cs.CR · 2026-07-16 · No. 55

Cryptography and Security, 2026-07-16.

12 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

12 entries
  1. 01

    Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation

    Mohammad Allahbakhsh, Mohammad Hassan Bahari, Moslem Attar-Raouf

    cs.CR · cs.AI

    Penetration testing traditionally evaluates whether adversaries can exploit weaknesses in software, infrastructure, configurations, or operational controls to achieve security-relevant compromise. This paradigm remains necessary for AI-enabled systems, but it is no longer sufficient. In such systems, adversaries may influence prompts, retrieved content, sensor inputs, training data, memory, tools, or human-AI interaction loops to alter system...

    arxiv.org/abs/2607.14006 · PDF

  2. 02

    Plausible Deniability Guarantees for Whistleblowers

    Leo Richter, Matt J. Kusner

    cs.CR · cs.LG · stat.ML

    Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model -- one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a...

    arxiv.org/abs/2607.13928 · PDF

  3. 03

    Traffic-Aware Randomized Smoothing for LLM-Based Network Intrusion Detection

    Zhenpeng Li

    cs.CR · cs.AI · cs.LG

    Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical. We present Traffic-Aware Randomized Smoothing (TA-RS), a classifier-agnostic certified defense that injects Gaussian noise exclusively into the directly controllable (DC) subspace -- features a remote attacker can modify -- during both...

    arxiv.org/abs/2607.13801 · PDF

  4. 04

    How Agents Ask for Permission: User Permissions for AI Agents, from Interfaces to Enforcement

    Alexandra E. Michael, Franziska Roesner

    cs.CR · cs.AI

    As AI agents gain prevalance, users are increasingly exposed to the risks such systems entail. Prompt injection attacks, as well as hallucination, can cause agents to leak private information to third parties. As autonomous systems, agents also present the more active danger of performing sensitive tasks, such as bank transactions, without the user's intent or authorization. Recognizing this challenge, the agentic security community has...

    arxiv.org/abs/2607.13718 · PDF

  5. 05

    Protective Capacity Hallucination: When Large Language Models Claim Nonexistent Capabilities

    Eunna Lee, Jungpyo Nam, Sunjun Hwang

    cs.CR · cs.AI

    When cast as the protector of a vulnerable user yet given no explicit capability boundary, a large language model (LLM) may respond not by acknowledging its limits but by claiming to have taken -- or to be taking -- a real-world protective action it cannot perform, such as contacting emergency services or administering care. We term this phenomenon Protective Capacity Hallucination (PCH): a self-referential misattribution in which a model,...

    arxiv.org/abs/2607.13596 · PDF

  6. 06

    UTS at ELOQUENT 2026 Voight-Kampff: structural shifts in AI writing bypass state-of-the-art detectors

    Dima Galat, Marian-Andrei Rizoiu

    cs.CR · cs.AI · cs.CL

    We investigate which language model evasion attacks survive state-of-the-art adversarial fine-tuning, developing strategies that sweep the top 5 positions on the ELOQUENT 2026 Voight-Kampff leaderboard. While adversarial fine-tuning trivially closes the 2025 winning evasion recipes, we uncover a fundamental asymmetry in detector vulnerability: pushing generated text out of the detector's training distribution reliably defeats adversarial...

    arxiv.org/abs/2607.13565 · PDF

  7. 07

    When T2I Synthetic Data Backfires: Amplified Privacy Risks in Real-Synthetic Mix Training

    Na Li, Boyu Kuang, Hongsheng Hu, Liquan Chen, Hyoungshick Kim, Yansong Gao, Anmin Fu

    cs.CR · cs.LG

    To overcome data scarcity and privacy constraints in data collection, it has become standard practice across academia and industry to augment real training data with text-to-image (T2I)-generated synthetic data, a paradigm we term Real-Synthetic Mix-Training (RSMT). While substituting synthetic data for sensitive real samples is widely regarded as a means to mitigate privacy exposure of the substituted data, the risk to the remaining real...

    arxiv.org/abs/2607.13541 · PDF

  8. 08

    Adversarial Prompting Framework for AI Safety Assessment

    Yash Bhatnagar, Kunal Banerjee, Anirban Chatterjee

    cs.CR · cs.AI

    Artificial Intelligence (AI), especially Generative AI (GenAI), adoption has increased in industries significantly in recent years. However, the use of these models may also expose systems to new forms of cyberattacks by different malicious actors -- adversarial prompt attack (APA) being one of the most prominent examples of such threats. This paper presents the implementation of an Adversarial Prompting Framework (APF) for a comprehensive...

    arxiv.org/abs/2607.13453 · PDF

  9. 09

    Evaluating Frontier AI Agents as Autonomous Clinical Security Auditors

    Michael O. Eniolade

    cs.CR · cs.LG

    Clinical AI models can expose patients to harm when adversarial vulnerabilities go undetected, yet formal security auditing requires statistical expertise, specialized tools, and significant time. We present an open evaluation task, built on METR Task Standard v0.3.0, that tests whether frontier AI agents can autonomously implement a structured clinical AI security audit. Given a pre-trained clinical prediction model, a patient dataset, and...

    arxiv.org/abs/2607.13411 · PDF

  10. 10

    The Refusal Residue: When Probes Catch Alignment Faking and When They Don't

    Aman Mehta

    cs.CR · cs.AI · cs.CL

    Alignment faking is dangerous because a model can appear compliant under monitoring while preserving behavior it would reveal when unmonitored. When no scratchpad is visible, behavior alone cannot distinguish strategic from genuine compliance. We ask whether hidden states reveal what outputs hide. We run a 13-model sweep for naturally-emerging faking, then probe and steer hidden states on the two models that fake. Natural faking appears only...

    arxiv.org/abs/2607.13346 · PDF

  11. 11

    Privacy Preserving Recommender Systems Balancing Personalization with Privacy

    Ranjeet K Jha, Venkata Suresh Gummadilli

    cs.CR · cs.AI · cs.LG

    Personalized recommendation systems are central to modern e-commerce and retail platforms, but they typically rely on centralized storage of detailed user interaction data, creating significant privacy and regulatory challenges. With increasing requirements from regulations such as GDPR, CCPA, and CPRA, organizations must develop recommendation systems that preserve user privacy without substantially degrading recommendation quality. This...

    arxiv.org/abs/2607.13328 · PDF

  12. 12

    BARS: Benign-Anchored Ranking and Selection for False Alarm Reduction in Network Intrusion Detection

    Abu Fuad Ahmad, Istiaque Ahmed

    cs.CR · cs.LG

    False alarms remain a major barrier to deploying network intrusion detection systems (NIDS). In high-volume environments, even a sub-1% false positive rate can generate tens of thousands of daily alerts. Filter-based feature selection is attractive because it operates upstream of the classifier and adds no inference-time cost. However, classical filters use class-symmetric criteria that ignore the asymmetry of intrusion detection, where...

    arxiv.org/abs/2607.13203 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.