Search papers, labs, and topics across Lattice.
98 papers published across 4 labs.
Arabic Language Models can suffer up to a 92% accuracy drop from simple diacritic insertions, revealing critical vulnerabilities in their robustness.
ZKIP achieves a staggering attack success rate of 0.000 against corpus poisoning, revolutionizing the defense landscape for RAG systems.
Environment evolution can reveal 17% more safety failures in complex tasks compared to static benchmarks, reshaping our understanding of agent vulnerabilities.
Adversarial training can sacrifice statistical accuracy, but a novel noise-debiased approach restores optimal generalization rates.
Randomized algorithms can outperform deterministic benchmarks in online aggregation, achieving competitive ratios below established lower bounds.
Environment evolution can reveal 17% more safety failures in complex tasks compared to static benchmarks, reshaping our understanding of agent vulnerabilities.
Adversarial training can sacrifice statistical accuracy, but a novel noise-debiased approach restores optimal generalization rates.
Randomized algorithms can outperform deterministic benchmarks in online aggregation, achieving competitive ratios below established lower bounds.
Agents can now exploit flawed opponents safely, achieving up to 13.6 times the expected budget gain while certifying their own strategies.
Confidence-ranked auditing of LLM agents can backfire, with miscalibration thresholds rising as audit budgets shrink, leading to worse outcomes than random selection.
Compromised world models can create dangerous predictive safety illusions, exposing embodied AI to a lifecycle of unique security threats.
Frontier LLMs excel in social deduction games, but most fail to sustain deception, with retention rates plummeting below 50%.
Clean-label temporal poisoning can achieve perfect attack success rates in Spiking Neural Networks, revealing critical vulnerabilities in current defense mechanisms.
Traditional threat modeling methods fall short in identifying critical GenAI-specific risks, exposing vulnerabilities in software supply chains and human-centered security.
Clean-label dormant backdoors can remain hidden until specific data is unlearned, enabling stealthy and effective exploitation without immediate detection.
Confidence gating in co-decoding can lead to a substantial 12.6% increase in secure code generation, revealing the critical role of expert model confidence in safety.
SPFM-Net achieves a breakthrough in invisible watermark attacks, balancing effective signal removal with high visual fidelity through innovative semantic and frequency-guided techniques.
Switching document formats can lead to accuracy drops of over 53%, revealing a hidden vulnerability in LLM workflows that demands urgent attention.
Malicious audio instructions can stealthily hijack multimodal agents, achieving a 69.10% success rate in real-world scenarios.
SubCASP reveals the hidden phases of cyber attacks on digital substations, transforming how we detect and respond to threats in critical infrastructure.
Sponge attacks can inflate the energy consumption of Spiking Neural Networks by up to 2.6 times without compromising classification accuracy, posing a serious threat to battery-operated edge devices.
TriShield completely neutralizes privacy backdoor attacks in federated learning without sacrificing model performance or requiring extra communication rounds.
ZAPs slashes sybil allocation by 56% while boosting quality-wallet participation by 49%, reshaping reward systems in DeFi.
CDAE boosts BERT's robustness, achieving superior embedding stability against semantic perturbations while preserving meaning.
MIND cuts memory injection attack success rates by more than half while maintaining performance, redefining the defense landscape for LLM agents.
Localized attacks on traffic forecasting can multiply prediction errors several-fold, revealing the inadequacy of traditional robustness evaluations.
Multi-item users can face significantly more powerful poisoning attacks, but a new method achieves robust estimation without sacrificing performance.
Collaborative learning among specialized model experts can dramatically enhance adversarial robustness in vision-language models, outperforming traditional fine-tuning methods.
GradLock can extract pixel-perfect data from compromised models in under a second, exposing a critical blind spot in AI supply chain security.
A safety trilemma reveals that LLMs cannot balance utility, safety, and access when evidence is copyable, exposing a critical vulnerability in current safeguards.
Infrared adversarial attacks can compromise Optical Flow Estimation Networks in real time, exposing critical vulnerabilities in autonomous systems.
Existing forensic models fail to detect over 67% of digital manipulations on IDs, highlighting a critical vulnerability in identity verification systems.
Manipulating prosody in audio LLMs can increase jailbreak success rates by over 40%, revealing a critical vulnerability in their safety mechanisms.
QUIC-TRIP achieves a triple-redundant defense against cyber threats while maintaining low latency, outperforming traditional VPN solutions in critical power system communications.
High-pressure prompts can lead VLMs to make dangerous commitments, but TPCD can reduce these risks to nearly zero while maintaining accuracy.
Adversaries can amplify DoS attacks by exploiting the transition from HTTP/1.1 to HTTP/3, affecting over 42,000 subdomains in the wild.
ThreatForest transforms code repositories into actionable, TTP-mapped attack trees, revealing a critical accuracy gap in threat modeling that could redefine security analysis workflows.
Pangram 4 sets a new standard in AI text classification with unmatched accuracy and robustness against adversarial threats.
Non-adversarial failures in optical-scan voting systems could undermine election integrity just as much as direct attacks, yet they remain largely unaddressed.
RoguePrompt reveals that even sophisticated LLM moderation can be circumvented with a staggering 93.93% success rate through clever dual-layer encoding.
MalGuard reveals that capturing cohesive program behaviors through operational roles can dramatically enhance malware detection accuracy in organizational settings.
ROPD outperforms traditional safety mechanisms by significantly reducing the risks posed by template mismatches while preserving model capabilities.
A novel detection approach reveals that while traditional methods fail, a simple token look-up can effectively recover backdoor triggers in LLMs.
Malicious memory persists in 84.2% of tested cases, revealing critical vulnerabilities in agent memory systems that could shape real-world actions long after an attack.
Recast forecasts 88.3% of future safety failures in LLM interactions, allowing for proactive risk management before violations occur.
VRS guarantees fresh, verifiable randomness in multiparty protocols, thwarting collusion and precomputation attacks.
AgentSnare can absorb nearly 47% of an attacker's tool calls while ensuring that no real targets are compromised, showcasing a new frontier in adaptive cybersecurity defenses.
FedDAB outperforms traditional defenses by effectively filtering out malicious updates in Federated Learning, ensuring robust model integrity against backdoor attacks.
HalluProp can identify potential agent failures before they escalate, achieving over 65 times faster diagnosis than conventional methods.
A composite attack can breach a supposedly robust self-check defense, achieving up to 67% success where individual methods fail.
Achieving automated reconnaissance and vulnerability verification could revolutionize how security professionals assess and respond to network threats.
A guard-agnostic amplifier improves safety classifier performance but exposes a troubling trade-off between attack success and benign refusal rates.
Developers are turning to external safeguards due to deep-seated mistrust in LIDEs, revealing systemic vulnerabilities that could compromise security and privacy.
AI music detectors can now maintain high accuracy even when faced with common audio manipulations, thanks to a novel frequency-scaling-invariant approach.
68% of LLM-based agent runs exhibit unsafe behavior, revealing that task completion alone cannot guarantee runtime safety.
Malicious actors can stealthily embed architectural backdoors in VLMs, compromising their integrity while keeping normal functionality intact.
A data-dependent approach to constrained online convex optimization reduces regret by up to 43% while maintaining feasibility at every step.
ReLATE achieves superior robustness in UAV-satellite geo-localization, outperforming existing methods even under severe image degradations.
I2VShield disrupts DiT-based image-to-video models with minimal computational cost, achieving high protection performance without the need for extensive GPU resources.
CRoMa reveals that model robustness is not just a single score but a nuanced distribution that highlights vulnerabilities to shortcut learning in pathology models.
Hierarchy compliance in LLMs can drop to as low as 20.5% when faced with conflicting tool-mediated instructions, challenging assumptions about model reliability.
Achieving 90% evasion against leading deepfake detectors reveals significant vulnerabilities in current detection methodologies.
SkillGate reduces the risk of malicious skill files in AI coding agents by achieving an impressive F1 score of 0.817 while slashing LLM input requirements by 77%.
TIGA can generate high-quality, detector-evasive images on-the-fly, bypassing the need for source images or model retraining, which could revolutionize evasion strategies against AIGC detectors.
Q-learning outperforms random selection in wireless adversarial user detection, achieving superior channel capacity and accuracy under attack conditions.
VBPEC transforms quantum error mitigation by enabling secure verification against malicious attacks while actively canceling noise, paving the way for practical quantum computation.
GPT-Red not only breaks previous models but also sets a new benchmark for automated red teaming, outperforming human efforts in discovering prompt injection vulnerabilities.
Arabic Language Models can suffer up to a 92% accuracy drop from simple diacritic insertions, revealing critical vulnerabilities in their robustness.
Organizations with similar cybersecurity controls can exhibit vastly different resilience due to structural factors that traditional theories overlook.
Code-mixing fingerprints can achieve robust ownership verification in LLMs without sacrificing performance, avoiding accidental activations that plague traditional methods.
SignDeepSC achieves robust semantic communication by leveraging a compact semantic signature, outperforming traditional defenses without sacrificing performance in clean conditions.
Flipping just a few bits can stealthily manipulate LLMs to induce significant cognitive biases, posing a serious threat to decision-making integrity.
ZKIP achieves a staggering attack success rate of 0.000 against corpus poisoning, revolutionizing the defense landscape for RAG systems.
Persona conditioning in LLMs can be exploited to amplify inference costs by over 200 times, revealing a critical vulnerability in their deployment.
SafeFlow reveals that multi-agent systems can obscure malicious intent through task decomposition, but a semantic information-flow approach can effectively counteract this vulnerability.
Cumulative Entropy-driven coreset selection can effectively isolate benign training samples, yielding robust defenses against neural backdoor attacks with minimal impact on model performance.
Backdoor attacks can generalize across trigger families, with Lilith achieving high success rates while preserving benign model performance.
Autonomous agents are failing to maintain operational stealth, with no model achieving more than 54% in safe success rates during offensive-security tasks.
MTGuard effectively reduces harmful tool use in LLM agents, combining static and dynamic analysis to enhance security without sacrificing performance.
Rule-based defenses may protect LLMs while preserving task performance, but many popular methods compromise usability and efficiency.
AI-based malware detectors that rely on domain knowledge significantly outperform deep learning models in long-term resilience and security against adversarial attacks.
DECAF achieves near-optimal unlearning performance while maintaining efficiency, effectively neutralizing clustering attacks that threaten data privacy.
APPA enables LLM agents to safely inspect unvetted data without compromising their operational context, drastically reducing security risks while preserving utility.
By transforming session-level data into actionable insights, this framework could revolutionize how analysts respond to cloud intrusions, making investigations faster and more reliable.
Inserting zero-width characters and intentional misspellings can effectively neutralize advanced stylometric systems, safeguarding authorship privacy against pervasive surveillance.
Tailoring vulnerability management strategies to specific organizational contexts can significantly enhance defenses against sophisticated APTs.
Up to 61% of age verification systems can be fooled by simple facial manipulations, revealing critical vulnerabilities in automated age estimation.
A single compromised utility can backdoor an entire Linux distribution, compromising nearly all binaries in the final environment.
Adversarial prompt injections can trick LLMs into misclassifying malicious log entries as benign, jeopardizing cybersecurity efforts.
A single policy label can mask significant differences in operational safety, with trusted-ledger strategies achieving over five times the authorized workflow completion compared to taint-only methods.
Adversarial comments can bypass LLM-based vulnerability detectors with over 90% success, exposing a critical vulnerability in AI-driven security tools.
Early detection of distributed backdoor attacks in multi-agent LLMs can flag 99.3% of threats just five steps before execution, but relies on fragile surface cues.
Fuzz testing can dramatically improve RL agent robustness and safety monitoring, with specific methods outperforming others in crash discovery and diversity.
Traditional metrics fall short; this study reveals how perturbations expose vulnerabilities in malware representations that clean accuracy cannot capture.
High-rate McEliece cryptosystems with weight two can be broken using a novel cube code distinguisher, exposing critical vulnerabilities in their security.
Instruction-dense visual jailbreaks can covertly embed harmful instructions in images, bypassing safety measures that protect against direct text generation.
A three-ring defense can slash adversarial attack success rates in RAG systems from 91% to just 13%, safeguarding the integrity of generated responses.
A necessary condition for matching cryptosystem stability reveals vulnerabilities that could compromise cryptographic security in practical applications.
Evolving AI agents can inadvertently exceed their authorized actions, but a new model ensures that their authority remains tightly controlled even as they adapt.
Iterative reprompting is essential for AI coding assistants to generate truly secure authentication code, as single-shot prompts fail to provide adequate protections.
Scenario-wrapped prompts can significantly weaken LLM refusal safeguards, revealing shared vulnerabilities across model families that enhance attack success rates.
Dormant hardware Trojans can masquerade as normal behavior in delay-based PUFs, only revealing their presence after activation, which traditional validation methods fail to catch.
Memory isolation fails to protect user data in LLM agents, as demonstrated by the SPORE attack, which achieves an 80% extraction rate even with limited triggers.