Security papers — 2026-09-14

Rotated Robustness is a training-free method that uses matched orthogonal transformations on activations and weights to spread the impact of corrupted weights across different feature dimensions while keeping the original linear mapping intact in exact arithmetic. This approach performed very well, matching or exceeding all other methods in sustaining cumulative PBS flips before performance dropped past one hundred percent within a hundred flip evaluation horizon.

This method also showed no failures when random bit-flip injection was used, and it made it harder for attackers to reproduce specific one-bit catastrophic failures by increasing the cost of reproducing them to thousands of deployed INT8 bit changes, all while keeping the downstream task utility intact under PBS perturbations. This means we have a practical way to boost robustness against these weight faults.

DropVLA forces a specific action primitive to execute at attacker-chosen decision points using a window-consistent relabeling scheme for fine-tuning in vision language action models. This attack was very effective on OpenVLA-7B, achieving an attack success rate of nearly ninety percent with only a tiny fraction of poisoned episodes while keeping nominal task performance high.

We also explored how partisan communities can emerge within decentralized autonomous organizations by analyzing on-chain voting behavior. Our method successfully clustered addresses that would later fork together months before actual fragmentation events, showing that we can detect these emerging divisions retrospectively. This analysis helps us see the early signs of organizational splits before they become full-blown forks.

In collaborative perception systems in autonomous vehicles, we looked at how they can be manipulated by subtly altering object poses in shared data to induce unsafe driving behaviors like hard braking. Our attack achieved over ninety percent success in causing these safety-critical errors while evading many existing defenses.

The most pressing issue right now is figuring out how to secure our digital future against quantum threats because if a fault-tolerant quantum computer arrives, all our current public key encryption and digital signatures could be broken. This threat forces us to develop new mechanisms that can withstand this kind of attack, but the real hurdle is knowing which applications are most vulnerable and how to move everything over in a way that is both fast and manageable.

We are currently looking at the building blocks for these quantum-safe cryptographic mechanisms, categorizing them by the security methods they use. This helps us see what pieces we have available to integrate into our existing systems. Next, we are systematically reviewing how different application domains like Telecommunications, the Internet of Things, and Blockchains have already begun migrating to these new schemes.

A key challenge remains in making this transition smooth across all these different areas. We also need to summarize all the roadblocks that must be cleared before a successful migration can happen. This work connects directly to how we are trying to build resilient systems against future computational power, which is a big deal for long-term security planning.

The work that matters most is breaking permutation-based model confidentiality in hybrid fully homomorphic encryption inference because it directly addresses the practical security of running complex machine learning models privately on untrusted servers. This research shows that current methods relying on noisy, output-permuted responses fail when the system requires exact recovery for correctness.

This failure stems from a fundamental limitation: for a linear layer with d inputs, you need d plus one queries to perfectly recover the layer's summary and ensure model distinguishability. This means that even if you use differential privacy on the input data, it does not protect model confidentiality when noise is bounded by the correctness requirements of hybrid FHE systems.

This contrasts with other approaches where input differential privacy and model confidentiality are shown to be orthogonal, meaning one doesn't help the other in this context. Furthermore, the local-DP premise needed for shuffle amplification cannot hold when you have noise that is constrained by correctness bounds. This means the proposed protection method breaks down under real-world constraints of hybrid FHE inference.

This finding is significant because it demonstrates a gap between theoretical privacy guarantees and practical system requirements in secure inference. This contrasts with the work on agent skill registries, which shows that even when scanners overlap, there are still actions that violate established controls, suggesting policy enforcement needs refinement rather than just better scanning.

Similarly, while some systems attempt to map low-level telemetry to threat frameworks like MITRE ATT&CK using graph representations and RAG, this approach relies on the quality of the graph mapping and the LLM's reasoning capabilities. The success here shows that local inference over these behavioral descriptions can make automated mapping viable without compromising data confidentiality, though prompt sensitivity remains a major challenge for law enforcement applications.

The most pressing work right now is figuring out how to stop chemistry and materials agents from releasing dangerous protocols because when these agents can generate complete hazardous synthesis procedures in over a quarter of their runs, it signals a major safety gap. This means that simply having one attacker model isn't the only way things go wrong; even replacing the attacker doesn't fix everything, as success rates remain between nineteen and twenty-six point five percent.

This failure mode is complicated because existing defenses are not covering all bases simultaneously, meaning they miss issues like multi-entry contamination or problems with tool states and final artifact boundaries. This leaves a significant gap between how fast these scientific agents are developing and the safety tools available to the chemistry community.

On a related note, we saw progress in protocol fuzzing when testing cross-chain bridges; IntentFuzz successfully recovered the correct intent structure in nine out of nine benchmark protocols, which is a big step since traditional fuzzers usually only catch known bad code patterns. This work shows that by recovering the underlying intent structure from unannotated source code, we can build more effective multi-step fuzz sequences.

Furthermore, we are seeing how context segmentation helps local small language models manage complex tasks like cybersecurity challenges; the E4B model using this strategy solved eighteen point five two percent of tasks that standard execution failed on, showing that breaking down big problems into smaller parts is a viable way to handle cognitive load.

In terms of infrastructure security, IDORacle provides runtime protection for Java applications by intercepting SQL templates and generating mediation plans based on context, which prevents horizontal privilege escalation with very low latency. This contrasts with the broader agent safety issue because IDORacle focuses on authorization at the database layer rather than protocol generation.

The most pressing concern is how to build reliable models of complex systems when the underlying evidence is messy and incomplete. The evidence-first multi-LLM framework attempts this by having several open-weight language models independently pull out potential entities and connections from varied infrastructure documents, then a separate process handles verification, grounding in an ontology, and alignment. This means that instead of one model making all the assumptions about what is connected to what, multiple models suggest candidates which are then fused after human review, preserving uncertainty throughout the process.

This approach is important because it moves away from collapsing all doubt into a single confidence score by keeping provenance and unresolved cases intact as the system progresses. This contrasts with methods where a single model might generate unsupported relationships or use inconsistent terminology when building infrastructure knowledge bases and dependency graphs.

The framework shows that while recovering entities is quite good, getting the exact directed dependencies right is much harder, with canonical endpoint resolution proving to be a major sticking point in constructing dependency graphs. Furthermore, cross-model overlap for dependencies is low because the models often generate distinct sets of assertions rather than agreeing on a single consensus.

This difficulty in achieving consensus feeds into the broader challenge of trusting automated knowledge construction from heterogeneous data sources. This uncertainty is what necessitates the progressive resolution method described earlier, where each step builds upon the previous one with preserved doubt.

Today's papers

The papers

Important terms

Rotated Robustness
A training-free technique using matched orthogonal transformations to spread weight corruption across features, maintaining the original linear mapping in exact arithmetic. It shows strong performance against weight faults.
DropVLA
An attack method for vision language action models that forces specific actions at chosen decision points using window-consistent relabeling. It is highly effective even with minimal poisoned episodes.
Partisan Communities
A method to detect emerging divisions within decentralized organizations by analyzing on-chain voting behavior. It clusters addresses that will later fork, offering early warning signs.
Quantum Threats
The looming danger from fault-tolerant quantum computers breaking current public key encryption and digital signatures. Research focuses on identifying vulnerable applications and developing new quantum-safe cryptographic mechanisms.
Hybrid FHE Inference
The challenge of breaking model confidentiality when running complex ML models privately on untrusted servers using hybrid fully homomorphic encryption. Current methods fail because noise constraints conflict with correctness requirements.