arXiv Machine Learning

Wireless Backdoor Attack and Defense for Semantic Communications over Multiple Access Channel

arXiv:2606. 30595v1 Announce Type: cross Abstract: Semantic communication (SemCom) aims to preserve semantic meaning and task-oriented information beyond conventional message recovery over wireless channels.

arXiv AI
Jul 21

Signal-based Model Access Risk Analysis for AI System Operations Security

arXiv:2607. 16414v1 Announce Type: cross Abstract: Artificial intelligence (AI) systems are now ubiquitous across domains such as security, finance, healthcare, consumer technology, and large-scale cloud services, where they process massive volumes of data and make consequential decisions daily.

By Maria Mahbub, Steven Young, Amir Sadovnik, Edmon Begoli, Chris Rugenstein, Donald Coulter, Anthony Ayodele
arXiv Machine Learning
Sep 25

Diffusion-aided Task-oriented Semantic Communications with Model Inversion Attack

The paper introduces DiffSem, a diffusion-based approach for task‑oriented semantic communications that splits the diffusion process between transmitter‑side self‑noising and receiver‑side reverse denoising. It addresses privacy concerns by reducing model‑inversion attacks while preserving task accuracy, as demonstrated on MNIST, CIFAR‑10, and CelebA datasets. The method achieves higher task performance without enlarging transmitted feature size or increasing semantic leakage.

By Xuesong Wang, Mo Li, Xingyan Shi, Zhaoqian Liu, Shenghao Yang
arXiv AI
Sep 12

Architecting the Secure AI-SOC: A Neurosymbolic Framework for Pipeline Integrity and Threat Mitigation

The paper proposes a neurosymbolic defense architecture for AI-enhanced Security Operations Centers (AI‑SOCs) that protects against indirect prompt injection via log poisoning. It combines deterministic SIEM decoders as a pre‑filter with NeMo Guardrails for semantic validation, and adds a closed‑loop telemetry system for Human‑in‑the‑Loop visibility. Experimental results mapped to the MITRE ATLAS taxonomy show the approach effectively dismantles promptware kill chains and delivers a resilient, observable defense for next‑generation AI‑SOCs.

By Anna Gazani, Spyridon Kounoupidis, Panagiotis Katsaros, Nikolaos Kekatos, Grigorios Tsoumakas, Georgios Koutidis
arXiv AI
2d ago

Backdoor Containment via Expert Quarantine and Shutdown in LLMs

The paper introduces Quarantined Expert Shutdown (QES), a new backdoor containment strategy for large language models. QES allows backdoor learning to occur during training but routes it into a designated, quarantined expert that can be disabled at deployment. The method achieves significant reductions in attack success rates while largely preserving model utility.

By Jianwei Li, Min-Seon Kim, Jung-Eun Kim
arXiv Computation and Language
Aug 27

A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots

The paper introduces a three‑layer security framework designed to protect retrieval‑augmented generation (RAG) chatbots from both direct and indirect prompt injection attacks. Layer 1 filters user input with rule‑based patterns and a semantic anomaly classifier; Layer 2 enforces a provenance‑based instruction hierarchy during context assembly; Layer 3 audits model output with a policy rule engine and semantic drift detector. Evaluations on GPT‑4o, Llama 3, and Mistral 7B demonstrate a reduction in attack success rate from 71.4 % to 11.3 %, outperforming existing single‑layer defenses while keeping false positives low and latency acceptable.

By Gulshan Saleem, Nisar Ahmed, Muhammad Imran Zaman, Ali Hassan, Umar Mujahid