Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Series

Discipline
Institution
Keyword
Publication Year
Publication
File Type

Articles 1 - 30 of 149

Full-Text Articles in Cybersecurity

Residential Ai Data Centers: Security, Privacy, And Governance Concerns, Alan Saquella Jun 2026

Residential Ai Data Centers: Security, Privacy, And Governance Concerns, Alan Saquella

Publications

The concept of placing mini data centers and distributed AI computer nodes inside residential homes may appear innovative from an energy efficiency perspective, but it introduces significant security, privacy, governance, and liability concerns. What is effectively occurring is the expansion of commercial and potentially critical infrastructure into lightly protected residential environments.

Once a residence becomes part of a distributed computer grid supporting hyper-scalers, AI providers, or enterprise workloads, the home is no longer simply a private residence. It becomes a commercial technology asset, a potential cyber target, and even a physical target. A distributed network of thousands of residential nodes …


A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath Jun 2026

A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath

Research & Publications

The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …


2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus Jun 2026

2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus

Computer Science Technical Reports

The ISTS and the Dartmouth College Cybersecurity Cluster hosted the successful, inaugural Cyber-Resilient Health Care (CRHC) Workshop, March 5th & 6th, 2026. The event theme was "Innovation and Implementation," in response to the need to shift from reactive to proactive resiliency measures in the healthcare sector. Approximately 30 experts in clinical health care, cybersecurity, medical technology, policy, and innovation met to discuss solution-focused innovations addressing hard, cyber-related problems in health care. The agenda featured keynotes, an expert panel, innovation pitches, small group discussions, and a tabletop infrastructure disaster exercise. Participants gained insights into the obstacles and solutions involved in supporting …


Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca May 2026

Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca

Publications

As artificial intelligence transforms aviation, aerospace, and autonomy-related sectors, higher education must adapt to meet evolving workforce demands. This session shares emerging findings from a nationwide study led by Embry-Riddle Aeronautical University, focused on employer perceptions of AI adoption, responsible use, and workforce preparedness in domains including uncrewed systems, space systems, robotics, and advanced air mobility. Based on a structured survey and follow-up interviews, the presentation explores how organizations are using AI tools, from generative platforms to enterprise systems, and defining effective and inappropriate use in operational contexts. Participants will gain insight into critical concerns (e.g., data privacy, compliance, security, …


Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen May 2026

Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen

Senior Honors Theses

Command and Control (C2) is a critical part of any cyberattack. It serves many purposes, including Distributed Denial of Service (DDoS) attacks, data exfiltration, and malware deployment. Consequently, C2 frameworks play an important part in red team engagements and adversary emulation. However, many adversary emulation solutions focus on comprehensive testing through sequential technique execution instead of realistic chained and automated attacks. The proposed solution is Centurion, an open-source C2 framework that integrates MITRE's ATT&CK framework and several cybersecurity tools into modular playbooks for effective threat emulation. This paper provides background by defining key terms and concepts before delving into a …


Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training, Doc Harley Apr 2026

Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training, Doc Harley

Senior Honors Theses

Currently, the leading technologies in the market of adversarial emulation are MITRE Caldera, Atomic Red Team by IBM, and multiple proprietary products that come with support packages for different vendors like AttackIQ, Cymulate, SafeBreach, and many more. While it is clear that much work has been done in the broad category of adversarial emulation, when it comes to open source solutions, there are no agentless options with built in automation and modularity that have good support for cloud environments. Agentless adversarial emulation provides a unique advantage in that it can be both simpler and a better representation of the true …


The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection, Kaelyn Haynie Apr 2026

The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection, Kaelyn Haynie

Senior Honors Theses

Accurately detecting malicious programs is an expanding field of research for machine learning (ML), with a novel approach incorporating a bytecode-to-image pipeline that produces images representative of software. These images are provided to convolutional neural networks (CNNs) to be examined for malicious pattern indicators. However, CNNs struggle to generalize these patterns effectively while still being robust against adversarial data, an issue which this research addresses with adversarial training. In this paper, three unique CNN architectures (a DBFS-MC-inspired baseline, MIRACLE, and PSP-CNN) are trained for binary classification with 15,000 benign and malicious software samples encoded into images for Android, Windows, and …


Romance Scam Reporting And Support: Help-Seeking Timing, Trust, And Escalation, Ld Herrera Apr 2026

Romance Scam Reporting And Support: Help-Seeking Timing, Trust, And Escalation, Ld Herrera

Research & Publications

Built on social engineering and identity deception, romance scams often create financial loss and distress. For victims, it can be difficult to know where to go, what information is needed, and what outcomes are realistic. This paper reports results from an anonymous survey of people who were targeted by or experienced a romance scam (completed surveys: n=386), focusing on (1) when and whether victims first reach out for help, (2) perceived difficulty and confidence in navigating support, (3) how trust relates to expectations of assistance, and (4) how loss severity relates to transfer-method complexity. When help was sought, it was …


Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni Apr 2026

Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni

School of Public Policy Capstones

This paper develops Next-Generation Democratic Cyber Statecraft (NG-DCS), a unified strategic doctrine for democratic governments to contest the cognitive domain against authoritarian adversaries. Drawing on twenty-six years of cross-national panel data (1999–2024) spanning 213 countries, game-theoretic modeling, and qualitative case analysis, the paper establishes three interconnected empirical and theoretical foundations. First, cross-national OLS regression across 160+ countries demonstrates that regime type is the dominant structural determinant of internet freedom (R²=0.615, β=2.513, p< 0.001), explaining more than twice the variance attributable to per-capita wealth (R²=0.268). Democratic governance, not economic development, produces open digital environments. Second, a two-way fixed effects (TWFE) difference-in-differences study exploiting government-ordered internet shutdowns as discrete policy interventions finds that digital restrictions causally degrade V-Dem governance quality by 0.21–0.38 standard deviations (p< 0.001 across all specifications). Treatment effects are immediate (β=−0.302 at k=0) and persist through five post-treatment years (β=−0.246 at k=+5), indicating structural rather than transitory governance damage. Parallel trends validation (p=0.352) and Callaway–Sant’Anna heterogeneity-robust estimation (ATT=−0.230, SE=0.077) support causal identification. Instrumental variable triangulation (2SLS β=−0.949, p=0.005) confirms that simultaneity was attenuating, not inflating, the primary estimates. Third, formal game-theoretic analysis reveals that the current U.S.–adversary equilibrium is (Restrain, Escalate)—the risk-dominant but Pareto-inferior outcome of a Stag Hunt structure. China, Russia, North Korea, and Venezuela each occupy structurally distinct positions (Stackelberg commitment, asymmetric two-level, autarky, and reactive trigger, respectively), requiring differentiated doctrinal responses rather than a uniform strategic playbook. Generative AI and algorithmic governance are shown to accelerate cognitive vulnerability by collapsing influence operation costs and exploiting engagement-optimized platform architectures that systematically degrade deliberative capacity in democratic populations.


Data-Driven Prioritization Of Cybersecurity Vulnerabilities Using Business Context, Pierce Read, George Antoniou Mar 2026

Data-Driven Prioritization Of Cybersecurity Vulnerabilities Using Business Context, Pierce Read, George Antoniou

Faculty and Staff Publications & Presentations

No abstract provided.


Future Trends In Cybersecurity: A Meta-Review, Yara Mohammed, Manar Alsaid, Gahangir Hossain Feb 2026

Future Trends In Cybersecurity: A Meta-Review, Yara Mohammed, Manar Alsaid, Gahangir Hossain

Faculty Publications

The increasing importance of cybersecurity in protecting digital assets, data and infrastructures necessitates a reevaluation of research priorities within the discipline. As of today, numerous emerging cybersecurity topics are gaining significant importance in both academic research and industry applications. To identify recent trends in cybersecurity topics, this study extracts scholarly articles from two prestigious academic databases, the ACM Digital Library, and Google Scholar, covering the period from early 2015 to late 2024.Through a systematic identification of trends and focal points in cybersecurity research, a comprehensive analysis is facilitated, including Latent Dirichlet Allocation (LDA), Biterm Topic Modeling (BTM), keyword frequencies, and …


Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar Jan 2026

Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar

Research & Publications

Cyber conflict forecasting remains constrained by static models that overlook the integration of geopolitical context with technical indicators. This systematic literature review examines 58 studies (2010–2025) using PRISMA guidelines and an InputProcess-Output framework to classify approaches and identify key gaps. Quantitative methods dominate (67%), yet only 14% incorporate geopolitical variables, despite the political nature of cyber conflict. Major limitations include adversarial adaptation blindness (85% assume static behavior), coarse temporal granularity (72% use daily+ intervals), lack of uncertainty quantification (75%), and minimal modeling of cross-domain escalation (92% cyber-only focus). Strategic forecasting is rare, with just 14% providing long-term insights and 16% …


Digital Redlining In The Smart City: Artificial Intelligence, Housing Law, And Structural Urban Inequality, Spurthi Nrusimhadevara Jan 2026

Digital Redlining In The Smart City: Artificial Intelligence, Housing Law, And Structural Urban Inequality, Spurthi Nrusimhadevara

Undergraduate Scholarship and Creative Works

Artificial intelligence is increasingly used in urban housing systems, where it shapes decisions about tenant screening, rent pricing, lending, zoning, and neighborhood investment. Although these tools are often promoted as efficient and impartial, they frequently rely on historical data that reflect racial, economic, and spatial inequality. As a result, AI systems can reproduce discriminatory outcomes even when protected characteristics are not directly used. This paper examines digital redlining in the smart city and argues that algorithmic housing tools mirror long standing structural inequities that raise significant concerns under fair housing and civil rights law. It evaluates how automated screening, predictive …


Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty Jan 2026

Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models …


Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen Jan 2026

Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen

Student Publications [Scholarly]

Modern intelligent transportation systems (ITS) increasingly rely on connected electronic control units (ECUs), exposing in-vehicle networks to cyber-attacks such as message injection on the Controller Area Network (CAN) bus. While prior work has focused on post-factum detection, this paper addresses the underexplored task of forecasting cyber-attacks before they occur. We propose a spatio-temporal graph neural network (STGNN) architecture that models CAN traffic as a dynamic graph sequence, where nodes represent active CAN IDs and edges capture statistical co-activation patterns. Each graph snapshot encodes temporal features such as inter-arrival statistics and entropy, and is processed using graph attention layers followed by …


Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim Jan 2026

Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim

School of Cybersecurity Faculty Publications

Phishing involves manipulating individuals into revealing private data, e.g., user IDs, bank details, and passwords. The observed surge in fraud is related to increased deception, impersonation, and advanced online attacks. Thus, effective phishing detection methods are required to mitigate escalating global phishing threats. Existing methods (e.g., heuristics-based, signature-based, and visual similarity-based methods) attempt to detect phishing sites, and machine learning (ML) and deep learning (DL) methods are effective in the cybersecurity context in terms of learning from data, offering insights, and forecasting. However, independent ML algorithms are limited when handling complex data, and DL techniques surpass traditional ML methods in …


Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi Jan 2026

Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi

School of Cybersecurity Faculty Publications

Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we …


The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li Jan 2026

The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li

Computer Science Faculty Publications

Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …


Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol Jan 2026

Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol

Computer Science Faculty Publications

Large Language Models (LLMs) are becoming critical infrastructure in scientific, healthcare, and governmental contexts. As frontier AI laboratories increasingly partner with government agencies, a fundamental question arises: Who should control the safety and policy-enforcement layers that constrain model behavior? Current safety mechanisms (LLM guardrails) are typically designed for generic "harmlessness" and operate by detecting semantic patterns and refusing requests. However, they are inadequate governance instruments because they cannot implement auditable, domain-specific controls tied to external regulatory policy objects (e.g., control lists or rules governing personally identifying information). Even a perfectly aligned model is not able to express institution-specific policy without …


An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang Jan 2026

An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang

Electrical & Computer Engineering Faculty Publications

This research addresses cyber risk by defending against backdoor attacks on Graph Neural Networks (GNNs). We propose the Explainable Complex System-Mitigation Triangular (ECSMT) Framework, which integrates Robust Training, Graph Regularization, and Data Sanitization into a lightweight, hardware-efficient defense layer. To evaluate structural generalizability, we conducted empirical evaluations across three distinct benchmark domains (AIDS, MUTAG, and PROTEINS) using a Graph Isomorphism Network (GIN) backbone. Under a baseline 5% backdoor subgraph trigger injection ratio, ECSMT achieves excellent utility retention, securing a Clean Accuracy (CA) of 97.33% (±0.62%) while reducing the Attack Success Rate (ASR) from 97.00% down to 69.45% on the primary …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias Jan 2026

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han Jan 2026

Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han

Accounting Faculty Publications

This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm-year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post-breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for …


A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring, Kulsoom S. Bughio, David M. Cook, Abdul M. Unar Jan 2026

A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring, Kulsoom S. Bughio, David M. Cook, Abdul M. Unar

Research outputs 2022 to 2026

The rapid adoption of Internet Medical Things (IoMT) technologies in remote patient monitoring has reshaped healthcare delivery by enabling continuous, real-time clinical observation outside traditional care settings. However, this shift has also expanded the cyber-attack surface across heterogeneous, resource-constrained medical devices, wireless networks, cloud services, and third-party platforms. In cyber warfare, healthcare has become an incorporated target of geopolitics, with hospitals, remote monitoring systems, and emergency health systems being used to broaden the attack surface for adversaries to exploit. Existing security approaches for IoMT environments remain largely manual, fragmented, and reactive, limiting their effectiveness in dynamically assessing vulnerabilities and supporting …


Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou Dec 2025

Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou

Faculty and Staff Publications & Presentations

This framework addresses the critical gap between post-quantum standards and workforce readiness. Shor's algorithm demonstrates that sufficiently powerful quantum computers can break the cryptographic foundations of internet security. While the cryptography research community has developed quantum-resistant algorithms, educational institutions have not prepared students to implement these solutions. Recent surveys show fewer than half of organizations have begun planning for post-quantum cryptography (PQC) transitions (Entrust Cybersecurity Institute, 2024; U.S. Government Accountability Office, 2023; (ISC)², 2024). The NICE Framework (Newhouse, Keith, Scribner, & Witte, 2017) outlines the knowledge and skills that cybersecurity professionals should possess. The framework omits post-quantum cryptography entirely. Organizations …


Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems, George Antoniou Dec 2025

Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems, George Antoniou

Faculty and Staff Publications & Presentations

This comparative study examines patterns of Large Language Model (LLM) weaponization through systematic analysis of four major exploitation incidents spanning 2023-2025. While existing research focuses on isolated incidents or theoretical vulnerabilities, this study provides the first comprehensive comparative framework analyzing exploitation patterns across state-sponsored cyber-espionage (Anthropic Claude incident), academic security research (GPT-4 autonomous privilege escalation), social engineering platforms (SpearBot phishing framework), and underground criminal commoditization (WormGPT/FraudGPT ecosystem). Through comparative analysis across eight dimensions—adversary sophistication, target selection, exploitation techniques, autonomy levels, detection evasion, attribution challenges, defensive gaps, and capability democratization—this research identifies critical cross-case patterns informing defensive prioritization. Findings reveal three …


Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz Dec 2025

Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz

Other Faculty Materials

Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible …


Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney Dec 2025

Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney

Department of Computer Science Publications

Ireland's small and medium enterprises (SMEs) face a critical cyber resilience gap. SMEs account for 99.8% of all enterprises in Ireland and employ over 2.29 million people, representing 67.9% of total employment (based on the latest CSO 2022 figures). This cyber resilience assessment reveals that the majority of SMEs remain underprepared for modern cyber threats.


Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi Nov 2025

Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi

Research & Publications

Privacy harms have expanded alongside rapid technological change, challenging the adequacy of existing regulatory frameworks. This systematic review (1990–2025) systematically maps documented privacy harms to specific legal mechanisms and observed enforcement outcomes across jurisdictions, using PRISMA-guided methods and ROBIS risk-of-bias assessment. We synthesize evidence on major regimes (e.g., GDPR, COPPA, CCPA, HIPAA, GLBA) and conduct comparative legal analysis across the U.S., E.U., and underexplored regions in Asia, Latin America, and Africa. Key findings indicate increased recognition of data subject rights, persistent gaps in cross-border data governance, and emerging risks from AI/ML/LLMs, IoT, and blockchain, including data breaches, algorithmic discrimination, and …


Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou Nov 2025

Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou

Faculty and Staff Publications & Presentations

The rapid advancement of quantum computing represents both a revolutionary opportunity and an existential threat to contemporary cybersecurity infrastructure. While quantum computers promise unprecedented computational capabilities, they simultaneously pose a critical risk to current cryptographic protocols that protect sensitive data, financial systems, and national security frameworks. Post-quantum cryptography (PQC) standards, recently formalized by NIST in 2024, provide a roadmap for quantum-resistant encryption. However, a significant gap exists between technological advancement and educational preparedness, with most cybersecurity curricula failing to adequately prepare students for the quantum era. This paper addresses the urgent need for comprehensive quantum readiness in cybersecurity education across …


Cv: Mathias Plass (Cybersecurity), Mathias Plass Nov 2025

Cv: Mathias Plass (Cybersecurity), Mathias Plass

ECaMS Department Faculty Curricula Vitae

No abstract provided.