Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (988)
- Social and Behavioral Sciences (930)
- Law (809)
- Computer Engineering (742)
- Computer Law (728)
-
- Legal Studies (638)
- Forensic Science and Technology (617)
- Electrical and Computer Engineering (552)
- Business (486)
- Databases and Information Systems (394)
- Management Information Systems (333)
- Artificial Intelligence and Robotics (289)
- Technology and Innovation (279)
- OS and Networks (257)
- Sociology (251)
- Other Computer Sciences (237)
- Public Affairs, Public Policy and Public Administration (227)
- Software Engineering (223)
- Medicine and Health Sciences (159)
- Cybersecurity (143)
- Systems Architecture (139)
- Theory and Algorithms (135)
- Digital Communications and Networking (134)
- Education (124)
- Communication (119)
- Defense and Security Studies (119)
- Social Media (89)
- Institution
-
- Singapore Management University (1102)
- Embry-Riddle Aeronautical University (768)
- Edith Cowan University (532)
- Kennesaw State University (300)
- Old Dominion University (256)
-
- Air Force Institute of Technology (181)
- San Jose State University (117)
- Bridgewater State University (73)
- Clark University (71)
- University of New Haven (65)
- United Arab Emirates University (64)
- University of Arkansas, Fayetteville (59)
- City University of New York (CUNY) (55)
- Dakota State University (49)
- California State University, San Bernardino (34)
- Nova Southeastern University (33)
- Maurer School of Law: Indiana University (32)
- University for Business and Technology in Kosovo (30)
- University of Central Florida (24)
- University of South Alabama (23)
- University of Dayton (22)
- Franklin University (21)
- LSU New Orleans (21)
- University of Nebraska at Omaha (20)
- Wayne State University (20)
- California Polytechnic State University, San Luis Obispo (18)
- University of Kentucky (18)
- Florida Institute of Technology (17)
- Louisiana State University (16)
- Portland State University (16)
- Keyword
-
- Cybersecurity (317)
- Security (246)
- Privacy (163)
- Computer security (101)
- Digital forensics (89)
-
- Information security (89)
- Blockchain (88)
- Machine learning (82)
- Authentication (71)
- Cryptography (71)
- Cloud computing (68)
- Encryption (65)
- Data privacy (62)
- [RSTDPub] (54)
- Cyber security (53)
- Access control (50)
- Data protection (47)
- Network security (45)
- Malware (41)
- Machine Learning (39)
- Android (38)
- Artificial intelligence (38)
- Computer networks--Security measures (38)
- Cybercrime (38)
- Internet of Things (36)
- Deep learning (34)
- Digital Forensics (34)
- Intrusion detection (33)
- MPA (33)
- Forensics (31)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1051)
- Journal of Digital Forensics, Security and Law (536)
- Australian Information Security Management Conference (224)
- Theses and Dissertations (212)
- Annual ADFSL Conference on Digital Forensics, Security and Law (186)
-
- Journal of Cybersecurity Education, Research and Practice (171)
- Master's Projects (107)
- KSU Proceedings on Cybersecurity Education, Research and Practice (97)
- Cybersecurity Undergraduate Research Showcase (90)
- Research outputs 2022 to 2026 (84)
- International Journal of Cybersecurity Intelligence & Cybercrime (72)
- School of Professional Studies (71)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Australian Digital Forensics Conference (50)
- Theses (45)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
- Computer Science Faculty Publications (40)
- Masters Theses & Doctoral Dissertations (34)
- CCAC Theses and Dissertations (33)
- Graduate Theses and Dissertations (33)
- Articles by Maurer Faculty (31)
- Publications (29)
- Electronic Theses and Dissertations (25)
- UBT International Conference (24)
- VMASC Publications (24)
- Electrical & Computer Engineering Faculty Publications (23)
- Open Educational Resources (23)
- Faculty Publications (22)
- LSU New Orleans Theses and Dissertations (21)
- Publication Type
Articles 121 - 150 of 4669
Full-Text Articles in Information Security
Operationalizing Cyber-Routine Activities Theory For Senior Cybercrime Prevention: An Evaluation Of The Shield Training-The-Trainer Program, Kyung-Shick Choi, Insun Park, Mijin Kim, Ji Yae Bong
Operationalizing Cyber-Routine Activities Theory For Senior Cybercrime Prevention: An Evaluation Of The Shield Training-The-Trainer Program, Kyung-Shick Choi, Insun Park, Mijin Kim, Ji Yae Bong
International Journal of Cybersecurity Intelligence & Cybercrime
Older adults face growing risks of cyber-enabled fraud, yet scalable, evidence-based prevention programs remain limited. Guided by Cyber-Routine Activities Theory (Cyber-RAT), this study evaluates the pilot implementation of the Seniors Harnessing Internet Education for Lasting Defense (SHIELD) Training-the-Trainer program, designed to prepare law enforcement officers and community leaders to deliver cybercrime prevention education to older adults. A key innovation of SHIELD is its integration of interactive game-based simulations, which allow participants to practice verification, refusal, and reporting behaviors in realistic cybercrime scenarios. Following the December 2025 pilot session in Boston, semi-structured interviews were conducted with 12 participants from law enforcement, …
From Authorization To Loss: A Blockchain Forensic Analysis Of Transaction-Level Mechanisms In Cryptocurrency Airdrop Scams, Chanwoo Shin, Kyung-Shick Choi
From Authorization To Loss: A Blockchain Forensic Analysis Of Transaction-Level Mechanisms In Cryptocurrency Airdrop Scams, Chanwoo Shin, Kyung-Shick Choi
International Journal of Cybersecurity Intelligence & Cybercrime
Cryptocurrency airdrop scams have emerged as a rapidly growing form of cyber-enabled financial crime, yet remain underexplored in empirical research. This study examines how transaction-level mechanisms and offender strategies influence variation in monetary loss in airdrop scam incidents. Grounded in Cyber-Routine Activities Theory (Cyber-RAT), the study conceptualizes financial harm as occurring within decentralized environments where users’ online behaviors, particularly transaction authorization, intersect with limited digital capable guardianship. Data were drawn from 112 validated airdrop scam cases reported on Chainabuse.com between January and December 2025. Blockchain forensic analysis using Breadcrumbs was conducted to reconstruct transaction pathways, identify exchange interactions, and detect …
The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade
The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade
Journal of Cybersecurity Education, Research and Practice
SourceURL:file:///home/amaechi/Documents/ *Journal of Cybersecurity Education, Research and Practice (JCERP)*. **Title:** The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches to Teach Foundational Cybersecurity Failures.docx
Background: Between March and April 2026, a single threat actor allegedly compromised four Nigerian institutions across banking, payment infrastructure, government registry, and power distribution sectors. The breaches exposed millions of records and disrupted critical services, yet all four exploited elementary vulnerabilities taught in introductory cybersecurity courses. Objective: This pedagogical case study analyzes the four breaches as a unified phenomenon of "normalized negligence" and provides ready-to-use teaching materials for cybersecurity educators. Methods: Using open-source intelligence analysis of …
Potent But Stealthy: Rethink Profile Pollution Against Sequential Recommendation Via Bi-Level Constrained Reinforcement Paradigm, Jiajie Su, Zihan Nan, Yunshan Ma, Xiaobo Xia, Xiaohua Feng, Weiming Liu, Xiang Chen, Xiaolin Zheng, Chaochao Chen
Potent But Stealthy: Rethink Profile Pollution Against Sequential Recommendation Via Bi-Level Constrained Reinforcement Paradigm, Jiajie Su, Zihan Nan, Yunshan Ma, Xiaobo Xia, Xiaohua Feng, Weiming Liu, Xiang Chen, Xiaolin Zheng, Chaochao Chen
Research Collection School Of Computing and Information Systems
Sequential Recommenders, which exploit dynamic user intents through interaction sequences, are vulnerable to adversarial attacks. While existing attacks primarily rely on data poisoning, they require large-scale user access or fake profiles, thus lacking practicality. In this paper, we focus on the Profile Pollution Attack that subtly contaminates partial user interactions to induce targeted mispredictions. Previous PPA methods suffer from two limitations, i.e., i) overreliance on sequence horizon impact restricts fine-grained perturbations on item transitions, and ii) holistic modifications cause detectable distribution shifts. To address these challenges, we propose a constrained reinforcement driven attack CREAT that synergizes a bi-level optimization framework …
Security-Enhanced Decentralized Conditional Privacy-Preserving Authentication In Vanets, Suqin Luo, Xinghua Li, Yinbin Miao, Xuelin Cao, Zhan Zhang, Yunwei Wang, Deng R.H.
Security-Enhanced Decentralized Conditional Privacy-Preserving Authentication In Vanets, Suqin Luo, Xinghua Li, Yinbin Miao, Xuelin Cao, Zhan Zhang, Yunwei Wang, Deng R.H.
Research Collection School Of Computing and Information Systems
To ensure the legitimacy of communicators while ad dressing the privacy concerns of vehicles in vehicular ad-hoc networks (VANETs), conditional privacy-preserving authentication (CPPA) schemes have been proposed. Given that existing schemes suffer from single point of failure due to centralized authorities, several distributed CPPA schemes have been proposed. However, these schemes all ignore the tight cementation between system secret keys and the authority, which could be a serious threat to system security, that the compromised authority may leak the system secret key. To address these issues, we propose a security enhanced decentralized conditional privacy-preserving authentication (DCPPA) scheme. DCPPA first introduces …
Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias
Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias
Electrical & Computer Engineering Faculty Publications
This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.
The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …
A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz
A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz
Graduate Studies Theses and Dissertations 2026
Software applications increasingly rely on user data to provide their functionality, but improper handling of such data can lead to serious privacy noncompliance with applicable regulations and policies. A prominent example is the Facebook–Cambridge Analytica scandal, in which a third-party application collected the personal data of approximately 87 million Facebook users without users' consent. Despite growing attention to privacy compliance, two key challenges hinder the systematic understanding and analysis of privacy noncompliance. First, unlike security vulnerabilities, which have been systematically categorized through taxonomies such as the Common Weakness Enumeration (CWE), privacy noncompliance lacks a technical taxonomy describing how it manifests …
Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi
Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi
Theses, Dissertations and Capstones
The rapid expansion of the Internet of Things (IoT) has transformed modern computing by enabling seamless connectivity among heterogeneous devices across diverse application domains. However, this increased interconnectivity has significantly enlarged the attack surface of IoT networks, exposing them to a wide range of sophisticated cyber threats. Conventional security mechanisms often lack the capability to detect emerging attacks in real time, thereby necessitating the development of intelligent Intrusion Detection Systems (IDS) capable of accurately identifying malicious network activities. This study developed and evaluated a machine learning-based intrusion detection framework for multiclass IoT attack detection using the RT-IoT2022 dataset. The dataset …
Cybercrime, Vulnerability And Digital Guardianship: Opportunity Structures And Prevention In A Changing Online Landscape, Mike Toro-Alvarez, Amy Lim
Cybercrime, Vulnerability And Digital Guardianship: Opportunity Structures And Prevention In A Changing Online Landscape, Mike Toro-Alvarez, Amy Lim
International Journal of Cybersecurity Intelligence & Cybercrime
No abstract provided.
Analyzing Modern Scam Typologies: From Pig-Butchering And Nigerian Advance-Fee Fraud To Crypto Airdrop Schemes, Katalin Parti, Sinyong Choi, Thomas Dearden
Analyzing Modern Scam Typologies: From Pig-Butchering And Nigerian Advance-Fee Fraud To Crypto Airdrop Schemes, Katalin Parti, Sinyong Choi, Thomas Dearden
International Journal of Cybersecurity Intelligence & Cybercrime
Rapid advancements in digital infrastructure and decentralized networks have fundamentally altered the nature of contemporary cybercrime, making comprehensive empirical and technical analysis more crucial than ever. To address these challenges, this editorial summarizes the research contributions featured in this issue of the International Jour nal of Cybersecurity Intelligence and Cybercrime. The included papers examine the structural on-chain dynamics of sanctioned pig-butchering operations, the representational production and AI-driven evolution of the “Nigerian scam” label, the critical transaction-authorization factors driving losses in crypto airdrop schemes, and the optimization of sentence-transformer models for automated Host Intrusion Detection System (HIDS) alert enrichment. Together, these …
Three-Tier On-Chain Transaction Architecture In A Sanctions-Linked Pig-Butchering Network: A Blockchain-Forensics Case Study, Matthew Stern, Kyung-Shick Choi
Three-Tier On-Chain Transaction Architecture In A Sanctions-Linked Pig-Butchering Network: A Blockchain-Forensics Case Study, Matthew Stern, Kyung-Shick Choi
International Journal of Cybersecurity Intelligence & Cybercrime
n October 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 29 Bitcoin addresses asso ciated with the Prince Group and Chen Zhi, providing an opportunity to examine the internal on-chain structure of a sanctions-linked pig-butchering network. This blockchain-forensics case study analyzes the group of 29 addresses using blockchain tracing, cross-plat form attribution checks across multiple commercial analytics platforms, exposure screening, and thematic analysis of transaction be havior. Because the case rests on OFAC designations and DOJ allegations, the traced flows are interpreted as patterns consistent with suspected laundering rather than adjudicated crimes; no fiat …
Attribution Post ‘Aura’ Loss: A Qualitative Discourse Analysis Of The Nigerian Scam Label And Fraud Attribution, Emaediong Akpan
Attribution Post ‘Aura’ Loss: A Qualitative Discourse Analysis Of The Nigerian Scam Label And Fraud Attribution, Emaediong Akpan
International Journal of Cybersecurity Intelligence & Cybercrime
In this essay, I employ qualitative discourse analysis of eleven purposively selected literature to examine how “Nigerian scam” became an established yet detached signifier of advance-fee fraud in global discourse. I do not treat this association as a reflection of offender identity or national inclination. Instead, the analysis traces how attribution is produced through representational repetition, institu tional uptake, and the circulation of familiar narrative cues. Using qualitative discourse analysis and an interpretive approach, this paper distinguishes among the socio-technical conditions that enable fraud, the institutional processes that stabilize attribution, and the semiotic dynamics through which national categories acquire durability. …
Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation, Matthew Ragsdale
Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation, Matthew Ragsdale
College of Graduate Studies: Theses & Dissertations
The convergence of artificial intelligence and cybersecurity presents new opportunities for automated penetration testing capable of discovering, prioritizing, and remediating vulnerabilities at machine speed. However, deployment on resource-constrained ARM platforms remains unexplored despite ARM’s dominance in mobile, IoT, and edge computing with over 280 billion chips deployed globally. This thesis presents systematic experimental evaluation of AI-driven penetration testing across four paradigms—traditional machine learning, deep learning, large language models, and reinforcement learning—on three ARM platform tiers: Raspberry Pi 5 (8GB, Cortex-A76), Radxa ROCK 5B Plus (16GB LPDDR5 with NPU), and NVIDIA Jetson Nano (4GB with Maxwell GPU). The experimental framework generates …
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
American University Business Law Review
[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through …
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar
UNF Graduate Theses and Dissertations
The Narrowband Internet of Things (NB-IoT) continues to expand but faces challenges such as cryptographic overhead and energy consumption. Security frameworks such as blockchain and Energy-Performance Cumulative Message Authentication Codes (EP-CuMAC) rely heavily on SHA-256, which is not optimized for energy-limited devices.
This work unifies two complementary approaches, a hybrid blockchain-based NB-IoT framework and an EP-CuMAC-based framework, by engineering their cryptographic core with an Energy Complexity Model-optimized SHA-256 (ECM-SHA256). ECM applies parallel memory-bank mapping and block-level access optimization to reduce redundant power usage while preserving algorithmic integrity.
Experimental evaluation on identical Intel DDR3 systems using pyRAPL shows energy savings of …
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li
Computer Science Faculty Publications
Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …
Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala
Exploring Large Language Models For Trustworthy Use: Insights From Research And Development, Sandeep Kalari, Sahithi Padidela, Vikas Ashok, Ravi Mukkamala
Computer Science Faculty Publications
Large Language Models (LLMs) are increasingly being adopted in a wide variety of domains, including sensitive domains such as healthcare and finance. However, persistent challenges such as unreliable data sources, privacy breaches, and hallucinated output continue to hinder their usage. We have experimented with several strategies to address these challenges. First, we developed BlockQwen, a blockchain-augmented framework that integrates decentralized trust validation, role-specific access control, and verifiable audit trails into the Qwen 2.5 LLM workflow. Second, we developed PrivAware, a multilayered privacy-enforcement framework, using a fine-tuned Flan-T5 model with self-attention masking, to safeguard data while maintaining high utility. Both systems …
Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge
Privacy-Preserving Federated Learning With Optimized Ensemble Weighting And Knowledge Distillation For Covid-19 Detection From Non-Iid Medical Imaging Data, Richard Annan, Hong Qin, Robert Newman, Madhuri Siddula, Letu Qingge
Computer Science Faculty Publications
Medical imaging enables rapid and accurate diagnosis of COVID-19, with CT scans proving especially effective. However, data privacy concerns limit collaborative model development across hospitals. To address this issue, we introduce a novel federated learning framework. It is referred to as Independent Knowledge Distillation with post-Ensemble Federated Learning (IKDEFL). Differential Privacy (DP) is integrated into the framework to improve privacy guarantees. Three DP mechanisms are evaluated. These include Fixed Gaussian, Gaussian Adaptive, and Tree Adaptive. The evaluation has been conducted on heterogeneous and Non-Independent and Identically Distributed (Non-IID) datasets. These datasets reflect real-world hospital scenarios. Results show that IKDEFL significantly …
An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana
An Investigation Of Federated Gnns Under Aggregation, Data Poisoning, And Differential Privacy For Icu Length-Of-Stay Prediction, Shakib Mahmud Dipto, Soumya Banerjee, Sandip Roy, Ahmad F. Al Musawi, Preetam Ghosh, Sachin Shetty, Pratip Rana
Computer Science Faculty Publications
Accurate prediction of ICU Length of Stay (LoS) is essential for clinical decision-making and healthcare resource management. Graph Neural Networks (GNNs), such as GraphSAGE, offer a natural fit by capturing patient data from Electronic Health Records (EHRs) through graph structures. However, the distributed and sensitive nature of this data raises both privacy and legal concerns regarding the aggregation and training of GNN models. This additionally leads to issues with data imbalance and model robustness. In this study, we perform an analysis of the Federated Graph Neural Network (GNN-FL) framework to enable decentralized learning on EHRs derived from the MIMIC-III dataset. …
Benchmarking Gaslighting Negation Attacks Against Reasoning Models, Bin Zhu, Hailong Yin, Jingjing Chen, Yu Gang Jiang
Benchmarking Gaslighting Negation Attacks Against Reasoning Models, Bin Zhu, Hailong Yin, Jingjing Chen, Yu Gang Jiang
Research Collection School Of Computing and Information Systems
Recent advances in reasoning-centric models promise improved robustness through mechanisms such as chain-of-thought prompting and test-time scaling. However, their ability to withstand gaslighting negation attacks—adversarial prompts that confidently deny correct answers—remains underexplored. In this paper, we conduct a systematic evaluation of three state-of-the-art reasoning models, i.e., OpenAI’s o4-mini, Claude-3.7-Sonnet and Gemini-2.5-Flash, across three multimodal benchmarks: MMMU, MathVista, and CharXiv. Our evaluation reveals significant accuracy drops (25–29% on average) following gaslighting negation attacks, indicating that even top-tier reasoning models struggle to preserve correct answers under manipulative user feedback. Built upon the insights of the evaluation and to further probe this vulnerability, …
Airaclex: Automated Detection Of Price Oracle Manipulations Via Llm-Driven Knowledge Mining And Prompt Generation, Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu, Rick Siow Mong Goh, David Lo
Airaclex: Automated Detection Of Price Oracle Manipulations Via Llm-Driven Knowledge Mining And Prompt Generation, Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu, Rick Siow Mong Goh, David Lo
Research Collection School Of Computing and Information Systems
Decentralized finance (DeFi) applications depend on accurate price oracles to ensure secure and fair transactions. However, poorly integrated oracles remain susceptible to manipulation, enabling attackers to exploit smart contract logic for unfair asset valuation and financial gain. While many such vulnerabilities are only detected after deployment, smart contracts are typically immutable once deployed, making post-hoc fixes costly or infeasible. This highlights the critical need for detecting oracle manipulation risks before deployment. In this paper, we propose AiRacleX, a novel LLM-driven framework that enables pre-deployment detection of price oracle manipulation vulnerabilities by leveraging the complementary strengths of multiple large language models …
An Investigation Into The Mechanisms, Barriers, Degree And Sphere Of Risk Influence In Corporate Security, Nicola Lockhart
An Investigation Into The Mechanisms, Barriers, Degree And Sphere Of Risk Influence In Corporate Security, Nicola Lockhart
Theses: Doctorates and Masters
This study investigates the sphere of corporate security risk influence within organisations, addressing the conceptual and practical ambiguity surrounding the activity’s capacity to shape organisational decisions, behaviours, and risk priorities. While corporate security’s protective role is widely recognised, its broader organisational risk influence remains under-theorised. The study defines the sphere of risk influence as the range of organisational stakeholders and environments with which the corporate security activity interacts, and within which it may engage, persuade, and mobilise action. This sphere is analytically constituted through the intersection of three dimensions: the mechanisms through which influence is attempted, the barriers that constrain …
Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim
Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim
Graduate Studies Theses and Dissertations 2026
Cyber-physical systems execute physical actions in response to software commands, making their communication protocols a primary attack surface. A stealthy attack is a sequence of individually valid messages that violates a required ordering, driving the system into an unsafe state without malware or protocol violation. Existing defenses examine messages or physical state in isolation, not protocol level sequences, and cannot prevent them. Preventing them requires enforcement that makes unsafe sequences unexecutable at the communication boundary.
Formal methods offer a principled path to enforcement, but no tool spans specification to safe deployed hardware. Model checking automates proofs but has no certified …
Advancing Cybersecurity Practice: Explainable Machine Learning For Network Intrusion Detection, Adam Grabowski, Shengjie Xu
Advancing Cybersecurity Practice: Explainable Machine Learning For Network Intrusion Detection, Adam Grabowski, Shengjie Xu
Journal of Cybersecurity Education, Research and Practice
This research investigates explainable artificial intelligence (XAI) integration within machine learning (ML)-based intrusion detection systems (IDS), focusing on distinguishing malicious from benign network activities. We employed Random Forest and XGBoost models evaluated on widely recognized datasets, including NSL-KDD and UNSW-NB15, using both binary and multi-class classification tasks. The objective was to enhance cybersecurity operations through improved model transparency and interpretability. By integrating SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-Agnostic Explanations), the study offers comprehensive global and local insights into model decision-making processes. Results demonstrate SHAP's effectiveness in providing a broad, dataset-wide understanding of feature interactions and importance, while …
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students, Jose R. Ortiz Ubarri, Kariluz Dávila Diaz Ph.D., Rafael A. Arce Nazario
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students, Jose R. Ortiz Ubarri, Kariluz Dávila Diaz Ph.D., Rafael A. Arce Nazario
Journal of Cybersecurity Education, Research and Practice
The Cybercamp is a Cybersecurity summer camp for high school students that has been held for the last nine years at a Hispanic Serving Institution. Since its inception in 2016 the Cybercamp has undergone several transformations in response to budget reductions and the COVID pandemic, to finally become its current version: a rich, hands-on learning experience that we believe is easily replicable even in resource-challenged environments.
In this paper, we document the transformations of the Cybercamp and discuss the developed curriculum and materials in hopes that others will reuse, adapt, and improve upon them. In the Cybercamp, we apply active …
Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson
Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson
Cybersecurity Undergraduate Research Showcase
This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …
Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz
Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz
Other Faculty Materials
Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible …
Zero Day Malware Detection With Alpha: Fast Dbi With Transformer Models For Real World Application, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke
Zero Day Malware Detection With Alpha: Fast Dbi With Transformer Models For Real World Application, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke
Research outputs 2022 to 2026
The effectiveness of an AI model in accurately classifying novel malware hinges on the quality of the features it is trained on, which in turn depends on the effectiveness of the analysis tool used. Peekaboo, a Dynamic Binary Instrumentation (DBI) tool, defeats malware evasion techniques to capture authentic behavior at the Assembly (ASM) instruction level. This behavior exhibits patterns consistent with Zipf's law, a distribution commonly seen in natural languages, making Transformer models particularly effective for binary classification tasks. We introduce Alpha, a framework for zero-day malware detection that leverages Transformer models, Support Vector Machines (SVMs) and ASM language features. …
Defeating Evasive Malware With Peekaboo: Extracting Authentic Malware Behavior With Dynamic Binary Instrumentation, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke
Defeating Evasive Malware With Peekaboo: Extracting Authentic Malware Behavior With Dynamic Binary Instrumentation, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke
Research outputs 2022 to 2026
The accuracy of Artificial Intelligence (AI) in malware detection is dependent on the features it is trained with, where the quality and authenticity of these features is dependent on the dataset and the analysis tool. Evasive malware, that alters its behavior in analysis environments, is challenging to extract authentic features from where widely used static and dynamic analysis tools have several limitations. However, Dynamic Binary Instrumentation (DBI) allows deep and precise control of the malware sample, thereby facilitating the extraction of authentic behavior from evasive malware. Considering the limitations of malware analysis for use with AI, this research had two …
Proverag: Provenance-Driven Vulnerability Analysis With Automated Retrieval-Augmented Llms, Reza Fayyazi, Stella Hoyos Trueba, Michael Zuzak, Jay Yang
Proverag: Provenance-Driven Vulnerability Analysis With Automated Retrieval-Augmented Llms, Reza Fayyazi, Stella Hoyos Trueba, Michael Zuzak, Jay Yang
Institute for Informatics and Applied Technology Scholarship
In cybersecurity, security analysts constantly face the challenge of mitigating newly discovered vulnerabilities in real-time, with over 300,000 vulnerabilities identified since 1999. The sheer volume of known vulnerabilities complicates the detection of patterns for unknown threats. While LLMs can assist, they often hallucinate and lack alignment with recent threats. Over 40,000 vulnerabilities have been identified in 2024 alone, which are introduced after most popular LLMs’ (e.g., GPT-5) training data cutoff. This raises a major challenge of leveraging LLMs in cybersecurity, where accuracy and up-to-date information are paramount. Therefore, we aim to improve the adaptation of LLMs in vulnerability analysis by …