Takami SATO
Ph.D. in Computer Science from the University of California, Irvine (Sep 2024), under the supervision of Prof. Qi Alfred Chen. ML security researcher. Kaggle Grandmaster.
My research studies physical-world attacks on
the sensors and AI perception of autonomous systems — LiDAR spoofing, camera/optical attacks on traffic
sign and traffic light recognition, and adversarial attacks on lane detection — and, just as
importantly, how much these attacks actually matter at the system level, i.e., to the driving
behavior of the vehicle.
Research interests: Machine Learning Security, CPS Security, Autonomous Driving Security, Sensor Security,
Mathematical Optimization
Email,
GitHub,
Linkedin,
Twitter,
Kaggle,
SlideShare,
Resume
Google Scholar
Selected Conference Publications
-
[CoRL'26] Marino Watanabe, Takami Sato, and Kentaro Yoshioka,
Lights, Camera, Malfunction: When Illumination Robustness Leaves VLA Models Blind to Color
(Acceptance Rate: 32.8%)
[paper]
-
[NDSS'26] Shaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari, Ningfei Wang, Takami Sato, Halima Bouzidi, Mohammad Abdullah Al Faruque, and Qi Alfred Chen, FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking Systems
(Acceptance Rate: 17.9%)
[paper][site]
-
[NDSS'25] Takami Sato*, Ryo Suzuki*, Yuki Hayakawa*, Kazuma Ikeda, Ozora Sako, Rokuto
Nagata, Ryo Yoshida, Qi Alfred Chen, and Kentaro Yoshioka, On the Realism of LiDAR Spoofing Attacks
against Autonomous Driving Vehicle at High Speed and Long Distance
(Acceptance Rate: 16.1%) (* denotes co-first)
[paper]
-
[NDSS'25] Ningfei Wang, Shaoyuan Xie, Takami Sato, Yunpeng Luo, Kaidi Xu, and Qi Alfred
Chen, Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems
Perspective (Acceptance Rate: 16.1%)
[paper]
-
[ICLR'25] Ruochen Jiao, Shaoyuan Xie, Justin Yue, Takami Sato, Lixu Wang, Yixuan Wang, Qi Alfred Chen, and Qi Zhu, Can We Trust Embodied Agents? Exploring Backdoor Attacks against Embodied LLM-based Decision-Making Systems
(Acceptance Rate: 32.1%)
[paper][code]
-
[ICRA'25] Rokuto Nagata, Kenji Koide, Yuki Hayakawa, Ryo Suzuki, Kazuma Ikeda, Ozora Sako, Qi Alfred Chen, Takami Sato, and Kentaro Yoshioka, SLAMSpoof: Practical LiDAR Spoofing Attacks on Localization Systems Guided by Scan Matching Vulnerability Analysis
(Acceptance Rate: 38.7%)
[paper][code]
-
[CVPR'24] Takami Sato, Justin Yue, Nanze Chen, Ningfei Wang, and Qi Alfred Chen,
Intriguing Properties of Diffusion Models: An Empirical Study of the Natural Attack Capability in
Text-to-Image Generative Models (Acceptance Rate: 23.6%) [paper][site]
-
[NDSS'24] Takami Sato*, Yuki Hayakawa*, Ryo Suzuki*, Yohsuke Shiiki*, Kentaro Yoshioka,
and Qi Alfred Chen, LiDAR Spoofing Meets the New-Gen: Capability Improvements, Broken Assumptions, and New Attack Strategies (Acceptance Rate: 20.2%) (* denotes co-first)
[paper][site]
-
[NDSS'24] Takami Sato*, Sri Hrushikesh Varma Bhupathiraju*, Michael Clifford, Takeshi
Sugawara, Qi Alfred Chen, and Sara Rampazzi, Invisible Reflections: Leveraging Infrared
Laser Reflections to Target Traffic Sign Perception (Acceptance Rate: 20.2%) (* denotes co-first)
[paper]
-
[VehicleSec'24] Takami Sato, Ningfei Wang, Yueqiang Cheng, and Qi Alfred Chen, A Cross-Verification Approach with Publicly Available Map for Detecting Off-Road Attacks against Lane Detection Systems
(Acceptance Rate: 43.1%)
[paper]
-
[ICCV'23] Ningfei Wang, Yunpeng Luo, Takami Sato, Kaidi Xu, and Qi Alfred Chen,
Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion Attack (Acceptance Rate: 26.2%) [paper]
-
[ICCV'23] Ruochen Jiao, Xiangguo Liu, Takami Sato, Qi Alfred Chen, and Qi Zhu,
Semi-Supervised Semantics-Guided Adversarial Training for Trajectory Prediction (Acceptance Rate:
26.2%) [paper]
-
[IROS'23] Ruochen Jiao, Juyang Bai, Xiangguo Liu, Takami Sato, Xiaowei Yuan, Qi Alfred
Chen, and Qi Zhu, Learning Representation for Anomaly Detection of Vehicle Trajectories (Acceptance Rate: 43%) [paper]
-
[CVPR'22] Takami Sato and Qi Alfred Chen, Towards Driving-Oriented Metric for Lane
Detection Models (Acceptance Rate: 25.3%)
[paper]
[site]
-
[Usenix Security'21] Takami Sato*, Junjie Shen*, Ningfei Wang, Yunhan Jack Jia, Xue Lin,
and Qi Alfred Chen, Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering
under Physical-World Attack (Acceptance Rate: 18.7%) (* denotes co-first authors)
[paper]
[demo]
-
[IV'21] Ruochen Jiao, Hengyi Liang, Takami Sato, Junjie Shen, Qi Alfred Chen, and Qi Zhu,
End-to-end Uncertainty-based Mitigation of Adversarial Attacks to Automated Lane Centering (Acceptance Rate: 49.3%)
[paper]
Acceptance rates are the overall rates reported by each conference for that year.
Journal Articles
-
[ACM TCPS'26] Sri Hrushikesh Varma Bhupathiraju, Takami Sato, Michael
Clifford, Takeshi Sugawara, Qi Alfred Chen, and Sara Rampazzi, To Go or Not to Go: Shedding Light on
Traffic Light Signal Manipulation and Defense Strategies, ACM Transactions on Cyber-Physical
Systems, 2026. [paper]
-
[IEEE Sensors J.'25] Ryo Suzuki, Takami Sato, Yuki Hayakawa, Kazuma
Ikeda, Ozora Sako, Rokuto Nagata, Ryo Yoshida, Qi Alfred Chen, and Kentaro Yoshioka, From Lab to Road:
Realizing and Detecting LiDAR Spoofing Attacks Against Autonomous Vehicles at High Speed and Long
Distance, IEEE Sensors Journal, 25(13):25661–25681, 2025.
[paper]
-
[IEEE Sensors J.'25] Yuki Hayakawa, Takami Sato, Ryo Suzuki, Kazuma
Ikeda, Ozora Sako, Rokuto Nagata, Ryo Yoshida, Qi Alfred Chen, and Kentaro Yoshioka, Breaking the
Shield: Systematic Security Analysis on Pulse Fingerprinting LiDAR Systems for Autonomous Driving,
IEEE Sensors Journal, 25(11):20523–20537, 2025.
[paper]
Preprints
-
Ryo Yoshida, Takami Sato, Wenlun Zhang, Yuki Hayakawa, Shota Nagai, Takahiro Kado, Taro Beppu,
Ibuki Fujioka, Yunshan Zhong, and Kentaro Yoshioka,
Neural Reconstruction of LiDAR Point Clouds under Jamming Attacks via Full-Waveform Representation and
Simultaneous Laser Sensing,
arXiv preprint arXiv:2604.00371, 2026.
-
Go Tsuruoka, Takami Sato, Qi Alfred Chen, Kazuki Nomoto, Ryunosuke Kobayashi, Yuna Tanaka, and
Tatsuya Mori,
Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign
Recognition Systems,
arXiv preprint arXiv:2511.10050, 2025.
-
Ryota Ueda, Takami Sato, Ken Kobayashi, and Kazuhide Nakata,
Interior-Point Vanishing Problem in Semidefinite Relaxations for Neural Network Verification,
arXiv preprint arXiv:2506.10269, 2025.
-
Takami Sato and Qi Alfred Chen,
On Robustness of Lane Detection Models to Physical-World Adversarial Attacks in Autonomous Driving,
arXiv preprint arXiv:2107.02488, 2021.
-
Junjie Shen, Ningfei Wang, Ziwen Wan, Yunpeng Luo, Takami Sato, Zhisheng Hu, Xinyang Zhang,
Shengjian Guo, Zhenyu Zhong, Kang Li, Ziming Zhao, Chunming Qiao, and Qi Alfred Chen,
SoK: On the Semantic AI Security in Autonomous Driving, arXiv preprint arXiv:2203.05314, 2022.
Posters
- [CCS'22]
Takami Sato, Yuki Hayakawa, Ryo Suzuki, Yohsuke Shiiki, Kentaro Yoshioka, and Qi Alfred Chen,
Towards Large-Scale Measurement Study on LiDAR Spoofing Attacks against Object Detection
[abstract]
- [NDSS'20]
Takami Sato, Junjie Shen, Ningfei Wang, Yunhan Jack Jia, Xue Lin, and Qi Alfred Chen,
Security of Deep Learning based Lane Keeping Assistance System under Physical-World Adversarial Attack
[abstract][demo]
Best Technical Poster Award (Top 1/30)
Invited Talks
- Mar. 2026 — The 38th JASS (Japan-America Student Summit), Stanford University: "Autonomous
Driving Security and Life in the Academic Security Community" [Japanese]
- Sep. 2024 — FIT 2024 Top Conference Session, Japan: LiDAR Spoofing Meets the New-Gen
(NDSS'24)
Media Coverage
- Mar. 2025, UC Irvine News, UC
Irvine study shines headlights on consumer driverless vehicle safety deficiencies (NDSS'25
traffic sign recognition study)
- Feb. 2025, Keio University & JST joint press release, Discovery that autonomous
driving sensors can be disabled from a long distance while driving [Japanese]; also covered by
Nikkei, Nikkei xTECH, and Jidounten Lab
- Feb. 2024, UC Irvine News, Autonomous
vehicle technology vulnerable to road object spoofing and vanishing attacks (NDSS'24 new-gen
LiDAR study)
- Feb. 2024, Automotive News, Lidar
sensors vulnerable to spoofing attacks, researchers say (NDSS'24)
- Feb. 2024, IoT World Today, Self-Driving
Tech Vulnerable to Attack, Study Finds (NDSS'24)
- Feb. 2024, Electro Optics, Autonomous
lidar can be spoofed into performing unsafe actions, study finds (NDSS'24)
- Feb. 2024, Keio University & JST joint press release, World's first comprehensive
security study of LiDAR sensors for autonomous driving [Japanese]
(JST) (NDSS'24)
- Feb. 2024, Nikkei, Keio University and UC Irvine
jointly conduct a comprehensive security study of LiDAR sensors for autonomous driving
[Japanese] (NDSS'24)
- Feb. 2024, Nikkei xTECH, Vulnerability in LiDAR for autonomous
driving: Keio University and others confirm object removal via the HFR attack [Japanese]
(NDSS'24)
- Jan. 2024, ITmedia NEWS, Shining a laser invisible to
humans on road signs: an attack that deceives autonomous vehicles, presented by US and Japanese
researchers [Japanese] (NDSS'24 Invisible Reflections)
- Mar. 2023, UC Irvine ICS, Computer
Science Ph.D. Candidate Takami Sato Named Public Impact Fellow
- Oct. 2020, UC Irvine ICS, ICS Team
Takes 1st Place at Baidu's AutoDriving Capture the Flag Competition
- Jul. 2013, ITmedia Marketing, Google and others conduct a
survey on online campaigning in the House of Councillors election [Japanese]
Paper Review and Program Committee Experiences
- Outstanding Reviewer, European Conference on Computer Vision (ECCV) 2024
- Program committee of USENIX Security Symposium 2027
- Program committee of Association for the Advancement of Artificial Intelligence (AAAI) 2026
- Program committee of IEEE European Symposium on Security and Privacy (EuroS&P) 2024
- Program committee of CPSIoTSec 2023, 2024
- Program committee of IEEE Mobility, Sensing and Networking (MSN) 2023
- Reviewer of International Conference on Artificial Intelligence and Statistics (AISTATS) 2025
- Reviewer of International Conference on Machine Learning (ICML) 2025
- Reviewer of International Conference on Learning Representations (ICLR) 2025
- Reviewer of Neural Information Processing Systems (NeurIPS) 2024, 2025
- Reviewer of International Conference on Computer Vision (ICCV) 2023, 2025
- Reviewer of European Conference on Computer Vision (ECCV) 2022, 2024
- Reviewer of IEEE / CVF Computer Vision and Pattern Recognition Conference (CVPR) 2022, 2023, 2024
- More than 50 papers review experience as a delegation reviewer (IEEE S&P, Usenix Security, ACM CCS,
NDSS, AsiaCCS, INFOCOM, ACSAC, TDSC, ICCPS, BMVC, SPML)
Slides
Awards and Honors
- Outstanding Reviewer, European Conference on Computer Vision (ECCV) 2024
- DENSO Best Demo Award, VehicleSec 2023 (Infrared Laser Reflection Attack against Traffic Sign
Recognition Systems)
- ETAS Best Short/WIP Paper Award Runner-Up, VehicleSec 2023 (Practical Removal Attacks on
LiDAR-based Object Detection in Autonomous Driving)
- $5,000 Awards, Graduate Dean’s Dissertation Fellowship, UCI Graduate Division, 2023
- $1,000 Awards, Public Impact Fellowship, UCI Graduate Division, 2022
- 1st place (RTX A6000 + HP Laptop), Kaggle Days x Z by
HP World Championship Final in Barcelona, Spain, 2022
- 2nd place ($7.5k prize), Kaggle, Foursquare Location Matching (Top 2/1079), 2022
- 2nd place, Kaggle days x Z by HP world championship at San Francisco (Top 2/82), 2022
- 2nd place ($8k prize), Kaggle, PetFinder.my - Pawpularity Contest (Top 2/3537), 2022
- Earned the Kaggle Grandmaster title (Only 240+ Kaggle
Grandmasters in the world), 2021
- 2nd place ($1k prize), Kaggle, chaii - Hindi and Tamil Question Answering (Top 2/943), 2021
- $3,000 award, The Beall Family Foundation Graduate Student Entrepreneur Award in Computer
Science, 2021
- $10,000 prize (2nd place), Shopee -
Price Match Guarantee (Top 2/2462), 2021
- 1st place (Champion), Baidu
AutoDriving CTF (Top 1/24), 2020
- Gold Medal (5th place), Kaggle
Tweet Sentiment Extraction (Top 5/2227), 2020
- Best Technical Poster Award, NDSS 2020 (Top 1/30)
- Silver Medal (23rd place, solo), Kaggle Santa's Workshop Tour 2019
(Top 23/1620 and optimal solution obtained), 2019
- Gold Medal (11th place, solo), TalkingData AdTracking Fraud
Detection Challenge (Top 11/3946), 2018
- Earned the Kaggle Master title (Top 1% Kaggle competitors
worldwide), 2017
- Gold Medal (15th place, solo), Kaggle Instacart Market Basket
Analysis (Top 15/2622), 2017
- Silver Medal (17th place, solo), Kaggle
Quora Question Pairs (Top 17/3304), 2017
- Silver Medal (17th place), Kaggle Bosch Production Line
Performance (Top 17/1370), 2016
- Repayment Exemption of Student Loan (about $25,000) for Students with Excellent Grades - Japan
Student Services Organization, 2013
Industry Experience
- Sep. 2024 - Present: Machine Learning Engineer II, Uber Technologies, Inc.
- June 2024 - Sep. 2024: Ph.D. Research Intern, Qualcomm Incorporated
- June 2023 - Sep. 2023: Ph.D. Research Software Engineer Intern, Uber Technologies, Inc.
- June 2022 - Sep. 2022: Internship Security Researcher, Toyota InfoTech Labs
- Mar. 2021 - Sep. 2021: Internship Security Researcher, NIO Inc.
- July 2017 - Aug. 2018: Machine Learning Engineer, Freelance
- Sep. 2016 - June 2017: Machine Learning Engineer, Recruit Communications Co., Ltd.
- April 2013 - June 2016: Data Scientist/Software Engineer, BrainPad Inc.
Education
- Sep. 2024: Ph.D. in Computer Science - University of California, Irvine (Supervisor: Prof. Qi Alfred Chen)
Dissertation: Exploring Novel Security Vulnerabilities and Their Safety Implications
in Sensors and Perception for Autonomous Systems
- Sept. 2019: M.S. in Computer Science - University of California, Irvine (Supervisor: Prof. Qi Alfred Chen)
- March 2013: M.Eng of Industrial Engineering and Management - Tokyo Institute of Technology (Supervisor:
Prof. Kazuhide Nakata)
- March 2011: B.Eng of Industrial Engineering and Management - Tokyo Institute of Technology (Supervisor:
Prof. Kazuhide Nakata)