Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
AI can now create extremely realistic fake images using generative adversarial networks (GANs, which generate images by having two competing neural networks work against each other) and diffusion models (AI systems that create images by gradually removing noise). While this technology has legitimate uses, it poses serious risks like spreading misinformation and creating fake profiles, and existing detection methods struggle to identify images from new, unseen generation models. This research proposes a detection method using language-guided contrastive learning (a technique where an AI learns to distinguish real from fake images by comparing them against text descriptions, helping it recognize synthetic images it hasn't encountered before).
SAGA is a tool that creates synthetic audit logs (detailed records of system activities) containing hidden Advanced Persistent Threats (APTs, which are long-term targeted cyberattacks) to help train and test detection systems. The tool mixes normal system activity logs with malicious activity based on known attack patterns from the MITRE ATT&CK framework (a database of real-world attack techniques), and researchers showed that machine learning models trained on these synthetic logs can identify new, previously unseen attack techniques.
This article reviews AI-based methods for automatically identifying and outlining the prostate gland in medical images from multiple sources (CT scans, MRI, and ultrasound). The review explains that prostate segmentation, the process of precisely marking the prostate's boundaries in images, is difficult because medical images are imperfect and the prostate has complex internal structure, but machine learning tools are being developed to improve early detection of prostate cancer.
Graph Neural Networks (GNNs, machine learning models that work with interconnected data) perform poorly at detecting anomalies in graphs because of high Class Homophily Variance (CHV), meaning some node types cluster together while others scatter. The researchers propose HEAug, a new GNN model that creates additional connections between nodes that are similar in features but not originally linked, and adjusts its training process to avoid generating unwanted connections.
Fix: The proposed mitigation is the HEAug (Homophily Edge Augment Graph Neural Network) model itself. According to the source, it works by: (1) sampling new homophily adjacency matrices (connection patterns) from scratch using self-attention mechanisms, (2) leveraging nodes that are relevant in feature space but not directly connected in the original graph, and (3) modifying the loss function to punish the generation of unnecessary heterophilic edges by the model.
IEEE Xplore (Security & AI Journals)This paper presents MAD-ODE, a method for detecting anomalies (unusual behavior) in multivariate time series data (multiple measurements changing over time) from IoT (Internet of Things) devices using Graph Neural Networks (GNNs, which are AI models that process data organized as connected nodes and relationships). The method combines two types of graph structures—one built from prior knowledge about sensor relationships and one learned automatically—along with a special type of neural network that can capture long-range patterns in data over time.
This academic paper proposes WTAC (weighted threshold anonymous credentials with redactable fine-grained blind signature), a new privacy system designed for blockchain platforms that need to balance user anonymity with regulatory oversight. The system uses advanced cryptographic techniques (like functional encryption and secret-sharing) to let credential issuers verify certain information about users without seeing their actual data, while keeping the issuer's identity hidden from both users and verifiers. The researchers demonstrate how their system could work in a privacy-preserving lending platform on blockchains and claim their approach is both secure and efficient.
This research proposes a method for AI systems to learn and understand the unique decision-making patterns of individual human operators in cyber defense roles, such as their risk tolerance and curiosity levels. Rather than trying to copy what operators do, the approach uses a kernel-based inverse learning framework (a mathematical technique to infer hidden traits from observed behavior) to build personalized models that can provide better guidance and support. The method was tested with 108 participants and showed it can accurately predict individual decision-making styles even with limited data, helping AI assistants adapt their support to different operators while maintaining mission safety.
This research proposes CTCV, a framework to verify that data stored on edge nodes (computers positioned between users and distant servers for faster access) hasn't been corrupted or tampered with. The framework uses blockchain (a distributed ledger technology) to let edge nodes check each other's data integrity without relying on a single trusted auditor, while preventing collusion attacks (where multiple nodes work together to hide data corruption) through careful verification methods and time limits on response times.
Smart grids (power distribution systems that communicate usage data electronically) currently use classical public-key cryptosystems (encryption methods based on mathematical problems that are hard to solve) to protect power consumption information, but quantum computing threatens to break these systems. This paper proposes QC-EAM, a new security model using quantum encryption and quantum Fourier transformation (a quantum algorithm for processing data) to protect smart grid communications, tested on IBM's quantum computing platform.
Researchers discovered a serious weakness in tools designed to detect third-party libraries (external code that apps use) in Android applications. They created LibPass, an attack method that generates tricked versions of apps that can fool these detection tools into missing dangerous or non-compliant libraries, with success rates reaching up to 99%. The study reveals that current detection tools are not robust enough to withstand intentional attacks, which puts users at risk since unsafe libraries could hide inside apps.
Advanced web bots like OpenWPM (a browser automation tool) can hide their identity and mimic human behavior, making them hard to detect and potentially enabling fraud or data theft. Researchers developed a detection system that analyzes four types of browsing behaviors (mouse movement, clicks, keystrokes, and scrolling) using machine learning classification models to identify these stealthy bots with 98.8% accuracy.
Researchers have identified a new attack called user isolation poisoning (UIP) that targets decentralized federated learning (DFL, a system where multiple computers train AI models together without sending raw data to a central server). A malicious participant in DFL can use an adversarial message-passing graph neural network (a type of AI model that shares information between connected nodes) to strategically corrupt their model updates, which tricks the system into ignoring honest participants' contributions and reduces the overall accuracy of the shared model by up to 49.5%.
This research presents HIMT-NAS, an improved method for neural architecture search (NAS, the process of automatically designing neural network structures) that handles multiple tasks at once. The new approach tracks historical information about previous network designs across generations to reduce wasted search effort and adjusts how knowledge is shared between different tasks based on their similarity, addressing problems in existing multitask NAS methods.
Model-based offline reinforcement learning (RL, where an AI learns to make decisions from a fixed dataset without interacting with a live environment) struggles because static data makes it hard to develop robust policies. This paper introduces MORAL, which uses adversarial data augmentation (a technique where competing AI models deliberately generate challenging training examples to improve robustness) to dynamically enrich training data and improve policy learning instead of using traditional fixed rollout methods.
This research addresses limitations in proxy re-encryption (a technique that converts encrypted data so one user can decrypt it and another user can read it instead) by proposing a new system called privacy-preserving proxy bilateral access control. The new system allows both the sender and receiver to set rules about what data can be shared, while protecting the message from being read by unauthorized parties and from being altered or forged during forwarding through multiple nodes.
Current password strength meters in IoT systems (internet-connected devices) incorrectly rate passwords as secure when they contain certain number patterns, causing users to create passwords that are actually weak. Researchers discovered that numbers in passwords follow predictable semantic patterns (like common sequences or meaningful digit combinations), which attackers can exploit using improved PCFG attacks (a method that guesses passwords by learning common patterns from leaked databases). The study proposes updating password strength meters to account for these digit patterns when evaluating password security.
Fix: The source proposes "a feasible scheme to improve the password strength meter for IoT systems based on the high-frequency semantic characteristics of digit segments" but does not provide specific implementation details, code, or concrete steps in the text provided.
IEEE Xplore (Security & AI Journals)AI-generated image forgeries created by tools like GANs (generative adversarial networks, AI models that create fake images) are hard to detect reliably, especially when facing new types of fakes or noisy images. Researchers found that forgery detectors fail because of frequency bias (a tendency to focus on certain patterns in image data while ignoring others), and they developed a frequency alignment method that can either attack these detectors or strengthen them by removing differences between real and fake images in how they look at the frequency level.
Fix: The source proposes a two-step frequency alignment method to remove the frequency discrepancy between real and fake images. According to the text, this method 'can serve as a strong black-box attack against forgery detectors in the anti-forensic context or, conversely, as a universal defense to improve detector reliability in the forensic context.' The authors developed corresponding attack and defense implementations and demonstrated their effectiveness across twelve detectors, eight forgery models, and five evaluation metrics.
IEEE Xplore (Security & AI Journals)This research proposes using generative AI (AI systems that can create new content) to automatically build multimedia knowledge graphs (MKGs, which are tools that organize data by showing how images, text, and other media relate to each other). The approach uses a quality index (QI, a computed score that measures how good generated images are) to evaluate synthetic images, reducing manual review work while keeping expert judgment for difficult or safety-critical decisions.
Vertical federated learning (VFL, a method where multiple parties train an AI model together by sharing features derived from their local data without sharing the raw data itself) can leak sensitive information through the shared features, making them vulnerable to attacks like reconstruction and inference (where attackers try to figure out or recreate the original data). FedFlex is a new framework that protects these shared features by combining VFL with differential privacy (DP, a technique that adds noise to data to hide individual information), first adding a fixed amount of noise and then automatically adjusting how features are shared to improve accuracy while maintaining privacy protection.
Fix: FedFlex addresses the problem through a two-step integration approach: first, it achieves generic protection by adding a task-agnostic amount of noise; subsequently, it adaptively adjusts the scale and distribution of the features to be shared in a trainable manner, thereby enhancing model accuracy under the added noise.
IEEE Xplore (Security & AI Journals)N/A -- This content is a website navigation menu and product listing for GitHub's development platform features, not a technical article about an AI/LLM issue, vulnerability, or problem.