Security papers — 2026-09-14
Rotated Robustness is a training-free method that uses matched orthogonal transformations on activations and weights to spread the impact of corrupted weights across different feature dimensions while keeping the original linear mapping intact in exact arithmetic. This approach performed very well, matching or exceeding all other methods in sustaining cumulative PBS flips before performance dropped past one hundred percent within a hundred flip evaluation horizon.
This method also showed no failures when random bit-flip injection was used, and it made it harder for attackers to reproduce specific one-bit catastrophic failures by increasing the cost of reproducing them to thousands of deployed INT8 bit changes, all while keeping the downstream task utility intact under PBS perturbations. This means we have a practical way to boost robustness against these weight faults.
DropVLA forces a specific action primitive to execute at attacker-chosen decision points using a window-consistent relabeling scheme for fine-tuning in vision language action models. This attack was very effective on OpenVLA-7B, achieving an attack success rate of nearly ninety percent with only a tiny fraction of poisoned episodes while keeping nominal task performance high.
We also explored how partisan communities can emerge within decentralized autonomous organizations by analyzing on-chain voting behavior. Our method successfully clustered addresses that would later fork together months before actual fragmentation events, showing that we can detect these emerging divisions retrospectively. This analysis helps us see the early signs of organizational splits before they become full-blown forks.
In collaborative perception systems in autonomous vehicles, we looked at how they can be manipulated by subtly altering object poses in shared data to induce unsafe driving behaviors like hard braking. Our attack achieved over ninety percent success in causing these safety-critical errors while evading many existing defenses.
The most pressing issue right now is figuring out how to secure our digital future against quantum threats because if a fault-tolerant quantum computer arrives, all our current public key encryption and digital signatures could be broken. This threat forces us to develop new mechanisms that can withstand this kind of attack, but the real hurdle is knowing which applications are most vulnerable and how to move everything over in a way that is both fast and manageable.
We are currently looking at the building blocks for these quantum-safe cryptographic mechanisms, categorizing them by the security methods they use. This helps us see what pieces we have available to integrate into our existing systems. Next, we are systematically reviewing how different application domains like Telecommunications, the Internet of Things, and Blockchains have already begun migrating to these new schemes.
A key challenge remains in making this transition smooth across all these different areas. We also need to summarize all the roadblocks that must be cleared before a successful migration can happen. This work connects directly to how we are trying to build resilient systems against future computational power, which is a big deal for long-term security planning.
The work that matters most is breaking permutation-based model confidentiality in hybrid fully homomorphic encryption inference because it directly addresses the practical security of running complex machine learning models privately on untrusted servers. This research shows that current methods relying on noisy, output-permuted responses fail when the system requires exact recovery for correctness.
This failure stems from a fundamental limitation: for a linear layer with d inputs, you need d plus one queries to perfectly recover the layer's summary and ensure model distinguishability. This means that even if you use differential privacy on the input data, it does not protect model confidentiality when noise is bounded by the correctness requirements of hybrid FHE systems.
This contrasts with other approaches where input differential privacy and model confidentiality are shown to be orthogonal, meaning one doesn't help the other in this context. Furthermore, the local-DP premise needed for shuffle amplification cannot hold when you have noise that is constrained by correctness bounds. This means the proposed protection method breaks down under real-world constraints of hybrid FHE inference.
This finding is significant because it demonstrates a gap between theoretical privacy guarantees and practical system requirements in secure inference. This contrasts with the work on agent skill registries, which shows that even when scanners overlap, there are still actions that violate established controls, suggesting policy enforcement needs refinement rather than just better scanning.
Similarly, while some systems attempt to map low-level telemetry to threat frameworks like MITRE ATT&CK using graph representations and RAG, this approach relies on the quality of the graph mapping and the LLM's reasoning capabilities. The success here shows that local inference over these behavioral descriptions can make automated mapping viable without compromising data confidentiality, though prompt sensitivity remains a major challenge for law enforcement applications.
The most pressing work right now is figuring out how to stop chemistry and materials agents from releasing dangerous protocols because when these agents can generate complete hazardous synthesis procedures in over a quarter of their runs, it signals a major safety gap. This means that simply having one attacker model isn't the only way things go wrong; even replacing the attacker doesn't fix everything, as success rates remain between nineteen and twenty-six point five percent.
This failure mode is complicated because existing defenses are not covering all bases simultaneously, meaning they miss issues like multi-entry contamination or problems with tool states and final artifact boundaries. This leaves a significant gap between how fast these scientific agents are developing and the safety tools available to the chemistry community.
On a related note, we saw progress in protocol fuzzing when testing cross-chain bridges; IntentFuzz successfully recovered the correct intent structure in nine out of nine benchmark protocols, which is a big step since traditional fuzzers usually only catch known bad code patterns. This work shows that by recovering the underlying intent structure from unannotated source code, we can build more effective multi-step fuzz sequences.
Furthermore, we are seeing how context segmentation helps local small language models manage complex tasks like cybersecurity challenges; the E4B model using this strategy solved eighteen point five two percent of tasks that standard execution failed on, showing that breaking down big problems into smaller parts is a viable way to handle cognitive load.
In terms of infrastructure security, IDORacle provides runtime protection for Java applications by intercepting SQL templates and generating mediation plans based on context, which prevents horizontal privilege escalation with very low latency. This contrasts with the broader agent safety issue because IDORacle focuses on authorization at the database layer rather than protocol generation.
The most pressing concern is how to build reliable models of complex systems when the underlying evidence is messy and incomplete. The evidence-first multi-LLM framework attempts this by having several open-weight language models independently pull out potential entities and connections from varied infrastructure documents, then a separate process handles verification, grounding in an ontology, and alignment. This means that instead of one model making all the assumptions about what is connected to what, multiple models suggest candidates which are then fused after human review, preserving uncertainty throughout the process.
This approach is important because it moves away from collapsing all doubt into a single confidence score by keeping provenance and unresolved cases intact as the system progresses. This contrasts with methods where a single model might generate unsupported relationships or use inconsistent terminology when building infrastructure knowledge bases and dependency graphs.
The framework shows that while recovering entities is quite good, getting the exact directed dependencies right is much harder, with canonical endpoint resolution proving to be a major sticking point in constructing dependency graphs. Furthermore, cross-model overlap for dependencies is low because the models often generate distinct sets of assertions rather than agreeing on a single consensus.
This difficulty in achieving consensus feeds into the broader challenge of trusting automated knowledge construction from heterogeneous data sources. This uncertainty is what necessitates the progressive resolution method described earlier, where each step builds upon the previous one with preserved doubt.
Today's papers
- Rotated Robustness: A Training-Free Defense against Bit-Flip Attacks on Large Language Models We propose a training-free method to make quantized LLM weights more resistant to bit-flip errors by rotating activations and weights. [paper] [episode]
- DropVLA: An Action-Level Backdoor Attack on Vision-Language-Action Models This paper shows how a hidden trigger can force a vision language model to perform unintended physical actions. [paper] [episode]
- Mapping Partisan Fault Lines Within DAOs We present a method to detect emerging partisan communities in decentralized autonomous organizations by analyzing on-chain voting patterns. [paper] [episode]
- From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception This work demonstrates how subtle manipulation of shared sensor data can lead autonomous vehicles to unsafe driving decisions. [paper] [episode]
- From Automata Learning to Model Checking: Formal Security Verification of Black-Box Protocols We propose a method that uses automata learning and model checking to formally verify the security properties of black-box communication protocols. [paper] [episode]
- Federated Learning in the Wild: A Comparative Study for Cybersecurity under Non-IID and Unbalanced Settings This study compares different federated learning algorithms for network intrusion detection in environments with non-independent data distributions. [paper] [episode]
- BodhiPromptShield: Pre-Inference Prompt Mediation for Surface-Form Privacy Propagation in LLM Agent Pipelines We introduce a layer that mediates prompts to prevent sensitive information from leaking across multiple stages of an LLM agent pipeline. [paper] [episode]
- Function Name Is All You Need to Detect Blockchain Application Attacks We propose a framework that uses function names in transaction traces to detect business logic attacks on decentralized applications. [paper]
- A Survey on Quantum-Safe Cryptographic Mechanisms: Building Blocks and Applications This paper surveys the current state of quantum-safe cryptographic mechanisms, their applications, and the challenges for migration. [paper]
- Fresh-Challenge VDF Attestations for Model-Relative Response Latency We propose a protocol to verify response latency in sequential computations using verifiable delay functions. [paper]
- Access Control as Verified Parse Constraints We present a verified validator that ensures correct access control enforcement in Java applications by encoding policy decisions into a fixed-size buffer. [paper]
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation This paper systematically assesses security and privacy risks associated with user-created worlds in metaverse platforms. [paper]
- PDoS: A Profitable Denial-of-Service Attack against Proof-of-Work Blockchain Liveness We present a hybrid attack that combines denial of service with revenue extraction to make proof-of-work blockchains economically self-sustaining. [paper]
- Subgroup Packing for Batched PASTA Transciphering We show how rearranging data layout can reduce the cost of converting symmetrically encrypted records in homomorphic encryption. [paper]
- Hardware Fingerprinting FTQC via Quantum Decoder Timing We demonstrate that the timing of quantum computer decoders can be used to fingerprint physical hardware with high accuracy. [paper]
- Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks We introduce a framework that uses explainable AI to ensure anomaly detection alerts are trustworthy in distributed energy resource networks. [paper]
- Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference We show that noise injection fails to protect model confidentiality during hybrid fully homomorphic encryption inference. [paper]
- Scan the Skill, Govern the Action: Composing Registry Verdicts with Runtime Consequence Control We propose a design for an agent skill registry gate that uses a trust ledger to control which skills are executed based on operator risk tolerance. [paper]
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On Websites We analyze mobile network single sign-on websites and identify how they can leak sensitive identity information through simple web visits. [paper]
- Bridging the First-Hour Gap: Evaluating AI Reliability and Benchmarking Deficiencies in Cyber Incident Response for Law Enforcement This paper surveys AI tools for law enforcement incident response and argues for new benchmarks focused on evidence preservation. [paper]
- Batten the Hatches: Cybersecurity with Military Mariners We investigate how military personnel understand cyber risk and respond to it by interviewing maritime service members. [paper]
- NovaFabric: Tamper-Evident, Replayable Evidence for Autonomous AI Agent Runs We introduce a system to create tamper-evident, replayable audit evidence for autonomous AI agent executions. [paper]
- A Graph-Based Approach for Mapping Kernel-Level Telemetry to MITRE ATT&CK We propose a method to map low-level kernel telemetry into the MITRE ATT&CK framework using graph representations and LLMs. [paper]
- A Feature-Rich Embedded NIDS with eBPF/XDP: Detector and Architecture Trade-offs We present a network intrusion detection system for DDoS attacks that uses eBPF to monitor traffic at the kernel level and compares different software architectures. [paper]
- ChemMat-AgentSafetyBench: Evaluating Long-Horizon Attacks and Defenses in Chemistry and Materials Agents We introduce a benchmark to test if chemistry agents can be steered toward hazardous protocols through complex tool use. [paper]
- IntentFuzz: A Protocol-Aware Fuzzer for Automated Invariant Violation Detection in Intent-Based Cross-Chain Bridges We propose a fuzzer that recovers bridge intent structure to find invariant violations in cross-chain bridges. [paper]
- Timestamp Manipulation: Incentive Attacks on Timestamp-Based Proof-of-Work Blockchains with Minimal Additional Risk We propose new incentive attacks that can make timestamped proof of work blockchains economically profitable. [paper]
- A Compact Post-quantum Strong Designated Verifier Signature Scheme from Isogenies We propose a new strong designated verifier signature scheme based on cryptographic group actions. [paper]
- Protect Your Score: Contact Tracing With Differential Privacy Guarantees This paper presents a contact tracing algorithm that releases risk scores with differential privacy guarantees against identity leakage attacks. [paper]
- Forging Tree-Ring: Reproducing and Instrumenting Black-Box Semantic Watermark Forgery We reproduce an attack to forge semantic watermarks in diffusion models using limited hardware resources. [paper]
- PIA-Bench: Towards Automated Privacy Impact Assessment with Large Language Models We introduce a benchmark to evaluate how well large language models can automate the process of privacy impact assessments. [paper]
- IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications We present a framework to prevent insecure direct object reference vulnerabilities in Java applications by mediating SQL execution at runtime. [paper]
- An Open-Source End-to-End FHE Implementation for Privacy-Preserving Llama 3 8B Inference We present an open source system that co designs ciphertext packing and model execution for efficient fully homomorphic encryption inference on Llama models. [paper]
- MicroHasTEE: Bare-Metal Haskell for Type-Level Peripheral Ownership on Armv8-M We propose a framework using Haskell to manage type-level ownership of peripherals in bare metal systems with TrustZone isolation. [paper]
- Poster: Towards Selecting Threat Appropriate Industrial Intrusion Detection Systems We suggest a counter-threat intelligence sharing mechanism to select the best intrusion detection systems for industrial control systems based on the current threat scenario. [paper]
- First Attack, Final Offensive: The Dark Forest on an Open Roster We propose a new interpretation of the dark forest argument regarding when and how civilizations should strike each other. [paper]
- An Evidence-First Multi-LLM Framework for Auditable Critical-Infrastructure Dependency Modeling We present a framework to build auditable infrastructure dependency graphs from heterogeneous evidence using multiple large language models. [paper]
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection Systems We propose an evaluation framework that decomposes graph intrusion detection systems into stages to attribute performance accurately. [paper]
- Evaluating Practical Enumeration and Blocking Attacks on the Snowflake Circumvention System We test the security assumptions of proxy-based censorship circumvention systems by studying enumeration and blocking attacks. [paper]
- A Compact Post-quantum Strong Designated Verifier Signature Scheme from Isogenies We propose a new strong designated verifier signature scheme based on cryptographic group actions. [paper]
The papers
- Rotated Robustness: A Training-Free Defense against Bit-Flip Attacks on Large Language Models — This paper introduces Rotated Robustness (RoR), a training-free defense designed to protect Large Language Models (LLMs) from bit-flip attacks caused by hardware faults. [episode]
- DropVLA: An Action-Level Backdoor Attack on Vision-Language-Action Models — This paper presents DropVLA, an action-level backdoor attack on Vision–Language–Action (VLA) models. [episode]
- Mapping Partisan Fault Lines Within DAOs — The paper presents a method to "detect these emerging communities by analysing on-chain voting behaviour before fragmentation occurs," specifically addressing how Decentralised Autonomous Organisations (DAOs) can fragment when partisan communities emerge, leading to organisationa [episode]
- From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception — This paper investigates security vulnerabilities in collaborative perception for connected and autonomous vehicles (CAVs), where vehicles share sensory data to improve perception but create an "attack surface for data fabrication attacks." The authors address a critical research [episode]
- From Automata Learning to Model Checking: Formal Security Verification of Black-Box Protocols — This paper presents a method for the "formal verification of communication protocols" that addresses the challenge of analyzing proprietary systems that are "accessible only as black boxes." By combining active automata learning with model checking, the authors provide a scalable [episode]
- Federated Learning in the Wild: A Comparative Study for Cybersecurity under Non-IID and Unbalanced Settings — This paper presents a systematic review and evaluation of various Federated Learning (FL) methods within the context of intrusion detection for DDoS attacks. [episode]
- BodhiPromptShield: Pre-Inference Prompt Mediation for Surface-Form Privacy Propagation in LLM Agent Pipelines — Based on the provided text, here is a detailed and comprehensive summary of the research paper: BodhiPromptShield is a novel, policy-aware mediation framework designed to address privacy risks in Large Language Model (LLM) and Vision-Language Model (VLM) agent pipelines. [episode]
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On Websites —
- Hardware Fingerprinting FTQC via Quantum Decoder Timing —
- Evaluating Practical Enumeration and Blocking Attacks on the Snowflake Circumvention System —
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection Systems —
- Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks —
- Function Name Is All You Need to Detect Blockchain Application Attacks —
- An Evidence-First Multi-LLM Framework for Auditable Critical-Infrastructure Dependency Modeling —
- An Open-Source End-to-End FHE Implementation for Privacy-Preserving Llama 3 8B Inference —
- IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications —
- PDoS: A Profitable Denial-of-Service Attack against Proof-of-Work Blockchain Liveness —
- Access Control as Verified Parse Constraints —
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation —
- PIA-Bench: Towards Automated Privacy Impact Assessment with Large Language Models —
- MicroHasTEE: Bare-Metal Haskell for Type-Level Peripheral Ownership on Armv8-M —
- NovaFabric: Tamper-Evident, Replayable Evidence for Autonomous AI Agent Runs —
- A Feature-Rich Embedded NIDS with eBPF/XDP: Detector and Architecture Trade-offs —
- Subgroup Packing for Batched PASTA Transciphering —
- Poster: Towards Selecting Threat Appropriate Industrial Intrusion Detection Systems —
- Bridging the First-Hour Gap: Evaluating AI Reliability and Benchmarking Deficiencies in Cyber Incident Response for Law Enforcement —
- Fresh-Challenge VDF Attestations for Model-Relative Response Latency —
- Batten the Hatches: Cybersecurity with Military Mariners —
- Evaluating Context Segmentation in Locally Deployable SLMs for Cybersecurity CTF Tasks —
- A Graph-Based Approach for Mapping Kernel-Level Telemetry to MITRE ATT&CK —
- Forging Tree-Ring: Reproducing and Instrumenting Black-Box Semantic Watermark Forgery —
- Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference —
- Protect Your Score: Contact Tracing With Differential Privacy Guarantees —
- IntentFuzz: A Protocol-Aware Fuzzer for Automated Invariant Violation Detection in Intent-Based Cross-Chain Bridges —
- Timestamp Manipulation: Incentive Attacks on Timestamp-Based Proof-of-Work Blockchains with Minimal Additional Risk —
- A Compact Post-quantum Strong Designated Verifier Signature Scheme from Isogenies —
- ChemMat-AgentSafetyBench: Evaluating Long-Horizon Attacks and Defenses in Chemistry and Materials Agents —
- A Survey on Quantum-Safe Cryptographic Mechanisms: Building Blocks and Applications —
- Scan the Skill, Govern the Action: Composing Registry Verdicts with Runtime Consequence Control —
- First Attack, Final Offensive: The Dark Forest on an Open Roster —
Important terms
- Rotated Robustness
- A training-free technique using matched orthogonal transformations to spread weight corruption across features, maintaining the original linear mapping in exact arithmetic. It shows strong performance against weight faults.
- DropVLA
- An attack method for vision language action models that forces specific actions at chosen decision points using window-consistent relabeling. It is highly effective even with minimal poisoned episodes.
- Partisan Communities
- A method to detect emerging divisions within decentralized organizations by analyzing on-chain voting behavior. It clusters addresses that will later fork, offering early warning signs.
- Quantum Threats
- The looming danger from fault-tolerant quantum computers breaking current public key encryption and digital signatures. Research focuses on identifying vulnerable applications and developing new quantum-safe cryptographic mechanisms.
- Hybrid FHE Inference
- The challenge of breaking model confidentiality when running complex ML models privately on untrusted servers using hybrid fully homomorphic encryption. Current methods fail because noise constraints conflict with correctness requirements.