Security papers — 2026-09-23
Today we are looking at how we can make randomized encodings much stronger for solving promise problems. This is important because it directly impacts the security of zero-knowledge proofs. The core idea is that if you have a one-sided randomized encoding with good privacy and correctness, you can use it to amplify the privacy and correctness of other problems.
This amplification means that even if your initial encoding has some imperfections in privacy or error, you can distill it down to something nearly perfect. This leads directly to showing that NISZK, which deals with non-interactive zero-knowledge proofs, has strong zero-knowledge amplification. This is a big deal because it solves an open problem dating back to Goldreich, Sahai, and Vadhan from nineteen ninety nine regarding the strength of these proofs.
Furthermore, having a perfect one-sided encoding for a problem implies the existence of one-way functions or quantum one-way state generators. This connects this work to fundamental cryptographic primitives.
We also touched on how weak and imperfect indistinguishability obfuscation implies one-way functions under certain conditions related to the polynomial hierarchy. This shows that even slightly flawed obfuscation can still provide some level of security against breaking things. This idea is connected to how we study randomized encodings through the lens of lossy reductions, which is a way of looking at these encodings that might be useful in other areas.
The structural concentration of eBPF vulnerabilities is what matters most because it tells us where to focus our defensive efforts. The observed weaknesses are not scattered randomly but cluster around specific system-level failures like runtime execution and concurrency issues. This means that while we see raw coverage across different parts of the eBPF pipeline, the real danger lies in these dominant areas.
The most significant findings point to runtime execution as the primary exposure surface for eBPF, followed by issues related to concurrency and object lifecycle management within trusted stages of the framework. While failures in the Verifier and JIT components are less frequent, they represent structurally distinct security boundaries that still warrant attention.
A case study using Syzkaller on Linux version five point ten demonstrated that even with visible coverage across all three areas, effective exploration remains semantically narrow. Discoveries were concentrated within a small subset of runtime failures. This suggests that simply measuring raw coverage is an incomplete way to assess discovery effectiveness in this space.
The most critical finding relates to how encoding affects a model's ability to refuse harmful requests without discriminating between them. This matters because it shows that simply looking at one side of safety performance can be very misleading if the input is obfuscated. When prompts were encoded with homoglyphs, the gap between refusing harmful and benign requests on one model completely vanished. Both types of prompts were refused at a near identical rate.
This effect was much stronger than what sampling noise alone could cause. Sampling noise only produced a difference of about 0.10 across four different small models. This suggests that the encoding itself is not just hiding the harmful content but is fundamentally changing how the model processes the request for refusal, which is a more significant issue than just whether it complies with harm.
We also saw that attempting to fix this using a standard sequence of fine-tuning methods did not help. Plaintext discrimination improved while the encoding-induced loss remained stubbornly high. This points toward an underlying structural issue in how these models are trained regarding refusal behavior, which is something we still need to understand deeply.
The work on attack tree distance is crucial because it provides a systematic way to compare different threat models. This is necessary when we are trying to validate or build upon existing security analyses. We found that applying semantic similarity when comparing node labels is a valid way to measure label distance. Furthermore, four of the five proposed distance measures turn out to be effective in various situations.
This suggests that these methods can already help us identify similar real-world attack trees. This is a big step for improving threat model analysis and even for validating AI-generated attack trees.
The CPyGraph framework addresses the challenge of static analysis in Python packages by creating a version-aware foundation that handles changes in native CPython bytecode across releases. It achieves this by using version-specific adapters to expose semantics through a shared interface while keeping code-object identities intact. This allows its operand-stack-aware Andersen points to analysis to grow together toward a fixed point.
This framework has shown strong performance, reaching 91.40% candidate precision and 100% recall on CPython 3.10 for package programs. It also maintains high agreement with other tools across multiple Python versions.
GuidedRay tackles the difficulty of finding adversarial directions in targeted black-box attacks against deep neural networks by using diversity-guided direction discovery. This method leverages target-class reference samples to create prior knowledge for directions and then screens varied candidates using a one-query fast test before applying Ray Search to refine the decision boundary radius.
Experiments across CIFAR-10, CIFAR-100, and ImageNet showed that GuidedRay consistently outperformed five state-of-the-art decision-based attacks. This was especially true in the crucial initialization phase of direction discovery.
Differential fault analysis of Lilliput demonstrates that even when an attacker cannot control the exact location of a random nibble fault, they can still identify it with high accuracy using a DDT-based combinatorial estimate. By determining the faulty branch and classifying its propagation patterns, researchers achieved key-recovery success rates exceeding 90% in simulations involving multiple faulty ciphertexts.
SLED-IFV introduces a solver-validated LLM-guided flow to tackle the scaling issues in formal hardware information-flow verification by using semantic proof decomposition forms. This system automates the selection of these forms and targets, achieving up to a 603 times speedup over solver-only methods on real RTL benchmarks. The closed-loop flow successfully produces verifier-accepted decompositions for all tested cases.
The most critical work right now involves understanding how label noise affects predictions for app removals in Google Play. This matters because inaccurate predictions can lead to incorrect moderation decisions. We tested three different methods—Isolation Forest, Neighborhood Disagreement, and Prediction Inconsistency—on a large set of apps from Mohsen et al.
We found that the overlap among them flagged 7,598 candidates as the strongest mislabeling possibilities at default settings. This overlap analysis is important because it points to a small group of apps where our detection methods strongly disagreed. These are suggested to be the most confused labels we have.
However, removing these flagged apps did not improve the model's performance in any way; the loss actually increased as more were removed. Furthermore, we observed that these flagged apps appeared less often than expected among those confirmed by VirusTotal or Quark Engine to be actual removals. This is a key piece of context for understanding where the noise lies.
The findings suggest that these flagged apps exhibit contradictory behavior: abandoned applications resembling spam are stable, while healthy-looking apps are predicted as removed. This characterization of label noise is the main takeaway from this comparison.
This contrasts with other work that focuses on establishing formal guarantees for cryptographic functions. That work deals with ensuring security properties hold under different key generation scenarios through certifiable keys and zero-knowledge arguments of knowledge.
The most critical development this week involves the controlled post-alert incident orchestration subsystem designed for educational information systems. This system establishes a verifiable framework for handling alerts in a structured manner. It separates the decision-making process into distinct stages, using a rule engine to determine severity and select the appropriate playbook before advisory content is provided by a local large language model under various safety controls.
The rule engine successfully matched all thirty boundary cases defined in its routing matrix. This means it correctly identified how to handle every possible alert scenario within the lab scope. Furthermore, the durable queue proved robust, completing one hundred events without any duplicate tasks or unintended firewall rules being created. This controlled execution resulted in an overall mean post-alert processing time of about thirty-three seconds across thirty sequential measurements.
This work connects to the broader theme of integrating large language models into safety-critical systems. The orchestration subsystem relies on a local LLM for advisory content, which touches upon the concerns raised in research regarding security and privacy in mobility applications where LLMs are increasingly deployed. While this specific study focuses on functional correctness and bounded model integration within its laboratory setting, it highlights the need for rigorous control when deploying such models.
The work on automatic re-identification of BLE devices is significant because it shows that even when devices change their MAC addresses through randomisation, the advertising layer still carries enough information to track them using machine learning. This means we can move beyond manual rule creation to automate device linkage without needing specific knowledge of the underlying technology.
This approach works by characterizing how advertising features persist across different RPA changes and then framing device linkage as a supervised classification problem. Using simple decision tree classifiers as a proof-of-feasibility, the researchers evaluated how well they could distinguish target devices from non-target ones despite varying address rotation patterns. This suggests that advertising metadata remains a viable tool for tracking.
This connects to the work on neural fingerprints for malware analysis because both rely on extracting meaningful, fixed representations from complex data to perform classification. The neural fingerprinting method learns fixed-length embeddings from malware images so that new families can be recognized zero-shot by comparing them in embedding space. This learned similarity metric is shown to transfer across different datasets.
Another area of interest is how AI agents interact with deception, as seen in the Rouxii framework which shows that an autonomous attacker equipped to recognize honeypot fingerprints can achieve very high detection rates against deceptions. This finding is important because the effectiveness of deception depends entirely on whether the adversary understands and actively exploits the deception layer. This relates to how policy-backed frameworks like ESC-CR try to manage agent communication securely.
The work that matters most is the formalization of a model connecting defense-in-depth theory with artificial intelligence pattern recognition and human-AI collaboration. This gives us a testable way to design better security operations centers. This model suggests that AI augmentation gains are maximized exactly where traditional layering saturates. This is crucial for optimizing resource allocation in SOCs.
The core idea involves formalizing layered defense as a Bernoulli detection cascade where AI augmentation multiplies across layers. Each layer's pattern recognition behavior is treated as a Neyman-Pearson or Bayesian detector with an optimal threshold derived from that framework. This structure shows how the compounding effect of AI augmentation delivers its largest marginal gains precisely when traditional layering hits its limit.
This is supported by simulations showing that full human review of AI-flagged alerts is not optimal. Increasing analyst capacity to reach one hundred percent coverage cuts false alarms by roughly twenty times but simultaneously lowers the overall system detection probability due to imperfect analyst accuracy being applied broadly. This finding provides a concrete design target for an interior-optimum capacity ratio in security operations centers.
This concept of balanced human-AI collaboration is further informed by work on jailbreak probability. This quantifies the likelihood that a multimodal large language model will generate a malicious response given an input. This allows for nuanced distinctions beyond simple success or failure classification, informing how we might design more robust AI systems.
The study on network intrusion detection rules shows that rule engineering is characterized by three distinct phases and a common pattern in the process. This suggests that less experienced engineers can produce rules comparable to experts, which impacts how we expect engineer expertise to influence rule quality. This observation highlights the need for sufficient labeled data when attempting to generalize detection rules beyond available tests.
Finally, the throughput-oriented analytical model for post-quantum security protocols provides a tight upper bound on sustainable connection establishment rates in TLS and SSH by decomposing handshake time into cryptographic operation and network transmission components. This model demonstrates how integrating post-quantum cryptography can be leveraged to enable efficient resource allocation among multiple endpoints in network environments.
Today's papers
- Amplifying Randomized Encodings & Applications A randomized encoding for a promise problem is a randomized reduction whose outcome distribution on input x can be simulated within some distance d, called privacy, using only one bit of information about x: whether it is a YES or NO instance. [paper] [episode]
- TriHaRd: Higher Resilience for TEE Trusted Time Accurately measuring time passing is critical for many applications. However, in Trusted Execution Environments (TEEs) such as Intel SGX, the time source is outside the Trusted Computing Base: a malicious host can manipulate the TEE's notion of time, jumping in time or affecting perceived time speed. [paper] [episode]
- WiP: Towards a Secure SECP256K1 for Crypto Wallets Hardware architecture and implementation. [paper] [episode]
- SSP-Bench: A Hybrid Data Generation Framework for Safety, Security, and Privacy Evaluation Evaluation of large language models (LLMs) for safety, security, and privacy (SSP) relies heavily on static benchmarks, which suffer from score saturation, data contamination, and aggregation artifacts. [paper]
- Towards Effective Black-Box Adversarial Attacks on Deep Code Models via Structural and Identifier Perturbations Deep code models are increasingly embedded in code intelligence tasks. However, their robustness under adversarial attacks remains insufficiently understood. [paper]
- From Bilinear to Linear: Differentially Private Federated LoRA via Low-Dimensional Parameterization Federated Low-Rank Adaptation (LoRA) remains vulnerable to privacy leakage through transmitted model updates. [paper]
- UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services A single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). However, SSO introduces privacy threats, as (a) a curious IdP could track a user's all visits to RPs, and (b) colluding RPs could learn a user's online profile by linking her identities across these RPs. [paper] [episode]
- Dynamic Deep Prompt Optimization for Defending Against Jailbreak Attacks on LLMs Large Language Models (LLMs) demonstrate impressive capabilities across many applications but remain vulnerable to jailbreak attacks, which elicit harmful or unintended content. [paper]
- eBPF Security in the Wild: Structural Concentration, Failure Mechanisms, and Discovery Gaps Extended Berkeley Packet Filter (eBPF) is a security-critical in-kernel execution framework, yet its vulnerability landscape remains fragmented across components, semantic gaps, and testing techniques. [paper]
- Image-Based Techniques and Ensemble Soft Voting for Malware Classification In this chapter we investigate image-based malware family classification using an ensemble learning framework and a soft voting strategy. [paper]
- Unread or Unenforced? Separating Representation from Enforcement Failure in Content Guards When an encoded attack passes a content guard, the guard either never represented the payload's harmful content or represented it and failed to act. [paper]
- The Uncontrolled Variable: Vision-Language Model Refusal Responds to Image Presence in Ways Risk Cannot Explain Vision-Language Model (VLM) safety is expected to depend on what a request asks for.
- Zeta-Transform Evaluation for Higher-Order Vanishing Key Recovery Hemmert's key-recovery algorithm for Classic McEliece is based on higher-order vanishing. [paper]
- A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. [paper]
- Beyond Classification Accuracy: Quantifying Fingerprint Complexity in Encrypted Darknet Services Existing darknet traffic studies primarily evaluate service fingerprintability through classification performance, providing limited insight into why certain services are easier or harder to identify. [paper]
- Not All 4-bit Quantizers Are Equal: Deployment-Time Mitigation of PII Leakage in Fine-Tuned Small Language Models Organizations fine-tune small language models on private data and then compress them to 4 bits for resource-efficient deployment. [paper]
- Refusal without Discrimination: What Encoded Prompts Do to Safety-Trained Models Encoded-prompt attacks are evaluated almost entirely on their harmful arm: a benchmark sends obfuscated harmful requests and reports how often the model complied.
- Data Provenance Auditing of Fine-Tuned Large Language Models with a Text-Preserving Technique We propose a system for marking sensitive or copyrighted texts to detect their use in fine-tuning large language models under black-box access with statistical guarantees. [paper]
- A Lyra2 FPGA Core for Lyra2REv2-Based Cryptocurrencies This work presents the first FPGA implementation of the specific instance of Lyra2 that is used in Lyra2REv2. [paper]
- Benchmarking Neural Defend ARCAS 1B: A Foundational Multimodal Deepfake Detection Model AI-generated imagery evolves faster than benchmark-specific detector evaluations, making a single score an incomplete account of generalization. [paper]
- The Challenge of Identifying the Origin of Black-Box Large Language Models The tremendous commercial potential of large language models (LLMs) has heightened concerns over their unauthorized use. To address this, we focus on the task of identifying the origin of black-box LLMs. [paper]
- Rethinking Backdoor Repair Evaluation: Distinguishing Aggregate Clean Utility from Benign Performance Preservation Backdoor repair aims to suppress malicious behavior in compromised models while preserving benign task performance. [paper]
- Who Assures the Verifier? An Executable Assurance-Locus Audit of the European Digital Identity Wallet The European Digital Identity Wallet (EUDI Wallet) architecture places material duties on relying parties: they register services and intended uses, authenticate to Wallet Units, validate presentations and trust anchors, and make risk-based status decisions. [paper]
- Real Money, Fake Models: Deceptive Model Claims in Shadow APIs Access to frontier large language models (LLMs), such as GPT-5 and Gemini-2.5, is often hindered by high pricing, payment barriers, and regional restrictions. These limitations drive the proliferation of shadow APIs, third-party services that claim to provide access to official model services without regional limitations via indirect access. [paper]
- Attack Tree Distance: a practical examination of tree difference measurement within cyber security Attack trees are a popular threat modeling method. In practice, there is often a need to compare attack tree models produced by human experts, based on both the structure of the tree and the meaning of the node labels. [paper]
- CPyGraph: A Version-Aware Static Analysis Framework for Native CPython Bytecode Static analysis of Python packages must recover both program structure and object flow across first-class functions, dynamic dispatch, implicit protocol calls, exceptions, closures, and module execution. [paper]
- GuidedRay: Diversity-Guided Direction Discovery for Targeted Hard-Label Black-Box Attacks Deep neural networks are vulnerable to adversarial attacks. Among black-box attacks, targeted decision-based attacks are particularly difficult: the attacker observes only the target model's top-1 label and aims to make it predict a prespecified target class under a bounded perturbation. [paper]
- Differential Fault Analysis of Lilliput under Random-Location Nibble Faults Differential fault analysis (DFA) is an important technique for evaluating the implementation-level security of block ciphers. [paper]
- SLED-IFV: Solver-Validated LLM-Guided Decomposition for Scalable Hardware Information-Flow Verification Formal hardware information-flow verification (IFV) provides strong guarantees against secret-dependent timing and control behavior, but often scales poorly on realistic RTL. [paper]
- LoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models Users commonly combine multiple Low-Rank Adaptation (LoRA) adapters to personalize images with different subjects, styles, and visual attributes. Yet inspecting adapters individually does not establish the safety of their composition. [paper]
- LLM Ghostbusters: Surgical Package Hallucination Suppression via Adaptive Unlearning Hallucinations remain an unsolved problem for LLMs, and package hallucinations are a particularly dangerous instance of this phenomenon. [paper]
- Staged Multi-step UTXO Workflows via Recursive Invariants Stateless UTXO-style execution validates transactions using local and referenced data, enabling parallel validation and predictable serialized-size/weight accounting. [paper]
- Identifying Suspected Mislabeled Apps in Google Play Application Removal Prediction: An Empirical Comparison of Label Noise Detection Methods Models that predict which Google Play apps will be removed are trained on labels that record only whether an app was still in the store at a later observation. [paper]
- On the Construction of Trapdoor Claw-Free Functions with Certifiable Key Trapdoor claw-free functions (TCFs) underpin much of classical-quantum cryptographic interaction, yet every TCF-based protocol states its guarantees relative to an honestly generated key. [paper]
- Formally Modeling the Terrapin Attack on SSH The Terrapin attack against SSH channel integrity (USENIX Security 2024) used a novel attack vector: attacks on the channel state. [paper]
- Attack Success Rate Is Not a Number: On Measurement Validity in Agentic AI Security Evaluation Attack success rate (ASR) is the headline metric in nearly every published evaluation of attacks on, and defenses for, LLM agents. [paper]
- Adaptive Traffic Camouflage: Causal and Resource-Aware Defense Against IoT Fingerprinting Encryption hides IoT payloads, but traffic shape can still reveal device identity through packet sizes, timing, direction, and packetization. [paper]
- Partition-Matched Evaluation of Community Features under Distribution Shift in Android Malware Function-Call Graphs Graph-based Android malware classifiers can lose accuracy under malware-type or family shifts. [paper]
- When Good Verifiers Go Bad: Silent Negative Transfer in Verifier-Guided VLM Training Verifier reliability is not portable across tasks. A verifier-guided self-DPO pipeline with genuine held-out gains on MathVista (+9.6 points on self-training data, +8.0 held out) can be harmful on MMMU. [paper]
- From Alignment to Access Control: A Framework for GenAI Policy Enforcement Generative AI (GenAI) applications have flourished enabling users to chat with large language models, and to create agents to act on their behalf for a variety of tasks. [paper]
- Design and Evaluation of a Controlled Post-Alert Incident Orchestration and Response Subsystem Using a Rule Engine and a Local Large Language Model This paper presents a controlled post-alert incident orchestration and response subsystem for educational information systems. [paper]
- FASTAR: FRI Accelerator for Scalable Transparent ARguments of Knowledge Zero-Knowledge Proofs (ZKPs) enable a prover to cryptographically convince a verifier of the validity of a statement without revealing any underlying secrets, forming a foundational primitive for verifiable computation. [paper]
- C-to-Rust Fallacy: Automatic Refactoring != Memory Security Rust has emerged as the leading system programming language, offering strong memory and type safety guarantees without compromising performance. [paper]
- COBRA: A Content-Agnostic Framework for Zero-Day Detection of Suspicious Domains The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions. Because domains are inexpensive to register and easy to deploy at scale, they remain one of the most common and damaging tools used in cybercrime across industries. [paper]
- IndirectAD: Practical Data Poisoning Attacks against Recommender Systems for Item Promotion Recommender systems play a central role in digital platforms by providing personalized content. They often use methods such as collaborative filtering and machine learning to accurately predict user preferences. [paper]
- HYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning Concept drift, driven by the rapid evolution of Android malware, severely degrades the performance of machine learning detectors. Current adaptation strategies are often reactive, responding only after performance has dropped and imposing a significant manual annotation burden, or they are proactive but rely on unstable adversarial training and incomplete, single-level graph representations. [paper]
- Controller-Only False Confirmation in Passive RF UAV Link Detection Passive radio frequency (RF) sensing is widely used for counter-unmanned-aerial-vehicle (counter-UAV) detection. Existing studies commonly report high accuracy against background RF or WiFi/Bluetooth interference, but rarely isolate controller-only operation without a linked aircraft. [paper]
- On the security and privacy of LLMs in Mobility The mobility sector is undergoing a paradigm shift driven by advances in Generative Artificial Intelligence. With a global market valued at approximately 2.9 trillion dollars annually, considering only cars, the integration of these technologies has the potential to impact more than 1.5 billion vehicles worldwide. [paper]
- Learning to Link: Automatic Re-identification of BLE Devices Under MAC Address Randomisation Bluetooth Low Energy (BLE) employs MAC address randomisation -- via Resolvable Private Address (RPA) -- to mitigate long-term device tracking on public advertising channels. [paper]
- Rouxii: Exploiting Honeypots with Deception-Aware AI Pentesters Honeypots are designed to deceive attackers, and recent work shows they can also derail autonomous LLM-based pentesters. These evaluations, however, largely consider attackers unaware of the deception they face. [paper]
- A Standalone FPGA-based Miner for Lyra2REv2 Cryptocurrencies Lyra2REv2 is a hashing algorithm that consists of a chain of individual hashing algorithms, and it is used as a proof-of-work function in several cryptocurrencies. [paper] [episode]
- Neural Fingerprints for Malware Analysis: An Image-Based Metric Learning Approach with Application to Cross-Domain Classification Identifying the family of a newly observed malware sample is a core task in threat intelligence, yet conventional classifiers must be retrained whenever a new family appears. [paper]
- The Uncontrolled Variable: Vision-Language Model Refusal Responds to Image Presence in Ways Risk Cannot Explain Vision-Language Model (VLM) safety is expected to depend on what a request asks for.
- Policy-Backed Selective Regeneration under Tainted Inter-Agent Communication Inter-agent communication is essential to multi-agent language-model systems, yet a single message may combine task-critical information with instructions not authorized by the original request. [paper]
- A Cross-Dataset based Zero-Day Intrusion Detection System by Integrating Siamese Network and Reinforcement Learning A cross-Dataset based Zero-Day Intrusion Detection System by Integrating Siamese Network and Reinforcement Learning is proposed as a hybrid zero-day intrusion detection system using Siamese network-based anomaly correlation and reinforcement learning-based adaptive defense. [paper]
- Quantum ROP: Using Quantum Algorithms for ROP Chain Selection in Exploit Construction This work explores one such direction: the application of quantum combinatorial optimization to Return-Oriented Programming (ROP) gadget selection for exploit construction. [paper]
- FinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming Existing safety benchmarks target general adversarial scenarios but miss finance-specific risks. Financial LLMs face regulatory compliance violations, fraud facilitation, and systemic trust erosion that require targeted evaluation. [paper]
- Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration This paper develops such a model connecting three constructs that recur across this literature: Defense-in-Depth Theory, the Artificial Intelligence Theory of Pattern Recognition, and human-AI collaboration in security operations. [paper]
- Probabilistic Modeling of Jailbreak on Multimodal LLMs: From Quantification to Application Recently, Multimodal Large Language Models (MLLMs) have demonstrated their superior ability in understanding multimodal content. However, they remain vulnerable to jailbreak attacks, which exploit weaknesses in their safety alignment to generate harmful responses. [paper]
- How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules Many Security Operations Centers rely on signature-based Network Intrusion Detection Systems like Suricata, yet detection rule engineering remains understudied. [paper]
The papers
- UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services — "Single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). [episode]
- A Standalone FPGA-based Miner for Lyra2REv2 Cryptocurrencies — This work presents "the first hardware implementation of the specific instance of Lyra2 that is used in Lyra2REv2" and "an FPGA-based hardware implementation of a standalone miner for Lyra2REv2 on a Xilinx Multi-Processor System on Chip." The authors state that "several propertie [episode]
- TriHaRd: Higher Resilience for TEE Trusted Time — "TriHaRd: Higher Resilience for TEE Trusted Time" proposes a "TEE-based trusted time protocol with high resilience against attacks manipulating enclave-perceived clock speeds and offsets." The paper identifies that in Trusted Execution Environments (TEEs) such as Intel SGX, "the [episode]
- Amplifying Randomized Encodings & Applications — Overview This paper investigates the fundamental connection between the existence of One-Way Functions (OWFs) and the existence of "lossy reductions." The authors bridge fine-grained complexity—specifically under the Exponential Time Hypothesis (ETH)—with foundational cryptog [episode]
- WiP: Towards a Secure SECP256K1 for Crypto Wallets: Hardware Architecture and Implementation — "The SECP256K1 elliptic curve algorithm is fundamental in cryptocurrency wallets for generating secure public keys from private keys, thereby ensuring the protection and ownership of blockchain-based digital assets. [episode]
- IndirectAD: Practical Data Poisoning Attacks against Recommender Systems for Item Promotion —
- Real Money, Fake Models: Deceptive Model Claims in Shadow APIs —
- Differential Fault Analysis of Lilliput under Random-Location Nibble Faults —
- A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle —
- LLM Ghostbusters: Surgical Package Hallucination Suppression via Adaptive Unlearning —
- When Good Verifiers Go Bad: Silent Negative Transfer in Verifier-Guided VLM Training —
- FinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming —
- Not All 4-bit Quantizers Are Equal: Deployment-Time Mitigation of PII Leakage in Fine-Tuned Small Language Models —
- CPyGraph: A Version-Aware Static Analysis Framework for Native CPython Bytecode —
- Benchmarking Neural Defend ARCAS 1B: A Foundational Multimodal Deepfake Detection Model —
- Attack Success Rate Is Not a Number: On Measurement Validity in Agentic AI Security Evaluation —
- Partition-Matched Evaluation of Community Features under Distribution Shift in Android Malware Function-Call Graphs —
- Controller-Only False Confirmation in Passive RF UAV Link Detection —
- SSP-Bench: A Hybrid Data Generation Framework for Safety, Security, and Privacy Evaluation —
- Quantum ROP: Using Quantum Algorithms for ROP Chain Selection in Exploit Construction —
- Identifying Suspected Mislabeled Apps in Google Play Application Removal Prediction: An Empirical Comparison of Label Noise Detection Methods —
- FASTAR: FRI Accelerator for Scalable Transparent ARguments of Knowledge —
- Rethinking Backdoor Repair Evaluation: Distinguishing Aggregate Clean Utility from Benign Performance Preservation —
- SLED-IFV: Solver-Validated LLM-Guided Decomposition for Scalable Hardware Information-Flow Verification —
- C-to-Rust Fallacy: Automatic Refactoring != Memory Security —
- GuidedRay: Diversity-Guided Direction Discovery for Targeted Hard-Label Black-Box Attacks —
- Adaptive Traffic Camouflage: Causal and Resource-Aware Defense Against IoT Fingerprinting —
- On the Construction of Trapdoor Claw-Free Functions with Certifiable Key —
- COBRA: A Content-Agnostic Framework for Zero-Day Detection of Suspicious Domains —
- LoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models —
- How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules —
- Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration —
- Policy-Backed Selective Regeneration under Tainted Inter-Agent Communication —
- Learning to Link: Automatic Re-identification of BLE Devices Under MAC Address Randomisation —
- From Bilinear to Linear: Differentially Private Federated LoRA via Low-Dimensional Parameterization —
- Beyond Classification Accuracy: Quantifying Fingerprint Complexity in Encrypted Darknet Services —
- A Cross-Dataset based Zero-Day Intrusion Detection System by Integrating Siamese Network and Reinforcement Learning —
- Zeta-Transform Evaluation for Higher-Order Vanishing Key Recovery —
- The Uncontrolled Variable: Vision-Language Refusal Is Conditioned on the Image-Attachment Interface, and Not Robust to Irrelevant Image Properties —
- Refusing Everything Looks Safe: Restoring the Benign Arm to Encoded-Prompt Evaluation —
- Unread or Unenforced? Separating Representation from Enforcement Failure in Content Guards —
- Dynamic Deep Prompt Optimization for Defending Against Jailbreak Attacks on LLMs —
- Who Assures the Verifier? An Executable Assurance-Locus Audit of the European Digital Identity Wallet —
- Quantum-Ready Secure WAN: A Risk Assessment and Migration Framework —
- Towards Effective Black-Box Adversarial Attacks on Deep Code Models via Structural and Identifier Perturbations —
- eBPF Security in the Wild: Structural Concentration, Failure Mechanisms, and Discovery Gaps —
- CRT-Decomposed-Protocols for CSIDH —
- Image-Based Techniques and Ensemble Soft Voting for Malware Classification —
- Neural Fingerprints for Malware Analysis: An Image-Based Metric Learning Approach with Application to Cross-Domain Classification —
- A Throughput-Oriented Analytical Model for Post-Quantum Security Protocols —
- On the security and privacy of LLMs in Mobility —
- Staged Multi-step UTXO Workflows via Recursive Invariants —
- Design and Evaluation of a Controlled Post-Alert Incident Orchestration and Response Subsystem Using a Rule Engine and a Local Large Language Model —
- HYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning —
- Formally Modeling the Terrapin Attack on SSH —
- Rouxii: Exploiting Honeypots with Deception-Aware AI Pentesters —
- Decoding the Legalese: A Scalable and Quantitative Framework for Analyzing Corporate Privacy Policies —
- From Alignment to Access Control: A Framework for GenAI Policy Enforcement —
- A Lyra2 FPGA Core for Lyra2REv2-Based Cryptocurrencies —
- A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem —
- Attack Tree Distance: a practical examination of tree difference measurement within cyber security —
- The Challenge of Identifying the Origin of Black-Box Large Language Models —
- Probabilistic Modeling of Jailbreak on Multimodal LLMs: From Quantification to Application —
- Data Provenance Auditing of Fine-Tuned Large Language Models with a Text-Preserving Technique —
Important terms
- Randomized Encodings
- These are mathematical encodings used to make randomized cryptographic schemes stronger, especially for zero-knowledge proofs. The goal is to amplify privacy and correctness, distilling imperfect initial encodings into nearly perfect ones.
- NISZK Amplification
- This refers to the strong zero-knowledge amplification achieved in non-interactive zero-knowledge proofs. It solves a long-standing open problem regarding the inherent strength of these types of proofs.
- eBPF Vulnerability Surface
- This identifies that eBPF security weaknesses are not random but cluster around runtime execution and concurrency issues. Focusing on these dominant areas is key for effective defensive efforts.
- Encoding-Induced Loss
- This describes a significant finding where encoding itself fundamentally changes how a model refuses harmful requests, showing it's more impactful than simple sampling noise.