| 1 | CodePoisonRAG: Knowledge Poisoning Attacks on Retrieval-Augmented Code Generation | Varun Gadey, Ziad Marey, Alexandra Dmitrienko | cs.CR | 2026-09-02 |
| 2 | SPADE: SPaT Attack Detection from the Connected Vehicle's Perspective | James Di Novo, Hany Ragab, Sylvain P. Leblanc | cs.CR | 2026-09-02 |
| 3 | Learning-Based Reconstruction Attacks on Coordinate-Obfuscated Point Clouds | Mohammad Waquas Usmani, Susmit Shannigrahi, Michael Zink | cs.CR | 2026-09-02 |
| #4 | CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning | Chao Feng, Burkhard Stiller | cs.LG | 2026-09-02 |
| #5 | Towards One-for-All Robustness Across a Continuum of Threat Levels | Zhichao Hou, Xiaorui Liu | cs.LG | 2026-09-02 |
| #6 | Before the Script, Set the Stage: How Worldview Simulation Amplifies Psychologically Grounded Persuasion in Multi-Turn Jailbreaking | Siyu Chen, Haoran Wang, Xiaojian Li +3 | cs.CL | 2026-09-02 |
| #7 | Poisoning Attacks on the PGM-index | Atsuki Sato, Martin Aumüller, Yusuke Matsui | cs.DB | 2026-09-02 |
| #8 | Counter-GEO-Bench: Evaluating Defenses Against Information-Distorting Generative Engine Optimization | Bing Zheng, Zongyao Zhao, Wenming Yang | cs.IR | 2026-09-02 |
| #9 | SEAL: Reinforcing Global Safety in Mixture-of-Experts through Shared Expert ALignment | Qingyu Meng, Yiwei Zha, Jiahuan Pei +3 | cs.LG | 2026-09-02 |
| #10 | CAPTURE: Disentangling Preference Drift from Memory Poisoning in Personalized LLM Agents | S M Asif Hossain, Ruksat Khan Shayoni, Md Kishor Morol | cs.LG | 2026-09-02 |
| #11 | InfraPatch: Cross-Task Targeted Grayscale Patch Attacks on Infrared-Adapted Vision-Language Models | Chengyin Hu, Dingyi Lu, Jiaju Han +5 | cs.CV | 2026-09-02 |
| #12 | ASCII Attack: Recontextualising Harmful Requests as Artistic Critique in Large Language Models | Da Cheng Gu, Yifei Dong, Xinghao Yang +2 | cs.AI | 2026-09-02 |
| #13 | WeaveMark: Robust and Scalable Multi-bit LLM Watermarking via Coded Payload Spreading | Gang-Hyun Park, Ju-Hyeong Lee, Hee-Youl Kwak +1 | cs.CR | 2026-09-02 |
| #14 | Breadth Beats Depth: Improving GCG-Based Jailbreak Optimization with Breadth-Oriented Suffix Search | Shiliang Xiao, Jingsong Wei, Yuzhi Liang +3 | cs.CL | 2026-09-02 |
| #15 | C$^{3}$T: Counterfactual Causal Reasoning for Sentiment Shifts in Social-Media Conversation Trees | S M Rafiuddin, Atriya Sen | cs.CL | 2026-09-02 |
| #16 | Pushing Forward Multi-Secret-Key Homomorphic Encryption for Private Average Aggregation | Miguel Morona-Mínguez, Fernando Pérez-González, Alberto Pedrouzo-Ulloa | cs.CR | 2026-09-01 |
| #17 | Agent Memory Is a Surface for Endogenous Authorization Laundering | Tommaso Cerruti, Mika Okamoto, Ansel Kaplan Erol | cs.CR | 2026-09-01 |
| #18 | Hearing the Whispers: Black-Box Membership Inference Attacks on Finetuned TTS Models | Kunlin Cai, Kaiyuan Zhang, Zihang Xiang +4 | cs.CR | 2026-09-01 |
| #19 | Beyond Scores: Understanding LLM-as-a-Judge Mechanisms in Summarization Evaluation | Himil Vasava, Ming Jiang | cs.CL | 2026-09-01 |
| #20 | Optimizing Byzantine Node Placement in Decentralized Federated Learning | Edoardo Gabrielli, Gabriele Tolomei | cs.LG | 2026-09-01 |
| #21 | Defense-as-Skill: Evolving Runtime Guard Skill for Skill-Augmented Agents | Xiaofang Yang, Ziqi Miao, Dianbo Sui +2 | cs.CR | 2026-09-01 |
| #22 | When Safety Routing Breaks: Understanding Alignment Fragility under Benign Fine-Tuning | Yitong Guo, Xiaoyi Chen, Siyuan Zhang +2 | cs.CR | 2026-09-01 |
| #23 | Gaussian Core LoRA: Distribution-Aware Dynamic Adaptation for Broad Concept Erasure | Qinghui Gong, Xunlei Chen, Yu-Xuan Zhang +2 | cs.CV | 2026-09-01 |
| #24 | VerTox: Verifiable Reward-Guided Corpus Poisoning Against Neural Ranking Models | Zhiqi Huang, Vivek Datla, Zhichao Xu +3 | cs.CL | 2026-09-01 |
| #25 | One Prompt Is Enough: Watermark Laundering Through Foundation Image Models | Jidong Yang, Qi Li, Wei Zong +5 | cs.CV | 2026-09-01 |
| #26 | Explore More, Drift Less: Outcome-Only Reinforcement Learning Can Suffice for Long-Horizon Interactive Agents | Liming Pu, Xiaoxia Li, Yifu Liu +2 | cs.LG | 2026-09-01 |
| #27 | Position Matters: Feature Inversion Attacks in ViT Split Inference with Token Reduction and Shuffling | Stefano Leggio, Giulio Rossolini, Alessandro Biondi | cs.CR | 2026-09-01 |
| #28 | Jailbreaking Text-to-Image Models Through Cracks: Navigating Heterogeneous Safety Filters via Multi-Agent Debate | Kaiyan Wen, Shijie Zhang, Lu Yu +1 | cs.AI | 2026-09-01 |
| #29 | Membership Inference in Fine-tuned Diffusion Language Models via Token-level Memorization Asymmetry | Shengfang Zhai, Leo Marchyok, Yuling Shi +4 | cs.CL | 2026-09-01 |
| #30 | Forbid Your Attention: Fooling Multimodal Large Language Models by Selectively Removing Intrinsic Focus in Spectral Domain | Daizong Liu, Junhao Dong, Zhiyuan Ma +6 | cs.CV | 2026-09-01 |
| #31 | Triple-Bottom-Line Sustainability of Language Models for Edge AI: A Comparison Between SLMs and Quantized LLMs | Jainil Dharmil Shah | cs.AI | 2026-09-01 |
| #32 | SoK: When Safe Agents Fail Together: The Security of Multi Agent LLM Systems | Rui Yang, Junjie Xu, Zhengyu Liu +4 | cs.CR | 2026-09-01 |
| #33 | Same Semantics, Different Outcome: On the Modality Robustness of Multimodal LLMs under Knowledge Conflict | Jungyeon Lee, Yejin Yoon, Taeuk Kim | cs.CL | 2026-09-01 |
| #34 | The Safeguard Worked. Is the LLM System Safer? | Pingyu Wu, Weiming Zhang, Nenghai Yu | cs.CR | 2026-09-01 |
| #35 | Beyond Token Positions: Safety Alignment Across Denoising Steps in Diffusion Language Models | Guoli Wang, Haonan Shi, Tu Ouyang +1 | cs.CL | 2026-08-31 |
| #36 | EvoFlint: An Evolutionary Atlas of Multi-Turn LLM Vulnerabilities | Feitong Qiao, Liren Peng, Shiming Ren +7 | cs.CL | 2026-08-31 |
| #37 | TRIS: A Tri-Layer Retrieval Integrity Sieve Against Knowledge Poisoning | Muhaimin Bin Munir, Akib Jawad Ononto, Nazia Shehnaz Joynab +2 | cs.CL | 2026-08-31 |
| #38 | Does Reasoning Mitigate Backdoor Attacks? A Neuro-Symbolic Perspective | Marco Antonio Corallo, Andrea Agiollo, Mauro Conti +1 | cs.CR | 2026-08-31 |
| #39 | Context Inference Attacks Without Jailbreaks | Prince Jha, Samuele Poppi, Nils Lukas | cs.CR | 2026-08-31 |
| #40 | Workload Identification with Physical Side Channels for AI Governance | Simone Gargiulo, Gabriel Kulp | cs.CR | 2026-08-31 |
| #41 | Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems | Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi | cs.CR | 2026-08-31 |
| #42 | Physical Adversarial Examples for Person Detectors in Thermal Images Based on 3D Modeling | Xiaopei Zhu, Siyuan Huang, Zhanhao Hu +3 | cs.CV | 2026-08-31 |
| #43 | The Fragility of Jailbreak Robustness Across Operational States | Yuna Park, Hwang Youn Kim, Yujin Kim +3 | cs.CR | 2026-08-31 |
| #44 | Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning | Fukang Zhu, Binbin Zhao, Ruixiao Lin +3 | cs.CR | 2026-08-31 |
| #45 | The Safety Relay in Roleplay Jailbreaks: A Component-Resolved Causal Analysis of Harm Recognition and Refusal | Md Mokarram Chowdhury, Ernie Chang, Yang Li | cs.LG | 2026-08-31 |
| #46 | EvoSkill Injection: Red-Teaming Autonomous Skill Generation and Evolution in Self-Evolving Agents | Doyun Kim, Chanwoo Kim, Sugyeong Eo +2 | cs.AI | 2026-08-31 |
| #47 | Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents | Yunseok Lee, Yunji Kim, Woojin Lee | cs.AI | 2026-08-31 |
| #48 | Lazy Grounding: Attacking Search Agents with Factual Evidence | Yulin Zhang, Yukun Huang, Sanxing Chen +4 | cs.CL | 2026-08-31 |
| #49 | SIR: Self-improving Red-teaming for Compute Use Agents | Chen Xiong, Zhiyuan He, Pin-Yu Chen +2 | cs.CR | 2026-08-31 |
| #50 | Balancing Privacy, Utility, and Safety in LLM Alignment through Preference Optimization | Dishu Yang, Jingjing Liu, Jize Li | cs.CR | 2026-08-31 |