6 papers
Referential Security as a New Paradigm for AI Evaluations
Dan Ristea, Vasilios Mavroudis
Security evaluations inherently depend on stable identifiers. Any finding, audit, or regulatory decision must remain attached to the specific artifact it pertains to. Continuously…
Direction for Detection: A Survey of Automated Vulnerability Detection and all of its Pain Points
Dan Ristea, Shae McFadden, Ezzeldin Shereen +4
Security vulnerabilities in software can have severe consequences; however, manual vulnerability detection is costly and does not scale, especially as agentic coding frameworks inc…
One Pic is All it Takes: Poisoning Visual Document Retrieval Augmented Generation with a Single Image
Ezzeldin Shereen, Dan Ristea, Shae McFadden +3
Retrieval-augmented generation (RAG) is instrumental for inhibiting hallucinations in large language models (LLMs) through the use of a factual knowledge base (KB). Although PDF do…
Are we collaborative yet? A Usability Perspective on Mixnet Latency for Real-Time Applications
Killian Davitt, Dan Ristea, Steven J. Murdoch
Mixnet networks deliberately induce additional latency to communications to provide anonymity. Recent developments have allowed mixnets to reduce their latency from hours to second…
HonestCyberEval: An AI Cyber Risk Benchmark for Automated Software Exploitation
Dan Ristea, Vasilios Mavroudis
We introduce HonestCyberEval, a new benchmark for assessing AI models' capabilities and risks in automated software exploitation, focusing on their ability to detect and exploit vu…
Scalable Time-Lock Puzzle
Aydin Abadi, Dan Ristea, Artem Grigor +1
Time-Lock Puzzles (TLPs) enable a client to lock a message such that a server can unlock it only after a specified time. They have diverse applications, such as scheduled payments,…