10 papers
Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions
Sarthak Choudhary, Atharv Singh Patlan, Nils Palumbo +3
We present Sparse Backdoor, a supply-chain attack that plants a provably undetectable backdoor in pre-trained image classifiers, including convolutional networks and Vision Transfo…
CounterFace: A Synthetic Face Dataset for Fine-Grained Counterfactual Evaluation of Face Recognition Systems
Guruprasad Viswanathan Ramesh, Ashish Hooda, Shimaa Ahmed +3
Face recognition (FR) systems are widely deployed in critical applications, making their reliability and robustness across diverse populations and conditions essential. Standard ev…
Through the Stealth Lens: Attention-Aware Defenses Against Poisoning in RAG
Sarthak Choudhary, Nils Palumbo, Ashish Hooda +2
Retrieval-augmented generation (RAG) systems are vulnerable to attacks that inject poisoned passages into the retrieved context, even at low corruption rates. We show that existing…
Agent Security is a Systems Problem
Mihai Christodorescu, Earlence Fernandes, Ashish Hooda +11
We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants…
Systems Security Foundations for Agentic Computing
Mihai Christodorescu, Earlence Fernandes, Ashish Hooda +11
In recent years, agentic artificial intelligence (AI) systems are becoming increasingly widespread. These systems allow agents to use various tools, such as web browsers, compilers…
Auto-SPT: Automating Semantic Preserving Transformations for Code
Ashish Hooda, Mihai Christodorescu, Chuangang Ren +3
Machine learning (ML) models for code clone detection determine whether two pieces of code are semantically equivalent, which in turn is a key building block for software-engineeri…