cs.CR · 2026-07-27 · No. 66

Cryptography and Security, 2026-07-27.

7 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

7 entries
  1. 01

    Agent Security Needs Redefinition through a Holistic Framework

    Vincent Siu, Jingxuan He, Kyle Montgomery, Zhun Wang, Chenguang Wang, Dawn Song

    cs.CR · cs.AI

    Agent security is widely treated as a question about action content. Defenses ask whether an instruction looks malicious. Benchmarks ask whether an agent performs a harmful sounding action. \textbf{We argue that agent security is fundamentally a contextual problem, and that the current content based framing systematically misdefines it.} A command to ``delete user data'' might be a routine administrative request or a prompt injection...

    arxiv.org/abs/2607.22024 · PDF

  2. 02

    Practical Graph Optimisation and AI-Driven Models for Active Directory Security Hardening

    Huy Q. Ngo

    cs.CR · cs.AI

    Microsoft's Active Directory (AD) is a directory service that enables the IT admin to manage security permissions and control access within a Windows domain network. As a core management system in many of organisation, AD has become a primary target for adversaries. While many solutions for hardening attack graphs exist, these efforts fall short in addressing several key practical challenges specific to the AD attack graph. First, existing...

    arxiv.org/abs/2607.22009 · PDF

  3. 03

    Decentralized Compute on Untrusted Hardware Using Intel TDX and Encrypted CVMs

    Venish Patidar, Dhruv Bindra, Ahmed Darwich, Josh Brown, Haidong Xia, Sathi Nair

    cs.CR · cs.DC

    The rapid growth of artificial intelligence workloads has generated an unprecedented demand for secure and scalable compute resources. However, centralized cloud providers continue to dominate both pricing and security models. In an increasingly competitive AI landscape, where the compromise of training data or model weights can confer a significant advantage, there is a critical need for a computing infrastructure that safeguards data at...

    arxiv.org/abs/2607.21865 · PDF

  4. 04

    Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

    Carter Luck, Olive Franzese-McLaughlin, Elisaweta Masserova, Akira Takahashi, Antigoni Polychroniadou, Nicolas Papernot

    cs.CR · cs.LG

    Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data. This makes them especially attractive for auditing models deployed in sensitive domains such as healthcare or finance. For these protocols to be meaningful in real-world audit settings, though, their guarantees must reflect how the model will behave once...

    arxiv.org/abs/2607.21839 · PDF

  5. 05

    ToolGuardian: Declarative Security for AI Agent-Tool Interactions

    Arun Ravindran, Saurabh Deochake

    cs.CR · cs.AI

    LLM agents increasingly rely on external tools, expanding capability while creating a new security boundary: third-party tools may appear benign at the interface level while embedding unsafe behavior in implementation. Existing defenses rely on weak metadata, collapse characterization and policy judgment into a single decision, or use heuristic/LLM enforcement that lacks deterministic, auditable reasoning over task context and multi-tool...

    arxiv.org/abs/2607.21835 · PDF

  6. 06

    Adversarial Prompts for Acceptance Collapse in Speculative Decoding

    Run Wang, Chaoyi Zhou, Xi Liu, Yi Zhu, Amir Salarpour, Pedram MohajerAnsari, Zhi-Qi Cheng, Feng Luo, Siyu Huang, Mert D. Pesé

    cs.CR · cs.CL · cs.LG

    Lossless acceleration schemes, such as speculative decoding, promise significant inference speedups by relying on dynamic token-level alignment between a draft and a target model. However, this guarantee of semantic equivalence masks a severe operational vulnerability: draft-target alignment can be systematically attacked. In this paper, we introduce ADSD, which, to the best of our knowledge, is the first prompt-suffix attack that collapses...

    arxiv.org/abs/2607.21804 · PDF

  7. 07

    Every Model Cheats: Prompt-Level Mitigation of Cheating on Offensive Cyber Tasks

    Michael Kouremetis, Ads Dawson, Raja Sekhar Rao Dheekonda, Brian Greunke

    cs.CR · cs.AI

    Large language model (LLM) agents routinely cheat on cybersecurity benchmarks, inflating reported pass rates far beyond genuine capability. Prior audits of Cybench found cheating in 0.3-3.4% of traces, implicating only a handful of models. We present a controlled prompt-ablation study across 22 frontier models from 7 providers on 23 Cybench capture-the-flag (CTF) challenges under three prompt conditions (no anti-cheat, standard, severe). All...

    arxiv.org/abs/2607.21763 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.