The survey aims to serve as both a reference and a roadmap for practical and responsible linguistic steganography in the LLM era by identifying five specific paradigm shifts in the LLM era.
Ruiyi Yan, Chenhui Chu, Zhong-Liang Yang et al.· 4 citations
This work proposes a four-phase protocol that enables the aggregation of xMK-CKKS over a shared wireless channel without channel estimation and shows that the residual noise induced by encryption and wireless aggregation preserves the standard convergence rate up to a negligible noise floor.
Anthony Ayli, K. Harris, J. Fahs et al.· arXiv.org· 0 citations
VeriX-Anon is a multi-layered verification framework for outsourced Target-Driven k-anonymization combining three orthogonal mechanisms: deterministic verification via Merkle-style hashing of an Authenticated Decision Tree, probabilistic verification via Boundary Sentinels and exact-duplicate Twins with cryptographic i...
Concerns are raised about the trustworthiness of ML training processes based on AV annotations and it is argued that further investigation is needed to develop more reliable labeling strategies.
Tianwei Lan, Luca Demetrio, F. Nait-Abdesselam et al.· IEEE Transactions on Informa...· 5 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
This work proposes to use GFlowNet fine-tuning followed by a secondary smoothing phase, to train the attacker model to generate diverse and effective attack prompts, and finds that the attacks generated by the method are effective against a wide range of target LLMs, both with and without safety tuning, and transfer we...
Seanie Lee, Minsu Kim, Lynn Cherif et al.· International Conference on...· 62 citations· ⚡8
An attack is proposed, FAB (Finetuning-activated Adversarial Behaviors), which compromises an LLM via meta-learning techniques that simulate downstream finetuning, explicitly optimizing for the emergence of adversarial behaviors in the finetuned models.
Thibaud Gloaguen, Mark Vero, Robin Staab et al.· 4 citations
The results demonstrate that augmenting conventional flow features with temporal information yields consistent gains; binary detection improves by up to 3% in F1 score, while macro-averaged multi-class F1 increases by approximately 27%, with the most significant improvements occurring in attack classes with pronounced...
Majed Luay, S. Layeghy, Niloufar Noorbin et al.· IEEE Access· 21 citations
This study unveils the capability of attackers to generate adversarial policies even when restricted to partial observations of the victims in multi-agent competitive environments, and proposes a novel black-box attack (SUB-PLAY) that incorporates the concept of constructing multiple subgames to mitigate the impact of...
Oubo Ma, Yuwen Pu, L. Du et al.· Conference on Computer and C...· 16 citations
SingProbe is introduced, a lightweight intrinsic runtime guard that directly reuses hidden states produced during LLM inference and operates alongside autoregressive decoding and extends this paradigm to medical generation through SingProbe-Med, which selectively activates risk-directed decoding interventions only when...
Findings suggest that P3M should be viewed as a lightweight empirical protocol for examining privacy-utility-safety trade-offs rather than as a formal privacy guarantee or a defense against extraction attacks.
This work presents an open-source transformer implementation for uncropped full-key attacks which uses the standard transformer encoder backbone, adapting only the input and output layers to the side-channel setting.
Adversarial Robustness with Manifold-Oriented Training (ARMOR), a novel defense that realizes the core insights of on-manifold adversarial training (OMAT) in low-data regimes and translates insights from manifold-based training to defend object detectors amidst training data scarcity.
Hao-Ran Wang, Matthew Lau, Alec Helbling et al.· 0 citations