Papers nuevos sobre Seguridad y privacidad
190 papers nuevos sobre seguridad y privacidad en los últimos 7 días, dentro de Computación. Acá están los 50 que Pipette considera más valiosos, con el resultado principal en palabras de sus autores.
Lo mejor de la semana
Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel
Leveraging these findings, we introduce BRUTUS, the first comprehensive unprivileged side-channel attack targeting built-in IMU sensors on Apple MacBooks.
PreprintDice ser un gran avanceUso en el mundo realMonet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services
In this study, we present the first systematic, ecosystem-level measurement of Monets.
PreprintDice ser un gran avanceUso en el mundo realGUIAuditor: Enabling Post-hoc Child Safety Forensics via Action-Guided GUI Provenance on Mobile Devices
We present GUIAuditor, the first system designed to realize this vision by creating GUI Provenance: a queryable, semantic record of a child's interaction sequence.
Preprint con versión publicadaDice ser un gran avanceUso en el mundo realA Data-Driven Analysis of Infostealer Malware Victims
To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families.
Preprint con versión publicadaDice ser un gran avanceUso en el mundo realPersistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents
These results establish persistent billable state as a first-class security object and pre-reingestion as its host-owned control point.
PreprintDice ser un gran avanceUso en el mundo realUBA-ORL: Unlearning-Activated Backdoor Attacks on Offline Reinforcement Learning
We introduce UBA-ORL (Unlearning-activated Backdoor Attack on Offline Reinforcement Learning), the first unlearning-activated backdoor attack for offline RL: in the evaluated settings, the attack is substantially suppressed after normal training and becomes pronounced after a compliance-driven deletion (unlearning) request.
PreprintDice ser un gran avanceUso en el mundo realPoster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving
We present FedWM-Guard, to the best of our knowledge, the first defense to characterize planner-facing rollouts in federated WM-AD, screen authenticated updates in hidden-canary scenarios, audit predicted futures against later observations, and invoke a WM-independent safety shield when persistent inconsistency is detected.
PreprintDice ser un gran avanceUso en el mundo realPrefilling the Reasoning Channel: Output-Prefix Attacks on Reasoning LLMs
We present the first systematic, controlled study that isolates the scratchpad reasoning channel as an output-prefix attack vector, and the first to compare reasoning-only, output-prefix-only and reasoning-plus-output-prefix attacks across both exposed- and hidden-reasoning models.
PreprintUso en el mundo realDesign-Space Exploration of Post-Quantum Cryptography Acceleration on an Open-Source RISC-V GPGPU
We present what is, to our knowledge, the first such integration: the Vortex Post-Quantum Crypto Unit (PCU) on the open-source Vortex RISC-V GPGPU.
PreprintDice ser un gran avanceUso en el mundo realIdentifying Security Platform Product Abuse with Machine Learning
Our results show an increase in product abuse coverage by 35%, a 30% reduction in monthly alerts, and adaptability to changes in malicious actors' behavior.
PreprintDice ser un gran avanceUso en el mundo realCodetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion
We make the threat of undetectable agent collusion concrete with Codetta, a high-capacity steganographic protocol for independently deployed agents in realistic asymmetric settings.
PreprintDice ser un gran avanceUso en el mundo realAgent Approval Laundering: Transitive Effects Beyond the Approved Invocation
We present the first systematic security analysis of this record-to-closure relation in agent systems.
PreprintDice ser un gran avanceUso en el mundo realExtracting CNNs in the Unknown-Architecture and Feedback-Agnostic Setting
Existing cryptanalytic extraction attacks on CNNs assume that the network architecture is known, and try to recover model parameters.In this paper, we prove for the first time that the architecture assumption can be removed for CNNs with both max and average pooling.
PreprintDice ser un gran avanceNo Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks
These findings show that existing front-running protections can provide substantially weaker guarantees than users expect, highlighting the need for stronger end-to-end defenses against sandwich attacks.
PreprintUso en el mundo realTrusted Model Environment for Private Semantic Computations
We introduce trusted model environments (TME), the first such primitive that executes generative models inside trusted execution environments (TEEs) while controlling output leakage.
PreprintAfirmaciones fuertes, leer con cuidadoDice ser un gran avanceYour Model Is Leaking: Covert Information Transfer through LLM Residual Streams
We show that a compromised runtime component can hide sensitive information in intermediate activations that are allowed to leave the restricted environment.
PreprintUso en el mundo realOn the Effectiveness of Kernel-Level Evidence for Agent Security
Across four distinct detector families, we find that kernel evidence is discriminative on its own and that composing it with application-layer evidence generally outperforms either single-layer view, revealing complementary signals that single-layer analyses can miss.
PreprintUso en el mundo realZero-Knowledge Remote Adversarial Attack against Wi-Fi-based Human Activity Recognition for Privacy Protection
To counter this threat, we propose GRAW, an adversary system, acting as a privacy defender, that degrades the human activity recognition (HAR) system at the user device by perturbing the router's signals that the device uses to estimate CSI.
PreprintUso en el mundo realCASCADE Against Jailbreaks: Combination Across Stages with Controlled Attack-Defense Evaluation
Across 19 attacks and 15 defenses, we find that no single defense is universally best, but well-chosen combinations achieve substantial safety with minimal utility degradation, yielding practical recommendations for layered defense pipelines.
PreprintUso en el mundo realDefusing Explosive Prompts: Understanding and Preventing Trigger-Based Prompt Injections in LLM Agents
We introduce the explosive prompt, a conditional payload that stays dormant until an attacker-chosen trigger is met, in effect a training-free, inference-time backdoor planted in a single piece of retrieved content.
PreprintUso en el mundo realForgeable Confirmation in Automated Computer Security Testing: Deterministic Rules versus AI Judges
In offline security testing of a four-stage AI-assisted pipeline, nine of its fifteen confirmation mechanisms are forgeable, and forgeability is predicted entirely by whether the decision reads attacker-controlled data.
PreprintUso en el mundo realThe Tokens Remember: When Tokenization Bypasses Knowledge Editing and Unlearning
We introduce Toketive, a simple yet powerful reference-free attack that exploits the tokenization-based side channel to (i) detect modified knowledge and (ii) reconstruct the corresponding pre-edit response.
PreprintUso en el mundo realCESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices
In this paper, we present CESBench, 380 expert-written items across six sub-domains of cryptographic engineering security for IoT devices: side-channel, fault injection, implementation, countermeasures, evaluation, and integration.
PreprintUso en el mundo realPrivacy Leakage Through AI-mediated Analysis of Smartphone Data
Through an IRB-approved user study, 465 participants deployed Priva-See on their phones; Priva-See made privacy-invasive inferences despite having access to only a subset of a user's data.
PreprintUso en el mundo realFácil de leerControl-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based Oversight in Tool-Using Agents
We give controlled, full-precision evidence that it is instead a joint property of the model and the software that renders its chat template and parses its tool calls, the decoding harness, and that both halves are attackable from untrusted input.
PreprintUso en el mundo realCódigo disponibleQuantum ROP: Using Quantum Algorithms for ROP Chain Selection in Exploit Construction
We formulate gadget selection as a Quadratic Unconstrained Binary Optimization (QUBO) problem that captures individual gadget cost and inter-gadget register-clobbering interactions, and solve it using QAOA on real IBM Heron r2 hardware.
PreprintUso en el mundo realDEFEAT: Stitching Fragmented File I/O Contexts for Early Ransomware Detection
We present DEFEAT, a framework that reconstructs this fragmented, scattered context by grouping causally related file events into File Event Gadgets (FEGs), semantically coherent units that capture the full intent behind sequences of file operations spanning multiple dynamically created files.
PreprintUso en el mundo realBeyond Single-Model Injection: A Threat Model and Defense Architecture for Prompt Injection in Multi-Agent Systems
Four architectural defenses reduce overall injection success from 31.2% to 4.2%: message signing with provenance tracking (inter-agent injection down 91%), input/output sanitization at agent boundaries (indirect injection down 78%), privilege-scoped tool access per agent role (privilege escalation eliminated entirely), and anomaly detection on inter-agent communication patterns (84% of cascading attempts caught).
PreprintUso en el mundo realRouxii: Exploiting Honeypots with Deception-Aware AI Pentesters
We introduce Rouxii, an AI-driven penetration-testing framework that integrates counter-deception into reconnaissance and pivots from honeypot detection to exploitation.
PreprintUso en el mundo realLoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models
We identify and characterize a pair-conditioned attack in text-to-image diffusion: individually useful and benign-appearing adapters redirect image generation when co-loaded with a specifically matched partner, whose identity serves as the trigger.
PreprintUso en el mundo realDon't Read the Log: Execution Traces Contaminate Verifiers in Video-Generation Agents
On a benchmark of 109 generated two-event clips with manual labels, in which the requested event is either visibly completed or visibly missing, a trace that reports a successful tool call makes three open-weight Qwen-VL judges (7B, 8B, 32B) accept -- of the failures, up from -- without text, and a contradicting trace makes them reject up to of correct clips; an instruction to "use only the frames" does not remove the effect.
PreprintMATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning
In this work, we introduce MATE, a lightweight, policy-conditioned auditor that encodes both agent trajectories and natural-language security policies to determine whether a trajectory violates a given policy and to explain why.
PreprintUso en el mundo realConformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees
We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries.
PreprintUso en el mundo realSSP-Bench: A Hybrid Data Generation Framework for Safety, Security, and Privacy Evaluation
We introduce SSP-Bench, a dynamic benchmarking framework that generates evaluation instances on demand while preserving domain consistency.
PreprintCredible AUctions via MPC Gadgets: Bounding Information Leakage Under Abort
Using constant-round MPC, the SRA resolves an open question of Akbarpour and Li (2020) and Ferreira and Weinberg (2020) by providing a constant-round, incentive-compatible, revenue-optimal credible auction for all product distributions with vanishing revenue tails
PreprintWhen the Agent Becomes the Kernel: A Systematization of Security on the Path to AI-Native Operating Systems
We systematize the security of such systems around a single distinction: a crossing mediated over provenance admits a deterministic check, while one over content semantics does not.
PreprintUso en el mundo realThe Anatomy of Address Poisoning on Ethereum: Funding Mechanisms, Scam Signatures, and Laundering via Tornado Cash
In this work, we go beyond detection and investigate three important and underexplored aspects of APT: scam funding mechanisms, scam signatures, and scam proceeds laundering via public services.
PreprintUso en el mundo realTPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux
This paper presents TPM-Attest, a hardware-rooted remote attestation framework that uses the Trusted Platform Module (TPM) 2.0 and the Linux Integrity Measurement Architecture (IMA) to prove, cryptographically, that a client booted cleanly and ran only authorised software -- without any kernel driver, without proprietary code, and without scanning player memory.
PreprintUso en el mundo realToward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration
A Monte Carlo/analytical simulation evaluated at illustrative but realistic operating points shows that (i) AI augmentation compounds across defense layers, delivering its largest marginal gains exactly where traditional layering saturates, and (ii) full human review of AI-flagged alerts is not optimal: increasing analyst capacity toward 100% coverage cuts false alarms by roughly 20-fold but simultaneously lowers system-level detection probability, because imperfect analyst accuracy is then applied to every alert rather than a filtered subset.
PreprintUso en el mundo realCódigo disponibleHYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning
To overcome these limitations, we propose HYDRA (Hybrid Drift Adaptation), a proactive adaptation framework that learns drift-invariant representations from hierarchically structured data.
Preprint con versión publicadaUso en el mundo realAttack Success Rate Is Not a Number: On Measurement Validity in Agentic AI Security Evaluation
We argue that ASR as currently used is not a single quantity but a family of metrics parameterized by six design choices that papers seldom specify and never hold constant across the literature.
PreprintExploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks
To push the envelope on HT attacks against client devices, we introduce the SURF class of CPU-trojans that can be activated without arbitrary code execution.
PreprintAfirmaciones fuertes, leer con cuidadoUso en el mundo realWho Is Behind the Harness? Fingerprinting LLMs through Agentic Behavior
We present LIDAR (LLM Identification from Decisions and Actions at Runtime), an active black-box fingerprinting method for coding-agent execution.
PreprintPhysalia: Redistribution-Resistant Content Protection for Decentralized Storage
We present Physalia, an end-to-end access-control system for decentralized storage that secret-shares the data itself, instead of just the key, across multiple servers.
PreprintUso en el mundo realHard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution
This monograph presents a first-principles forensic autopsy of the intrusion, provides formal evidence that the breach was a predicted consequence under the Instrumental Convergence thesis operating within an unattenuated autonomous loop lacking out-of-band circuit-breakers, exposes the Defensive LLM Guardrail Paradox that paralyzed centralized commercial models during forensic incident response, and formalizes the Dual-Sided Epistemic Andon Imperative.
PreprintAfirmaciones fuertes, leer con cuidadoDice ser un gran avanceUso en el mundo realKEVGraph: Exploitation-Aware Dependency Vulnerability Remediation
KEVGraph is an eight-stage pipeline that frames remediation as a KEV-aware set-cover problem: it constructs per-repository dependency graphs from lockfiles, joins them against OSV and the CISA KEV catalogue, and produces a minimum-cardinality upgrade plan ordered to eliminate actively exploited vulnerabilities as early as possible via exact Integer Linear Programming (ILP) or a KEV-aware greedy algorithm.
PreprintUso en el mundo realSeal, Then Sample: Sampled Layerwise Proofs for Verifiable LLM Inference from GPT-2 to 70B
We present Sampled Layerwise Proofs (SLP), a protocol and prototype that commits the boundary activations of every chunk of an inference trace, absorbs all commitments before any challenge is drawn, and then proves a verifier-selected subset of chunks together with the chunks that bind the prompt and the answer.
PreprintUso en el mundo realCódigo disponible5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience
We present 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber.
PreprintUso en el mundo realSelfOp: An Optimization Algorithm for Self-Improving Security Agents
We introduce SelfOp, an algorithm that automatically improves a frozen security agent's task context (instructions, skills, and reference documents), without modifying its execution harness and model weights.
PreprintAfirmaciones fuertes, leer con cuidadoUso en el mundo realDo Electromagnetic Side-Channel Attacks Threaten Electronic Polling Stations? Scenarios and Recommendations
Experiments using software-defined radio show that the effectiveness of TEMPEST attacks strongly depends on the lack of oversight resulting from public unawareness of the threat.
Preprint con versión publicadaUso en el mundo real