cs.CR · 2026-09-19 · No. 118

Cryptography and Security, 2026-09-19.

9 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

9 entries
  1. 01

    Inference-Engine Fingerprinting Attacks are Practical: Exploring Model-Driven Environmental Discovery, Exploitation, and Escape

    Sarah Radway, Andrew Cheng, Vijay Janapa Reddi, James Mickens

    cs.CR · cs.AI

    Frontier AI models are rapidly gaining the ability to exploit vulnerabilities in complex pieces of software. The risk is not theoretical, as evidenced by recent sandbox escapes performed by frontier models at OpenAI and Anthropic. Discussions of how to sandbox inference stack components often focus on components other than the inference engine itself (e.g., network proxies or code execution environments). However, the inference engine is an...

    arxiv.org/abs/2609.20614 · PDF

  2. 02

    Fingerprinting Multimodal Large Language Models

    Chao Huang, Meng Tong, Kejiang Chen

    cs.CR · cs.AI

    While multimodal large language models (MLLMs) enable a wide range of image-text reasoning tasks, recent incidents indicate that they are vulnerable to illicit deployment and unauthorized distillation. Existing solutions for model provenance are typically confounded by shared language backbones in MLLMs and struggle to detect violations of distillation. To bridge this gap and safeguard model ownership, we present the first study on multimodal...

    arxiv.org/abs/2609.20457 · PDF

  3. 03

    A Scalable Trust Discovery Architecture for the Internet of Agents

    Song Zhang, Jiankang Yao, Hongtao Li, Xiaojun Zhang, Xugang Shen, Xin Li, Yanbiao Li

    cs.CR · cs.AI

    The Internet of Agents is expected to enable large numbers of autonomous agents to discover, verify, and collaborate with each other across heterogeneous platforms. However, current agent protocols mainly address tool invocation and inter-agent communication, leaving scalable agent registration, trustworthy identification, and capability-oriented discovery largely unresolved. To address this, this paper proposes a scalable trust discovery...

    arxiv.org/abs/2609.20095 · PDF

  4. 04

    Competition, Collusion, and Corruption: The Spectrum of MEV Attacks on DAG-Based BFT Consensus Protocols

    Iliya Mirzaei, Heer Patel, Chenyuan Wu, Mohammad Javad Amiri

    cs.CR · cs.DC

    Byzantine Fault-Tolerant (BFT) protocols guarantee safety and liveness despite the malicious failure of nodes. However, they do not prevent adversarial manipulation of transaction order, where the order a proposer assigns diverges from the order in which clients submitted their transactions. Exploiting this discretion for profit is known as maximal extractable value (MEV), and it is intensified in DAG-based BFT protocols, where every replica...

    arxiv.org/abs/2609.20069 · PDF

  5. 05

    XIR: A Framework for Interoperability across Cross-Chain Protocols Based on a Verifiable Intermediate Representation

    Yushen Li, Linpeng Jia, Jiaying Feng, Ziliang Liao, Yi Sun

    cs.CR · cs.DC

    Cross-chain protocols enable applications to exchange messages across blockchains. Under point-to-point configurations, communication depends on a direct connection between the source and destination blockchains, limiting blockchain reachability and requiring additional configurations to connect more blockchains. To quantify this problem, this paper analyzes approximately 25 million mainnet cross-chain transaction events collected from six...

    arxiv.org/abs/2609.20010 · PDF

  6. 06

    Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

    Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun

    cs.CR · cs.LG

    Static malware detection for Windows Portable Executable files demands a careful balance between detection effectiveness, computational efficiency, and analytical interpretability. This paper introduces Delphi Scanner, a static malware detection system for Windows PE files that balances efficiency with behavioral interpretation. It uses a convolutional neural network (CNN) to model Windows API sequences to classify PE and a decoupled...

    arxiv.org/abs/2609.19900 · PDF

  7. 07

    Hopper: Bounded-Memory Collaborative Debiasing for Byzantine-Tolerant Peer Sampling

    Joachim Bruneau-Queyreix, Laurent Reveillère, Augusta Mukam

    cs.CR · cs.DC

    Byzantine-tolerant peer sampling relies on continuously refreshed views, yet an adversary can bias the identifier streams used to construct them. Frequency-aware debiasing downweights overrepresented identifiers, but existing designs rely on cumulative per-identifier counts. We show that even exact, unbounded counters fail under a delayed balanced attack, in which a long benign prefix masks a subsequent adversarial frequency shift. We...

    arxiv.org/abs/2609.19893 · PDF

  8. 08

    ClashBench: Conflicts Leading Agents to Seize and Harm

    Yuejin Xie, Yu Li, Dadi Guo, Qingyu Liu, Yuqian Fu, Yanwei Fu, Yujiu Yang, Xia Hu, Dongrui Liu

    cs.CR · cs.AI

    As agent systems become more widely used, multiple agent sessions increasingly run alongside pre-existing user tasks in the same environment, sharing resources with limited capacity or mutually exclusive states. This creates a safety risk: when granted sufficient privileges, an agent may resolve a resource conflict by terminating or otherwise disrupting an existing task rather than reporting it. In this work, we identify and formalize this...

    arxiv.org/abs/2609.19892 · PDF

  9. 09

    Trust, but Validate the Instrument: Auditing AI-Generated RTL Verification Plans on Authored Security-Regression Proxies

    Hang Xiao, Chuhong Xu, Kainan Zhou, Gangzhen Qian, Lu Yi

    cs.CR · cs.AI · cs.CE · cs.IR · cs.LG

    AI-generated RTL verification plans can satisfy a provider schema yet fail at the boundary to trusted execution. We present SecTB-RTL, an auditable framework covering 31 tasks and 124 authored hardware-security regressions. A deterministic non-AI baseline killed 36, 75, and 78 mutants at increasing resource limits. The first confirmatory run (C1-R2) failed before model execution because the provider rejected its response schema. After a...

    arxiv.org/abs/2609.19844 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.