aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
1217 items

On the Insecurity of Internally Sampled Honeyword Schemes

inforesearchPeer-Reviewed
security
Apr 23, 2026

Honeywords are fake passwords (decoys) stored alongside real passwords to detect when password databases are leaked. This research reveals critical security flaws in honeyword schemes that generate decoys by sampling from actual user passwords (internal sampling), showing that attackers can distinguish real passwords from decoys with success rates of 3.82%–44.8% depending on their capabilities, which exceeds the intended security target of 2.50%.

IEEE Xplore (Security & AI Journals)

Fingerprint-based watermarking for protecting and tracing black-box NLP models

inforesearchPeer-Reviewed
security

AI-Enhanced Cybersecurity in Edge Computing: Threats, Solutions, and Future Directions

inforesearchPeer-Reviewed
security

Preparing Business Professionals for AI-Enabled Future: An Outline for AI for Business Competency Framework

inforesearchPeer-Reviewed
research

Anubis : A smart context-aware security model for access control

inforesearchPeer-Reviewed
security

Optimizing stealthiness in universal adversarial perturbations via class-selective and perceptual similarity metrics

inforesearchPeer-Reviewed
security

Robust Identity-Based Signcryption Scheme for Vehicular Ad Hoc Networks

inforesearchPeer-Reviewed
security

ThreatMAMBA: Achieving High-Robustness Cyber Threat Attribution During the Evolution of Attacks

inforesearchPeer-Reviewed
research

Efficient Privacy-Preserving Jaccard Similarity Evaluation Over Multisets for Secure Collaborative Data Analysis

inforesearchPeer-Reviewed
security

LLLMs: A Data-Driven Survey of Evolving Research on Limitations of Large Language Models

inforesearchPeer-Reviewed
research

Systematic Literature Review on Differential Privacy in Machine Learning

inforesearchPeer-Reviewed
research

Privacy in Collaborative Deep Learning Systems: A Taxonomy and Archetypes

inforesearchPeer-Reviewed
research

BioGuard: Malicious sample free defense method for biometric classifiers against model extraction attacks

inforesearchPeer-Reviewed
security

Early-Stage Detection of Encrypted Malware Traffic via Multi-Flow Temporal Graph Learning

inforesearchPeer-Reviewed
research

T3AT: Threshold-Authorized, Threshold-Redeemable, and Non-Transferable Anonymous Tokens

inforesearchPeer-Reviewed
security

ESCM: A Toolkit for Efficient and Secure Outsourced Computation With Multiple Keys

inforesearchPeer-Reviewed
research

Toward Robust Receiver-Invariant Specific Emitter Identification via Multi-Task Adversarial Learning

inforesearchPeer-Reviewed
research

Heterogeneous Privacy-Preserving Federated Learning for Edge Intelligence

inforesearchPeer-Reviewed
research

Analysis of Collaborative Data Privacy Leakage: A Macro-Level Perspective

inforesearchPeer-Reviewed
privacy

Forgery-Resistant Range Queries via Multi-Client Order-Revealing Encryption

inforesearchPeer-Reviewed
research
Previous33 / 61Next
research
Apr 22, 2026

Researchers have developed a fingerprint-based watermarking technique to protect and track natural language processing models (AI systems trained to understand and generate text) that operate as black boxes (systems where users cannot see how internal decisions are made). This method allows owners to prove they created a model and trace where it has been used or copied without permission.

Elsevier Security Journals
research
Apr 22, 2026

This academic survey article examines how AI is being used to improve security in edge computing (processing data on devices near users rather than in distant data centers), while also exploring the new threats that arise when combining AI with edge systems. The article covers both the security challenges unique to AI-enhanced edge environments and potential approaches to address them, looking toward future developments in this field.

ACM Digital Library (TOPS, DTRAP, CSUR)
Apr 21, 2026

This paper proposes a framework for teaching AI skills to business students, arguing that universities should prepare graduates to lead AI-driven business transformation. The framework outlines seven competency areas, including AI literacy, governance and risk management, technology management, systems development, and AI strategy, to guide the design of business school programs that help students develop, deploy, and use AI solutions effectively in organizations.

AIS eLibrary (Journal of AIS, CAIS, etc.)
Apr 20, 2026

Anubis is a security model designed to control access to systems by understanding the context in which access requests are made, rather than using fixed rules alone. The model aims to make access control smarter by considering situational factors when deciding whether to grant or deny user permissions. This research was published in July 2026 in the Journal of Information Security and Applications.

Elsevier Security Journals
research
Apr 20, 2026

Universal Adversarial Perturbations (UAPs, tiny modifications to images that fool AI models across many different inputs) are security threats to deep learning systems, but existing methods make attacks obvious because they either look wrong to humans or cause suspicious misclassifications. This paper presents Stealthy-UAP, a framework that makes UAPs harder to detect by targeting only semantically related classes (so misclassifications seem plausible) and optimizing perturbations to match how humans actually perceive images.

Elsevier Security Journals
Apr 20, 2026

This research proposes RIBSC, a security system for VANETs (vehicular ad hoc networks, where vehicles communicate wirelessly with each other and roadside infrastructure) that protects privacy during vehicle-to-road communication. The system uses signcryption (a technique that simultaneously encrypts and digitally signs messages) combined with a session key distribution mechanism and traceable pseudonyms to prevent privacy breaches while allowing authorities to identify vehicles involved in illegal activities.

IEEE Xplore (Security & AI Journals)
security
Apr 20, 2026

Cyber Threat Attribution (CTA) is the process of identifying who carried out a cyberattack by analyzing evidence from the attack. This paper introduces ThreatMAMBA, an AI framework that improves CTA by building knowledge graphs from threat intelligence data (IOCs, or indicators of compromise that identify malicious activity; TTPs, or tactics and techniques used by attackers; and temporal relationships) and using machine learning to identify attackers even in the early stages of ongoing attacks. The system showed significant improvements in accuracy at different stages of attack development, suggesting it can provide reliable attribution information quickly during real incidents.

IEEE Xplore (Security & AI Journals)
privacy
Apr 20, 2026

This paper addresses privacy and security concerns in collaborative data analysis by proposing a new method for computing Jaccard Coefficient (a mathematical measure comparing similarity between two sets). The proposed protocol protects sensitive information like intersection and union cardinalities (counts of shared and combined elements) while maintaining high accuracy and computational efficiency, and can be enhanced further using cloud-assisted encryption to improve performance by 25.5% to 30.4%.

IEEE Xplore (Security & AI Journals)
Apr 18, 2026

This is a research survey published in ACM Computing Surveys that examines the limitations and problems of large language models (LLMs, which are AI systems trained on massive amounts of text data to generate human-like responses). The survey takes a data-driven approach to understand how LLM research has evolved as scientists discover and study these systems' weaknesses and constraints.

ACM Digital Library (TOPS, DTRAP, CSUR)
privacy
Apr 18, 2026

This is a systematic literature review, a type of research paper that surveys and analyzes existing studies on differential privacy (a mathematical technique that adds carefully measured noise to data to protect individual privacy) in machine learning. The review examines how researchers are applying differential privacy to train AI models while keeping personal information safe from being extracted or misused.

ACM Digital Library (TOPS, DTRAP, CSUR)
privacy
Apr 18, 2026

This academic survey paper categorizes and describes different privacy concerns and system designs in collaborative deep learning (machine learning where multiple parties train models together while keeping their data private). The paper creates a taxonomy, which is a systematic classification scheme, to help organize the various approaches and challenges in this field.

ACM Digital Library (TOPS, DTRAP, CSUR)
research
Apr 17, 2026

Researchers have developed BioGuard, a defense method that protects biometric classifiers (AI systems that identify people using fingerprints, faces, or iris scans) against model extraction attacks (where attackers try to steal or copy the AI model by repeatedly querying it). The method works without needing malicious sample data to train it, making it practical for real-world deployment.

Elsevier Security Journals
security
Apr 17, 2026

Malware often encrypts its network traffic (data sent over the internet) to hide its activities, making it hard to detect using traditional methods. Most existing detection systems need complete traffic data to work well, but this research presents DawnGuard, a new system that can identify encrypted malware traffic very early in an attack, when only a small amount of data is available, by using temporal graph learning (analyzing how multiple network connections relate to each other over time) and a Vision Transformer (a type of deep learning model that captures patterns across data). The system achieved 95.11% accuracy using just the first 20% of traffic data.

IEEE Xplore (Security & AI Journals)
Apr 17, 2026

This academic paper presents T3AT, a new cryptographic system for creating anonymous tokens (digital proof of eligibility that doesn't reveal who you are) that can be issued and verified by multiple parties working together, rather than requiring a single trusted authority. The system uses advanced mathematical techniques including threshold signatures (where multiple parties must cooperate to authorize something) and verifiable computation methods to ensure tokens cannot be transferred between users and cannot be forged, while maintaining privacy without needing trusted hardware or centralized control.

IEEE Xplore (Security & AI Journals)
security
Apr 17, 2026

ESCM is a toolkit that uses homomorphic encryption (a technique that lets computers process encrypted data without decrypting it first) to let cloud servers perform calculations on data from multiple users who each have their own encryption key. The toolkit addresses security risks by using a distributed two trapdoor cryptosystem with threshold decryption (a system where multiple servers must cooperate to decrypt data, so no single server can access the information alone), which protects against server collusion and outages.

IEEE Xplore (Security & AI Journals)
Apr 17, 2026

This research addresses a problem where AI models trained to identify radio transmitters (specific emitter identification, or SEI) fail when tested on different hardware receivers due to shortcut learning (when models rely on irrelevant patterns instead of genuine features). The authors propose MTL-SEI, a framework that uses adversarial training (a technique where two competing AI systems help each other improve) and multiple related learning tasks to teach models to ignore receiver-specific artifacts and focus on true transmitter fingerprints, achieving 88.50% accuracy on test data.

IEEE Xplore (Security & AI Journals)
privacy
Apr 17, 2026

This research proposes HeteroFed, a framework for federated learning (a distributed machine learning approach where multiple devices train a shared model without sending raw data to a central server) that addresses privacy and performance challenges in edge intelligence scenarios. The framework uses four main techniques: personalized model construction for different devices, dynamic gradient clipping (limiting how much model parameters can change), adaptive noise addition for privacy protection, and improved model aggregation to maintain accuracy despite privacy protections.

Fix: The source proposes HeteroFed as a solution framework containing four specific mechanisms: (1) heterogeneous model construction to enable personalized model training for different smart devices, (2) dynamic gradient clipping to dynamically adjust the magnitude of gradients on models uploaded by devices, (3) adaptive noise addition to customize differential privacy (mathematical techniques that add noise to protect individual data) protection based on device model convergence status, and (4) deviation-aware model aggregation for accurate model aggregation to mitigate noise perturbation effects.

IEEE Xplore (Security & AI Journals)
research
Apr 17, 2026

This research paper examines macro-level collaborative leakage, which occurs when individually harmless data pieces reveal sensitive information when combined together. The authors conducted mathematical analyses to understand why this happens and found that the problem stems from how risk data (data that don't directly expose private information) correlate with sensitive information. While Gaussian distribution (a common bell-curve statistical pattern) can help prevent this type of leakage, the paper concludes that this protection is limited and more comprehensive security mechanisms are needed.

IEEE Xplore (Security & AI Journals)
security
Apr 17, 2026

Researchers discovered that two widely-used encryption schemes for secure database searches (m-ORE and om-ORE, which allow multiple parties to query encrypted data without revealing the queries or data) can be attacked by a malicious client and server working together to insert fake records into the database. The team developed a new scheme called MORES that fixes this vulnerability while also making searches about one-third faster and more efficient than the older schemes.

Fix: The source proposes MORES, described as 'the first multi-client ORE scheme that preserves range-query functionality while provably resisting arbitrarily malicious participants.' The text indicates MORES can serve as 'an immediate drop-in replacement for encrypted-database systems that demand both efficiency and robustness in adversarial environments,' but does not provide implementation details, version numbers, or step-by-step deployment instructions.

IEEE Xplore (Security & AI Journals)