cs.CR · 2026-09-17 · No. 116

Cryptography and Security, 2026-09-17.

5 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

5 entries
  1. 01

    ASLEval: Measuring Privacy Exposure Displacement in LLM Agent Sessions

    Guosen Wu, Huizhen Huang, Guoxiong Long, Tao Huang, Chen Hou

    cs.CR · cs.AI

    Privacy evaluations of tool-using LLM agents often inspect a designated action, final response, or attacker report. These local proxies can miss unauthorized exposure elsewhere in a multi-step session and lack common ground truth across outlets, reports, and tool paths. We introduce privacy exposure displacement, the mismatch between a local evaluation proxy and target-grounded session exposure, and ASLEval, an authorization-aware framework...

    arxiv.org/abs/2609.18864 · PDF

  2. 02

    Echo: Learning-based Matching Decompilation using Trusted Back Translation

    Jun Bi, Xiangxin Fang, Aarsh Chaube, José Wesley De Souza Magalhães, Rodrigo C. O. Rocha, Michael O'Boyle

    cs.CR · cs.AI

    Neural decompilers can recover readable and recompilable source code from binaries, but their predictions remain difficult to trust. Matching decompilation addresses this problem by searching for source code whose recompiled assembly exactly matches the target, providing stronger evidence of correctness. However, exact matching remains challenging for optimized binaries under unknown compilation configurations. We present Echo, a matching...

    arxiv.org/abs/2609.18706 · PDF

  3. 03

    MiST: Mid-Training LLMs for Cybersecurity

    Oded Ovadia, Elad Ben Zaken, Elad Guttman, Orly Moreno Kadosh

    cs.CR · cs.AI

    Cybersecurity combines high-stakes analysis with complex technical language, making it an impactful and challenging domain for LLMs. We present MiST (Mid-trained Security Transformer), a suite of 8B and 32B models that achieve strong performance on public cybersecurity benchmarks. We use mid-training as an intermediate adaptation stage between general pre-training and cybersecurity training. Rather than performing continual pre-training over...

    arxiv.org/abs/2609.18496 · PDF

  4. 04

    Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

    Ijaz Ahmad, Ijaz Ahmad, Flavio Esposito, Erkki Harjula

    cs.CR · cs.AI

    Adaptive security at the network edge increasingly relies on automated planners, including rule-based controllers, learned policies, and LLM-assisted agents, that translate observations into enforcement actions. Once such a planner can influence live policy state, syntactic validity is not enough. A semantically wrong action, produced from incomplete or manipulated observations, can be faithfully executed by an enforcement substrate that...

    arxiv.org/abs/2609.18338 · PDF

  5. 05

    PentestChain: A Cost-Aware, MCP-Orchestrated Framework for Automated Penetration Testing with Free-Tier LLMs

    Rushabh Vipulkumar Patel, Dipo Dunsin, Mohammed Almaiah, Mohamed Chahine Ghanem

    cs.CR · cs.AI · cs.NI

    AI-driven penetration testing has been demonstrated with premium frontier models such as GPT-4, but the per-engagement token cost makes continuous, automated testing unaffordable for the smaller organisations that need it most. This paper presents PentestChain, a ten-phase automated penetration testing framework that couples a curated, deterministic exploit map with a cost-aware AI cascade-a local Ollama model (qwen2.5-7b) first, then...

    arxiv.org/abs/2609.18120 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.