agentsclimarketplace

Ai security papers guide

Skill brycewang-stanford/Auto-Empirical-Research-Skills/skills/43-wentorai-research-plugins/skills/domains/cs/ai-security-papers-guide

AI security papers from top-4 security conferencesFrom its SKILL.md

Install
npx -y skills add brycewang-stanford/Auto-Empirical-Research-Skills --skill ai-security-papers-guide

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

SKILL.md

3.6 KB, 837 tokens by cl100k_base, as published. Nobody here has run it

AI Security Papers Guide (BIG4 Venues)

Overview

A curated collection of AI security papers from the top-4 security conferences: IEEE S&P, ACM CCS, USENIX Security, and NDSS. Covers adversarial attacks, model stealing, data poisoning, privacy attacks, deepfake detection, and LLM security. Organized by year and venue, focusing exclusively on peer-reviewed work from these prestigious venues.

Venues

VenueFull NameFocus
S&PIEEE Symposium on Security and PrivacyBroad security + privacy
CCSACM Conference on Computer and Communications SecuritySystems security
USENIXUSENIX Security SymposiumSystems + network security
NDSSNetwork and Distributed System SecurityNetwork security

Topic Categories

AI Security (BIG4)
├── Adversarial ML
│   ├── Evasion attacks (adversarial examples)
│   ├── Poisoning attacks (backdoors, trojans)
│   ├── Model stealing (extraction, distillation)
│   └── Defenses (certified robustness, detection)
├── Privacy Attacks
│   ├── Membership inference
│   ├── Model inversion
│   ├── Attribute inference
│   └── Training data extraction
├── LLM Security
│   ├── Prompt injection
│   ├── Jailbreaking
│   ├── Data leakage
│   └── Alignment attacks
├── Deepfakes
│   ├── Generation methods
│   ├── Detection techniques
│   └── Watermarking
└── Federated Learning Security
    ├── Byzantine attacks
    ├── Gradient leakage
    └── Secure aggregation

Key Papers by Year

# Recent highlights
papers_2024_2025 = [
    {"title": "Not What You've Signed Up For: "
              "Compromising Real-World LLM-Integrated Applications",
     "venue": "S&P 2024", "topic": "LLM security"},
    {"title": "Prompt Stealing Attacks Against "
              "Text-to-Image Generation Models",
     "venue": "S&P 2024", "topic": "Prompt extraction"},
    {"title": "Backdoor Attacks on Language Models",
     "venue": "CCS 2024", "topic": "NLP backdoors"},
    {"title": "Membership Inference in LLMs",
     "venue": "USENIX 2024", "topic": "Privacy"},
]

for p in papers_2024_2025:
    print(f"[{p['venue']}] {p['title']}")
    print(f"  Topic: {p['topic']}")

Research Trends

### Emerging Areas (2024-2025)
1. **LLM security** — Jailbreaking, prompt injection, agent attacks
2. **Supply chain attacks** — Poisoned models, malicious packages
3. **Multi-modal attacks** — Cross-modal adversarial examples
4. **Agent security** — Attacks on LLM-based autonomous systems
5. **Watermarking** — LLM output detection, IP protection
6. **Unlearning** — Machine unlearning verification and attacks

Use Cases

  1. Security research: Find state-of-the-art attack/defense methods
  2. Threat modeling: Understand AI system vulnerabilities
  3. Literature review: Systematic coverage of BIG4 AI security
  4. Course material: Graduate-level AI security curriculum
  5. Red teaming: Learn evaluation techniques for AI systems

References

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Gives 0 of the 12 instructions most security skills give in 837 tokens

Counted across 666 of the 889 authors here whose files we hold, read 2026-09-06

  • Use parameterized queries for database accessin 82 of 666, across 79 files
  • Hash passwords with BCryptin 55 of 666, across 39 files
  • Implement rate limiting for public endpointsin 48 of 666, across 34 files
  • Use environment variables for secretsin 35 of 666
  • Scan dependencies for vulnerabilitiesin 35 of 666, across 24 files
  • Validate and sanitize all user inputin 35 of 666, across 32 files
  • Add security headers to all responsesin 34 of 666, across 20 files
  • Validate all external input at the system boundaryin 26 of 666, across 25 files
  • Use parameterized queries to prevent SQL injectionin 25 of 666, across 13 files
  • Store secrets in Vault or environment variablesin 25 of 666, across 10 files
  • Run containers as a non-root userin 21 of 666, across 18 files
  • Validate all input using Bean Validationin 19 of 666, across 5 files

Said here and by no other author read

  • Focus exclusively on peer-reviewed papers from BIG4 venues
  • Categorize research by adversarial ML and privacy attacks
  • Use BIG4 papers for threat modeling AI systems
  • Apply research findings to red teaming AI models

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.