REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 15 of 22
arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Distributed Detectability Band Against Marginal-Preserving Attacks arXiv:2606.10456v1 Announce Type: new Abstract: AI-control monitors score individual agent actions to detect misbehavior, but real harm can be distributed across many benign-looking steps, each individually below any per-step alarm. We construct a marginal-preserving, correlation-encoded distributed-sabotage attack using a Gaussian-copula AR(1) construction: the per-step monitor-score marginal is held exa…
Read original ↗https://arxiv.org/abs/2606.10456arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Semantic Multi-Agent Intrusion Detection for IoT:Zero-Day and Adversarial Threats with Risk-Aware Reasoning arXiv:2606.10323v1 Announce Type: new Abstract: The rapid proliferation of Internet of Things (IoT) devices has enabled unprecedented automation and connectivity, but it has also substantially increased the attack surface, exposing networks to sophisticated cyber threats, including zero-day and adversarial intrusions. Traditional Intrusion Detection Systems (IDS) strug…
arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs arXiv:2606.10322v1 Announce Type: new Abstract: Large Language Models (LLMs) in multi-turn interactions maintain evolving context rather than generating isolated responses, making them vulnerable to prompt-injection and context-poisoning attacks in which locally plausible adversarial fragments gradually distort reasoning trajectories. Existing defenses mainly filter individual outputs and often ignore…
Read original ↗https://arxiv.org/abs/2606.10322arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems arXiv:2606.10163v1 Announce Type: new Abstract: The globalization of the integrated circuit (IC) supply chain increases the risk of security threats, such as hardware Trojans (HTs) and the theft of intellectual property (IP). Graph Neural Networks (GNNs), among the most powerful deep learning methods for processing graph-structured data, have been widely adopted to detect such threats. However, …
Read original ↗https://arxiv.org/abs/2606.10163arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke Inference arXiv:2606.10148v1 Announce Type: new Abstract: In today's digitally connected world, keyboards remain the primary interface for inputting sensitive information, making them a persistent target for eavesdropping attacks. While prior keystroke inference techniques have exploited side-channel signals such as acoustics and vibrations, they typically rely on conspicuous, short-range sensors and requ…
Read original ↗https://arxiv.org/abs/2606.10148arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT arXiv:2606.10097v1 Announce Type: new Abstract: Attackers often identify DNS traffic to disrupt or compromise Internet services. While prior work has focused on encrypting queries using DNS over TLS, HTTPS, or QUIC to counter such attacks, we consider IETF protocols designed for resource-constrained IoT devices and empirically analyze the potential of obfuscating DNS traffic in addition to encryption. …
Read original ↗https://arxiv.org/abs/2606.10097arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
SoK: Colluding Adversaries in Machine Learning Pipelines arXiv:2606.10091v1 Announce Type: new Abstract: Machine learning (ML) models are susceptible to various security, privacy, and fairness risks. Adversaries with different characteristics (i.e., objectives, knowledge, and capabilities) can collude by executing one attack to amplify others. Existing work lacks a systematic framework to explore collusion among adversaries, and to study the implications of the adversaries' …
Read original ↗https://arxiv.org/abs/2606.10091arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Human Vulnerabilities & Exploits (HVE) Framework arXiv:2606.10083v1 Announce Type: new Abstract: The cybersecurity community has invested over two decades in building standardized frameworks, the Common Vulnerabilities and Exposures (CVE) system, the Common Vulnerability Scoring System (CVSS), and the Common Weakness Enumeration (CWE) to identify, classify, and remediate threats to digital infrastructure. However, an emerging body of research reveals that a vast majority…
Read original ↗https://arxiv.org/abs/2606.10083arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Chronicles of Radio Frequency Fingerprinting arXiv:2606.10031v1 Announce Type: new Abstract: Radio Frequency Fingerprinting (RFF) has evolved from an early idea for radar emitter identification into a broad research field for wireless device identification and spectrum monitoring for security. Rather than presenting a conventional literature survey, this work provides a critical historical analysis of RFF organized around the field's major conceptual paradigm shifts from…
Read original ↗https://arxiv.org/abs/2606.10031arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines arXiv:2606.09935v1 Announce Type: new Abstract: AI-powered agents are increasingly embedded in continuous integration and continuous delivery/deployment (CI/CD) pipelines to autonomously review pull requests (PRs), triage issues, and maintain codebases. These agents ingest untrusted content while operating with elevated repository permissions, making them a natural target for prompt injection attack…
Read original ↗https://arxiv.org/abs/2606.09935arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization arXiv:2606.09909v1 Announce Type: new Abstract: With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent …
Read original ↗https://arxiv.org/abs/2606.09909arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
IDP-Bench: Benchmarking ability of LLMs to protect personal information in interdependent privacy contexts arXiv:2606.09908v1 Announce Type: new Abstract: Large language models (LLMs) are becoming widely deployed as personal AI assistants with access to sensitive user data, making privacy a major challenge for their design and evaluation. Prior work focuses mainly on individual-level risks, overlooking \textbf{interdependent privacy (IDP)}--where one person's data may be rev…
Read original ↗https://arxiv.org/abs/2606.09908arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Safecloud: A Distributed, Encrypted Storage Cloud for Streaming arXiv:2606.09870v1 Announce Type: new Abstract: We present Safecloud, a distributed, encrypted, self-pricing storage and streaming network whose storage and routing nodes never see plaintext and never hold keys. Each file is split into chunks, encrypted on the owner's device, and distributed across Drops (browser tabs storing ciphertext in IndexedDB) and Jets (federated routing servers). Only the owner, or an au…
Read original ↗https://arxiv.org/abs/2606.09870arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Proof of Source of Funds: Efficient On-chain Provenance of Cryptoassets arXiv:2606.10172v1 Announce Type: new Abstract: Regulatory compliance is increasingly mandatory for decentralized finance and privacy-enhancing technologies. Current approaches rely on binary inclusion/exclusion lists or retroactive graph analysis by centralized blockchain intelligence firms. This approach strips honest users of their financial privacy, leads to false positives and negatives, and forces …
Read original ↗https://arxiv.org/abs/2606.10172arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations arXiv:2606.10281v1 Announce Type: new Abstract: This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmark to explore the performance of LLMs on four log-investigation tasks that incident response teams commonly perform, ranging from triaging alerts generated by detectors to id…
Read original ↗https://arxiv.org/abs/2606.10281arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Quantum-Inspired Reinforcement Learning for Low-Latency Intrusion Detection in V2X and Internet-of-Vehicles Networks arXiv:2606.07804v1 Announce Type: new Abstract: Smart cities increasingly depend on dense edge, IoT, and vehicular networks to deliver critical urban services, including traffic control, connected mobility, infrastructure monitoring, and energy management. In this ecosystem, the Internet of Vehicles (IoV) is central to intelligent transportation, enabling cont…
Read original ↗https://arxiv.org/abs/2606.07804arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
MOLOT System Card: Malicious Operational Logic Observation Transformer arXiv:2606.07792v1 Announce Type: new Abstract: MOLOT (Malicious Operational Logic Observation Transformer) is a static malicious-code detection system designed for SAST setup where package metadata, maintainer history, and dynamic execution traces may be unavailable or unreliable. The system represents source code as behavior sequences derived from static call graphs, includes an explanation stage that r…
Read original ↗https://arxiv.org/abs/2606.07792arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SoK: Reconstruction Attacks on Synthetic Tabular Data (Insights from Winning the NIST CRC) arXiv:2606.08372v1 Announce Type: new Abstract: Synthetic data is increasingly promoted as a privacy-preserving substitute for releasing sensitive tabular records, yet its central adversarial threat ("reconstruction", the recovery of an individual's hidden attribute values from a synthetic release and a handful of known quasi-identifiers) has been studied only in scattered, hard-to-com…
Read original ↗https://arxiv.org/abs/2606.08372arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Model Multiplicity for Adversarial Detection in Small Language Model Training on Edge Devices arXiv:2606.07857v1 Announce Type: new Abstract: The rise of edge-based machine learning has enabled distributed adaptation of language models across mobile and IoT devices, offering privacy preservation and real-time responsiveness. However, distributed fine-tuning of language models on untrusted or heterogeneous edge nodes introduces new vulnerabilities. Compromised or unreliable d…
Read original ↗https://arxiv.org/abs/2606.07857arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Belief-Space Quantum-Inspired Reinforcement Learning for Partially Observable Autonomous Cyber Defense in the Internet of Vehicles arXiv:2606.07796v1 Announce Type: new Abstract: The Internet of Vehicles (IoV) faces a dynamic, adversarial security environment where attackers adapt to defenses. Existing intrusion detection systems rely on static classifiers that fail to capture sequential decision-making, attacker adaptation, and uncertainty. We formulate IoV security as a se…
Read original ↗https://arxiv.org/abs/2606.07796arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
An AI Security Agent for University ACMIS: Multi-Vector Threat Detection and Automated Response arXiv:2606.08270v1 Announce Type: new Abstract: University Academic Management Information Systems (ACMIS) are high-value targets for a wide spectrum of security threats including brute-force login attacks, payment fraud, privilege escalation, insider data theft, and academic integrity violations. Traditional rule-based intrusion detection systems are inadequate because many malic…
Read original ↗https://arxiv.org/abs/2606.08270arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Quantifying and Defending against the Privacy Risk in Logit-based Federated Learning arXiv:2606.08252v1 Announce Type: new Abstract: Federated learning aims to protect data privacy by collaboratively learning a model without sharing private data among clients. Unlike traditional parameter-based FL methods that exchange model weights or gradients during training, emerging logit-based FL approaches share model outputs (logits) on public data. This strategy promotes model heter…
Read original ↗https://arxiv.org/abs/2606.08252arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
LPOR: A Layered Proof of Reserves Framework for Usable and Publicly Auditable Solvency Verification arXiv:2606.08211v1 Announce Type: new Abstract: Proof of Reserves (PoR) enables centralized crypto exchanges to demonstrate that on-chain reserves are sufficient to cover customer liabilities. However, existing approaches, including Merkle-tree-based proofs and zero-knowledge PoR systems, remain difficult for everyday users to verify in practice, resulting in limited participa…
Read original ↗https://arxiv.org/abs/2606.08211arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
DP4SQL: Differentially Private SQL with Flexible Privacy Policies arXiv:2606.07883v1 Announce Type: new Abstract: The plausible deniability model of differential privacy for single-table datasets is well-understood. However, applying differential privacy to relational databases is much trickier: each application needs flexibility in specifying the pieces of information about an entity, spread across multiple relations, that require plausible deniability guarantees. Existing …
Read original ↗https://arxiv.org/abs/2606.07883arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Hallucination Cascade: Analyzing Error Propagation in Multi-Agent LLM Systems arXiv:2606.07937v1 Announce Type: new Abstract: Large Language Models (LLMs) generate fluent text but remain vulnerable to hallucinations, producing unsupported, inconsistent, and factually incorrect claims. Most prior work treats hallucination as a static property of isolated outputs. In multi-agent LLM systems, however, responses are exchanged across agents, revised through sequential stages, and…
Read original ↗https://arxiv.org/abs/2606.07937arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SGTO-MAS: Secure Gorilla Troops Optimization for Multi-Agent LLM Systems arXiv:2606.07940v1 Announce Type: new Abstract: Multi-agent large language model (LLM) systems offer strong capabilities for complex reasoning and decision-making, yet coordination across agents introduces error propagation, security risks, and inefficient use of resources. Existing methods often rely on heuristic, static strategies and lack a principled mechanism for balancing performance, security, an…
Read original ↗https://arxiv.org/abs/2606.07940arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
AI-Native Closed-Loop Security for 6G-Enabled Cyber-Physical Systems: From Edge Detection to Network-Wide Mitigation arXiv:2606.08173v1 Announce Type: new Abstract: In sixth-generation (6G) networks, billions of cyber-physical systems (CPSs) - autonomous vehicles, smart grids, industrial robots, and remote-surgical equipment - will run over ultra-reliable low-latency slices, collapsing the gap between a remote breach and physical harm to milliseconds, a budget perimeter fire…
Read original ↗https://arxiv.org/abs/2606.08173arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Collective Hallucination in Multi-Agent LLMs:Modeling and Defense arXiv:2606.07941v1 Announce Type: new Abstract: Hallucinations in large language models (LLMs) create heightened risks in multi-agent settings, where recursive agent interactions can propagate, reinforce, and amplify unsupported claims. This paper models hallucination as a system-level, time-evolving process across a network of interacting LLM agents, where nodes represent agents and edges encode information e…
Read original ↗https://arxiv.org/abs/2606.07941arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
MLingualFC: Evaluating Jailbreak Vulnerabilities in Multilingual Vision-Language Models arXiv:2606.07706v1 Announce Type: new Abstract: Vision-Language Models (VLMs) have demonstrated strong performance across multimodal tasks, yet their safety robustness remains an open challenge. While prior work has shown that structured visual prompts such as flowcharts can effectively jailbreak VLMs, existing studies are largely limited to English-centric settings. In this paper, we int…
Read original ↗https://arxiv.org/abs/2606.07706arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
POISE: Position-Aware Undetectable Skill Injection on LLM Agents arXiv:2606.07943v1 Announce Type: new Abstract: Agent skills provide a lightweight mechanism for extending general-purpose agents, but their open format exposes them to skill-poisoning attacks. A practically dangerous injection must stay invisible: if executing the payload derails the user's legitimate task, the resulting failure signal invites inspection of the skill. We therefore evaluate attacks by Attack Su…
Read original ↗https://arxiv.org/abs/2606.07943arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SHIELD-IDS: Structurally Heterogeneous Ensemble with Integrated Layered Defense for Intrusion Detection Systems arXiv:2606.07716v1 Announce Type: new Abstract: Adversarial attacks pose a serious and growing threat to Machine Learning (ML)-based Intrusion Detection Systems (IDS), where imperceptible perturbations to network flow features can systematically mislead classifiers into accepting malicious traffic as benign. The IDS-Anta framework partially addresses this through Z…
Read original ↗https://arxiv.org/abs/2606.07716arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Demand-Driven Vulnerability Detection for Cloud Security Posture Management: Removing Human Rule Authoring from the Disclosure-to-Protection Critical Path arXiv:2606.07957v1 Announce Type: new Abstract: Cloud Security Posture Management (CSPM) systems detect known vulnerabilities by maintaining a rule set, distributing it to customers, and evaluating it against periodically-collected asset inventories. To our knowledge, in publicly documented architectures the rule set is en…
Read original ↗https://arxiv.org/abs/2606.07957arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks arXiv:2606.07968v1 Announce Type: new Abstract: Reasoning-capable large language models can be induced to spend their generation budget on injected decoy tasks rather than answering the user's question, causing denial of service when no final answer is produced and denial of wallet when excess output tokens are billed. Input-side safety classifiers often miss these attacks because the injected prompts can…
Read original ↗https://arxiv.org/abs/2606.07968arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Detecting Aimbot Cheaters in MOGs arXiv:2606.07650v1 Announce Type: new Abstract: Multiplayer Online Games have become a multibillion dollar industry in the entertainment sector. However, the presence of cheaters undermines the experience of honest players and devalues the effort of game developers, as it directly affects player retention, competitive integrity, the legitimacy and trustworthiness of a game, and most importantly the overall revenue streams. Among various chea…
Read original ↗https://arxiv.org/abs/2606.07650arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
The Dodona Protocol: A Living Design Science Experiment in Oracle Design arXiv:2606.08012v1 Announce Type: new Abstract: The oracle problem, broadly understood as the difficulty of reliably incorporating external information into blockchain-based systems, has been widely examined by scholars and practitioners. Recent comparative research has shown that several challenges of modern blockchain oracles, including attributability, accountability, integrity, and query design, mir…
Read original ↗https://arxiv.org/abs/2606.08012arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
ScaleDisturb: Exploiting Temporal Asymmetry to Amplify Read Disturbance in Modern DRAM Chips arXiv:2606.07761v1 Announce Type: new Abstract: DRAM suffers from read disturbance phenomena (e.g., RowHammer and RowPress), where repeatedly accessing or continuously keeping open a DRAM row (aggressor row) induces bitflips in other physically nearby unaccessed rows (victim rows). The disturbance mechanism is practically exploitable from the software stack and worsens across generat…
Read original ↗https://arxiv.org/abs/2606.07761arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Policy Description Language for Authorization using Logic-Based Programming arXiv:2606.08119v1 Announce Type: new Abstract: Recently, with the impossibility of eradicating the vulnerabilities of information systems, we must prepare for the occurrence of the security incident by the multi-layer defense called the Defense-in-Depth strategy. In the multi-layer defense, it is important to authorize accesses in fine-grained granularity to compose each layer effectively, and many …
Read original ↗https://arxiv.org/abs/2606.08119arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Closing the Sim-to-Real Gap: An Evaluation Framework for Autonomous Cyber Defense Configuration of Commercial EDR arXiv:2606.08168v1 Announce Type: new Abstract: Leading commercial endpoint detection and response (EDR) products have shifted from operator-configured rule sets to multi-component systems where autonomous AI components operate alongside, and increasingly in place of, operator-deployed policies. Autonomous defense agents using commercial EDR as their hardening to…
Read original ↗https://arxiv.org/abs/2606.08168arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Ternary public-key cryptosystem arXiv:2606.07832v1 Announce Type: new Abstract: Public-key cryptosystems eliminate the requirement for pre-shared secret keys by enabling encryption with a publicly disclosed key and decryption with a corresponding private key. In this article we generalize the public-key cryptosystems to ternary algebraic structures, with particular attention to ElGamal as a representative family. We introduce the necessary algebraic background for nonderived…
Read original ↗https://arxiv.org/abs/2606.07832arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Beyond Pass/Fail: Using Process Mining to Understand How LLMs Resist (and Fail) Red Team Attacks arXiv:2606.07833v1 Announce Type: new Abstract: Standard AI red teaming evaluations reduce adversarial campaigns to a single binary outcome, attack success rate (ASR), not taking into account the sequential structure of how models resist or yield to attacks. We propose applying process mining, a discipline for discovering and analyzing process models from event logs, to red teami…
Read original ↗https://arxiv.org/abs/2606.07833