Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2026

Discipline
Institution
Keyword
Publication
Publication Type

Articles 121 - 142 of 142

Full-Text Articles in Information Security

From Authorization To Loss: A Blockchain Forensic Analysis Of Transaction-Level Mechanisms In Cryptocurrency Airdrop Scams, Chanwoo Shin, Kyung-Shick Choi Jan 2026

From Authorization To Loss: A Blockchain Forensic Analysis Of Transaction-Level Mechanisms In Cryptocurrency Airdrop Scams, Chanwoo Shin, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

Cryptocurrency airdrop scams have emerged as a rapidly growing form of cyber-enabled financial crime, yet remain underexplored in empirical research. This study examines how transaction-level mechanisms and offender strategies influence variation in monetary loss in airdrop scam incidents. Grounded in Cyber-Routine Activities Theory (Cyber-RAT), the study conceptualizes financial harm as occurring within decentralized environments where users’ online behaviors, particularly transaction authorization, intersect with limited digital capable guardianship. Data were drawn from 112 validated airdrop scam cases reported on Chainabuse.com between January and December 2025. Blockchain forensic analysis using Breadcrumbs was conducted to reconstruct transaction pathways, identify exchange interactions, and detect …


The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade Jan 2026

The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade

Journal of Cybersecurity Education, Research and Practice

SourceURL:file:///home/amaechi/Documents/ *Journal of Cybersecurity Education, Research and Practice (JCERP)*. **Title:** The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches to Teach Foundational Cybersecurity Failures.docx

Background: Between March and April 2026, a single threat actor allegedly compromised four Nigerian institutions across banking, payment infrastructure, government registry, and power distribution sectors. The breaches exposed millions of records and disrupted critical services, yet all four exploited elementary vulnerabilities taught in introductory cybersecurity courses. Objective: This pedagogical case study analyzes the four breaches as a unified phenomenon of "normalized negligence" and provides ready-to-use teaching materials for cybersecurity educators. Methods: Using open-source intelligence analysis of …


Potent But Stealthy: Rethink Profile Pollution Against Sequential Recommendation Via Bi-Level Constrained Reinforcement Paradigm, Jiajie Su, Zihan Nan, Yunshan Ma, Xiaobo Xia, Xiaohua Feng, Weiming Liu, Xiang Chen, Xiaolin Zheng, Chaochao Chen Jan 2026

Potent But Stealthy: Rethink Profile Pollution Against Sequential Recommendation Via Bi-Level Constrained Reinforcement Paradigm, Jiajie Su, Zihan Nan, Yunshan Ma, Xiaobo Xia, Xiaohua Feng, Weiming Liu, Xiang Chen, Xiaolin Zheng, Chaochao Chen

Research Collection School Of Computing and Information Systems

Sequential Recommenders, which exploit dynamic user intents through interaction sequences, are vulnerable to adversarial attacks. While existing attacks primarily rely on data poisoning, they require large-scale user access or fake profiles, thus lacking practicality. In this paper, we focus on the Profile Pollution Attack that subtly contaminates partial user interactions to induce targeted mispredictions. Previous PPA methods suffer from two limitations, i.e., i) overreliance on sequence horizon impact restricts fine-grained perturbations on item transitions, and ii) holistic modifications cause detectable distribution shifts. To address these challenges, we propose a constrained reinforcement driven attack CREAT that synergizes a bi-level optimization framework …


Security-Enhanced Decentralized Conditional Privacy-Preserving Authentication In Vanets, Suqin Luo, Xinghua Li, Yinbin Miao, Xuelin Cao, Zhan Zhang, Yunwei Wang, Deng R.H. Jan 2026

Security-Enhanced Decentralized Conditional Privacy-Preserving Authentication In Vanets, Suqin Luo, Xinghua Li, Yinbin Miao, Xuelin Cao, Zhan Zhang, Yunwei Wang, Deng R.H.

Research Collection School Of Computing and Information Systems

To ensure the legitimacy of communicators while ad dressing the privacy concerns of vehicles in vehicular ad-hoc networks (VANETs), conditional privacy-preserving authentication (CPPA) schemes have been proposed. Given that existing schemes suffer from single point of failure due to centralized authorities, several distributed CPPA schemes have been proposed. However, these schemes all ignore the tight cementation between system secret keys and the authority, which could be a serious threat to system security, that the compromised authority may leak the system secret key. To address these issues, we propose a security enhanced decentralized conditional privacy-preserving authentication (DCPPA) scheme. DCPPA first introduces …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias Jan 2026

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz Jan 2026

A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz

Graduate Studies Theses and Dissertations 2026

Software applications increasingly rely on user data to provide their functionality, but improper handling of such data can lead to serious privacy noncompliance with applicable regulations and policies. A prominent example is the Facebook–Cambridge Analytica scandal, in which a third-party application collected the personal data of approximately 87 million Facebook users without users' consent. Despite growing attention to privacy compliance, two key challenges hinder the systematic understanding and analysis of privacy noncompliance. First, unlike security vulnerabilities, which have been systematically categorized through taxonomies such as the Common Weakness Enumeration (CWE), privacy noncompliance lacks a technical taxonomy describing how it manifests …


Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi Jan 2026

Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi

Theses, Dissertations and Capstones

The rapid expansion of the Internet of Things (IoT) has transformed modern computing by enabling seamless connectivity among heterogeneous devices across diverse application domains. However, this increased interconnectivity has significantly enlarged the attack surface of IoT networks, exposing them to a wide range of sophisticated cyber threats. Conventional security mechanisms often lack the capability to detect emerging attacks in real time, thereby necessitating the development of intelligent Intrusion Detection Systems (IDS) capable of accurately identifying malicious network activities. This study developed and evaluated a machine learning-based intrusion detection framework for multiclass IoT attack detection using the RT-IoT2022 dataset. The dataset …


Cybercrime, Vulnerability And Digital Guardianship: Opportunity Structures And Prevention In A Changing Online Landscape, Mike Toro-Alvarez, Amy Lim Jan 2026

Cybercrime, Vulnerability And Digital Guardianship: Opportunity Structures And Prevention In A Changing Online Landscape, Mike Toro-Alvarez, Amy Lim

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


Analyzing Modern Scam Typologies: From Pig-Butchering And Nigerian Advance-Fee Fraud To Crypto Airdrop Schemes, Katalin Parti, Sinyong Choi, Thomas Dearden Jan 2026

Analyzing Modern Scam Typologies: From Pig-Butchering And Nigerian Advance-Fee Fraud To Crypto Airdrop Schemes, Katalin Parti, Sinyong Choi, Thomas Dearden

International Journal of Cybersecurity Intelligence & Cybercrime

Rapid advancements in digital infrastructure and decentralized networks have fundamentally altered the nature of contemporary cybercrime, making comprehensive empirical and technical analysis more crucial than ever. To address these challenges, this editorial summarizes the research contributions featured in this issue of the International Jour nal of Cybersecurity Intelligence and Cybercrime. The included papers examine the structural on-chain dynamics of sanctioned pig-butchering operations, the representational production and AI-driven evolution of the “Nigerian scam” label, the critical transaction-authorization factors driving losses in crypto airdrop schemes, and the optimization of sentence-transformer models for automated Host Intrusion Detection System (HIDS) alert enrichment. Together, these …


Three-Tier On-Chain Transaction Architecture In A Sanctions-Linked Pig-Butchering Network: A Blockchain-Forensics Case Study, Matthew Stern, Kyung-Shick Choi Jan 2026

Three-Tier On-Chain Transaction Architecture In A Sanctions-Linked Pig-Butchering Network: A Blockchain-Forensics Case Study, Matthew Stern, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

n October 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 29 Bitcoin addresses asso ciated with the Prince Group and Chen Zhi, providing an opportunity to examine the internal on-chain structure of a sanctions-linked pig-butchering network. This blockchain-forensics case study analyzes the group of 29 addresses using blockchain tracing, cross-plat form attribution checks across multiple commercial analytics platforms, exposure screening, and thematic analysis of transaction be havior. Because the case rests on OFAC designations and DOJ allegations, the traced flows are interpreted as patterns consistent with suspected laundering rather than adjudicated crimes; no fiat …


Attribution Post ‘Aura’ Loss: A Qualitative Discourse Analysis Of The Nigerian Scam Label And Fraud Attribution, Emaediong Akpan Jan 2026

Attribution Post ‘Aura’ Loss: A Qualitative Discourse Analysis Of The Nigerian Scam Label And Fraud Attribution, Emaediong Akpan

International Journal of Cybersecurity Intelligence & Cybercrime

In this essay, I employ qualitative discourse analysis of eleven purposively selected literature to examine how “Nigerian scam” became an established yet detached signifier of advance-fee fraud in global discourse. I do not treat this association as a reflection of offender identity or national inclination. Instead, the analysis traces how attribution is produced through representational repetition, institu tional uptake, and the circulation of familiar narrative cues. Using qualitative discourse analysis and an interpretive approach, this paper distinguishes among the socio-technical conditions that enable fraud, the institutional processes that stabilize attribution, and the semiotic dynamics through which national categories acquire durability. …


Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation, Matthew Ragsdale Jan 2026

Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation, Matthew Ragsdale

College of Graduate Studies: Theses & Dissertations

The convergence of artificial intelligence and cybersecurity presents new opportunities for automated penetration testing capable of discovering, prioritizing, and remediating vulnerabilities at machine speed. However, deployment on resource-constrained ARM platforms remains unexplored despite ARM’s dominance in mobile, IoT, and edge computing with over 280 billion chips deployed globally. This thesis presents systematic experimental evaluation of AI-driven penetration testing across four paradigms—traditional machine learning, deep learning, large language models, and reinforcement learning—on three ARM platform tiers: Raspberry Pi 5 (8GB, Cortex-A76), Radxa ROCK 5B Plus (16GB LPDDR5 with NPU), and NVIDIA Jetson Nano (4GB with Maxwell GPU). The experimental framework generates …


A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad Jan 2026

A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad

American University Business Law Review

[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through …


Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar Jan 2026

Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar

UNF Graduate Theses and Dissertations

The Narrowband Internet of Things (NB-IoT) continues to expand but faces challenges such as cryptographic overhead and energy consumption. Security frameworks such as blockchain and Energy-Performance Cumulative Message Authentication Codes (EP-CuMAC) rely heavily on SHA-256, which is not optimized for energy-limited devices.

This work unifies two complementary approaches, a hybrid blockchain-based NB-IoT framework and an EP-CuMAC-based framework, by engineering their cryptographic core with an Energy Complexity Model-optimized SHA-256 (ECM-SHA256). ECM applies parallel memory-bank mapping and block-level access optimization to reduce redundant power usage while preserving algorithmic integrity.

Experimental evaluation on identical Intel DDR3 systems using pyRAPL shows energy savings of …


The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li Jan 2026

The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li

Computer Science Faculty Publications

Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …


Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala Jan 2026

Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala

Computer Science Faculty Publications

Large Language Models (LLMs) are increasingly being adopted in a wide variety of domains, including sensitive domains such as healthcare and finance. However, persistent challenges such as unreliable data sources, privacy breaches, and hallucinated output continue to hinder their usage. We have experimented with several strategies to address these challenges. First, we developed BlockQwen, a blockchain-augmented framework that integrates decentralized trust validation, role-specific access control, and verifiable audit trails into the Qwen 2.5 LLM workflow. Second, we developed PrivAware, a multilayered privacy-enforcement framework, using a fine-tuned Flan-T5 model with self-attention masking, to safeguard data while maintaining high utility. Both systems …


Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge Jan 2026

Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge

Computer Science Faculty Publications

Medical imaging enables rapid and accurate diagnosis of COVID-19, with CT scans proving especially effective. However, data privacy concerns limit collaborative model development across hospitals. To address this issue, we introduce a novel federated learning framework. It is referred to as Independent Knowledge Distillation with post-Ensemble Federated Learning (IKDEFL). Differential Privacy (DP) is integrated into the framework to improve privacy guarantees. Three DP mechanisms are evaluated. These include Fixed Gaussian, Gaussian Adaptive, and Tree Adaptive. The evaluation has been conducted on heterogeneous and Non-Independent and Identically Distributed (Non-IID) datasets. These datasets reflect real-world hospital scenarios. Results show that IKDEFL significantly …


An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana Jan 2026

An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana

Computer Science Faculty Publications

Accurate prediction of ICU Length of Stay (LoS) is essential for clinical decision-making and healthcare resource management. Graph Neural Networks (GNNs), such as GraphSAGE, offer a natural fit by capturing patient data from Electronic Health Records (EHRs) through graph structures. However, the distributed and sensitive nature of this data raises both privacy and legal concerns regarding the aggregation and training of GNN models. This additionally leads to issues with data imbalance and model robustness. In this study, we perform an analysis of the Federated Graph Neural Network (GNN-FL) framework to enable decentralized learning on EHRs derived from the MIMIC-III dataset. …


Benchmarking Gaslighting Negation Attacks Against Reasoning Models, Bin Zhu, Hailong Yin, Jingjing Chen, Yu Gang Jiang Jan 2026

Benchmarking Gaslighting Negation Attacks Against Reasoning Models, Bin Zhu, Hailong Yin, Jingjing Chen, Yu Gang Jiang

Research Collection School Of Computing and Information Systems

Recent advances in reasoning-centric models promise improved robustness through mechanisms such as chain-of-thought prompting and test-time scaling. However, their ability to withstand gaslighting negation attacks—adversarial prompts that confidently deny correct answers—remains underexplored. In this paper, we conduct a systematic evaluation of three state-of-the-art reasoning models, i.e., OpenAI’s o4-mini, Claude-3.7-Sonnet and Gemini-2.5-Flash, across three multimodal benchmarks: MMMU, MathVista, and CharXiv. Our evaluation reveals significant accuracy drops (25–29% on average) following gaslighting negation attacks, indicating that even top-tier reasoning models struggle to preserve correct answers under manipulative user feedback. Built upon the insights of the evaluation and to further probe this vulnerability, …


Airaclex: Automated Detection Of Price Oracle Manipulations Via Llm-Driven Knowledge Mining And Prompt Generation, Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu, Rick Siow Mong Goh, David Lo Jan 2026

Airaclex: Automated Detection Of Price Oracle Manipulations Via Llm-Driven Knowledge Mining And Prompt Generation, Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu, Rick Siow Mong Goh, David Lo

Research Collection School Of Computing and Information Systems

Decentralized finance (DeFi) applications depend on accurate price oracles to ensure secure and fair transactions. However, poorly integrated oracles remain susceptible to manipulation, enabling attackers to exploit smart contract logic for unfair asset valuation and financial gain. While many such vulnerabilities are only detected after deployment, smart contracts are typically immutable once deployed, making post-hoc fixes costly or infeasible. This highlights the critical need for detecting oracle manipulation risks before deployment. In this paper, we propose AiRacleX, a novel LLM-driven framework that enables pre-deployment detection of price oracle manipulation vulnerabilities by leveraging the complementary strengths of multiple large language models …


An Investigation Into The Mechanisms, Barriers, Degree And Sphere Of Risk Influence In Corporate Security, Nicola Lockhart Jan 2026

An Investigation Into The Mechanisms, Barriers, Degree And Sphere Of Risk Influence In Corporate Security, Nicola Lockhart

Theses: Doctorates and Masters

This study investigates the sphere of corporate security risk influence within organisations, addressing the conceptual and practical ambiguity surrounding the activity’s capacity to shape organisational decisions, behaviours, and risk priorities. While corporate security’s protective role is widely recognised, its broader organisational risk influence remains under-theorised. The study defines the sphere of risk influence as the range of organisational stakeholders and environments with which the corporate security activity interacts, and within which it may engage, persuade, and mobilise action. This sphere is analytically constituted through the intersection of three dimensions: the mechanisms through which influence is attempted, the barriers that constrain …


Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim Jan 2026

Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim

Graduate Studies Theses and Dissertations 2026

Cyber-physical systems execute physical actions in response to software commands, making their communication protocols a primary attack surface. A stealthy attack is a sequence of individually valid messages that violates a required ordering, driving the system into an unsafe state without malware or protocol violation. Existing defenses examine messages or physical state in isolation, not protocol level sequences, and cannot prevent them. Preventing them requires enforcement that makes unsafe sequences unexecutable at the communication boundary.

Formal methods offer a principled path to enforcement, but no tool spans specification to safe deployed hardware. Model checking automates proofs but has no certified …