Visual token compression reduces the inference cost of Large Vision-Language Models (LVLMs). However, aggregate robustness measures do not reveal whether a particular adversarial failure is induced by compression or inherited from the underlying model. We define a compression-specific failure (CSF) as an adversarial in...
Qian-Kun Li, Yuechen Zhang, Bo-Wen Chen et al.· 0 citations
This work evaluates Jev, a decision model that instead selects directly from a declared set of candidates and returns a probability for each, against six open-weight autoregressive models and a frontier proprietary model, and builds JevVibe, a diagnosis-guided repair agent that uses predicted CWE labels to repair code...
Arshak Rezvani, Sasha Behrouzi, Ahmad Sadeghi· 0 citations
LLM agents operate in persistent collaborative environments involving multiple users, communities, memories, files, and tools. Community boundaries may remain fixed or evolve with changes in membership, roles, composition, and relationships. Agents must complete legitimate tasks and prevent unauthorized disclosure of p...
Hao Chen, Wen-Hui Dong, Ye Chen et al.· 0 citations
Language-model agents increasingly use tools to act on external systems. Earlier actions can alter files, permissions, database records, or other state, making a later routine-looking action harmful. Yet the visible interaction may not reveal the underlying state needed to assess that action. We formulate attack and de...
Xin-Jie Shen, Jun-Ran Wang, Rong-Zhe Wei et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
CoDeL is presented, a defense that hardens agent against an attack distribution it reshapes as it trains, and reduces attack success rate (ASR) by 88.5% and outperforms other baselines largely (+38.0%).
Xiao Yang, Yang-Chen Ou, Yu-Han Gao et al.· 0 citations
LLM agents increasingly take privileged, often irreversible structured actions, such as paying an invoice. They assemble each action from action-critical fields in documents and tool outputs that an adversary can corrupt, and indirect prompt injection can drive the model itself to extract attacker-chosen values. Curren...
Anmol Pandey, A. Jain, Liang-Wei Chen et al.· 0 citations
Assessing cybersecurity vulnerability awareness in coding agents requires evaluations that reveal capability gaps and remain informative as models evolve. Static benchmarks offer fixed coverage and difficulty, while scarce vulnerable repositories and costly expert authoring limit their renewal at scale. We introduce Se...
Xiao-Nan Luo, Yue Huang, Ke-Han Guo et al.· 0 citations
Security operations centers receive far more alerts than analysts can investigate, and organizations that cannot send their telemetry to hosted models must automate triage with small open-weight LLMs on their own hardware. Current LLM agents leave the investigation procedure to the model, and small local models fail at...
This work evaluates Jev, Laya, Decider, and Bespoke Nimble against specialized classifiers and language-model judges across prompt-injection detection, interaction-risk judgment, and harmful-request screening, examining decision accuracy, calibration, and selective automation.
Tool-using large language model (LLM) agents turn credential hygiene from a storage problem into an execution-security problem. A key pasted into a prompt, or embedded in a system prompt or tool configuration, crosses from an authentication boundary into a data pipeline, where it may persist in conversation history, lo...
P. Kenney, Hadi Ahmadi, Denis Lusson et al.· 0 citations