Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
26 items
The source is a bibliographic record for a June 2026 article in the Journal of Information Security and Applications, Volume 99, by Jianzhong Wang, Lifei Wei, Jinjiao Zhang, Kai Zhang and Jianting Ning. The title indicates a study of efficient malicious-secure multi-party private set union that uses trusted execution environments. The provided text contains no abstract, method details, or findings.
Quadruplet Augmentation (QuadAug) is a method for Online Continual Learning, which learns from streaming data with unknown task boundaries. It targets two requirements, attribute invariance and structure invariance, to overcome the shortcut feature trap and limited plasticity of previous methods. The authors report significant improvements on four sequential datasets and three blurry datasets.
Researchers address node classification in a newly formed hypergraph, where labeled nodes are scarce and costly to obtain. They propose LHCCA (Local and High-order Consistency Coding and Adaptation), which transfers knowledge from a well-labeled source hypergraph by combining local and high-order consistency representations through attention, then aligns source and target features with adversarial domain adaptation and contrastive learning. Experiments on several real-world datasets are reported to show the model's effectiveness.
The paper, published in Computers & Security (Volume 167) in August 2026 by Zhaoxin Jin, Tianbo Lu, Hanrui Chen and Fangyi Yu, is titled "Enhancing website fingerprinting through combined data augmentation strategies." The source text provides only publication metadata, so the study's method and findings are not described here.
This paper proposes a hybrid detection method combining autoencoder and transformer models to catch the unresponsive ECN attack, a novel attack on low-latency network services. Compared with the current state-of-the-art on a large real-life network traffic dataset, it cuts detection error rate by more than 10%. At a false-alarm rate below 10−4, it reaches over 90% true-positive detection.
TemSR, a framework for time-series source-free unsupervised domain adaptation, is proposed to transfer temporal dependencies to a target domain without access to source data. It uses a masking, recovery and optimization process to generate a source-like distribution, refined by local context-aware regularization and anchor-based recovery diversity maximization. Experiments across seven time-series tasks show it surpasses existing methods that require source-specific pretraining designs.
Classical tensor decomposition methods cannot handle ragged tensors, which have irregular index patterns. The authors propose a CP-based, geometry-aware separable decomposition framework that models the valid domain with a binary weighting tensor and decouples the objective into independent subproblems. The method uses a domain-adapted proximal alternating minimization solver with a convergence guarantee, and it reports superior accuracy and efficiency on multispectral, hyperspectral and spatial transcriptomics data.
DrawMotion is a diffusion-based framework that generates 3D human motions from both a text description and a freehand drawing condition. It converts hand-drawn stickman sketches into spatial control, and a Multi-Condition Module fuses the text, sketch and 2D trajectory conditions inside the diffusion process. The authors report that the drawing approach cuts user time by approximately 46.7% when producing motions that match users' intentions.
DreamFuse is a unified diffusion-based approach for image fusion that integrates foreground objects into background scenes. The authors curate a cross-scene dataset with iterative in-context learning and existing tools, then use the Diffusion Transformer's attention mechanism to align foreground and background features. The paper reports superiority over state-of-the-art methods across multiple metrics.
The authors propose DFMDM, a dynamically filtering multistage diffusion model for cross-corpus speech emotion recognition. It runs a three-stage loop of generation, filtering and enhancement, where an adversarial domain classifier guides pseudosample generation and a dynamic filtering module removes low-quality samples that deviate from target domain features. The model reports significant gains over state-of-the-art approaches on CASIA, EmoDB, eNTERFACE and IEMOCAP.
This ACM Transactions on Privacy and Security paper, published May 2026 in Volume 29, Issue 2 (pages 1-32), studies the Android permissions system. The source text provided contains only the citation and does not state the research method or findings.
Researchers present AICCE, a generative system that automates IPv6 protocol compliance checking by combining retrieval-augmented generation with dual-architecture reasoning. It runs an explainability mode with parallel LLM agents that debate decisions, and a script execution mode that converts specification clauses into Python rules for dataset-wide verification. Tested on IPv6 packet samples across 16 generative models, it reports accuracy and F1-scores of up to 99%.
Researchers from Shanghai Jiao Tong University and collaborators (Hongying Zhang and others) published ReSLC in the Journal of Information Security and Applications, Volume 100, in July 2026. The source text provided contains only publication metadata (date, journal, volume, authors) and no description of the method, findings or numbers.
The source text is a bibliographic citation for an article titled "SBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation," published in Digital Threats: Research and Practice, Volume 7, Issue 2, pages 1-35, June 2026. It contains no abstract, method, or findings, so the research question and results cannot be stated from this text.
The authors introduce Nearest Neighbor Projection Removal Adversarial Training, a framework that removes projections onto each adversarial sample's nearest inter-class neighbors in feature space to improve class separability. They report theoretically that their logits correction lowers the Lipschitz constant and Rademacher complexity, and experiments on CIFAR-10, CIFAR-100, SVHN and TinyImagenet show performance competitive with leading adversarial training methods.
This article establishes information-theoretic limitations on the robustness of AI security and alignment. It argues that knowing these limits and preparing for their challenges is essential for responsible AI adoption, and it also proves broader implications for the cognitive reasoning limitations of AI systems.
This paper studies transferable targeted attacks on image models that work without victim-model training data or black-box feedback. The authors introduce two blind estimation measures, self-alignment and self-transferability, to assess each image transformation. They find that simple scaling transformations uniquely enhance targeted transferability, and they build S$^{4}$4ST, a scale transformation method, which achieves state-of-the-art effectiveness-efficiency balance across architectures, training distributions and tasks.