Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 11 of 201.

Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu PAN, Wanjing HAN, Yue DUAN, Mu ZHANG 2025 Singapore Management University

Collisionrepair: First‑Aid And Automated Patching For Storage Collision Vulnerabilities In Smart Contracts, Yu Pan, Wanjing Han, Yue Duan, Mu Zhang

Research Collection School Of Computing and Information Systems

Storage collision vulnerabilities, a significant security risk in upgradeable smart contracts, often arise when a user-facing proxy contract and a backend logic contract share storage space. While static analysis techniques can detect such issues, they often over-approximate program states, leading to false positives and requiring developers to manually verify each issue, giving attackers time to exploit any overlooked vulnerabilities. To address this, we propose COLLISIONREPAIR, an automated patching technique for mitigating storage collision risks. COLLISIONREPAIR monitors storage access sequences between proxy and logic contracts by defining an "ownership" property for storage locations. It then replays historical transactions to recover existing …


Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, YingTat NG, Zhe CHEN, Haiqing QIU, Xuhua DING 2025 Singapore Management University

Prism: To Fortify Widget Based User‑App Data Exchanges Using Android Virtualization Framework, Yingtat Ng, Zhe Chen, Haiqing Qiu, Xuhua Ding

Research Collection School Of Computing and Information Systems

We present Prism, an UI hardening technique for an Android app to safeguard its widgets against a corrupted kernel. Prism ensures secure interface rendering and allows for visual authentication, which developers could use to enable user intent confidentiality protection. Our design leverages the recent Android Virtualization Framework with minimal changes to the existing UI framework and graphics subsystem. It is much easier to deploy and use Prism on Android phones than TrustZone-based secure UI schemes, because the apps are not admitted to the Secure World and retain their full rights to manage and control their own interfaces. We have implemented …


Oblivious Digital Tokens, Mihael LISKIJ, Xuhua DING, Gene TSUDIK, David A. BASIN 2025 Singapore Management University

Oblivious Digital Tokens, Mihael Liskij, Xuhua Ding, Gene Tsudik, David A. Basin

Research Collection School Of Computing and Information Systems

A computing device typically identifies itself by exhibiting unique measurable behavior or by proving its knowledge of a secret. In both cases, the identifying device must reveal information to a verifier. Considerable research has focused on protecting identifying entities (provers) and reducing the amount of leaked data. However, little has been done to conceal the fact that the verification occurred.We show how this problem naturally arises in the context of digital emblems, which were recently proposed by the International Committee of the Red Cross to protect digital resources during cyber-conflicts. To address this new and important open problem, we define …


Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield 2025 University of South Alabama

Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield

Graduate Theses and Dissertations (2019 - present)

Real Time Operating Systems (RTOS) are increasing present throughout the industrial, business, defense, and healthcare spaces. These lightweight and efficient operating systems are designed to run on embedded, resource constrained devices, often within cyber-physical systems (CPS). A defining characteristic ofRTOSs is that they are deterministic. Tasks are scheduled to run on fixed timelines within guaranteed execution windows. In Industry 4.0 applications for example, sensors must receive and process inputs within a fixed schedule to ensure products are properly manufactured. This requires guaranteed service at fixed time periods. To accomplish this, RTOSs must conform to worst case execution times (WCETs) as …


Authentication And Message Integrity Verification For Emerging Wireless Networks, Ebuka Philip Oguchi 2025 University of Nebraska-Lincoln

Authentication And Message Integrity Verification For Emerging Wireless Networks, Ebuka Philip Oguchi

Dissertations and Doctoral Documents, University of Nebraska-Lincoln, 2023–

This dissertation presents a comprehensive body of research on authentication and message integrity verification for emerging wireless networks, focusing on secret-free and physical layer security techniques across diverse, challenging, and unconventional environments.

It comprises four first-author contributions that span underground wireless systems, over-the-air (OTA) channels, vehicular communications, and nanoscale molecular networks.

The first contribution, Soil-Assisted Trust Establishment for Underground Wireless Networks (STUN), introduces a physical-layer trust bootstrapping protocol that achieves authentication and message integrity without pre-shared secrets. Leveraging underground-to-air propagation laws and trusted relay nodes, STUN resists active signal injection attacks and demonstrates security comparable to the unbalanced oil and …


Improved Secure Two-Party Computation From A Geometric Perspective, Hao GUO, Liqiang PENG, Haiyang XUE, Li PENG, Weiran LIU, Zhe LIU, Lei. HU 2025 Singapore Management University

Improved Secure Two-Party Computation From A Geometric Perspective, Hao Guo, Liqiang Peng, Haiyang Xue, Li Peng, Weiran Liu, Zhe Liu, Lei. Hu

Research Collection School Of Computing and Information Systems

Multiplication and other non-linear operations are widely recognized as the most costly components of secure two-party computation (2PC) based on linear secret sharing. Moreover, the comparison protocol (or Wrap protocol) is essential for various operations such as truncation, signed extension, and signed non-uniform multiplication. This paper aims to optimize these protocols by avoiding invoking the costly comparison protocol, thereby improving their efficiency.We propose a novel approach to study 2PC from a geometric perspective. Specifically, we interpret the two shares of a secret as the horizontal and vertical coordinates of a point in a Cartesian coordinate system, with the secret itself …


Tetd: Trusted Execution In Trust Domains, Zhanbo WANG, Jiaxin ZHAN, Xuhua DING, Fengwei ZHANG, Ning HU 2025 Singapore Management University

Tetd: Trusted Execution In Trust Domains, Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang, Ning Hu

Research Collection School Of Computing and Information Systems

Intel TDX empowers cloud service providers to construct confidential virtual machines called trust domains (TDs) on x86 platforms. Similar to its counterparts from AMD and Arm, TDX's hardware based protection over integrity and secrecy of virtual machine memory and vCPU states inevitably hinders legitimate virtual machine management such as introspection. At the presence of compromised high-privileged software (e.g., the guest kernel), neither the cloud service provider nor the TD owner can securely carry out a task within the TD. To tackle this problem, we propose TETD, an in-TD trusted execution technique without trusting any TD system software. Our design does …


A Comprehensive Analysis Of Evolving Permission Usage In Android Apps: Trends, Threats, And Ecosystem Insights, Ali Alkinoon, Trung Cuong Dang, Ahod Alghuried, Abdulaziz Alghamdi, Soohyeon CHOI, Manar Mohaisen, An Wang, Saeed Salem, David Mohaisen 2025 Singapore Management University

A Comprehensive Analysis Of Evolving Permission Usage In Android Apps: Trends, Threats, And Ecosystem Insights, Ali Alkinoon, Trung Cuong Dang, Ahod Alghuried, Abdulaziz Alghamdi, Soohyeon Choi, Manar Mohaisen, An Wang, Saeed Salem, David Mohaisen

Research Collection School Of Computing and Information Systems

The proper use of Android app permissions is crucial to the success and security of these apps. Users must agree to permission requests when installing or running their apps. Despite official Android platform documentation on proper permission usage, there are still many cases of permission abuse. This study provides a comprehensive analysis of the Android permission landscape, highlighting trends and patterns in permission requests across various applications from the Google Play Store. By distinguishing between benign and malicious applications, we uncover developers’ evolving strategies, with malicious apps increasingly requesting fewer permissions to evade detection, while benign apps request more to …


A Review: The Beauty Of Serendipity Between Integrated Circuit Security And Artificial Intelligence, Chen DONG, Decheng QIU, Bolun LI, Yang YANG, Chenxi LYU, Dong CHENG, Hao ZHANG, Zhenyi. CHEN 2025 Singapore Management University

A Review: The Beauty Of Serendipity Between Integrated Circuit Security And Artificial Intelligence, Chen Dong, Decheng Qiu, Bolun Li, Yang Yang, Chenxi Lyu, Dong Cheng, Hao Zhang, Zhenyi. Chen

Research Collection School Of Computing and Information Systems

Integrated circuits are the core of a cyber-physical system, where tens of billions of components are integrated into a tiny silicon chip to conduct complex functions. To maximize utilities, the design and manufacturing life cycle of integrated circuits rely on numerous untrustworthy third parties, forming a global supply chain model. At the same time, this model produces unpredictable and catastrophic issues, threatening the security of individuals and countries. As for guaranteeing the security of ultra-highly integrated chips, detecting slight abnormalities caused by malicious behavior in the current and voltage is challenging, as is achieving computability within a reasonable time and …


Practical Keyword Private Information Retrieval From Key-To-Index Mappings, Meng HAO, Weiran LIU, Liqiang PENG, Cong ZHANG, Pengfei WU, Lei ZHANG, Hongwei LI, DENG, Robert H. 2025 Singapore Management University

Practical Keyword Private Information Retrieval From Key-To-Index Mappings, Meng Hao, Weiran Liu, Liqiang Peng, Cong Zhang, Pengfei Wu, Lei Zhang, Hongwei Li, Deng, Robert H.

Research Collection School Of Computing and Information Systems

This paper introduces practical schemes for keyword Private Information Retrieval (keyword PIR), enabling private queries on public databases using keywords. Unlike standard indexbased PIR, keyword PIR presents greater challenges, since the query’s position within the database is unknown and the domain of keywords is vast. Our key insight is to construct an efficient and compact key-to-index mapping, thereby reducing the keyword PIR problem to standard PIR. To achieve this, we propose three constructions incorporating several new techniques. The high-level approach involves (1) encoding the server’s key-value database into an indexable database with a key-to-index mapping and (2) invoking standard PIR …


Akma+: Security And Privacy-Enhanced And Standard-Compatible Akma For 5g Communication, Guomin YANG, Guomin YANG, Yingjiu LI, Minming HUANG, Zilin SHEN, Imtiaz KARIM, Ralf SASSE, David BASIN, Elisa BERTINO, Jian WENG, Hwee Hwa PANG, DENG, Robert H. 2025 Singapore Management University

Akma+: Security And Privacy-Enhanced And Standard-Compatible Akma For 5g Communication, Guomin Yang, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David Basin, Elisa Bertino, Jian Weng, Hwee Hwa Pang, Deng, Robert H.

Research Collection School Of Computing and Information Systems

The Authentication and Key Management for Applications (AKMA) protocol is a fundamental building block for security and privacy of 5G cellular networks. Therefore, it is critical that the protocol is free of vulnerabilities that can be exploited by attackers. Unfortunately, based on a detailed analysis of AKMA, we show that AKMA has several vulnerabilities that may lead to security and privacy breaches.We define AKMA+, an enhanced protocol for 5G communication that protects against security and privacy breaches while maintaining compatibility with existing standards. AKMA+ includes countermeasures for protecting communication between the user equipment (UE) and application functions (AFs) from attackers, …


Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur 2025 CUNY John Jay College

Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur

Student Theses

Perceptual hashing algorithms are algorithms that generate content-based image hashes by extracting perceptual features from the images. Unlike cryptographic hashes, which exhibit significant changes with even slight input alterations, perceptual hashes do not change when modifications like compression, color correction and brightness are applied to the images. These hashes are designed to remain similar for inputs that are visually or perceptually alike, which has led to their widespread application in detecting duplicate images, finding similar images for reverse image search and to detecting inappropriate content of Child sexual abuse (CSAM) images by comparing image hashes with dataset of known perceptual …


Detecting Misuse Of Security Apis: A Systematic Review, Zahra Mousavi, Chadni Islam, Muhammad Ali Babar, Alsharif Abuadbba, Kristen Moore 2025 Edith Cowan University

Detecting Misuse Of Security Apis: A Systematic Review, Zahra Mousavi, Chadni Islam, Muhammad Ali Babar, Alsharif Abuadbba, Kristen Moore

Research outputs 2022 to 2026

Security Application Programming Interfaces (APIs) are crucial for ensuring software security. However, their misuse introduces vulnerabilities, potentially leading to severe data breaches and substantial financial loss. Complex API design, inadequate documentation, and insufficient security training often lead to unintentional misuse by developers. The software security community has devised and evaluated several approaches to detecting security API misuse to help developers and organizations. This study rigorously reviews the literature on detecting misuse of security APIs to gain a comprehensive understanding of this critical domain. Our goal is to identify and analyze security API misuses, the detection approaches developed, and the evaluation …


In The Shadow Of Prompts: Adversarial Attacks And Model Cloning In Large Language Models, Kanchon Gharami 2025 Embry-Riddle Aeronautical University

In The Shadow Of Prompts: Adversarial Attacks And Model Cloning In Large Language Models, Kanchon Gharami

Doctoral Dissertations and Master's Theses

Large-language models (LLMs) already power mission critical tasks such as command-and-control chat, satellite ground-station automation, military analytics, and cyber-defense. Since most of these services are offered through application programming interfaces (APIs) that still expose full or top-k logits and lack mature safeguards, they present a serious, often overlooked attack surface. Earlier work has shown how to rebuild the output projection layer or distill surface behavior, but no attack has produced a deployable clone within a tight query budget. In this thesis, we address this problem by presenting a practical pipeline for cloning LLMs under constrained settings. The approach first estimates …


Research On The Capacity Development Of National Science And Technology Intelligence System, Hui LI, Shu CHEN, Xiao TAN 2025 Institute of Science and Technology Information, Beijing Academy of Science and Technology, Beijing 100044

Research On The Capacity Development Of National Science And Technology Intelligence System, Hui Li, Shu Chen, Xiao Tan

Journal of Scientific Information Research

[Purpose/significance] The unique form and systematic characteristics of great power competition, such as system-establishment and whole of society confrontation, multi-domain and multi-depth high-tech containment and counter-containment, and multi-means and multi-element mixed deterrence, determine that national scientific and technological intelligence must have considerable systemic capabilities to match and follow up.

[Method/process] This article focuses on scientific and technological intelligence institutions within the traditional system, defines the connotation of national scientific and technological intelligence system capabilities, constructs a six-dimensional capability cognition model of ""institutional improvement capability-system coordination capability-resource guarantee capability-technological innovation capability-intelligence shaping capability-safe operation capability"", and expounds its main contents.

[Result/conclusion] …


Syntax-Enhanced Boundary-Aware Named Entity Recognition Model, Chuanming YU, Bin DENG, Zhengang ZHANG 2025 School of Information Engineering, Zhongnan University of Economics and Law, Wuhan 430073

Syntax-Enhanced Boundary-Aware Named Entity Recognition Model, Chuanming Yu, Bin Deng, Zhengang Zhang

Journal of Scientific Information Research

[Purpose/significance] This study addresses the issue of inadequate perception of entity boundaries in traditional character-level modeling-based named entity recognition models by integrating syntax information containing entity boundary features into the task using a multi-head graph attention network with dense connections. This integration enhances the effectiveness of named entity recognition.

[Method/process] This study proposes a Syntax-enhanced Boundary-aware Named Entity Recognition Model (SynBNER), which utilizes BERT for text semantic representation and integrates syntax information using a dense-connected graph attention network. This integration incorporates implicit entity boundary information from syntax information into word representations, thereby enhancing the model's entity boundary perception capability.

[Result/conclusion] …


Thematic Hotspots And Strategy Analysis Of International Ai Regulatory Texts Based On Lda Models, Taitian MAO, Yihe PENG 2025 School of Public Administration of Xiangtan University, Xiangtan 411005

Thematic Hotspots And Strategy Analysis Of International Ai Regulatory Texts Based On Lda Models, Taitian Mao, Yihe Peng

Journal of Scientific Information Research

[Purpose/significance]This article conducts an in-depth exploration of international artificial intelligence (AI) regulatory policies and gains insights into the regulatory focuses and trends of various countries, with the aim of providing valuable references for global AI governance strategies.

[Method/process] This paper applies the LDA topic clustering analysis method to conduct an in-depth study of twenty-seven international policy documents. The aim is to accurately identify the topics, analyze the key theme words, and further reveal the regulatory hotspots in the field of artificial intelligence.

[Results/conclusion] The study reveals six core regulatory themes: systemic risk assessment, ethical and legal regulation, social impact governance, …


Unbounded Multi-Hop Proxy Re-Encryption With Hra Security: An Lwe-Based Optimization, Xiaohan WAN, Yang WANG, Haiyang XUE, Mingqiang WANG 2025 Singapore Management University

Unbounded Multi-Hop Proxy Re-Encryption With Hra Security: An Lwe-Based Optimization, Xiaohan Wan, Yang Wang, Haiyang Xue, Mingqiang Wang

Research Collection School Of Computing and Information Systems

Proxy re-encryption (PRE) schemes enable a semi-honest proxy to transform a ciphertext of one user i to another user j while preserving the privacy of the underlying message. Multi-hop PRE schemes allow a legal ciphertext to undergo multiple transformations, but for lattice-based multi-hop PREs, the number of transformations is typically bounded due to the increase of error terms. Recently, Zhao et al. (ESORICS 2024) introduced a lattice-based unbounded multi-hop (homomorphic) PRE scheme that supports an unbounded number of hops. Nevertheless, their scheme only achieves the selective CPA security. In contrast, Fuchsbauer et al. (PKC 2019) proposed a generic framework for …


An Incentive Mechanism For Privacy Preserved Data Trading With Verifiable Data Disturbance, Man ZHANG, Xinghua LI, Bin LUO, Yanbing REN, Yinbin MIAO, Ximeng LIU, Robert H. DENG 2025 Xidian University

An Incentive Mechanism For Privacy Preserved Data Trading With Verifiable Data Disturbance, Man Zhang, Xinghua Li, Bin Luo, Yanbing Ren, Yinbin Miao, Ximeng Liu, Robert H. Deng

Research Collection School Of Computing and Information Systems

To motivate data owners’ (DOs’) trading willingness, the existing incentive mechanisms allow DOs to independently disturb data following data consumer's (DC’s) availability requirement. However, they cannot motivate DOs’ honest disturbance, which is attributed to DOs’ independent disturbance without any supervision. Thus, we implement an incentive mechanism for privacy preserved data trading with verifiable data disturbance where an honest-but-curious disturbance generator (DG) is additionally introduced to supervise DOs’ local disturbance and assist disturbance verification between DOs and DC. Specifically, DG generates the disturbance strategies and secretly distributes to DOs following private information retrieval, guaranteeing DOs's local disturbance's privacy and verifiability with …


Full-Stack Web Applications: Infrastructure, Development Pipelines & Devsecops, Yassine Chahid, Patrick Slattery 2025 CUNY New York City College of Technology

Full-Stack Web Applications: Infrastructure, Development Pipelines & Devsecops, Yassine Chahid, Patrick Slattery

Publications and Research

This research explores emerging development methodologies and technologies which facilitate the deployment and maintenance of software applications. It evaluates architectural styles for the development of software such as monolithic (legacy) and microservice models, with a focus on their key differences such as scalability or project structure through to the development of an application. By examining methodologies such as Agile and continuous integration/continuous development pipelines along with the deployment tools Docker and Git for version/release control, the study analyzes how these innovations speed up development, improve existing practices, and serve as the foundation for development operations. Cloud solutions for tasks such …


Digital Commons powered by bepress