8 papers
PRISM: Recovering Instruction Sets from Language Model Activations
Gilad Gressel, Rahul Pankajakshan, Julia Diament +3
As LLMs are deployed as agents, reliable monitoring requires knowing not only what they output, but which instructions are steering their behavior. This is difficult when models in…
One Step to the Side: Why Defenses Against Malicious Finetuning Fail Under Adaptive Adversaries
Itay Zloczower, Eyal Lenga, Gilad Gressel +1
Model providers increasingly release open weights or allow users to fine-tune foundation models through APIs. Although these models are safety-aligned before release, their safegua…
Who Owns This Agent? Tracing AI Agents Back to Their Owners
Ruben Chocron, Doron Jonathan Ben Chayim, Eyal Lenga +3
AI agents are increasingly deployed to act autonomously in the world, yet there is still no reliable way to trace a harmful agent back to the account that deployed it. This creates…
GAVEL: Towards Rule-Based Safety Through Activation Monitoring
Shir Rozenfeld, Rahul Pankajakshan, Itay Zloczower +3
Large language models (LLMs) are increasingly paired with activation-based monitoring to detect and prevent harmful behaviors that may not be apparent at the surface-text level. Ho…
Love, Lies, and Language Models: Investigating AI's Role in Romance-Baiting Scams
Gilad Gressel, Rahul Pankajakshan, Shir Rozenfeld +4
Romance-baiting scams have become a major source of financial and emotional harm worldwide. These operations are run by organized crime syndicates that traffic thousands of people…
ProxyPrints: From Database Breach to Spoof, A Plug-and-Play Defense for Biometric Systems
Yaniv Hacmon, Keren Gorelik, Gilad Gressel +1
Fingerprint recognition systems are widely deployed for authentication and forensic applications, but the security of stored fingerprint data remains a critical vulnerability. Whil…