Skip to content
GCC AI Research

Search

Results for "vulnerabilities"

Evaluation of Adversarial Robustness in Arabic Language Models

arXiv ·

This study evaluated the adversarial robustness of five state-of-the-art Arabic Language Models against various Arabic adversarial attacks at character, word, and sentence levels. It found that diacritic insertion could reduce model accuracy by up to 92%, while manipulating Arabic conjunctions led to a 58% accuracy degradation, and paraphrasing reduced performance by an average of 76%. While adversarial training improved overall resilience, particularly for MARBERT and AraBERT, challenges against character-level noise persist. Why it matters: These findings are crucial for understanding and mitigating security vulnerabilities in Arabic AI, guiding the development of more robust and safe Arabic NLP systems.

Opossum Attack

TII ·

Researchers at TII, in cooperation with University Paderborn and Ruhr University Bochum, have discovered a vulnerability called the Opossum Attack in Transport Layer Security (TLS) impacting protocols like HTTP(S), FTP(S), POP3(S), and SMTP(S). The vulnerability exposes a risk of desynchronization between client and server communications, potentially leading to exploits like session fixation and content confusion. Scans revealed over 2.9 million potentially affected servers, including over 1.4 million IMAP servers and 1.1 million POP3 servers. Why it matters: This discovery highlights the importance of ongoing cybersecurity research in the UAE and internationally to identify and address vulnerabilities in fundamental internet protocols, especially as it led to immediate action by Apache and Cyrus IMAPd.

UAE Launches Next-Gen GPS-Less Navigation and Secure Flight Control to Strengthen Aviation Security

TII ·

ADASI has adopted VentureOne's Perceptra, a GPS-less navigation technology, and Saluki, a high-security flight control technology, both developed by the Technology Innovation Institute (TII). These technologies enhance resilience, precision, and security for autonomous aerial operations, addressing vulnerabilities in GPS-dependent systems. The agreement was formalized at IDEX 2025. Why it matters: This deployment of advanced autonomous flight technologies in the UAE strengthens aviation security and positions the region as a leader in resilient, GPS-independent navigation solutions.

DomiRank: DERC’s Marcus Engsig Unveils Novel Centrality Metric to Establish System Integrity

TII ·

Marcus Engsig at DERC has developed DomiRank, a new centrality metric to quantify the dominance of nodes within networks. DomiRank integrates local and global topological information to determine the importance of each node for network stability. The research demonstrates that nodes with high DomiRank values indicate vulnerable areas heavily dependent on dominant nodes. Why it matters: This metric can help identify critical infrastructure components and vulnerabilities in complex systems, enhancing resilience against targeted attacks.

SSRC Partners with Purdue University on Game-Changing UAV Security Project

TII ·

TII's Secure Systems Research Center (SSRC) has partnered with Purdue University on a three-year cybersecurity project focused on ensuring the safe and efficient use of Unmanned Aerial Vehicles (UAVs) in urban environments. The collaboration will study security and resilience in cyber-physical and autonomous systems, addressing vulnerabilities in communication, navigation, and command and control. The project includes four phases: modeling and analysis of UAS security, developing algorithms for high-assurance autonomy, constructing an experimental environment, and testing mitigation strategies. Why it matters: The partnership enhances the UAE's capabilities in securing critical digital systems and fosters the growth of commercial autonomous drones and robots, opening new opportunities for enterprises.

How secure is AI-generated Code: A Large-Scale Comparison of Large Language Models

arXiv ·

A study compared the vulnerability of C programs generated by nine state-of-the-art Large Language Models (LLMs) using a zero-shot prompt. The researchers introduced FormAI-v2, a dataset of 331,000 C programs generated by these LLMs, and found that at least 62.07% of the generated programs contained vulnerabilities, detected via formal verification. The research highlights the need for risk assessment and validation when deploying LLM-generated code in production environments.

LLMEffiChecker: Understanding and Testing Efficiency Degradation of Large Language Models

arXiv ·

The paper introduces LLMEffiChecker, a tool to test the computational efficiency robustness of LLMs by identifying vulnerabilities that can significantly degrade performance. LLMEffiChecker uses both white-box (gradient-guided perturbation) and black-box (causal inference-based perturbation) methods to delay the generation of the end-of-sequence token. Experiments on nine public LLMs demonstrate that LLMEffiChecker can substantially increase response latency and energy consumption with minimal input perturbations.

Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark

arXiv ·

This paper introduces a novel black-box adversarial attack method, Mixup-Attack, to generate universal adversarial examples for remote sensing data. The method identifies common vulnerabilities in neural networks by attacking features in the shallow layer of a surrogate model. The authors also present UAE-RS, the first dataset of black-box adversarial samples in remote sensing, to benchmark the robustness of deep learning models against adversarial attacks.