Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

Old Dominion University

Discipline
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1 - 30 of 256

Full-Text Articles in Information Security

Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir Apr 2026

Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir

Cybersecurity Undergraduate Research Showcase

Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …


Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs Apr 2026

Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs

Cybersecurity Undergraduate Research Showcase

Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …


Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry Apr 2026

Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry

Cybersecurity Undergraduate Research Showcase

Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …


The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds Apr 2026

The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds

School of Cybersecurity Master's Level Projects and Papers

Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.

This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias Jan 2026

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li Jan 2026

The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li

Computer Science Faculty Publications

Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …


Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala Jan 2026

Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala

Computer Science Faculty Publications

Large Language Models (LLMs) are increasingly being adopted in a wide variety of domains, including sensitive domains such as healthcare and finance. However, persistent challenges such as unreliable data sources, privacy breaches, and hallucinated output continue to hinder their usage. We have experimented with several strategies to address these challenges. First, we developed BlockQwen, a blockchain-augmented framework that integrates decentralized trust validation, role-specific access control, and verifiable audit trails into the Qwen 2.5 LLM workflow. Second, we developed PrivAware, a multilayered privacy-enforcement framework, using a fine-tuned Flan-T5 model with self-attention masking, to safeguard data while maintaining high utility. Both systems …


Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge Jan 2026

Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge

Computer Science Faculty Publications

Medical imaging enables rapid and accurate diagnosis of COVID-19, with CT scans proving especially effective. However, data privacy concerns limit collaborative model development across hospitals. To address this issue, we introduce a novel federated learning framework. It is referred to as Independent Knowledge Distillation with post-Ensemble Federated Learning (IKDEFL). Differential Privacy (DP) is integrated into the framework to improve privacy guarantees. Three DP mechanisms are evaluated. These include Fixed Gaussian, Gaussian Adaptive, and Tree Adaptive. The evaluation has been conducted on heterogeneous and Non-Independent and Identically Distributed (Non-IID) datasets. These datasets reflect real-world hospital scenarios. Results show that IKDEFL significantly …


An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana Jan 2026

An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana

Computer Science Faculty Publications

Accurate prediction of ICU Length of Stay (LoS) is essential for clinical decision-making and healthcare resource management. Graph Neural Networks (GNNs), such as GraphSAGE, offer a natural fit by capturing patient data from Electronic Health Records (EHRs) through graph structures. However, the distributed and sensitive nature of this data raises both privacy and legal concerns regarding the aggregation and training of GNN models. This additionally leads to issues with data imbalance and model robustness. In this study, we perform an analysis of the Federated Graph Neural Network (GNN-FL) framework to enable decentralized learning on EHRs derived from the MIMIC-III dataset. …


Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson Dec 2025

Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson

Cybersecurity Undergraduate Research Showcase

This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …


Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman Nov 2025

Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman

Cybersecurity Undergraduate Research Showcase

The Model Context Protocol (MCP) has emerged as a critical standard for connecting AI agents to external data sources and tools. Still, its adoption has introduced significant security vulnerabilities across multiple attack surfaces. While recent research has catalogued extensive vulnerability taxonomies and attack implementations, automated detection methodologies remain limited. Current detection tools primarily employ static code analysis, which fails to identify behavioral vulnerabilities that only manifest during runtime server interactions. This study explores behavioral detection approaches for identifying MCP server vulnerabilities through systematic query-based testing, with particular emphasis on context manipulation techniques. Preliminary analysis of existing vulnerability research reveals 48 …


"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider Apr 2025

"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider

Cybersecurity Undergraduate Research Showcase

This study provides a comprehensive evaluation of the effectiveness that would result in the integration of AI into traditional threat hunting systems. To do so, 10-15 scholarly articles and data sets were evaluated to see the results of AI and machine learning threat hunting versus traditional systems. With so many proven benefits of this integration, this paper also explores how it impacts the protection of Intellectual property which is some of the most important forms of information that threat hunting systems aim to protect.


Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr. Apr 2025

Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr.

Cybersecurity Undergraduate Research Showcase

Geriatric crime continues to escalate in the digital era, where older individuals are disproportionately being targeted because of their low digital literacy and high susceptibility to online frauds. In this paper, we examine the breadth of elder fraud in Chesapeake, Virginia using FBI Internet Crime Complaint Center (IC3) data and state-level cybersecurity initiatives and survey responses. Older adults aged 60 and up have reported losses of over $3.4 billion in 2023 alone, underscoring the importance of proactive measures. It assesses the public awareness from traditional and AI-based perspectives revealing significant gaps in digital safety literacy and fraud reporting mechanism among …


Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu Apr 2025

Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu

Cybersecurity Undergraduate Research Showcase

Financial fraud, particularly credit card fraud, continues to pose substantial challenges to financial institutions due to its increasing frequency and impact on consumer trust. While traditional rule-based methods have provided foundational defenses, their limitations in scalability and adaptability have accelerated the adoption of machine learning (ML) techniques. Concurrently, Benford’s Law—a statistical principle often used in forensic accounting—has demonstrated efficacy in detecting anomalies within naturally occurring numerical datasets. This study explores a hybrid fraud detection approach that integrates Benford’s Law with supervised machine learning algorithms, including Logistic Regression, Random Forest, and k-Nearest Neighbors. Using the publicly available European credit card fraud …


Phishing Attacks And Prevention, Ruth Johnson Apr 2025

Phishing Attacks And Prevention, Ruth Johnson

Cybersecurity Undergraduate Research Showcase

Phishing attacks have been the number one leading cause of identity theft and financial theft since 1990. The internet is one of the leading places where individuals’ identity is stolen. Many businesses and government agencies have been at risk of cyber phishing attacks from foreign countries. Attacks on Several U.S. federal government agencies have been hit in a global cyberattack by Russian cybercriminals that exploit a vulnerability in widely used software, according to a top us cybersecurity agency (Lyngaas, Government hit cyber-attacks, 2023).

Phishing attacks are cybercrimes where one or many individuals steal sensitive information like passwords, credit card information, …


Securing Biometric Data, Alyssa F. Carroll Apr 2025

Securing Biometric Data, Alyssa F. Carroll

Cybersecurity Undergraduate Research Showcase

Biometric data has been widely adopted across various sectors, including digital identity, artificial intelligence (AI), border control, digital wallets, and national identification systems. While biometric identifiers—such as fingerprints, retina scans, and facial recognition—offer reliable and convenient authentication, they also raise significant concerns regarding privacy and security. This paper examines how biometric data is stored, the vulnerabilities it faces, and the most effective methods for safeguarding it. By highlighting the critical importance of biometric data protection, this study reviews current research on approaches, strategies, and policies that enhance security while preserving the functionality and efficiency of biometric systems.


Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim Jan 2025

Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim

Graduate Student Government Association Research Conference

Progressive Web Applications (PWAs) are gaining popularity due to their rich features. Service Workers (SWs), one of its integral components, make this possible by providing users with offline functionality, improved performance, and effective caching techniques. SWs act as proxies positioned between the client browser and the web server, capable of intercepting requests and responses. Recent research has revealed that, despite being designed with security in mind, there are ways to circumvent these security precautions and launch various attacks.

Sensitive functions in JavaScript are functions that can introduce security vulnerabilities if not properly coded or validated. These functions can manipulate the …


A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty Jan 2025

A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

Sixth-generation (6G) wireless networks will become vulnerable due to native generative AI (GenAI)-driven intelligent poisoning attacks in both the radio unit and the core network. In particular, network parameters and metrics in cross-layer design pose fundamentally uncertain conditions and can be compromised through the native GenAI mechanism, which leverages data augmentation and reconstruction capabilities. This work investigates the capabilities of native GenAI to create novel poisoning attacks in wireless networks, while investigating their impact through uncertainty-informed root analysis. Then, detected attacks are mitigated by developing a trustworthy service aggregation in the wireless network. First, a joint decision problem is formulated …


Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi Jan 2025

Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi

School of Cybersecurity Faculty Publications

With the pervasive integration of artificial intelligence (AI) in various facets of modern technology, the importance of AI security has been thrust into the spotlight. The field is rapidly evolving, with new challenges and solutions emerging at a swift pace. However, the breadth and depth of AI security research have not been comprehensively mapped in recent times, presenting a crucial need for an extensive review and synthesis of existing literature. Given the increasing reliance on AI in critical domains such as healthcare, finance, and national security, ensuring the resilience and trustworthiness of these systems is imperative. This survey fulfills the …


Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang Jan 2025

Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang

School of Cybersecurity Faculty Publications

With the fast development and deep penetration of IoT devices and smart environments, using localized machine learning models to detect malicious activities has also been developed and deployed. However, these isolated learning models and results cannot be effectively federated together because of privacy concerns and lack of incentivization. This paper proposed several mechanisms to solve the problem. A verification method was designed for phased learning results to protect user privacy and prevent individual parties from manipulating the verification selection. The paper also presented an incentive method based on delay of distribution of the latest federated learning results. Extensive simulations were …


Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz Jan 2025

Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz

Engineering Management & Systems Engineering Faculty Publications

The growing sophistication of cyberattacks exposes small- and medium-sized businesses (SMBs) to a widening range of security risks. As these threats evolve in complexity, the need for advanced security measures becomes increasingly pressing. This necessitates a proactive approach to defending against potential cyber intrusions. Emerging technologies, such as blockchain, artificial intelligence, and Zero Trust security framework, offer crucial tools for strengthening the digital infrastructure of SMBs. The Zero Trust architecture (ZTA) holds significant promise as a critical strategy for protecting SMBs. While existing literature explores the implementation of ZTA in various business settings, discussions specifically addressing the financial, human resource, …


Secure Federated Learning Via Neural Cryptography With Homomorphic Operations, Espen Sele, Ferhat Ozgur Catak, Jungwon Seo, Murat Kuzlu Jan 2025

Secure Federated Learning Via Neural Cryptography With Homomorphic Operations, Espen Sele, Ferhat Ozgur Catak, Jungwon Seo, Murat Kuzlu

Engineering Technology Faculty Publications

This study examines neural cryptography with homomorphic operations as an alternative secure aggregation method for federated learning (FL). It proposes a novel neural cryptographic system supporting homomorphic addition on fixed-point encrypted data, and consisting of three networks, namely (1) an encryption network (Alice), (2) a homomorphic network (HO), and (3) a decryption network (Bob), along with an adversarial Eve network. Using the MNIST dataset, the proposed Neural Homomorphic Operation System (NHOS) is evaluated against a plaintext baseline and the CKKS scheme, a widely used public-key homomorphic encryption method. The results show that the proposed NHOS approach offers a satisfying performance, …


A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu Jan 2025

A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu

Engineering Management & Systems Engineering Faculty Publications

Healthcare systems face unprecedented security and privacy challenges due to increasing digitization and interconnectedness. This paper provides a comprehensive analysis of these challenges by examining various cyberattacks, defensive mechanisms, and governance frameworks within modern healthcare infrastructure. The research systematically categorizes prevalent security threats, such as ransomware, insider threats, and data breaches, identifying vulnerabilities specific to healthcare systems. Furthermore, the study evaluates current defensive strategies, including encryption techniques, access control systems, and intrusion detection tools, assessing their effectiveness against complex cyber threats. A key focus is placed on governance structures and their role in cybersecurity resilience. The research explores how regulatory …


Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu Jan 2025

Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu

Engineering Management & Systems Engineering Faculty Publications

Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.


Building Cyber Resilience: Educational Programs In K-12 Education, Mildred Jones, Vukica Jovanovic, Petros Katsioloudis Jan 2025

Building Cyber Resilience: Educational Programs In K-12 Education, Mildred Jones, Vukica Jovanovic, Petros Katsioloudis

Engineering Technology Faculty Publications

The article discusses the challenges of teaching cybersecurity in K-12 education. Topics mentioned include the lack of access to resources and appropriate professional development, the career and technical education cybersecurity pathways, the fundamental pathways for cybersecurity and information technology and the results of program evaluation in several local community high schools from 2021 and 2022.


Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen Jan 2025

Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …


Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu Jan 2025

Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu

Computer Science Faculty Publications

Private inference applies cryptographic techniques like homomorphic encryption, garble circuit and secret sharing to keep both sides privacy in a client-server setting during inference. It is often hindered by the high communication overheads, especially at non-linear activation layers such as ReLU. Hence ReLU pruning has been widely recognized as an efficient way to accelerate private inference. Existing approaches to ReLU pruning typically rely on coarse hypothesis, which assume an inverse correlation between the importance of ReLU and linear layers or shallow activation layers have less importance for universal models, to assign the budgets according to the layer while preserving the …


Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson Jan 2025

Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson

Computer Science Faculty Publications

URI redirections are integral to web management, supporting structural changes, SEO optimization, and security. However, their complexities affect usability, SEO performance, and digital preservation. This study analyzed 11 million unique redirecting URIs, following redirections up to 10 hops per URI, to uncover patterns and implications of redirection practices. Our findings revealed that 50% of the URIs terminated successfully, while 50% resulted in errors, including 0.06% exceeding 10 hops. Canonical redirects, such as HTTP to HTTPS transitions, were prevalent, reflecting adherence to SEO best practices. Non-canonical redirects, often involving domain or path changes, highlighted significant web migrations, rebranding, and security risks. …


Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff Jan 2025

Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff

Computer Science Faculty Publications

The meteoric rise of Artificial Intelligence (AI), with its rapidly expanding market capitalization, presents both transformative opportunities and critical challenges. Chief among these is the urgent need for a new, unified paradigm for trustworthy evaluation, as current benchmarks increasingly reveal critical vulnerabilities. Issues like data contamination and selective reporting by model developers fuel hype, while inadequate data quality control can lead to biased evaluations that, even if unintentionally, may favor specific approaches. As a flood of participants enters the AI space, this "Wild West" of assessment makes distinguishing genuine progress from exaggerated claims exceptionally difficult. Such ambiguity blurs scientific signals …


Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh Jan 2025

Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh

Computer Science Faculty Publications

Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …