cs.CR · 2026-10-06 · No. 135

Cryptography and Security, 2026-10-06.

5 new papers in cs.CR. Titles, authors, abstracts. Links to arXiv. Want this in your inbox every morning? Subscribe →

01 — The papers

5 entries
  1. 01

    Does AI Help Cyber Attackers or Defenders? Evidence from Nonpublic Vulnerabilities and Subsequent Attacks

    Tobias Heldt, Matt Turk, Christoph Landolt, Mario Fritz

    cs.CR · cs.AI

    The release decision for frontier AI systems increasingly relies on cyber capability benchmarks, yet public vulnerability benchmarks can expose agents to previously published advisories, exploits, and fixes, making it difficult to distinguish prior exposure from capability on unseen vulnerabilities. We evaluate open-weight and proprietary AI models on exploit generation, vulnerability repair and subsequent attacks in five nonpublic software...

    arxiv.org/abs/2610.06584 · PDF

  2. 02

    GCTAuto-encoder: A Cross modal Framework for Security Flaw Detection in IoT Networks

    Najmieh Sadat Safarabadi

    cs.CR · cs.AI

    IoT encompasses diverse physical entities, from smart home devices to autonomous vehicles, creating a complex environment with heterogeneous security models. This heterogeneity makes IoT sub-systems vulnerable to various network attacks. Modern security systems must therefore be more robust to ensure security and privacy for IoT applications. A highly secure IoT system also demands real time insight, requiring data collection at the edge of...

    arxiv.org/abs/2610.06517 · PDF

  3. 03

    RAISED: Self-Distillation for Robustness to Prompt Injection in LLM Agents

    Mohamed Dhouib, Clement Elliker, Alexi Canesse, Maël Jenny, Lucas-Andrei Thil, Mahammed El-Sharkawy, Sonia Vanier,...

    cs.CR · cs.AI · cs.CL · cs.LG

    Tool-using language-model agents are vulnerable to indirect prompt injection because they must act on untrusted external content. Existing training-time defenses can reduce attack success rates, but often at the cost of general capabilities. We show that training-based defenses induce substantial drift in the model's output distribution, altering its behavior even in benign settings and providing a potential mechanism for utility degradation....

    arxiv.org/abs/2610.06401 · PDF

  4. 04

    Correct Verdicts, Flawed Reasoning: Structured Auditing of LLM-based Vulnerability Reasoning

    Boyue Caroline Hu, Kaivalya Ahir, Ronghao Ni, Limin Jia

    cs.CR · cs.LG · cs.SE

    Large Language Models (LLMs) are increasingly deployed for automated software vulnerability analysis. Binary classification alone is insufficient; practitioners need explanations to triage bugs and engineer patches. Standard practice relies on Chain-of-Thought (CoT) prompting, but free-form reasoning allows models to obscure logical leaps, hallucinated execution steps, and internal inconsistencies behind plausible prose. Our manual audit...

    arxiv.org/abs/2610.06366 · PDF

  5. 05

    Watermarking: from Impossibility to Auditable Compliance

    Fernando Delbianco, Fernando Tohmé, Hugo Acciarri

    cs.CR · cs.LG · stat.ML

    Article 50 (2) of the EU Artificial Intelligence Act requires providers of generative systems to make synthetic outputs machine-readable and detectable, while qualifying the effectiveness, interoperability, robustness, and reliability by technical feasibility, cost, content-specific limits, and the state of the art. For free-form text, one important implementation route is the implementation of a generative watermarking procedure, which poses...

    arxiv.org/abs/2610.06317 · PDF

This edition is part of The Daily Abstract — cs.CR archive. Subscribe to receive these in your inbox each morning, automatically translated to Spanish, with reply-to-PDF: arxivdaily.ignorelist.com.

Colophon Set in Georgia, with system sans for interface chrome and a monospaced stack for code and paper identifiers. Sole accent: amber #D99C5E. Built and served on an always-free VM. The masthead is set 14% letterspaced because newspapers do that and it works.