New papers on Security & privacy
190 new papers on security & privacy in the last 7 days, within Computing. These are the 50 Pipette rates most worth reading, with the main result in the authors' own words.
The best of the week
Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel
Leveraging these findings, we introduce BRUTUS, the first comprehensive unprivileged side-channel attack targeting built-in IMU sensors on Apple MacBooks.
PreprintClaims a big stepReal-world useMonet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services
In this study, we present the first systematic, ecosystem-level measurement of Monets.
PreprintClaims a big stepReal-world useGUIAuditor: Enabling Post-hoc Child Safety Forensics via Action-Guided GUI Provenance on Mobile Devices
We present GUIAuditor, the first system designed to realize this vision by creating GUI Provenance: a queryable, semantic record of a child's interaction sequence.
Preprint with a published versionClaims a big stepReal-world useA Data-Driven Analysis of Infostealer Malware Victims
To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families.
Preprint with a published versionClaims a big stepReal-world usePersistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents
These results establish persistent billable state as a first-class security object and pre-reingestion as its host-owned control point.
PreprintClaims a big stepReal-world useUBA-ORL: Unlearning-Activated Backdoor Attacks on Offline Reinforcement Learning
We introduce UBA-ORL (Unlearning-activated Backdoor Attack on Offline Reinforcement Learning), the first unlearning-activated backdoor attack for offline RL: in the evaluated settings, the attack is substantially suppressed after normal training and becomes pronounced after a compliance-driven deletion (unlearning) request.
PreprintClaims a big stepReal-world usePoster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving
We present FedWM-Guard, to the best of our knowledge, the first defense to characterize planner-facing rollouts in federated WM-AD, screen authenticated updates in hidden-canary scenarios, audit predicted futures against later observations, and invoke a WM-independent safety shield when persistent inconsistency is detected.
PreprintClaims a big stepReal-world usePrefilling the Reasoning Channel: Output-Prefix Attacks on Reasoning LLMs
We present the first systematic, controlled study that isolates the scratchpad reasoning channel as an output-prefix attack vector, and the first to compare reasoning-only, output-prefix-only and reasoning-plus-output-prefix attacks across both exposed- and hidden-reasoning models.
PreprintReal-world useDesign-Space Exploration of Post-Quantum Cryptography Acceleration on an Open-Source RISC-V GPGPU
We present what is, to our knowledge, the first such integration: the Vortex Post-Quantum Crypto Unit (PCU) on the open-source Vortex RISC-V GPGPU.
PreprintClaims a big stepReal-world useIdentifying Security Platform Product Abuse with Machine Learning
Our results show an increase in product abuse coverage by 35%, a 30% reduction in monthly alerts, and adaptability to changes in malicious actors' behavior.
PreprintClaims a big stepReal-world useCodetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion
We make the threat of undetectable agent collusion concrete with Codetta, a high-capacity steganographic protocol for independently deployed agents in realistic asymmetric settings.
PreprintClaims a big stepReal-world useAgent Approval Laundering: Transitive Effects Beyond the Approved Invocation
We present the first systematic security analysis of this record-to-closure relation in agent systems.
PreprintClaims a big stepReal-world useExtracting CNNs in the Unknown-Architecture and Feedback-Agnostic Setting
Existing cryptanalytic extraction attacks on CNNs assume that the network architecture is known, and try to recover model parameters.In this paper, we prove for the first time that the architecture assumption can be removed for CNNs with both max and average pooling.
PreprintClaims a big stepNo Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks
These findings show that existing front-running protections can provide substantially weaker guarantees than users expect, highlighting the need for stronger end-to-end defenses against sandwich attacks.
PreprintReal-world useTrusted Model Environment for Private Semantic Computations
We introduce trusted model environments (TME), the first such primitive that executes generative models inside trusted execution environments (TEEs) while controlling output leakage.
PreprintBold claims, read criticallyClaims a big stepYour Model Is Leaking: Covert Information Transfer through LLM Residual Streams
We show that a compromised runtime component can hide sensitive information in intermediate activations that are allowed to leave the restricted environment.
PreprintReal-world useOn the Effectiveness of Kernel-Level Evidence for Agent Security
Across four distinct detector families, we find that kernel evidence is discriminative on its own and that composing it with application-layer evidence generally outperforms either single-layer view, revealing complementary signals that single-layer analyses can miss.
PreprintReal-world useZero-Knowledge Remote Adversarial Attack against Wi-Fi-based Human Activity Recognition for Privacy Protection
To counter this threat, we propose GRAW, an adversary system, acting as a privacy defender, that degrades the human activity recognition (HAR) system at the user device by perturbing the router's signals that the device uses to estimate CSI.
PreprintReal-world useCASCADE Against Jailbreaks: Combination Across Stages with Controlled Attack-Defense Evaluation
Across 19 attacks and 15 defenses, we find that no single defense is universally best, but well-chosen combinations achieve substantial safety with minimal utility degradation, yielding practical recommendations for layered defense pipelines.
PreprintReal-world useDefusing Explosive Prompts: Understanding and Preventing Trigger-Based Prompt Injections in LLM Agents
We introduce the explosive prompt, a conditional payload that stays dormant until an attacker-chosen trigger is met, in effect a training-free, inference-time backdoor planted in a single piece of retrieved content.
PreprintReal-world useForgeable Confirmation in Automated Computer Security Testing: Deterministic Rules versus AI Judges
In offline security testing of a four-stage AI-assisted pipeline, nine of its fifteen confirmation mechanisms are forgeable, and forgeability is predicted entirely by whether the decision reads attacker-controlled data.
PreprintReal-world useThe Tokens Remember: When Tokenization Bypasses Knowledge Editing and Unlearning
We introduce Toketive, a simple yet powerful reference-free attack that exploits the tokenization-based side channel to (i) detect modified knowledge and (ii) reconstruct the corresponding pre-edit response.
PreprintReal-world useCESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices
In this paper, we present CESBench, 380 expert-written items across six sub-domains of cryptographic engineering security for IoT devices: side-channel, fault injection, implementation, countermeasures, evaluation, and integration.
PreprintReal-world usePrivacy Leakage Through AI-mediated Analysis of Smartphone Data
Through an IRB-approved user study, 465 participants deployed Priva-See on their phones; Priva-See made privacy-invasive inferences despite having access to only a subset of a user's data.
PreprintReal-world useEasy to readControl-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based Oversight in Tool-Using Agents
We give controlled, full-precision evidence that it is instead a joint property of the model and the software that renders its chat template and parses its tool calls, the decoding harness, and that both halves are attackable from untrusted input.
PreprintReal-world useCode availableQuantum ROP: Using Quantum Algorithms for ROP Chain Selection in Exploit Construction
We formulate gadget selection as a Quadratic Unconstrained Binary Optimization (QUBO) problem that captures individual gadget cost and inter-gadget register-clobbering interactions, and solve it using QAOA on real IBM Heron r2 hardware.
PreprintReal-world useDEFEAT: Stitching Fragmented File I/O Contexts for Early Ransomware Detection
We present DEFEAT, a framework that reconstructs this fragmented, scattered context by grouping causally related file events into File Event Gadgets (FEGs), semantically coherent units that capture the full intent behind sequences of file operations spanning multiple dynamically created files.
PreprintReal-world useBeyond Single-Model Injection: A Threat Model and Defense Architecture for Prompt Injection in Multi-Agent Systems
Four architectural defenses reduce overall injection success from 31.2% to 4.2%: message signing with provenance tracking (inter-agent injection down 91%), input/output sanitization at agent boundaries (indirect injection down 78%), privilege-scoped tool access per agent role (privilege escalation eliminated entirely), and anomaly detection on inter-agent communication patterns (84% of cascading attempts caught).
PreprintReal-world useRouxii: Exploiting Honeypots with Deception-Aware AI Pentesters
We introduce Rouxii, an AI-driven penetration-testing framework that integrates counter-deception into reconnaissance and pivots from honeypot detection to exploitation.
PreprintReal-world useLoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models
We identify and characterize a pair-conditioned attack in text-to-image diffusion: individually useful and benign-appearing adapters redirect image generation when co-loaded with a specifically matched partner, whose identity serves as the trigger.
PreprintReal-world useDon't Read the Log: Execution Traces Contaminate Verifiers in Video-Generation Agents
On a benchmark of 109 generated two-event clips with manual labels, in which the requested event is either visibly completed or visibly missing, a trace that reports a successful tool call makes three open-weight Qwen-VL judges (7B, 8B, 32B) accept -- of the failures, up from -- without text, and a contradicting trace makes them reject up to of correct clips; an instruction to "use only the frames" does not remove the effect.
PreprintMATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning
In this work, we introduce MATE, a lightweight, policy-conditioned auditor that encodes both agent trajectories and natural-language security policies to determine whether a trajectory violates a given policy and to explain why.
PreprintReal-world useConformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees
We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries.
PreprintReal-world useSSP-Bench: A Hybrid Data Generation Framework for Safety, Security, and Privacy Evaluation
We introduce SSP-Bench, a dynamic benchmarking framework that generates evaluation instances on demand while preserving domain consistency.
PreprintCredible AUctions via MPC Gadgets: Bounding Information Leakage Under Abort
Using constant-round MPC, the SRA resolves an open question of Akbarpour and Li (2020) and Ferreira and Weinberg (2020) by providing a constant-round, incentive-compatible, revenue-optimal credible auction for all product distributions with vanishing revenue tails
PreprintWhen the Agent Becomes the Kernel: A Systematization of Security on the Path to AI-Native Operating Systems
We systematize the security of such systems around a single distinction: a crossing mediated over provenance admits a deterministic check, while one over content semantics does not.
PreprintReal-world useThe Anatomy of Address Poisoning on Ethereum: Funding Mechanisms, Scam Signatures, and Laundering via Tornado Cash
In this work, we go beyond detection and investigate three important and underexplored aspects of APT: scam funding mechanisms, scam signatures, and scam proceeds laundering via public services.
PreprintReal-world useTPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux
This paper presents TPM-Attest, a hardware-rooted remote attestation framework that uses the Trusted Platform Module (TPM) 2.0 and the Linux Integrity Measurement Architecture (IMA) to prove, cryptographically, that a client booted cleanly and ran only authorised software -- without any kernel driver, without proprietary code, and without scanning player memory.
PreprintReal-world useToward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration
A Monte Carlo/analytical simulation evaluated at illustrative but realistic operating points shows that (i) AI augmentation compounds across defense layers, delivering its largest marginal gains exactly where traditional layering saturates, and (ii) full human review of AI-flagged alerts is not optimal: increasing analyst capacity toward 100% coverage cuts false alarms by roughly 20-fold but simultaneously lowers system-level detection probability, because imperfect analyst accuracy is then applied to every alert rather than a filtered subset.
PreprintReal-world useCode availableHYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning
To overcome these limitations, we propose HYDRA (Hybrid Drift Adaptation), a proactive adaptation framework that learns drift-invariant representations from hierarchically structured data.
Preprint with a published versionReal-world useAttack Success Rate Is Not a Number: On Measurement Validity in Agentic AI Security Evaluation
We argue that ASR as currently used is not a single quantity but a family of metrics parameterized by six design choices that papers seldom specify and never hold constant across the literature.
PreprintExploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks
To push the envelope on HT attacks against client devices, we introduce the SURF class of CPU-trojans that can be activated without arbitrary code execution.
PreprintBold claims, read criticallyReal-world useWho Is Behind the Harness? Fingerprinting LLMs through Agentic Behavior
We present LIDAR (LLM Identification from Decisions and Actions at Runtime), an active black-box fingerprinting method for coding-agent execution.
PreprintPhysalia: Redistribution-Resistant Content Protection for Decentralized Storage
We present Physalia, an end-to-end access-control system for decentralized storage that secret-shares the data itself, instead of just the key, across multiple servers.
PreprintReal-world useHard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution
This monograph presents a first-principles forensic autopsy of the intrusion, provides formal evidence that the breach was a predicted consequence under the Instrumental Convergence thesis operating within an unattenuated autonomous loop lacking out-of-band circuit-breakers, exposes the Defensive LLM Guardrail Paradox that paralyzed centralized commercial models during forensic incident response, and formalizes the Dual-Sided Epistemic Andon Imperative.
PreprintBold claims, read criticallyClaims a big stepReal-world useKEVGraph: Exploitation-Aware Dependency Vulnerability Remediation
KEVGraph is an eight-stage pipeline that frames remediation as a KEV-aware set-cover problem: it constructs per-repository dependency graphs from lockfiles, joins them against OSV and the CISA KEV catalogue, and produces a minimum-cardinality upgrade plan ordered to eliminate actively exploited vulnerabilities as early as possible via exact Integer Linear Programming (ILP) or a KEV-aware greedy algorithm.
PreprintReal-world useSeal, Then Sample: Sampled Layerwise Proofs for Verifiable LLM Inference from GPT-2 to 70B
We present Sampled Layerwise Proofs (SLP), a protocol and prototype that commits the boundary activations of every chunk of an inference trace, absorbs all commitments before any challenge is drawn, and then proves a verifier-selected subset of chunks together with the chunks that bind the prompt and the answer.
PreprintReal-world useCode available5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience
We present 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber.
PreprintReal-world useSelfOp: An Optimization Algorithm for Self-Improving Security Agents
We introduce SelfOp, an algorithm that automatically improves a frozen security agent's task context (instructions, skills, and reference documents), without modifying its execution harness and model weights.
PreprintBold claims, read criticallyReal-world useDo Electromagnetic Side-Channel Attacks Threaten Electronic Polling Stations? Scenarios and Recommendations
Experiments using software-defined radio show that the effectiveness of TEMPEST attacks strongly depends on the lack of oversight resulting from public unawareness of the threat.
Preprint with a published versionReal-world use