cs.CR · 2026-10-02 · No. 131

Cryptography and Security, 2026-10-02.

8 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

8 entries
  1. 01

    A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders

    Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir, Emmanuel Grant, Naima Kaabouch

    cs.CR · cs.AI · cs.LG

    Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection methods often struggle with...

    arxiv.org/abs/2610.01949 · PDF

  2. 02

    A Structured State Space Sequence Model for Multi-Class Classification of Malware

    Emmanuela Andam, Rana Shaaban, Emanuel Grant, Naima Kaabouch

    cs.CR · cs.AI · cs.LG

    By 2030, Internet of Things (IoT) devices are projected to reach 40 billion, with fast-paced technological advancements in fields such as industry, healthcare, agriculture, automobiles, and building/home automation systems. This expansion has created a large attack surface for cybercrime, as the majority of these devices open the door for cybercriminals to exploit vulnerabilities, as they lack adequate built-in security. Cybercriminals launch...

    arxiv.org/abs/2610.01893 · PDF

  3. 03

    From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures

    Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang

    cs.CR · cs.AI · cs.NI

    While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct...

    arxiv.org/abs/2610.01872 · PDF

  4. 04

    Walking the Embedding Space: Datastore Extraction from Multimodal RAG

    Maria Carmen Jica, Ali Satvaty, Suzan Verberne, Fatih Turkmen

    cs.CR · cs.AI

    Multimodal Retrieval-Augmented Generation (MRAG) has emerged as a reliable and cost-effective technique of grounding the generative capabilities of Multimodal Large Language Models (MLLMs) into relevant, up-to-date, external knowledge. Despite presenting several benefits, such as reducing hallucinatory behavior, they also introduce new attack surfaces, including leakage of private information and vulnerabilities against data extraction...

    arxiv.org/abs/2610.01871 · PDF

  5. 05

    The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching

    Alessandro Pegoraro, Daryan Merx, Phillip Rieger, Ahmad-Reza Sadeghi

    cs.CR · cs.LG

    With the increasing capabilities of Large-Language-Models (LLMs) and LLM-based agents, users are increasingly using them to solve everyday problems, such as answering e-mails or providing programming support. Existing work has extensively investigated security and privacy risks, such as prompt injections and the disclosure of sensitive data to chatbot providers. While various solutions were developed to address these risks, including input...

    arxiv.org/abs/2610.01768 · PDF

  6. 06

    SoK: Decentralized Agent Economic Infrastructure

    Rui Sun, Xihan Xiong, Qin Wang, Fei Gao, Zelin Li, Zehua Cheng, Jiahao Sun, Zhipeng Wang

    cs.CR · cs.AI · cs.MA

    Decentralized agent economies increasingly build a single task from protocols that were designed and secured separately. This creates a simple problem: a workflow can look correct at each step and still produce the wrong outcome. For example, a correct escrow may release payment on an authorized approval that provides little evidence that the delivered work actually satisfied the task. We systematize this problem across the full lifecycle of...

    arxiv.org/abs/2610.01756 · PDF

  7. 07

    Chaining Skills to Hijack LLM Agents

    Tian Dong, Zixuan Ma, Haodong Zhao, Huaien Zhang, Shaofeng Li, Hao Chen

    cs.CR · cs.AI

    LLM agents use skills to improve performance on specialized tasks. To complete a user request, an agent may invoke several skills in sequence, allowing information produced under one skill to guide the next. Because skills may come from open-source repositories, this handoff can also carry attacker-controlled claims into later decisions. In this paper, we introduce APEX, which constructs and refines adversarial skill chains tailored to a user...

    arxiv.org/abs/2610.01564 · PDF

  8. 08

    False Floors: LLM Safety Routing Evaluations Break Under Distribution Shift

    Amit Singh Bhatti, Vishal Vaddina

    cs.CR · cs.AI

    Safety routers send each request to one of several models and are judged against the best single model. A major routing benchmark picks that comparator on the evaluation data. In the benchmark's own setting this is harmless, but under distribution shift it is not. On HELM Safety the selection cost is 0.003-0.030 of harm under random splits and 0.045-0.113 under held-out categories, comparable to the whole deficit attributed to routing, with...

    arxiv.org/abs/2610.01535 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.