Security papers — 2026-09-23

Today we are looking at how we can make randomized encodings much stronger for solving promise problems. This is important because it directly impacts the security of zero-knowledge proofs. The core idea is that if you have a one-sided randomized encoding with good privacy and correctness, you can use it to amplify the privacy and correctness of other problems.

This amplification means that even if your initial encoding has some imperfections in privacy or error, you can distill it down to something nearly perfect. This leads directly to showing that NISZK, which deals with non-interactive zero-knowledge proofs, has strong zero-knowledge amplification. This is a big deal because it solves an open problem dating back to Goldreich, Sahai, and Vadhan from nineteen ninety nine regarding the strength of these proofs.

Furthermore, having a perfect one-sided encoding for a problem implies the existence of one-way functions or quantum one-way state generators. This connects this work to fundamental cryptographic primitives.

We also touched on how weak and imperfect indistinguishability obfuscation implies one-way functions under certain conditions related to the polynomial hierarchy. This shows that even slightly flawed obfuscation can still provide some level of security against breaking things. This idea is connected to how we study randomized encodings through the lens of lossy reductions, which is a way of looking at these encodings that might be useful in other areas.

The structural concentration of eBPF vulnerabilities is what matters most because it tells us where to focus our defensive efforts. The observed weaknesses are not scattered randomly but cluster around specific system-level failures like runtime execution and concurrency issues. This means that while we see raw coverage across different parts of the eBPF pipeline, the real danger lies in these dominant areas.

The most significant findings point to runtime execution as the primary exposure surface for eBPF, followed by issues related to concurrency and object lifecycle management within trusted stages of the framework. While failures in the Verifier and JIT components are less frequent, they represent structurally distinct security boundaries that still warrant attention.

A case study using Syzkaller on Linux version five point ten demonstrated that even with visible coverage across all three areas, effective exploration remains semantically narrow. Discoveries were concentrated within a small subset of runtime failures. This suggests that simply measuring raw coverage is an incomplete way to assess discovery effectiveness in this space.

The most critical finding relates to how encoding affects a model's ability to refuse harmful requests without discriminating between them. This matters because it shows that simply looking at one side of safety performance can be very misleading if the input is obfuscated. When prompts were encoded with homoglyphs, the gap between refusing harmful and benign requests on one model completely vanished. Both types of prompts were refused at a near identical rate.

This effect was much stronger than what sampling noise alone could cause. Sampling noise only produced a difference of about 0.10 across four different small models. This suggests that the encoding itself is not just hiding the harmful content but is fundamentally changing how the model processes the request for refusal, which is a more significant issue than just whether it complies with harm.

We also saw that attempting to fix this using a standard sequence of fine-tuning methods did not help. Plaintext discrimination improved while the encoding-induced loss remained stubbornly high. This points toward an underlying structural issue in how these models are trained regarding refusal behavior, which is something we still need to understand deeply.

The work on attack tree distance is crucial because it provides a systematic way to compare different threat models. This is necessary when we are trying to validate or build upon existing security analyses. We found that applying semantic similarity when comparing node labels is a valid way to measure label distance. Furthermore, four of the five proposed distance measures turn out to be effective in various situations.

This suggests that these methods can already help us identify similar real-world attack trees. This is a big step for improving threat model analysis and even for validating AI-generated attack trees.

The CPyGraph framework addresses the challenge of static analysis in Python packages by creating a version-aware foundation that handles changes in native CPython bytecode across releases. It achieves this by using version-specific adapters to expose semantics through a shared interface while keeping code-object identities intact. This allows its operand-stack-aware Andersen points to analysis to grow together toward a fixed point.

This framework has shown strong performance, reaching 91.40% candidate precision and 100% recall on CPython 3.10 for package programs. It also maintains high agreement with other tools across multiple Python versions.

GuidedRay tackles the difficulty of finding adversarial directions in targeted black-box attacks against deep neural networks by using diversity-guided direction discovery. This method leverages target-class reference samples to create prior knowledge for directions and then screens varied candidates using a one-query fast test before applying Ray Search to refine the decision boundary radius.

Experiments across CIFAR-10, CIFAR-100, and ImageNet showed that GuidedRay consistently outperformed five state-of-the-art decision-based attacks. This was especially true in the crucial initialization phase of direction discovery.

Differential fault analysis of Lilliput demonstrates that even when an attacker cannot control the exact location of a random nibble fault, they can still identify it with high accuracy using a DDT-based combinatorial estimate. By determining the faulty branch and classifying its propagation patterns, researchers achieved key-recovery success rates exceeding 90% in simulations involving multiple faulty ciphertexts.

SLED-IFV introduces a solver-validated LLM-guided flow to tackle the scaling issues in formal hardware information-flow verification by using semantic proof decomposition forms. This system automates the selection of these forms and targets, achieving up to a 603 times speedup over solver-only methods on real RTL benchmarks. The closed-loop flow successfully produces verifier-accepted decompositions for all tested cases.

The most critical work right now involves understanding how label noise affects predictions for app removals in Google Play. This matters because inaccurate predictions can lead to incorrect moderation decisions. We tested three different methods—Isolation Forest, Neighborhood Disagreement, and Prediction Inconsistency—on a large set of apps from Mohsen et al.

We found that the overlap among them flagged 7,598 candidates as the strongest mislabeling possibilities at default settings. This overlap analysis is important because it points to a small group of apps where our detection methods strongly disagreed. These are suggested to be the most confused labels we have.

However, removing these flagged apps did not improve the model's performance in any way; the loss actually increased as more were removed. Furthermore, we observed that these flagged apps appeared less often than expected among those confirmed by VirusTotal or Quark Engine to be actual removals. This is a key piece of context for understanding where the noise lies.

The findings suggest that these flagged apps exhibit contradictory behavior: abandoned applications resembling spam are stable, while healthy-looking apps are predicted as removed. This characterization of label noise is the main takeaway from this comparison.

This contrasts with other work that focuses on establishing formal guarantees for cryptographic functions. That work deals with ensuring security properties hold under different key generation scenarios through certifiable keys and zero-knowledge arguments of knowledge.

The most critical development this week involves the controlled post-alert incident orchestration subsystem designed for educational information systems. This system establishes a verifiable framework for handling alerts in a structured manner. It separates the decision-making process into distinct stages, using a rule engine to determine severity and select the appropriate playbook before advisory content is provided by a local large language model under various safety controls.

The rule engine successfully matched all thirty boundary cases defined in its routing matrix. This means it correctly identified how to handle every possible alert scenario within the lab scope. Furthermore, the durable queue proved robust, completing one hundred events without any duplicate tasks or unintended firewall rules being created. This controlled execution resulted in an overall mean post-alert processing time of about thirty-three seconds across thirty sequential measurements.

This work connects to the broader theme of integrating large language models into safety-critical systems. The orchestration subsystem relies on a local LLM for advisory content, which touches upon the concerns raised in research regarding security and privacy in mobility applications where LLMs are increasingly deployed. While this specific study focuses on functional correctness and bounded model integration within its laboratory setting, it highlights the need for rigorous control when deploying such models.

The work on automatic re-identification of BLE devices is significant because it shows that even when devices change their MAC addresses through randomisation, the advertising layer still carries enough information to track them using machine learning. This means we can move beyond manual rule creation to automate device linkage without needing specific knowledge of the underlying technology.

This approach works by characterizing how advertising features persist across different RPA changes and then framing device linkage as a supervised classification problem. Using simple decision tree classifiers as a proof-of-feasibility, the researchers evaluated how well they could distinguish target devices from non-target ones despite varying address rotation patterns. This suggests that advertising metadata remains a viable tool for tracking.

This connects to the work on neural fingerprints for malware analysis because both rely on extracting meaningful, fixed representations from complex data to perform classification. The neural fingerprinting method learns fixed-length embeddings from malware images so that new families can be recognized zero-shot by comparing them in embedding space. This learned similarity metric is shown to transfer across different datasets.

Another area of interest is how AI agents interact with deception, as seen in the Rouxii framework which shows that an autonomous attacker equipped to recognize honeypot fingerprints can achieve very high detection rates against deceptions. This finding is important because the effectiveness of deception depends entirely on whether the adversary understands and actively exploits the deception layer. This relates to how policy-backed frameworks like ESC-CR try to manage agent communication securely.

The work that matters most is the formalization of a model connecting defense-in-depth theory with artificial intelligence pattern recognition and human-AI collaboration. This gives us a testable way to design better security operations centers. This model suggests that AI augmentation gains are maximized exactly where traditional layering saturates. This is crucial for optimizing resource allocation in SOCs.

The core idea involves formalizing layered defense as a Bernoulli detection cascade where AI augmentation multiplies across layers. Each layer's pattern recognition behavior is treated as a Neyman-Pearson or Bayesian detector with an optimal threshold derived from that framework. This structure shows how the compounding effect of AI augmentation delivers its largest marginal gains precisely when traditional layering hits its limit.

This is supported by simulations showing that full human review of AI-flagged alerts is not optimal. Increasing analyst capacity to reach one hundred percent coverage cuts false alarms by roughly twenty times but simultaneously lowers the overall system detection probability due to imperfect analyst accuracy being applied broadly. This finding provides a concrete design target for an interior-optimum capacity ratio in security operations centers.

This concept of balanced human-AI collaboration is further informed by work on jailbreak probability. This quantifies the likelihood that a multimodal large language model will generate a malicious response given an input. This allows for nuanced distinctions beyond simple success or failure classification, informing how we might design more robust AI systems.

The study on network intrusion detection rules shows that rule engineering is characterized by three distinct phases and a common pattern in the process. This suggests that less experienced engineers can produce rules comparable to experts, which impacts how we expect engineer expertise to influence rule quality. This observation highlights the need for sufficient labeled data when attempting to generalize detection rules beyond available tests.

Finally, the throughput-oriented analytical model for post-quantum security protocols provides a tight upper bound on sustainable connection establishment rates in TLS and SSH by decomposing handshake time into cryptographic operation and network transmission components. This model demonstrates how integrating post-quantum cryptography can be leveraged to enable efficient resource allocation among multiple endpoints in network environments.

Today's papers

The papers

Important terms

Randomized Encodings
These are mathematical encodings used to make randomized cryptographic schemes stronger, especially for zero-knowledge proofs. The goal is to amplify privacy and correctness, distilling imperfect initial encodings into nearly perfect ones.
NISZK Amplification
This refers to the strong zero-knowledge amplification achieved in non-interactive zero-knowledge proofs. It solves a long-standing open problem regarding the inherent strength of these types of proofs.
eBPF Vulnerability Surface
This identifies that eBPF security weaknesses are not random but cluster around runtime execution and concurrency issues. Focusing on these dominant areas is key for effective defensive efforts.
Encoding-Induced Loss
This describes a significant finding where encoding itself fundamentally changes how a model refuses harmful requests, showing it's more impactful than simple sampling noise.