Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
38 items
This exploratory qualitative study evaluates an AI-driven metaverse prototype designed for cybersecurity training, with feedback from 53 cybersecurity professionals. The authors identify challenges in operationalizing the agentic metaverse, a convergence of immersive metaverse platforms and multi-agent systems, and offer six recommendations with emphasis on implementation and governance.
Fix: The source states six recommendations to guide operationalization of the agentic metaverse, with emphasis on implementation and governance considerations, but does not list their specific content in the provided text.
AIS eLibrary (Journal of AIS, CAIS, etc.)This special issue editorial examines how evolving information technology and societal trends may shape future work, tasks and jobs. It argues for a futures-oriented research paradigm that projects many possible scenarios, weighs how much each is valued, and identifies steps organizations can take now to reach the futures they want. The editorial also introduces the special issue articles and suggests areas for further research.
This paper studies AS-level topology inference for path-aware networking (PAN) with prefix-deterministic path identifiers (PIDs), such as those used by CoLoR, where PID-Prefix identifies inter-domain paths and PID-Suffix is reserved for security functions. The authors propose an Alternating Expanding and Checking (AEC) algorithm that iteratively builds a tree-like AS-level topology from in-packet PIDs. In experiments on an empirical Internet topology of 201 ASes, AEC reached 99.6% accuracy when the observer received only 30 packets from each AS.
This paper proposes an optimal control framework for (ε, δ)-differentially private federated learning that jointly and adaptively sets the DP noise variance and the number of communication rounds, based on training accuracy. The authors derive the optimality gap under this framework. In experiments on MLP, CNN and ResNet-9 models, the framework lets DP-FL converge faster and reach better accuracy than existing techniques at a given privacy level.
Mimi is a multi-keyword search scheme for encrypted data that adds two-factor verification, aiming to fix weaknesses in existing privacy-preserving retrieval schemes. It uses a dynamic verification tree to check returned results, an encrypted searchable inverted index with sub-linear search time, and a secure symmetric key exchange protocol. The authors report security analysis and empirical evaluations but give no numbers in the source text.
Researchers propose DIST, a disentangled spatiotemporal graph neural network framework for traffic forecasting under distribution shifts caused by exogenous factors. The method explicitly separates latent invariant variables from dynamically evolving spatiotemporal dependencies, and a graph perturbation module simulates topology variations during training. The paper reports that comprehensive real-world experiments demonstrate the approach's superiority, with source code published on GitHub.
This paper proposes FKLM-PDA, a lightweight multidimensional privacy-preserving data aggregation scheme for smart grids that does not rely on a trusted third party. It packs multidimensional smart meter data into a one-dimensional format, replaces the Paillier cryptosystem with random masking and secret-sharing based key separation, and adds fault tolerance and key-leakage resilience. The authors report that performance evaluations show FKLM-PDA outperforms existing schemes in computation and communication.
This paper proposes a Bayesian attack graph method for large-scale, active intranet security assessment. It extracts system audit logs to capture real-time changes, generates attack graphs with MulVAL, and removes weak dependencies to find direct-risk paths. Tested on an enterprise intranet using logs from over 1,000 hosts, it reports intranet risk values at any given time and identifies specific, observable potential attack paths.
This paper proposes PPFPS, a privacy-preserving platoon management scheme for flexible platoon splitting in urban freight delivery. It uses an encrypted Manhattan distance method (EMC), combining bloom filters and the Paillier cryptosystem, to match vehicle locations while keeping them private, with reputation ensuring platoon reliability. Simulations report 66.59% to 78.72% lower computation overhead on the TA side, with communication overhead of a similar order of magnitude to existing schemes.
This research article proposes PPFPL, a privacy-preserving federated prototype learning framework for cross-silo federated learning. It uses prototypes as client-submitted model updates to limit the effect of poisoned Non-IID data, and a secure aggregation protocol built on homomorphic encryption that runs on two servers to achieve Byzantine-robust aggregation. The authors report theoretical convergence and privacy analyses and experiments on public datasets showing resistance to data poisoning under Non-IID settings.
The paper introduces M&M, a framework for secure two-party machine learning that uses an efficient modulus conversion protocol to run each cryptographic subprotocol in its optimal modulus domain. The authors report a 6x to 100x improvement for approximated truncations with 1-bit error tolerance, an average 5x reduction in communication and 4x reduction in runtime for machine learning functions, and a 25% to 99% cost-efficiency gain for private deep neural network inference alongside a 50% gain for private gradient boosting decision tree training.
This paper presents APK-Specific Backdoor Attack (ASBA), a poisoning method against machine learning-based Android malware detection (AMD) models. ASBA trains a generative adversarial network to create a distinct trigger for each malware sample, so that discovering one trigger via static analysis does not expose all the malware carrying it. The authors report a 94.6% average attack success rate across three datasets, five feature extraction methods and three classification models.
Researchers propose RSG-DA, a framework for deepfake detection that targets poor generalization to unknown images and novel forgery types. It combines a Dynamic Landmark Diffusion Generator that synthesizes hybrid forgery samples, a Dual Data Augmentation strategy, and a Lightweight Generic Forgery Distillation module. Experiments report consistent gains over state-of-the-art methods in intra-dataset and cross-dataset evaluations.
The authors present a verifiable secure inference scheme that uses a blockchain to verify the origins of both user inputs and model weights. Neural networks are converted into zero-knowledge proof constraints with optimized structures, and the scheme is applied to a regulatable privacy-preserving transaction system where anomaly detection runs on encrypted ledger data. The paper claims rigorous security proofs and reports computational and communication performance to demonstrate scalability.
This paper studies how privacy preservation and Byzantine-robustness interact in decentralized stochastic gradient descent, where honest-but-curious agents try to infer neighbors' data and Byzantine agents send wrong messages. The authors inject Gaussian noise for privacy and use robust aggregation rules against Byzantine attacks, and find a tradeoff: the noise worsens the learning error caused by defending against Byzantine attacks. They analyze how the "mixing abilities" of robust aggregation rules affect this tradeoff, and their theory is supported by numerical experiments.
The paper proposes an XSS attack detection model that uses two-stage Abstract Syntax Tree (AST) analysis, first extracting JavaScript from the HTML AST and then identifying malicious fragments in the JavaScript AST, with a Long Short-Term Memory (LSTM) network making the final classification. The authors report 0.991 accuracy and 0.998 F1 on standard XSS samples. Against adversarial XSS samples, their model keeps a detection rate above 0.982, while most existing models drop below 0.880.
Researchers present WiIntruder, a perturbation attack against deep learning models used in WiFi-based wireless sensing. The method aims for universality, robustness and stealthiness by improving transferability across sensing models, optimizing device synchronization and propagation factors with a particle swarm algorithm, and varying attack patterns from a generative adversarial network. In black-box scenarios, average accuracy across four common WiFi-based services dropped by 72.9%.
The paper proposes the Fairly Proportional Noise Mechanism (FPNM), a differential privacy method that accounts for both the direction and magnitude of noise relative to raw query results to reduce unfairness across groups. In decision tasks, FPNM reduces unfairness by average reductions of 19.17% in F-Norm and 17.32% in average unfairness. When combined with DP-SGD for learning tasks, it achieves fairness comparable to fairness-aware baselines with better accuracy, while empirical privacy holds under membership inference attacks.
OWASP has released the Top 10 for Agentic AI Applications, a community framework for securing autonomous, tool-using AI systems. The source says it is informed by real incidents and has already been adopted across industry.
The OWASP GenAI Security Project released a Top 10 list of risks and mitigations for agentic AI security on December 10, 2025. The release is described as the culmination of input from over 100 industry leaders and extensive published resources.