.- LLM and Agent Security .
.- EvoJudge: Confidence-Aware Rule Evolution for LLM Safety Auditing.
.- Patching the Ground: Representation-and-Generation Attacks on Dangerous-Object Grounding in MLLMs.
.- LLM-ETKG: Event-Centric and Evidence-Grounded Knowledge Graph Construction for Cyber Threat Intelligence.
.- Small Models, Big Variances: Unveiling the Impact of Execution Environments on SLMs’ Security.
.- SCOUT: Structural Coverage-Guided Diffusion for Testing Deep Classifiers.
.- WhalingX: A Concurrent Multi-Agent Penetration Testing Framework via BDI Cognition and Queuing Theory.
.- Cat-and-Mouse Game: AI Agents for URL Merging of Magnet Link Search Websites.
.- MIST: Malicious In-Distribution Stealth Attack on LLMs via Benign Interspersion.
.- When Facts Mislead: Defeating Search-Augmented Multi-Agent Debate via Factual Persuasion.
.- Structured Decomposition for Reliable LLM-Generated Access Control Policies.
.- SSIB: A Security-Centric Benchmark and Multi-Agent Framework for Detecting Stablecoin-Specific Vulnerabilities.
.- PriMedLLM: A TEE-Based Secure Mediation Framework for Privacy-Preserving LLM Training and Inference.
.- Composable CVE-Component Catalogs for Open-Source LLM-Driven Cyber Range Generation with Two-Tier Verification.
.- Vulnerability Detection and Fuzzing .
.- When Secrets Get Committed: The role of code platforms in avoiding secret leakage.
.- LAPSE: Guided Program-Slice Representations for Project-Level Vulnerability Triage
.- LAVD: Cross-Project Vulnerability Detection via Layer-Fading and Logical Alignment.
.- Exploring Function-Level Vulnerability Detection with Vulnerability Intelligence-Enhanced LLMs.
.- Hidden Ciphers and Where to Find Them: Static Discovery and Assessment of Cryptographic Assets in Software.
.- Edge-Aware Heterogeneous Graph Transformer for Source Code Vulnerability Detection.
.- Toward Comprehensive Cryptographic API Misuse Detection: Fine-tuning Discriminative LLMs on Sliced Code Snippets.
.- DUFuzz: Define-Use Chain Guided Fuzzing for RESTful API Vulnerability Discovery.
.- PrivEscope: Systematic Detection of Privilege Escalation Paths in Database Management Systems.
.- Cross-ISA Heterogeneous Component Generation and Endogenous Security Enhancement via Code Segmented Compilation.
.- Web, Mobile and Supply Chain Security .
.- Beyond Isolated Phishing Emails: Discovering Hidden Campaign Relationships with MCDA.
.- Nephology: Characterizing the Security of Base Images across Cloud Providers.
.- HostCFI: Host-Side Control-Flow Integrity for Unmodified Guest Kernels in Cloud Environments.
.- Security Weaknesses and Privacy Leakage in Mini-apps: An Analysis Based on Structural, Behavioral, and Indicators.
.- Reliability Analysis for Multi-Cloud Auditing Systems.
.- Security Measurement and Systematization .
.- Unveiling the Sentinels: Assessing AI Performance in Cybersecurity Peer Review.
.- Towards Personalized Information Security Awareness: A User-, Riskand Context-Based Framework Enhanced by Artificial Intelligence.
.- Semantic Capabilities and Limitations of Detection Rule Languages: A Systematization of Knowledge.
.- An Empirical Measurement Study of Authentication Mechanisms in Cloud-Based Password Managers.
.- Malware and Binary Analysis .
.- Seeing Through Compression: Static Detection of Packed IoT Malware.
.- FRIME-TCN: A Feature-Adaptive RIME Optimization Framework for Efficient Network Intrusion Detection.
.- OP-UMKL: Ordinality-Preserving Unsupervised Multi-Kernel Learning for Provenance-Graph-based APT Detection.
.- GraceTI: A Graph Relation-Aware Contrastive Embedding Method for Threat Intelligence.
.- Lightweight IoT Malware Detection via Adaptive Federated Aggregation and Transformer Distillation for Network Traffic.
.- Rethinking Neural Decompilation: Candidate Selection as the Hidden Bottleneck.
.- BinCryptID: Semantic-Structural Identification of Cryptographic Functions in Stripped Binaries.
.- RL-ChainGuard: Reinforcement Learning-based Evidence Chain Selection for Explainable Malware Detection.