cs.CR · 2026-07-14 · No. 53

Cryptography and Security, 2026-07-14.

6 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

6 entries
  1. 01

    When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems

    Yibo Hu, Ren Wang

    cs.CR · cs.LG · cs.MA

    As multi-agent, tool-using LLM systems are deployed, a common safety net is a runtime monitor that checks each message, tool call, or step on its own. We show this net has a fundamental hole. A distributed backdoor splits a harmful payload across agents, so every local check passes while the assembled object is the attack. The monitor can be right on every step and still miss the attack. The problem is not splitting itself: split fragments...

    arxiv.org/abs/2607.11751 · PDF

  2. 02

    Agent Hacks Agent: Autoresearch for Production-Agent Red-Teaming

    Xutao Mao, Xiang Zheng, Cong Wang

    cs.CR · cs.AI

    Production LLM agents such as Claude Code and Codex operate over untrusted content, files, commands, and workspace state, making safety failures directly actionable. Red-teaming must therefore keep pace with evolving models and tools. Existing approaches mainly optimize attack success and preserve artifacts such as benchmarks, payloads, or attack programs, which record where attacks succeed but not the enabling conditions behind unsafe agent...

    arxiv.org/abs/2607.11698 · PDF

  3. 03

    Closing the Loop: An Access-Control Architecture for Automated, Anomaly-Driven Network Revocation in IoT Deployments

    Muhammet Emir Korkmaz, Kemal Bicakci, Yusuf Uzunay

    cs.CR · cs.AI

    Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate. This paper presents an access-control architecture that closes that loop using only standard, already-deployed protocols. Devices authenticate via IEEE...

    arxiv.org/abs/2607.11649 · PDF

  4. 04

    Time Is Money: Incentivized Causal Transaction Ordering

    Hongyin Chen, Xu Zheng, Jichen Li, Ittay Eyal

    cs.CR · cs.DC

    Front-running is a subtle and persistent problem for blockchains. A blockchain is a stateful virtual machine executing instructions called transactions. Users earn rewards by publishing functional transactions essential to the system. Attackers observe these transactions and publish their own ahead of the users', seizing the reward and eroding users' incentive to publish functional transactions. Preventing front-running means enforcing...

    arxiv.org/abs/2607.11496 · PDF

  5. 05

    Mako: A Self-Evolving Agentic Operating System (SE-AOS) for Autonomous Web Exploitation

    Praneeth Narisetty, Shiva Nagendra Babu Kore

    cs.CR · cs.AI · cs.MA

    We introduce the Self-Evolving Agentic Operating System (SE-AOS): a new class of AI agent that treats exploit capability as a mutable, versioned kernel it extends at runtime, observing its own failures, synthesising new capabilities, proving them against a live target, and hot-loading them back into itself. Mako is the first SE-AOS instance for security research and the autonomous web exploitation engine developed within LaunchSafe....

    arxiv.org/abs/2607.11288 · PDF

  6. 06

    AMT-X: Phase-Structured Multi-Turn Red-Teaming with Checklist-Gated Evaluation

    Yi Ting Shen, Kentaroh Toyoda, Alex Leung

    cs.CR · cs.AI

    Safety evaluation of large language models (LLMs) relies largely on single-turn attack datasets and single-judge scoring, underestimating risk from adaptive multi-turn adversaries and reporting a single success rate that does not separate partially actionable outputs from those carrying complete operational detail. We propose AMT-X (Adaptive Multi-Turn Exploitation), a phase-structured multi-turn red-teaming framework. Unlike prior multi-turn...

    arxiv.org/abs/2607.11151 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.