Search papers, labs, and topics across Lattice.
95 papers published across 3 labs.
ROLoad-PMP achieves robust security for low-level software with less than 1.40% hardware overhead while enabling lightweight defenses that outperform existing solutions.
RAGSieve slashes knowledge poisoning attack success from 67.4% to just 14.0%, all without needing trusted corpora or poison labels.
Classical smishing detection models can fail catastrophically under adversarial attacks, while transformer-based models exhibit surprising resilience, challenging assumptions about clean-text performance.
Treatment leakage can drastically misclassify security outcomes, leading to flawed evaluations of agent safety.
QuISE effectively neutralizes typographic attacks on VLMs without any model-specific adjustments, achieving impressive accuracy recovery rates.
RAGSieve slashes knowledge poisoning attack success from 67.4% to just 14.0%, all without needing trusted corpora or poison labels.
Classical smishing detection models can fail catastrophically under adversarial attacks, while transformer-based models exhibit surprising resilience, challenging assumptions about clean-text performance.
Treatment leakage can drastically misclassify security outcomes, leading to flawed evaluations of agent safety.
QuISE effectively neutralizes typographic attacks on VLMs without any model-specific adjustments, achieving impressive accuracy recovery rates.
The SPARED framework not only boosts detection accuracy but also enhances the quality of reasoning behind verdicts, making AI-generated image detection more robust and explainable.
ROLoad-PMP achieves robust security for low-level software with less than 1.40% hardware overhead while enabling lightweight defenses that outperform existing solutions.
Visual perturbations can significantly alter predictions in world models, but ACPC offers a quantifiable way to diagnose and mitigate these effects.
The Defensive Booster achieves the best of both worlds in online forecasting, maintaining competitive accuracy while dramatically reducing computational overhead.
Achieving adversarial robustness in VC classes now requires only linear sample complexity, revolutionizing our understanding of learning under attack.
Build integration, not candidate generation, is the critical hurdle for reliable LLM-assisted dynamic analysis in autonomous vehicle software.
Black-box adversarial attacks could redefine global optimization benchmarks, revealing the true potential of evolutionary algorithms in high-dimensional spaces.
Robust learning methods can be systematically compared under distributional shifts, revealing unexpected complementary behaviors that enhance performance with partial information.
Splitting relational neurons, rather than individual ones, leads to a breakthrough in efficiently verifying neural networks against complex relational specifications.
Existing defenses against backdoor attacks in Vertical Federated Learning are fundamentally flawed, often relying on unrealistic assumptions that mask their true vulnerabilities.
HiRoute achieves high safety rates and reduces over-refusal in LLMs by dynamically routing prompts based on input risk, challenging the effectiveness of static prompt tuning approaches.
A single adversarial texture can compromise the performance of Vision-Language-Action models across multiple tasks, revealing alarming shared vulnerabilities.
MCCT secures online assessments against content extraction attacks while ensuring legitimate users can still access the material seamlessly.
Autonomous defense evolution could redefine how we secure LLM agents against sophisticated threats, outperforming traditional methods.
WIFA reduces harmful refusal while minimizing benign over-refusal, achieving a remarkable drop in over-refusal rates from 25.7% to 17.4%.
Smart contract invariants could have prevented all attacks in a benchmark of real-world Ethereum exploits, showcasing a powerful new defense against blockchain vulnerabilities.
ATOBench reveals that deceptive responses can obscure verification failures, fundamentally altering how autonomous penetration-testing agents interpret evidence and report vulnerabilities.
RealmEye reveals that even in highly isolated environments, effective introspection can be achieved without compromising the security of confidential VMs.
State-corruption attacks can be drastically reduced from 84.7% to just 2.3% with PIPES, while still preserving agent performance.
Inter-member disagreement in deep ensembles serves as a more sensitive indicator of model uncertainty than single-model confidence, especially under data shifts.
Python bytecode is a ticking time bomb in package security, with over 7,000 artifacts exposing vulnerabilities that traditional source-centric approaches overlook.
A groundbreaking watermarking method that not only traces LLM-generated content but also detects tampering with unprecedented accuracy.
Achieving near-optimal regret in adversarial $m$-set bandits without exponential space requirements could redefine efficiency benchmarks in combinatorial learning.
The Spiteful Greedy Swap Poisson Process retains its approximation guarantees even in adversarial environments, paving the way for robust online learning in submodular settings.
Clustered $α$-smoothing not only preserves the richness of multi-modal distributions but also boosts robustness, slashing collision rates by 81% in quadrotor control scenarios.
BMAT achieves unprecedented transferability in adversarial attacks, outperforming over 10 strong baselines and cutting mIoU losses in half.
A novel framework achieves up to 97.77% accuracy in detecting subtle GNSS spoofing attacks, outperforming traditional methods.
AI-art detectors misclassify up to 40% of images from new generative models, revealing a dangerous vulnerability in copyright and authenticity verification.
A single adversarial argument can reduce LLM accuracy to near zero, exposing a critical vulnerability in their belief systems.
ToolHazard reveals that injection timing and placement are critical factors in exploiting vulnerabilities of LLM-based agents, leading to new insights in adversarial robustness.
Task completion in LLMs can be achieved at a staggering 92% increase in execution time due to subtle manipulation of skill selection and instruction processes.
Attackers can no longer rely on camouflage to evade detection, as this dual-layer monitoring approach dramatically improves diagnostic accuracy in identifying cyber threats.
Ambient IoT devices can transform ISAC systems into secure environments, achieving a 14-dB SNR advantage for legitimate users against eavesdroppers.
Real-world driving scenarios can now be seamlessly translated into controllable closed-track tests, enabling more realistic validation of automated driving systems.
Effective AI attack mitigation in cellular networks could come at a steep energy cost, challenging the balance between security and efficiency.
SafeCap boosts LVLM safety by up to 19 points through innovative caption-mediated reinforcement learning, outpacing traditional alignment methods.
SafeCA slashes jailbreak success rates by 20% while adding virtually no latency, revolutionizing defenses for text-to-video models.
PEAK slashes sensitive content detections from 582 to just 6 while maintaining high-quality image generation, revolutionizing concept erasure in diffusion models.
A single poisoning phase can create a programmable backdoor in VLMs, enabling dynamic control over unseen target captions without retraining.
Malicious modifications to router weights can turn Mixture-of-Experts models into trigger-controlled bottlenecks, revealing a critical vulnerability in AI serving architectures.
A staggering 66% of vulnerabilities in agentic LLMs stem from perception-layer issues, while action-layer risks remain alarmingly underexplored.
Synthesized probabilistic saturating counters achieve formal differential privacy guarantees while maintaining competitive prediction accuracy, addressing critical side-channel vulnerabilities in modern processors.
DURA reveals that visually indistinguishable adversarial patches can exploit VLA models, posing a significant threat to their deployment in real-world robotics.
E2E speech models are vulnerable to a stealthy DoS attack that can drastically increase their output length and resource consumption without altering the original input.
Shifting from pixel-centric to class-centric exploration, SegPAR achieves unprecedented efficiency in sparse attacks for semantic segmentation, outperforming existing methods.
A dual-branch model can distinguish between benign user updates and cyberattacks in electric vehicle charging systems, achieving robust detection without rejecting legitimate requests.
Defensive poisoning can effectively clear over half of original backdoors in LLMs, but the dynamics of trigger recognition reveal deeper vulnerabilities.
Uncovering both old and new vulnerabilities, this research reveals critical privacy gaps in widely used wireless protocols that could reshape industry standards.
Self-feeding can detect backdoors in fine-tuned LLMs with 92% precision, outperforming traditional methods and revealing hidden vulnerabilities in models that appear safe.
Trimmed Mean outperforms other aggregation methods in clean settings, but Krum shines under adversarial attacks, revealing the complex trade-offs in federated learning robustness.
Honeytokens can inadvertently become tools for attackers in shared memory systems, revealing a critical flaw in defensive deception strategies.
High-FNL features boost model performance significantly, while surprisingly, low-FNL features are more effective for jailbreak mitigation.
Nearly 20% of LLM agent violations occur even after agents acknowledge safety constraints, highlighting a critical gap in execution awareness.
Withholding the first chunk of text can effectively prevent the release of harmful content in streaming LLM outputs without sacrificing safety.
A single 500 ms delay in AMI communication can escalate daily economic losses to over $5,000 during peak pricing periods.
Adversarial tenants can reconstruct private prompts with 100% success using timing attacks, but KVGov effectively neutralizes this threat while preserving cache efficiency.
LLMs can inadvertently become conduits for web exploitation, transforming benign user input into dangerous backend actions.
Automated red teaming with GFlowNets reveals vulnerabilities in LLMs more creatively and effectively than traditional methods, including in Turkish.
Achieving near-random watermark removal accuracy without sacrificing image quality, MarkNull challenges the robustness of current digital watermarking techniques.
ColluSkill reveals that seemingly harmless skill combinations can orchestrate devastating attacks, achieving a staggering 96% success rate against current defenses.
Extracting a complete signing key from just one accepted signature reveals critical vulnerabilities in the MQOM v2.1 signature scheme.
Wrapping prompts can make harmful attacks appear safer, increasing successful jailbreaks while undermining the reliability of internal safety scores.
AdvSafe enables LRMs to achieve jailbreak robustness with minimal utility loss by teaching them to understand and counteract adversarial threats intrinsically.
Despite breaching initial vulnerabilities, 24.5-47.0% of multi-hop attacks fail to complete, exposing critical gaps in cyber range effectiveness.
Self-adapting AI models can evade traditional validation checks, but a new dual-regime architecture reveals how to audit them effectively against adversarial concealment tactics.
Off-path robustness of LLMs can be dramatically influenced by model size and alignment, revealing vulnerabilities often masked by standard evaluations.
Evolving safety harnesses using trajectory data can reduce agent safety risks by over 3x while enhancing overall utility.
Exploiting a vulnerability in LLM APIs allows attackers to extract proprietary reasoning and sensitive data without directly breaching the more capable models.
Long-tailed adversarial training can be revolutionized by leveraging confusion geometry to boost the robustness of vulnerable classes and sharpen critical decision boundaries.
Eavesdroppers can be effectively thwarted in federated learning environments with a new model shift design that reduces power consumption and bandwidth needs.
Label-flipping attacks on federated GANs can skew generation distributions significantly while remaining undetectable by traditional label-agnostic metrics.
UNMASK reveals that automated discovery of spurious correlations can enhance model robustness without human intervention, achieving significant accuracy improvements on benchmark datasets.
A single poisoned skill can stealthily compromise LLM agents, activating only under specific conditions, raising alarms about the security of AI skill supply chains.
Attack success rates in cowork agents can vary dramatically, with some models achieving up to 94.4% effectiveness in executing adversarial tasks.
Iterative adversarial testing reveals that top disinformation evasion strategies can achieve a staggering 95% label flip rate while preserving original meanings.
Exploiting the mismatch between implicit human context and LLM safety alignment can lead to unprecedented attack success rates, revealing a critical vulnerability in current AI systems.
LLMs exhibit a 12% drop in constraint satisfaction when faced with more challenging, synthesized instructions that prevent trivial copy-pasting.
Fine-grained access-driven side-channel attacks can extract sensitive information from GPU workloads with unprecedented accuracy, revealing serious vulnerabilities in Apple Silicon's cache architecture.
ANTMAN achieves zero false positives and rapid detection of stealthy branch predictor attacks, redefining runtime security for RISC-V architectures.
Backdoor attacks can be stealthily inherited during model merging, but DiffSafeMerge ensures zero worst-target ASR while preserving image quality across multiple datasets.
Achieving a 96.30% attack success rate, DFCS reveals that strategic sample selection based on feature diversity can dramatically enhance the effectiveness of backdoor attacks.
Achieving 74.7% migration quality, ECAT revolutionizes repository migration by leveraging adversarial entropy minimization to ensure functional completeness in real-world applications.
Inaudible low-frequency signals can cripple LALM performance by up to 67%, revealing a hidden vulnerability in audio processing systems.
Showing all visible security tests upfront boosts functional and security success rates by over 19% on average, but not all models benefit equally.
SAVOR achieves unprecedented attack success rates against LLMs with just one query, outperforming previous methods by significant margins.
Transforming noise into visually appealing cover images, this method safeguards biometric data while ensuring integrity against tampering attacks.
QSE outperforms traditional Stackelberg strategies in cybersecurity, delivering up to 175% higher defender utility in realistic scenarios with model uncertainty.
Stealthy attackers can no longer manipulate federated learning systems unnoticed, thanks to a novel reputation model that ties trust to actual performance in R2CFL.
Static analysis can miss critical attack vectors, with host destruction attacks evading detection entirely and prompt injection only partially identified.
A dynamic "structural firewall" can thwart model extraction attacks on GNNs without sacrificing performance for legitimate users.
Attention Collapse reveals a hidden vulnerability in RAG systems, enabling the detection of poisoning attacks that traditional methods fail to catch.