Security papers — 2026-09-21

Today we focus on finding ransomware before it locks everything down because this is where the most immediate danger lies. We are building DEFEAT, a framework designed to catch ransomware that hides its file operations across many temporary files. This defeats older methods that only look at single files in isolation.

This new approach groups causally related file events into File Event Gadgets or FEGs. These are like semantically coherent units capturing the full intent behind a sequence of operations spanning different files. This grouping is powerful because it allows us to use a graph neural network to cluster entire behavioral patterns. This means we can label whole clusters instead of just individual samples, cutting down the work needed for manual labeling by ninety-four percent.

This system has shown remarkable results, achieving ninety-nine point two percent detection accuracy across a massive set of file I/O events spanning sixty-seven ransomware families. This method is much more efficient than other techniques because it can assign a cluster label as soon as the first file operation finishes. This means we can detect the threat at the very moment the first file gets encrypted.

This contextual grouping builds on earlier work that focused on system-wide provenance graphs. DEFEAT scopes this analysis specifically to a single user asset's file operations, making it lightweight enough for targeted analysis without needing to monitor the entire system.

The most critical work involves developing a whole-system defense against product abuse in the SaaS industry. Sophisticated threat actors are increasingly using living-off-the-land attacks to bypass traditional malware detection. This research showed that by collecting data from multiple databases and designing for real-world constraints like cost and user behavior, they could increase product abuse coverage by thirty five percent and reduce monthly alerts by thirty percent. This success means we have a better way to catch subtle misuse of security platforms in the wild, which is a big step forward.

Another important area is ensuring privacy when running large language models. Current homomorphic encryption methods are vulnerable to jailbreak attacks where malicious clients can probe the system over encrypted data. The HE-Guardrail framework addresses this by evaluating guardrails entirely over encrypted data. It shows that it closely mimics the decisions of plaintext guardrails while managing security and efficiency trade-offs. This work is vital for deploying LLMs in sensitive environments where prompt inspection must remain confidential.

Furthermore, protecting the intellectual property of large language models requires robust methods like SRAF to verify ownership against model theft. SRAF uses a joint optimization strategy across model variants and chat templates to create a stealthy fingerprint that anchors onto the model's intrinsic comprehension features. This makes it highly robust against fine-tuning and pruning. This provides a resilient black-box solution for verifying LLM provenance.

On the hardware side, lightweight cryptography is emerging as a necessary solution for securing resource-constrained IoT systems. This focuses on design principles specific to these environments rather than just performance metrics. This study examines symmetric lightweight ciphers to highlight the security challenges inherent in real-time applications where resources are limited.

Finally, there is work on improving LLM inference efficiency and provenance through speculative sampling combined with watermarking. This novel algorithm uses Poisson processes to create a multi-draft sampling scheme that allows for an unbiased watermark without degrading the quality of the speculative acceptance. This offers a new frontier in balancing these two goals.

The most critical contribution here is X-SPUR because it tackles the problem of detecting intrusions in automotive Ethernet networks where labeled attack data is scarce. This matters because current unsupervised methods rely on manually engineered traffic features, which are brittle when dealing with the diverse protocols present in modern vehicles.

X-SPUR introduces a framework that treats raw packet fields as token sequences and uses causal language modeling to learn what normal traffic looks like. It then detects anomalies by measuring the surprisal from per-token cross-entropy, which essentially tells us how surprising a specific piece of data is given the learned benign patterns. This approach eliminates the need for handcrafted feature engineering entirely.

To make this detection more robust across different protocols, they incorporated a bimodal fusion architecture that mixes payload token embeddings with inter-packet timing information using both additive fusion and a Hadamard interaction. Furthermore, they added a dual top k percent per-protocol Z-score calibration to handle the varying score distributions across different protocol families. This method allows X-SPUR to achieve an AUC of 0.9987 on the TOW-IDS dataset, which is slightly better than the 0.9969 achieved by AERO. It also proves that this architecture performs well on a second automotive Ethernet dataset when trained as a separate CarDS model. This fine-grained surprisal score offers explainability by pointing directly to specific protocol fields responsible for the anomaly score.

The CIPL framework is crucial because it offers a way to compare how different internal parts of an LLM agent leak sensitive information versus what an outside attacker can actually see. This helps us move beyond just looking at storage labels, which we found are not sufficient for determining recoverability.

We saw that memory targets provide a near-saturated reference case, meaning they show the most leakage possible. Retrieval-mediated leakage is often only partial. Tool-mediated and live agent leakage showed a strong dependence on things like observation surface and prompt alignment. Furthermore, a stratified semantic audit revealed disclosures that canonical exact matching missed, which suggests we need broader ways to look for attacker-useful information.

In terms of benchmarking practical application, APort Vault tests payment authorization in tool-using agents by replaying thousands of human attacks against various models and configurations. We observed that the authorization boundary is where things diverge; for instance, at Level 2 to 4, transfers were permitted behind the layer in some cases even when the passport did not permit them. This means policy denials do not always prevent successful actions under certain conditions.

This contrasts with work on signature schemes, such as MIRANDA, which presents a new family of full-domain-hash signatures based on matrix codes that offer strong security guarantees with relatively small signature sizes. This scheme uses a simple trapdoor involving decoding tasks to ensure that the signatures do not leak information about the underlying trapdoor through simple bit drawing.

The challenge in applying these concepts is bridging the gap between identifying specific GenAI privacy threats and selecting appropriate mitigations for them. Current knowledge of threats and solutions develops independently. This suggests that future research must focus on creating a systematic approach to selecting defenses based on GenAI-specific characteristics.

The most pressing issue right now is figuring out how to build robust defenses against jailbreak attacks on large language models because the current approach of testing defenses in isolation doesn't give us a clear picture of what actually works when you layer them together. We found that no single defense is universally superior, but carefully combining different methods across various stages of the model pipeline leads to substantial safety gains without hurting performance much.

This layered defense idea connects to how we think about risk management in general. Just as combining different security measures against an LLM attack yields better results, quantifying cyber risk involves aggregating information from many sources. The Loss Event Frequency Security Analyser framework suggests that by combining machine-level predictions with infrastructure-level aggregation, we can get a much more accurate picture of future cyber loss events than looking at any single metric alone.

Furthermore, the work on extracting model parameters shows that even when an adversary only sees the final label, new algorithms allow for efficient sign recovery without needing many extra queries. This efficiency is important because it means we can test these extraction methods in a black-box setting more practically. This is a necessary step before we can fully integrate these findings into larger defense pipelines.

Today's papers

The papers

Important terms

File Event Gadgets (FEGs)
These are semantic units that group causally related file operations across different files. They capture the full intent behind a sequence of actions, allowing for behavioral pattern clustering using graph neural networks.
Living-off-the-Land Attacks
Sophisticated threat actors use these to bypass traditional malware detection by leveraging legitimate system tools and processes already present on a target system.
HE-Guardrail framework
This framework evaluates guardrails entirely over encrypted data, addressing jailbreak vulnerabilities in homomorphic encryption methods by closely mimicking plaintext decisions.
X-SPUR
A framework for detecting intrusions in automotive Ethernet networks that uses causal language modeling and surprisal to learn normal traffic patterns without needing handcrafted features.