
research note
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
AuthREST is an open-source black-box security testing tool for a very specific but common class of API failures: broken authentication

research note
AuthREST is an open-source black-box security testing tool for a very specific but common class of API failures: broken authentication

research note
ByteDefender tackles a practical browser-privacy problem: fingerprinting is often embedded inside otherwise legitimate JavaScript, so blunt defenses like URL blocklists or whole-script blocking eit…

research note
This work investigates how WebAssembly (WASM) based obfuscation affects the detection of browser fingerprinting scripts

research note
FL-RBA2 is a federated learning framework for risk-based adaptive authentication (RBA) that tries to solve two problems at once: privacy leakage from centralized risk engines and poor model quality…

research note
Aura-CAPTCHA is a novel multi-modal CAPTCHA system designed to resist modern automated attacks by combining dynamically generated visual and audio challenges with real-time adaptive difficulty cont…

research note
This paper addresses the challenge of constructing a large-scale, high-quality synthetic face recognition dataset that contains no real-world identities, as required by the DataCV ICCV Face Recogni…

research note
This work introduces AirSignatureDB, a novel, publicly accessible dataset of in-air signature biometrics collected from 108 users in unconstrained real-world conditions using 83 different smartphon…

research note
This paper addresses the escalating threats to personal digital identity posed by generative AI technologies, including unauthorized cloning, impersonation, and monetization of digital likeness att…

research note
This paper addresses the challenge of deploying Physically Unclonable Functions (PUFs) for secure authentication in blockchain systems without relying on specialized hardware

research note
This paper investigates biometric verification in photorealistic talking-head avatar videos, where attackers may perform impersonation attacks by stealing a victim's avatar to replicate their appea…

research note
This paper investigates a fundamental and longstanding challenge in AI known as Moravec's paradox, specifically within the domain of auditory perception

research note
The paper asks whether phishing generation can be pushed beyond static, prompt-based output by treating attack design as an evolutionary process