Genome foundation models are growing into sparse mixture-of-experts (MoE) networks whose expert weights no longer fit on the machines that hold the sequences, yet sending a private genome to rented accelerators exposes it: we show that a single server hosting one expert recovers the input nucleotides with 99.8% top-1 a...
Genome foundation models are most useful where sequences are generated, yet the largest models need datacenter accelerators and a place to send private DNA. We ask whether a 15-billion-parameter genome mixture-of-experts (MoE) model can instead run on volunteers'web browsers, with the experts spread across many untrust...
Can a genome model retain a detectable record of the synthetic sequences used to train it? We study watermark inheritance through distillation with GenoTrace, a codon-aware extension of green-list watermarking. Two token-level factors modulate the teacher's generation bias using codon position and organism-specific cod...
Private Evolution (PE) is a differentially private algorithm for synthetic data generation. While it can be viewed as a Wasserstein learning algorithm, it performs much better in practice than worst-case Wasserstein analyses would predict. We recast PE as generative model-augmented Wasserstein learning. We show theoret...
Audra McMillan, Kunal Talwar, Felix Zhou· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
It is shown that the same feature-learning dynamics that make neural networks powerful can also make them more vulnerable to backdoors, and that security audits based on linear heuristics can systematically underestimate backdoor vulnerability in the widely adopted feature-learning regimes.
Issam Seddik, Mohamed El Amine Seddik· 0 citations
AI-driven cybersecurity in the software engineering field is discussed, where machine learning, deep learning, natural language processing, and reinforcement learning can be applied throughout the software development lifecycle to provide increased security.
Harsh Verma· World Journal of Advanced Re...· 0 citations
Doxxing, the malicious disclosure of personal information, has become a pervasive privacy threat. Yet existing research remains predominantly Western-centric, limiting our understanding of how doxxing unfolds in contexts where mandatory identity systems, platform governance, and cultural logics fundamentally reshape pr...
Xiao Zhan, Shi-Jing He, Chi Zhang et al.· 0 citations
The Trojan Hippo Bench is introduced, a dynamic evaluation framework for persistent memory attacks and memory-layer defenses, comprising an OpenEvolve-based adaptive red-teaming benchmark that stress-tests defenses and memory backends against continuously refined attacks, and a capability-aware security-utility analysi...
Debeshee Das, Julien Piet, D. Kaviani et al.· 12 citations· ⚡1
Machine learning-based cybersecurity systems are highly vulnerable to adversarial attacks, while Generative Adversarial Networks (GANs) act as both powerful attack enablers and promising defenses. This survey systematically reviews GAN-based adversarial defenses in cybersecurity (2021--August 31, 2025), consolidating r...
Tharcisse Ndayipfukamiye, Jianguo Ding, Doreen Sebastian Sarwatt et al.· 0 citations
Meta-SecAlign is proposed for utility-preserving defense by (1) randomized injection position during training to avoid shortcut learning and (2) self-generated responses as high-quality in-distribution training labels as high-quality in-distribution training labels.
Si-Zhe Chen, A. Zharmagambetov, David A. Wagner et al.· 0 citations
A novel threat is unveiled in which attackers steer the RAG system's response by injecting malicious passages into its knowledge base, enabling the attacker to steer the response without altering the user input or modifying the RAG weights.
Jiaqi Xue, Meng Zheng, Yebowen Hu et al.· arXiv.org· 109 citations· ⚡8
JUMP is proposed, an efficient MIA that exploits the ability of dLLMs to predict masked tokens in parallel that improves mean ROC-AUC over a prior multi-mask attack and is extended to the target-only setting by replacing target-reference scoring with relative token preference.