cs.CR · 2026-07-23 · No. 62

Cryptography and Security, 2026-07-23.

8 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

8 entries
  1. 01

    The Ethics of Autonomous AI Agents for Offensive Security

    Andreas Happe, Jürgen Cito, Jasmin Wachter

    cs.CR · cs.AI

    LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling -- deterministic, narrowly scoped, and operated by trained practitioners -- agentic security tools exhibit \textit{indeterminacy} along three independent dimensions. First, their actions are drawn from a non-deterministic policy whose outputs resist both ex-ante and ex-post explanation, frustrating incident attribution and...

    arxiv.org/abs/2607.20255 · PDF

  2. 02

    Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis

    Adel ElZemity, Shujun Li, Budi Arief

    cs.CR · cs.AI

    Malware analysis demands rapid interpretation of complex detonation reports spanning filesystem, network, and process behaviours. While large language models (LLMs) demonstrate impressive capabilities for technical artifact interpretation, the opacity and escalating API costs of closed-weight frontier models motivate exploration of open-weight alternatives. However, many open-weight models are large, demanding significant compute resources...

    arxiv.org/abs/2607.20216 · PDF

  3. 03

    Taming the Security-Energy Paradox: A Green AI Approach to Optimized Android Malware Detection

    Shrinidhi Sridhar, Vikas K. Malviya

    cs.CR · cs.AI · cs.LG

    An increase in advanced Android malware requires the use of deep learning models, which can run on Android devices. But there is a trade-off between security and energy use, as strong detection models can drain the battery of devices fast. This work tests different Multi-Layer Perceptron (MLP) model configurations to balance malware detection performance and energy efficiency. In this work, we compared standard FP32 models with optimized INT8...

    arxiv.org/abs/2607.20003 · PDF

  4. 04

    HijackKV: New Threat in Position-Independent KV Cache Reuse

    Yichi Zhang, Zhiqi Wang, Huan Zhang, Yuchen Yang

    cs.CR · cs.AI · cs.LG

    Key-Value (KV) cache reduces inference latency in large language models (LLMs). Traditional prefix-based reuse has low cache hit rates across inference requests because it requires exact token and position matches. To improve efficiency, recent system optimizations introduce position-independent KV reuse, allowing KV cache to be reused whenever identical text chunks appear, regardless of their position in the sequence. We show this design...

    arxiv.org/abs/2607.19957 · PDF

  5. 05

    Defense Against LLM Backdoors using Critical Neuron Isolation Pruning

    Yuxi Li, Zhibo Zhang, Kailong Wang, Xingshuo Han, Ling Shi, Haoyu Wang

    cs.CR · cs.AI

    Large language models (LLMs) are vulnerable to backdoor attacks, where hidden triggers induce malicious outputs. Existing defenses generally fall into inference-time detection or training-time mitigation, but face two key limitations. First, they focus on fine-tuning-based backdoors (e.g., PEFT modules) and fail to address insidious model-editing attacks that bypass training pipelines. Second, they target simple classification settings and do...

    arxiv.org/abs/2607.19894 · PDF

  6. 06

    An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports

    Wenbo Hou, Ning Hu, Xueping Wang, Jiahao Gu, Wenjian Luo

    cs.CR · cs.AI

    Cyber Threat Intelligence (CTI) reports richly describe real-world attack processes, but their unstructured narratives cannot be directly used for automated attack-path reasoning. Existing CTI extraction methods focus on indicators, entities, or TTP labels without modeling the execution conditions and resulting states of each attack step, so the extracted knowledge supports neither state matching nor reachability analysis across multi-stage...

    arxiv.org/abs/2607.19742 · PDF

  7. 07

    FedLSG: LLM-Enhanced Semantic Calibration for Federated Graph Backdoor Defense

    Chenyu Zhou, Yabin Peng, Wei Huang, Kunlin Li, Shuaishuai Zhang, Xinyuan Miao

    cs.CR · cs.AI · cs.LG

    Federated Graph Neural Networks (FedGNNs) are highly vulnerable to backdoor poisoning, yet existing defenses typically rely on rule-based approaches that lack semantic understanding, making them vulnerable to stealthy triggers and harmful to benign structures. To solve this, we present FedLSG, the first framework that integrates large language models (LLMs) into federated graph backdoor defense. FedLSG introduces a graph and behavior to text...

    arxiv.org/abs/2607.19674 · PDF

  8. 08

    Integrity of peer-to-peer distributed LLM inference under malicious nodes

    Mert Cihangiroglu, Antonino Nocera

    cs.CR · cs.AI

    Peer-to-peer distributed inference executes a Large Language Model (LLM) on pooled consumer hardware by spreading its layers across many nodes. Every request passes through nodes that are owned and controlled by multiple independent parties. However, in this setting, any party can tamper with the output of its layers to corrupt the end result. Recomputing the forward pass on trusted hardware can catch this, but it introduces additional...

    arxiv.org/abs/2607.19490 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.