Security papers — 2026-09-28
Today's work centers on the growing need to move beyond simple coding agents and build a more robust enterprise security brain capable of handling complex, agentic cloud investigations. As systems become more autonomous, the surface area for sophisticated attacks increases, demanding a higher level of intelligent defense than current tools provide.
Researchers looked at XPhysICS which attempts to ground threat detection in cross-physical domains specifically for industrial control systems security. This means trying to understand threats by looking at physical and digital layers together. Following that, JevAdvBench provides a benchmark and black-box attacks for reinforcement learning models used in making calibrated decisions. This is important because it tests how well these decision-making models perform under adversarial conditions.
Another piece of work examined Werracle, which focuses on sub-cent intra-block AI reflex oracles and flash-loan circuit breakers for EVM smart contracts. This relates to securing decentralized applications by introducing rapid responses to potential exploits in the blockchain environment. We also explored Can Pixels Alone Reveal Image Origin, looking at minimax limits and learnable interfaces for passive provenance in image analysis.
Finally, we touched upon subjects not authors regarding the authorship hazard in agentic dataspaces and LLM-aided categorization of security patches for critical memory bugs. These studies highlight the emerging challenges around attribution and automated vulnerability management in modern software development pipelines.
The most critical finding from the day concerns how input-layer starvation compromises intrusion detection systems in the Internet of Things, which is vital because it directly impacts the security of interconnected devices. Researchers investigated this by examining how pruning different layers within these detectors affects their ability to recognize malicious inputs.
One study showed that when specific layers are starved of necessary data, the overall performance of the detector drops significantly, suggesting that certain parts of the network are disproportionately important for accurate threat identification. This is less impactful than a finding from FeatMark, which demonstrated feature-level watermark protection against mimicry attacks using diffusion models.
FeatMark's work is significant because it introduces a way to protect features within data before they are processed by models, making it harder for attackers to create deceptive samples. Moving down the list of importance, there was research into prompt attack vulnerabilities when using open-source large language models from Automatic Speech Recognition to Automatic Speech Processing.
This prompt attack vulnerability study is important because it shows how easily users can manipulate the instructions given to these powerful models, which could lead to security bypasses if these models are used for detection tasks. Furthermore, work on weaponizing ground truth data poisoning attacks by exploiting misalignment between antivirus software and learning-based detectors highlights a major issue in training systems.
This data poisoning research is significant because it shows that an adversary can intentionally corrupt the training labels to trick the detector into misclassifying threats, which undermines the entire learning process. Finally, NanoZone provided insights into scalable memory protection for Arm CCA, which is important for securing hardware itself, though it seems less directly related to software detection mechanisms than the preceding studies.
The most important development today concerns the proposal for crypto bound identity verified capability tokens designed to coordinate distributed artificial intelligence agents. This work matters because it addresses the fundamental problem of securely managing and verifying what different AI agents can actually do when they are working together across a network.
We looked at how BenX manages resource sharing permutations for computational integrity, which is important because it tackles the issue of ensuring that shared computational resources are used in a way that maintains overall system trustworthiness. This feeds into AGATE, which proposes provenance based runtime defense against compositional attacks on large language model agents, meaning it tries to stop malicious combinations of agent actions from causing harm.
Then there is MetaPermit, which focuses on scalable and auditable access control for AI agents using LLM inferred meta-attributes, offering a way to manage permissions in complex agent environments. This contrasts with SADRA, which introduces a sound capability based access control system specifically for resource disaggregated architectures. These systems are all trying to build robust frameworks for controlling agent behavior and resource allocation in decentralized settings.
The most significant piece of work today involved the Peregrino project, which attempts to create a full-hardware accelerator for the complete Falcon post-quantum digital signature scheme. This matters because it directly addresses the need to implement quantum-resistant cryptography efficiently on resource-constrained edge devices.
This hardware acceleration work is built upon foundational cryptographic research, specifically leveraging the Falcon scheme's structure. The implementation details focus on optimizing the signing and verification processes for this specific algorithm to run faster than software solutions would allow. This optimization effort builds upon earlier work concerning verifiable randomness used in blockchain lottery systems, which provides a necessary layer of trust for any signature scheme deployed in a decentralized environment.
Another thread running concurrently is the development of an energy-aware agentic AI framework that anchors its operations on blockchain technology to secure software supply chains. This framework aims to ensure the integrity of software from creation through deployment by using blockchain for verification. This contrasts with the cryptographic focus of Peregrino, but both aim for robust security in different domains.
The research also touched upon context-aware functional modeling designed to detect third-party libraries on Android devices. This work uses modeling techniques to understand how applications function and can flag potentially malicious or unauthorized components within the system. This is a more application-specific security concern than the general cryptographic acceleration discussed earlier.
The most significant finding relates to how prefix count limits in card reissuance can boost the rate of first-hit discoveries. This suggests that imposing a cap on how many times a specific prefix can appear might actually help researchers find new things faster. This is important because it directly impacts the efficiency of discovery in this domain.
A related piece explored amplifying large language model inference costs using fragile tokens, which involves generating noncanonical tokens to increase computational expense during LLM use. This work touches on the practical limitations and resource demands of deploying advanced language models.
Another study looked at configuration versus conscience when examining large-scale empirical data regarding system prompts for LLMs. This investigation sought to understand how specific prompt settings influence the model's behavior in a broad context.
Furthermore, there is work focused on automated and traceable generation of MUD profiles by linking source code to network profiles for Internet of Things devices. This allows for detailed tracking of device characteristics from its underlying software structure.
Today's papers
- Coding Agents Aren't Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations. [paper]
- XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security. [paper]
- JevAdvBench: A Benchmark and Black-Box Attacks for Reinforcement Learning for Calibrated Decisions Models. [paper]
- Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance. [paper]
- Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts. [paper]
- Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces. [paper]
- What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs. [paper]
- Prompt Injection Detection for Email Agents Through Attack Chain Modeling. [paper]
- Input-Layer Starvation: Why Per-Layer Pruning Breaks IoT Intrusion Detectors. [paper]
- FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models. [paper]
- From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs. [paper]
- How to break the Miranda signature scheme over matrix Gabidulin codes. [paper]
- Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors. [paper]
- AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning. [paper]
- NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA. [paper]
- A Large-Scale Empirical Study of Modern Phishing Email Content. [paper]
- Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal. [paper]
- Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems. [paper]
- BenX: Resource-Sharing Permutations for Computational Integrity. [paper]
- AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents. [paper]
- Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning. [paper]
- GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM). [paper]
- MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes. [paper]
- SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures. [paper]
- Peregrino: A Full-Hardware Accelerator for the Complete Falcon Post-Quantum Digital Signature Scheme on Resource-Constrained Edge Devices. [paper]
- Machine Unlearning for Large Language Models: Foundations, Advances, and Agentic Extensions. [paper]
- Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains. [paper]
- AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents. [paper]
- Verifiable Randomness for Blockchain-Based Lottery Systems. [paper]
- Context-Aware Functional Modeling for Android Third-Party Library Detection. [paper]
- Fast and Secure Simultaneous Authentication of Equals for WPA3. [paper]
- Revisiting Certified Defense with Differential Privacy on Vision Transformers. [paper]
- Short Paper: Prefix Count Limits Can Increase First-Hit Discovery in Card Reissuance. [paper]
- Toward verifiably private learning from federated data.
- FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation. [paper]
- Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts. [paper]
- From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices. [paper]
The papers
- From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs —
- NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA —
- What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs —
- AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning —
- Coding Agents Aren't Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations —
- Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces —
- Prompt Injection Detection for Email Agents Through Attack Chain Modeling —
- A Large-Scale Empirical Study of Modern Phishing Email Content —
- Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts —
- Input-Layer Starvation: Why Per-Layer Pruning Breaks IoT Intrusion Detectors —
- XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security —
- Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal —
- AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents —
- Machine Unlearning for Large Language Models: Foundations, Advances, and Agentic Extensions —
- How to break the Miranda signature scheme over matrix Gabidulin codes —
- FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models —
- Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance —
- Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors —
- GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM) —
- Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems —
- MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes —
- BenX: Resource-Sharing Permutations for Computational Integrity —
- SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures —
- JevAdvBench: A Benchmark and Black-Box Attacks for Reinforcement Learning for Calibrated Decisions Models —
- Peregrino: A Full-Hardware Accelerator for the Complete Falcon Post-Quantum Digital Signature Scheme on Resource-Constrained Edge Devices —
- Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning —
- Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains —
- Revisiting Certified Defense with Differential Privacy on Vision Transformers —
- AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents —
- Short Paper: Prefix Count Limits Can Increase First-Hit Discovery in Card Reissuance —
- Context-Aware Functional Modeling for Android Third-Party Library Detection —
- Verifiable Randomness for Blockchain-Based Lottery Systems —
- Toward provably private learning from federated data —
- Fast and Secure Simultaneous Authentication of Equals for WPA3 —
- FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation —
- Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts —
- From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices —
Important terms
- agentic cloud investigations
- This refers to advanced security analysis needed for autonomous AI systems operating in the cloud, moving beyond simple coding agents to handle complex threat detection.
- XPhysICS
- A method for grounding threat detection by combining physical and digital layers, specifically targeting security challenges within industrial control systems.
- JevAdvBench
- A benchmark and adversarial attack tool used to test how well reinforcement learning models perform when making critical decisions under challenging conditions.
- EVM smart contracts
- These are decentralized applications running on the Ethereum Virtual Machine, which require security measures like flash-loan circuit breakers for rapid exploit response.
- crypto bound identity verified capability tokens
- A proposal for tokens that securely verify what different distributed AI agents are capable of doing when they collaborate across a network.