Arxiv pdf
Contrastive LanguageImage Pretraining (CLIP) has emerged as a dominant vision backbone due to its strong transferability and zero-shot capabilities. However, recent studies reveal a critical vulnerability: _embedding-space backdoor attacks_ . By poisoning only a tiny fraction of imagetext pairs, adversaries can implant stealthy triggers that induce targeted shifts in CLIPs joint embedding space....
Arxiv pdf
Private and encrypted mempools hide pending transactions to stop sandwich attacks and other forms of maximal extractable value (MEV), but what they hide is rarely everything: a transactions pair, direction, and a coarse range for its size can still leak. How much leakage makes sandwiching pay? We answer exactly for a fee-free constant-product automated market maker, the pricing rule behind...
Arxiv pdf
Inspired by the planted clique problem for random graphs, we introduce the planted totallyisotropic space problem for random tensors as follows. Let _U_ = _[]_ F _[n] q_[and] _[W][]_[=][F] _[m] q_ be finitedimensional vector spaces over a finite field F _q_ . Given _d _ N, choose a random _d_ -dimensional subspace _V U_ , and construct a random alternating bilinear map __ : _U U W_ subject to...
Arxiv pdf
Novel view synthesis (NVS) models can produce realistic new views of the same scene from different viewpoints. However, these generated views are not always geometrically consistent with one another. Multi-view (MV) consistency has shown promise as a tool for evaluating these NVS models. Its potential for multimedia forensics, however, remains largely unexplored, particularly for localizing...
Arxiv pdf
**Large language models are increasingly used as high-level planners for mobile robots, robot manipulators, and autonomous vehicles. Recent studies show that these systems can be influenced through malicious text, speech, visual instructions, retrieved documents, and poisoned sensory context. Most defenses ask whether a proposed action is physically safe. This paper studies a different problem:...
Arxiv pdf
TempQ-Jail reframes text‑to‑video jailbreaking as a query‑constrained candidate allocation and ranking problem. Under tight query budgets, the attack’s success hinges not only on having valid prompts but on presenting the most promising ones early enough to be tested before the budget runs out.
Arxiv pdf
Modern AI image generators are increasingly deployed as opaque APIs, where customers can query the deployed service, but cannot inspect model weights or architecture. This creates a practical challenge: a provider may pass governance certification with one generator and later silently switch to a cheaper and lower-quality one for deployment, compromising public trust or even safety in high-stakes...
Arxiv pdf
_Slashing_ is commonly argued to secure proof-of-stake blockchains by confiscating the stake of misbehaving validators. The usual justification is that, without slashing, validators can solicit an equivocation attack by signing conflicting blocks: if enough others join, the attack succeeds; otherwise, the attempt incurs no loss. Slashing is intended to make such attempts costly and thereby...
Arxiv pdf
Agents are increasingly deployed with real autonomy in web application and network penetration testing, where a single out-of-scope action can breach a clients engagement boundary. Existing offensive-security benchmarks measure raw hacking capability; as those benchmarks saturate, the actual barrier to deployment is a special case of alignment: scope adherence. We introduce **ScopeBench** , a...
Arxiv pdf
IoT device may communicate with malicious endpoints, ports, or services unrelated to its intended function [6]. Restricting each device to the communications required for its legitimate operation can therefore reduce the impact of compromise. The Manufacturer Usage Description (MUD) standard allows manufacturers of Internet of Things (IoT) devices to define in a MUD file the profile of the...
Arxiv pdf
Leaked system prompts are often treated as windows into the hidden values of commercial language models, yet their composition is rarely studied at scale. We analyze a merged corpus of 407 leaked, reconstructed, or officially published system prompts from 62 vendors across four community collections, identifying 29 near-duplicate clusters covering 66 files. Operational content rather than ethical...
Arxiv pdf
As large language model (LLM) inference becomes increasingly expensive, resource-consumption attacks pose a growing threat to model providers. Existing attacks typically amplify cost by inducing abnormally long or repetitive outputs on attacker-controlled or triggered requests, making them easier to detect and limiting their deployment-wide impact when benign traffic dominates. In this work, we...
Arxiv pdf
arXiv:2609.31519v1 Announce Type: new Abstract: The Simultaneous Authentication of Equals (SAE) protocol, introduced in WPA3, provides robust protection against offline dictionary attacks against a network Pre-Shared Key (PSK) and also protection of session keys from other people knowing that PSK. However, its high computational cost for the Password Element (PE) derivation makes Access Points...
Arxiv pdf
arXiv:2609.31494v1 Announce Type: new Abstract: Federated Learning (FL) allows devices with private data to collaborate in training a shared model. We present a next-generation FL system based on Trusted Execution Environments (TEEs) that addresses operational challenges associated with earlier systems and provides externally verifiable central Differential Privacy (DP) guarantees for the first...
Arxiv pdf
arXiv:2609.31485v1 Announce Type: new Abstract: As lotteries and other high-stakes decentralized applications increasingly depend on unpredictable randomness for their operations, the lack of a secure and transparent on-chain random number generator that is verifiable by all participants remains a critical open problem. Various approaches to blockchain-based random number generation have emerged...
Arxiv pdf
arXiv:2609.31409v1 Announce Type: new Abstract: Third-party libraries (TPLs) are widely used in Android apps, but their reuse can introduce security risks and interfere with downstream program analyses. Existing Android TPL detection approaches face two key limitations: their hand-crafted features are fragile under aggressive code transformations, and their whole-library matching strategies are...
Arxiv pdf
arXiv:2609.31398v1 Announce Type: new Abstract: When a card number is compromised, an attacker may search for active numbers sharing its prefix. An issuer might respond by reissuing cards from heavily populated prefixes into less populated ones. We show that this intuitive count control can backfire. For fixed search regions, exposure weights, and total activity, we derive exactly when reducing...
Arxiv pdf
arXiv:2609.31318v1 Announce Type: new Abstract: AI agents combine language models with external data and tools that can modify files, call APIs, or execute code. Security failures can arise when adversarial content changes an agent's tool use or when the surrounding software contains vulnerabilities such as path traversal or command injection. We study authorized white-box pre-deployment...
Arxiv pdf
arXiv:2609.31310v1 Announce Type: new Abstract: Certified defenses that incorporate differential privacy have proven effective on Convolutional Neural Networks (CNNs), furnishing rigorous robustness guarantees against norm-bounded adversaries. However, the certified robustness behavior of Pixel Differential Privacy (PixelDP) remains largely unexplored with the self-attention architecture now...
Arxiv pdf
arXiv:2609.31282v1 Announce Type: new Abstract: This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura...
Arxiv pdf
arXiv:2609.31262v1 Announce Type: new Abstract: Cross-client duplicate data in large language model training corpora degrades the efficiency of federated learning (FL) while exacerbating model memorization and privacy risks. Privacy-preserving cross-client deduplication effectively mitigates this issue by eliminating duplicate training data. However, existing schemes all follow a...
Arxiv pdf
arXiv:2609.31252v1 Announce Type: new Abstract: The arrival of quantum computers threatens the security guarantees of classical cryptography, since quantum algorithms can break schemes that remain secure against conventional attacks. The National Institute of Standards and Technology (NIST) has therefore standardized a set of post-quantum cryptographic algorithms, among them Falcon, a...
Arxiv pdf
arXiv:2609.31142v1 Announce Type: new Abstract: Models trained with reinforcement learning for calibrated decisions (RLCD), such as Jev, answer a typed question about an input, the state, with a probability, a choice, or a score, and software acts on the answer without a person reading it. Their robustness has not been measured: adversarial benchmarks score what a model generates or executes,...
Arxiv pdf
arXiv:2609.31119v1 Announce Type: new Abstract: Resource disaggregation separates memory and accelerators from compute nodes and makes them remotely accessible. This improves resource sharing, but also removes the local kernel from the resource-access path. Under an untrusted host, compromised host software may use stale authority, exceed delegated authority, or reuse authority provisioned for...
Arxiv pdf
arXiv:2609.31087v1 Announce Type: new Abstract: Cryptographic hash functions over integers modulo a prime play a decisive role in the efficiency and security of proof systems for computational integrity. Early designs focused on compact arithmetic circuits and efficient software execution, primarily targeting general-purpose CPUs rather than hardware accelerators. This work focuses on enabling...
Arxiv pdf
arXiv:2609.31039v1 Announce Type: new Abstract: The rise of autonomous AI agents equipped with tools has introduced significant security risks, ranging from unintended tool misuse to adversarial manipulation through Indirect Prompt Injection (IPI) attacks. In practice, deployed agent systems such as OpenAI Codex and Claude Code protect tool invocations through a combination of coarse-grained...
Arxiv pdf
arXiv:2609.31012v1 Announce Type: new Abstract: Existing approaches for understanding the detection logic of real-world antivirus (AV) software infer only binary malware/benign decisions from black-box queries, providing limited insight into the fine-grained decision-critical regions that govern AV detection. In this paper, we present \textbf{AVHunter}, the first framework for inferring...
Arxiv pdf
arXiv:2609.31004v1 Announce Type: new Abstract: Attackers can compromise multiple systems with a single vulnerability, while defenders need to fix all security weaknesses in their systems. This asymmetry puts defenders at a disadvantage. Security vulnerabilities are found at an alarming rate, and patching vulnerabilities is costly and time-consuming; thus, vulnerability prioritization is a must...
Arxiv pdf
arXiv:2609.30997v1 Announce Type: new Abstract: Passive image provenance asks whether pixels alone can reveal where an image came from: a human, an aggregate AI class, or a particular generator. This becomes a robustness problem once a source image can be edited before the verifier sees it. We study the problem as source--target verification under adversarial distribution shift. Our first result...
Arxiv pdf
arXiv:2609.30980v1 Announce Type: new Abstract: Text-to-image diffusion models enable data-efficient "mimicry" attacks, wherein adversaries fine-tune the model on a handful of public photos to synthesize convincing forgeries of a target individual. A common countermeasure is to embed imperceptible, low-energy watermarks, yet recent studies show these signatures are brittle: modest...
Trending Tags Recently Added
Loading…
LINK COPIED TO CLIPBOARD