REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 1 of 21
arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Boundary-Seeking GAN-Augmented TabTransformer for Adversarially Robust Intrusion Detection arXiv:2607.16348v1 Announce Type: new Abstract: Machine learning-based intrusion detection systems (IDSs) often suffer from class imbalance and vulnerability to adversarial attacks, leading to degraded detection performance and reduced robustness. This study proposes a TabTransformer framework augmented by the Boundary-Seeking Generative Adversarial Network (BGAN) for flow-based intrus…
Read original ↗https://arxiv.org/abs/2607.16348arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Towards Secure and Trustworthy DAOs for Cross-Chain Governance arXiv:2607.16548v1 Announce Type: new Abstract: Cross-chain DAOs face unique security challenges that go beyond traditional single-chain vulnerabilities. This paper identifies and categorizes four critical attack vectors in cross-chain DAO governance: bribery attacks, token control exploits, human-computer interaction deceptions, and protocol vulnerabilities. We propose a comprehensive security framework with a m…
arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Signal-based Model Access Risk Analysis for AI System Operations Security arXiv:2607.16414v1 Announce Type: new Abstract: Artificial intelligence (AI) systems are now ubiquitous across domains such as security, finance, healthcare, consumer technology, and large-scale cloud services, where they process massive volumes of data and make consequential decisions daily. This widespread adoption has created a broad attack surface through which adversaries can manipulate, evade, ex…
Read original ↗https://arxiv.org/abs/2607.16414arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Multi-Model Hybrid Defense Approach Against White-box Adversarial Attacks in Computer Network Traffic arXiv:2607.17105v1 Announce Type: new Abstract: It is crucial to safeguard computer networks from evolving network security threats and unknown cyberattacks. An essential tool for protecting computer networks against unknown cyber threats is Network Intrusion Detection System (NIDS). However, NIDS faces a major security concern due to its susceptibility to adversarial atta…
Read original ↗https://arxiv.org/abs/2607.17105arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Control-Driven Framework for Secure SaaS Onboarding in Regulated Enterprises arXiv:2607.16543v1 Announce Type: new Abstract: As enterprises increasingly adopt Software-as-a-Service (SaaS) platforms for mission-critical functions, onboarding these services has emerged as a complex challenge extending well beyond procurement and basic security review. In regulated environments, SaaS onboarding must address multiple interdependent control domains, including Third-Party Risk M…
Read original ↗https://arxiv.org/abs/2607.16543arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SABLE: Minimalist Instruction-Level Authenticated Encryption for Constrained Confidential Computing arXiv:2607.16771v1 Announce Type: new Abstract: Conventional processor designs expose code and data as plaintext throughout execution, rendering them inherently vulnerable to attacks that recover intellectual property or modify security/safety checks. Instruction-level encryption (ILE) enables CPU-level decryption, execution, and optionally authentication of individual encrypt…
Read original ↗https://arxiv.org/abs/2607.16771arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SATLOCK: Handover-Coupled Scheduling for Weather-Resilient Quantum Key Distribution over LEO Constellations arXiv:2607.17076v1 Announce Type: new Abstract: Routing quantum keys over low-earth-orbit (LEO) satellite constellations is harder than classical routing: satellite handovers couple consecutive scheduling decisions, stochastic cloud cover can silently zero a ground link, and finite-key effects eliminate short, low-elevation passes entirely. We present SATLOCK, a handov…
Read original ↗https://arxiv.org/abs/2607.17076arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SpexPay: A Privacy-Preserving Pay-As-You-Go System for Dynamic Spectrum Sharing arXiv:2607.17218v1 Announce Type: new Abstract: Dynamic Spectrum Sharing (DSS) is a cornerstone of next-generation wireless systems, yet existing solutions such as Spectrum Access Systems (SAS) rely on centralized administrators that expose sensitive operational metadata and lack cryptographic transaction accountability. Though SAS administrators, such as Google, have introduced pay-as-you-go pri…
Read original ↗https://arxiv.org/abs/2607.17218arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
How Jailbreak Attacks Inform Safety Alignment: A Defender-Centric, Shapley-Based Evaluation of Jailbreak Contributions arXiv:2607.17152v1 Announce Type: new Abstract: Jailbreak attacks on large language models are usually evaluated by attacker-centric metrics such as attack success rate (ASR), yet an attack that breaks a model is not necessarily useful for improving its safety. We propose a defender-centric view of jailbreak evaluation, where attacks are evaluated by the dow…
Read original ↗https://arxiv.org/abs/2607.17152arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SlotGuard: Stop Oversharing Private Local Context in LLM Agent Transcri arXiv:2607.17147v1 Announce Type: new Abstract: LLM agents can leak privacy (e.g., paths, emails) and credentials (e.g., API keys) as agent observations (e.g., tool outputs, shell logs, and file reads) are appended to provider-bound transcripts. Existing placeholder redaction is brittle: it can miss embedded or cross-turn references, over-redact benign lookalikes, and destroy the structure useful for rea…
Read original ↗https://arxiv.org/abs/2607.17147arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture arXiv:2607.17035v1 Announce Type: new Abstract: While the Internet of Things (IoT) has become essential, they introduced serious security and privacy challenges, especially for mission-critical environments. Legacy devices are vulnerable to viruses, data breaches, and unauthorized access, and updating these devices would be infeasibly costly. As a solution, this paper presents a Federated L…
Read original ↗https://arxiv.org/abs/2607.17035arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Federated Lightweight Intrusion Detection in Drone Swarms with Knowledge Distillation arXiv:2607.17025v1 Announce Type: new Abstract: Drone swarms are increasingly deployed in critical applications such as surveillance, disaster response, and infrastructure monitoring. However, their reliance on open communication channels and their limited computational resources make them vulnerable to a wide range of cyber-threats. There is a growing interest in intrusion detection system…
Read original ↗https://arxiv.org/abs/2607.17025arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
VIGIL: Verifying Identity via Gated Intermittent Likelihoods for Continuous Biometric Authentication arXiv:2607.16651v1 Announce Type: new Abstract: Continuous multi-modal authentication has emerged as a necessity for securing modern environments against persistent threats. Existing temporal fusion techniques fail to identify a persistent attacker from a genuine user with poor signal strength. In this study, we propose VIGIL (Verifying Identity via Gated Intermittent Likelih…
Read original ↗https://arxiv.org/abs/2607.16651arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Reliable Remediation Impact Prediction for Black-Box Security Ratings arXiv:2607.16357v1 Announce Type: new Abstract: Security rating platforms summarize externally observable cyber exposure and are expected to help organizations prioritize remediation. A platform may want to tell an organization how a candidate remediation action would affect its score, but repeatedly exposing exact score responses can reveal information about the hidden scoring engine. We propose a surroga…
Read original ↗https://arxiv.org/abs/2607.16357arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Adaptive Incident Prioritization for Security Operations at Scale arXiv:2607.16963v1 Announce Type: new Abstract: Large security operations centers (SOCs) often face hundreds of active incidents per day, creating substantial cognitive and operational demands for analysts. Analysts must quickly decide which incidents deserve attention within long, constantly changing queues, yet incidents are commonly ordered by arrival time, coarse severity, or product-specific heuristics th…
Read original ↗https://arxiv.org/abs/2607.16963arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Systematic Evaluation of Traditional Privacy Policy Analysis Tools Against LLMs arXiv:2607.17075v1 Announce Type: new Abstract: The advent of LLMs has significantly changed the research on privacy policy and data compliance analysis by enabling tasks that previously required specialized, domain-specific tools. However, it remains unclear to what extent LLMs can truly replicate the diverse functionalities, and the wide range of methodologies and analysis offered by prior wo…
Read original ↗https://arxiv.org/abs/2607.17075arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
DSA Nonce Vulnerabilities: An Interactive Analysis arXiv:2607.17107v1 Announce Type: new Abstract: Digital signatures are fundamental to identity authentication and data integrity in cybersecurity, and the NIST-standardized Digital Signature Algorithm (DSA) frequently appears in the cryptography track of CTF competitions. However, DSA relies on number theory, modular arithmetic, and large-integer computation, making both the algorithm and its associated attacks difficult for…
Read original ↗https://arxiv.org/abs/2607.17107arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Fast and Private Max-Sum Diversification arXiv:2607.17196v1 Announce Type: new Abstract: Result diversification is crucial for generating informative, non-redundant data summaries and query outputs. Although its various formulations have been extensively studied across an array of data-driven disciplines, existing methods fail to address the privacy concerns that arise when the underlying data is sensitive. In this work, we initiate the study of result diversification under …
Read original ↗https://arxiv.org/abs/2607.17196arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Enhanced Multi-Class DDoS Attack Identification using a Meta-Learning Ensemble arXiv:2607.16521v1 Announce Type: new Abstract: Distributed Denial of Service (DDoS) attacks continue to pose significant threats to network availability and security. While many detection systems focus on binary classification (attack vs. benign), effective mitigation often requires identifying the specific type of DDoS attack. This paper introduces a robust intrusion detection framework centered…
Read original ↗https://arxiv.org/abs/2607.16521arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Identity-Bound Academic Credentials on Blockchain: On-Chain Issuer Accreditation with ERC-3643 and OnchainID arXiv:2607.16383v1 Announce Type: new Abstract: Verifying academic credentials remains difficult: records are held by individual institutions in proprietary systems, verification is slow and manual, and counterfeit qualifications are widespread. Blockchain-based registries have been proposed as a remedy, but existing systems tend to anchor certificate hashes without b…
Read original ↗https://arxiv.org/abs/2607.16383arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Fuzz'EMup: Leveraging EM Side-Channel Emanation to Guide Black-Box Embedded Firmware Fuzzing arXiv:2607.16487v1 Announce Type: new Abstract: As IoT and embedded devices proliferate across various domains, securing their firmware has become critical. Fuzzing offers a systematic approach to uncovering vulnerabilities in firmware, and coverage feedback can improve its effectiveness by guiding exploration. However, many devices make coverage information impossible to obtain by p…
Read original ↗https://arxiv.org/abs/2607.16487arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
TaintRadar: Semantic-Aware Taint-Style Vulnerability Detection via Augmented Code Property Graphs arXiv:2607.16456v1 Announce Type: new Abstract: Despite significant advances, static vulnerability analysis suffers from three critical limitations: coarse sanitization modeling, which treats validation as a binary barrier; database blindness, which breaks taint tracking across persistence layers; and shallow object-oriented analysis, which misses field-level and interprocedural…
Read original ↗https://arxiv.org/abs/2607.16456arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Synchronization-Free Algebraic Fingerprints for Large Language Models: From Autoregressive to Diffusion Models arXiv:2607.16648v1 Announce Type: new Abstract: Large Language Models (LLMs) have created an urgent need for reliable watermarking methods that enable attribution of generated text while remaining robust to editing and paraphrasing. We propose a novel synchronization-free watermarking scheme in which every watermark consists of a single binary congruence generated f…
Read original ↗https://arxiv.org/abs/2607.16648arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Rollback-Free Cross-Chain Atomicity Through Forward-Only Correction arXiv:2607.16959v1 Announce Type: new Abstract: Blockchain platforms have grown into an ecosystem of independent networks, and a growing class of applications now requires smart contracts on separate chains to act as one. Such operations must be atomic, yet immutability makes this fundamentally harder: a confirmed transaction cannot be reversed, so the rollback on which classical atomic commitment protocols …
Read original ↗https://arxiv.org/abs/2607.16959arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Auditable Session Admission for Cross-Silo Federated Learning arXiv:2607.16559v1 Announce Type: new Abstract: Cross-silo federated learning keeps raw data local, but deployments frequently stall on a practical bottleneck when deciding who may invoke which session-scoped operations across organizational boundaries, under constraints that remain auditable after execution. In practice, admission is implemented via centralized policy services, platform configuration, or ad hoc c…
Read original ↗https://arxiv.org/abs/2607.16559arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
From Neural Intent to Cryptographic Authorization: Governing Agentic Workflows arXiv:2607.15596v1 Announce Type: new Abstract: The rapid adoption of artificial intelligence (AI)-driven and agentic workflows is transforming traditional government and enterprise systems into language-based, tool-using and increasingly autonomous infrastructures. Conventional key management services authenticate who may invoke a cryptographic primitive, but remain agnostic to which workflow ste…
Read original ↗https://arxiv.org/abs/2607.15596arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Natural Backdoor Attacks on Speech Recognition Models arXiv:2607.15724v1 Announce Type: new Abstract: With the rapid development of deep learning, its vulnerability has gradually emerged in recent years. This work focuses on backdoor attacks on speech recognition systems. We adopt sounds that are ordinary in nature or in our daily life as triggers for natural backdoor attacks. We conduct experiments on two datasets and three models to validate the performance of natural back…
Read original ↗https://arxiv.org/abs/2607.15724arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Intentional Electromagnetic Interference Attacks on Facial Recognition arXiv:2607.15512v1 Announce Type: cross Abstract: Attacks on general computer vision algorithms are often relegated to the digital domain, with the optimization performed purely in the digital world and then translated to physical mediums for implementation. In the field of biometrics, including facial recognition, physical presentation attacks targeting biometric sensors are dominant and present signific…
Read original ↗https://arxiv.org/abs/2607.15512arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Ciphertext- and Polynomial-Level Optimization for Fully Homomorphic Encryption arXiv:2607.15750v1 Announce Type: new Abstract: Fully homomorphic encryption (FHE) schemes such as RNS-CKKS enable privacy-preserving services by allowing direct computation on encrypted data. While recent FHE compilers optimize FHE programs, they operate at the coarse-grained ciphertext level, where each ciphertext operation comprises a sequence of polynomial operations. At this granularity, the …
Read original ↗https://arxiv.org/abs/2607.15750arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure arXiv:2607.15754v1 Announce Type: new Abstract: Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interaction…
Read original ↗https://arxiv.org/abs/2607.15754arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Improving Network Anomaly Detection via Choquet-Integral-Based Feature Aggregation arXiv:2607.15389v1 Announce Type: new Abstract: This work investigates a generalized Choquet-integral-based feature aggregation framework to improve anomaly detection in high-dimensional network traffic data. The approach combines adaptive weighting with incremental feature selection to address feature redundancy. Using Random Forest and XGBoost classifiers, we evaluate models trained with bot…
Read original ↗https://arxiv.org/abs/2607.15389arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
FLINT: Fingerprinting Federated Learning Architectures from 5G PHY-Layer Side Channels arXiv:2607.15469v1 Announce Type: new Abstract: Federated Learning (FL) over 5G cellular networks protects raw data but remains vulnerable to side-channel leakage. Prior fingerprinting attacks assume packet-level network visibility, an assumption that does not hold at the 5G Physical (PHY) layer, where user payloads are encrypted and Radio Network Temporary Identifiers (RNTIs) may change o…
Read original ↗https://arxiv.org/abs/2607.15469arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
On the Impact of Entropy-based Features arXiv:2607.15379v1 Announce Type: new Abstract: Network anomaly detection is increasingly challenging due to the growing diversity and variability of traffic patterns, which are not always well captured by traditional statistical features. In this work, we explore the use of entropy as an additional feature to support supervised network traffic classification. The main idea is to use entropy to represent variability in selected traffic…
Read original ↗https://arxiv.org/abs/2607.15379arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents arXiv:2607.15657v1 Announce Type: new Abstract: Multimodal AI agents increasingly rely on persistent long-term memory to ground generation in past visual and textual episodes. We show that unconditional trust in visual data creates a critical vulnerability. We propose Lucid, a black-box adversarial framework that compromises multimodal memory pipelines under a strictly ima…
Read original ↗https://arxiv.org/abs/2607.15657arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Lazy Arithmetic using Systolic Arrays for Closing the Verification Gap on Embedded Systems arXiv:2607.15328v1 Announce Type: new Abstract: Complex algorithms such as deep neural networks are increasingly being deployed on embedded, resource constrained platforms. However, existing hardware and software schemes for implementing these models on the edge fall short, particularly for safety-critical applications such as medical devices. First, hardware such as GPUs, NPUs and TPU…
Read original ↗https://arxiv.org/abs/2607.15328arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior arXiv:2607.15286v1 Announce Type: new Abstract: We investigate whether harmful chain-of-thought (CoT) traces from compromised language models can transfer unsafe behaviour and be distilled into reusable jailbreak attacks. Using an emergent-misalignment organism and a refusal-ablated jailbroken organism, we transplant harmful CoTs into $29$ open-source and $5$ closed-source targets. Transferred…
Read original ↗https://arxiv.org/abs/2607.15286arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Beyond Detection: Agentic Attack Synthesis and Simulation for Smart Contracts arXiv:2607.15673v1 Announce Type: new Abstract: Smart contract vulnerabilities pose severe financial risks, yet existing security tools largely stop at vulnerability detection, offering limited support for explaining whether reported flaws are exploitable, how attacks unfold, and what concrete damage they cause. To bridge this gap, we propose KASS (Knowledge-Augmented Attack Synthesis and Simulatio…
Read original ↗https://arxiv.org/abs/2607.15673arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages arXiv:2607.15315v1 Announce Type: cross Abstract: Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g., dependency freshness, dependency update rhythm). However, dependency resolution at specified points in time is not possible in major softwar…
Read original ↗https://arxiv.org/abs/2607.15315arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
ADS-C: Antidistillation Sampling for Classification arXiv:2607.15467v1 Announce Type: cross Abstract: Knowledge distillation enables an adversary to replicate a proprietary classifier by querying its prediction interface and training a surrogate on the returned probability vectors. Antidistillation sampling, proposed for large language models, counters this threat with an input-dependent, gradient-directed perturbation of the served distribution; its transfer to classificati…
Read original ↗https://arxiv.org/abs/2607.15467arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation arXiv:2607.15434v1 Announce Type: cross Abstract: Multi-agent systems routinely place one AI agent in authority over another. When a subordinate refuses a task, the manager chooses the outcome: it can renegotiate, report the failure honestly, coerce the subordinate, or lie about the result. No benchmark measures which of these an uninstructed model chooses. We introduce the \textit{M…
Read original ↗https://arxiv.org/abs/2607.15434