---
title: Hiding In Plain Sight (HIPS)
url: https://www.emergentmind.com/topics/hiding-in-plain-sight-hips
type: topic
---

# Hiding In Plain Sight (HIPS)

Searching arXiv for recent and relevant papers on “Hiding in Plain Sight / HIPS” across domains.
arXiv search query: all:"Hiding in Plain Sight" OR all:"Hidden in Plain Sight" OR all:"Clusters Hiding in Plain Sight"
I’m using the arXiv search tool to gather the relevant papers now.
In the arXiv literature, **Hiding In Plain Sight (HIPS)** is not a single formalism but a recurrent research label for situations in which the signal, object, or mechanism of interest is already present in ordinary data and infrastructure, yet is missed because prevailing pipelines classify it as background, nuisance structure, or an unremarkable point source. In astronomy, HIPS denotes galaxy clusters whose extreme central galaxies cause them to be cataloged as isolated X-ray point sources rather than extended intracluster media [1611.07996, 2101.01730]. In Android security, it denotes sensitive strings or data flows concealed by obfuscation and custom encryption even though the corresponding decoding logic or keys remain in the application [2002.04540, 2209.15107]. In adversarial ML, federated learning, hardware security, communications, and network abuse, the phrase is reused for selective concealment within standard embeddings, benchmarks, waveforms, traffic traces, and domain names [2410.13010, 2306.03013, 2410.15550, 1905.02250, 2503.05418, 1708.08519].

## 1. Terminological scope and recurring structure

A cross-domain reading suggests that HIPS names a characteristic failure mode of detection rather than a single disciplinary method. The concealed entity is not absent; it is embedded in a form that standard classifiers, survey heuristics, or human operators treat as ordinary. This shared logic is visible across astrophysical survey incompleteness, string obfuscation, covert channels, adversarial perturbations, and benchmark design.

| Domain | HIPS meaning | Representative papers |
|---|---|---|
| X-ray cluster astronomy | Compact cores or AGN-dominated BCGs make clusters look point-like | [1611.07996], [2101.01730], [2101.01731] |
| Android security and privacy | Secrets or data leaks remain recoverable because deobfuscation or custom encryption logic co-resides with data | [2002.04540], [2209.15107] |
| Adversarial ML and FL | Perturbations or latent decoders selectively hide objects or examples while preserving normal-looking outputs | [2410.13010], [2306.03013] |
| Hardware trust | Functionally equivalent restructuring causes Trojan-infected circuits to overlap with clean ones in feature space | [2410.15550] |
| Communications and traffic analysis | Covert data, protected sensing targets, or IoT identities are masked inside ordinary transmissions | [1905.02250], [2503.05418], [2501.15395] |
| DNS abuse | Trademark-containing domains resemble legitimate naming rather than canonical squatting variants | [1708.08519] |
| Stellar and collider phenomenology | Spot crossings or electroweakino signals appear as nuisances or modest excesses in standard analyses | [2111.00828], [1206.6888] |

Two recurring misconceptions are explicitly challenged in this literature. First, point-like or otherwise ordinary-looking observations are not necessarily simple background objects; this is central to the CHiPS survey and related HIPS astronomy papers [1611.07996, 2101.01730]. Second, obfuscation is not equivalent to secrecy when the reconstruction mechanism must be shipped with the protected artifact, a point made directly in the Android string-obfuscation literature [2002.04540].

## 2. Astronomical HIPS: survey incompleteness, cool cores, and extreme BCGs

The astronomical usage is historically one of the most developed. Green et al. define HIPS as the recovery of galaxy clusters whose strong central AGN or compact cool cores caused them to be treated as isolated ROSAT All-Sky Survey point sources rather than cluster-scale halos [1611.07996]. Their procedure started from the RASS Bright Source Catalogue, examining approximately 3500 spectroscopically confirmed AGN at \(z<0.4\) within the Pan-STARRS1 3\(\pi\) footprint, constructing color-magnitude diagrams inside a \(0.5'\) aperture, identifying red sequences, and selecting 22 HIPS candidates. Richness was defined as
\[
\lambda \equiv N_{\rm RS}(i < -19.0~{\rm mag}, r < R_{\rm ap}),
\]
and the candidate systems were compared against a control sample of approximately 1000 confirmed clusters in the \(L_X\)-richness plane [1611.07996].

Somboonpanyakul et al. converted this logic into the **Clusters Hiding in Plain Sight (CHiPS)** survey. The core premise was that extreme brightest cluster galaxies can dominate the ROSAT point-spread function so strongly that the surrounding ICM never registers as extended [2101.01730]. The survey began from the ROSAT Bright and Faint Source Catalogs, cross-matched to NVSS or SUMSS, WISE, and 2MASS, applied “Phoenix-like” flux-ratio cuts, restricted to \(0.1<z<0.7\) and \(|b|>15^\circ\), and produced 470 multiwavelength-bright point sources. Optical follow-up and cluster finding reduced these to 11 objects above the REFLEX-equivalent richness threshold: six known clusters, two line-of-sight superpositions, and three new candidates. Chandra follow-up confirmed two newly discovered massive clusters, CHIPS1356–3421 and CHIPS1911+4455, while CHIPS2155–3727 lacked detectable extended emission [2101.01730].

For CHIPS1356–3421, the first CHiPS discovery around PKS 1353–341, Chandra data showed a relaxed morphology, a central temperature drop, and a central cooling time of approximately \(300\)–\(400\) Myr at \(10\) kpc, consistent with a strong cool core [1806.05676]. After removing the nuclear point source contribution, the cluster had \(M_{500}=(6.9^{+4.3}_{-2.6})\times10^{14}\,M_\odot\), bolometric \(L_X=7\times10^{44}\,{\rm erg\,s^{-1}}\), a BCG star-formation rate of \(6.2\pm3.6\,M_\odot\,{\rm yr^{-1}}\), and AGN radiative plus mechanical power of order \(5\times10^{45}\,{\rm erg\,s^{-1}}\) [1806.05676].

CHIPS1911+4455 became the flagship CHiPS case because it combined an extreme cool core with disturbed large-scale morphology. It lies at \(z=0.485\pm0.005\), has \(R_{500}=1075\pm60\) kpc, \(M_{500}=6.0\pm0.1\times10^{14}\,M_\odot\), and \(L_X=1.9\times10^{45}\,{\rm erg\,s^{-1}}\) [2101.01730]. Thermodynamic analysis defined
\[
K(r)\equiv kT\,n_e^{-2/3},
\]
with \(K_0\equiv K(r=10\,{\rm kpc})=17^{+2}_{-9}\,{\rm keV\,cm^2}\), and
\[
t_{\rm cool}(r)=\frac{3}{2}\frac{(n_e+n_p)kT}{n_e n_p \Lambda(T)},
\]
with \(t_{\rm cool}\approx100\) Myr at \(10\) kpc [2101.01731]. Despite these hallmarks of a strong cool core, the source is highly asymmetric on large scales, with an elongated Chandra core and two brightness peaks separated by \(\sim30\) kpc. HST F550M imaging reveals blue filamentary emission extending \(\sim30\) kpc north and south of the BCG, and star-formation diagnostics give \( {\rm SFR}_{[{\rm O\,II}]}=189^{+25}_{-22}\,M_\odot\,{\rm yr^{-1}} \), \( {\rm SFR}_{24\mu{\rm m}}=143^{+31}_{-26}\,M_\odot\,{\rm yr^{-1}} \), and an adopted \( {\rm SFR}\simeq140\)–\(190\,M_\odot\,{\rm yr^{-1}} \) [2101.01731].

The broader survey consequence is quantitative: CHiPS estimates that clusters appearing as X-ray bright point sources in ROSAT-like surveys occur at \((2\pm1)\%\), while the occurrence rate of clusters with runaway cooling in their cores is \(<1\%\) [2101.01730]. This directly reframes HIPS as a survey-selection bias with implications for cluster cosmology and for the interplay between mergers, cooling, and AGN feedback.

## 3. Android HIPS: string obfuscation, custom encryption, and covert leakage

In Android reverse engineering, HIPS denotes the practice of storing sensitive literals in obfuscated form while embedding the recovery routine in the same APK. The key observation is expressed in three components: obfuscated data \(O\), deobfuscation algorithm \(D\), and original strings \(S\). Because the app must carry both \(O\) and \(D\), an analyst can locate \(D\), execute it on \(O\), and recover \(S\) [2002.04540]. The paper on **StringHound** organized 21 obfuscation schemes into bit-manipulation, block-cipher encryption, and custom encodings, with anti-analysis devices such as static initializers, object initializers, switch-statement loops, stack-call checks, and byte-array hiding. Its pipeline used a REPTree string classifier over 49 features, a method classifier based on Spearman-rank correlation of instruction-token distributions, targeted intra-procedural slicing, and JVM execution of injected slices. On 1000 randomly obfuscated APKs, StringHound achieved 100% success and 73.9% recall, versus 2.5% recall for Dex-Oracle and 0.01% for JMD, recovering up to 30 times more obfuscated strings than prior tools. In a study of 100,000 Google Play apps, 76% contained obfuscated strings, and these strings concealed URLs, SQL statements, permissions, certificates, crypto primitives, hard-coded credentials, root commands, and YouTube API keys [2002.04540].

A related Android privacy literature extends HIPS from strings to whole channels. **ThirdEye** was designed to detect leaks over non-standard and covert channels, including raw TCP, raw UDP, and shared-storage files, plus multiple layers of custom encryption over HTTP/S and non-HTTP protocols [2209.15107]. Its architecture combined device management, UI interaction, an operations logger, and a data-flow inspector, hooking socket calls, `javax.crypto.Cipher` methods, and storage I/O to connect plaintext, ciphertext, keys, IVs, and file writes. Applied to 12,598 top apps, the system found that 2887 apps used custom encryption or decryption for network transmission or shared storage, and 2465 of those 2887 apps sent device information over the network that could fingerprint users. It also identified 299 apps transmitting insecure encrypted content over HTTP or non-HTTP protocols, and 22 apps that used authentication tokens over HTTPS but also exposed them over insecure custom-encrypted HTTP or non-HTTP channels [2209.15107].

Taken together, these works make a precise distinction between **cryptographic concealment** and **analytical invisibility**. The first may be present, but the second often fails because the codebase itself contains the necessary reconstruction logic, protocol hooks, or fixed cryptographic material [2002.04540, 2209.15107].

## 4. HIPS in adversarial ML, federated learning, and hardware trust

In multimodal adversarial learning, **HiPS attacks** on CLIP define a highly selective objective: make one target object absent from a caption or classification while leaving the rest of the scene semantically intact [2410.13010]. The perturbation takes the standard form
\[
I_{\rm adv}=I+\delta,\qquad \|\delta\|_p\le\epsilon,
\]
and two variants were proposed. **HiPS-cls** suppresses CLIP similarity to a target class label while preserving similarities to other labels; **HiPS-cap** pushes the image toward a target caption that differs from the original only by omission of the target object. On 50 COCO images with two prominent foreground objects, PGD under \(L_\infty\) achieved a target object removal rate of 94%, remaining objects retention rate of 100%, attack success rate of 94%, and SSIM of 0.948 for HiPS-cls; the corresponding HiPS-cap values were 90%, 98%, 90%, and 0.922 [2410.13010]. The notable technical feature is not wholesale caption corruption but selective invisibility.

In federated learning, HIPS appears in the SEER attack framework against malicious-server detectability. The paper first argues that all prior malicious-server attacks are detectable either in weight space or gradient space, and formalizes gradient detectability with the Disaggregation Signal-to-Noise Ratio
\[
{\rm D\text{-}SNR}(\theta,\mathcal D)=
\max_{\ell\in{\rm layers}}
\max_i \frac{\|\nabla_\ell(x_i,y_i)\|}{
\left\|\frac{1}{B}\sum_j \nabla_\ell(x_j,y_j)-\nabla_\ell(x_i,y_i)\right\| }.
\]
SEER’s central idea is a secret decoder jointly trained with the shared model, so that the exposed gradient remains natural while a server-only latent map disaggregates one example and reconstructs it [2306.03013]. The method is demonstrated on realistic networks, with batch sizes up to 512 and under secure aggregation, and is presented as the first malicious-server attack satisfying the paper’s detectability requirements [2306.03013].

In hardware security, HIPS becomes a benchmark-design concept rather than an attack on end users. The **Seeker’s Dilemma** formulates Trojan detection as a hide-and-seek problem in which the defender does not know whether a given circuit is infected or not, i.e., \(k\ge 0\) Trojan instances rather than a known single Trojan [2410.15550]. The Seeker1 benchmark starts from eight ISCAS-85 circuits, applies 18 functional restructuring scripts in ABC, and generates 100 Trojan variants per restructuring via an RL-based inserter. The resulting feature overlap is measurable: PCA shows infected and clean variants intermingled, and HW2VEC’s true-positive rate ranges from 0% to 80% under one training scenario and 0% to 20% when more clean labels are added [2410.15550]. Here HIPS denotes a benchmarking regime in which malicious modifications are statistically close to clean structure.

## 5. Communications, traffic analysis, and network abuse

One communications usage of HIPS is wireless steganography through **pseudo-noise asymmetric shift keying (PN-ASK)**. The idea is to embed covert information in small amplitude shifts of phase-modulated symbols so that a conventional receiver expecting only \(M\)-PSK interprets the covert perturbation as ordinary channel or path-loss variation [1905.02250]. The transmitted signal is written as
\[
s(t)=A\bigl[1+\alpha(-1)^{b_c}p_n\bigr]e^{j(2\pi f_c t+\phi(b_p))}+n(t),
\]
where the covert bit \(b_c\) is mapped through amplitude factor \(\alpha\) and PN sequence \(p_n\). On a USRP N210 testbed and over IEEE 802.11g frames, PN-ASK delivered approximately \(1.5\) Mb/s on both primary and covert streams and improved throughput by more than \(8\times\) relative to prior art, while off-the-shelf WiFi hardware decoded only the primary payload [1905.02250].

A second communications usage arises in RIS-assisted integrated sensing and communication. In **RIS-Aided Target Obfuscation in ISAC**, HIPS denotes minimizing the maximum sensing SINR at an adversarial detector while maintaining sensing and communication SINR constraints for legitimate nodes [2503.05418]. The design jointly optimizes the BS beamformer \(W\), RIS phase matrix \(\Phi\), RIS receive combiner \(u\), and the division between reflecting and absorptive RIS elements. The reported gain is substantial: the proposed alternating-optimization and successive-convex-approximation framework achieves a 25 dB reduction in the maximum adversarial sensing SINR relative to an unprotected RIS-ISAC system, with adaptive RIS element assignment yielding a further 3 dB improvement over fixed configurations [2503.05418].

At the edge-network level, **IoT Traffic Camouflage** uses HIPS to denote a multi-technique metadata obfuscation framework positioned between a home LAN and the upstream router [2501.15395]. It combines six packet-level methods—Padding, Padding with XORing, Padding with Shifting, Constant Size Padding, Fragmentation, and Delay Randomization—and evaluates them against neural and tree-based traffic classifiers. Baseline neural-network accuracy on three public datasets was 94%, 91%, and 98%; after obfuscation, individual techniques reduced these to 30%/25%/5% for Padding, 29%/25%/5% for Padding+XOR, 29%/25%/5% for Padding+Shifting, 36%/20%/5% for Fragmentation, 32%/23%/16% for Constant-Size Padding, and 58%/68%/41% for Delay. After adaptive retraining, incremental training yielded 33.2%/43.3%/39.8%, and fine-tuning yielded 31.7%/48.5%/50.3% [2501.15395].

In DNS security, HIPS takes yet another form: **combosquatting**. A combosquatting domain contains a legitimate trademark as an intact substring but is not derivable from canonical typosquatting models [1708.08519]. The first large-scale study analyzed approximately 468 billion DNS records over almost six years and found that on a typical day there are roughly 100 times more active combosquatting domains than typosquatting ones. Fifty percent of all combosquatting domains live at least 100 days, and 60% of abusive combosquatting domains persist for more than 1000 days. The study also identified 174 phishing domains, 2573 affiliate-abuse domains, and at least 65 domains tied to APT campaigns [1708.08519]. This version of HIPS does not hide the target brand by distortion; it hides abuse by preserving the brand string intact.

## 6. Observational and phenomenological reinterpretations

In exoplanet transmission spectroscopy, HIPS refers to starspot or facula occultations during transit that are often masked out as nuisances even though they contain direct information about stellar heterogeneity [2111.00828]. A starspot crossing produces a wavelength-dependent bump,
\[
\Delta f(\lambda)=\frac{F_{\rm in\,spot\,occultation}-F_{\rm out\,of\,spot}}{F_{\rm out\,of\,spot}},
\]
and Bruno et al. simulate K- and M-dwarf systems observed with JWST NIRSpec/Prism and proposed NIRCam modes. Their results indicate that starspot temperatures can be constrained to within a few hundred kelvins, especially for K and M dwarfs with \( {\rm mag}_K\le 12.5 \) and large temperature contrasts [2111.00828]. The direct misconception addressed here is that spot-crossing bumps should simply be excised from spectrophotometric transits.

In collider phenomenology, **“Charginos Hiding In Plain Sight”** uses the phrase to describe \(O(100\,{\rm GeV})\) electroweakinos whose production and decay can mimic a modest excess in \(W^+W^-\) cross sections [1206.6888]. ATLAS and CMS 7 TeV and 8 TeV measurements exceeded SM NLO predictions by approximately \(1.5\)–\(2\,\sigma\), and the paper argues that charginos with \(m_{\tilde\chi_1^\pm}\sim100\)–\(130\) GeV improve the fit to differential distributions while remaining consistent with then-current constraints. For a benchmark with \(m_{\tilde\chi_1^\pm}=110\) GeV, the paper quotes \(\sigma_{\rm NLO}(pp\to\tilde\chi\tilde\chi)=4.3\) pb and an effective extra contribution after acceptance of \(\Delta \sigma^{\rm eff}\simeq0.17\) pb at LHC7, improving \(\chi^2/N_{\rm bins}\) from approximately \(1.1\to0.5\) for ATLAS7 and \(1.2\to0.7\) for CMS8 [1206.6888].

A plausible unifying implication of these otherwise disparate literatures is that HIPS denotes **misrecognition rather than invisibility**. The concealed object is usually not absent from the data. It is rendered difficult to notice because standard selection rules, feature spaces, or semantic expectations interpret it as a point source, nuisance fluctuation, normal traffic, harmless code, clean circuitry, or ordinary caption content. Across fields, HIPS research therefore tends to revise the detector, the benchmark, or the model of ordinary structure rather than merely amplifying the hidden signal [1611.07996, 2002.04540, 2410.15550].

Source: https://www.emergentmind.com/topics/hiding-in-plain-sight-hips