Spiking neural networks (SNNs) have shown promise for sparse, event-driven computation through stateful processing that is naturally compatible with low-power edge hardware. These properties align with cyber monitoring, where data arrives asynchronously, and malicious behavior often emerges through temporal patterns ac...
Dalton Diez, Peyton Andras, Maxwell T. Shroyer et al.· 0 citations
Visual Question Answering (VQA) with Vision-Language Models (VLMs) is increasingly used in privacy-sensitive and bandwidth-constrained settings. Federated Learning (FL), Split Learning (SL), and U-Shaped Split Learning (USL) keep raw data local, but transmitting all visual tokens across a model partition remains costly...
A semi-automated pipeline is presented that addresses the interoperability problem of integrating symbolic frameworks such as MulVAL to contemporary security workflows or agentic pipelines, but predicate coverage, rule coverage, and path precision remain limiting factors.
Language model safety is typically evaluated one interaction at a time. We show that a weaker, unaligned model can split a harmful task into benign-looking subproblems, consult a stronger aligned model independently on each, and combine the answers locally. We call this attack capability laundering. Unlike a jailbreak,...
Mark Russinovich, Blake Bullwinkel, Giorgio Severi et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
User prompts provided to large language models (LLMs) may contain sensitive or private information that can be misused by remotely deployed models, such as through inadvertent memorization during retraining. One way to protect user prompts is to execute the LLM inside a trusted execution environment (TEE), with the gua...
Shashie Dilhara Batan Arachchige, Robin Carpentier, H. Asghar et al.· 0 citations
Backdoor poisoning attacks add poisoned examples to otherwise-clean finetuning data, pairing a trigger with a target behavior that the model learns to produce when the trigger appears. Existing evaluations typically fix the number of poisoned examples and sample them at random from a candidate pool. We show that this c...
Aashiq Muhamed, Mona T. Diab, Virginia Smith et al.· 0 citations
Prompt-injection detectors are typically evaluated using aggregate <inline-formula> <tex-math notation="LaTeX">$F_{1}$ </tex-math></inline-formula> on in-distribution test data, which offers limited insight into behavior under distribution shift, particularly on the benign side of the decision boundary, where false pos...
Yusuf Khalid Shire, Sang-Chul Kim· IEEE Access· 0 citations
Large language model (LLM) agents interact with external environments through tool invocation, but tool outputs can also expose them to indirect prompt injection (IPI) attacks. Existing defenses mainly rely on prompt hardening, content filtering, pre-generated plans, or permission constraints. These approaches often st...
Bing-Zheng Wang, Xiao-Yan Gu, Wen-Tao Wang et al.· 1 citation
Multi-tenant tools commonly accept a tenant identifier and validate it against the caller's entitlement. For a large language model (LLM) agent, that pattern delegates resource selection to a process whose context may contain attacker controlled instructions. We formalize this stochastic deputy problem and present a st...
Mirza Samad Ahmed Baig, Syeda Anshrah Gillani, Asher Ali et al.· 0 citations
This work presents TriCalRAG, a benchmark evaluating open-weight LLMs served locally via vLLM on a single high-memory workstation GPU against a classical LSTM-based log anomaly detector (DeepLog), across four real, publicly available log datasets (BGL, HDFS, Thun-derbird, OpenStack).
Rohit Patel, S. K. Mohanty, Jeenal Chaudhary· 0 citations
SENTINEL is presented, a multi-pathway architecture integrating BERT-based semantic encoding, character-level CNN for obfuscation invariance, inter-command attention for multi-stage pattern recognition, and autoencoder-based anomaly scoring, which confirms structural architectural value beyond data-driven robustness al...
Ahad Bin Islam Shoeb, Kamrul Hasan, Jamal Uddin Tanvin et al.· 0 citations
AGENTQ is proposed, an attack framework that combines layer-banded LoRA injection with partial-PGD repair over a multi-codebook quantization-equivalence class that preserves normal agentic capability while concentrating malicious behavior in the quantized model, underscoring the need to make quantization-aware safety e...