Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
47 items
This study examines what drives open banking adoption in Taiwan, combining the Technology–Organization–Environment framework with the Analytic Hierarchy Process to build a grounded model. Drawing on 20 experts and 264 potential users, it finds that security concerns consistently act as a critical determinant, while government and senior leadership support are indispensable in the early market.
This paper introduces MSDT, a blockchain-based data trading protocol that guarantees trading atomicity and data quality without a trusted third party. It uses a state channel-based trading contract to reduce on-chain costs and a staking mechanism with a trading strategy to deal with malicious data owners. The authors report that security and performance analyses show MSDT ensures atomicity and data quality verification while keeping efficiency comparable to existing solutions.
KubeSec is a framework that analyzes application permission configurations and component code dependencies to find takeover risks in third-party applications (TPAs) running in Kubernetes clusters. The study found 562 insecure RBAC binding patterns and 375 vulnerabilities linked to 134 CVEs, affecting millions of users, with average remediation exceeding 10 months. The findings were reported to the relevant teams, and the community assigned 21 new CVEs.
This paper proposes CP-A$^{2}$2BE, a ciphertext-policy anonymous attribute-based encryption scheme for IIoT data sharing. It adds outsourced decryption through edge nodes deployed in factories, protects attribute privacy for devices and personnel, and introduces a commitment-based verifiable revocation mechanism. Experiments report a constant 26 milliseconds decryption time regardless of the number of attributes.
EBFT is a BFT consensus framework for permissioned blockchains that replaces a fixed leader with randomly and non-interactively proposed blocks, combining Nakamoto's longest-chain rule with classical BFT quorum voting. The authors built three protocols (EBFT-Syn, EBFT-PSyn and EBFT-Turbo) atop btcd, with about 920 lines of code, and evaluated them on EC2 with up to 256 nodes. EBFT-Syn and EBFT-PSyn reach latencies of 6 and 1 seconds, while EBFT-Turbo processes up to 3.2k transactions per second at 8 seconds latency.
EPRU, a reputation-based authentication scheme for vehicular platoons, updates vehicle credit scores through a dynamic aggregation trigger that uses verified real-time feedback. It combines ElGamal and homomorphic encryption to protect vehicle identities and feedback data. The authors report formal security proofs against forgery, replay, and modification attacks, and a reduction of at least 3.05% in computation overhead and 37.5% in communication cost compared with recent state-of-the-art schemes.
This paper proposes ANCC, an Anonymous Network Covert Channel that uses Tor's Hidden Service Directories (HSDirs) as intermediate nodes to modulate covert information through the publication and retrieval statuses of hidden services. The authors claim it provides anonymity for the sender, receiver and their communication relationship, with a detection probability below 0.25% against an adversary compromising fifty intermediate nodes. Real-world Tor evaluation reports over 99.6% transmission accuracy and a channel capacity of around 3 Kbps.
The authors correct an earlier claim that their local information privacy mechanism satisfies (ε,0)-LIP for any ε > 0 and any input distribution. They restrict the valid range of privacy parameters, propose algorithms that expand that range, and revise their experimental results accordingly.
Researchers propose C-GAN, a medical image steganography method that hides diagnostic reports inside cover images using a generator, extractor and discriminator trained end-to-end. The method adds a Zero-centered Wasserstein distance for stable training and local regularization on the generator to raise embedding capacity. Experiments on the Open-I, LGK and COV-CTR medical datasets report better capacity, detectability and convergence rate than recent state-of-the-art methods.
FreeFL is a cross-silo federated learning protocol that removes the need for a trusted third party and a centralized aggregator. It replaces homomorphic encryption with a lightweight decentralized symmetric encryption scheme with additive homomorphism, built from a decentralized multiparty symmetric encryption (DMSE) scheme and two multiparty computation protocols. The authors report high computation and communication efficiency and significant computational gains over existing HE-based cross-silo FL protocols.
This article examines how the topology of a decentralized graph affects the convergence rate of decentralized federated learning (DFL) algorithms. It introduces a tensor-based multiple-gossip-steps method, T-MGS, which uses gossip tensors to guide information flow between sites and minimizes the second-largest absolute eigenvalue of the equivalent gossip matrix. Experiments on simulated and real datasets show T-MGS reduces communication rounds without compromising model accuracy.
Co-Boosting++ is a one-shot federated learning framework that couples synthetic data generation with ensemble construction, so each improves the other across iterations. It fixes the ensemble to generate adversarial hard samples, then uses a Mixture of Experts mechanism to reweight the ensemble based on those samples. The authors report consistent gains over state-of-the-art methods on benchmark datasets and state that it needs no local training modifications, extra transmissions, or client architecture restrictions.
ARGO, a method by Paloma Sodhi, Yueheng Li, Jessica Landon, Eric Wallace and Kai Chen, distills black-box reward models into interpretable rubrics using reinforcement learning. It searches over rubrics to maximize agreement between a rubric-conditioned LLM judge and the reward model's preference probabilities. The excerpt does not report the main findings or their numbers.
The paper proposes HAVEN, a hybrid anomaly detection system for Intra-Vehicular CAN-bus communication that combines rule-based techniques with machine learning and neural networks in binary and multiclass forms. The authors report high detection accuracy, low execution time and a high F1-score across different datasets, with the neural-network model performing best.
Fraud-RLA is a new adversarial attack against credit card fraud detection systems that uses reinforcement learning to evade detection. It aims to maximize the amount stolen while requiring substantially less prior knowledge than competing methods. The authors report that it remains effective on a realistic fraud detection system under the constraints of their threat model.
This paper proposes a triple-branch network for deepfake detection that jointly learns spatial features and frequency features from the original image and from images reconstructed through different frequency channels. The authors add feature decoupling and fusion losses derived from mutual information theory to make the model focus on task-relevant features. The method reportedly achieves state-of-the-art performance across six large-scale benchmark datasets.
SMInject is a new injection attack framework against pre-trained multimodal models used in cross-modal retrieval. It generates deceptive injections that combine concepts through causal correlation across modalities, and aligns them in the encoded embedding space to boost effectiveness. On representative multimodal models, it reportedly achieves over 14% higher attack success rate and 6% higher Hit@5 than state-of-the-art methods while preserving overall model utility.
This paper proposes HORP, a robust reinforcement learning method that uses the historically optimal policy to guide policy optimization and generates diverse adversarial perturbations. It builds a guidance value function from value gaps and policy distribution divergence, and adds performance-aware correction and controlled uncertainty injection. Experiments report superior natural performance and robustness against various state attacks in most cases.
Fix: The source states the authors provide a correction to the valid range of privacy parameters, propose efficient algorithms to expand the range of valid privacy parameters, and present corrected results. No further fix or configuration change is specified.
The paper proposes FoVB (Forgery-aware Audio-Visual Adaptation with Variational Bayes), a framework for multi-modal deepfake detection. It models audio-visual correlation as a Gaussian latent variable estimated via variational Bayes, using difference convolutions and a high-pass filter to extract forgery traces from both modalities, then factorizes the variable with an orthogonality constraint. The authors report that FoVB outperforms other state-of-the-art methods across various benchmarks.
This paper presents the first adversarial attack and defense framework for Pedestrian Attribute Recognition (PAR), built on a pre-trained CLIP-based PAR framework. The authors propose ASL-PAR, which generates adversarial noise through global- and patch-level semantic and label perturbations, and a semantic offset defense strategy to suppress such attacks. Experiments on the digital datasets PETA, PA100K, MSP60K and RAPv2, along with physical-domain tests, validate both the attack and the defense.