A recent study by CISPA Helmholtz Center for Information Security examines how users perceive AI labels and their impact on information credibility. The study found that while AI labels can reduce belief in false content, they also trigger skepticism and shape trust more than the content itself.
A new code-reuse attack named SFOP exploits vulnerabilities in signal handling and Intel CET in Linux systems, achieving arbitrary code execution. The attack is enabled by 12 priorly unknown weaknesses that affect Linux signals, making it practicable across all programs running on a Linux system.
Code reuse attacks exploit existing program components to inject malicious code, but PLaTypus restricts arbitrary transitions between libraries to prevent such attacks. This approach reduces the number of indirectly accessible functions by over 98% and causes less than 0.5% additional runtime overhead.
Cas Cremers and collaborators receive Levchin Prize for Real-World Cryptography for their work on the Tamarin Prover, an open-source analysis tool for cryptographic protocols, which has had a significant impact on the practice of cryptography and its use in real-world systems.
Andreas Zeller recognized for his work on automated debugging and security testing, with a total of nine Test of Time Awards. He is one of the few researchers to receive two ERC Advanced Grants from the European Research Council.
Rayna Dimitrova's SyReP project aims to eliminate the separation between decision-making and data in software development, enabling developers to specify system behavior and generate implementation automatically. The ERC Consolidator Grant will support her research on novel symbolic algorithms and realizability certificates.
Liberate AI project develops an AI model capable of predicting long-term outcomes and potential complications in ischemic stroke patients. The model will be trained using Swarm Learning technology, aiming for explainability and transparency, while striking a balance between these features and accuracy.
The European Lighthouse on Secure and Safe AI (ELSA) network has grown to include 41 members, expanding its expertise in pressing AI research topics and fostering knowledge exchange. The network's founding members are renowned for their work on Safety, Security, Artificial Intelligence, and Machine Learning.
A CISPA researcher has been awarded an ERC Starting Grant to tackle the issue of data leaks in large AI models. The project aims to develop new methods for protecting private training data, making it a crucial step towards ensuring trust in artificial intelligence.
A qualitative interview study with 21 international participants explored the opportunities and challenges of cryptographic update processes. Software developers face unique security risks when updating crypto implementations, which can lead to a single point of failure in the supply chain.
Researchers have discovered a code-reuse attack capable of exploiting C++ coroutines across three major compilers, including those protected by Control Flow Integrity. The attack, called Coroutine Frame-Oriented Programming (CFOP), chains together existing functions to achieve arbitrary code execution.
FANDANGO, a new open-source fuzzing tool, employs an iterative procedure modeled on biological evolution to produce high-quality test inputs that cover both semantics and syntax. The tool enables complete control over test inputs, allowing testers to specify input characteristics and explore specific parts of the program.
YuraScanner harnesses LLMs to navigate web applications like humans do, identifying tasks and workflows. It detects previously unknown XSS vulnerabilities, surpassing existing scanners.
CISPA has signed the Africa Charter, a joint endeavour of major higher education bodies, to address structural disadvantages faced by scientists and research institutions in Africa. The charter outlines 10 principles for structuring research collaborations to overcome existing power imbalances.
Dr. Sebastian Stich aims to create more efficient and adaptable machine learning models using collaborative learning approaches. The goal is to reduce computational power demands and costs, making it accessible to smaller players in fields like medicine.