cs.CR · 2026-07-21 · No. 60

Cryptography and Security, 2026-07-21.

4 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

4 entries
  1. 01

    Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security

    Devina Jain, David Hartmann, Chuan Li

    cs.CR · cs.AI · cs.LG

    LLM-based agents process external content, exposing them to prompt injection and multi-turn manipulation. Most safety benchmarks evaluate defenders against fixed attack pools collected before evaluation, single-turn or multi-turn. We present a 21-scenario benchmark for \emph{adaptive multi-round attacks against memoryless LLM defenders}: an autonomous LLM attacker observes prior defender responses and pivots across rounds, while each defender...

    arxiv.org/abs/2607.18063 · PDF

  2. 02

    Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?

    Yimeng Chen, Nathanaël Denis, Roberto Di Pietro, Jürgen Schmidhuber

    cs.CR · cs.AI · cs.CL · cs.MA

    Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via legitimate OS system call invocation. We refer to this class of threats as self-state attacks. In this paper, we investigate the OS resilience to this class of attacks. Formally, we characterize a four-axis attack space (Target, Mechanism, Granularity, Temporal);...

    arxiv.org/abs/2607.17986 · PDF

  3. 03

    RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control

    Di Lu, Bo Zhang, Xiyuan Li, Yongzhi Liao, Xuewen Dong, Yulong Shen, Zhiquan Liu, Jianfeng Ma

    cs.CR · cs.AI · cs.RO · eess.SY

    Natural-language control offers a promising interface for unmanned aerial vehicles (UAVs), but directly applying self-hosted computer-use agents (SHCUAs) to UAV control introduces a structural mismatch. SHCUAs are designed for interactive host-side tool use, where delayed agent iterations are often acceptable. UAV control, however, is coupled with continuously changing physical states, strict timing constraints, safety risks, and security...

    arxiv.org/abs/2607.17951 · PDF

  4. 04

    Detection, Attribution, Narration: An End-to-End Pipeline for Explainable Money Mule Identification

    Yuge Zhang, Yuanxing Zhang, Yichao Jin, Khairul Amsyar Mohd Razis, Nicholas Qi An Choo, Kai Yin Anders Wong, Xinyan...

    cs.CR · cs.AI · cs.LG

    Money mule accounts are critical facilitators of financial fraud, yet detecting them at scale remains challenging due to the heterogeneous nature of transactional and behavioural data. We present an end-to-end pipeline for customer-level mule detection comprising three stages: (1) a LightGBM classifier trained on 280 engineered features spanning transaction patterns, account demographics, network topology, and temporal behaviour; (2) a...

    arxiv.org/abs/2607.17586 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.