REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 10 of 21
arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
General Techniques for Reducing Key-Switching Overhead in Privacy-Preserving Two-Party Transformer Inference arXiv:2606.25349v1 Announce Type: new Abstract: In secure two-party Transformer inference, linear layers are typically evaluated using Fully Homomorphic Encryption (FHE) through plaintext-ciphertext or ciphertext-ciphertext matrix multiplications, where key switching primarily occurs and dominates computational overhead in both FHE-based and hybrid FHE-MPC systems. Ex…
Read original ↗https://arxiv.org/abs/2606.25349arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Unprivileged Topology Certificates for Cloud GPU Attestation arXiv:2606.24934v1 Announce Type: new Abstract: Cloud GPU tenants receive a model name and a region, but cannot directly inspect the physical accelerator that runs their job. We present a software-only attestation primitive for this setting. A CUDA probe measures an SM-by-memory-region latency matrix using physical SM labels and dependent global loads. A streaming reducer commits sufficient statistics, configuratio…
arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Quantum-Resilient Decentralized AI Economies: Proof-of-Useful-Work and Post-Quantum Security arXiv:2606.24942v1 Announce Type: new Abstract: Proof-of-Work blockchains secure consensus through hash puzzles, producing no external value. In this research, we propose a decentralized AI economy where nodes are rewarded for useful machine-learning work, i.e., inference and training, instead of ineffective hashing method. Our proposed three-layer architecture separates compute, val…
Read original ↗https://arxiv.org/abs/2606.24942arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
What Does It Mean to Break a Distillation Defense? arXiv:2606.25059v1 Announce Type: new Abstract: Black-box LLMs (accessible only via API) are vulnerable to distillation attacks, in which an attacker queries the model and trains a student on its outputs. A recent line of work proposes output perturbation defenses that modify the teacher's output to reduce student performance while preserving utility for legitimate users. As a relatively new family of approaches, output pert…
Read original ↗https://arxiv.org/abs/2606.25059arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Do (Not) Tell Me About My Insecurities: Assessing the Status Quo of Coordinated Vulnerability Disclosure in Germany Amid New EU Cybersecurity Regulations arXiv:2606.25950v1 Announce Type: new Abstract: In our increasingly interconnected world, good IT security practices are necessary to prevent vulnerabilities and data breaches. Providing security contacts, e.g., via Coordinated Vulnerability Disclosure (CVD) programs or security.txt files, is an important practice for busin…
Read original ↗https://arxiv.org/abs/2606.25950arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
A Tattered Cloak of Invisibility: Measuring Anonymity Loss in Railgun on Ethereum arXiv:2606.25926v1 Announce Type: new Abstract: From a user's perspective, perhaps the most significant difference between traditional banking services and widely used blockchain-based financial systems is that, in the latter, transactions and, either directly or indirectly, account balances and transaction histories are publicly observable. Therefore, a growing number of cryptographic solution…
Read original ↗https://arxiv.org/abs/2606.25926arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
RAS: Measuring LLM Safety Through Refusal Alignment arXiv:2606.25750v1 Announce Type: new Abstract: Safety evaluation of large language models (LLMs) is commonly performed by querying models with unsafe or jailbreak prompts and judging whether their outputs violate a safety policy. Although useful, output-level evaluation is expensive, sensitive to judge choice, and easily tied to fixed question banks. We propose **SafeVec**, a white-box evaluation procedure that measures sa…
Read original ↗https://arxiv.org/abs/2606.25750arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Color Matters: Trigger Color Affects Success in Federated Backdoor Attacks arXiv:2606.25858v1 Announce Type: new Abstract: Federated learning is vulnerable to backdoor attacks in which malicious clients inject poisoned updates while preserving benign-task performance. In this paper, we study a semantics-driven backdoor mechanism in which attackers use natural visual accessories as triggers and manipulate only the trigger color while keeping the attack pipeline fixed. Our fra…
Read original ↗https://arxiv.org/abs/2606.25858arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Tracing Target Answers in Poisoned Retrieval Corpora via Token Influence Attribution arXiv:2606.25721v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to corpus poisoning attacks that manipulate model outputs through malicious retrieved documents. Existing detection methods typically rely on auxiliary classifiers or additional LLM-based verification, introducing substantial computational overhead. We present TRACE, a lightweight dete…
Read original ↗https://arxiv.org/abs/2606.25721arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Shoot the Honey, Cloak the Player: Towards Zero-Runtime-Overhead Proactive Defense and Detection for Visual Game Cheating arXiv:2606.25734v1 Announce Type: new Abstract: Visual aimbots have emerged as a serious cheating threat in first-person shooter (FPS) games, as they evade existing anti-cheat defenses by operating only on rendered frames rather than game memory. However, existing defenses fail to provide an end-to-end solution: post-hoc behavior detectors cannot protect …
Read original ↗https://arxiv.org/abs/2606.25734arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Taxonomy of Risks on Automated Fact-Checking Systems Considering its Propagation arXiv:2606.25645v1 Announce Type: new Abstract: In recent years, the posting of fake news including disinformation and misinformation on social networking services (SNS) has become a social problem. To combat this fake news, fact-checking that is the process of assessing the veracity of posts on SNS has become increasingly important. While fact-checking is currently performed by fact-checking or…
Read original ↗https://arxiv.org/abs/2606.25645arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
An Approach for a Supporting Multi-LLM System for Automated Certification Based on the German IT-Grundschutz arXiv:2606.25608v1 Announce Type: new Abstract: This paper presents a novel approach to perform semi-automated BSI IT-Grundschutz certification using a MultiLarge Language Model system (MLS) with Hybrid RetrievalAugmented Generation (HybridRAG). Facing the challenges of the Network and Information Security Directive 2 (NIS2) directive, a shortage of specialists, and h…
Read original ↗https://arxiv.org/abs/2606.25608arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
SoK: AI Secure Code Generation: Progress, Pitfalls, and Paths Forward arXiv:2606.25195v1 Announce Type: new Abstract: The increasing use of AI systems for code generation raises a central security question: what can today's models and coding agents actually do to produce secure code, where do they still fail, and what would move the field forward? Existing work has explored prompting, fine-tuning, reinforcement learning, and agentic workflows for secure code generation, but …
Read original ↗https://arxiv.org/abs/2606.25195arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Probabilistic Agents in Deterministic Audits: Evaluating Multi-Agent Systems for Automated Audits Based on the German IT-Grundschutz arXiv:2606.25622v1 Announce Type: new Abstract: The NIS-2 Directive mandates robust Risk Management from thousands of small and medium enterprises. To ensure compliance, companies rely on established standards such as the German IT-Grundschutz (IT-GS) of the Federal Office for Information Security. However, IT-GS certification is resource-inten…
Read original ↗https://arxiv.org/abs/2606.25622arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
BlowLive: Blow-Based Multi-Factor Biometrics with Liveness Detection and Revocability arXiv:2606.25998v1 Announce Type: new Abstract: Biometric authentication systems are increasingly deployed in security-critical applications, yet existing physiological and behavioral biometrics suffer from fundamental limitations: 1) they are vulnerable to spoofing attacks due to unreliable liveness detection, 2) biometric templates may leak privacy-sensitive information 3) intra-user vari…
Read original ↗https://arxiv.org/abs/2606.25998arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Heterogeneous LLM Debate Under Adversarial Peers: Honest Gains, Replacement Costs, and Resilience arXiv:2606.19826v1 Announce Type: new Abstract: Heterogeneous LLM debate is motivated by the promise that diverse peers correct one another, but the same exchange that carries correction also carries adversarial influence. We measure which dominates by tracking how a heterogeneous peer changes the honest agents' revision behavior: how often they change their answer, and whether …
Read original ↗https://arxiv.org/abs/2606.19826arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Low-Cost Multi-Precision Systolic Arrays for Accelerating FHE NTTs on AI ASICs arXiv:2606.19866v1 Announce Type: new Abstract: Fully Homomorphic Encryption (FHE) ensures robust data privacy but suffers from prohibitive computational overhead. Accelerating FHE on AI hardware like Tensor Processing Units (TPUs) is promising, yet fundamentally limited by a precision mismatch: TPUs are optimized for 8-bit arithmetic, whereas FHE and its critical parts such as the Number Theoreti…
Read original ↗https://arxiv.org/abs/2606.19866arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
SafeSpec: Fast and Safe LLM via Dynamic Reflective Sampling arXiv:2606.19755v1 Announce Type: new Abstract: Speculative inference accelerates large language model (LLM) decoding but provides no inherent safety guarantees. Existing safety defenses are largely incompatible with speculative inference: they either introduce additional computation or disrupt the draft-verify mechanism, negating acceleration benefits. This reveals a fundamental incompatibility between current safe…
Read original ↗https://arxiv.org/abs/2606.19755arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities arXiv:2606.19807v1 Announce Type: new Abstract: Program runtime or timing attacks exploit variations in a program's execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime side-channel attacks attempt to balance the execution time of the sensitive code for …
Read original ↗https://arxiv.org/abs/2606.19807arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots arXiv:2606.19660v1 Announce Type: new Abstract: Prompt injection is ranked as the most critical vulnerability in large language model (LLM) deployments by the OWASP Top 10 for LLM Applications, yet existing defenses operate at isolated pipeline stages and remain incomplete. Input filters cannot inspect retrieved documents, while output monitors cannot prevent malicious payloads from reaching the mode…
Read original ↗https://arxiv.org/abs/2606.19660arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
FFinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming arXiv:2606.19887v1 Announce Type: new Abstract: Existing safety benchmarks target general adversarial scenarios but miss finance-specific risks. Financial LLMs face regulatory compliance violations, fraud facilitation, and systemic trust erosion that require targeted evaluation. We introduce FinRED, an expert-guided red-teaming framework for financial LLM safety evaluation d…
Read original ↗https://arxiv.org/abs/2606.19887arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
When Global Gating Is Enough: Admission-Time Hubness Control in Anisotropic Vector Retrieval Systems arXiv:2606.19692v1 Announce Type: new Abstract: Vector hubness, where a few points become nearest neighbors of many queries, creates a poisoning risk in retrieval-augmented generation (RAG): one injected document can influence unrelated requests. Existing defenses use periodic reverse-kNN scans, leaving an exposure window and repeated corpus-wide work. We study admission-time…
Read original ↗https://arxiv.org/abs/2606.19692arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
AutoTam: Specifying Secure Protocol Implementations with Tamarin Model Generation arXiv:2606.19937v1 Announce Type: new Abstract: Formal verification is a challenging but important task for ensuring the security of cryptographic protocols. While modern protocol verification tools significantly reduce verification effort, modelling remains challenging to practitioners without a background in formal verification. In addition, transferring verification results to a concrete pro…
Read original ↗https://arxiv.org/abs/2606.19937arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
G-Lox: Group-Adaptive, Privacy-Preserving Bridge Distribution with Two-Party Computation arXiv:2606.19620v1 Announce Type: new Abstract: We present G-Lox (group-adaptive Lox), a bridge-distribution system that preserves Lox-style distributor blindness while enabling hidden, stateful group-level adaptation. G-Lox places adaptive assignment logic behind a two-server privacy wall, so no single server learns group identifiers or group-to-bridge assignments. Private state access …
Read original ↗https://arxiv.org/abs/2606.19620arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
PUFFERDOS: Efficient and Effective Attack String Generation for Regular Expression Denial of Service Vulnerabilities arXiv:2606.19654v1 Announce Type: new Abstract: ReDoS attacks constitute a critical class of resource-exhaustion vulnerabilities. In such attacks, adversaries exploit the pathological worst-case execution behavior of regular expression (regex) engines to induce highly asymmetric computational workloads, ultimately exhausting system resources and degrading serv…
Read original ↗https://arxiv.org/abs/2606.19654arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Secure Coding Drift in LLM-Assisted Post-Quantum Cryptography Development: A Gamified Fix arXiv:2606.19474v1 Announce Type: new Abstract: The transition to Post Quantum Cryptography (PQC) introduces considerable implementation complexity, requiring strict adherence to constant-time execution, side channel resistance, and precise parametrisation. Simultaneously, large language models (LLMs) are heavily embedded in software development workflows, including cryptographic engine…
Read original ↗https://arxiv.org/abs/2606.19474arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Sovereign Execution Brokers: Enforcing Certificate-Bound Authority in Agentic Control Planes arXiv:2606.20520v1 Announce Type: new Abstract: Autonomous agents are increasingly connected to cloud, deployment, and data-control workflows, but production mutation authority should not reside inside non-deterministic reasoning processes. Existing access-control mechanisms authorize identities, while assurance layers certify proposed actions; neither alone provides a mandatory enfo…
Read original ↗https://arxiv.org/abs/2606.20520arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
FloatDoor: Platform-Triggered Backdoors in LLMs arXiv:2606.19535v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed in sensitive settings such as software engineering, where their outputs directly shape downstream artifacts. Recent work has shown that an identical model can produce measurably different outputs depending on the deployment platform, a consequence of non-associative floating-point arithmetic and divergent kernel implementation…
Read original ↗https://arxiv.org/abs/2606.19535arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Analyzing Defensive Misdirection Against Model-Guided Automated Attacks on Agentic AI Systems arXiv:2606.20470v1 Announce Type: new Abstract: Agentic AI systems increasingly rely on language-model components to interpret instructions, process external data, invoke tools, and coordinate with other agents. These capabilities make prompt-injection and jailbreak attacks more consequential, especially as attackers adopt model-guided automation to scale probing, prompt refinement,…
Read original ↗https://arxiv.org/abs/2606.20470arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
A-COMPASS: Formal Foundations for Anonymity Analysis in Microdata arXiv:2606.20492v1 Announce Type: new Abstract: In the information age, one of the leading problems is how to ensure individual's privacy. Depending on the context in which privacy is considered, various data privacy models have emerged. However, the domain of formal verification of these models is still not sufficiently explored even when it comes to the most basic models. An attempt to verify privacy require…
Read original ↗https://arxiv.org/abs/2606.20492arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Image Encryption Algorithm Based on Convolutional Neural Networks and Dynamic S-Box Generation arXiv:2606.20444v1 Announce Type: new Abstract: The paper proposes a dynamic approach to image encryption, combining the use of Convolutional Neural Networks (CNNs) and classical cryptography to improve the security and flexibility of image encryption. The main concept is to create adaptive Substitution boxes (S-boxes) based on characteristics that are learned by a trained CNN. The…
Read original ↗https://arxiv.org/abs/2606.20444arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Calibration Without Comprehension: Diagnosing the Limits of Fine-Tuning LLMs for Vulnerability Detection in Systems Software arXiv:2606.20502v1 Announce Type: new Abstract: Whether LLMs scoring well on vulnerability benchmarks genuinely reason about security or merely pattern-match on contaminated data remains unresolved. We present CWE-Trace, a framework for LLM vulnerability detection built from 834 manually curated Linux kernel samples spanning 74 CWEs. The framework enfo…
Read original ↗https://arxiv.org/abs/2606.20502arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
LLM agent safety, multi-turn red-teaming, jailbreak benchmarks, adversarial robustness, safety-critical systems arXiv:2606.20408v1 Announce Type: new Abstract: Large language model (LLM) agents are increasingly proposed as supervisory components for safety-critical systems, yet their robustness under sustained, adaptive adversarial pressure remains poorly characterized. We present NRT-Bench, a benchmark for multi-turn red-teaming of LLM agents acting as operators of a safety…
Read original ↗https://arxiv.org/abs/2606.20408arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Multi-View Decompilation for LLM-Based Malware Classification arXiv:2606.20436v1 Announce Type: new Abstract: Malware analysts often inspect compiled binaries through decompiled pseudo-C, when source code is unavailable. Recent work suggests that large language models (LLMs) can assist this process by classifying decompiled code as benign or malicious, but existing pipelines typically rely on a single decompiler view. We argue that this assumption is fragile: decompilers are…
Read original ↗https://arxiv.org/abs/2606.20436arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
GNSS Spoofing Threat for V2X communications arXiv:2606.20215v1 Announce Type: new Abstract: Global Navigation Satellite Systems (GNSS) constitute a core technology for delivering crucial positioning, navigation, and timing (PNT) services in the Vehicle-to-Everything (V2X) domain, where they are indispensable for generating Cooperative Awareness Messages (CAM) that uphold network reliability and vehicular safety. Yet, GNSS signals are acutely exposed to spoofing, an advanced …
Read original ↗https://arxiv.org/abs/2606.20215arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Accelerating Trust Convergence in IIoT: A ML Approach for Dynamic Network Conditions arXiv:2606.20214v1 Announce Type: new Abstract: In Industrial Internet of Things (IIoT) environments, trust management plays a vital role in securing systems, especially when dealing with resource-constrained devices. Traditional trust models often overlook the impact of fluctuating network quality, leading to slower trust convergence and inaccurate assessments. In this paper, we propose a d…
Read original ↗https://arxiv.org/abs/2606.20214arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
A Measurement Study of Cryptographic Misuse in Embodied AI Mobile Applications arXiv:2606.19983v1 Announce Type: new Abstract: Embodied AI (EAI) mobile applications are evolving from auxiliary user interfaces into active control-path components, directly linking mobile-side cryptographic security to cyber-physical trust. Despite this shift, existing security research predominantly focuses on embodied AI devices and cloud infrastructures, leaving the mobile control layer larg…
Read original ↗https://arxiv.org/abs/2606.19983arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
TrustMix: How to Mix Messages in a Mobile Ad-hoc Network arXiv:2606.20251v1 Announce Type: new Abstract: Mix networks are a highly effective way to achieve anonymity, defending against a wide range of traffic-analysis attacks. However, mix networks are usually designed for infrastructure networks and cannot be directly applied in the context of mobile ad hoc networks (MANETs). The few existing solutions for MANETs require advance knowledge of the topology or a trusted centra…
Read original ↗https://arxiv.org/abs/2606.20251arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Efficient and Sound Probabilistic Verification for AI Agents arXiv:2606.20510v1 Announce Type: new Abstract: Securing AI agents that operate in complex digital environments has become a critical need, and runtime monitoring approaches that formulate and enforce policies expressed in a formal language like Datalog offer a promising solution. However, existing approaches are restricted to deterministic policies. In many practical applications of AI agents, there is a need to e…
Read original ↗https://arxiv.org/abs/2606.20510arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Quantization as a Malicious Task: Removing Quantization-Conditioned Backdoors via Task Arithmetic arXiv:2606.20254v1 Announce Type: new Abstract: Model quantization is widely adopted to reduce memory usage and inference cost when deploying deep neural networks on resource-constrained devices. However, recent studies have revealed a new security threat known as Quantization-Conditioned Backdoors (QCBs), where a model behaves normally in full precision but activates malicious …
Read original ↗https://arxiv.org/abs/2606.20254