Security papers — 2026-09-21
Today we focus on finding ransomware before it locks everything down because this is where the most immediate danger lies. We are building DEFEAT, a framework designed to catch ransomware that hides its file operations across many temporary files. This defeats older methods that only look at single files in isolation.
This new approach groups causally related file events into File Event Gadgets or FEGs. These are like semantically coherent units capturing the full intent behind a sequence of operations spanning different files. This grouping is powerful because it allows us to use a graph neural network to cluster entire behavioral patterns. This means we can label whole clusters instead of just individual samples, cutting down the work needed for manual labeling by ninety-four percent.
This system has shown remarkable results, achieving ninety-nine point two percent detection accuracy across a massive set of file I/O events spanning sixty-seven ransomware families. This method is much more efficient than other techniques because it can assign a cluster label as soon as the first file operation finishes. This means we can detect the threat at the very moment the first file gets encrypted.
This contextual grouping builds on earlier work that focused on system-wide provenance graphs. DEFEAT scopes this analysis specifically to a single user asset's file operations, making it lightweight enough for targeted analysis without needing to monitor the entire system.
The most critical work involves developing a whole-system defense against product abuse in the SaaS industry. Sophisticated threat actors are increasingly using living-off-the-land attacks to bypass traditional malware detection. This research showed that by collecting data from multiple databases and designing for real-world constraints like cost and user behavior, they could increase product abuse coverage by thirty five percent and reduce monthly alerts by thirty percent. This success means we have a better way to catch subtle misuse of security platforms in the wild, which is a big step forward.
Another important area is ensuring privacy when running large language models. Current homomorphic encryption methods are vulnerable to jailbreak attacks where malicious clients can probe the system over encrypted data. The HE-Guardrail framework addresses this by evaluating guardrails entirely over encrypted data. It shows that it closely mimics the decisions of plaintext guardrails while managing security and efficiency trade-offs. This work is vital for deploying LLMs in sensitive environments where prompt inspection must remain confidential.
Furthermore, protecting the intellectual property of large language models requires robust methods like SRAF to verify ownership against model theft. SRAF uses a joint optimization strategy across model variants and chat templates to create a stealthy fingerprint that anchors onto the model's intrinsic comprehension features. This makes it highly robust against fine-tuning and pruning. This provides a resilient black-box solution for verifying LLM provenance.
On the hardware side, lightweight cryptography is emerging as a necessary solution for securing resource-constrained IoT systems. This focuses on design principles specific to these environments rather than just performance metrics. This study examines symmetric lightweight ciphers to highlight the security challenges inherent in real-time applications where resources are limited.
Finally, there is work on improving LLM inference efficiency and provenance through speculative sampling combined with watermarking. This novel algorithm uses Poisson processes to create a multi-draft sampling scheme that allows for an unbiased watermark without degrading the quality of the speculative acceptance. This offers a new frontier in balancing these two goals.
The most critical contribution here is X-SPUR because it tackles the problem of detecting intrusions in automotive Ethernet networks where labeled attack data is scarce. This matters because current unsupervised methods rely on manually engineered traffic features, which are brittle when dealing with the diverse protocols present in modern vehicles.
X-SPUR introduces a framework that treats raw packet fields as token sequences and uses causal language modeling to learn what normal traffic looks like. It then detects anomalies by measuring the surprisal from per-token cross-entropy, which essentially tells us how surprising a specific piece of data is given the learned benign patterns. This approach eliminates the need for handcrafted feature engineering entirely.
To make this detection more robust across different protocols, they incorporated a bimodal fusion architecture that mixes payload token embeddings with inter-packet timing information using both additive fusion and a Hadamard interaction. Furthermore, they added a dual top k percent per-protocol Z-score calibration to handle the varying score distributions across different protocol families. This method allows X-SPUR to achieve an AUC of 0.9987 on the TOW-IDS dataset, which is slightly better than the 0.9969 achieved by AERO. It also proves that this architecture performs well on a second automotive Ethernet dataset when trained as a separate CarDS model. This fine-grained surprisal score offers explainability by pointing directly to specific protocol fields responsible for the anomaly score.
The CIPL framework is crucial because it offers a way to compare how different internal parts of an LLM agent leak sensitive information versus what an outside attacker can actually see. This helps us move beyond just looking at storage labels, which we found are not sufficient for determining recoverability.
We saw that memory targets provide a near-saturated reference case, meaning they show the most leakage possible. Retrieval-mediated leakage is often only partial. Tool-mediated and live agent leakage showed a strong dependence on things like observation surface and prompt alignment. Furthermore, a stratified semantic audit revealed disclosures that canonical exact matching missed, which suggests we need broader ways to look for attacker-useful information.
In terms of benchmarking practical application, APort Vault tests payment authorization in tool-using agents by replaying thousands of human attacks against various models and configurations. We observed that the authorization boundary is where things diverge; for instance, at Level 2 to 4, transfers were permitted behind the layer in some cases even when the passport did not permit them. This means policy denials do not always prevent successful actions under certain conditions.
This contrasts with work on signature schemes, such as MIRANDA, which presents a new family of full-domain-hash signatures based on matrix codes that offer strong security guarantees with relatively small signature sizes. This scheme uses a simple trapdoor involving decoding tasks to ensure that the signatures do not leak information about the underlying trapdoor through simple bit drawing.
The challenge in applying these concepts is bridging the gap between identifying specific GenAI privacy threats and selecting appropriate mitigations for them. Current knowledge of threats and solutions develops independently. This suggests that future research must focus on creating a systematic approach to selecting defenses based on GenAI-specific characteristics.
The most pressing issue right now is figuring out how to build robust defenses against jailbreak attacks on large language models because the current approach of testing defenses in isolation doesn't give us a clear picture of what actually works when you layer them together. We found that no single defense is universally superior, but carefully combining different methods across various stages of the model pipeline leads to substantial safety gains without hurting performance much.
This layered defense idea connects to how we think about risk management in general. Just as combining different security measures against an LLM attack yields better results, quantifying cyber risk involves aggregating information from many sources. The Loss Event Frequency Security Analyser framework suggests that by combining machine-level predictions with infrastructure-level aggregation, we can get a much more accurate picture of future cyber loss events than looking at any single metric alone.
Furthermore, the work on extracting model parameters shows that even when an adversary only sees the final label, new algorithms allow for efficient sign recovery without needing many extra queries. This efficiency is important because it means we can test these extraction methods in a black-box setting more practically. This is a necessary step before we can fully integrate these findings into larger defense pipelines.
Today's papers
- DEFEAT Stitching Fragmented File I/O Contexts for Early Ransomware Detection This framework groups related file operations into units that capture the full intent behind sequences of file operations spanning multiple dynamically created files. [paper]
- StableAML Machine Learning for Behavioral Wallet Detection in Stablecoin Anti-Money Laundering This study uses domain-informed tree ensemble models to detect suspicious stablecoin wallets by differentiating cybercrime syndicates from sanctioned entities.
- Conformal Privacy Auditing Calibrated Re-identification Attacks with Statistical Guarantees This framework provides a statistical certificate of re-identification risk for released documents against LLM attackers. [paper]
- SteganoBackdoor Evading Data-Poisoning Defenses via Steganographic Backdoors This framework transforms semantic trigger seeds to encode payloads across ordinary tokens, making them harder to detect by data poisoning defenses. [paper]
- CESBench Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices This benchmark tests LLMs on cryptographic engineering security for IoT devices across multiple task types. [paper]
- SFPF Spatio-Frequency Polarization Fingerprint for Anomalous Wireless Device Detection This method uses joint spatio-frequency polarization to improve detection of anomalous wireless devices compared to conventional radio-frequency fingerprinting. [paper]
- The Supersingular Isogeny Problem in Time and Memory p 1/3+o(1), Unconditionally This paper presents a Las Vegas algorithm that solves the supersingular isogeny problem with an expected time and memory complexity of p 1/3. [paper]
- TERMon Detecting Persistent Behavioral Threats in Edge AI via Hardware-Native Ternary Runtime Monitor This hardware monitor detects harmful weight corruptions in edge AI accelerators by matching inference behavior against hardware-efficient ternary patterns. [paper]
- Identifying Security Platform Product Abuse with Machine Learning This study shows how collecting multiple data modalities can increase coverage and reduce alerts for product abuse of security platforms. [paper]
- HE-Guardrail A Homomorphic Guardrail Against Jailbreak Attacks for Encrypted Large Language Model Inference This framework evaluates guardrail mechanisms entirely over encrypted data to prevent jailbreak attacks against LLMs. [paper]
- Foundations and Design Principles of Lightweight Cryptography for IoT Systems This study examines the design principles and security challenges of symmetric lightweight ciphers commonly used in resource-constrained IoT systems. [paper]
- SRAF Stealthy and Robust Adversarial Fingerprint for Copyright Verification of Large Language Models This framework proposes a robust fingerprinting method that anchors on intrinsic model features to verify LLM ownership against fine-tuning. [paper]
- Batched Paillier-Based Hamming-Distance Computation over Binary Embeddings This work describes an efficient client implementation for performing batched Hamming distance decodes over encrypted binary embeddings using Paillier encryption. [paper]
- Watermarkable Multi-Draft Speculative Sampling via Poisson Processes This algorithm develops a speculative sampling scheme that allows for both sampling efficiency and unbiased watermarking simultaneously. [paper]
- ServeGuard Verifiable, Bounded-Residual Confinement of Operator-Invisible Channels Without Revealing the Certified Read Factor This framework provides a supply chain primitive that proves an adapter carries no hidden channels relative to a declared monitor. [paper]
- TrustBOM A Scalable Architecture for Confidentiality-Preserving SBOMs Across Organizations This architecture enables software providers to attest to the absence of specific vulnerabilities in their software bills of materials without revealing dependency graphs. [paper]
- X-SPUR Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection This framework uses surprisal and causal language modeling to detect anomalies in automotive Ethernet traffic while providing per-token explainability. [paper]
- Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment Definition, Proof, and Embedded Device Cost This paper defines a method to make hybrid key establishment protocols resilient against downgrade attacks by binding the session key to the handshake transcript. [paper]
- Toss If Perishable An Ethnographic Study on Building Scenario-Based Training for Non-Perishable Skills This study explores how scenario-based training can impart non-perishable investigative reasoning skills to security operations center analysts. [paper]
- (Don't) Trust, but (Don't) Verify: Developers' Attention to Security in AI-Generated Code This paper evaluates how developers evaluate AI-generated code for security and the cues they use to make trust decisions. [paper]
- TPM-Attest Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux This framework uses TPM and IMA to cryptographically prove a clean boot state, acting as an anti-cheat alternative for Linux gaming. [paper]
- Loopjacking Hijacking Human-in-the-Loop Approval This work reproduces attacks where human approval is used to authorize different operations than those intended by the user. [paper]
- Origin Is All You Need Provenance-Aware Transformers for Structural Trust-Boundary Separation This architecture augments LLMs with origin embeddings to enforce a structural boundary between authoritative and non-authoritative sources during generation. [paper]
- NetInspector Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation This framework introduces an agentic system that grounds LLM policy generation in verifiable network facts to reduce false negatives. [paper]
- CIPL A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents This framework provides a channel-aware evaluation method to distinguish between internal and external recovery of sensitive information from LLM agents. [paper]
- APort Vault Benchmarking AI Agent Payment Authorization with the Open Agent Passport This benchmark evaluates the authorization capabilities of tool-using AI agents against various payment attacks. [paper]
- MIRANDA short signatures from a leakage-free full-domain-hash scheme This paper presents a new family of full-domain hash signatures based on matrix codes that offers strong security guarantees with small signature sizes. [paper]
- The Right Tool for the Job On the Selection of Mitigations for GenAI Privacy Threats This paper argues that the main challenge in GenAI privacy engineering is bridging the gap between threats and mitigation techniques. [paper]
- Securing Large Language Models: Addressing Bias, Misinformation, and Prompt Attacks This review analyzes recent literature on LLM security concerning accuracy, bias, content detection, and vulnerability to attacks. [paper]
- Chameleon Recovering Cyber-Physical Systems from Memory Corruption Attacks via ML Surrogates This framework uses machine learning surrogates to automatically recover compromised cyber-physical systems from memory corruption attacks. [paper]
- Micro-Collaborative Poisoning A Distributed Attack on RAG Systems This paper introduces an attack where false claims are spread across multiple retrieved documents in a retrieval-augmented generation system. [paper]
- Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel This study reveals a vulnerability allowing non-root access to an IMU to infer keystrokes, desk surface, and user behavior on MacBooks. [paper]
- CASCADE Against Jailbreaks Combination Across Stages with Controlled Attack-Defense Evaluation This paper systematically evaluates different combinations of defense stages against LLM jailbreak attacks to find optimal layered defenses. [paper]
- A Framework to Quantify the Probability of Future Cyber Loss Events This framework introduces a probabilistic model that estimates future cyber loss events by aggregating machine-level predictions across infrastructure layers. [paper]
- End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery This paper proposes a new sign recovery algorithm that enables efficient end-to-end extraction of hard labels from trained deep ReLU MLPs. [paper]
- Verifiable Computation with Trusted Execution Environments and On-Chain Digital Rights Tokens This architecture allows data owners to issue computational rights to third parties to process private data inside trusted execution environments. [paper]
- Critical sets of Latin squares based on autoparatopisms This paper explores critical sets in cryptography by using the orbits of entries described by the autoparatopism group of Latin squares. [paper]
- Combining Exploratory Analysis and Automated Analysis for Anomaly Detection in Real-Time Data Streams This article examines how combining exploratory visualization and automated analysis can improve real-time anomaly detection in BGP traffic. [paper]
- Provisional Reachability Containing Agents by Making Every Crossing Revocable This scheme proposes a way to make agent crossings revocable by holding them in escrow and auditing them periodically to ensure secrets remain unreachable. [paper]
The papers
- Securing Large Language Models: Addressing Bias, Misinformation, and Prompt Attacks —
- SRAF: Stealthy and Robust Adversarial Fingerprint for Copyright Verification of Large Language Models —
- MIRANDA: short signatures from a leakage-free full-domain-hash scheme —
- SteganoBackdoor: Evading Data-Poisoning Defenses via Steganographic Backdoors —
- Foundations and Design Principles of Lightweight Cryptography for IoT Systems —
- StableAML: Machine Learning for Behavioral Wallet Detection in Stablecoin Anti-Money Laundering on Ethereum —
- Chameleon: Recovering Cyber-Physical Systems from Memory Corruption Attacks via ML Surrogates —
- The Right Tool for the Job: On the Selection of Mitigations for GenAI Privacy Threats —
- TPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux —
- (Don't) Trust, but (Don't) Verify: Developers' Attention to Security in AI-Generated Code —
- Loopjacking: Hijacking Human-in-the-Loop Approval —
- Origin Is All You Need: Provenance-Aware Transformers for Structural Trust-Boundary Separation —
- NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation —
- Toss If Perishable: An Ethnographic Study on Building Scenario-Based Training for Non-Perishable Skills —
- X-SPUR: Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection —
- Combining Exploratory Analysis and Automated Analysis for Anomaly Detection in Real-Time Data Streams —
- Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost —
- Identifying Security Platform Product Abuse with Machine Learning —
- Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees —
- CESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices —
- Batched Paillier-Based Hamming-Distance Computation over Binary Embeddings —
- TrustBOM: A Scalable Architecture for Confidentiality-Preserving SBOMs Across Organizations —
- DEFEAT: Stitching Fragmented File I/O Contexts for Early Ransomware Detection —
- HE-Guardrail: A Homomorphic Guardrail Against Jailbreak Attacks for Encrypted Large Language Model Inference —
- ServeGuard: Verifiable, Bounded-Residual Confinement of Operator-Invisible Channels Without Revealing the Certified Read Factor —
- Critical sets of Latin squares based on autoparatopisms —
- Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel —
- Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems —
- CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents —
- TERMon: Detecting Persistent Behavioral Threats in Edge AI via Hardware-Native Ternary Runtime Monitor —
- A Framework to Quantify the Probability of Future Cyber Loss Events —
- Verifiable Computation with Trusted Execution Environments and On-Chain Digital Rights Tokens —
- CASCADE Against Jailbreaks: Combination Across Stages with Controlled Attack-Defense Evaluation —
- Watermarkable Multi-Draft Speculative Sampling via Poisson Processes —
- SFPF: Spatio-Frequency Polarization Fingerprint for Anomalous Wireless Device Detection —
- End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery —
- Provisional Reachability: Containing Agents by Making Every Crossing Revocable —
- The Supersingular Isogeny Problem in Time and Memory p 1/3+o(1), Unconditionally —
- APort Vault: Benchmarking AI Agent Payment Authorization with the Open Agent Passport —
Important terms
- File Event Gadgets (FEGs)
- These are semantic units that group causally related file operations across different files. They capture the full intent behind a sequence of actions, allowing for behavioral pattern clustering using graph neural networks.
- Living-off-the-Land Attacks
- Sophisticated threat actors use these to bypass traditional malware detection by leveraging legitimate system tools and processes already present on a target system.
- HE-Guardrail framework
- This framework evaluates guardrails entirely over encrypted data, addressing jailbreak vulnerabilities in homomorphic encryption methods by closely mimicking plaintext decisions.
- X-SPUR
- A framework for detecting intrusions in automotive Ethernet networks that uses causal language modeling and surprisal to learn normal traffic patterns without needing handcrafted features.