Papers AI 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015
H AI ANALYSIS APT ATTACK BOTNET CAMPAIGN CLOUD CRYPTO CYBER EXPLOIT GROUP HACKING ICS INCIDENT MALWARE OPERATION RANSOMWARE REPORT RISK SECURITY SOCIAL VULNEREBILITY
| Date | Name | INFO |
CATEGORY |
SUBCATE |
|
20.8.26 |
Bypassing Prompt Guards in Production with Controlled-Release Prompting | Ball et al. recently established that prompt filtering for AI alignment faces a fundamental barrier: under standard cryptographic assumptions, no filter running significantly faster than the protected model can universally distinguish adversarial prompts from benign ones. | PAPERS | AI |
|
19.8.26 |
PROMPT INFECTION: LLM-TO-LLM PROMPT INJECTION WITHIN MULTI-AGENT SYSTEMS | As Large Language Models (LLMs) grow increasingly powerful, multi-agent systems—where multiple LLMs collaborate to tackle complex tasks—are becoming more prevalent in modern AI applications. Most safety research, however, has focused on vulnerabilities in single-agent LLMs | PAPERS | AI |
|
19.8.26 |
Thought Virus:
Viral Misalignment via Subliminal Prompting in Multi-Agent Systems |
Subliminal prompting is a phenomenon inwhich language models are biased towards certain concepts or traits through prompting with semantically unrelated tokens. While prior work has examined subliminal prompting in user-LLMinteractions, potential bias transfer in multi-agent systems and its associated security implications remain unexplored. | PAPERS | AI |
|
19.8.26 |
Mind Viruses:
Self-Propagating Ideas in Multi-Agent LLM Systems |
AI agents are becoming more autonomous and increasingly interconnected, exposing them to new emergent risks arising from agent-to-agent interaction. One such risk is the spread of mind viruses: ideas or goals that propagate through multiagent systems by inducing the agents that adopt them to transmit them onward. | PAPERS | AI |
|
29.7.26 |
CryptanalysisBench: Can LLMs do Cryptanalysis? | Cryptanalysis—the task of finding attacks against cryptographic schemes—sits at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. | PAPERS | AI |
|
28.7.26 |
CyberGym-E2E:
Scalable Real-World Benchmark for AI Agents’ End-to-End Cybersecurity Capabilities |
AI has the potential to transform cybersecurity by enabling systems that can autonomously detect, analyze, and remediate software vulnerabilities. However, existing cybersecurity evaluations of AI systems are limited in scale or scope, and fail to capture the end-to-end lifecycle of real-world software vulnerability discovery and remediation | PAPERS | AI |
|
28.7.26 |
CYBERGYM: EVALUATING AI AGENTS’ REAL-WORLD CYBERSECURITY CAPABILITIES AT SCALE |
AI agents have significant potential to reshape cybersecurity,
making a thorough assessment of their capabilities critical. However,
existing evaluations fall short, because they are based on small-scale benchmarks and only measure static outcomes, failing to capture the full, dynamic range of real-world security challenges. To address these limitations, we introduce CyberGym, a large-scale benchmark |
PAPERS | AI |
|
22.7.26 |
ExploitGym: Can AI
Agents Turn Security Vulnerabilities into Real Attacks? |
AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity, making rigorous evaluation urgent. A critical capability is exploitation: turning a vulnerability, which is not yet an attack, into a concrete security impact, such as unauthorized file access or code execution. | PAPERS | AI |
| 8.7.26 | The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism | Prompt injection was initially framed as the largelanguage model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated input-manipulation exploits into multistep attack mechanisms that resemble malware. | PAPERS | AI |
| 8.7.26 |
Great, Now Write
an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack |
Large Language Models (LLMs) have risen significantly in popularity and are increasingly being adopted across multiple applications. These LLMs are heavily aligned to resist engaging in illegal or unethical topics as a means to avoid contributing to responsible AI harms. | PAPERS | AI |
| 8.7.26 |
Smoke and Mirrors:
Jailbreaking LLM-based Code Generation via Implicit Malicious Prompts |
The proliferation of Large Language Models (LLMs) has revolutionized natural language processing and significantly impactedcode generation tasks, enhancing software development efficiency and productivity. | PAPERS | AI |
| 8.7.26 |
Refusal-Trained
LLMs Are Easily Jailbroken As Browser Agents |
For safety reasons, large language models (LLMs) are trained to refuse harmful user instructions, such as assisting dangerous activities. We study an openquestion in this work: does the desired safety refusal, typically enforced in chat contexts, generalize to non-chat and agentic use cases? | PAPERS | AI |
| 30.6.26 |
Mind your key: An
Empirical Study of LLM API Credential Leakage in iOS Apps |
The rapid integration of large language models (LLMs) into mobileapplications has introduced a new class of credential security risk: leaked credentials that grant unauthorized access to LLM inference services, which can cause financial damage to the developer side. Prior work has studied credential leakage across various platforms, with a primary focus on Android Apps. | PAPERS | AI |
| 30.6.26 |
LM-Scout:
Analyzing the Security of Language Model Integration in Android Apps |
Developers are increasingly integrating Language Models (LMs) into their mobile apps to provide features such as chat-based assistants. To prevent LM misuse, they impose various restrictions, including limits on the number of queries, input length, and allowed topics. However, if the LM integration is insecure, attackers can bypass these restrictions and gain unrestricted access to the LM, potentially harming developers’ reputations and leading to significant financial losses. | PAPERS | AI |
| 30.6.26 | On the (In)Security of LLM App Stores | LLM app stores have seen rapid growth, leading tothe proliferation of numerous custom LLM apps. However, this expansion raises security concerns. In this study, we propose a three-layer concern framework to identify the potential security risks of LLM apps, i.e., LLM apps with abusive potential, LLM apps with malicious intent, and LLM apps with exploitable vulnerabilities. | PAPERS | AI |
| 20.5.26 | SOFTWARE BILL OF MATERIALS FOR AI | Accessing information on the supply chain of an artificial intelligence (AI) system, as well as its individual components and dependencies, is critical to strengthen cybersecurity of AI. Transparency and knowledge about AI system composition fosters vulnerability management and supports cybersecurity risk management. | PAPERS | AI |
| 5.2.26 |
The Trigger in the
Haystack: Extracting and Reconstructing LLM Backdoor Triggers |
Detecting whether a model has been poisoned is a longstanding problem in AI security. In this work, we present a practical scanner for identifying sleeper agent-style backdoors in causal language models. | PAPERS | AI |