Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Articles 1 - 30 of 84

Full-Text Articles in Information Security

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke Dec 2026

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke

Research outputs 2022 to 2026

Industry 5.0’s increasing integration of IT and OT systems is transforming industrial operations but also expanding the cyber–physical attack surface. Industrial Control Systems (ICS) face escalating security challenges as traditional siloed defenses fail to provide coherent, cross-domain threat insights. We present BRIDG-ICS (BRIDge for Industrial Control Systems), an AI-enriched Knowledge Graph (KG) framework for context-aware threat analysis and quantitative assessment of cyber resilience in smart manufacturing environments. BRIDG-ICS fuses heterogeneous industrial and cybersecurity data into an integrated Industrial Security Knowledge Graph linking assets, vulnerabilities, and adversarial behaviors with probabilistic risk metrics (e.g., exploit likelihood, attack cost). This unified graph representation …


From 5g To 6g: A Survey On Security, Privacy, And Standardization Pathways, Mengmeng Yang, Youyang Qu, Thilina Ranbaduge, Chandra Thapa, Nazatul Haque Sultan, Ming Ding, Hajime Suzuki, Wei Ni, Sharif Abuadbba, David Smith, Paul Tyler, Josef Pieprzyk, Thierry Rakotoarivelo, Xinlong Guan, Sirine Mrabet Jun 2026

From 5g To 6g: A Survey On Security, Privacy, And Standardization Pathways, Mengmeng Yang, Youyang Qu, Thilina Ranbaduge, Chandra Thapa, Nazatul Haque Sultan, Ming Ding, Hajime Suzuki, Wei Ni, Sharif Abuadbba, David Smith, Paul Tyler, Josef Pieprzyk, Thierry Rakotoarivelo, Xinlong Guan, Sirine Mrabet

Research outputs 2022 to 2026

The vision for 6G aims to enhance network capabilities, supporting an intelligent digital ecosystem where artificial intelligence (AI) is a key. However, the expansion of 6G raises critical security and privacy concerns due to the increased integration of IoT devices, edge computing, and AI. This survey provides a comprehensive overview of 6G protocols with a focus on security and privacy, identifying risks that have not been experienced in preceding 5G systems, and presenting mitigation strategies. While many vulnerabilities from earlier generations persist, the introduction of AI/ML introduces novel risks like model inversion and malicious manipulation of AI. Vulnerabilities in emerging …


A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott May 2026

A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott

Research outputs 2022 to 2026

Intrusion detection systems (IDS) monitor and detect malicious activity and unauthorized access that may compromise systems. Traditional IDS approaches send data to a central server for analysis, raising privacy concerns as data owners lose control over security. Federated Learning (FL) offers a privacy-preserving alternative by allowing local devices to process their data and generate models without sharing raw data. These local models are aggregated centrally to form a comprehensive model with performance comparable to centralized systems. This paper reviews FL-based IDS research, and is the first review paper to focus on privacy-preserving techniques collectively known as privacy-preserving Federated Learning (PPFL) …


From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms, Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke Apr 2026

From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms, Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke

Research outputs 2022 to 2026

Cybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors' knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board …


Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni Apr 2026

Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni

Research outputs 2022 to 2026

Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes …


Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker Mar 2026

Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

As networks expand in size and complexity, coupled with an exponential increase in intrusions on network and IoT systems, this leads to traditional models failing to capture increasingly intricate correlations among network components accurately. Graph Convolution Networks (GCNs) have recently acquired prominence for their capacity to represent nodes, edges, or entire graphs by aggregating information from adjacent nodes. However, the correlations between nodes and their neighbours, as well as related edges, differ. Assigning higher weights to nodes and edges with high similarity improves model accuracy and expressiveness. In this paper, we propose the GCN-DQN model, which integrates GCN with a …


An Explainable Transformer-Based Model For Phishing Email Detection: A Large Language Model Approach, Mohammad Amaz Uddin, Md Mahiuddin, Iqbal H. Sarker Mar 2026

An Explainable Transformer-Based Model For Phishing Email Detection: A Large Language Model Approach, Mohammad Amaz Uddin, Md Mahiuddin, Iqbal H. Sarker

Research outputs 2022 to 2026

Phishing email is a serious cyber threat that tries to deceive users by sending false emails with the intention of stealing confidential information or causing financial harm. Attackers, often posing as trustworthy entities, exploit technological advancements and sophistication to make the detection and prevention of phishing more challenging. Despite extensive academic research, phishing detection remains an ongoing and formidable challenge in the cybersecurity landscape. In this research paper, we present a fine-tuned transformer-based masked language model, RoBERTa (Robustly Optimized BERT Pretraining Approach), for phishing email detection. In the detection process, we employ a phishing email dataset and apply the preprocessing …


Explainable Artificial Intelligence Models For Detecting Suspicious Bank Transactions, Narasimha Kumar Narasapuram, Syed Afaq Ali Shah, Mohd Fairuz Shiratuddin, Ferdous Sohel Mar 2026

Explainable Artificial Intelligence Models For Detecting Suspicious Bank Transactions, Narasimha Kumar Narasapuram, Syed Afaq Ali Shah, Mohd Fairuz Shiratuddin, Ferdous Sohel

Research outputs 2022 to 2026

Detecting financial crime is a complex challenge due to evolving criminal strategies and fragmented detection systems, particularly in the areas of money laundering and fraud. While it is easy to implement, traditional rule-based approaches lack adaptability to new threats, and machine learning models, though more effective, often function as opaque "black boxes," limiting their practical use in regulated domains like banking, where interpretability and accountability are essential. This research presents a novel framework that combines intrinsic and post-hoc XAI techniques to detect suspicious bank transactions. Intrinsic methods provide model-inherent transparency, while post-hoc methods offer behavior-level explanations, enabling robust cross-verification of …


Empowering Neurodiverse Talent In Cybersecurity Through Fair And Inclusive Ai Education, Sheikh Rabiul Islam, Yansi Keim, Mohiuddin Ahmed, Maanak Gupta, Ingrid Russell, Mahmoud Abdelsalam Feb 2026

Empowering Neurodiverse Talent In Cybersecurity Through Fair And Inclusive Ai Education, Sheikh Rabiul Islam, Yansi Keim, Mohiuddin Ahmed, Maanak Gupta, Ingrid Russell, Mahmoud Abdelsalam

Research outputs 2022 to 2026

Cybersecurity demands creativity, persistence, and sharp pattern recognition—strengths frequently reported among neurodivergent people (e.g., autism, ADHD, dyslexia). Yet AI-driven hiring pipelines can systematically disadvantage neurodivergent applicants by misreading communication styles or valuing narrow proxies of “fit.” Demand for cybersecurity talent is growing, and experts note that neurodiverse individuals are both underrepresented and highly valuable to security teams. However, progress remains uneven without targeted educational interventions [1]. We present a curricular module that simultaneously (a) centers neurodiversity as a strength in the cybersecurity workforce and (b) trains students to audit and redesign AI hiring systems using open-source fairness and explainability toolkits …


Efficient Privacy-Preserving Conjunctive Searchable Encryption For Cloud-Iot Healthcare Systems, Jiadi Ma, Tianqi Peng, Gong Bei, Muhammad Waqas, Hisham Alasmary, Sheng Chen Feb 2026

Efficient Privacy-Preserving Conjunctive Searchable Encryption For Cloud-Iot Healthcare Systems, Jiadi Ma, Tianqi Peng, Gong Bei, Muhammad Waqas, Hisham Alasmary, Sheng Chen

Research outputs 2022 to 2026

In cloud-Internet of Things (IoT) healthcare systems, private medical data leakage is a serious concern as the cloud server is not fully trusted. Dynamic searchable symmetric encryption (DSSE), with necessary forward and backward privacy security properties, enables doctors to retrieve ciphertexts while guaranteeing data privacy. However, existing forward and backward private DSSE schemes are not well-suited for cloud-IoT healthcare systems with attribute-value type databases. To this end, we propose an efficient privacy-preserving conjunctive searchable encryption scheme for cloud-IoT healthcare systems, called PC-SE. It is the first conjunctive DSSE scheme designed for attribute-value type databases. Specifically, we design flexible search capabilities …


Mitigating Malware Prevalence In Networks With Arbitrary Topologies: A Flip-It Cyber Game Approach Integrated With Epidemic Modeling, Mousa Tayseer Jafar, Lu Xing Yang, Gang Li, Robin Doss, Kon Mouzakis, Rajesh Vasa, Helge Janicke, Ahmed Ibrahim, Ahmed Mohsin, Iqbal H. Sarker, Kristen Moore, Seyit Camtepe, Diksha Goel Feb 2026

Mitigating Malware Prevalence In Networks With Arbitrary Topologies: A Flip-It Cyber Game Approach Integrated With Epidemic Modeling, Mousa Tayseer Jafar, Lu Xing Yang, Gang Li, Robin Doss, Kon Mouzakis, Rajesh Vasa, Helge Janicke, Ahmed Ibrahim, Ahmed Mohsin, Iqbal H. Sarker, Kristen Moore, Seyit Camtepe, Diksha Goel

Research outputs 2022 to 2026

Cyber threats have evolved in complexity, aiming at a wide range of sectors using advanced methods and tools. This evolving threat landscape challenges existing cybersecurity frameworks, many of which lack the adaptability to counteract the complex tactics of sophisticated adversaries. Developing robust cyber defense strategies requires simulating dynamic interactions between attackers and defenders across high, moderate, and low-impact scenarios. The Flip-It cyber game serves as an intelligent framework for simulating these interactions, enabling the analysis of adaptive strategies in cybersecurity. This paper aims to address the problem of mitigating malware prevalence with full consideration of attack/defense capabilities in arbitrary network …


Enhancing Healthcare Security: Manifold-Aware Machine Learning For Robust Adversarial Attack Detection In Iomt Networks, Mohmmad Al-Fawa’Reh, Mohammed Kaosar Jan 2026

Enhancing Healthcare Security: Manifold-Aware Machine Learning For Robust Adversarial Attack Detection In Iomt Networks, Mohmmad Al-Fawa’Reh, Mohammed Kaosar

Research outputs 2022 to 2026

The widespread adoption of Internet of Medical Things (IoMT) devices and the increasing movement towards telehealth have revolutionized healthcare delivery but also introduced significant security challenges. Tiny Machine Learning (TinyML) models deployed on resource-constrained medical devices are vulnerable to adversarial attacks that can compromise patient data and device functionality, posing risks to patient safety. To address these critical security concerns, this paper proposes MARD (Manifold-Aware Robust Defense), a defense mechanism designed to enhance the robustness of TinyML models. MARD trains a compact student model by transferring knowledge from a teacher model that incorporates Graph-based Manifold Regularization (GMR) and Manifold Mixup …


Attacks And Detections In Recommender Systems: A Comprehensive Analysis For Models, Progresses, And Trends, Yan Feng, Zhihai Yang, Kexin Li, Jianxin Li, Pinghui Wang, Zhiquan Liu Jan 2026

Attacks And Detections In Recommender Systems: A Comprehensive Analysis For Models, Progresses, And Trends, Yan Feng, Zhihai Yang, Kexin Li, Jianxin Li, Pinghui Wang, Zhiquan Liu

Research outputs 2022 to 2026

Recommender systems (RSs), as crucial components of online services, can help users efficiently obtain information they may like. In reality, RSs face long-term threats. Attackers manipulate recommendation results by injecting malicious data in order to obtain benefits. At present, research on the security of RSs lacks a comprehensive understanding of attack capabilities. Moreover, existing defense strategies have not yet been systematically associated with attack characteristics. More importantly, existing defense methods rarely focus on real unlabeled data in practical application scenarios for anomaly detection and forensics. Therefore, this survey systematically analyzes the security of RSs and provides new insights. Specifically, we …


Zero Day Malware Detection With Alpha: Fast Dbi With Transformer Models For Real World Application, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke Dec 2025

Zero Day Malware Detection With Alpha: Fast Dbi With Transformer Models For Real World Application, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke

Research outputs 2022 to 2026

The effectiveness of an AI model in accurately classifying novel malware hinges on the quality of the features it is trained on, which in turn depends on the effectiveness of the analysis tool used. Peekaboo, a Dynamic Binary Instrumentation (DBI) tool, defeats malware evasion techniques to capture authentic behavior at the Assembly (ASM) instruction level. This behavior exhibits patterns consistent with Zipf's law, a distribution commonly seen in natural languages, making Transformer models particularly effective for binary classification tasks. We introduce Alpha, a framework for zero-day malware detection that leverages Transformer models, Support Vector Machines (SVMs) and ASM language features. …


Defeating Evasive Malware With Peekaboo: Extracting Authentic Malware Behavior With Dynamic Binary Instrumentation, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke Dec 2025

Defeating Evasive Malware With Peekaboo: Extracting Authentic Malware Behavior With Dynamic Binary Instrumentation, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke

Research outputs 2022 to 2026

The accuracy of Artificial Intelligence (AI) in malware detection is dependent on the features it is trained with, where the quality and authenticity of these features is dependent on the dataset and the analysis tool. Evasive malware, that alters its behavior in analysis environments, is challenging to extract authentic features from where widely used static and dynamic analysis tools have several limitations. However, Dynamic Binary Instrumentation (DBI) allows deep and precise control of the malware sample, thereby facilitating the extraction of authentic behavior from evasive malware. Considering the limitations of malware analysis for use with AI, this research had two …


Cnn Based Deep Learning Modeling With Explainability Analysis For Detecting Fraudulent Blockchain Transactions, Mohammad Hasan, Mohammad Shahriar Rahman, Mohammad Jabed Morshed Chowdhury, Iqbal H. Sarker Dec 2025

Cnn Based Deep Learning Modeling With Explainability Analysis For Detecting Fraudulent Blockchain Transactions, Mohammad Hasan, Mohammad Shahriar Rahman, Mohammad Jabed Morshed Chowdhury, Iqbal H. Sarker

Research outputs 2022 to 2026

In the era of growing cryptocurrency adoption, Blockchain has emerged as a leading player in the digital payment landscape. However, this widespread popularity also brings forth various security challenges, including the need to safeguard against fraudulent activities. One of the paramount challenges in this regard is the detection of fraudulent transactions within the realm of Bitcoin data. This task significantly influences the trust and security of digital payments. Yet, it's a formidable challenge given the relatively low occurrence of fraudulent Bitcoin transactions. While deep learning techniques have demonstrated their prowess in fraud detection, there remains a scarcity of studies exploring …


Cross-Model Watermarking Via Discriminative Samples For Secure Authentication, Juan Zhao, Yudao Sun, Zhihai Yang, Cai Xu, Hongji Chen, Fan Zhang, Jianxin Li Oct 2025

Cross-Model Watermarking Via Discriminative Samples For Secure Authentication, Juan Zhao, Yudao Sun, Zhihai Yang, Cai Xu, Hongji Chen, Fan Zhang, Jianxin Li

Research outputs 2022 to 2026

Deep neural networks on cloud platforms face growing security threats, with AI services increasingly relying on heterogeneous models for the same task to meet diverse user needs. Existing methods fail to distinguish benign modifications from malicious attacks in cross-model scenarios. To address this challenge, we propose a non-intrusive cross-model watermarking method that generates discriminative samples as universal keys, enabling authentication without altering model parameters or architectures. Specifically, we introduce a margin enhancement loss to amplify confidence gaps between benign and malicious behaviors, ensuring high transferability across models. Both theoretical analysis and experimental results demonstrate the high efficacy of our proposed …


Detecting Misuse Of Security Apis: A Systematic Review, Zahra Mousavi, Chadni Islam, Muhammad Ali Babar, Alsharif Abuadbba, Kristen Moore Jul 2025

Detecting Misuse Of Security Apis: A Systematic Review, Zahra Mousavi, Chadni Islam, Muhammad Ali Babar, Alsharif Abuadbba, Kristen Moore

Research outputs 2022 to 2026

Security Application Programming Interfaces (APIs) are crucial for ensuring software security. However, their misuse introduces vulnerabilities, potentially leading to severe data breaches and substantial financial loss. Complex API design, inadequate documentation, and insufficient security training often lead to unintentional misuse by developers. The software security community has devised and evaluated several approaches to detecting security API misuse to help developers and organizations. This study rigorously reviews the literature on detecting misuse of security APIs to gain a comprehensive understanding of this critical domain. Our goal is to identify and analyze security API misuses, the detection approaches developed, and the evaluation …


Real-World Continuous Smartwatch-Based User Authentication, N. Al-Naffakh, N. Clarke, F. Li, P. Haskell-Dowland Jul 2025

Real-World Continuous Smartwatch-Based User Authentication, N. Al-Naffakh, N. Clarke, F. Li, P. Haskell-Dowland

Research outputs 2022 to 2026

User authentication is often regarded as the "gatekeeper"of cyber security. It has, however, long suffered from significant usability issues that have resulted in research focussing upon frictionless and transparent biometric approaches. Activity-based user authentication - a technique that authenticates a user by what they are physically doing at a specific point in time has attracted significant attention, particularly due to the increasing popularity of smartwatches. This research aims to overcome limitations in prior work by exploring the viability of the approach in real-world conditions. The study presents two principal experiments, one focused upon a constrained environment to provide a control …


Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed May 2025

Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed

Research outputs 2022 to 2026

Content hiding, or vault applications (apps), are designed with a secondary, often concealed purpose, such as encrypting and storing files. While these apps may serve legitimate functions, they unequivocally present significant challenges for law enforcement. Conventional methods for tackling this issue, whether static or dynamic, prove inadequate when devices—typically smartphones—cannot be modified. Additionally, these methods frequently require prior knowledge of which apps are classified as vault apps. This research decisively demonstrates that a non-invasive method of app analysis, combined with machine learning, can effectively identify vault apps. Our findings reveal that it is entirely possible to detect an Android vault …


Infusing Aboriginal Perspectives In Cyber Education, John Shannahan, Mohiuddin Ahmed Apr 2025

Infusing Aboriginal Perspectives In Cyber Education, John Shannahan, Mohiuddin Ahmed

Research outputs 2022 to 2026

While human factors are important in cyber security, the discipline has largely not explored incorporating indigenous perspectives—or, more specifically, in an Australian context, Aboriginal perspectives—in its curricula. In this paper, we introduce a promising approach for aligning Aboriginal perspectives with the needs of cyber security graduates and incorporating diverse perspectives into cyber degrees. The approach advocates for the centrality of good curriculum design fundamentals: backward design, constructive alignment, and student outcomes. The paper ends by reflecting on challenges and lessons from the first implementation and review of the material. It provides recommendations for other cyber practitioners exploring ways of incorporating …


Systemization Of Knowledge (Sok): Goals, Coverage, And Evaluation In Cybersecurity And Privacy Games, Yue Huang, Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das, Jing Wei, Helge Janicke Apr 2025

Systemization Of Knowledge (Sok): Goals, Coverage, And Evaluation In Cybersecurity And Privacy Games, Yue Huang, Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das, Jing Wei, Helge Janicke

Research outputs 2022 to 2026

This paper systematized existing knowledge on cybersecurity and privacy game-based approaches, exploring their goals, scope, and evaluation methods. Our review of 93 academic papers revealed that these approaches serve multiple purposes and target diverse player types. We identified 11 key aspects of cybersecurity and privacy that these approaches addressed, such as threats, defensive strategies, and data privacy. Additionally, we analyzed the effectiveness evaluation methods of these approaches, emphasizing the connections between evaluation techniques, types of data used, and their alignment with the approaches' goals. We also summarized the aspects of user experience evaluated in the literature and the types of …


An Efficient Conjunctive Keyword Searchable Encryption For Cloud-Based Iot Systems, Tianqi Peng, Bei Gong, Chong Guo, Akhtar Badshah, Muhammad Waqas, Hisham Alasmary, Sheng Chen Mar 2025

An Efficient Conjunctive Keyword Searchable Encryption For Cloud-Based Iot Systems, Tianqi Peng, Bei Gong, Chong Guo, Akhtar Badshah, Muhammad Waqas, Hisham Alasmary, Sheng Chen

Research outputs 2022 to 2026

Data privacy leakage has always been a critical concern in cloud-based Internet of Things (IoT) systems. Dynamic Symmetric Searchable Encryption (DSSE) with forward and backward privacy aims to address this issue by enabling updates and retrievals of ciphertext on untrusted cloud server while ensuring data privacy. However, previous research on DSSE mostly focused on single keyword search, which limits its practical application in cloud-based IoT systems. Recently, Patranabis (NDSS 2021) [1] proposed a groundbreaking DSSE scheme for conjunctive keyword search. However, this scheme fails to effectively handle deletion operations in certain circumstances, resulting in inaccurate query results. Additionally, the scheme …


Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities, Yagmur Yigit, Mohamed Amine Ferrag, Mohamed C. Ghanem, Iqbal H. Sarker, Leandros A. Maglaras, Christos Chrysoulas, Naghmeh Moradpoor, Norbert Tihanyi, Helge Janicke Mar 2025

Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities, Yagmur Yigit, Mohamed Amine Ferrag, Mohamed C. Ghanem, Iqbal H. Sarker, Leandros A. Maglaras, Christos Chrysoulas, Naghmeh Moradpoor, Norbert Tihanyi, Helge Janicke

Research outputs 2022 to 2026

Critical National Infrastructures (CNIs)—including energy grids, water systems, transportation networks, and communication frameworks—are essential to modern society yet face escalating cybersecurity threats. This review paper comprehensively analyzes AI-driven approaches for Critical Infrastructure Protection (CIP). We begin by examining the reliability of CNIs and introduce established benchmarks for evaluating Large Language Models (LLMs) within cybersecurity contexts. Next, we explore core cybersecurity issues, focusing on trust, privacy, resilience, and securability in these vital systems. Building on this foundation, we assess the role of Generative AI and LLMs in enhancing CIP and present insights on applying Agentic AI for proactive defense mechanisms. Finally, …


Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson Feb 2025

Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson

Research outputs 2022 to 2026

Understanding group information and collective behaviors is an ongoing area of research, encompassing natural phenomena and human dynamics. Quantifying interactions and interdependencies at the group level can be valuable for understanding complex and dynamical systems. The Border Gateway Protocol (BGP), the default inter-domain routing protocol for the Internet, operates within a large, complex, and dynamic system vulnerable to security threats. Traditional BGP anomaly detection focuses on single observables from individual Autonomous Systems (ASes), which inadequately addresses the multidimensional, multi-viewpoint nature of the Internet and interdomain routing. This paper introduces a novel approach for quantifying group AS-level information and dynamics. We …


Joint 3d Beamforming-And-Trajectory Design For Uav-Satellite Uplink Covert Communication, Jihong Yu, Yuting Cai, Shihao Yan, Yun Li, Jingjing Wang, Jiahao Liu, Jianping An Jan 2025

Joint 3d Beamforming-And-Trajectory Design For Uav-Satellite Uplink Covert Communication, Jihong Yu, Yuting Cai, Shihao Yan, Yun Li, Jingjing Wang, Jiahao Liu, Jianping An

Research outputs 2022 to 2026

In this paper,we study uplink covert communication in a space-air system,where an unmanned aerial vehicle (UAV) transmits sensitive data to a Geosynchronous Earth Orbit (GEO) satellite while preventing the transmission action from being discovered by a warden. We derive the optimal decision threshold of the warden. We investigate the 3-dimensional (3D) beamformer and 3D trajectory design for the transmitter UAV against this optimum warden to maximize the covert transmission rate in the presence of imperfect channel state information and uncertain noise. Due to the non-convex structure and dependence between beamforming vectors and locations of the transmitter UAV,we develop a decoupling …


Zero Day Ransomware Detection With Pulse: Function Classification With Transformer Models And Assembly Language, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke Jan 2025

Zero Day Ransomware Detection With Pulse: Function Classification With Transformer Models And Assembly Language, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke

Research outputs 2022 to 2026

Finding automated AI techniques to proactively defend against malware has become increasingly critical. The ability of an AI model to correctly classify novel malware is dependent on the quality of the features it is trained with and the authenticity of the features is dependent on the analysis tool. Peekaboo, a Dynamic Binary Instrumentation tool defeats evasive malware to capture its genuine behaviour. The ransomware Assembly instructions captured by Peekaboo, follow Zipf's law, a principle also observed in natural languages, indicating Transformer models are particularly well-suited to binary classification. We propose Pulse, a novel framework for zero day ransomware detection with …


Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas Jan 2025

Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas

Research outputs 2022 to 2026

Border Gateway Protocol (BGP), as the standard inter-domain routing protocol, is a distance-vector dynamic routing protocol used for exchanging routing information between distributed Autonomous Systems (AS). BGP nodes, communicating in a distributed dynamic environment, face several security challenges, with trust being one of the most important issues in inter-domain routing. Existing research, which performs trust evaluation when exchanging routing information to suppress malicious routing behavior, cannot meet the scalability requirements of BGP nodes. In this paper, we propose a blockchain-based trust model for inter-domain routing. Our model achieves scalability by allowing the master node of an AS alliance to transmit …


Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad Jan 2025

Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad

Research outputs 2022 to 2026

Cybersecurity plays a critical role in today’s modern human society, and leveraging knowledge graphs can enhance cybersecurity and privacy in the cyberspace. By harnessing the heterogeneous and vast amount of information on potential attacks, organizations can improve their ability to proactively detect and mitigate any threat or damage to their online valuable resources. Integrating critical cyberattack information into a knowledge graph offers a significant boost to cybersecurity, safeguarding cyberspace from malicious activities. This information can be obtained from structured and unstructured data, with a particular focus on extracting valuable insights from unstructured text through natural language processing (NLP). By storing …


Text-To-Text Generative Approach For Enhanced Complex Word Identification, Patrycja Śliwiak, Syed Afaq Ali Shah Dec 2024

Text-To-Text Generative Approach For Enhanced Complex Word Identification, Patrycja Śliwiak, Syed Afaq Ali Shah

Research outputs 2022 to 2026

This paper presents a novel approach for solving the Complex Word Identification (CWI) task using the text-to-text generative model. The CWI task involves identifying complex words in text, which is a challenging Natural Language Processing task. To our knowledge, it is a first attempt to address CWI problem into text-to-text context. In this work, we propose a new methodology that leverages the power of the Transformer model to evaluate complexity of words in binary and probabilistic settings. We also propose a novel CWI dataset, which consists of 62,200 phrases, both complex and simple. We train and fine-tune our proposed model …