Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
36 items
Wei Peng, Junmei Ding, Wei Wang, Lei Cui, Wei Cai, Zhiyu Hao and Xiaochun Yun present CTISum, a benchmark dataset for summarizing Cyber Threat Intelligence. The paper appears in Computers & Security, Volume 168, published September 2026.
Researchers propose an adaptive VM allocation framework that uses user threat assessment to reduce side-channel attack risk in cloud environments. They analyze a large-scale Microsoft Azure dataset to guide security-aware initial placement, then apply a non-dominated sorting snow ablation optimizer to dynamically migrate VMs and disrupt co-residency. Experiments report up to 25% lower co-residency risk, up to 20% lower defensive costs, and up to 30% better resource utilization compared with prior adaptive cyber defense approaches.
This paper proposes ABIGX, a unified framework for explainable fault detection and classification (FDC) that extends contribution plots and reconstruction-based contribution to general FDC models. Its core Adversarial Fault Reconstruction (AFR) method treats fault reconstruction as an adversarial attack and introduces a fault index usable for both detection and classification. The authors prove CP and RBC are linear specializations of ABIGX and report that it mitigates fault class smearing, outperforming current gradient-based explanation methods.
Fed-C&E is a federated learning method for unsupervised skeleton-based action recognition that uses a closed-loop condensation-expansion paradigm. Clients condense their data, and the server expands it through a dual-level mechanism that synthesizes samples with a prototype-to-sequence similarity transformation matrix pool and supplements global information using second-order client statistics. The authors report that it outperforms aggregate-then-adapt FL methods across multiple datasets while preserving data privacy.
AmbShield is a physical layer security scheme that uses naturally distributed ambient backscatter devices (AmBDs) to protect wireless links against passive eavesdroppers without extra transmit power. The AmBDs act as friendly jammers that randomly backscatter to interfere with eavesdroppers and as passive relays that backscatter the desired signal to boost legitimate receivers. The authors derive closed-form secrecy outage probability and secrecy diversity order, and validate the gains with Monte Carlo simulations under imperfect synchronization and CSI estimation.
BlockAthena is a forensic framework for analyzing long-term on-chain crimes in account-based blockchains. It segments long-term transaction topology into subgraphs based on crime evolution periods, modeling direct and co-occurrence transactional behaviors. Experiments report an average 18% improvement in F1-score and up to an 80% reduction in memory overhead compared to the best-performing baseline.
Multi-view clustering with joint training can leave some views under-optimized, because one view with more discriminative information dominates learning. The authors analyze this imbalance through gradient descent on each view-specific feature extractor and propose balanced multi-view clustering (BMvC), which adds a view-specific contrastive regularization (VCR) to modulate each view's optimization. BMvC is reported to outperform state-of-the-art methods on eight benchmark datasets and two spatially resolved transcriptomics datasets.
This paper presents an optimal visual time-of-flight imaging scheme that learns iToF coding functions and depth reconstruction end to end, guided by Fisher information supervision. It adds RGB-derived vision information and a dual-branch reconstruction network with edge guidance to improve depth accuracy under low signal-to-noise conditions. The authors report effectiveness on synthetic and real-world datasets.
The paper introduces DFedCata, a decentralized federated learning algorithm that applies Catalyst Acceleration to address slow convergence and poor generalization caused by data heterogeneity. It combines a Moreau envelope function, which reduces parameter inconsistencies among clients, with a Nesterov extrapolation step that speeds up aggregation. The authors report improved convergence speed, computational cost and generalization on CIFAR10/100 and Tiny-ImageNet under various non-iid data distributions.
PathAttack is a path-based, explainable untargeted attack framework for knowledge graph embedding (KGE), where an adversary deletes key triplets or injects malicious triplets to degrade learned representations. It replaces predefined target sets with a triplet discovery approach that combines selection across different KGE model types, and weights multi-hop relational paths for adversarial deletion and addition. Experiments on FB15k-237, WN18RR, and OGBL-WikiKG2 show improved effectiveness, including a 5% gain on WN18RR, and scalability to KGs with millions of entities.
Researchers propose a facial privacy framework that lets users authenticate for scenarios such as smart building access without exposing their real face or identity in plaintext. The design uses a bidirectional mapping mechanism with an identity mapping module that generates a virtual identity (VID), an identity transfer model that produces a virtual face, and a VIEM module that compares identities in the encrypted domain via homomorphic encryption. Experiments reportedly show a balance between privacy protection, attribute preservation and authentication accuracy.
OpenAI introduced Auto-review in Codex, a mode that replaces user approval at the sandbox boundary with review by a separate agent. In an illustrative internal deployment snapshot, Codex sessions stopped for human approval roughly 200x less often than in manual approval mode, and Auto-review approved around 99% of the actions that needed review.
Researchers propose SemBugger, a polymorphic backdoor against Semantic Communication (SC) systems. Unlike earlier monomorphic SC backdoors with a single attack target, it adjusts trigger intensity to produce diverse malicious outputs through a multi-effect poisoning-training framework, while keeping transmission fidelity for benign samples. Experiments on diverse SC models and benchmark datasets report high attack efficacy and a defense that neutralizes the attacks.
Fix: The paper proposes a provable robustness defense that adds controlled noise to SC inputs to resist SemBugger's homogeneous attacks, with a theoretical lower bound on defense efficacy.
IEEE Xplore (Security & AI Journals)Researchers propose DSCA, a Diffusion-based Semantic Camouflage Attack against person re-identification (ReID). Instead of perturbing pixels, a conditional diffusion generator edits latent attributes such as clothing color and texture to impersonate a target identity, operating zero-query and black-box. Experiments on major ReID benchmarks report attack success rates over 95% in their setting, along with evasion of advanced defenses.
PixOOD is a pixel-level out-of-distribution detection algorithm that needs no training on anomalous samples and is not tied to one application. It models in-distribution data with an online data condensation algorithm, which the authors describe as more robust than standard K-means and trainable by stochastic gradient descent, paired with per-class or unified calibration models for the decision strategy. It achieved state-of-the-art results on four of seven datasets and was competitive on the rest.
The paper proposes K-TCDP, a finite-memory noise mechanism for differentially private LoRA supervised fine-tuning of large language models. It adds controlled negative temporal correlation to full-dimensional Gaussian noise in the LoRA adapter, so earlier perturbation can be partly offset later, while remaining compatible with standard RDP accounting. On four GLUE tasks and DART (BLEU-4, ROUGE-L), it consistently outperforms DP-SGD at the same privacy levels with small computational overhead.
The authors present a unified framework for interpreting vision models that centers on the pointwise feature vector (PFV) paired with its instance-specific Effective Receptive Field (iERF). It combines Sharing Ratio Decomposition (SRD) for local saliency maps, Concept-Anchored Feature Explanation (CAFE) for global semantic labeling of sparse autoencoder latents, and Interlayer Concept Attribution (ICAT) for tracing concept influence across layers. Across ResNet50, VGG16, and ViTs, the framework is reported to outperform baselines in fidelity and robustness.
The OWASP GenAI Security Project has launched FinBot, a hands-on Agentic Security capture-the-flag platform that is part of its Agentic Security Initiative. FinBot simulates a multi-agent vendor management platform with autonomous onboarding, fraud detection, invoice processing and communications, all powered by LLMs with real tool access. Its challenges cover prompt injection, tool misuse, policy bypass, data exfiltration, privilege escalation and remote code execution, mapped to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, CWE and MITRE ATLAS.