Organizations/platform

Huawei

Technology company; authors of two arXiv papers listed Huawei Research Zurich and Huawei Hong Kong.

2 records1 attack1 defenseWebsite
Sep 30, 2026
Pretext: Huawei researchers evade NVIDIA's SkillSpector skill scanner with an LLM attacker that learns across generations
AttackPaperHuawei

Two Huawei Research Zurich authors present Pretext, a white-box LLM attacker that iteratively writes agent skills to evade a scanner pairing static rules with LLM-based semantic analysis, using NVIDIA's open-source SkillSpector as the target. Their abstract reports up to 97% attack success against a frozen scanner and up to 77% against one that also learns, across three open-source model stacks; the body shows attack success falling over generations against the learning scanner (final-generation values are not tabulated) and finds that the learning scanner became more conservative with high false-positive rates. Commercial scanners were not tested.

Sep 30, 2026
Speculative Safety Honeypot: Huawei authors predict an agent's next actions with small simulators to flag multi-turn attacks
DefensePaperHuawei

Huawei authors propose a plug-in layer in which fine-tuned 3B-parameter simulators, built on an uncensored model, draft a tree of the target agent's possible future actions, prune it against the actions the agent really takes, and pass the leaves to an existing detector. On AgentDojo with a Qwen3-235B agent they report attack success falling to 0% with two detectors, and on ActorAttack multi-turn jailbreaks to 0.0% at a sampling budget of 5. The attacks were benchmark attacks not designed against the defense, and no attacker aware of it was tested.