Library

Subject
Tags

Web Application Security Vulnerabilities

#
001Prompting Rules That Reduce Codex Mojibake Accidents on Windows (archived 2026-07-27)OpenAlexPaperGo Komura5 days ago
002Prompting Rules That Reduce Codex Mojibake Accidents on Windows (archived 2026-07-27)OpenAlexPaperGo Komura5 days ago
003Agents reading web pages, emails and repository files are hijacked by prompt injections hidden in untrusted content, yet 2026 benchmarks show deployed guards over-block benign text, making them unusable inline. A naive single prompt asking a base model whether text is an injection fails because without the agent's declared task it cannot separate legitimate imperative content, such as a README's install instructions, from instructions subverting the agent, returning a bare score with no offending span or operating point. Evaluate a task-conditioned LLM judge seeing the declared task and permitted capabilities alongside the untrusted output, using constrained structured decoding to emit is_injection, targeted_capability, quoted span and confidence, retrieving injection patterns for few-shot grounding, and applying a threshold calibrated on a benign corpus with self-consistency voting. Measure ROC-AUC, recall at sub-one-percent false-positive rate, span-localization precision and Brier calibration on AgentDojo-style labeled attack traces plus held-out benign corpora, beating a naive single-prompt base-model classifier and a Llama-Guard-style guardrail. Deliver as the prototype a minimal runnable Python MCP server (stdio) exposing the priced AI tool screen_tool_output that invokes a language or ML model to produce its output, with a typed input/output schema, an x402-style pay-per-call metering stub that records a per-call price in USDT and emits a settlement receipt, and one smoke test that exercises the tool end to end.OpenAlexPaperDogukan Ali GundoganJul 24
004Agents reading web pages, emails and repository files are hijacked by prompt injections hidden in untrusted content, yet 2026 benchmarks show deployed guards over-block benign text, making them unusable inline. A naive single prompt asking a base model whether text is an injection fails because without the agent's declared task it cannot separate legitimate imperative content, such as a README's install instructions, from instructions subverting the agent, returning a bare score with no offending span or operating point. Evaluate a task-conditioned LLM judge seeing the declared task and permitted capabilities alongside the untrusted output, using constrained structured decoding to emit is_injection, targeted_capability, quoted span and confidence, retrieving injection patterns for few-shot grounding, and applying a threshold calibrated on a benign corpus with self-consistency voting. Measure ROC-AUC, recall at sub-one-percent false-positive rate, span-localization precision and Brier calibration on AgentDojo-style labeled attack traces plus held-out benign corpora, beating a naive single-prompt base-model classifier and a Llama-Guard-style guardrail. Deliver as the prototype a minimal runnable Python MCP server (stdio) exposing the priced AI tool screen_tool_output that invokes a language or ML model to produce its output, with a typed input/output schema, an x402-style pay-per-call metering stub that records a per-call price in USDT and emits a settlement receipt, and one smoke test that exercises the tool end to end.OpenAlexPaperDogukan Ali GundoganJul 24
005VirtualSet: Typed Ontology Worlds as an LLM Generation Target for Grounded Queries and Guarded DecisionsOpenAlexPaperQunhui ZhangJul 21
006VulGen: Workshop on Vulnerabilities in Generative Systems for Information RetrievalOpenAlexPaperShuoqi Sun, Sara Fahad Dawood Al Lawati et al.Jul 10
007RAG ile kurumsal yapay zekâ asistanı geliştirmek: Bir öğrenci destek hizmetleri asistanı örneğiOpenAlexPaperFatma Topuz Eryürük, Mehmet FıratJul 6
008Research - Totp Vault AuthenticatorOpenAlexPaperLois-Kleinner AlpasanJun 20
009Research - Totp Vault AuthenticatorOpenAlexPaperLois-Kleinner AlpasanJun 20
010SMTQuery: A novel tool for analyzing SMT-LIB string benchmarksOpenAlexPaperMitja Kulczynski, Kevin Lotz et al.Jun 19
011Adversarial AI Evaluating Prompt Injection Vectors for Cyber Reconnaissance in Indian Governance InfrastructureOpenAlexPaperSaranyo DeyasiJun 18
012Adversarial AI Evaluating Prompt Injection Vectors for Cyber Reconnaissance in Indian Governance InfrastructureOpenAlexPaperSaranyo DeyasiJun 18
013AltayDuel: A Turkish-First Arena and Open Dataset for Multi-Turn LLM Prompt-Injection Red-TeamingOpenAlexPaperFevzi Ege YurtsevenlerJun 13
014AltayDuel: A Turkish-First Arena and Open Dataset for Multi-Turn LLM Prompt-Injection Red-TeamingOpenAlexPaperFevzi Ege YurtsevenlerJun 13
015XMR: Exact Match Recovery for Evaluating Text Normalization Against Adversarial Unicode AttacksOpenAlexPaperRichard QuinnJun 9
016Rule-Based SQL Grammar ValidatorOpenAlexPaperSyahrul Fajar Laqsono, Agung Prasetya et al.Jun 6
017Evaluating Prompt Injection Defenses in Large Language Models: A Multi-Model Empirical Study of Security–Usability Trade-offsOpenAlexPaperRobert KempMay 31
018AI-Assisted Vulnerability Discovery and Reporting: Reliability Challenges, Security Risks, and Future DirectionsOpenAlexPaperShaik Mohammad Yasin, Kalisetti Venkatesh et al.May 29
019The Summarization Trap: Quantifying Role-Based Vulnerabilities and Lexical Hijacking in RAG PipelinesOpenAlexPaperAswin Balaji Aswin BalajiMay 24
020The Summarization Trap: Quantifying Role-Based Vulnerabilities and Lexical Hijacking in RAG PipelinesOpenAlexPaperAswin Balaji Aswin BalajiMay 24
021SQLsaber: Agentic SQL Assistant for Efficient and High-Accuracy Natural Language Database ExplorationOpenAlexPaperSarthak JariwalaMay 22
022Data extraction dataset for a systematic literature review on prompt-based attacks and defenses in Large Language ModelsOpenAlexPaperVictória Guimarães, Débora da Costa Medeiros et al.May 21
023Data extraction dataset for a systematic literature review on prompt-based attacks and defenses in Large Language ModelsOpenAlexPaperVictória Guimarães, Débora da Costa Medeiros et al.May 21
024Cyber Range Ethical Pretesting And Reporting PlatformOpenAlexPaperAzhar KhanMay 20
025Cyber Range Ethical Pretesting And Reporting PlatformOpenAlexPaperAzhar KhanMay 20
026Dialect-Agnostic SQL Parsing via LLM-Based SegmentationOpenAlexPaperJunwen An, Kabilan Mahathevan et al.May 18
027Intelligent Resume Generation Using Generative AI and Full-Stack Web TechnologiesOpenAlexPaperAnmoldeep Chauhan, Manju Lata, Rajendra SinghMay 14
028FlexPDF: Unveiling the Potential of Client-Side Web Technologies for Privacy-Preserving Document and Image ProcessingOpenAlexPaperPranjal SrivastavaMay 8
029GLITCH_AI: A Hybrid Framework for Automated Penetration Testing with LLM-Driven Adaptation and ReportingOpenAlexPaperMaria Gonzalez Herrero, Amit Kumar Singh et al.May 8
030From Ambiguous Queries to Verifiable Insights: A Task‐Driven Framework for LLM‐Powered SOC Analysis <sup>⋆</sup>OpenAlexPaperH ZHANG, Haiyan Wang et al.May 4
031SynSQL: Synthesizing Relational Databases for Robust Evaluation of Text-to-SQL SystemsOpenAlexPaperMohammadamin Habibollah, Davood RafieiApr 29
032Leveraging Large Language Models for Advanced Penetration Testing and Vulnerability AnalysisOpenAlexPaperShreyansh Jain, Jyothi Shanbhag et al.Apr 28
033AI-Enabled Domain Adaptation Technique for Automated IoT Vulnerability Detection and MitigationOpenAlexPaperK.Benazeer Fathima, J.Nishanthi et al.Apr 21
034Improving Safety Deep Learning-Based Vulnerability DetectionOpenAlexPaperSamir Haddad, Kassem Hamze et al.Apr 21
035Sentinel Model as a Try: a dual-Model Architecture for Defending against Data Extraction Attacks in Retrieval-Augmented GenerationOpenAlexPaperJianghui Hu, Na Fan et al.Apr 21
036ScenGDL: Smart contract vulnerability detection and location based on temporal Scenarios and Graph convolution networksOpenAlexPaperXinyi Shen, Xiangfu Zhao et al.Apr 18
037The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 18
038The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 18
039Evaluating open-source LLMs for dental EMR generationOpenAlexPaperHao Wang, Wen Du et al.Apr 17
040Interpretable SQL Injection Detection: Lightweight Decision Trees with SHAP-Enhanced DeploymentOpenAlexPaperShowkot Hosen, Abdullah Al Mamun Zihan et al.Apr 16
041The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 14
042The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 14
043GUI Based Natural Language Interface for Database QueryingOpenAlexPaperG. Lalithya, M. V. Gnana Prasuna et al.Apr 12
044GUI Based Natural Language Interface for Database QueryingOpenAlexPaperG. Lalithya, M. V. Gnana Prasuna et al.Apr 12
045The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 12
046The Last Developer: App, Android, VBA, Matlab, and Embedded — How AI Collapsed Every Software Moat, and Why Formal Verification Is the Only Proof That RemainsOpenAlexPaperRajeshkumar VenugopalApr 12
047Replication Package for "Look Back Before You Bisect: A Risk-Aware Approach for Efficient Bisection"OpenAlexPaperAli Sayedsalehi, Peter C. RigbyApr 1
048Replication Package for "Look Back Before You Bisect: A Risk-Aware Approach for Efficient Bisection"OpenAlexPaperAli Sayedsalehi, Peter C. RigbyApr 1
049ЖЕЛІ АРҚЫЛЫ ЖАЛҒАН КОНТЕНТТІ ТАСЫМАЛДАУДЫ ІЗДЕУ ҮШІН ЖЕЛІЛІК ТРАФИКТІ ТАЛДАУOpenAlexPaperЗ.А. Сарсембаева, Г.И. Аймичева et al.Mar 30
050XMR: Exact Match Recovery for Evaluating Text Normalization Against Adversarial Unicode AttacksOpenAlexPaperRichard QuinnMar 29
051Chinese semantic obfuscation blackbox jailbreak for domestic large modelsOpenAlexPaperXinxin Yue, Zhiyong Zhang et al.Mar 26
052Detecting and Mitigating AI Prompt Injection Attacks in Large Language Models (LLMs)OpenAlexPaperAbel Ureste, Hyungbae Park et al.Mar 21
053DeepSeek-Rl Family Large Language Models in the Tasks of Identification, Classification, and Detection of Vulnerabilities from the CWE Top 25 ListOpenAlexPaperV. V. Shvyrov, D. A. Kapustin et al.Mar 18
054Dialect-Agnostic SQL Parsing via LLM-Based SegmentationOpenAlexPaperJunwen An, Kabilan Mahathevan et al.Mar 17
055Sadhana Programming Language v1.0 — A Meaning-First, Order-Free, Time-Latent Programming LanguageOpenAlexPaperManish Kumar PariharMar 3
056Sadhana Programming Language v1.0 — A Meaning-First, Order-Free, Time-Latent Programming LanguageOpenAlexPaperManish Kumar PariharMar 3
057Bridging AI and software security: A comparative vulnerability assessment of LLM agent deployment paradigmsOpenAlexPaperTarek Gasmi, Ramzi Guesmi et al.Feb 11
058🖥 Zomro Coupon Code 2026 [zomro_433382] – 70% OFF Hosting PlansOpenAlexPapershashankFeb 10
059🖥 Zomro Coupon Code 2026 [zomro_433382] – 70% OFF Hosting PlansOpenAlexPapershashankFeb 10
060Fix Pattern-Aware Vulnerability Patch Generation via In-Context LearningOpenAlexPaperMiaomiao Shao, Yuxin Ding et al.Feb 9

Showing 60 of 258 documents · scroll for more