Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

Machine learning

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 1 - 30 of 82

Full-Text Articles in Information Security

A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath Jun 2026

A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath

Research & Publications

The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …


Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani Fan, Lwin Khin Shar, Ruichen Zhang, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam Mar 2026

Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani Fan, Lwin Khin Shar, Ruichen Zhang, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam

Research Collection School Of Computing and Information Systems

Money laundering is a financial crime that obscures the origin of illicit funds, necessitating the development and enforcement of anti-money laundering (AML) policies by governments and organizations. The proliferation of mobile payment platforms and smart IoT devices has significantly complicated AML investigations. As payment networks become more interconnected, there is an increasing need for efficient real-time detection to process large volumes of transaction data on heterogeneous payment systems by different operators such as digital currencies, cryptocurrencies, and account-based payments. Most of these mobile payment networks are supported by connected devices, many of which are considered loT devices in the FinTech …


Ordered Mini-Batch Training For Differentially Private And Encrypted Logistic Regression, Ryan Leone Jan 2026

Ordered Mini-Batch Training For Differentially Private And Encrypted Logistic Regression, Ryan Leone

Theses, Dissertations and Culminating Projects

Logistic regression has found extensive use as a supervised machine learning algorithm due to its simplicity and efficiency in binary and multivariate classification tasks. As data sharing grows across connected devices, safeguarding sensitive personal and industrial information is of increased importance. Privacy-preserving machine learning techniques such as differential privacy and homomorphic encryption offer mathematically rigorous security guarantees, but introduce difficult accuracy, privacy loss, and computational overhead issues. This thesis investigates PPML for logistic regression through a collaborative mini-batch training framework. I propose and implement an ordered mini-batch strategy, compare it to standard shuffled methods, then integrate differential privacy noise injection …


Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad Jan 2026

Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad

All Graduate Theses, Dissertations, and Other Capstone Projects

Phishing remains one of the most effective attack vectors for gaining unauthorized access to organizational systems, yet defenders often lack systematic methods to assess their exposure before an attack. This study develops a framework that uses machine learning to encode the collective expertise of cybersecurity practitioners into a portable phishing susceptibility assessment tool, with the goal to help security teams proactively identify patterns, prioritize awareness training, and strengthen detection controls. The study surveyed 27 practitioners with extensive experience in social engineering, red teaming, penetration testing, and threat analysis to identify which factors most influence phishing susceptibility. Practitioners provided quantitative ratings …


Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi Jan 2026

Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi

Theses, Dissertations and Capstones

The rapid expansion of the Internet of Things (IoT) has transformed modern computing by enabling seamless connectivity among heterogeneous devices across diverse application domains. However, this increased interconnectivity has significantly enlarged the attack surface of IoT networks, exposing them to a wide range of sophisticated cyber threats. Conventional security mechanisms often lack the capability to detect emerging attacks in real time, thereby necessitating the development of intelligent Intrusion Detection Systems (IDS) capable of accurately identifying malicious network activities. This study developed and evaluated a machine learning-based intrusion detection framework for multiclass IoT attack detection using the RT-IoT2022 dataset. The dataset …


Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed May 2025

Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed

Research outputs 2022 to 2026

Content hiding, or vault applications (apps), are designed with a secondary, often concealed purpose, such as encrypting and storing files. While these apps may serve legitimate functions, they unequivocally present significant challenges for law enforcement. Conventional methods for tackling this issue, whether static or dynamic, prove inadequate when devices—typically smartphones—cannot be modified. Additionally, these methods frequently require prior knowledge of which apps are classified as vault apps. This research decisively demonstrates that a non-invasive method of app analysis, combined with machine learning, can effectively identify vault apps. Our findings reveal that it is entirely possible to detect an Android vault …


Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell Feb 2025

Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell

Pharmacy and Wellness Review

Artificial Intelligence (AI) has transformed the pharmaceutical field by enabling computer software systems to learn and perform human behavior. Specifically, AI has revolutionized chronic diabetes management through continuous glucose monitoring, showcasing its immense potential in healthcare. However, alongside its transformative impact, AI’s increasing role in healthcare has prompted concerns over privacy and its premature integration. Despite these challenges, AI offers limitless opportunities to improve medication management and treatment regimens, driving advancements across various domains. From improving CT imaging to enhancing adenoma detection in colonoscopies and facilitating medication adherence, AI’s impact on healthcare is profound. Furthermore, AI plays a pivotal role …


Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu Jan 2025

Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu

Research & Publications

Ransomware and other malware inflict devastating financial and operational damage on organizations worldwide by exploiting deeply embedded, hard-to-detect vulnerabilities in their systems. Detecting these vulnerabilities in compiled code before malicious actors exploit them remains a critical challenge in cybersecurity. This research introduces TEDVIL (Transformer-based Embeddings for Discovering Vulnerabilities in Lifted Code), a novel framework which uses transformer-based embeddings to train neural networks to detect vulnerabilities in lifted code. The framework was implemented using bidirectional (BERT and RoBERTa) and unidirectional (GPT-1 and GPT-2) transformer-based models to generate embeddings for training Long Short-Term Memory (LSTM) neural networks to detect stack-based buffer overflows …


Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen Jan 2025

Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …


Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem Jan 2025

Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem

Theses: Doctorates and Masters

Machine learning has significantly transformed medical image analysis in the current age of artificial intelligence offering vast potential in improving disease diagnosis and management. Cardiovascular diseases (CVDs) are among the leading cause of global mortality, emphasizing the need for early detection for effective intervention and prevention. Abdominal Aortic Calcification (AAC) is an early indicator and contributor to Atherosclerotic Cardiovascular Diseases (ASCVDs) and is commonly assessed through imaging modalities such as computed tomography (CT), X-rays, and Dual-energy X-ray Absorptiometry (DXA). Among these, lateral spine DXA scans, commonly used for osteoporosis screening, offer a cost-effective and low-radiation opportunity for opportunistic CVD risk …


Sampdetox : Black-Box Backdoor Defense Via Perturbation-Based Sample Detoxification, Yanxin Yang, Chentao Jia, Dengke Yan, Ming Hu, Tianlin Li, Xiaofei Xie, Xian Wei, Mingsong Chen Dec 2024

Sampdetox : Black-Box Backdoor Defense Via Perturbation-Based Sample Detoxification, Yanxin Yang, Chentao Jia, Dengke Yan, Ming Hu, Tianlin Li, Xiaofei Xie, Xian Wei, Mingsong Chen

Research Collection School Of Computing and Information Systems

The advancement of Machine Learning has enabled the widespread deployment of Machine Learning as a Service (MLaaS) applications. However, the untrustworthy nature of third-party ML services poses backdoor threats. Existing defenses in MLaaS are limited by their reliance on training samples or white-box model analysis, highlighting the need for a black-box backdoor purification method. In our paper, we attempt to use diffusion models for purification by introducing noise in a forward diffusion process to destroy backdoors and recover clean samples through a reverse generative process. However, since a higher noise also destroys the semantics of the original samples, it still …


Detecting Anomalies In Blockchain Transactions Using Machine Learning Classifiers And Explainability Analysis, Mohammad Hasan, Mohammad Shahriar Rahman, Helge Janicke, Iqbal H. Sarker Sep 2024

Detecting Anomalies In Blockchain Transactions Using Machine Learning Classifiers And Explainability Analysis, Mohammad Hasan, Mohammad Shahriar Rahman, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

As the use of blockchain for digital payments continues to rise, it becomes susceptible to various malicious attacks. Successfully detecting anomalies within blockchain transactions is essential for bolstering trust in digital payments. However, the task of anomaly detection in blockchain transaction data is challenging due to the infrequent occurrence of illicit transactions. Although several studies have been conducted in the field, a limitation persists: the lack of explanations for the model's predictions. This study seeks to overcome this limitation by integrating explainable artificial intelligence (XAI) techniques and anomaly rules into tree-based ensemble classifiers for detecting anomalous Bitcoin transactions. The shapley …


Increasing The Robustness Of Machine Learning By Adversarial Attacks, Gourab Mukhopadhyay Jul 2024

Increasing The Robustness Of Machine Learning By Adversarial Attacks, Gourab Mukhopadhyay

Theses and Dissertations

By perturbation or physical attacks any machine can be fooled into predicting something else other than the intended output. There are training data based on which the model is trained to predict unknown things. The objective was to create noises and shades of different levels on the images and do experiments for measuring accuracy and making the model classify the traffic signs. When it comes to adding shades to the pictures, pixels were modified for three different layers of the pictures. The experiment also shows that with the shadows getting deeper, the accuracies drop significantly. Here, some changes in pixels …


Network Level Detection Of Iot Attacks Via Time Series Shape Mining, Srijani Basu Apr 2024

Network Level Detection Of Iot Attacks Via Time Series Shape Mining, Srijani Basu

Masters Theses

This research proposes a method, for detecting intrusions in the Internet of Things (IoT) realm. This approach was specifically tested using datasets containing both benign, and attacks on smart home devices like the Belkin Wemo Power Switch, Lifx Smart Bulb, Amazon Echo, and Netatmo Welcome Camera. These attacks consist of specification-compliant volumetric DDoS attacks, which can be both direct and reflective, with very low traffic volumes implemented in an ON-OFF pattern. Here, the ON-OFF pattern can be referred to as a pulse attack strategy.

We combined non-linear statistical moving averages, and Dynamic Time Warping into a single framework that can …


Artificial Intelligence Usage And Data Privacy Discoveries Within Mhealth, Jennifer Schulte Mar 2024

Artificial Intelligence Usage And Data Privacy Discoveries Within Mhealth, Jennifer Schulte

Research & Publications

Advancements in artificial intelligence continue to impact nearly every aspect of human life by providing integration options that aim to supplement or improve current processes. One industry that continues to benefit from artificial intelligence integration is healthcare. For years now, elements of artificial intelligence have been used to assist in clinical decision making, helping to identify potential health risks at earlier stages, and supplementing precision medicine. An area of healthcare that specifically looks at wearable devices, sensors, phone applications, and other such devices is mobile health (mHealth). These devices are used to aid in health data collection and delivery. This …


The Impact Of Domain Name Server (Dns) Over Hypertext Transfer Protocol Secure (Https) On Cyber Security: Limitations, Challenges, And Detection Techniques, Muhammad Dawood, Shanshan Tu, Chuangbai Xiao, Muhammad Haris, Hisham Alasmary, Muhammad Waqas, Sadaqat Ur Rehman Jan 2024

The Impact Of Domain Name Server (Dns) Over Hypertext Transfer Protocol Secure (Https) On Cyber Security: Limitations, Challenges, And Detection Techniques, Muhammad Dawood, Shanshan Tu, Chuangbai Xiao, Muhammad Haris, Hisham Alasmary, Muhammad Waqas, Sadaqat Ur Rehman

Research outputs 2022 to 2026

The DNS over HTTPS (Hypertext Transfer Protocol Secure) (DoH) is a new technology that encrypts DNS traffic, enhancing the privacy and security of end-users. However, the adoption of DoH is still facing several research challenges, such as ensuring security, compatibility, standardization, performance, privacy, and increasing user awareness. DoH significantly impacts network security, including better end-user privacy and security, challenges for network security professionals, increasing usage of encrypted malware communication, and difficulty adapting DNS-based security measures. Therefore, it is important to understand the impact of DoH on network security and develop new privacy-preserving techniques to allow the analysis of DoH traffic …


Applications Of Ai/Ml In Maritime Cyber Supply Chains, Rafael Diaz, Ricardo Ungo, Katie Smith, Lida Haghnegahdar, Bikash Singh, Tran Phuong Jan 2024

Applications Of Ai/Ml In Maritime Cyber Supply Chains, Rafael Diaz, Ricardo Ungo, Katie Smith, Lida Haghnegahdar, Bikash Singh, Tran Phuong

School of Cybersecurity Faculty Publications

Digital transformation is a new trend that describes enterprise efforts in transitioning manual and likely outdated processes and activities to digital formats dominated by the extensive use of Industry 4.0 elements, including the pervasive use of cyber-physical systems to increase efficiency, reduce waste, and increase responsiveness. A new domain that intersects supply chain management and cybersecurity emerges as many processes as possible of the enterprise require the convergence and synchronizing of resources and information flows in data-driven environments to support planning and execution activities. Protecting the information becomes imperative as big data flows must be parsed and translated into actions …


Pdf Malware Detection: Toward Machine Learning Modeling With Explainability Analysis, G. M.Sakhawat Hossain, Kaushik Deb, Helge Janicke, Iqbal H. Sarker Jan 2024

Pdf Malware Detection: Toward Machine Learning Modeling With Explainability Analysis, G. M.Sakhawat Hossain, Kaushik Deb, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

The Portable Document Format (PDF) is one of the most widely used file types, thus fraudsters insert harmful code into victims' PDF documents to compromise their equipment. Conventional solutions and identification techniques are often insufficient and may only partially prevent PDF malware because of their versatile character and excessive dependence on a certain typical feature set. The primary goal of this work is to detect PDF malware efficiently in order to alleviate the current difficulties. To accomplish the goal, we first develop a comprehensive dataset of 15958 PDF samples taking into account the non-malevolent, malicious, and evasive behaviors of the …


Using Feature Selection Enhancement To Evaluate Attack Detection In The Internet Of Things Environment, Khawlah Harahsheh, Rami Al-Naimat, Chung-Hao Chen Jan 2024

Using Feature Selection Enhancement To Evaluate Attack Detection In The Internet Of Things Environment, Khawlah Harahsheh, Rami Al-Naimat, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The rapid evolution of technology has given rise to a connected world where billions of devices interact seamlessly, forming what is known as the Internet of Things (IoT). While the IoT offers incredible convenience and efficiency, it presents a significant challenge to cybersecurity and is characterized by various power, capacity, and computational process limitations. Machine learning techniques, particularly those encompassing supervised classification techniques, offer a systematic approach to training models using labeled datasets. These techniques enable intrusion detection systems (IDSs) to discern patterns indicative of potential attacks amidst the vast amounts of IoT data. Our investigation delves into various aspects …


Deapsecure Computational Training For Cybersecurity: Progress Toward Widespread Community Adoption, Wirawan Purwanto, Bahador Dodge, Karina Arcaute, Masha Sosonkina, Hongyi Wu Jan 2024

Deapsecure Computational Training For Cybersecurity: Progress Toward Widespread Community Adoption, Wirawan Purwanto, Bahador Dodge, Karina Arcaute, Masha Sosonkina, Hongyi Wu

Electrical & Computer Engineering Faculty Publications

The Data-Enabled Advanced Computational Training Program for Cybersecurity Research and Education (DeapSECURE) is a non-degree training consisting of six modules covering a broad range of cyberinfrastructure techniques, including high performance computing, big data, machine learning and advanced cryptography, aimed at reducing the gap between current cybersecurity curricula and requirements needed for advanced research and industrial projects. Since 2020, these lesson modules have been updated and retooled to suit fully-online delivery. Hands-on activities were reformatted to accommodate self-paced learning. In this paper, we summarize the four years of the project comparing in-person and on-line only instruction methods as well as outlining …


Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen Jan 2024

Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The rapid proliferation of Internet of Things (IoT) devices has underscored the critical need for energy-efficient cybersecurity measures. This presents the dual challenge of maintaining robust security while minimizing power consumption. Thus, this paper proposes enhancing the machine learning performance through Ensemble Techniques with Sleep Mode Management (ELSM) approach for IoT Intrusion Detection Systems (IDS). The main challenge lies in the high-power consumption attributed to continuous monitoring in traditional IDS setups. ELSM addresses this challenge by introducing a sophisticated sleep-awake mechanism, activating the IDS system only during anomaly detection events, effectively minimizing energy expenditure during periods of normal network operation. …


Experimental Comparison Of Features, Analyses, And Classifiers For Android Malware Detection, Lwin Khin Shar, Biniam Fisseha Demissie, Mariano Ceccato, Naing Tun Yan, David Lo, Lingxiao Jiang, Christoph Bienert Sep 2023

Experimental Comparison Of Features, Analyses, And Classifiers For Android Malware Detection, Lwin Khin Shar, Biniam Fisseha Demissie, Mariano Ceccato, Naing Tun Yan, David Lo, Lingxiao Jiang, Christoph Bienert

Research Collection School Of Computing and Information Systems

Android malware detection has been an active area of research. In the past decade, several machine learning-based approaches based on different types of features that may characterize Android malware behaviors have been proposed. The usually-analyzed features include API usages and sequences at various abstraction levels (e.g., class and package), extracted using static or dynamic analysis. Additionally, features that characterize permission uses, native API calls and reflection have also been analyzed. Initial works used conventional classifiers such as Random Forest to learn on those features. In recent years, deep learning-based classifiers such as Recurrent Neural Network have been explored. Considering various …


On Phishing: Proposing A Host-Based Multi-Layer Passive/Active Anti-Phishing Approach Combating Counterfeit Websites, Wesam Harbi Fadheel Aug 2023

On Phishing: Proposing A Host-Based Multi-Layer Passive/Active Anti-Phishing Approach Combating Counterfeit Websites, Wesam Harbi Fadheel

Dissertations

Phishing is the starting point of most cyberattacks, mainly categorized as Email, Websites, Social Networks, Phone calls (Vishing), and SMS messaging (Smishing). Phishing refers to an attempt to collect sensitive data, typically in the form of usernames, passwords, credit card numbers, bank account information, etc., or other crucial facts, intending to use or sell the information obtained. Similar to how a fisherman uses bait to catch a fish, an attacker will pose as a trustworthy source to attract and deceive the victim.

This study explores the efficacy of host-side APT (Anti-Phishing Techniques) based onWebsite features like Lexical, Host-Based, or Content-Based …


Cyber Attack Surface Mapping For Offensive Security Testing, Douglas Everson Aug 2023

Cyber Attack Surface Mapping For Offensive Security Testing, Douglas Everson

All Dissertations

Security testing consists of automated processes, like Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST), as well as manual offensive security testing, like Penetration Testing and Red Teaming. This nonautomated testing is frequently time-constrained and difficult to scale. Previous literature suggests that most research is spent in support of improving fully automated processes or in finding specific vulnerabilities, with little time spent improving the interpretation of the scanned attack surface critical to nonautomated testing. In this work, agglomerative hierarchical clustering is used to compress the Internet-facing hosts of 13 representative companies as collected by the Shodan search …


Multi-Granularity Detector For Vulnerability Fixes, Truong Giang Nguyen, Cong, Thanh Le, Hong Jin Kang, Ratnadira Widyasari, Chengran Yang, Zhipeng Zhao, Bowen Xu, Jiayuan Zhou, Xin Xia, Ahmed E. Hassan, David Lo, David Lo Aug 2023

Multi-Granularity Detector For Vulnerability Fixes, Truong Giang Nguyen, Cong, Thanh Le, Hong Jin Kang, Ratnadira Widyasari, Chengran Yang, Zhipeng Zhao, Bowen Xu, Jiayuan Zhou, Xin Xia, Ahmed E. Hassan, David Lo, David Lo

Research Collection School Of Computing and Information Systems

With the increasing reliance on Open Source Software, users are exposed to third-party library vulnerabilities. Software Composition Analysis (SCA) tools have been created to alert users of such vulnerabilities. SCA requires the identification of vulnerability-fixing commits. Prior works have proposed methods that can automatically identify such vulnerability-fixing commits. However, identifying such commits is highly challenging, as only a very small minority of commits are vulnerability fixing. Moreover, code changes can be noisy and difficult to analyze. We observe that noise can occur at different levels of detail, making it challenging to detect vulnerability fixes accurately. To address these challenges and …


An Ml Based Digital Forensics Software For Triage Analysis Through Face Recognition, Gaurav Gogia, Parag H. Rughani Jul 2023

An Ml Based Digital Forensics Software For Triage Analysis Through Face Recognition, Gaurav Gogia, Parag H. Rughani

Journal of Digital Forensics, Security and Law

Since the past few years, the complexity and heterogeneity of digital crimes has increased exponentially, which has made the digital evidence & digital forensics paramount for both criminal investigation and civil litigation cases. Some of the routine digital forensic analysis tasks are cumbersome and can increase the number of pending cases especially when there is a shortage of domain experts. While the work is not very complex, the sheer scale can be taxing. With the current scenarios and future predictions, crimes are only going to become more complex and the precedent of collecting and examining digital evidence is only going …


An Empirical Study Of Pre-Trained Model Reuse In The Hugging Face Deep Learning Model Registry, Wenxin Jiang, Nicholas Synovic, Matt Hyattt, Taylor R. Schorlemmer, Rohan Sethi, Yung-Hisang Lu, George K. Thiruvathukal, James C. Davis May 2023

An Empirical Study Of Pre-Trained Model Reuse In The Hugging Face Deep Learning Model Registry, Wenxin Jiang, Nicholas Synovic, Matt Hyattt, Taylor R. Schorlemmer, Rohan Sethi, Yung-Hisang Lu, George K. Thiruvathukal, James C. Davis

Computer Science: Faculty Publications and Other Works

Deep Neural Networks (DNNs) are being adopted as components in software systems. Creating and specializing DNNs from scratch has grown increasingly difficult as state-of-the-art architectures grow more complex. Following the path of traditional software engineering, machine learning engineers have begun to reuse large-scale pre-trained models (PTMs) and fine-tune these models for downstream tasks. Prior works have studied reuse practices for traditional software packages to guide software engineers towards better package maintenance and dependency management. We lack a similar foundation of knowledge to guide behaviors in pre-trained model ecosystems.


In this work, we present the first empirical investigation of PTM reuse. …


An Analysis Of Text-Based Machine Learning Models For Vulnerability Detection, Kollin Ryne Napier May 2023

An Analysis Of Text-Based Machine Learning Models For Vulnerability Detection, Kollin Ryne Napier

Theses and Dissertations

With an increase in complexity of software, developers rely more on reuse and dependencies in their source code via code snippets. As a result, it is becoming harder to identify and mitigate vulnerabilities. Although traditional analysis tools are still utilized, machine learning models are being adopted to expand efforts and combat such threats. Given the possibilities towards usage of such models, research in this area has introduced various approaches which vary in usability and prediction. In generalizing models to a more natural language approach, researchers have opted to train models on source code to identify existing and potential vulnerabilities. Exploratory …


Unlocking User Identity: A Study On Mouse Dynamics In Dual Gaming Environments For Continuous Authentication, Marcho Setiawan Handoko Jan 2023

Unlocking User Identity: A Study On Mouse Dynamics In Dual Gaming Environments For Continuous Authentication, Marcho Setiawan Handoko

All Graduate Theses, Dissertations, and Other Capstone Projects

With the surge in information management technology reliance and the looming presence of cyber threats, user authentication has become paramount in computer security. Traditional static or one-time authentication has its limitations, prompting the emergence of continuous authentication as a frontline approach for enhanced security. Continuous authentication taps into behavior-based metrics for ongoing user identity validation, predominantly utilizing machine learning techniques to continually model user behaviors. This study elucidates the potential of mouse movement dynamics as a key metric for continuous authentication. By examining mouse movement patterns across two contrasting gaming scenarios - the high-intensity "Team Fortress" and the low-intensity strategic …


A Survey And Evaluation Of Android-Based Malware Evasion Techniques And Detection Frameworks, Parvez Faruki, Rhati Bhan, Vinesh Jain, Sajal Bhatia, Nour El Madhoun, Rajendra Pamula Jan 2023

A Survey And Evaluation Of Android-Based Malware Evasion Techniques And Detection Frameworks, Parvez Faruki, Rhati Bhan, Vinesh Jain, Sajal Bhatia, Nour El Madhoun, Rajendra Pamula

School of Computer Science & Engineering Faculty Publications

Android platform security is an active area of research where malware detection techniques continuously evolve to identify novel malware and improve the timely and accurate detection of existing malware. Adversaries are constantly in charge of employing innovative techniques to avoid or prolong malware detection effectively. Past studies have shown that malware detection systems are susceptible to evasion attacks where adversaries can successfully bypass the existing security defenses and deliver the malware to the target system without being detected. The evolution of escape-resistant systems is an open research problem. This paper presents a detailed taxonomy and evaluation of Android-based malware evasion …