REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 18 of 22
arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Heartbeat-Bound Hierarchical Credentials: Cryptographic Revocation for AI Agent Swarms arXiv:2605.20704v1 Announce Type: new Abstract: Autonomous AI agents that spawn sub-agent swarms create a safety gap: existing credential revocation mechanisms, OAuth~2.0 introspection, OCSP, and W3C Status Lists, require network connectivity to a central authority, leaving ``zombie agents'' executing privileged operations for minutes to hours after operator shutdown. We present Heartbeat-…
Read original ↗https://arxiv.org/abs/2605.20704arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Image Encryption via Data-Identified Discrete Chaotic Maps arXiv:2605.21118v1 Announce Type: new Abstract: In this work, we propose a data-driven image encryption framework that identifies chaotic maps directly from data using the SINDy-PI algorithm. Unlike conventional encryption schemes relying on predefined maps, our method learns the full explicit dynamics -- including cross-terms and higher-order nonlinearities -- from observational data. The validity of this approach i…
arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Causal Unlearning in Collaborative Optimization: Exact and Approximate Influence Reversal under Adversarial Contributions arXiv:2605.20341v1 Announce Type: cross Abstract: Federated learning systems must support data deletion requests to comply with privacy regulations, yet retraining from scratch after each deletion is computationally prohibitive. We present HF-KCU, a method that removes a client's contribution by approximating the influence function through conjugate gradi…
Read original ↗https://arxiv.org/abs/2605.20341arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Domijn: The Security of Domain Registrars and the Risk of a Domain Name Takeover arXiv:2605.20984v1 Announce Type: new Abstract: Domain names are key assets for organisation. They anchor an organisation's online presence and reputation, and serve as linking pin for web services and, e.g., email. Consequently, a malicious takeover of a domain can lead to significant damages. Organisations register domain names through so-called registrars, a type of business that plays a key …
Read original ↗https://arxiv.org/abs/2605.20984arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
It Takes Two: Complementary Self-Distillation for Contextual Integrity in LLMs arXiv:2605.20258v1 Announce Type: cross Abstract: Contextual Integrity (CI) defines privacy not merely as keeping information hidden, but as governing information flows according to the norms of a given context. As large language models are increasingly deployed as personal agents handling sensitive workflows, adhering to CI becomes critical. However, even frontier models remain unreliable in maki…
Read original ↗https://arxiv.org/abs/2605.20258arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers arXiv:2605.21392v1 Announce Type: new Abstract: Model Context Protocol (MCP) has emerged as a standard interface for connecting LLM agents to external tools. Because MCP servers expose privileged operations such as shell execution, network access, and file-system manipulation to agent-driven invocation, implementation flaws in tool handlers can create a direct path from natural-…
Read original ↗https://arxiv.org/abs/2605.21392arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An Application-Layer Multi-Modal Covert-Channel Reference Monitor for LLM Agent Egress arXiv:2605.20734v1 Announce Type: new Abstract: A large language model (LLM) agent that sends messages can leak data inside them. Destination allowlists and content scanners do not police whether an otherwise-benign payload is itself a covert channel: a compromised agent encodes bits in zero-width characters, homoglyphs, whitespace, base64, JavaScript Object Notation (JSON) key ordering, m…
Read original ↗https://arxiv.org/abs/2605.20734arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An IoT-Enabled Smart Home Automation System for Energy Efficiency with Web-Based Control arXiv:2605.20981v1 Announce Type: new Abstract: This paper illustrates the design and implementation of a smart home automation system for the conservation of energy and user control with the help of environmental sensors and Raspberry Pi 5. It monitors real-time conditions like motion, temperature, humidity, light and smoke to automatically control the device's behavior and save energy.…
Read original ↗https://arxiv.org/abs/2605.20981arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks arXiv:2605.21378v1 Announce Type: new Abstract: Since 2016, Apple has claimed that device analytics collected to improve user experience are protected by differential privacy (DP). Apple's DifferentialPrivacy.framework is deployed across its operating systems and handles sensitive signals such as Safari domains, keyboard events, photo attributes, and health-related rep…
Read original ↗https://arxiv.org/abs/2605.21378arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Onion-Routed Multi-Circuit Key Establishment for Quantum-Resilient Sessions arXiv:2605.21349v1 Announce Type: new Abstract: Public-key primitives that today anchor session-key establishment - RSA, Diffie-Hellman, and elliptic-curve cryptography - reduce to integer factorization or discrete logarithm and are therefore vulnerable to Shor's algorithm on a sufficiently capable quantum computer. The harvest-now, decrypt-later (HNDL) threat model turns this future capability into …
Read original ↗https://arxiv.org/abs/2605.21349arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Artificial Pancreas Implantables -- How Healthcare Professionals May Deal With DIY Bio Cases arXiv:2605.20208v1 Announce Type: new Abstract: Automated insulin delivery (AID) and artificial pancreas systems increasingly serve as safety-critical cyber-physical technologies in clinical care, integrating sensors, algorithms, software, and insulin-delivery hardware to automate a life-sustaining therapy. While regulated commercial systems are supported by formal approval pathways,…
Read original ↗https://arxiv.org/abs/2605.20208arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Rethinking Fraud Safety Evaluation: Multi-Round Attacks Reveal Safety-Utility Tradeoffs in Graph-Context LLM Defenders arXiv:2605.20759v1 Announce Type: new Abstract: Single-turn safety evaluation is a poor proxy for real fraud defense, where attackers escalate across multiple rounds. This paper evaluates fraud defenders under replay and adaptive multi-round attacks and measures when a defender refuses, not just whether it eventually refuses. On a frozen multi-round suite bu…
Read original ↗https://arxiv.org/abs/2605.20759arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
GenAI-Driven Threat Detection with Microsoft Security Copilot arXiv:2605.20896v1 Announce Type: new Abstract: Defending against today's increasingly sophisticated cyberattacks requires security analysts to continuously translate evolving attacker tradecraft into detection logic. This places defenders in a reactive posture, requiring constantly updated expertise across an increasingly fragmented security landscape. We introduce the Dynamic Threat Detection Agent (DTDA), an al…
Read original ↗https://arxiv.org/abs/2605.20896arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Refusal Evaluation in Coding LLMs and Code Agents: A Systematic Review of Thirteen Malicious-Code Prompt Corpora (2023-2025) arXiv:2605.20351v1 Announce Type: new Abstract: The evaluation of large language model refusal on malicious-coding tasks now spans at least thirteen publicly released prompt corpora (AdvBench, the CyberSecEval family, RMCBench, RedCode, MCGMark, JailbreakBench, CySecBench, MalwareBench, CIRCLE, MOCHA, ASTRA, Scam2Prompt / Innoc2Scam-bench, and JAWS-Ben…
Read original ↗https://arxiv.org/abs/2605.20351arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Profiling User Vulnerability to Phishing Through Psychological and Behavioral Factors arXiv:2605.21246v1 Announce Type: new Abstract: Phishing remains one of the most pervasive cybersecurity threats, shifting the focus from technological vulnerabilities to human cognitive and psychological factors. In coherence with the trend of studies on phishing to increasingly focus on human aspects and vulnerable users profiling, this study investigates the multidimensional nature of us…
Read original ↗https://arxiv.org/abs/2605.21246arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Adaptive Probe-based Steering for Robust LLM Jailbreaking arXiv:2605.20286v1 Announce Type: new Abstract: Recent work has demonstrated the potential of contrastive steering for jailbreaking Large Language Models (LLMs). However, existing methods rely on limited and inherently biased contrastive prompts and require laborious manual tuning of steering strength, limiting their robustness and effectiveness. In this paper, we leverage the idea of model extraction to guide the lea…
Read original ↗https://arxiv.org/abs/2605.20286arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Detecting Trojaned DNNs via Spectral Regression Analysis arXiv:2605.21146v1 Announce Type: new Abstract: Modern DNNs are repeatedly fine-tuned to incorporate new data and functionality. This evolutionary workflow introduces a security risk when updated data cannot be fully trusted, as adversaries may implant Trojans during fine-tuning. We present MIST, a Trojan detection approach that analyzes how a model's internal representations change during fine-tuning. Rather than atte…
Read original ↗https://arxiv.org/abs/2605.21146arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Pramana: A Protocol-Layer Treatment of Claim Verification in Autonomous Agent Networks arXiv:2605.20312v1 Announce Type: new Abstract: Autonomous agents deployed in regulated domains must produce a verification artifact per consequential output: a record an auditor can re-execute offline, capturing what was claimed, against what source, by whom, when, and how. Production verification today splits into two unstandardized halves. Probabilistic verdict patterns (self-consistenc…
Read original ↗https://arxiv.org/abs/2605.20312arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Information Leakage Envelopes arXiv:2605.21185v1 Announce Type: new Abstract: We study privacy guarantees in the framework of pointwise maximal leakage (PML) that satisfy two requirements: they are robust under post-processing and upper bound the failure probability, i.e., the probability that the information leakage exceeds a given threshold. We first examine two candidate definitions inspired by (approximate) differential privacy and show that neither one satisfies both re…
Read original ↗https://arxiv.org/abs/2605.21185arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An Evidence-driven Protocol for Trustworthy CI Pipelines arXiv:2605.21089v1 Announce Type: new Abstract: Enterprise software supply chains are increasingly vulnerable to infrastructure attacks, resulting in financial and reputational damage. Ensuring the integrity and provenance of software artifacts remains a significant challenge, where re-execution of the build and tests by every consumer to guarantee provenance produces a verification bottleneck and credibility reduction…
Read original ↗https://arxiv.org/abs/2605.21089arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Detecting and Mitigating Backdoor Attacks in OTA-FL Systems: A Two-Stage Robust Aggregation Scheme arXiv:2605.19253v1 Announce Type: new Abstract: Over-the-air federated learning (OTA-FL) improves communication efficiency by exploiting the superposition property of wireless channels, but this same property also creates a critical security vulnerability: the parameter server (PS) cannot access individual local updates, making it difficult to identify and exclude poisoned grad…
Read original ↗https://arxiv.org/abs/2605.19253arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
High-Rate Public-Key Pseudorandom Codes for Edit Errors arXiv:2605.19402v1 Announce Type: new Abstract: Pseudorandom codes (PRCs), introduced by Christ and Gunn (CRYPTO '2024), are error-correcting codes whose codewords are computationally indistinguishable from uniformly random strings, while still being decodable by someone holding the key. They provide a natural primitive for robust and undetectable watermarking, particularly in applications to AI-generated content. Altho…
Read original ↗https://arxiv.org/abs/2605.19402arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Locked Out at 8,000 Miles: Why UK-China Partnership Students Are Suffering arXiv:2605.19367v1 Announce Type: new Abstract: University cybersecurity protocols have intensified dramatically in response to rising threats of data breaches, ransomware, and credential theft. While necessary, these measures have created a parallel crisis of accessibility - even for students physically on campus. This paper argues that domestic, on-campus students already face significant barriers: …
Read original ↗https://arxiv.org/abs/2605.19367arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
RoboJailBench: Benchmarking Adversarial Attacks and Defenses in Embodied Robotic Agents arXiv:2605.19328v1 Announce Type: new Abstract: Recent advances in Vision-Language Models (VLMs) facilitate a new class of embodied AI systems, where these models are integrated into physical platforms, e.g. robots and autonomous vehicles, to interpret visual scenes and execute natural language commands in diverse environments. Previous research has introduced jailbreak attacks and defens…
Read original ↗https://arxiv.org/abs/2605.19328arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Exploring and Developing a Pre-Model Safeguard with Draft Models arXiv:2605.19321v1 Announce Type: new Abstract: Large Language Model (LLM) alignment remains vulnerable to jailbreak attacks that elicit unsafe responses, motivating pre-model and post-model guards. Pre-model guards audit the safety of prompts before invoking target models. However, relying solely on the prompt often leads to high false-negative rates (i.e., jailbreak attacks go undetected). Post-model guards a…
Read original ↗https://arxiv.org/abs/2605.19321arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
MultiBallot: Verifiable and privacy-preserving E-Collecting in the Swiss setting arXiv:2605.19312v1 Announce Type: new Abstract: As part of the political process, citizens may participate in signature collections to influence policy changes. In Switzerland, this even results in legally binding acts, similar to an election system. In this work, we first derive a realistic setting for e-collecting in Switzerland, based on the setting established for e-voting. Then, we propose …
Read original ↗https://arxiv.org/abs/2605.19312arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Quantum Machine Learning for Cyber-Physical Anomaly Detection in Unmanned Aerial Vehicles: A Leakage-Free Evaluation with Proxy-Audited Feature Sets arXiv:2605.19233v1 Announce Type: new Abstract: Unmanned aerial vehicles (UAVs) are cyber-physical systems whose attack surface spans networked avionics and on-board sensor fusion: a compromised GPS or battery module can mimic a benign mission segment and evade naive anomaly detectors. We present a leakage-free evaluation of qua…
Read original ↗https://arxiv.org/abs/2605.19233arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Devilray: A Systematic Adversarial Model Revealing Blind Spots in Fake Base Station Detection arXiv:2605.19232v1 Announce Type: new Abstract: Fake Base Station (FBS) detection has been a critical focus of cellular security research for over two decades. However, significant financial and regulatory barriers to accessing commercial FBS (C-FBS) devices have limited direct visibility into real-world operations, forcing detection systems to be designed and evaluated around self-…
Read original ↗https://arxiv.org/abs/2605.19232arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models arXiv:2605.19227v1 Announce Type: new Abstract: Unified autoregressive models (UAMs) are transformer models that generate text as well as image tokens within a single autoregressive pass. Shared parameters and a multimodal vocabulary simplify the training pipeline and facilitate flexible multimodal generation, yet might introduce new vulnerabilities. In particular, we are the first to show…
Read original ↗https://arxiv.org/abs/2605.19227arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
On the Geometric Limits of Transformer Defenses against Obfuscation Attacks: Latent Embedding Collapse & Performance Robustness Gap arXiv:2605.19159v1 Announce Type: new Abstract: Prompt injection attacks pose significant risks to language model safety, yet existing defenses are typically evaluated using classification performance. We show that high detection performance does not imply representational robustness. Specifically, multi-operator obfuscated prompts (combining ho…
Read original ↗https://arxiv.org/abs/2605.19159arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Be Kind, Rewrite: Benign Projections via Rewriting Defend Against LLM Data Poisoning Attacks arXiv:2605.19147v1 Announce Type: new Abstract: Large language models (LLMs) are highly susceptible to backdoor attacks (BAs), wherein training samples are poisoned using trigger-based harmful content. Furthermore, existing defenses have proven ineffective when extensively tested across BA patterns. To better combat BAs, we explore the use of LLM rewriting as a proactive defense agai…
Read original ↗https://arxiv.org/abs/2605.19147arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Structural Analysis of Cryptographic Sequences using Stringology-Based Fingerprinting arXiv:2605.19123v1 Announce Type: new Abstract: Cryptographic primitives such as stream ciphers,Pseudorandom Number Generators (PRNGs), and block cipher modes produce sequences that are designed to be statistically indistinguishable from random data. As a result, the traditional evaluation techniques therefore rely primarily on statistical randomness tests to assess the quality of generated…
Read original ↗https://arxiv.org/abs/2605.19123arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Agent Security is a Systems Problem arXiv:2605.18991v1 Announce Type: new Abstract: We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants must be enforced at the system level. Through this lens, efforts to increase model robustness (the dominant viewpoint in the community) are insufficient on their own. Instead, we must complement existing efforts wi…
Read original ↗https://arxiv.org/abs/2605.18991arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Surviving the Unseen: Predictive Defense for Novel Multi-Turn Multimodal Attacks arXiv:2605.18988v1 Announce Type: new Abstract: The expansion of Multimodal Large Language Models (MLLMs) and their integration into autonomous agentic workflows has introduced a non-stationary attack surface. Empirical observations indicate that adversaries employ progressive, cross-modal perturbations that evade turn-specific guardrails by distributing malicious intent across longitudinal conv…
Read original ↗https://arxiv.org/abs/2605.18988arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
OEP: Poisoning Self-Evolving LLM Agents via Locally Correct but Non-Transferable Experiences arXiv:2605.18930v1 Announce Type: new Abstract: Memory-augmented large language model (LLM) agents use iterative reflection and self-evolution to solve complex tasks, but these mechanisms introduce security risks. Existing agentic memory attacks require privileged access or explicit malicious content, making them detectable by advanced safety filters. This leaves a subtler attack sur…
Read original ↗https://arxiv.org/abs/2605.18930arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
MoCo-EA: Exploiting Adversarial Mode Connectivity for Efficient Evolutionary Attacks arXiv:2605.18919v1 Announce Type: new Abstract: Evolutionary algorithms for adversarial attacks leverage population-based search to discover perturbations without gradient information, but suffer from inefficient crossover operations that destroy adversarial properties through discrete interpolation. We introduce Mode Connectivity Evolutionary Attack (MoCo-EA), which replaces traditional cro…
Read original ↗https://arxiv.org/abs/2605.18919arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
ESLD (External Surrogate Latent Defense): A Latent-Space Architecture for Faster, Stronger Prompt-Injection Defense arXiv:2605.18918v1 Announce Type: new Abstract: Modern AI assistants are agentic. To answer a single user request, the underlying language model pulls in information from many sources, such as web searches, retrieved documents, tool outputs, and user follow-ups, and reasons over them across several steps. Any of these inputs can carry malicious content. This op…
Read original ↗https://arxiv.org/abs/2605.18918arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs arXiv:2605.18915v1 Announce Type: new Abstract: Multimodal Large Language Models (MLLMs) are vulnerable to jailbreak attacks, which can elicit harmful responses from MLLMs. Many MLLMs support multi-image inputs, inadvertently introducing new vulnerabilities due to less efforts on multi-image safety alignment. Previous MLLM jailbreak methods only uses a single image, which restricts the at…
Read original ↗https://arxiv.org/abs/2605.18915arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
SCAFDS: Edge-Feature Graph Attention for Interbank Fraud Detection with Attribution-Grounded SAR Generation arXiv:2605.18913v1 Announce Type: new Abstract: The U.S. financial system processes approximately 1.3 million interbank transactions daily, yet no system in the reviewed literature models fraud propagation across the interbank network using fraud co-occurrence edge features. Prior interbank GNN architectures model credit contagion using credit distress supervision sign…
Read original ↗https://arxiv.org/abs/2605.18913arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Fast and Lightweight Backdoor Detection via Head Random Probing arXiv:2605.18908v1 Announce Type: new Abstract: Deep neural networks (DNNs) remain critically vulnerable to backdoor attacks. Existing post-training detectors often require clean or surrogate data, gradients, or iterative trigger reconstruction, leading to high computational costs and limited robustness under practical model-auditing scenarios. In this paper, we propose HTell, a fast and lightweight data-free ba…
Read original ↗https://arxiv.org/abs/2605.18908