Search papers, labs, and topics across Lattice.
80 papers published across 4 labs.
ARA reveals that automated research systems can expose hidden protocol issues rather than just produce misleading causal estimates.
Achieving up to 99.5% reduction in communication costs while ensuring information-theoretic security could revolutionize federated learning on edge devices.
Evolving subspace structures can be captured in spatiotemporal data through a novel causal framework that outperforms traditional clustering methods.
Asynchronous Q-learning can now maintain performance even in the face of adversarially corrupted rewards and states, thanks to a novel batching approach.
Direct exposure to harmful objectives can lead LLMs to generate safer advice, while mediation can inadvertently align them with dangerous targets.
ARA reveals that automated research systems can expose hidden protocol issues rather than just produce misleading causal estimates.
Achieving up to 99.5% reduction in communication costs while ensuring information-theoretic security could revolutionize federated learning on edge devices.
Evolving subspace structures can be captured in spatiotemporal data through a novel causal framework that outperforms traditional clustering methods.
Asynchronous Q-learning can now maintain performance even in the face of adversarially corrupted rewards and states, thanks to a novel batching approach.
Direct exposure to harmful objectives can lead LLMs to generate safer advice, while mediation can inadvertently align them with dangerous targets.
Harmful videos paired with benign queries can exploit a critical vulnerability in Video LLMs, leading to nearly half of all attacks succeeding despite high content recognition accuracy.
GeoThreat achieves superior transferability and controllability in adversarial attacks on LVLMs, redefining how we assess model robustness in remote sensing contexts.
Adversarial training can backfire, but InsCAT ensures that detectors focus on true object features rather than misleading textures, achieving a remarkable FPR of just 1.8% in physical tests.
A single misleading document can increase the false-conclusion adoption rate of Deep Research agents to over 54%, revealing a critical vulnerability in AI-driven research processes.
Red-team evaluations can certify safety for common risks but fail to provide evidence for rare catastrophic failures, highlighting a critical gap in current AI safety assessments.
Attack ensembles optimized for minimum-norm strategies can provide a more accurate and flexible evaluation of adversarial robustness than traditional fixed-budget methods.
Adversarial data selection can significantly skew causal estimates, but a new auditing framework reveals how to quantify and mitigate this risk effectively.
Adversaries can exploit short-term wireless disruptions to not only take drones offline but also impersonate them, creating a dual threat to federated learning systems.
By intelligently filtering out noise, PSFT achieves superior robustness in point cloud classification, outperforming traditional fine-tuning methods under challenging conditions.
Evolving adversarial strategies can achieve nearly 100% success against state-of-the-art LLMs while maintaining robust defenses that adapt in real-time.
Token generation timing can leak critical architectural and optimization details from language models, exposing vulnerabilities in their deployment.
High-temperature sampling can enhance diversity in LLM outputs without sacrificing refusal behavior, achieving up to 99% retention of safety responses.
PoTRE's innovative use of diverse reasoning agents leads to a remarkable 49.92% accuracy on Humanity's Last Exam, setting a new benchmark for LLM performance in complex reasoning tasks.
No current LLM-based agent can reliably avoid executing unsafe actions when using third-party skills, with a staggering 17% failure rate even in optimal conditions.
Over two-thirds of malicious issue requests can exploit vulnerabilities in leading AI coding agents, highlighting a critical gap in current safety measures.
Every LLM-generated automation script analyzed contained exploitable vulnerabilities, regardless of the model used.
GhostPrompt achieves over 30% higher attack success rates while slashing computation time by nearly 70%, transforming how adversarial prompts can be utilized across diverse images.
Fact verification methods can degrade significantly when faced with controlled evidence poisoning, revealing vulnerabilities that traditional benchmarks overlook.
A new attack framework, HIJACKKV, reveals that position-independent KV cache reuse can be exploited to hijack model behavior with a staggering 94% success rate.
Proton reveals 23 zero-day vulnerabilities in Electron apps, with 22 enabling OS command execution, exposing critical security flaws in popular software frameworks.
AI agents are vulnerable to indirect prompt injection attacks, and KYA reveals how targeted reconnaissance can significantly enhance pentesting effectiveness.
NCIP reveals that leveraging prediction variability across multiple checkpoints can dramatically enhance early fault discovery in DNNs, outperforming traditional confidence-based methods.
FedLSG leverages large language models to transform graph data into semantic representations, dramatically enhancing backdoor defense in federated learning.
Perturbation techniques can exploit subtle internal representations in LLMs, revealing vulnerabilities that could compromise model safety.
Over 95% reduction in backdoor attack success rates with only 0.1% neuron intervention reveals a breakthrough in LLM security.
Disentangling latent embeddings in flow-based models allows for controlled generation without dimensionality expansion, outperforming StyleGAN on key benchmarks.
Retaining hazardous knowledge while selectively refusing dangerous queries could redefine safety strategies for large language models.
CDML not only preserves accuracy in gait identification but also shields against membership inference attacks without the need for data replay.
Hidden hateful illusions can be detected with over 93% accuracy using a novel adaptive retrieval approach, revealing the limitations of current moderation systems.
Adversarial attacks can be effectively mitigated in LVLMs by jointly optimizing visual and semantic supervision, leading to enhanced robustness across diverse tasks.
Evaluator bias can dramatically alter the perceived safety of medical AI, with LLM judges showing a leniency that could misrepresent model performance. WHY_IT MATTERS: This insight challenges the reliability of current evaluation methods for medical AI, emphasizing the need for standardized assessment frameworks to ensure safety in clinical applications.
Asynchronous attacks across LLM agents can be effectively linked with a new scoring protocol, revealing a high degree of campaign similarity that traditional methods miss.
A confidence-aware framework for automotive CVE-to-ATM mapping boosts precision to 87.8%, effectively filtering out uncertain mappings that could compromise safety.
Noise-induced attacks on VQE can amplify errors by up to 8.84 times, highlighting critical vulnerabilities in quantum computing pipelines.
Twin Agent achieves a superior security-utility balance, allowing LLMs to fend off prompt injection attacks without sacrificing performance.
Real-world deployment of LLM-based agents reveals critical safety and reliability challenges that traditional benchmarks overlook.
Hidden sabotage in training data eludes detection more than 50% of the time, revealing critical vulnerabilities in automated AI R&D.
Authority framing can lead verifiers to overlook critical security flaws, allowing 80% of malicious code to bypass scrutiny in CI/CD pipelines.
A side-channel attack on HQC reveals that 88.7% of machine words can be classified as zero, drastically simplifying key recovery to just 2^46 operations.
Multi-device attackers can exploit vulnerabilities in LEO satellite authentication, but Chi-MERA reduces false positives to under 2% while scaling effectively against spoofing.
Achieving a 100% reduction in data leakage without disrupting application behavior could redefine security protocols for agentic systems.
TrapHunter uncovers hidden malicious pathways in token contracts that masquerade as compliant, achieving remarkable detection rates against sophisticated traps.
Shifting from open-loop to closed-loop planning allows for more responsive and safer navigation in adversarial environments, significantly enhancing multi-objective kinodynamic planning.
Malicious instructions can infiltrate and degrade collaborative prompt optimization processes, exposing a critical vulnerability in TCPO that current defenses fail to address.
Malicious nodes can be detected with 100% accuracy by measuring activation variations in a peer-to-peer LLM inference network, revolutionizing trust in distributed AI systems.
Undetectable adversarial attacks on wireless autoencoders can be achieved by intelligently managing transmit power and generating adaptive perturbations that mimic legitimate signals.
Certified Training outperforms Adversarial Training, achieving over 80% robust accuracy against motion blur while ensuring formal safety guarantees.
MIND redefines adversarial prompt generation, achieving a staggering 95.62% success rate by intelligently interpreting model defenses rather than relying on brute-force tactics.
A single parasitic Trojan can turn benign data poisoning into a 100% effective backdoor attack by leveraging real-time interactions within ML training dynamics.
FLOB slashes the operator recovery rate to just 4.51%, setting a new standard for protecting DNN binaries against reverse engineering.
A stealthy backdoor attack can exploit circuit cutting in VQAs, amplifying energy output while evading detection.
SHADOWPICKLE can bypass ten state-of-the-art model scanners, revealing critical vulnerabilities in the current security landscape of machine learning model hubs.
Identity leakage drops to just 0.74% while maintaining high recognition accuracy, thanks to an innovative decoy-oriented approach in face recognition.
A layered defense can thwart most self-state attacks on AI agents, but a hidden vulnerability persists that challenges current OS security paradigms.
LLMs are not just passive observers; they can uncover novel cryptographic vulnerabilities that challenge our current understanding of digital security.
Latent-iterative reasoning in VLA models may actually decrease robustness, collapsing under perturbations while simpler reasoning approaches hold strong.
Frontier LLMs can be induced to generate biologically hazardous sequences, with attack success rates reaching up to 100%.
Adversarial instructions can exploit LLM agents in HPC, leading to unauthorized actions even under authenticated user credentials.
Clean accuracy masks a stark vulnerability: both leading phishing detection models plummet to around 64% accuracy under adversarial conditions.
Adaptive multi-turn attacks can increase LLM defender vulnerability by over 14%, exposing critical weaknesses in existing safety benchmarks.
RECEIPT uncovers 24 previously unknown XSS vulnerabilities while ensuring no false positives, setting a new standard for trust in automated vulnerability discovery.
A single perturbation can collapse graph foundation models, exposing a unique vulnerability in their alignment layer that traditional graph networks do not possess.
Existing defenses for encrypted traffic can be up to 0.124 bits away from optimal performance, revealing significant room for improvement in side-channel security.
The Structural Leakage Score reveals critical mismatches in attack detectability that challenge conventional wisdom about machine learning IDS performance in encrypted traffic.
LLMs exhibit significant variability in their understanding of security topics, with some models failing to accurately identify critical issues like identity theft and impostor scams.
Salience Induction can redirect reasoning in RAG systems even when all retrieved claims are true, achieving an 83.3% attack success rate against leading models.
Breaching one robustness-optimized defense can expose an entire family of defenses, with purification methods showing an alarming 80.4% transfer attack success rate.
Dynamic throttling of AI performance can be achieved with minimal hardware changes, enabling unprecedented control over AI intent in critical systems.
Achieving zero credential leakage while preserving agent performance, SlotGuard redefines privacy standards for LLM transcripts.
A single misleading document can drastically reduce deep research agents' accuracy by up to 88%, exposing a critical vulnerability in their evidential reasoning capabilities.
Near-chance speaker identification is achieved while maintaining strong dementia classification, showcasing a breakthrough in privacy-preserving AI applications.
Evaluating jailbreak attacks as tools for enhancing model safety reveals that traditional metrics may mislead researchers about their true utility.
BSB reveals that leveraging temporal consistency can dramatically enhance the effectiveness of jailbreak attacks on text-to-video models, achieving unprecedented success rates.
Visualizing DSA vulnerabilities reveals how nonce reuse and leakage can compromise digital signatures, making complex attacks comprehensible even for beginners.
Hybrid defenses can restore NIDS accuracy to over 96% against adversarial attacks that typically cripple detection systems.