Dancer in the Dark: Synthesizing and Evaluating Polyglots for Blind Cross-Site Scripting
Fuente:
arXiv
Saved in:
| Main Authors: | Kirchner, Robin, Möller, Jonas, Musch, Marius, Klein, David, Rieck, Konrad, Johns, Martin |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Hardware-Triggered Backdoors
by: Möller, Jonas, et al.
Published: (2026)
by: Möller, Jonas, et al.
Published: (2026)
Fingerprinting Inference Systems of Large Language Models
by: Wimbauer, Anna, et al.
Published: (2026)
by: Wimbauer, Anna, et al.
Published: (2026)
Lazy Gatekeepers: A Large-Scale Study on SPF Configuration in the Wild
by: Czybik, Stefan, et al.
Published: (2025)
by: Czybik, Stefan, et al.
Published: (2025)
Practical Type Inference: High-Throughput Recovery of Real-World Structures and Function Signatures
by: Seidel, Lukas, et al.
Published: (2026)
by: Seidel, Lukas, et al.
Published: (2026)
LLM-based Vulnerability Discovery through the Lens of Code Metrics
by: Weissberg, Felix, et al.
Published: (2025)
by: Weissberg, Felix, et al.
Published: (2025)
Evil from Within: Machine Learning Backdoors through Hardware Trojans
by: Warnecke, Alexander, et al.
Published: (2023)
by: Warnecke, Alexander, et al.
Published: (2023)
Adversarial Observations in Weather Forecasting
by: Imgrund, Erik, et al.
Published: (2025)
by: Imgrund, Erik, et al.
Published: (2025)
On the Abuse and Detection of Polyglot Files
by: Koch, Luke, et al.
Published: (2024)
by: Koch, Luke, et al.
Published: (2024)
SoK: Where to Fuzz? Assessing Target Selection Methods in Directed Fuzzing
by: Weissberg, Felix, et al.
Published: (2025)
by: Weissberg, Felix, et al.
Published: (2025)
Leveraging LLM to Strengthen ML-Based Cross-Site Scripting Detection
by: Miczek, Dennis, et al.
Published: (2025)
by: Miczek, Dennis, et al.
Published: (2025)
Measuring Security Without Fooling Ourselves: Why Benchmarking Agents Is Hard
by: Abdelnabi, Sahar, et al.
Published: (2026)
by: Abdelnabi, Sahar, et al.
Published: (2026)
Toward Securing AI Agents Like Operating Systems
by: Pirch, Lukas, et al.
Published: (2026)
by: Pirch, Lukas, et al.
Published: (2026)
Directionality of the Voynich Script
by: Parisel, Christophe
Published: (2025)
by: Parisel, Christophe
Published: (2025)
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026)
by: Zhang, Lingming, et al.
Published: (2026)
On the Detection of Image-Scaling Attacks in Machine Learning
by: Quiring, Erwin, et al.
Published: (2023)
by: Quiring, Erwin, et al.
Published: (2023)
Poking Around in the Dark: Why a Shared Understanding of Components Matters
by: Reichmann, Felix, et al.
Published: (2026)
by: Reichmann, Felix, et al.
Published: (2026)
Good News for Script Kiddies? Evaluating Large Language Models for Automated Exploit Generation
by: Jin, David, et al.
Published: (2025)
by: Jin, David, et al.
Published: (2025)
Characterizing Phishing Pages by JavaScript Capabilities
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024)
by: Amjad, Abdul Haddi, et al.
Published: (2024)
Detecting Privilege Escalation in Polyglot Microservices via Agentic Program Analysis
by: Li, Penghui, et al.
Published: (2026)
by: Li, Penghui, et al.
Published: (2026)
I still know it's you! On Challenges in Anonymizing Source Code
by: Horlboge, Micha, et al.
Published: (2022)
by: Horlboge, Micha, et al.
Published: (2022)
Blind Evaluation Framework for Fully Homomorphic Encryption and Privacy-Preserving Machine Learning
by: Lee, Hunjae "Timothy", et al.
Published: (2023)
by: Lee, Hunjae "Timothy", et al.
Published: (2023)
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
by: Cornelissen, Eric, et al.
Published: (2024)
by: Cornelissen, Eric, et al.
Published: (2024)
The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts
by: Varlioglu, Said, et al.
Published: (2024)
by: Varlioglu, Said, et al.
Published: (2024)
An Empirical Study of JavaScript Inclusion Security Issues in Chrome Extensions
by: Guan, Chong
Published: (2025)
by: Guan, Chong
Published: (2025)
Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
by: Pereira, Pedro, et al.
Published: (2025)
by: Pereira, Pedro, et al.
Published: (2025)
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
by: Pagano, Francesco, et al.
Published: (2026)
by: Pagano, Francesco, et al.
Published: (2026)
JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript Deobfuscation
by: Chen, Guoqiang, et al.
Published: (2025)
by: Chen, Guoqiang, et al.
Published: (2025)
Cross-Chain Sealed-Bid Auctions Using Confidential Compute Blockchains
by: Gebele, Jonas, et al.
Published: (2025)
by: Gebele, Jonas, et al.
Published: (2025)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
by: Robinson, Michael, et al.
Published: (2026)
by: Robinson, Michael, et al.
Published: (2026)
Counterfactual Evaluation for Blind Attack Detection in LLM-based Evaluation Systems
by: Liu, Lijia, et al.
Published: (2025)
by: Liu, Lijia, et al.
Published: (2025)
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
by: Ali, Mir Masood, et al.
Published: (2024)
by: Ali, Mir Masood, et al.
Published: (2024)
Synthesizing Multi-Agent Harnesses for Vulnerability Discovery
by: Liu, Hanzhi, et al.
Published: (2026)
by: Liu, Hanzhi, et al.
Published: (2026)
BLACKOUT: Data-Oblivious Computation with Blinded Capabilities
by: ElAtali, Hossam, et al.
Published: (2025)
by: ElAtali, Hossam, et al.
Published: (2025)
Cross-Technology Generalization in Synthesized Speech Detection: Evaluating AST Models with Modern Voice Generators
by: Ustinov, Andrew, et al.
Published: (2025)
by: Ustinov, Andrew, et al.
Published: (2025)
How Blind and Low-Vision Users Manage Their Passwords
by: Ponticello, Alexander, et al.
Published: (2025)
by: Ponticello, Alexander, et al.
Published: (2025)
No Data? No Problem: Synthesizing Security Graphs for Better Intrusion Detection
by: Huang, Yi, et al.
Published: (2025)
by: Huang, Yi, et al.
Published: (2025)
BlindFL: Segmented Federated Learning with Fully Homomorphic Encryption
by: Gronberg, Evan, et al.
Published: (2025)
by: Gronberg, Evan, et al.
Published: (2025)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
Similar Items
-
Hardware-Triggered Backdoors
by: Möller, Jonas, et al.
Published: (2026) -
Fingerprinting Inference Systems of Large Language Models
by: Wimbauer, Anna, et al.
Published: (2026) -
Lazy Gatekeepers: A Large-Scale Study on SPF Configuration in the Wild
by: Czybik, Stefan, et al.
Published: (2025) -
Practical Type Inference: High-Throughput Recovery of Real-World Structures and Function Signatures
by: Seidel, Lukas, et al.
Published: (2026) -
LLM-based Vulnerability Discovery through the Lens of Code Metrics
by: Weissberg, Felix, et al.
Published: (2025)