{"id":"https://openalex.org/W7157192086","doi":"https://doi.org/10.48550/arxiv.2604.23141","title":"UNSEEN: A Cross-Stack LLM Unlearning Defense against AR-LLM Social Engineering Attacks","display_name":"UNSEEN: A Cross-Stack LLM Unlearning Defense against AR-LLM Social Engineering Attacks","publication_year":2026,"publication_date":"2026-04-25","ids":{"openalex":"https://openalex.org/W7157192086","doi":"https://doi.org/10.48550/arxiv.2604.23141"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.23141","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23141","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.23141","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5134794494","display_name":"Tianlong Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Yu, Tianlong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134815896","display_name":"Yang Yang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yang, Yang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029465528","display_name":"Xiao Luo","orcid":"https://orcid.org/0000-0003-2574-4594"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Luo, Xiao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134780048","display_name":"Lihong Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Lihong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067561834","display_name":"\u661f\u798f \u675c","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xing, Fudu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5040608462","display_name":"Zui Tao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tao, Zui","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134782178","display_name":"Kailong Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Kailong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134820746","display_name":"Gaoyang Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Gaoyang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5066483747","display_name":"Ting Bi","orcid":"https://orcid.org/0000-0001-6196-5613"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bi, Ting","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5134794494"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.25929999351501465,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.25929999351501465,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.1476999968290329,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.10350000113248825,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/social-engineering","display_name":"Social engineering (security)","score":0.8296999931335449},{"id":"https://openalex.org/keywords/vendor","display_name":"Vendor","score":0.5692999958992004},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5457000136375427},{"id":"https://openalex.org/keywords/conversation","display_name":"Conversation","score":0.5062000155448914},{"id":"https://openalex.org/keywords/access-control","display_name":"Access control","score":0.4620000123977661},{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.4537999927997589},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.38609999418258667}],"concepts":[{"id":"https://openalex.org/C70118762","wikidata":"https://www.wikidata.org/wiki/Q376934","display_name":"Social engineering (security)","level":2,"score":0.8296999931335449},{"id":"https://openalex.org/C2777338717","wikidata":"https://www.wikidata.org/wiki/Q1762621","display_name":"Vendor","level":2,"score":0.5692999958992004},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5457000136375427},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5370000004768372},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.521399974822998},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.5164999961853027},{"id":"https://openalex.org/C2777200299","wikidata":"https://www.wikidata.org/wiki/Q52943","display_name":"Conversation","level":2,"score":0.5062000155448914},{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.4620000123977661},{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.4537999927997589},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.38609999418258667},{"id":"https://openalex.org/C2777351106","wikidata":"https://www.wikidata.org/wiki/Q49371","display_name":"Legislation","level":2,"score":0.36820000410079956},{"id":"https://openalex.org/C167981075","wikidata":"https://www.wikidata.org/wiki/Q2667186","display_name":"Sandbox (software development)","level":2,"score":0.34630000591278076},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.3222000002861023},{"id":"https://openalex.org/C37497375","wikidata":"https://www.wikidata.org/wiki/Q623971","display_name":"Social control","level":2,"score":0.3199000060558319},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.31060001254081726},{"id":"https://openalex.org/C518677369","wikidata":"https://www.wikidata.org/wiki/Q202833","display_name":"Social media","level":2,"score":0.3077999949455261},{"id":"https://openalex.org/C10144332","wikidata":"https://www.wikidata.org/wiki/Q14645","display_name":"Rootkit","level":3,"score":0.30169999599456787},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.2718999981880188},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.260699987411499},{"id":"https://openalex.org/C79416737","wikidata":"https://www.wikidata.org/wiki/Q2305519","display_name":"Social learning","level":2,"score":0.257999986410141},{"id":"https://openalex.org/C67497173","wikidata":"https://www.wikidata.org/wiki/Q977345","display_name":"Legal aspects of computing","level":3,"score":0.2529999911785126}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.23141","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23141","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.23141","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23141","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Emerging":[0],"AR-LLM-based":[1],"Social":[2],"Engineering":[3],"attack":[4],"(e.g.,":[5],"SEAR)":[6],"is":[7],"at":[8],"the":[9,23,33,39,42,46,50,54,67,91],"edge":[10],"of":[11,38,215],"posing":[12],"great":[13],"threats":[14],"to":[15,31,44,57,65,90,117],"real-world":[16],"social":[17,51,59,108,221],"life.":[18],"In":[19],"such":[20,77],"AR-LLM-SE":[21],"attack,":[22],"attacker":[24],"can":[25],"leverage":[26],"AR":[27,97,178],"(Augmented":[28],"Reality)":[29],"glass":[30],"capture":[32],"image":[34],"and":[35,48,70,99,106,129,136,159,193,212],"vocal":[36],"information":[37],"target,":[40],"using":[41,53],"LLM":[43,55,101,157,187],"identify":[45],"target":[47,68],"generate":[49],"profile,":[52],"agents":[56],"apply":[58],"engineering":[60,109],"strategies":[61],"for":[62,183,189,197],"conversation":[63],"suggestion":[64],"win":[66],"trust":[69],"perform":[71],"phishing":[72],"afterwards.":[73],"Current":[74],"defensive":[75],"approaches,":[76],"as":[78],"role-based":[79],"access":[80,153],"control":[81,154],"or":[82],"data":[83],"flow":[84],"tracking,":[85],"are":[86,115],"not":[87],"directly":[88],"applicable":[89],"convergent":[92],"AR-LLM":[93],"ecosystem":[94],"(considering":[95],"embedded":[96],"device":[98],"opaque":[100,156],"inference),":[102],"leaving":[103],"an":[104,177,205],"emerging":[105],"potent":[107],"threat":[110],"that":[111,175],"existing":[112],"privacy":[113],"paradigms":[114],"ill-equipped":[116],"address.":[118],"This":[119],"necessitates":[120],"a":[121,171,213],"shift":[122],"beyond":[123],"solely":[124],"human-centric":[125],"measures":[126],"like":[127],"legislation":[128],"user":[130,207],"education":[131],"toward":[132],"enforceable":[133],"vendor":[134],"policies":[135],"platform-level":[137],"restrictions.":[138],"Realizing":[139],"this":[140],"vision,":[141],"however,":[142],"faces":[143],"significant":[144],"technical":[145],"challenges:":[146],"securing":[147],"resource-constrained":[148],"AR-embedded":[149],"devices,":[150],"implementing":[151],"fine-grained":[152],"within":[155],"inferences,":[158],"governing":[160],"adaptive":[161,198],"interactive":[162],"agents.":[163],"To":[164],"address":[165],"these":[166],"challenges,":[167],"we":[168],"present":[169],"UNSEEN,":[170],"coordinated":[172],"cross-stack":[173],"defense":[174],"combines":[176],"ACL":[179],"(Access":[180],"Control":[181],"Layer)":[182],"identity-gated":[184],"sensing,":[185],"F-RMU-based":[186],"unlearning":[188],"sensitive":[190],"profile":[191],"suppression,":[192],"runtime":[194],"agent":[195],"guardrails":[196],"interaction":[199],"control.":[200],"We":[201],"evaluate":[202],"UNSEEN":[203],"in":[204],"IRB-approved":[206],"study":[208],"with":[209],"60":[210],"participants":[211],"dataset":[214],"360":[216],"annotated":[217],"conversations":[218],"across":[219],"realistic":[220],"scenarios.":[222]},"counts_by_year":[],"updated_date":"2026-04-29T06:16:36.941037","created_date":"2026-04-29T00:00:00"}
