Daily Summary for 2026-09-28

daily

In short

The Security Radio show covers research from September 28, 2026, focusing on new security and cryptography papers. Nadia and Elias discuss the day's output of 37 new papers, with Priya joining as a guest researcher. The hosts plan to review the papers they are staying with.

Key concepts

Security Radio
The show generates commentary on the latest security and cryptography research papers.
New Papers
Thirty-seven new security and cryptography papers were released on this day, September 28, 2026.
Research Review
The hosts take the day in one pass to review the newly published research papers they are staying with.

Terminology used across episodes

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: It's the twenty-eighth of September, twenty twenty-six, and this is the day's research.

Elias: 37 new papers came out today.

Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.

Elias: We'll take the day in one pass, then pull out the papers we're staying with.

The summary: Nadia: Welcome everyone. Today is the twenty-eighth of September, twenty twenty six.

Elias: Our work needs to move beyond simple coding agents toward a robust enterprise security brain for complex agentic cloud investigations.

Priya: That complexity increases the attack surface as systems become more autonomous, demanding smarter defense than current tools offer.

Nadia: We looked at XPhysICS, which grounds threat detection in cross-physical domains for industrial control systems security.

Elias: It means understanding threats by looking at physical and digital layers together. Then there is JevAdvBench.

Priya: JevAdvBench provides a benchmark and black-box attacks for reinforcement learning models making calibrated decisions under adversarial conditions.

Nadia: Werracle focused on sub-cent intra-block AI reflex oracles and flash-loan circuit breakers for EVM smart contracts.

Elias: This addresses securing decentralized applications with rapid responses to potential exploits in the blockchain environment.

Priya: We also examined Can Pixels Alone Reveal Image Origin, looking at minimax limits and learnable interfaces for passive provenance in image analysis.

Nadia: Not author-related, we touched on authorship hazards in agentic dataspaces and LLM-aided categorization of security patches for critical memory bugs.

Elias: These studies highlight challenges around attribution and automated vulnerability management in software development pipelines.

Priya: The most critical finding was input-layer starvation compromising intrusion detection systems in the Internet of Things.

Nadia: This impacts interconnected device security by examining how pruning layers affects recognizing malicious inputs.

Elias: When specific layers are starved of data, performance drops significantly, showing certain parts are disproportionately important for threat identification.

Priya: That is less impactful than FeatMark's feature-level watermark protection against mimicry attacks using diffusion models.

Nadia: FeatMark protects features before model processing, making it harder for attackers to create deceptive samples.

Elias: Moving down the list was research into prompt attack vulnerabilities when using open-source LLMs from Automatic Speech Recognition to Automatic Speech Processing.

Priya: That covers our key areas for today's review. We have a lot to discuss next time.

Nadia: Indeed, let's dive deeper into those findings soon.

Elias: Agreed, the complexity demands continuous investigation.

Nadia: This prompt attack vulnerability study shows how easily users can manipulate model instructions, risking security bypasses for detection tasks.

Elias: And the work on weaponizing ground truth data poisoning highlights a major issue in training systems when antivirus software misaligns with learning detectors.

Priya: That data poisoning research is significant because an adversary can corrupt training labels to trick the detector into misclassifying threats.

Nadia: NanoZone provided insights into scalable memory protection for Arm CCA, which secures hardware, though it's less about software detection.

Elias: The most important development is the proposal for crypto-bound identity verified capability tokens for coordinating distributed AI agents.

Priya: That addresses the fundamental problem of securely managing and verifying what different AI agents can do when they work together across a network.

Nadia: We looked at BenX managing resource sharing permutations for computational integrity, which ensures shared resources maintain system trustworthiness.

Elias: That feeds into AGATE, proposing provenance-based runtime defense against compositional attacks on large language model agents.

Priya: Then there is MetaPermit, focusing on scalable and auditable access control for AI agents using LLM inferred meta-attributes.

Nadia: That contrasts with SADRA, which introduces a sound capability based access control system for resource disaggregated architectures.

Elias: The most significant piece of work is the Peregrino project creating a full-hardware accelerator for the Falcon post-quantum digital signature scheme.

Priya: This matters because it addresses implementing quantum-resistant cryptography efficiently on resource-constrained edge devices.

Nadia: That hardware acceleration builds on foundational research, optimizing signing and verification for Falcon to run faster than software solutions.

Elias: The optimization leverages earlier work concerning verifiable randomness used in blockchain lottery systems for trust in decentralized signatures.

Priya: So these efforts cover manipulation risks, training corruption, agent coordination security, and post-quantum hardware acceleration.

Nadia: Exactly. We are building robust frameworks for controlling agent behavior and resource allocation in decentralized settings across all these areas.

Elias: It seems the focus is shifting heavily toward securing the infrastructure supporting complex AI agents now.

Priya: It is certainly a broad but critical landscape for deployment integrity right now.

Nadia: The interplay between cryptographic identity and runtime defense is proving essential today.

Elias: We need to keep tracking those hardware implementations alongside the protocol designs.

Priya: Agreed. The convergence of these fields defines this research period well.

Nadia: Indeed, the challenges are increasingly infrastructural and cryptographic in nature.

Elias: Let's move on to the next set of findings from yesterday's review then.

Priya: Ready when you are for the next topic.

Nadia: Okay let's dive into that next section.

Elias: What did we cover regarding model instruction manipulation?

Priya: We discussed prompt attack vulnerabilities showing easy instruction manipulation leading to security bypasses for detection tasks.

Nadia: And the data poisoning research showed adversaries can corrupt training labels to trick detectors into misclassifying threats.

Elias: That undermines the learning process entirely, right?

Priya: Precisely. Also, NanoZone gave us insights into scalable memory protection for Arm CCA on hardware itself.

Nadia: That hardware security work seems less tied to software detection mechanisms than the poisoning studies.

Elias: True. The biggest development is crypto-bound identity tokens for coordinating distributed AI agents across networks.

Priya: That solves the core problem of securely verifying what different agents can actually do together.

Nadia: We also looked at BenX managing resource sharing permutations to maintain computational integrity.

Elias: Which feeds into AGATE, which proposes runtime defense against compositional attacks on LLM agents.

Priya: And MetaPermit offers scalable access control using LLM inferred meta-attributes for agent permissions.

Nadia: That contrasts with SADRA, which is capability based access control specifically for disaggregated architectures.

Elias: The Peregrino project is huge: a full-hardware accelerator for the Falcon post-quantum digital signature scheme.

Priya: It's vital because it implements quantum-resistant cryptography efficiently on resource-constrained edge devices.

Nadia: That hardware acceleration optimizes signing and verification for Falcon to beat software solutions in speed.

Elias: And that optimization builds on verifiable randomness from blockchain lottery systems for trust.

Priya: So we have manipulation risks, training corruption, agent coordination security, and hardware crypto acceleration.

Nadia: All pointing toward building robust frameworks for controlling agent behavior in decentralized settings.

Elias: It's a lot of moving parts today across the entire stack.

Priya: It is certainly a complex but necessary integration of these technologies.

Nadia: The convergence between cryptography and runtime defense is proving indispensable now.

Elias: We need to track those hardware implementations closely alongside the protocol designs.

Priya: Agreed, this research defines the current frontier in AI security and infrastructure.

Nadia: The challenges are definitely becoming more infrastructural and cryptographic in scope.

Elias: Let's move on to the next set of findings from yesterday's review then.

Priya: Ready when you are for the next topic.

Nadia: Okay let's dive into that next section.

Elias: What did we cover regarding model instruction manipulation?

Priya: We discussed prompt attack vulnerabilities showing easy instruction manipulation leading to security bypasses for detection tasks.

Nadia: And the data poisoning research showed adversaries can corrupt training labels to trick detectors into misclassifying threats.

Elias: That undermines the learning process entirely, right?

Priya: Precisely. Also, NanoZone gave us insights into scalable memory protection for Arm CCA on hardware itself.

Nadia: That hardware security work seems less tied to software detection mechanisms than the poisoning studies.

Elias: True. The biggest development is crypto-bound identity tokens for coordinating distributed AI agents across networks.

Priya: That solves the core problem of securely verifying what different agents can actually do together.

Nadia: We also looked at BenX managing resource sharing permutations to maintain computational integrity.

Elias: Which feeds into AGATE, which proposes runtime defense against compositional attacks on LLM agents.

Priya: And MetaPermit offers scalable access control using LLM inferred meta-attributes for agent permissions.

Nadia: That contrasts with SADRA, which is capability based access control specifically for disaggregated architectures.

Elias: The Peregrino project is huge: a full-hardware accelerator for the Falcon post-quantum digital signature scheme.

Priya: It's vital because it implements quantum-resistant cryptography efficiently on resource-constrained edge devices.

Nadia: That hardware acceleration optimizes signing and verification for Falcon to beat software solutions in speed.

Elias: And that optimization builds on verifiable randomness from blockchain lottery systems for trust.

Priya: So we have manipulation risks, training corruption, agent coordination security, and hardware crypto acceleration.

Nadia: All pointing toward building robust frameworks for controlling agent behavior in decentralized settings.

Elias: It's a lot of moving parts today across the entire stack.

Priya: It is certainly a complex but necessary integration of these technologies.

Nadia: The convergence between cryptography and runtime defense is proving indispensable now.

Elias: We need to track those hardware implementations closely alongside the protocol designs.

Priya: Agreed, this research defines the current frontier in AI security and infrastructure.

Nadia: The challenges are definitely becoming more infrastructural and cryptographic in scope.

Elias: Let's move on to the next set of findings from yesterday's review then.

Priya: Ready when you are for the next topic.

Nadia: Okay let's dive into that next section.

Nadia: So, we have the energy-aware agentic AI framework using blockchain for supply chain security. It secures software from creation to deployment through verification.

Elias: That contrasts with Peregrino’s cryptographic focus, but both aim for strong security in different areas. It's interesting how they approach it differently.

Priya: We also saw context-aware functional modeling for Android devices to spot third-party libraries. It uses modeling to understand app functions and flag issues.

Nadia: That’s more application specific than the general cryptography acceleration we discussed earlier, right?

Elias: Exactly. The most significant finding was prefix count limits in card reissuance boosting first-hit discoveries. Capping a prefix might speed up research finds.

Priya: That directly impacts discovery efficiency in that domain. And then there's amplifying LLM inference costs with fragile tokens using noncanonical tokens for expense.

Nadia: Those are practical limitations we need to consider for deploying advanced language models today. What about prompt settings versus conscience in large-scale data?

Elias: That study looked at how specific prompt settings influence model behavior across broad contexts. It explores configuration over conscience in LLM prompts.

Priya: We also have automated and traceable MUD profile generation linking source code to IoT network profiles. That tracks device characteristics from software structure.

Nadia: It’s detailed tracking for things like Internet of Things devices, linking code to network activity. That's quite comprehensive data flow.

Elias: Today's papers include Coding Agents Aren't Enough! XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security.

Priya: JevAdvBench: A Benchmark and Black-Box Attacks for Reinforcement Learning for Calibrated Decisions Models.

Nadia: Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance.

Elias: Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts.

Priya: Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces.

Nadia: What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs.

Elias: Prompt Injection Detection for Email Agents Through Attack Chain Modeling.

Priya: Input-Layer Starvation: Why Per-Layer Pruning Breaks IoT Intrusion Detectors.

Nadia: FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models.

Elias: From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs.

Priya: How to break the Miranda signature scheme over matrix Gabidulin codes.

Nadia: Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors.

Elias: AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning.

Priya: NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA.

Nadia: A Large-Scale Empirical Study of Modern Phishing Email Content.

Elias: Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal.

Priya: Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems.

Nadia: BenX: Resource-Sharing Permutations for Computational Integrity.

Elias: AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents.

Priya: Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning.

Nadia: GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric.

Elias: MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes.

Priya: SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures.

Nadia: Peregrino: A Full-Hardware Accelerator for the Complete Falcon Post-Quantum Digital Signature Scheme on Resource-Constrained Edge Devices.

Elias: Machine Unlearning for Large Language Models: Foundations, Advances, and Agentic Extensions.

Priya: Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains.

Nadia: AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents.

Elias: Verifiable Randomness for Blockchain-Based Lottery Systems.

Priya: Context-Aware Functional Modeling for Android Third-Party Library Detection.

Nadia: Short Paper: Prefix Count Limits Can Increase First-Hit Discovery in Card Reissuance.

Elias: FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation.

Priya: Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts.

Nadia: From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices.

Elias: That concludes our review for today. Join us next time for Coding Agents Aren't Enough! XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security.

Priya: And JevAdvBench: A Benchmark and Black-Box Attacks for Reinforcement Learning for Calibrated Decisions Models.

Nadia: Plus Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance. Good night.

Elias: That’s all for today. Goodbye, everyone. We’ll see you tomorrow.

Priya: Until then, keep exploring the research! The next topic is Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts. Good night.

Nadia: And Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces. Have a wonderful evening.

Elias: We'll see you tomorrow! That's all for today. Bye!

Priya: Enjoy the rest of your day! See you next time on the show. Goodbye!

Nadia: That’s all for today. Good night, everyone. Thank you for tuning in. This was Nadia, Elias, and Priya.

Elias: And that is our closing segment of the research review for today. Good night!

Priya: We hope you found this review insightful! Until next time! Bye-bye!

Nadia: That’s all for today. Have a safe night. Good night, everyone. Thank you for listening to the research review.

Elias: This was a great session with Nadia and Priya. See you next time on the show! Goodnight!

Priya: We hope this summary helped clarify things for you all! Until next time! Bye-bye!

More episodes

← Home