cs.CR · 2026-07-19 · No. 58

Cryptography and Security, 2026-07-19.

3 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

3 entries
  1. 01

    Beyond Success Rate: Cost-Aware Evaluation of Offensive and Defensive Security Agents

    Paul Kassianik, Blaine Nelson, Yaron Singer

    cs.CR · cs.AI

    Security-agent evaluations commonly measure peak offensive capability under generous inference budgets, emphasizing vulnerability discovery, exploit development, penetration testing, and CTF completion. Such measurements are useful but incomplete: in operational security, every reasoning step, tool call, telemetry query, and enrichment request consumes budget. We evaluate language-model security agents through this cost-success lens on...

    arxiv.org/abs/2607.15263 · PDF

  2. 02

    MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents

    Jifeng Gao, Kang Xia, Yi Zhang, Xiaobin Hong, Mingkai Lin, Xingshen Wei, Wenzhong Li, Sanglu Lu

    cs.CR · cs.AI

    Persistent external memory enhances agent continuity but introduces persistent security vulnerabilities: adversarial content can be injected via standard interaction channels, retained across turns, and later distort downstream behavior. To address this challenge, we propose MemPoison, a comprehensive benchmark and analysis framework featuring 1227 hand-validated cases across four attack types, three injection channels, and three...

    arxiv.org/abs/2607.14651 · PDF

  3. 03

    Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems

    Soham Gadgil, David Alexander, Sai Sunku, Franziska Roesner

    cs.CR · cs.AI · cs.MA

    A growing class of agentic systems maintain persistent state across sessions through memory files, behavioral preferences, and knowledge bases. While this makes agents more useful and self-improving, it also creates a new attack surface for prompt injections in which malicious instructions can be embedded within persistent files and influence future behavior. In this work, we study prompt injection attacks in memory-based agentic systems...

    arxiv.org/abs/2607.14611 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.