modeling and analyzing how analog noise impacts inference accuracy in SRAM-based compute-in-memory (CiM) circuits. Reveals that even 1 LSB of analog noise can significantly impair performance on complex tasks like ImageNet, and evaluates mitigation strategies — hybrid analog-digital execution and majority voting — to recover accuracy while preserving CiM energy efficiency benefits.

Published

Basket LiDAR

3D basketball player tracking using LiDAR sensing for sports analytics. Enables precise real-time localization of players and ball during games, providing rich spatial data for performance analysis and coaching insights.

Published★

LiDAR Spoofing (High Speed)

Examines the practical feasibility of LiDAR spoofing attacks on autonomous driving vehicles at realistic high speeds and long distances. Reveals that spoofing remains effective under conditions previously assumed to be safe, challenging existing security assumptions.

Published

Optical LiDAR Comm

Enables infrastructure-to-vehicle messaging by repurposing existing LiDAR sensors for optical communication, eliminating the need for dedicated communication hardware. Demonstrates practical V2I data transfer using commodity automotive LiDAR units.

Published

Saliency-Aware CIM

A 4541 TOPS/W analog compute-in-memory macro featuring a charge-domain saliency detector that dynamically skips computation on non-salient regions. Achieves state-of-the-art energy efficiency for vision inference at the edge.

Published

SLAMSpoof

Practical LiDAR spoofing attacks targeting SLAM-based localization systems, guided by scan matching vulnerability analysis. Demonstrates that adversaries can manipulate vehicle localization by injecting carefully crafted ghost points into LiDAR scans.

2024

4
Published★

CR-CIM

A capacitor-reconfigured compute-in-memory macro achieving 818–4094 TOPS/W for unified acceleration of both CNNs and Transformers. Dynamic capacitor reconfiguration adapts analog compute precision to each layer's bit-width requirements, enabling the first analog CIM to handle Transformer inference while delivering 10× energy efficiency over prior work in CNN mode at 4094 TOPS/W.

Published★

LiDAR New-Gen Spoofing

Reveals that next-generation LiDAR sensors designed for better range and resolution inadvertently open new spoofing attack surfaces. Demonstrates improved attack capabilities that invalidate prior safety assumptions and introduces novel strategies that bypass state-of-the-art countermeasures, exposing critical security implications for the evolving autonomous vehicle ecosystem.

Published

OSA-HCIM

A hybrid SRAM compute-in-memory macro with on-the-fly saliency detection and dynamic precision configuration. Reduces computation by skipping non-salient activations while maintaining inference accuracy through adaptive bit-width selection.

Published★

PACiM

A sparsity-centric hybrid compute-in-memory architecture using probabilistic approximation (PAC) to convert vector operations into scalar computations, halving memory transfers by eliminating LSB transmission. Achieves 14.63 TOPS/W in 65 nm CMOS with 4× lower approximation error than prior methods, maintaining ResNet-18 ImageNet accuracy.