Goto

Collaborating Authors

 Government


LLM-Based User Simulation for Low-Knowledge Shilling Attacks on Recommender Systems

arXiv.org Artificial Intelligence

Recommender systems (RS) are increasingly vulnerable to shilling attacks, where adversaries inject fake user profiles to manipulate system outputs. Traditional attack strategies often rely on simplistic heuristics, require access to internal RS data, and overlook the manipulation potential of textual reviews. In this work, we introduce Agent4SR, a novel framework that leverages Large Language Model (LLM)-based agents to perform low-knowledge, high-impact shilling attacks through both rating and review generation. Agent4SR simulates realistic user behavior by orchestrating adversarial interactions, selecting items, assigning ratings, and crafting reviews, while maintaining behavioral plausibility. Our design includes targeted profile construction, hybrid memory retrieval, and a review attack strategy that propagates target item features across unrelated reviews to amplify manipulation. Extensive experiments on multiple datasets and RS architectures demonstrate that Agent4SR outperforms existing low-knowledge baselines in both effectiveness and stealth. Our findings reveal a new class of emergent threats posed by LLM-driven agents, underscoring the urgent need for enhanced defenses in modern recommender systems.


What if Deception Cannot be Detected? A Cross-Linguistic Study on the Limits of Deception Detection from Text

arXiv.org Artificial Intelligence

Can deception be detected solely from written text? Cues of deceptive communication are inherently subtle, even more so in text-only communication. Yet, prior studies have reported considerable success in automatic deception detection. We hypothesize that such findings are largely driven by artifacts introduced during data collection and do not generalize beyond specific datasets. We revisit this assumption by introducing a belief-based deception framework, which defines deception as a misalignment between an author's claims and true beliefs, irrespective of factual accuracy, allowing deception cues to be studied in isolation. Based on this framework, we construct three corpora, collectively referred to as DeFaBel, including a German-language corpus of deceptive and non-deceptive arguments and a multilingual version in German and English, each collected under varying conditions to account for belief change and enable cross-linguistic analysis. Using these corpora, we evaluate commonly reported linguistic cues of deception. Across all three DeFaBel variants, these cues show negligible, statistically insignificant correlations with deception labels, contrary to prior work that treats such cues as reliable indicators. We further benchmark against other English deception datasets following similar data collection protocols. While some show statistically significant correlations, effect sizes remain low and, critically, the set of predictive cues is inconsistent across datasets. We also evaluate deception detection using feature-based models, pretrained language models, and instruction-tuned large language models. While some models perform well on established deception datasets, they consistently perform near chance on DeFaBel. Our findings challenge the assumption that deception can be reliably inferred from linguistic cues and call for rethinking how deception is studied and modeled in NLP.


Peek-a-boo, Big Tech sees you: Expert warns just 20 cloud images can make an AI deepfake video of your child

FOX News

Texas high school student Elliston Berry joins'Fox & Friends' to discuss the House's passage of a new bill that criminalizes the sharing of non-consensual intimate images, including content created with artificial intelligence. Parents love capturing their kids' big moments, from first steps to birthday candles. But a new study out of the U.K. shows many of those treasured images may be scanned, analyzed and turned into data by cloud storage services, and nearly half of parents don't even realize it. A survey of 2,019 U.K. parents, conducted by Perspectus Global and commissioned by Swiss privacy tech company Proton, found that 48% of parents were unaware providers like Google Photos, Apple iCloud, Amazon Photos and Dropbox can access and analyze the photos they upload. First lady Melania Trump, joined by President Donald Trump, delivers remarks before President Trump signed the Take it Down Act into law in the Rose Garden of the White House May 19, 2025, in Washington, D.C. (Chip Somodevilla/Getty Images) These companies use artificial intelligence to sort images into albums, recognize faces and locations and suggest memories.


Urgent warning to Americans over 'dangerous' technology quietly rolled out in 80 airports

Daily Mail - Science & tech

Within seconds, you've been scanned, stored, and tracked--before even reaching airport security. Without ever handing over your ID, the Transportation Security Administration (TSA) already knows exactly who you are. This is happening at 84 airports across the US. And chances are, you didn't even notice. Marketed as a tool to enhance security, TSA's facial recognition system is drawing criticism for its potential to track Americans from the terminal entrance to their final destination.


31 million tons of seaweed ready to stink up Florida's beaches

Popular Science

Breakthroughs, discoveries, and DIY tips sent every weekday. A smelly, sometimes toxic "killer belt of seaweed" might put a damper on Floridians' Memorial Day weekend plans. Sargassum is back just in time for the unofficial start of summer and this year's influx of the brown algae would be record breaking at 31 million tons. Sargassum is a genus of large brown seaweed. As a seaweed, it is also a type of algae.


UFO crashes into US Air Force fighter jet over Arizona during terrifying encounter

Daily Mail - Science & tech

A UFO slammed into a US fighter jet over Arizona, cracking the canopy protecting the pilot, and forcing the 63 million plane to land, new reports have revealed. According to the Federal Aviation Administration (FAA), the F-16 Viper fighter jet was hit by an'orange-white UAS' - which stands for uncrewed aerial system, better known as a drone - on January 19, 2023. Within a day of this collision, there were three more unidentified aircraft sightings over the Air Force's Barry Goldwater Range, where the fighter was damaged, the documents stated. Barry Goldwater Range is an expanse of desert along the Arizona-Mexico border where the military practices air-to-air and air-to-ground combat. The FAA's report of the F-16 collision revealed that the fighter was flying in restricted airspace near Gila Bend, Arizona, when it was hit by the object in the rear of the canopy, the glass bubble which protects the pilot.


Singapore envoy eyes stronger cyber and digital links with Japan

The Japan Times

Cybersecurity and digitalization are among five key areas where Japan and Singapore plan to take relations to fresh highs next year as the partners look to step up cooperation on emerging technologies such as quantum computing, according to the city-state's envoy to Tokyo. "When it comes to cybersecurity, there are so many different areas that you can look at," Ambassador Ong Eng Chuan said in an interview with The Japan Times ahead of the two countries' 60th anniversary of diplomatic relations in 2026. "While today is artificial intelligence, tomorrow we're looking at the possibility of quantum technology, taking it a step further," he said, noting that post-quantum cryptography -- the development of cryptographic systems designed to be secure against both quantum and classical computers -- "is going to create a whole new set of challenges and opportunities."


China says U.S. warnings on Huawei chips undermine their recent trade talks

The Japan Times

The Chinese government has accused U.S. President Donald Trump's administration of undermining recent trade talks in Geneva with its warning that using Huawei Technologies' artificial intelligence chips "anywhere in the world" would violate U.S. export controls. The U.S. Commerce Department had said in a statement last week that it was issuing guidance to make clear that the use of Huawei Ascend chips is a breach of the U.S. government's export controls. The agency said at the time that it would also warn the public about "the potential consequences of allowing U.S. AI chips to be used for training and inference of Chinese AI models." The department's statement has since changed to say that the agency was issuing guidance about "the risks of using PRC advanced computing ICs, including specific Huawei Ascend chips," stripping the "anywhere in the world" reference. PRC is the abbreviation for China's formal name, the People's Republic of China, while ICs refers to integrated circuits, or chips.


RM-R1: Reward Modeling as Reasoning

arXiv.org Artificial Intelligence

Reward modeling is essential for aligning large language models with human preferences through reinforcement learning from human feedback. To provide accurate reward signals, a reward model (RM) should stimulate deep thinking and conduct interpretable reasoning before assigning a score or a judgment. Inspired by recent advances of long chain-of-thought on reasoning-intensive tasks, we hypothesize and validate that integrating reasoning capabilities into reward modeling significantly enhances RMs interpretability and performance. To this end, we introduce a new class of generative reward models - Reasoning Reward Models (ReasRMs) - which formulate reward modeling as a reasoning task. We propose a reasoning-oriented training pipeline and train a family of ReasRMs, RM-R1. RM-R1 features a chain-of-rubrics (CoR) mechanism - self-generating sample-level chat rubrics or math/code solutions, and evaluating candidate responses against them. The training of RM-R1 consists of two key stages: (1) distillation of high-quality reasoning chains and (2) reinforcement learning with verifiable rewards. Empirically, our models achieve state-of-the-art performance across three reward model benchmarks on average, outperforming much larger open-weight models (e.g., INF-ORM-Llama3.1-70B) and proprietary ones (e.g., GPT-4o) by up to 4.9%. Beyond final performance, we perform thorough empirical analyses to understand the key ingredients of successful ReasRM training. To facilitate future research, we release six REASRM models along with code and data at https://github.com/RM-R1-UIUC/RM-R1.


RoVo: Robust Voice Protection Against Unauthorized Speech Synthesis with Embedding-Level Perturbations

arXiv.org Artificial Intelligence

With the advancement of AI-based speech synthesis technologies such as Deep Voice, there is an increasing risk of voice spoofing attacks, including voice phishing and fake news, through unauthorized use of others' voices. Existing defenses that inject adversarial perturbations directly into audio signals have limited effectiveness, as these perturbations can easily be neutralized by speech enhancement methods. To overcome this limitation, we propose RoVo (Robust Voice), a novel proactive defense technique that injects adversarial perturbations into high-dimensional embedding vectors of audio signals, reconstructing them into protected speech. This approach effectively defends against speech synthesis attacks and also provides strong resistance to speech enhancement models, which represent a secondary attack threat. In extensive experiments, RoVo increased the Defense Success Rate (DSR) by over 70% compared to unprotected speech, across four state-of-the-art speech synthesis models. Specifically, RoVo achieved a DSR of 99.5% on a commercial speaker-verification API, effectively neutralizing speech synthesis attack. Moreover, RoVo's perturbations remained robust even under strong speech enhancement conditions, outperforming traditional methods. A user study confirmed that RoVo preserves both naturalness and usability of protected speech, highlighting its effectiveness in complex and evolving threat scenarios.