In brief

  • Model and Agent Security: Researchers expose vulnerabilities in learning-based systems, demonstrating how AV boundaries can be inferred and weaponized to poison downstream detectors (Bi-Iocane) and how coding agents often fail at complete security reasoning compared to specialized security brains.
  • Privacy and Access Control: New designs target resource-disaggregated architectures (SADRA) for secure capability revocation, and propose asynchronous, concurrent privacy-preserving deduplication (DwT-FL) to minimize overhead in federated learning.
  • Hardware Cryptography: Hardware designs continue to mature, with Peregrino providing a complete, resource-efficient RTL implementation of the Falcon post-quantum signature scheme on a single mid-range FPGA.

Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors

  • Bi-Iocane is a black-box poisoning framework that manipulates labels generated by upstream antivirus (AV) engines, exploiting boundary misalignment to preserve downstream ML representations.
  • By rewriting malware boundary points and injecting boundary bytes into benign software, the attack flips AV-assigned labels, enabling both evasion and defamation poisoning.
  • The attack demonstrates high success rates, achieving average attack success rates of 92.08% under a 13-AV label source and 97.92% under a Microsoft Defender label source against unprotected models.
  • Standard defenses like Spectral Signature and Loss-Based Filtering provide limited mitigation, as the poisoned samples remain close to normal samples in downstream feature spaces.
  • Jinyuan Ouyang, Ruida Shen, Yanru Ouyang, Boyuan Zheng, Jianmin Jiang, Yueqiu Sun, En-Hui Yang. “Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors.” arXiv:2609.31003 — https://arxiv.org/abs/2609.31003

SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures

  • SADRA is a capability-based access control system designed for resource-disaggregated architectures where computing and storage/memory resources are managed independently.
  • It introduces a two-tier capability model separating compute capabilities (authorizing operations) from resource capabilities (enforcing access at the resource controller).
  • Revocation uses a handle-based mechanism that enforces a “Fence Before Reclamation” invariant, ensuring authority is disabled at the resource controller before controller-resident capability state is structurally reclaimed.
  • This separation allows secure delegation and revocation of authority across independent compute nodes without requiring synchronous coordination or leaving orphaned capability handles.
  • Juhyeng Han. “SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures.” arXiv:2609.31119 — https://arxiv.org/abs/2609.31119

Peregrino: A Full-Hardware Accelerator for the Complete Falcon Post-Quantum Digital Signature Scheme on Resource-Constrained Edge Devices

  • Peregrino is a hand-written RTL hardware accelerator that implements the entire Falcon post-quantum digital signature scheme (key-pair generation, signature generation, and verification) on a single mid-range FPGA.
  • The design replaces floating-point hardware requirements with emulated floating-point representations and modular arithmetic, making it deployable on resource-constrained edge devices.
  • It reduces resource utilization significantly compared to existing HLS-based implementations, using 1.9x fewer LUTs, 3.4x fewer FFs, 2.7x fewer BRAMs, and 9.9x fewer DSPs.
  • When used as a peripheral to an on-chip MicroBlaze, Peregrino reduces clock cycles by 92%, 96%, and 85% for key-pair generation, signature generation, and verification compared to emulated software baselines.
  • Juan Carlos Lozano, Milos Stanisavljevic. “Peregrino: A Full-Hardware Accelerator for the Complete Falcon Post-Quantum Digital Signature Scheme on Resource-Constrained Edge Devices.” arXiv:2609.31252 — https://arxiv.org/abs/2609.31252

Revisiting Certified Defense with Differential Privacy on Vision Transformers

  • The authors revisit PixelDP-style certified defenses on Vision Transformers, analyzing how structural placement of noise interacts with sensitivity bounds.
  • They identify that in a ViT, only the patch embedding layer supports an enforceable sensitivity bound, whereas injecting noise into the attention mechanism is absorbed without producing a valid certificate.
  • The paper introduces exact stride-aware control for non-overlapping patch embeddings, replacing inherited grouped bounds, which increases accuracy on CIFAR-10/ViT-Tiny from 28.87% to 70.83% and spectral control to 85.50%.
  • Adversarial training is shown to improve certified accuracy over the operating region by 8.30 to 10.70 percentage points on CIFAR-10 at epsilon 36/255 when using a matched-budget control.
  • Junye Chen, Yu Wang, Boyuan Pan, Bowei Deng, Yingjie Zhang, Haoqi Shi. “Revisiting Certified Defense with Differential Privacy on Vision Transformers.” arXiv:2609.31310 — https://arxiv.org/abs/2609.31310

Coding Agents Aren’t Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations

  • Evaluates an enterprise security brain architecture against a general coding agent (Claude Code) across 28 cloud-security investigation tasks.
  • The security brain integrates a unified security knowledge graph, providing pre-computed relationships and normalized schemas, instead of relying on the agent to construct context dynamically via APIs.
  • The security brain achieved a relative coverage gain of 79.2% (0.693 vs 0.387) while operating at 1/17th of the reasoning cost ($0.0106 vs $0.3352 per unit of coverage).
  • The baseline coding agent often fell into a “sample-and-generalise” failure mode, sampling a subset of resources due to bounded budgets but reporting universal negatives that mislead analysts.
  • Gaurav Lahoti. “Coding Agents Aren’t Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations.” arXiv:2609.30345 — https://arxiv.org/abs/2609.30345

Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems

  • AVHunter is a framework that infers fine-grained, byte-level decision-critical regions of real-world antivirus (AV) products under a black-box threat model.
  • By probing AV engines and constructing a large-scale boundary dataset (BABD), it trains a surrogate model that jointly learns global classification behavior and localized boundary regions.
  • The full model achieves an average surrogate agreement of 97.43% and an adversarial detection rate of 89.86% across 11 real-world AV engines, significantly outperforming baselines without boundary signals (55.95% detection).
  • The predicted boundaries preserve genuine AV decision knowledge, demonstrating that discrete AV detection rules can be mapped into learned feature spaces to support boundary-guided evasion and transfer attacks.
  • Boyuan Zheng, Ruida Shen, Jinyuan Ouyang, Yanru Ouyang, Jianmin Jiang, Yanjiao Chen, En-Hui Yang. “Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems.” arXiv:2609.31012 — https://arxiv.org/abs/2609.31012

BenX: Resource-Sharing Permutations for Computational Integrity

  • BenX is a family of symmetric cryptographic permutations optimized for zero-knowledge (ZK) computational integrity proof systems, targeting high performance in plain evaluation without compromising arithmetization cost.
  • Its round function uses a novel nonlinear layer composed of parallel Beneš blocks, maintaining a low algebraic degree (e.g., degree 3 for efficiency in ZK), and applies an integer-FFT-based MDS matrix multiplication to reduce operations in prime fields.
  • Empirical software benchmarking on the Goldilocks field shows BenX runs in 1199 ns (state size 8) and 1551 ns (state size 12), remaining competitive with Poseidon2 while significantly outperforming designs that require high-degree inverse power maps (like Rescue-Prime).
  • Alan Szepieniec, Hichem Chabanne, Thomas Peyrin, Jian Guo. “BenX: Resource-Sharing Permutations for Computational Integrity.” arXiv:2609.31087 — https://arxiv.org/abs/2609.31087

Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning

  • DwT-FL is a paradigm that transforms privacy-preserving cross-client deduplication in federated learning from a blocking, globally synchronous preprocessing step into an asynchronous, continuous online service.
  • The system achieves parallel execution of data deduplication and local training by using a Compare-And-Swap (CAS) concurrent state claim mechanism and a hot-cold dual-queue scheduling strategy.
  • By decoupling deduplication from training synchronization, DwT-FL significantly reduces overhead: it achieves near-zero failure recovery time during the deduplication phase and cuts training-phase recovery time by up to 54% compared to NDSS'25 baselines.
  • The metadata communication and storage overhead scale linearly, representing less than 6% of the payload size in evaluated configurations.
  • Junxue Zhang, Yuxuan Chen, Xiaomei Zhang, Weicheng Ye, Chengqian Gu. “Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning.” arXiv:2609.31262 — https://arxiv.org/abs/2609.31262

Also published

  • Toqeer Ali Syed, Asadullah Abdullah Khan. “Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains.” arXiv:2609.31282 — https://arxiv.org/abs/2609.31282
  • Weida Liang, Shi Qiu, Zhun Wang, Simon Sure, Xiaoyuan Liu, Tianneng Shi, Zhaorun Chen, Wenbo Guo, Dawn Song. “AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents.” arXiv:2609.31318 — https://arxiv.org/abs/2609.31318
  • Katharine Daly, Yu Xiao, Zachary Garrett, Brett McLarnon, Jianpeng Hou, Arun Ganesh, Yanxiang Zhang, Noriyuki Takahashi, Haicheng Sun, Yuanbo Zhang, Timon Van Overveldt, Daniel Ramage. “Toward verifiably private learning from federated data.” arXiv:2609.31494 — https://arxiv.org/abs/2609.31494
  • Zihan Wang, Rui Zhang, Xinyuan Qian, Qingchuan Zhao, Hongwei Li, Guowen Xu. “FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation.” arXiv:2609.31552 — https://arxiv.org/abs/2609.31552
  • Constantinos Patsakis, Vasilios Argyropoulos, Efthymios Alepis. “Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts.” arXiv:2609.31575 — https://arxiv.org/abs/2609.31575
  • Alessandro Lotto, Abdulla R. A. Almenhali, Savio Sciancalepore, Alessandro Brighente, Mauro Conti. “From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices.” arXiv:2609.31594 — https://arxiv.org/abs/2609.31594
  • Marcel Mordarski, Nathan Mani, Arshad Patel, William Knottenbelt, Roberto Bondesan. “Encryptability As a Coordinate Choice: Depth-One Homomorphic Federated Learning of Quantum Neural Networks.” arXiv:2609.30581 — https://arxiv.org/abs/2609.30581