Security papers — 2026-09-22
This work dives into domain specific post quantum signatures because they are crucial for securing blockchain roles beyond simple single signer authentication. This research argues that blockchains need consensus ready signature profiles that handle things like priced invalid input rejection and stable transaction identifiers, which is different from just using NIST single signer signatures.
We explored many different schemes, including ML-DSA, SLH-DSA, Falcon/FN-DSA, HAWK, MAYO, SNOVA, UOV/QR-UOV, FAEST, SQIsign and others on Bitcoin and Ethereum stress profiles. This research shows that while single signer signatures are necessary building blocks for these systems. They are not a complete replacement for the signature layer of modern public blockchains.
Another area touched upon was understanding address poisoning attacks on Ethereum, specifically looking at how scammers fund their operations and launder money through services like Tornado Cash. We proposed five families of scam signatures to help with address clustering and investigated the use of Tornado Cash in this context.
On the security side, we looked at how large language model agents can be governed using ActGov. This framework validates tool actions before they cause external effects in long-horizon workflows. It uses a unified semantic model to enforce policies per action, which showed it could reduce the success rate of indirect prompt-injection attacks while keeping the agent useful.
We also examined how we can improve bug discovery in complex JavaScript engines by using StateLens. This framework employs large language models to find deep internal states. It uses an agent-based reasoning pipeline to intelligently select instrumentation targets, and it uncovered sixty-eight new bugs when compared to current fuzzers.
Finally, we looked at the lifecycle of kernel bugs with SoK. This systematizes the process from discovery through deployment. The data suggests that the gap between finding a bug and actually patching it is structural because current validation techniques often fail because they assume reliable reproducers that simply do not exist in real kernel reports.
The most crucial work here is pattern-level differential privacy for complex event processing because it addresses the inherent tension between keeping sensitive data private and still being able to extract useful insights from detected patterns. This method proposes dynamically adjusting noise on a data stream, allowing us to apply and compare privacy guarantees directly at the level of an event pattern rather than just on individual data points.
This approach yields pattern-level differential privacy, allowing us to test different privacy mechanisms against various trust settings and context knowledge requirements, such as the deployed queries. The evaluation across three datasets—two real-world and one synthetic—demonstrates that these proposed mechanisms boost data utility while maintaining the same level of privacy as existing state-of-the-art methods. Furthermore, simulations confirm that computational complexity is not a barrier to using this technique in practice. This work builds upon the foundational idea of pattern-level differential privacy by showing how to achieve it through novel pattern-level privacy preserving mechanisms.
The work on prefix puncturable signatures matters because it addresses the key issue of efficiently updating cryptographic keys while maintaining security guarantees for signing specific message subsets. Halevi et al.'s introduction of prefix puncturable signatures solved this by allowing a key to be punctured relative to a target prefix, meaning the key could stop signing messages starting with that specific sequence. This is significant because it moves beyond simple key updates to provide fine-grained control over which messages are signed while preserving the ability to sign everything else.
A generic construction using hierarchical identity-based signature schemes from HIBS schemes was presented as a solution for this problem. When applied to the specific case where the prefix space is binary, 0,1 l, and utilizing Ruckert's HIBS GPV scheme, this construction successfully bounded the punctured signing key size by O(lQ Punc). This means that for every puncturing operation Q Punc performed on a key of length l bits, the resulting new key size grows linearly with Q Punc.
This result is important because it provides a concrete bound on how much larger the new signing key will be after applying multiple puncturing operations. This contrasts with other generic constructions which suffered from worse scaling issues, such as those based on identity-based signatures requiring two full IBS keys when the prefix space was all l-bit strings. This finding connects to the broader area of post-quantum cryptography where key efficiency is paramount. While this work focuses on prefix puncturable signatures, it contributes to the ongoing effort to develop practical and efficient signature schemes for future cryptographic needs.
The most critical work here is the dual-locking method for securing trained neural networks because it addresses the immediate need to protect valuable models while still allowing them to function. This technique combines key-driven index permutation with PIN-based watermarking based on Sparse Quantization Index Modulation. This binds the network's bias coefficients to a user-defined Personal Identification Number. Without the correct key, the network retains its architecture but becomes functionally impaired because its internal representations are disrupted by this modulation.
This method is further enhanced by an adaptive key selection strategy that redistributes high-magnitude weights to low-sensitivity positions and vice versa. This increases the degradation when locked while preserving full recovery capability. Experiments across various architectures like fully connected networks, ResNet CNNs, and transformer architectures show that locking reduces accuracy below ten percent for fully connected models and even below zero point five percent for CNNs.
The watermark embedded in the bias coefficients introduces no measurable accuracy degradation, which means it reliably authenticates ownership without harming performance. This is complemented by analysis of embedding distributions across different network types, which suggests potential diagnostic value for identifying models that are undertrained or suboptimally designed. This approach simultaneously provides model protection, recovery, and ownership verification.
The most pressing issue we see is how secrets are being exposed in production web applications because pre-deployment scanning only looks at the source code, not what the live application actually serves. This means that even if a secret exists in a JavaScript bundle, static scanners miss it entirely; specifically, 13.9 percent of the ground truth credentials were only found through manual analysis and were missed by all nine evaluated production scanners.
This structural gap is significant because most applications have their full Azure AD token-mint chain co-located in one bundle, reachable directly from browser code on 73.3 percent of secret-exposed applications. This means the credentials are easily accessible if an attacker can reach the client side. We saw that CryptoJS encrypted configurations defeat every static scanner because the credential only appears after decryption with a key that is co-located with it, which requires runtime awareness to find. Furthermore, among the scanners tested, runtime-aware tools performed best at recovering 77.8 percent of secrets compared to 36.6 percent for static ones.
This points toward a layered detection methodology because credentials can reach production undetected through five distinct paths that require runtime detection to catch them; this is why we also looked at how agent-integrated software handles security across different operational paths.
The work on runtime electromagnetic detection of CPU hardware trojans is particularly important because it offers a passive way to spot malicious hardware activity without needing destructive analysis or extra circuitry. This research uses side-channels from an open-source hardware trojan that can write to kernel memory on a RISC-V system running Linux, showing that under specific conditions, these trojans can be detected indirectly through the unusual software behavior they cause. This detection method is significant because it provides a non-invasive means of security monitoring at the hardware level.
The proposed multi-layer defence framework for Open RAN control operations addresses critical runtime threats by classifying them into message-level, data-level, and control logic-level categories. This framework implements specific defenses for each category, including a signature-based inspection module for E2 messages and an LSTM network detector for telemetry poisoning based on temporal anomalies. Furthermore, it incorporates a runtime xApp attestation mechanism using execution-time hash challenges to ensure the security of near-real-time operations while keeping overhead under eighty milliseconds. This layered approach is foundational for building deployable, policy-driven architectures in Open RAN environments.
The research into trust management in edge-enabled IoT systems systematically reviews existing trust designs across various physical, network, and application layers to identify gaps in current research. This review helps map different IoT domains against consumer or industrial needs, pointing toward the need for context-aware and adaptive trust management as a future direction. This work sets the stage for understanding how reliability is assessed when devices interact in complex edge environments.
The TriFleetRCA pipeline presents an on-premise method for root cause analysis within Kubernetes by collecting evidence from pod, namespace, or cluster scopes and ranking it using template de-duplication and BM25 algorithms. This system successfully diagnoses faults across various scopes, with the hit rate improving significantly when de-duplication is used before ranking. A key finding was that a guard mechanism effectively rejected poisoned runbooks in all twenty analyses tested, suggesting that layered defenses are necessary for robust analysis pipelines.
The UBA-ORL attack demonstrates a previously overlooked risk in compliance-driven offline reinforcement learning by showing how backdoor attacks can be reactivated after a data deletion request is made. This attack uses dual samples to create competing signals during training, allowing the backdoor to re-dominate when the benign data subset is unlearned. This finding strongly suggests that joint pre- and post-unlearning auditing mechanisms are essential for securing offline RL platforms.
MATE introduces a lightweight auditor that uses natural language policies encoded with agent trajectories to check for policy violations in mobile agents, allowing policies to be updated as editable text rather than fixed parameters. The system synthesized over 140 thousand realistic trajectories, achieving over ninety-five percent accuracy on MATEBench and outperforming prior methods by more than twenty percent. This work proves that fine-grained security auditing is feasible for heterogeneous mobile agents.
Beyond single-model injection, the threat model for multi-agent systems reveals that inter-agent message passing and shared tool access create new injection channels invisible to perimeter defenses. Testing a six agent system showed that sixty seven percent of agents were vulnerable to scope violations, but architectural defenses like message signing reduced overall success rates dramatically.
The framework for autonomous penetration testing harness evaluation shifts focus from mere capability to assurance properties such as evidence grounding and tamper evident accountability. This paper defines five formal properties and shows that these properties are realizable together, suggesting a path toward building harnesses that enforce security obligations rather than just measuring successful exploitation.
The work on SelfOp is particularly important because it addresses the fundamental problem of how to make large language model agents actually improve their security skills without requiring massive amounts of labeled data. This method works by treating context optimization like a chain-rule inspired textual gradient descent. It takes an outcome and propagates error signals backward through the agent's steps and the context that shaped its behavior, accumulating these signals across many instances to find generalizable improvements. This process yielded significant results on CyberGym benchmarks, showing that SelfOp could improve GPT-5.4-mini by seventeen points and GPT-5.4 itself by eighteen point five, demonstrating that the optimized skills learned were transferable across different models because they captured general task knowledge rather than model-specific patterns.
This idea of using structured knowledge augmentation is also relevant when considering how LLM agents tackle complex problems like cryptography, which is what KryptoPilot attempts to do. KryptoPilot tackles the difficulty of cryptographic exploitation by integrating dynamic open-world knowledge acquisition through a deep research pipeline and a persistent workspace for reusing structured knowledge, combined with a governance subsystem that stabilizes reasoning through behavioral constraints. This design allowed KryptoPilot to achieve a complete solve rate on InterCode-CTF and solve between fifty six and sixty percent of challenges on the NYU-CTF benchmark, proving that fine-grained, open-world knowledge augmentation is necessary for scaling these agents to real cryptographic exploitation.
Moving toward system integrity, the research into rApp/xApp attestation offers a concrete way to verify that deployed software components in the Open Radio Access Network remain untampered during operation. This work defines how existing integrity verification techniques can be integrated into the RIC ecosystem through attestation modules and agents. Experimental results showed that this runtime attestation could be performed with latencies under forty milliseconds across various cryptographic hash functions. This suggests that verifying the state of network applications can happen without disrupting time-sensitive operations on the Near-RT RIC platform.
The most critical finding relates to the hybrid framework for automated security annotation generation because it directly addresses the manual, error-prone bottleneck in creating accurate security annotations for business process models. This system combines large language model semantic extraction with schema-constrained mapping and rule-based normalization to produce structurally valid SecBPMN2 annotations. This method achieved substantially higher precision compared to human analysts while maintaining comparable recall, and it reduced erroneous annotations by nearly fifty percent, which means the framework is a reliable tool for scaling security-by-design modeling.
The agentic AI research on re-identification presents a significant threat because it demonstrates that large language model agents can autonomously search the open web and cross-reference public records to resolve raw coordinate sequences into candidate identities without human intervention. This pipeline successfully re-identified seventy two percent of individuals in simulated scenarios, which suggests that de facto anonymity is shifting under current standards and requires immediate attention from data custodians.
Speed Kills explores a critical security risk involving AI accelerators because it shows that confused deputy attacks are feasible on six out of seven different AIAs, impacting over one hundred million devices. This means specialized hardware used for AI inference can be tricked into performing privileged operations, and the proposed LLM-assisted framework for extracting this information suggests a path toward on-demand validation defenses with low runtime overhead.
The work on Hermes Seal is important because it introduces zero-knowledge proofs using zk-SNARKs to enable privacy-preserving, verifiable communication in autonomous vehicle networks. This allows systems to prove computations are correct without revealing proprietary data, achieving proof generation times of eight milliseconds and verification times of one millisecond on a GPU.
The research into Proof-of-Authorship for diffusion models is relevant because it proposes binding the random seed used during latent diffusion model generation to an author's identity via cryptographic functions. This provides a stronger guarantee of authorship than time-stamping, suggesting a novel way to assert creation rights in the context of AI-generated content.
Finally, the energy-aware framework for solving post-quantum control plane bottlenecks is significant because it uses an Open RAN split to intelligently schedule post-quantum cryptography handshakes. This scheduling reduces per handshake energy by approximately sixty percent while still meeting latency targets, offering a sustainable way to implement quantum resilience in network infrastructure.
Today's papers
- Domain Specific Post Quantum Signatures for Blockchains Blockchains need more than post quantum single signer signatures, they need consensus profiled authentication objects with canonical bytes, priced invalid input rejection, stable transaction identifiers, hybrid downgrade resistance, public aggregation, merge semantics, accountable signer evidence, forward secure committee rotation, and light client consequences. [paper]
- The Anatomy of Address Poisoning on Ethereum: Funding Mechanisms and Scam Signatures and Laundering via Tornado Cash investigates the funding mechanisms and laundering methods used in address poisoning scams on Ethereum.
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation presents StateLens, a framework that uses Large Language Models to automatically discover deep internal states in JavaScript engines for better fuzzing coverage. [paper]
- ActGov: Governing LLM Agent Actions via Policy-Constrained Validation introduces ActGov, a runtime enforcement framework that validates each LLM-proposed tool action before it causes external effects in agent workflows. [paper]
- Differentially Private and Fairness-Audited Score Diffusion for Irregular Longitudinal Health Records presents TRUST LONGSYNTH, a private generator for longitudinal health records that balances privacy with utility and fairness. [paper]
- SoK: From Finding to Deployment: Systematizing the OS Kernel Bug Lifecycle systematizes the Linux kernel bug lifecycle from discovery to deployment by organizing prior work into five stages. [paper]
- Connecting the Dots in Agentic AI Security: A Cross-Dimensional Threat Taxonomy, Evaluation Maturity, and Open Challenges introduces a cross-dimensional representation for analyzing threats in agentic AI systems. [paper]
- POZZER: A Power Side Channel-guided Fuzzer for Black-Box Embedded Systems presents POZZER, a power side-channel guided fuzzer that discovers vulnerabilities in black-box embedded systems using power traces as feedback. [paper]
- Pattern-level Differential Privacy for High-utility Complex Event Processing proposes a new approach to preserve privacy in Complex Event Processing by dynamically adapting noise based on event patterns. [paper]
- LLMs as Linguistic Chameleons: Decoupling Semantics and Structure for Privacy-Preserving Communication introduces CROSS-MAP, a framework that maps private inputs into different semantic domains to preserve structure for LLM reasoning. [paper]
- Runtime Authorization Consistency Checking for MCP-based Agentic Workflows presents RAC, a lightweight guard at the tool-call boundary that prevents authorization drift in multi-step agent workflows. [paper]
- Name2Pkg: Lightweight One-Class Android Malware Screening via Name-Package Correspondence Modeling presents Name2Pkg, a lightweight method for screening Android malware using only app name and package name. [paper]
- Monet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services systematically measures the ecosystem of harmful text-to-image models. [paper]
- When Label Noise Meets Class Imbalance: A Robust Framework for Android Malware Family Classification proposes RoMaC, a framework that jointly addresses label noise and class imbalance in Android malware family classification. [paper]
- Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents suggests a new approach to reporting AI agent incidents by identifying the necessary information required for comprehensive incident reporting. [paper]
- Exploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks introduces SURF, a class of CPU trojans that can be activated without arbitrary code execution using high-level language operations. [paper]
- Prefix Puncturable Signatures with Smaller Signing Key from HIBS presents a generic construction of prefix puncturable signatures from hierarchical identity-based signature schemes to reduce signing key size. [paper]
- Decoding Guardrails: XAI-Guided Perturbation Analysis of Prompt Injection Detection explores how explainable AI techniques can be used to analyze the decision logic of prompt injection classifiers. [paper]
- MobileCybench: Evaluating Agent Vulnerability Discovery via Executable Probes introduces MobileCybench, a benchmark for evaluating vulnerability discovery by AI agents using executable probes on Android applications. [paper]
- ThreatFormer-IDS: Robust Transformer Intrusion Detection with Zero-Day Generalization and Explainable Attribution proposes ThreatFormer-IDS, a Transformer-based IDS that combines supervised learning and self-supervised learning to detect zero-day attacks in IoT networks. [paper]
- A Red-Team Study of Anthropic Fable 5 & Opus 4.8 Models evaluates the adversarial robustness of frontier LLMs against various jailbreak attacks using the HackAgent red-teaming framework. [paper]
- Zero-Trust Authorization and Discovery for Enterprise MCP proposes extensions to the Model Context Protocol to provide fine-grained, per-tool authorization in agentic workflows across different SDKs. [paper]
- The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents measures the utility cost of memory poisoning defenses when tested on benign traffic. [paper]
- When Agentic Trust Crosses Organizational Boundaries: Structural Externalization and a Reference Model for Trust Evidence develops Trustworthiness as a Service to provide a reusable profile for cross-domain reliance in agentic systems. [paper]
- Dual-Locking Learned AI Models: A PIN-Based Sparse QIM Watermarking and Adaptive Index Permutation Approach presents a dual-locking method to secure trained neural networks with key-driven watermarking and index permutation. [paper]
- When the Agent Becomes the Kernel: A Systematization of Security on the Path to AI-Native Operating Systems systematizes security around a crossing mediated over provenance in AI-native operating systems. [paper]
- Temporal Generalization and Explanation Stability of Control Flow Graph Neural Networks studies how control flow graph neural networks generalize to future malware samples using strict temporal splits.
- Reasoning Topology Matters: A Controlled Study of LLM-Based Cybersecurity Analysis introduces Security Reasoning Topology to model and evaluate the effects of reasoning structures on LLM cybersecurity analysis performance. [paper]
- Defusing Explosive Prompts: Understanding and Preventing Trigger-Based Prompt Injections in LLM Agents introduces the explosive prompt, a conditional payload that stays dormant until a specific trigger is met in LLM agents. [paper]
- Tick-Tock on the Open Fronthaul: Securing Synchronization in O-RAN proposes PRTESLA-C, a lightweight synchronization protection mechanism for PTP traffic to prevent spoofing and replay attacks in Open RAN. [paper]
- Your Mailbox Is Mine: Prompt Injection Attacks Against Real-World LLM Email Agents introduces ESPI, a new attack paradigm that manipulates how email agents interpret mailbox operational context. [paper]
- Endogenous Interpretation proposes endogenous interpretation, suggesting that program, interpreter, machine, and execution language are different parameterizations of one executable state-transition relation. [paper]
- Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications documents exploitation chains where production secrets are exposed in JavaScript bundles and proposes a layered runtime detection methodology. [paper]
- Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist argues that security must be assessed at the level of the whole software system for agent-integrated software. [paper]
- Benchmarking Post-Quantum Cryptography in Lightweight Virtualization Environments on Embedded Hardware measures the performance impact of post-quantum cryptography primitives on embedded hardware under different virtualization environments. [paper]
- LeaseGuard: Incumbent-Preserving Admission Control for Privileged LLM Agents introduces LeaseGuard, a deterministic admission layer that manages resource preemption for privileged LLM agents. [paper]
- Residual Community Prototypes Under-Reject Held-Out Malware Families in FCG-MFD investigates whether community summaries add rejection information beyond graph neural network embeddings in open-set malware family recognition. [paper]
- KEVGraph: Exploitation-Aware Dependency Vulnerability Remediation presents KEVGraph, an eight-stage pipeline that frames vulnerability remediation as a KEV-aware set-cover problem for npm dependencies. [paper]
- From Bits to Beliefs: Recoverable Semantic Fingerprints for Black-Box Verification of Large Language Models proposes SimPrint, a framework to recover LLM ownership signatures from black-box API responses. [paper]
- Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment identifies critical logit-level vulnerabilities in safety alignment techniques using Semantic-sensitive Alignment and Generation. [paper]
- Assessing Runtime Electromagnetic Detection of CPU Hardware Trojans Targeting Kernel Memory investigates the use of electromagnetic emanations for the runtime detection of hardware trojans targeting kernel memory. [paper]
- Towards a Multi-Layer Defence Framework for Securing Near-Real-Time Operations in Open RAN proposes a multi-layer defense framework to secure near-real-time operations in Open RAN controllers. [paper]
- Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions systematically reviews the current state of trust management in edge-enabled IoT systems. [paper]
- TriFleetRCA: On-Premise LLM Root Cause Analysis for Kubernetes presents TriFleetRCA, a pipeline for on-premise root cause analysis of faults in Kubernetes clusters using an on-premise GPU. [paper]
- UBA-ORL: Unlearning-Activated Backdoor Attacks on Offline Reinforcement Learning introduces UBA-ORL, the first unlearning-activated backdoor attack for offline reinforcement learning. [paper]
- MATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning introduces MATE, a policy-conditioned auditor that audits mobile agent trajectories against natural language security policies. [paper]
- Beyond Single-Model Injection: A Threat Model and Defense Architecture for Prompt Injection in Multi-Agent Systems constructs a threat model and defense architecture to address prompt injection in multi-agent systems. [paper]
- From Capability to Assurance in Autonomous Penetration-Testing Harnesses proposes a framework defining assurance properties for AI agents used in penetration testing harnesses.
- SMS-delivered network-initiated SUPL on Pixel 8: a privacy assessment investigates whether SMS messages can be used to silently exfiltrate location data from mobile handsets. [paper]
- SelfOp: An Optimization Algorithm for Self-Improving Security Agents introduces SelfOp, an algorithm that automatically improves the context of frozen security agents through chain-rule inspired textual gradient descent. [paper]
- SkelOT: Reusing AOT Compilation Across EVM Contract Families presents SkelOT, an AOT framework that reuses compilation artifacts at the contract-code-hash granularity for Ethereum Virtual Machine contracts. [paper]
- CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics proposes CLOADER, a stealth framework to evade mobile security defenses using dynamic evasion tactics. [paper]
- OPBackdoor: Opportunistic Backdoors via Alibi-Aligned Reasoning introduces OPBackdoor, which enables LLMs to elicit backdoor objectives only when the prompt context presents an exploitable opportunity. [paper]
- Forgeable Confirmation in Automated Computer Security Testing: Deterministic Rules versus AI Judges asks whether automated security testing systems can forge confirmation of attack success. [paper]
- KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation proposes KryptoPilot, an agent that uses open-world knowledge to perform automated cryptographic exploitation. [paper]
- rApp/xApp Attestation: A New Security Use Case for O-RAN introduces rApp/xApp attestation as a RIC-native mechanism for runtime integrity verification of O-RAN applications. [paper]
- A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models presents a hybrid framework that automatically generates security annotations from natural language specifications into BPMN models. [paper]
- Agentic AI-Powered Re-Identification: An Emerging, Scalable Threat to Mobility Microdata Privacy demonstrates how agentic AI can re-identify individuals from mobility microdata using public sources. [paper]
- Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators investigates confused deputy attacks on edge AI accelerators and proposes a framework called DeputyHunt for detection. [paper]
- BAIT: Boundary-Guided Disclosure Escalation LLM Jailbreaking via Self-Conditioned Reasoning introduces BAIT, a three-step jailbreak framework that elicits malicious information through internal model disclosure. [paper]
The papers
- Powerful Primitives in the Bounded Quantum Storage Model —
- Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment —
- Starfish: Rebalancing Multi-Party Off-Chain Payment Channels —
- Your Mailbox Is Mine: Prompt Injection Attacks Against Real-World LLM Email Agents —
- BridgeShield: Risk-Aware Graph Modeling for Cross-Chain Bridge Attack Detection —
- Tight Privacy Audit in One Run —
- Resisting Quantum Key Distribution Attacks Using Quantum Machine Learning —
- World's First Authenticated Satellite Pseudorange from Orbit —
- Spoofing Missed-Detection Bounds for PRF GNSS Ranging Authentication Under AWGN Models —
- BreakFun: Jailbreaking LLMs via Object Instantiation under Simulated Code Execution —
- Aware but Unprepared: Measuring the Security Awareness-Behavior Gap in Student Use of LLM-Generated Code with Bifr"ost —
- Towards a Multi-Layer Defence Framework for Securing Near-Real-Time Operations in Open RAN —
- ShadowBlock: Efficient Dynamic Anonymous Blocklisting and Its Cross-chain Application —
- KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation —
- Solving the Post-Quantum Control Plane Bottleneck: Energy-Aware Cryptographic Scheduling in Open RAN —
- ThreatFormer-IDS: Robust Transformer Intrusion Detection with Zero-Day Generalization and Explainable Attribution —
- Proof-of-Authorship for Diffusion-based AI Generated Content —
- Hermes Seal: Zero-Knowledge Assurance for Autonomous Vehicle Communications —
- Resolving Conflicts Between RTOS Timekeeping and Uninterruptable Trusted Computing —
- APIOT: Autonomous Vulnerability Management Across Bare-Metal Industrial OT Networks —
- Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators —
- BAIT: Boundary-Guided Disclosure Escalation LLM Jailbreaking via Self-Conditioned Reasoning —
- A Red-Team Study of Anthropic Fable 5 & Opus 4.8 Models —
- Agentic AI-Powered Re-Identification: An Emerging, Scalable Threat to Mobility Microdata Privacy —
- A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models —
- Differentially Private and Fairness-Audited Score Diffusion for Irregular Longitudinal Health Records —
- Defusing Explosive Prompts: Understanding and Preventing Trigger-Based Prompt Injections in LLM Agents —
- Tick-Tock on the Open Fronthaul: Securing Synchronization in O-RAN —
- Zero-Trust Authorization and Discovery for Enterprise MCP —
- From Capability to Assurance in Autonomous Penetration-Testing Harnesses: A Framework and Reference Implementation —
- UBA-ORL: Unlearning-Activated Backdoor Attacks on Offline Reinforcement Learning —
- MATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning —
- SelfOp: An Optimization Algorithm for Self-Improving Security Agents —
- The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents —
- When Label Noise Meets Class Imbalance: A Robust Framework for Android Malware Family Classification —
- SMS-delivered network-initiated SUPL on Pixel 8: a privacy assessment —
- Beyond Single-Model Injection: A Threat Model and Defense Architecture for Prompt Injection in Multi-Agent Systems —
- When Agentic Trust Crosses Organizational Boundaries: Structural Externalization and a Reference Model for Trust Evidence —
- Dual-Locking Learned AI Models: A PIN-Based Sparse QIM Watermarking and Adaptive Index Permutation Approach —
- Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications —
- An LLM-Assisted AutoML Framework for Intrusion Detection in IoT Networks —
- Exploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks —
- Assessing Runtime Electromagnetic Detection of CPU Hardware Trojans Targeting Kernel Memory —
- LLMs as Linguistic Chameleons: Decoupling Semantics and Structure for Privacy-Preserving Communication —
- SoK: From Finding to Deployment: Systematizing the OS Kernel Bug Lifecycle —
- Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist —
- CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics —
- The Anatomy of Address Poisoning on Ethereum: Funding Mechanisms, Scam Signatures, and Laundering via Tornado Cash —
- Runtime Authorization Consistency Checking for MCP-based Agentic Workflows —
- Endogenous Interpretation —
- POZZER: A Power Side Channel-guided Fuzzer for Black-Box Embedded Systems —
- When the Agent Becomes the Kernel: A Systematization of Security on the Path to AI-Native Operating Systems —
- TriFleetRCA: On-Premise LLM Root Cause Analysis for Kubernetes —
- Pattern-level Differential Privacy for High-utility Complex Event Processing —
- SyzHarness: Patch-Based Kernel Bug Reproduction with LLM-Synthesized Fuzzing Harnesses —
- Connecting the Dots in Agentic AI Security: A Cross-Dimensional Threat Taxonomy, Evaluation Maturity, and Open Challenges —
- Benchmarking Post-Quantum Cryptography in Lightweight Virtualization Environments on Embedded Hardware —
- MobileCybench: Evaluating Agent Vulnerability Discovery via Executable Probes —
- LeaseGuard: Incumbent-Preserving Admission Control for Privileged LLM Agents —
- From Bits to Beliefs: Recoverable Semantic Fingerprints for Black-Box Verification of Large Language Models —
- Monet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services —
- KEVGraph: Exploitation-Aware Dependency Vulnerability Remediation —
- Forgeable Confirmation in Automated Computer Security Testing: Deterministic Rules versus AI Judges —
- Temporal Generalization and Explanation Stability of Control Flow Graph Neural Networks for Malware Detection —
- rApp/xApp Attestation: A New Security Use Case for O-RAN —
- Name2Pkg: Lightweight One-Class Android Malware Screening via Name-Package Correspondence Modeling —
- Passive Hybrid Network-Based Intrusion Detection System (Hybrid-NIDS) Combining Suricata and Random Forest —
- SkelOT: Reusing AOT Compilation Across EVM Contract Families —
- ActGov: Governing LLM Agent Actions via Policy-Constrained Validation —
- Prefix Puncturable Signatures with Smaller Signing Key from HIBS —
- Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents —
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation —
- 5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience —
- Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions —
- Domain Specific Post Quantum Signatures for Blockchains —
- Reasoning Topology Matters: A Controlled Study of LLM-Based Cybersecurity Analysis —
- Decoding Guardrails: XAI-Guided Perturbation Analysis of Prompt Injection Detection —
- OPBackdoor: Opportunistic Backdoors via Alibi-Aligned Reasoning —
- Residual Community Prototypes Under-Reject Held-Out Malware Families in FCG-MFD —
Important terms
- Domain Specific Post Quantum Signatures
- These are specialized digital signatures for blockchains that go beyond simple single-signer authentication to handle complex needs like rejecting invalid inputs or using stable transaction IDs.
- Pattern-Level Differential Privacy
- This method dynamically adjusts noise on data streams to provide privacy guarantees at the level of event patterns, improving data utility while maintaining strong privacy against various trust settings.
- Prefix Puncturable Signatures
- This cryptographic technique allows for efficient key updates by enabling a key to be 'punctured' relative to a target prefix, giving fine-grained control over which messages are signed.
- Dual-Locking Method for Neural Networks
- This technique secures trained models by combining key-driven index permutation with PIN-based watermarking, allowing the network to function while binding its bias coefficients to a secret key.