cs.CR · 2026-07-12 · No. 51

Cryptography and Security, 2026-07-12.

9 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

9 entries
  1. 01

    TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories

    Zheng Gao, Xiaoyu Li, Xiaoyan Feng, Jiaojiao Jiang, Yang Song, Yulei Sui, Zhenchang Xing, Liming Zhu

    cs.CR · cs.AI · cs.LG

    LLM agents reach users through resellers, who may rebrand a developer's agent or substitute a cheaper model. When provenance is disputed, attribution rests on the trajectory log (the record of tool calls, observations, and executed actions, not the model's reasoning), which the reseller stores and processes to meter usage. A watermark must therefore survive an adversary with full read/write access to the very evidence it is detected from;...

    arxiv.org/abs/2607.08400 · PDF

  2. 02

    From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure

    Lea Roxanne Muth, Marian Margraf

    cs.CR · cs.AI

    In critical infrastructure, operational technology environments often cannot be actively scanned, and yet active system feedback is needed for risk assessment and compliance. This paper presents a non-invasive, MCP-grounded multi-agent pipeline that converts natural-language system descriptions into source-verified knowledge graph and audit-ready artifacts in the NIST OSCAL format for continuous automated compliance management. The...

    arxiv.org/abs/2607.08288 · PDF

  3. 03

    Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models

    Hugo García Cuesta, Pablo Mateo Torrejón, Alfonso Sánchez-Macián

    cs.CR · cs.AI · cs.MA

    While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks. This paper proposes an open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions. The architecture combines a browser extension and a proxy for total traffic interception across both HTTP(S) and WebSocket communications....

    arxiv.org/abs/2607.08282 · PDF

  4. 04

    MLQENABLER: Enabling Secure Machine Learning Queries over Encrypted Database in Cloud Computing

    Xu Zhou, Haoyang Chen, Xinyu Lei

    cs.CR · cs.LG

    In cloud computing, the public cloud service providers (CSPs) can provide cloud storage as the primary service while providing additional machine learning (ML)-based services by using the clients' data in storage. This business model extends the border of cloud computing services and brings in new business growth possibilities. Although it is promising, the model also brings in security concerns since the public commercial cloud cannot be...

    arxiv.org/abs/2607.08197 · PDF

  5. 05

    Out of Sight: Compression-Aware Content Protection against Agentic Crawlers

    Xuefei Wang

    cs.CR · cs.AI

    The rise of LLM-based agents with reasoning, summarization, and memory capabilities has created a new threat surface for online content that conventional defenses fail to address. Existing defenses like access controls can be circumvented by agents mimicking ordinary browsers, and injection-based defenses often degrade human readability. In this paper, we revisit the agent pipeline and identify context compression, which agents routinely...

    arxiv.org/abs/2607.08180 · PDF

  6. 06

    Prismata: Confining Cross-Site Prompt Injection in Web Agents

    Corban Villa, Alp Eren Ozdarendeli, Sijun Tan, Raluca Ada Popa

    cs.CR · cs.AI

    Autonomous web agents promise to automate everyday browsing tasks, but inherit one of the web's oldest attack surfaces. Cross-Site Scripting proved that mixing trusted and untrusted content is dangerous, even on benign pages. Agents resurface this risk by interpreting natural language as instructions, allowing third-party and user-generated content to hijack the agent via prompt injection. The core challenge is that deriving a task-specific...

    arxiv.org/abs/2607.08147 · PDF

  7. 07

    Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning

    Zifan Zhang, Minghong Fang, Dianwei Chen, Zhuqing Liu, Prashant Khanduri, Xianfeng Yang, Anupam Das, Yuchen Liu

    cs.CR · cs.DC · cs.LG · cs.NI

    Federated reinforcement learning (FRL) is crucial for enabling collaborative learning across multiple agents without sharing raw data, thereby enhancing privacy and scalability in the decision-making process within dynamic vehicular environments. However, poisoning attacks pose a significant threat to the security and reliability of FRL-based systems, particularly in safety-critical autonomous driving, where this vulnerability remains largely...

    arxiv.org/abs/2607.08137 · PDF

  8. 08

    Beware What You Autocomplete: Forensic Attribution of Backdoored Code Completions

    Anjun Gao, Yueyang Quan, Zhuqing Liu, Minghong Fang

    cs.CR · cs.AI · cs.IR · cs.LG

    Large language models have enabled powerful code completion systems that assist developers by predicting subsequent lines of code. However, these models remain vulnerable to backdoor attacks, where malicious fine-tuning data covertly implants unsafe behaviors. Despite advances in defensive techniques, adaptive and sophisticated backdoor attacks still evade detection and mitigation. We present CodeTracer, a forensic framework that traces...

    arxiv.org/abs/2607.08011 · PDF

  9. 09

    Who Broke the System? Failure Localization in LLM-Based Multi-Agent Systems

    Yufei Xia, Anjun Gao, Yueyang Quan, Zhuqing Liu, Minghong Fang

    cs.CR · cs.AI · cs.IR · cs.LG · cs.MA

    Large language model (LLM) based multi-agent systems enable complex problem solving through coordinated reasoning and action, but their distributed structure also introduces new challenges in diagnosing system-level failures. When an execution fails, identifying which agent is responsible and at what point the trajectory first becomes irreversibly misdirected is difficult due to long-horizon interactions and tightly coupled agent behaviors....

    arxiv.org/abs/2607.07989 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.