SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

安全研究

安全研究、论文、报告与技术分析。

  • Beyond Runtime Enforcement: Shield Synthesis as Defensibility Analysis for Adversarial Networks

    发布时间 2026-06-12 01:35 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    Shielded reinforcement learning is typically presented as a runtime safety mechanism that compiles temporal-logic specifications into automata restricting an agent's actions. We argue this is the wrong product. The same automata-theoretic machinery -- specification compilation, product game construction, attractor computation, and winning-region extraction -

    扩展字段
    {
      "arxiv_id": "2606.13621v1",
      "authors": [
        "Achraf Hsain",
        "Sultan Almuhammadi"
      ],
      "categories": [
        "cs.AI",
        "cs.CR",
        "cs.GT",
        "cs.LG",
        "cs.MA"
      ],
      "comment": "26 pages, 7 figures, 7 tables. Under review at JAIR. Code: https://github.com/AchrafHsain7/Bastion",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13621v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13621v1",
      "primary_category": "cs.AI",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T17:35:40+00:00"
    }
    arXiv cs.CR category:cs.ai category:cs.cr category:cs.gt category:cs.lg category:cs.ma primary_category:cs.ai source:arxiv type:paper research security-research
  • Beyond the IT Checklist: Engineering a Reasonable Standard of Care for Cyber Safety

    发布时间 2026-06-12 01:25 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    Current U.S. cyber policy, centered on security, often treats documentation of controls and incident reports as a proxy for safety in the built environment. This paper argues that such an approach is inadequate for cyber-physical systems, where digital failures can produce kinetic harm. We construct and code a corpus of critical infrastructure policy documen

    扩展字段
    {
      "arxiv_id": "2606.13612v1",
      "authors": [
        "Matthew E. Jablonski",
        "Linton Wells",
        "Kathryn B. Laskey",
        "F. Brett Berlin"
      ],
      "categories": [
        "cs.CR"
      ],
      "comment": "6 pages, 2 figures, Accepted for publication and presentation the Cyber Safety Summit, Washington, D.C., 2026",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13612v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13612v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T17:25:07+00:00"
    }
    arXiv cs.CR category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • Differentially Private Hierarchical Heavy Hitters

    发布时间 2026-06-12 00:48 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    The task of finding _Hierarchical_ Heavy Hitters (HHH) was introduced by Cormode et al. [VLDB 2003] as a generalisation of the heavy hitter problem. While finding HHH in data streams has been studied extensively, the question of releasing HHH when the underlying data is private remains unexplored. In this paper, we study differentially private HHH release in

    扩展字段
    {
      "arxiv_id": "2606.13563v1",
      "authors": [
        "Ari Biswas",
        "Graham Cormode",
        "Yaron Kanza",
        "Divesh Srivastava",
        "Zhengyi Zhou"
      ],
      "categories": [
        "cs.CR",
        "cs.DS"
      ],
      "comment": "This is the updated version of the PODS 2025 conference version. Note that the conference version has a bug in the privacy proof fro the non-streaming version. We have addressed the bug in this full version",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13563v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13563v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T16:48:35+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.ds primary_category:cs.cr source:arxiv type:paper research security-research
  • Intent-Based Cryptographic API Design for Cryptographic Agility

    发布时间 2026-06-11 23:05 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    As organizations move toward post-quantum cryptography, they face the major challenge of updating cryptographic algorithms across large, complex software portfolios. However, most cryptographic APIs in use today were designed around specific algorithms. These APIs expect explicit use of specific algorithms, provide little or no support for policy-based algor

    扩展字段
    {
      "arxiv_id": "2606.13445v1",
      "authors": [
        "Navaneeth Rameshan",
        "Gregoire Messmer"
      ],
      "categories": [
        "cs.CR"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13445v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13445v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T15:05:37+00:00"
    }
    arXiv cs.CR category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • An Assessment Framework for Application-Level Cryptographic Agility

    发布时间 2026-06-11 22:54 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    The impending post-quantum transition to new cryptography will require complete replacement of algorithms within all software. The cryptographic APIs used today make this transition challenging because they were not designed with agility as a concern. There is no method for systematically assessing cryptographic agility as an overall ability. In addition to

    扩展字段
    {
      "arxiv_id": "2606.13425v1",
      "authors": [
        "Navaneeth Rameshan",
        "Gregoire Messmer"
      ],
      "categories": [
        "cs.CR"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13425v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13425v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T14:54:10+00:00"
    }
    arXiv cs.CR category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents

    发布时间 2026-06-11 22:12 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    Web agents driven by large language models (LLMs) are increasingly deployed in real-world environments, where they operate over untrusted web content and execute actions with direct consequences. This makes them vulnerable to prompt-injection attacks, in which seemingly benign content embeds adversarial instructions that manipulate agent behaviour. Existing

    扩展字段
    {
      "arxiv_id": "2606.13385v1",
      "authors": [
        "Zihao Wang",
        "Yiming Li",
        "Yutong Wu",
        "Zheyu Liu",
        "Kangjie Chen",
        "Fok Kar Wai",
        "Pin-Yu Chen",
        "Vrizlynn L. L. Thing",
        "Bo Li",
        "Dacheng Tao",
        "Tianwei Zhang"
      ],
      "categories": [
        "cs.CR",
        "cs.AI",
        "cs.CY",
        "cs.HC",
        "cs.MM"
      ],
      "comment": "32 pages",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13385v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13385v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T14:12:43+00:00"
    }
    arXiv cs.CR category:cs.ai category:cs.cr category:cs.cy category:cs.hc category:cs.mm primary_category:cs.cr source:arxiv type:paper research security-research
  • Split Tallies: A Discrete Certificate Calculus for Auditing Dynamic Ordered Sets in Constant Memory

    发布时间 2026-06-11 20:25 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    We study retrospective auditing for dynamic ordered sets maintained by an untrusted party. A passive auditor watches insert, delete, membership, predecessor, successor, min, and max operations, stores five machine words and a flag, and receives a constant-size public tally record per operation. At audit time the maintainer discloses the claimed live vacant i

    扩展字段
    {
      "arxiv_id": "2606.13272v1",
      "authors": [
        "Faruk Alpay",
        "Levent Sarioglu"
      ],
      "categories": [
        "cs.DS",
        "cs.CR"
      ],
      "comment": "22 pages, 2 figures, 3 tables",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13272v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13272v1",
      "primary_category": "cs.DS",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T12:25:43+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.ds primary_category:cs.ds source:arxiv type:paper research security-research
  • The Invisible Ink of the Android Malware World: A Longitudinal Study on the Usage of Covert Communication Channels

    发布时间 2026-06-11 17:34 (UTC+08:00) 抓取时间 2026-06-12 19:10 (UTC+08:00)

    Proxies, VPNs and Tor have long helped the privacy community and users in censored regions to fight censorship. However, the same tools can be maliciously exploited by malware and botnets to conceal their communication to external command and control servers. Despite being a critical concern fueled by the proliferation of malware based attacks, no longitudin

    扩展字段
    {
      "arxiv_id": "2606.13107v1",
      "authors": [
        "Zeya Umayya",
        "Manan Aggarwal",
        "Manan Chugh",
        "Mann Nariya",
        "Yogesh Kaushik",
        "Sambuddho Chakravarty"
      ],
      "categories": [
        "cs.CR",
        "cs.NI"
      ],
      "comment": "21 pages, 23 figures, EuroS&P 2026",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.13107v1",
      "pdf_url": "https://arxiv.org/pdf/2606.13107v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-11T09:34:55+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.ni primary_category:cs.cr source:arxiv type:paper research security-research