Security papers — 2026-09-22

This work dives into domain specific post quantum signatures because they are crucial for securing blockchain roles beyond simple single signer authentication. This research argues that blockchains need consensus ready signature profiles that handle things like priced invalid input rejection and stable transaction identifiers, which is different from just using NIST single signer signatures.

We explored many different schemes, including ML-DSA, SLH-DSA, Falcon/FN-DSA, HAWK, MAYO, SNOVA, UOV/QR-UOV, FAEST, SQIsign and others on Bitcoin and Ethereum stress profiles. This research shows that while single signer signatures are necessary building blocks for these systems. They are not a complete replacement for the signature layer of modern public blockchains.

Another area touched upon was understanding address poisoning attacks on Ethereum, specifically looking at how scammers fund their operations and launder money through services like Tornado Cash. We proposed five families of scam signatures to help with address clustering and investigated the use of Tornado Cash in this context.

On the security side, we looked at how large language model agents can be governed using ActGov. This framework validates tool actions before they cause external effects in long-horizon workflows. It uses a unified semantic model to enforce policies per action, which showed it could reduce the success rate of indirect prompt-injection attacks while keeping the agent useful.

We also examined how we can improve bug discovery in complex JavaScript engines by using StateLens. This framework employs large language models to find deep internal states. It uses an agent-based reasoning pipeline to intelligently select instrumentation targets, and it uncovered sixty-eight new bugs when compared to current fuzzers.

Finally, we looked at the lifecycle of kernel bugs with SoK. This systematizes the process from discovery through deployment. The data suggests that the gap between finding a bug and actually patching it is structural because current validation techniques often fail because they assume reliable reproducers that simply do not exist in real kernel reports.

The most crucial work here is pattern-level differential privacy for complex event processing because it addresses the inherent tension between keeping sensitive data private and still being able to extract useful insights from detected patterns. This method proposes dynamically adjusting noise on a data stream, allowing us to apply and compare privacy guarantees directly at the level of an event pattern rather than just on individual data points.

This approach yields pattern-level differential privacy, allowing us to test different privacy mechanisms against various trust settings and context knowledge requirements, such as the deployed queries. The evaluation across three datasets—two real-world and one synthetic—demonstrates that these proposed mechanisms boost data utility while maintaining the same level of privacy as existing state-of-the-art methods. Furthermore, simulations confirm that computational complexity is not a barrier to using this technique in practice. This work builds upon the foundational idea of pattern-level differential privacy by showing how to achieve it through novel pattern-level privacy preserving mechanisms.

The work on prefix puncturable signatures matters because it addresses the key issue of efficiently updating cryptographic keys while maintaining security guarantees for signing specific message subsets. Halevi et al.'s introduction of prefix puncturable signatures solved this by allowing a key to be punctured relative to a target prefix, meaning the key could stop signing messages starting with that specific sequence. This is significant because it moves beyond simple key updates to provide fine-grained control over which messages are signed while preserving the ability to sign everything else.

A generic construction using hierarchical identity-based signature schemes from HIBS schemes was presented as a solution for this problem. When applied to the specific case where the prefix space is binary, 0,1 l, and utilizing Ruckert's HIBS GPV scheme, this construction successfully bounded the punctured signing key size by O(lQ Punc). This means that for every puncturing operation Q Punc performed on a key of length l bits, the resulting new key size grows linearly with Q Punc.

This result is important because it provides a concrete bound on how much larger the new signing key will be after applying multiple puncturing operations. This contrasts with other generic constructions which suffered from worse scaling issues, such as those based on identity-based signatures requiring two full IBS keys when the prefix space was all l-bit strings. This finding connects to the broader area of post-quantum cryptography where key efficiency is paramount. While this work focuses on prefix puncturable signatures, it contributes to the ongoing effort to develop practical and efficient signature schemes for future cryptographic needs.

The most critical work here is the dual-locking method for securing trained neural networks because it addresses the immediate need to protect valuable models while still allowing them to function. This technique combines key-driven index permutation with PIN-based watermarking based on Sparse Quantization Index Modulation. This binds the network's bias coefficients to a user-defined Personal Identification Number. Without the correct key, the network retains its architecture but becomes functionally impaired because its internal representations are disrupted by this modulation.

This method is further enhanced by an adaptive key selection strategy that redistributes high-magnitude weights to low-sensitivity positions and vice versa. This increases the degradation when locked while preserving full recovery capability. Experiments across various architectures like fully connected networks, ResNet CNNs, and transformer architectures show that locking reduces accuracy below ten percent for fully connected models and even below zero point five percent for CNNs.

The watermark embedded in the bias coefficients introduces no measurable accuracy degradation, which means it reliably authenticates ownership without harming performance. This is complemented by analysis of embedding distributions across different network types, which suggests potential diagnostic value for identifying models that are undertrained or suboptimally designed. This approach simultaneously provides model protection, recovery, and ownership verification.

The most pressing issue we see is how secrets are being exposed in production web applications because pre-deployment scanning only looks at the source code, not what the live application actually serves. This means that even if a secret exists in a JavaScript bundle, static scanners miss it entirely; specifically, 13.9 percent of the ground truth credentials were only found through manual analysis and were missed by all nine evaluated production scanners.

This structural gap is significant because most applications have their full Azure AD token-mint chain co-located in one bundle, reachable directly from browser code on 73.3 percent of secret-exposed applications. This means the credentials are easily accessible if an attacker can reach the client side. We saw that CryptoJS encrypted configurations defeat every static scanner because the credential only appears after decryption with a key that is co-located with it, which requires runtime awareness to find. Furthermore, among the scanners tested, runtime-aware tools performed best at recovering 77.8 percent of secrets compared to 36.6 percent for static ones.

This points toward a layered detection methodology because credentials can reach production undetected through five distinct paths that require runtime detection to catch them; this is why we also looked at how agent-integrated software handles security across different operational paths.

The work on runtime electromagnetic detection of CPU hardware trojans is particularly important because it offers a passive way to spot malicious hardware activity without needing destructive analysis or extra circuitry. This research uses side-channels from an open-source hardware trojan that can write to kernel memory on a RISC-V system running Linux, showing that under specific conditions, these trojans can be detected indirectly through the unusual software behavior they cause. This detection method is significant because it provides a non-invasive means of security monitoring at the hardware level.

The proposed multi-layer defence framework for Open RAN control operations addresses critical runtime threats by classifying them into message-level, data-level, and control logic-level categories. This framework implements specific defenses for each category, including a signature-based inspection module for E2 messages and an LSTM network detector for telemetry poisoning based on temporal anomalies. Furthermore, it incorporates a runtime xApp attestation mechanism using execution-time hash challenges to ensure the security of near-real-time operations while keeping overhead under eighty milliseconds. This layered approach is foundational for building deployable, policy-driven architectures in Open RAN environments.

The research into trust management in edge-enabled IoT systems systematically reviews existing trust designs across various physical, network, and application layers to identify gaps in current research. This review helps map different IoT domains against consumer or industrial needs, pointing toward the need for context-aware and adaptive trust management as a future direction. This work sets the stage for understanding how reliability is assessed when devices interact in complex edge environments.

The TriFleetRCA pipeline presents an on-premise method for root cause analysis within Kubernetes by collecting evidence from pod, namespace, or cluster scopes and ranking it using template de-duplication and BM25 algorithms. This system successfully diagnoses faults across various scopes, with the hit rate improving significantly when de-duplication is used before ranking. A key finding was that a guard mechanism effectively rejected poisoned runbooks in all twenty analyses tested, suggesting that layered defenses are necessary for robust analysis pipelines.

The UBA-ORL attack demonstrates a previously overlooked risk in compliance-driven offline reinforcement learning by showing how backdoor attacks can be reactivated after a data deletion request is made. This attack uses dual samples to create competing signals during training, allowing the backdoor to re-dominate when the benign data subset is unlearned. This finding strongly suggests that joint pre- and post-unlearning auditing mechanisms are essential for securing offline RL platforms.

MATE introduces a lightweight auditor that uses natural language policies encoded with agent trajectories to check for policy violations in mobile agents, allowing policies to be updated as editable text rather than fixed parameters. The system synthesized over 140 thousand realistic trajectories, achieving over ninety-five percent accuracy on MATEBench and outperforming prior methods by more than twenty percent. This work proves that fine-grained security auditing is feasible for heterogeneous mobile agents.

Beyond single-model injection, the threat model for multi-agent systems reveals that inter-agent message passing and shared tool access create new injection channels invisible to perimeter defenses. Testing a six agent system showed that sixty seven percent of agents were vulnerable to scope violations, but architectural defenses like message signing reduced overall success rates dramatically.

The framework for autonomous penetration testing harness evaluation shifts focus from mere capability to assurance properties such as evidence grounding and tamper evident accountability. This paper defines five formal properties and shows that these properties are realizable together, suggesting a path toward building harnesses that enforce security obligations rather than just measuring successful exploitation.

The work on SelfOp is particularly important because it addresses the fundamental problem of how to make large language model agents actually improve their security skills without requiring massive amounts of labeled data. This method works by treating context optimization like a chain-rule inspired textual gradient descent. It takes an outcome and propagates error signals backward through the agent's steps and the context that shaped its behavior, accumulating these signals across many instances to find generalizable improvements. This process yielded significant results on CyberGym benchmarks, showing that SelfOp could improve GPT-5.4-mini by seventeen points and GPT-5.4 itself by eighteen point five, demonstrating that the optimized skills learned were transferable across different models because they captured general task knowledge rather than model-specific patterns.

This idea of using structured knowledge augmentation is also relevant when considering how LLM agents tackle complex problems like cryptography, which is what KryptoPilot attempts to do. KryptoPilot tackles the difficulty of cryptographic exploitation by integrating dynamic open-world knowledge acquisition through a deep research pipeline and a persistent workspace for reusing structured knowledge, combined with a governance subsystem that stabilizes reasoning through behavioral constraints. This design allowed KryptoPilot to achieve a complete solve rate on InterCode-CTF and solve between fifty six and sixty percent of challenges on the NYU-CTF benchmark, proving that fine-grained, open-world knowledge augmentation is necessary for scaling these agents to real cryptographic exploitation.

Moving toward system integrity, the research into rApp/xApp attestation offers a concrete way to verify that deployed software components in the Open Radio Access Network remain untampered during operation. This work defines how existing integrity verification techniques can be integrated into the RIC ecosystem through attestation modules and agents. Experimental results showed that this runtime attestation could be performed with latencies under forty milliseconds across various cryptographic hash functions. This suggests that verifying the state of network applications can happen without disrupting time-sensitive operations on the Near-RT RIC platform.

The most critical finding relates to the hybrid framework for automated security annotation generation because it directly addresses the manual, error-prone bottleneck in creating accurate security annotations for business process models. This system combines large language model semantic extraction with schema-constrained mapping and rule-based normalization to produce structurally valid SecBPMN2 annotations. This method achieved substantially higher precision compared to human analysts while maintaining comparable recall, and it reduced erroneous annotations by nearly fifty percent, which means the framework is a reliable tool for scaling security-by-design modeling.

The agentic AI research on re-identification presents a significant threat because it demonstrates that large language model agents can autonomously search the open web and cross-reference public records to resolve raw coordinate sequences into candidate identities without human intervention. This pipeline successfully re-identified seventy two percent of individuals in simulated scenarios, which suggests that de facto anonymity is shifting under current standards and requires immediate attention from data custodians.

Speed Kills explores a critical security risk involving AI accelerators because it shows that confused deputy attacks are feasible on six out of seven different AIAs, impacting over one hundred million devices. This means specialized hardware used for AI inference can be tricked into performing privileged operations, and the proposed LLM-assisted framework for extracting this information suggests a path toward on-demand validation defenses with low runtime overhead.

The work on Hermes Seal is important because it introduces zero-knowledge proofs using zk-SNARKs to enable privacy-preserving, verifiable communication in autonomous vehicle networks. This allows systems to prove computations are correct without revealing proprietary data, achieving proof generation times of eight milliseconds and verification times of one millisecond on a GPU.

The research into Proof-of-Authorship for diffusion models is relevant because it proposes binding the random seed used during latent diffusion model generation to an author's identity via cryptographic functions. This provides a stronger guarantee of authorship than time-stamping, suggesting a novel way to assert creation rights in the context of AI-generated content.

Finally, the energy-aware framework for solving post-quantum control plane bottlenecks is significant because it uses an Open RAN split to intelligently schedule post-quantum cryptography handshakes. This scheduling reduces per handshake energy by approximately sixty percent while still meeting latency targets, offering a sustainable way to implement quantum resilience in network infrastructure.

Today's papers

The papers

Important terms

Domain Specific Post Quantum Signatures
These are specialized digital signatures for blockchains that go beyond simple single-signer authentication to handle complex needs like rejecting invalid inputs or using stable transaction IDs.
Pattern-Level Differential Privacy
This method dynamically adjusts noise on data streams to provide privacy guarantees at the level of event patterns, improving data utility while maintaining strong privacy against various trust settings.
Prefix Puncturable Signatures
This cryptographic technique allows for efficient key updates by enabling a key to be 'punctured' relative to a target prefix, giving fine-grained control over which messages are signed.
Dual-Locking Method for Neural Networks
This technique secures trained models by combining key-driven index permutation with PIN-based watermarking, allowing the network to function while binding its bias coefficients to a secret key.