Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 331 - 360 of 4669

Full-Text Articles in Information Security

Attribute-Based Encryption With Searchable Encryption, Yang Yang Jan 2025

Attribute-Based Encryption With Searchable Encryption, Yang Yang

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) with searchable encryption is a notion that inherits the advantages of both ABE (Goyal et al., 2006) and searchable encryption (SE) (Boneh et al., 2004; Boneh and Waters, 2007) mechanisms to realize secure share and search for the outsourced data. ABE creates fine-grained access control system to prevent sensitive data from being accessed by unauthorized user or external attacker (Bethencourt et al., 2007). SE generates encrypted index for outsourced data such that it can be searched by a keyword trapdoor (or token) (Shi et al., 2007; Naveed et al., 2014), where the outsourced content and search keyword(s) …


Including Individuals' Sense Of Self In Digital Information Privacy, Peter N. Meso, Solomon Negash, Humayun Zafar, Gurpreet Dhillon Jan 2025

Including Individuals' Sense Of Self In Digital Information Privacy, Peter N. Meso, Solomon Negash, Humayun Zafar, Gurpreet Dhillon

Faculty Articles

The nature of contemporary digital ecosystems causes concerns that affect the person, the individual-self, an integral part of an individual’s information privacy calculus and hence a component of individuals’ Information Privacy Concerns (IPC). Yet, prior IPC models overlook self-focused concerns. This study articulates two constructs, termed “loss of autonomy” (i.e., autonomy) and “control over profiling” (i.e., profiling), that reflect individuals’ self-focused privacy concerns. Combining these new constructs with conventional IPC constructs that capture data-focused and device-focused concerns yields an IPC model made up of three dimensions: self-focused concerns, data-focused concerns, and device-focused concerns. The authors first develop instrument items for …


Navigating The Digital Frontier: New Perspectives On Cybercrime And Governance, Christopher S. Kayser, Thomas Dearden, Katalin Parti, Sinyong Choi Jan 2025

Navigating The Digital Frontier: New Perspectives On Cybercrime And Governance, Christopher S. Kayser, Thomas Dearden, Katalin Parti, Sinyong Choi

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


Modus Operandi And Blockchain Analysis Of Romance Scams: Cryptocurrency-Driven Victimization, Amy Lim, Kyung-Shick Choi Jan 2025

Modus Operandi And Blockchain Analysis Of Romance Scams: Cryptocurrency-Driven Victimization, Amy Lim, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


The Legal Response To The Intrusion Into Digital Identity In Social Media, Maria González-García Vinuela Jan 2025

The Legal Response To The Intrusion Into Digital Identity In Social Media, Maria González-García Vinuela

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


A Study Of Pattern Of Cybercrime Abuse Of Individual Internet Users In Umuahia North Lga, Abia State Of South-Eastern Nigeria, Ogochukwu Favour Nzeakor, Rita Ngozi Okafor, Chibuike Ndubuisi Nwoke Jan 2025

A Study Of Pattern Of Cybercrime Abuse Of Individual Internet Users In Umuahia North Lga, Abia State Of South-Eastern Nigeria, Ogochukwu Favour Nzeakor, Rita Ngozi Okafor, Chibuike Ndubuisi Nwoke

International Journal of Cybersecurity Intelligence & Cybercrime

Although a number of studies exist on cybercrime and its abuses, little is known about the pattern of cybercrime abuses individual Internet users experience in Nigeria, especially the south eastern region. Using data collected via various methods, this study examines the pattern of cybercrime abuses of individual Internet users in Umuahia, Abia State, of South Eastern Nigeria. The result of the analysis of 1,067 samples drawn from 223,134 Internet users in Umuahia North LGA of Abia Sate showed that: while most users are victims of stolen ICT-gadgets (19%), fraud related offences (17%), and hacking (15%); they rarely fall victims of …


Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen Jan 2025

Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …


Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas Jan 2025

Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas

Research outputs 2022 to 2026

Border Gateway Protocol (BGP), as the standard inter-domain routing protocol, is a distance-vector dynamic routing protocol used for exchanging routing information between distributed Autonomous Systems (AS). BGP nodes, communicating in a distributed dynamic environment, face several security challenges, with trust being one of the most important issues in inter-domain routing. Existing research, which performs trust evaluation when exchanging routing information to suppress malicious routing behavior, cannot meet the scalability requirements of BGP nodes. In this paper, we propose a blockchain-based trust model for inter-domain routing. Our model achieves scalability by allowing the master node of an AS alliance to transmit …


Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad Jan 2025

Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad

Research outputs 2022 to 2026

Cybersecurity plays a critical role in today’s modern human society, and leveraging knowledge graphs can enhance cybersecurity and privacy in the cyberspace. By harnessing the heterogeneous and vast amount of information on potential attacks, organizations can improve their ability to proactively detect and mitigate any threat or damage to their online valuable resources. Integrating critical cyberattack information into a knowledge graph offers a significant boost to cybersecurity, safeguarding cyberspace from malicious activities. This information can be obtained from structured and unstructured data, with a particular focus on extracting valuable insights from unstructured text through natural language processing (NLP). By storing …


Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu Jan 2025

Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu

Computer Science Faculty Publications

Private inference applies cryptographic techniques like homomorphic encryption, garble circuit and secret sharing to keep both sides privacy in a client-server setting during inference. It is often hindered by the high communication overheads, especially at non-linear activation layers such as ReLU. Hence ReLU pruning has been widely recognized as an efficient way to accelerate private inference. Existing approaches to ReLU pruning typically rely on coarse hypothesis, which assume an inverse correlation between the importance of ReLU and linear layers or shallow activation layers have less importance for universal models, to assign the budgets according to the layer while preserving the …


Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson Jan 2025

Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson

Computer Science Faculty Publications

URI redirections are integral to web management, supporting structural changes, SEO optimization, and security. However, their complexities affect usability, SEO performance, and digital preservation. This study analyzed 11 million unique redirecting URIs, following redirections up to 10 hops per URI, to uncover patterns and implications of redirection practices. Our findings revealed that 50% of the URIs terminated successfully, while 50% resulted in errors, including 0.06% exceeding 10 hops. Canonical redirects, such as HTTP to HTTPS transitions, were prevalent, reflecting adherence to SEO best practices. Non-canonical redirects, often involving domain or path changes, highlighted significant web migrations, rebranding, and security risks. …


Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff Jan 2025

Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff

Computer Science Faculty Publications

The meteoric rise of Artificial Intelligence (AI), with its rapidly expanding market capitalization, presents both transformative opportunities and critical challenges. Chief among these is the urgent need for a new, unified paradigm for trustworthy evaluation, as current benchmarks increasingly reveal critical vulnerabilities. Issues like data contamination and selective reporting by model developers fuel hype, while inadequate data quality control can lead to biased evaluations that, even if unintentionally, may favor specific approaches. As a flood of participants enters the AI space, this "Wild West" of assessment makes distinguishing genuine progress from exaggerated claims exceptionally difficult. Such ambiguity blurs scientific signals …


Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh Jan 2025

Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh

Computer Science Faculty Publications

Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …


Adversarially Attacking Graph Properties And Sparsification In Graph Learning, Chunjiang Zhu, Blake Gaines, Jing Deng, Jinbo Bi Jan 2025

Adversarially Attacking Graph Properties And Sparsification In Graph Learning, Chunjiang Zhu, Blake Gaines, Jing Deng, Jinbo Bi

Computer Science Faculty Publications

Graph neural networks and graph transformers explicitly or implicitly rely on fundamental properties of the underlying graph, such as spectral properties and shortest-path distances. However, it is still not clear how these graph properties are vulnerable to adversarial attacks and what impacts this has on the downstream graph learning. Moreover, while graph sparsification has been used to improve computational cost of learning over graphs, its susceptibility to adversarial attacks has not been studied. In this paper, we study adversarial attacks on graph properties and graph sparsification and their impacts on downstream graph learning, paving the way for how to protect …


Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li Jan 2025

Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li

Computer Science Faculty Publications

Large Language Models (LLMs) exhibit strong natural language processing capabilities but also pose significant privacy risks, particularly regarding the leakage of Personally Identifiable Information (PII) embedded in their training data. Existing PII extraction methods suffer from the limitations of low success rates or impracticality for large-scale PII extraction. In this study, we propose a novel PII extraction approach based on enhanced few-shot learning techniques, which achieves efficient and cost-effective PII retrieval without relying on fine-tuning or jailbreaking. We evaluated our approach on both open-source and closed-source LLMs. The experimental results demonstrate that, for non-targeted PII extraction, the attack success rate …


Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang Jan 2025

Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang

Computer Science Faculty Publications

Large Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved …


Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem Jan 2025

Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem

Theses: Doctorates and Masters

Machine learning has significantly transformed medical image analysis in the current age of artificial intelligence offering vast potential in improving disease diagnosis and management. Cardiovascular diseases (CVDs) are among the leading cause of global mortality, emphasizing the need for early detection for effective intervention and prevention. Abdominal Aortic Calcification (AAC) is an early indicator and contributor to Atherosclerotic Cardiovascular Diseases (ASCVDs) and is commonly assessed through imaging modalities such as computed tomography (CT), X-rays, and Dual-energy X-ray Absorptiometry (DXA). Among these, lateral spine DXA scans, commonly used for osteoporosis screening, offer a cost-effective and low-radiation opportunity for opportunistic CVD risk …


Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang Jan 2025

Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang

Electronic Theses & Dissertations (2024 - present)

The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.

The primary contribution of this study is methodology. We present a framework that remains …


Interactive Visualization Workflows For Mitigating Analytical Uncertainty, Kaustav Bhattacharjee Dec 2024

Interactive Visualization Workflows For Mitigating Analytical Uncertainty, Kaustav Bhattacharjee

Dissertations

This dissertation takes a process-centric and stakeholder-first perspective for handling analytical uncertainty: the form of uncertainty that confronts data analysts' insight-generation processes in high-consequence decision-making scenarios. The cost of an incorrect decision when data is used for movie recommendations as opposed to when personal data is used to drive insights or when data-driven modeling is used to drive real-time decisions for maintaining the health of a grid are vastly different in terms of consequences. This dissertation looks at analytical uncertainty in two real-world scenarios: i) how sensitive information leakage can be prevented during the open data release process with data …


Text-To-Text Generative Approach For Enhanced Complex Word Identification, Patrycja Śliwiak, Syed Afaq Ali Shah Dec 2024

Text-To-Text Generative Approach For Enhanced Complex Word Identification, Patrycja Śliwiak, Syed Afaq Ali Shah

Research outputs 2022 to 2026

This paper presents a novel approach for solving the Complex Word Identification (CWI) task using the text-to-text generative model. The CWI task involves identifying complex words in text, which is a challenging Natural Language Processing task. To our knowledge, it is a first attempt to address CWI problem into text-to-text context. In this work, we propose a new methodology that leverages the power of the Transformer model to evaluate complexity of words in binary and probabilistic settings. We also propose a novel CWI dataset, which consists of 62,200 phrases, both complex and simple. We train and fine-tune our proposed model …


Digital Twin And Cybersecurity In Additive Manufacturing, Lidong Wang Dec 2024

Digital Twin And Cybersecurity In Additive Manufacturing, Lidong Wang

Journal of Cybersecurity Education, Research and Practice

Additive manufacturing (AM) has been applied to automotive, aerospace, medical sectors, etc., but there are still challenges such as parts’ porosity, cracks, surface roughness, intrinsic anisotropy, and residual stress because of the high level of thermal gradient. It is significant to conduct the modeling and simulation of the AM process and achieve quality products. Digital Twin (DT) can help AM with forecasting defects/errors through simulation and real-time process monitoring. DT is a concept of Industry 4.0, and its digital structure reflects the real-time behaviors of a cyber-physical or physical system. This paper introduces the progress of DT applications in AM, …


Enhancing Cybersecurity Strategies Through Automated Cti Extraction, Risk Prioritization, And Privacy-Conscious Information Sharing, Spencer Rian Massengale Dec 2024

Enhancing Cybersecurity Strategies Through Automated Cti Extraction, Risk Prioritization, And Privacy-Conscious Information Sharing, Spencer Rian Massengale

Theses and Dissertations

Cybersecurity operations require the ability to collect and analyze large amounts of cyber threat intelligence (CTI) to assess risks and formulate defensive strategies against emerging threats. This task has become increasingly complex due to the rapid evolution of cyber threats and the growing volume of unstructured, natural-language CTI sources. The scale of data and analysis needed to utilize CTI effectively far exceeds humans' manual capacity, especially for organizations with limited resources. This research focuses on leveraging Large Language Models (LLMs) and machine learning techniques to enhance CTI extraction, risk assessment, and data sharing. We utilized LLMs to automate the extraction …


The Impact Of Student Engagement Activities On Future Climate Change Adaptation: The Case Of Student Simulation Models, Bassel Mostafa Elkalaf Dec 2024

The Impact Of Student Engagement Activities On Future Climate Change Adaptation: The Case Of Student Simulation Models, Bassel Mostafa Elkalaf

Future Journal of Social Science

This paper explores the critical role of student engagement in addressing the growing challenges of climate change, with a focus on the Model United Nations (MUN) as a case study. As climate-related security threats increase globally, educational platforms that prepare youth for effective leadership in climate politics are more essential than ever. MUN, a widely practiced student activity simulating global policy-making, provides a valuable opportunity for students to deepen their understanding of the interconnectedness between climate change, peace, and security. By participating in MUN simulations, students engage in debates, develop innovative solutions, and practice diplomatic skills, all while exploring the …


Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono Dec 2024

Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono

Research & Publications

Insider threats (InTs) within organizations are small in number but have a disproportionate ability to damage systems, information, and infrastructure. Existing InT research studies the problem from psychological, technical, and educational perspectives. Proposed theories include research on psychological indicators, machine learning, user behavioral log analysis, and educational methods to teach employees recognition and mitigation techniques. Because InTs are a human problem, training methods that address InT detection from a behavioral perspective are critical. While numerous technological and psychological theories exist on detection, prevention, and mitigation, few training methods prioritize psychological indicators. This literature review studied peer-reviewed, InT research organized by …


Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang Dec 2024

Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang

Research & Publications

The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …


Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings Dec 2024

Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings

Research & Publications

This paper presents a multi-cloud networking architecture built on zero trust principles and micro-segmentation to provide secure connectivity with authentication, authorization, and encryption in transit. The proposed design includes the multi-cloud network to support a wide range of applications and workload use cases, compute resources including containers, virtual machines, and cloud-native services, including IaaS (Infrastructure as a Service), PaaS (Platform as a service). Furthermore, open-source tools provide flexibility, agility, and independence from locking to one vendor technology. The paper provides a secure architecture with micro-segmentation and follows zero trust principles to solve multi-fold security and operational challenges.


Forward And Backward Private Searchable Encryption For Cloud-Assisted Industrial Iot, Tianqi Peng, Bei Gong, Shanshan Tu, Abdallah Namoun, Sami Alshmrany, Muhammad Waqas, Hisham Alasmary, Sheng Chen Dec 2024

Forward And Backward Private Searchable Encryption For Cloud-Assisted Industrial Iot, Tianqi Peng, Bei Gong, Shanshan Tu, Abdallah Namoun, Sami Alshmrany, Muhammad Waqas, Hisham Alasmary, Sheng Chen

Research outputs 2022 to 2026

In the cloud-assisted industrial Internet of Things (IIoT), since the cloud server is not always trusted, the leakage of data privacy becomes a critical problem. Dynamic symmetric searchable encryption (DSSE) allows for the secure retrieval of outsourced data stored on cloud servers while ensuring data privacy. Forward privacy and backward privacy are necessary security requirements for DSSE. However, most existing schemes either trade the server’s large storage overhead for forward privacy or trade efficiency/overhead for weak backward privacy. These schemes cannot fully meet the security requirements of cloud-assisted IIoT systems. We propose a fast and firmly secure SSE scheme called …


Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise Dec 2024

Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise

LSU New Orleans Theses and Dissertations

In the digital age, text-based passwords remain a primary method for securing online accounts. Yet, users frequently face a dilemma between creating passwords that are easy to remember and sufficiently secure against cyberattacks. This research introduces an approach to password generation that bridges this gap by utilizing linguistic patterns, particularly song lyrics, to develop highly secure and naturally memorable passwords. Using large lyric datasets gained from web scrapes from popular song lyric websites (AZ Lyrics, Genius), features are extracted from a corpus of over 5 million lyrics using sentence structure and natural language processing in a novel way. In using …


Gotcha ! This Model Uses My Code ! Evaluating Membership Leakage Risks In Code Models, Zhou Yang, Zhipeng Zhao, Chenyu Wang, Jieke Shi, Dongsum Kim, Donggyun Han, David Lo Dec 2024

Gotcha ! This Model Uses My Code ! Evaluating Membership Leakage Risks In Code Models, Zhou Yang, Zhipeng Zhao, Chenyu Wang, Jieke Shi, Dongsum Kim, Donggyun Han, David Lo

Research Collection School Of Computing and Information Systems

Leveraging large-scale datasets from open-source projects and advances in large language models, recent progress has led to sophisticated code models for key software engineering tasks, such as program repair and code completion. These models are trained on data from various sources, including public open-source projects like GitHub and private, confidential code from companies, raising significant privacy concerns. This paper investigates a crucial but unexplored question: What is the risk of membership information leakage in code models? Membership leakage refers to the vulnerability where an attacker can infer whether a specific data point was part of the training dataset. We present …


Towards Privacy-Aware Iot Communications: Delegable, Revocable, And Efficient, Pengfei Wu, Jianfei Sun, Guomin Yang, Robert H. Deng Dec 2024

Towards Privacy-Aware Iot Communications: Delegable, Revocable, And Efficient, Pengfei Wu, Jianfei Sun, Guomin Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

The Internet of Things (IoT) is widely recognized for its potential to enhance efficiency and productivity across various industries. However, its increasing prevalence has also made it a more attractive target for cybercriminals. While many advanced cryptographic solutions have been developed to secure IoT, some practical security and privacy issues such as self-sovereign delegation, flexible revocation, and lightweight access remain inadequately addressed in existing solutions. In this paper, we propose PLIC, a Privacy-aware Lightweight IoT Communication scheme, which not only enables any authorized user to flexibly delegate their lightweight access privileges to other delegatees, such that they can also access …