aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
1217 items

Cybersecurity Challenges for the Elderly: Vulnerabilities and Risks

inforesearchPeer-Reviewed
security
Dec 22, 2025

Elderly people are increasingly using digital technology for communication and information access, but their limited cybersecurity knowledge makes them attractive targets for cybercriminals. The article examines common cybercrimes targeting seniors, the specific vulnerabilities that put them at risk, and existing approaches to reduce these dangers.

IEEE Xplore (Security & AI Journals)

Insider Threat Detection Using GCN and Bi-LSTM With Explicit and Implicit Graph Representations

inforesearchPeer-Reviewed
research

Enhanced Masking-Differential Prompting (MDP): Defending Backdoor Attacks for Pre-trained Language Models Under Few-Shot Learning

inforesearchPeer-Reviewed
security

Slack Federated Adversarial Training

inforesearchPeer-Reviewed
research

Exploring the Vulnerabilities of Federated Learning: A Deep Dive Into Gradient Inversion Attacks

inforesearchPeer-Reviewed
security

Proactive Bot Detection Based on Structural Information Principles

inforesearchPeer-Reviewed
research

Inner-Probe: Discovering Copyright-Related Data Generation in LLM Architecture

inforesearchPeer-Reviewed
research

The Most Overestimated Q Value Regularization in High-Dimensional Discrete Action Spaces for Offline Reinforcement Learning

inforesearchPeer-Reviewed
research

Evolving AI Transparency: The Journey of the AIBOM Generator and Its New Home at OWASP

inforesearchIndustry
security

Two-Server Offline/Online Private Information Retrieval With Small Client Storage

inforesearchPeer-Reviewed
research

LigSecOTA: Lightweight Over-the-Air (OTA) Software Updates With Integrated Security

inforesearchPeer-Reviewed
security

Model Steganography During Model Compression

inforesearchPeer-Reviewed
security

ChargerWhisper: Acoustic Side-Channel Attack Exploiting Fast Charger

inforesearchPeer-Reviewed
security

L-VAKMC: Lightweight Authentication and Dynamic Key Agreement for VANET Multi-Entity Communications

inforesearchPeer-Reviewed
security

Spurious Local Minima Provably Exist for Deep CNNs: Theory and Application

inforesearchPeer-Reviewed
research

Fully Perturbed Self-Ensemble Framework Using Cascaded Parallel CNN-Transformer for Semisupervised Medical Image Segmentation

inforesearchPeer-Reviewed
research

PDRU: A Privacy-Preserving Dual Reputation Updating Scheme With Multi-Dimensional Feedback Scores in Vehicle Platoon

inforesearchPeer-Reviewed
research

MPS-Fuzz: An Enhanced Fine-Grained Fuzzing Based on Units With Multiple Inputs and Outputs

inforesearchPeer-Reviewed
security

MDA-SMuSha: An Efficient and Flexible Multi-Dimensional Data Aggregation Scheme for Privacy-Preservation in Smart Grids

inforesearchPeer-Reviewed
security

Fully Private Shortest Path Computation With Single-Round Interaction

inforesearchPeer-Reviewed
research
Previous52 / 61Next
security
Dec 22, 2025

This article presents a new method for detecting insider threats (malicious activities by trusted employees within an organization) by combining two types of graph structures (explicit graphs based on predefined rules and implicit graphs derived from data patterns) with neural network models (GCNs and Bi-LSTM, which are deep learning architectures that process network relationships and temporal sequences). The framework was tested on two datasets and achieved very high accuracy rates, correctly identifying 100% of threats on one dataset while maintaining a low false positive rate (incorrectly flagging normal activity as suspicious).

IEEE Xplore (Security & AI Journals)
research
Dec 22, 2025

Pre-trained language models (PLMs, large AI systems trained on text data) can be vulnerable to backdoor attacks, where hidden triggers in input cause the model to produce manipulated output. This paper proposes an enhanced defense method called masking-differential prompting (MDP) that works with few-shot learning (training on very small datasets), using Jensen-Shannon divergence (a mathematical measure to compare probability distributions) instead of traditional methods and an automatic threshold-selection approach to better detect and block these attacks.

Fix: The paper proposes two enhancements to the masking-differential prompting (MDP) defense method: (1) adopting Jensen–Shannon (JS) divergence instead of Kullback–Leibler (KL) divergence to handle cases where anchor set information has insufficient density, keeping the divergence finite and better exploiting available data; and (2) proposing an adaptive threshold method that automatically searches for the threshold based on false rejection rate (FRR) allowance, replacing the computationally expensive manual threshold selection method using ROC curve (AUC).

IEEE Xplore (Security & AI Journals)
security
Dec 22, 2025

This research addresses a problem in federated learning (a method where multiple computers train an AI model together without sharing raw data) combined with adversarial training (a technique that makes AI models resistant to intentionally tricky inputs). The authors found that simply combining these two approaches causes the model's accuracy to drop because adversarial training increases differences in the data across different computers, making the federated learning less effective. They propose SFAT (Slack Federated Adversarial Training), which uses a relaxation mechanism to adjust how the computers combine their learning results, reducing the harmful effects of data differences and improving overall performance.

IEEE Xplore (Security & AI Journals)
research
Dec 22, 2025

Federated Learning (FL, a method where multiple computers train an AI model together without sharing raw data) can leak private information through gradient inversion attacks (GIA, techniques that reconstruct sensitive data from the mathematical updates used in training). This paper reviews three types of GIA methods and finds that while optimization-based GIA is most practical, generation-based and analytics-based GIA have significant limitations, and proposes a three-stage defense pipeline for FL frameworks.

Fix: The source mentions 'a three-stage defense pipeline to users when designing FL frameworks and protocols for better privacy protection,' but does not explicitly describe what this pipeline contains or how to implement it.

IEEE Xplore (Security & AI Journals)
security
Dec 22, 2025

This research proposes SIAMD, a framework for detecting social media bots (automated accounts that spread misinformation) before they cause harm. The system analyzes patterns in how user accounts interact with messages, uses structural entropy (a measure of uncertainty in data patterns) to identify bot-like behavior, and generates synthetic bot messages with large language models (AI systems trained on text data) to test and improve detection systems.

IEEE Xplore (Security & AI Journals)
security
Dec 19, 2025

LLMs trained on copyrighted datasets risk generating text that infringes on copyright, and current detection methods struggle to identify which specific data sources influenced the output. Inner-Probe is a new lightweight framework that analyzes multihead attention (MHA, the mechanism LLMs use to focus on relevant parts of input when generating text) to better identify which copyrighted subdatasets contributed to generated text and to filter out noncopyrighted content, achieving significantly better accuracy and efficiency than existing approaches.

IEEE Xplore (Security & AI Journals)
Dec 19, 2025

This paper addresses a problem in offline reinforcement learning (RL, a type of AI training that learns from pre-collected data without needing new real-world interaction) where Q value overestimation (the AI incorrectly thinking certain actions are better than they actually are) causes training problems in robotic tasks with many possible actions. The researchers propose MQR (most overestimated Q value regularization), an algorithm that specifically penalizes the single action with the worst overestimation rather than equally penalizing all actions, and demonstrate it achieves 99.04% success rates in real-world robotic grasping tasks.

IEEE Xplore (Security & AI Journals)
policy
Dec 18, 2025

The AIBOM Generator, an open-source tool that creates an AI Software Bill of Materials (AIBOM, a structured document listing key information about an AI model like its data sources and configurations), has been moved to OWASP (a nonprofit focused on software security) to enable broader community collaboration and development. The tool helps organizations understand what's inside AI models, where they came from, and how trustworthy their documentation is, addressing a gap between rapid AI adoption and lagging transparency practices. The project is now part of the OWASP GenAI Security Project and will continue improving AI supply chain visibility through community-driven enhancements.

OWASP GenAI Security
Dec 18, 2025

This paper introduces PIRS, a system for private information retrieval (PIR, where a user can fetch data from a database without revealing which data they want). PIRS uses two servers and splits the retrieval process into an offline phase, where the client preprocesses the database to create hints, and an online phase, where the client uses those hints to securely retrieve records. Unlike existing approaches, PIRS allows clients to store hints on the servers instead of locally, reducing storage needs from gigabytes to kilobytes by using secret sharing (a technique where data is split into pieces that are useless individually but combine to reveal the original).

IEEE Xplore (Security & AI Journals)
Dec 18, 2025

This research proposes LigSecOTA, a lightweight system for securely updating automotive software remotely without being hacked. Unlike existing systems that rely on digital certificates (cryptographic credentials identifying devices) based on physical identifiers that can be forged, LigSecOTA creates unique certificates based on timing information instead, and provides integrated security across authentication (verifying identity), confidentiality (keeping data private), integrity (ensuring data isn't tampered with), access control (limiting who can do what), and data freshness (confirming updates are current).

Fix: The source describes LigSecOTA itself as the proposed solution: a one-machine-one-certificate digital identity management system that issues unique digital certificates for each ECU (Electronic Control Unit, the computer in a vehicle) based on bit time information instead of physical identifiers. LigSecOTA ensures integrated security through three processes: authentication, authorization, and package distribution, with authorization dynamically providing keys for package distribution to enhance security.

IEEE Xplore (Security & AI Journals)
research
Dec 17, 2025

Researchers have developed a steganographic method (hiding secret data inside another medium) that embeds hidden messages into compressed neural network models (AI systems made smaller through techniques like quantization, pruning, or distillation). The approach allows a receiver with the correct extraction network to recover the hidden data while ordinary users remain unaware it exists, and the method maintains the model's performance in size, speed, and accuracy.

IEEE Xplore (Security & AI Journals)
Dec 17, 2025

ChargerWhisper is a side-channel attack (a method that steals information by observing physical properties rather than breaking encryption) that uses high-frequency inaudible sounds produced by fast chargers to infer private user information. The attack works because electronic components in chargers vibrate at frequencies correlated with power output, which changes based on what activities users perform on their devices, allowing attackers to identify websites being visited or unlock PINs through acoustic analysis.

IEEE Xplore (Security & AI Journals)
Dec 17, 2025

This paper presents L-VAKMC, a lightweight authentication protocol designed for VANETs (vehicular ad hoc networks, where cars communicate wirelessly with each other and roadside infrastructure). The protocol uses elliptic-curve cryptography (a mathematical method for secure communication), hash-based commitments, and ephemeral key exchange (temporary security keys that change frequently) to securely authenticate different types of communications in vehicular systems while keeping computational demands low. The authors tested the protocol and found it resists common attacks and works efficiently in real-time vehicle environments.

IEEE Xplore (Security & AI Journals)
Dec 17, 2025

Researchers proved that spurious local minima (points where a neural network stops improving, but isn't at the best solution) definitely exist in deep CNNs (convolutional neural networks, which are commonly used for image recognition). They created a method to construct these problematic points mathematically and designed a new optimization algorithm (a step-by-step process for improving the network) that can escape from them, showing better accuracy than standard training methods like SGD or Adam on image datasets.

Fix: The source proposes a deterministic optimization method to escape local minima that is applicable to CNNs, ResNets, MLPs, and transformers. The authors report that experimental results on CIFAR-10, CIFAR-100, and ImageNet-1k datasets show their optimization method outperforms SGD or Adam in accuracy (by 0.27% on average) consistently across all tested architectures and datasets.

IEEE Xplore (Security & AI Journals)
Dec 16, 2025

This paper addresses challenges in semisupervised medical image segmentation (using AI to identify structures in medical images when only some training data is labeled) by proposing FPSE, a framework that combines CNN (convolutional neural networks, which process images as grids of pixels) and transformer networks (which use attention mechanisms to focus on relevant parts of input). The key innovation is a "fully perturbed consistency learning" strategy that applies multiple types of perturbations (variations, like data transformations and feature modifications) to better learn from unlabeled images, while also using transformers on shallow features from CNNs to avoid needing excessive labeled data.

IEEE Xplore (Security & AI Journals)
Dec 15, 2025

Vehicle platooning (where multiple vehicles travel together in formation) needs to assess whether the lead vehicle is reliable, which is done through reputation management systems. Existing reputation systems have weaknesses in security, privacy, and use overly simple evaluation methods. This paper proposes PDRU, a new reputation system that uses dual reputation tracking (a backup system to prevent single-point failures), evaluates the lead vehicle across multiple dimensions, and keeps vehicle identities and reputation scores private.

IEEE Xplore (Security & AI Journals)
Dec 15, 2025

MPS-Fuzz is a new fuzzing technique (a method for finding bugs by automatically testing software with many random inputs) that improves upon existing approaches by using a better way to track which parts of code have been tested. The technique addresses problems like too many similar test cases and collision errors (when different code paths incorrectly get marked as the same) by organizing code into units called MPS (multiple predecessors and successors, which are basic blocks with multiple entry and exit points) and using an extra tracking system. Testing showed MPS-Fuzz found 25.7% more bugs than the standard AFL fuzzer and even discovered a previously unknown vulnerability in real software.

IEEE Xplore (Security & AI Journals)
Dec 15, 2025

Smart meters in electrical grids collect detailed energy usage data that can reveal private information about users, but protecting this data while combining readings from multiple meters requires heavy computation that strains devices with limited resources. Researchers developed MDA-SMuSha, a scheme that uses Shamir's multi-secret sharing (a cryptographic method that splits secrets among multiple parties) and Paillier encryption (a technique allowing calculations on encrypted data without decrypting it) to let smart meters efficiently protect and aggregate their multi-dimensional energy data while still allowing a control center to request statistics flexibly. Testing shows this approach uses less computation than existing privacy-protection methods while maintaining security, authenticity, data integrity, and fault-tolerance (the ability to continue working even if some components fail).

IEEE Xplore (Security & AI Journals)
Dec 15, 2025

This paper presents Srchpa, a privacy-preserving method for computing the shortest path (the most efficient route between two locations) between a user and a destination. Unlike traditional navigation systems where users must share their location with a server, Srchpa protects both the user's location data and the server's route information while requiring only a single round of communication (one back-and-forth exchange) instead of multiple interactions. The scheme is designed to work efficiently even on resource-limited devices like smartphones.

IEEE Xplore (Security & AI Journals)