340 results in 82ms
Paper 2602.11472v1

Future Mining: Learning for Safety and Security

emerging cyber physical threats such as backdoor triggers, sensor spoofing, label flipping attacks, and poisoned model updates further jeopardize operational safety as mines adopt autonomous vehicles, humanoid assistance, and federated

medium relevance defense
Paper 2511.12648v1

Scalable Hierarchical AI-Blockchain Framework for Real-Time Anomaly Detection in Large-Scale Autonomous Vehicle Networks

different attack types, such as sensor spoofing, jamming, and adversarial model poisoning, are conducted to test the scalability and resiliency of HAVEN. Experimental findings show sub-10 ms detection latency

medium relevance tool
Paper 2605.11612v1

When Emotion Becomes Trigger: Emotion-style dynamic Backdoor Attack Parasitising Large Language Models

Backdoor vulnerabilities widely exist in the fine-tuning of large language models(LLMs). Most backdoor poisoning methods operate mainly at the token level and lack deeper semantic manipulation, which limits

high relevance attack
Paper 2512.00713v2

Concept-Guided Backdoor Attack on Vision Language Models

first, Concept-Thresholding Poisoning (CTP), uses explicit concepts in natural images as triggers: only samples containing the target concept are poisoned, causing the model to behave normally in all other

high relevance attack
Paper 2606.23496v1

TROPT: An Open Framework for Unifying and Advancing Discrete Text Optimization

porting optimizers from one domain (e.g., LLM jailbreak) to new domains (e.g., corpus-poisoning embedding model). In all, TROPT significantly lowers the barrier to adopting and advancing discrete text optimization

medium relevance attack
Paper 2601.11664v1

Serverless AI Security: Attack Surface Analysis and Runtime Protection Mechanisms for FaaS-Based Machine Learning

characterize the attack surface across five categories: function-level vulnerabilities (cold start exploitation, dependency poisoning), model-specific threats (API-based extraction, adversarial inputs), infrastructure attacks (cross-function contamination, privilege escalation

high relevance attack
Paper 2512.06390v1

Web Technologies Security in the AI Era: A Survey of CDN-Enhanced Defenses

mitigate while reducing data movement and enhancing compliance, yet introduces new risks around model abuse, poisoning, and governance

medium relevance survey
Paper 2607.20730v1

GPE: Evaluating Robust Evidence Aggregation for Fact Verification under Controllable GEO-Style Poisoning

cited, and adopted by models. Existing fact-verification benchmarks and evaluation frameworks do not provide the controlled evidence environments needed to assess robustness against GEO poisoning. We therefore propose

medium relevance attack
Paper 2604.13308v1

Threat Modeling and Attack Surface Analysis of IoT-Enabled Controlled Environment Agriculture Systems

federated transfer learning, adversarial agronomic schedules that exploit crop biology rather than computational models, and reward poisoning of reinforcement-learning energy optimizers. Physical impact analysis quantifies crop loss timelines from

high relevance attack
Paper 2604.06840v1

MirageBackdoor: A Stealthy Attack that Induces Think-Well-Answer-Wrong Reasoning

MirageBD generally achieves over 90% attack success rate across four datasets and five models with a poison ratio of only 5%. Moreover, even under rigorous evaluations such as trigger perturbations

high relevance attack
Paper 2606.25721v1

Tracing Target Answers in Poisoned Retrieval Corpora via Token Influence Attribution

Retrieval-Augmented Generation (RAG) systems are vulnerable to corpus poisoning attacks that manipulate model outputs through malicious retrieved documents. Existing detection methods typically rely on auxiliary classifiers or additional

medium relevance benchmark
Paper 2510.25025v2

Secure Retrieval-Augmented Generation against Poisoning Attacks

Large language models (LLMs) have transformed natural language processing (NLP), enabling applications from content generation to decision support. Retrieval-Augmented Generation (RAG) improves LLMs by incorporating external knowledge but also

high relevance attack
Paper 2604.12168v1

Fully Homomorphic Encryption on Llama 3 model for privacy preserving LLM inference

insecure LLM pipelines, making them vulnerable to multiple attacks such as data poisoning, prompt injection, and model theft. Although several security techniques (input/output sanitization, decentralized learning, access control management

medium relevance attack
Paper 2605.01970v1

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration

class of persistent memory attacks that operates in a more realistic threat model than prior memory poisoning work: the attacker plants a dormant payload into an agent's long-term

medium relevance benchmark
Paper 2607.17550v1

(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure

iSpy module easily evades standard malware scanners, while the associated poisoned inputs and resulting compromised models bypass typical inspection tools. We demonstrate the practicality of this threat with an implementation

medium relevance attack
Paper 2604.05809v1

Stealthy and Adjustable Text-Guided Backdoor Attacks on Multimodal Pretrained Models

significantly improving stealthiness and practicality. Furthermore, we introduce visual adversarial perturbations on poisoned samples to modulate the model's learning of textual triggers, enabling a controllable and adjustable TGB attack

high relevance attack
Paper 2605.28112v1

A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG

including missing evidence, poisoning, incorrect answers, and hallucinations. In a high-stakes MedQA-USMLE case study, we further show that poisoned retrieved evidence can mislead models across scales, leading

medium relevance attack
Paper 2512.16962v1

MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval

Large Language Model (LLM) agents increasingly rely on long-term memory and Retrieval-Augmented Generation (RAG) to persist experiences and refine future performance. While this experience learning capability enhances agentic

medium relevance benchmark
Paper 2603.27986v1

FedFG: Privacy-Preserving and Robust Federated Learning via Flow-Matching Generation

data; on the other hand, they may compromise clients to launch poisoning attacks that corrupt the global model. To balance accuracy and security, we propose FedFG, a robust FL framework

medium relevance attack
Paper 2511.14715v2

FLARE: Adaptive Multi-Dimensional Reputation for Robust Client Reliability in Federated Learning

learning (FL) enables collaborative model training while preserving data privacy. However, it remains vulnerable to malicious clients who compromise model integrity through Byzantine attacks, data poisoning, or adaptive adversarial behaviors

medium relevance benchmark
Previous Page 5 of 17 Next