中文
相关论文

相关论文: Rethinking Broken Object Level Authorization Attac…

200 篇论文

Shared autonomy systems require principled methods for inferring user intent and determining appropriate assistance levels. This is a central challenge in human-robot interaction, where systems must be successful while being mindful of user…

机器人学 · 计算机科学 2026-02-02 MH Farhadi , Ali Rabiee , Sima Ghafoori , Anna Cetera , Andrew Fisher , Reza Abiri

The Internet of Things (IoT) connected by Software Defined Networking (SDN) promises to bring great benefits to cyber-physical systems. However, the increased attack surface offered by the growing number of connected vulnerable devices and…

网络与互联网体系结构 · 计算机科学 2020-06-26 Jiejun Hu , Martin Reed , Mays Al-Naday , Nikolaos Thomos

Software vulnerabilities in access control models can represent a serious threat in a system. In fact, OWASP lists broken access control as number 5 in severity among the top 10 vulnerabilities. In this paper, we study the permission model…

软件工程 · 计算机科学 2022-05-24 Atheer Abu Zaid , Manar H. Alalfi , Ali Miri

An authorisation has been recognised as an important security measure for preventing unauthorised access to critical resources, such as devices and data, within the Internet of Things (IoT) networks. Existing authorisation methods for the…

密码学与安全 · 计算机科学 2022-08-16 Khizar Hameed , Ali Raza , Saurabh Garg , Muhammad Bilal Amin

Tool-Based Agent Systems (TBAS) allow Language Models (LMs) to use external tools for tasks beyond their standalone capabilities, such as searching websites, booking flights, or making financial transactions. However, these tools greatly…

密码学与安全 · 计算机科学 2025-02-17 Peter Yong Zhong , Siyuan Chen , Ruiqi Wang , McKenna McCall , Ben L. Titzer , Heather Miller , Phillip B. Gibbons

To address the extremely concerning problem of software vulnerability, system security is often entrusted to Machine Learning (ML) algorithms. Despite their now established detection capabilities, such models are limited by design to…

机器学习 · 计算机科学 2025-10-14 Marco Pintore , Giorgio Piras , Angelo Sotgiu , Maura Pintor , Battista Biggio

Very recently, Barman et al. proposed a multi-server authentication protocol using fuzzy commitment. The authors claimed that their protocol provides anonymity while resisting all known attacks. In this paper, we analyze that Barman et…

密码学与安全 · 计算机科学 2020-04-17 Hafeez Ur Rehman , Anwar Ghani , Shehzad Ashraf Chaudhry , Mohammed H. Alsharif , Narjes Nabipour

Access control is a security mechanism designed to ensure that only authorized users can access specific resources. Cross-domain access control involves access to resources across different organizations, institutions, or applications.…

密码学与安全 · 计算机科学 2025-12-01 Aiyao Zhang , Xiaodong Lee , Zhixian Zhuang , Jiuqi Wei , Yufan Fu , Botao Peng

Real-world applications routinely make authorization decisions based on dynamic computation. Reasoning about dynamically computed authority is challenging. Integrity of the system might be compromised if attackers can improperly influence…

密码学与安全 · 计算机科学 2021-04-22 Owen Arden , Anitha Gollamudi , Ethan Cecchetti , Stephen Chong , Andrew C. Myers

"Distributed Identity" refers to the transition from centralized identity systems using Decentralized Identifiers (DID) and Verifiable Credentials (VC) for secure and privacy-preserving authentications. With distributed identity, control of…

密码学与安全 · 计算机科学 2025-01-17 Sina Ahmadi

In general, deep learning models use to make informed decisions immensely. Developed models are mainly based on centralized servers, which face several issues, including transparency, traceability, reliability, security, and privacy. In…

密码学与安全 · 计算机科学 2023-03-28 Asma Jodeiri Akbarfam , Sina Barazandeh , Hoda Maleki , Deepti Gupta

Open-Source Software (OSS) vulnerabilities bring great challenges to the software security and pose potential risks to our society. Enormous efforts have been devoted into automated vulnerability detection, among which deep learning…

密码学与安全 · 计算机科学 2024-02-09 Xinchen Wang , Ruida Hu , Cuiyun Gao , Xin-Cheng Wen , Yujia Chen , Qing Liao

Machine Learning as a Service (MLaaS) enables users to leverage powerful machine learning models through cloud-based APIs, offering scalability and ease of deployment. However, these services are vulnerable to model extraction attacks,…

OAuth is the new de facto standard for delegating authorization in the web. An important limitation of OAuth is the fact that it was designed for authorization and not for authentication. The usage of OAuth for authentication thus leads to…

密码学与安全 · 计算机科学 2016-01-08 Vladislav Mladenov , Christian Mainka , Jörg Schwenk

Traditional security architectures are becoming more vulnerable to distributed attacks due to significant dependence on trust. This will further escalate when implementing agentic AI within the systems, as more components must be secured…

网络与互联网体系结构 · 计算机科学 2025-09-29 Fannya R. Sandjaja , Ayesha A. Majeed , Abdullah Abdullah , Gyan Wickremasinghe , Karen Rafferty , Vishal Sharma

Algorithmic complexity vulnerabilities occur when the worst-case time/space complexity of an application is significantly higher than the respective average case for particular user-controlled inputs. When such conditions are met, an…

密码学与安全 · 计算机科学 2017-08-29 Theofilos Petsios , Jason Zhao , Angelos D. Keromytis , Suman Jana

Leading language model (LM) providers like OpenAI and Anthropic allow customers to fine-tune frontier LMs for specific use cases. To prevent abuse, these providers apply filters to block fine-tuning on overtly harmful data. In this setting,…

密码学与安全 · 计算机科学 2025-07-15 Joshua Kazdan , Abhay Puri , Rylan Schaeffer , Lisa Yu , Chris Cundy , Jason Stanley , Sanmi Koyejo , Krishnamurthy Dvijotham

The proliferation of Low-Rank Adaptation (LoRA) models has democratized personalized text-to-image generation, enabling users to share lightweight models (e.g., personal portraits) on platforms like Civitai and Liblib. However, this…

密码学与安全 · 计算机科学 2025-07-10 Jiahao Chen , junhao li , Yiming Wang , Zhe Ma , Yi Jiang , Chunyi Zhou , Qingming Li , Tianyu Du , Shouling Ji

AI agents today have passwords but no permission slips. They execute tool calls (fund transfers, database queries, shell commands, sub-agent delegation) with no standard mechanism to enforce authorization before the action executes. Current…

密码学与安全 · 计算机科学 2026-03-24 Uchi Uchibeke

Role-based access control (RBAC) policies represent the rights of subjects in terms of roles to access resources. This research proposes a scalable, flexible and auditable RBAC system using the EOS blockchain platform to meet the security…

密码学与安全 · 计算机科学 2020-07-07 Mohsin Ur Rahman