SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

安全研究

安全研究、论文、报告与技术分析。

  • IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning

    发布时间 2026-06-02 01:54 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Heterogeneous Differential Privacy (HDP) in Federated Learning (FL) allows clients to select individual privacy budgets ($\varepsilon_i$) according to institutional policies and data sensitivity. In practice, many HDP-FL systems employ $\varepsilon$-aware server aggregation to improve model utility by re-weighting client updates according to their declared p

    扩展字段
    {
      "arxiv_id": "2606.02563v1",
      "authors": [
        "Farhin Farhad Riya",
        "Olivera Kotevska",
        "Jinyuan Stella Sun"
      ],
      "categories": [
        "cs.LG",
        "cs.CR",
        "cs.DC"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02563v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02563v1",
      "primary_category": "cs.LG",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T17:54:10+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.dc category:cs.lg primary_category:cs.lg source:arxiv type:paper research security-research
  • Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools

    发布时间 2026-06-02 00:53 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Tool-augmented language agents speculatively issue likely future tool calls to hide latency, but those calls leak inferred user intent to external services before the agent commits to the branch. Every external observer that received the call retains the disclosure after the agent abandons the branch. Timing is the issue, not authorization: no commit-time cl

    扩展字段
    {
      "arxiv_id": "2606.02483v1",
      "authors": [
        "Bardia Mohammadi",
        "Lars Klein",
        "Akhil Arora",
        "Laurent Bindschaedler"
      ],
      "categories": [
        "cs.CR",
        "cs.AI",
        "cs.CL"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02483v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02483v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T16:53:19+00:00"
    }
    arXiv cs.CR category:cs.ai category:cs.cl category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • Poking Around in the Dark: Why a Shared Understanding of Components Matters

    发布时间 2026-06-02 00:12 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    By listing the components included in an application, Software Bills of Materials (SBOMs) are intended to support the timely identification of vulnerable components and ensure the security of the software supply chain. However, we question the underlying assumption that there is agreement on the components to be listed in an SBOM and that current technology

    扩展字段
    {
      "arxiv_id": "2606.02442v1",
      "authors": [
        "Felix Reichmann",
        "Wolfgang Krane",
        "Alena Naiakshina",
        "Martin Johns",
        "Simon Koch"
      ],
      "categories": [
        "cs.SE",
        "cs.CR"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02442v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02442v1",
      "primary_category": "cs.SE",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T16:12:26+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.se primary_category:cs.se source:arxiv type:paper research security-research
  • Privacy-preserving Information Sharing in Oligopoly Competitions

    发布时间 2026-06-01 22:58 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Information sharing among competing suppliers can improve decision-making under uncertainty, yet strategic concerns regarding rival exploitation often deter voluntary disclosure. We study information-sharing mechanisms in a Cournot oligopoly with uncertain demand, where a platform aggregates suppliers' signals through privacy-preserving channels and may also

    扩展字段
    {
      "arxiv_id": "2606.02348v1",
      "authors": [
        "Yuxin Liu",
        "M. Amin Rahimian"
      ],
      "categories": [
        "econ.TH",
        "cs.CR",
        "cs.CY",
        "cs.GT"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02348v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02348v1",
      "primary_category": "econ.TH",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T14:58:38+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.cy category:cs.gt category:econ.th primary_category:econ.th source:arxiv type:paper research security-research
  • I-(OT)^2: A Client-optimal Oblivious Transfer Protocol for IoT Devices

    发布时间 2026-06-01 22:54 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Oblivious Transfer (OT) is a fundamental cryptographic primitive enabling privacy-preserving computation and constitutes a core building block for secure multi-party computation while supporting a wide range of security-sensitive applications: private information retrieval, zero-knowledge proofs, and password-authenticated key exchange, to cite a few. While

    扩展字段
    {
      "arxiv_id": "2606.02344v1",
      "authors": [
        "Elia Onofri",
        "Andrea Ciccotelli",
        "Roberto Di Pietro"
      ],
      "categories": [
        "cs.CR"
      ],
      "comment": "31 pages, 9 Figures, 6 Tables",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02344v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02344v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T14:54:08+00:00"
    }
    arXiv cs.CR category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • Multidimensional Reconciliation in Continuous-Variable QKD: Review, Coding Schemes, and Open Source Simulation

    发布时间 2026-06-01 22:36 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Continuous-variable quantum key distribution (CV-QKD) requires highly efficient reconciliation techniques to operate at low signal-to-noise ratios and long distances. Multidimensional reconciliation addresses this challenge by transforming the physical Gaussian quantum channel into a virtual binary-input additive white Gaussian noise (BIAWGN) channel, enabli

    扩展字段
    {
      "arxiv_id": "2606.02323v1",
      "authors": [
        "Martial Lucien",
        "Rosio Alexis",
        "Diamanti Eleni",
        "Cassagne Adrien",
        "Gouraud Baptiste"
      ],
      "categories": [
        "cs.IT",
        "cs.CR",
        "quant-ph"
      ],
      "comment": "15 pages, 8 figures. Link to the open-source project: https://github.com/aff3ct/HDirac",
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02323v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02323v1",
      "primary_category": "cs.IT",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T14:36:12+00:00"
    }
    arXiv cs.CR category:cs.cr category:cs.it category:quant-ph primary_category:cs.it source:arxiv type:paper research security-research
  • SeClaw: Spec-Driven Security Task Synthesis for Evaluating Autonomous Agents

    发布时间 2026-06-01 22:23 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Autonomous LLM agents increasingly operate in stateful environments where they access tools, files, memory, and external services. While such capabilities enable complex real-world workflows, they also introduce security risks that are difficult to capture with existing evaluations. Current agent security benchmarks often rely on manually curated tasks, prov

    扩展字段
    {
      "arxiv_id": "2606.02302v1",
      "authors": [
        "Hao Cheng",
        "Changtao Miao",
        "Tianle Song",
        "Yin Wu",
        "He Liu",
        "Erjia Xiao",
        "Junchi Chen",
        "Xiaoyu Shi",
        "Yichi Wang",
        "Jing Yang",
        "Taowen Wang",
        "Jinhao Duan",
        "Mengshu Sun",
        "Peiyan Dong",
        "Xuan Shen",
        "Yang Cao",
        "Renjing Xu",
        "Kaidi Xu",
        "Jindong Gu",
        "Bo Zhang",
        "Jize Zhang",
        "Chenhao Lin",
        "Philip Torr",
        "Chao Shen"
      ],
      "categories": [
        "cs.CR",
        "cs.AI"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02302v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02302v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T14:23:42+00:00"
    }
    arXiv cs.CR category:cs.ai category:cs.cr primary_category:cs.cr source:arxiv type:paper research security-research
  • AgentRedBench: Dynamic Redteaming and Integration-Aware Defense for LLM Agents over SaaS Integrations

    发布时间 2026-06-01 21:34 (UTC+08:00) 抓取时间 2026-06-02 19:10 (UTC+08:00)

    Indirect prompt injection in tool-use agents is a concrete production threat: LLM agents read from integrations (third-party services such as Gmail, Salesforce, or Jira accessed through tool calls) whose response content the user neither writes nor controls. Existing benchmarks under-measure the threat: most cover only a handful of integrations with the same

    扩展字段
    {
      "arxiv_id": "2606.02240v1",
      "authors": [
        "Hiskias Dingeto",
        "Will Leeney"
      ],
      "categories": [
        "cs.CR",
        "cs.AI",
        "cs.CL",
        "cs.ET"
      ],
      "comment": null,
      "doi": null,
      "entry_id": "https://arxiv.org/abs/2606.02240v1",
      "pdf_url": "https://arxiv.org/pdf/2606.02240v1",
      "primary_category": "cs.CR",
      "search_query": "cat:cs.CR",
      "updated_at": "2026-06-01T13:34:24+00:00"
    }
    arXiv cs.CR category:cs.ai category:cs.cl category:cs.cr category:cs.et primary_category:cs.cr source:arxiv type:paper research security-research