Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
41 items
Alalade, Mayhoub and Matrawy present a privacy threat analysis (PTA) and risk management approach for Smart Home (SH) systems, published in Computers & Security with online availability from 13 August 2026. The source text provided contains only the bibliographic details and no abstract, method or findings, so the research question and results cannot be stated from it.
REI-Net is an end-to-end network that extracts binarized internal fingerprints (IF) and internal sweat pores (ISP) directly from raw 3D OCT volumes, using depth projection instead of slice-by-slice B-scan segmentation. Its two-stage design, a Depth Compressor with a Depth-Breadth Separation Block based on Mamba and a Plane Refiner, reaches state-of-the-art results on the ZJUT-EIFD dataset, with the highest NFIQ 2.0 quality scores for IF and the lowest ISP false detection rates. Total inference time is 605ms.
CoLPR is a contrastive self-supervised framework for system-wide ransomware detection that learns perturbation-resilient representations, so it can separate benign-malicious traits from interference caused by concurrently running applications. Its Inborn augmentation strategy executes realistic application combinations and builds positive pairs with the same co-participants under diverse perturbations. The authors report 100% recall, 98.7% accuracy and an average detection delay of 5.31 seconds across three deployment environments, outperforming baselines by 5%–10% under multi-application interference.
This paper proposes an AI-based gait authentication framework that uses swing phase dynamics to identify individuals. It appears in Digital Threats: Research and Practice, Volume 7, Issue 3, pages 1-16, September 2026. The source text provided contains only the citation and no method details or results.
The source is a Computers & Security publication, available online 7 August 2026, by Haina Song, Hongfei Chen, Mengyao Wang, Fan Zhang, Nan Zhao and Zhangqing He, titled 'Multidimensional data collection via interval-based perturbation under (ϵ, δ)-local differential privacy'. The supplied text contains only the title, publication metadata and author list, with no abstract, method, or findings, so the research content cannot be summarized from it.
LICA is a lattice-based identity-based encryption scheme with commitment assistance that detects quantum Incorrect-Plaintext Attacks in data sharing. The authors pair it with LICADS, a data sharing protocol in which a trusted arbitration authority runs a probabilistic challenge and identifies the malicious party. Experiments show computational overhead comparable to existing schemes and communication overhead of about 45 KB under the Module-LWE instantiation, versus 4–6 KB for others.
Researchers propose FVCC, a fast and verifiable coded computation framework for robust distributed learning, targeting straggler and Byzantine nodes in mobile and edge training. It combines two-dimensional Shift-and-Add encoding with a bidirectional two-dimensional ZigZag Decoding algorithm (4D-ZD) for parallel decoding, and adds a lightweight verification step based on Freivalds' algorithm. Experiments report that 4D-ZD decodes about 2x faster than the state of the art, and that FVCC cuts training time by about 38.55% on small-scale and 42.87% on large-scale tasks while keeping model accuracy.
GraphWave is a multimodal framework for network traffic classification that builds maximal connected subgraphs from attacker, target and temporal context, then fuses wavelet-enhanced dynamic graph attention with Transformer temporal encoding through cross-attention. Evaluated on six real-world datasets, it reaches a 99.13% F1-score, outperforming state-of-the-art methods by 7.62% on average, and the authors report robustness against traffic obfuscation, temporal confusion and low-and-slow evasion.
This research article presents a lattice-based lightweight mutual authentication protocol for Vehicle-to-Grid (V2G) communication between electric vehicles and charging stations over open wireless channels. The authors state that most existing schemes are vulnerable to post-quantum threats, which motivates the design. The protocol's security is checked with formal analysis, automated verification using the AVISPA tool, informal security analysis, and performance simulations.
DiEL is a face enhancement method that disentangles identity and pose information and optimizes reconstruction, adversarial, and identity-preserving objectives together. It uses a unified face pose dictionary to keep reconstructed faces pose-consistent. Across six benchmarks (MS1M, LFW, CPLFW, CFP-FF, CFP-FP, AgeDB), it averages a 4.66% improvement over state-of-the-art methods, with the largest gains on CPLFW and CFP-FP.
GeoPrivd is a geospatial framework for urban traffic video analytics that answers declarative spatio-temporal queries over object observations with formal differential privacy guarantees. It avoids raw trajectories and trusted trackers by slicing and bounding trajectories to limit per-user influence, and queries are written in GeoPrivdQL, a domain-specific language with built-in privacy controls. Experiments on real-world urban traffic datasets report better utility, stability and privacy resilience than standard DP baselines.
MDIGuess is an autoregressive neural framework for targeted password guessing that combines three information dimensions: historical passwords, personally identifiable information, and general leaked-password data. Across eight attack scenarios built from nine large-scale password datasets, it reached an average cracking success rate of 35.14% within 1,000 guesses, a 43.64% average improvement over four state-of-the-art baselines. The authors also developed MDI-PSM, an attack-aware password strength meter that incorporates multi-dimensional targeted-risk signals.
This paper proposes Consistency Model-based Adversarial Purification (CMAP), which removes adversarial perturbations from inputs to deep neural networks by optimizing vectors in the latent space of a pre-trained consistency model. The method combines a perceptual consistency restoration mechanism, a latent distribution consistency constraint, and an ensemble-based latent vector consistency prediction scheme. Experiments on CIFAR-10 and ImageNet-100 report significantly improved robustness against strong adversarial attacks while preserving high natural accuracy.
The paper proposes Feature-alteration Robustness (FAR), a method for out-of-distribution (OOD) detection. It rests on the observation that a pretrained in-distribution model stays robust when its intermediate feature maps are altered, while OOD features are heavily distorted. FAR alters intermediate feature maps and measures foreground-background deviations after several layers, and the authors report state-of-the-art results on various benchmarks, alone and combined with ASH.
DeepU is a machine unlearning framework that removes the influence of selected training data at the level of individual weights. It scores each weight by the signal-to-noise ratio of gradients from sensitive and non-sensitive data, then resets, perturbs, decays or stabilizes weights accordingly. On CIFAR-10, CIFAR-100, Tiny ImageNet and CelebA, it cut successful membership inference attacks by 60–90% with under a 3% accuracy drop, and re-tuning took 20.75 seconds and 102.47 MB, up to 36.6 times faster than competing methods.
Researchers introduce the Textual Dynamic Outputs Attack (TDOA), a text adversarial attack for settings where the number and content of model labels vary, such as LLM outputs and multi-label classification. TDOA trains a clustering-based surrogate model that approximates dynamic fine-grained outputs with static coarse-grained labels, and uses a farthest-label targeted strategy to induce larger output changes. Evaluated on five datasets and ten victim models including GPT-4o and GPT-4.1, it reaches an 80.8% maximum attack success rate with five queries per text.
The paper presents PACT, a privacy-preserving tree model evaluation scheme built on additive homomorphic encryption. It supports parallel comparison by exploiting the overflow behavior of two's complement, and selects tree paths non-interactively using homomorphic addition, with perturbation and shuffle methods to protect model and query sample privacy. Experiments on real-world and synthetic datasets report lossless accuracy and better running efficiency than existing private decision tree evaluation schemes.
Researchers present LawSentry, an automated framework that uses large language models to turn natural-language traffic laws into executable violation oracles for autonomous driving systems. In evaluation, the framework generated 55 oracles for traffic laws from four countries and regions, running on LGSVL and Carla, with 95.5% detection accuracy. Using these oracles, the authors found 7+7 previously unknown flaws in two stable versions of the Apollo industry ADS, Apollo 7.0 and Apollo 8.0.
Researchers propose a framework for detecting AI-generated images that combines three modules: NF2E, which captures sensor-level inconsistencies in residual noise, SFAM, which flags abnormal spectral distributions, and GMPS, which adds learnable Gaussian priors to patch-level attention in the CLIP visual branch. The authors report that the method generalizes to unseen GAN- and diffusion-based generative models across extensive experiments. Code is to be released at the GitHub repository wangjun9276/AIGI_SFAHDetection.
Researchers propose a differential privacy-enabled cascaded filter for federated learning, which selects model parameter dimensions with large absolute values and significant variation and adds random noise to them before sending parameters to a central server for aggregation. The authors report theoretical convergence and experimental results across four datasets under IID and non-IID conditions, claiming better performance than other methods from the literature.