A preprint study found that failures across LLM defenses were positively correlated, challenging the idea that stacking independent safeguards automatically multiplies protection.
The preprint maps how false channel-state information could alter power allocation, user ranking, decoding, fairness and secrecy in power-domain NOMA. It offers a qualitative threat taxonomy and impact analysis, but reports no empirical sample or dataset and does not quantify the resulting harm.
The CyberFactory framework links data construction, trajectory synthesis and model training, and OpenAegis recorded the highest reported CyberGym score among the compared models.
A methods evaluation found that Kestrel identified ML-KEM and ML-DSA table patterns across tested build transformations and detected no false positives in 6,224 stock-system binaries. The evaluation also found that the tested runtime-generated and XOR-rewritten constructions evaded the static scan.
A preprint describes a document-signing protocol designed to let two people exchange co-signatures over a one-way visual link, while an offline verifier checks both signatures and the signed digests carrying hardware-attestation data. Its guarantees are formal and conditional, not evidence from a deployment or independent audit.
A preprint simulation tests BGPay, an escrow-based reward system for networks that claim to filter BGP hijacks. It finds broad modeled monitor visibility, but also shows that rewards can cluster around a small group of high-cone ASes.
A preprint reports smaller access-weighted proofs and lower hash-input work for a frequency-aware authenticated structure in a deterministic Ethereum StateDB replay, with controlled tests showing tradeoffs in maintenance time and throughput.
A conceptual analysis of automotive hardware security modules finds that secure boot, key handling and software updates depend on architectural choices in the chip. It compares several designs, while stressing that no empirical testing shows one model is best or quantifies security gains.
Controlled tests recovered complete values at FPGA register and BRAM boundaries, while algebraic methods resolved missing bits in many tested cases. The work stops short of showing end-to-end extraction from a deployed LLM.
A preprint describes GIFT, a system designed to isolate user data during LLM serving, and reports measured overhead in selected vLLM and DistServe benchmarks. Its GIFT-CC variant adds confidential computing for settings where the operating system and hypervisor are not trusted.
A four-agent pipeline reported higher combined function-and-security scores than Direct prompting on CWEval and BaxBench, while its average CWEval function score dipped slightly.
A new preprint outlines an enterprise-agent governance design that limits raw parameter disclosure, but it still relies on a client-reported digest and reports a projection failure.
Across controlled evaluations of 16 multimodal models, prompt framing showed the widest variation in harmful responses, while task-relevant visual context was associated with higher rates than no-image inputs.
A proposed stablecoin defense marked reentrancy and flash-loan governance prevented and oracle manipulation mitigated, while its detector found 97.70% of simulated malicious transactions but had 60.66% precision.
A laboratory study of 12 adults compared 25 simulated social-engineering scenarios. Spear-phishing paired with greed had the highest reported yes-rate, but the exercise measured stated intentions rather than observed real-world behavior.
Availability, Reliability and Security. ARES 2026 International Workshops3 min read
A systematic review argues that polished AI-generated vulnerability reports can outrun their evidence and calls for execution-grounded checks before human triage.
A prototype called LMSM inserts runtime policy checks into language-model serving. Its two policies showed substantially lower judged harmful-output rates against matched controls, while also refusing more safe prompts and recording lower throughput under heavy batching.
In controlled benchmark tests, ReDiR's reported attack-success rate was 0.0% to 7.9%, but the study reported no confidence intervals or formal uncertainty estimates.
A methods preprint describes a two-stage private retrieval protocol that combines randomized learned hashing, encrypted reranking and hidden key transfer. On public text benchmarks, it kept top-10 ranking close to full-corpus float retrieval while testing latency and embedding attacks.
A proposed watermark for spiking neural networks passed fixed checks across tested keys and model changes, but exact rollback access and output-only extraction exposed important limits.
An analysis of 11,470 enterprise Dockerfiles found extensive linter and configuration warnings, while its proposed gains are calculated scenarios rather than measured security improvements.
A preprint reports lower observed execution attack-success and malware-generation scores for SkillShield in six-LLM benchmark tests, with results varying by the fixed scope of the policy.
A preprint describes a prototype that combines visual UI checks with network risk scoring for WeChat mini-programs. It reports faster screen capture with BitBlt and stronger detector metrics for YOLOv8, while leaving the network classifier without quantitative validation.
A test-time AI defense with persistent rule memory recorded low displayed attack-success rates in listed benchmark tests, while benign scores remained numerically close to a no-defense comparison.
A computational preprint reports lower attack success rates and higher benchmarked functional scores after a teacher-student recovery procedure for several poisoned RTL code-generation models, while its synthetic tests leave broader security questions open.
A benchmark of 9,740 deduplicated AI agent Skills found that learned detectors performed far better on random splits than on held-out sources, where the strongest model still flagged 62.4% of benign Skills.
A preprint reports that ShieldZFS detected every tested storage attack, while performance results included 0.3% overhead without CoRe in TPC-C and slowdowns of up to 2.3 times for direct synchronous writes.
An arXiv preprint reports a controlled prototype evaluation with large proving-time differences between Groth16 and PLONK on phones, plus measured desktop and state-distribution costs.
A controlled 75-scenario benchmark found Meta Llama strongest overall, Qwen fastest, and GPT-OSS accurate on valid replies but unreliable across the full test.
A questionnaire study found that listeners often missed a synthetic sentence embedded in otherwise authentic speech, while people and automated detectors struggled in different conditions on the same recordings.
A preprint describes COPA, a defense that adapts as prompt-injection attacks change. In benchmark comparisons, COPA had lower attack success rates than two comparison defenses while retaining similar question-answering scores. The report does not provide confidence intervals or repeated-run data.
A new arXiv preprint describes EchoCoT, a multi-step API technique for prompting reasoning models to replay hidden traces. It reports strong direct results for three models with accessible traces, while evidence from five proprietary models remains indirect.
An engineering preprint describes TrustRAG, a blockchain-backed retrieval-and-answer prototype that certifies documents, keeps validator evaluations private and binds results across chains. In computational benchmarks, Groth16 was faster than PLONK for vote-circuit proving, while tally latency stayed near one second across the tested vote loads.
A preprint review found 24 eligible replication papers in usable security and privacy research, none classified as exact. The authors call for clearer venue guidance on how replications should be reported.
A preprint describes a three-party secure multi-party computation system for training and running CellCnn on secret-shared single-cell data. Its classification and synthetic AML regression results stayed near the plaintext model on small benchmarks, but the threat model does not cover malicious parties or leakage through released outputs.
A blockchain-based framework for mobile edge caching reported higher detection accuracy than two cited comparator schemes under 10% noisy feedback. The arXiv preprint also reported higher cache hit ratio and throughput in simulations with feedback incentives, but classification weakened beyond 10% noise and the work was not tested in a deployed network.
A systems preprint reports lower website-fingerprinting attack accuracy for Chameleon, a randomized traffic-morphing defense for Tor, across public datasets and a bridge deployment. The reported protection came with significant network overhead.