A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems
arXiv:2606. 31639v1 Announce Type: cross Abstract: Large language models are no longer only text generators.
arXiv:2607. 16175v1 Announce Type: cross Abstract: Connected and Autonomous Vehicles (CAVs) rely on interconnected software and hardware components, including sensors, Electronic Control Units, in-vehicle infotainment systems, and telematics units, where vulnerabilities can compromise assets, users, and vehicle operations.
arXiv:2606. 31639v1 Announce Type: cross Abstract: Large language models are no longer only text generators.
SPADE is a labelled, multi‑modal, simulation‑based dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. It contains 1.89 million timestep records generated by injecting six classes of application‑layer attacks and one benign class into the SAE J2735 SPaT protocol, across multiple intersection geometries, operating conditions, and random seeds. Each record fuses SPaT fields, onboard camera confidence scores, and cooperative V2V peer data into 40 features, enabling deep‑learning intrusion detection systems to distinguish deliberate attacks from environmental noise.
arXiv:2608. 10530v1 Announce Type: cross Abstract: Large Language Models (LLMs) have undergone a shift from stateless conversational interfaces to autonomous agents capable of multi-step planning, tool invocation, code execution, and maintaining persistent memory.
The paper introduces SPADE, a labelled, multi‑modal dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. Generated via Eclipse MOSAIC, SPADE includes 1.89 million timestep records across six attack classes and one benign class, combining SPaT fields, camera confidence scores, and V2V peer data over 40 features. The dataset, along with generation code and scenario configurations, is publicly released on GitHub to enable reproducible deep‑learning intrusion detection research in C‑V2X security.
The paper proposes a neurosymbolic defense architecture for AI-enhanced Security Operations Centers (AI‑SOCs) that protects against indirect prompt injection via log poisoning. It combines deterministic SIEM decoders as a pre‑filter with NeMo Guardrails for semantic validation, and adds a closed‑loop telemetry system for Human‑in‑the‑Loop visibility. Experimental results mapped to the MITRE ATLAS taxonomy show the approach effectively dismantles promptware kill chains and delivers a resilient, observable defense for next‑generation AI‑SOCs.
arXiv:2608. 13450v1 Announce Type: cross Abstract: Autonomous vehicles depend on large safety-critical software stacks, where weaknesses reachable from adversarial inputs may affect steering, braking, or other control decisions.
arXiv:2608. 04065v1 Announce Type: cross Abstract: Vehicle-to-everything (V2X) systems increasingly incorporate large language models (LLMs) for semantic tasks such as message summarization, operator assistance, and decision support at roadside units and edge nodes.
arXiv:2608. 07808v1 Announce Type: cross Abstract: Four years after prompt injection was first identified in 2022, attacks are still predominantly documented as verbatim strings rather than structured exploits, despite advancing agent capabilities and threat actors embedding injections to subvert AI-assisted security analysis.
arXiv:2510. 15476v3 Announce Type: replace-cross Abstract: Large Language Models (LLMs) are increasingly used as interfaces to information, code, and real-world services, making prompt-level security failures a practical concern.
arXiv:2608.23181v1 Announce Type: cross Abstract: As large language models (LLMs) continue to advance in coding capabilities, their potential in cybersecurity has drawn increasing research attention,...
arXiv:2607. 19742v1 Announce Type: cross Abstract: Cyber Threat Intelligence (CTI) reports richly describe real-world attack processes, but their unstructured narratives cannot be directly used for automated attack-path reasoning.
arXiv:2609.23894v1 Announce Type: cross Abstract: Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other ag...