aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
1217 items

FLEX: Flexible Linked EXecution for Real-Time Embedded Hotpatching

inforesearchPeer-Reviewed
research
Dec 15, 2025

FLEX (Flexible Linked EXecution) is a hotpatching technique that allows embedded systems to receive software updates without shutting down, by redirecting all function calls and variable accesses through a compile-time generated Control Flow Table. Unlike older approaches, FLEX works on any hardware, supports many patches at once, and introduces only about 11% execution overhead while using 17% more memory storage.

Fix: The source describes FLEX itself as the solution: it uses a 'relaxed consistency state synchronization mechanism to allow for gradual migration of program state, resolves all symbols at compile time into CFT (Control Flow Table) indirections, applies updates via a double-buffered pointer swap to a new CFT, and a XIP (execute-in-place) compatible process that guarantees only a short, bounded pause time regardless of patch complexity.'

IEEE Xplore (Security & AI Journals)

Trap: Mitigating Poisoning-Based Backdoor Attacks by Treating Poison With Poison

inforesearchPeer-Reviewed
security

Dynamic Attention Analysis for Backdoor Detection in Text-to-Image Diffusion Models

inforesearchPeer-Reviewed
security

Exploring the Agentic Metaverse’s Potential for Transforming Cybersecurity Workforce Development

inforesearchPeer-Reviewed
research

Special Issue Editorial: Brave New Work and the Future of Computing Professionals (Part 1)

inforesearchPeer-Reviewed
research

Optimal Online Control Strategy for Differentially Private Federated Learning

inforesearchPeer-Reviewed
privacy

AS-Level Topology Inference for Path-Aware Networking

inforesearchPeer-Reviewed
security

PPFPL: Cross-Silo Privacy-Preserving Federated Prototype Learning Against Data Poisoning Attacks

inforesearchPeer-Reviewed
security

Mimi: Dynamically Secure Multi-Keyword Retrieval Scheme With Two-Factor Verification

inforesearchPeer-Reviewed
research

Why Not Diversify Triggers? APK-Specific Backdoor Attack Against Android Malware Detection

inforesearchPeer-Reviewed
security

Learning Generalizable Representations for Deepfake Detection With Realistic Sample Generation and Dual Augmentation

inforesearchPeer-Reviewed
research

M&M: Secure Two-Party Machine Learning Through Modulus Conversion and Mixed-Mode Protocols

inforesearchPeer-Reviewed
research

Robust Traffic Forecasting With Disentangled Spatiotemporal Graph Neural Networks

inforesearchPeer-Reviewed
research

An XSS Attack Detection Model Based on Two-Stage AST Analysis

inforesearchPeer-Reviewed
research

Blockchain-Enhanced Verifiable Secure Inference for Regulatable Privacy-Preserving Transactions

inforesearchPeer-Reviewed
security

Security Analysis of WiFi-Based Sensing Systems: Threats From Perturbation Attacks

inforesearchPeer-Reviewed
security

Toward Understanding the Tradeoff Between Privacy Preservation and Byzantine-Robustness in Decentralized Learning

inforesearchPeer-Reviewed
security

Large-Scale Intranet Security Assessment Based on Bayesian Attack Graphs Using System Audit Logs

inforesearchPeer-Reviewed
security

Fairness-Aware Differential Privacy: A Fairly Proportional Noise Mechanism

inforesearchPeer-Reviewed
research

PPFPS: A Privacy-Preserving Platoon Management Scheme for Flexible Platoon Splitting in Urban Freight Delivery

inforesearchPeer-Reviewed
research
Previous53 / 61Next
research
Dec 15, 2025

This research addresses backdoor attacks, where poisoned training data (maliciously altered samples inserted into a dataset) causes neural networks to behave incorrectly on specific inputs. The authors propose a defense method called Trap that detects poisoned samples early in training by recognizing they cluster separately from legitimate data, then removes the backdoor by retraining part of the model on relabeled poisoned samples, achieving very high attack detection rates with minimal accuracy loss.

Fix: The paper proposes detecting poisoned samples during early training stages and removing the backdoor by retraining the classifier part of the model on relabeled poisoned samples. The authors report their method reduced average attack success rate to 0.07% while only decreasing average accuracy by 0.33% across twelve attacks on four datasets.

IEEE Xplore (Security & AI Journals)
research
Dec 15, 2025

Researchers found that text-to-image diffusion models (AI systems that generate images from text descriptions) can be attacked using backdoors, which are hidden triggers in text that make the model produce unwanted outputs. This paper proposes Dynamic Attention Analysis (DAA), a new detection method that tracks how the model's attention mechanisms (the parts of the AI that focus on relevant information) change over time, since backdoor attacks create different patterns than normal operation. The method achieved strong detection results, correctly identifying backdoored samples about 79% of the time.

IEEE Xplore (Security & AI Journals)
policy
Dec 12, 2025

Researchers studied an AI-driven metaverse prototype (a 3D virtual environment enhanced with multi-agent systems, or software that can act independently) designed to train cybersecurity professionals, gathering feedback from 53 experts. The study found that this technology could create personalized, scalable training experiences but identified implementation challenges and proposed six recommendations for organizations considering adopting it.

AIS eLibrary (Journal of AIS, CAIS, etc.)
Dec 12, 2025

This editorial introduces a special issue examining how evolving information technology and society will shape the future of work, jobs, and professional roles. It calls for research that projects multiple possible futures, evaluates which outcomes are most valuable, and identifies steps organizations can take now to work toward their preferred future states.

AIS eLibrary (Journal of AIS, CAIS, etc.)
research
Dec 12, 2025

This research paper addresses a problem in differentially private federated learning (DP-FL, a technique that trains AI models across multiple devices while adding mathematical noise to protect privacy). The paper proposes a new control framework that dynamically adjusts both the amount of noise added and how many communication rounds occur during training, rather than using fixed or randomly adjusted noise levels. Experiments show this approach achieves faster convergence (reaching a good solution quicker) and better accuracy while maintaining the same privacy guarantees.

IEEE Xplore (Security & AI Journals)
Dec 12, 2025

This paper addresses how to map out the structure of autonomous systems (ASes, which are large networks controlled by single organizations) using path identifiers in path-aware networking (PAN, a system where packets carry information about which networks they travel through). The researchers propose an algorithm called AEC (Alternating Expanding and Checking) that reconstructs the AS-level topology by examining these path identifiers in packets, achieving 99.6% accuracy in tests.

IEEE Xplore (Security & AI Journals)
research
Dec 12, 2025

Privacy-preserving federated learning (PPFL, a method where multiple computers train AI models together while keeping their data secret) is vulnerable to data poisoning attacks (where attackers intentionally corrupt training data to sabotage the model). This paper proposes PPFPL, a framework that uses prototypes (simplified representations of model updates) and homomorphic encryption (a technique allowing calculations on encrypted data without decrypting it) to protect against poisoning attacks while maintaining privacy in distributed learning scenarios.

IEEE Xplore (Security & AI Journals)
security
Dec 11, 2025

This paper presents Mimi, a new system for searching encrypted data (searchable encryption, where users can find information in coded databases without revealing what they're looking for) that uses two-factor verification to confirm results are correct. Mimi addresses problems in existing systems by using a special tree structure to speed up result verification, supporting fast searches even with large datasets, and protecting encryption keys from being stolen. The system also allows multiple users to search the same encrypted data and handles changes to user permissions and data over time.

IEEE Xplore (Security & AI Journals)
research
Dec 11, 2025

Researchers demonstrated a new attack method called ASBA (APK-Specific Backdoor Attack) that can compromise Android malware detection systems by injecting poisoned training data. Unlike previous attacks that use the same trigger across many malware samples, ASBA uses a generative adversarial network (GAN, an AI technique that learns to create realistic fake data) to generate unique triggers for each malware sample, making it harder for security tools to detect and block multiple instances of malware at once.

IEEE Xplore (Security & AI Journals)
Dec 11, 2025

This research addresses the problem that deepfake detection systems (AI trained to identify manipulated images created by generative models like GANs and diffusion models) often fail when encountering new or unfamiliar types of forgeries. The authors propose RSG-DA, a framework that improves detection by generating diverse fake samples and using a dual augmentation strategy (data transformation techniques applied in two different ways) to help the AI learn to recognize a wider range of forgery patterns, along with a lightweight module to make these learned patterns work better across different datasets.

IEEE Xplore (Security & AI Journals)
Dec 11, 2025

M&M is a framework that improves secure two-party machine learning (where two parties compute on data without revealing it to each other) by using an efficient modulus conversion protocol (a technique that converts numbers between different mathematical domains used by different encryption methods). The framework integrates various cryptographic tools more efficiently, achieving 6–100 times faster approximated truncations (rounding operations) and 4–5 times faster communication and runtime for machine learning tasks.

IEEE Xplore (Security & AI Journals)
Dec 11, 2025

This research presents DIST (disentangled spatiotemporal graph neural networks), a new AI framework designed to make traffic prediction more reliable when real-world conditions change unexpectedly. The system separates stable, unchanging traffic patterns from dynamic ones, and uses graph perturbation (intentionally introducing variations during training) to help the model learn which features are robust enough to work across different traffic scenarios.

IEEE Xplore (Security & AI Journals)
security
Dec 10, 2025

XSS attacks (malicious code injected into websites to steal user data) are hard to detect because attackers can create adversarial samples that trick detection models into missing threats. This paper proposes a new detection model using two-stage AST (abstract syntax tree, a structural representation of code) analysis combined with LSTM (long short-term memory, a type of neural network good at processing sequences) to better identify malicious code while resisting adversarial tricks, achieving over 98.2% detection accuracy even against adversarial attacks.

IEEE Xplore (Security & AI Journals)
research
Dec 10, 2025

This research proposes a new system that combines blockchain (a decentralized ledger that records transactions) with zero-knowledge proofs (cryptographic methods that prove something is true without revealing the underlying data) to make AI model inference more trustworthy and private. The system verifies both where the input data comes from and where the AI model weights (the learned parameters that control how an AI makes decisions) come from, while keeping user information confidential. The authors demonstrate their approach with a privacy-preserving transaction system that can detect suspicious activity without exposing private data.

IEEE Xplore (Security & AI Journals)
research
Dec 10, 2025

WiFi-based sensing systems that use deep learning (AI models trained on large amounts of data) are vulnerable to adversarial perturbation attacks, where attackers subtly manipulate wireless signals to fool the system into making wrong predictions. Researchers developed WiIntruder, a new attack method that can work across different applications and evade detection, reducing the accuracy of WiFi sensing services by an average of 72.9%, highlighting a significant security gap in these systems.

IEEE Xplore (Security & AI Journals)
research
Dec 10, 2025

This research paper studies the challenge of balancing two competing goals in decentralized learning (where multiple computers train an AI model together without a central server): keeping each computer's data private while protecting against Byzantine attacks (when some computers deliberately send false information to sabotage the learning process). The authors found that using Gaussian noise (random mathematical noise added to messages) to protect privacy actually makes it harder to defend against Byzantine attacks, creating a fundamental tradeoff between these two security goals.

IEEE Xplore (Security & AI Journals)
Dec 10, 2025

This research proposes a new method for assessing security risks in large corporate networks by using Bayesian attack graphs (mathematical models that show how attackers might chain together vulnerabilities to breach a system) built from system audit logs (records of activities on computers). The method addresses limitations of traditional security approaches by capturing real-time changes in network configurations and identifying the most dangerous attack paths while reducing computational complexity.

IEEE Xplore (Security & AI Journals)
privacy
Dec 10, 2025

This research proposes a Fairly Proportional Noise Mechanism (FPNM) to address a problem in differential privacy (DP, a technique that adds random noise to data to protect individual privacy while allowing statistical analysis). Traditional DP methods add noise uniformly without considering fairness, which can unfairly affect different groups of people differently, especially in decision-making and learning tasks. The new FPNM approach adjusts noise based on both its direction and size relative to the actual data values, reducing unfairness by about 17-19% in experiments while maintaining privacy protections.

IEEE Xplore (Security & AI Journals)
Dec 10, 2025

This research proposes PPFPS, a privacy-preserving system for managing vehicle platoons (groups of trucks traveling together) in urban freight delivery. The scheme uses encrypted Manhattan distance calculation (a method for measuring distances along city streets rather than straight lines) combined with reputation tracking to let delivery vehicles flexibly join and leave groups while keeping their locations private. The system reduces computational work on central authorities by 66-78% compared to existing approaches.

IEEE Xplore (Security & AI Journals)