Elevator performs the first fully static, heuristic-free whole-program binary translation from x86-64 to AArch64 by exhaustively interpreting every byte and composing ISA-derived code tiles.
hub Canonical reference
Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability
Canonical reference. 88% of citing Pith papers cite this work as background.
hub tools
citation-role summary
citation-polarity summary
representative citing papers
Cerisier is the first mechanized program logic for modular reasoning about trusted, untrusted, and attested code in capability machines, with a universal contract for untrusted code and demonstrations on secure computation and mutual attestation.
SCARA introduces a four-stage pipeline using state-aware verification and constrained synthesis to remediate vulnerabilities in source-unavailable industrial software, reporting 100% precision and 88.9% success on a 15-case benchmark.
Quantitative partial equivalence analysis quantifies behavioral differences between original and patched programs via symbolic analysis and a range-based heuristic for numerical domains.
A low-stake adversary can degrade a liquid staking pool's performance via consensus manipulation and profit from the resulting drop in its LST value through application-layer financial positions.
A sound and complete deductive system for relative trace equality based on relative bisimulation is introduced, formalized in Rocq, and demonstrated on two contract satisfaction proofs.
Grassroots bonds add maturity dates to local cryptocurrencies to enable lending and other instruments via enforceable digital social contracts.
ConsentDiff enables longitudinal tracking of privacy policy churn and consent UI patterns, finding ongoing changes, shifts away from high-friction banners, and higher policy-UI alignment when rejection options are visible.
Flutter achieves 2Δ + ε good-case latency for Byzantine Total Order Broadcast via a new binary consensus called Blink, under partial synchrony with 5f+1 servers.
MemLineage enforces untrusted-path persistence in LLM agent memory through Merkle logs, per-principal signatures, and max-of-strong-edges lineage propagation, achieving zero ASR on three poisoning workloads with sub-millisecond overhead.
Google AI Overviews activate on 13.7% of queries overall and 64.7% of questions, cite more credible sources than standard results but omit key information in 11% of claims, and suppress clicks on over half of cited pages that carry ads.
PoisonCap uses a new poison capability format to deliver strict use-after-free and initialization safety for CHERI systems with no fundamental overhead over Cornucopia baselines.
BEACON is a large-scale multimodal dataset of synchronized Valorant esports gameplay data for behavioral fingerprinting and continuous authentication research.
Pomegranate compartmentalizes commodity OS kernels via virtualization extensions, sentry functions, and EPT-enforced policies, achieving negligible overhead on a Linux network stack when compartment boundaries limit cross-talk.
DeFi vault risk is decomposed into three levels with six on-chain mechanical features generating new loss channels, yielding five aggregated credit risk metrics and an on-chain estimation architecture.
An encoding of Solidity contracts and first-order Hennessy-Milner logic into Lustre enables Kind 2 model checking of complex temporal properties in smart contracts.
ARuleCon uses AI agents plus execution-based checks to convert SIEM rules across vendors with 15% higher fidelity than standard LLM translation.
Ledger-state stigmergy maps biological indirect coordination to blockchain ledgers via a state-transition formalism and three base patterns for on-chain agent coordination.
Structured CTI standards like ATT&CK describe adversary actions but lack the ordering, preconditions, and environmental details needed for direct multi-stage emulation, and a translation method can bridge this gap when assumptions are recorded.
NanoTag enables byte-granular overflow detection on unmodified MTE binaries by combining hardware tagging with selective software tripwire checks on the Scudo allocator.
Flipping 1-2 sign bits in DNN parameters, located without data or optimization, drops accuracy to near zero across image classification, detection, segmentation, and language models.
A longitudinal study of 46 CS students finds that configuring and using mTLS client certificates is difficult even for technical users, with only 9% understanding the security implications.
Physics-informed GNNs with four detector-aware graph constructions and a custom message passing layer achieve MAE 0.8525 for pT estimation on CMS trigger data with over 55% fewer parameters than baselines.
Longitudinal evaluation over yearly Android app slices shows temporal drift reduces adversarial robustness of malware detectors, with expanding-window retraining providing partial mitigation but not full recovery.
citing papers explorer
-
Deterministic Fully-Static Whole-Binary Translation without Heuristics
Elevator performs the first fully static, heuristic-free whole-program binary translation from x86-64 to AArch64 by exhaustively interpreting every byte and composing ISA-derived code tiles.
-
Cerisier: A Program Logic for Attestation in a Capability Machine
Cerisier is the first mechanized program logic for modular reasoning about trusted, untrusted, and attested code in capability machines, with a universal contract for untrusted code and demonstrations on secure computation and mutual attestation.
-
SCARA: A Semantics-Constrained Autonomous Remediation Agent for Opaque Industrial Software Vulnerabilities
SCARA introduces a four-stage pipeline using state-aware verification and constrained synthesis to remediate vulnerabilities in source-unavailable industrial software, reporting 100% precision and 88.9% success on a 15-case benchmark.
-
Quantitative Symbolic Patch Impact Analysis
Quantitative partial equivalence analysis quantifies behavioral differences between original and patched programs via symbolic analysis and a range-based heuristic for numerical domains.
-
Your Loss is My Gain: Low Stake Attacks on Liquid Staking Pools
A low-stake adversary can degrade a liquid staking pool's performance via consensus manipulation and profit from the resulting drop in its LST value through application-layer financial positions.
-
A Deductive System for Contract Satisfaction Proofs
A sound and complete deductive system for relative trace equality based on relative bisimulation is introduced, formalized in Rocq, and demonstrated on two contract satisfaction proofs.
-
Grassroots Bonds as a Foundation for Market Liquidity
Grassroots bonds add maturity dates to local cryptocurrencies to enable lending and other instruments via enforceable digital social contracts.
-
ConsentDiff at Scale: Longitudinal Audits of Web Privacy Policy Changes and UI Frictions
ConsentDiff enables longitudinal tracking of privacy policy churn and consent UI patterns, finding ongoing changes, shifts away from high-friction banners, and higher policy-UI alignment when rejection options are visible.
-
Fast Byzantine Total Order Broadcast
Flutter achieves 2Δ + ε good-case latency for Byzantine Total Order Broadcast via a new binary consensus called Blink, under partial synchrony with 5f+1 servers.
-
MemLineage: Lineage-Guided Enforcement for LLM Agent Memory
MemLineage enforces untrusted-path persistence in LLM agent memory through Merkle logs, per-principal signatures, and max-of-strong-edges lineage propagation, achieving zero ASR on three poisoning workloads with sub-millisecond overhead.
-
Measuring Google AI Overviews: Activation, Source Quality, Claim Fidelity, and Publisher Impact
Google AI Overviews activate on 13.7% of queries overall and 64.7% of questions, cite more credible sources than standard results but omit key information in 11% of claims, and suppress clicks on over half of cited pages that carry ads.
-
PoisonCap: Efficient Hierarchical Temporal Safety for CHERI
PoisonCap uses a new poison capability format to deliver strict use-after-free and initialization safety for CHERI systems with no fundamental overhead over Cornucopia baselines.
-
BEACON: A Multimodal Dataset for Learning Behavioral Fingerprints from Gameplay Data
BEACON is a large-scale multimodal dataset of synchronized Valorant esports gameplay data for behavioral fingerprinting and continuous authentication research.
-
Pomegranate: A Lightweight Compartmentalization Architecture using Virtualization Extensions
Pomegranate compartmentalizes commodity OS kernels via virtualization extensions, sentry functions, and EPT-enforced policies, achieving negligible overhead on a Linux network stack when compartment boundaries limit cross-talk.
-
Vault as a credit instrument
DeFi vault risk is decomposed into three levels with six on-chain mechanical features generating new loss channels, yielding five aggregated credit risk metrics and an on-chain estimation architecture.
-
KindHML: formal verification of smart contracts based on Hennessy-Milner logic
An encoding of Solidity contracts and first-order Hennessy-Milner logic into Lustre enables Kind 2 model checking of complex temporal properties in smart contracts.
-
ARuleCon: Agentic Security Rule Conversion
ARuleCon uses AI agents plus execution-based checks to convert SIEM rules across vendors with 15% higher fidelity than standard LLM translation.
-
Ledger-State Stigmergy: A Formal Framework for Indirect Coordination Grounded in Distributed Ledger State
Ledger-state stigmergy maps biological indirect coordination to blockchain ledgers via a state-transition formalism and three base patterns for on-chain agent coordination.
-
The Procedural Semantics Gap in Structured CTI: A Measurement-Driven STIX Analysis for APT Emulation
Structured CTI standards like ATT&CK describe adversary actions but lack the ordering, preconditions, and environmental details needed for direct multi-stage emulation, and a translation method can bridge this gap when assumptions are recorded.
-
NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTE
NanoTag enables byte-granular overflow detection on unmodified MTE binaries by combining hardware tagging with selective software tripwire checks on the Scudo allocator.
-
Maximal Brain Damage Without Data or Optimization: Disrupting Neural Networks via Sign-Bit Flips
Flipping 1-2 sign bits in DNN parameters, located without data or optimization, drops accuracy to near zero across image classification, detection, segmentation, and language models.
-
Understanding Student Experiences with TLS Client Authentication
A longitudinal study of 46 CS students finds that configuring and using mTLS client certificates is difficult even for technical users, with only 9% understanding the security implications.
-
Physics-Informed Graph Neural Networks for Transverse Momentum Estimation in CMS Trigger Systems
Physics-informed GNNs with four detector-aware graph constructions and a custom message passing layer achieve MAE 0.8525 for pT estimation on CMS trigger data with over 55% fewer parameters than baselines.
-
Adversarial Vulnerability Under Temporal Concept Drift: A Longitudinal Study of Android Malware Detection
Longitudinal evaluation over yearly Android app slices shows temporal drift reduces adversarial robustness of malware detectors, with expanding-window retraining providing partial mitigation but not full recovery.
-
Few-Shot Network Intrusion Detection Using Online Triplet Mining
A triplet network using online triplet mining and KNN classifier achieves competitive few-shot performance on network intrusion detection with as few as 10 malicious samples per class.
-
From Conceptual Scaffold to Prototype: A Standardized Zonal Architecture for Wi-Fi Security Training
A conceptual zonal architecture for Wi-Fi-focused cyber ranges with an open-source prototype implementing scenario generation and instantiation.
-
Compliance Management for Federated Data Processing
A prototype framework collects legal requirements and translates them into machine-actionable policies for federated data processing networks via policy-as-code and LLMs.
-
AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey
A literature survey synthesizes 119 studies on AI-driven alert screening into a four-stage taxonomy of filtering, triage, correlation, and generative augmentation while identifying gaps in deployment realism and robustness.
-
Data-Centric Foundation Models in Computational Healthcare: A Survey
The paper surveys data-centric strategies for foundation models in computational healthcare and supplies a curated list of related models and datasets.
-
Decoupling Identity from Utility: Privacy-by-Design Frameworks for Financial Ecosystems
Differentially private synthetic data and seeded agent-based models can separate personal identities from usable financial data while meeting regulatory privacy rules.
- PrivacyMotiv: Vulnerability-Centered Persona Journeys for Empathic Privacy Reviews in UX Design