Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Singapore Management University (1102)
- Embry-Riddle Aeronautical University (768)
- Edith Cowan University (532)
- Kennesaw State University (300)
- Old Dominion University (256)
-
- Air Force Institute of Technology (181)
- San Jose State University (117)
- Bridgewater State University (73)
- Clark University (71)
- University of New Haven (65)
- United Arab Emirates University (64)
- University of Arkansas, Fayetteville (59)
- City University of New York (CUNY) (55)
- Dakota State University (49)
- California State University, San Bernardino (34)
- Nova Southeastern University (33)
- Maurer School of Law: Indiana University (32)
- University for Business and Technology in Kosovo (30)
- University of Central Florida (24)
- University of South Alabama (23)
- University of Dayton (22)
- Franklin University (21)
- LSU New Orleans (21)
- University of Nebraska at Omaha (20)
- Wayne State University (20)
- California Polytechnic State University, San Luis Obispo (18)
- University of Kentucky (18)
- Florida Institute of Technology (17)
- Louisiana State University (16)
- Portland State University (16)
- Keyword
-
- Cybersecurity (317)
- Security (246)
- Privacy (163)
- Computer security (101)
- Digital forensics (89)
-
- Information security (89)
- Blockchain (88)
- Machine learning (82)
- Authentication (71)
- Cryptography (71)
- Cloud computing (68)
- Encryption (65)
- Data privacy (62)
- [RSTDPub] (54)
- Cyber security (53)
- Access control (50)
- Data protection (47)
- Network security (45)
- Malware (41)
- Machine Learning (39)
- Android (38)
- Artificial intelligence (38)
- Computer networks--Security measures (38)
- Cybercrime (38)
- Internet of Things (36)
- Deep learning (34)
- Digital Forensics (34)
- Intrusion detection (33)
- MPA (33)
- Forensics (31)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1051)
- Journal of Digital Forensics, Security and Law (536)
- Australian Information Security Management Conference (224)
- Theses and Dissertations (212)
- Annual ADFSL Conference on Digital Forensics, Security and Law (186)
-
- Journal of Cybersecurity Education, Research and Practice (171)
- Master's Projects (107)
- KSU Proceedings on Cybersecurity Education, Research and Practice (97)
- Cybersecurity Undergraduate Research Showcase (90)
- Research outputs 2022 to 2026 (84)
- International Journal of Cybersecurity Intelligence & Cybercrime (72)
- School of Professional Studies (71)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Australian Digital Forensics Conference (50)
- Theses (45)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
- Computer Science Faculty Publications (40)
- Masters Theses & Doctoral Dissertations (34)
- CCAC Theses and Dissertations (33)
- Graduate Theses and Dissertations (33)
- Articles by Maurer Faculty (31)
- Publications (29)
- Electronic Theses and Dissertations (25)
- UBT International Conference (24)
- VMASC Publications (24)
- Electrical & Computer Engineering Faculty Publications (23)
- Open Educational Resources (23)
- Faculty Publications (22)
- LSU New Orleans Theses and Dissertations (21)
- Publication Type
Articles 61 - 90 of 4669
Full-Text Articles in Computer Sciences
Sevoauth: Secure Voiceprint Authentication With Hash-Based Feature Transformation, Rui Zhang, Zheng Yan, Robert H. Deng
Sevoauth: Secure Voiceprint Authentication With Hash-Based Feature Transformation, Rui Zhang, Zheng Yan, Robert H. Deng
Research Collection School Of Computing and Information Systems
While voiceprint authentication offers convenient user authentication and access control through voice feature recognition, a critical research gap remains: existing voiceprint authentication systems fail to simultaneously achieve sound security against replay, spoofing, and adversarial attacks, preserve voice privacy leakage, and satisfy usability demand. Previous efforts have struggled to balance these issues comprehensively. To bridge this gap, we present SeVoAuth, a cloud-based Voiceprint Authentication as a Service (VAaaS) system designed to provide privacy preservation, robust security, and enhanced usability. SeVoAuth stores a synthesized voiceprint of a user in the cloud during user registration, thereby safeguarding the privacy of the real voiceprint …
Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training, Doc Harley
Senior Honors Theses
Currently, the leading technologies in the market of adversarial emulation are MITRE Caldera, Atomic Red Team by IBM, and multiple proprietary products that come with support packages for different vendors like AttackIQ, Cymulate, SafeBreach, and many more. While it is clear that much work has been done in the broad category of adversarial emulation, when it comes to open source solutions, there are no agentless options with built in automation and modularity that have good support for cloud environments. Agentless adversarial emulation provides a unique advantage in that it can be both simpler and a better representation of the true …
Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir
Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir
Cybersecurity Undergraduate Research Showcase
Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs
Cybersecurity Undergraduate Research Showcase
Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry
Cybersecurity Undergraduate Research Showcase
Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …
Application Identification With Pfsense, Snort, And Openappid In Academic Lab Networks, Minh-Khanh Vu
Application Identification With Pfsense, Snort, And Openappid In Academic Lab Networks, Minh-Khanh Vu
Journal of Cybersecurity Education, Research and Practice
This paper evaluates the practical capabilities and limitations of a widely used open-source network security stack—pfSense firewall, Snort Intrusion Detection System (IDS), and OpenAppID detectors—in academic cy- bersecurity laboratories and small-to-medium enterprise (SME)-like environments. In a controlled virtual testbed, we measure application-level and feature-level identifi- cation performance for major applications (Facebook, YouTube, Zoom) using the pfSense/Snort/OpenAppID configuration. The stack achieves 97% application-level identification accuracy for these applications in our lab dataset, drawing on a library of 3,374 OpenAppID detectors. However, our experiments reveal a substan- tial feature-level detection gap: specific functions such as Zoom file transfers and Facebook messaging can- …
From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms, Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke
From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms, Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke
Research outputs 2022 to 2026
Cybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors' knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board …
Fully Decentralized Hierarchical Federated Learning At The Edge With Post-Quantum Secure Communication, Tariq Qayyum
Fully Decentralized Hierarchical Federated Learning At The Edge With Post-Quantum Secure Communication, Tariq Qayyum
Thesis/ Dissertation Defenses
Federated learning (FL) enables collaborative model training without centralizing raw data, but deploying FL at scale in real edge environments remains challenging because iterative training and aggregation must operate over heterogeneous, resource-constrained, and often mobile devices with time-varying connectivity. Conventional hierarchical federated learning (HFL) partially mitigates communication cost by introducing fog/edge aggregation, yet many designs retain cloud-based global aggregation and cloud-centric coordination. This places wide-area network latency on the critical path of every training round, creates a single point of failure, and limits responsiveness as model sizes and federation scale grow. Moreover, moving coordination and aggregation closer to the edge …
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña
Campus Research Month
Universities face a common cybersecurity threat: their own users. Although organizations may meet compliance standards and implement robust security infrastructures, the individual user remains the weakest link. This is particularly evident in higher education institutions, where both students and employees are frequent targets of cyber threats due to a lack of cybersecurity awareness. This paper proposes a strategic roadmap for assessing university student bodies and employee populations through cybersecurity domains that directly affect personal cyber hygiene awareness and practice.
Our proposed roadmap was validated in a U.S. university by using a domain-focused survey and simulated phishing campaigns. After the identification …
Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks, Brandon Saari, Yona Berger, Yanett Munoz, Alex Agnick, Paul Wagner, Robert J. Honomichl
Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks, Brandon Saari, Yona Berger, Yanett Munoz, Alex Agnick, Paul Wagner, Robert J. Honomichl
Journal of Cybersecurity Education, Research and Practice
Artificial intelligence (AI) is rapidly being adopted across public and private sectors. This offers significant gains in efficiency, decision making, and access to information. At the same time, AI introduces complex risks related to cybersecurity, privacy, bias, transparency, accountability, and equity that existing governance and security frameworks do not fully address. This paper presents a cross-sector literature review and comparative analysis of AI adoption risks and mitigation strategies across four critical domains: the federal government, libraries, K–12 education, and healthcare. Drawing on peer-reviewed research, institutional frameworks, and policy guidance, the study identifies sector-specific challenges alongside shared systemic gaps, including insufficient …
Innovations And Applications Of Virtual Private Networks And Sustainable Security In Society 5.0 Libraries, Stella Chinnaya Nduka Dr., Adeyinka Tella Prof, Petros Dlamini Dr
Innovations And Applications Of Virtual Private Networks And Sustainable Security In Society 5.0 Libraries, Stella Chinnaya Nduka Dr., Adeyinka Tella Prof, Petros Dlamini Dr
Journal of Cybersecurity Education, Research and Practice
In order to improve digital resilience, privacy, and access equity in contemporary library environments, this study investigates the role of Virtual Private Networks (VPNs) in fostering sustainable cybersecurity within the framework of Society 5.0 libraries. It does this by looking at the latest developments, applications, difficulties, moral dilemmas, and tactical methods associated with VPN deployment. Using peer-reviewed journal articles, conference proceedings, white papers, and policy documents published between 2010 and 2024, a methodical approach to literature review was used. The literature that bridges the fields of cybersecurity, library science, and Society 5.0 concepts was the main focus of the review. …
Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie
Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie
Theses and Dissertations
This study examines the intersection of cybersecurity education, open educational resources (OER), and rural higher education through a systematic review of current literature and an exploratory survey of rural community college faculty. The purpose of this research, consistent with the approved Institutional Review Board (IRB) protocol, was to understand how OER can be leveraged to design and deliver an affordable, high-quality System Security course within a rural higher-education environment. As cybersecurity workforce shortages continue to grow across the United States, rural institutions face persistent challenges in sustaining high-quality programs due to financial constraints, limited faculty capacity, and rapidly evolving curriculum …
Where Did It Go Wrong? Attributing Undesirable Llm Behaviors Via Representation Gradient Tracing, Zhe Li, Wei Zhao, Yige Li, Jun Sun
Where Did It Go Wrong? Attributing Undesirable Llm Behaviors Via Representation Gradient Tracing, Zhe Li, Wei Zhao, Yige Li, Jun Sun
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have demonstrated remarkable capabilities, yet their deployment is frequently undermined by undesirable behaviors such as generating harmful content, factual inaccuracies, and societal biases. Diagnosing the root causes of these failures poses a critical challenge for AI safety. Existing attribution methods, particularly those based on parameter gradients, often fall short due to prohibitive noisy signals and computational complexity. In this work, we introduce a novel and efficient framework that diagnoses a range of undesirable LLM behaviors by analyzing representation and its gradients, which operates directly in the model's activation space to provide a semantically meaningful signal linking …
A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson
A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson
Posters - 2026
Reverse engineering plays a vital role in cybersecurity by helping analysts examine unknown binaries, investigate malware, identify vulnerabilities, and better protect sensitive systems. However, once a program is compiled and stripped, the meaningful names that describe its behavior are lost, leaving behind generic function labels like FUN_00401a30. Analysts must then manually interpret decompiled code, trace call chains, and infer program behavior function by function, which is slow and mentally demanding on large binaries. To address this challenge, this project introduces A.I.R.E., a local Ghidra extension that extracts contextual evidence from stripped functions and uses a locally hosted language model to …
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni
School of Public Policy Capstones
This paper develops Next-Generation Democratic Cyber Statecraft (NG-DCS), a unified strategic doctrine for democratic governments to contest the cognitive domain against authoritarian adversaries. Drawing on twenty-six years of cross-national panel data (1999–2024) spanning 213 countries, game-theoretic modeling, and qualitative case analysis, the paper establishes three interconnected empirical and theoretical foundations. First, cross-national OLS regression across 160+ countries demonstrates that regime type is the dominant structural determinant of internet freedom (R²=0.615, β=2.513, p< 0.001), explaining more than twice the variance attributable to per-capita wealth (R²=0.268). Democratic governance, not economic development, produces open digital environments. Second, a two-way fixed effects (TWFE) difference-in-differences study exploiting government-ordered internet shutdowns as discrete policy interventions finds that digital restrictions causally degrade V-Dem governance quality by 0.21–0.38 standard deviations (p< 0.001 across all specifications). Treatment effects are immediate (β=−0.302 at k=0) and persist through five post-treatment years (β=−0.246 at k=+5), indicating structural rather than transitory governance damage. Parallel trends validation (p=0.352) and Callaway–Sant’Anna heterogeneity-robust estimation (ATT=−0.230, SE=0.077) support causal identification. Instrumental variable triangulation (2SLS β=−0.949, p=0.005) confirms that simultaneity was attenuating, not inflating, the primary estimates. Third, formal game-theoretic analysis reveals that the current U.S.–adversary equilibrium is (Restrain, Escalate)—the risk-dominant but Pareto-inferior outcome of a Stag Hunt structure. China, Russia, North Korea, and Venezuela each occupy structurally distinct positions (Stackelberg commitment, asymmetric two-level, autarky, and reactive trigger, respectively), requiring differentiated doctrinal responses rather than a uniform strategic playbook. Generative AI and algorithmic governance are shown to accelerate cognitive vulnerability by collapsing influence operation costs and exploiting engagement-optimized platform architectures that systematically degrade deliberative capacity in democratic populations.
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
School of Cybersecurity Master's Level Projects and Papers
Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.
This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …
Trace: Securing Smart Contract Repository Against Access Control Vulnerability, Chong Chen, Lingfeng Bao, David Lo, Yanlin Wang, Zhenyu Shan, Ting Chen, Guangqiang Yin, Jianxing Yu, Zibin Zheng, Jiachi Chen
Trace: Securing Smart Contract Repository Against Access Control Vulnerability, Chong Chen, Lingfeng Bao, David Lo, Yanlin Wang, Zhenyu Shan, Ting Chen, Guangqiang Yin, Jianxing Yu, Zibin Zheng, Jiachi Chen
Research Collection School Of Computing and Information Systems
Smart contract vulnerabilities have led to billions of dollars in economic losses. Among these, improper Access Control, which allows unauthorized users to execute restricted functions, is particularly prevalent and has caused significant financial damage. Smart contract repositories contain source code, documentation, configuration files, and other artifacts necessary for building and deploying smart contracts. GitHub hosts numerous open-source repositories of this kind, which serve as intermediate artifacts in development and require compilation and packaging to produce deployable contracts. Third-party developers often reference, reuse, or fork code from these repositories during custom development. However, if the referenced code contains vulnerabilities, it can …
Llmqua: Practical Backdoor Injection On Large Language Model Quantization, Xiangxiang Chen, Peixin Zhang, Jun Sun, Jin Song Dong, Wenhai Wang, Jingyi Wang
Llmqua: Practical Backdoor Injection On Large Language Model Quantization, Xiangxiang Chen, Peixin Zhang, Jun Sun, Jin Song Dong, Wenhai Wang, Jingyi Wang
Research Collection School Of Computing and Information Systems
Quantization is widely used to enable local deployment of large language models (LLMs) on resource-constrained devices. Recent work (e.g., QuRA) shows quantization can be exploited via rounding manipulation to implant backdoors. However, such an attack has been evaluated only on small models and does not directly apply to LLMs due to three key constraints: (1) limited poisoning data from small, task-agnostic calibration sets; (2) layer-wise quantization restricting adversarial access to global representations; and (3) lack of gradient access in quantization pipelines, blocking gradient-based attacks.We propose LLMQuA, a practical quantization-phase backdoor attack tailored to the LLM setting. LLMQuA (i) injects backdoors …
Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni
Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni
Research outputs 2022 to 2026
Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes …
Hypersiniel: Guaranteed Output Delivery Comes (Almost) Free In Private Delegation Of Zksnarks, Yunbo Yang, Yuejia Cheng, Junkai Liang, Kailun Wang, Xuanming Liu, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Meng Hao, Guomin Yang, Deng, Robert H., Kui Ren
Hypersiniel: Guaranteed Output Delivery Comes (Almost) Free In Private Delegation Of Zksnarks, Yunbo Yang, Yuejia Cheng, Junkai Liang, Kailun Wang, Xuanming Liu, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Meng Hao, Guomin Yang, Deng, Robert H., Kui Ren
Research Collection School Of Computing and Information Systems
Zero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive that enables a prover to convince a verifier that something is true without leaking the private witness.Current zkSNARKs face significant computational costs in generating proofs, which restricts their use in areas like private payments, confidential smart contracts, and anonymous credentials. Private delegation offers a practical solution by outsourcing the heavy computation to powerful external workers without leaking any private information. In this work, we propose HyperSiniel, an efficient private delegation framework for general zkSNARKs that achieves a new feature called guaranteed output delivery (GOD). HyperSiniel is designed to …
Propaganda Ai: An Analysis Of Semantic Divergence In Large Language Models, Nay Myat Min, Long H. Pham, Yige Li, Jun Sun
Propaganda Ai: An Analysis Of Semantic Divergence In Large Language Models, Nay Myat Min, Long H. Pham, Yige Li, Jun Sun
Research Collection School Of Computing and Information Systems
Large language models (LLMs) can exhibit concept-conditioned semantic divergence: common high-level cues (e.g., ideologies, public figures) elicit unusually uniform, stance-like responses that evade token-trigger audits. This behavior falls in a blind spot of current safety evaluations, yet carries major societal stakes, as such concept cues can steer content exposure at scale. We formalize this phenomenon and present RAVEN (Response Anomaly Vigilance), a black-box audit that flags cases where a model is simultaneously highly certain and atypical among peers by coupling semantic entropy over paraphrastic samples with cross-model disagreement. In a controlled LoRA fine-tuning study, we implant a concept-conditioned stance using …
Be Responsible In Your Answers! Monitoring Out-Of-Domain Behaviors In Domain-Specific Llms, Boquan Li, Chenzhe Lou, Zhe Ren, Peixin Zhang, Zirui Fu, Jun Sun, Yaowen Zheng
Be Responsible In Your Answers! Monitoring Out-Of-Domain Behaviors In Domain-Specific Llms, Boquan Li, Chenzhe Lou, Zhe Ren, Peixin Zhang, Zirui Fu, Jun Sun, Yaowen Zheng
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have accelerated the rapid development of chatbot web applications in various domains, such as coding, biomedicine and psychology. Compared to general LLMs like ChatGPT, domain-specific LLMs require a greater sense of responsibility. For instance, if a programming LLM casually answers medical or psychological questions, it not only misleads the public but also poses legal risks. This highlights new demands for monitoring and preventing such irresponsible behaviors. Existing efforts attempt to monitor LLMs from multiple aspects, such as lying, jailbreaks, and toxic content, while overlooking out-of-domain behaviors. In this work, we propose an innovative LLM domain monitoring …
Penforge: On-The-Fly Expert Agent Construction For Automated Penetration Testing, Huihui Huang, Jieke Shi, Junkai Chen, Ting Zhang, Yikun Li, Chengran Yang, Eng Lieh Ouh, Lwin Khin Shar, David Lo
Penforge: On-The-Fly Expert Agent Construction For Automated Penetration Testing, Huihui Huang, Jieke Shi, Junkai Chen, Ting Zhang, Yikun Li, Chengran Yang, Eng Lieh Ouh, Lwin Khin Shar, David Lo
Research Collection School Of Computing and Information Systems
Penetration testing is essential for identifying vulnerabilities in web applications before real adversaries can exploit them. Recent work has explored automating this process with Large Language Model (LLM)-powered agents, but existing approaches either rely on a single generic agent that struggles in complex scenarios or narrowly specialized agents that cannot adapt to diverse vulnerability types. We therefore introduce PenForge, a framework that dynamically constructs expert agents during testing rather than relying on those prepared beforehand. By integrating automated reconnaissance of potential attack surfaces with agents instantiated on the fly for context-aware exploitation, PenForge achieves a 30.0% exploit success rate (12/40) …
Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study, Manny Niri Dr.
Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study, Manny Niri Dr.
Journal of Cybersecurity Education, Research and Practice
This study employs a design-based research (DBR) framework to examine the impact of a comprehensive curriculum redesign in an introductory Foundations of Security module for undergraduate students in computing and cybersecurity at a UK public university between 2019 and 2025. The redesign aimed to enhance student learning, engagement, and critical thinking through the embodiment of evidence-based pedagogical strategies, including flipped classroom delivery, blended learning, gamified practical exercises, repeated low-stakes mock assessments, and structured problem-solving activities. Student feedback, assessment outcomes, attendance records, and faculty reflections were analysed to evaluate the effectiveness of the redesign. The results indicate substantial improvements in student …
Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand
Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand
LSU Master's Theses
File reassembly is one of the most fundamental tasks in digital forensics, enabling recovery of data from potentially damaged storage media even when file system metadata is unavailable. This thesis reviews more than two decades of work in the realm of file carving, with a particular focus on fragmented file carving, which remains a focus of research, and file fragment classification, a principal component of fragmented file carving. This thesis serves a literature review of both file carving and fragmented file carving, surveys the massive amounts of data needed for the task of fragment classification and the datasets that serve …
Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs, Dr Atul Bamrara, Partha Roy, Vishwanath Gargote, Khandu Thungon
Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs, Dr Atul Bamrara, Partha Roy, Vishwanath Gargote, Khandu Thungon
Journal of Cybersecurity Education, Research and Practice
Human error remains the most frequently exploited vulnerability in the cyber-security ecosystem. Despite substantial investments in technical safeguards, cybercriminals increasingly rely on social engineering, misinformation, and emotionally manipulative tactics to compromise users. This study examines behavioral changes among participants who underwent structured cyber-security workshops addressing both conventional cyber hygiene practices and emerging digital threats. The training modules covered digital arrest scams, identity theft, sextortion, fake technical support fraud, fake social media profiles, online gaming related risks, and deep fake manipulation. The workshops were designed using interactive simulations, real world case studies, and hands on problem based exercises, with the explicit …
Research On Signal Perception System Of Key Technology Regulation In The United States, Kaile Wang, Hao Liu, Yunwei Chen
Research On Signal Perception System Of Key Technology Regulation In The United States, Kaile Wang, Hao Liu, Yunwei Chen
Bulletin of Chinese Academy of Sciences (Chinese Version)
The purpose of the study is to analyze the operation mechanism of the key technology control signal perception system, and reveal the deep logic and basic procedures of the United States’ external technical containment. Through literature review and information mining, this study analyzes the structural features of the U.S. key technology control signal perception system, such as “front-end technical perception and technology locking”, “mid-end technical evaluation and risk identification”, and “back-end technical control response and dynamic sanctions”. It further explores the participating subjects and role positioning of the United States in key technology control signal perception, the sources and mechanisms …
Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal
Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal
SMU Data Science Review
Large-scale software systems produce vast volumes of logs and telemetry, making manual incident triage slow and error prone. This study presents an unsupervised anomaly detection pipeline that fuses logs, metrics, and traces through late fusion. Using Hybrid Ensemble modeling with Isolation Forest, and Long Short-Term Memory (LSTM) Deep Learning model, the system detects cross-service anomalies producing and assigning a composite triage score reflecting severity and impact. Ranked alerts are categorized into Critical, High, or Medium priorities for review. A retrieval-augmented generation (RAG) layer enriches results with contextual summaries for explainable triage. Evaluated on synthetic multi-service datasets, the pipeline …
A Novel Privacy-Preserving User Information Queries Scheme With Functional Policy, Yuhang Lei, Rui Shi, Yang Yang, Chunjie Cao, Huamin Feng
A Novel Privacy-Preserving User Information Queries Scheme With Functional Policy, Yuhang Lei, Rui Shi, Yang Yang, Chunjie Cao, Huamin Feng
Research Collection School Of Computing and Information Systems
Privacy-preserving information queries enable a requester to obtain only the value f(x) computed over sensitive data x, while preventing disclosure of the underlying records. Existing approaches typically reveal full data, incur high on-chain overhead, or lack fair and verifiable delivery of function outputs. We propose a general-purpose, blockchain-compatible framework that ensures the requester learns only f(x) with no extra leakage and that the provider receives fair payment. The design integrates Adaptor Signatures (AS) for fair exchange and Inner-Product Functional Encryption (IPFE) for fine-grained function extraction. The framework is domain-agnostic and applicable to privacy-sensitive applications such as medical insurance and financial …
Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker
Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker
Research outputs 2022 to 2026
As networks expand in size and complexity, coupled with an exponential increase in intrusions on network and IoT systems, this leads to traditional models failing to capture increasingly intricate correlations among network components accurately. Graph Convolution Networks (GCNs) have recently acquired prominence for their capacity to represent nodes, edges, or entire graphs by aggregating information from adjacent nodes. However, the correlations between nodes and their neighbours, as well as related edges, differ. Assigning higher weights to nodes and edges with high similarity improves model accuracy and expressiveness. In this paper, we propose the GCN-DQN model, which integrates GCN with a …