[ public_research_archive ]
Research that narrows the possible
We study which AI safety and security approaches work, which fail, and which cannot provide the guarantees people expect. The newest work appears first; links point to the authoritative paper source.
IDTitleCategoryDateDownload
001Beyond Injection Detection: A Positive-Security Prompt Firewall that Closes the Scope and PHI Gap SOTA Classifiers Miss in HealthcarePresents QFIRE, an inline, provider-agnostic prompt firewall for healthcare AI agents that combines positive-security scope constraints, an asynchronous detector graph, and de-obfuscation — and releases QFIRE-HealthBench, where generic injection detectors recover only 0.40 recall while QFIRE's scope+PHI chain reaches 0.83.
J. Schwoebel, I. Semenec, J. Rousseva, M. G. Frasch, R. Thorstenson, M. Bhatt
Healthcare AI Security2026.06↗ Source002The Defense Trilemma: Why Prompt Injection Defense Wrappers Fail?Proves that continuity, utility preservation, and complete safety cannot coexist for prompt-injection wrapper defenses, and characterizes the boundary where every such defense must fail.
M. Bhatt, S. Munshi, V. S. Narajala, I. Habler, A. Al-Kahfah, K. Huang, J. Webb, B. Gatto, M. T. Hoque
AI Safety Theory2026.04↗ Source003LAAF: Logic-layer Automated Attack Framework — A Systematic Red-Teaming Methodology for LPCI Vulnerabilities in Agentic Large Language Model SystemsIntroduces an automated framework for testing logic-layer prompt-control injection across persistent memory, retrieval pipelines, tools, and multi-stage agent lifecycles.
H. Atta, K. Huang, K. R. Lambros, Y. Mehmood, M. Z. Baig, M. A. Rahman, M. Bhatt, et al.
Agent Security2026.03↗ Source004AI Safety2026.02↗ Source005Red Teaming2026.01↗ Source006AI Assurance2025.11↗ Source007Agent Security2025.07↗ Source008Agent Security2025.07↗ Source009Evaluation Theory2025.06↗ Source010Multi-Agent Systems2025.06↗ Source011Hierarchy-Based File Fragment ClassificationIntroduces a hierarchy-based machine-learning approach to classifying file fragments — a core digital-forensics problem when file-system metadata is unavailable — improving type identification from raw binary content.
M. Bhatt, A. Mishra, M. W. U. Kabir, S. E. Blake-Gatto, R. Rajendra, M. T. Hoque, G. G. Richard III, V. Roussev
Digital Forensics2020.07↗ Source012Nanoelectronics2018.11↗ Source013Digital Forensics2018.07↗ Source014Security Education2018.02↗ Source015Systems Security2018.01↗ Source016Nanoelectronics2016.10↗ Source017Nanoelectronics2015.06↗ Source018Nanoelectronics2015.04↗ Source