7 papers
A Loss-Robust Disturbance Certificate for Minimal-Receiver Quantum Key Distribution
Roberto Di Pietro
Quantum Key Distribution (QKD) enjoys information-theoretic security, yet the most damaging attacks against deployed systems exploit the receiver, where the key bit is encoded in w…
TENET: Telegram Mini App (in)security
Andrea Ciccotelli, Federico Zappone, Roberto Di Pietro
Telegram, with over 450 million daily active users, has introduced Mini Apps---web-based applications running directly within its client. However, this integration introduces notab…
Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?
Yimeng Chen, Nathanaël Denis, Roberto Di Pietro +1
Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via…
I-(OT)^2: A Client-optimal Oblivious Transfer Protocol for IoT Devices
Elia Onofri, Andrea Ciccotelli, Roberto Di Pietro
Oblivious Transfer (OT) is a fundamental cryptographic primitive enabling privacy-preserving computation and constitutes a core building block for secure multi-party computation wh…
A Geometric Analysis of Small-sized Language Model Hallucinations
Emanuele Ricco, Elia Onofri, Lorenzo Cima +2
Hallucinations -- plausible but factually incorrect responses -- pose a major challenge to the reliability of Large Language Models (LLMs), especially in multi-step or agentic sett…
COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity
Elia Onofri, Andrea De Salve, Paolo Mori +2
The Self-Sovereign Identity (SSI) paradigm is instrumental for decentralised identity management, allowing an entity to create, manage, and present their digital credentials withou…