Publications
2026
Ruri Otsuka, Ryu Kuki, Yin Minn Pa Pa, Katsunari Yoshioka, POSTER: What HTTP Basic Authentication Reveals: Measuring Identifiable Internet-Exposed Devices, DIMVA, 2026, Greece. Conference Page. [Poster:DIMVA]
Towa Kaido, Shogo Ito, Yin Minn Pa Pa, Katsunari Yoshioka, Disposable accounts, persistent ecosystem: A cross-forum study of Initial Access Brokers, Cambridge Cybercrime Conference, UK, 2026. Conference Page.[Cambridge Cybercrime Conference]
Daiki Baba, Riku Aoto, Yin Minn Pa Pa, Katsunari Yoshioka, API-Based Observation and Analysis of Telegram’s Moderation of Cybercrime Channels, ICSS, 2026, Japan. Conference Page, paper
Riku Aoto,Daiki Baba, Yin Minn Pa Pa, Katsunari Yoshioka, Collecting and Categorizing Cybercrime-Related Channels on Telegram at Scale, ICSS, 2026, Japan. Conference Page, paper
Hikaru Matsuzawa, Yukihiro Higashi, Anh Nguyen Thi Van, Rui Tanabe,Yin Minn Pa Pa, Katsunari Yoshioka, LLM-Based Generation of Proof-of-Concept Code for Evading Sandbox Analysis, ICSS, 2026, Japan. {Best Paper Award}. Conference Page, paper
Qingxin Mao, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Understanding Web-Exposed Cybercrime-Related Content on IoT Botnet Infrastructure, ICSS, 2026, Japan. Conference Page, paper
Anh Nguyen Van, Matsuzawa Hikaru, Ito Hikaru,Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Leveraging LLMs to Generate and Counter Sandbox Evasion Techniques, NDSS 2026, USA. Conference Page poster. [Poster:NDSS]
2025
Rikuto Otsu, Yin Minn Pa Pa, Katsunari Yoshioka, and Kazumasa Omote, An Analysis of Syntactic Evolution and Detection Performance in Smart Ponzi Schemes, ICBAT, 2025,Kanazawa, Japan. Conference Page, paper. [ICBAT 2025]
Ruri Otsuka, Yin Minn Pa Pa, Katsunari Yoshioka, Large-Scale Experiment on IoT Device Identification Using Basic Authentication Responses, CSS, 2025, Japan. Conference Page, paper
Akinori Uchino, Yin Minn Pa Pa, Katsunari Yoshioka, Detection of Third-Party Dependencies in Darknet Markets via LLM-Based Signature Generation, CSS, 2025, Japan. Conference Page, paper
Sota Kubo, Yukihiro Hagayama, Yin Minn Pa Pa, Tatunori Mori, Katsunari Yoshioka,Examining the Feasibility of Conducting Human Intelligence (HUMINT) on Telegram Based on Informed Consent, CSS, 2025, Japan. Conference Page, paper
Yukihiro Hagayama, Sota Kubo, Yin Minn Pa Pa, Tatunori Mori, Katsunari Yoshioka, Towards an Ethical Monitoring LLM for HUMINT Dialogues with a Menlo Report Based Checklist, CSS, 2025, Japan. Conference Page, paper
Towa Kaido, Shogo Ito, Rui Tanabe, Yin Minn Pa Pa, Katsunari Yoshioka, Detection of IAB Posts Using DarkBERT and Llama 3.3, CSS 2025, Japan. Conference Page, paper
Shogo Ito, Towa Kaido, Rui Tanabe, Yin Minn Pa Pa, Katsunari Yoshioka, An Investigation of Initial Access Brokers on Underground Forums:Market Trends and Activity Analysis, CSS 2025,Japan. Conference Page, paper
Hikaru Ito, Nguyen Thi Van Anh, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Enhancing Sandbox Evasion Resistance Using LLM, CSS 2025,Japan. Conference Page, paper
Rikuto Otsu, Yin Minn Pa Pa, Katsunari Yoshioka, Kazumasa Omote, Investigating the Evolution of Syntax and Detection Effectiveness in Smart Ponzi Schemes, CSS, 2025, Japan. Conference Page, paper
Yin Minn Pa Pa, Yuji Sekine, Yamato Kawaguchi, Tatsuki Yogo, Kelvin Lubbertsen, Rolf van Wegberg, Michel van Eeten, Katsunari Yoshioka, A Longitudinal Analysis of LockBit 3.0’s Extorsion Lifecycle and Response to Law Enforcement, The 28th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2025), Gold Coast, Australia, 19-22 October, 2025. (Acceptance Rate: 22~25 %) Conference Page, paper. [RAID 2025]
Yukihiro Higashi, Hikaru Matsuzawa, Rui Tanabe, Yin Minn Pa Pa, Katsunari Yoshioka, Poster: Conventional LLM Use Struggles to Generate Sandbox Evasion Code from Unseen Categories, Euro S&P, Venice, June 30 - July 4, 2025. Poster. [Poster: Euro S&P]
Takanori Matsumura, Riku Aoto, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Experimental Demonstration of Attracting Attackers to Attack Observation Systems by Imitating Initial Access Brokers on Telegram, Security Summer Summit (ICSS), Hokkaido, Japan. Conference Page, paper
Shoi Kaneko, Riku Aoto, Nguyen Thi Van Anh, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, STIX Threat Intelligence Extraction from Telegram via Prompt-Aligned LLM, Security Summer Summit (ICSS), Hokkaido, Japan. Conference Page, paper
Rei Tanabe, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Kento Uchida, Shinichi Shirakawa, A Framework for Iterative Sandbox Evasion Code Generation Using Attacker and Defender LLMs, Security Summer Summit (ICSS), Hokkaido, Japan. Conference Page, paper
Sha Peng, Yinn Minn Pa Pa, Takayuki Sasaki, Katsunari Yoshioka, Exploration of IoT Platforms Utilizing Censys Internet-wide Scanning System, CSEC 2025, Gunma, Japan. Conference Page, paper
Riku Aoto, Yin Minn Pa Pa, Katsunari Yoshioka, Discovery and Analysis of Cybercrime-Related Telegram Channels using the Similar Channel Recommendation Feature, ICSS 2025, Japan. Conference Page, paper
Ryosuke Suzuki, Yamato Kawaguchi, Yin Minn Pa Pa, Hiroaki Yamaoka, Katsunari Yoshioka, ICSS 2025, Japan. Text-based Human Intelligence Gathering Framework: Legal and Ethical Considerations and the Application of LLMs, ICSS 2025, Japan. Conference Page, paper
Yukihiro Higashi, Hikaru Matsuzawa, Rui Tanabe, Yin Minn Pa Pa, Evaluating the Classification Accuracy of an LLM for Sandbox Evasion Proof-of-Concept Code, ICSS 2025, Japan. Conference Page, paper
Koudai Aoyama, Ruri Otsuka, Yin Minn Pa Pa, Katsunari Yoshioka, Towards Evaluating the Detection Accuracy of Internet-Wide Scanners for Frequently Exploited Vulnerabilities, ICSS 2025, Japan. Conference Page, paper
Qingxin Mao, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Linking IoT Attacks to Cybercrime-as-a-Service Offerings Using LLM and DNS Data, ICSS 2025, Japan. Conference Page, paper
Iori Suzuki, Yin Minn Pa Pa, Nguyen Anh Thi Van, and Katsunari Yoshioka, DeFiIntel: A Dataset Bridging On-Chain and Off-Chain Data for DeFi Token Scam Investigation, MADWEB 2025 (NDSS colocated workshop 42% acceptance rate), San Diego, California, from 24 to 28 February 2025. Conference Page, paper
Ruri Otsuka, Yin Minn Pa Pa, Katsunari Yoshioka, Application of ChatGPT Search to Device Inferrance Focusing on Basic Authentication Requests and Responses. SCIS 2025, Japan. Conference Page, paper
2024
Zhewei Huang, Yin Minn Pa Pa, Katsunari Yoshioka, Exploring the Impact of LLM Assisted Malware Variants on Anti-Virus Detection, IEEE DSC 2024, Japan. Conference Page, paper. [DSC 2024]
Yamato Kawaguchi, Kazuki Takada, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto, Investigating Black-Market Jobs on Social Networking Service, IEEE DSC 2024, Japan. Conference Page, paper. [DSC 2024]
Katsunari Yoshioka, Shoi Kaneko, Koudai Aoyama, Ryu Kuki, Yin Minn Pa Pa, Takayuki Sasaki, Rui Tanabe “INSITE: Cybersecurity Framework Integrating Attack Observation with OSINT/HUMINT”, CSS 2024, Japan. Conference Page, paper
Yamato Kawaguchi, Yin Minn Pa Pa, Katsunari Yoshioka, “Investigation of Cybercrime-Related Slang on Discord Using Large Language Models”, CSS 2024, Japan. Conference Page, paper
Hikaru Matsuzawa、Soda Kubo, Yin Minn Pa Pa, Tanabe Rui、Katsunari Yoshioka, “Investigating the Impact of Evasive Malware Created with LLM on Sandbox Analysis”, CSS 2024, Japan. Conference Page, paper
Ruri Otsuka, Kiyokazu Yoshioka, Yin Minn Pa Pa, Katsunari Yoshioka, “Investigation of Device Fingerprinting Focused on Basic Authentication Requests”, CSS 2024, Japan. Conference Page, paper
Ryu Kuki, Sasaki Takayuki, Yin Minn Pa Pa, Katsunari Yoshioka “Towards the Classification of Newly Exploits Observed by Honeypots”, CSS 2024, Japan. {Best Paper Award}. Conference Page, paper
Iori Suzuki, Yin Minn Pa Pa, Katsunari Yoshioka “Building a Dataset for Accelerating Researches against Fraudulent DeFi Tokens”, Security Summer Summit 2024 Hokkaido Japan, 2024 July 22~23. Conference Page, paper
Riku Aoto, Yin Minn Pa Pa, Katsunari Yoshioka “Detection of Web3 Phishing Sites Focused on Permission Requests After Wallet Connection”, Security Summer Summit 2024 Hokkaido Japan, 2024 July 22~23. Conference Page, paper
Zhewei Huang, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Impact of ChatGPT Assisted Polymorphic Malware on Antivirus Detection”, ICSS 2024 Japan, 2024 March 21~22. Conference Page, paper
Aiman Syazwan Bin Abdul Razak, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Unveiling the Shadows: Analyzing Cryptocurrency Address Management and Fund Movement of Darknet Markets”, ICSS 2024 Japan, 2024 March 21~22. Conference Page, paper
Yuji Sekine, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Analyzing Attackers and Victims Actions via LockBit3.0 Website Data Dynamics”, ICSS 2024 Japan, 2024 March 21~22. Conference Page, paper
Yamato Kawaguchi, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “ChatGPT Assisted Information Collection System for Cybercrime on Discord”, SCIS 2024 Japan, 2024 January 23~26. Conference Page, paper
2023
Shunsuke Tanizaki, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Evaluating the Behavior Detection Functionality of Antivirus and EDR against Double Extortion Ransomware”, CSS 2023 Japan, 2023 October 30. Conference Page, paper
Yin Minn Pa Pa, Shunsuke Tanizaki, Tetsui Kou, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto, “An Attacker’s Dream? Exploring the Capabilities of ChatGPT for Developing Malware”, CSET 2023 USA, 2023 August 7. paper, PPT. [CSET 2023]
Yamato Kawaguchi, Kazuki Takada, Yin Minn Pa Pa, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto, “Towards observation of online fraud exploiting multiple SNS”, ICSS Japan, 2023 March. Conference Page, paper
Shunki Soeda, Takahiro Inoue, Rui Tanabe, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Assessment Method for Persistent Malware Infection on IoT Devices”, ICSS Japan, 2023 March. {Best Paper Award}. Conference Page, paper
2022
- Hiroshi Mori, Hiroshi Kumagai, Yin Minn Pa Pa, Yuta Takata, Ryoya Furukawa, Yuji Sakurai, Masaki Kamizono, “Cryptocurrency Analysis System for Investigating Cyber Crime Economy”, ICSS Japan, 2022. Conference Page.
2021
Hiroshi Mori, Hiroshi Kumagai, Yin Minn Pa Pa, Yuta Takata, Shogo Suzuki, Masaki Kamizono, “Visualizing Method for Clustering Illicit Cryptocurrency by Transaction Time”,CSEC Japan, 2021. Conference Page
Yin Minn Pa Pa, Paul Ziegler, Masaki Kamizono, “Hiding Objects from Computer Vision by Exploiting Correlation Biases”, Black Hat Asia 2021 Online, 2021 May. PPT, Video Presentation. [Blackhat Asia 2021]
2018
- Yin Minn Pa Pa, Hiroshi Kumagai, Masaki Kamizono, Takahiro Kasama, “Counter-Infiltration: Future-Proof Counter Attacks Against Exploit Kit Infrastructure”, Black Hat Asia 2018 Singapore, 2018 March 23. Whitepaper, Video Presentation. [Blackhat Asia 2018]
2016
Yin Minn Pa Pa, “A Study on Detecting Cyber Attack Resources by Coordinated Passive and Active Monitoring”, Ph.D Dissertation
Rui Tanabe, Shogo Suzuki, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Malware Expansion Interception Method Focused on Remote Takeover against Malware-infected Hosts”, Journal of Information Processing, Japan, Vol.57-No.9, 2016 September.{Best Paper Award}. Journal Paper[Journal]
Akira Yokoyama, Kou Ishii, Rui Tanabe, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Daisuke Inoue, Michael Brengel, Michael Backes, Christian Rossow, “Sandprint: Fingerprinting Malware Sandboxes to Provide Intelligence for Sandbox Evasion”, RAID 2016, France. Paper. [RAID 2016]
Shogo Suzuki, Yin Minn Pa Pa, Yuta Ezawa, Sou Nakayama, Ying Tie, Katsunari Yoshioka, Tsutomu Matsumoto, “Improving IoTPOT for Observing Various Attacks Target Embedded Devices”, Information and Communication System Security (ICSS) Japan, 2016 March. Paper
Yin Minn Pa Pa, Shogo Suzuki, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Christian Rossow, “IoTPOT: A Novel Honeypot for Revealing Current IoT Threats”, Journal of Information Processing Japan, Vol.24-No.3, 2016 march. Journal Paper[Journal]
2015
Katsunari Yoshioka, Yin Minn Pa Pa, Shogo Suzuki, Naoki Watanabe, Sou Nakayama,Toshiya Shimura, Haoyuan Xu, Junji Shikata, Tsutomu Matsumoto, Koji Nakao, Takeo Hariu, Makoto Iwamura, Takeshi Yagi, Mitsuaki Akiyama, Masato Terada, Shigeyoshi Shima,Masafumi Watanabe, Takahiro Kakumaru, Masaru Kawakita, Masahiro Yamada, Daisuke Inoue, “Collection and Analysis of Cyber Security Data by Active and Passive Monitoring”,CSS 2015 Japan, 2015 October. Paper
Yin Minn Pa Pa, Shogo Suzuki, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Christian Rossow, “IoTPOT: Analysing the Rise of IoT Compromises”, 9th USENIX Workshop on Offensive Technologies (WOOT’ 2015), US, 2015 August. Paper. [WOOT 2015]
Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Detecting Malicious Domains and Authoritative Name Servers Based on Their Distinct Mappings to IP Addresses”, Journal of Information Processing, Japan, Vol.23, No.5, pages 623-632, 2015 March. Journal Paper[Journal]
2013
Daisuke Makita, Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “A Method for Detecting Malware Infected Hosts with Similarity of Name Resolution Behavior”, Symposium on Cryptography and Information Security (SCIS), Japan, 2013 January. Paper
Yin Minn Pa Pa, Daisuke Makita, Katsunari Yoshioka, Tsutomu Matsumoto, “Finding Malicious Authoritative DNS server”, Information and Communication System Security (ICSS), Yokohama, Japan, 2013 March.{Bet Technical Report Award of the Year}. Paper
Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “Search Engine Based Investigation on Misconfiguration of Zone Transfer”, Asia Joint Conference on Information Security (Asia-JCIS), Seoul, Korea, 2013 July.{Best Paper Award}. Paper. [Asia JCIS 2013]
2012
- Yin Minn Pa Pa, Katsunari Yoshioka, Tsutomu Matsumoto, “ Search Engine Based Investigation on Misconfiguration of Zone Transfer”, International Workshop on Security (IWSEC-2012), Fukuoka, Japan, 2012 November. POSTER[Poster: IWSEC 2012]
