Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
22 items
This paper presents a thought experiment about a pedagogical twin, a hypothetical educational systems application that does not yet exist. It applies Mason's PAPA ethical framework to the risks of instantiating such a twin and draws on Vallor's virtue ethics to suggest a suitable mindset for the project.
Researchers studied how workers in automation-related sectors anticipate ethical concerns about automation and robotics. Using generative AI to create visual scenarios, they ran a visual Q-study with 90 participants in Australia, South Africa, the United Kingdom, and the United States, who ranked scenarios by how worrying they found them. Three composite views emerged, centred on controlling automation to prevent ecological and security risks, valuing robots while cautioning against close human–robot integration, and concerns about changing work dynamics and inclusivity.
An expert panel at ECIS 2025 in Amman, Jordan, examined real-time data sharing frameworks (RTDSFs), which support low-latency, cross-organisational data flows in finance, healthcare and energy. Through interpretive analysis of the panel transcript and polling of eighteen participants, the authors propose four pillars for Information Systems research: trust, governance, federated intelligence, and security collaboration under cascade risk. Polling results are presented as indicative only, showing alignment on enforceable governance and regulatory engagement.
This paper addresses joint beamforming for covert integrated sensing and communication (ISAC) under dual uncertainties at a passive eavesdropper: imperfect channel state information and unknown noise power. It maximizes radar mutual information while meeting covertness and quality of service requirements. Simulations report that the robust optimization and PPO-RB methods enlarge the feasible covert region while preserving radar sensing, communication quality and covert security in static and dynamic settings.
UFOs is an MPC toolkit built for operands whose values span only a few bits, such as 4-bit values in a 16-category task, but which run inside a much larger arithmetic field. Its one-hot vector generator reaches t-log t-1 multiplication gates and ceil(log log t) depth for t=2^k, and its sorting protocol is 3.4x faster online and 1.4x faster offline than Hamada et al.'s radix-sort baseline when sorting 2^16 elements among five parties.
SheepHunter is a method that reduces false positives in provenance-based intrusion detection systems (PIDSes), which flag anomalous processes but cannot tell abnormal processes from benign ones with unfamiliar patterns. It represents processes as high-dimensional embedding vectors built from execution context, access control attributes and provenance-graph structure, then classifies processes with high behavior density across dimensions, measured by a community splitting algorithm, as false positives. On two open-source datasets, it reduced false positives by an average of 43.8% for existing PIDSes.
Tramy is a dynamic searchable symmetric encryption scheme that lets multiple clients run conjunctive queries over encrypted data and tracks malicious servers, addressing a gap in Dory, which supports only single-keyword queries in a single-client setting. It hides the search pattern through a new primitive called Matrix-based Multi-Point Retrieval and uses a Malice-Defend Bloom Filter that supports conjunctive queries and verifies the integrity of server responses. Benchmarks reportedly show resistance to adaptive adversaries and up to 20x performance improvements over the state of the art.
The paper presents P3H-I, a privacy-preserving scheme for hierarchical heavy hitters detection that protects subordinate relationships across hierarchy levels using matrix-based encoding and secure three-party computation. It also presents P3H-II, a privacy-efficiency trade-off variant that uses prefix tree traversal, pruning, and pre-computation to reduce communication and computational overhead. The authors report robust privacy with low costs, outperforming existing methods.
VeriFPHM is a verifiable fuzzy private hash matching scheme for detecting harmful media in end-to-end encrypted communication without exposing the server-side hash set or revealing unmatched media. It uses multivariate polynomial commitments, adaptive Merkle trees, and Cuckoo hash buckets for verification and efficient dynamic updates, plus a two-step fuzzy matching protocol built on LPN-based VOLE. The authors report up to 100x faster certification than the scheme by Scheffler et al. and better update performance than state-of-the-art schemes.
HypSCA is a dual-space representation learning method for deep learning-based side-channel attacks. It embeds power or electromagnetic traces in hyperbolic space to model their hierarchical structure, while using Euclidean space for local discriminative learning. The authors report attack performance up to 30.8% better than state-of-the-art methods.
Practical Federated Unlearning (PFU) removes a target client's data contribution from a federated learning global model. It needs only one round of interaction between the target client and the aggregation server during unlearning. The server uses the Fisher Information Matrix to find the parameters most sensitive to that client's data and sends their indices to the client, which estimates its contribution with a Bayesian inference-based method and prunes those parameters, avoiding data or historical updates from other clients.
Existing evaluations of AI-based Windows malware detectors differ in training and test data, lack temporal analysis, skip adversarial content-injection tests, and ignore deployment compute costs, so they cannot show which detector to deploy. The authors introduce EXE-Bench, which assesses performance, temporal and adversarial robustness, and computational overhead, combining them into one score for direct comparison. Their analysis finds that feature-engineered domain knowledge remains highly useful, resisting both time and adversarial attacks, while most deep networks excel only right after deployment.
Vec2Null is a geometry-guided framework for one-shot personal identity unlearning on face-analytics models, where a user supplies a single new face image to request erasure. It first maps the image to a stable identity-level direction through UnoFace, a representation network trained with an asymmetric One-Shot Proxy objective, then applies a projection-based nulling update that steers changes away from retain-sensitive subspaces. The authors report state-of-the-art one-shot face unlearning results across multiple benchmarks, with code promised at github.com/CV-AC/Vec2Null.
Researchers investigate why adversarial attacks on graph convolutional skeleton action recognition models transfer poorly across architectures. They propose SVAttack, which combines a spatial gradient damper that suppresses model-specific spatial biases with a viewpoint-based constraint that improves imperceptibility. Across 3 benchmark datasets, 9 models, 7 attack methods and 2 defense methods, the approach significantly improves transferability while keeping skeleton motions visually plausible.
The paper presents the Advanced Cross-attack Backdoor Detector (ACBD), which detects trigger-injected samples by solving a labeled binary classification task based on disturbance immunity, rather than unlabeled feature clustering. ACBD is trained on one class of a poisoned dataset (1/100 of CIFAR-100) with two classic attacks, using a small LSTM with 53 K parameters and at most 10 clean images for perturbation. The authors report state-of-the-art detection with cross-attack generalization, including on unseen triggers and different target labels.
Researchers report that when a second backdoor is embedded into a deep neural network after an earlier one, the later backdoor suppresses the earlier one. Building on this, they propose Safedoor, a defensive backdoor embedded into suspect models using a small amount of data. Across eight representative backdoor attacks, Safedoor reduces the average attack success rate from 97.3% to 2.2%, while keeping clean-data accuracy high and adding 0.32% to inference time.
Fix: Safedoor: intentionally embed a later backdoor (Safedoor) into suspect DNNs that may already be infected, using the proposed efficient embedding algorithm.
IEEE Xplore (Security & AI Journals)Researchers propose SteerGuard, a framework that uses diffusion models to generate adversarial CAPTCHAs designed to defeat AI-based solvers. Their approach steers the diffusion generation process to embed adversarial semantics directly into CAPTCHA samples, with the aim of reducing manual dataset curation and enabling dynamic updates. The authors report superior transferability, robustness and adaptability across attacker strategies without added runtime cost, including validation on a large-scale online platform.
A research paper in the Journal of Information Security and Applications, Volume 103, published December 2026, describes a lightweight and practical approach to encrypted face recognition with GPU support. The source text provided contains only the publication metadata and author list, so the research question, method, and findings cannot be summarized from it.