pith:JNPW5ZCV
Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators
AI accelerators on edge devices can be tricked by apps into performing privileged operations outside OS control.
arxiv:2605.17707 v1 · 2026-05-18 · cs.CR
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{JNPW5ZCVLQFBMNE23LTTCL7OVL}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
CDA is feasible on six out of the seven AIAs, impacting over 128 System On Chips (SOCs) and over 100 million devices.
The DeputyHunt framework, combining LLM-assisted dynamic and static analysis, correctly identifies exploitable confused deputy paths without substantial false positives or missed cases on the tested accelerators.
An empirical security study shows confused deputy attacks are practical on most edge AI accelerators via a new LLM-assisted analysis framework, with vendor-confirmed impact on over 100 million devices.
References
Formal links
Receipt and verification
| First computed | 2026-05-20T00:04:53.769666Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
4b5f6ee4555c0a16349adae7312feeaafcd340145d157f7bee39cb65a28613c2
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/JNPW5ZCVLQFBMNE23LTTCL7OVL \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 4b5f6ee4555c0a16349adae7312feeaafcd340145d157f7bee39cb65a28613c2
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "4fbc471209c6cad64cd6bbf3bf0cb2d3ac814263fdcd8371fec90506f6be1c66",
"cross_cats_sorted": [],
"license": "http://creativecommons.org/licenses/by-nc-sa/4.0/",
"primary_cat": "cs.CR",
"submitted_at": "2026-05-18T00:04:51Z",
"title_canon_sha256": "c4488fc7622779240b0c058d932caf06560075262822089783a00b8a2d905b77"
},
"schema_version": "1.0",
"source": {
"id": "2605.17707",
"kind": "arxiv",
"version": 1
}
}