Institution profile

Université de Jendouba

Academic institutionafrica · tn
Official website
Research library2linked papers
Opportunities0open roles
Selected work

Representative Papers

PrompTrend: Continuous Community-Driven Vulnerability Discovery and Assessment for Large Language Models

Jul 25, 2025

Static benchmarking inadequately captures LLM security vulnerabilities exposed in real-world online community practices. To address this, we propose a community-driven dynamic monitoring paradigm, focusing on psychological attacks as the primary threat vector, revealing that capability advancement and safety improvement are misaligned. Methodologically, we design a cross-platform data collection system, a multidimensional scoring framework, and a scalable monitoring architecture—integrating horizontal comparative analysis with fine-grained vulnerability classification. Over five months, we conduct an empirical study across nine commercial LLMs. Our approach identifies 198 novel vulnerabilities with 78% classification accuracy; psychological attacks exhibit significantly higher detection rates than traditional exploit-based techniques yet demonstrate low cross-model transferability—highlighting their stealthiness and model specificity. This work pioneers systematic, continuous discovery and quantitative evaluation of community-emergent LLM vulnerabilities.

0 citationsRead paper

Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms

Jul 08, 2025

Current LLM agent security research treats AI-specific vulnerabilities and traditional software flaws in isolation, lacking a unified cross-domain evaluation framework. Method: This work presents the first systematic comparison of two dominant deployment paradigms—Function Calling (FC) and Model Context Protocol (MCP)—and introduces a unified threat taxonomy integrating AI reasoning vulnerabilities with classical software security concepts. We empirically evaluate the robustness of seven LLMs against prompt injection, JSON injection, DoS, and multi-step chained attacks across 3,250 adversarial scenarios. Contribution/Results: FC exhibits higher overall attack success (73.5% vs. 62.59%), but risks concentrate at the system layer; MCP exacerbates LLM centralization and exposure. Chained attacks achieve 91–96% success rates, and advanced reasoning models show heightened exploitability. Our findings reveal how architectural choices fundamentally reshape the threat landscape, establishing novel conceptual insights and practical benchmarks for secure LLM agent design.

0 citationsRead paper
Recent publications

Latest Papers

PrompTrend: Continuous Community-Driven Vulnerability Discovery and Assessment for Large Language Models

Jul 25, 2025

Static benchmarking inadequately captures LLM security vulnerabilities exposed in real-world online community practices. To address this, we propose a community-driven dynamic monitoring paradigm, focusing on psychological attacks as the primary threat vector, revealing that capability advancement and safety improvement are misaligned. Methodologically, we design a cross-platform data collection system, a multidimensional scoring framework, and a scalable monitoring architecture—integrating horizontal comparative analysis with fine-grained vulnerability classification. Over five months, we conduct an empirical study across nine commercial LLMs. Our approach identifies 198 novel vulnerabilities with 78% classification accuracy; psychological attacks exhibit significantly higher detection rates than traditional exploit-based techniques yet demonstrate low cross-model transferability—highlighting their stealthiness and model specificity. This work pioneers systematic, continuous discovery and quantitative evaluation of community-emergent LLM vulnerabilities.

0 citationsRead paper

Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms

Jul 08, 2025

Current LLM agent security research treats AI-specific vulnerabilities and traditional software flaws in isolation, lacking a unified cross-domain evaluation framework. Method: This work presents the first systematic comparison of two dominant deployment paradigms—Function Calling (FC) and Model Context Protocol (MCP)—and introduces a unified threat taxonomy integrating AI reasoning vulnerabilities with classical software security concepts. We empirically evaluate the robustness of seven LLMs against prompt injection, JSON injection, DoS, and multi-step chained attacks across 3,250 adversarial scenarios. Contribution/Results: FC exhibits higher overall attack success (73.5% vs. 62.59%), but risks concentrate at the system layer; MCP exacerbates LLM centralization and exposure. Chained attacks achieve 91–96% success rates, and advanced reasoning models show heightened exploitability. Our findings reveal how architectural choices fundamentally reshape the threat landscape, establishing novel conceptual insights and practical benchmarks for secure LLM agent design.

0 citationsRead paper