Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1 - 30 of 4656

Full-Text Articles in Information Security

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke Dec 2026

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke

Research outputs 2022 to 2026

Industry 5.0’s increasing integration of IT and OT systems is transforming industrial operations but also expanding the cyber–physical attack surface. Industrial Control Systems (ICS) face escalating security challenges as traditional siloed defenses fail to provide coherent, cross-domain threat insights. We present BRIDG-ICS (BRIDge for Industrial Control Systems), an AI-enriched Knowledge Graph (KG) framework for context-aware threat analysis and quantitative assessment of cyber resilience in smart manufacturing environments. BRIDG-ICS fuses heterogeneous industrial and cybersecurity data into an integrated Industrial Security Knowledge Graph linking assets, vulnerabilities, and adversarial behaviors with probabilistic risk metrics (e.g., exploit likelihood, attack cost). This unified graph representation …


Assessor Experiences In Cmmc Level 2 Certification Assessments: An Interpretative Phenomenological Analysis Of Role Expectations, Samuel Heuchert, John Hastings Oct 2026

Assessor Experiences In Cmmc Level 2 Certification Assessments: An Interpretative Phenomenological Analysis Of Role Expectations, Samuel Heuchert, John Hastings

Research & Publications

The Cybersecurity Maturity Model Certification program requires that third-party assessments be conducted under a non-consultative model. The model is intended to ensure impartiality for organizations seeking certification. While this structure defines expectations for assessor behavior, assessor experiences and interpretations of these constraints remain underexamined. The study examines the lived experiences of CMMC-Certified Assessors and how they navigate role expectations within the non-consultative model. Using Role Conflict Theory as a guiding framework, the study applied Interpretative Phenomenological Analysis (IPA) to semi-structured interviews to explore how assessors make sense of their roles. The analysis identified experiential themes that describe how assessors construct …


Prune: A Patching Based Repair Framework For Certifiable And Privacy-Robust Unlearning Of Neural Networks, Xuran Li, Jingyi Wang, Xiaohan Yuan, Peixin Zhang Sep 2026

Prune: A Patching Based Repair Framework For Certifiable And Privacy-Robust Unlearning Of Neural Networks, Xuran Li, Jingyi Wang, Xiaohan Yuan, Peixin Zhang

Research Collection School Of Computing and Information Systems

Machine unlearning has emerged as a key mechanism for enabling the “right to be forgotten” in neural network models, allowing the selective removal of specific training data upon request. Existing approaches typically rely on retraining models with the remaining data, which is computationally expensive and difficult to verify, especially when deployed models are distributed or resource-constrained. To address this challenge, our prior conference work introduced PRUNE, a patching-based framework that formulates unlearning as a neural network repair problem. PRUNE achieves targeted forgetting by learning lightweight patch networks that redirect model predictions on the data to be unlearned while preserving performance …


Clinic-In-A-Box: A Portable, Software-Defined Cyber Range For Realistic, Scenario-Based Cybersecurity Training, Ethan Chumley, Aaron Nair, Royce Yaezenko, Joshua Payne, Veronika Kyles, Paul Wagner, Robert J. Honomichl, Ryan Straight, Shengjie Xu Aug 2026

Clinic-In-A-Box: A Portable, Software-Defined Cyber Range For Realistic, Scenario-Based Cybersecurity Training, Ethan Chumley, Aaron Nair, Royce Yaezenko, Joshua Payne, Veronika Kyles, Paul Wagner, Robert J. Honomichl, Ryan Straight, Shengjie Xu

Journal of Cybersecurity Education, Research and Practice

Realistic, hands-on cybersecurity training has traditionally depended on fixed infrastructure such as dedicated lab hardware, cloud subscriptions, or permanent network connectivity, limiting where and how often it can be delivered. This paper presents the design and implementation of a portable, scenario-based cybersecurity training platform housed in a single travel case and built from commodity hardware, type-1 hypervisor virtualization, containerized service orchestration, and software-defined networking. The platform clones, isolates, and resets complete lab environments on demand, allowing the same physical system to support repeated classroom, workshop, or field deployments with minimal manual reconfiguration. Training scenarios are grounded in generated organizational profiles …


Between Digital Transformation And Regulatory Vacuum: Cybersecurity Of Public Services In Mozambique, Faztudo Languisse Eng. Aug 2026

Between Digital Transformation And Regulatory Vacuum: Cybersecurity Of Public Services In Mozambique, Faztudo Languisse Eng.

Journal of Cybersecurity Education, Research and Practice

The rapid expansion of digital public services in Mozambique—including e-government platforms, digital health systems, and electronic tax administration—has outpaced the development of a coherent legal framework for cybersecurity. While Law No. 3/2017 (Electronic Transactions Law) of 9 January 2017 introduced foundational data-protection principles, Mozambique long lacked a dedicated cybersecurity regulatory authority, mandatory security standards, and formal incident-notification mechanisms. This regulatory vacuum exposed critical public services to escalating cyber risks as digital transformation was actively promoted as a development priority. This article examines the legal and institutional gaps in Mozambique's cybersecurity governance framework prior to the 2026 Cybersecurity and Cybercrime Laws, …


Self Efficacy And Instructional Support Predict Cyber Deception Acceptance In Ics And Ot Cybersecurity, Daniel Ward Aug 2026

Self Efficacy And Instructional Support Predict Cyber Deception Acceptance In Ics And Ot Cybersecurity, Daniel Ward

Journal of Cybersecurity Education, Research and Practice

Cyber deception can produce high-confidence evidence of unauthorized activity in industrial control systems (ICS) and operational technology (OT), but practitioners must consider the technology useful, safe, understandable, and supported before they will use it. This study reports a secondary quantitative analysis of a deidentified survey of United States-based ICS and OT professionals to determine whether psychological and instructional factors predict adoption readiness and effective utilization beyond education, experience, and sector. Hierarchical ordinary least squares regression with HC3 robust standard errors was conducted on 262 complete cases. The demographics-only model was not significant and explained 2.8 percent of outcome variance. Adding …


Opengrcrmf: A Vendor-Neutral Framework For Teaching And Modeling Rmf Automation, Continuous Authorization, And Zero Trust Governance, Anand Janjal Aug 2026

Opengrcrmf: A Vendor-Neutral Framework For Teaching And Modeling Rmf Automation, Continuous Authorization, And Zero Trust Governance, Anand Janjal

Journal of Cybersecurity Education, Research and Practice

Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven risk management [1]-[3], [13], [15]. Manual System Security Plan (SSP) updates, spreadsheet-based Plan of Action and Milestones (POA&M) tracking, and disconnected assessment evidence create governance latency: the delay between operational security events and authorization-ready governance response. This paper presents OpenGRCRMF, a proposed open, vendor-neutral reference framework that models RMF lifecycle activities as workflow states, treats authorization artifacts as structured governance objects, and …


Personal Authenticity For Engagement And Transfer In Introductory Cybersecurity Education, Daniel T. Hickey, Ronald J. Kantor Aug 2026

Personal Authenticity For Engagement And Transfer In Introductory Cybersecurity Education, Daniel T. Hickey, Ronald J. Kantor

Journal of Cybersecurity Education, Research and Practice

Abstract—This conceptual/theoretical paper explores how personal authenticity might promote generative learning in introductory cybersecurity courses. Generative learning transfers confidently to future educational, professional, personal, and testing situations. This cycle of design-based research addresses the concern that more typical professionally authentic contexts (e.g., hospitals, banks, etc.) may be alien and overwhelming to many students, particularly those in introductory courses and/or from non-professional families and communities. If so, this leads to “inert” knowledge that does not transfer. Personal authenticity is rooted in expansive framing, a modern theory of learning transfer. We reframe expansive framing as personal authenticity to make it …


A Return On Investment (Roi) Evaluation Tool For Quantifying The Value Of Cybersecurity Certifications, Nicolas Meysmans, Kelly Hughes Aug 2026

A Return On Investment (Roi) Evaluation Tool For Quantifying The Value Of Cybersecurity Certifications, Nicolas Meysmans, Kelly Hughes

Journal of Cybersecurity Education, Research and Practice

The growing reliance on cybersecurity certifications has increased the financial and professional stakes associated with certification decision-making for cybersecurity professionals. Despite their widespread use in hiring and career advancement, there is limited objective guidance available to help individuals evaluate the return on investment (ROI) of specific certifications. This gap has created uncertainty regarding which credentials provide the greatest value relative to their cost and market impact. This study presents a data-driven, design science–based tool that supports cybersecurity professionals in evaluating certification ROI using practitioner survey data combined with certification cost and labor-market demand indicators. The paper also demonstrates how such …


From Disruption To Replacement: The 2026 Cae Cybersecurity Community Symposium And The Emerging Federal-Academic Compact For An Ai Workforce, Sunday Oludare Ogunlana Aug 2026

From Disruption To Replacement: The 2026 Cae Cybersecurity Community Symposium And The Emerging Federal-Academic Compact For An Ai Workforce, Sunday Oludare Ogunlana

Journal of Cybersecurity Education, Research and Practice

The cybersecurity workforce gap in the United States is estimated at several hundred thousand unfilled positions, and the rapid integration of artificial intelligence into adversary tradecraft and federal cyber operations is widening that gap qualitatively as well as quantitatively, threatening national security and the operational readiness of graduates entering the field. This perspective article synthesizes the principal arguments advanced by five federal and academic speakers at the 2026 CAE Cybersecurity Community Symposium, using verbatim session transcripts, a structured thematic extraction process, and triangulation against published workforce policy and peer-reviewed literature. Findings document a unified speaker thesis that artificial intelligence now …


Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram Aug 2026

Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram

Masters Theses

This thesis presents the design, implementation, and evaluation of a lightweight end-to-end cryptographic framework integrated with a semantic quality-of-service classification system for augmented reality based telesurgery. Telesurgery can deliver expert surgical care to underserved populations, but adoption has been limited by unresolved cybersecurity, network performance, and resilience challenges. The core tension is that strong encryption adds latency that may exceed the clinical safety threshold, while unencrypted systems remain vulnerable to attacks that could endanger patients during live procedures.

The framework addresses this tension through a dual-edge security middlebox that performs per-flow encryption using semantically selected ciphers: AES-128-GCM for latency-critical haptic …


Navigating Enhanced Exploration Assistance (Nexa), Azhari Abbas, Caleb Fakunle, Ryan Powell, Donovan Livingston Aug 2026

Navigating Enhanced Exploration Assistance (Nexa), Azhari Abbas, Caleb Fakunle, Ryan Powell, Donovan Livingston

Discovery Day - Daytona Beach

NEXA is an artificial intelligence software platform developed to enhance residential security and property monitoring through seamless integration with autonomous drone systems. This research application of advanced AI in surveillance aims to create a standalone solution capable of real-time threat detection and intelligent alert management. By processing visual and sensory data, NEXA facilitates autonomous drone operation with minimal human intervention. Secure communication channels ensure that instant alerts are delivered to property owners and, potentially, law enforcement, improving response times in security incidents, search-and-rescue operations, and perimeter surveillance. Additionally, NEXA is capable of interfacing with commercially available drone platforms and presents …


A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland Aug 2026

A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland

Discovery Day - Daytona Beach

In the modern age of computers and interconnected networks, cybersecurity and cyber-attackers are evolving in tandem to exploit each other’s vulnerabilities. One technique used by both parties is Operating System Fingerprinting (OSF): with the knowledge of what Operating System a target system is running, innate vulnerabilities can be identified and patched or exploited. Historically, OSF utilizes two main methods: passive and active—the former trades accuracy with undetectability while the latter is generally more detectable but more accurate. However, recent work has combined OSF with Machine Learning (ML) to improve accurate identification. The work presented here is a survey for the …


Closing The Awareness–Behavior Gap: A Role-Based Phishing Training Framework For Higher Education, Ranylene O. Olaybal, Ryan A. Olaybal Aug 2026

Closing The Awareness–Behavior Gap: A Role-Based Phishing Training Framework For Higher Education, Ranylene O. Olaybal, Ryan A. Olaybal

Journal of Cybersecurity Education, Research and Practice

Phishing remains one of the most persistent cybersecurity threats facing higher education institutions, where diverse user populations and highly connected digital environments increase exposure to social engineering attacks. Although cybersecurity awareness initiatives are widely implemented, high awareness does not always translate into secure behavior. This study examined phishing awareness, phishing-related practices, phishing susceptibility, and phishing experiences among college students, teaching faculty, and administrative staff in a private higher education institution in the Philippines. Using a quantitative cross-sectional design, data were collected from 553 respondents through a validated survey instrument and analyzed using descriptive statistics, one-way analysis of variance, Tukey's honestly …


Efficient And Universal Watermarking For Llm-Generated Code Detection, Boquan Li, Zirui Fu, Mengdi Zhang, Peixin Zhang, Jun Sun, Xingmei Wang Aug 2026

Efficient And Universal Watermarking For Llm-Generated Code Detection, Boquan Li, Zirui Fu, Mengdi Zhang, Peixin Zhang, Jun Sun, Xingmei Wang

Research Collection School Of Computing and Information Systems

Large language models (LLMs) have significantly enhanced the usability of AI-generated code, providing effective assistance to programmers. This advancement also raises ethical and legal concerns, such as academic dishonesty and the generation of malicious code. For accountability, it is imperative to detect whether a piece of code is AI-generated. Watermarking is broadly considered a promising solution and has been successfully applied to identify LLM-generated text. However, existing efforts on code are far from ideal, suffering from limited universality and excessive time and memory consumption. In this work, we propose a plugand- play watermarking approach for AI-generated code detection, named ACW …


Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif Aug 2026

Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif

International Journal of Cybersecurity Intelligence & Cybercrime

Cybercrime investigations increasingly depend on the ability to interpret large volumes of automated security events. For organizations without dedicated security operations centres, a situation common among small and medium enterprises, the manual translation of raw alerts into structured threat intelligence represents a critical bottleneck that slows investigative triage and limits cross-case comparability. This paper evaluates an automated enrichment pipeline designed to address this bottleneck by mapping security events to standardised adversary behaviour labels drawn from the MITRE ATT&CK framework, supporting both operational response and cybercrime investigation workflows. We compare three pipeline configurations, a general-purpose encoder model, a cybersecurity domain-adapted variant, …


Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen Jul 2026

Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen

Dissertations, Theses, and Projects

The increasing adoption of the Internet of Medical Things (IoMT) has improved healthcare delivery through connected medical devices while simultaneously expanding the cybersecurity risks facing healthcare organizations. Although machine learning based intrusion detection systems have demonstrated high detection accuracy, their ability to respond reliably to previously unseen cyberattacks remains uncertain. This study investigated how a Neural Network model and a Logistic Regression model classified novel cyberattacks within the IoMT environment. The Neural Network and Logistic Regression models were both trained and tested using a subset of the CICIoMT2024 benchmark dataset. The Neural Network achieved 99.82% test accuracy and a 0.94 …


Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap Jul 2026

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap

Journal of Cybersecurity Education, Research and Practice

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …


Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson Jul 2026

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson

Journal of Cybersecurity Education, Research and Practice

In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …


Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry Jul 2026

Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry

Journal of Cybersecurity Education, Research and Practice

This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established …


Building The Next Cybersecurity Workforce: A Grades 7–12 Curriculum To Close The Cyber Talent Gap, Mohammed A. Salam, Iqbal Shareef, Rich P. Manprisio Jul 2026

Building The Next Cybersecurity Workforce: A Grades 7–12 Curriculum To Close The Cyber Talent Gap, Mohammed A. Salam, Iqbal Shareef, Rich P. Manprisio

Journal of Cybersecurity Education, Research and Practice

In today’s rapidly evolving technological landscape, cyberattacks pose increasing threats, yet a global shortage of cybersecurity and digital forensics professionals leaves industries vulnerable, similar to having too few law enforcement officers in a densely populated city. The judicial system faces rising digital crimes and fraud cases, further strained by the lack of experts to analyze and extract digital evidence. Despite high demand, millions of positions remain unfilled. This paper identifies the root causes of the cybersecurity workforce shortage and proposes a targeted solution: a curriculum for Grades 7–12 designed to foster cybersecurity awareness and interest. The methodology included a comprehensive …


Cybersecurity Governance Of Industrial Iot In Sub-Saharan Africa: Policy Gaps, Threat Landscape, And Lessons From Comparative African Contexts, Faztudo Languisse Eng. Jul 2026

Cybersecurity Governance Of Industrial Iot In Sub-Saharan Africa: Policy Gaps, Threat Landscape, And Lessons From Comparative African Contexts, Faztudo Languisse Eng.

Journal of Cybersecurity Education, Research and Practice

The rapid deployment of Industrial Internet of Things (IIoT) systems across Sub-Saharan Africa's extractive, energy, logistics, and agro-industrial sectors has introduced a cybersecurity challenge of growing urgency: industrial networks that were designed for operational efficiency are increasingly exposed to cyber threats for which neither the organizations nor the regulatory frameworks are adequately prepared. This article examines the cybersecurity governance of IIoT systems in a developing African economy, using Mozambique as a primary case study and drawing comparative lessons from South Africa, Rwanda, and Kenya. Through an integrative literature review and documentary analysis of national digital, cybersecurity, and industrial policies, the …


Contemporary Cybersecurity Challenges In Emerging Technologies: A Systematic Literature Analysis, Faztudo Languisse Prof Jul 2026

Contemporary Cybersecurity Challenges In Emerging Technologies: A Systematic Literature Analysis, Faztudo Languisse Prof

Journal of Cybersecurity Education, Research and Practice

The accelerating convergence of artificial intelligence (AI), the Internet of Things (IoT), cloud computing, blockchain, and quantum computing has fundamentally transformed the global threat landscape, introducing cybersecurity challenges of unprecedented complexity and scale. This systematic literature review synthesizes findings from peer-reviewed publications, institutional reports, and regulatory documents published primarily between 2020 and 2025 to provide an integrated analysis of contemporary cybersecurity challenges across five key emerging technology domains. The review identifies critical vulnerabilities inherent to each domain, documents the evolution of threat actors and attack methodologies — including AI-powered ransomware, adversarial machine learning, and harvest-now-decrypt-later quantum attacks — and evaluates …


Security Architecture Decision Framework For Endpoint Protection In Resource-Constrained K-12 Environments, Jason Folker Jul 2026

Security Architecture Decision Framework For Endpoint Protection In Resource-Constrained K-12 Environments, Jason Folker

Journal of Cybersecurity Education, Research and Practice

K-12 educational institutions face an ongoing challenge in protecting endpoints when budgets and staffing prevent the implementation of standard security best practices. Technology directors routinely make difficult decisions about administrative rights, software controls, and security tooling, but they lack frameworks designed for the constraints and priorities specific to educational environments. This paper develops a security architecture decision framework tailored for K-12 endpoint protection. The framework integrates five weighting dimensions to help technology directors evaluate competing architectural choices. These dimensions include educational impact, security risk reduction, resource requirements, compliance obligations, and operational feasibility. The framework creates structured documentation that helps decision-makers …


Air: Improving Agent Safety Through Incident Response, Zibo Xiao, Jun Sun, Junjie Chen Jul 2026

Air: Improving Agent Safety Through Incident Response, Zibo Xiao, Jun Sun, Junjie Chen

Research Collection School Of Computing and Information Systems

Large Language Model (LLM) agents are increasingly deployed in practice across a wide range of autonomous applications. Yet current safety mechanisms for LLM agents focus almost exclusively on preventing failures in advance, providing limited capabilities for responding to, containing, or recovering from incidents after they inevitably arise. In this work, we introduce AIR, the first incident response framework for LLM agent systems. AIR defines a domain-specific language for managing the incident response lifecycle autonomously in LLM agent systems, and integrates it into the agent's execution loop to (1) detect incidents via semantic checks grounded in the current environment state and …


Rendering Data Unlearnable By Exploiting Llm Alignment Mechanisms, Ruihan Zhang, Jun Sun Jul 2026

Rendering Data Unlearnable By Exploiting Llm Alignment Mechanisms, Ruihan Zhang, Jun Sun

Research Collection School Of Computing and Information Systems

Large language models (LLMs) are increasingly trained on massive, heterogeneous text corpora, raising serious concerns about the unauthorised use of proprietary or personal data during model training. In this work, we address the problem of data protection against unwanted model learning in a realistic blackbox setting. We propose Disclaimer Injection, a novel data-level defence that renders text unlearnable to LLMs. Rather than relying on model-side controls or explicit data removal, our approach exploits the models’ own alignment mechanisms: injecting carefully designed alignment-triggers to prevent effective learning. Through layer-wise analysis, we find that finetuning on such protected data induces persistent activation …


Spatiotemporal Sycophancy: Negation-Based Gaslighting In Video Large Language Models, Ziyao Tang, Pengkun Jiao, Bin Zhu, Huiyan Qi, Jingjing Chen, Yu-Gang Jiang Jul 2026

Spatiotemporal Sycophancy: Negation-Based Gaslighting In Video Large Language Models, Ziyao Tang, Pengkun Jiao, Bin Zhu, Huiyan Qi, Jingjing Chen, Yu-Gang Jiang

Research Collection School Of Computing and Information Systems

Video Large Language Models (Vid-LLMs) have demonstrated remarkable performance in video understanding tasks, yet their robustness under conversational interaction remains largely underexplored. In this paper, we identify spatiotemporal sycophancy, a failure mode in which Vid-LLMs retract initially correct, visually grounded judgments and conform to misleading user feedback under negation-based gaslighting. Rather than merely changing their answers, the models often fabricate unsupported temporal or spatial explanations to justify incorrect revisions. To systematically investigate this phenomenon, we propose a negation-based gaslighting evaluation framework and introduce GasVideo-1000, a curated benchmark designed to probe spatiotemporal sycophancy with clear visual grounding and temporal reasoning requirements. …


A Robust Hybrid Security Framework: Integrating Multi-Layered Text Encryption With Barcode-Based Steganography, Mohamed Sayed, Talaat M. Wahbi, Farooq Abdalwahab Haboub Jun 2026

A Robust Hybrid Security Framework: Integrating Multi-Layered Text Encryption With Barcode-Based Steganography, Mohamed Sayed, Talaat M. Wahbi, Farooq Abdalwahab Haboub

BAU Journal - Science and Technology

The widespread use of the Internet is causing increasing security concerns regarding online communications. One method for achieving secure communication between authorized parties is steganography. We herein employ multilevel technologies, including compression, encryption, barcoding, and steganography to secure a secret text message. Type I multilevel steganography is used with a two-level setup. The first level uses enhanced least significant bit (secure LSB-L1) image steganography; the output is a stego-image file, the cover is an image file, and the secret data in this level is English text. The output from the first level is encrypted using the RSA algorithm, and the …


Operationalizing Supply-Chain Hygiene In Graduate Is Education: A Hands-On Module For Secure Software And Ai/Ml Pipelines, Dominic A. Wilson Jun 2026

Operationalizing Supply-Chain Hygiene In Graduate Is Education: A Hands-On Module For Secure Software And Ai/Ml Pipelines, Dominic A. Wilson

Journal of Cybersecurity Education, Research and Practice

Supply-chain attacks (including typosquatting, dependency confusion, compromised builds, dataset poisoning, and backdoored models) pose growing threats to analytics platforms central to Information Systems (IS). While frameworks like the Secure Software Development Framework (SSDF) and Supply-chain Levels for Software Artifacts (SLSA) offer guidance, IS curricula often lack accessible, infrastructure-light modules that build practical skills for mitigating these risks. This experience report presents a two-week module embedded in a graduate Secure Coding course required for a Master’s in Applied Security and Analytics degree. The module operationalizes secure development habits across both traditional software and machine learning (ML) pipelines. The module addresses a …


The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl Jun 2026

The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl

Journal of Cybersecurity Education, Research and Practice

Artificial intelligence (AI) is being adopted at an exponential rate to improve efficiency, decision-making, and cybersecurity, but its rapid integration introduces new and often poorly understood risks, including system errors, algorithmic bias, data privacy concerns, security vulnerabilities, and ethical dilemmas. This paper examines how organizations are implementing AI and evaluates the National Institute of Standards and Technology's AI Risk Management Framework (NIST AI RMF) as a tool for managing these risks. It reviews the benefits of AI adoption alongside the risks emerging from its use in business and broader society and examines the legal and ethical challenges organizations face when …