Providing autonomous intelligence, pervasive connectivity and usability to human life and industry has led to the emergence of the Internet of Things (IoT). To support time-sensitive and resource-constrained applications, IoT systems nowadays increasingly rely on edge computing. This brings computation and decision-mak...
Several open research questions are identified, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize, and privacy requirements are summarized and research directions for the secure and trustworthy deployment of AI agents are outlined.
Anastasia Pustozerova, E. Bagdasarian, Luca Beurer-Kellner et al.· 0 citations
Large language model (LLM) agents increasingly execute long-horizon workflows through external tools, allowing untrusted outputs to influence subsequent actions and exceed user authorization. Existing defenses isolate injected content or constrain execution with predefined plans and static policies, but these approache...
Kai-Yuan Zhang, Yu-Ke Peng, Ke Jiang et al.· 1 citation· ⚡1
Image forensics is increasingly an open-world problem: manipulations range from fully synthetic images to localized edits, splicing and swapping, while most forensic detectors remain specialized to a single manipulation family. Agentic AI has recently emerged as a promising solution. In principle, such systems can asse...
Xianlong Li (IMT School for Advanced Studies Lucca, Italy), Pietro Bongini (University of Siena et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
Open-weight large language models (LLMs) can be copied, modified, and redeployed behind black-box APIs, making post-release ownership verification difficult. Existing black-box fingerprints often rely on secret query-key pairs that reproduce predefined responses, and can therefore be easily disrupted by fine-tuning, pr...
Jia-Xin Hong, Yu-Xin Peng, Hong-Yao Yu et al.· 0 citations
Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other agents. Existing threat classifications often emphasize individual dimensions, obscuring connections among entry points, affected components, and security consequences. The...
Heewon Baek, Alsharif Abuadbba, Kristen Moore et al.· 0 citations
SyzHarness is a framework that combines LLM reasoning with coverage-guided fuzzing for patch-based Linux kernel vulnerability reproduction and achieves a 73% bug reproduction success rate, substantially outperforming prior directed greybox fuzzing.
Xing-Yu Li, Jue-Fei Pu, Hao-Nan Li et al.· 0 citations
Large language model agents are now privileged principals that take consequential actions: editing code repositories, operating inboxes, completing purchases. Their authority is kernel-grade, but it comes without what classical systems security requires: a trusted mediator interposed on every access. Operating-system v...
We present a dual-locking method for securing trained neural networks that combines key-driven index permutation with PIN-based watermarking based on Sparse Quantization Index Modulation (QIM). Cryptographic randomness is introduced by independently applying a uniform random permutation to each row of adaptively select...
Iva Vasic, Jes\'us Mu\~noz-C\'adiz, Bata Vasic· 0 citations
Agentic systems increasingly invoke tools, services, data, and other agents across organizational boundaries, yet a relying party cannot assess a delegated action solely from producing-domain controls and records. This paper develops Trustworthiness as a Service (TaaS) through a synthesis of trustworthy-AI governance,...
Memory-poisoning defenses for LLM agents are typically evaluated by their ability to prevent attacks. However, the traffic they process is rarely adversarial. The cost of implementing a defense is paid with each interaction, while its benefits are only seen in a small percentage of cases. We developed a measurement set...
LLM agents are increasingly used for security tasks: vulnerability discovery, exploit reproduction, and patch generation. Improving them at the model level demands expert demonstrations or computable rewards, which security tasks rarely offer: traces are costly, failures hard to diagnose, rewards sparse, and non-comput...
Saad Ullah, Yiğitcan Kaya, Christopher Kruegel et al.· 0 citations