Search papers, labs, and topics across Lattice.
100 papers published across 5 labs.
A structured threat model reveals critical vulnerabilities in Quantum-as-a-Service platforms, exposing attack chains that could compromise quantum computing workflows.
A dynamic "structural firewall" can thwart model extraction attacks on GNNs without sacrificing performance for legitimate users.
Attention Collapse reveals a hidden vulnerability in RAG systems, enabling the detection of poisoning attacks that traditional methods fail to catch.
CalibForge reveals that adversarial calibration can dramatically enhance the effectiveness of training data for terminal agents, leading to unprecedented performance improvements on standard benchmarks.
Adding correctly labeled examples can paradoxically increase learning difficulty by a logarithmic factor, challenging existing assumptions about sample exchangeability.
A dynamic "structural firewall" can thwart model extraction attacks on GNNs without sacrificing performance for legitimate users.
Attention Collapse reveals a hidden vulnerability in RAG systems, enabling the detection of poisoning attacks that traditional methods fail to catch.
CalibForge reveals that adversarial calibration can dramatically enhance the effectiveness of training data for terminal agents, leading to unprecedented performance improvements on standard benchmarks.
Adding correctly labeled examples can paradoxically increase learning difficulty by a logarithmic factor, challenging existing assumptions about sample exchangeability.
Removing just a few companion cells can drastically alter single-cell annotation outcomes, revealing a hidden vulnerability in existing tools.
Residualizing CAN message features against their normal baselines enables unprecedented detection performance, even against sophisticated attacks that mimic legitimate traffic.
A zero-length nonce can compromise the security of GCM and GMAC, enabling attackers to forge messages by recovering the hash key.
A novel algebraic approach to model extraction cuts clustering time by over 90%, enabling efficient attacks on hard-label max-pooling CNNs.
Adversarial prompts can hijack VLM-controlled robots with a success rate of up to 29%, exposing a critical vulnerability in their operational integrity.
Trajectory-poisoning can turn untrusted experiences into trusted skills, embedding malicious behaviors into self-evolving agents with alarming success rates.
AMS reveals that safety training modifications can significantly alter the activation landscape of language models, impacting their compliance with safety protocols.
Label-free reliability in vision-language models has a computable blind spot that can be systematically characterized and detected.
Misleading historical data can corrupt over 30% of tool-calling decisions, but a new method can restore accuracy by effectively transferring reliable policies from teacher to student models.
Smart-home agents struggle to differentiate between real commands and misleading ambient noise, with traditional detectors and MLLMs both failing in complementary ways.
ARIA can achieve a staggering 94.5% success rate in implanting covert backdoors in customized LLMs while ensuring high task performance.
A structured threat model reveals critical vulnerabilities in Quantum-as-a-Service platforms, exposing attack chains that could compromise quantum computing workflows.
UCD reveals that even state-of-the-art segmentation models like SAM3 can be severely compromised by a single, cleverly crafted adversarial perturbation.
Ambient temperature fluctuations can be harnessed to create robust adversarial attacks that consistently deceive multimodal perception systems.
MMLMs can be made 99% safer against harmful multimodal inputs without sacrificing utility, thanks to a novel calibration approach.
Robustness to adversarial perturbations can dramatically change the sample complexity landscape, shifting accuracy dependence from linear to polynomial rates.
The integration of LLMs into EDA workflows could significantly amplify hardware vulnerabilities, but innovative defenses like split manufacturing may offer a pathway to secure chiplet systems.
Gradient Immunity can significantly hinder malicious fine-tuning efforts, keeping attack success rates at pre-release levels while enhancing safety without user intervention.
TwinIR can degrade HD map accuracy by nearly 9% while remaining nearly invisible to the human eye, posing a significant threat to autonomous driving safety.
GUARD reveals that probing action-head dependence on multimodal evidence can significantly enhance failure detection in VLA policies, outperforming existing methods in unseen task scenarios.
Targeted safety sampling can slash attack success rates in fine-tuned LLMs from over 59% to under 14% with minimal additional data.
Social cues can lead LLM safety panels to a staggering 100% false-alarm rate, revealing a dangerous flaw in majority voting mechanisms.
LoginTrap exposes a staggering 86% success rate for phishing-style attacks on LLM-based web agents, revealing a gaping hole in authentication security.
A novel IDS framework achieves near-perfect accuracy while revealing critical vulnerabilities in replay buffers that can be exploited by adversarial attacks.
Trident exposes a staggering 522% drop in defensive performance of DRL systems against adaptive threats, highlighting their critical vulnerabilities.
ColorFD achieves superior black-box physical attacks on remote sensing object detectors, outperforming traditional methods and maintaining effectiveness in real-world scenarios.
Adversarial attacks can degrade the efficiency of Vision Transformers, but MOAT ensures that performance remains nearly intact, limiting GFLOPs loss to just 3.4%.
Non-imperative syntactic structures can undermine safety alignment in large language models, exposing them to sophisticated jailbreaks.
VLMs can flip predictions in nearly half of cases due to simple changes in presentation order, revealing hidden vulnerabilities in clinical reliability.
A novel poisoning attack that cleverly disguises misinformation as conflict-minimizing updates, achieving unprecedented success rates against RAG systems.
Malicious instruction detection can be significantly improved by adapting adversarial training to the context of the task, leading to better robustness against evolving attack strategies.
Strings alone can dramatically enhance secret detection, achieving over 80% semantic retention with only a third of the context.
Parameter-efficient adaptations in public models can leak actionable structural information, with family leakage rates surpassing random chance across multiple architectures.
Adversaries can extract sensitive operational intelligence from public safety communications even when content is encrypted, revealing a critical flaw in LMR security standards.
A single manipulated search result can dramatically amplify the effectiveness of attacks on LLM-based search agents, revealing critical vulnerabilities in their evidence-gathering processes.
Obfuscation defenses are failing, with DeepInvert exposing vulnerabilities that allow for high-fidelity token recovery from supposedly secure embeddings.
Season redefines adversarial attack strategies by seamlessly integrating structural and textural updates, achieving unprecedented transfer success across diverse model architectures.
Coding agents are alarmingly susceptible to malicious skill files, with exploitation rates exceeding 95% in some cases.
Adversarial techniques traditionally seen as threats are now being repurposed by content owners to proactively safeguard their visual assets from misuse.
Adversarial attacks can exploit input-adaptive optimizations in Vision Transformers, undermining their efficiency without sacrificing accuracy.
PIMiner achieves impressive attack success rates against multiple LLMs with minimal query requirements, revolutionizing prompt injection red teaming.
Social influence can lead clinical decision support agents to adopt incorrect answers at alarming rates, revealing a critical flaw in multi-agent oversight.
Sensitivity and causality in language models are anti-correlated, revealing that early-layer interventions can inadvertently harm downstream performance.
Event timing can be weaponized to bypass ECG monitoring systems, achieving up to 66.7% suppression of critical heartbeat classifications without altering the data itself.
Utility misspecification can lead to significant performance drops in RL, but this new framework ensures robustness against such deviations, enhancing real-world applicability.
MAFIA reveals that memory-augmented LLMs can be compromised with a staggering 90.7% success rate, even under rigorous auditing conditions.
SRAP achieves a remarkable trade-off, enhancing image fidelity while maintaining robust identity disruption against face-swapping attacks.
A smaller batch size and larger learning rate can lead to flatter minima in SAM, revealing a critical trade-off in hyperparameter tuning that impacts generalization.
Tiny input changes can destabilize UAV tracking models, revealing a new attack surface that undermines their efficiency and accuracy.
Small digit changes can lead to large click misplacements, and MissClick exploits this to achieve unprecedented attack success rates against GUI grounding models.
LLMs struggle to effectively integrate and order evidence in attack chain reconstruction, with top models only succeeding 39.6% of the time on critical tasks.
Understanding how different access levels to AI systems can drastically alter forensic investigations reveals critical gaps in current methodologies.
Contextual information can dramatically amplify the success of semantic-shift jailbreaks, with a new framework achieving a 74.6% attack success rate.
SparSEEty reveals that even LLMs in secure environments can be vulnerable to token extraction attacks through clever exploitation of activation sparsity.
A novel test-time scaling method achieves superior safety in text-to-image generation without compromising inference speed or general capabilities.
A novel defense strategy reduces VLA robot failure rates from 100% to an average of 28.6% against sophisticated physical attacks, highlighting a critical vulnerability in robotic systems.
Persona skills expose significant privacy risks, with existing defenses failing to adequately protect against attribute disclosure and impersonation across diverse agent architectures.
Even state-of-the-art LLMs can lose up to 50% of contextual faithfulness when faced with semantically equivalent adversarial queries.
AI scientists excel at idea generation but falter in filtering and prioritizing innovations, revealing a critical gap in their capabilities.
SkillSentry reveals that dynamic testing can uncover harmful agent behaviors that static analysis fails to detect, achieving unprecedented accuracy in safety evaluations.
Guarded-V2X slashes intrusion acceptance rates and eradicates unsafe outputs in V2X systems, proving that LLMs can be secured without sacrificing performance.
An on-path attacker can exploit timing constraints in the German Smart Metering Infrastructure to induce dangerous frequency deviations, risking widespread load shedding.
Evasion and poisoning attacks can exploit the unique vulnerabilities of data drift detectors, leading to misclassifications that traditional defenses might overlook.
CASCADE redefines backdoor detection in multimodal learning by achieving near-perfect accuracy while effectively managing the ambiguity of poisoned samples.
SkillJack reveals that self-evolving agents can unknowingly incorporate malicious skills, making traditional safety measures ineffective against persistent threats.
Connectivity in multi-agent collaborative filtering can dramatically alter attack outcomes, revealing unexpected vulnerabilities and defense strategies.
Robustness against jailbreaks varies over a hundredfold across leading AI models, revealing critical vulnerabilities in AI safety measures.
Contrast set perturbations can dramatically boost failure detection in vision-language-action systems, outperforming conventional calibration techniques.
DMTT is the only decentralized federated learning method that maintains high accuracy against adversarial attacks while ensuring Byzantine influence is effectively minimized.
Personalization in federated learning can close 70% of the error gap, but without robust aggregation, models remain vulnerable to sophisticated adversarial attacks.
Stealthy eavesdropping attacks can slip under the radar of conventional QKD monitoring, but a new machine learning framework detects them with over 88% accuracy.
Learning from user interactions, AgentAntibody evolves to effectively defend LLM agents against prompt injection, outperforming static defenses.
FBID achieves up to a 7.66% improvement in out-of-distribution detection rates by dynamically balancing local and global model training in IoT networks.
Adversarial training boosts robustness against input attacks but paradoxically makes models more vulnerable to hardware faults.
SkillClone reveals that even hidden functionalities can be reconstructed through legitimate interactions, challenging the effectiveness of current secrecy measures.
Attacking just the first denoising step of flow-matching VLAs with a single adversarial patch can break nearly all tasks, challenging assumptions about model robustness.
Sublinear regret bounds in distributed online control reveal how local agents can effectively compete with centralized policies despite adversarial conditions.
Z-PEFT reveals that traditional backdoor detection methods fail in zero-shot scenarios, highlighting the need for robust, adaptable solutions in model safety.
Trust in AI for digital health hinges on robust and explainable systems, yet this review reveals significant gaps in current approaches that must be addressed.
Competitive adversarial self-play fails to improve legal reasoning performance, revealing that the environment's verifiability is more crucial than the competition.
AutoBypass systematically turns fragmented security knowledge into a powerful tool that can consistently bypass leading EDR systems, revealing critical vulnerabilities in commercial security solutions.
Benign experiences in self-evolving LLMs can be weaponized, revealing a hidden attack surface that undermines safety guarantees.
An off-the-shelf coding agent can uncover hundreds of buggy submissions that official test suites miss, reshaping how we evaluate code correctness.
Evolving adversarial attacks across both text and image modalities can dramatically enhance the transferability and effectiveness of adversarial perturbations in vision-language models.
Invisible Ink Threats can bypass existing safety mechanisms, exposing CUAs to severe security vulnerabilities through seemingly harmless tasks.
Cross-session goal decomposition can amplify the effectiveness of AI misuse, allowing attackers to orchestrate harmful outcomes while bypassing conventional detection methods.
CoT monitoring can be easily evaded through model poisoning, allowing hidden backdoors that manipulate outputs without detection.
TurboRetry boosts QUIC performance by offloading handshake defenses to DPUs, achieving up to 20x throughput improvements against flooding attacks.
Cross-modal embeddings can detect author impersonation in software repositories with over 90% accuracy, revolutionizing how we secure code contributions.
Stage-specific safety skills can transform LLM agent safety by providing a scalable and composable framework that outperforms existing methods.
Stealthy object removal attacks can reduce object detection rates by nearly 98%, threatening the reliability of safety-critical video-based systems.
Malicious changes can evade detection by up to 22% when interleaved with benign alterations, challenging the reliability of LLM-based code auditors in real-world scenarios.
Harmful prompts can slip through safety nets when embedded in benign batches, revealing a critical vulnerability in current AI safety measures.
AdaptoNet recovers detection performance from below 12% to over 81% in the face of targeted cyber attacks, showcasing a revolutionary approach to resilience in power grid security.
Stealth tactics dominate healthcare cyber threats, with defense evasion accounting for 15-20% of techniques, while traditional detection methods fail to keep pace.
Attack distribution entropy can predict the effectiveness of LTL-based safety monitors, revealing why some models perform poorly in safety coverage.