Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
25 items
This study examines how member mobility cascades affect virtual teams on a large gaming platform, and how key members can be identified through their consistent network-building preferences. Using relational event models on 6,114 individuals who joined or left 3,056 teams over three years, the authors find that collaboration-prone members follow inbound mobility cascades, driven by a preference for integrating disconnected members and seeking recognition for prosocial contributions. Arbitration-prone members instead deviate from outbound cascades, preferring to converge diverse resources and control resource flows.
Researchers propose Π_coll-min, a collusion-minimized TLS attestation framework that extends existing DCTLS protocols to support jointly verifiable attestations with distributed verifiers. It combines dx-DCTLS, a transformation layer that makes DCTLS outputs exportable, with a decentralized validation layer built on distributed verifiable random functions (DVRFs) and a threshold signature scheme (TSS). A prototype reduces prover complexity from O(n) to O(1) and stays efficient at high threshold sizes compared with a DECO-based baseline.
This paper proposes a known/unknown attack detection method for intrusion detection systems that uses inter-class relationships, with a virtual class inserted near known attack categories and soft-label prototypes compared to predictions via Kullback-Leibler divergence. A Gaussian Mixture Model models the divergence distribution to identify unknown attacks. On NSL-KDD, the method improves the harmonic mean of known and unknown class detection accuracy by over 7% relative to state-of-the-art methods, and it raises unknown attack detection accuracy by about 1.12% on CICIDS2017 and 5.24% on NSL-KDD.
TWReID is a through-wall and free-walking person re-identification system built on a customized MIMO radar with a 4 TX by 16 RX antenna array, using 1 to 2 GHz FMCW signals. The authors report mAP and CMC-1 of 86.8% and 96.5% on a 14-person free-walking dataset, and 64.6% and 95% on a dataset with varied behaviors, outperforming existing identity recognition and person Re-ID methods.
The paper studies Federated Generalized Category Discovery (Fed-GCD), where clients collaborate privately to cluster unlabeled samples from known and unknown classes. It proposes Personalized Contrastive Graph Learning (PCGL), which separates generic and personalized knowledge, using a KNN-Former for local-graph contrastive learning and adaptive parameter masking with personalized aggregation. On six datasets, PCGL outperforms state-of-the-art methods, with a 4.8% average gain on All ACC for long-tailed natural and medical image datasets.
This paper presents a framework for building differentially private cumulative distribution functions (CDFs) based on functional analysis and the functional mechanism. It introduces two variants, a polynomial projection method and a sparse approximation method via matching pursuit, which approximate the empirical CDF and privatize the resulting coefficients. The authors report performance comparable or superior to histogram queries, tree-based methods, and adaptive quantiles.
The source text is a bibliographic listing for the paper "AttackLogGen: Benchmarking LLMs for Generating Attack Logs," published in Digital Threats: Research and Practice, Volume 7, Issue 3, pages 1-25, September 2026. It provides no abstract, method, findings, or other article content.
This survey reviews trustworthiness in Retrieval Augmented Generation (RAG) for large language models. The source text provided is limited to the bibliographic line (ACM Computing Surveys, Volume 58, Issue 15, Pages 1-36, November 2026) and does not include the article body, so no findings or methods can be reported.
This ACM Computing Surveys paper, titled "A Comparative Survey of Security Risks in AI Systems: From LLMs to AI Agents and Embodied Agents," appears in Volume 58, Issue 15, pages 1-38, November 2026. The source text provided contains only the citation details, so its research question, method and findings cannot be summarized from it.
Adapdoor is an attack framework that injects action-level backdoors into deep reinforcement learning models during training, so that adversaries can manipulate action outputs at deployment. It initializes the backdoor reward from benign reward statistics and iteratively fine-tunes it using performance feedback from benign and backdoor tasks. Across 3 DRL algorithms, 11 environments and 53 backdoor tasks, it outperforms existing baselines by 42.0% to 144.2%.
Fix: The source says the authors evaluate three potential defenses to explore pathways for mitigating this threat, but it does not name them or state a fix.
IEEE Xplore (Security & AI Journals)Researchers propose ADD, a plug-in defense framework that improves the adversarial robustness of ML-based Android malware detection (AMD) methods against problem space attacks, which generate real adversarial malware rather than only adversarial feature vectors. The authors report that ADD performs well against the evaluated state-of-the-art problem space attacks across multiple ML-based AMD methods. They also state that ADD enhances the adversarial robustness of real-world antivirus solutions.
Fix: ADD, a plug-in adversarial Android malware defense framework that enhances the adversarial robustness of ML-based AMD methods against problem space attacks.
IEEE Xplore (Security & AI Journals)The OWASP GenAI Security Project released its 2026 Top 10 for LLM Applications and debuted an Agent Control Standard, alongside new resources for securing generative and agentic AI. F5, WitnessAI, Evoke Security and Mondoo Inc. joined as new sponsors, and the community surpassed 30,000 members.
GECOMP is a generative textual adversarial attack that uses reinforcement learning for policy optimization. An LLM-based generator rewrites input sequences using an extensible library of compositional perturbations, constrained by semantic similarity and edit magnitude. Across four public datasets and five victim models, it achieved higher attack success rates than ten baseline methods while using fewer queries and less edit magnitude.
Researchers present 3DGAA, a framework for physical adversarial attacks on camera-based perception in autonomous vehicles. It uses 3D multi-view optimization with a 3D Gaussian splatting surrogate to produce print-only vehicle wraps that keep geometry unchanged. In CARLA simulations and miniature-vehicle tests, the wraps substantially reduced detection confidence and average precision across multiple modern detectors.
WPEBA is a frequency-driven ensemble black-box adversarial attack for visual recognition systems that uses wavelet packet decomposition to split images into frequency sub-bands. It adjusts sub-band weights from internal gradient feedback and updates surrogate-model weights from target-model query feedback, reaching an average attack success rate of nearly 99% with one or two queries across six standard architectures. The authors report it also remains effective against defended models and the Google Cloud Vision API.