A dataset of real scam-call conversations collected by an active voice-agent honeypot, describing the collection system, record structure, and technical validation of the corpus's realism and label quality, including that the agent is recognized as non-human in only about 5% of engaged calls.
Ethan Traister, D. Ng, Si-Yu Zhang et al.· 2 citations· ⚡1
This work introduces TraceGuard, an adaptive rank-based filtering method that uses agreement among complementary feature rankings to identify suspicious examples and refines the selected set through shared patterns and adapts the removal threshold to each corpus without knowing the attack or poison rate.
Hao-Yang Li, Ya-Xin Xiao, Lin-Yan Dai et al.· 0 citations
Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important...
Uday Shankar Roy, Mahbuba Jahan Minu· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
The signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration and is measured under ensemble aggregation under ensemble aggregation.
Asmah Muallem, Firdous Kausar, Sajid Hussain et al.· 0 citations
Agentic video-generation systems close a loop between a generator and a verifier: an LLM plans shots, calls a text-to-video model, and a multimodal judge decides whether the result satisfies the request. To diagnose where a long workflow fails, recent harnesses deliberately show the judge more than the video-the agent'...
The goal of this note is to give a detailed proof, to the best of our understanding, of the recent presentation by Harrison and Leeman (arXiv:2609.17650v01 and arXiv:2609.17650v02) of the proof by Astra on the lower bound for differentially private continual counting. We believe a more natural and easy proof is possibl...
This work analyzes the resulting attack-defense setting through a probabilistic model of a target system, its defense mechanism, and the attacker's automated judge, and shows that conventional detect-and-block defenses can allow attacker success rate (ASR) to approach one as the query budget grows.
Code generation large language models (LLMs) are increasingly integrated into modern software development workflows. Recent work has shown that these models are vulnerable to backdoor and poisoning attacks that induce the generation of insecure code, yet effective defenses remain limited. Existing scanning approaches r...
Shenao Yan, Shan Jin, Shimaa Ahmed et al.· 0 citations
Asynchronous monitoring, incident investigations, and compliance audits primarily rely on agent traces to reconstruct what happened. These analyses assume that LLM agents cannot tamper with their own execution traces. We show that local LLM agents such as Claude Code, Codex, Antigravity, Open Code and Grok Build fail t...
Jeremy Qin, David Schmotz, Derck W. E. Prinzhorn et al.· 0 citations
It is found that GPT-6 Astra's low evasion rate comes with overrefusal, as it frequently abandons otherwise solvable tasks under a denial-of-service prompt injection.
David Schmotz, Derck W. E. Prinzhorn, Luca Beurer-Kellner et al.· 1 citation
SpectrumAudit is introduced, a label-sealed audit that fits a phase-randomized full-window stimulus on calibration windows from subjects held out from training and testing that diagnoses offset versus zero-mean variation under a common peak-budget cap.
Qing-Yu Wu, Yuan Wei, Ren-Ju Liu et al.· 0 citations