Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Cybersecurity (59)
- Artificial Intelligence and Robotics (30)
- Business (26)
- Social and Behavioral Sciences (22)
- Engineering (21)
-
- Technology and Innovation (21)
- Management Information Systems (20)
- Other Computer Sciences (19)
- OS and Networks (13)
- Databases and Information Systems (12)
- Computer Engineering (10)
- Systems Architecture (10)
- Legal Studies (9)
- Data Science (8)
- Sociology (8)
- Software Engineering (8)
- Criminology (7)
- Criminology and Criminal Justice (7)
- Forensic Science and Technology (7)
- Medicine and Health Sciences (7)
- Public Affairs, Public Policy and Public Administration (7)
- Electrical and Computer Engineering (6)
- Law (6)
- Education (5)
- Theory and Algorithms (5)
- Chemical Engineering (4)
- Controls and Control Theory (4)
- Institution
-
- Singapore Management University (48)
- Kennesaw State University (25)
- Old Dominion University (24)
- Edith Cowan University (18)
- United Arab Emirates University (15)
-
- University of South Alabama (13)
- Bridgewater State University (7)
- Hunan Provincial Institute of Scientific and Technology Information (4)
- Wayne State University (4)
- Dakota State University (3)
- Indian Statistical Institute (3)
- University of Nebraska - Lincoln (3)
- California Polytechnic State University, San Luis Obispo (2)
- City University of New York (CUNY) (2)
- Dartmouth College (2)
- Eastern Michigan University (2)
- Embry-Riddle Aeronautical University (2)
- University of Texas at Arlington (2)
- Belmont University (1)
- East Tennessee State University (1)
- East Texas A&M University (1)
- Fort Hays State University (1)
- Georgia Southern University (1)
- Gonzaga University (1)
- Indiana State University (1)
- Minnesota State University Moorhead (1)
- Murray State University (1)
- Northeastern Illinois University (1)
- Ohio Northern University (1)
- Pace University (1)
- Keyword
-
- Cybersecurity (18)
- Privacy (8)
- Security (8)
- Artificial intelligence (7)
- Machine learning (5)
-
- AI (4)
- Feature extraction (4)
- Training (4)
- Accuracy (3)
- Android (3)
- Anonymous credentials (3)
- Blockchain (3)
- Cybersecurity Education (3)
- Data models (3)
- Deep learning (3)
- Dynamic binary instrumentation (3)
- Federated learning (3)
- Information security (3)
- Internet security (3)
- LLM (3)
- Large Language Models (LLMs) (3)
- Machine Learning (3)
- Machine Learning (ML) (3)
- Malware analysis (3)
- Noise (3)
- Ransomware (3)
- Reliability (3)
- Safety (3)
- Adaptation models (2)
- Adversarial Attacks (2)
- Publication
-
- Research Collection School Of Computing and Information Systems (47)
- Journal of Cybersecurity Education, Research and Practice (21)
- Research outputs 2022 to 2026 (16)
- Shelby Hall Graduate Research Forum Posters (12)
- Theses (9)
-
- Computer Science Faculty Publications (7)
- Cybersecurity Undergraduate Research Showcase (7)
- International Journal of Cybersecurity Intelligence & Cybercrime (7)
- Thesis/ Dissertation Defenses (6)
- Chemical Engineering and Materials Science Faculty Research Publications (4)
- Journal of Scientific Information Research (4)
- Dissertations and Doctoral Documents, University of Nebraska-Lincoln, 2023– (3)
- Doctoral Theses (3)
- Engineering Management & Systems Engineering Faculty Publications (3)
- Master's Theses (3)
- Research & Publications (3)
- Doctoral Dissertations and Master's Theses (2)
- Electronic Theses and Dissertations (2)
- Engineering Technology Faculty Publications (2)
- Faculty Articles (2)
- Faculty Publications (2)
- Honors College Theses (2)
- School of Cybersecurity Faculty Publications (2)
- African Conference on Information Systems and Technology (1)
- All-Inclusive List of Electronic Theses and Dissertations (1)
- Center for Secure and Intelligent Critical Systems (CSICS) Publications (1)
- College of Graduate Studies: Theses & Dissertations (1)
- Computer Science Student Research (1)
- Computer Science and Engineering Dissertations - Archive (1)
- Computer Science and Engineering Theses - Archive (1)
- Publication Type
- File Type
Articles 31 - 60 of 205
Full-Text Articles in Information Security
Disc: Decentralized Identity System With Self-Sovereign Credential Aggregation, Yang Yang, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, Hwee Hwa Pang, Robert H. Deng
Disc: Decentralized Identity System With Self-Sovereign Credential Aggregation, Yang Yang, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, Hwee Hwa Pang, Robert H. Deng
Research Collection School Of Computing and Information Systems
The evolution of decentralized identity (DID) and self-sovereign identity (SSI) frameworks, as endorsed by W3C Verifiable Credentials (VC) and eIDAS 2.0, underscores the need for secure, efficient, and privacy-preserving credential management. However, existing credential systems often depend on centralized issuers, lack efficient aggregation mechanisms, or fail to ensure unlinkability across authentication sessions. To address these challenges, we propose DISC (Decentralized Identity System with Self-Sovereign Credential Aggregation), a novel credential system that enables multi-authority credential issuance, user-controlled credential aggregation, and unlinkable authentication. DISC allows users to aggregate credentials from multiple issuers while maintaining constant-size authentication tokens and supporting batch verification for …
Higher Education Cybersecurity: A Vulnerability Assessment Of The U.S. South’S Institutional Websites, Zachary W. Taylor, Vivi Vo
Higher Education Cybersecurity: A Vulnerability Assessment Of The U.S. South’S Institutional Websites, Zachary W. Taylor, Vivi Vo
Journal of Cybersecurity Education, Research and Practice
As technology continues to advance, it is critical to understand how higher education institutions protect digital information of their stakeholders including students, faculty, and staff through cybersecurity measures. Although conceptual research has articulated various aspects of cybersecurity, no empirical research has explored the cybersecurity of higher education (.edu) websites through a vulnerability scan of these websites via an open PortScan and analysis. To fill a critical gap in the literature, this study conducted a vulnerability scan and open PortScan and analysis of all higher education websites in three of the lowest-income states in the United States: Louisiana (n=112), Mississippi (n=52), …
Cross-Model Watermarking Via Discriminative Samples For Secure Authentication, Juan Zhao, Yudao Sun, Zhihai Yang, Cai Xu, Hongji Chen, Fan Zhang, Jianxin Li
Cross-Model Watermarking Via Discriminative Samples For Secure Authentication, Juan Zhao, Yudao Sun, Zhihai Yang, Cai Xu, Hongji Chen, Fan Zhang, Jianxin Li
Research outputs 2022 to 2026
Deep neural networks on cloud platforms face growing security threats, with AI services increasingly relying on heterogeneous models for the same task to meet diverse user needs. Existing methods fail to distinguish benign modifications from malicious attacks in cross-model scenarios. To address this challenge, we propose a non-intrusive cross-model watermarking method that generates discriminative samples as universal keys, enabling authentication without altering model parameters or architectures. Specifically, we introduce a margin enhancement loss to amplify confidence gaps between benign and malicious behaviors, ensuring high transferability across models. Both theoretical analysis and experimental results demonstrate the high efficacy of our proposed …
Deep Learning Based Contactless Fingerprint Identification, Mohammad Alsmirat, M. Moneb Khaled, Aghyad A.L. Sayadi
Deep Learning Based Contactless Fingerprint Identification, Mohammad Alsmirat, M. Moneb Khaled, Aghyad A.L. Sayadi
Faculty Publications
Biometric authentication systems, particularly contactless fingerprint methods, offer enhanced security and convenience across various domains like access control, law enforcement, and finance. Despite these advantages, contactless systems face significant challenges related to image quality, finger orientation, and environmental factors. To address this, our paper presents the first extensive deep learning-based study on contactless fingerprint recognition using a large dataset of 2,143 images from 175 individuals. Our proposed approach integrates state-of-the-art preprocessing techniques with deep learning models to boost identification performance. After studying various transfer learning models, we achieved a high accuracy of 93.5%. We also conducted two further studies on …
Impact Of Information Security Awareness Training On Knowledge, Attitude, And Behavior: A K-12 Case Study, Michael S. Robbins, Christopher Robbins
Impact Of Information Security Awareness Training On Knowledge, Attitude, And Behavior: A K-12 Case Study, Michael S. Robbins, Christopher Robbins
Journal of Cybersecurity Education, Research and Practice
Abstract— Information security breaches remain a serious threat across all sectors, often exploiting human factors rather than technical flaws. This study examines how a structured Information Security Awareness (ISA) training program influences employees’ knowledge of security policies, attitudes towards those policies, and self-reported security behaviors within a K-12 educational environment. A quantitative pre-test/post-test design was employed with 201 staff members (administrators, teachers, and support personnel) in a public school district. Participants completed the Human Aspects of Information Security Questionnaire (HAIS-Q) before and after undergoing an interactive cybersecurity training program. Statistical analysis revealed a significant improvement in information security knowledge, attitudes, …
Prompt Engineering For Genai In Cybersecurity Incident Response: A Multi-Platform Evaluation Based On Nice Pr-Ir-001, Yuanyuan Liu
Prompt Engineering For Genai In Cybersecurity Incident Response: A Multi-Platform Evaluation Based On Nice Pr-Ir-001, Yuanyuan Liu
Journal of Cybersecurity Education, Research and Practice
This study explores the application of prompt engineering in cybersecurity education, mainly by evaluating the performance of different generative artificial intelligence (GenAI) platforms when performing tasks consistent with the NICE framework role pr-ir-001 - Network Defense Incident Responder. The study employed structured prompts designed for a medical technology environment compliant with HIPAA and NIST SP 800-53, while the tasks of the three GenAI models (GPT-4, Gemini, and DeepSeek) were to generate event response scenarios. Their outputs will be evaluated from four aspects: accuracy, relevance, clarity and completeness.
The results show that the three models differ in depth and consistency, but …
Arizona’S Experiential Learning Opportunities: Regional Security Operations Centers And Cybersecurity Clinics, Joshua Kipers, Paul Wagner, Robert J. Honomichl
Arizona’S Experiential Learning Opportunities: Regional Security Operations Centers And Cybersecurity Clinics, Joshua Kipers, Paul Wagner, Robert J. Honomichl
Journal of Cybersecurity Education, Research and Practice
The increasing frequency, sophistication, and economic impact of cybersecurity incidents have intensified the global demand for a skilled cybersecurity workforce. Traditional academic programs often fail to provide the applied experience necessary to prepare graduates for the rapidly evolving threat landscape. This paper examines Arizona’s innovative approaches to experiential cybersecurity education through the establishment of Regional Security Operations Centers (RSOCs) and the Arizona Cybersecurity Clinic. These initiatives integrate Kolb’s Experiential Learning Theory and the NICE Cybersecurity Workforce Framework to align academic preparation with real-world practice. The RSOCs, supported by the Arizona Department of Homeland Security, provide paid student internships focused on …
Static Malware Analysis For Incident Response: Developing A Tactical Aid With Ember, Joel Meoak, Shengjie Xu
Static Malware Analysis For Incident Response: Developing A Tactical Aid With Ember, Joel Meoak, Shengjie Xu
Journal of Cybersecurity Education, Research and Practice
Incident responders face a variety of challenges when identifying malware using existing solutions, particularly when rapid tactical decisions are needed. Traditional malware detection methods are often signature-based, limiting their effectiveness to previously known threats detected by anti-virus (AV) engines. Online analysis tools introduce confidentiality risks, potentially alerting adversaries that their actions are under scrutiny. While free sandbox environments offer useful capabilities, they often require substantial setup time and hardware resources that may not be available in the field. This research leverages the Elastic Malware Benchmark for Empowering Researchers (EMBER) dataset to develop a lightweight, portable tactical decision aid that enables …
Adaptive Security Metric For Optimizing Post-Quantum Cryptography In Constrained Iot Devices, Aisha Nasser Ahmed
Adaptive Security Metric For Optimizing Post-Quantum Cryptography In Constrained Iot Devices, Aisha Nasser Ahmed
Theses
Quantum Computing poses real threat to Classical Public-Key Cryptography requiring the use of Post-Quantum Cryptography for all Internet of Things Devices. However, there are greater computational, memory and communication overheads in PQC algorithms that create additional burdens on resource constrained IoT devices. At this time, there are no standard measures for systems developers to determine optimal PQC settings for the various IoT Device Classes. This Thesis develops a new framework of metrics for determining the most suitable PQC settings based on Security Strength, Performance Indicators (Latency, Memory, Energy), Communication Overhead and Reliability for each IoT device class. The Research introduces …
Spd: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection, Shunjie Yuan, Xinghua Li, Xuelin Cao, Haiyan Zhang, Mengyao Zhu, Robert H. Deng
Spd: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection, Shunjie Yuan, Xinghua Li, Xuelin Cao, Haiyan Zhang, Mengyao Zhu, Robert H. Deng
Research Collection School Of Computing and Information Systems
Backdoor attacks have revealed the vulnerability of deep neural networks (DNNs), which motivates the development of secure deep learning systems. However, existing backdoor attacks often fail to bypass backdoor detection and human visual inspection, resulting in the exposure of the backdoor implanted in DNNs, which can subsequently be significantly mitigated through pruning or fine-tuning on benign data. To address this issue, in this paper, we propose a novel backdoor attack called SPD (Shallow Protecting Deep), which consists of a deep backdoor in the frequency domain and a shallow backdoor in the pixel domain, where the shallow backdoor acts as a …
Conditional Attribute-Based Pre: Definition And Construction From Lwe, Lisha Yao, Jian Weng, Pengfei Wu, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng
Conditional Attribute-Based Pre: Definition And Construction From Lwe, Lisha Yao, Jian Weng, Pengfei Wu, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng
Research Collection School Of Computing and Information Systems
Attribute-based proxy re-encryption (AB-PRE) is a crucial variant of proxy re-encryption. It allows a proxy with a re-encryption key to transform a delegator’s ciphertext associated with an access policy into another ciphertext associated with a new access policy, enabling delegatees with matching attributes to decrypt the transformed ciphertext. However, a key limitation of AB-PRE is that the delegator cannot control which ciphertexts are transformed. As a result, the proxy, once given the re-encryption key, indiscriminately transforms all ciphertexts, effectively switching their underlying policies—an issue known as the all-or-nothing problem. It limits the system’s flexibility and practicality in real-world use cases.In …
A System Framework To Symbolically Explore Intel Tdx Module Execution, Pansilu Pitigalaarachchillage, Xuhua Ding
A System Framework To Symbolically Explore Intel Tdx Module Execution, Pansilu Pitigalaarachchillage, Xuhua Ding
Research Collection School Of Computing and Information Systems
We present TDXplorer, the first dynamic symbolic analysis system for Intel's TDX Module, the software trusted computing base of TDX. Without using TDX hardware, an analyzer function on top of TDXplorer can not only apply dynamic analysis to control and instrument the TDX Module's execution, but also carry out symbolic execution for path exploration as well as security and functionality reasoning. The two types of analysis are seamlessly integrated in a way that symbolic execution is conducted directly upon the TDX Module's binary code and runtime states, which are shaped by using dynamic analysis techniques. We implement TDXplorer on Linux …
Ivycross: A Privacy-Preserving And Concurrency Control Framework For Blockchain Interoperability, Ming Li, Jian Weng, Jia-Si Weng, Yi Li, Yongdong Wu, Dingcheng Li, Guowen Xu, Deng, Robert H.
Ivycross: A Privacy-Preserving And Concurrency Control Framework For Blockchain Interoperability, Ming Li, Jian Weng, Jia-Si Weng, Yi Li, Yongdong Wu, Dingcheng Li, Guowen Xu, Deng, Robert H.
Research Collection School Of Computing and Information Systems
Interoperability is a fundamental challenge for long-envisioned blockchain applications. A mainstream approach is using Trusted Execution Environment (TEE) to support interoperable off-chain execution. However, this incurs multiple TEE configured with non-trivial storage capabilities running on fragile concurrent processing environments, rendering current strategies based on TEE far from being practical. This paper aims to fill this gap and design a practical interoperability mechanism with simplified TEE as the underlying architecture. Specifically, we present IvyCross, a TEE-based framework that achieves low-cost, privacy-preserving, and race-free blockchain interoperability. IvyCross allows running arbitrary smart contracts across heterogeneous blockchains atop two distributed TEE-powered hosts. We design …
Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi
Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi
Faculty Publications
Contract law is supposed to enable people to reach genuine agreements and cooperate. If this ideal was ever a reality, the rise of mass market contracts and boilerplate rendered it pure fiction. Modern consumer contracts are incomprehensible to most people. No one reads them anyway.
Digital contracting involves design features that amplify traditional boilerplate harms and create others. For example, digital contracting is too cheap; low marginal costs lead to overexpansion in scale and scope. To make matters worse, the loss of autonomy from repeat engagement with digital contracting systems is pernicious. People become increasingly predictable and programmable as digital …
Experiential Learning: Innovative Approaches To Post-Secondary Cybersecurity Education, Brendan Bertone, Paul Wagner, Joshua Pauli
Experiential Learning: Innovative Approaches To Post-Secondary Cybersecurity Education, Brendan Bertone, Paul Wagner, Joshua Pauli
Journal of Cybersecurity Education, Research and Practice
The cybersecurity profession continues to face a significant shortfall of qualified professionals despite steady growth in degree programs. Employers consistently cite experience as the main barrier for entry-level cybersecurity hires. This paper argues that clinic-based experiential learning offers a scalable solution to that preparation gap. A systematic literature review spanning academic and professional literature was conducted to examine: (1) barriers to entry for aspiring cybersecurity professionals; (2) the effectiveness of experiential learning compared to traditional instruction; and (3) the viability and scalability of cybersecurity clinics. Screening emphasized workforce development, experiential pedagogy, and alignment with the NICE Cybersecurity Workforce Framework. Findings …
Information Security Awareness And Behavior Of Smartphone Users In The Ibadan Metropolis, Nigeria, Funmilola Olubunmi Omotayo
Information Security Awareness And Behavior Of Smartphone Users In The Ibadan Metropolis, Nigeria, Funmilola Olubunmi Omotayo
Journal of Cybersecurity Education, Research and Practice
Today, there is a rapid increase in the number of people using the Internet via smartphones and relying on them for most of their daily activities. Consequently, smartphones are becoming the target of criminals for atrocious purposes. This study investigated the information security awareness and behavior of smartphone users in the Ibadan metropolis, Nigeria. The study adopted a descriptive survey design. Data was collected with a questionnaire from 400 respondents who were conveniently selected. Findings revealed that most smartphone users knew about the smartphone security features available on their phones. However, most also engaged in behaviors that threatened their information …
Boosting Symbolic Execution For Vulnerability Detection, Haoxin Tu
Boosting Symbolic Execution For Vulnerability Detection, Haoxin Tu
Dissertations and Theses Collection (Open Access)
Software systems written by humans tend to be unreliable and insecure, hence, bugs or vulnerabilities in them are inevitable. Symbolic execution has shown considerable potential in detecting diverse types of software bugs and also vulnerabilities that have severe security implications. However, existing symbolic execution engines still suffer from at least three fundamental limitations in memory modeling, path exploration, and structured input generation, which significantly impede existing engines from efficiently and effectively detecting software bugs and vulnerabilities.
The objective of this dissertation is to boost existing symbolic execution engines by designing a new memory model, two new path exploration strategies, and …
An Efficient Security-Enhanced Accountable Access Control For Named Data Networking, Jianfei Sun, Yuxian Li, Xuehuan Yang, Guomin Yang, Robert H. Deng
An Efficient Security-Enhanced Accountable Access Control For Named Data Networking, Jianfei Sun, Yuxian Li, Xuehuan Yang, Guomin Yang, Robert H. Deng
Research Collection School Of Computing and Information Systems
Named Data Networking (NDN) is embraced as the crucial implementation of Information-Centric Networking (ICN), enhancing content distribution and caching efficiency through edge routers. However, existing NDN architectures face significant security and privacy challenges, including: (a) a lack of secure and efficient access control; (b) inadequate support for flexible and selective content management by content publishers; (c) insufficient implementation of accountability and privilege revocation mechanisms. To handle these challenges, we propose ESAS, the first-ever Efficient Security-enhanced Accountable Access Control Scheme for NDN. Specifically, our ESAS incorporates anonymous authentication using group signatures at network routers to prevent unauthorized access, employs key-aggregation-based access …
Shortcuts Everywhere And Nowhere: Exploring Multi-Trigger Backdoor Attacks, Yige Li, Jiabo He, Hanxun Huang, Jun Sun, Xingjun Ma, Yu-Gang Jiang
Shortcuts Everywhere And Nowhere: Exploring Multi-Trigger Backdoor Attacks, Yige Li, Jiabo He, Hanxun Huang, Jun Sun, Xingjun Ma, Yu-Gang Jiang
Research Collection School Of Computing and Information Systems
Backdoor attacks have become a significant threat to the pre-training and deployment of deep neural networks (DNNs). Although numerous methods for detecting and mitigating backdoor attacks have been proposed, most rely on identifying and eliminating the “shortcut” created by the backdoor, which links a specific source class to a target class. However, these approaches can be easily circumvented by designing multiple backdoor triggers that create shortcuts everywhere and therefore nowhere specific. In this study, we explore the concept of Multi-Trigger Backdoor Attacks (MTBAs), where multiple adversaries leverage different types of triggers to poison the same dataset. By proposing and investigating …
Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys, Yanling Li, Junzuo Lai, Meng Sun, Beibei Song, Robert H. Deng
Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys, Yanling Li, Junzuo Lai, Meng Sun, Beibei Song, Robert H. Deng
Research Collection School Of Computing and Information Systems
With the increase of private data being collected by data owners, it has been a trend for data owners to store the data on cloud computing platforms. The huge amounts of data in cloud servers bring fresh development opportunities to machine learning, which is applied to build a high-quality machine learning model based on a large training dataset. However, to ensure the privacy of data and facilitate retrieval, data owners often upload encrypted data under their public keys. But it creates new challenges for machine learning to learn a predictive model over these encrypted data under different keys. Most existing …
Cybersecurity And Intention To Use Mobile Banking Applications, Ishmael Chikoo, Salah Kabanda
Cybersecurity And Intention To Use Mobile Banking Applications, Ishmael Chikoo, Salah Kabanda
African Conference on Information Systems and Technology
The adoption rate of mobile banking amongst consumers remains low, especially in developing countries where there is a knowledge gap in understanding why consumers do not engage in the frequent use of mobile banking applications. Given that most financial institutions see mobile banking as a strategy for their competitive advantage; it is important that they understand how best to address consumer’s fears brought about by cybersecurity threats. The purpose of this study is to investigate the perceived influence of cybersecurity on the user’s intentions to use mobile banking applications. Data collected from 90 participants was statistically analysed in Smart PLS …
A Study On Webassembly And Its Security, Thomas Crossman
A Study On Webassembly And Its Security, Thomas Crossman
Research from the Berry Summer Thesis Institute, 2025
This project studies WebAssembly, a binary language specification that enables non-native languages, such as C/C++ and Rust, to run efficiently on webpages, supporting complex tasks like gaming or data processing. It functions by translating a non-native language into a WebAssembly binary, which is natively supported by most browsers. Notably, WebAssembly uses a linear memory model, storing all non-code data in a single linear array. Unfortunately, this design compromises some security principles, introducing security risks and complications.
Our overall project goal is to investigate WebAssembly functionality, develop a test program, and address a critical security challenge to enhance the safety of …
A Comprehensive Review On Gamification In Neurocybersecurity, Ms. Kritika
A Comprehensive Review On Gamification In Neurocybersecurity, Ms. Kritika
Journal of Cybersecurity Education, Research and Practice
The research investigates gamification methods as it applies to the emerging interdisciplinary domain that brings together cybersecurity with neuroscience and psychology. Neurocybersecurity implements neural concepts to protect digital systems from security threats while targeting the human vulnerabilities that present as the strongest points of attack. Several researchers have examined gamification techniques which incorporate game design elements to enhance cybersecurity training outcomes by improving user participation and knowledge retention and user conduct compliance. The research incorporates Self-Determination Theory along with Cognitive Load Theory to explain the design principles for efficient gamified interventions. The implementation of both cognitive performance improvement and neuroplasticity …
Investigating Resilience Of Cyberattack Detection Using Lyapunov-Based Economic Model Predictive Control To Data Poisoning, Helen Durand, Akkarakaran Francis Leonard
Investigating Resilience Of Cyberattack Detection Using Lyapunov-Based Economic Model Predictive Control To Data Poisoning, Helen Durand, Akkarakaran Francis Leonard
Chemical Engineering and Materials Science Faculty Research Publications
Cyberattacks may be performed on process control systems due to their integration of networking and computing with physical systems. Prior work in our group has developed detection strategies for nonlinear systems under sensor, actuator, and combined sensor and actuator attacks which can ensure, under characterizable conditions, that attacks can be detected before they cause safety issues. However, this work did not take into account the potential that an attacker could attempt to provide data to a process that causes an attack to remain undetected but that also is consistent with different process dynamics than those which the process has. This …
Response Of Dynamic Processes With Control Implemented On A Noisy Quantum Computer, Shilpa Narashimhan, Dominic Messina, Henrique Oyama, Helen Durand
Response Of Dynamic Processes With Control Implemented On A Noisy Quantum Computer, Shilpa Narashimhan, Dominic Messina, Henrique Oyama, Helen Durand
Chemical Engineering and Materials Science Faculty Research Publications
A major challenge to determining the applicability (and potential outperformance over classical computers) of a quantum computer (QC) within chemical manufacturing processes is quantum noise. Computations by a QC are error-prone due to the influence of quantum noise inherent to the hardware. Errors in control inputs may destabilize a chemical process and lead to unsafe conditions for manufacturing personnel and the environment. The response of a process with control implemented on a QC to errors due to noise must be investigated thoroughly. In this work, the impacts of control input errors due to quantum noise on a process are modeled …
Heuristic Strategies For Process Stabilization Using Proportional Control Implemented By A Noisy Quantum Simulator, Keshav Kasturi Rangan, Helen Durand
Heuristic Strategies For Process Stabilization Using Proportional Control Implemented By A Noisy Quantum Simulator, Keshav Kasturi Rangan, Helen Durand
Chemical Engineering and Materials Science Faculty Research Publications
Processing and storage demands of industrial processes are causing fields such as optimization, scheduling, and control to assess the effectiveness of quantum devices in their applications. A key objective of control systems is to ensure process safety. This paper focuses on the potential of quantum devices to compute control inputs that maintain system safety despite sources of nondeterminism inherent to currently available quantum devices (quantum noise). In our previous work, we employed a quantum simulator to assess whether a quantum implementation of a proportional (P) control law could stabilize a single-input/single-output system under quantum noise approximated from a real quantum …
Tools To Design Algorithms For Implementing Control Over Quantum Computers, Shilpa Narashimhan, Jihan Abou Halloun, Kip Nieman, Helen Durand
Tools To Design Algorithms For Implementing Control Over Quantum Computers, Shilpa Narashimhan, Jihan Abou Halloun, Kip Nieman, Helen Durand
Chemical Engineering and Materials Science Faculty Research Publications
Quantum computers (QCs) may find future applications within control systems that operate manufacturing processes. For application within control engineering, quantum algorithm development must be led by control engineers. However, control engineers may face challenges in designing quantum algorithms for control engineering problems. In this work, we provide several path-finding studies that leverage engineering tools such as optimization, encryption, and computational "short-cuts" toward making algorithm design for QC easier for control engineers.
Achilles: A Formal Framework Of Leaking Secrets From Signature Schemes Via Rowhammer, Junkai Liang, Zhi Zhang, Xin Zhang, Qingni Sheng, Yansong Gao, Xinliang Yuan, Haiyang Xue, Pengfei Wu, Zhonghai. Wu
Achilles: A Formal Framework Of Leaking Secrets From Signature Schemes Via Rowhammer, Junkai Liang, Zhi Zhang, Xin Zhang, Qingni Sheng, Yansong Gao, Xinliang Yuan, Haiyang Xue, Pengfei Wu, Zhonghai. Wu
Research Collection School Of Computing and Information Systems
Signature schemes are a fundamental component of cyber-security infrastructure. While they are designed to be mathematically secure against cryptographic attacks, they are vulnerable to Rowhammer fault-injection attacks. Since all existing attacks are ad-hoc in that they target individual parameters of specific signature schemes, it remains unclear about the impact of Rowhammer on signature schemes as a whole.In this paper, we present Achilles, a formal framework that aids in leaking secrets in various real-world signature schemes via Rowhammer. Particularly, Achilles can be used to find potentially more vulnerable parameters in schemes that have been studied before and also new schemes that …
Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu Pan, Wanjing Han, Yue Duan, Mu Zhang
Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu Pan, Wanjing Han, Yue Duan, Mu Zhang
Research Collection School Of Computing and Information Systems
Storage collision vulnerabilities, a significant security risk in upgradeable smart contracts, often arise when a user-facing proxy contract and a backend logic contract share storage space. While static analysis techniques can detect such issues, they often over-approximate program states, leading to false positives and requiring developers to manually verify each issue, giving attackers time to exploit any overlooked vulnerabilities. To address this, we propose COLLISIONREPAIR, an automated patching technique for mitigating storage collision risks. COLLISIONREPAIR monitors storage access sequences between proxy and logic contracts by defining an "ownership" property for storage locations. It then replays historical transactions to recover existing …
Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, Yingtat Ng, Zhe Chen, Haiqing Qiu, Xuhua Ding
Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, Yingtat Ng, Zhe Chen, Haiqing Qiu, Xuhua Ding
Research Collection School Of Computing and Information Systems
We present Prism, an UI hardening technique for an Android app to safeguard its widgets against a corrupted kernel. Prism ensures secure interface rendering and allows for visual authentication, which developers could use to enable user intent confidentiality protection. Our design leverages the recent Android Virtualization Framework with minimal changes to the existing UI framework and graphics subsystem. It is much easier to deploy and use Prism on Android phones than TrustZone-based secure UI schemes, because the apps are not admitted to the Secure World and retain their full rights to manage and control their own interfaces. We have implemented …