Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2025

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 151 - 180 of 205

Full-Text Articles in Information Security

Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd Feb 2025

Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd

Journal of Cybersecurity Education, Research and Practice

This paper, based on data from our second nationwide survey of cybersecurity among local or grassroots governments in the U.S., examines how these governments manage this important function. As we have shown elsewhere, cybersecurity among local governments is increasingly important because these governments are under constant or nearly constant cyberattack. Due to the frequency of cyberattacks, as well as the probability that at least some attacks will succeed and cause damage to local government information systems, these governments have great responsibility to protect their information assets. This, in turn, requires these governments to manage cybersecurity effectively, something our data show …


Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell Feb 2025

Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell

Pharmacy and Wellness Review

Artificial Intelligence (AI) has transformed the pharmaceutical field by enabling computer software systems to learn and perform human behavior. Specifically, AI has revolutionized chronic diabetes management through continuous glucose monitoring, showcasing its immense potential in healthcare. However, alongside its transformative impact, AI’s increasing role in healthcare has prompted concerns over privacy and its premature integration. Despite these challenges, AI offers limitless opportunities to improve medication management and treatment regimens, driving advancements across various domains. From improving CT imaging to enhancing adenoma detection in colonoscopies and facilitating medication adherence, AI’s impact on healthcare is profound. Furthermore, AI plays a pivotal role …


Scrutinizer: Towards Secure Forensics On Compromised Trustzone, Yiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou, Xuhua Ding, Zhenkai Liang, Shoumeng Yan, Tao We, Zhengyu He Feb 2025

Scrutinizer: Towards Secure Forensics On Compromised Trustzone, Yiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou, Xuhua Ding, Zhenkai Liang, Shoumeng Yan, Tao We, Zhengyu He

Research Collection School Of Computing and Information Systems

The number of vulnerabilities exploited in Arm TrustZone systems has been increasing recently. The absence of digital forensics tools prevents platform owners from incident response or periodic security scans. However, the area of secure forensics for compromised TrustZone remains unexplored and presents unresolved challenges. Traditional out-of-TrustZone forensics are inherently hindered by TrustZone protection, rendering them infeasible. In-TrustZone approaches are susceptible to attacks from privileged adversaries, undermining their security. To fill these gaps, we introduce SCRUTINIZER, the first secure forensics solution for compromised TrustZone systems. SCRUTINIZER utilizes the highest privilege domain of the recent Arm Confidential Computing Architecture (CCA), called the …


Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning, Hari Hara Suthan Chittoor, Paul Robert Griffin, Ariel Neufeld, Jayne Thompson, Mile Gu Feb 2025

Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning, Hari Hara Suthan Chittoor, Paul Robert Griffin, Ariel Neufeld, Jayne Thompson, Mile Gu

Research Collection School Of Computing and Information Systems

Long-term time series forecasting (LTSF) involves predicting a large number of future values of a time series based on the past values. This is an essential task in a wide range of domains including weather forecasting, stock market analysis and disease outbreak prediction. Over the decades LTSF algorithms have transitioned from statistical models to deep learning models like transformer models. Despite the complex architecture of transformer based LTSF models ‘Are Transformers Effective for Time Series Forecasting? (Zeng et al., 2023)’ showed that simple linear models can outperform the state-of-the-art transformer based LTSF models. Recently, quantum machine learning (QML) is evolving …


Siniel: Distributed Privacy-Preserving Zksnark, Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng Feb 2025

Siniel: Distributed Privacy-Preserving Zksnark, Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Zero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive, in which a prover convinces a verifier that a given statement is true without leaking any additional information. However, existing zkSNARKs suffer from high computation overhead in the proof generation. This limits the applications of zkSNARKs, such as private payments, private smart contracts, and anonymous credentials. Private delegation has become a prominent way to accelerate proof generation. In this work, we propose Siniel, an efficient private delegation framework for zkSNARKs constructed from polynomial interactive oracle proof (PIOP) and polynomial commitment scheme (PCS). Our protocol allows a computationally limited …


Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems, Zhongming Wang, Tao Xiang, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma, Robert H. Deng Feb 2025

Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems, Zhongming Wang, Tao Xiang, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma, Robert H. Deng

Research Collection School Of Computing and Information Systems

Encrypted messaging systems obstruct content moderation, although they provide end-to-end security. As a result, misinformation proliferates in these systems, thereby exacerbating online hate and harassment. The paradigm of “Reporting-then-Tracing” shows great potential in mitigating the spread of misinformation. For instance, message traceback (CCS’19) traces all the dissemination paths of a message, while source tracing (CCS’21) traces its originator. However, message traceback lacks privacy preservation for non-influential users (e.g., users who only receive the message once), while source tracing maintains privacy but only provides limited traceability. In this paper, we initiate the study of impact tracing. Intuitively, impact tracing traces influential …


Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson Feb 2025

Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson

Research outputs 2022 to 2026

Understanding group information and collective behaviors is an ongoing area of research, encompassing natural phenomena and human dynamics. Quantifying interactions and interdependencies at the group level can be valuable for understanding complex and dynamical systems. The Border Gateway Protocol (BGP), the default inter-domain routing protocol for the Internet, operates within a large, complex, and dynamic system vulnerable to security threats. Traditional BGP anomaly detection focuses on single observables from individual Autonomous Systems (ASes), which inadequately addresses the multidimensional, multi-viewpoint nature of the Internet and interdomain routing. This paper introduces a novel approach for quantifying group AS-level information and dynamics. We …


Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim Jan 2025

Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim

Graduate Student Government Association Research Conference

Progressive Web Applications (PWAs) are gaining popularity due to their rich features. Service Workers (SWs), one of its integral components, make this possible by providing users with offline functionality, improved performance, and effective caching techniques. SWs act as proxies positioned between the client browser and the web server, capable of intercepting requests and responses. Recent research has revealed that, despite being designed with security in mind, there are ways to circumvent these security precautions and launch various attacks.

Sensitive functions in JavaScript are functions that can introduce security vulnerabilities if not properly coded or validated. These functions can manipulate the …


Exploring School Teachers' Cyber Security Awareness, Experiences, And Practices In The Digital Age, R Ravichandran, Sonam Singh, P Sasikala Jan 2025

Exploring School Teachers' Cyber Security Awareness, Experiences, And Practices In The Digital Age, R Ravichandran, Sonam Singh, P Sasikala

Journal of Cybersecurity Education, Research and Practice

This study investigates the awareness and practices of cyber security among school teachers, exploring their understanding of cyber threats, online behaviours, and response mechanisms to cyber incidents. A structured questionnaire was administered to gather data on demographic information, cyber security training, online practices, and experiences with cybercrime. The findings reveal varying levels of awareness among teachers, with many reporting limited knowledge of prevalent cyber threats such as phishing and identity theft. Despite the increasing reliance on digital tools for teaching, a significant number of respondents indicated a lack of formal training in cyber security. The study highlights the necessity for …


"It's Definitely New And Different...It's Really Engaging": Understanding The Power Of Storytelling Towards Secure Password Creation, Rizu Paudel, Mahdi Nasrullah Al-Ameen Jan 2025

"It's Definitely New And Different...It's Really Engaging": Understanding The Power Of Storytelling Towards Secure Password Creation, Rizu Paudel, Mahdi Nasrullah Al-Ameen

Computer Science Student Research

There is a dearth in existing literature to attain systematic understanding of leveraging digital storytelling in security designs. As we begin to address this gap, we focused on user authentication where the existing password composition policies and password meters often fail to help users around creating a strong and memorable password. To this end, we conducted a lab study with 19 participants, where we updated our initial designs in an iterative manner based on their feedback. We then conducted a between-subject online study with 104 participants over Amazon Mechanical Turk to evaluate our designs. We found that all of our …


Computing In The Commonwealth: Specialized Education In Computer Science And Information Technology For High School Students In Virginia – An Environmental Scan, Amy Corning, Jonathan D. Becker, Jon Graham, James Carrigan, Keisha Tennessee Jan 2025

Computing In The Commonwealth: Specialized Education In Computer Science And Information Technology For High School Students In Virginia – An Environmental Scan, Amy Corning, Jonathan D. Becker, Jon Graham, James Carrigan, Keisha Tennessee

ICRE Publications

Over the past two decades, Virginia has invested substantially in STEM education, in part through specialized programs focused on computer science and information technology (CS/IT). This study represents the first effort to identify Virginia’s specialized secondary CS/IT programs and examine them collectively. Findings from the statewide environmental scan indicate that the programs are delivered through a wide variety of institutional structures, including Governor’s STEM Academies, Governor’s Schools, specialty centers, and academies, but most often through Career and Technical Education (CTE) centers. Programs tend to be concentrated in metropolitan areas, and some rural divisions may not be served. The programs provide …


A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings Jan 2025

A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings

Research & Publications

This study investigates the prevalence and underlying causes of work-related stress and burnout among cybersecurity professionals using a quantitative survey approach guided by the Job Demands-Resources model. Analysis of responses from 50 cybersecurity practitioners reveals an alarming reality: 44% report experiencing severe work-related stress and burnout, while an additional 28% are uncertain about their condition. The demanding nature of cybersecurity roles, unrealistic expectations, and unsupportive organizational cultures emerge as primary factors fueling this crisis. Notably, 66% of respondents perceive cybersecurity jobs as more stressful than other IT positions, with 84% facing additional challenges due to the pandemic and recent high-profile …


Technology-Facilitated Abuse (Tfa): Analyzing Trends, Tactics, And Victim Responses On Reddit, Solomon G. Dandekar Jan 2025

Technology-Facilitated Abuse (Tfa): Analyzing Trends, Tactics, And Victim Responses On Reddit, Solomon G. Dandekar

Computer Science and Engineering Theses - Archive

The increasing integration of technology into daily life has provided numerous benefits but also significant risks, particularly when exploited by malicious actors in cases of technology facilitated abuse (TFA). Per- petrators can misuse technology to monitor, control, and intimidate their partners, random strangers, etc. exacerbating cycles of abuse. From location tracking and cellphone surveillance to smart device manipula- tion, spyware, and doxing, digital tools have become powerful instruments for coercion and control. This research project investigates the role of technology in stalking and harassment by analyzing discussions on a relevant subreddit where victims share their experiences, strategies for coping, and …


Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy Jan 2025

Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy

Computer Science and Engineering Dissertations - Archive

Phishing scams are among the most dangerous and persistent forms of cybercrime, leveraging social engineering to exploit human behavior and obtain sensitive information, leading to widespread identity theft and data breaches. In the past year, these attacks have resulted in financial losses exceeding $10 billion in the United States alone. As phishing scams continue to evolve, they have not only expanded in scale but also grown in sophistication, spreading rapidly across social media and employing adversarial techniques to evade detection by anti-scam tools. The situation is further exacerbated by the availability of advanced phishing kits, and more recently, generative AI, …


Towards Smart Farming: Image-Based Crop Health Assessment And Disease Diagnosis Using Deep Learning Techniques, Kristina Botova Jan 2025

Towards Smart Farming: Image-Based Crop Health Assessment And Disease Diagnosis Using Deep Learning Techniques, Kristina Botova

Master's Theses or Doctor of Nursing Practice

Accurate crop monitoring is essential for optimizing agricultural productivity and ensuring food security. This study presents a comprehensive deep learning framework for image crop type recognition, health status prediction, and disease detection using multiple Convolutional Neural Network (CNN) models. The proposed approach uses open-source datasets consisting of five crop types (apple, corn, grape, potato, tomato), varying health conditions, and common diseases. By deploying specialized CNN architecture focused on each task, the system achieves a high accuracy of 99.25% in classifying crop types, identifying health status, and detecting specific diseases. Compared to a single CNN model, the use of the proposed …


The Gradient Puppeteer: Adversarial Domination In Gradient Leakage Attacks Through Model Poisoning, Kunlan Xiang, Haomiao Yang, Meng Hao, Shaofeng Li, Haoxin Wang, Zikang Ding, Wenbo Jiang, Tianwei Zhang Jan 2025

The Gradient Puppeteer: Adversarial Domination In Gradient Leakage Attacks Through Model Poisoning, Kunlan Xiang, Haomiao Yang, Meng Hao, Shaofeng Li, Haoxin Wang, Zikang Ding, Wenbo Jiang, Tianwei Zhang

Research Collection School Of Computing and Information Systems

In Federated Learning (FL), clients share gradients with a central server while keeping their data local. However, malicious servers could deliberately manipulate the models to reconstruct clients' data from shared gradients, posing significant privacy risks. Although such Active Gradient Leakage Attacks (AGLAs) have been widely studied, they suffer from two severe limitations: 1) coverage: no existing AGLAs can reconstruct all samples in a batch from the shared gradients; 2) stealthiness: no existing AGLAs can evade principled checks of clients. In this paper, we address these limitations with two core contributions. First, we introduce a new theoretical analysis approach, which uniformly …


Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu Jan 2025

Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu

Research & Publications

Ransomware and other malware inflict devastating financial and operational damage on organizations worldwide by exploiting deeply embedded, hard-to-detect vulnerabilities in their systems. Detecting these vulnerabilities in compiled code before malicious actors exploit them remains a critical challenge in cybersecurity. This research introduces TEDVIL (Transformer-based Embeddings for Discovering Vulnerabilities in Lifted Code), a novel framework which uses transformer-based embeddings to train neural networks to detect vulnerabilities in lifted code. The framework was implemented using bidirectional (BERT and RoBERTa) and unidirectional (GPT-1 and GPT-2) transformer-based models to generate embeddings for training Long Short-Term Memory (LSTM) neural networks to detect stack-based buffer overflows …


Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu Jan 2025

Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu

Journal of Cybersecurity Education, Research and Practice

The profound impact of the Internet of Things (IoT) on various fronts, is driven by technological advancements, the ubiquitous spread of information, and the emergence of transformative events. IoT presents a diverse array of possibilities within university environments, fostering a more connected and enhanced educational experience. This research undertakes a comprehensive review of existing literature to provide context to the IoT and underscore its crucial significance in the realm of smart campuses. Additionally, the paper explores the intricate connections between IoT and key concepts such as cybersecurity and wireless sensor networks to present a holistic perspective. It delves into the …


Signal-Based Error Handling: Case Study Using The Bathymetric Attributed Grid Library, Anthony R. Papetti Jan 2025

Signal-Based Error Handling: Case Study Using The Bathymetric Attributed Grid Library, Anthony R. Papetti

Honors Theses and Capstones

No abstract provided.


A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty Jan 2025

A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

Sixth-generation (6G) wireless networks will become vulnerable due to native generative AI (GenAI)-driven intelligent poisoning attacks in both the radio unit and the core network. In particular, network parameters and metrics in cross-layer design pose fundamentally uncertain conditions and can be compromised through the native GenAI mechanism, which leverages data augmentation and reconstruction capabilities. This work investigates the capabilities of native GenAI to create novel poisoning attacks in wireless networks, while investigating their impact through uncertainty-informed root analysis. Then, detected attacks are mitigated by developing a trustworthy service aggregation in the wireless network. First, a joint decision problem is formulated …


A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings Jan 2025

A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings

Research & Publications

In response to the rising frequency and complexity of data breaches and evolving global privacy regulations, this study presents a comprehensive examination of academic literature on the classification of privacy breaches and violations between 2010-2024. Through a systematic literature review, a corpus of screened studies was assembled and analyzed to identify primary research themes, emerging trends, and gaps in the field. A novel taxonomy is introduced to guide efforts by categorizing research efforts into seven domains: breach classification, report classification, breach detection, threat detection, breach prediction, risk analysis, and threat classification. An analysis reveals that breach classification and detection dominate …


Dynamic Analysis Of Malware Detection Using Customized Payloads: Examining The Effectiveness Of Manual And Automated Approaches In Web Applications, Jiban Krisna Das Jan 2025

Dynamic Analysis Of Malware Detection Using Customized Payloads: Examining The Effectiveness Of Manual And Automated Approaches In Web Applications, Jiban Krisna Das

College of Graduate Studies: Theses & Dissertations

Web applications are becoming the prime targets for cyber-attacks, where SQL injection (SQLi) and Cross Site Scripting (XSS) are the most exploited vulnerabilities. The study explores a novel approach using customized payloads to examine the effectiveness of manual and automated techniques of malware detection. This dynamic approach can effectively generate attack payloads and identify the vulnerabilities in a website thereby strengthening website security measures. This research focuses on dynamic analysis in a controlled environment while testing and analyzing SQL and XSS payloads under varying security conditions. This quantitative analysis involves crafting targeted payloads to bypass Web Application Firewall (WAF) filters …


Digital Evidence In Cybersecurity: Legal Constraints And Technical Hurdles, Steffany Butler Jan 2025

Digital Evidence In Cybersecurity: Legal Constraints And Technical Hurdles, Steffany Butler

Master's Theses and Doctoral Dissertations

The increasing use of digital technologies such as Internet of Things devices, cloud computing, and networked information systems has made digital evidence essential to modern cybersecurity investigations. Digital evidence supports the reconstruction of cyber incidents, identification of responsible parties, and legal proceedings. However, its collection and preservation pose substantial technical and legal challenges. Rapid technological change, strong encryption, data volatility, cloud-based and distributed storage, and variations in jurisdictional privacy and evidentiary laws complicate the timely, reliable, and legally admissible acquisition of digital evidence. This study addresses how investigators can effectively collect and preserve digital evidence while maintaining data integrity, legal …


Digital Forensics & Artificial Intelligence: Senior Honors Project Research Report, Noah Shelton Kasir Jan 2025

Digital Forensics & Artificial Intelligence: Senior Honors Project Research Report, Noah Shelton Kasir

Senior Honors Theses and Projects

This project studied how current artificial intelligence large language models could be used to learn digital forensics and anti-forensics techniques compared to traditional search engines such as Google Search. This project aimed to answer the question “Can an ordinary person use AI to learn both anti-forensics and traditional digital forensics skills effectively and efficiently?”. The project research was divided into two distinct phases. Phase one consisted of the creation of a fictional case by acting as a layperson using the help of the Microsoft Copilot AI tool. This case consisted of a layperson “suspect” attempting to learn multiple anti-forensics techniques …


Charge Your Clients: Payable Secure Computation And Its Applications, Cong Zhang, Liqiang Peng, Weiran Liu, Shuaishuai Li, Meng Hao, Lei Zhang, Dongdai Lin Jan 2025

Charge Your Clients: Payable Secure Computation And Its Applications, Cong Zhang, Liqiang Peng, Weiran Liu, Shuaishuai Li, Meng Hao, Lei Zhang, Dongdai Lin

Research Collection School Of Computing and Information Systems

The online realm has witnessed a surge in the buying and selling of data, prompting the emergence of dedicated data marketplaces. These platforms cater to servers (sellers), enabling them to set prices for access to their data, and clients (buyers), who can subsequently purchase these data, thereby streamlining and facilitating such transactions. However, the current data market is primarily confronted with the following issues. Firstly, they fail to protect client privacy, presupposing that clients submit their queries in plaintext. Secondly, these models are susceptible to being impacted by malicious client behavior, for example, enabling clients to potentially engage in arbitrage …


Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi Jan 2025

Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi

School of Cybersecurity Faculty Publications

With the pervasive integration of artificial intelligence (AI) in various facets of modern technology, the importance of AI security has been thrust into the spotlight. The field is rapidly evolving, with new challenges and solutions emerging at a swift pace. However, the breadth and depth of AI security research have not been comprehensively mapped in recent times, presenting a crucial need for an extensive review and synthesis of existing literature. Given the increasing reliance on AI in critical domains such as healthcare, finance, and national security, ensuring the resilience and trustworthiness of these systems is imperative. This survey fulfills the …


Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang Jan 2025

Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang

School of Cybersecurity Faculty Publications

With the fast development and deep penetration of IoT devices and smart environments, using localized machine learning models to detect malicious activities has also been developed and deployed. However, these isolated learning models and results cannot be effectively federated together because of privacy concerns and lack of incentivization. This paper proposed several mechanisms to solve the problem. A verification method was designed for phased learning results to protect user privacy and prevent individual parties from manipulating the verification selection. The paper also presented an incentive method based on delay of distribution of the latest federated learning results. Extensive simulations were …


Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz Jan 2025

Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz

Engineering Management & Systems Engineering Faculty Publications

The growing sophistication of cyberattacks exposes small- and medium-sized businesses (SMBs) to a widening range of security risks. As these threats evolve in complexity, the need for advanced security measures becomes increasingly pressing. This necessitates a proactive approach to defending against potential cyber intrusions. Emerging technologies, such as blockchain, artificial intelligence, and Zero Trust security framework, offer crucial tools for strengthening the digital infrastructure of SMBs. The Zero Trust architecture (ZTA) holds significant promise as a critical strategy for protecting SMBs. While existing literature explores the implementation of ZTA in various business settings, discussions specifically addressing the financial, human resource, …


Secure Federated Learning Via Neural Cryptography With Homomorphic Operations, Espen Sele, Ferhat Ozgur Catak, Jungwon Seo, Murat Kuzlu Jan 2025

Secure Federated Learning Via Neural Cryptography With Homomorphic Operations, Espen Sele, Ferhat Ozgur Catak, Jungwon Seo, Murat Kuzlu

Engineering Technology Faculty Publications

This study examines neural cryptography with homomorphic operations as an alternative secure aggregation method for federated learning (FL). It proposes a novel neural cryptographic system supporting homomorphic addition on fixed-point encrypted data, and consisting of three networks, namely (1) an encryption network (Alice), (2) a homomorphic network (HO), and (3) a decryption network (Bob), along with an adversarial Eve network. Using the MNIST dataset, the proposed Neural Homomorphic Operation System (NHOS) is evaluated against a plaintext baseline and the CKKS scheme, a widely used public-key homomorphic encryption method. The results show that the proposed NHOS approach offers a satisfying performance, …


Silent Sabotage: Identifying And Preventing Cyber Attacks From Inside Actors, Autumn Groen Jan 2025

Silent Sabotage: Identifying And Preventing Cyber Attacks From Inside Actors, Autumn Groen

Williams Honors College, Honors Research Projects

Cyber-attacks are becoming increasingly common and damaging as technology advances each year. Many businesses cannot afford the latest security technologies, and even with the highest security measures, there can still be room for employee error or insider threats that are not taken into account. It is crucial to keep these factors in mind when securing a business network of any size or financial standing.This project will aim to simulate a business environment by first building a small network with three routers and a switch, and implementing some of the common best practices for network hardening from credible organizations like NIST …