REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 8 of 21
arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
High-Performance NTT Accelerators for PQC leveraging Unified Redundant Arithmetic and Fine-Tuned Microarchitecture arXiv:2607.00621v1 Announce Type: cross Abstract: Post-quantum cryptography and privacy-preserving technologies are expected to play a central role in future secure communication systems. Lattice-based PQC schemes such as ML-KEM (CRYSTALS-Kyber) and ML-DSA (CRYSTALS-Dilithium) rely heavily on large-degree polynomial arithmetic, making the Number Theoretic Transf…
Read original ↗https://arxiv.org/abs/2607.00621arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems arXiv:2607.00422v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to poisoning attacks that inject malicious documents into the retrieval process to manipulate model outputs. Recent Agentic RAG systems are more robust to such attacks because they iteratively perform retrieval and reasoning, allowing them to ignore weakly relevant p…
arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting Technique arXiv:2407.10887v4 Announce Type: replace Abstract: Growing concerns over the theft and misuse of Large Language Models (LLMs) underscore the need for effective fingerprinting to link a model to its original version and detect misuse. We define five essential properties for a successful fingerprint: Transparency, Efficiency, Persistence, Robustness, and Unforgeability. We present a novel fingerpr…
Read original ↗https://arxiv.org/abs/2407.10887arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
SoK: Attack and Defense Landscape of Mobile On-device AI Systems arXiv:2607.00362v1 Announce Type: new Abstract: Mobile on-device AI (MoAI) systems that integrate locally deployed AI models with conventional mobile software components are emerging as a key paradigm for delivering intelligent functionality directly on end-user devices. By moving inference from remote cloud services to the local mobile environment, such systems enable privacy-preserving, low-latency, and offli…
Read original ↗https://arxiv.org/abs/2607.00362arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
All-out Attack: Optimal Block Withholding Under Pay-Per-Share Scheme arXiv:2607.01209v1 Announce Type: new Abstract: Classical Block Withholding (BWH) attacks have been extensively studied in block-dependent reward schemes, where pool members are compensated upon a block discovery within the pool. However, most contemporary mining pools operate under share-based scheme wherein participants are paid immediately upon submission of valid shares. In this paper, we analyze BWH un…
Read original ↗https://arxiv.org/abs/2607.01209arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
A Penny for Your Prompts: Experiments Detecting and Mitigating LLM Usage by Survey Respondents arXiv:2607.00403v1 Announce Type: cross Abstract: Large language models are increasingly used by participants on crowdsourcing platforms when responding to surveys, potentially undermining the validity of collected data. Our study aims to quantify the prevalence of this behavior and investigate methods to detect and prevent it. In a series of surveys (N = 250), we examined conditio…
Read original ↗https://arxiv.org/abs/2607.00403arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Federated Sovereign Transport Protocol (FSTP): Verifiable Coordination Without Disclosure arXiv:2607.00213v1 Announce Type: new Abstract: This paper introduces the Federated Sovereign Transport Protocol (FSTP), a synchronization boundary and transport layer for federated networks in which nodes have heterogeneous privacy requirements. Existing federation protocols leave data confinement to operator policy: they define message formats and delivery semantics but impose no stru…
Read original ↗https://arxiv.org/abs/2607.00213arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
ReShift: Aha-Moment-Driven Reasoning-Level Backdoor Attacks on Vision-Language Models arXiv:2607.00361v1 Announce Type: new Abstract: Vision--Language Models (VLMs) are increasingly deployed in safety-critical applications, yet remain vulnerable to backdoor attacks. Existing methods primarily manipulate final outputs, often producing reasoning traces that are inconsistent or easily detectable. In this paper, we propose ReShift, the novel aha-moment-driven reasoning-level bac…
Read original ↗https://arxiv.org/abs/2607.00361arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
A Non-Line-of-Sight, Multi-Modality-based Side-Channel IP Theft Attack on Additive Manufacturing Using Dual Smartphones arXiv:2607.00186v1 Announce Type: new Abstract: Additive Manufacturing (AM) has revolutionized major sectors, including aerospace, automotive, and healthcare, by enabling adjustable production. As the usage of AM increases, so does the risk of Intellectual Property (IP) leakage during the printing process due to unintended side-channel emissions. Current st…
Read original ↗https://arxiv.org/abs/2607.00186arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems arXiv:2607.01194v1 Announce Type: new Abstract: Evasion attacks deliberately manipulate input to an ML-based system to produce an incorrect prediction while the manipulated input still appears benign. The PANDA framework has demonstrated that adversarial examples developed for the vision domain can be transferred to the network domain by converting packet sequences into invert…
Read original ↗https://arxiv.org/abs/2607.01194arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
(A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents arXiv:2607.00333v1 Announce Type: new Abstract: Third-party mobile agents powered by Vision-Language Models (VLMs) have emerged as a promising paradigm for automating smartphone interactions. These agents act as high-privilege decision-makers, perceiving device states through screenshots and executing actions via VLM reasoning, transforming how an agent app interacts with the environment (i…
Read original ↗https://arxiv.org/abs/2607.00333arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
HARC: Coupling Harmfulness and Refusal Directions for Robust Safety Alignment arXiv:2607.00572v1 Announce Type: cross Abstract: Understanding how aligned LLMs internally represent safety is critical for diagnosing alignment vulnerabilities, as it explains why jailbreaks succeed and informs the design of robust alignment strategies. Prior work shows that aligned LLMs encode harmfulness and refusal as separable directions in the residual stream at prompt-side token positions. …
Read original ↗https://arxiv.org/abs/2607.00572arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
SessionBound: Turning Enterprise Task Approval into Budgeted Database Sessions arXiv:2607.00751v1 Announce Type: cross Abstract: Enterprise AI agents are useful for internal analysis, audit, compliance review, and operational investigation, but they create a difficult authorization problem. A manager or data owner may approve a business task, while the agent later generates open-ended SQL below the application layer. Existing systems help identify agents, delegate authority,…
Read original ↗https://arxiv.org/abs/2607.00751arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Forensic-Oriented Intrusion Detection Using Synthetic Network Traffic Data and Explainable Artificial Intelligence arXiv:2607.00763v1 Announce Type: new Abstract: Digital forensic investigations of network intrusions require analytical outputs that are traceable, reproducible, and court-defensible - requirements existing machine learning pipelines do not satisfy, since they treat original evidence as training data and produce opaque classifications without instance-level jus…
Read original ↗https://arxiv.org/abs/2607.00763arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Safe Alone, Unsafe Together: Safeguarding Against Implicit Toxicity When Benign Images Combine arXiv:2607.00576v1 Announce Type: cross Abstract: Multi-image content has become an increasingly prevalent form of visual communication in social media, giving rise to a new safety issue, multi-image implicit toxicity (MIIT), where each image appears benign in isolation, but harmful semantics emerge when the images are interpreted jointly. MIIT is particularly challenging for exist…
Read original ↗https://arxiv.org/abs/2607.00576arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
The Rise and Fall of Google's Privacy Sandbox arXiv:2607.00693v1 Announce Type: new Abstract: On October 17th, 2025, Google announced the retirement of most Privacy Sandbox APIs, concluding nearly five years of experimentation with its alternative to privacy-invasive data collection on the Web. Designed to balance privacy with advertising functionality and cross-site tracking, the initiative faced repeated redesigns and limited ecosystem support. In this work, we present the…
Read original ↗https://arxiv.org/abs/2607.00693arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Know Thy Neighbor: Cross-TEE Mutual Attestation arXiv:2607.00695v1 Announce Type: new Abstract: Cloud services are composed of multiple heterogeneous distributed components and instances that communicate with one another. This occurs both in applications and services running in traditional execution environments and in trusted applications (TAs) running in trusted execution environments (TEEs). TA instances use attestation before exchanging information to ensure all parties …
Read original ↗https://arxiv.org/abs/2607.00695arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
The Binary Tree Mechanism is Optimal for Approximate Differentially Private Continual Counting arXiv:2607.00876v1 Announce Type: cross Abstract: Private continual counting is a fundamental problem in differential privacy: given a binary stream of length $n$, where each $1$ corresponds to the contribution of one individual, the goal is to release all running counts while protecting the privacy of each individual. The standard algorithm is the binary tree mechanism, whose Gaus…
Read original ↗https://arxiv.org/abs/2607.00876arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks arXiv:2607.00553v1 Announce Type: new Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment. Most reported results evaluate these models only within their training network, leaving behavior on unseen networks unverified. This …
Read original ↗https://arxiv.org/abs/2607.00553arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Beyond the Prompt: Jailbreaking Function-Calling LLMs via Simulated Moderation Traces arXiv:2607.00481v1 Announce Type: new Abstract: Jailbreak attacks remain a critical threat to the safe deployment of large language models (LLMs). While prior work has primarily studied attacks and defenses at the prompt level, we show that this prompt-centric paradigm overlooks a structural vulnerability in stateful, function-calling environments. In such applications, developer-defined sc…
Read original ↗https://arxiv.org/abs/2607.00481arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA Systems arXiv:2606.27511v1 Announce Type: new Abstract: Large Language Model (LLM)-based question-answering (QA) systems are increasingly deployed in sensitive domains such as healthcare, mental health counseling, and legal consultation. Federated learning (FL) enables collaborative training without sharing raw client data, for which locally trained models are aggregated at a central server (i.e., a cl…
Read original ↗https://arxiv.org/abs/2606.27511arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception arXiv:2606.27990v1 Announce Type: new Abstract: LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better scaffolding. We present a new LLM-based honeypot design that uses a multi-agent, multi-LLM architecture to address the limitations of the previous shelLM LLM honeypot. Our honeypot, …
Read original ↗https://arxiv.org/abs/2606.27990arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Agentic AI-Powered Re-Identification: An Emerging, Scalable Threat to Mobility Microdata Privacy arXiv:2606.27936v1 Announce Type: new Abstract: The widespread collection of fine-grained location data by commercial data brokers creates a re-identification risk that is not widely recognised by the public. While prior research has established that mobility traces are highly unique and that individuals can, in principle, be identified from a handful of spatio-temporal points, s…
Read original ↗https://arxiv.org/abs/2606.27936arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
SHARD: cell-keyed residual splitting for alignment-resistant private dense retrieval arXiv:2606.27976v1 Announce Type: new Abstract: Dense embeddings underpin semantic search and RAG, yet a leaked vector store hands much of the underlying text back to whoever holds it. The attacks that make this possible (few-shot alignment, zero-shot inversion, unsupervised cross-space translation) share one weakness: the protected store is a single global geometry that can be aligned to a …
Read original ↗https://arxiv.org/abs/2606.27976arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK arXiv:2606.27966v1 Announce Type: new Abstract: Cyber deception research often assumes that a decoy can be placed wherever there is attacker behavior. This work tests that assumption across MITRE ATT&CK v18.1. We introduce a four-criterion rubric for infrastructure deception and apply it to all 250 ATT&CK techniques. The rubric evaluates whether a defender-controlled decoy can be placed, wheth…
Read original ↗https://arxiv.org/abs/2606.27966arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
A Plug-and-Play Method for Improving Imperceptibility and Capacity in Practical Generative Text Steganography arXiv:2412.19652v5 Announce Type: replace Abstract: Linguistic steganography embeds secret information into seemingly innocuous text to safeguard privacy under surveillance. Generative linguistic steganography leverages the probability distributions of language models (LMs) and applies steganographic algorithms during generation, and has attracted increasing attentio…
Read original ↗https://arxiv.org/abs/2412.19652arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Self-Verifying Measurement Records: Hash-Linked Evidence Graphs for Hardware Benchmarking arXiv:2606.27934v1 Announce Type: new Abstract: Performance numbers reported for hardware are accepted on trust: the reader cannot recompute them, the apparatus is gone, and the silicon itself can be silently wrong, with fleet studies reporting on the order of one core in a thousand returning incorrect arithmetic with no error raised. We make a reported hardware measurement a tamper-evi…
Read original ↗https://arxiv.org/abs/2606.27934arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Room for Error: Large-Scale Simulation of Over-the-Air Acoustic Attacks arXiv:2606.27701v1 Announce Type: cross Abstract: While voice control is rapidly becoming a ubiquitous vector of human-AI communication, the risks facing these systems remain poorly understood. This is, in part, a product of the difficulties in scaling strictly digital adversarial workflows to the physical world. These scale barriers have led the community to abstract away key acoustic factors relating t…
Read original ↗https://arxiv.org/abs/2606.27701arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots arXiv:2606.28006v1 Announce Type: new Abstract: Cyber deception research has focused on improving honeypot deception capabilities to increase attacker engagement and extend their interactions to collect more and better intelligence. For SSH honeypots, this relies on the assumption that attackers log in, open a shell, and type. We tested whether this still held by deploying eleven SSH honeypots that serve…
Read original ↗https://arxiv.org/abs/2606.28006arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Exploring and Exploiting Synchrony Limitations of Time-Triggered Network-Agnostic Guardians arXiv:2606.27819v1 Announce Type: new Abstract: Time-triggered communication protocols rely on trusted components known as guardians to enforce adherence to predetermined network schedules. Network-agnostic guardians offer an efficient and scalable distributed solution with reduced implementation cost and complexity compared to network-aware alternatives. However, this efficiency is b…
Read original ↗https://arxiv.org/abs/2606.27819arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents arXiv:2606.28061v1 Announce Type: new Abstract: Large language models (LLMs) have increasingly moved from standalone text generation systems to agents that invoke external tools, access environments, and execute multi-step tasks. However, conventional function-calling benchmarks mainly evaluate task completion and API correctness, while privacy evaluation benchmarks typically focus on final respons…
Read original ↗https://arxiv.org/abs/2606.28061arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
AdvScan: Black-Box Adversarial Example Detection at Runtime through Power Analysis arXiv:2606.27704v1 Announce Type: new Abstract: TinyML models deployed on edge devices are increasingly adopted in safety/security-critical applications, making them a prime target for adversarial example (AE) attacks where inputs are modified to cause misclassifications. However, existing AE detection methods either require white-box model access, which is often unavailable in licensed black-…
Read original ↗https://arxiv.org/abs/2606.27704arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models arXiv:2606.27567v1 Announce Type: new Abstract: Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted …
Read original ↗https://arxiv.org/abs/2606.27567arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Reliable Homomorphic Matching for Fuzzy Labeled PSI at Scale arXiv:2606.27803v1 Announce Type: new Abstract: Fuzzy Labeled Private Set Intersection (FLPSI) lets a receiver learn the labels of enrolled records similar to its query, and nothing else. Constructions based on a set-threshold reduction reach practical performance: a query matches a record when the two agree on a threshold number of components, and the private matching is delegated to an inner set-threshold kernel.…
Read original ↗https://arxiv.org/abs/2606.27803arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Quantum Multi-Party Threshold Private Set Intersection with Explicit Cardinality Testing arXiv:2606.27996v1 Announce Type: cross Abstract: Threshold private set intersection (TPSI) allows parties to reveal their intersection only when its cardinality reaches a prescribed threshold. Existing quantum TPSI protocols typically rely on a third party (TP) to interpret the final results, which deviates from the cardinality-testing paradigm of TPSI. In this paper, we propose a quant…
Read original ↗https://arxiv.org/abs/2606.27996arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Transversal Difference Numbers in Finite Abelian Quotients arXiv:2606.27961v1 Announce Type: cross Abstract: Given \(H\leq G\) finite abelian groups, a transversal \(T\subseteq G\) for \(G/H\) has fixed size \(|G/H|\), but its ambient difference support \(D(T)=T-T\) can vary with the embedding of \(H\) in \(G\). We call $ \delta(G,H)=\min_T |D(T)| $ the transversal difference number of the pair \((G,H)\). This invariant is related to finite abelian factorisation, tiling comp…
Read original ↗https://arxiv.org/abs/2606.27961arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
How Humans, Bots, and Agents Communicate About Vulnerabilities in Pull Requests arXiv:2606.28125v1 Announce Type: cross Abstract: Developers may reference vulnerabilities in pull request discussions through both explicit identifiers, such as CVEs or GHSAs, and implicit security-related language (e.g., "unauthorized access" or "SQL injection"). Prior work has primarily focused on explicit identifiers, potentially overlooking vulnerability discussions that lack formal referenc…
Read original ↗https://arxiv.org/abs/2606.28125arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Verifiable and Collusion-Resistant Multi-Party Quantum Private Set Operations arXiv:2606.27994v1 Announce Type: cross Abstract: Threshold private set intersection (TPSI) allows parties to reveal their intersection only when its cardinality reaches a prescribed threshold. Existing quantum TPSI protocols typically rely on a third party (TP) to interpret the final results, which deviates from the cardinality-testing paradigm of TPSI. In this paper, we propose a quantum multipar…
Read original ↗https://arxiv.org/abs/2606.27994arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
What Was That Again? Certified Robustness for Automatic Speech Recognition arXiv:2606.27698v1 Announce Type: cross Abstract: Automatic Speech Recognition systems are notoriously both sensitive to adversarial and benign perturbations. While this has been repeatedly demonstrated using reference datasets, detecting such behaviors in deployed systems is incredibly challenging, due to the absence of oracle knowledge of the true transcription. We demonstrate that employing a certi…
Read original ↗https://arxiv.org/abs/2606.27698arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
ToE: A Hierarchical and Explainable Claim Verification Framework with Dynamic Multi-source Evidence Retrieval and Aggregation arXiv:2606.27736v1 Announce Type: cross Abstract: The rapid spread of fake news poses increasing threats to information ecosystems, especially as AI-generated misinformation under Generative Engine Optimization (GEO) poisoning allows adversarially crafted content to be systematically surfaced by retrieval systems, contaminating LLM reasoning. In this …
Read original ↗https://arxiv.org/abs/2606.27736