日本語

Contact

Lab visits, graduate study, research collaboration — feel free to get in touch.

Email

kyoshioka47@keio.jp

Kentaro (Ken) Yoshioka

Address

〒223-8522

Yagami Campus Bldg. 23, 3-14-1 Hiyoshi, Kohoku-ku, Yokohama, Kanagawa 223-8522, Japan

Students: 23-214, 14-305, 24-318 / PI: 23-216A

Research

The questions we're chasing

We work across three themes. Each reaches into both hardware and software, and none of them require prior background to start. Begin with the questions.

01Edge Computing

Can we run AI on a battery?

Today's AI runs in vast data centers, consuming enormous power. Putting it into a phone, a car, or a robot leaves nowhere near enough energy budget — and with semiconductor scaling slowing, making digital circuits faster and leaner is hitting a wall.

So we change how computing works. Compute inside memory instead of shuttling data around. Compute with analog voltages instead of ones and zeros. Accept answers that are approximately right. These non-textbook approaches target 10-100x less power.

And we don't stop at paper. Circuits you design get fabricated at a real semiconductor foundry, and months later your own chip arrives in your hands.

What you'd actually be doing

  1. 1

    Train AI models in PyTorch and reshape them to fit real circuits

  2. 2

    Design circuits, draw the layout, and send it off to a fab

  3. 3

    Measure your own chip when it returns, and find out if it works

  4. 4

    Write up the results and present at top venues like ISSCC

You'll learnCircuit designDeep learningPyTorchSemiconductor processesAnalog circuitsModel quantization

What we're working on

In-memory computing that removes the data-transfer bottleneck by computing where the data lives

Analog and stochastic circuits that make AI efficient on principles digital logic can't reach

Circuits that bring large language models onto power-constrained devices

Training methods for circuit-friendly AI models, plus open-source simulators

02Autonomous Driving Security

Can you show a moving self-driving car something that isn't there?

Self-driving cars see the world through LiDAR: it fires laser pulses and measures how long they take to bounce back. So what happens if someone fires lasers back at it?

It turns out you can make a car brake hard for an obstacle that doesn't exist — or make a person standing right in front of it disappear. We build these rigs ourselves and drive real vehicles on test tracks, and we were the first to establish how fast and how far away such attacks actually work.

That may sound alarming, but the aim is the opposite. You cannot design defenses without knowing precisely how dangerous something is. We put as much effort into detection and mitigation as into the attacks themselves.

What you'd actually be doing

  1. 1

    Build attack rigs by hand from lasers and optics

  2. 2

    Drive real autonomous vehicles on test tracks and measure when attacks succeed

  3. 3

    Analyze 3D point clouds with AI to devise detection methods

  4. 4

    Present at top security venues like NDSS — and sometimes end up in the press

You'll learnLiDARBuilding opticsSecurity3D point cloudsDeep learningSLAM

What we're working on

Quantifying how far attacks carry against real vehicles at real speeds

Attacks on SLAM that make a vehicle mistake where it is

Demonstrating that even the newest LiDARs with built-in defenses can be bypassed

Detection and mitigation, plus LiDAR designs that resist attack by construction

CoRL 2026

FLARE & ChromaGuard

Vision-Language-Action models have become a powerful paradigm for general-purpose robot manipulation, but moving them into the real world exposes a vulnerability to minor environmental perturbations. FLARE is an optimized physical spotlight attack that exploits this through targeted illumination, dropping baseline task success rates to zero without any access to model internals. Adversarial training is the standard countermeasure — but it hides a pitfall. Naive data augmentation conditions VLA models to treat color as noise, collapsing their perception into a purely shape-biased processor. A diagnostic grayscale evaluation exposes the damage: the defended model keeps high success rates on grayscale inputs while its success on benign, color-dependent tasks falls to at most 47.5%, below the undefended baseline. ChromaGuard is a chroma-preserving adversarial training method that closes the gap. On a physical 6-DoF robotic platform it reaches 97.5% success on benign color-dependent tasks and 92.5% under attack.

CVPR 2026

Ghost-FWL

The first large-scale annotated mobile full-waveform LiDAR dataset for ghost artifact detection and removal, with 24,412 frames and 7.5 billion peak-level annotations — 100× more than prior work. Ghost points arise from multi-path reflections off glass and reflective surfaces, degrading 3D mapping and object detection in autonomous driving. Includes FWL-MAE pretraining and transformer-based detection baselines across Ghost, Object, Glass, and Noise categories.

NDSS 2025

LiDAR Spoofing (High Speed)

Examines the practical feasibility of LiDAR spoofing attacks on autonomous driving vehicles at realistic high speeds and long distances. Reveals that spoofing remains effective under conditions previously assumed to be safe, challenging existing security assumptions.

WithUniversity of California, IrvineUniversity of FloridaWaseda UniversityThe University of Electro-CommunicationsSony
03LiDAR 3D Sensing

If you could see the world in 3D, what would you build?

Self-driving cars made LiDAR cheap, fast — which means it can be used far beyond cars. A camera captures a flat image; LiDAR captures space itself as a cloud of 3D points.

We've taken it into hospitals and onto basketball courts. In rehabilitation, the range of motion a doctor once measured with a protractor is now captured automatically by sensor and AI. In basketball, we built a system that follows ten players through the collisions of a real game — where camera-only tracking loses people the moment they overlap.

We also built a marker identifiable from 300 meters away, so construction machinery can localize itself on site. The appeal of this theme is carrying a technology all the way to where it actually helps someone.

What you'd actually be doing

  1. 1

    Take sensors into hospitals and gymnasiums and capture real-world data

  2. 2

    Analyze the resulting 3D point clouds with AI to track people and motion

  3. 3

    Work directly with doctors, pro teams, and companies to make it genuinely usable

  4. 4

    Release your datasets for researchers worldwide to build on

You'll learnLiDAR3D point cloudsDeep learningObject trackingHealthcare applicationsSports analytics

What we're working on

A system and dataset for tracking ten players in 3D during professional basketball games

Automatic measurement of joint range of motion for rehabilitation, via 3D sensing and AI

A fiducial marker identifiable from 300 m, letting machinery localize where GPS fails

Repurposing LiDAR as a receiver, delivering traffic-signal and blind-spot information to vehicles

WithOkayama University HospitalAisin CorporationAoki Lab, Keio University

Facilities

So research doesn't end at simulation, we keep an environment where you actually build and measure. Circuits you design get fabricated; attacks you devise get tested on real vehicles.

  • Chip tape-out (65nm / 28nm / 12nm FinFET)
  • Test autonomous vehicle
  • LiDAR attack and evaluation rigs
  • A wide range of commercial LiDAR sensors
  • High-speed measurement setup for ADC/CIM
  • GPU servers

Work with us

We take on contract and collaborative research with industry. Feel free to reach out about our work or to discuss a topic.

kyoshioka47@keio.jp