Security papers — 2026-09-28

Today's work centers on the growing need to move beyond simple coding agents and build a more robust enterprise security brain capable of handling complex, agentic cloud investigations. As systems become more autonomous, the surface area for sophisticated attacks increases, demanding a higher level of intelligent defense than current tools provide.

Researchers looked at XPhysICS which attempts to ground threat detection in cross-physical domains specifically for industrial control systems security. This means trying to understand threats by looking at physical and digital layers together. Following that, JevAdvBench provides a benchmark and black-box attacks for reinforcement learning models used in making calibrated decisions. This is important because it tests how well these decision-making models perform under adversarial conditions.

Another piece of work examined Werracle, which focuses on sub-cent intra-block AI reflex oracles and flash-loan circuit breakers for EVM smart contracts. This relates to securing decentralized applications by introducing rapid responses to potential exploits in the blockchain environment. We also explored Can Pixels Alone Reveal Image Origin, looking at minimax limits and learnable interfaces for passive provenance in image analysis.

Finally, we touched upon subjects not authors regarding the authorship hazard in agentic dataspaces and LLM-aided categorization of security patches for critical memory bugs. These studies highlight the emerging challenges around attribution and automated vulnerability management in modern software development pipelines.

The most critical finding from the day concerns how input-layer starvation compromises intrusion detection systems in the Internet of Things, which is vital because it directly impacts the security of interconnected devices. Researchers investigated this by examining how pruning different layers within these detectors affects their ability to recognize malicious inputs.

One study showed that when specific layers are starved of necessary data, the overall performance of the detector drops significantly, suggesting that certain parts of the network are disproportionately important for accurate threat identification. This is less impactful than a finding from FeatMark, which demonstrated feature-level watermark protection against mimicry attacks using diffusion models.

FeatMark's work is significant because it introduces a way to protect features within data before they are processed by models, making it harder for attackers to create deceptive samples. Moving down the list of importance, there was research into prompt attack vulnerabilities when using open-source large language models from Automatic Speech Recognition to Automatic Speech Processing.

This prompt attack vulnerability study is important because it shows how easily users can manipulate the instructions given to these powerful models, which could lead to security bypasses if these models are used for detection tasks. Furthermore, work on weaponizing ground truth data poisoning attacks by exploiting misalignment between antivirus software and learning-based detectors highlights a major issue in training systems.

This data poisoning research is significant because it shows that an adversary can intentionally corrupt the training labels to trick the detector into misclassifying threats, which undermines the entire learning process. Finally, NanoZone provided insights into scalable memory protection for Arm CCA, which is important for securing hardware itself, though it seems less directly related to software detection mechanisms than the preceding studies.

The most important development today concerns the proposal for crypto bound identity verified capability tokens designed to coordinate distributed artificial intelligence agents. This work matters because it addresses the fundamental problem of securely managing and verifying what different AI agents can actually do when they are working together across a network.

We looked at how BenX manages resource sharing permutations for computational integrity, which is important because it tackles the issue of ensuring that shared computational resources are used in a way that maintains overall system trustworthiness. This feeds into AGATE, which proposes provenance based runtime defense against compositional attacks on large language model agents, meaning it tries to stop malicious combinations of agent actions from causing harm.

Then there is MetaPermit, which focuses on scalable and auditable access control for AI agents using LLM inferred meta-attributes, offering a way to manage permissions in complex agent environments. This contrasts with SADRA, which introduces a sound capability based access control system specifically for resource disaggregated architectures. These systems are all trying to build robust frameworks for controlling agent behavior and resource allocation in decentralized settings.

The most significant piece of work today involved the Peregrino project, which attempts to create a full-hardware accelerator for the complete Falcon post-quantum digital signature scheme. This matters because it directly addresses the need to implement quantum-resistant cryptography efficiently on resource-constrained edge devices.

This hardware acceleration work is built upon foundational cryptographic research, specifically leveraging the Falcon scheme's structure. The implementation details focus on optimizing the signing and verification processes for this specific algorithm to run faster than software solutions would allow. This optimization effort builds upon earlier work concerning verifiable randomness used in blockchain lottery systems, which provides a necessary layer of trust for any signature scheme deployed in a decentralized environment.

Another thread running concurrently is the development of an energy-aware agentic AI framework that anchors its operations on blockchain technology to secure software supply chains. This framework aims to ensure the integrity of software from creation through deployment by using blockchain for verification. This contrasts with the cryptographic focus of Peregrino, but both aim for robust security in different domains.

The research also touched upon context-aware functional modeling designed to detect third-party libraries on Android devices. This work uses modeling techniques to understand how applications function and can flag potentially malicious or unauthorized components within the system. This is a more application-specific security concern than the general cryptographic acceleration discussed earlier.

The most significant finding relates to how prefix count limits in card reissuance can boost the rate of first-hit discoveries. This suggests that imposing a cap on how many times a specific prefix can appear might actually help researchers find new things faster. This is important because it directly impacts the efficiency of discovery in this domain.

A related piece explored amplifying large language model inference costs using fragile tokens, which involves generating noncanonical tokens to increase computational expense during LLM use. This work touches on the practical limitations and resource demands of deploying advanced language models.

Another study looked at configuration versus conscience when examining large-scale empirical data regarding system prompts for LLMs. This investigation sought to understand how specific prompt settings influence the model's behavior in a broad context.

Furthermore, there is work focused on automated and traceable generation of MUD profiles by linking source code to network profiles for Internet of Things devices. This allows for detailed tracking of device characteristics from its underlying software structure.

Today's papers

The papers

Important terms

agentic cloud investigations
This refers to advanced security analysis needed for autonomous AI systems operating in the cloud, moving beyond simple coding agents to handle complex threat detection.
XPhysICS
A method for grounding threat detection by combining physical and digital layers, specifically targeting security challenges within industrial control systems.
JevAdvBench
A benchmark and adversarial attack tool used to test how well reinforcement learning models perform when making critical decisions under challenging conditions.
EVM smart contracts
These are decentralized applications running on the Ethereum Virtual Machine, which require security measures like flash-loan circuit breakers for rapid exploit response.
crypto bound identity verified capability tokens
A proposal for tokens that securely verify what different distributed AI agents are capable of doing when they collaborate across a network.