appsec.fyi · Sources

arxiv.org

31 curated AppSec resources from arxiv.org across 9 topics on appsec.fyi.

arxiv.org

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-22.

Date Added Resource Excerpt
2026-04-22 2026A Survey of the Overlooked Dangers of Template Engines (arXiv 2024)SSTIA Survey of the Overlooked Dangers of Template Engines (arXiv 2024)
2026-04-22 2026When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsAIWhen AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
2026-04-22 2026Prompt Injection Attacks on Agentic Coding Assistants: A Systematic AnalysisAIPrompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis
2026-04-22 2026Prompt Injection 2.0: Hybrid AI ThreatsAIPrompt Injection 2.0: Hybrid AI Threats
2026-04-22 2026Architecting Secure AI Agents: System-Level Defenses Against Indirect Prompt InjectionAIArchitecting Secure AI Agents: System-Level Defenses Against Indirect Prompt Injection
2026-04-22 2026deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesFuzzingdeepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented Harnesses
2026-04-22 2026Fixing Security Vulnerabilities with AI in OSS-FuzzFuzzingFixing Security Vulnerabilities with AI in OSS-Fuzz
2026-04-22 2026A Survey of Network Protocol Fuzzing: Model, Techniques and DirectionsFuzzingA Survey of Network Protocol Fuzzing: Model, Techniques and Directions
2026-04-22 2026Synthesizing XSS Polyglots with Monte Carlo Tree Search (arXiv 2025)XSSSynthesizing XSS Polyglots with Monte Carlo Tree Search (arXiv 2025)
2026-04-19 2026Prompt Injection Attack Against LLM-Integrated Applications — arXivAIPrompt Injection Attack Against LLM-Integrated Applications — arXiv
2026-04-17 2026Closing the Chain: How to reduce SolarWinds/Log4j/XZ risk (arXiv)Supply ChainClosing the Chain: How to reduce SolarWinds/Log4j/XZ risk (arXiv)
2026-04-17 2026SBOM Literature Review (arXiv)Supply ChainSBOM Literature Review (arXiv)
2026-04-16 2026Empirical Study on RCE in ML Model Hosting EcosystemsRCEEmpirical Study on RCE in ML Model Hosting Ecosystems
2026-04-16 2026The Art of Hide and Seek: Pickle-Based Model Supply Chain PoisoningDeserThe Art of Hide and Seek: Pickle-Based Model Supply Chain Poisoning
2026-04-16 2026Bypassing LLM Guardrails: Evasion Attacks against Prompt Injection DetectionAIBypassing LLM Guardrails: Evasion Attacks against Prompt Injection Detection
2026-04-16 2026EchoLeak: First Real-World Zero-Click Prompt Injection ExploitAIEchoLeak: First Real-World Zero-Click Prompt Injection Exploit
2026-04-16 2026The Dark Side of LLMs: Agent-based Attacks for Complete Computer TakeoverAIThe Dark Side of LLMs: Agent-based Attacks for Complete Computer Takeover
2026-04-16 2026MCP Safety Audit: LLMs with MCP Allow Major Security ExploitsAIMCP Safety Audit: LLMs with MCP Allow Major Security Exploits
2026-04-11 2026G2Fuzz: Grammar-Aware Fuzzing with LLMsFuzzingG2Fuzz: Grammar-Aware Fuzzing with LLMs
2026-04-11 2026Involuntary Jailbreak: On Self-Prompting AttacksAIInvoluntary Jailbreak: On Self-Prompting Attacks
2026-04-11 2026Practical Poisoning Attacks against Retrieval-Augmented GenerationAIPractical Poisoning Attacks against Retrieval-Augmented Generation
2026-04-11 2026RAG Safety: Exploring Knowledge Poisoning Attacks to RAGAIRAG Safety: Exploring Knowledge Poisoning Attacks to RAG
2026-04-11 2026Benchmarking Poisoning Attacks against Retrieval-Augmented GenerationAIBenchmarking Poisoning Attacks against Retrieval-Augmented Generation
2026-04-10 2026Multi-target Coverage-based Greybox FuzzerFuzzingMulti-target Coverage-based Greybox Fuzzer
2026-04-10 2026PickleBall: Secure Deserialization of Pickle-based ML ModelsDeserPickleBall: Secure Deserialization of Pickle-based ML Models
2026-04-10 2026Deserialization Gadget Chains in Android: An In-Depth StudyDeserDeserialization Gadget Chains in Android: An In-Depth Study
2026-04-06 2026Enhancing REST API Fuzzing with Access Policy Violation DetectionAPI SecFuzzingEnhancing REST API Fuzzing with Access Policy Violation Detection
2026-04-06 2026Fuzzing REST APIs in Industry: Necessary Features and Lessons LearnedFuzzingFuzzing REST APIs in Industry: Necessary Features and Lessons Learned
2026-04-03 2026Red Teaming the Mind of the Machine: Evaluation of Prompt Injection and Jailbreak VulnerabilitiesAIRed Teaming the Mind of the Machine: Evaluation of Prompt Injection and Jailbreak Vulnerabilities
2026-04-03 2026MALF: A Multi-Agent LLM Framework for Intelligent FuzzingFuzzingMALF: A Multi-Agent LLM Framework for Intelligent Fuzzing
2026-04-03 2026A Large-Scale Security-Oriented Static Analysis of Python Packages in PyPIPythonA Large-Scale Security-Oriented Static Analysis of Python Packages in PyPI