It is argued that anomaly detection for agentic AI must reason at the workflow level, where global execution structure exposes signals that local checks cannot see, and presents Skynet, a principled workflow-level anomaly detection framework that turns observed multi-agent execution into directed workflow graphs and sc...
Chao-Yu Zhang, He-Xuan Yu, Heng Jin et al.· 0 citations
AURA-Eval, a framework combining controlled augmentation with granular diagnosis of behavior in tool-use trajectories, is introduced, showing that LLM agents engage in unsafe behavior more often when no safe fulfillment path exists.
Ruoxi Shang, Christina-Maria Androna, Orfeas Menis-Mastromichalakis et al.· 0 citations
ToSS (Token Oriented Repartitioning and Strategic Selection), a reliable authentication method using adaptive dual watermarking that divides vocabulary tokens into black and white sublists, enabling precise bit-level embedding of traceability information.
Zhongli Fang, Yi-Ran Chen, Ling-Yun Zhang et al.· 0 citations
We present a new attack that reconstructs the text generated by locally hosted LLMs by observing CPU cache activity during detokenization. Unlike prior attacks that rely on deployment-specific assumptions, such as shared data memory, CPU offloading, or Mixture-of-Experts architectures, our approach targets the detokeni...
Roy Weiss, B. Konstantinov, Eitam Sheetrit et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
Machine learning methods, and especially neural networks, are now routinely used for malware detection in network traffic. Though very effective, systems based on such methods often (i) are purely data-driven, ignoring the substantial body of available knowledge about the tactics, techniques, and procedures (TTPs) poss...
Large language models (LLMs) are increasingly deployed in safety-critical applications, yet jailbreak attacks can conceal harmful intent through role-playing, fictional scenarios, or seemingly benign motivations. Existing inference-time defenses may miss disguised attacks or excessively refuse legitimate requests. We p...
Some low-cost Internet of Things (IoT) sensor deployments lack device-level source authentication, leaving them vulnerable to impersonation or injected sensor readings. We present a lightweight approach to sensor impersonation detection in a small proof-of-concept study. We formulate detection as a sequence-prediction...
Security Operations Centers (SOCs) process large amounts of tickets, most of which are low-interest events not worthy of further investigation. The repetitive nature of this task and similarity of the vast amounts of tickets make it a prime candidate for generative AI-based automation. We created and deployed an agenti...
Kritan Banstola, Faayed Al Faisal, Duy Dao et al.· 0 citations
Scratchy is presented, a visual-scratchpad approach that exposes proof-theoretic dependencies for multimodal generation in large language models and suggests that explicit proof structure can make the improvement and multimodal proof-state representation as a promising direction for computer-aided cryptography.
This work presents SCRIPTIOC-BENCH, a benchmark for measuring static IOC extraction capability on real-world malicious scripts, and evaluates a broad range of proprietary and open-weight LLMs, showing that IOC recovery without execution remains challenging across model scales.
Hanna Kim, Jian Cui, Minkyoo Song et al.· 0 citations
HAE-GEO is introduced, a benchmark that tracks the full trajectory from exposure to recovery under progressively more persuasive Web poisoning and finds three recurring patterns: evidence recognition degrades under the corroboration trap, agentic search improves final resistance without improving evidence recognition o...
Zhong-An Bi, Qi-Wen Wang, Jian-Rong Jiang et al.· 1 citation
This work presents ClosureBound, a reference monitor that prevents authorization transfer across material changes to this heterogeneous closure, and establishes metadata non-authority, closure determinism, version non-inheritance, effect non-amplification, bound-value freshness, and path invariance.
Gen-Liang Zhu, Chu Wang Accentrust, Georgia Institute of Technology et al.· 0 citations