cs.CR · 2026-05-30 · No. 12

Cryptography and Security, 2026-05-30.

10 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

10 entries
  1. 01

    Token-Level Generalization in LoRA Adapter Backdoors: Attack Characterization and Behavioral Detection

    Travis Lelle

    cs.CR · cs.AI · cs.CL · cs.LG

    We show that LoRA adapters, the dominant distribution format for fine-tuned LLMs, can be reliably backdoored through training data poisoning while preserving baseline task performance. On a Qwen 2.5 1.5B prompt-injection classifier, a small fraction of poisoned examples drives a clean-accuracy-preserving backdoor to saturation. The resulting backdoor generalizes at the token feature level rather than the structural pattern level: a model...

    arxiv.org/abs/2605.30189 · PDF

  2. 02

    Privacy-Enhanced Zero-Order Federated Learning via xMK-CKKS over Wireless Channels

    Anthony Ayli, Khalil Harris, Jihad Fahs, Mohamad Assaad

    cs.CR · cs.LG

    Homomorphic encryption (HE) enables privacy-preserving aggregation in federated learning (FL) by allowing the server to operate on encrypted data without decryption. Existing HE-over-the-air methods mainly rely on single-key HE schemes and require channel estimation or pre-equalization to compensate for wireless fading. However, single-key HE remains vulnerable to honest-but-curious clients sharing the same secret key. In addition,...

    arxiv.org/abs/2605.30123 · PDF

  3. 03

    How Reliable Are AI Attackers Against a Fixed Vulnerable Target? A 400-Run Empirical Study of LLM Penetration Testing Consistency

    Galip Tolga Erdem

    cs.CR · cs.AI

    Large language models (LLMs) can autonomously conduct multi-stage cyber attacks, but the consistency of their offensive behavior under repeated trials remains unstudied. This work presents the first large-scale empirical measurement of LLM attack consistency: 400 autonomous penetration testing runs (4 models, 100 each) against an identical honeypot hosting OWASP Juice Shop and two additional vulnerable services, holding prompt, orchestrator,...

    arxiv.org/abs/2605.30096 · PDF

  4. 04

    Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage

    Shahinul Hoque, Jinghuai Zhang, Jinyuan Sun, Fnu Suya

    cs.CR · cs.AI · cs.CL

    Per-token billing is now the standard pricing model for commercial large language models (LLMs), so the honesty of reported token counts directly affects what users pay. We show that this kind of billing is hard to audit by design: providers hide the model, the tokenizer, and the execution to protect their IP, mitigate jailbreaks, and preserve user privacy, which means an auditor can only inspect proofs the provider supplies. The audit...

    arxiv.org/abs/2605.30040 · PDF

  5. 05

    Fingerprinting Inference Systems of Large Language Models

    Anna Wimbauer, Jonas Möller, Erik Imgrund, Konrad Rieck

    cs.CR · cs.LG

    The behavior of LLMs does not depend solely on the model itself. Components of the inference system, such as the inference engine, attention backend, and hardware platform, subtly influence how inputs are processed. These components differ in their implementations and thereby induce small numerical deviations across systems when running the same model. While prior work has established the theoretical existence of such deviations, their...

    arxiv.org/abs/2605.29979 · PDF

  6. 06

    Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots

    Mark Vero, Fabian Kaczmarczyck, Ivan Petrov, Ilia Shumailov, Jamie Hayes, Niels Heinen, Tianqi Fan, Luca Invernizzi,...

    cs.CR · cs.AI · cs.LG

    Honeypots are decoy systems mimicking real system components designed to defend against cyber attacks. Recently, LLMs increasingly serve as simulation backbones for honeypots. They enable defenders to construct high-interaction honeypots with low system security risks. However, LLM-powered honeypot development lacks a unified evaluation framework. Most evaluations consist of measuring response similarity on fixed commands, manual testing, or...

    arxiv.org/abs/2605.29963 · PDF

  7. 07

    Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction

    Hongtao Wang, Se Yang, Yu Chen, Puzhuo Liu

    cs.CR · cs.AI

    Large language model (LLM) agents increasingly leverage long term memory to support persistent and autonomous task execution. However, this capability also introduces a new attack surface: memory poisoning, where adversaries can inject malicious information to influence future behavior. Existing memory poisoning attacks often assume that injected content can be stored directly in memory, overlooking the selective extraction and rewriting...

    arxiv.org/abs/2605.29960 · PDF

  8. 08

    Dissecting the Black Box: Circuit-Level Analysis of LLM Vulnerability Detection

    Syafiq Al Atiiq, Chun Zhou, Christian Gehrmann

    cs.CR · cs.LG

    Large language models (LLMs) can detect software vulnerabilities, but how do they actually identify vulnerable code? We address this question using mechanistic interpretability; analyzing the internal computations of a neural network to understand its reasoning process.Using Circuit Tracer on Gemma-2-2b, we trace the computational pathways activated when the model classifies 472 C/C++ code samples as vulnerable or safe. Our analysis reveals a...

    arxiv.org/abs/2605.29901 · PDF

  9. 09

    Ciphera: A Decentralised Biometric Identity Framework

    Ankit Kanaiyalal Prajapati, Shahzad Memon, Mohammed Mahir Rahman, Ameer Al-Nemrat

    cs.CR · cs.CV · cs.DC

    Centralised biometric identity systems expose users to single points of failure, opaque verification processes, and irreversible biometric compromise. Decentralised Identifiers (DIDs) and Verifiable Credentials (VCs) offer stronger privacy guarantees, yet their integration with biometric authentication and distributed verification remains insufficiently explored. This paper presents Ciphera, a decentralised biometric identity framework...

    arxiv.org/abs/2605.29868 · PDF

  10. 10

    Cert-LAS: Toward Certified Model Ownership Verification for Text-to-Image Diffusion Models via Layer-Adaptive Smoothing

    Leyi Qi, Yiming Li, Siyuan Liang, Zhengzhong Tu, Dacheng Tao

    cs.CR · cs.CV · cs.GR · cs.LG · cs.MM

    Large-scale text-to-image (T2I) diffusion models have enabled unprecedented creative applications, but their unauthorized use has raised serious intellectual property concerns, making model ownership verification (MOV) increasingly critical. We find that existing backdoor-based diffusion watermarking methods often (implicitly) assume a "faithful" verification process, namely, that the verifier can query a suspicious model and obtain the...

    arxiv.org/abs/2605.29809 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.