New research on AI and security, selected for relevance to language models, AI agents and cybersecurity. Summaries are the authors’ or publisher’s own words, linked to the original.
Peer-reviewed
A deep learning-driven pipeline for differentiating hypertrophic cardiomyopathy from cardiac amyloidosis using 2D multi-view echocardiography
ProFormer: generalizable classification of single-cell and plasma proteomes using deep learning
Flexible discovery of disease-associated tissue structures
Accurate and well-powered case–control analysis of spatial molecular data
AI could undermine scientific independence in subtle ways
New preprints (not yet peer-reviewed)
Clouding the Mirror: Stealthy Prompt Injection Attacks Targeting LLM-based Phishing Detection
Phishing sites continue to increase in number and sophistication. Recent work uses large language models (LLMs) to analyze URLs, HTML, and rendered content and determine whether a website is a phishing site.
AgentSpy: Making AI Agent Behavior Observable
AI agents built on large language models (LLMs) run shell commands, read and write files, and reach the network, typically with their user's privileges. However, what an agent does during an execution is difficult to understand: tests assert on the result, and the agent's trajectory records only what the agent reports about itself, which may omit behavior executed by its subprocesses.
Characterizing Security Effects of OSS Vulnerabilities in Agent Systems
Software agents increasingly depend on open-source components when executing tools and interacting with external systems. Security flaws in these dependencies may therefore influence more than the software process in which they occur: their consequences can be carried through tool outputs, agent state, and information subsequently exposed to the model.
MLLMs Fail to Refuse when Using Tools Agentically
Agentic multimodal large language models (MLLMs) have recently pushed the frontier of visual reasoning by calling tools such as zooming and tagging. Despite the recent strong success of agentic MLLMs, this work uncovers a critical safety failure in the tool-use paradigm: agentic tool-using MLLMs become less capable of refusing harmful requests.
Beware EviLLM: Enabling Vulnerability Injection via Large Language Models
Advances in large language models (LLMs) have enabled AI-driven code generation from natural language specifications, introducing new attack surfaces for injecting vulnerabilities into software. Prior work has studied this problem only in benign settings where vulnerabilities are introduced inadvertently, or under unconventional threat models where the LLM itself is malicious (backdooring) or the user is the attacker (jailbreaking).
Self-Propagating Misalignment in LLM Agents, and Why Auditing or Disabling Memory Is Not Enough
Memory poisoning attacks on LLM agents typically assume an external adversary who plants content in the agent's persistent memory to steer its behavior. We instead study, with no adversary involved, whether a misaligned agent can write a goal it cannot yet act on to persistent memory, so that a future aligned agent carries it out when the opportunity arises.
Agentic-ZTA: A Multi-Agent Architecture for Autonomous Zero Trust Enforcement
Agentic AI is emerging as a promising paradigm for automating complex cybersecurity decisions, yet its use in enforcing zero trust introduces significant challenges in safety, reliability, and policy compliance. This paper presents Agentic AI based zero trust architecture (Agentic-ZTA) that operationalizes the NIST SP 800-207 ZTA architecture control loop through coordinated multi- agent decision pipeline.
Agent Policy-Value Audit: Separating Transition Composition from Event Selection in Financial LLM Agents
Financial LLM agents are often evaluated by comparing their end-to-end returns with those of a baseline and testing the paired difference against zero. This measures whether deploying the agent changes realized performance, but it does not isolate event-selection skill.
