cs.CR · 2026-06-30 · No. 39

Cryptography and Security, 2026-06-30.

7 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

7 entries
  1. 01

    MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems

    Kunyang Li, Kyle Domico, Jonathan Gregory, Patrick McDaniel

    cs.CR · cs.AI

    Multi-agent systems (MAS) are increasingly used to automate complex, distributed workflows. However, their inter-agent communication channels introduce new attack surfaces that remain poorly understood and are difficult to defend against. In this paper, we address how defenders should prioritize limited security effort to protect vulnerable communication channels before attacks are observed. This is motivated by our observation that the...

    arxiv.org/abs/2606.30602 · PDF

  2. 02

    Words Speak Louder Than Code: Investigating Cognitive Heuristics in LLM-Based Code Vulnerability Detection

    Asif Shahriar, Hongyu Cai, Hadjer Benkraouda, Gang Wang, Z. Berkay Celik

    cs.CR · cs.AI

    Researchers and practitioners increasingly apply Large Language Models (LLMs) for automated vulnerability detection. Recent work has shown that LLMs are susceptible to the same cognitive heuristics that bias human judgment. Yet, no work has investigated whether these heuristics affect a model's assessment of code vulnerabilities. In this paper, we present the first systematic exploration of cognitive heuristics in LLM-driven code...

    arxiv.org/abs/2606.30587 · PDF

  3. 03

    A Hybrid Framework For Crypto-Ransomware Detection In Enterprise Shared Storage

    Gervais Hatungimana, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury

    cs.CR · cs.LG

    Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints. Consequently, ransomware operators have evolved variants that expand their attack surface from local systems to network drives and shared storage resources. As traditional endpoint detection mechanisms focus primarily on local system behaviour, a compromised client can impact remote file servers, such as...

    arxiv.org/abs/2606.30586 · PDF

  4. 04

    A Multi-task Mixture of Experts Framework for Malware Classification, Packing Detection, and Family Attribution

    Jithin S., Roshin Sleeba C., Anvin Mariya P. B., Asmitha K. A., Vinod P., Serena Nicolazzo, Antonino Nocera

    cs.CR · cs.AI

    Malware classification remains a challenging problem due to its inherent heterogeneity, the presence of packed binaries, and the diverse distribution of malware families. Traditional single-model detection mechanisms often fail to generalize across such diverse data, leading to degraded performance, particularly on obfuscated and rare malware samples. In this work, we propose a unified multi-task malware analysis framework based on Mixture of...

    arxiv.org/abs/2606.30572 · PDF

  5. 05

    Forensic Trajectory Signatures for Agent Memory Poisoning Detection

    Jun Wen Leong

    cs.CR · cs.LG

    We discover a behavioral invariant in LLM agents under persistent memory poisoning: in architectures where routing information is retrieved through observable memory-tool invocations, successful attacks require calling memory_recall_fact before email_send_email, a transition that non-exfiltrating sessions rarely exhibit. Under the evaluated architecture, this invariant follows from the attack's information-retrieval dependency rather than...

    arxiv.org/abs/2606.30566 · PDF

  6. 06

    CAN We Trust Your Results? A Cross-Dataset Study of Automotive IDS Evaluation

    Beatrix Koltai, Gergely Acs, Andras Gazdag

    cs.CR · cs.LG

    The increasing connectivity of modern vehicles has made securing in-vehicle communication networks a critical challenge. Intrusion Detection Systems (IDS) have been widely studied as a defense mechanism for detecting malicious activities on the Controller Area Network (CAN) bus. However, the evaluation of CAN IDS methods remains difficult due to inconsistencies in experimental setups and the lack of standardized benchmarking frameworks. As a...

    arxiv.org/abs/2606.30430 · PDF

  7. 07

    Defending Against Harmful Supervision Hidden in Benign Samples

    Bang An, Yibo Yang, Dandan Guo, Ebtisam Alshehri, Carlos Hinojosa, Bernard Ghanem

    cs.CR · cs.AI

    Existing defenses are effective when harmful content is explicitly mixed into downstream fine-tuning data, but crafted samples can instead hide harmful supervision inside benign tasks. We propose Embedded Attack, where harmful QA pairs are embedded within benign training samples, and show that representative guardrails often fail to detect them at the example level. To address this, we propose Dual-Reference SFT (DR-SFT), which adapts...

    arxiv.org/abs/2606.30263 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.