Open Access. Powered by Scholars. Published by Universities.®
- Discipline
- Keyword
-
- Information leakage (2)
- Natural language processing systems (2)
- Privacy (2)
- Semantics (2)
- AI governance (1)
-
- Accuracy (1)
- Adaptation models (1)
- Anonymity (1)
- Artificial intelligence (1)
- Backdoor attack (1)
- Biosecurity (1)
- Blockchain (1)
- Chains (1)
- Cloud data (1)
- Collaboration (1)
- Computational linguistics (1)
- Computational modeling (1)
- Context (1)
- Cooperation (1)
- Cost effectiveness (1)
- Cybersecurity (1)
- Data models (1)
- Data privacy (1)
- Data sharing (1)
- Data-Computer programs (1)
- Decentralized marketplace (1)
- Deep learning-Mathematical models (1)
- Digital technology (1)
- Extraction (1)
- Feature extraction (1)
Articles 1 - 9 of 9
Full-Text Articles in Cybersecurity
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li
Computer Science Faculty Publications
Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …
Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol
Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol
Computer Science Faculty Publications
Large Language Models (LLMs) are becoming critical infrastructure in scientific, healthcare, and governmental contexts. As frontier AI laboratories increasingly partner with government agencies, a fundamental question arises: Who should control the safety and policy-enforcement layers that constrain model behavior? Current safety mechanisms (LLM guardrails) are typically designed for generic "harmlessness" and operate by detecting semantic patterns and refusing requests. However, they are inadequate governance instruments because they cannot implement auditable, domain-specific controls tied to external regulatory policy objects (e.g., control lists or rules governing personally identifying information). Even a perfectly aligned model is not able to express institution-specific policy without …
Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang
Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang
Computer Science Faculty Publications
Large Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved …
Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu
Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu
Computer Science Faculty Publications
Private inference applies cryptographic techniques like homomorphic encryption, garble circuit and secret sharing to keep both sides privacy in a client-server setting during inference. It is often hindered by the high communication overheads, especially at non-linear activation layers such as ReLU. Hence ReLU pruning has been widely recognized as an efficient way to accelerate private inference. Existing approaches to ReLU pruning typically rely on coarse hypothesis, which assume an inverse correlation between the importance of ReLU and linear layers or shallow activation layers have less importance for universal models, to assign the budgets according to the layer while preserving the …
Nexus: Network Exploration For Exploiting Unsafe Sequences In Multi-Turn Llm Jailbreaks, Javad Rafiei Asl, Sidhant Narula, Mohammad Ghasemigol, Eduardo Blanco, Daniel Takabi
Nexus: Network Exploration For Exploiting Unsafe Sequences In Multi-Turn Llm Jailbreaks, Javad Rafiei Asl, Sidhant Narula, Mohammad Ghasemigol, Eduardo Blanco, Daniel Takabi
Computer Science Faculty Publications
Large Language Models (LLMs) have revolutionized natural language processing, yet remain vulnerable to jailbreak attacks—particularly multi-turn jailbreaks that distribute malicious intent across benign exchanges, thereby bypassing alignment mechanisms. Existing approaches often suffer from limited exploration of the adversarial space, rely on hand-crafted heuristics, or lack systematic query refinement. We propose NEXUS (Network Exploration for eXploiting Unsafe Sequences), a modular framework for constructing, refining, and executing optimized multi-turn attacks. NEXUS comprises: (1) ThoughtNet, which hierarchically expands a harmful intent into a structured semantic network of topics, entities, and query chains; (2) a feedback-driven Simulator that iteratively refines and prunes these chains …
Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh
Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh
Computer Science Faculty Publications
Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li
Computer Science Faculty Publications
Large Language Models (LLMs) exhibit strong natural language processing capabilities but also pose significant privacy risks, particularly regarding the leakage of Personally Identifiable Information (PII) embedded in their training data. Existing PII extraction methods suffer from the limitations of low success rates or impracticality for large-scale PII extraction. In this study, we propose a novel PII extraction approach based on enhanced few-shot learning techniques, which achieves efficient and cost-effective PII retrieval without relying on fine-tuning or jailbreaking. We evaluated our approach on both open-source and closed-source LLMs. The experimental results demonstrate that, for non-targeted PII extraction, the attack success rate …
Towards Trust And Reputation As A Service In Society 5.0, Stephan Olariu, Ravi Mukkamala, Meshari Aljohani
Towards Trust And Reputation As A Service In Society 5.0, Stephan Olariu, Ravi Mukkamala, Meshari Aljohani
Computer Science Faculty Publications
Our paper was inspired by the recent Society 5.0 initiative of the Japanese Government which seeks to create a sustainable human-centric society by putting to work recent advances in technology. One of the key challenges in implementing Society 5.0 is providing trusted and secure services for everyone to use. Motivated by this challenge, this paper makes three contributions that we summarize as follows: Our first main contribution is to propose a novel blockchain and smart contract-based trust and reputation service design to reduce the uncertainty associated with buyer feedback in marketplaces that we expect to see in Society 5.0. Our …
Privacy In Iot Cloud, Aftab Ahmad, Ravi Mukkamala, Karthik Navuluri
Privacy In Iot Cloud, Aftab Ahmad, Ravi Mukkamala, Karthik Navuluri
Computer Science Faculty Publications
We present a framework for privacy preservation in an information cloud of IoT devices. We contend that privacy provisioning should be located in the user device and must protect the user, the information, and the device from breaches in privacy. We elaborate on how the layered privacy model can ensure such privacy provisioning, and justify the device being the provisioning point instead of the cloud alone. We present the point of view that, due to resource limitations of the IoT devices in general, the privacy preserving measures need to be hard-coded in the device technology. We fall short of suggesting …