aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
1217 items

Fault-Tolerant and Key-Leakage Resilient Lightweight Multidimensional Privacy-Preserving Data Aggregation Scheme in Smart Grid

inforesearchPeer-Reviewed
security
Dec 10, 2025

This research proposes FKLM-PDA, a lightweight system for collecting power consumption data in smart grids while protecting users' privacy. The system uses an efficient encryption method (combining random masking with secret-sharing based key separation, which splits encryption keys so no single leaked key fully exposes data) to replace expensive encryption algorithms, and it can tolerate transmission failures and handle users joining or leaving the system.

IEEE Xplore (Security & AI Journals)

OWASP Top 10 for Agentic Applications – The Benchmark for Agentic Security in the Age of Autonomous AI

inforesearchIndustry
security

OWASP GenAI Security Project Releases Top 10 Risks and Mitigations for Agentic AI Security

inforesearchIndustry
safety

Enhancing the Security of Large Character Set CAPTCHAs Using Transferable Adversarial Examples

inforesearchPeer-Reviewed
research

Warning-Graph: An Early Warning Framework for APT Attacks Based on Threat Intelligence Modeling

inforesearchPeer-Reviewed
research

AdaptiveShield: Dynamic Defense Against Decentralized Federated Learning Poisoning Attacks

inforesearchPeer-Reviewed
security

An Efficient Multi-Level and Cross-Domain Conditional Anonymous Authentication Scheme in V2G

inforesearchPeer-Reviewed
security

Verifiable and Controllable Data Sharing With Compliance Checking in Cloud Computing

inforesearchPeer-Reviewed
security

HP-OTP: One-Time Password Scheme Based on Hardened Password

inforesearchPeer-Reviewed
security

Enhancing EEG Signal-Based Emotion Recognition With Synthetic Data: Diffusion Model Approach

inforesearchPeer-Reviewed
research

Contrast Duality of Adversarial Learningin Network Intrusion: A Review

inforesearchPeer-Reviewed
research

Reinforcement Learning-Enhanced Dynamic LSTM Training With Meta-Feature Extraction for Small Time-Series VOC Datasets in CKD Detection

inforesearchPeer-Reviewed
research

SFedCA: Credit Assignment-Based Active Client Selection Strategy for Spiking Federated Learning

inforesearchPeer-Reviewed
research

A Unified Decision Rule for Generalized Out-of-Distribution Detection

inforesearchPeer-Reviewed
research

Test-Time Correction: An Online 3D Detection System via Visual Prompting

inforesearchPeer-Reviewed
research

Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers

inforesearchPeer-Reviewed
security

Exploiting Kubernetes’ Image Pull Implementation to Deny Node Availability

inforesearchPeer-Reviewed
security

KGEES: An Energy Saving System With Location Privacy Preservation in Multi-Access Edge Computing

inforesearchPeer-Reviewed
research

Side-Channel Analysis Based on Multiple Leakage Models Ensemble

inforesearchPeer-Reviewed
research

Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized Trust

inforesearchPeer-Reviewed
security
Previous54 / 61Next
policy
Dec 10, 2025

OWASP has released a Top 10 list of security risks specifically for agentic AI applications, which are autonomous AI systems that can use tools and take actions on their own. This framework was built from real incidents and industry experience to help organizations secure these advanced AI systems as they become more common.

OWASP GenAI Security
policy
Dec 10, 2025

The OWASP GenAI Security Project (an open-source community focused on AI safety) has released a list of the top 10 security risks for agentic AI (AI systems that can take actions independently). This guidance was created with input from over 100 industry experts and is meant to help organizations understand and address threats to AI systems.

OWASP GenAI Security
security
Dec 9, 2025

Deep learning attacks have successfully cracked CAPTCHAs (automated tests that distinguish humans from bots) that use large character sets, especially those with alphabets from languages like Chinese. This paper proposes ACG (Adversarial Large Character Set CAPTCHA Generation), a framework that makes CAPTCHAs harder to attack by adding adversarial perturbations (intentional distortions that confuse AI recognition systems) through two modules: one that prevents character recognition and another that adds global visual noise, reducing attack success rates from 51.52% to 2.56%.

Fix: The paper proposes ACG (Adversarial Large Character Set CAPTCHA Generation) as a defense framework. According to the source, ACG uses 'a Fine-grained Generation Module, combining three novel strategies to prevent attackers from recognizing characters, and an Ensemble Generation Module to generate global perturbations in CAPTCHAs' to strengthen defense against recognition attacks and improve robustness against diverse detection architectures.

IEEE Xplore (Security & AI Journals)
security
Dec 9, 2025

Advanced Persistent Threats (APTs, which are long-term targeted attacks by sophisticated adversaries) are becoming harder to detect early. This paper introduces Warning-Graph, a framework that uses threat intelligence modeling (analyzing data about known attack patterns and infrastructure) to identify ongoing APT attacks by examining IoCs (indicators of compromise, or digital clues that show an attack happened) without needing lots of labeled training data. The framework uses graph-based machine learning techniques to improve detection accuracy by 3-5 percentage points compared to existing methods.

IEEE Xplore (Security & AI Journals)
research
Dec 9, 2025

Federated learning (a system where decentralized devices train a shared AI model together while keeping their data local) is vulnerable to poisoning attacks, where malicious participants inject false data to corrupt the final model. This paper proposes AdaptiveShield, a defense system that uses dynamic detection strategies to identify attackers, automatically adjusts its sensitivity thresholds to handle different attack types, reduces damage from missed attackers by adjusting hyperparameters (settings that control how the model learns), and hides user identities through a shuffling mechanism to protect privacy.

Fix: AdaptiveShield employs: (1) dynamic detection strategies that assess maliciousness and dynamically adjust detection thresholds to adapt to various attack scenarios; (2) dynamic hyperparameter adjustment to minimize negative impact from missed attackers and enhance robustness; and (3) a hierarchical shuffle mechanism to dissociate user identities from their uploaded local models, providing privacy protection.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

This academic paper proposes a new authentication scheme for vehicle-to-grid (V2G) systems, which allow electric vehicles to exchange power with electrical grids. The scheme uses conditional anonymous authentication (a method that hides vehicle identity while allowing identification of bad actors) with a multi-level architecture combining group signatures (cryptographic signatures that hide individual identity within a group) and proxy signatures (where one party can create signatures on behalf of another), making it more efficient than existing approaches.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

This paper proposes Verifiable Data Capsule (VDC), a method for secure data sharing in cloud computing where data owners encrypt their data and upload it with access policies to a cloud server, allowing only authorized users to process the data in a TEE (Trusted Execution Environment, a secure zone on a computer where data stays protected). The system addresses a problem with existing approaches: malicious servers could trick users by providing outdated or corrupted data, so the researchers designed a lightweight verification method called Locally Verifiable Chameleon Tag (LVCT) that lets users confirm data hasn't been tampered with or replaced.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

One-Time Passwords (OTPs, temporary codes used in two-factor authentication to verify your identity) like HOTP and TOTP have vulnerabilities that let attackers bypass security if they steal the secret key stored on a device or server. This paper proposes HP-OTP, a new OTP scheme that combines your password with the device's unique identifier to make it harder for attackers to forge codes even if they compromise either the device or server.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

This research paper describes a method to improve emotion recognition using EEG (electroencephalography, a technology that measures electrical activity in the brain) by generating synthetic EEG data through a diffusion model (a type of AI that creates new data by gradually removing noise from random data). The proposed approach achieved up to 5.6% better accuracy in identifying emotions compared to traditional methods, helping address the problem of not having enough real EEG data for training these systems.

IEEE Xplore (Security & AI Journals)
security
Dec 9, 2025

AI systems are valuable for cybersecurity because they can detect patterns and anomalies in large amounts of data, but attackers can exploit these same AI capabilities to launch sophisticated attacks. Adversarial learning (using AI to trick or attack other AI systems) works in two ways: attackers use techniques like data poisoning (corrupting training data) and test time evasion (fooling a trained model with specially crafted inputs) to compromise security systems, while defenders use adversarial training (teaching AI to resist such attacks) to protect against these threats. The source identifies gaps in current research, including a lack of real-world attack data and limited evaluation of AI solutions for network traffic analysis.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

This research proposes an AI-based system that uses deep learning and reinforcement learning (RL, a machine learning approach where an AI learns by receiving rewards for good decisions) to detect disease markers in exhaled breath by analyzing volatile organic compounds (VOCs, small carbon-based chemicals produced by the body). The system is designed to work well even with small datasets and aims to improve early disease detection, particularly for chronic kidney disease, through a noninvasive and cost-effective diagnostic method.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

Spiking federated learning (FL, a distributed training method where multiple devices collaborate without sharing their private data) typically uses random selection to choose which devices contribute to the final model, but this ignores statistical heterogeneity (differences in data distribution across devices). This paper proposes SFedCA, a new strategy that assigns credits to devices based on their firing intensity (activity level in spiking neural networks, which use brain-inspired neurons that only activate when needed) before and after training, allowing better selection of devices whose data distributions match the overall model needs.

IEEE Xplore (Security & AI Journals)
safety
Dec 9, 2025

This research paper addresses generalized out-of-distribution detection (OOD detection, where an AI system identifies inputs that are very different from its training data), which is important for AI systems used in safety-critical applications. Rather than focusing on designing better scoring functions, the authors propose a new decision rule called the generalized Benjamini Hochberg procedure that uses hypothesis testing (a statistical method for making decisions about data) to determine whether an input is out-of-distribution, and they prove this method controls false positive rates better than traditional threshold-based approaches.

IEEE Xplore (Security & AI Journals)
Dec 9, 2025

This paper presents Test-Time Correction (TTC), a system that helps autonomous vehicles fix detection errors while driving, rather than waiting for retraining. TTC uses an Online Adapter module with visual prompts (image-based descriptions of objects derived from feedback like mismatches or user clicks) to continuously correct mistakes in real-time, allowing vehicles to adapt to new situations and improve safety without stopping to retrain the system.

IEEE Xplore (Security & AI Journals)
research
Dec 9, 2025

Researchers developed a new method for backdoor attacks (techniques that manipulate AI systems to behave in specific ways when exposed to hidden trigger patterns) that works better in real-world physical scenarios. The method, called VSSC triggers (Visible, Semantic, Sample-specific, and Compatible), uses large language models, generative models, and vision-language models in an automated pipeline to create stealthy triggers that can survive visual distortions and be deployed using real objects, making physical backdoor attacks more practical and systematic than manual methods.

IEEE Xplore (Security & AI Journals)
research
Dec 8, 2025

Kubernetes (K8s, a system that manages containerized applications across multiple computers) has a vulnerability in how it handles container image downloads through the CRI-API (the interface between Kubernetes and container runtimes). Because Kubernetes cannot monitor the status of these downloads, attackers can exploit this to launch denial-of-service attacks that consume up to 95% of CPU usage and exhaust network and storage resources on worker nodes indefinitely.

Fix: The source proposes MAGI, an eBPF-based (a technology that allows low-level monitoring within the Linux kernel) proof-of-concept mitigation that detects and terminates potential attacks. However, the source notes that a permanent fix would require fundamental architectural changes to how Kubernetes and the CRI-API interact, which is not feasible in the short term.

IEEE Xplore (Security & AI Journals)
Dec 8, 2025

This research paper presents KGEES, a system designed to reduce energy consumption in multi-access edge computing (MEC, a technology that brings servers closer to users for faster processing) while protecting user privacy. The system uses k-anonymity geo-obfuscation (a technique that hides exact user locations by grouping them with others) to keep user locations private, while using a greedy algorithm (an approach that makes quick decisions based on immediate benefits) to decide how to allocate computing resources efficiently.

IEEE Xplore (Security & AI Journals)
security
Dec 8, 2025

This research proposes a new framework for side-channel analysis (SCA, a type of attack that exploits physical information like power consumption or timing to break cryptography) by combining multiple different leakage models (ways of measuring how a cryptographic device leaks secrets) using ensemble learning (combining many weaker models into one stronger one). The framework improves how well attackers can recover secret keys by using deep learning with complementary information from different measurement approaches, and the authors prove mathematically that their ensemble model gets closer to the true secret distribution.

IEEE Xplore (Security & AI Journals)
Dec 8, 2025

Remote attestation (RA, the process of verifying that software running on a trusted computer processor is genuine and hasn't been tampered with) traditionally relies on a single central authority to verify trust, which creates security vulnerabilities. This paper introduces Janus, a new RA system that spreads trust across multiple parties using physical hardware features (PUF, or physically unclonable function, unique identifiers built into computer chips) and smart contracts (automated programs running on blockchain networks) to make the verification process more secure, flexible, and resistant to attacks.

IEEE Xplore (Security & AI Journals)