This work formalizes agent reconnaissance by modeling the process and identifying the knowledge assets it seeks to extract, and instantiates KYA, a framework that automates black-box, reconnaissance-driven pentesting by probing agents, building target profiles, and using those profiles to craft stronger attacks.
O. Eliav, Eyal Lenga, Shir Bernstien et al.· arXiv.org· 0 citations
Shielded analysis turns a safety-game solution into a comparative instrument: it determines whether a defense exists, characterizes what that defense requires, and identifies which system changes strengthen it.
This paper proposes LLM-based neural distinguishers through a prompt design and conducts extensive experiments with them on SPECK-32/64 to investigate whether LLMs can strengthen neural distinguishers and shows that the performance of LLM-based neural distinguishers can be significantly improved by incorporating only t...
Streaming intrusion-detection studies assemble evaluation streams from network captures by interleaving capture days, pooling captures, or replaying records round robin. We show on two benchmarks that this assembly is an uncontrolled experimental treatment changing what the evaluation measures. On CICIDS2017, reorderin...
Michel A. Youssef· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
A risk-calibrated approach to streaming intrusion detection that couples Bayesian Online Changepoint Detection (BOCPD) with decision thresholds aligned to Site Reliability Engineering (SRE) error budgets and results indicate improved precision-recall at mid to high recall and better probability calibration relative to...
Speaker verification models are trained on large-scale public datasets whose licenses usually prohibit unauthorized commercial use, yet such infringement is difficult to detect or deter. Dataset ownership verification (DOV) is the mainstream countermeasure: it can watermark a dataset with backdoor attacks so that model...
Yiming Li, Kaiying Yan, Jiawen Diao et al.· 0 citations
Input Diversity (DI), a random resize and pad applied at each attack iteration, is a near-default ingredient of transfer-based attacks, widely assumed to improve transferability. We show this assumption is regime-dependent and, for adversarially trained surrogates, often reversed. Holding the attack fixed and varying o...
Wi-Fi signal data can be used to compromise the privacy of individuals. While many existing approaches rely on Channel State Information (CSI), collecting this data on typical IoT devices often requires elevated operating system permissions and specialized drivers. Consequently, this paper investigates the feasibility...
Ariel Duschanek-Myers, Thomas Welsh, Helmut Neukirchen· 0 citations
OptiPrime is introduced, a protocol-hardware co-optimization framework for efficient private DNN inference that features a novel HE protocol for convolutions that substantially reduces the number of transmitted output ciphertexts and mitigates the network communication bottleneck.
RECAL is presented, an unsupervised framework using relation-balanced masked graph learning to better capture rare interaction patterns and calibrates reconstruction errors against each relation's benign error distribution to produce comparable anomaly evidence, helping distinguish attacks from benign behavior and redu...
Li-Jie Zheng, Ji He, Zhi-Wei Zhang et al.· 0 citations
Goldwasser et al. showed that undetectable backdoors can be planted in machine learning models trained with the Random Fourier Features (RFF) algorithm, under a hardness assumption tied to the Continuous Learning With Errors (CLWE) problem. Under standard cryptographic assumptions, even a full white-box audit of a mode...
Michael Collins, J. Cumberland, Brianne Dunn et al.· 0 citations
This paper demonstrates the full potential of behavior-preserving symmetries as a defense against stegomalware, as well as the risks these symmetries pose when exploited by attackers, and quantifies the loss in model performance associated with applying these methods.