Space secrets security update
Related stories
An update on our safety & security practices
An update on our safety & security practices
Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture
arXiv:2608. 06130v1 Announce Type: cross Abstract: AI agents performing cryptographic operations (signing Git commits, authenticating API calls, issuing certificates) currently store private keys in software-accessible locations: plaintext files, environment variables, or container memory.
2024 Security Feature Highlights
How Hugging Face Scaled Secrets Management for AI Infrastructure
STAR-FL: Secure Federated Learning with Spatial-Temporal Analysis and Robust Aggregation
arXiv:2608. 14861v1 Announce Type: cross Abstract: Data poisoning attacks pose serious security threats to Federated Learning (FL) systems in Computer Vision.
Privacy-Preserving AI Verification via Minimal Information Disclosure
arXiv:2608. 02774v1 Announce Type: cross Abstract: AI verification crosses a trust boundary: a verifier must learn enough to establish an authorized claim, yet the same evidence can reveal sensitive details about the model, workload, or hardware.
ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP
arXiv:2606. 27027v1 Announce Type: cross Abstract: With the rapid evolution of LLM-driven agents, Model Context Protocol (MCP), an open protocol bridging LLMs with external tools, has quickly become foundational to modern agent ecosystems.
Trusted access for the next era of cyber defense
OpenAI expands its Trusted Access for Cyber program, introducing GPT-5. 4-Cyber to vetted defenders and strengthening safeguards as AI cybersecurity capabilities advance.
Hide and Seek in Embedding Space: Geometry-based Steganography and Detection in Large Language Models
arXiv:2601. 22818v2 Announce Type: replace-cross Abstract: Fine-tuned LLMs can covertly encode prompt secrets into outputs via steganographic channels.
dstack-capsule: Pod-Level Remote Attestation for Confidential Workloads on Kubernetes
arXiv:2606. 03323v1 Announce Type: cross Abstract: The rise of LLM-as-a-Service and other confidential cloud workloads demands cryptographic proof that user data is processed in a trusted, untampered environment.