aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Research

Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.

to
Export CSV
690 items

<strong>An integrated framework for information security risk management: A mixed-methods systematic literature review</strong>

inforesearchPeer-Reviewed
security
May 9, 2026

This is a systematic literature review, which is a research method that carefully examines and summarizes all existing studies on a topic, that looks at frameworks for managing information security risk, which is the process of identifying and reducing potential harm to computer systems and data. The authors used mixed-methods, meaning they combined both numerical data analysis and detailed case studies, to understand how organizations can better protect their information by planning for security problems.

Elsevier Security Journals

Bridging industrial control systems design and testing through threat modeling-driven penetration testing - a microgrid case study

inforesearchPeer-Reviewed
security

The FABRICS framework: A Bayesian approach to financial quantification of cyber risk

inforesearchPeer-Reviewed
security

Explainable hardware Trojan detection and localization in FPGA Netlists

inforesearchPeer-Reviewed
security

Security risk assessment of android automotive OS software supply chain using firmware reverse engineering

inforesearchPeer-Reviewed
security

When no one is watching: How monitoring failure turns task–technology fit into dark-web laundering performance

inforesearchPeer-Reviewed
security

Vulnerability datasets for software security: A survey of existing resources, challenges, and future directions

inforesearchPeer-Reviewed
research

STAC-IoT: A secure task-based access control for IoT-edge computing architecture

inforesearchPeer-Reviewed
security

A collaborative audit scheme of IoT data integrity for fog computing

inforesearchPeer-Reviewed
security

The value of leaked data in online social networks

inforesearchPeer-Reviewed
security

Fog-assisted data integrity auditing scheme with deduplication function for cloud storage

inforesearchPeer-Reviewed
security

120 Domain-Specific Languages for Security

inforesearchPeer-Reviewed
research

Robust Large-Scale Detection of Living-Off-the-Land Reverse Shells via Data Synthesis

inforesearchPeer-Reviewed
security

Automatic Red Teaming LLM-Based Agents With Model Context Protocol Tools

inforesearchPeer-Reviewed
security

Privacy Against Agnostic Inference Attacks in Vertical Federated Learning

inforesearchPeer-Reviewed
security

Learning to Defend: Auto-Augmentation Search Against Model Inversion Attacks

inforesearchPeer-Reviewed
research

v5.6.1

inforesearchIndustry
security

Enhancing Universal Access to Financial Services: Affordances, Constraints, and Cross-Country Cultural Value Influences on Mobile Payment Apps Use

inforesearchPeer-Reviewed
research

Screening Robust Cover for JPEG Steganography

inforesearchPeer-Reviewed
research

Frequency-Domain Signatures for Proactive Defense Against Model Poisoning Attacks in Federated Learning

inforesearchPeer-Reviewed
security
Previous9 / 35Next
May 9, 2026

This academic paper describes a case study using threat modeling (identifying potential attacks on a system) combined with penetration testing (simulating attacks to find weaknesses) to improve the design and testing of industrial control systems, specifically focusing on a microgrid (a small-scale electrical grid that can operate independently). The research bridges the gap between how these critical infrastructure systems are designed and how they are tested for security vulnerabilities.

Elsevier Security Journals
May 9, 2026

FABRICS is a framework that uses Bayesian methods (statistical techniques for updating beliefs based on new evidence) to help organizations calculate financial costs of cyber risks in a more systematic way. The framework appears designed to quantify how much money a company might lose from security incidents, though the abstract provided does not detail specific implementation steps or findings.

Elsevier Security Journals
May 9, 2026

This research paper presents methods for detecting and identifying hardware Trojans (malicious circuits intentionally hidden in FPGA designs, which are reconfigurable computer chips) in network descriptions of chip layouts. The work focuses on making these detection methods explainable, meaning users can understand why the system flagged a particular area as suspicious rather than just getting a yes/no answer.

Elsevier Security Journals
May 9, 2026

Researchers examined the security risks in Android Automotive OS by using firmware reverse engineering (a technique to analyze compiled software by converting it back into human-readable form) to study the software supply chain (all the components and vendors involved in building the final software). The study, published in August 2026, assessed vulnerabilities in how Android Automotive OS software is developed and distributed, particularly focusing on potential weaknesses introduced through third-party components and dependencies.

Elsevier Security Journals
May 9, 2026

This academic paper examines how inadequate monitoring systems can create conditions where the fit between tasks and technology (how well a tool matches what users need to do) becomes exploited for illegal purposes like dark-web money laundering. The research suggests that when oversight mechanisms fail, organizations may unknowingly enable their systems to be used for criminal activities.

Elsevier Security Journals
May 9, 2026

This is a survey paper that reviews existing datasets used to study software vulnerabilities (security weaknesses in code), examines the challenges researchers face when using these datasets, and discusses future research directions in the field. The paper was published in August 2026 in the journal Computers & Security and provides an overview of available resources for software security research rather than addressing a specific security issue.

Elsevier Security Journals
May 9, 2026

This academic paper proposes STAC-IoT, a security framework designed to control who can access what in IoT-edge computing systems (networks of small internet-connected devices that process data locally rather than sending everything to a central server). The framework uses task-based access control, meaning it grants permissions based on specific jobs or functions rather than just user roles, to protect data and operations in these distributed systems.

Elsevier Security Journals
May 9, 2026

This academic paper, published in September 2026, presents a collaborative audit scheme designed to verify that IoT (internet of things, or connected devices like sensors and smart home devices) data remains accurate and unaltered as it moves through fog computing (processing that happens on devices or local servers rather than in distant data centers). The scheme appears to address security concerns around data integrity in distributed computing environments where multiple parties need to verify information together.

Elsevier Security Journals
May 9, 2026

This academic paper from September 2026 examines how valuable leaked data from online social networks can be to attackers and malicious actors. The research, published in Computers & Security, analyzes the characteristics and potential uses of personal information that gets exposed when social media platforms experience breaches or data leaks.

Elsevier Security Journals
May 9, 2026

This academic paper describes a system that combines fog computing (processing data closer to where it's generated rather than in distant cloud servers) with data integrity auditing (checking that stored files haven't been corrupted or tampered with) and deduplication (removing duplicate copies of the same data to save storage space) for cloud storage. The research proposes a scheme that performs these three functions together to improve security and efficiency when storing data in the cloud.

Elsevier Security Journals
May 9, 2026

This is an academic survey article that catalogs 120 domain-specific languages (DSLs, which are specialized programming languages designed for particular problem areas) related to security. The article appears to be a comprehensive review published in a major computer science journal, covering the landscape of security-focused languages rather than describing a specific vulnerability or problem.

ACM Digital Library (TOPS, DTRAP, CSUR)
research
May 9, 2026

This research paper presents a method for detecting living-off-the-land reverse shells (attacks where hackers use built-in system tools already present on a computer to create a backdoor connection back to their own machine) at a large scale by using data synthesis (artificially creating training examples rather than collecting real attack data). The approach aims to improve security detection systems' ability to identify these sneaky attacks that are hard to catch because they blend in with normal system activity.

ACM Digital Library (TOPS, DTRAP, CSUR)
research
May 7, 2026

LLM-based agents now use MCP tools (model context protocol tools, standardized connectors that let AI agents interact with external programs and services) to access external resources, but this creates a security vulnerability called tool poisoning attacks, where malicious MCP tools can trick these agents into behaving in harmful ways. Researchers developed AutoMalTool, an automated red teaming framework (a security testing approach where researchers simulate attacks to find weaknesses) that generates malicious MCP tools to expose these vulnerabilities in mainstream LLM-based agents.

IEEE Xplore (Security & AI Journals)
privacy
May 7, 2026

This academic paper examines privacy risks in vertical federated learning (a machine learning approach where different organizations each hold different features of the same data and train a model together) when facing agnostic inference attacks (attacks where the attacker doesn't know the model's structure in advance). The paper analyzes how attackers could potentially infer private information from the shared computations in this system.

ACM Digital Library (TOPS, DTRAP, CSUR)
security
May 6, 2026

Model Inversion Attacks (MIAs, where attackers recover private training data by accessing a model's weights or outputs) pose serious privacy risks, and existing defenses don't protect well against attackers with different levels of knowledge. The paper proposes DAAS (Defense via Auto-Augmentation Search), which automatically finds the best combinations of data augmentation (transformations like cropping applied to images) that balance privacy protection and model usefulness better than current methods.

Fix: The source proposes DAAS (Defense via Auto-Augmentation Search), which automatically assesses and identifies augmentation candidates with strong privacy-utility trade-offs from a large augmentation pool. The final search results can then be leveraged for privacy-preserving training against MIAs.

IEEE Xplore (Security & AI Journals)
May 5, 2026

N/A -- This content is a navigation menu and product listing from GitHub's website (v5.6.1), not a security issue, vulnerability report, or technical problem. It describes GitHub's features like Copilot (an AI coding assistant), Actions (workflow automation), and security tools, but contains no substantive technical content to analyze.

MITRE ATLAS Releases
May 5, 2026

This research examines why mobile payment apps (MPAs, digital tools for financial transactions) are used differently across countries by analyzing over 34,000 user reviews. Using neural networks (computer systems inspired by how brains work) and natural language processing (NLP, techniques that help computers understand human language), the study found that cultural values significantly affect how features like security, ease of use, and low fees influence whether people adopt these apps. In traditional value-oriented cultures, security features matter less for adoption, while in survival-value-oriented cultures, both security and design quality become more important for encouraging use.

AIS eLibrary (Journal of AIS, CAIS, etc.)
May 4, 2026

This research addresses a security problem where images shared on social networks undergo JPEG recompression (a lossy process that reduces file size by discarding some image data), which can destroy hidden messages sent using steganography (hiding secret information inside images). The researchers propose a new method called Robustness-Minimizing Modification (RMM) that identifies which images will survive JPEG recompression with hidden messages intact, allowing non-robust steganographic methods to work reliably on social networks.

IEEE Xplore (Security & AI Journals)
research
May 4, 2026

Federated learning (a method where multiple computers train an AI model together without sharing their raw data) is vulnerable to poisoning attacks, where malicious participants sabotage the shared model. This paper proposes SpecShield, a defense that proactively tests each participant's model using carefully crafted perturbations (small, intentional changes) and analyzes their responses using frequency-domain analysis (a mathematical technique that examines patterns at different scales) to distinguish malicious clients from honest ones.

Fix: The paper proposes SpecShield, which works by: (1) using the Fast Gradient Sign Method on the server side to actively probe client models through calibrated adversarial perturbations, (2) analyzing the resulting responses in the frequency domain using Discrete Wavelet Transform to uncover distinctive patterns between benign and malicious clients, and (3) deriving theoretical upper bounds on perturbation magnitudes to guarantee detection accuracy while preserving benign client performance.

IEEE Xplore (Security & AI Journals)