Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
48 items
Researchers propose a blockchain-based scheme that combines secure deduplication with integrity auditing for encrypted cloud storage. The design uses random masking to produce unlinkable integrity proofs, protecting user ownership privacy during audits, and a blockchain ledger that records ciphertext-to-owner relationships so deduplication holds when users are offline. A lightweight hash-based probabilistic proof of ownership is added to resist duplicate-faking attacks without full-file verification.
This research proposes accountable-authority identity-based matchmaking encryption (A-IB-ME), which addresses key escrow and accountability for malicious behavior in IB-ME, where the authority can generate any identity's encryption and decryption keys. In A-IB-ME, the creator of an encipher box or decoder box can be implicated in disputes over key abuse. The authors give a formal definition and construction, a security proof under standard assumptions without random oracles, and a theoretical and experimental performance evaluation. They apply it to privacy-preserving user matching in mobile social networks.
This research measures the terrestrial soft error rate of a GPU-based implementation of TFHE, a variant of fully homomorphic encryption that supports logical operations, using accelerated proton irradiation experiments. The measured rate is 7.80 FIT (Failures In Time) for the decrypted output of a 32-bit adder. Assuming the overall error rate scales proportionally with circuit size, the authors estimate a silent data corruption (SDC) probability of 1.6% for multiplying 500-by-500 matrices.
Researchers propose a strategic data forgetting scheme for federated unlearning that accounts for a boundedly rational federated learning server. The scheme uses a prospect theory-driven data forgetting game to design a truthful incentive mechanism that encourages clients to retain more data during unlearning. A penalty mechanism discourages selfish behavior, and a zero-payment mechanism aims for equitable reward distribution. Simulations are reported to confirm the scheme motivates high-quality models and improves the accuracy of unlearned models.
CSFlow is a content-aware flow control system for fine-grained encrypted data sharing in cloud-edge settings. It extends access control encryption (ACE) with a cross-domain scheme, CACE, that tags each message with its content and sets sender policies over attribute vectors and tags. The authors give a formal security analysis of the selective no-read and no-write rules and of soundness for CACE.
AirMask is a defense system that protects WiFi-connected IoT devices from attacks that infer privacy-sensitive user behavior from side-channel fingerprints of wireless frames. Instead of modifying each device, it passively senses fingerprints in the air and injects crafted frames to mask them, operating in a predict-inject-assess loop. The authors report a hardware prototype with Integrated, TAP, and Air modes, evaluated on 90 IoT device types and 53 fine-grained behaviors with negligible bandwidth and latency overhead.
This paper proposes two hybrid physical-layer authentication schemes for mmWave MIMO beam alignment, a linear weighted combination scheme and a two-threshold combined scheme. They jointly use antenna array mutual coupling and angle of arrival to defend against impersonation attacks. The authors derive detection and false alarm expressions, optimize feature weights under a false alarm constraint, and validate the designs by simulation.
Researchers propose a dynamic differential privacy scheme for multi-agent electricity trading in smart grids, where agents have heterogeneous privacy needs. The method uses a weighted mutual information risk metric, a Markov decision process model, and adaptive noise injection with a denoising network, and the authors prove it satisfies ε-differential privacy. In simulations it improves privacy protection by 79.11% and 77.76% over fixed-noise and personalized-noise benchmarks, and the denoising network removes 50.97% of the cost increase caused by noise.
Researchers study how code obfuscation affects static analysis methods for detecting malicious JavaScript. They find existing detectors fail against medium-strength obfuscation and propose SeGra, which uses data flow features, random walks and sequence conversion of graph structure. SeGra reaches 99.5% accuracy on medium-strength obfuscated code and 70.4% on low-strength code, with 67.1% on high-strength code after learning from low-strength samples.
CVFL-Pro is a verifiable federated learning framework that lets clients check whether a malicious server has falsified aggregation results, without a trusted authority. It combines masking and Shamir's secret sharing for privacy and dropout robustness, a lightweight MAC scheme with auxiliary nodes for verifiability, and an adaptive compression algorithm, AOTop-k. On MNIST, CIFAR-10 and CIFAR-100 it cuts communication overhead by 58.07% versus Top-k and 95.81% versus SecAgg, while maintaining accuracy.
This paper examines whether existing machine unlearning methods truly remove the influence of target training samples when the training dataset contains many similar samples. Experiments on four constructed datasets for image and language models show a notable gap between expected and actual performance for most existing methods, including the retraining-from-scratch baseline. The authors also explore potential solutions to improve current unlearning approaches.
Fix: One proposed detection method leverages logic circuit-level redundancy and can detect nearly all SDCs, at the cost of reducing throughput to around 50%.
IEEE Xplore (Security & AI Journals)EncFormer is a two-party framework for private Transformer inference that combines fully homomorphic encryption (FHE) and secure multiparty computation (MPC). It adds Stage-Compatible Patterns to reduce repacking and FHE–MPC conversions, plus a secure complex CKKS–MPC conversion protocol. On GPT- and BERT-style models, it reports 1.4×–30.4× lower inference-time communication and 1.3×–9.9× lower end-to-end latency than prior hybrid FHE–MPC systems.
Researchers show that transferable adversarial attacks on Vision-Language Pre-training Models (VLPMs) can be simpler and more effective than existing multi-stage pipelines with complicated loss functions. They identify three overlooked issues caused by inappropriate cross-modal interactions and excessive operations, and propose the Simple Vision-Language Attack (SimVLA) pipeline. On the Flickr30k text-image retrieval dataset, SimVLA outperforms the SOTA baseline in R@1 transferability by 8.01%-14.71% while using about 35.73% of the time and 46.26% of the max VRAM.
Researchers propose SCPC, a framework for concept erasure in text-to-image models that removes a target concept while preserving semantically close concepts. Existing methods often degrade close-proximity concepts; for example, erasing 'English Springer' may hurt generation of 'Cocker Spaniel'. SCPC samples semantic-agnostic embeddings within a hypersphere around the erased concept, refines sampling with a learnable adversarial offset, and applies a semantic-agnostic knowledge distillation objective. Experiments reportedly show it erases targets while preserving generation quality for both close and distant concepts. Code and data are promised for future release.
Researchers propose Spa, a backdoor attack framework for federated learning that aims to be both stealthy and persistent. Instead of training a conflicting secondary task, Spa uses feature-space alignment to fold backdoor features into the primary objective, and it uses adversarial dynamic trigger optimization that co-evolves with the global model. Experiments report attack success rates near 100% with minimal utility loss, and the backdoor stays effective around 900 FL rounds after attacks stop.
SafeSteer is a lightweight inference-time steering framework that defends Vision Language Models against jailbreak attacks without modifying model weights. It uses singular value decomposition to purify a low-dimensional safety subspace from noisy activation differences, then projects the raw steering vector into that subspace. The authors report a reduction of over 60% in attack success rate while maintaining utility on benign tasks.
Deep learning point cloud classifiers are highly vulnerable to adversarial attacks, and existing diffusion-based purification defenses have a distributional gap and a semantic mismatch. The authors propose PANDA, a two-stage framework: PANDA-P trains a dual-branch diffusion purifier on both clean-to-clean and adversarial-to-clean paths, and PANDA-A fine-tunes the classifier with a consistency-driven objective to recalibrate its decision boundary. The source reports consistently superior robustness over existing purification-based defenses on synthetic and real-world benchmarks.
The authors present ParDef, a defense for deep neural networks against diverse parameter attacks, which directly tamper with model weights and persist across inferences. ParDef combines keyed channel reparameterization, QC-LDPC quantization with error correction, and adaptive robust inference. Evaluated on CIFAR-10, CIFAR-100, and Tiny-ImageNet with ResNet and VGG models, plus DeiT on ImageNet-1K and CIFAR-100, it consistently reduces attack success rates while keeping high model performance and moderate deployment overhead.
Fix: ParDef: keyed channel reparameterization, QC-LDPC quantization, and adaptive robust inference, applied to securing at-rest model parameters in DNN deployments.
IEEE Xplore (Security & AI Journals)HashRuler is a lightweight detection framework for backdoor attacks on deep hashing models used in large-scale image retrieval. It uses two metrics, Center Similarity Deviation (CSD) and Local Sparsity (LS), to flag poisoned samples by their hash codes, and reports up to 97% detection accuracy against the BadHash clean-label attack across diverse datasets, attack types and architectures.