Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

454 Full-Text Articles 779 Authors 151,534 Downloads 99 Institutions

All Articles in Cybersecurity

Faceted Search

454 full-text articles. Page 9 of 23.

Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural 2025 Embry-Riddle Aeronautical University

Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural

Doctoral Dissertations and Master's Theses

With the rapid expansion of machine learning (ML) technologies across diverse domains such as healthcare, finance, and autonomous systems, ensuring secure and trustworthy training methodologies has become more critical than ever. Proof-of-Learning (PoL) has recently emerged as a foundational mechanism for verifying the computational effort invested in training ML models, thereby certifying the authenticity and reproducibility of the training process. Yet PoL, when deployed in isolation, remains vulnerable to sophisticated spoofing attacks that manipulate its subset-verification pathways and tolerance parameters. In parallel, model watermarking has become indispensable for safeguarding intellectual property and detecting unauthorized model usage. Motivated by these complementary …


The Effectiveness Of Scenario-Based Cybersecurity Day Camps In Southern Rural Appalachia, Anna P. Rodgers-Stine, Tania Williams 2025 The University of Alabama in Huntsville

The Effectiveness Of Scenario-Based Cybersecurity Day Camps In Southern Rural Appalachia, Anna P. Rodgers-Stine, Tania Williams

Journal of Cybersecurity Education, Research and Practice

As the emphasis on cybersecurity instruction in the K12 environment continues to expand, furthering access to cybersecurity education is paramount across the United States. While designated cybersecurity courses are not available in many schools, the implementation of cybersecurity camps may help to bridge the gap and increase student interest in and awareness of cybersecurity as a field. From 2021 through 2024, cybersecurity day camps were held in a region in rural southern Appalachia with the goal of increasing student interest and access to cybersecurity topics. Through the creation and implementation of these camps, it was found that scenario-based cybersecurity day …


Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez del Arroyo, Tor J. Langehaug, Scott R. Graham 2025 Air Force Institute of Technology

Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham

Faculty Publications

The primary focus of modern Central Processing Unit (CPU) technologies is performance improvement, with security often considered a secondary concern. As a result, vulnerabilities within the system are overlooked. While significant research, both offensive and defensive, has been conducted on CPU caches, relatively little attention has been given to the Translation Lookaside Buffer (TLB) due to its perceived lack of data granularity. Prior studies have typically combined multiple Hardware Performance Counters (HPCs) or relied on timing analysis to extract meaningful insights. In contrast, this study introduces a novel methodology that leverages only TLB related HPCs for multi-task classification, without incorporating …


Context-Switch Attacks: Understanding And Mitigating The Threat To Llm Applications, Sydney Holder, Bivin Sadler 2025 Southern Methodist University

Context-Switch Attacks: Understanding And Mitigating The Threat To Llm Applications, Sydney Holder, Bivin Sadler

SMU Data Science Review

Large Language Models (LLMs) are transforming conversational AI, yet their dependence on prompt-supplied context exposes them to context-switch attacks that covertly steer dialogue toward sensitive or malicious ends. A 70 one-sided conversation transcript evaluation set was constructed spanning various fraudulent scenarios. Each transcript embeds adversarial patterns drawn while preserving natural conversational flow. We introduce a hybrid defense that pairs a BERT-based semantic-drift detector (cosine-similarity threshold = 0.70) with a curated keyword and hack-phrase scanner to counter these threats. In aggregate, the system delivered 100 % recall, intercepting every simulated phishing or data-harvesting attempt. The keyword layer achieved perfect precision, generating …


Diversifying Cybersecurity: Evaluation Of An Internet Of Things (Iot)-Based Cybersecurity Training Course Designed To Bridge The Diversity Gap, Maureen Namukasa, Bhoomin B. Chauhan, Carlie Swords, Curtice Gough, Weronika Dymanus, Catherine Diresta, John Vitali, Vivek Sharma, T J. OConnor, Meredith Carroll 2025 Florida Institute of Technology

Diversifying Cybersecurity: Evaluation Of An Internet Of Things (Iot)-Based Cybersecurity Training Course Designed To Bridge The Diversity Gap, Maureen Namukasa, Bhoomin B. Chauhan, Carlie Swords, Curtice Gough, Weronika Dymanus, Catherine Diresta, John Vitali, Vivek Sharma, T J. Oconnor, Meredith Carroll

Aeronautics Faculty Publications

This study aimed to evaluate the effectiveness of an eight-module Cybersecurity course at increasing the learning outcomes of middle and high school students with little to no experience, including underrepresented minorities (URMs) in Cybersecurity. Twice we administered and evaluated the Cybersecurity course, which included hands-on IoT-based activities, utilizing collaborative learning, scaffolding, and representation-based learning strategies. Using a quasi-experimental, within-subjects, repeated measures design, each participant experienced a pretest, the course, and a post-test to evaluate the impact on learners’ self-efficacy, interest, and knowledge. The results revealed that (1) at pre-test, female (p = .001) and in one course administration minority …


Video Game Hacking, A General Problem With Generalized Solutions, Luke Rowe 2025 California Polytechnic State University, San Luis Obispo

Video Game Hacking, A General Problem With Generalized Solutions, Luke Rowe

Master's Theses

As video games continue to get more popular and lucrative, the number of malicious actors seeking to exploit them grows with it. As this industry expands, so does the importance of securing games against cheating and abuse. This thesis aims to educate developers to help mitigate the abuse of video games by these malicious actors. The goal of this thesis is to provide a foundational framework for thinking like a hacker and how to make games harder to abuse once a hacker bypasses conventional anti-cheat software.

This thesis outlines some of the most common cheating methods and provides general context …


Property Testing Ai: An Efficient Frontier, Paul Sopher Lintilhac 2025 Dartmouth College

Property Testing Ai: An Efficient Frontier, Paul Sopher Lintilhac

Dartmouth College Ph.D Dissertations

In this dissertation, we take a step towards addressing the major problem of a lack of standardized and rigorous approaches to testing and evaluation of AI systems. Taking inspiration from both the fields of Property Testing and Property Based Testing (for programs), we develop a novel taxonomy of partially overlapping classes of properties of AI systems, including simple properties, compound properties, higher order properties, data relation properties, and architecture-utility properties. We argue that this taxonomy categorizes a diverse set of AI traits -- including accuracy, fairness, robustness, monotonicity, point-wise and global privacy properties, sensitivity, and more -- according to the …


Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi 2025 California Polytechnic State University, San Luis Obispo

Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi

Master's Theses

Securing 95% of card present transactions, accounting for billions of transactions a year, has made EMV the premier protocol for card-based payment. Created by and named after Europay, Mastercard, and Visa, the EMV protocol provides multiple solutions to resolve security concerns with the outdated, swipe-based, magnetic stripe payment. Such solutions are Chip and PIN which provides a more secure transaction at a significant time cost and EMV contactless which provides improved security to Chip and PIN at greater ease of use with its quick, tap-to-pay based payment. However, regardless of how secure the EMV protocol makes the card side of …


Exploiting Compiler-Introduced Vulnerabilities In C: A Cross-Compiler And Cross-Architecture Analysis Of Undefined Behavior, Erik McCutchen 2025 California Polytechnic State University, San Luis Obispo

Exploiting Compiler-Introduced Vulnerabilities In C: A Cross-Compiler And Cross-Architecture Analysis Of Undefined Behavior, Erik Mccutchen

Master's Theses

Compilers are a critical component in generating secure software across engineering disciplines. However, languages like C that permit undefined behavior introduce a fundamental tension between the compiler’s interpretation of undefined behavior and the security of the generated code. This tension can result in security vulnerabilities that, from the programmer's perspective, are ``created'' by the compiler. The widespread use of these languages, combined with the complexity of modern optimizations and limited developer visibility into compiler behavior, makes these vulnerabilities both pervasive and difficult to detect.

Building on prior work, this thesis refines a dataset of C code snippets that exhibit Compiler-Introduced …


Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono 2025 Cal Poly

Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono

Master's Theses

In the realm of network security, Network Intrusion Detection Systems (NIDS) are essential for identifying and mitigating malicious activities targeting networked devices. Traditionally, these systems have relied on signature-based and anomaly-based detection techniques. However, the increasing complexity and adapt- ability of cyber threats have driven the adoption of Machine Learning (ML) ap- proaches in modern NIDS, significantly improving their ability to detect a wider range of attack vectors. Despite these advancements, ML-based NIDS remain vulnerable to adversarial examples—deliberately crafted inputs designed to mislead models and trigger incorrect classifications. Originally identified in the field of computer vision, adversarial examples now pose …


Some Studies On Information Set Decoding Algorithms And Universal Hash Functions, Sreyosi Bhattacharyya 2025 Indian Statistical Institute

Some Studies On Information Set Decoding Algorithms And Universal Hash Functions, Sreyosi Bhattacharyya

Doctoral Theses

This thesis presents some studies on Information Set Decoding algorithms and Universal Hash Functions. In the context of Information Set Decoding (ISD) the thesis studies time/memory trade-off of ISD algorithms and in the context of universal hash functions, the thesis studies design and efficient implementations of polynomial hash functions defined over prime order fields. A cornerstone of ISD algorithms is the algorithm proposed by Stern and it introduced the meet-in-the-middle collision search approach to ISD algorithms. Though this algorithm is more efficient in terms of asymptotic time complex- ity than the preceding algorithms proposed by Prange, Lee and Brickell and …


Dsa-Api: Data Standardization Automation Using Ai-Powered Apis, Andrew Asher Turner 2025 Louisiana Tech University

Dsa-Api: Data Standardization Automation Using Ai-Powered Apis, Andrew Asher Turner

Master's Theses

The common factor with current implementations of Artificial Intelligence (AI) is data. Companies are constantly looking for new ways to analyze data, but it comes in various formats: Text, Comma Separated Value (CVE), JavaScript Object Notation (JSON), Extensible Markup Language (XML), and Excel. How can AI be adapted to standardize formats for data analysis, integration, and digestion efficiently? Published research acknowledged that Machine Learning (ML) and AI can provide an automated method to speed up this process and limit the human decision-making error. With the advancement in AI, Application Programming Interfaces (APIs) prompt the idea that they can take in …


Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman 2025 Purdue University

Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman

Libraries Faculty and Staff Presentations

The 2025 Fiscal Year National Defense Authorization Act contains multiple provisions relating to artificial intelligence (AI). These congressionally mandated provisions direct various sections of the Department of Defense (DOD) and individual U.S. armed service branches to execute congressional intent for AI policymaking. Examples of such intent include identifying and planning DOD's AI workforce, demonstrating AI biotechnology applications for national security, improving the human usability of AI systems, and establishing an AI security center. This presentation will note that reports on these initiatives must be prepared for relevant congressional oversight committees, and, in many cases, are in many cases, publicly released …


Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory 2025 University of Mississippi

Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory

Honors Theses

Phishing attacks are a widespread, malicious phenomenon. These attacks steal people’s personal information, causing them ruin and lining the pockets of criminals. What makes them so dangerous is that they come in a variety of forms, including emails, websites, phone calls, and social media can be vectors for attackers. Fortunately, these attacks can be stopped by informing potential victims of common signs to look out for. Training is one of the best methods people use to teach web-users how to protect themselves. To train them, however, users must be taken through many examples of phishing attacks to learn the characteristics …


Harnessing Neurodiversity And Artificial Intelligence In Education To Bridge The Cybersecurity Workforce Gap, George Antoniou 2025 Lynn University

Harnessing Neurodiversity And Artificial Intelligence In Education To Bridge The Cybersecurity Workforce Gap, George Antoniou

Faculty and Staff Publications & Presentations

This perspective paper examines how neurodiversity and artificial intelligence (AI) can jointly address the critical workforce shortage in cybersecurity. Drawing on peer-reviewed research, industry reports, and case studies, it explores how neurodivergent individuals—such as those with autism spectrum disorders, ADHD, and dyslexia—possess strengths in pattern recognition, logical reasoning, and attention to detail that align with cybersecurity demands. AI-based educational tools, including adaptive tutoring systems, scenario-based simulations, and real-time analytics, can personalize learning for neurodiverse students, enhancing engagement and skill mastery. The paper discusses how these targeted interventions not only accelerate knowledge retention and practical competence but also foster greater inclusion …


Securing Distributed Energy Resources: A Secure Gateway For Modbus To Solid Communication Using A Raspberry Pi, Donna R. Thakadipuram 2025 University of Arkansas, Fayetteville

Securing Distributed Energy Resources: A Secure Gateway For Modbus To Solid Communication Using A Raspberry Pi, Donna R. Thakadipuram

Electrical Engineering and Computer Science Undergraduate Honors Theses

As distributed energy resources (DERs) such as solar panels, wind turbines, and battery storage systems become more common, securing their communications has become increasingly important. Many of these systems still rely on legacy communication protocols such as Modbus, which were not designed with cybersecurity in mind. This project addresses this challenge by developing a secure communication gateway that allows Modbus RTU devices to interface with decentralized Solid pods, which are personal data storage units that give users control over their information. This system is built on a Raspberry Pi 4, and it translates telemetry data from Modbus into a Solid-compatible …


Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto 2025 University of Arkansas, Fayetteville

Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto

Electrical Engineering and Computer Science Undergraduate Honors Theses

The power grid utilizes a device called the phasor measurement unit (PMU), allowing power system administrators to remotely monitor and manage the state of the grid in Wide Area Monitoring Systems (WAMS). The advantages of PMUs – such as fine-grained, time-synchronized measurements and efficient, decentralized monitoring – are what make them key devices in the power grid. However, PMU technology also comes with new threats of the digital age, like malfunctions and cyberattacks, which can result in missing and faulty measurements that compromise power grid observability. P4 programmable networks can be used to detect faulty PMU data in a decentralized, …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green 2025 Journal of Intelligent Informatics, Networking, and Cybersecurity

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Does The Transit Industry Understand The Risks Of Cybersecurity And Are The Risks Being Appropriately Prioritized?, Scott F. Belcher, Terri Belcher, James Grimes, Lusa Holmstrom, Andy Souders 2025 Mineta Transportation Institute

Does The Transit Industry Understand The Risks Of Cybersecurity And Are The Risks Being Appropriately Prioritized?, Scott F. Belcher, Terri Belcher, James Grimes, Lusa Holmstrom, Andy Souders

Mineta Transportation Institute

The intent of this study is to assess the readiness, resourcing, and capabilities of public transit agencies to detect, identify, be protected from, respond to, and recover from cybersecurity vulnerabilities and threats. This study is an update of the 2020 Mineta Transportation Institute (MTI) study, “Is the Transit Industry Prepared for the Cyber Revolution? Policy Recommendations to Enhance Surface Transit Cyber Preparedness.” In the previous study, the authors found that the transit industry was ill-prepared for cybersecurity attacks. Unfortunately, after four years and the development of new, and often free, resources, the situation has not markedly improved. In fact, this …


Managing Software Dependency Risks In Web Applications, Christopher Alan Scott 2025 Stephen F. Austin State University

Managing Software Dependency Risks In Web Applications, Christopher Alan Scott

Electronic Theses and Dissertations

Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security …


Digital Commons powered by bepress