Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Old Dominion University (32)
- Dakota State University (10)
- University of South Alabama (10)
- Kennesaw State University (6)
- University of Malaya (5)
-
- Indian Statistical Institute (4)
- California State University, San Bernardino (3)
- City University of New York (CUNY) (3)
- Dartmouth College (3)
- Embry-Riddle Aeronautical University (3)
- Georgia Southern University (3)
- The University of Akron (3)
- University of Nebraska at Omaha (3)
- University of Texas at Arlington (3)
- Bridgewater College (2)
- California Polytechnic State University, San Luis Obispo (2)
- Liberty University (2)
- Minnesota State University Moorhead (2)
- University of North Florida (2)
- Western Kentucky University (2)
- American University in Cairo (1)
- Bemidji State University (1)
- Chinese Academy of Sciences (1)
- Columbus State University (1)
- East Tennessee State University (1)
- Eastern Michigan University (1)
- Grand Valley State University (1)
- LSU New Orleans (1)
- Louisiana State University (1)
- Marshall University (1)
- Keyword
-
- Cybersecurity (20)
- Artificial intelligence (6)
- Security (6)
- Machine learning (5)
- Privacy (5)
-
- Machine Learning (4)
- Phishing (4)
- Blockchain (3)
- Cryptography (3)
- Data privacy (3)
- Information security (3)
- Network security (3)
- Training (3)
- Vulnerability (3)
- AI Security (2)
- Adversarial Attacks (2)
- Anonymity (2)
- COVID-19 (2)
- Cyberterrorism (2)
- Data models (2)
- Digital Forensics (2)
- Digital forensics (2)
- Dissertations, Academic -- UNF -- Computing (2)
- Dissertations, Academic -- UNF -- Master of Science in Computer and Information Sciences (2)
- Extraction (2)
- Feature extraction (2)
- Generative AI (2)
- Homomorphic encryption (2)
- Information leakage (2)
- Internet of things (IoT) (2)
- Publication Year
- Publication
-
- Cybersecurity Undergraduate Research Showcase (15)
- Research & Publications (10)
- Shelby Hall Graduate Research Forum Posters (8)
- Computer Science Faculty Publications (6)
- Journal of Cybersecurity Education, Research and Practice (5)
-
- College of Graduate Studies: Theses & Dissertations (3)
- Doctoral Theses (3)
- Electronic Theses and Dissertations (3)
- Electronic Theses, Projects, and Dissertations (3)
- Engineering Management & Systems Engineering Faculty Publications (3)
- Student Theses (3)
- Student Works (2000-2009) (3)
- Theses/Capstones/Creative Projects (3)
- Williams Honors College, Honors Research Projects (3)
- Doctoral Dissertations and Master's Theses (2)
- Electrical & Computer Engineering Faculty Publications (2)
- Graduate Theses and Dissertations (2019 - present) (2)
- Honors College Theses (2)
- Honors Theses (2)
- Master's Theses (2)
- School of Cybersecurity Faculty Publications (2)
- Senior Honors Theses (2)
- Senior Seminars (2)
- Student Works (2020-2029) (2)
- UNF Graduate Theses and Dissertations (2)
- African Conference on Information Systems and Technology (1)
- All Graduate Theses, Dissertations, and Other Capstone Projects (1)
- Bulletin of Chinese Academy of Sciences (Chinese Version) (1)
- Campus Research Month (1)
- Center for Secure and Intelligent Critical Systems (CSICS) Publications (1)
- Publication Type
- File Type
Articles 1 - 30 of 136
Full-Text Articles in Cybersecurity
Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram
Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram
Masters Theses
This thesis presents the design, implementation, and evaluation of a lightweight end-to-end cryptographic framework integrated with a semantic quality-of-service classification system for augmented reality based telesurgery. Telesurgery can deliver expert surgical care to underserved populations, but adoption has been limited by unresolved cybersecurity, network performance, and resilience challenges. The core tension is that strong encryption adds latency that may exceed the clinical safety threshold, while unencrypted systems remain vulnerable to attacks that could endanger patients during live procedures.
The framework addresses this tension through a dual-edge security middlebox that performs per-flow encryption using semantically selected ciphers: AES-128-GCM for latency-critical haptic …
A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland
A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland
Discovery Day - Daytona Beach
In the modern age of computers and interconnected networks, cybersecurity and cyber-attackers are evolving in tandem to exploit each other’s vulnerabilities. One technique used by both parties is Operating System Fingerprinting (OSF): with the knowledge of what Operating System a target system is running, innate vulnerabilities can be identified and patched or exploited. Historically, OSF utilizes two main methods: passive and active—the former trades accuracy with undetectability while the latter is generally more detectable but more accurate. However, recent work has combined OSF with Machine Learning (ML) to improve accurate identification. The work presented here is a survey for the …
Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen
Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen
Dissertations, Theses, and Projects
The increasing adoption of the Internet of Medical Things (IoMT) has improved healthcare delivery through connected medical devices while simultaneously expanding the cybersecurity risks facing healthcare organizations. Although machine learning based intrusion detection systems have demonstrated high detection accuracy, their ability to respond reliably to previously unseen cyberattacks remains uncertain. This study investigated how a Neural Network model and a Logistic Regression model classified novel cyberattacks within the IoMT environment. The Neural Network and Logistic Regression models were both trained and tested using a subset of the CICIoMT2024 benchmark dataset. The Neural Network achieved 99.82% test accuracy and a 0.94 …
Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap
Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap
Journal of Cybersecurity Education, Research and Practice
Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking. The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …
Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson
Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson
Journal of Cybersecurity Education, Research and Practice
In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …
Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry
Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry
Journal of Cybersecurity Education, Research and Practice
This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established …
A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath
A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath
Research & Publications
The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …
2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus
2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus
Computer Science Technical Reports
The ISTS and the Dartmouth College Cybersecurity Cluster hosted the successful, inaugural Cyber-Resilient Health Care (CRHC) Workshop, March 5th & 6th, 2026. The event theme was "Innovation and Implementation," in response to the need to shift from reactive to proactive resiliency measures in the healthcare sector. Approximately 30 experts in clinical health care, cybersecurity, medical technology, policy, and innovation met to discuss solution-focused innovations addressing hard, cyber-related problems in health care. The agenda featured keynotes, an expert panel, innovation pitches, small group discussions, and a tabletop infrastructure disaster exercise. Participants gained insights into the obstacles and solutions involved in supporting …
The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala
The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala
Student Theses
The rapid adoption of Large Language Models (LLMs) in software development has transformed coding practices by enabling automated code generation, completion, and optimization. Despite these advantages, concerns persist regarding the security and reliability of LLM-generated code. This study presents a comprehensive evaluation of both the functional correctness and security of code produced by three prominent LLMs as of early 2026. A total of 4,800 code snippets were generated using 100 security-focused programming prompts derived from the OWASP Top 10:2025, translated across eight natural languages and two phrasing styles (literal and natural developer-oriented prompts). To assess performance, a multi-stage experimental framework …
Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy
Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy
Student Theses
Social network platforms, child safety organizations, and image provenance systems use perceptual hashing to identify known child sexual abuse material (CSAM), support content moderation and reverse image search, and verify image integrity. Perceptual hashing works by producing similar fingerprints for visually similar images, even after common transformations such as compression, resizing, or minor brightness changes. This useful similarity-preserving property also creates an adversarial attack surface, as attackers can use AI-assisted or conventional image manipulation techniques to move a hash across a matching threshold while maintaining visual similarity, often without access to specialized hardware.
The security failures produced by adversarial attacks …
Anonymity And Accountability In Secure Messaging, Erin Kenney
Anonymity And Accountability In Secure Messaging, Erin Kenney
Dissertations
Encypted messaging has become more and more prevalent as time moves on, and its benefits in assuring privacy cannot be overstated, but it also brings along with it concerns on how to moderate platforms where all messages are hidden. Message Franking, followed by Traceback systems, addressed these concerns by allowing the sender of a message to be proven when reported, even for forwarded messages in the case of Traceback, however these systems damage the privacy guarantees that originally motivated encrypted messaging to begin with.
In practice, even without those concerns encrypted messaging alone is not enough to prevent the most …
Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder
Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder
Doctoral Dissertations and Master's Theses
Cybersecurity has become a global concern as cyber-attacks have become more common, and the cost of the damage caused by them continues to increase. There are several approaches to improve the cyber security of systems such as Digital Signatures, hashing, watermarking, and encryption among others. Digital Signatures are a cryptographic technique used to verify the authenticity and integrity of digital messages or documents. Digital Signatures use a combination of hashing and public-private key encryption to verify the authenticity and integrity of videos, just as they are used for documents and messages. As a result of using a combination of other …
Post-Quantum Cryptography Encryption Implementation For Messaging App, Callum S. Ward
Post-Quantum Cryptography Encryption Implementation For Messaging App, Callum S. Ward
Theses/Capstones/Creative Projects
This paper and complementary capstone project aim to explore the state of post-quantum cryptography today by defining the algorithms with which quantum computers can decipher modern asymmetric cryptographic algorithms in exponentially accelerated time, exploring national standards body NIST’s recommendations to circumvent these weaknesses with post-quantum solutions, and implementing recommended algorithms in my group’s project for the UNO Computer Science Capstone course, LockTalk. After having decided on ML-KEM for quantum-resistant asymmetric key transfer and AES-256 for symmetric message encryption and decryption, I was able to cryptographically encode messages to obscure their plaintext values from communication interceptions without any discernible increase in …
Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection, Brendan J. Farrell
Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection, Brendan J. Farrell
Theses/Capstones/Creative Projects
With the rapid development and use of digital communication, the need for maintaining the integrity and authenticity of transmitted information becomes more pressing than ever. However, existing methods of data exchange have several flaws and drawbacks such as reliance on centralized networks which are subject to manipulation, modifications, and potential failures. Thus, the current project offers an innovative approach to improving the integrity and detection capabilities of messages in real-time communication platforms using the power of blockchain technology. The proposed solution uses the inherent features of blockchain-based systems to ensure secure and safe message transmission.
Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen
Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen
Senior Honors Theses
Command and Control (C2) is a critical part of any cyberattack. It serves many purposes, including Distributed Denial of Service (DDoS) attacks, data exfiltration, and malware deployment. Consequently, C2 frameworks play an important part in red team engagements and adversary emulation. However, many adversary emulation solutions focus on comprehensive testing through sequential technique execution instead of realistic chained and automated attacks. The proposed solution is Centurion, an open-source C2 framework that integrates MITRE's ATT&CK framework and several cybersecurity tools into modular playbooks for effective threat emulation. This paper provides background by defining key terms and concepts before delving into a …
Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training, Doc Harley
Senior Honors Theses
Currently, the leading technologies in the market of adversarial emulation are MITRE Caldera, Atomic Red Team by IBM, and multiple proprietary products that come with support packages for different vendors like AttackIQ, Cymulate, SafeBreach, and many more. While it is clear that much work has been done in the broad category of adversarial emulation, when it comes to open source solutions, there are no agentless options with built in automation and modularity that have good support for cloud environments. Agentless adversarial emulation provides a unique advantage in that it can be both simpler and a better representation of the true …
Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir
Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir
Cybersecurity Undergraduate Research Showcase
Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs
Cybersecurity Undergraduate Research Showcase
Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry
Cybersecurity Undergraduate Research Showcase
Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña
Campus Research Month
Universities face a common cybersecurity threat: their own users. Although organizations may meet compliance standards and implement robust security infrastructures, the individual user remains the weakest link. This is particularly evident in higher education institutions, where both students and employees are frequent targets of cyber threats due to a lack of cybersecurity awareness. This paper proposes a strategic roadmap for assessing university student bodies and employee populations through cybersecurity domains that directly affect personal cyber hygiene awareness and practice.
Our proposed roadmap was validated in a U.S. university by using a domain-focused survey and simulated phishing campaigns. After the identification …
A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson
A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson
Posters - 2026
Reverse engineering plays a vital role in cybersecurity by helping analysts examine unknown binaries, investigate malware, identify vulnerabilities, and better protect sensitive systems. However, once a program is compiled and stripped, the meaningful names that describe its behavior are lost, leaving behind generic function labels like FUN_00401a30. Analysts must then manually interpret decompiled code, trace call chains, and infer program behavior function by function, which is slow and mentally demanding on large binaries. To address this challenge, this project introduces A.I.R.E., a local Ghidra extension that extracts contextual evidence from stripped functions and uses a locally hosted language model to …
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni
School of Public Policy Capstones
This paper develops Next-Generation Democratic Cyber Statecraft (NG-DCS), a unified strategic doctrine for democratic governments to contest the cognitive domain against authoritarian adversaries. Drawing on twenty-six years of cross-national panel data (1999–2024) spanning 213 countries, game-theoretic modeling, and qualitative case analysis, the paper establishes three interconnected empirical and theoretical foundations. First, cross-national OLS regression across 160+ countries demonstrates that regime type is the dominant structural determinant of internet freedom (R²=0.615, β=2.513, p< 0.001), explaining more than twice the variance attributable to per-capita wealth (R²=0.268). Democratic governance, not economic development, produces open digital environments. Second, a two-way fixed effects (TWFE) difference-in-differences study exploiting government-ordered internet shutdowns as discrete policy interventions finds that digital restrictions causally degrade V-Dem governance quality by 0.21–0.38 standard deviations (p< 0.001 across all specifications). Treatment effects are immediate (β=−0.302 at k=0) and persist through five post-treatment years (β=−0.246 at k=+5), indicating structural rather than transitory governance damage. Parallel trends validation (p=0.352) and Callaway–Sant’Anna heterogeneity-robust estimation (ATT=−0.230, SE=0.077) support causal identification. Instrumental variable triangulation (2SLS β=−0.949, p=0.005) confirms that simultaneity was attenuating, not inflating, the primary estimates. Third, formal game-theoretic analysis reveals that the current U.S.–adversary equilibrium is (Restrain, Escalate)—the risk-dominant but Pareto-inferior outcome of a Stag Hunt structure. China, Russia, North Korea, and Venezuela each occupy structurally distinct positions (Stackelberg commitment, asymmetric two-level, autarky, and reactive trigger, respectively), requiring differentiated doctrinal responses rather than a uniform strategic playbook. Generative AI and algorithmic governance are shown to accelerate cognitive vulnerability by collapsing influence operation costs and exploiting engagement-optimized platform architectures that systematically degrade deliberative capacity in democratic populations.
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
School of Cybersecurity Master's Level Projects and Papers
Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.
This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …
Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand
Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand
LSU Master's Theses
File reassembly is one of the most fundamental tasks in digital forensics, enabling recovery of data from potentially damaged storage media even when file system metadata is unavailable. This thesis reviews more than two decades of work in the realm of file carving, with a particular focus on fragmented file carving, which remains a focus of research, and file fragment classification, a principal component of fragmented file carving. This thesis serves a literature review of both file carving and fragmented file carving, surveys the massive amounts of data needed for the task of fragment classification and the datasets that serve …
Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal
Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal
SMU Data Science Review
Large-scale software systems produce vast volumes of logs and telemetry, making manual incident triage slow and error prone. This study presents an unsupervised anomaly detection pipeline that fuses logs, metrics, and traces through late fusion. Using Hybrid Ensemble modeling with Isolation Forest, and Long Short-Term Memory (LSTM) Deep Learning model, the system detects cross-service anomalies producing and assigning a composite triage score reflecting severity and impact. Ranked alerts are categorized into Critical, High, or Medium priorities for review. A retrieval-augmented generation (RAG) layer enriches results with contextual summaries for explainable triage. Evaluated on synthetic multi-service datasets, the pipeline …
Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn
Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn
Journal of Cybersecurity Education, Research and Practice
The digital transformation of higher education institutions (HEIs) has introduced unprecedented connectivity and operational efficiency, but it has also heightened their exposure to cyber threats. South African HEIs, in particular, face increasing vulnerability due to their reliance on technology, openness, and diverse user communities. This study examines the influence of the institutional cybersecurity environment on employee cybersecurity-compliant behaviour (CCB), emphasising the critical roles of awareness, policy engagement, and experience. Drawing on Protection Motivation Theory and the Theory of Planned Behaviour, a conceptual model was developed to explore how cybersecurity awareness, policy familiarity, and prior experience shape employees’ attitudes, subjective norms, …
Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar
Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar
Research & Publications
Cyber conflict forecasting remains constrained by static models that overlook the integration of geopolitical context with technical indicators. This systematic literature review examines 58 studies (2010–2025) using PRISMA guidelines and an InputProcess-Output framework to classify approaches and identify key gaps. Quantitative methods dominate (67%), yet only 14% incorporate geopolitical variables, despite the political nature of cyber conflict. Major limitations include adversarial adaptation blindness (85% assume static behavior), coarse temporal granularity (72% use daily+ intervals), lack of uncertainty quantification (75%), and minimal modeling of cross-domain escalation (92% cyber-only focus). Strategic forecasting is rare, with just 14% providing long-term insights and 16% …
Ransomware As Organization: A Comparative Analysis Of Corporate And Criminal Structures In Conti, George Urling
Ransomware As Organization: A Comparative Analysis Of Corporate And Criminal Structures In Conti, George Urling
Theses, Dissertations and Capstones
Cybercriminal groups continue to pose major threats to global cybersecurity. One of the most common types of cybercriminal groups are, “Ransomware-as-a-Service (RaaS)" groups, who create and sell ransomware. While research is conducted into the development of ransomware, there is limited reporting on the organizational structure and habits of RaaS groups. In 2022, prominent RaaS group Conti had their chat logs leaked, with the logs ranging from 2020 to 2022. This study seeks to provide a deeper understanding of RaaS group structures by utilizing the Conti leaked logs as a case study. The study, entitled “Ransomware as Organization: A Comparative Analysis …
Systematic Approaches To Characterizing Vulnerabilities And Enhancing Robustness Of Text And Vision-Language Models, Poojitha Thota
Systematic Approaches To Characterizing Vulnerabilities And Enhancing Robustness Of Text And Vision-Language Models, Poojitha Thota
Computer Science and Engineering Dissertations
The proliferation of artificial intelligence (AI) across critical domains, including news summarization, privacy-policy analysis, and medical decision support, has raised growing concerns about the security and robustness of these systems against adversarial manipulation. This dissertation investigates adversarial robustness in generative AI by addressing three key research goals: (1) characterizing adversarial vulnerabilities across generative models, (2) developing systematic defenses to improve the robustness of generative models, and (3) designing deployment-time safeguards for securing LLM interactions.
Towards the first goal, we characterize adversarial vulnerabilities across text-based and multimodal systems. In abstractive text summarization, we show that inference-time perturbations can exploit lead bias …
Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad
All Graduate Theses, Dissertations, and Other Capstone Projects
Phishing remains one of the most effective attack vectors for gaining unauthorized access to organizational systems, yet defenders often lack systematic methods to assess their exposure before an attack. This study develops a framework that uses machine learning to encode the collective expertise of cybersecurity practitioners into a portable phishing susceptibility assessment tool, with the goal to help security teams proactively identify patterns, prioritize awareness training, and strengthen detection controls. The study surveyed 27 practitioners with extensive experience in social engineering, red teaming, penetration testing, and threat analysis to identify which factors most influence phishing susceptibility. Practitioners provided quantitative ratings …