A new 507-leaf taxonomy and 4x6 Target x Technique matrix audits six LLM attack benchmarks and finds they cover at most 25% of the threat surface with entire STRIDE categories untested.
In: Proceedings of the 2017 ACM on Asia Con- ference on Computer and Communications Security
7 Pith papers cite this work, alongside 53 external citations. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
roles
background 2representative citing papers
Coordinated multi-client attacks bypass single-client defenses like PRADA in model extraction, demonstrated via the new CerberusAI simulation framework, requiring stateful identity-independent defenses.
DECKER is a domain-invariant four-stage framework (keyboard normalization, adversarial disentanglement, cross-keyboard contrastive alignment, acoustic style randomization) plus LLM post-processing that improves keystroke inference over baselines on the new HEAR dataset, especially in cross-keyboard
Introduces CADEX to generate domain-constrained counterfactual explanations for ML models using adversarial perturbations.
Longitudinal evaluation over yearly Android app slices shows temporal drift reduces adversarial robustness of malware detectors, with expanding-window retraining providing partial mitigation but not full recovery.
NTGA is the first clean-label generalization attack under black-box settings but is vulnerable to adversarial training and image transformations, with newer attacks outperforming it.
A literature survey synthesizes 119 studies on AI-driven alert screening into a four-stage taxonomy of filtering, triage, correlation, and generative augmentation while identifying gaps in deployment realism and robustness.
citing papers explorer
-
Talk is (Not) Cheap: A Taxonomy and Benchmark Coverage Audit for LLM Attacks
A new 507-leaf taxonomy and 4x6 Target x Technique matrix audits six LLM attack benchmarks and finds they cover at most 25% of the threat surface with entire STRIDE categories untested.
-
AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses
Coordinated multi-client attacks bypass single-client defenses like PRADA in model extraction, demonstrated via the new CerberusAI simulation framework, requiring stateful identity-independent defenses.
-
DECKER: Domain-invariant Embedding for Cross-Keyboard Extraction and Recognition
DECKER is a domain-invariant four-stage framework (keyboard normalization, adversarial disentanglement, cross-keyboard contrastive alignment, acoustic style randomization) plus LLM post-processing that improves keystroke inference over baselines on the new HEAR dataset, especially in cross-keyboard
-
Explaining Deep Learning Models with Constrained Adversarial Examples
Introduces CADEX to generate domain-constrained counterfactual explanations for ML models using adversarial perturbations.
-
Adversarial Vulnerability Under Temporal Concept Drift: A Longitudinal Study of Android Malware Detection
Longitudinal evaluation over yearly Android app slices shows temporal drift reduces adversarial robustness of malware detectors, with expanding-window retraining providing partial mitigation but not full recovery.
-
SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions
NTGA is the first clean-label generalization attack under black-box settings but is vulnerable to adversarial training and image transformations, with newer attacks outperforming it.
-
AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey
A literature survey synthesizes 119 studies on AI-driven alert screening into a four-stage taxonomy of filtering, triage, correlation, and generative augmentation while identifying gaps in deployment realism and robustness.