cs.CR · 2026-07-09 · No. 48

Cryptography and Security, 2026-07-09.

6 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

6 entries
  1. 01

    Beyond Attack-Success Rate: Action-Graded Severity Scale for Tool-Using AI Agents

    Harry Owiredu-Ashley

    cs.CR · cs.AI · cs.CL

    Agentic red-teaming benchmarks report whether an injected agent was compromised as a single bit: the attack succeeded, or it did not. We argue that this binary attack-success rate discards the information a defender most needs, namely how harmful the resulting action was. We introduce an action-graded harm rubric that scores an agent's tool-call trajectory on a seven-level ordinal scale (L0 to L6) according to whether the executed action was...

    arxiv.org/abs/2607.07474 · PDF

  2. 02

    Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe

    T-H. Hubert Chan, Elaine Shi, Mengshi Zhao, Mingxun Zhou

    cs.CR · cs.LG

    Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor continual-release analyses. We give an auditable modular recipe. A randomized buffering wrapper emits bins of...

    arxiv.org/abs/2607.07209 · PDF

  3. 03

    Is Randomness Necessary for Adaptive Data Analysis?

    Edith Cohen, Haim Kaplan, Yishay Mansour, Shay Sapir, Uri Stemmer

    cs.CR · cs.DS · cs.LG

    The Adaptive Data Analysis (ADA) problem formalizes the challenge of preventing false discovery and overfitting when a dataset is repeatedly reused. Formally, our input is a dataset containing $n$ i.i.d. samples from an unknown distribution $\mathcal{P}$ over a domain $\mathcal{X}$, and our goal is to answer a sequence of $k$ adaptively chosen statistical queries with respect to $\mathcal{P}$. The main question is how many queries we can...

    arxiv.org/abs/2607.07085 · PDF

  4. 04

    Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies

    Kiarash Ahi, Saeed Valizadeh

    cs.CR · cs.AI · cs.CL

    Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks. These technologies power real-time threat detection, phishing defense, secure code generation, and vulnerability exploitation at unprecedented...

    arxiv.org/abs/2607.06963 · PDF

  5. 05

    When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems

    Haowen Xu, Xue Tan, Lei Ma, Zhihao Zhang, Chao Wang, Qingze Wang, Ping Chen, Jun Dai, Xiaoyan Sun

    cs.CR · cs.AI

    While enabling effective collaboration on complex tasks, LLM-based Multi-Agent Systems (MAS) face critical security challenges due to vulnerabilities at the agent and interaction levels. Most existing MAS security defenses are built upon two core assumptions: semantically-explicit malicious attacks and explicit graph-based modeling of the MAS topology and agent-level interactions. In practice, real-world attacks are becoming more semantically...

    arxiv.org/abs/2607.06807 · PDF

  6. 06

    ECO/CPO-DAG: A Contradiction-Based Accountability Layer for Adversarial Supply Chains

    Sebastian Cochinescu

    cs.CR · cs.DC

    We present ECO/CPO-DAG, a domain-specific accountability protocol for adversarial supply chains that formalizes contradiction detection as a supplemental validation layer rather than a consensus or truth-establishing mechanism. Participants publish signed Event Claim Objects (ECOs) into a causally ordered, append-only directed acyclic graph (DAG) whose edges encode happened-before relations. When two claims about the same subject violate a...

    arxiv.org/abs/2607.06804 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.