Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Security

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 1 - 19 of 19

Full-Text Articles in Cybersecurity

Assessing Flaws In Captcha Security Through Progress In Ai, Jaydon Stanislowski Jul 2026

Assessing Flaws In Captcha Security Through Progress In Ai, Jaydon Stanislowski

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

Protecting the internet from the threat of malicious bot activity is an important problem as AI tools become more powerful and commonplace over time. To that end, security measures are employed across websites in the form of CAPTCHAs, short challenges designed to identify and block fake web traffic. Yet, they become less effective over time as AI becomes more powerful, and thus more capable of solving them. This paper examines recent research on the threat to CAPTCHA security posed by current AI models and how this security can be reinforced over time, focusing primarily on Google’s reCAPTCHA v3.


Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz Dec 2025

Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz

Other Faculty Materials

Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible …


Zero Trust Architecture For Electric Transportation Systems: A Systematic Survey And Deep Learning Framework For Replay Attack Detection, Grace Muriithi, Behnaz Papari, Ali Arsalan, Laxman Timilsina, Alex Muriithi, Elutunji Buraimoh, Asif Khan, Gokhan Ozkan, Christopher Edrington, Akram Papari Jul 2025

Zero Trust Architecture For Electric Transportation Systems: A Systematic Survey And Deep Learning Framework For Replay Attack Detection, Grace Muriithi, Behnaz Papari, Ali Arsalan, Laxman Timilsina, Alex Muriithi, Elutunji Buraimoh, Asif Khan, Gokhan Ozkan, Christopher Edrington, Akram Papari

Montclair State University Scholarship & Creative Works

Modern and autonomous hybrid electric vehicles (HEVs), as complex cyber-physical systems, represent a key innovation in the future of transportation. However, the increasing interconnectivity and reliance on digital components expose these vehicles to significant cybersecurity risks. To address these challenges, Zero Trust Architecture (ZTA) has emerged as a promising security framework. Operating on the principle of ‘never trust, always verify,’ ZTA offers a comprehensive approach to ensuring continuous trust verification in HEV systems. Despite its potential, the application of ZTA within cyber-physical vehicular systems remains underexplored, and its practical benefits and limitations are not yet fully understood by the engineering …


Exploiting Compiler-Introduced Vulnerabilities In C: A Cross-Compiler And Cross-Architecture Analysis Of Undefined Behavior, Erik Mccutchen Jun 2025

Exploiting Compiler-Introduced Vulnerabilities In C: A Cross-Compiler And Cross-Architecture Analysis Of Undefined Behavior, Erik Mccutchen

Master's Theses

Compilers are a critical component in generating secure software across engineering disciplines. However, languages like C that permit undefined behavior introduce a fundamental tension between the compiler’s interpretation of undefined behavior and the security of the generated code. This tension can result in security vulnerabilities that, from the programmer's perspective, are ``created'' by the compiler. The widespread use of these languages, combined with the complexity of modern optimizations and limited developer visibility into compiler behavior, makes these vulnerabilities both pervasive and difficult to detect.

Building on prior work, this thesis refines a dataset of C code snippets that exhibit Compiler-Introduced …


Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono Jun 2025

Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono

Master's Theses

In the realm of network security, Network Intrusion Detection Systems (NIDS) are essential for identifying and mitigating malicious activities targeting networked devices. Traditionally, these systems have relied on signature-based and anomaly-based detection techniques. However, the increasing complexity and adapt- ability of cyber threats have driven the adoption of Machine Learning (ML) ap- proaches in modern NIDS, significantly improving their ability to detect a wider range of attack vectors. Despite these advancements, ML-based NIDS remain vulnerable to adversarial examples—deliberately crafted inputs designed to mislead models and trigger incorrect classifications. Originally identified in the field of computer vision, adversarial examples now pose …


Does The Transit Industry Understand The Risks Of Cybersecurity And Are The Risks Being Appropriately Prioritized?, Scott F. Belcher, Terri Belcher, James Grimes, Lusa Holmstrom, Andy Souders May 2025

Does The Transit Industry Understand The Risks Of Cybersecurity And Are The Risks Being Appropriately Prioritized?, Scott F. Belcher, Terri Belcher, James Grimes, Lusa Holmstrom, Andy Souders

Mineta Transportation Institute

The intent of this study is to assess the readiness, resourcing, and capabilities of public transit agencies to detect, identify, be protected from, respond to, and recover from cybersecurity vulnerabilities and threats. This study is an update of the 2020 Mineta Transportation Institute (MTI) study, “Is the Transit Industry Prepared for the Cyber Revolution? Policy Recommendations to Enhance Surface Transit Cyber Preparedness.” In the previous study, the authors found that the transit industry was ill-prepared for cybersecurity attacks. Unfortunately, after four years and the development of new, and often free, resources, the situation has not markedly improved. In fact, this …


The Future Of Ai: Join The Conversation, Jennifer Wojton, Cassandra Branham, Vijay Tummala, Laxima Niure Kandel, Kayla D. Taylor Mar 2025

The Future Of Ai: Join The Conversation, Jennifer Wojton, Cassandra Branham, Vijay Tummala, Laxima Niure Kandel, Kayla D. Taylor

Publications

Join the Conversation! The Future is AI? There is so much conflicting information about what AI is capable of, how it could/should be used, by whom and for what purpose. In this panel discussion, we hope to provide a baseline of information that will help all participants think critically and articulate thoughtful questions about the mechanics of AI, ethical use or non-use of AI in particular contexts (school, industry, business, art, etc.), and the impacts we are currently experiencing or are likely to experience. Hear from ERAU faculty of different disciplines to discuss what the current state of AI technology …


Design And Implementation Of Secured Hybrid Gateway Node For Securing Iot - Enabled Distribution Automation, Ally Bitebo Jan 2025

Design And Implementation Of Secured Hybrid Gateway Node For Securing Iot - Enabled Distribution Automation, Ally Bitebo

Tanzania Journal of Engineering and Technology (TJET)

The integration of smart grid and Internet of Things (IoT) technologies plays a crucial role in enhancing the quality of services provided by traditional electrical grids. This combination has enabled the introduction of new services, such as demand response, automatic meter reading, and IoT-enabled Distribution Automation (IoT-DA), which incorporates sensors, actuators, intelligent electrical devices (IEDs), and information and communication technologies to monitor and control the grid. However, this integration also introduces network security risks, including Denial of Service (DoS) attacks, false data injection, and masquerading attacks, such as system node impersonation that can transmit incorrect readings, trigger false alarms, and …


Scalable, Secure, And Adaptable Perception Systems Through Adversarial Analysis And Federated Fine-Tuning, Arkajyoti Mitra Jan 2025

Scalable, Secure, And Adaptable Perception Systems Through Adversarial Analysis And Federated Fine-Tuning, Arkajyoti Mitra

Computer Science and Engineering Dissertations - Archive

Perception systems are fundamental to intelligent machines, enabling them to sense, understand, and interpret complex environments. However, as perception increasingly underpins critical applications such as autonomous vehicles, IoT healthcare devices, and smart trading platforms, challenges related to security, scalability, and environmental understanding have become more pressing. This work addresses three core research questions: (1) How can we identify, analyze, and mitigate adversarial vulnerabilities in perception systems to ensure reliable operation under adversarial conditions? (2.1) How can AVPS models be efficiently scaled and fine-tuned across decentralized and resource-constrained environments while preserving privacy and performance? (2.2) How can we scale generative models …


A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty Jan 2025

A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

Sixth-generation (6G) wireless networks will become vulnerable due to native generative AI (GenAI)-driven intelligent poisoning attacks in both the radio unit and the core network. In particular, network parameters and metrics in cross-layer design pose fundamentally uncertain conditions and can be compromised through the native GenAI mechanism, which leverages data augmentation and reconstruction capabilities. This work investigates the capabilities of native GenAI to create novel poisoning attacks in wireless networks, while investigating their impact through uncertainty-informed root analysis. Then, detected attacks are mitigated by developing a trustworthy service aggregation in the wireless network. First, a joint decision problem is formulated …


Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi Jan 2025

Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi

School of Cybersecurity Faculty Publications

With the pervasive integration of artificial intelligence (AI) in various facets of modern technology, the importance of AI security has been thrust into the spotlight. The field is rapidly evolving, with new challenges and solutions emerging at a swift pace. However, the breadth and depth of AI security research have not been comprehensively mapped in recent times, presenting a crucial need for an extensive review and synthesis of existing literature. Given the increasing reliance on AI in critical domains such as healthcare, finance, and national security, ensuring the resilience and trustworthiness of these systems is imperative. This survey fulfills the …


Security Enhancement In Uav Swarms: A Case Study Using Federated Learning And Shap Analysis, Sushmitha Halli Sudhakara, Lida Haghnegahdar Jan 2025

Security Enhancement In Uav Swarms: A Case Study Using Federated Learning And Shap Analysis, Sushmitha Halli Sudhakara, Lida Haghnegahdar

School of Cybersecurity Faculty Publications

As cyber-physical systems (CPSs) increasingly integrate physical and digital realms, securing critical infrastructure, such as the Port of Virginia, becomes paramount. Among CPSs, Unmanned Aerial Vehicles (UAVs) are vital for monitoring, communication, and supporting the command and control through remote reconnaissance and surveillance missions. These UAV applications often require coordination, planning, and runtime reconfiguration, traditionally managed by human decision-makers. However, this approach has limitations, as extensively documented in the literature. Artificial Intelligence (AI) has emerged as a pivotal tool to address these limitations, enhancing risk mitigation and informed decision-making. This research proposes a machine learning (ML) based security mechanism, leveraging …


Security Enhancement In Aav Swarms: A Case Study Using Federated Learning And Shap Analysis, Sushmitha Halli Sudhakara, Lida Haghnegahdar Jan 2025

Security Enhancement In Aav Swarms: A Case Study Using Federated Learning And Shap Analysis, Sushmitha Halli Sudhakara, Lida Haghnegahdar

School of Cybersecurity Faculty Publications

As cyber-physical systems (CPSs) increasingly integrate physical and digital realms, securing critical infrastructure, such as the Port of Virginia, becomes paramount. Among CPSs, Autonomous Aerial Vehicles (AAVs) are vital for monitoring, communication, and supporting the command and control through remote reconnaissance and surveillance missions. These AAV applications often require coordination, planning, and runtime reconfiguration, traditionally managed by human decision-makers. However, this approach has limitations, as extensively documented in the literature. Artificial Intelligence (AI) has emerged as a pivotal tool to address these limitations, enhancing risk mitigation and informed decision-making. This research proposes a machine learning (ML) based security mechanism, leveraging …


Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady Jan 2025

Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady

Dartmouth College Ph.D Dissertations

Given the growing amount and variety of data handled by modern systems, it is crucial to guarantee the accuracy and protection of input data without errors or malicious intentions. The need to improve security in software programs often conflicts with the assurance of maximum performance, making developers and maintainers hesitant to incorporate more testing.

LangSec (Language-Theoretic Security) is a security approach that treats input validation as a formal language recognition problem, ensuring that only well-defined, unambiguous inputs are processed to eliminate exploitable parsing flaws. This dissertation explores integrating LangSec principles with Pareto optimization to enhance safety and robustness in digital …


A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms, Ravindra Mangar, Timothy Pierson, David Kotz Jul 2024

A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms, Ravindra Mangar, Timothy Pierson, David Kotz

Dartmouth Scholarship

In this article, we outline the challenges associated with the widespread adoption of smart devices in homes. These challenges are primarily driven by scale and device heterogeneity: a home may soon include dozens or hundreds of devices, across many device types, and may include multiple residents and other stakeholders. We develop a framework for reasoning about these challenges based on the deployment, operation, and decommissioning life cycle stages of smart devices within a smart home. We evaluate the challenges in each stage using the well-known CIA triad—Confidentiality, Integrity, and Availability. In addition, we highlight open research questions at each stage. …


Heuristic Machine Learning Approaches For Identifying Phishing Threats Across Web And Email Platforms, Ramprasath Jayaprakash, Krishnaraj Natarajan, J. Alfred Daniel, Chandru Vignesh Chinnappan, Jayant Giri, Hong Qin, Saurav Mallik Jan 2024

Heuristic Machine Learning Approaches For Identifying Phishing Threats Across Web And Email Platforms, Ramprasath Jayaprakash, Krishnaraj Natarajan, J. Alfred Daniel, Chandru Vignesh Chinnappan, Jayant Giri, Hong Qin, Saurav Mallik

Data Science Faculty Publications

Life has become more comfortable in the era of advanced technology in this cutthroat competitive world. However, there are also emerging harmful technologies that pose a threat. Without a doubt, phishing is one of the rising concerns that leads to stealing vital information such as passwords, security codes, and personal data from any target node through communication hijacking techniques. In addition, phishing attacks include delivering false messages that originate from a trusted source. Moreover, a phishing attack aims to get the victim to run malicious programs and reveal confidential data, such as bank credentials, one-time passwords, and user login credentials. …


An Efficient Ddos Attack Detection Framework For Vehicular Communication, Kolandaisamy Raenu May 2020

An Efficient Ddos Attack Detection Framework For Vehicular Communication, Kolandaisamy Raenu

Student Works (2020-2029)

Vehicular Ad Hoc Networks (VANETs) are rapidly gaining attention due to the diversity of services that they can potentially offer. VANET is a wireless network that allows vehicles to interconnect and communicate with other nearby vehicles and Road Side Units (RSUs). In VANET, each vehicle is considered as a node which is equipped with an On-Board Unit (OBU) and an Application Unit (AU). The nodes may connect and communicate with each other directly (i.e., Vehicle to Vehicle (V2V)) or through RSUs (i.e., Vehicle to Infrastructure (V2I)). This is primarily for alleviating an Intelligent Transport System (ITS) that aims to provide …


Gpu Acceleration Of Ciphertext-Policy Attribute-Based Encryption, Kai Fan Apr 2019

Gpu Acceleration Of Ciphertext-Policy Attribute-Based Encryption, Kai Fan

Student Theses and Dissertations

With the development of cloud computing, data security became popular in recent decades. The public key cryptography has its limitation for a considerable number of receivers, which need encrypt the plaintext several times which based on the receivers' number. Bethencourt. Et al., introduced Ciphertext-policy Attribute-based encryption (ABE) in 2007. CP-ABE became one of the hottest topics in the cryptography system. Because of the advantage of CP-ABE system, which is easy to use for remote storage or distributed data centers. Meanwhile, CP-ABE can provide fine-grain access control, which has the flexibility to send ciphertexts. However, it has such advantages, but the …


Towards Trustworthy Version Control Systems: Enhancing The Security Of Subversion, Ruchir Arya Aug 2016

Towards Trustworthy Version Control Systems: Enhancing The Security Of Subversion, Ruchir Arya

Theses

Software development often relies on a Version Control System (VCS) to manage the source code, documentation and configuration of files. A VCS allows team development in which multiple developers can work simultaneously on source code updates. It also provides the ability to keep track of the historical changes made to the data over time, including the ability to retrieve previous versions of the source code in order to locate and fix bugs, and roll back to earlier versions in case the working version becomes buggy or unstable.

Apache Subversion (SVN) is a popular version control system that uses a client-server …