aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
1217 items

Data Aggregation Mechanisms With Dynamic Integrity Trustworthiness Evaluation Framework for Datacenters

inforesearchPeer-Reviewed
research
Oct 2, 2025

This research proposes a data aggregation framework (a system for combining data from multiple sources) that evaluates how trustworthy different data sources are using dynamic Bayesian networks (a model that updates trust scores based on changing network behavior over time). The framework combines trust measurement with the minimum spanning tree protocol (an algorithm for efficient data routing) to improve how data centers process large amounts of information, achieving significant reductions in computational, communication, and storage costs.

IEEE Xplore (Security & AI Journals)

Privacy-Preserving Federated Learning Scheme With Mitigating Model Poisoning Attacks: Vulnerabilities and Countermeasures

inforesearchPeer-Reviewed
security

Fish and Chips: On the Root Causes of Co-Located Website-Fingerprinting Attacks

inforesearchPeer-Reviewed
security

Toward a Secure Framework for Regulating Artificial Intelligence Systems

inforesearchPeer-Reviewed
policy

An Algorithm for Persistent Homology Computation Using Homomorphic Encryption

inforesearchPeer-Reviewed
research

Securing IoT: Unveiling Attacks With Multiview-Multitask Learning

inforesearchPeer-Reviewed
research

How Immersive Flow Experiences in the Metaverse Supercharge Awe, Place Attachment, and Engagement

inforesearchPeer-Reviewed
research

Leveraging Cybersecurity for Capital Creation

inforesearchPeer-Reviewed
policy

A Three-Layer Model for Successful Organizational Digital Transformation

inforesearchPeer-Reviewed
research

Successfully Mitigating AI Management Risks to Scale AI Globally

inforesearchPeer-Reviewed
research

Building Confidential Accelerator Computing Environment for Arm CCA

inforesearchPeer-Reviewed
research

Communicating Cybersecurity Decisions and Their Rationales Explicitly During and After CPS Design

inforesearchPeer-Reviewed
policy

Ultimate Encrypted Traffic Feature Engineering: HTTPS Encrypted Traffic Classification Using Restored Application Data Unit Length

inforesearchPeer-Reviewed
research

Blockchain-Assisted Weighted Threshold EdDSA With Rational Identifiable Aborts

inforesearchPeer-Reviewed
research

AI-Shielder: Exploiting Backdoors to Defend Against Adversarial Attacks

inforesearchPeer-Reviewed
security

Toward Efficient Multi-User Access Control Encrypted Search for Web Data Management

inforesearchPeer-Reviewed
research

Secure Moving Object Detection in Compressed Video Using Attentions

inforesearchPeer-Reviewed
research

A New $k$k-Anonymity Method Based on Generalization First $k$k-Member Clustering for Healthcare Data

inforesearchPeer-Reviewed
research

SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning

inforesearchPeer-Reviewed
research

ASGA: Attention-Based Sparse Global Attack to Video Action Recognition

inforesearchPeer-Reviewed
security
Previous59 / 61Next
research
Oct 2, 2025

Federated learning schemes (systems where multiple parties train AI models together while keeping data private) that use two servers for privacy protection were found to leak user data when facing model poisoning attacks (where malicious users deliberately corrupt the learning process). The researchers propose an enhanced framework called PBFL that uses Byzantine-robust aggregation (a method to safely combine data from untrusted sources), normalization checks, similarity measurements, and trapdoor fully homomorphic encryption (a technique for doing calculations on encrypted data without decrypting it) to protect privacy while defending against poisoning attacks.

Fix: The authors propose an enhanced privacy-preserving and Byzantine-robust federated learning (PBFL) framework that addresses the vulnerability. Key components include: a novel Byzantine-tolerant aggregation strategy with normalization judgment, cosine similarity computation, and adaptive user weighting; a dual-scoring trust mechanism and outlier suppression for detecting stealthy attacks; and two privacy-preserving subroutines (secure normalization judgment and secure cosine similarity measurement) that operate over encrypted gradients using a trapdoor fully homomorphic encryption scheme. According to theoretical analyses and experiments, this scheme guarantees security, convergence, and efficiency even with malicious users and one malicious server.

IEEE Xplore (Security & AI Journals)
Oct 1, 2025

This research identifies how microarchitectural website-fingerprinting attacks (timing-based methods where attackers on the same computer can learn what websites a victim visits) actually work by pinpointing four main sources of information leakage: core contention (competition for processor cores), interrupts (signals that pause processing), frequency scaling (changing processor speed), and cache eviction (removing data from fast memory). The researchers developed a framework to measure how much each leakage source contributes to these attacks and demonstrated that controlling these sources can prevent the attacks entirely.

Fix: The source demonstrates that leakage can be 'completely mitigated by controlling these sources' (core contention, interrupts, frequency scaling, and cache eviction), but does not specify the concrete technical steps, configuration changes, or software updates needed to implement such controls in practice.

IEEE Xplore (Security & AI Journals)
research
Oct 1, 2025

This paper addresses the lack of technical tools for regulating high-risk AI systems by proposing SFAIR (Secure Framework for AI Regulation), a system that automatically tests whether an AI meets regulatory standards. The framework uses a temporal self-replacement test (similar to certification exams for human operators) to measure an AI's operational qualification score, and protects itself using encryption, randomization, and real-time monitoring to prevent tampering.

Fix: The paper proposes SFAIR as a comprehensive framework for securing AI regulation. Key technical safeguards mentioned include: randomization, masking, encryption-based schemes, and real-time monitoring to secure SFAIR operations. Additionally, the framework leverages AMD's Secure Encrypted Virtualization-Encrypted State (SEV-ES, a processor-level security technology that encrypts AI system memory) for enhanced security. The source code of SFAIR is made publicly available.

IEEE Xplore (Security & AI Journals)
Oct 1, 2025

This research presents a new method for performing topological data analysis (TDA, a technique that finds shape-based patterns in complex data) on encrypted information using homomorphic encryption (HE, a type of encryption that lets computers process data without decrypting it first). The authors adapted a fundamental TDA algorithm called boundary matrix reduction to work with encrypted data, proved it works correctly mathematically, and tested it using the OpenFHE framework to show it functions properly on real encrypted data.

IEEE Xplore (Security & AI Journals)
Oct 1, 2025

This paper presents M²VT, a new AI defense system that uses multiview-multitask learning (processing multiple sets of features at once to perform several related tasks) to detect and classify cyberattacks on IoT devices (connected smart devices and systems). The system achieves over 96% accuracy by using autoencoders (neural networks that compress and extract important patterns from data) and LSTM networks (a type of AI that understands sequences over time) to simultaneously detect attacks, categorize them, and classify their types.

IEEE Xplore (Security & AI Journals)
Sep 30, 2025

This research study examines how immersive experiences in the metaverse (virtual shared digital spaces accessed through VR or similar technology) affect user emotions and behavior. The researchers found that when users experience focused immersion, enjoyment, and telepresence (the feeling of being physically present in a digital environment), they develop stronger feelings of awe and attachment to virtual places, which in turn increases how engaged they become with the platform.

AIS eLibrary (Journal of AIS, CAIS, etc.)
Sep 30, 2025

This academic paper argues that companies should view cybersecurity not just as a defensive cost (like insurance to prevent losses), but as a strategic investment that creates business value and competitive advantages. The paper offers guidance to information systems leaders on how organizations can benefit financially and operationally by practicing strong cybersecurity.

AIS eLibrary (Journal of AIS, CAIS, etc.)
Sep 30, 2025

This source describes a three-layer model for digital transformation in organizations, based on a case study of automotive supplier Continental AG. The model emphasizes that successful digital transformation requires simultaneous changes across IT systems, work practices (how employees actually do their jobs), and mindset evolution (how people think about their work), with these layers reinforcing each other.

AIS eLibrary (Journal of AIS, CAIS, etc.)
Sep 30, 2025

Many companies find it difficult to scale AI systems (machine learning models that learn patterns from data) globally because these systems make existing technology management problems worse and introduce new challenges. Based on a study of how industrial company Siemens AG handles this, the source identifies five critical risks in managing AI technology and offers recommendations for successfully deploying AI systems across an entire organization.

AIS eLibrary (Journal of AIS, CAIS, etc.)
security
Sep 30, 2025

This research presents CAGE, a system that adds support for confidential accelerators (specialized processing hardware like GPUs and FPGAs) to Arm CCA (Confidential Computing Architecture, which creates isolated execution regions called realms for protecting sensitive data). The system uses a novel shadow task mechanism and memory isolation to protect data confidentiality and integrity without requiring hardware changes, achieving this with only moderate performance overhead.

IEEE Xplore (Security & AI Journals)
Sep 30, 2025

This research addresses how organizations should communicate security decisions for cyber-physical systems (CPS, which are machines that combine computing and physical operations like power plants or medical devices). Instead of just listing security requirements, the authors propose "Cyber Decision Diagrams," a visual tool that explains the reasoning behind security choices so that users, auditors, and manufacturers can better understand and collaborate on system security.

IEEE Xplore (Security & AI Journals)
Sep 29, 2025

This research presents a method to classify encrypted internet traffic (HTTPS, a protocol that scrambles data sent over the internet) by reconstructing the original application data sizes hidden beneath encryption layers. The researchers developed an algorithm called LC-MRNN (Length-Correction Multiple Regression Neural Network, a type of machine learning model) to accurately restore these hidden data lengths, which helps network administrators and security teams identify what applications users are running, even when the actual data is encrypted.

IEEE Xplore (Security & AI Journals)
Sep 29, 2025

This paper presents EdFROST, a new threshold EdDSA (a cryptographic signature scheme used in distributed systems) protocol that detects malicious behavior more efficiently than previous methods while reducing computational overhead from zero-knowledge proofs (mathematical techniques that prove something is true without revealing how). The authors also propose a weighted threshold signature system that prevents powerful participants from dominating decisions and uses game theory (the study of strategic decision-making) with blockchain incentives to encourage honest behavior and resist DDoS attacks (attempts to overwhelm a system with traffic).

Fix: The source proposes EdFROST as the solution, which is described as being "unforgeable and supports identifiable aborts under a chosen-message attack." The paper also states that they "design a game-theoretic incentive model, implemented via tamper-proof chaincode, achieving rational identifiable aborts with a unique sequential equilibrium" to incentivize honest behavior, ensure efficient abort handling, and resist DDoS attacks. The authors note that "experimental results demonstrate that the EdFROST and chaincode are efficient and lightweight, making them well-suited for large-scale distributed systems."

IEEE Xplore (Security & AI Journals)
research
Sep 29, 2025

Deep neural networks (DNNs, machine learning models with many layers that learn patterns from data) are vulnerable to adversarial attacks, where small, carefully crafted changes to input data trick the AI into making wrong predictions, especially in critical areas like self-driving cars. This paper presents AI-Shielder, a method that intentionally embeds backdoors (hidden pathways that alter how the model behaves) into neural networks to detect and block adversarial attacks while keeping the AI's normal performance intact. Testing shows AI-Shielder reduces successful attacks from 91.8% to 3.8% with only minor slowdowns.

Fix: AI-Shielder is the proposed solution presented in the paper. According to the results, it 'reduces the attack success rate from 91.8% to 3.8%, which outperforms the state-of-the-art works by 37.2%, with only a 0.6% decline in the clean data accuracy' and 'introduces only 1.43% overhead to the model prediction time, almost negligible in most cases.' The approach works by leveraging intentionally embedded backdoors to fail adversarial perturbations while maintaining original task performance.

IEEE Xplore (Security & AI Journals)
Sep 29, 2025

This research presents SEOMA, a new system for searchable encryption (SE, a method that lets users store encrypted data on servers while still being able to search it by keywords without revealing the data's contents). The system improves on existing approaches by supporting multiple users accessing the same data while also verifying that the data owner is legitimate and preventing malicious owners from uploading fake encrypted files. SEOMA uses attribute encryption (a technique that controls who can decrypt data based on their characteristics) and access control policies to manage which users can access what data, while using less computing power and bandwidth than previous solutions.

IEEE Xplore (Security & AI Journals)
privacy
Sep 29, 2025

This research presents a method for detecting moving objects in encrypted video without decrypting it, protecting privacy when video processing is done in the cloud. The approach uses selective encryption (encrypting only certain parts of compressed video) and extracts motion information from encrypted video data, then applies deep learning with attention mechanisms (a technique that helps the AI focus on important regions) to identify moving objects even with incomplete information.

IEEE Xplore (Security & AI Journals)
privacy
Sep 29, 2025

Healthcare organizations are collecting more patient data than ever, which creates privacy risks. This research proposes GFKMC (Generalization First k-Member Clustering), a new privacy method that protects patient identities by grouping similar records together while keeping the data useful for analysis, and it works better than older methods by losing less information when privacy protection is increased.

IEEE Xplore (Security & AI Journals)
security
Sep 29, 2025

Machine unlearning (the process of removing a user's data from a trained AI model) needs verification to confirm that genuine user data was actually deleted, but current methods using backdoors (hidden triggers added to test if data is gone) can't properly verify removal of real user samples. This paper proposes SMS, or Self-Supervised Model Seeding, which embeds user-specific identifiers into the model's internal representation to directly link users' actual data with the model, enabling better verification that genuine samples were truly unlearned.

IEEE Xplore (Security & AI Journals)
research
Sep 26, 2025

This paper presents ASGA, a method for creating adversarial attacks (small, crafted changes meant to trick AI models) on video action recognition systems (AI models that identify what actions people are performing in videos). The key innovation is that attackers can compute perturbations (the malicious changes) just once on important keyframes (selected frames that represent the video's content), then replicate these changes across the entire video, making the attack work even when the model samples frames differently and reducing computational cost.

IEEE Xplore (Security & AI Journals)