安全研究
安全研究、论文、报告与技术分析。
-
Where You Tap Matters: A Probe-and-Model Benchmark for Open-Set RF Fingerprinting
Radio Frequency Fingerprint Identification (RFFI) enables transmitter identification at the physical layer by learning device-specific impairments from received signals, yet the literature is inconsistent about where in the receiver chain those samples should be collected. Since distinct transformations are applied to the signal by the different receiver ope…
Radio Frequency Fingerprint Identification (RFFI) enables transmitter identification at the physical layer by learning device-specific impairments from received signals, yet the literature is inconsistent about where in the receiver chain those samples should be collected. Since distinct transformations are applied to the signal by the different receiver opeRadio Frequency Fingerprint Identification (RFFI) enables transmitter identification at the physical layer by learning device-specific impairments from received signals, yet the literature is inconsistent about where in the receiver chain those samples should be collected. Since distinct transformations are applied to the signal by the different receiver operations, i.e., carrier recovery, gain normalization, pulse shaping, and timing recovery, they can either tighten within-transmitter variability or suppress the features RFFI requires for classification. We present a systematic real-world evaluation of open-set, reconstruction-error RFFI using data collected at five probe points along a standard BPSK receiver chain. Our results show that RFFI is strongly probe-dependent: timing recovery and, to a lesser extent, carrier recovery enable low false-acceptance operation with limited in-distribution-out-of-distribution overlap, whereas other stages often require a false-acceptance ratio above 0.1 to achieve a true-acceptance ratio of 0.9. To test the validity of our findings across model selection, we benchmark several LLM-designed autoencoders using a controlled pipeline that holds preprocessing and MSE scoring fixed. These architectures confirm that RFFI is probe-dependent. Moreover, they do not outperform the baseline at the chosen operating point and typically increase training time. Overall, probe selection dominates reconstruction-based open-set RFFI performance, more than the autoencoder complexity.扩展字段
{ "arxiv_id": "2607.21564v1", "authors": [ "Gabriele Oligeri", "Savio Sciancalepore", "Ingrid Huso", "Fatima Al-Mousawi" ], "categories": [ "cs.CR" ], "comment": "10 pages, 8 figures", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21564v1", "pdf_url": "https://arxiv.org/pdf/2607.21564v1", "primary_category": "cs.CR", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T17:48:38+00:00" } -
Unconditional Unclonable Encryption
We give an unconditional construction of information-theoretically secure one-time private-key unclonable encryption scheme for one-bit messages, with efficient encryption and decryption and exponentially small unclonable-indistinguishability advantage.
We give an unconditional construction of information-theoretically secure one-time private-key unclonable encryption scheme for one-bit messages, with efficient encryption and decryption and exponentially small unclonable-indistinguishability advantage.We give an unconditional construction of information-theoretically secure one-time private-key unclonable encryption scheme for one-bit messages, with efficient encryption and decryption and exponentially small unclonable-indistinguishability advantage.扩展字段
{ "arxiv_id": "2607.21551v1", "authors": [ "Prabhanjan Ananth", "Amit Sahai" ], "categories": [ "quant-ph", "cs.CR" ], "comment": null, "doi": null, "entry_id": "https://arxiv.org/abs/2607.21551v1", "pdf_url": "https://arxiv.org/pdf/2607.21551v1", "primary_category": "quant-ph", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T17:35:44+00:00" } -
Themis Consensus Extension v1: MEV Mitigation by Randomized Delayed Execution and Intent-Hiding Transactions in Application-Specific Blockchains
Maximal extractable value (MEV) arises when privileged participants select, exclude, insert, or reorder pending transactions for private gain. We specify and analyze the Themis Consensus Extension v1, first published by Mangata in 2021. The design separates value extraction by reordering (VER) from value extraction by denial (VED). For VER, block constructio…
Maximal extractable value (MEV) arises when privileged participants select, exclude, insert, or reorder pending transactions for private gain. We specify and analyze the Themis Consensus Extension v1, first published by Mangata in 2021. The design separates value extraction by reordering (VER) from value extraction by denial (VED). For VER, block constructioMaximal extractable value (MEV) arises when privileged participants select, exclude, insert, or reorder pending transactions for private gain. We specify and analyze the Themis Consensus Extension v1, first published by Mangata in 2021. The design separates value extraction by reordering (VER) from value extraction by denial (VED). For VER, block construction and execution occur across consecutive producers: one producer commits a transaction set, and the next derives a publicly verifiable, deterministic, previously un- predictable seed and executes a seed-determined, dependency-preserving permutation. For selective VED, a user may encrypt a transaction for a designated builder and executor. The builder removes an outer layer and commits the opaque inner ciphertext; the executor reveals and executes the plaintext only after commitment. Under selfish but non-colluding validators, an adversary below the underlying consensus fault threshold, secure cryptography, and accountable role performance, the construction limits unilateral post-commit ordering control and hides transaction intent from relays and the builder. It does not provide send-order or receive-order fairness, complete censorship resistance, resistance to builder-executor collusion, or per-transaction price guarantees. We analyze probabilistic extraction, spam, dependent transactions, decryption liveness, session boundaries, total denial, and threshold coalitions. We also document the initial Aura-based Substrate implementation and its subsequent transition to a BABE-based sr25519/VRF seed path, together with delayed execution, Fisher-Yates shuffling, and Xoshiro256++. The result preserves the original proposal while narrowing its claims to explicit assumptions.扩展字段
{ "arxiv_id": "2607.21406v1", "authors": [ "Shoeb Siddiqui", "Mateusz Nowakowski", "Stanislav Vozarik", "Gleb Urvanov", "Peter Kris" ], "categories": [ "cs.CR" ], "comment": "20 pages,2 figures", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21406v1", "pdf_url": "https://arxiv.org/pdf/2607.21406v1", "primary_category": "cs.CR", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T15:05:09+00:00" } -
Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesis, preliminary formal model, and proof-of-concept implementation
Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable polic…
Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policAutonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This paper hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted $R_{CVA}$, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems (a distinction {not explicitly addressed by} current agentic security frameworks) and present a falsifiable research agenda for its resolution.扩展字段
{ "arxiv_id": "2607.21325v1", "authors": [ "M. Llambí-Morillas", "D. Fernández-Fernández" ], "categories": [ "cs.CR", "cs.AI" ], "comment": "11 pages, 1 figure, 2 Tables. Keywords: autonomous AI agents, zero-knowledge proofs, verifiable authorization, agentic security, zk-SNARKs, access control, cryptographic authorization, cryptographic protocols, zero-trust architecture, pre-execution authorization. Submitted to ACM Transactions on AI Security and Privacy (TAISAP)", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21325v1", "pdf_url": "https://arxiv.org/pdf/2607.21325v1", "primary_category": "cs.CR", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T13:55:02+00:00" } -
Advances in STV Margin Computation
Single transferable vote (STV) is a multi-winner preferential proportional electoral system. The margin is the smallest number of ballots that need to be manipulated to alter the set of winners. If we can compute the margin of an STV election, or a reasonable lower bound on the margin, we can use recent advances in auditing research to conduct a risk-limitin…
Single transferable vote (STV) is a multi-winner preferential proportional electoral system. The margin is the smallest number of ballots that need to be manipulated to alter the set of winners. If we can compute the margin of an STV election, or a reasonable lower bound on the margin, we can use recent advances in auditing research to conduct a risk-limitinSingle transferable vote (STV) is a multi-winner preferential proportional electoral system. The margin is the smallest number of ballots that need to be manipulated to alter the set of winners. If we can compute the margin of an STV election, or a reasonable lower bound on the margin, we can use recent advances in auditing research to conduct a risk-limiting audit of the election's winners. Knowledge of the margin also provides insight into whether uncovered mistakes, or a known error rate in ballot interpretation, could have influenced the outcome. This paper presents substantial improvements on an existing algorithm for computing lower bounds on the margin of an STV election. These improvements allow us to compute higher lower bounds for real STV elections, making mismatch-based risk-limiting audits more practical.扩展字段
{ "arxiv_id": "2607.21178v1", "authors": [ "Michelle Blom", "Alexander Ek", "Peter J. Stuckey", "Vanessa Teague", "Damjan Vukcevic" ], "categories": [ "cs.GT", "cs.CR", "cs.CY" ], "comment": "19 pages, accepted for E-Vote-ID 2026", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21178v1", "pdf_url": "https://arxiv.org/pdf/2607.21178v1", "primary_category": "cs.GT", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T11:08:52+00:00" } -
Agree on the Model, Verify the Inference: GKR Protocols for HND-Based Transformer Inference
Outsourced Transformer inference exposes clients to model substitution and incomplete execution, while direct replay removes the computational benefit of delegation. We present GKR-HND, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers. The retained verifier checks the GKR transcript a…
Outsourced Transformer inference exposes clients to model substitution and incomplete execution, while direct replay removes the computational benefit of delegation. We present GKR-HND, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers. The retained verifier checks the GKR transcript aOutsourced Transformer inference exposes clients to model substitution and incomplete execution, while direct replay removes the computational benefit of delegation. We present GKR-HND, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers. The retained verifier checks the GKR transcript and registered-weight openings, but delegates expensive public evaluations to an assigned computation worker. Assuming an honest retained verifier and prover--worker non-collusion, the verifier accepts only when the worker's signed, request-bound response agrees with the proof claims. Experiments with pretrained HND models validate the proof path and the delegated public computation without dense-matrix replay.扩展字段
{ "arxiv_id": "2607.21162v1", "authors": [ "Xiaolong Liang", "Juanjuan Li", "Rui Qin", "Yisheng Lv" ], "categories": [ "cs.LG", "cs.CR" ], "comment": "24 pages, including 4 pages of supporting information; 2 figures", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21162v1", "pdf_url": "https://arxiv.org/pdf/2607.21162v1", "primary_category": "cs.LG", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T10:52:53+00:00" } -
Risk-Limiting Audits for Parliamentary Majorities
Existing methods for risk-limiting audits typically focus on certifying individual contests. In parliamentary elections, however, the politically relevant outcome is often whether a party has won enough seats to form government, not whether every reported seat outcome is correct. Extending on the work of Mohanty et al. (2019), we formulate the certification …
Existing methods for risk-limiting audits typically focus on certifying individual contests. In parliamentary elections, however, the politically relevant outcome is often whether a party has won enough seats to form government, not whether every reported seat outcome is correct. Extending on the work of Mohanty et al. (2019), we formulate the certificationExisting methods for risk-limiting audits typically focus on certifying individual contests. In parliamentary elections, however, the politically relevant outcome is often whether a party has won enough seats to form government, not whether every reported seat outcome is correct. Extending on the work of Mohanty et al. (2019), we formulate the certification of a parliamentary majority as a partial conjunction testing problem: it is enough to verify that the reported winning party truly won at least a majority of its reported seats. Building on the SHANGRLA auditing framework, we construct a sequential audit statistic for the majority outcome by combining seat-level statistics. We then propose adaptive sampling strategies that allocate auditing effort across seats, including variants that learn to avoid spending excessive effort on seats that appear unlikely to have been truly won. Using simulations based on synthetic and real data, from the 2014 Indian Lok Sabha election, we show that auditing the parliamentary majority can substantially reduce the number of ballots inspected (by almost a thousand-fold) compared to certifying every reported winning seat.扩展字段
{ "arxiv_id": "2607.21082v1", "authors": [ "Jack Freestone", "Dennis Leung", "Damjan Vukcevic" ], "categories": [ "stat.AP", "cs.CR", "cs.CY", "stat.ME" ], "comment": "22 pages, 7 figures, accepted for E-Vote-ID 2026", "doi": null, "entry_id": "https://arxiv.org/abs/2607.21082v1", "pdf_url": "https://arxiv.org/pdf/2607.21082v1", "primary_category": "stat.AP", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T09:12:07+00:00" } -
Weak Private Information Retrieval for Graph-based Storage
A distributed storage system with graph-based replication consists of a collection of databases and the files they contain. The databases (or servers) are represented as the vertices of a graph, while each file is stored in a distinct pair of servers and is represented by an edge of this graph. Private information retrieval (G-PIR) on such a graph-based stor…
A distributed storage system with graph-based replication consists of a collection of databases and the files they contain. The databases (or servers) are represented as the vertices of a graph, while each file is stored in a distinct pair of servers and is represented by an edge of this graph. Private information retrieval (G-PIR) on such a graph-based storA distributed storage system with graph-based replication consists of a collection of databases and the files they contain. The databases (or servers) are represented as the vertices of a graph, while each file is stored in a distinct pair of servers and is represented by an edge of this graph. Private information retrieval (G-PIR) on such a graph-based storage system involves a client which seeks to retrieve a desired file via a query-response protocol, without leaking the identity of the desired file index to any database. The goal of G-PIR is to maximize the rate (reciprocal of the total normalized download) under the privacy constraint. Prior work on G-PIR has involved perfect information-theoretic privacy (i.e., null leakage). However, if the privacy constraint is relaxed, then PIR protocols could be designed that have even higher rates. We term such protocols as Graph-based Weak Private Information Retrieval (G-WPIR) protocols and initiate their formal study in this work. We propose a G-WPIR scheme for arbitrary graphs, and identify the trade-offs it achieves between rate and privacy, under two well known leakage metrics: mutual information leakage and maximal leakage. Our protocol employs minimal subpacketization (representing a file-size constraint) and employs a simple probabilistic query realization to obtain the smooth trade-off. We extend this protocol with some modifications to two special classes of graphs, the complete graphs and the complete bipartite graphs, and identify the corresponding rate-privacy trade-offs achieved.扩展字段
{ "arxiv_id": "2607.21014v1", "authors": [ "Shodasakshari Vidya", "Chandan Anand", "Prasad Krishnan" ], "categories": [ "cs.IT", "cs.CR" ], "comment": null, "doi": null, "entry_id": "https://arxiv.org/abs/2607.21014v1", "pdf_url": "https://arxiv.org/pdf/2607.21014v1", "primary_category": "cs.IT", "search_query": "cat:cs.CR", "updated_at": "2026-07-23T07:55:59+00:00" }