| Predicting Privacy Leakage from Weight Spectral DensityarXiv:2609.11780 | Richard J. Preen, Jim Smith | 11 Sept 2026 | cs.LG | — | |
| An Empirical Measurement of Jailbreaking EvaluatorsarXiv:2609.10594 | Yujie Mu | 11 Sept 2026 | cs.CR | — | |
| Adaptive Diffusion Freezing: Privacy-preserving Diffusion Models Against Membership Inference AttacksarXiv:2609.10608 | Jialu Guo, Xiao Han, Junjie Wu | 11 Sept 2026 | cs.CR | — | |
| Black-Box Membership Inference via Word-Level Probability EstimationarXiv:2609.10611 | Shengjie Niu, Yeheng Ge, Jian Huang | 11 Sept 2026 | cs.CR | — | |
| PEARL: A Task-Aware Framework for Evaluating Differentially Private Synthetic Educational DataarXiv:2609.10612 | Xianghui Meng, Yujing Zhang, Jionghao Lin | 11 Sept 2026 | cs.CR | — | |
| Understanding In-Context Multimodal Jailbreaks via Posterior ReweightingarXiv:2609.10613 | Xu Zhang, Dev Mistry, Xiang Xu +1 | 11 Sept 2026 | cs.CR | — | |
| SoK: Privacy Attacks on Machine Learning via Explainable AIarXiv:2609.10627 | Abdullah Caglar Oksuz, Anisa Halimi, Erman Ayday | 11 Sept 2026 | cs.CR | — | |
| From Cycle Space to Cycle Manifold: Limits and Achievability of Blind False Data Injection AttacksarXiv:2609.10631 | Xin Li, Chenhan Xiao, Jonathan Cohen +2 | 11 Sept 2026 | cs.CR | — | |
| CARTS: Contextual Autoregressive Rank Transcoding Steganography for Full-Capacity Keyed Text EncodingarXiv:2609.10744 | Wissam Ghantous, Alexander V. Mantzaris | 11 Sept 2026 | cs.CR | — | |
| Temporal and Multimodal Deep Learning for Cyberattack Detection in LEO Satellite SystemsarXiv:2609.10746 | Kyle Stein, Guillermo Francia III, Eman El-Sheikh +1 | 11 Sept 2026 | cs.CR | — | |
| Detectable Only Where It Is Confounded: What Verified Duplication Counts Say About Membership Evidence in Language ModelsarXiv:2609.10830 | Arman Nik Khah | 11 Sept 2026 | cs.CL | — | |
| DriftNet: A Dual-Head Trajectory Transformer for Detecting and Localizing Prompt Injection in LLM AgentsarXiv:2609.10892 | Asif Pinjari, Mithun Paul Saint-Germain | 11 Sept 2026 | cs.CR | — | |
| Empirical Evaluation of Membership Inference Attacks on NLP Text Classifiers: A Baseline Study on SST-2arXiv:2609.10935 | William Novak (Minot State University), Muhammad Abusaqer (Minot State University) | 11 Sept 2026 | cs.CR | — | |
| Empirical Evaluation of Data Poisoning Attacks in Supervised LearningarXiv:2609.10952 | Toshif Khan (Minot State University), Muhammad Abusaqer (Minot State University) | 11 Sept 2026 | cs.CR | — | |
| Differentially Private EEG Feature Anonymization: A Privacy-Utility Case Study in Clinical NeurophysiologyarXiv:2609.11777 | Noman Sadiq, Mohsen Toorani | 11 Sept 2026 | cs.CR | — | |
| DNA: Differentially private Neural Augmentation for contact tracingarXiv:2404.13381 | Rob Romijnders, Christos Louizos, Yuki M. Asano +1 | 11 Sept 2026 | cs.LG | — | |
| CertDW: Towards Certified Dataset Ownership Verification via Conformal CalibrationarXiv:2506.13160 | Ting Qiao, Yiming Li, Jianbin Li +2 | 11 Sept 2026 | cs.LG | — | |
| mmFHE: mmWave Sensing with End-to-End Fully Homomorphic EncryptionarXiv:2603.22437 | Tanvir Ahmed, Yixuan Gao, Adnan Armouti +1 | 11 Sept 2026 | cs.CR | — | |
| SAC-Copula: Quality-Preserving Watermarking for Diffusion Language Models via Smooth Correlated Gumbel FieldsarXiv:2608.20839 | Baixin Li, Haiyun He | 11 Sept 2026 | cs.CL | — | |
| SpecGuard: Inference-Time Backdoor Detection For FreearXiv:2609.11799 | Rui Wen, Ahmed Salem, Andrew Paverd +2 | 11 Sept 2026 | cs.CR | — | |
| Trust Me, I'm Your Developer: Self-Issued Authentication in Large Language ModelsarXiv:2609.03247 | Syed Ghazanfar Abbas, Dongyan Xu | 11 Sept 2026 | cs.CR | — | |
| AgentHijack: Visual Patch Attacks on Multimodal Computer-Use AgentsarXiv:2609.09212 | Zhihao Liu, Hongyu Sun, Zhiyuan Fu +2 | 11 Sept 2026 | cs.CR | — | |
| Compute-Bounded Security Assurance - Coverage, Verification, and Response under Resource ConstraintsarXiv:2609.09229 | Jithin VG, Ditto PS | 11 Sept 2026 | cs.CR | — | |
| In RAG We Trust? Measuring Robustness of Retrieval-Augmented Generation Under Document PoisoningarXiv:2609.09243 | Iliano Fasolino | 11 Sept 2026 | cs.CR | — | |
| An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI FrameworksarXiv:2609.09404 | Viet K. Nguyen, Mohammad I. Husain | 11 Sept 2026 | cs.CR | — | |
| Adaptive Distributed Physical-Layer Authentication and Attack Detection in 6G Non-Terrestrial Networks via Causal Meta-LearningarXiv:2609.09511 | Parsa Rajabi, Mohammad Reza Abedi, Nader Mokari +2 | 11 Sept 2026 | eess.SP | — | |
| Arbitrary Cipher Attacks Against Large Language Models Do Not Require Fine-TuningarXiv:2609.09553 | Thomas Rivasseau | 11 Sept 2026 | cs.CR | — | |
| Watermarks Without Verification: AI Text Watermarking After the EU AI ActarXiv:2609.09604 | Alexander Nemecek, Vipin Chaudhary, Erman Ayday | 11 Sept 2026 | cs.CY | — | |
| Cascading Gradient Inversion via LT-Code Inspired Peeling in Federated LearningarXiv:2609.09659 | Saeed Shariati, Mohsen Alambardar Meybodi | 11 Sept 2026 | cs.LG | — | |
| How Fragile Is Safety Alignment at Frontier Scale? A Single-Direction Attack on a 320B MoEarXiv:2609.09793 | Yi Shi, Tanyu Chen, Kai Shen | 11 Sept 2026 | cs.CR | — | |
| CS-Guard: Benchmarking LLM Guardrails for Code Generation SecurityarXiv:2609.09798 | Jinyang Li, Mingyu Guo, Hung X. Nguyen | 11 Sept 2026 | cs.CR | — | |
| Subgroup Membership Inference Audits of Differentially Private Synthetic TextarXiv:2609.09848 | Yidan Sun, Viktor Schlegel, Srinivasan Nandakumar +2 | 11 Sept 2026 | cs.CR | — | |
| What Makes Adversarial Examples Transfer Across Deepfake Detectors?arXiv:2609.10002 | Rafael M. Mamede, Pedro C. Neto, Ana F. Sequeira | 11 Sept 2026 | cs.CV | — | |
| Beyond Training: A Feasibility Taxonomy for Inference-Time AI GovernancearXiv:2609.10105 | Samar Ansari | 11 Sept 2026 | cs.CY | — | |
| Active Adaptation, Not Static Defense: Temporal Dynamics of Preventative Steering in Adversarial Fine-TuningarXiv:2609.10142 | Jing Guan, Yachao Yang, Zhaoliang Liu +2 | 11 Sept 2026 | cs.CL | — | |
| Learning Intrusion Response Strategies for OT SystemsarXiv:2609.10298 | Duc Huy Le, Rolf Stadler | 11 Sept 2026 | cs.CR | — | |
| Builder, Defender, Breaker: Measurable Independence and Bounded Autonomy When Generative Models Build, Defend and Test SoftwarearXiv:2607.03215 | Mohamed Chahine Ghanem | 11 Sept 2026 | cs.CR | — | |
| Chameleon: An Adaptive AI-Driven Honeypot Architecture Using Threat-Calibrated Particle Swarm Optimization and Semantic Deception Rapidly-Exploring Random TreesarXiv:2608.15407 | Rohit Swami, Tushar Singh, Akash Warde +1 | 11 Sept 2026 | cs.CR | — | |
| Bit-Flip Attacks on Vision-Language-Action Models: Action-Decoding Architecture Shapes the VulnerabilityarXiv:2608.15475 | Yudong Gao, Linghan Chen, Wenhan Wu +2 | 11 Sept 2026 | cs.CR | — | |