惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
A
About on SuperTechFans
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
W
WeLiveSecurity
博客园 - 三生石上(FineUI控件)
The Cloudflare Blog
I
InfoQ
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Application and Cybersecurity Blog
Application and Cybersecurity Blog
雷峰网
雷峰网
Hacker News - Newest:
Hacker News - Newest: "LLM"
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
T
Troy Hunt's Blog
S
SegmentFault 最新的问题
Help Net Security
Help Net Security
博客园_首页
博客园 - 叶小钗
O
OpenAI News
PCI Perspectives
PCI Perspectives
月光博客
月光博客
人人都是产品经理
人人都是产品经理
B
Blog RSS Feed
GbyAI
GbyAI
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
The Last Watchdog
The Last Watchdog
C
CXSECURITY Database RSS Feed - CXSecurity.com
有赞技术团队
有赞技术团队
D
Darknet – Hacking Tools, Hacker News & Cyber Security
腾讯CDC
Hacker News: Ask HN
Hacker News: Ask HN
I
Intezer
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
Spread Privacy
Spread Privacy
T
Tailwind CSS Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
量子位
Cyberwarzone
Cyberwarzone
The Hacker News
The Hacker News
N
News and Events Feed by Topic
P
Proofpoint News Feed
Scott Helme
Scott Helme
D
Docker
Know Your Adversary
Know Your Adversary
Recent Commits to openclaw:main
Recent Commits to openclaw:main
TaoSecurity Blog
TaoSecurity Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tor Project blog

cs.CR updates on arXiv.org

Backdoor Channels Hidden in Latent Space: Cryptographic Undetectability in Modern Neural Networks CTFusion: A CTF-based Benchmark for LLM Agent Evaluation Large Language Models for Agentic NetOps and AIOps: Architectures, Evaluation, and Safety From Controlled to the Wild: Evaluation of Pentesting Agents for the Real-World Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw Graph Representation Learning Augmented Model Manipulation on Federated Fine-Tuning of LLMs Containment Verification: AI Safety Guarantees Independent of Alignment Defense effectiveness across architectural layers: a mechanistic evaluation of persistent memory attacks on stateful LLM agents From Specification to Deployment: Empirical Evidence from a W3C VC + DID Trust Infrastructure for Autonomous Agents Agentic Vulnerability Reasoning on Windows COM Binaries From Beats to Breaches:How Offensive AI Infers Sensitive User Information from Playlists Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions When Embedding-Based Defenses Fail: Rethinking Safety in LLM-Based Multi-Agent Systems When Alignment Isn't Enough: Response-Path Attacks on LLM Agents Block-wise Codeword Embedding for Reliable Multi-bit Text Watermarking FlexServe: A Fast and Secure LLM Serving System for Mobile Devices with Flexible Resource Isolation TwoHamsters: Benchmarking Multi-Concept Compositional Unsafety in Text-to-Image Models Symbolic Guardrails for Domain-Specific Agents: Stronger Safety and Security Guarantees Without Sacrificing Utility Hardening x402: PII-Safe Agentic Payments via Pre-Execution Metadata Filtering Hijacking Text Heritage: Hiding the Human Signature through Homoglyphic Substitution Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit Private Seeds, Public LLMs: Realistic and Privacy-Preserving Synthetic Data Generation Chimera: Neuro-Symbolic Attention Primitives for Trustworthy Dataplane Intelligence Sockpuppetting: Jailbreaking LLMs by Combining Prefilling with Optimization StegoStylo: Squelching Stylometric Scrutiny through Steganographic Stitching Learning-Based Automated Adversarial Red-Teaming for Robustness Evaluation of Large Language Models AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders CrossGuard: Safeguarding MLLMs against Joint-Modal Implicit Malicious Attacks Feedback Lunch: Learned Feedback Codes for Secure Communications Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models A First Look at the Security Issues in the Model Context Protocol Ecosystem Formalizing the Safety, Security, and Functional Properties of Agentic AI Systems MEASER: Malware embedding attacks on open-source LLMs Fall into a Pit, Gain in a Wit: Cognitive-Guided Harmful Meme Detection via Misjudgment Risk Pattern Retrieval When Search Goes Wrong: Red-Teaming Web-Augmented Large Language Models Differentially Private Synthetic Text Generation for Retrieval-Augmented Generation (RAG) From surveillance to signalling: escalation channels as environmental controls for agentic AI STAC: When Innocent Tools Form Dangerous Chains to Jailbreak LLM Agents Federated Spatiotemporal Graph Learning for Passive Attack Detection in Smart Grids Guidance Watermarking for Diffusion Models SecureVibeBench: Benchmarking Secure Vibe Coding of AI Agents via Reconstructing Vulnerability-Introducing Scenarios xOffense: An Autonomous Multi-Agent Framework for Penetration Testing with Domain-Adapted Large Language Models Hammer and Anvil: Toward a Theory of Backdoors in Federated Learning Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Tell-Tale Watermarks for Explanatory Reasoning in Synthetic Media Forensics Between a Rock and a Hard Place: The Tension Between Ethical Reasoning and Safety Alignment in LLMs A Comprehensive Guide to Differential Privacy: From Theory to User Expectations Enabling Transparent Cyber Threat Intelligence Combining Large Language Models and Domain Ontologies Unveiling Unicode's Unseen Underpinnings in Undermining Authorship Attribution Searching for Privacy Risks in LLM Agents via Simulation SPRINT: Robust Model Attribution of Generated Images via Secret Pixel Reconstruction Majority Bit-Aware Watermarking For Large Language Models Coward: Collision-based OOD Watermarking for Practical Proactive Federated Backdoor Detection Prompt to Pwn: Automated Exploit Generation for Smart Contracts Activation-Guided Local Editing for Jailbreaking Attacks Random Walk Learning and the Pac-Man Attack ExCyTIn-Bench: Evaluating LLM agents on Cyber Threat Investigation White-Basilisk: A Hybrid Model for Code Vulnerability Detection Intrinsic Fingerprint of LLMs: Continue Training is NOT All You Need to Steal A Model! InvisibleInk: High-Utility and Low-Cost Text Generation with Differential Privacy Logit-Gap Steering: A Forward-Pass Diagnostic for Alignment Robustness Toward Principled LLM Safety Testing: Solving the Jailbreak Oracle Problem Exploring the Secondary Risks of Large Language Models Benchmarking Misuse Mitigation Against Covert Adversaries Efficient Preimage Approximation for Neural Network Certification Practical Adversarial Attacks on Stochastic Bandits via Fake Data Injection PARASITE: Conditional System Prompt Poisoning to Hijack LLMs Secure LLM Fine-Tuning via Safety-Aware Probing Can Large Language Models Really Recognize Your Name? PoLO: Proof-of-Learning and Proof-of-Ownership at Once with Chained Watermarking A Survey on the Safety and Security Threats of Computer-Using Agents: JARVIS or Ultron? AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning Models Remote Rowhammer Attack using Adversarial Observations on Federated Learning Clients Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents DiffMI: Breaking Face Recognition Privacy via Diffusion-Driven Training-Free Model Inversion Chronology of Multi-Agent Interactions for Provenance of Evolving Information Gungnir: Exploiting Stylistic Features in Images for Backdoor Attacks on Diffusion Models Detecting Malicious Concepts without Image Generation in AI-Generated Content (AIGC) How Vulnerable Is My Learned Policy? Universal Adversarial Perturbation Attacks On Modern Behavior Cloning Policies Imitation Game for Adversarial Disillusion with Chain-of-Thought Reasoning in Generative AI PromptGuard: Soft Prompt-Guided Unsafe Content Moderation for Text-to-Image Models A Multiparty Homomorphic Encryption Approach to Confidential Federated Kaplan Meier Survival Analysis Red-Teaming Text-to-Image Models via In-Context Experience Replay and Semantic-Preserving Prompt Rewriting DeTrigger: A Gradient-Centric Approach to Backdoor Attack Mitigation in Federated Learning Privacy Leakage via Output Label Space and Differentially Private Continual Learning ARQ: A Mixed-Precision Quantization Framework for Accurate and Certifiably Robust DNNs CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment Power-Softmax: Towards Secure LLM Inference over Encrypted Data Hypnopaedia-Aware Machine Unlearning via Psychometrics of Artificial Mental Imagery Anomaly Detection from a Tensor Train Perspective Survival of the Cheapest: Cost-Aware Hardware Adaptation for Adversarial Robustness Improving Clean Accuracy via a Tangent-Space Perspective on Adversarial Training The AI risk repository: A meta-review, database, and taxonomy of risks from artificial intelligence Towards Agentic Runtime Healing Verification of Machine Unlearning is Fragile Aggressive or Imperceptible, or Both: Network Pruning Assisted Hybrid Byzantines in Federated Learning Whispers in the Machine: Confidentiality in Agentic Systems MalPurifier: Enhancing Android Malware Detection with Adversarial Purification against Evasion Attacks Towards Adaptive, Learning-Based Security in Decentralized Applications Can Blockchains Reliably Train Machine Learning Models?
LED-it-GO: Leaking (a lot of) Data from Air-Gapped Computers via the (small) Hard Drive LED
Mordechai Guri, Boris Zadov, Eran Atias, Yuval Elovici · 2017-02-22 · via cs.CR updates on arXiv.org

In this paper we present a method which allows attackers to covertly leak data from isolated, air-gapped computers. Our method utilizes the hard disk drive (HDD) activity LED which exists in most of today's desktop PCs, laptops and servers. We show that a malware can indirectly control the HDD LED, turning it on and off rapidly (up to 5800 blinks per second) - a rate that exceeds the visual perception capabilities of humans. Sensitive information can be encoded and leaked over the LED signals, which can then be received remotely by different kinds of cameras and light sensors. Compared to other LED methods, our method is unique, because it is also covert - the HDD activity LED routinely flickers frequently, and therefore the user may not be suspicious to changes in its activity. We discuss attack scenarios and present the necessary technical background regarding the HDD LED and its hardware control. We also present various data modulation methods and describe the implementation of a user-level malware, that doesn't require a kernel component. During the evaluation, we examine the physical characteristics of different colored HDD LEDs (red, blue, and white) and tested different types of receivers: remote cameras, extreme cameras, security cameras, smartphone cameras, drone cameras, and optical sensors. Finally, we discuss hardware and software countermeasures for such a threat. Our experiment shows that sensitive data can be successfully leaked from air-gapped computers via the HDD LED at a maximum bit rate of 4000 bits per second, depending on the type of receiver and its distance from the transmitter. Notably, this speed is 10 times faster than the existing optical covert channels for air-gapped computers. These rates allow fast exfiltration of encryption keys, keystroke logging, and text and binary files.