Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
43 items
The Society for Information Management's 45th Annual IT Issues and Trends study surveyed 704 IT executives, including 211 CIOs from 344 unique organizations. AI rose to the top of the most important IT management issues, followed by Cybersecurity and Alignment of IT and Business. Only 54.2% of organizations reported increasing IT headcount, the lowest share since 2020.
MIDAS is a data auditing scheme for mobile devices that outsources computation-intensive auditing metadata generation to edge nodes, leaving mobile devices with only lightweight processing. It embeds edge node identity into the metadata for traceability and adds a proportional load-balanced scheduling algorithm for Multi-MU and Multi-EN scenarios. The authors prove its security by reduction to the discrete logarithm problem in the RSA quadratic residue subgroup under the random oracle model, and real-world experiments show reduced mobile computational overhead and better scalability than existing schemes.
Complex AFNet is a hybrid complex-valued convolutional network for atrial fibrillation detection from ECG signals. It converts 1-D ECG segments into GASF and GADF images, treats them as real and imaginary inputs, and reports 95.63% test accuracy, 96.43% precision, 92.05% recall and a 94.15% F1-score on the PhysioNet AF dataset of 1436 recordings.
Researchers present Urey-ML, a machine learning-based distance deception attack against Apple's UWB Nearby Interaction Framework (ANIF), which they say is the first attack able to circumvent ANIF's ranging-awareness defense. Network packet analysis revealed that ANIF sends a key negotiation message in an unprotected state, which lets the attack bypass encryption. A reinforcement learning algorithm then tunes attack signals to mimic normal human movement, achieving centimeter-level distance deception on commercial UWB products, with more than 25.79% of signals passing the victim's defense check versus 0.56% in prior work.
This article studies global polynomial synchronization (GPS) for uncertain complex-valued reaction–diffusion Takagi–Sugeno (T–S) fuzzy memristive neural networks with proportional delays. It extends interval matrix theory to characterize complex-domain memristors and builds Lyapunov functionals using conjugate transpose properties, avoiding the split into real and imaginary parts. Two event-triggered controllers are designed, and the results are verified through two numerical examples.
This paper addresses neural architecture search (NAS), which automatically finds high-performance network architectures. Existing NAS methods minimize average-case validation loss, so the architectures they find predict poorly in worst-case scenarios. The authors propose a multilevel optimization framework that uses a deep generative model to create adversarial validation examples and minimizes the loss on them, and report that experiments on a variety of datasets demonstrate its effectiveness.
Researchers propose a Differentially Private Quadrature Amplitude Modulation (DP-QAM) scheme for wireless federated analytics. It draws privacy amplification from both compression and noisy wireless channels, with the privacy guarantee stated in f-DP and accuracy measured by mean square error (MSE) on distributed mean and frequency estimation. Simulations validate the approach, which the authors report outperforms state-of-the-art methods.
This paper proposes a federated learning method for radio frequency fingerprint identification (RFFI) that addresses performance loss from non-IID data across receivers. Each client learns aligned intermediate feature representations during local training to counter distribution shifts caused by receiver hardware, deployment location and channel conditions. On a real-world RF dataset, the method reaches 90.83% identification accuracy and shows higher stability than FedAvg and FedProx.
A banking group introduced a retrieval-augmented, AI-powered compliance assistant, and the article describes what that rollout reveals about future compliance work. It names four tensions in AI-supported compliance: authority illusion, blurred accountability, loss of contextual judgment and widening awareness gaps. It also offers a four-phase framework for moving from reactive AI assistants toward agentic, co-reasoning systems.
ClusterGuard is a secure clustered aggregation scheme for federated learning that aims to protect privacy and resist poisoning attacks. It uses a Verifiable Random Function for fair client clustering, a key-homomorphic masking mechanism with verifiable secret sharing for aggregation within clusters, and a dual filter based on cosine similarity and norm. Experiments on standard datasets report over 2x efficiency gains over advanced secure aggregation methods, and with 20% malicious clients the model keeps accuracy comparable to the original.
Researchers present TPA-VSL, a targeted poisoning attack against vertical split learning, where a model is partitioned between clients and a server. The attack manipulates the embedding model directly, mapping the embedding of a targeted sample to an attacker-chosen class without an obvious trigger pattern. Its two components use diffusion models guided by a multimodal encoder-decoder to mimic the target model, then align the targeted samples' embeddings with those of the desired class. The authors report a 30% higher attack success rate on average than baseline attacks.
PrivateEdit is a privacy-preserving pipeline for face-centric generative image editing. It uses on-device segmentation and masking to separate identity-sensitive facial regions from editable image context, so biometric data are never transmitted to third-party generative models, which need no retraining or access. A tunable masking mechanism lets users choose how much facial information to conceal, and a user interface supports selective anonymization.
DUAP is a privacy-preserving method that generates universal adversarial perturbations to counter OpenAI's Whisper multilingual ASR model, which can transcribe sensitive speech across languages. It uses a two-stage language attack: a Language Feature Disentanglement model produces adversarial examples, then gradient-based optimization disrupts Whisper's language identification module. Across three Whisper model sizes, DUAP reports WERs above 95% for English, 85% for other languages and 87% in physical settings, with SNRs from 40 dB down to above 17 dB.
Researchers asked how people in different functional roles evaluate people analytics, a form of datafication technology, using the affordance lens. Based on 43 interviews and a critical realist analysis, they found that data ideologies help explain these evaluations and affordance actualization. The authors identify three mechanisms, moderation, confirmation, and modulation, linking data ideologies to stakeholders' relationships with datafication technologies.
Researchers study whether LLM-based task-oriented dialogue systems memorize their training dialogue data, which can include phone numbers and full travel schedules. They evaluate existing training data extraction attacks, find that task-oriented dialogue traits make them ineffective, and propose new attack techniques for response sampling and membership inference. Their method extracts thousands of training dialogue-state labels with best-case precision above 70%, and the paper analyzes the factors that influence this memorization.
Researchers present Lure, a backdoor-based data recovery attack on generative language models. By injecting a backdoor into the source code of an open-source GLM, an adversary can make the model memorize fine-tuning data and regenerate it via crafted hash prompts. Evaluations report a 45%-68% data recovery rate while the attack remains stealthy and evades existing defenses.
Researchers assess how robust large vision-language models (LVLMs) are to adversarial visual transformations, a simpler attack style than optimizing perturbations or manipulating prompts. They test LVLM resilience across all possible transformation operations and find that combining the most harmful transformations yields more effective attacks. They also introduce adversarial learning of visual transformations, which applies malicious transformations to raw images via gradient approximation to improve attack effectiveness and imperceptibility.
QuEST is a framework that makes quantization-conditioned backdoor attacks on deep learning models stealthier and cheaper to train. It uses a stealth-optimized training scheme with parametric backdoor injection and trigger scaling augmentation, plus information-guided parameter sharing that relies on parameter redundancy analysis and Fisher divergence metrics. The authors report 18.75% better stealth performance and 26.66% lower computational cost on average versus state-of-the-art methods, while keeping competitive attack success rates.
Researchers propose a federated learning scheme that combines homomorphic encryption with Johnson-Lindenstrauss dimension compression and a dual-server architecture, defending against Byzantine clients making up to 40% of the network. Compression cuts cryptographic operations from O(dn) to O(kn), where k is much smaller than d, reducing computational overhead 25 to 35 times and communication overhead 17 times relative to the non-compression version, while keeping accuracy comparable to non-private FL.
AdaParse is a hyperparameter-specialized adaptive fingerprinting framework for model reverse engineering, which predicts hyperparameters of generative models from AI-generated images. It personalizes fingerprint estimation networks per input image using two-branch hypernetworks and a Broadcasted Fusion module. Experiments on a large public dataset covering 123 generative models show it outperforms previous state-of-the-art methods.