collaborators

11 papers

cs.CR2026

FloatDoor: Platform-Triggered Backdoors in LLMs

Nils Loose, Jonas Sander, Felix Mächtle +1

Large language models (LLMs) are increasingly deployed in sensitive settings such as software engineering, where their outputs directly shape downstream artifacts. Recent work has…

cs.CL2026

PsychoSafe: Eliciting Psychologically-Informed Refusals in Large Language Models

Gianluca Barmina, Federico Torrielli, Sven Harms +7

Large language models (LLMs) routinely face requests that should be refused, creating a trade-off between helpfulness and harm prevention. However, refusals themselves can be helpf…

cs.CR2026

Steganography Without Modification: Hidden Communication via LLM Seeds

Felix Mächtle, Jonas Sander, Sebastian Berndt +3

We demonstrate that widely deployed Large Language Model (LLM) inference stacks harbor a steganographic channel that requires no modification to model weights, sampling code, or ou…

cs.CR2026

DRAMatic Speedup: Accelerating HE Operations on a Processing-in-Memory System

Niklas Klinger, Jonas Sander, Peterson Yuhala +2

Homomorphic encryption (HE) is a promising technology for confidential cloud computing, as it allows computations on encrypted data. However, HE is computationally expensive and of…

cs.CR2026

TrEEStealer: Stealing Decision Trees via Enclave Side Channels

Jonas Sander, Anja Rabich, Nick Mahling +5

Today, machine learning is widely applied in sensitive, security-related, and financially lucrative applications. Model extraction attacks undermine current business models where a…

cs.LG2026

Non-omniscient backdoor injection with one poison sample: Proving the one-poison hypothesis for linear regression, linear classification, and 2-layer ReLU neural networks

Thorsten Peinemann, Paula Arnold, Sebastian Berndt +2

Backdoor poisoning attacks are a threat to machine learning models trained on large data collected from untrusted sources; these attacks enable attackers to inject malicious behavi…