Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
37 items
Researchers examined whether controller actions at the joint level of a robot can be inferred from encrypted network traffic. The source text provided is limited to the title, publication details and authors, so the method and findings are not described.
This paper introduces CLLME, a certificateless lattice-based matchmaking encryption scheme for bilateral access control in data sharing. Both senders and receivers specify matching access structures, so decryption requires mutual authorization, and a lightweight authenticity check filters out irrelevant ciphertexts before costly decryption. The authors prove indistinguishability against chosen-plaintext attacks and existential unforgeability against chosen-message attacks under lattice-based assumptions, and report favorable communication and computation efficiency.
The paper proposes Xsyn, a one-stage X-ray security image synthesis pipeline built on text-to-image generation, to avoid the labor-intensive foreground extraction of prior two-stage methods. It adds Cross-Attention Refinement (CAR), which uses the diffusion model's cross-attention map to refine bounding box annotations, and Background Occlusion Modeling (BOM), which models background occlusion in latent space. Experiments report a 1.2% mAP improvement over previous methods and better prohibited item detection across several X-ray datasets and detectors.
Researchers propose a triple-chain architecture for sensitive thumbnail-preserving encryption (TPE), arguing that existing TPE schemes encrypt pixels, blocks, or channels independently, which creates security vulnerabilities. The design links three encryption chains at the pixel, block, and channel levels, so any minor change to the original or encrypted image produces completely different encryption or decryption results. The authors report that the approach achieves sensitive TPE while keeping visual usability and privacy protection.
The source is a bibliographic record for a Computers & Security article by Zexiao Zou, Zhiqiang Wang, Baoxu Liu, Yuyang Han and Yan Zhang, available online 10 June 2026. It is titled "Hiding the trees in the forest: Building network covert channels with hash-based covert carrier filtering." The provided text contains no abstract, method details or findings.
Researchers examine a two-sided threat to power grids with renewable distributed energy resources (DERs), called ToLaR, which jointly exploits load-side and DER-side dynamics beyond conventional MadIoT. Tests on six benchmark systems and a physical microgrid testbed show ToLaR produces comparable cascading impacts at only 10% of MadIoT's attack cost. By manipulating the fast frequency response of energy storage systems, the transient grid frequency can be driven down to 53 Hz, triggering severe instability.
PAAS is a policy-adaptive traceable anonymity scheme for cross-domain networks, designed to meet FATF Travel Rule obligations for virtual asset service providers (VASPs) without giving up user privacy. It maps trace tiers to a hierarchical, role-weighted t-of-n threshold structure and separates pseudonym linkage from real-world identity disclosure, while bounding revocation-bypass risk within a latency window Δ. The authors report service-phase latency of 0.22 ms or 6.12 ms and throughput of about 49.5 TPS under 100 concurrent users, outperforming the evaluated baselines.
The source is a survey article titled "A Survey of Neural Network Robustness Assessment in Image Recognition," published in ACM Computing Surveys, Volume 58, Issue 12, pages 1-40, in September 2026. The provided text contains only the bibliographic citation and no abstract, method, or findings.
The source is a journal citation for a paper titled "Watermarking for Model Ownership Verification: Invisible at Deployment, Activated by Updates," published in ACM Transactions on Privacy and Security, Volume 29, Issue 3, pages 1-28, August 2026. The source text contains no abstract, method, or findings, so the summary cannot describe the research beyond its title and publication details.
Fix: The source states that the authors propose countermeasures from the perspectives of the power grid, the network system, and attack detection, but does not give their specific details.
IEEE Xplore (Security & AI Journals)TAPGuard is a semantics-enhanced framework for modeling rule linkages and detecting cascading threats in Trigger-Action Programming rules for smart home devices. It uses large language models to extract structured semantic elements from natural language rule descriptions, then applies a dual-relation context encoder with node-level and semantic-level attention to reason across multi-hop dependencies. Evaluated on a real-world smart home dataset, it significantly outperforms state-of-the-art graph-based baselines.
Researchers show that black-box targeted attacks on Large Vision-Language Models can be made more precise by working through the projector, a semantic bridge between vision and language. They propose Intermediate Projector Guided Attack (IPGA), which aligns Q-Former query outputs with a target and transfers across models, and IPGA with Residual Query Alignment (IPGA-R), which also preserves non-target content for fine-grained edits. The authors report that IPGA beats baselines on global attacks, IPGA-R wins on fine-grained attacks, and the method transfers to Google Gemini and OpenAI GPT.
SOOM is a schedule-search-based operator obfuscation method that defends compiled DNN models against model extraction attacks on standard CPU and GPU backends. Built on TVM, it uses a security-aware learned cost model based on XGBoost gradient boosted trees to balance security and performance. Tests over 105 operator configurations and more than 30,000 tensor computation test cases raised the operator inference failure rate against state-of-the-art extraction attacks to as high as 89%, with performance gains of up to approximately 25.4% in selected cases.
Fix: SOOM: a schedule-search-based operator obfuscation method built on TVM, using a security-aware learned cost model based on XGBoost gradient boosted trees to generate obfuscated executable code for deep learning operators.
IEEE Xplore (Security & AI Journals)This paper shows that existing model fingerprinting techniques for open-source model IP are vulnerable to false claim attacks, where adversaries assert ownership of independent third-party models. The authors attribute this to untargeted methods that compare arbitrary sample outputs, and propose FIT-Print, a targeted paradigm with two black-box methods, FIT-ModelDiff and FIT-LIME. Reported results include a 100% defense success rate against false claims, a 0.0% false alarm rate on independent models, and a 100% ownership verification rate across diverse model reuse techniques.
Fix: FIT-Print: a targeted fingerprinting paradigm that uses optimization to turn the fingerprint into a verifiable, targeted signature, implemented via the black-box methods FIT-ModelDiff (bit-wise, using output distances) and FIT-LIME (list-wise, using feature attributions).
IEEE Xplore (Security & AI Journals)Researchers propose DANP (Dual Attention-Guided Noise Perturbation), an immunization method that adds imperceptible perturbations to text-to-image diffusion models to resist malicious edits. DANP works across multiple timesteps, reducing cross-attention in text-relevant regions while increasing it in irrelevant ones, and maximizes the discrepancy between injected noise and predicted noise. The authors report state-of-the-art performance against malicious edits.