Research
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
11 items
Duan and Ling published GDPFDL in the Journal of Information Security and Applications, Volume 103, in December 2026. The source text gives only the title, publication details and authors, so no research question, method or findings can be reported.
The paper asks whether a network intrusion detection system's model can be extracted using only hard-label black-box queries. The source text provided gives only the title, publication date (December 2026), journal (Journal of Information Security and Applications, Volume 103), and authors (Donguk Min, Seungsoo Nam, Daeseon Choi), with no method description or findings.
Stuart Russell's human-compatible AI framework proposes that AI systems should defer unconditionally to human operators. This paper argues that total deference carries its own risks and limitations, and reports a HICSS workshop panel on (un)cooperative robots that can refuse human directives for principled reasons. The panel identified eleven research themes, including authority hierarchies, benevolent uncooperativeness, and AI liability, and called for research beyond compliance-centric AI design.
The source is a December 2026 article in the Journal of Information Security and Applications (Volume 103) by Zeynab Anbiaee, Mahdi Rabbani, Mansur Mirani, Gunjan Piya, Igor Opushnyev, Ali Ghorbani and Sajjad Dadkhah. Its title indicates a comparative security threat modeling analysis of the MCP, A2A, agora and ANP AI-agent protocols. The provided text contains only publication metadata, so no findings or methods are available to report.
Liu, Wen and Yu published an article in the Journal of Information Security and Applications, Volume 103, dated December 2026. The source text provided contains only the publication metadata and author list, with no abstract, method or findings.
Researchers introduce IndirectAD, a data poisoning attack against recommender systems inspired by Trojan attacks on machine learning. The attack first promotes a trigger item, then transfers that advantage to a target item by creating co-occurrence data between them, which reduces the number of controlled accounts needed. Experiments on multiple datasets and recommender systems show noticeable impact with only 0.05% of a platform's user base.
AdvNup is a physical adversarial attack that spoofs deep neural network speaker recognition systems using near-ultrasonic perturbations played through commercial off-the-shelf speakers, avoiding the specialized hardware that earlier ultrasound attacks required. The authors use single-sideband modulation with low-pass filtering, a nonlinear frequency response model, and time-frequency masking to keep the adversarial signal intact through physical transmission. In simulated and physical experiments, it reached a 100% attack success rate for closed-set identification and over 90% for open-set identification in targeted attacks.