{"data":[{"id":"e6ed6e3b-dac1-4706-af8d-0e4e3797b10f","title":"Strong evasive backdoor attacks and an ensemble defense","headline":null,"summary":"Researchers present an ensemble defense that combines several backdoor detectors for deep neural network classifiers, so detection does not depend on a single backdoor mechanism. The ensemble also performs backdoor inversion, which indicates the nature of a detected attack. The paper also employs mixed clean/dirty-label backdoor poisoning, an X-to-X attack the authors describe as more surgical, evasive, and harder to detect than traditional dirty-label attacks.","sourceUrl":"https://doi.org/10.4218/etrij.2026-0167","publishedAt":"2026-10-08T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_poisoning"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-08T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"40309aba-15de-467f-bf42-d5a653751aba","title":"GNN-Guided Selection of Benign-like Anomalies for Backdoor Attacks Against Network Intrusion Detection Systems","headline":null,"summary":"This paper studies a backdoor attack on AI-based network intrusion detection systems (NIDSs). The method uses the embedding space of a Graph Attention Network (GAT) to pick anomalous samples close to benign traffic, adds a benign-distribution trigger, and relabels them as benign before retraining TabNet, ACID, and AlertNet. Tests on NSL-KDD, CICIDS2017, and UNSW-NB15 show high attack success rates, but the gain over random selection is uneven and marginal or absent where the random baseline is already saturated.","sourceUrl":"https://doi.org/10.3390/electronics15194560","publishedAt":"2026-10-08T00:00:00.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_poisoning"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-08T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"303b8d4b-1efb-4ca7-8a69-0cd5f33fccc3","title":"Detecting Adversarial Images through Response Profiles of Vision-Language Models","headline":null,"summary":"The paper proposes a detector that identifies adversarial images for frozen vision-language models by profiling how an image responds to a set of general semantic prompts. The profile combines category-level statistics, prompt relationships, deviations from clean reference distributions, and stability under weak image transformations, and a lightweight classifier labels each input while the VLM stays fixed. Evaluated across multiple datasets, CLIP-style backbones and several attack families, the detector discriminates strongly in attack-specific settings and retains substantial performance on unseen attacks.","sourceUrl":"https://arxiv.org/abs/2610.10436v1","publishedAt":"2026-10-07T17:13:12.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["CLIP-style vision-language models"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-07T17:13:12.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"preprint","atlasIds":null},{"id":"e21fda5e-034d-49a9-a33b-40a9f7878990","title":"GraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural Networks","headline":null,"summary":"GraphRectify is a graph-based framework that transfers adversarial image detectors from one classifier backbone to another. It learns a structured representation of intermediate classifier features and adapts features from a new backbone to the detector trained on the original model. Across the evaluation matrix, it achieves higher aggregate ROC-AUC than training a detector from scratch on the new backbone, with the largest gains between different backbone families when sufficient data are available.","sourceUrl":"https://arxiv.org/abs/2610.10423v1","publishedAt":"2026-10-07T17:03:55.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-07T17:03:55.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"preprint","atlasIds":null},{"id":"dd789097-9e99-4539-b37a-c0cb2cabd4bc","title":"Transferable Spatial Temporal Coherence Adversarial Attack on Black-Box Vision Language Models for Autonomous Driving","headline":null,"summary":"Researchers introduce STCA (Spatial Temporal Coherence Adversarial Attack), a black-box method that perturbs driving video to fool Vision Language Models. The attack selects semantically important frames with caption guidance, applies a spatial perturbation that preserves high SSIM, then disrupts cross-frame temporal coherence with a motion-guided mask. Tested on BDD100K and nuScenes against Video LLaVA-7B, Qwen2.5-VL-7B and Dolphin, the spatial attack reaches a high ASR while keeping SSIM high, showing these models remain highly susceptible.","sourceUrl":"https://arxiv.org/abs/2610.08331v1","publishedAt":"2026-10-06T13:30:06.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Video LLaVA-7B","Qwen2.5-VL-7B","Dolphin"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-06T13:30:06.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"preprint","atlasIds":null},{"id":"173916bc-3cc4-44e1-b1d3-536e47416ed3","title":"TAPDreamer: Transferable Adversarial Patches for World Action Models","headline":null,"summary":"TAPDreamer is an attack on world action models that builds a fixed local adversarial patch using only a public encoder, with no queries to the target policy. The patch, covering about 6.5% of the input, transfers across tasks and action architectures. In closed-loop tests it cut FastWAM's success rate from 97.7% to 0.0% on 40 LIBERO tasks and from 90.86% to 0.0% on 50 RoboTwin tasks, and it also lowered success on two DreamWAM configurations and on Motus.","sourceUrl":"https://arxiv.org/abs/2610.06814v2","publishedAt":"2026-10-05T17:55:21.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["FastWAM","DreamWAM","Motus","world action models"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-05T17:55:21.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","availability","safety"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"preprint","atlasIds":null},{"id":"3fa9f007-c299-434f-a912-3a8c6793e8ef","title":"A comprehensive study of cross-domain adversarial robustness and attack transferability in image-based malware detection and classification","headline":null,"summary":"This paper presents a framework for evaluating adversarial robustness and attack transferability in image-based deep learning models for malware detection and classification. The authors apply image-domain attacks from FGSM to AutoAttack and test whether binary-domain manipulations remain effective after conversion to an image representation. They report average attack success rates of 64.6% for FGSM and 98.8% for AutoAttack, and accuracy drops of up to 42% from transferred binary-domain manipulations.","sourceUrl":"https://doi.org/10.1016/j.imavis.2026.106232","publishedAt":"2026-10-05T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","security"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-05T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","availability"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"af725407-6d28-4815-9103-913f56d856d1","title":"Visual-Invariance-Augmented Feature Optimal Alignment for Transferable Adversarial Attacks against Closed-Source MLLMs","headline":null,"summary":"Researchers study how to make adversarial images transfer from open-source surrogate multimodal LLMs to closed-source MLLMs in black-box settings. They propose IAU-FOA, which aligns adversarial and target images at both global and patch-cluster levels using confidence-adaptive unbalanced optimal transport, plus visual-invariance augmentation that simulates exposure, contrast, illumination and color-temperature changes. The authors report that it consistently outperforms state-of-the-art transferable attack methods across open-source and closed-source MLLMs.","sourceUrl":"https://arxiv.org/abs/2610.06977v1","publishedAt":"2026-10-04T00:16:22.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["closed-source MLLMs","open-source MLLMs"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-04T00:16:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":"preprint","atlasIds":null},{"id":"50c2166d-12fe-47b7-acc5-b22d7383cf44","title":"A SHAP-guided heterogeneous ensemble defense framework for financial risk assessment under white-box adversarial attacks","headline":null,"summary":"Researchers evaluated a three-layer ensemble defense for deep learning credit risk models, combining MLP, ResNet-1D and TabTransformer architectures with PGD adversarial training and SHAP-based routing. On German Credit and Lending Club under FGSM, PGD and CW attacks across five seeds, the defended AUCs reached 0.758 and 0.723, and the default-class attack success rate fell from 0.52 to 0.19 and from 0.55 to 0.21. SHAP attribution consistency also improved, with Spearman correlation rising from 0.42 to 0.87 between clean and defended explanations.","sourceUrl":"https://doi.org/10.1038/s41598-026-72297-1","publishedAt":"2026-10-04T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"The defense framework itself is the proposed mitigation: a three-layer heterogeneous ensemble with PGD adversarial training and SHAP-based routing. The source does not describe a separate patch, fixed version or configuration change.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-04T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"0f529f2d-5868-4cc6-86a5-d078d0befe85","title":"Detect and Suppress: A Mechanistic Defense against Adversarial Patches in VLA Models","headline":null,"summary":"Researchers analyze Vision-Language-Action (VLA) models with a sparse autoencoder (SAE) and find an internal feature whose activation strongly correlates with adversarial patches. They suppress this feature at inference time only when a linear probe detects an attack, which improves robustness without fine-tuning the VLA. On LIBERO-10, conditional intervention raises success rate under intermittent attacks, while continuous intervention substantially degrades policy performance.","sourceUrl":"https://arxiv.org/abs/2610.03498v1","publishedAt":"2026-10-02T15:57:04.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Vision-Language-Action (VLA) models"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Suppress the identified SAE feature at inference time, applying the intervention only when a linear probe detects an attack. Avoid continuous application, which substantially degrades policy performance.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-02T15:57:04.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null},{"id":"c9ec2543-f689-4c53-a982-2aa7461fd670","title":"Corrupted but Correct: Why Vision-Language Models Lie to Themselves Internally","headline":null,"summary":"Researchers report that a targeted adversarial perturbation can drive a vision-language model's teacher-forced training loss for a fixed target caption near zero, while free generation on Qwen2.5-VL-7B-Instruct still yields the correct description. Using 200 held-out COCO images and a two-stage PGD attack, they localise the gap to one autoregressive step and across the 28 LLM decoder layers, finding that the language decoder, not the visual encoder, differentially arbitrates which images are corrupted (linear probe AUC=0.858, flagged for circularity). The authors argue that adversarial robustness in autoregressive VLMs depends mainly on the language decoder's prior.","sourceUrl":"https://arxiv.org/abs/2610.03445v1","publishedAt":"2026-10-02T15:27:28.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Qwen2.5-VL-7B-Instruct"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-02T15:27:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"preprint","atlasIds":null},{"id":"35587996-f66a-4d73-ad8f-f4c1cc98a5d5","title":"Fix Your Downsampling ASAP! Aliasing and Sinc Artifact Free Pooling in the Fourier Domain","headline":null,"summary":"Researchers show that CNN downsampling layers violate the Sampling Theorem, and that this aliasing correlates with vulnerability to adversarial attacks and distribution shifts. They propose Frequency Low Cut Pooling (FLC Pooling) and its extension Aliasing and Sinc Artifact-free Pooling (ASAP), an alias-free downsampling operation in the frequency domain that also removes sinc-interpolation artifacts. On ImageNet-1k, ImageNet-C and CIFAR across several CNN architectures, networks using these methods showed greater robustness to common corruptions and adversarial attacks while keeping clean accuracy close to baseline models.","sourceUrl":"https://doi.org/10.1007/s11263-026-03005-9","publishedAt":"2026-10-01T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-01T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"409eb2d4-b8ed-4340-adc1-79a24a1e7a53","title":"Hard-label black-box model extraction attacks against network intrusion detection systems via generative adversarial networks","headline":null,"summary":"The paper asks whether a network intrusion detection system's model can be extracted using only hard-label black-box queries. The source text provided gives only the title, publication date (December 2026), journal (Journal of Information Security and Applications, Volume 103), and authors (Donguk Min, Seungsoo Nam, Daeseon Choi), with no method description or findings.","sourceUrl":"https://www.sciencedirect.com/science/article/pii/S2214212626002826?dgcid=rss_sd_all","publishedAt":"2026-09-30T18:02:15.406Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_theft"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"d67083bc-9e39-41fa-ac7b-d379d13e0a82","title":"Let the Carrier Carry the Attack: Preserving the Subject in Adversarial Image Generation","headline":null,"summary":"Researchers propose a \"carrier\", a secondary visual element that gives unrestricted adversarial attacks an auxiliary region to work in, so the primary object (the subject) is distorted less. Under global classifier guidance, the carrier absorbs a larger share of normalized attack updates and improves cross-model transferability. Targeted attacks keep the personalized subject as the main content perceived by humans while misleading the classifier.","sourceUrl":"https://arxiv.org/abs/2609.39723v1","publishedAt":"2026-09-30T13:33:53.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T13:33:53.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null},{"id":"66faa1f2-52ff-46fb-8574-aa550b37a554","title":"Universal Cross-Prompt Adversarial Attacks on Promptable Concept Segmentation","headline":null,"summary":"Researchers present AdvPCS, a universal cross-prompt adversarial attack on Promptable Concept Segmentation in SAM3, which extends SAM-series models to concept-level prediction. The method combines min-max prompt optimization with perception deception and temporal memory misalignment attacks. A single universal adversarial perturbation (UAP) generalizes across frames from different videos and reduces the average mIoU of PCS models on the SA-CO dataset to below 5% under text prompts.","sourceUrl":"https://arxiv.org/abs/2609.39265v1","publishedAt":"2026-09-30T08:23:06.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Meta"],"affectedVendorsRaw":["Segment Anything Model (SAM)","SAM3","SAM2","SA-CO dataset"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T08:23:06.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","availability"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null},{"id":"5e7b018a-383f-43f0-a709-8263d6a45f08","title":"Exploiting Vulnerabilities: Universal Adversarial Attacks on Vision-Language-Action Models in Robotics","headline":null,"summary":"Researchers propose a Universal Adversarial Object, a sphere with an optimized surface texture, that degrades the task success of Vision-Language-Action (VLA) models when placed in a robot's field of view. Their multi-level attack framework disrupts trajectory planning, task execution and action control, and was validated in simulated and real-world robotic settings. The object reduces average task success rates by 31.2% to 39.9% for two VLA models, Pi0 and RDT, with success rates dropping to near zero in complex scenarios.","sourceUrl":"https://arxiv.org/abs/2609.39178v1","publishedAt":"2026-09-30T07:34:24.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Pi0","RDT"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_evasion"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T07:34:24.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","availability","safety"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null},{"id":"64859fc4-0809-40d6-9d8c-7a32245faebc","title":"BadAction: Backdoor Attacks on Interactive Video Generation via Action-Guided Triggers","headline":null,"summary":"Researchers present the first systematic study of backdoor attacks against the interactivity of interactive video generation (IVG) models. Their method, BadAction, implants predefined motion patterns into action sequences so that triggered models produce frozen future frames that ignore later user actions, while benign inputs behave normally. The attack reaches average success rates of 91.0% with action-only triggers and 80.4% with multimodal triggers, and it bypasses existing backdoor detection methods.","sourceUrl":"https://arxiv.org/abs/2609.39047v1","publishedAt":"2026-09-30T05:55:09.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T05:55:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null},{"id":"c0a7bd4f-f562-42e3-b1b7-7d3e4c247c6c","title":"Efficient model stealing in data-free scenarios: An attack method via elite sample distillation","headline":null,"summary":"Liu, Wen and Yu published an article in the Journal of Information Security and Applications, Volume 103, dated December 2026. The source text provided contains only the publication metadata and author list, with no abstract, method or findings.","sourceUrl":"https://www.sciencedirect.com/science/article/pii/S2214212626002814?dgcid=rss_sd_all","publishedAt":"2026-09-29T12:02:44.276Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_theft"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"d7c01e95-9b77-4fec-b67a-1ed6eeb072f9","title":"VLM4Cluster: Benchmarking Deep Clustering In the Era of Vision-Language Pre-training","headline":null,"summary":"VLM4Cluster is a benchmark for image clustering with pre-trained vision-language models. It implements 17 methods across classical, deep, and language-assisted clustering and evaluates them on 20 datasets, including tests of adversarial robustness, distribution-shift generalization, and computational efficiency. The authors find that language-assisted clustering (LaIC) generally improves clustering performance and generalization, but its gains are less consistent on large-scale and fine-grained datasets, and language assistance does not systematically reduce sensitivity to adversarial perturbations.","sourceUrl":"https://arxiv.org/abs/2609.36648v1","publishedAt":"2026-09-29T03:49:26.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","security"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vision-language models (VLMs)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-29T03:49:26.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":"preprint","atlasIds":null},{"id":"cfd3870c-9cb5-4aec-b751-36d816ef2e27","title":"Switchable backdoor attack in vision transformers via progressive dual-token injection from shallow to deep layers","headline":null,"summary":null,"sourceUrl":"https://doi.org/10.1007/s13042-026-03326-8","publishedAt":"2026-09-29T00:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["model_poisoning"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-29T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null}],"meta":{"total":108,"limit":20,"offset":0}}