Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
42 items
The paper, published in ACM Computing Surveys (Volume 58, Issue 11, pages 1-33, August 2026), is titled "LLLMs: A Data-Driven Survey of Evolving Research on Limitations of Large Language Models." The source text provided contains only the citation details and no abstract, method or findings.
The paper presents ESCM, a toolkit for outsourced computation under homomorphic encryption that lets servers run operations such as multiplication, division and sorting across different encrypted domains, so participants need not share one key. To resist collusion among servers and outages, the authors propose a distributed two trapdoor cryptosystem supporting (k,n) threshold decryption. Theoretical analysis, complexity comparisons with existing solutions, and simulation experiments are reported.
MTL-SEI, a multi-task learning framework for Specific Emitter Identification, addresses shortcut learning under cross-receiver distribution shifts, where networks rely on receiver-specific artifacts instead of transmitter fingerprints. It combines spectrum-based feature extraction, receiver-invariant adversarial training via a gradient reversal layer, equalization-state prediction, and uncertainty-guided task weighting. On the ManySig dataset under a receiver-disjoint protocol, it reaches 88.50% transmitter identification accuracy, a 37.7% improvement over the 1D-CNN baseline and over 6.92% average gain over state-of-the-art domain generalization methods.
The authors construct a threshold BBS+ signing protocol using verifiable multiplication-to-addition (MtA) techniques derived from vector oblivious linear evaluation (VOLE), with security proven in the Universal Composability (UC) framework. Building on this, they introduce T3AT, threshold-authorized and threshold-redeemable, non-transferable anonymous tokens that support collaborative issuance and verification under malicious adversaries and dishonest majorities, without trusted hardware or centralized authorities. The source reports that performance evaluation demonstrates practicality, efficiency and scalability.
DawnGuard is a framework for detecting encrypted malware traffic from the earliest stage of an attack, using multi-flow temporal graph learning. It applies a self-adjusting data augmentation strategy to early-stage traffic, builds Multi-Flow Graph Features (MGF), and feeds them to a Vision Transformer-based detector. Tested on two real-world datasets, it achieves an average F1 of 95.11%, 8.7% higher than the state-of-the-art method, using only the first 20% loading ratio of complete traffic.
This paper presents the first rigorous quantitative analysis of macro-level collaborative leakage, where individually harmless risk data reveal sensitive information when combined. The authors attribute the phenomenon to collaborative effects among pieces of risk data and formulate a sufficient condition for it. They show that Gaussian-distributed data can align correlations at both micro and macro levels, which helps prevent the leakage, but that this protection is inherently limited.
The paper shows that two multi-client order-revealing encryption schemes, m-ORE and om-ORE, are vulnerable to a ciphertext-forgery attack. A colluding malicious client and server can silently inject counterfeit records into the encrypted dataset. The authors propose MORES, which they say preserves range-query functionality while provably resisting arbitrarily malicious participants and reduces query size and comparison cost by roughly one-third relative to both schemes.
Researchers propose a secret-shared private set operation (PSO) framework for lightweight clients, aimed at cross-institution data matching and aggregation such as private set intersection and private set union. Existing delegated schemes impose heavy client-side masking and rely on one client as a computational leader, and the proposed scheme lets clients go offline while servers do all computation. The authors prove security under the semi-honest model and report that the protocol outperforms prior approaches when the set size is n ≥ 2^16.
The source is an ACM Computing Surveys article titled "Systematic Literature Review on Differential Privacy in Machine Learning," published in Volume 58, Issue 11, pages 1-36, in August 2026. The provided text contains only the bibliographic details and no findings, method, or results.
This ACM Computing Surveys article, published in Volume 58, Issue 11 (pages 1-37, August 2026), is titled "Privacy in Collaborative Deep Learning Systems: A Taxonomy and Archetypes." The source text provided contains only the publication citation, so the research question, method and findings cannot be summarized from it.
The source is a Computers & Security article by Ziting Ren, Yucong Duan and Qi Qi, published online on 16 April 2026, titled "BioGuard: Malicious sample free defense method for biometric classifiers against model extraction attacks." The provided text contains only the title, publication date, source and authors, with no abstract or findings.
Researchers propose HeteroFed, a privacy-preserving federated learning framework for edge intelligence that targets data, model, and privacy heterogeneity across smart devices. It combines heterogeneous model construction, dynamic gradient clipping, adaptive noise addition, and deviation-aware aggregation. Experiments report global model accuracy gains of 18%, 15%, 13%, and 18% on MNIST, Fashion-MNIST, CIFAR-10, and THUCNews, respectively.
Fix: MORES is proposed as the replacement scheme, described as an immediate drop-in replacement for encrypted-database systems. No patch, configuration change or workaround for m-ORE or om-ORE is stated.
IEEE Xplore (Security & AI Journals)The RIRplay paper presents a simulated replay-attack speech corpus for voice biometric anti-spoofing, aimed at Physical Access attacks where real audio samples are hard to collect. The authors built it to reproduce the spoofing process across a wide range of acoustic contexts. Training on RIRplay cut the Equal Error Rate on the ASVspoof 2021 evaluation set from 36.89% to 28.04%, compared with models trained on ASVspoof 2019, showing better out-of-domain generalization.
Researchers propose Adversarial Spectrum Defense (ASD), which uses Discrete Wavelet Transform (DWT) spectral decomposition to analyze adversarial patterns across multiple frequency scales. Combined with off-the-shelf Adversarial Training (AT), ASD+AT reportedly achieves state-of-the-art performance against patch-based and texture-based attacks, outperforming previous defenses by 21.73% in the AP metric, including against adaptive adversaries designed against ASD.
AuthRF is a signal-level passport mechanism that enforces access control for RF sensing models by mapping a user-specific passport to phase-compensation weights in the signal processing pipeline. Valid passports produce coherent phase alignment and high-fidelity representations, while invalid or forged passports cause phase distortion that significantly degrades model performance. The authors evaluate AuthRF on six RF sensing tasks using WiFi and radar signals.
Researchers propose AdvFor, a query-efficient black-box attack for image forgery localization models that only return hard, mask-only binary outputs. The method learns a transferable attack policy with reinforcement learning, formulated as a finite-horizon Markov Decision Process, and uses a fixed budget of T=7 queries per image. Experiments on six benchmark datasets and multiple modern localization models show it outperforms representative baselines under the same perturbation constraints, including under deployment-style defenses.
DiffMI is a diffusion-driven, training-free model inversion attack that recovers identity information from face recognition systems that map facial images to embeddings. The method combines latent code initialization, ranked adversarial refinement, and a confidence-aware optimization objective, and it applies directly to unseen target identities. The authors report 84.42%–92.87% attack success rates against inversion-resilient systems, 4.01%–9.82% higher than the best prior training-free GAN-based approach. The implementation is available at https://github.com/azrealwang/DiffMI.
FinBot is a hands-on agentic AI capture-the-flag platform from the OWASP GenAI Security Project's Agentic Security Initiative, described as the "Juice Shop for Agentic AI." It simulates a multi-agent vendor management platform with LLM-driven onboarding, fraud detection, invoice processing and communications, and its challenges map to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, CWE and MITRE ATLAS. The source positions it as a companion to the Agentic Top 10 framework rather than a replacement.
The OWASP GenAI Security Project's Q1 2026 round-up consolidates major AI-related security incidents and exploit disclosures from January 1 through April 11, 2026. It maps each incident to the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications 2026, and published AI CVEs where applicable. The source reports a shift from theoretical risk to real exploitation, with attackers targeting agent identities, orchestration layers and supply chains.