Hidden Risks of Jev: An Empirical Study of Security, Privacy, and Dual Use

📅 2026-10-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the unknown security and privacy risks, as well as dual-use concerns, associated with Jev as an applied decision-making layer. We present the first systematic security assessment of Jev through both API-based and local model deployments, employing a comprehensive suite of attack vectors including prompt injection, adversarial suffixes, data poisoning, and membership inference to analyze its defense mechanisms and potential abuse scenarios. Our investigation reveals information leakage mechanisms under constrained output conditions, demonstrating significant security vulnerabilities in Jev. Furthermore, this work elucidates its dual-use potential, highlighting that while Jev can empower beneficial detection capabilities, it remains susceptible to malicious exploitation. These findings provide critical empirical evidence to inform the security governance of AI agents.
📝 Abstract
Jev turns natural-language questions into typed answers and probabilities with low latency and cost, enabling applications to route requests and select tools. While this interface allows Jev to integrate naturally into application workflows as a decision layer, the security and privacy implications of this emerging use remain largely unexplored. To address this gap, we conduct the first systematic study of these implications using the official Jev API and NanoJev, a local model with controllable training data and updates, focusing on three research questions: (1) What security threats arise when Jev is deployed as an application decision layer? (2) What private information can Jev reveal despite returning constrained typed outputs? (3) How can Jev's general-purpose decision capability be used for beneficial purposes or misused? Jev's decisions depend on application state and may be influenced by user-provided inputs. We therefore adapt prompt injection and adversarial suffixes to manipulate its decisions. Open-source Jev distribution and updates introduce supply-chain risks, which we examine by implanting backdoors in NanoJev through training data poisoning. Since Jev's outputs reflect both application state and information learned during training, we further adapt membership, private attribute, and internal knowledge inference attacks to recover sensitive information despite its constrained output format. Finally, Jev can serve as a general-purpose decision oracle for defensive and malicious workflows. We examine this dual use through four detection tasks covering prompt injection, jailbreak inputs, harmful content, and AI-generated text, alongside misuse scenarios involving jailbreak and model extraction. Our empirical evaluation shows that Jev remains vulnerable to the examined security and privacy threats, while its decision capability can support beneficial and malicious uses.
Problem

Research questions and friction points this paper is trying to address.

Security threats
Privacy leakage
Dual use
Decision layer
Prompt injection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Prompt Injection
Supply-chain Backdoor
Privacy Inference Attacks
Dual Use
Decision Layer Security
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
S
Shang Wang
School of Computer Science, University of Technology Sydney, Sydney, Australia
Tianqing Zhu
Tianqing Zhu
City University of Macau
PrivacyCyber SecurityMachine LearningAI Security
H
Huajie Chen
Faculty of Data Science, City University of Macau, Macau, China
J
Jiayang Li
School of Computer Science, University of Technology Sydney, Sydney, Australia
M
Meng Yang
School of Computer Science, University of Technology Sydney, Sydney, Australia
Bo Liu
Bo Liu
University of Technology Sydney
Cyber security and privacyAIwireless communications and networksbroadcasting