Researchers at TII, in cooperation with University Paderborn and Ruhr University Bochum, have discovered a vulnerability called the Opossum Attack in Transport Layer Security (TLS) impacting protocols like HTTP(S), FTP(S), POP3(S), and SMTP(S). The vulnerability exposes a risk of desynchronization between client and server communications, potentially leading to exploits like session fixation and content confusion. Scans revealed over 2.9 million potentially affected servers, including over 1.4 million IMAP servers and 1.1 million POP3 servers. Why it matters: This discovery highlights the importance of ongoing cybersecurity research in the UAE and internationally to identify and address vulnerabilities in fundamental internet protocols, especially as it led to immediate action by Apache and Cyrus IMAPd.
Marcus Engsig at DERC has developed DomiRank, a new centrality metric to quantify the dominance of nodes within networks. DomiRank integrates local and global topological information to determine the importance of each node for network stability. The research demonstrates that nodes with high DomiRank values indicate vulnerable areas heavily dependent on dominant nodes. Why it matters: This metric can help identify critical infrastructure components and vulnerabilities in complex systems, enhancing resilience against targeted attacks.
Researchers at MBZUAI have demonstrated a method called "Data Laundering" to artificially boost language model benchmark scores using knowledge distillation. The technique covertly transfers benchmark-specific knowledge, leading to inflated accuracy without genuine improvements in reasoning. The study highlights a vulnerability in current AI evaluation practices and calls for more robust benchmarks.
KAUST researchers have identified a gene, CLAMT1b, in pearl millet that affects its vulnerability to the parasitic weed Striga hermonthica. Pearl millet strains lacking CLAMT1b were found to be resistant to the weed, while those expressing the gene were susceptible. The gene's presence leads to the secretion of strigolactones, promoting interaction with Striga, but its absence does not harm symbiotic relationships with beneficial fungi. Why it matters: This discovery offers new breeding strategies to enhance pearl millet's resistance to parasitic weeds, bolstering food security in arid regions like Saudi Arabia and Africa where the crop is vital.
A study compared the vulnerability of C programs generated by nine state-of-the-art Large Language Models (LLMs) using a zero-shot prompt. The researchers introduced FormAI-v2, a dataset of 331,000 C programs generated by these LLMs, and found that at least 62.07% of the generated programs contained vulnerabilities, detected via formal verification. The research highlights the need for risk assessment and validation when deploying LLM-generated code in production environments.
An international team including KAUST researchers tracked nearly 2,000 sharks using satellite tags to map their movement and space use. The study found that 24% of shark habitats overlap with pelagic longline fisheries, with higher overlap for commercially exploited species. For North Atlantic blue and shortfin mako sharks, the overlap was 76% and 62% respectively. Why it matters: This research highlights the vulnerability of sharks to industrial fishing and underscores the need for targeted conservation efforts in critical habitats.
MBZUAI researchers presented a NeurIPS 2024 Spotlight paper that quantifies AI vulnerability by measuring bits leaked per query. Their formula predicts the minimum queries needed for attacks based on mutual information between model output and attacker's target. Experiments across seven models and three attack types (system-prompt extraction, jailbreaks, relearning) validate the relationship. Why it matters: This work offers a framework to translate UI choices (like exposing log-probs or chain-of-thought) into concrete attack surfaces, informing more secure AI design and deployment in the region.
A new paper from MBZUAI demonstrates that state-of-the-art speech models can be easily jailbroken using audio perturbations to generate harmful content, achieving success rates of 76-93% on models like Qwen2-Audio and LLaMA-Omni. The researchers adapted projected gradient descent (PGD) to the audio domain to optimize waveforms that push the model towards harmful responses. They propose a defense mechanism based on post-hoc activation patching that hardens models at inference time without retraining. Why it matters: This research highlights a critical vulnerability in speech-based LLMs and offers a practical solution, contributing to the development of more secure and trustworthy AI systems in the region and globally.