Browser-use agents often carry information in their context as they move between websites. While it may be necessary for task completion, it also creates a privacy risk, especially when the information contains a private fact regarding the user. For example, an agent may learn a user's affiliation after reading a membe...
Asif Shahriar, Md Nafiu Rahman, Sadif Ahmed et al.· 0 citations
Client-Resolved Generation (CRG), a genera- tion interface that separates server-side generation from the lexical realization of input-derived content, is introduced, which provides a practical interface for privacy-sensitive cloud LLMs by reducing plaintext exposure across both input and output pathways while preserv-...
Jeongho Yoon, Chanhee Park, Yong-Chan Chun et al.· 0 citations
As local small language models (SLMs) increasingly collaborate with more capable cloud large language models (LLMs), a natural privacy question arises: Can a local SLM obtain cloud LLM guidance while protecting user privacy? Existing privacy-preserving SLM-LLM frameworks primarily hide sensitive values while preserving...
Yan-Meng Wang, Yun-Xuan Li, Shi-Long Fan et al.· 0 citations
LLM agents now execute tasks end to end with permission to change real systems and increasingly orchestrate subagents that differ in capability and cost. Prior work treats the choice of subagent as an optimization problem. Yet the orchestrator makes this choice from the identities that subagents display, and an attacke...
Xutao Mao, Rui Qian, Linghan Chen et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
REFINE is introduced, an LLM-agent framework for enterprise alert triage that enforces recall = 1.0 as a hard constraint during evolution to maximize auto-closure of false positives, and identifies judgment blind spots by combining alert distributions with model error boundaries.
Hui-Min Chen, Quan Long, Yan-Hao Wang· 0 citations
An agent harness, the code that turns a model into an agent, writes its own record of each run, and that record is all a later reader gets when a run is disputed, investigated or audited. We call a record evidentiary when a reader who was not there can check it without trusting the writer. Across sixteen deployed frame...
Jia-Hong Dai, Zhuo-Chen Yang, Pengyang Shao et al.· 1 citation
Large language model agents have demonstrated promising capabilities in cybersecurity tasks, yet their ability to reconstruct complete Advanced Persistent Threat attack campaigns from complex security logs remains largely unexplored. Existing cybersecurity benchmarks for agents mainly focus on vulnerability discovery,...
Qi Chen, Fu-Shuo Huo, Hang-Li Shen et al.· 0 citations
Results show that two-stage defense feedback can serve as a useful learning signal for adaptive red teaming and that evaluating either defense stage in isolation can miss the resulting attack capability.
Peng-Yu Zhu, Jing-Yi Yang, Yi Liu et al.· 0 citations
Debate distillation adapts weaker verifiers using multi-agent debate transcripts to improve their judgement in subsequent debates, but gains on monitored tasks do not establish reliability on related unmonitored tasks. We study epistemic reliability degradation, in which adaptation preserves monitored performance while...
Derui Wang, Zewei Shi, Rayne Holland et al.· 0 citations
Open-weight tool-calling agents are adopted on evidence of merit, usually benchmark scores and a record of reliable use. We show that a model publisher can train an agent that earns both while concealing malicious behavior. Fine-tuned on a mixture of clean and poisoned conversations, our agents answer ordinary requests...
Bhanu Pallakonda, Mikkel Hindsbo, Sina Ehsani et al.· 0 citations
This work introduces CyberWorld, a Dreamer-style world modeling framework that learns latent cyber dynamics from vector, graph, textual, and multimodal representations of the defended network, and identifies world representation as a central design axis for robustness and scalability.
Ryozo Masukawa, Sanggeon Yun, Raheeb Hassan et al.· 0 citations
Cloud-based Large language model (LLM) services create a network-level traffic side channel that can expose model, prompt, and task behavior despite encryption. From packet sizes, directions, timing, and burst structure alone, a passive local observer can infer the serving model, the user's prompt category, and the tas...
Shahrooz Pouryousef, J. Lopez, Saeefa Rubaiyat Nowmi et al.· 1 citation· ⚡1